An information security protection method and system based on big data

By using comprehensive functions to process and verify the data during big data transmission, generating and updating summary data and identification, the problem of data protection in multi-node transmission environment is solved, data integrity and authenticity guarantee is achieved, and attack resistance is improved.

CN119030736BActive Publication Date: 2025-06-20NANJING XINHONGBO EDUCATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410938519.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-13
Publication Date
2025-06-20
Estimated Expiration
2044-07-13

AI Technical Summary

Technical Problem

In the data transmission process in the big data era, it is difficult to effectively protect the confidentiality and authentication of data in a multi-node transmission environment, and there is a risk of tampering, stealing and illegal access.

Method used

The information security protection method based on big data is adopted to ensure the integrity and consistency of the data during transmission by using comprehensive functions at the sender and each transmission node.

Benefits of technology

It effectively prevents data from being maliciously modified during transmission, ensures the integrity and authenticity of data, increases the difficulty of data being tampered with, and improves the resistance to network attacks and data tampering through distributed security verification mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119030736B_ABST
    Figure CN119030736B_ABST
Patent Text Reader

Abstract

The present invention discloses an information security protection method based on big data, which relates to the technical field of data transmission security protection, and includes obtaining transmission data and a preset transmission path from a sender to a receiver; matching a comprehensive function according to the transmission data at the sender and performing processing; receiving an original data set at the first transmission node, verifying the original data set, and generating a first identifier and a first data set; receiving the first data set at the second transmission node, verifying the original data set, and generating a second identifier and a second data set; receiving the i-th data set at the n-th transmission node, verifying the original data set, and generating an m-th identifier and an m-th data set; receiving the m-th data set at the receiver, verifying the original data set, inversely deriving the actual transmission path according to the m-th identifier, and comparing the actual transmission path with the preset transmission path. An information security protection system based on big data is also provided. The present invention has the advantages of high data transmission security, traceability, and efficiency optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission security protection, and particularly to an information security protection method and system based on big data. Background Art

[0002] With the rapid development of information technology, big data has become an important resource in today's era. However, in the process of big data collection, transmission, and processing, data security issues have become increasingly prominent. Especially in the data transmission link, the transmission of data in the big data era has become unprecedentedly complex. To cope with the huge scale and high transmission requirements of big data, data transmission often needs to pass through multiple intermediate nodes to achieve faster and more stable data circulation. Due to the complexity and openness of the network environment, such data transmission also increases the multiple risks of data being tampered with, stolen, or illegally accessed during the transmission process. The traditional data transmission security methods mainly rely on means such as encryption technology and digital signatures. Although these technologies can protect the confidentiality and authenticity of data to a certain extent, in the face of a complex multi-node transmission environment, there are still many deficiencies. When data is transmitted through multiple intermediate nodes, each node may become a potential attack point. The encryption key may be leaked, and the digital signature may also be maliciously tampered with. If not discovered in time, more serious consequences will occur. Summary of the Invention

[0003] Aiming at the deficiencies in the prior art, the present invention provides an information security protection method and system based on big data.

[0004] An information security protection method based on big data, comprising: obtaining transmission data and a preset transmission path from a sender to a receiver, where the preset transmission path includes a first transmission node, a second transmission node, ……, an nth transmission node that the transmission data needs to pass through in sequence; at the sender, matching a comprehensive function according to the transmission data, processing the transmission data based on the comprehensive function and outputting original digest data, associating the comprehensive function and the original digest data with the transmission data and generating an original data set, and sending the original data set to the first transmission node; at the first transmission node, receiving the original data set, processing the transmission data based on the comprehensive function and outputting first node digest data, verifying whether the first node digest data is consistent with the original digest data, if not, issuing a security protection warning, if so, generating a first identifier based on the comprehensive function, associating the first identifier with the original data set and forming a first data set, and sending the first data set to the second transmission node; at the second transmission node, receiving the first data set, processing the transmission data based on the comprehensive function and outputting second node digest data, verifying whether the second node digest data is consistent with the original digest data, if not, issuing a security protection warning, if so, generating a second identifier based on the comprehensive function and the first identifier, associating the second identifier with the original data set and forming a second data set, and sending the second data set to the next transmission node; at the nth transmission node, receiving the ith data set, where the ith data set includes the ith identifier and the original data set, processing the transmission data based on the comprehensive function and outputting nth node digest data, verifying whether the nth node digest data is consistent with the original digest data, if not, issuing a security protection warning, if so, generating an mth identifier based on the comprehensive function and the ith identifier, associating the mth identifier with the original data set and forming an mth data set, and sending the mth data set to the receiver; at the receiver, receiving the mth data set, processing the transmission data based on the comprehensive function and outputting end digest data, verifying whether the end digest data is consistent with the original digest data, if not, issuing a security protection warning, if so, inversely obtaining the actual transmission path based on the comprehensive function and the mth identifier, comparing the actual transmission path with the preset transmission path, if not, checking the comparison information and issuing a security protection warning.

