A Cross-Network Data Security Exchange Method, System, Device and Storage Medium
By conducting sensitive analysis and priority classification of cross-network data, combined with encryption processing, the problems of low efficiency and poor security in cross-network data exchange are solved, and efficient and secure cross-network data transmission is achieved.
Patent Information
- Application Number
- CN202211002751.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-08-19
AI Technical Summary
现有跨网数据交换方法存在数据交换时间长、网络故障风险大、数据完整性和安全性难以保障的问题。
By receiving the data to be sent for sensitive analysis and priority division, a sensitive information database is built, a transmission queue is set up, and a time stamp, slice and encryption process is used, and a symmetric key and pre-configured key are combined for double-layer or three-layer encryption to ensure secure data exchange.
It improves data exchange efficiency, enhances the security and integrity of cross-network data transmission, breaks down traditional technical barriers, and realizes efficient cross-network data security exchange.
Smart Images

Figure CN115378700B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things communication, and particularly to a cross-network data security exchange method, system, device and storage medium. Background Art
[0002] With the continuous development of electronic information construction, users have built a large number of private networks, and the demand for cross-network data exchange is becoming stronger and stronger. Cross-network data exchange refers to logically isolating different networks or different security domains by technical means and realizing data transmission through protocol-free communication, or referring to transmitting data from one end to the other end through a physically isolated network.
[0003] The Chinese patent with the publication number CN113141381B discloses a processing method for cross-network data exchange based on network isolation, including the following steps: establishing the Internet of Things; establishing any one or more of the service platform, management platform and sensing network platform on the cloud platform to form an in-network cloud platform; when multiple Internet of Things interact with at least one out-of-network cloud platform through the in-network cloud platform, the out-of-network cloud platform obtains the data of multiple Internet of Things to generate a first database; when the Internet of Things requests data from the out-of-network cloud platform, the out-of-network cloud platform extracts data from the first database according to the request information sent by the Internet of Things as the first data and sends it to the Internet of Things, realizing the formation of big data across industries and fields.
[0004] However, this processing method for cross-network data exchange still has deficiencies: large-scale data exchange takes a long time and the probability of network failures is high. If a failure occurs, it will lead to unsuccessful file acquisition, and there are many risks in cross-network exchange, and the integrity and security of data cannot be guaranteed. Summary of the Invention
[0005] In view of the above technical problems, the present invention provides a cross-network data security exchange method, system, device and storage medium.
[0006] The technical solution of the present invention to solve the above technical problems is as follows:
[0007] A cross-network data security exchange method includes the following steps:
[0008] Step 1. Receive the data to be sent by the sender, perform sensitive analysis and priority classification on the data to be sent, and thus allocate the data to be sent to different transmission queues and determine the transmission order of the data to be sent in the transmission queue;
[0009] Step 2. Perform timestamp, slicing and encryption processing on the data to be sent in different transmission queues;
[0010] Step 3. Send the processed data to the recipient, decrypt the received data, and complete the cross-network data security exchange.
[0011] Further, the sensitive analysis in step 1 includes:
[0012] Receive the data to be sent from the sender and construct a sensitive information database;
[0013] Based on the sensitive information database, divide the data to be sent into multiple sub-informations;
[0014] Extract and identify the sensitive information in each sub-information, count the number of sensitive information and its corresponding sensitive level in each sub-information, and obtain the number of information with different sensitive levels;
[0015] Set multiple sensitive thresholds, and allocate the data to be sent to the transmission queues corresponding to the sensitive thresholds according to the number of information with different sensitive levels.
[0016] Further, the priority division in step 1 includes:
[0017] The number of information with different sensitive levels, and construct a directed graph of sensitive information;
[0018] Based on the directed graph of sensitive information, set the weights of each sub-information;
[0019] Divide according to the weights of the sub-informations into multiple ranges, and count the number of sub-informations within each sub-information weight range;
[0020] Calculate the weighted sum of the sub-informations, the maximum sub-information weight value, and the distribution state parameter of the data to be sent;
[0021] Determine the information transmission order according to the weighted sum of the sub-informations, the maximum sub-information weight value, and the distribution state parameter of the data to be sent.
