All-in-one machine encryption communication transmission method and system based on dynamic strategy
By collecting the parameters of the all-in-one machine and the target communication partner in real time, calculating the risk index and matching the encryption strategy, and using segmented encryption and multi-channel transmission, the problem that the encryption communication transmission strategy in the existing technology cannot be dynamically adjusted, and the security and reliability improvement is achieved.
Patent Information
- Application Number
- CN202510682864.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-08-05
AI Technical Summary
The existing all-in-one encrypted communication transmission technology cannot dynamically adjust the encryption and transmission strategy according to the real-time communication environment and needs, resulting in insufficient security and efficiency, and cannot effectively ensure the security and reliability of communication.
By collecting the hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication partner in real time, calculating the risk index, matching the encryption algorithm sequence, key update frequency and transmission protocol, and using segmented encryption, multi-channel parallel transmission and distributed key management mechanisms to perform encrypted communication security verification.
It realizes dynamic optimization of encryption and transmission policies, enhances the security and reliability of communication, can effectively deal with complex and changeable communication environments, and ensures the security and reliability of data transmission.
Smart Images

Figure CN120434009A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication transmission technology, and in particular to an all-in-one encrypted communication transmission method and system based on dynamic strategy. Background Art
[0002] In today's digital age, all-in-one (AIM) devices, integrating multiple functions, are widely used in various fields, such as corporate offices, financial transactions, and smart security. With the increasing frequency and importance of information transmission, secure communication between AIMs and other devices has become crucial. Encrypted communication transmission technology is a core means of ensuring information security. It prevents the theft, tampering, or forgery of communication data, ensuring the confidentiality, integrity, and availability of information during transmission. With the rapid development of technologies such as the Internet of Things and cloud computing, the network environments connected to AIMs are becoming increasingly complex, and the security challenges they face are also increasing. Traditional fixed encryption and transmission strategies are difficult to adapt to this dynamically changing environment, and there is an urgent need for an encrypted communication transmission method that can flexibly adjust according to real-time conditions. A dynamic policy-based AIM encrypted communication transmission method and system aligns with this development trend and is expected to provide solid security for various AIM-based applications, with broad application prospects in the future of information security.
[0003] However, existing all-in-one encrypted communication transmission technologies lack sufficient understanding of communication environments and requirements. This makes it difficult to quantitatively assess communication risks, and there is a lack of effective mechanisms to rationally match detailed encryption and transmission strategies based on hardware status parameters, risk indexes, and communication content characteristics. This makes it difficult to precisely adapt encryption and transmission strategies to actual conditions. This impacts the security and efficiency of data transmission, and fails to effectively guarantee the security and reliability of communications.
[0004] Therefore, the present invention proposes an all-in-one encrypted communication transmission method and system based on dynamic strategy. Summary of the Invention
[0005] The present invention provides an all-in-one encrypted communication transmission method and system based on dynamic strategy. By real-time collection of hardware status parameters, network environment parameters and communication content characteristics of the all-in-one and the target communication peer, the communication status is fully understood, providing a basis for dynamic adjustment; the risk index is calculated based on the network environment parameters, and the risk is quantified to formulate encryption strategies in a targeted manner; the encryption algorithm sequence, key update frequency and transmission protocol are matched with multiple parameters to achieve an effective mechanism for reasonably matching detailed encryption and transmission strategies according to hardware status parameters, risk index and communication content characteristics, and also achieve dynamic optimization of encryption and transmission strategies, so that encryption and transmission strategies accurately adapt to actual conditions; segmented encryption, multi-channel parallel transmission and distributed key management mechanisms are used to enhance communication security and reliability; finally, encrypted communication security verification is performed based on security policy data and security keys to further ensure communication security, effectively cope with complex and changeable communication environments, and ensure safe and reliable data transmission.
[0006] The present invention provides an all-in-one encrypted communication transmission method based on a dynamic strategy, comprising: S1: Real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the integrated device and the target communication peer; S2: Calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; S3: Match the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer; S4: Based on the encryption algorithm sequence, key update frequency, and transmission protocol, the communication data of the integrated device is segmented and encrypted and transmitted in parallel over multiple channels. The distributed key management mechanism is used to distribute the secure key and obtain the secure key. S5: Perform encrypted communication security verification based on the security key to obtain communication verification data.
[0007] Optionally, S1: real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the all-in-one device and the target communication peer, including: Collect the maximum and current values of the CPU load, memory usage, and hard disk read and write throughput of the integrated device and the target communication peer in real time as hardware status parameters; Collect network environment parameters of the all-in-one machine and the target communication peer in the historical period; The data type, sensitivity level, target transmission frequency contained in the communication data of the all-in-one device in the historical period and the data type, sensitivity level, target transmission frequency contained in the communication data of the target communication peer in the historical period are collected in real time as communication content features.
[0008] Optionally, network environment parameters of the all-in-one device and the target communication peer in a historical period are collected, including: Collect historical characteristics of basic network performance, network topology status, network transmission status, network device status, and dynamic environment context of the integrated machine and the target communication peer over a historical period as network environment parameters of the integrated machine and the target communication peer over a historical period; Among them, the basic network performance historical characteristics include all historical bandwidth values, historical latency values, and historical packet loss rate values; The network topology status history features include the number of all transmission paths and routes, the historical value of the number of port connections, and the historical value of concurrent traffic; The historical characteristics of network transmission status include the security reputation level of the peer IP of all historical transmission tasks executed, protocol records, sensitivity level of transmission content, and historical network transmission throughput values during the execution of the corresponding historical transmission tasks; The network device status history feature includes the historical log exception records of all network devices; The dynamic environment context history features include the time periods and geographical areas of all historical transmission tasks executed.
[0009] Optionally, S2: calculating a risk index of the current communication process based on network environment parameters, including: Perform curve fitting on all similar historical records of each historical feature in the network environment parameters in time sequence to obtain all historical record curves of each historical feature; Determine the abnormality of each historical record curve at each moment in the historical period based on the first derivative function and the second derivative function of the function corresponding to each historical record curve; The abnormality of each historical record curve at all moments in the historical period is graded, and the relative abnormality level of each historical record curve at each moment in the historical period is determined; Based on the relative abnormality level of each historical record curve at all times in the historical period, all prominent abnormal intervals are marked in each historical record curve; The risk index of the current communication process is calculated based on all prominent abnormal intervals in all historical record curves.
[0010] Optionally, the risk index of the current communication process is calculated based on all prominent abnormal intervals in all types of historical record curves, including: According to the principle of starting time of all prominent anomaly intervals in all types of historical record curves of each historical feature from small to large, the starting time and corresponding data type of all prominent anomaly intervals in all types of historical record curves of each historical feature are sorted to obtain a prominent anomaly record sequence of the corresponding historical feature; The regularity of the prominent anomaly of each historical feature is calculated based on the prominent anomaly record sequence of each historical feature; According to the principle of starting time of all prominent abnormal intervals in all historical record curves of all historical features in ascending order, the starting time and corresponding data type of all prominent abnormal intervals in all historical record curves of all historical features are sorted to obtain a network environment prominent abnormal record sequence; Calculate the regularity of prominent anomalies in the network environment based on the prominent anomaly record sequence of the network environment; The risk index of the current communication process is calculated based on the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical characteristics.
