Call record file encryption method and device
By using the analytic hierarchy process (AHP) to determine the security level of 5G call detail records (CDRs) and performing hierarchical encryption, the security risks caused by the simple encryption in existing technologies are resolved, achieving a balance between security and ease of use.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GROUP JIANGSU
- Filing Date
- 2022-03-18
- Publication Date
- 2026-05-29
AI Technical Summary
Current 5G call detail record (CDR) file encryption is simple, but it poses security risks and cannot select the appropriate encryption method based on the different security levels of the CDR file.
The security level of the call detail record (CDR) file is determined by the analytic hierarchy process (AHP), and an appropriate encryption scheme is selected based on the level, including single or double encryption. An encryption matrix is constructed by weighting and verifying the consistency of sensitive information, and an encryption key is generated to encrypt the file.
It enables the selection of appropriate encryption methods based on the security level of the call detail record (CDR) file, thereby improving file security while maintaining the simplicity and ease of use of the file distribution system interface.
Smart Images

Figure CN116801238B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to a method and apparatus for encrypting call detail records (CDRs). Background Technology
[0002] With the development of 5G technology and the Internet of Things, many partner systems interact with telecommunications operator systems to obtain 5G call detail record (CDR) data. Because 5G CDR files contain sensitive fields such as caller ID, called number, destination, IMSI (International Mobile Subscriber Identity), and base station information, encryption of the CDR files is necessary to prevent leakage of sensitive information.
[0003] 5G call detail records (CDRs) are uploaded to a designated directory on the partner's system via the operator's File Distribute System (FDS). The partner then retrieves the relevant files through a unified interface. Because different CDR types may contain different sensitive information, the security requirements for each type of 5G CDR file also vary.
[0004] Existing carrier file distribution systems provide a unified interface for external calls to ensure simplicity, convenience, and ease of use. Although 5G call detail record (CDR) files are encrypted, the use of conventional encryption, while simple, still presents security risks. This means that after authentication, partner providers can access the relevant CDR data through the interface. Summary of the Invention
[0005] This invention provides a method and apparatus for encrypting call detail records (CDRs), which addresses the shortcomings of existing CDR encryption methods that are simple but have security risks, and enables the selection of appropriate encryption methods based on the security level of the CDR.
[0006] This invention provides a method for encrypting call detail records (CDRs), comprising:
[0007] The file distribution system uses the analytic hierarchy process (AHP) to determine the security level of a call detail record (CDR) file based on sensitive information within it.
[0008] The call detail record (CDR) file is encrypted based on the encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0009] According to a call detail record (CDR) file encryption method provided by the present invention, the step of determining the security level of the CDR file based on sensitive information in the CDR file using the hierarchical analysis method includes:
[0010] A hierarchical model is constructed by taking the file distribution system as the target layer, the sensitive information of the call detail records as the criteria layer, and the security level as the scheme layer.
[0011] Based on the hierarchical model, a first judgment matrix between sensitive information and a second judgment matrix between security levels under each sensitive information are constructed in the file distribution system.
[0012] A consistency check is performed on the first judgment matrix and the second judgment matrix. If the consistency check passes, the security level of the call detail record (CDR) file is determined based on the first judgment matrix and the second judgment matrix.
[0013] According to a call detail record (CDR) file encryption method provided by the present invention, the consistency check of the first judgment matrix and the second judgment matrix includes:
[0014] Calculate the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and use the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system;
[0015] Calculate the consistency index value of each second judgment matrix based on the maximum eigenvalue and order of each second judgment matrix;
[0016] Based on the order of each second judgment matrix, find the random consistency index value corresponding to the order; wherein, the order and the random consistency index value are pre-associated;
[0017] Based on the weight of each sensitive information to the file distribution system, and the calculated consistency index value and random consistency index value of the second judgment matrix corresponding to each sensitive information, the consistency ratio corresponding to the first judgment matrix and the second judgment matrix is obtained.
[0018] If the consistency ratio is less than a preset threshold, it is known that the consistency verification of the first judgment matrix and the second judgment matrix has passed.
[0019] According to a call detail record (CDR) file encryption method provided by the present invention, the step of determining the security level of the CDR file based on a first judgment matrix and a second judgment matrix includes:
[0020] Calculate the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and use the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system;
[0021] Calculate the eigenvector corresponding to the largest eigenvalue of each second judgment matrix, and use the elements in the eigenvector corresponding to each second judgment matrix as the weights of each security level for the sensitive information corresponding to each second judgment matrix.