[0022] Further, setting the weights for each sub-information based on the directed graph of sensitive information specifically includes:
[0023] Each sub-information is used as a node, and the calculation formula for the weight of the sub-information is:
[0024]
[0025]
[0026] Among them, ω(V i ) represents the weight of the sub-information V i , d represents the weight coefficient, sim i,j represents the similarity between the sub-information V i and V j , sim j,k represents the sub-information Vj and V k similarity, ω(V j ) represents the weight of V j , ind(V i ) and oud(V i ) respectively represent the in-degree and out-degree of the sub-information V i ; log|V i | represents the logarithm of the number of unit information in the sub-information V i , where the unit information is the minimum unit information, n s is the number of unit information jointly contained in the sub-information V i and V j , v s represents any one of the common unit information, v s′ represents any one of the non-common unit information, and vec(.) represents mapping the unit information to a vector.
[0027] Furthermore, calculating the weighted sum of the weights of the sub-information and the distribution state parameter of the data to be sent specifically includes:
[0028] Using ws to represent the weighted sum of the weights of the sub-information of the currently to-be-sent data, specifically:
[0029]
[0030] where represents the weight mean of the j-th weight range, and N(ω j ) represents the number of sub-information in the j-th weight range, j ∈ [1, J], and J represents the number of divisions of the weight range;
[0031] Using g to represent the distribution state parameter of the number of sub-information of the currently to-be-sent data in different weight ranges, specifically:
[0032]
[0033] where represents the weight mean of all sub-information of the currently to-be-sent data, and g0 represents the distribution state reference factor.
[0034] Furthermore, in the step 2, slicing includes:
[0035] Splitting the data to be sent into multiple data slices according to different fusion weights to obtain a data group, numbering each data slice in the data group, and each data slice contains at least one sub-information; the different weights are the sum of the weights of all sub-information included in the data slice.
[0036] Furthermore, in the step 2, encryption includes:
[0037] Encrypt the data group, set an encryption threshold. If the sensitivity level of the data slices in the data group of the data to be sent exceeds the set encryption threshold, the data slice is called a high-security data slice, and the high-security data slice uses three-layer encryption; non-high-security data slices use two-layer encryption.
[0038] The two-layer encryption includes a symmetric key and a pre-configured key, and the three-layer encryption encrypts the position of the high-security data slice on the basis of the two-layer encryption.
[0039] A cross-network data security exchange system includes an instruction publishing module, a sensitive analysis module, a priority comparison module, a transmission queue allocation module, a processing module, a cross-network data exchange platform, and a decryption module;
[0040] The instruction publishing module is used to receive the user's data sending instruction, and the data sending instruction includes the data to be sent;
[0041] The sensitive analysis module is used to analyze the number of pieces of information with sensitivity levels in the data to be sent;
[0042] The priority comparison module is used to analyze the priority of the data to be sent;
[0043] The transmission queue allocation module is used to allocate the data to be sent to different transmission queues and determine the transmission order of the data to be sent in the transmission queue;
[0044] The processing module is used to perform timestamp, slicing, and encryption processing on the data to be sent in different transmission queues;
[0045] The cross-network data exchange platform is used to send the data to be sent to the receiving party;
[0046] The decryption module is used to decrypt the received data.
[0047] A cross-network data security exchange device includes: a processor, a memory, and a program; the program is stored in the memory, and the processor calls the program stored in the memory to execute the cross-network data security exchange method.
[0048] A computer-readable storage medium is configured to store a program, and the program is configured to execute the above cross-network data security exchange method.
[0049] Compared with the prior art, the present invention has the following technical effects:
[0050] (1) This method divides the security level by combining the sensitivity level and priority of the data to be sent, simply and clearly showing the security levels of different data; compares the priority based on the weighted sum of sub-information, the maximum sub-information weight value, and the distribution state parameter of the data to be sent, clarifies the information transmission order, and improves the data exchange efficiency;
[0051] (2) This method realizes the cross-network secure exchange and sharing of data, breaks the limitations of traditional technical barriers, slices and encrypts the data to be sent with different priorities, and performs double-layer encryption or triple-layer encryption according to different confidentiality levels, realizing the fast transmission of transmission queues with different security levels, which can greatly improve the transmission efficiency; adopts the method of double-layer encryption with symmetric keys and pre-configured key pairs, and encrypts the positions of slices of highly confidential data on the basis of double-layer encryption, enhancing the security of cross-network data exchange and realizing the secure and efficient transmission of cross-network data;
[0052] (3) Large-scale data exchange takes a long time and the probability of network failure is high. If a failure occurs, it will lead to unsuccessful file acquisition, and there are many risks in cross-network exchange, which cannot guarantee the integrity and security of data. Moreover, the above system or method has undergone a series of effectiveness investigations and verifications, and finally can break the limitations of traditional technical barriers, improve the data encryption level and transmission efficiency, and realize the secure and efficient transmission of cross-network data. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 is the flowchart of the cross-network data secure exchange method of the present invention;
[0054] Figure 2 is the block diagram of the cross-network data secure exchange system of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0055] The principles and features of the present invention will be described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0056] Large-scale data exchange takes a long time and the probability of network failure is high. If a failure occurs, it will lead to unsuccessful file acquisition, and there are many risks in cross-network exchange, which cannot guarantee the integrity and security of data. In the embodiments of the present invention, a cross-network data secure exchange method is provided, which breaks the limitations of traditional technical barriers, improves the data encryption level and transmission efficiency, and realizes the secure and efficient transmission of cross-network data.
