Network data encryption and privacy protection system in cloud environment

By using a wolfpack algorithm-driven key management, encryption algorithm optimization, and dynamic adjustment of privacy policies, the efficiency and synergy issues of data encryption and privacy protection in cloud environments are solved, achieving intelligent encryption protection and efficient attack response, thereby improving system security and resource utilization.

CN120639438BActive Publication Date: 2026-02-03HUNAN WUXIANG ELECTRIC POWER TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510952163.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2026-02-03
Estimated Expiration
2045-07-10

AI Technical Summary

Technical Problem

Existing data encryption and privacy protection solutions in cloud environments suffer from problems such as low key management efficiency, insufficient adaptability of encryption algorithms, static privacy policies, and poor coordination in anomaly detection.

Method used

The system employs a wolf pack algorithm-driven key management unit, encryption algorithm optimization unit, privacy protection strategy dynamic adjustment unit, and security monitoring unit. Through key generation, encryption algorithm optimization, privacy strategy dynamic adjustment, and distributed attack detection, it achieves intelligent encryption protection and dynamic strategy adjustment in a cloud environment.

Benefits of technology

It significantly improves system security, resource utilization, and compliance capabilities in the cloud environment, and achieves intelligent encryption protection and efficient attack response throughout the entire data lifecycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639438B_ABST
    Figure CN120639438B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of cloud computing, in particular to a network data encryption and privacy protection system in a cloud environment, which comprises a key management unit driven by a wolf swarm algorithm, an encryption algorithm optimization unit, a privacy protection strategy dynamic adjustment unit and a security monitoring and abnormal response unit. The cloud environment network data encryption and privacy protection system is constructed based on the wolf swarm algorithm, high-security keys are dynamically generated and distributed through the key management unit, the encryption algorithm optimization unit balances the security performance and resource consumption, the privacy protection strategy unit realizes multi-target dynamic game and compliance guarantee, the security monitoring unit completes distributed attack detection and cooperative defense, and relying on the cooperative feedback mechanism between units, the intelligent encryption protection, dynamic strategy adjustment and efficient attack response of data in the whole life cycle in the cloud environment are realized, and the system security, resource utilization and compliance ability are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud computing technology, specifically to a network data encryption and privacy protection system in a cloud environment. Background Technology

[0002] A cloud environment refers to a virtualized, distributed computing environment built on cloud computing technology. It dynamically allocates and manages computing resources (such as servers, storage, network devices, and software services) through a network, enabling on-demand use and elastic scaling of resources. With the widespread adoption of cloud computing technology, the scale and complexity of data storage, transmission, and processing in cloud environments are growing exponentially, making data security and privacy protection core challenges. Existing technologies and traditional cloud environment data encryption and privacy protection schemes suffer from low key management efficiency, insufficient adaptability of encryption algorithms, static privacy policies, and poor coordination in anomaly detection.

[0003] Based on this, the present invention provides a network data encryption and privacy protection system in a cloud environment to solve the aforementioned technical problems. Summary of the Invention

[0004] The purpose of this invention is to provide a network data encryption and privacy protection system in a cloud environment. This invention is based on the wolf pack algorithm and is a cloud environment network data encryption and privacy protection system. Through a key management unit that dynamically generates and distributes high-security keys, an encryption algorithm optimization unit that balances security performance and resource consumption, a privacy protection strategy unit that realizes multi-objective dynamic game and compliance assurance, and a security monitoring unit that completes distributed attack detection and collaborative defense, and relying on the collaborative feedback mechanism between units, it realizes intelligent encryption protection, dynamic policy adjustment and efficient attack response throughout the entire lifecycle of data in the cloud environment, which significantly improves system security, resource utilization and compliance capabilities.

[0005] To achieve the above objectives, the present invention provides the following technical solution:

[0006] This invention provides a network data encryption and privacy protection system in a cloud environment, comprising a key management unit driven by a wolf pack algorithm, an encryption algorithm optimization unit, a privacy protection strategy dynamic adjustment unit, and a security monitoring and anomaly response unit, wherein:

[0007] The wolf pack algorithm-driven key management unit is used to optimize key generation, updating, and distribution by utilizing the wolf pack algorithm.

[0008] The encryption algorithm optimization unit is used to perform multi-objective collaborative optimization of various encryption algorithms and their parameters using the wolf pack algorithm, balancing security, performance and resource consumption.

[0009] The privacy protection strategy dynamic adjustment unit is based on a multi-objective dynamic game mechanism using the wolf pack algorithm, and adjusts through strategy weight allocation, cross-unit collaborative feedback, and compliance adaptive adjustment.

[0010] The security monitoring and anomaly response unit is used to construct a distributed anomaly detection model using the wolf pack algorithm, with proxy nodes collaboratively identifying attack behaviors and triggering dynamic defenses.