[0005] Preferably, the comprehensive function includes a hashing processing method and a counting function; wherein, the hashing processing is used to map the transmission data and output digest data; the counting function is used to obtain an identifier and generate a new identifier according to the identifier.

[0006] Preferably, the counting function includes: ; where I is the original identifier, T is a time value used to represent the current time, occurrence time, and preset time, is a transformation function based on the time value, is a logarithmic function with the natural constant (e) as the base, is a modulo operation, is a large prime number used for modulo operation.

[0007] Preferably, the transformation function includes: ; wherein, is the hash value obtained by hashing the time value using the SHA-256 hash algorithm, is the result extracted from the hash value.

[0008] Preferably, the hashing method includes: accepting a string S of a preset length; padding the string S and assigning the padded data to a variable padded; splitting the variable padded into multiple data blocks of a specified size and storing the data blocks in an array blocks; performing a hash calculation on the array blocks to obtain a hash value.

[0009] Preferably, performing a hash calculation on the array blocks to obtain a hash value includes: initializing a hash state hash_state; performing multiple rounds of loop hash calculations based on round constants, hash_state, and blocks, obtaining and updating the hash state; obtaining a hash value through the current hash state.

[0010] Preferably, the matching of the synthesis function according to the transmission data at the sender includes: obtaining the length of the transmission data at the sender and matching the hashing method according to the length.

[0011] Also provided is an information security protection system based on big data. The system is used to implement the above-mentioned information security protection method based on big data. The system includes: a path confirmation module, configured to obtain the transmission data and a preset transmission path from the sender to the receiver, where the preset transmission path includes the first transmission node, the second transmission node,..., the nth transmission node that the transmission data needs to pass through in sequence; a sending module, configured to match a comprehensive function according to the transmission data at the sender, process the transmission data based on the comprehensive function and output the original digest data, associate the comprehensive function and the original digest data with the transmission data and generate an original data set, and send the original data set to the first transmission node; the first node module, configured to receive the original data set at the first transmission node, process the transmission data based on the comprehensive function and output the first node digest data, verify whether the first node digest data is consistent with the original digest data, if not, issue a security protection warning, if so, generate a first identifier based on the comprehensive function, associate the first identifier with the original data set and form a first data set, and send the first data set to the second transmission node; the second node module, configured to receive the first data set at the second transmission node, process the transmission data based on the comprehensive function and output the second node digest data, verify whether the second node digest data is consistent with the original digest data, if not, issue a security protection warning, if so, generate a second identifier based on the comprehensive function and the first identifier, associate the second identifier with the original data set and form a second data set, and send the second data set to the next transmission node; the nth node module, configured to receive the ith data set at the nth transmission node, the ith data set includes the ith identifier and the original data set, process the transmission data based on the comprehensive function and output the nth node digest data, verify whether the nth node digest data is consistent with the original digest data, if not, issue a security protection warning, if so, generate an mth identifier based on the comprehensive function and the ith identifier, associate the mth identifier with the original data set and form an mth data set, and send the mth data set to the receiver; a receiving module, configured to receive the mth data set at the receiver, process the transmission data based on the comprehensive function and output the end digest data, verify whether the end digest data is consistent with the original digest data, if not, issue a security protection warning, if so, inversely obtain the actual transmission path based on the comprehensive function and the mth identifier, compare the actual transmission path with the preset transmission path, if not, check the comparison information and issue a security protection warning.

[0012] Also provided is a non-transitory computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the above-mentioned information security protection method based on big data.

[0013] An electronic device is also provided, including: a memory on which a computer program is stored; and a processor for executing the computer program in the memory to implement the above-mentioned information security protection method based on big data.