[0057] Figure 1 is the flowchart of the cross-network data secure exchange method of the present invention. Refer to Figure 1 , a cross-network data secure exchange method, includes the following steps:
[0058] Step 1. Receive the data to be sent from the sender, perform sensitive analysis and priority classification on the data to be sent, and thereby allocate the data to be sent to different transmission queues and determine the transmission order of the data to be sent in the transmission queue.
[0059] The two parties of information that need to perform cross-network data security exchange are located in different network regions. For the sake of easy distinction, the two parties of information are respectively called the sender and the receiver. When performing cross-network data exchange, there is at least one sender and one receiver. The information sender and the receiver respectively set up different levels of transmission queues for data of different security levels for the secure exchange of cross-network data.
[0060] Perform sensitive analysis on the data to be sent. This step includes the following specific implementation processes:
[0061] Step 1.1. According to the data to be sent from the sender, construct a sensitive information library, which includes various sensitive information and their sensitive levels, and perform sensitive analysis on the data to be sent based on the sensitive information library.
[0062] Step 1.2. Based on the sensitive information library, divide the data to be sent into multiple sub-informations.
[0063] The sensitive information library is shown as S = {S1, S2, …, S n}, S1, S2, …, S n are the sub-informations after division, and n is the number of divided sub-informations.
[0064] Step 1.3. Extract and identify the sensitive information in each sub-information, count the number of sensitive information and its corresponding sensitive level in each sub-information, and obtain the number of information of different sensitive levels.
[0065] Existing algorithms such as regular matching can be used to extract the sensitive information in each sub-information from the sub-information.
[0066] Step 1.4. Set up multiple sensitive thresholds, and allocate the data to be sent to the transmission queues corresponding to the sensitive thresholds according to the number of information of different sensitive levels.
[0067] Priority classification. This step includes the following specific implementation processes:
[0068] Step 1.5. According to the number of sensitive information and its corresponding sensitive level, that is, according to the number of information of different sensitive levels, construct a directed graph of sensitive information G = (V, E), where V represents the node set and E represents the edge set;
[0069] Step 1.6. Set sub-information weights for each sub-information based on the directed graph of sensitive information. Each sub-information is used as a node, and the calculation formula for the sub-information weight is:
[0070]
[0071]
[0072] Among them, ω(V i ) represents the weight of the sub - information V i , d represents the weight coefficient, and sim i,j represents the similarity between the sub - information V i and V j . sim j,k represents the similarity between the sub - information V j and V k . ω(V j ) represents the weight of V j . ind(V i ) and oud(V i ) respectively represent the in - degree and out - degree of the sub - information V i ; log|V i | represents the logarithm of the number of unit information in the sub - information V i , and the unit information is the minimum unit information. n s is the number of unit information jointly contained in the sub - information V i and V j . v s represents any one of the common unit information, and v s′ represents any one of the non - common unit information. vec(.) represents mapping the unit information into a vector.
[0073] Step 1.7 divides the sub - information weights into multiple ranges and counts the number of sub - information within each sub - information weight range.
[0074] Divide the weights into multiple ranges, and the division basis is determined according to the actual situation. Count the number of sub - information within each weight range.
[0075] Step 1.8 calculates the weighted sum of sub - information weights, the maximum sub - information weight value, and the distribution state parameter:
[0076] Use ws to represent the weighted sum of the sub - information weights of the currently to - be - sent data. Specifically:
[0077]
[0078] Among them, represents the weight mean of the j - th weight range, and N(ω j ) represents the number of sub - information within the j - th weight range, where j ∈ [1, J], and J represents the number of divisions of the weight range.