[0011] Optionally, the regularity of the prominent anomaly of each historical feature is calculated based on the prominent anomaly record sequence of each historical feature, including: The mean of the difference between the starting times of all adjacent prominent anomaly intervals of the same data type in the prominent anomaly record sequence of each historical feature is taken as the average anomaly occurrence interval of the corresponding data type, and the similarity of the average anomaly occurrence intervals of all data types of each historical feature is taken as the first prominent anomaly regularity of the corresponding historical feature; The mean of the average anomaly occurrence intervals of all data types of the corresponding historical feature is used as the period division value of the corresponding historical feature, and the historical period is divided based on the period division value to obtain multiple sub-historical periods; Divide the outstanding anomaly record sequence of each historical feature based on all sub-historical periods of the historical period to obtain the outstanding anomaly record subsequence of each historical feature in each sub-historical period, assign a value to each data type in the outstanding anomaly record subsequence of each historical feature in each sub-historical period, and generate the outstanding anomaly type value sequence of each historical feature in each sub-historical period; Based on the prominent anomaly type value sequence of each historical feature in all sub-historical periods and the starting time of all prominent anomaly intervals in the prominent anomaly record subsequence, a prominent anomaly type value matrix and a prominent anomaly occurrence time matrix of each historical feature are generated; The second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature; The average of the first prominent abnormal regularity and the second prominent abnormal regularity of each historical feature is regarded as the prominent abnormal regularity corresponding to each historical feature.
[0012] Optionally, the second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature, including: Determine all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature and all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix; All inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature are matched with all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix and similarity is calculated to obtain the similarity of multiple inter-row difference vectors and multiple inter-column difference vectors of each historical feature; Perform singular value decomposition on the prominent anomaly type value matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly type value matrix. At the same time, perform singular value decomposition on the prominent anomaly occurrence time matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly occurrence time matrix. All left singular vectors and all right singular vectors of the prominent anomaly type value matrix of each historical feature are matched with all left singular vectors and all right singular vectors of the prominent anomaly occurrence moment matrix and similarity is calculated to obtain multiple left singular similarities and multiple right singular similarities of each historical feature; Based on all inter-row differential vector similarities, all inter-column differential vector similarities, all left singular similarities, and all right singular similarities of each historical feature, a differential similarity matrix of the corresponding historical feature is generated; The square value of the second norm of the differential similarity matrix of each historical feature is regarded as the second prominent abnormal regularity of each historical feature.
[0013] Optionally, the risk index of the current communication process is calculated based on the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical features, including: A weight is assigned to each historical feature, and the prominent abnormal regularity of the network environment and the prominent abnormal regularity of all historical features are weighted and fused in combination with the global regularity weight to obtain the risk index of the current communication process.
[0014] Optionally, S3: matching the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the all-in-one device and the target communication peer, including: Get the preset encryption policy matching list; Based on the hardware status parameters, risk index and communication content characteristics of the all-in-one device and the target communication peer, the preset encryption policy matching list is retrieved to match the corresponding encryption algorithm sequence, key update frequency and transmission protocol.
[0015] The present invention provides an all-in-one encrypted communication transmission system based on dynamic strategy, comprising: The status perception module is used to collect hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication end in real time; A risk calculation module is used to calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; A policy matching module is used to match encryption algorithm sequences, key update frequencies, and transmission protocols based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer. The encryption transmission module is used to perform segmented encryption and multi-channel parallel transmission of the integrated device communication data based on the encryption algorithm sequence, key update frequency, transmission protocol and target communication end, and to distribute security keys in combination with the distributed key management mechanism to obtain security keys; The security verification module is used to perform encrypted communication security verification based on security policy data and security keys to obtain communication verification data.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: by collecting the hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication peer in real time, the communication status can be fully grasped to provide a basis for dynamic adjustment; the risk index is calculated based on the network environment parameters, and the risk is quantified to formulate encryption strategies in a targeted manner; the encryption algorithm sequence, key update frequency and transmission protocol are matched with multiple parameters to achieve an effective mechanism for reasonably matching detailed encryption and transmission strategies according to hardware status parameters, risk index and communication content characteristics, and also to achieve dynamic optimization of encryption and transmission strategies, so that encryption and transmission strategies cannot accurately adapt to actual conditions; segmented encryption, multi-channel parallel transmission and distributed key management mechanism are used to enhance communication security and reliability; finally, encrypted communication security verification is performed based on security policy data and security keys to further ensure communication security, effectively cope with complex and changing communication environments, and ensure safe and reliable data transmission.
[0017] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.
[0018] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings: Figure 1 This is a flow chart of an all-in-one encrypted communication transmission method based on dynamic policy in an embodiment of the present invention; Figure 2 This is a block diagram of an all-in-one encrypted communication transmission system based on dynamic policies in an embodiment of the present invention. DETAILED DESCRIPTION
[0020] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0021] refer to Figure 1 The present invention provides an implementation of an all-in-one encrypted communication transmission method based on a dynamic strategy, comprising: S1: Real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the integrated device and the target communication peer; S2: Calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; S3: Match the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer; S4: Based on the encryption algorithm sequence, key update frequency, and transmission protocol, the communication data of the integrated device is segmented and encrypted and transmitted in parallel over multiple channels. The distributed key management mechanism is used to distribute the secure key and obtain the secure key. S5: Perform encrypted communication security verification based on the security key to obtain communication verification data.
[0022] The target communication peer refers to the device at the other end of the communication process with the all-in-one computer. For example, if the all-in-one computer is an office computer, the target communication peer could be a corporate server or other office terminal. Real-time information such as hardware status parameters and network environment parameters is collected to formulate and adjust the overall communication strategy.
[0023] An encryption algorithm sequence is a set of encryption algorithms arranged in a specific order, used to encrypt data transmitted by the appliance. Different encryption algorithms have different security and efficiency characteristics. The appropriate sequence is selected based on the hardware status parameters of the appliance and the target communication peer, the risk index, and the characteristics of the communication content. For example, algorithms such as AES and RSA may form an encryption algorithm sequence, first using AES for data encryption to ensure speed, and then using RSA encryption keys to enhance security.
[0024] Key update frequency: This specifies the interval or conditions for updating encryption keys during communications. When the risk index is high, you may need to increase the key update frequency to enhance communication security and prevent keys from being cracked due to prolonged use. For example, you can update the key every 10 minutes, or immediately update the key when the network risk index exceeds a certain threshold.