[0022] Calculate the weight of each security level for the file distribution system based on the weight of each security level for each sensitive information and the weight of each sensitive information for the file distribution system.
[0023] The maximum value among the weights of the security level on the file distribution system is calculated, and the security level corresponding to the maximum value is selected as the security level of the call detail record (CDR) file.
[0024] According to a method for encrypting call detail records (CDRs) files provided by the present invention, the encryption scheme includes encrypting the CDR file once and encrypting it twice.
[0025] According to a call detail record (CDR) file encryption method provided by the present invention, wherein the encryption scheme corresponding to the security level is used to encrypt the CDR file once, the step of encrypting the CDR file based on the encryption scheme corresponding to the security level includes:
[0026] The call detail record (CDR) file is divided into multiple data blocks;
[0027] Calculate the algebraic signature of the call detail record (CDR) file based on the data of each data block, the preset constant corresponding to each data block, and the identifier of the user requesting the CDR file.
[0028] The encryption key for the call detail record (CDR) file is generated based on the algebraic signature, attribute information, and the timestamp of the user requesting the CDR file.
[0029] The call detail record (CDR) file is encrypted using the encryption key.
[0030] The present invention also provides a call detail record (CDR) file encryption device, comprising:
[0031] The determination module is used to determine the security level of the call detail record (CDR) file based on the sensitive information in the CDR file using the analytic hierarchy process (AHP).
[0032] An encryption module is used to encrypt the call detail record (CDR) file based on an encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0033] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the call detail record (CDR) file encryption method described above.
[0034] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the call detail record (CDR) file encryption method as described above.
[0035] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the call detail record (CDR) file encryption method described above.
[0036] The call detail record (CDR) file encryption method and apparatus provided by this invention calculate the security level of the CDR file by performing hierarchical analysis based on the sensitive fields contained in the CDR file. By combining sensitive fields with hierarchical analysis, the security level of the CDR file can be effectively quantified. The CDR file is then encrypted hierarchically according to the security level, which not only ensures the security of the CDR file, but also maintains the simplicity and ease of use of the file distribution system interface. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0038] Figure 1 This is a flowchart illustrating the call detail record (CDR) file encryption method provided by the present invention;
[0039] Figure 2 This is a schematic diagram of the hierarchical analysis model in the call detail record (CDR) file encryption method provided by the present invention;
[0040] Figure 3 This is a schematic diagram illustrating the relationship between key generation, encryption, and decryption in the call detail record (CDR) file encryption method provided by this invention.
[0041] Figure 4 This is a schematic diagram of the call detail record (CDR) file encryption device provided by the present invention;
[0042] Figure 5 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0044] The following is combined with Figure 1The present invention describes a method for encrypting call detail records (CDRs), comprising: step 101, in which a file distribution system determines the security level of the CDR based on the sensitive information in the CDR according to the hierarchical analysis method;
[0045] The execution entity in this embodiment is the file distribution system on the operator's side.
[0046] Optionally, sensitive information includes the calling number, the called number, the destination, the IMSI, and the base station information.
[0047] Security levels are categorized into Level 1, Level 0, and Level -1. Level 1 offers the highest security level; highly sensitive call detail records (CDRs) are not exposed to external interfaces, cannot be uploaded, and do not require encryption. Level 0 provides a middle level of security; CDRs require secondary encryption before uploading. Level -1 offers the lowest security level; only single encryption is required for uploading.
[0048] When a user requests a call detail record (CDR) file from the operator, the file distribution system determines the security level of the CDR file based on the sensitive information contained within it. Different types of sensitive information result in different security levels. In this embodiment, the user can be a partner platform.
[0049] Step 102: Encrypt the call detail record (CDR) file based on the encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0050] Call detail records (CDRs) with different security levels are encrypted using different encryption schemes. For example, CDRs with high security levels use more complex encryption schemes, while CDRs with low security levels use simple encryption. This embodiment does not specifically limit the encryption scheme.
[0051] After encrypting the call detail record (CDR) file according to its security level, the CDR file is uploaded to the partner platform, which then forwards it to the user.
[0052] Before uploading call detail records (CDR) files, the file distribution system checks whether the CDR file already exists in the operator's file server application, FileServer. FileServer stores CDR files already uploaded by the file distribution system. If the file already exists, FileServer performs a deduplication operation, informing the file distribution system that the CDR file is duplicated. Upon receiving this duplicate information, the file distribution system terminates the CDR file upload operation.