[0079] Use g to represent the distribution state parameter of the number of sub - information of the currently to - be - sent data in different weight ranges. Specifically:
[0080]
[0081] Among them, represents the average weight of all sub - information of the data to be sent currently, g0 represents the distribution state reference factor, and n is the number of sub - information divided.
[0082] The maximum sub - information weight value ω(V max ) is calculated according to the formula in step 1.6.
[0083] Step 1.9 determines the information transmission order according to the weighted sum of sub - information of the data to be sent, the maximum sub - information weight value, and the distribution state parameter.
[0084] According to the weighted sum of sub - information ws of the data to be sent, the maximum sub - information weight value ω(V max ) and the distribution state parameter g, the priorities are compared. If the weighted sum of sub - information of the data to be sent currently is greater than that of the data to be sent for comparison, the priority of the data to be sent currently is higher than that of the data to be sent for comparison; if the weighted sum of sub - information of the data to be sent currently is equal to that of the data to be sent for comparison, then compare the maximum sub - information weight values of the data to be sent currently and the data to be sent for comparison, and the one with the larger maximum sub - information weight value has priority. If the maximum sub - information weight values are the same, then compare the distribution state parameters, and the one with the smaller distribution state parameter has priority. Thus, the priority result of the data to be sent is obtained, and the order in the transmission queue is determined according to the priority, and the data is transmitted according to the principle of first - in - first - out.
[0085] By combining the sensitivity level and priority of the data to be sent for security level division, it simply and clearly shows the security levels of different data; by comparing the priorities according to the weighted sum of sub - information of the data to be sent, the maximum sub - information weight value, and the distribution state parameter, the information transmission order is determined, and the data exchange efficiency is improved.
[0086] Step 2. Perform timestamp, slicing, and encryption processing on the data to be sent in different transmission queues.
[0087] This step includes the following specific implementation processes:
[0088] Step 2.1 Determine that the data to be sent in the transmission queue needs to add a timestamp before transmission, that is, the sending time of the data to be sent.
[0089] Step 2.2 Split the data to be sent according to the preset data slicing rule. Split the data to be sent with timestamps added according to different fusion weights into multiple data slices, where each data slice contains at least one sub-information, obtaining multiple data groups, and number each data slice in the data group. The different weights are the sum of the weights of all sub-information contained in the data slice; the data slicing rule is set according to actual requirements.
[0090] Step 2.3 Encrypt the data group. Set an encryption threshold. If the sensitivity level of the data slice in the data group of the data to be sent exceeds the set encryption threshold, the data slice is called a high-security data slice, then the high-security data slice uses triple encryption; non-high-security data slices use double encryption; the double encryption includes a symmetric key and a pre-configured key, and the triple encryption is to encrypt the position of the high-security data slice on the basis of double encryption.
[0091] The specific implementation process of the double encryption is as follows:
[0092] The information sender and the receiver preset a protocol key in advance. The sender first encrypts the data slice using the symmetric key to obtain an initial ciphertext; then the sender uses the public key in the protocol key pair with the receiver to perform a second encryption on the first encryption result and the symmetric key to obtain the final ciphertext. The public key and the private key are a key pair pre-configured by the information sender and the receiver, and can authenticate the identity and permissions of both parties through the key pair. In order to enhance the security of cross-network data exchange, a method of double encryption with a pre-configured protocol key and a key pair is adopted.
[0093] The formula for the double encryption method is:
[0094] Key1 = S1(seid + reid + K ab + nhsds)
[0095] Key2 = S2(PK + K ab + Key1)
[0096] where Key1 and Key2 are the double encryption results of non-high-security data slices, S1 is the AES encryption method, S2 is the RSA encryption method, seid is the sender address, reid is the receiver address, PK represents the public key of S2, K ab represents the symmetric key of S1, and nhsds represents non-high-security data slices. After receiving the encrypted data, the receiver decrypts Key2 using the private key to obtain Key1 and the symmetric key of Key2, and decrypts Key2 using the symmetric key of Key1 to obtain non-high-security data slices.