[0025] Transmission Protocol: This protocol manages the transmission rules for all-in-one communication data within the network, such as TCP and UDP. Select the appropriate transmission protocol based on actual communication needs and the environment to ensure accurate and efficient data transmission. For example, TCP is recommended for communications requiring high data accuracy, while UDP is recommended for communications requiring high real-time performance and a tolerance for minimal data loss.
[0026] Based on the encryption algorithm sequence, key update frequency, and transmission protocol, the integrated device communication data is segmented and encrypted and transmitted in parallel over multiple channels. Secure key distribution is achieved through a distributed key management mechanism. The selected encryption algorithm sequence divides the integrated device communication data into different segments and encrypts them separately, improving encryption flexibility and security. Furthermore, the encrypted data is transmitted in parallel over multiple channels to accelerate transmission. The distributed key management mechanism distributes key storage and management, avoiding the risks associated with centralized key management. Keys are then securely distributed between communicating parties, ultimately resulting in a secure key.
[0027] Encrypted communication security verification is performed based on a security key to generate communication verification data. The encrypted communication process is verified using the obtained security key to check the integrity of the communication data, verify that it has not been tampered with, and verify the legitimacy of the identities of both parties. The verification process adheres to specific security policies. Upon completion, communication verification data is generated, which is used to determine the security and reliability of the communication. For example, the sender uses the security key to generate a verification code for the data before transmitting it. The receiver uses the same key and algorithm to generate a verification code and compares it with the received code. If they match, the communication data is complete and secure, and corresponding verification pass data is generated. Otherwise, verification fail data is generated, indicating that the communication may be risky.
[0028] In an alternative embodiment, S1: real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the all-in-one device and the target communication peer includes: Collect the maximum and current values of the CPU load, memory usage, and hard disk read and write throughput of the integrated device and the target communication peer in real time as hardware status parameters; Collect network environment parameters of the all-in-one machine and the target communication peer in the historical period; The data type, sensitivity level, target transmission frequency contained in the communication data of the all-in-one device in the historical period and the data type, sensitivity level, target transmission frequency contained in the communication data of the target communication peer in the historical period are collected in real time as communication content features.
[0029] The maximum CPU load refers to the highest workload reached by the CPU during the past operation of the device and the target communication peer. This value can help you understand the device's CPU's ability to handle high-load tasks.
[0030] Current CPU Load: This value represents the current CPU workload on the device and the target communication peer. Real-time CPU load monitoring allows you to monitor the CPU's current workload.
[0031] Maximum Memory Usage: This is the highest percentage of total memory used by the device and its target peer during previous operations. This value reflects the device's maximum memory demand in a specific operating scenario.
[0032] Current Memory Usage: Indicates the current percentage of the used memory of the device and the target communication peer to the total memory.
[0033] Maximum hard drive read / write throughput: This refers to the highest amount of data that the hard drive and the target communication partner can read and write per unit time during past data transmissions. It reflects the data transmission capacity of the hard drive at its optimal state.
[0034] Current hard drive read / write throughput: This value represents the actual amount of data read and written per unit time by the hard drive on the integrated device and the target communication peer. Obtaining this value in real time provides an understanding of the hard drive's current data transfer speed.
[0035] A historical period is a preset time period used to collect and analyze network environment parameters, communication data characteristics, and other information about the device and its target communication peers. By analyzing data within this historical period, you can uncover operational patterns, trends, and potential risks associated with devices and networks. For example, if you set the historical period to the past week, changes in network environment parameters for that week will be collected.
[0036] Data type: refers to the type of data transmitted between the integrated machine and the target communication end, such as text, image, audio, video, database records, etc.
[0037] Sensitivity Level: This is used to measure the sensitivity of communication data and can be categorized as Public, General, Sensitive, and Top Secret. For example, communication data involving a company's core technology is classified as Top Secret and encrypted using the Advanced Encryption Standard and a strict key management mechanism.
[0038] Target transmission frequency: This refers to the desired frequency of communication data transmission, specifically the number of times or rate at which data is planned to be transmitted per unit time. For example, for video calls with high real-time requirements, the target transmission frequency is high, requiring a protocol that guarantees real-time transmission, and a minimally complex encryption algorithm that affects transmission speed. For non-real-time file transfers, the target transmission frequency is relatively low, so more secure encryption algorithms and transmission protocols can be selected, albeit at a slightly slower rate.
[0039] In an alternative embodiment, collecting network environment parameters of the all-in-one device and the target communication peer within a historical period includes: Collect historical characteristics of basic network performance, network topology status, network transmission status, network device status, and dynamic environment context of the integrated machine and the target communication peer over a historical period as network environment parameters of the integrated machine and the target communication peer over a historical period; Among them, the basic network performance historical characteristics include all historical bandwidth values, historical latency values, and historical packet loss rate values; The network topology status history features include the number of all transmission paths and routes, the historical value of the number of port connections, and the historical value of concurrent traffic; The historical characteristics of network transmission status include the security reputation level of the peer IP of all historical transmission tasks executed, protocol records, sensitivity level of transmission content, and historical network transmission throughput values during the execution of the corresponding historical transmission tasks; The network device status history feature includes the historical log exception records of all network devices; The dynamic environment context history features include the time periods and geographical areas of all historical transmission tasks executed.
[0040] All historical bandwidth values are recorded over a historical period, showing the bandwidth of the network connection between the appliance and the target communication peer. For example, records may show that the bandwidth is typically stable at 100 Mbps between 9:00 AM and 11:00 AM on weekdays, but may drop to 50 Mbps between 5:00 PM and 7:00 PM.
[0041] Historical latency values refer to the time it takes for data to be transmitted from the device or target peer over a historical period. For example, during certain periods of time, data transmission latency may suddenly increase from a normal 50ms to 200ms.
[0042] Packet loss rate: This value records the ratio of lost data packets to the total number of sent data packets during the historical period.
[0043] Total transmission paths and number of routes: This indicates all paths that data was transmitted between the appliance and the target communication peer during the historical period, as well as the number of routes included in each path.
[0044] Port connection history value: records the change in the number of port connections established between the integrated device and the target communication peer and other devices over time during the historical period.
[0045] Concurrent traffic history record value: refers to the recorded value of the total amount of all data flows passing through the network at the same time during the historical period.
[0046] The peer IP security reputation rating assesses the security of the target peer IP address communicating with the device or target peer. This rating is based on various factors, such as whether the IP has been involved in malicious activity and whether it has security vulnerabilities. For example, an IP with a high security reputation rating indicates reliable security and low communication risk. However, an IP with a low reputation rating may pose a potential threat and require more stringent security measures, such as enhanced encryption or additional authentication, to ensure communication security.
[0047] Protocol records: Records the various network protocols used by the all-in-one device or the target communication peer in transmission tasks within the historical period.
[0048] Transmission Content Sensitivity Level: This is a classification of the sensitivity of the data content in each transmission task within the historical period. Similar to the communication data sensitivity levels mentioned above, it is categorized as public, general, sensitive, and top secret.