[0011] The wolf pack algorithm-driven key management unit includes a key generation module, a key update module, and a key distribution module, wherein:

[0012] The key generation module: by simulating the cooperative mechanism of "detecting wolves - making decisions as the alpha wolf - attacking wolves" in a wolf pack, the key space is mapped to the wolf pack search space. With the objective function of maximizing key entropy and minimizing repetition rate, the wolf pack algorithm is used to iteratively optimize and generate a key sequence with high complexity and low repetition rate.

[0013] The key update module: based on the dynamic cooperation characteristics of wolf packs, sets a periodic update cycle and monitors the risks of abnormal logins and key leakage in real time;

[0014] The key distribution module is used to detect the cloud network topology in real time through the wolf detection node, generate a weighted link graph, calculate multiple non-overlapping shortest paths through the wolf pack algorithm path optimization model, and transmit the key fragments to the target node in parallel along different paths.

[0015] The encryption algorithm optimization unit includes an algorithm parameter optimization module, an algorithm combination selection module, and a dynamic feedback optimization module, wherein:

[0016] The algorithm parameter optimization module is used to construct the fitness function of the wolf pack algorithm with encryption strength, computation delay, and resource consumption as optimization objectives.

[0017] The algorithm combination selection module is used to dynamically match the optimal combination of encryption algorithms based on data type, data sensitivity, and business requirements using the wolf pack algorithm.

[0018] The dynamic feedback optimization module is used to receive the attack type feedback from the security monitoring unit, and the wolf pack algorithm automatically switches defensive parameters and adjusts the complexity of the encryption algorithm.

[0019] The encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and homomorphic encryption algorithms. The wolf pack algorithm dynamically matches algorithm combinations based on data types such as real-time traffic, stored data, and private data.

[0020] The dynamic feedback optimization module receives attack types from the security monitoring unit, and the wolf pack algorithm automatically switches defensive parameters and adjusts the complexity of the encryption algorithm. The specific operations are as follows:

[0021] A1: Attack Feature Extraction: Receive attack type data fed back by the security monitoring unit and extract key parameters such as attack frequency f, attack duration t, and attack intensity s;

[0022] A2: Defense parameter calculation: Based on the wolf pack algorithm, a fitness function F(x) is constructed, where x is the encryption algorithm parameter vector. The priority of parameter adjustment is calculated by F(x)=α1·s+β1·f+γ1·t, where α1, β1, and γ1 are weight coefficients and α1+β1+γ1=1.

[0023] A3: Dynamic parameter adjustment: Based on the calculation results, if the attack strength S > 80, the number of rounds n of the AES encryption algorithm will be increased from the default 10 rounds to [missing value]. This reduces the parallelism of data encryption to decrease the risk of side-channel attacks.

[0024] A4: Strategy Learning and Optimization: Record the defense effect E after each parameter adjustment, and iteratively update the weight coefficients α1, β1, and γ1 using a wolf pack algorithm, with the formula being α... new =α old ·(1-E), where α new The updated weight coefficients α1 and α old The weight coefficient α1 from the previous iteration is used to ensure that subsequent adjustment strategies are more suitable for the attack scenario.

[0025] The privacy protection policy dynamic adjustment unit includes a policy weight allocation module, a cross-unit collaborative feedback module, and a compliance adaptive adjustment module, wherein:

[0026] The strategy weight allocation module is used to dynamically allocate the weight of each strategy based on the "siege prey" model of the wolf pack algorithm, using data anonymization level, access control granularity, and compliance indicators as game factors.

[0027] The cross-unit collaborative feedback module is used to establish data interaction between the wolf pack algorithm-driven key management unit, encryption algorithm optimization unit, and security monitoring and anomaly response unit, and to receive data on key update frequency, algorithm complexity, and threat level.

[0028] The compliance adaptive adjustment module is used to build a compliance rule base, and the wolf pack algorithm periodically scans the matching degree between the privacy policy and the rule base.

[0029] The strategy weight allocation module is used to dynamically allocate the weights of each strategy based on the "hunt and swarm" model of the wolf pack algorithm, using data anonymization level, access control granularity, and compliance indicators as game factors. The specific operation is as follows:

[0030] B1: Data anonymization levels are divided into three levels: complete anonymization, partial anonymization, and anonymization, with values ​​of 1, 0.6, and 0.3 respectively. Access control granularity is assigned according to the scope, such as user level = 1, department level = 0.7, and global level = 0.4. Compliance indicators are scored based on the degree of matching between the current policy and regulations.