[0053] Before determining the encryption scheme based on the security level, FileServer sends a user legitimacy verification request to the file distribution system. If the user legitimacy verification passes, the user is considered legitimate, and FileServer stores the user in the user information cache.
[0054] The FileServer sends an authorization verification request to the user, requiring them to verify their permissions. If the authorization verification is successful, it proves that the user does indeed own the call detail record (CDR) file, updates the information in the corresponding file information table, and adds the user to the list of legitimate users in the entity database.
[0055] If the user's legitimacy and permissions are verified, the encryption scheme is determined based on the security level.
[0056] This embodiment calculates the security level of a call detail record (CDR) file by performing hierarchical analysis based on the sensitive fields contained in the CDR file. By combining sensitive fields with the hierarchical analysis method, the security level of the CDR file can be effectively quantified. Based on the security level, the CDR file is encrypted in a hierarchical manner, which not only ensures the security of the CDR file, but also maintains the simplicity and ease of use of the file distribution system interface.
[0057] Based on the above embodiments, the method of determining the security level of a call detail record (CDR) file based on sensitive information in the CDR file according to the analytic hierarchy process in this embodiment includes: constructing a hierarchical structure model by taking the file distribution system as the target layer, the sensitive information of the CDR file as the criterion layer, and the security level as the scheme layer.
[0058] A hierarchical model constructed based on sensitive information, such as... Figure 2 As shown.
[0059] Based on the hierarchical model, a first judgment matrix between sensitive information in the file distribution system and a second judgment matrix between security levels under each sensitive information are constructed.
[0060] For example, construct a first judgment matrix between sensitive information in a file distribution system (FDS). Compare sensitive information pairwise using a relative scale to minimize the difficulty of comparing factors with different properties, thereby improving accuracy. The element a in the i-th row and j-th column of the first matrix is... ij It is obtained by comparing the i-th sensitive information with the j-th sensitive information. For a... ij The scaling method is shown in Table 1. The elements of the first judgment matrix are shown in Table 2. The construction method of the second judgment matrix is the same as that of the first judgment matrix. There is one first judgment matrix, and each FDS corresponds to one first judgment matrix. There are five second judgment matrices, with one second judgment matrix corresponding to each piece of sensitive information.
[0061] Table 1 Matrix a ij scaling methods
[0062] Scale meaning 1 This indicates that the two factors are equally important. 3 This indicates that, compared to another factor, one factor is slightly more important. 5 This indicates that, compared to two factors, one factor is significantly more important than the other. 7 This indicates that, compared to two factors, one factor is significantly more important than the other. 9 This indicates that, compared to another factor, one factor is extremely more important. 2,4,6,8 Termination of the above two adjacent judgments reciprocal <![CDATA[Factor a ji = 1 / a ij >
[0063] Table 2 Elements in the First Judgment Matrix
[0064] FDS Caller ID Called number Visited places IMSI base station Caller ID 1 1 1 4 1 Called number 1 1 2 4 1 Visited places 1 1 / 2 1 5 3 IMSI 1 / 4 1 / 4 1 / 5 1 1 / 3 base station 1 1 1 / 3 3 1
[0065] A consistency check is performed on the first judgment matrix and the second judgment matrix. If the consistency check passes, the security level of the call detail record (CDR) file is determined based on the first judgment matrix and the second judgment matrix.
[0066] When comparing multiple elements, it is difficult to maintain complete consistency in judgment. To ensure logical consistency in comparing the importance of influencing factors, a consistency check is required. If the consistency check passes, the security level of the call detail record (CDR) file is determined based on the first and second judgment matrices; if the consistency check fails, the first and second judgment matrices need to be reconstructed.
[0067] Based on the above embodiments, the consistency verification of the first judgment matrix and the second judgment matrix in this embodiment includes: calculating the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and using the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system;
[0068] Assume the criterion layer has m sensitive information pieces A1, A2, ..., A m The weights of FDS are sorted in descending order as a1, a2, ..., a m .
[0069] Calculate the consistency index value of each second judgment matrix based on the maximum eigenvalue and order of each second judgment matrix;
[0070] The consistency index CI is calculated as a standard to measure the degree of inconsistency in the second judgment matrix. CI = (λ) max -n) / (n-1). λ max Let n be the largest eigenvalue of each second judgment matrix, and n be the order of each second judgment matrix. Figure 2 The order of the second judgment matrix obtained is 3.