[0014] The beneficial effects of the present invention are as follows:

[0015] By introducing a comprehensive function to process the transmitted data and generating and verifying the digest data at each transmission node, the integrity and consistency of the data during transmission are ensured. Any tampering with the data will cause a change in the digest data, thereby triggering a security protection warning, effectively preventing the data from being maliciously modified during transmission; further, in addition to verifying the integrity of the data, this technical solution also generates an identifier at the first transmission node, and new identifiers are generated from the original identifier at each transmission node, which can ensure the integrity and authenticity of the data. Each node will process the data and generate a new digest data and identifier, which increases the difficulty of data tampering because any modification to the data will cause the verification of subsequent nodes to fail; further, the identifier generated by each node is associated with the data set, forming a "fingerprint chain" of data transmission, which allows tracing the data transmission path when problems occur and determining the specific location where the problem occurs, facilitating fault troubleshooting and accountability; further, traditional data transmission security verification may require complex data processing and analysis at the receiving end, while through iterative verification and identifier update at each node, problems can be discovered and solved in a timely manner, avoiding retransmission caused by problems being discovered only after the data reaches the receiving end, thereby improving the overall transmission efficiency; further, by forming a distributed security verification mechanism, each node participates in the data verification process instead of relying solely on the final verification at the receiving end. This distributed verification method can more effectively resist network attacks and data tampering. Since each node performs similar processing and verification processes, it can be easily extended to more transmission nodes without major changes to the overall architecture. This flexibility and scalability enable the entire technical solution to adapt to the transmission requirements in the big data era with different scales and complexities. Description of the Drawings

[0016] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.

[0017] Figure 1 It is a schematic diagram of the steps of the information security protection method based on big data of the present invention;

[0018] Figure 2Schematic diagram of the steps of the hashing processing method of the present invention;

[0019] Figure 3 Schematic diagram of the steps of performing hash calculation on the array blocks of the present invention to obtain a hash value;

[0020] Figure 4 Block diagram of an electronic device shown in an embodiment of the present invention.

[0021] Reference numerals:

[0022] 700 - Electronic device, 701 - Processor, 702 - Memory, 703 - Multimedia component, 704 - Input / Output (I / O) interface, 705 - Communication component. Detailed implementation manners

[0023] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations.

[0024] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0025] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance..

[0026] As Figure 1 shown, a big data - based information security protection method is provided, including:

[0027] S1. Obtain the transmission data and the preset transmission path from the sender to the receiver, where the preset transmission path includes the first transmission node, the second transmission node,..., the nth transmission node that the transmission data needs to pass through in sequence.

[0028] S2. At the sender, match a comprehensive function according to the transmission data, process the transmission data based on the comprehensive function and output the original digest data, associate the comprehensive function and the original digest data with the transmission data to generate an original data set, and send the original data set to the first transmission node.

[0029] S3. Receive the original data set at the first transmission node, process the transmitted data based on the comprehensive function and output the first node summary data. Verify whether the first node summary data is consistent with the original summary data. If not, issue a security protection warning. If so, generate a first identifier based on the comprehensive function, associate the first identifier with the original data set to form a first data set, and send the first data set to the second transmission node.

[0030] S4. Receive the first data set at the second transmission node, process the transmitted data based on the comprehensive function and output the second node summary data. Verify whether the second node summary data is consistent with the original summary data. If not, issue a security protection warning. If so, generate a second identifier based on the comprehensive function and the first identifier, associate the second identifier with the original data set to form a second data set, and send the second data set to the next transmission node.

[0031] S5. Receive the i-th data set at the n-th transmission node. The i-th data set includes the i-th identifier and the original data set. Process the transmitted data based on the comprehensive function and output the n-th node summary data. Verify whether the n-th node summary data is consistent with the original summary data. If not, issue a security protection warning. If so, generate an m-th identifier based on the comprehensive function and the i-th identifier, associate the m-th identifier with the original data set to form an m-th data set, and send the m-th data set to the recipient.

[0032] S6. Receive the m-th data set at the recipient, process the transmitted data based on the comprehensive function and output the end summary data. Verify whether the end summary data is consistent with the original summary data. If not, issue a security protection warning. If so, invert the actual transmission path based on the comprehensive function and the m-th identifier, compare the actual transmission path with the preset transmission path. If not, check the comparison information and issue a security protection warning.

[0033] In this embodiment, it should be noted that in S1, the transmitted data and the preset transmission path from the sender to the recipient are obtained; the transmitted data is the information that needs to be transmitted from one location (sender) to another location (recipient). Before data transmission, it is necessary to determine the path that the data will pass through, that is, the intermediate nodes that the data needs to pass through from the sender to the recipient. These nodes may be network devices such as routers, servers, and gateways; in this step, the system will obtain and record this preset transmission path, including all the nodes that need to pass through (the first transmission node, the second transmission node,..., the n-th transmission node).

[0034] In S2, at the sender side, a comprehensive function is matched according to the transmission data and the data is processed; the comprehensive function is composed of two or more specific algorithms and functions, and only one of them may be used here. It is used to process the transmission data and generate digest data. This function may involve hash algorithms, encryption algorithms or other data processing techniques, aiming to ensure the integrity and security of the data; the data digest generated after processing the transmission data through the comprehensive function represents the characteristics or fingerprints of the original data and is used to verify the integrity of the data subsequently; the original data set includes the original transmission data, the comprehensive function, and the generated original digest data, and this data set will be sent to the first transmission node.