[0031] B2: Given a wolf pack size of N, the position vector of each wolf is represented by X. i =[x i1 ,x i2 ,x i3 [These correspond to the weights of data anonymization, access control, and compliance, respectively, with initial weights and requirements to be met (x).] i1 +x i2 +x i3 =1;

[0032] B3: Construct the fitness function, formula F(X) i )=α2·x i1 ·D+β2·x i2 ·A+γ2·x i3 •C, where D, A, and C are the quantitative values ​​of data anonymization level, access control granularity, and compliance indicators, respectively, and α2, β2, and γ2 are empirical coefficients, such as: α2 = 0.4, β2 = 0.3, γ2 = 0.3;

[0033] B4: A "hunt-and-run" mechanism based on the wolf pack algorithm, using a formula... Iteratively update the weights, where, This is the current globally optimal solution. The wolf position is randomly selected, and δ is a random number between 0 and 1, until the fitness function converges;

[0034] B5: Apply the final optimized weight vector to the privacy protection strategy to dynamically adjust the priority of data anonymization, access control, and compliance-related measures.

[0035] The compliance adaptive adjustment module is used to build a compliance rule base. The wolf pack algorithm periodically scans the matching degree between the privacy policy and the rule base. The specific operation is as follows:

[0036] C1: Compliance Rule Parsing: Parses the clauses in the built-in compliance rule base into a set of triples {(R i A i V i )}, where: R i For rule number, A i For rule attributes, such as "data storage period" and "user access permissions"; V i For compliance thresholds, such as "≤30 days" or "explicit user consent required";

[0037] C2: Strategy-Rule Matching Degree Calculation: Constructing the matching degree function M(P,R) i ), where P is the current privacy policy parameter vector, calculated using the following formula:

[0038]

[0039] Where δ is the consistency function, which is 1 for a perfect match and 0 otherwise;

[0040] C3: Wolf Pack Algorithm Optimized Scan: Initialization: Set the wolf pack size N, and the position vector of each wolf X. j =x j1 ,x j2 ,…,x jm ] represents the scan priority weight for m rules, and

[0041] Fitness function: Among them W i As the weight of rule importance;

[0042] Iterative Update: Through the "siege" mechanism of the wolf pack algorithm, according to the formula... Adjusting the weights, among which This is the current optimal solution. The wolf's position is randomly selected, and α3 is the contraction factor;

[0043] C4: Compliance Risk Assessment: Calculating the Comprehensive Compliance Risk Index Policy correction is triggered when RI < θ;

[0044] C5: Dynamic Adjustment Strategy: Based on the optimized rule priority of the wolf pack algorithm, adjust the privacy policy parameter P to maximize RI. The adjustment formula is as follows: Where β3 is the learning rate. This is the gradient of the fitness function.

[0045] The security monitoring and anomaly response unit includes a distributed detection module, a collaborative identification module, and a dynamic defense module, wherein:

[0046] The distributed detection module employs a layered architecture, with edge nodes acting as "wolf-detecting agents" to detect traffic anomalies in real time based on a local lightweight wolf pack algorithm model, and a central node acting as a "lead wolf controller" to aggregate the detection results from each agent and identify attack chains through a global wolf pack algorithm model.

[0047] The collaborative identification module is used to employ a "voting mechanism" among agent nodes. When multiple wolf-detecting agents detect the same type of anomaly, the wolf-leader controller determines it as a valid attack.

[0048] The dynamic defense module is used to trigger dynamic defense measures once an attack is confirmed, including instructing the key management unit to urgently update the key in the affected area.

[0049] The voting mechanism includes a process where, when ≥M wolf-detecting agents detect the same type of anomaly, the alpha wolf controller determines it as a valid attack and triggers dynamic defense measures, including: ① an emergency update of the key in the affected area by a key management unit driven by the wolf pack algorithm; ② an encryption algorithm optimization unit that enhances the encryption level of the target data; and ③ a privacy protection strategy dynamic adjustment unit that improves the granularity of access control to the user level.

[0050] Compared with the prior art, the beneficial effects of the present invention are:

[0051] This invention utilizes a cloud-based network data encryption and privacy protection system built on a wolf pack algorithm. Through a key management unit that dynamically generates and distributes high-security keys, an encryption algorithm optimization unit that balances security performance and resource consumption, a privacy protection strategy unit that implements multi-objective dynamic game theory and compliance assurance, and a security monitoring unit that completes distributed attack detection and collaborative defense, and relying on the collaborative feedback mechanism between units, it achieves intelligent encryption protection, dynamic policy adjustment, and efficient attack response throughout the entire data lifecycle in the cloud environment, significantly improving system security, resource utilization, and compliance capabilities. Attached Figure Description

[0052] Figure 1 This is a system diagram of the network data encryption and privacy protection system in the cloud environment of the present invention.

[0053] Figure 2 This is an architecture diagram of the network data encryption and privacy protection system in the cloud environment of this invention.

[0054] Figure 3 This is a dynamic adjustment state diagram of the privacy policy in the network data encryption and privacy protection system under the cloud environment of this invention.