[0097] The three - layer encryption method is to add a third - layer encryption on the basis of the double - layer encryption. The highly confidential data slices are shuffled and arranged in a disordered order and interspersed into the non - highly confidential data slices. The third - layer encryption is to encrypt the position information of the highly confidential data slices.
[0098] The formula of the three - layer encryption method is:
[0099] Key3 = S1(seid+reid+k ab +hsds)
[0100] Key4 = S2(PK+K ab +Key3)
[0101] Key5 = S2(S2(L(hsds)+PK)+Key4)
[0102] Among them, Key3, Key4, and Key5 are the three - layer encryption results of the highly confidential data slices. L(hsds) represents the position information of the highly confidential data slices, and hsds represents the highly confidential data slices.
[0103] Slice and encrypt the data to be sent with different priorities, and perform double - layer encryption or three - layer encryption according to different confidentiality levels to achieve fast transmission of transmission queues with different security levels, which can greatly improve the transmission efficiency; adopt the method of double - layer encryption with symmetric keys and pre - configured key pairs, and encrypt the positions of the highly confidential data slices on the basis of double - layer encryption to enhance the security of cross - network data exchange and achieve safe and efficient transmission of cross - network data.
[0104] Step 3. Send the processed data to the receiving party and decrypt the received data to complete the secure cross - network data exchange.
[0105] The sender calls the interface published by the cross - network data exchange platform to transmit the data to be sent. The gateway of the cross - network data exchange platform receives the request, authenticates the identity of the sender, and verifies whether the parameter list of the data to be sent conforms to the specification. After passing the verification, the cross - network data exchange platform sends the data to be sent to the receiving party. A data structure exactly the same as the data to be sent is established at the receiving party to cache the received data. After all the data in the current cycle is received, the received data transmission is decrypted to complete the secure cross - network data exchange.
[0106] In the embodiment of the present invention, a cross - network data secure exchange system is also provided. Refer to Figure 2 , the system includes an instruction publishing module 10, a sensitive analysis module 30, a priority comparison module 40, a transmission queue allocation module 50, a processing module 60, a cross - network data exchange platform, and a decryption module 80.
[0107] The instruction issuing module 10 is used to receive the user's data sending instruction, and the data sending instruction includes the data to be sent.
[0108] The sensitive analysis module 30 is used to analyze the quantity of information with sensitive levels in the data to be sent.
[0109] Specifically, the sensitive analysis module 30 constructs a sensitive information library based on the data to be sent by the sender. The sensitive information library includes various sensitive information and their sensitive levels. The data to be sent is segmented into multiple sub-informations based on the sensitive information library. The sensitive information in each sub-information is extracted and identified, and the quantity of sensitive information and its corresponding sensitive level in each sub-information are counted to obtain the quantity of information with different sensitive levels. The sensitive analysis module 30 sends the analysis result to the priority comparison module 40 and the transmission queue allocation module 50 through data transmission.
[0110] The priority comparison module 40 is used to analyze the priority of the data to be sent.
[0111] Specifically, the priority comparison module 40 includes a directed graph construction unit 401, a weight calculation unit 402, a segmented statistics unit 403, a parameter calculation unit 404, and a comparison unit 405.
[0112] The directed graph construction unit 401 is used to construct a sensitive information directed graph G=(V, E) according to the quantity of information with different sensitive levels, where V represents the node set and E represents the edge set.
[0113] The weight calculation unit 402 is used to set weights for each sub-information based on the directed graph; each sub-information is used as a node, and the calculation formula for the weight of the sub-information is:
[0114]
[0115]
[0116] where, ω(V i ) represents the weight of the sub-information V i , d represents the weight coefficient, sim i,j represents the similarity between the sub-information V i and V j , sim j,k represents the similarity between the sub-information V j and V k , ω(V j ) represents the weight of V j , ind(V i ) and oud(V i ) respectively represent the in-degree and out-degree of the sub-information V i ; log|V i | represents the sub-information Vi The logarithm of the number of medium unit information, where the unit information is the minimum unit information, n s is the sub-information V i and V j The number of unit information jointly contained in, v s represents any one of the common unit information, v s′ represents any one of the non-common unit information, and vec(.) represents mapping the unit information to a vector.
[0117] The segmented statistics unit 403 is used to divide the weights into multiple ranges and count the number of sub-information in each weight range.
[0118] The parameter calculation unit 404 is used to calculate the weighted sum of the sub-information, the maximum sub-information weight value, and the distribution state parameter of the data to be sent.