[0049] Historical record value of network transmission throughput: the recorded value of the amount of data successfully transmitted per unit time during the execution of each historical transmission task.
[0050] Historical log anomaly records for all network devices: This includes anomalies recorded in logs generated by all network devices (such as routers and switches) involved in the appliance and its target communication peers during the historical period. These anomalies may include device failures, network attack attempts, and configuration errors. For example, a router log recording multiple abnormal connection requests from a specific IP address may indicate a network attack; a switch log showing a sudden increase in the port error rate may indicate a hardware problem.
[0051] Occurrence Time: Records the specific time intervals during which each transmission task occurred within the historical period. By analyzing the occurrence time, you can identify patterns in network usage. For example, high network traffic during certain periods may indicate peak office hours or specific business activity. These patterns can help you schedule communication tasks appropriately, avoiding critical data transmission during periods of network congestion or allocating more network resources in advance to meet peak demand. For example, if you discover that the network load is extremely high between 9:00 AM and 10:00 AM every Monday, you can schedule non-urgent data backup tasks at other times.
[0052] Geographic Region: This refers to the geographic location of the data sender and receiver for each transmission task within a historical period. Understanding the geographic region where transmission tasks occur is particularly important for multinational enterprises or distributed systems. Differences in network infrastructure, network regulations, and other factors can affect communication quality and security. For example, limited network bandwidth in some areas can result in slow transmission speeds, while data protection regulations vary from region to region. Encryption strategies and data storage methods may need to be adjusted based on regional characteristics to ensure that communications comply with local regulations while ensuring data security.
[0053] In an alternative embodiment, S2: calculating the risk index of the current communication process based on the network environment parameters includes: Perform curve fitting on all similar historical records of each historical feature in the network environment parameters in time sequence to obtain all historical record curves of each historical feature; the total number of types of all historical record curves of each historical feature is consistent with the total number of types of historical record values contained in the corresponding historical feature; Determine the abnormality of each historical record curve at each moment in the historical period based on the first derivative function and the second derivative function of the function corresponding to each historical record curve; The abnormality of each historical record curve at all moments in the historical period is graded, and the relative abnormality level of each historical record curve at each moment in the historical period is determined; Based on the relative abnormality level of each historical record curve at all times in the historical period, all prominent abnormal intervals are marked in each historical record curve; The risk index of the current communication process is calculated based on all prominent abnormal intervals in all historical record curves.
[0054] Each historical feature refers to a specific category of network environment parameters collected during a historical period. Examples include basic network performance historical features (such as bandwidth, latency, and packet loss rate), network topology status historical features (such as transmission paths and port connections), and network transmission status historical features. The data records in each category reflect the historical status of a specific aspect of the network.
[0055] Same type of historical record values: In each historical feature, data record values of the same type. For example, all bandwidth historical record values in the basic network performance historical feature belong to the same type of historical record values, which are used to describe the status of bandwidth at different time points.
[0056] Determine the abnormality degree of each historical record curve at each moment within the historical period based on the first derivative function and the second derivative function represented by the function corresponding to each historical record curve: Take the sum of the first derivative function values and the second derivative function values of the first derivative function and the second derivative function represented by the function corresponding to each historical record curve at each moment within the historical period as the abnormality degree of each historical record curve at each moment within the historical period. Calculate the abnormality degree at each moment within the historical period in this way. The greater the abnormality degree, the more剧烈 the data change at that moment, and there may be an abnormality.
[0057] Classify the abnormality degrees of each historical record curve at all moments within the historical period to determine the relative abnormality level of each historical record curve at each moment within the historical period: Suppose based on experience or data analysis, the abnormality degree is divided into three levels: low (abnormality degree A ≤ 1), medium (1 < A ≤ 3), high (A > 3).
[0058] According to this standard, assume that at the moment x = 5, the abnormality degree is 3.2, and its relative abnormality level is "high". By classifying the abnormality degree of each moment in this way, the relative abnormality level of each moment within the historical period is obtained, so as to intuitively reflect the abnormality degree of the data at each moment.
[0059] Based on the relative abnormality levels of each historical record curve at all moments within the historical period, mark all prominent abnormal intervals on each historical record curve: When the relative abnormality level continuously remains at a high level, these continuous time periods can be marked as prominent abnormal intervals. For example, from the moment x = 4 to x = 6, the relative abnormality level is "high", then the time period [4, 6] is a prominent abnormal interval on this historical record curve. By marking the prominent abnormal intervals, it is possible to more clearly find the time periods when the network environment parameters are abnormal within the historical period, providing a basis for subsequent risk assessment.
[0060] In an alternative implementation, calculate the risk index of the current communication process based on all prominent abnormal intervals in all historical record curves, including: According to the principle of arranging the start times of all prominent abnormal intervals in all historical record curves of each historical feature from small to large, sort the start times and corresponding data types of all prominent abnormal intervals in all historical record curves of each historical feature to obtain the prominent abnormal record sequence of the corresponding historical feature; Calculate the prominent abnormal regularity degree of each historical feature based on the prominent abnormal record sequence of each historical feature; According to the principle of arranging the start times of all prominent abnormal intervals in all historical record curves of all historical features from small to large, sort the start times and corresponding data types of all prominent abnormal intervals in all historical record curves of all historical features to obtain the network environment prominent abnormal record sequence; Calculate the prominent abnormal regularity degree of the network environment based on the network environment prominent abnormal record sequence; Calculate the risk index of the current communication process based on the prominent abnormal regularity degree of the network environment and the prominent abnormal regularity degrees of all historical features.
[0061] Among them, calculating the prominent abnormal regularity degree of the network environment based on the network environment prominent abnormal record sequence includes: Sort the prominent abnormal intervals to obtain the network environment prominent abnormal record sequence: Sort the start times and corresponding data types of the prominent abnormal intervals in all historical record curves of all historical features in ascending order of the start time, so as to obtain the network environment prominent abnormal record sequence. For example, there are three prominent abnormal intervals, coming from the historical record curves of bandwidth, latency, and packet loss rate respectively. The start time of the first interval is t1 (corresponding to bandwidth data), the start time of the second interval is t2 (corresponding to latency data), and the start time of the third interval is t3 (corresponding to packet loss rate data) and t1 < t2 < t3. After sorting, the network environment prominent abnormal record sequence is the start times and corresponding data types of these three intervals arranged in this order.
[0062] Calculate the average abnormal occurrence interval and similarity to obtain the first prominent abnormal regularity degree: For the same data type in the network environment prominent abnormal record sequence (such as the prominent abnormal intervals related to bandwidth), calculate the average of the differences between the start times of all adjacent prominent abnormal intervals as the average abnormal occurrence interval of this data type. Suppose there are three prominent abnormal intervals related to bandwidth, with start times tb1, tb2, and tb3 respectively, then the average abnormal occurrence interval Tb = [(tb2 - tb1) + (tb3 - tb2)] ÷ 2.