[0055] Explanation of icon numbers:

[0056] 100. Wolfpack Algorithm-Driven Key Management Unit; 101. Key Generation Module; 102. Key Update Module; 103. Key Distribution Module; 200. Encryption Algorithm Optimization Unit; 201. Algorithm Parameter Optimization Module; 202. Algorithm Combination Selection Module; 203. Dynamic Feedback Optimization Module; 300. Privacy Protection Strategy Dynamic Adjustment Unit; 301. Strategy Weight Allocation Module; 302. Cross-Unit Collaborative Feedback Module; 303. Compliance Adaptive Adjustment Module; 400. Security Monitoring and Anomaly Response Unit; 401. Distributed Detection Module; 402. Collaborative Identification Module; 403. Dynamic Defense Module. Detailed Implementation

[0057] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0058] Example:

[0059] like Figures 1-3 As shown, this embodiment provides a network data encryption and privacy protection system in a cloud environment, including a key management unit 100 driven by a wolf pack algorithm, an encryption algorithm optimization unit 200, a privacy protection strategy dynamic adjustment unit 300, and a security monitoring and anomaly response unit 400. Specifically: the key management unit 100 driven by the wolf pack algorithm is used to optimize key generation, updating, and distribution using the wolf pack algorithm; the encryption algorithm optimization unit 200 is used to perform multi-objective collaborative optimization of various encryption algorithms and their parameters using the wolf pack algorithm, balancing security, performance, and resource consumption; the privacy protection strategy dynamic adjustment unit 300 is based on a multi-objective dynamic game mechanism using the wolf pack algorithm, adjusting through strategy weight allocation, cross-unit collaborative feedback, and compliance adaptive adjustment; and the security monitoring and anomaly response unit 400 is used to construct a distributed anomaly detection model using the wolf pack algorithm, with proxy nodes collaboratively identifying attack behaviors and triggering dynamic defense.

[0060] In this embodiment, it should be noted that: the key management unit 100 driven by the wolf pack algorithm provides dynamic key support for the encryption algorithm optimization unit 200, the encryption algorithm optimization unit 200 provides algorithm strength feedback for the privacy protection strategy dynamic adjustment unit 300, the privacy protection strategy dynamic adjustment unit 300 defines a policy benchmark for the security monitoring and anomaly response unit 400, and the security monitoring and anomaly response unit 400 feeds back to the dynamic adjustment of the key management unit 100 and the encryption algorithm optimization unit 200 through anomaly detection.

[0061] In this invention, the wolf pack algorithm-driven key management unit 100 includes a key generation module 101, a key update module 102, and a key distribution module 103. Specifically: the key generation module 101 maps the key space to a wolf pack search space by simulating the wolf pack's collaborative mechanism of "detecting wolves - alpha wolf decision-making - attacking wolves." Using the goal of maximizing key entropy and minimizing repetition rate, it iteratively optimizes using the wolf pack algorithm to generate a high-complexity, low-repetition-rate key sequence. The key update module 102 sets a periodic update cycle based on the dynamic collaborative characteristics of the wolf pack and monitors the risks of abnormal logins and key leakage in real time. The key distribution module 103 is used to detect the cloud network topology in real time through wolf detection nodes, generate a weighted link graph, and the alpha wolf node calculates multiple non-overlapping shortest paths using the wolf pack algorithm path optimization model. The alpha wolf nodes then fragment the key and transmit it in parallel along different paths to the target node.

[0062] In this embodiment, it should be noted that: the key generation module 101 uses collective intelligence to generate a high-security key, the key update module 102 uses a dynamic cooperation mechanism to ensure the security of the key lifecycle, and the key distribution module 103 uses multi-path fragmentation transmission to achieve reliable distribution.

[0063] Furthermore, it should be noted that the periodic update cycle ranges from T1 to 5-30 minutes, and the specific indicator for anomaly monitoring is three consecutive invalid key attempts triggering an emergency update. The path optimization model uses a combination of Dijkstra's algorithm and wolf pack iteration. For key sharding security design, if the number of shards is ≥3, all shards must arrive before the key can be reconstructed.