[0119] Use ws to represent the weighted sum of the sub-information weights of the currently to-be-sent data, specifically:
[0120]
[0121] Among them, represents the weight mean of the j-th weight range, N(ω j ) represents the number of sub-information in the j-th weight range, j ∈ [1, J], and J represents the number of weight range divisions.
[0122] Use g to represent the distribution state parameter of the number of sub-information of the currently to-be-sent data in different weight ranges, specifically:
[0123]
[0124] Among them, represents the mean weight of all sub-information of the currently to-be-sent data, and g0 represents the distribution state reference factor.
[0125] The comparison unit 405 is used to compare the priorities based on the weighted sum of the sub-information, the maximum sub-information weight value, and the distribution state parameter of the data to be sent. The priority comparison module 40 sends the comparison result to the transmission queue allocation module 50 by means of data transmission.
[0126] The transmission queue allocation module 50 is used to allocate the data to be sent to different transmission queues and determine the order of the data to be sent in the transmission queue.
[0127] Specifically, the transmission queue allocation module 50 is used to set up multiple sensitive thresholds, and allocate the data to be sent to the transmission queues corresponding to the sensitive thresholds according to the sensitive analysis results of the data to be sent; determine the order in the transmission queue according to the priority of the data to be sent, and transmit the data according to the principle of first in first out. The transmission queue allocation module 50 sends the transmission queue to the processing module 60 through data transmission.
[0128] The processing module 60 performs timestamp, slicing, and encryption processing on the data in different transmission queues. The processing module 60 includes a timestamp unit 601, a data slicing unit 602, and an encryption unit 603.
[0129] The timestamp unit 601 is used to add a timestamp to the data to be sent.
[0130] The data slicing unit 602 is used to split the data to be sent according to the preset data slicing rules, split the data to be sent into multiple data slices according to different weights to obtain a data group, and number each data slice in the data group.
[0131] The encryption unit 603 is used to encrypt the data group and set an encryption threshold. If the sensitive level of the data slices in the data group of the data to be sent exceeds the set encryption threshold, the data slice is called a high-security data slice. Then, the high-security data slices are encrypted with three layers, and the non-high-security data slices are encrypted with two layers; the two-layer encryption includes a symmetric key and a pre-configured key, and the three-layer encryption is to encrypt the position of the high-security data slices on the basis of the two-layer encryption.
[0132] The specific implementation process of the two-layer encryption is as follows:
[0133] The information sender and the receiver preset a protocol key in advance. The sender first encrypts the data slice with the symmetric key to obtain an initial ciphertext; then the sender uses the public key in the protocol key pair with the receiver to encrypt the first encryption result and the symmetric key for the second time to obtain the final ciphertext. The public key and the private key are a key pair pre-configured by the information sender and the receiver, and can authenticate the identity and permissions of both parties through the key pair. In order to enhance the security of cross-network data exchange, a method of double encryption with a pre-configured protocol key and a key pair is adopted.
[0134] The formula for the two-layer encryption method is:
[0135] Key1 = S1(seid + reid + K ab + nhsds)
[0136] Key2 = S2(PK + K ab + Key1)
[0137] Among them, Key1 and Key2 are the double-layer encryption results of non-highly confidential data slices. S1 is the AES encryption method, S2 is the RSA encryption method, seid is the sender address, reid is the receiver address, PK represents the public key of S2, and K ab represents the symmetric key of S1, and nhsds represents the non-highly confidential data slice. After receiving the encrypted data, the receiver decrypts Key2 with the private key to obtain the symmetric keys of Key1 and Key2, and decrypts Key2 with the symmetric key of Key1 to obtain the non-highly confidential data slice.
[0138] The three-layer encryption method adds a third layer of encryption on the basis of double-layer encryption. It shuffles the order of the highly confidential data slices and intersperses them into the non-highly confidential data slices. The third layer of encryption encrypts the position information of the highly confidential data slices.
[0139] The formula for the three-layer encryption method is:
[0140] Key3 = S1(seid + reid + k ab + hsds)
[0141] Key4 = S2(PK + K ab + Key3)
[0142] Key5 = S2(S2(L(hsds) + PK) + Key4)
[0143] Among them, Key3, Key4, and Key5 are the three-layer encryption results of the highly confidential data slices. L(hsds) represents the position information of the highly confidential data slices, and hsds represents the highly confidential data slices.