[0071] When CI is 0, there is perfect consistency; when CI is close to 0, there is satisfactory consistency; the larger the CI, the more serious the inconsistency.
[0072] Based on the order of each second judgment matrix, find the random consistency index value corresponding to the order; wherein, the order and the random consistency index value are pre-associated;
[0073] Due to the complexity of objective things and the ambiguity in judging and comparing them, it is difficult to construct a completely consistent comparison matrix. To measure the magnitude of CI, a random consistency index RI is introduced. The relationship between the random consistency index value and the matrix order is shown in Table 3. By referring to Table 3, the random consistency index value corresponding to the order of each second judgment matrix can be obtained.
[0074] Table 3 Elements in the First Judgment Matrix
[0075] n 1 2 3 4 5 6 7 8 9 10 RI 0 0 0.58 0.90 1.12 1.24 1.32 1.41 1.45 1.49
[0076] Based on the weight of each sensitive information to the file distribution system, and the calculated consistency index value and random consistency index value of the second judgment matrix corresponding to each sensitive information, the consistency ratio corresponding to the first judgment matrix and the second judgment matrix is obtained.
[0077] The weights of all sensitive information in the file distribution system, sorted from largest to smallest, are a1, a2, ..., a m The consistency index values of the second judgment matrix corresponding to all sensitive information are sorted in descending order as C1, C2, ..., C m The random consistency index values of the second judgment matrix corresponding to all sensitive information are sorted in descending order as RI1, RI2, ..., RI m .
[0078] The consistency ratio between the first judgment matrix and the second judgment matrix
[0079] If the consistency ratio is less than a preset threshold, it is known that the consistency verification of the first judgment matrix and the second judgment matrix has passed.
[0080] Optionally, the preset threshold is 0.1. When CR < 0.1, the overall hierarchical sorting of the first and second judgment matrices passes the consistency check.
[0081] Based on the above embodiments, the method of determining the security level of the call detail record file according to the first judgment matrix and the second judgment matrix in this embodiment includes: calculating the feature vector corresponding to the largest feature value of the first judgment matrix, and using the elements in the feature vector corresponding to the first judgment matrix as the weight of each sensitive information to the file distribution system;
[0082] Assume the criterion layer has m sensitive information pieces A1, A2, ..., A m The weights of FDS are sorted in descending order as a1, a2, ..., a mThis weight is used to characterize the degree of connection between sensitive information and the file distribution system.
[0083] Calculate the eigenvector corresponding to the largest eigenvalue of each second judgment matrix, and use the elements in the eigenvector corresponding to each second judgment matrix as the weights of each security level for the sensitive information corresponding to each second judgment matrix.
[0084] The nth security level in the scheme layer corresponds to the jth sensitive information A in the criterion layer. j The hierarchical single sort is b 1j b 2j , ..., b nj , j = 1, 2, ..., m. This weight is used to characterize the degree of correlation between each security level and each piece of sensitive information.
[0085] Calculate the weight of each security level for the file distribution system based on the weight of each security level for each piece of sensitive information and the weight of each piece of sensitive information for the file distribution system;
[0086] The weight B of the i-th security level in the scheme layer to the target layer FDS i for This weight is used to characterize the degree of connection between each security level and the target layer. That is:
[0087] B1:a1b 11 +a2b 12 +...+a m b 1m ;
[0088] B2:a1b 21 +a2b 22 +...+a m b 2m ; ...;
[0090] B n :a1b n1 +a2b n2 +...+a m b nm .
[0091] The maximum value among the weights of the security level on the file distribution system is calculated, and the security level corresponding to the maximum value is selected as the security level of the call detail record (CDR) file.
[0092] Based on the above embodiments, the encryption scheme in this embodiment includes primary encryption and secondary encryption of the call detail record (CDR) file.
[0093] Optionally, security levels include Level 1, Level 0, and Level -1. Level 1 offers the highest security level; highly sensitive call detail records (CDRs) are not exposed to external interfaces, and CDRs cannot be uploaded. Level 1 encryption requires no encryption. Level 0 offers a middle level of security; CDRs require secondary encryption before uploading, and the corresponding encryption scheme is secondary encryption. Level -1 offers the lowest security level; only single encryption is required for uploading, and the corresponding encryption scheme is single encryption.