[0064] In this invention, the encryption algorithm optimization unit 200 includes an algorithm parameter optimization module 201, an algorithm combination selection module 202, and a dynamic feedback optimization module 203. Specifically: the algorithm parameter optimization module 201 is used to construct the fitness function of the wolf pack algorithm with encryption strength, computational latency, and resource consumption as optimization objectives; the algorithm combination selection module 202 is used to dynamically match the optimal encryption algorithm combination using the wolf pack algorithm based on data type, data sensitivity, and business requirements; the encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and homomorphic encryption algorithms, and the wolf pack algorithm dynamically matches algorithm combinations based on data types such as real-time traffic, stored data, and privacy data. The dynamic feedback optimization module 203 is used to receive attack types fed back by the security monitoring unit, and the wolf pack algorithm automatically switches defensive parameters and adjusts the complexity of the encryption algorithm. The specific operations are as follows: A1: Attack Feature Extraction: Receive attack type data fed back by the security monitoring unit and extract key parameters such as attack frequency f, attack duration t, and attack strength s; A2: Defense Parameter Calculation: Construct a fitness function F(x) based on the wolf pack algorithm, where x is the encryption algorithm parameter vector. Calculate the parameter adjustment priority using F(x)=α1·s+β1·f+γ1·t, where α1, β1, and γ1 are weight coefficients, and α1+β1+γ1=1; A3: Dynamic Parameter Adjustment: Based on the calculation results, if the attack strength S>80, increase the number of rounds n of the AES encryption algorithm from the default 10 rounds to... The algorithm reduces the parallelism of data encryption to mitigate the risk of side-channel attacks. A4: Policy learning optimization: Record the defense effect E after each parameter adjustment, and iteratively update the weight coefficients α1, β1, and γ1 using the wolf pack algorithm, with the formula α... new =α old ·(1-E), where α new The updated weight coefficients α1 and α old The weight coefficient α1 from the previous iteration is used to ensure that subsequent adjustment strategies are more suitable for the attack scenario.

[0065] In this embodiment, it should be noted that: the algorithm parameter optimization module 201 constructs a multi-target fitness function, the algorithm combination selection module 202 realizes intelligent algorithm matching, and the dynamic feedback optimization module 203 completes the attack response parameter adjustment.

[0066] Furthermore, it should be noted that the boundary conditions of the fitness function F(x) are as follows: Resource consumption thresholds are set (e.g., CPU utilization not exceeding 80%) and minimum encryption strength standards are established (e.g., AES key length ≥ 128 bits) to prevent optimization results from exceeding security or performance limits. When the optimization result violates the constraints, secondary optimization is triggered, forcibly adjusting the parameter vector x until the requirements are met. Real-time traffic: For real-time data such as video streams and voice calls, lightweight symmetric encryption algorithms (e.g., ChaCha20) are prioritized, combined with hash message authentication codes to ensure data integrity. The wolf pack algorithm dynamically adjusts the encryption block size based on network bandwidth. For example, in low-bandwidth environments, the encryption block size is reduced from the default 128 bytes to 64 bytes to reduce transmission latency. Stored data: For long-term stored financial data and medical records, a hybrid mode of "symmetric encryption (AES-256) + asymmetric encryption (RSA-4096)" is adopted. The wolf pack algorithm optimizes the key management strategy based on the data update frequency. For example, for data with very few updates, the key update cycle is extended to 3 months; for data with frequent modifications, it is shortened to 1 week. Privacy data: When processing privacy information such as user ID numbers and biometrics, homomorphic encryption algorithms (such as CKKS) are enabled to support data analysis in encrypted state. The wolf pack algorithm dynamically adjusts the homomorphic operation depth according to the privacy protection level. For example, in the face recognition scenario, in order to ensure recognition accuracy, the operation depth is set to 3 layers, while reducing the computational overhead by optimizing parameters.

[0067] In this invention, the privacy protection strategy dynamic adjustment unit 300 includes a strategy weight allocation module 301, a cross-unit collaborative feedback module 302, and a compliance adaptive adjustment module 303. Specifically: the strategy weight allocation module 301 is used to dynamically allocate the weights of each strategy based on a wolf pack algorithm's "hunt and kill" model, using data anonymization level, access control granularity, and compliance indicators as game factors. The specific operations are as follows: B1: The data anonymization level is divided into three levels: complete anonymization, partial anonymization, and anonymization, assigned values ​​of 1, 0.6, and 0.3 respectively. The access control granularity is assigned values ​​according to the range, such as user level = 1, department level = 0.7, and global level = 0.4. The compliance indicator is scored based on the current strategy's matching degree with regulations. B2: The wolf pack size is defined as N, and the position vector of each wolf is represented as X. i =[x i1 ,x i2 ,x i3 [These correspond to the weights of data anonymization, access control, and compliance, respectively, with initial weights and requirements to be met (x).] i1 +x i2 +x i3 =1; B3: Construct the fitness function, the formula is F(X) i )=α2·x i1 ·D+β2·x i2 ·A+γ2·xi3 • C, where D, A, and C are the quantitative values ​​of data anonymization level, access control granularity, and compliance indicators, respectively; α², β², and γ² are empirical coefficients, such as α² = 0.4, β² = 0.3, and γ² = 0.3; B4: A "hunt-and-run" mechanism based on the wolf pack algorithm, using the formula... Iteratively update the weights, where, This is the current globally optimal solution. The wolf position is randomly selected, and δ is a random number between 0 and 1 until the fitness function converges; B5: The final optimized weight vector is applied to the privacy protection strategy to dynamically adjust the priority of data anonymization, access control and compliance-related measures. Cross-unit collaborative feedback module 302: Used to establish data interaction between the key management unit 100, encryption algorithm optimization unit 200 and security monitoring and anomaly response unit 400 driven by the wolf pack algorithm, and receive data on key update frequency, algorithm complexity and threat level; Compliance adaptive adjustment module 303: Used for the built-in compliance rule base, the wolf pack algorithm periodically scans the matching degree between the privacy strategy and the rule base. The specific operation is as follows: C1: Compliance rule parsing: Parses the clauses in the built-in compliance rule base into a set of triples {(R i A i V i )}, where: R i For rule number, A i For rule attributes, such as "data storage period" and "user access permissions"; V i For compliance thresholds, such as "≤30 days" or "explicit user consent required"; C2: Policy-rule matching degree calculation: Construct the matching degree function M(P,R) i ), where P is the current privacy policy parameter vector, calculated using the following formula:

[0068]

[0069] Where δ is the consistency function, 1 for a perfect match and 0 otherwise; C3: Wolf Pack Algorithm Optimized Scan: Initialization: Set the wolf pack size N, and the position vector X of each wolf. j =[x j1 ,x j2 ,…,x jm ] represents the scan priority weight for m rules, and

[0070] Fitness function: Among them W i Assigning importance weights to rules; iterative updates: using the "siege" mechanism of the wolf pack algorithm, according to the formula... Adjusting the weights, among which This is the current optimal solution. For randomly selected wolf positions, α3 is the contraction factor; C4: Compliance Risk Assessment: Calculate the comprehensive compliance risk index. When RI < θ, policy correction is triggered; C5: Dynamic correction policy: Based on the rule priority optimized by the wolf pack algorithm, the privacy policy parameter P is adjusted to maximize RI. The correction formula is: Where β3 is the learning rate. This is the gradient of the fitness function.

[0071] In this embodiment, it should be noted that: the strategy weight allocation module 301 realizes multi-objective dynamic game decision-making, the cross-unit collaborative feedback module 302 obtains global security situation information, and the compliance adaptive adjustment module 303 ensures strategy compliance.

[0072] Furthermore, it's important to explain the optimization process of the "siege of prey" model mapping strategy, such as "the alpha wolf representing the current optimal strategy, the scout wolves exploring new strategy spaces, and the aggressive wolves quickly executing high-priority strategy adjustments." The compliance rule base update mechanism, such as automatically synchronizing official regulatory documents weekly, is illustrated by the compliance risk amendment example: "When data storage period is detected to exceed the 30 days stipulated by GDPR, a strategy correction is automatically triggered, adjusting the storage period parameter to 25 days."

[0073] In this invention, the security monitoring and anomaly response unit 400 includes a distributed detection module 401, a collaborative identification module 402, and a dynamic defense module 403. The distributed detection module 401 employs a layered architecture, with edge nodes acting as "wolf-hunting agents" to detect traffic anomalies in real time based on a local lightweight wolf pack algorithm model. The central node acts as a "leader wolf controller," aggregating the detection results from each agent and identifying the attack chain through a global wolf pack algorithm model. The collaborative identification module 402 uses a "voting mechanism" among agent nodes. When multiple wolf-hunting agents detect the same type of anomaly, the leader wolf controller determines it as a valid attack. The voting mechanism includes determining a valid attack and triggering dynamic defense measures when ≥M wolf-hunting agents detect the same type of anomaly, including: ① an emergency update of the affected area key by a wolf pack algorithm-driven key management unit 100; ② an enhanced encryption level for target data by an encryption algorithm optimization unit 200; and ③ a user-level granularity for privacy protection strategy dynamic adjustment by a privacy protection strategy dynamic adjustment unit 300. The dynamic defense module 403 triggers dynamic defense measures upon confirmation of an attack, including instructing the key management unit to urgently update the affected area key.

[0074] In this embodiment, it should be noted that: the distributed detection module 401 performs initial attack identification, the collaborative identification module 402 completes attack verification and confirmation, and the dynamic defense module 403 executes multi-dimensional emergency response.

[0075] Furthermore, it should be noted that: the computing power allocation between edge nodes and central nodes is as follows: edge nodes handle 90% of real-time traffic detection, while central nodes are responsible for complex attack chain analysis. The voting mechanism's threshold M (e.g., M=3), and false alarm rate control methods, such as introducing a time window (e.g., triggering voting only if more than 5 similar anomalies occur within 3 minutes), and the time delay requirements for multi-unit collaboration, such as ≤10 seconds from attack detection to key update completion, are all based on the defensive measures determined by the technical solution of this invention.