[0063] Calculate the similarity of the average anomaly occurrence intervals for all data types (such as bandwidth, latency, and packet loss rate) and use this similarity as the first prominent anomaly regularity. For example, use the Pearson correlation coefficient to calculate similarity. Assume that the average anomaly occurrence intervals for bandwidth, latency, and packet loss rate are Tb, Td, and Tl, respectively. Calculate the similarity between them using the Pearson correlation coefficient formula to obtain the first prominent anomaly regularity.
[0064] According to the similarity division cycle and the generation matrix, the second prominent abnormal regularity is obtained: The mean of the average anomaly occurrence intervals for all data types is used as the period partition value. Based on this value, the historical period is divided into multiple sub-periods. For example, if the average anomaly occurrence intervals are Tb = 5, Td = 6, and Tl = 4, the mean is (5 + 6 + 4) ÷ 3 = 5. Using 5 as the period partition value, the historical period is divided into multiple sub-periods of length 5.
[0065] The prominent anomaly record sequence is divided into sub-historical periods to obtain a sub-sequence of prominent anomaly records for each sub-historical period. Each data type in each sub-historical period's sub-sequence is assigned a value to generate a sequence of prominent anomaly type values. For example, if a sub-historical period's prominent anomaly record sub-sequence contains bandwidth- and latency-related anomalies, the bandwidth anomaly is assigned a value of 1 and the latency anomaly is assigned a value of 2, resulting in a sequence of prominent anomaly type values [1, 2].
[0066] Based on the prominent anomaly type value sequence of all sub-historical periods and the starting time of the prominent anomaly interval in the prominent anomaly record sub-sequence, the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix are generated. Assuming that the prominent anomaly type value sequences of the three sub-historical periods obtained through the above steps are [1,2], [2], [1], and the corresponding prominent anomaly interval starting times are ts1, ts2, ts3, and ts4, the prominent anomaly type value matrix is (Zero padding makes the matrix dimensions consistent), highlighting the matrix at the time of abnormality occurrence is .
[0067] Determine the inter-row and inter-column difference vectors of the two matrices and calculate their similarity. Simultaneously, perform singular value decomposition on the two matrices, calculate the similarity between the corresponding singular vectors, and generate a differential similarity matrix based on these similarities. For example, calculate the inter-row difference vector similarity, inter-column difference vector similarity, left singular similarity, and right singular similarity of the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix to form a differential similarity matrix.
[0068] The square value of the second norm of the difference similarity matrix is regarded as the second prominent abnormal regularity.
[0069] Calculating the Prominent Anomaly Regularity of the Network Environment: The average of the first and second Prominent Anomaly Regularity is used as the Prominent Anomaly Regularity. Assuming the first Prominent Anomaly Regularity is R1 and the second Prominent Anomaly Regularity is R2, then the Prominent Anomaly Regularity is R = (R1 + R2) ÷ 2. In short, the calculation logic for calculating the Prominent Anomaly Regularity based on the sequence of network environment prominent anomaly records is the same as the calculation logic for calculating the Prominent Anomaly Regularity for each historical feature based on the sequence of prominent anomaly records for each historical feature. This value is used to measure the regularity of network environment prominent anomalies and provides a basis for calculating the risk index of the current communication process.
[0070] In an alternative embodiment, the regularity of the prominent anomaly of each historical feature is calculated based on the sequence of prominent anomaly records of each historical feature, including: The mean of the difference between the starting times of all adjacent prominent anomaly intervals of the same data type in the prominent anomaly record sequence of each historical feature is taken as the average anomaly occurrence interval of the corresponding data type, and the similarity of the average anomaly occurrence intervals of all data types of each historical feature is taken as the first prominent anomaly regularity of the corresponding historical feature; The mean of the average anomaly occurrence intervals of all data types of the corresponding historical feature is used as the period division value of the corresponding historical feature, and the historical period is divided based on the period division value to obtain multiple sub-historical periods; Divide the outstanding anomaly record sequence of each historical feature based on all sub-historical periods of the historical period, obtain the outstanding anomaly record subsequence of each historical feature in each sub-historical period, assign values to each data type in the outstanding anomaly record subsequence of each historical feature in each sub-historical period, and generate the outstanding anomaly type value sequence of each historical feature in each sub-historical period; Based on the prominent anomaly type value sequence of each historical feature in all sub-historical periods and the starting time of all prominent anomaly intervals in the prominent anomaly record subsequence, a prominent anomaly type value matrix and a prominent anomaly occurrence time matrix of each historical feature are generated; The second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature; The average of the first prominent abnormal regularity and the second prominent abnormal regularity of each historical feature is regarded as the prominent abnormal regularity corresponding to each historical feature.
[0071] Among them, the similarity of the average anomaly occurrence interval of all data types of each historical feature is: When calculating the average anomaly occurrence interval similarity for a specific historical characteristic (such as basic network performance historical characteristics, including data types such as bandwidth, latency, and packet loss rate), first calculate the average anomaly occurrence interval for each data type (e.g., bandwidth, latency, and packet loss rate). For example, for the bandwidth data type, the start times of adjacent prominent anomaly intervals are tb1, tb2, and tb3, respectively. Their average anomaly occurrence interval is Tb = [(tb2 - tb1) + (tb3 - tb2)] / 2. The corresponding average anomaly occurrence interval for the latency data type is Td, and the corresponding average anomaly occurrence interval for the packet loss rate data type is Tl.
[0072] The ratio of the difference between the average anomaly occurrence time intervals of the pairwise data types of each historical feature to a preset time (e.g., 100 hours) is used as the deviation of the average anomaly occurrence time intervals of the pairwise data types of each historical feature; The deviation between 1 and the average anomaly occurrence time interval of each pairwise data type of each historical feature is regarded as the similarity of the average anomaly occurrence time interval of the corresponding two data types of the corresponding historical feature; The mean of the similarities of the average anomaly occurrence time intervals between two data types of each historical feature is taken as the similarity of the average anomaly occurrence time intervals of all data types of the corresponding historical feature.
[0073] Assign a value to each data type in the subsequence of prominent anomaly records of each historical feature in each sub-historical period, and generate a sequence of prominent anomaly type values of each historical feature in each sub-historical period: After the historical period is divided into multiple sub-periods based on the similarity of the average anomaly occurrence interval, the outstanding anomaly record subsequence within each sub-period is processed. For example, the outstanding anomaly record subsequence of a sub-period contains anomaly records of two data types: bandwidth and port connection number.
[0074] To distinguish anomalies of different data types, each data type is assigned a specific value. For example, if bandwidth anomalies are assigned a value of 1 and port connection number anomalies are assigned a value of 3, then the sequence of prominent anomaly type values generated in this sub-historical period will be [1, 3]. In this way, a corresponding sequence of prominent anomaly type values is generated for each historical feature in each sub-historical period, which is used to subsequently construct a matrix and analyze anomaly patterns.