[0094] Based on the above embodiments, in this embodiment, when the encryption scheme corresponding to the security level is to encrypt the call detail record (CDR) file once, the encryption of the CDR file based on the encryption scheme corresponding to the security level includes: dividing the CDR file into multiple data blocks;
[0095] To verify data integrity, an algebraic signature is added to the encryption key. The integrity of the data is verified by checking whether the algebraic signature of the data block matches the algebraic signature result of the corresponding data block.
[0096] The call detail record (CDR) file F is divided into c data blocks f[1], f[2], ..., f[c].
[0097] Calculate the algebraic signature of the call detail record (CDR) file based on the data of each data block, the preset constant corresponding to each data block, and the identifier of the user requesting the CDR file.
[0098] Let the preset constants corresponding to all data blocks form a tuple λ = (λ1, λ2, ..., λ3) in a finite field. c This tuple is a vector consisting of non-zero elements. If the user's identifier is UID, then the algebraic signature of the call detail record (CDR) file F is...
[0099] By combining user identifiers to generate algebraic tags, it is convenient to trace files and facilitates error correction.
[0100] Based on the algebraic signature, attribute information, and timestamp of the user requesting the call detail record (CDR) file, an encryption key for the CDR file is generated; the CDR file is then encrypted using the encryption key.
[0101] During the initialization of the file distribution system, the key generation system generates a multi-key key pool based on the identifiers of the partner platforms. For example... Figure 3 As shown, the key generation system, encryption application, and decryption application register their own call addresses with the registry center. Each time the application performs encryption, it requests an encryption key from the key pool system through the key address. Upon receiving the request, the key pool will provide the encryption application with a key and the decryption application with a decryption key.
[0102] When the security level is -1, only one encryption is required for direct upload; secondary encryption is not necessary. Optionally, after the user receives the uploaded encrypted file, the FileServer sends the user's decryption key request to the FDS via the Netty protocol. The FDS sends λ, the user's UID, the call detail record (CDR) file's attribute information, and the timestamp of the user's CDR file request to the FileServer. The FileServer calculates the decryption key and verifies whether it is equal to the encryption key. If they are equal, the decryption key is correct, and the decryption key is sent to the user for decryption.
[0103] When the security level is 0, the call detail record (CDR) file requires secondary encryption. A second encryption is performed on top of the first encryption. Optionally, the FileServer encrypts a random key using its public key and sends it to the FDS via the Netty protocol. The FDS receives the random key, decrypts it using its private key, and then uses this key to encrypt the first-encrypted CDR file again before uploading it.
[0104] The call detail record (CDR) file encryption device provided by the present invention is described below. The CDR file encryption device described below can be referred to in correspondence with the CDR file encryption method described above.
[0105] like Figure 4 As shown, the device includes a determination module 401 and an encryption module 402, wherein:
[0106] The determination module 401 is used to determine the security level of the call detail record (CDR) file based on the sensitive information in the CDR file using the analytic hierarchy process (AHP).
[0107] The encryption module 402 is used to encrypt the call detail record (CDR) file based on the encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0108] This embodiment calculates the security level of a call detail record (CDR) file by performing hierarchical analysis based on the sensitive fields contained in the CDR file. By combining sensitive fields with the hierarchical analysis method, the security level of the CDR file can be effectively quantified. Based on the security level, the CDR file is encrypted in a hierarchical manner, which not only ensures the security of the CDR file, but also maintains the simplicity and ease of use of the file distribution system interface.