[0076] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0077] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A network data encryption and privacy protection system in a cloud environment, characterized in that, It includes a key management unit (100) driven by the wolf pack algorithm, an encryption algorithm optimization unit (200), a privacy protection strategy dynamic adjustment unit (300), and a security monitoring and anomaly response unit (400), wherein: The wolf pack algorithm-driven key management unit (100) is used to optimize key generation, updating, and distribution by utilizing the wolf pack algorithm. The encryption algorithm optimization unit (200) is used to perform multi-objective collaborative optimization of various encryption algorithms and their parameters through the wolf pack algorithm, balancing security, performance and resource consumption; The privacy protection strategy dynamic adjustment unit (300) is based on a multi-objective dynamic game mechanism of wolf pack algorithm to perform strategy weight allocation, cross-unit collaborative feedback and compliance adaptive adjustment. The security monitoring and anomaly response unit (400) is used to construct a distributed anomaly detection model through the wolf pack algorithm, and the proxy nodes collaboratively identify attack behaviors and trigger dynamic defense. The wolf pack algorithm-driven key management unit (100) includes a key generation module (101), a key update module (102), and a key distribution module (103), wherein: The key generation module (101) maps the key space to the wolf pack search space by simulating the cooperative mechanism of "wolf scout - alpha wolf decision - wolf attack". With the goal of maximizing key entropy and minimizing repetition rate, the wolf pack algorithm is used to iteratively optimize and generate a key sequence with high complexity and low repetition rate. The key update module (102) is based on the dynamic cooperation characteristics of wolf packs, sets a periodic update cycle, and monitors the risks of abnormal logins and key leakage in real time. The key distribution module (103) is used to detect the cloud network topology in real time through the wolf detection node, generate a weighted link graph, calculate multiple non-overlapping shortest paths through the wolf pack algorithm path optimization model, and transmit the key fragments to the target node in parallel along different paths.

2. The network data encryption and privacy protection system in a cloud environment according to claim 1, characterized in that, The encryption algorithm optimization unit (200) includes an algorithm parameter optimization module (201), an algorithm combination selection module (202), and a dynamic feedback optimization module (203), wherein: The algorithm parameter optimization module (201) is used to construct the fitness function of the wolf pack algorithm with encryption strength, computation delay and resource consumption as optimization objectives; The algorithm combination selection module (202) is used to dynamically match the optimal encryption algorithm combination based on data type, data sensitivity and business requirements using the wolf pack algorithm. The dynamic feedback optimization module (203) is used to receive the attack type feedback from the security monitoring unit, and the wolf pack algorithm automatically switches the defensive parameters and adjusts the complexity of the encryption algorithm.

3. The network data encryption and privacy protection system in a cloud environment according to claim 2, characterized in that, The encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and homomorphic encryption algorithms. The wolf pack algorithm dynamically matches algorithm combinations based on data types.

4. The network data encryption and privacy protection system in a cloud environment according to claim 2, characterized in that, The dynamic feedback optimization module (203) receives the attack type feedback from the security monitoring unit. The wolf pack algorithm automatically switches defensive parameters and adjusts the complexity of the encryption algorithm. The specific operation is as follows: A1: Attack Feature Extraction: Receive attack type data fed back by the security monitoring unit and extract key parameters such as attack frequency f, attack duration t, and attack intensity s; A2: Defense parameter calculation: Based on the wolf pack algorithm, a fitness function F(x) is constructed, where x is the encryption algorithm parameter vector. The priority of parameter adjustment is calculated by F(x)=α1·s+β1·f+γ1·t, where α1, β1, and γ1 are weight coefficients and α1+β1+γ1=1. A3: Dynamic parameter adjustment: Based on the calculation results, if the attack strength S > 80, the number of rounds n of the AES encryption algorithm will be increased from the default 10 rounds to [missing value]. This reduces the parallelism of data encryption to decrease the risk of side-channel attacks. A4: Strategy Learning and Optimization: Record the defense effect E after each parameter adjustment, and iteratively update the weight coefficients α1, β1, and γ1 using a wolf pack algorithm, with the formula being α... new =α old ·(1-E), where α new The updated weight coefficients α1 and α old The weight coefficient α1 from the previous iteration is used to ensure that subsequent adjustment strategies are more suitable for the attack scenario.

5. The network data encryption and privacy protection system in a cloud environment according to claim 1, characterized in that, The privacy protection policy dynamic adjustment unit (300) includes a policy weight allocation module (301), a cross-unit collaborative feedback module (302), and a compliance adaptive adjustment module (303), wherein: The strategy weight allocation module (301) is used to dynamically allocate the weight of each strategy based on the "siege prey" model of the wolf pack algorithm, using data anonymization level, access control granularity, and compliance indicators as game factors. The cross-unit collaborative feedback module (302) is used to establish data interaction with the wolf pack algorithm-driven key management unit (100), encryption algorithm optimization unit (200), and security monitoring and anomaly response unit (400), and to receive data on key update frequency, algorithm complexity, and threat level. The compliance adaptive adjustment module (303) is used to build a compliance rule base, and the wolf pack algorithm periodically scans the matching degree between the privacy policy and the rule base.