[0075] Based on the prominent anomaly type value sequence of each historical feature in all sub-historical periods and the starting time of all prominent anomaly intervals in the prominent anomaly record subsequence, the prominent anomaly type value matrix and prominent anomaly occurrence time matrix of each historical feature are generated: Taking the basic network performance history characteristics as an example, assume that n sub-historical periods are divided and n prominent anomaly type value sequences are obtained, such as [1,2], [3], [1], etc. (corresponding to different sub-historical periods). These sequences are organized into a matrix form. If the number of elements in a sub-historical period sequence is less than that of other sequences, zeros are added to make the matrix dimension consistent, thereby generating a prominent anomaly type value matrix. For example, the prominent anomaly type value matrix composed of these three sequences is .
[0076] For the prominent anomaly occurrence time matrix, the starting time of the prominent anomaly interval in the prominent anomaly record subsequence in each sub-historical period is arranged into a matrix according to the sub-historical period order. Assuming that the starting time of the prominent anomaly interval in the above three sub-historical periods are t1, t2, t3, and t4 respectively, the prominent anomaly occurrence time matrix is These two matrices contain information about the anomaly type and the time of occurrence, which can be used for subsequent analysis such as calculating anomaly regularity.
[0077] In an alternative embodiment, the second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature, including: Determine all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature and all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix; All inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature are matched with all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix and similarity is calculated to obtain the similarity of multiple inter-row difference vectors and multiple inter-column difference vectors of each historical feature; Perform singular value decomposition on the prominent anomaly type value matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly type value matrix. At the same time, perform singular value decomposition on the prominent anomaly occurrence time matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly occurrence time matrix. All left singular vectors and all right singular vectors of the prominent anomaly type value matrix of each historical feature are matched with all left singular vectors and all right singular vectors of the prominent anomaly occurrence moment matrix and similarity is calculated to obtain multiple left singular similarities and multiple right singular similarities of each historical feature; Based on all inter-row differential vector similarities, all inter-column differential vector similarities, all left singular similarities, and all right singular similarities of each historical feature, a differential similarity matrix of the corresponding historical feature is generated; The square value of the second norm of the differential similarity matrix of each historical feature is regarded as the second prominent abnormal regularity of each historical feature.
[0078] Among them, the inter-row difference vector: For a matrix, the inter-row difference vector is an element formed by calculating the absolute value of the difference between the elements at the same position in different rows of the matrix. For example, for the matrix , the difference vector between the first and second rows is .
[0079] Inter-column difference vector: Similarly, for a matrix, it is an element formed by calculating the absolute value of the difference between the elements at the same position in different columns of the matrix. For example, for the matrix , the inter-row difference vector between the first and second columns is . .
[0080] All inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature are matched with all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix and similarity is calculated to obtain the similarity of multiple inter-row difference vectors and multiple inter-column difference vectors of each historical feature: When calculating similarity, methods such as cosine similarity can be used. For example, based on cosine similarity, the similarity between the difference vectors between the first and second rows of the prominent anomaly type value matrix of each historical feature and the difference vectors between the first and second rows of the prominent anomaly occurrence time matrix is calculated; Then, based on the cosine similarity, the similarity between the difference vectors between the second and third rows of the prominent anomaly type value matrix of each historical feature and the difference vectors between the second and third rows of the prominent anomaly occurrence time matrix is calculated; Then, based on the cosine similarity, the similarity between the row difference vectors of the first and second columns of the prominent anomaly type value matrix of each historical feature and the column difference vectors of the first and second columns of the prominent anomaly occurrence time matrix is calculated.
[0081] Left and right singular vectors: These are the results of singular value decomposition (SVD) of a matrix. For a matrix M (m×n), SVD yields M = UΣVT, where the column vectors of U (m×m) are the left singular vectors, and the column vectors of V (n×n) are the right singular vectors. Σ (m×n) is a diagonal matrix, with the diagonal elements being singular values. Left and right singular vectors can reflect the key characteristics and structural information of the matrix data from different perspectives.
[0082] All left singular vectors and all right singular vectors of the prominent anomaly type value matrix of each historical feature are matched with all left singular vectors and all right singular vectors of the prominent anomaly occurrence moment matrix and similarity is calculated to obtain multiple left singular similarities and multiple right singular similarities of each historical feature: The matrix B at the time of the prominent anomaly is also subjected to singular value decomposition to obtain B=UbΣbVbT, and the left singular vector and right singular vector of B are obtained.
[0083] Then, the left singular vectors of the prominent anomaly type value matrix A are matched with the corresponding left singular vectors of the prominent anomaly occurrence time matrix B. Using an appropriate similarity calculation method (such as cosine similarity), the similarity of each pair of corresponding left singular vectors is calculated to obtain multiple left singular similarities. Similarly, a similar operation is performed on the right singular vectors to obtain multiple right singular similarities. These similarities further measure the similarity between the anomaly type matrix and the anomaly occurrence time matrix from the perspective of matrix structural characteristics.
[0084] Based on the difference vector similarities between all rows, all columns, all left singular similarities, and all right singular similarities of each historical feature, the difference similarity matrix of the corresponding historical feature is generated: Assume that a inter-row difference vector similarities, b inter-column difference vector similarities, p left singular similarities, and q right singular similarities are obtained.
[0085] Arrange these similarity values into a matrix in a certain order, for example: The first row of the difference similarity matrix is: inter-row difference vector similarity 1⋯inter-row difference vector similarity a; The second row of elements is: inter-column difference vector similarity 1⋯inter-column difference vector similarity b; The third row of elements is: left singular similarity 1⋯left singular similarity p; The fourth row of elements is: right singular similarity 1⋯right singular similarity q; The row elements of the differential similarity matrix can be padded with zeros to make the matrix column dimensions consistent.
[0086] This differential similarity matrix combines multiple indicators to measure the similarity between the two matrices, and is used to subsequently calculate the second prominent abnormal regularity of each historical feature, thereby comprehensively evaluating the regular characteristics of network environment anomalies.
[0087] In an alternative embodiment, the risk index of the current communication process is calculated based on the prominent abnormal regularity of the network environment and the prominent abnormal regularity of all historical features, including: Assign a weight to each historical feature, and combine the global regularity weight to weightedly fuse the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical features to obtain the risk index of the current communication process, including: Assign weights to each historical feature: Different historical features (such as basic network performance and network topology) have varying degrees of impact on network communication risk, so they should be assigned different weights. For example, basic network performance historical features have a greater impact on communication risk and could be assigned a weight of 0.4; network topology historical features have a lower impact and could be assigned a weight of 0.3; and other historical features (such as network transmission status, network device status, and dynamic environment context) could be assigned a total weight of 0.3. These weights are typically determined based on experience, in-depth understanding of the network system, or through data analysis to reflect the relative importance of each historical feature in assessing communication risk.