[0109] Figure 5 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 5As shown, the electronic device may include a processor 510, a communications interface 520, a memory 530, and a communication bus 540, wherein the processor 510, communications interface 520, and memory 530 communicate with each other via the communication bus 540. The processor 510 can call logical instructions in the memory 530 to execute a call detail record (CDR) file encryption method. This method includes: a file distribution system determining the security level of the CDR file based on sensitive information in the CDR file using a hierarchical analysis method; encrypting the CDR file based on an encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0110] Furthermore, the logical instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0111] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the call detail record (CDR) file encryption method provided by the above methods. The method includes: a file distribution system determining the security level of the CDR file based on the sensitive information in the CDR file using the hierarchical analysis method; encrypting the CDR file based on the encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0112] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program implements the call detail record (CDR) file encryption method provided by the above methods. The method includes: a file distribution system determining the security level of the CDR file based on sensitive information in the CDR file using a hierarchical analysis method; encrypting the CDR file based on an encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
[0113] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0114] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0115] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for encrypting call detail records (CDRs), characterized in that, include: A hierarchical model is constructed by taking the file distribution system as the target layer, the sensitive information in the call detail records (CDRs) as the criteria layer, and the security level as the solution layer. Based on the hierarchical model, a first judgment matrix between sensitive information and a second judgment matrix between security levels under each sensitive information are constructed in the file distribution system. Calculate the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and use the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system; Calculate the consistency index value of each second judgment matrix based on the maximum eigenvalue and order of each second judgment matrix; Based on the order of each second judgment matrix, find the random consistency index value corresponding to the order; wherein, the order and the random consistency index value are pre-associated; Based on the weight of each sensitive information to the file distribution system, and the calculated consistency index value and random consistency index value of the second judgment matrix corresponding to each sensitive information, the consistency ratio corresponding to the first judgment matrix and the second judgment matrix is obtained. If the consistency ratio is less than a preset threshold, and it is known that the consistency verification of the first judgment matrix and the second judgment matrix has passed, then the security level of the call detail record file is determined based on the first judgment matrix and the second judgment matrix. The call detail record (CDR) file is encrypted based on the encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
2. The call detail record (CDR) file encryption method according to claim 1, characterized in that, The step of determining the security level of the call detail record (CDR) file based on the first judgment matrix and the second judgment matrix includes: Calculate the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and use the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system; Calculate the eigenvector corresponding to the largest eigenvalue of each second judgment matrix, and use the elements in the eigenvector corresponding to each second judgment matrix as the weights of each security level for the sensitive information corresponding to each second judgment matrix. Calculate the weight of each security level for the file distribution system based on the weight of each security level for each piece of sensitive information and the weight of each piece of sensitive information for the file distribution system; The maximum value among the weights of the security level on the file distribution system is calculated, and the security level corresponding to the maximum value is selected as the security level of the call detail record (CDR) file.
3. The call detail record (CDR) file encryption method according to any one of claims 1-2, characterized in that, The encryption scheme includes encrypting the call detail record (CDR) file once and then encrypting it twice.
4. The call detail record (CDR) file encryption method according to claim 3, characterized in that, When the encryption scheme corresponding to the security level is to encrypt the call detail record (CDR) file once, the encryption of the CDR file based on the encryption scheme corresponding to the security level includes: The call detail record (CDR) file is divided into multiple data blocks; Calculate the algebraic signature of the call detail record (CDR) file based on the data of each data block, the preset constant corresponding to each data block, and the identifier of the user requesting the CDR file. The encryption key for the call detail record (CDR) file is generated based on the algebraic signature, attribute information, and the timestamp of the user requesting the CDR file. The call detail record (CDR) file is encrypted using the encryption key.
5. A call detail record (CDR) file encryption device, characterized in that, include: The determination module is used to construct a hierarchical model by taking the file distribution system as the target layer, the sensitive information of the call detail records as the criteria layer, and the security level as the solution layer. Based on the hierarchical model, a first judgment matrix between sensitive information and a second judgment matrix between security levels under each sensitive information are constructed in the file distribution system. Calculate the eigenvector corresponding to the largest eigenvalue of the first judgment matrix, and use the elements in the eigenvector corresponding to the first judgment matrix as the weights of each sensitive information to the file distribution system; Based on the maximum eigenvalue and order of each second judgment matrix, a calculated consistency index value is calculated for each second judgment matrix; based on the order of each second judgment matrix, a random consistency index value corresponding to the order is found; wherein, the order and the random consistency index value are pre-associated; based on the weight of each sensitive information to the file distribution system, and the calculated consistency index value and random consistency index value of the second judgment matrix corresponding to each sensitive information, the consistency ratio corresponding to the first judgment matrix and the second judgment matrix is obtained; if the consistency ratio is less than a preset threshold, it is known that the consistency verification of the first judgment matrix and the second judgment matrix has passed, and the security level of the call detail record file is determined based on the first judgment matrix and the second judgment matrix; An encryption module is used to encrypt the call detail record (CDR) file based on an encryption scheme corresponding to the security level; wherein the security level and the encryption scheme are pre-associated.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the call detail record (CDR) file encryption method as described in any one of claims 1 to 4.
7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the call detail record (CDR) file encryption method as described in any one of claims 1 to 4.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the call detail record (CDR) file encryption method as described in any one of claims 1 to 4.