6. The network data encryption and privacy protection system in a cloud environment according to claim 5, characterized in that, The strategy weight allocation module (301) is used to dynamically allocate the weights of each strategy based on the "siege prey" model of the wolf pack algorithm, using data anonymization level, access control granularity, and compliance indicators as game factors. The specific operation is as follows: B1: Data anonymization levels are divided into three levels: complete anonymization, partial anonymization, and anonymization, with values ​​of 1, 0.6, and 0.3 respectively. Access control granularity is assigned according to the scope size, and compliance indicators are scored based on the degree of matching between the current policy and regulations. B2: Given a wolf pack size of N, the position vector of each wolf is represented by X. i =[x i1 ,x i2 ,x i3 [These correspond to the weights of data anonymization, access control, and compliance, respectively, with initial weights and requirements to be met (x).] i1 +x i2 +x i3 =1; B3: Construct the fitness function, the formula is F(X) i )=α2·x i1 ·D+β2·x i2 ·A+γ2·x i3 •C, where D, A, and C are the quantitative values ​​of data anonymization level, access control granularity, and compliance indicators, respectively, and α2, β2, and γ2 are empirical coefficients; B4: A "hunt-and-run" mechanism based on the wolf pack algorithm, using a formula... Iteratively update the weights, where, This is the current globally optimal solution. The wolf position is randomly selected, and δ is a random number between 0 and 1, until the fitness function converges; B5: Apply the final optimized weight vector to the privacy protection strategy to dynamically adjust the priority of data anonymization, access control, and compliance-related measures.

7. The network data encryption and privacy protection system in a cloud environment according to claim 5, characterized in that, The compliance adaptive adjustment module (303) is used to build a compliance rule base. The wolf pack algorithm periodically scans the matching degree between the privacy policy and the rule base. The specific operation is as follows: C1: Compliance rule parsing: Parses the clauses in the built-in compliance rule base into a set of triples {(R i A i V i )}, where: R i For rule number, A i For rule attributes; V i For compliance thresholds; C2: Strategy-Rule Matching Degree Calculation: Constructing the matching degree function M(P,R) i ), where P is the current privacy policy parameter vector, calculated using the following formula: Where δ is the consistency function, which is 1 for a perfect match and 0 otherwise; C3: Wolf Pack Algorithm Optimized Scan: Initialization: Set the wolf pack size N, and the position vector of each wolf X. j =[x j1 ,x j2 ,…,x jm ] represents the scan priority weight for m rules, and Fitness function: Among them W i As the weight of rule importance; Iterative Update: Through the "siege" mechanism of the wolf pack algorithm, according to the formula... Adjusting the weights, among which This is the current optimal solution. The wolf's position is randomly selected, and α3 is the contraction factor; C4: Compliance Risk Assessment: Calculating the Comprehensive Compliance Risk Index Policy correction is triggered when RI < θ; C5: Dynamic Adjustment Strategy: Based on the optimized rule priority of the wolf pack algorithm, adjust the privacy policy parameter P to maximize RI. The adjustment formula is as follows: Where β3 is the learning rate. This is the gradient of the fitness function.

8. The network data encryption and privacy protection system in a cloud environment according to claim 1, characterized in that, The security monitoring and anomaly response unit (400) includes a distributed detection module (401), a collaborative identification module (402), and a dynamic defense module (403), wherein: The distributed detection module (401) is used to adopt a layered architecture, with edge nodes acting as "wolf-detecting agents" to detect traffic anomalies in real time based on a local lightweight wolf pack algorithm model, and central nodes acting as "alpha wolf controllers" to aggregate the detection results of each agent and identify attack chains through a global wolf pack algorithm model. The collaborative identification module (402) is used to adopt a "voting mechanism" among agent nodes. When multiple wolf-detecting agents detect the same type of anomaly, the wolf-leader controller determines it as a valid attack. The dynamic defense module (403) is used to trigger dynamic defense measures once an attack is confirmed, including instructing the key management unit to urgently update the key in the affected area.

9. The network data encryption and privacy protection system in a cloud environment according to claim 8, characterized in that, The voting mechanism includes a system where, when at least M wolf-detecting agents detect the same anomaly, the alpha wolf controller determines it as a valid attack and triggers dynamic defense measures, including: ① an emergency update of the affected area key by a wolf pack algorithm-driven key management unit (100); ② an encryption algorithm optimization unit (200) to enhance the encryption level of the target data; and ③ a privacy protection strategy dynamic adjustment unit (300) to improve the granularity of access control to the user level.