[0088] Global Regularity Weight: This is a weight used to adjust the relationship between the network environment's prominent anomaly regularity and the prominent anomaly regularity of all historical features. Assuming the global regularity weight is set to 0.6, it indicates the emphasis placed on overall regularity when integrating the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical features when calculating the risk index.
[0089] Weighted fusion calculation risk index: Assume that the regularity of prominent anomalies in the network environment is Rnet, and the regularities of prominent anomalies of all historical features are R1 (basic network performance), R2 (network topology status), R3 (network transmission status), R4 (network device status), and R5 (dynamic environment context), and the weights w1=0.4, w2=0.3, w3=w4=w5=0.1 have been assigned.
[0090] First, calculate the weighted sum S=w1R1+w2R2+w3R3+w4R4+w5R5 of all historical characteristics’ prominent anomaly regularity.
[0091] Then, based on the global regularity weight W = 0.6, the risk index of the current communication process is calculated using the formula RiskIndex = W × Rnet + (1 - W) × S. For example, if Rnet = 0.7 and S = 0.6, the risk index is RiskIndex = 0.6 × 0.7 + (1 - 0.6) × 0.6 = 0.42 + 0.24 = 0.66. A higher risk index indicates a greater risk for the current communication process, which can be used to adjust encryption and transmission strategies to ensure communication security.
[0092] In an alternative embodiment, S3: matching the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer includes: Get the preset encryption policy matching list; Based on the hardware status parameters, risk index and communication content characteristics of the all-in-one device and the target communication peer, the preset encryption policy matching list is retrieved to match the corresponding encryption algorithm sequence, key update frequency and transmission protocol.
[0093] The preset encryption policy matching list is a pre-defined list used to quickly match appropriate encryption algorithm sequences, key update frequencies, and transmission protocols based on the hardware status parameters, risk index, and communication content characteristics of the all-in-one device and the target communication peer. This list is typically constructed by network security experts and engineers based on their in-depth understanding and experience of different hardware performance, network risk conditions, and communication content characteristics. For example, factors such as the impact of varying CPU loads and memory usage on encryption algorithm execution efficiency, as well as the encryption strength requirements for communication data of varying sensitivity levels, are considered. The list is presented in a structured format, perhaps as a two-dimensional table or database table. Rows or records represent different matching rules, while columns correspond to different parameters and matching results. For example, the first column might record the hardware status parameter range (e.g., current CPU load less than 30%, current memory usage less than 50%), the second column the risk index range (e.g., risk index less than 0.5), and the third column the communication content characteristics (e.g., data type is text, sensitivity level is normal). Subsequent columns correspond to the matched encryption algorithm sequence (e.g., AES-128 followed by RSA for key encryption), key update frequency (e.g., every 30 minutes), and transmission protocol (e.g., TCP). After obtaining the real-time hardware status parameters of the all-in-one device and the target communication peer, calculating the risk index, and identifying the communication content characteristics, the system can use this information to quickly search the preset encryption policy matching list to quickly find the corresponding encryption algorithm sequence, key update frequency, and transmission protocol. This allows for dynamic and appropriate selection of encryption and transmission strategies based on actual conditions, ensuring the security and transmission efficiency of communication data under different circumstances.
[0094] refer to Figure 2 The present invention provides an implementation scheme of an all-in-one encrypted communication transmission system based on a dynamic strategy, comprising: The status perception module is used to collect hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication end in real time; A risk calculation module is used to calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; A policy matching module is used to match encryption algorithm sequences, key update frequencies, and transmission protocols based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer. The encryption transmission module is used to perform segmented encryption and multi-channel parallel transmission of the integrated device communication data based on the encryption algorithm sequence, key update frequency, transmission protocol and target communication end, and to distribute security keys in combination with the distributed key management mechanism to obtain security keys; The security verification module is used to perform encrypted communication security verification based on security policy data and security keys to obtain communication verification data.
[0095] The above system fully grasps the communication status by collecting the hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication end in real time, providing a basis for dynamic adjustment; calculates the risk index based on the network environment parameters, quantifies the risk and formulates a targeted encryption strategy; combines multiple parameters to match the encryption algorithm sequence, key update frequency and transmission protocol, and realizes an effective mechanism for reasonably matching detailed encryption and transmission strategies according to hardware status parameters, risk index and communication content characteristics, and also realizes dynamic optimization of encryption and transmission strategies, making it impossible for encryption and transmission strategies to accurately adapt to actual conditions; uses segmented encryption, multi-channel parallel transmission and distributed key management mechanisms to enhance communication security and reliability; finally, performs encrypted communication security verification based on security policy data and security keys to further ensure communication security, effectively cope with complex and changing communication environments, and ensure safe and reliable data transmission.
[0096] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalents, the present invention is intended to include these modifications and variations.
Claims
1. A dynamic strategy-based all-in-one encrypted communication transmission method, characterized in that: include: S1: Real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the integrated device and the target communication peer; S2: Calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; S3: Match the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer; S4: Based on the encryption algorithm sequence, key update frequency, and transmission protocol, the communication data of the integrated device is segmented and transmitted in parallel through multiple channels. In addition, a distributed key management mechanism is used to distribute secure keys and obtain security keys. S5: Perform encrypted communication security verification based on the security key to obtain communication verification data.
2. The method for encrypted communication transmission based on dynamic strategy according to claim 1, characterized in that: S1: Real-time collection of hardware status parameters, network environment parameters, and communication content characteristics of the integrated device and the target communication peer, including: Collect the maximum and current values of the CPU load, memory usage, and hard disk read and write throughput of the integrated device and the target communication peer in real time as hardware status parameters; Collect network environment parameters of the all-in-one machine and the target communication peer in the historical period; The data type, sensitivity level, target transmission frequency contained in the communication data of the all-in-one device in the historical period and the data type, sensitivity level, target transmission frequency contained in the communication data of the target communication peer in the historical period are collected in real time as communication content features.
3. The method for encrypted communication transmission based on dynamic strategy according to claim 2, characterized in that: Collects network environment parameters of the integrated device and the target communication peer over a historical period, including: Collect historical characteristics of basic network performance, network topology status, network transmission status, network device status, and dynamic environment context of the integrated machine and the target communication peer over a historical period as network environment parameters of the integrated machine and the target communication peer over a historical period; Among them, the basic network performance historical characteristics include all historical bandwidth values, historical latency values, and historical packet loss rate values; The network topology status history features include the number of all transmission paths and routes, the historical value of the number of port connections, and the historical value of concurrent traffic; The historical characteristics of network transmission status include the security reputation level of the peer IP of all historical transmission tasks executed, protocol records, sensitivity level of transmission content, and historical network transmission throughput values during the execution of the corresponding historical transmission tasks; The network device status history feature includes the historical log exception records of all network devices; The dynamic environment context history features include the time periods and geographical areas of all historical transmission tasks executed.