[0144] The processing module 60 sends the processed data to the cross-network data exchange platform through data transmission.
[0145] The cross-network data exchange platform is used to send the data to be sent to the receiver.
[0146] Specifically, the sender calls the interface published by the cross-network data exchange platform to transmit the data to be sent. The gateway of the cross-network data exchange platform receives the request, authenticates the identity of the sender, and verifies whether the parameter list of the data to be sent meets the specifications. After passing the verification, the cross-network data exchange platform sends the data to be sent to the receiver.
[0147] The decryption module 80 is used to decrypt the received data to complete the cross-network data security exchange.
[0148] In some embodiments, the system further includes a sending cache module 20 and a receiving cache module 70. Refer to Figure 2 .
[0149] The sending cache module 20 is used to cache the backup of the data to be sent in a preset file type, and the sending cache module 20 sends the backed-up data to the sensitive analysis module 30 and the priority comparison module 40 through data transmission.
[0150] The receiving cache module 70 is used to establish a data structure exactly the same as the data to be sent and cache the received data. The receiving cache module 70 sends the received data to the decryption module 80 through data transmission.
[0151] In an embodiment of the present invention, a cross-network data security exchange device is further provided, which includes: a processor, a memory, and a program; the program is stored in the memory, and the processor calls the program stored in the memory to execute the above-mentioned cross-network data security exchange method.
[0152] In the implementation of the above cross-network data security exchange device, the memory and the processor are directly or indirectly electrically connected to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines, such as through a bus connection. The memory stores computer execution instructions for implementing the data access control method, including at least one software function module that can be stored in the memory in the form of software or firmware. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory.
[0153] The memory can be, but is not limited to, a random access memory (Random Access Memory, abbreviated as RAM), a read-only memory (Read Only Memory, abbreviated as ROM), a programmable read-only memory (Programmable Read-Only Memory, abbreviated as PROM), an erasable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), an electrically erasable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), etc. Among them, the memory is used to store the program, and the processor executes the program after receiving the execution instruction.
[0154] The processor can be an integrated circuit chip with the ability to process signals. The above-mentioned processor can be a general-purpose processor, including a Central Processing Unit (CPU for short), a Network Processor (NP for short), etc. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0155] In an embodiment of the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium is configured to store a program, and the program is configured to execute the above-mentioned cross-network data security exchange method.
[0156] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0157] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for realizing the functions specified in the flowcharts.
[0158] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions specified in the flowcharts.
[0159] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for realizing the functions specified in the flowcharts.
[0160] The above has introduced in detail the cross-network data security exchange method, cross-network data security exchange system, cross-network data security exchange device and the application of a computer-readable storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. A cross-network data security exchange method, characterized in that, It includes the following steps: Step 1. Receive the data to be sent from the sender, perform sensitive analysis and priority division on the data to be sent, and thus allocate the data to different transmission queues and determine the transmission order of the data to be sent in the transmission queue; Step 2. Perform timestamp, slicing and encryption processing on the data to be sent in different transmission queues; Step 3. Send the processed data to be sent to the receiver, and decrypt the received data to complete cross-network data security exchange; The priority division in Step 1 includes: constructing a directed graph of sensitive information based on the number of information with different sensitive levels; setting sub-information weights for each sub-information based on the directed graph of sensitive information; dividing into multiple ranges according to the sub-information weights, and counting the number of sub-information within each sub-information weight range; calculating the weighted sum of sub-information, the maximum sub-information weight value and the distribution state parameter of the data to be sent; determining the information transmission order according to the weighted sum of sub-information, the maximum sub-information weight value and the distribution state parameter of the data to be sent.
2. The cross-network data security exchange method according to claim 1, characterized in that The sensitive analysis in Step 1 includes: Receiving the data to be sent from the sender and constructing a sensitive information database; Dividing the data to be sent into multiple sub-informations based on the sensitive information database; Extracting and identifying the sensitive information in each sub-information, counting the number of sensitive information and its corresponding sensitive level in each sub-information, and obtaining the number of information with different sensitive levels; Setting multiple sensitive thresholds, and allocating the data to be sent to the transmission queue corresponding to the sensitive threshold according to the number of information with different sensitive levels.