4. The method for encrypted communication transmission based on dynamic strategy according to claim 1, characterized in that: S2: Calculates the risk index of the current communication process based on network environment parameters, including: Perform curve fitting on all similar historical records of each historical feature in the network environment parameters in time sequence to obtain all historical record curves of each historical feature; Determine the abnormality of each historical record curve at each moment in the historical period based on the first derivative function and the second derivative function of the function corresponding to each historical record curve; The abnormality of each historical record curve at all moments in the historical period is graded, and the relative abnormality level of each historical record curve at each moment in the historical period is determined; Based on the relative abnormality level of each historical record curve at all times in the historical period, all prominent abnormal intervals are marked in each historical record curve; The risk index of the current communication process is calculated based on all prominent abnormal intervals in all historical record curves.
5. The method for encrypted communication transmission based on dynamic strategy according to claim 4, characterized in that: Calculate the risk index of the current communication process based on all prominent abnormal intervals in all historical curves, including: According to the principle of starting time of all prominent anomaly intervals in all types of historical record curves of each historical feature from small to large, the starting time and corresponding data type of all prominent anomaly intervals in all types of historical record curves of each historical feature are sorted to obtain a prominent anomaly record sequence of the corresponding historical feature; The regularity of the prominent anomaly of each historical feature is calculated based on the prominent anomaly record sequence of each historical feature; According to the principle of starting time of all prominent abnormal intervals in all historical record curves of all historical features in ascending order, the starting time and corresponding data type of all prominent abnormal intervals in all historical record curves of all historical features are sorted to obtain a network environment prominent abnormal record sequence; Calculate the regularity of prominent anomalies in the network environment based on the prominent anomaly record sequence of the network environment; The risk index of the current communication process is calculated based on the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical characteristics.
6. The method for encrypted communication transmission based on dynamic strategy according to claim 5, characterized in that: Based on the prominent anomaly record sequence of each historical feature, the prominent anomaly regularity of each historical feature is calculated, including: The mean of the difference between the starting times of all adjacent prominent anomaly intervals of the same data type in the prominent anomaly record sequence of each historical feature is taken as the average anomaly occurrence interval of the corresponding data type, and the similarity of the average anomaly occurrence intervals of all data types of each historical feature is taken as the first prominent anomaly regularity of the corresponding historical feature; The mean of the average anomaly occurrence intervals of all data types of the corresponding historical feature is used as the period division value of the corresponding historical feature, and the historical period is divided based on the period division value to obtain multiple sub-historical periods; Divide the outstanding anomaly record sequence of each historical feature based on all sub-historical periods of the historical period, obtain the outstanding anomaly record subsequence of each historical feature in each sub-historical period, assign values to each data type in the outstanding anomaly record subsequence of each historical feature in each sub-historical period, and generate the outstanding anomaly type value sequence of each historical feature in each sub-historical period; Based on the prominent anomaly type value sequence of each historical feature in all sub-historical periods and the starting time of all prominent anomaly intervals in the prominent anomaly record subsequence, a prominent anomaly type value matrix and a prominent anomaly occurrence time matrix of each historical feature are generated; The second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature; The average of the first prominent abnormal regularity and the second prominent abnormal regularity of each historical feature is regarded as the prominent abnormal regularity corresponding to each historical feature.
7. The method for encrypted communication transmission based on dynamic policy according to claim 6, characterized in that: The second prominent anomaly regularity of each historical feature is calculated based on the prominent anomaly type value matrix and the prominent anomaly occurrence time matrix of each historical feature, including: Determine all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature and all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix; All inter-row difference vectors and all inter-column difference vectors of the prominent anomaly type value matrix of each historical feature are matched with all inter-row difference vectors and all inter-column difference vectors of the prominent anomaly occurrence time matrix and similarity is calculated to obtain the similarity of multiple inter-row difference vectors and multiple inter-column difference vectors of each historical feature; Perform singular value decomposition on the prominent anomaly type value matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly type value matrix. At the same time, perform singular value decomposition on the prominent anomaly occurrence time matrix of each historical feature to obtain all left singular vectors and all right singular vectors of the prominent anomaly occurrence time matrix. All left singular vectors and all right singular vectors of the prominent anomaly type value matrix of each historical feature are matched with all left singular vectors and all right singular vectors of the prominent anomaly occurrence moment matrix and similarity is calculated to obtain multiple left singular similarities and multiple right singular similarities of each historical feature; Based on all inter-row differential vector similarities, all inter-column differential vector similarities, all left singular similarities, and all right singular similarities of each historical feature, a differential similarity matrix of the corresponding historical feature is generated; The square value of the second norm of the differential similarity matrix of each historical feature is regarded as the second prominent abnormal regularity of each historical feature.
8. The method for encrypted communication transmission based on dynamic strategy according to claim 5, characterized in that: The risk index of the current communication process is calculated based on the prominent anomaly regularity of the network environment and the prominent anomaly regularity of all historical characteristics, including: A weight is assigned to each historical feature, and the prominent abnormal regularity of the network environment and the prominent abnormal regularity of all historical features are weighted and fused in combination with the global regularity weight to obtain the risk index of the current communication process.
9. The method for encrypted communication transmission based on dynamic strategy according to claim 1, characterized in that: S3: Match the encryption algorithm sequence, key update frequency, and transmission protocol based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer, including: Get the preset encryption policy matching list; Based on the hardware status parameters, risk index and communication content characteristics of the all-in-one device and the target communication peer, the preset encryption policy matching list is retrieved to match the corresponding encryption algorithm sequence, key update frequency and transmission protocol.
10. An all-in-one encrypted communication transmission system based on dynamic strategy, characterized in that: include: The status perception module is used to collect hardware status parameters, network environment parameters and communication content characteristics of the all-in-one machine and the target communication end in real time; A risk calculation module is used to calculate the risk index of the current communication process based on the network environment parameters of the all-in-one device and the target communication peer; A policy matching module is used to match encryption algorithm sequences, key update frequencies, and transmission protocols based on the hardware status parameters, risk index, and communication content characteristics of the integrated device and the target communication peer. The encryption transmission module is used to perform segmented encryption and multi-channel parallel transmission of the integrated device communication data based on the encryption algorithm sequence, key update frequency, transmission protocol and target communication end, and to distribute security keys in combination with the distributed key management mechanism to obtain security keys; The security verification module is used to perform encrypted communication security verification based on security policy data and security keys to obtain communication verification data.
Citation Information
Patent Citations
Temperature sensor data exception processing method
CN115840897A
Communication risk joint early warning method based on data source analysis
CN116938676A
Data encryption transmission method based on zero-trust architecture
CN119966746A
Risk scoring in a connected graph
US10728272B1
Cited By
Picture encryption internet transmission method and system
CN121397158A
A method and system for encrypted internet transmission of images
CN121397158B