3. The cross-network data security exchange method according to claim 2, wherein Setting sub-information weights for each sub-information based on the directed graph of sensitive information, specifically including: Each sub-information is used as a node, and the calculation formula for the sub-information weight is: Among them, ω(V i ) represents the weight of the sub-information V i , d represents the weight coefficient, sim i,j represents the similarity between the sub-information V i and Vj, simj,k represents the similarity between the sub-information Vj and V k , ω(Vj) represents the weight of Vj, ind(V i ) and oud(V i ) respectively represent the in-degree and out-degree of the sub-information V i ; log|V i | represents the logarithm of the number of unit information in the sub-information V i , where the unit information is the smallest unit of information, n s is the number of unit information jointly contained in the sub-information V i and V j , v s represents any one of the common unit information, v s′ represents any one of the non-common unit information, and vec(.) represents mapping the unit information into a vector.
4. The cross-network data security exchange method according to claim 3, wherein Calculating the weighted sum of sub-information weights and the distribution state parameter of the data to be sent includes: Using ws to represent the weighted sum of the current sub-information weights of the data to be sent, specifically: Among them, represents the weight mean of the j-th weight range, and N(ω j ) represents the number of sub-information within the j-th weight range, where j ∈ [1, J], and J represents the number of partitions of the weight range; Using g to represent the distribution state parameter of the number of sub-information of the current data to be sent in different weight ranges, specifically: Among them, represents the average weight of all sub-information of the data to be sent currently, g0 represents the distribution state reference factor; n is the number of sub-information divided.
5. A cross-network data security exchange method according to claim 1, characterized in that, In Step 2, slicing includes: Splitting the data to be sent into multiple data slices according to different fusion weights to obtain a data group, numbering each data slice in the data group, and each data slice contains at least one sub-information; the different fusion weights are the sum of the weights of all sub-information contained in the data slice.
6. The cross-network data security exchange method according to claim 5, characterized in that In Step 2, encryption includes: Encrypting the data group, setting an encryption threshold. If the sensitive level of the data slice in the data group of the data to be sent exceeds the set encryption threshold, the data slice is called a high-security data slice, and the high-security data slice uses triple encryption; non-high-security data slices use double encryption; The double encryption includes a symmetric key and a pre-configured key, and the triple encryption is to encrypt the position of the high-security data slice on the basis of the double encryption.
7. A cross-network data security exchange system, characterized in that It includes an instruction publishing module, a sensitive analysis module, a priority comparison module, a transmission queue allocation module, a processing module, a cross-network data exchange platform and a decryption module; The instruction publishing module is used to receive the user's data sending instruction, and the data sending instruction includes the data to be sent; The sensitive analysis module is used to analyze the number of information with sensitive levels in the data to be sent; The priority comparison module is used to analyze the priority of the data to be sent; The priority comparison module includes a directed graph construction unit, a weight calculation unit, a segmented statistics unit, a parameter calculation unit, and a comparison unit; the directed graph construction unit is used to construct a directed graph of sensitive information according to the quantity of information at different sensitive levels; The weight calculation unit is used to set weights for each sub-information based on the directed graph; The segmented statistics unit is used to divide the weights into multiple ranges and count the quantity of sub-information in each weight range; the parameter calculation unit is used to calculate the weighted sum of the sub-information of the data to be sent, the maximum sub-information weight value, and the distribution state parameter; the comparison unit is used to compare the priority according to the weighted sum of the sub-information of the data to be sent, the maximum sub-information weight value, and the distribution state parameter; The priority comparison module sends the comparison result to the transmission queue allocation module by means of data transmission; The transmission queue allocation module is used to allocate the data to be sent to different transmission queues and determine the transmission order of the data to be sent in the transmission queues; The processing module is used to perform timestamp, slicing, and encryption processing on the data to be sent in different transmission queues; The cross-network data exchange platform is used to send the data to be sent to the receiving party; The decryption module is used to decrypt the received data.
8. A cross-network data security exchange device, characterized in that, It includes: A processor, a memory, and a program; the program is stored in the memory, and the processor calls the program stored in the memory to execute the cross-network data security exchange method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is configured to store a program, and the program is configured to execute the cross-network data security exchange method according to any one of claims 1-6.
Citation Information
Patent Citations
IoT Cross-Network Data Interaction Methods and Systems
CN113141381B
Industrial time sensitive network multilevel security data scheduling method
CN109450943A
Cross-network data secure transmission system and method
CN113114589A
Sensitive data security level labeling method and device
CN114265967A