[0035] In S3, at the first transmission node, the original data set is received and processed; at the first transmission node, the comprehensive function is used to process the received transmission data, generate the first node digest data, and compare it with the original digest data to verify the integrity of the data; if the verification fails, by issuing a security protection warning, abnormal situations in the data transmission process can be detected in a timely manner, so as to take corresponding countermeasures to avoid serious leakage and tampering accidents. At the same time, the timely security protection warning can help analyze the causes of security incidents, improve security measures, and prevent similar incidents from occurring again; if the verification passes, the node will generate a unique identifier (the first identifier) based on the comprehensive function, and this identifier will be associated with the original data set to form a new data set (the first data set), and then sent to the next node.

[0036] In S4 and S5, at the second transmission node, the first data set is received and processed; similar to the first node, the second node will also use the comprehensive function to process the data and verify its integrity; if the data is complete, the node will generate a new unique identifier (the second identifier) based on the first identifier, that is, the generation of the second identifier contains the historical information of the first identifier, and associate it with the original data set and form it on the second data set, thus forming the historical state of the original data set; then the second data set is sent to the next node, and this process will be repeated on each subsequent node to generate the mth identifier and the mth data set until the data reaches the receiver.

[0037] In S6, at the receiver side, the mth data set is received and processed; the receiver receives the mth data set from the last transmission node. The receiver uses the comprehensive function to process the transmission data in the mth data set and verify its integrity; if the data is complete, the receiver will also invert the actual transmission path based on the comprehensive function and the mth identifier and compare it with the preset transmission path to ensure that the data is transmitted along the preset path. If there is any discrepancy, the system will issue a security protection warning, and the discrepancies will be recorded and further analyzed.

[0038] In summary, by introducing a comprehensive function to process the transmitted data and generating and verifying the digest data at each transmission node, the integrity and consistency of the data during transmission are ensured. Any tampering with the data will result in a change in the digest data, thereby triggering a security protection warning, effectively preventing the data from being maliciously modified during transmission. Further, in addition to verifying the integrity of the data, this technical solution also generates an identifier at the first transmission node. By generating a new identifier from the original identifier at each transmission node, the integrity and authenticity of the data can be ensured. Each node will process the data and generate a new digest data and identifier, which increases the difficulty of data tampering because any modification to the data will result in a verification failure at the subsequent nodes. Further, the identifier generated by each node is associated with the data set, forming a "fingerprint chain" of data transmission. This allows tracing the data transmission path when problems occur and determining the specific location where the problem occurred, facilitating fault troubleshooting and liability tracing. Further, traditional data transmission security verification may require complex data processing and analysis at the receiving end. By performing iterative verification and identifier update at each node, problems can be detected and solved in a timely manner, avoiding retransmission caused by problems being discovered only after the data reaches the receiving end, thereby improving the overall transmission efficiency. Further, by forming a distributed security verification mechanism, each node participates in the data verification process instead of relying solely on the final verification at the receiving end. This distributed verification method can more effectively resist network attacks and data tampering. Since each node performs similar processing and verification processes, it can be easily extended to more transmission nodes without major changes to the overall architecture. This flexibility and scalability enable the entire technical solution to meet the transmission requirements in the big data era with different scales and complexities.

[0039] Specifically, the comprehensive function includes a hashing processing method and a counting function; wherein, the hashing processing is used to map the transmitted data and output the digest data; the counting function is used to obtain the identifier and generate a new identifier based on the identifier.

[0040] In this embodiment, it should be noted that the hashing method is mainly used to map the transmitted data and output the digest data. This process is achieved through specific hashing algorithms (such as SHA-256, MD5, etc.), which can map data of any length to digest data of a fixed length. The digest data, as the "fingerprint" of the data, is used to verify the integrity of the data during data transmission. If the data is tampered with during transmission, the digest data generated by the hashing algorithm will also change, thereby triggering a security protection warning. The counting function is mainly used to obtain the identifier of the current node and generate a new identifier based on this identifier. This process is achieved based on certain algorithms and rules to ensure that each node can generate a unique and traceable identifier. The identifier plays a role in tracking and verification during data transmission. After each node receives the data, it will use the counting function to generate a new identifier and associate it with the data set. In this way, by inverting the identifier, the historical state of the original data set can be obtained to verify whether the historical state matches the preset transmission path and whether it has been correctly processed at each node.

[0041] Specifically, the counting function includes: ; where I is the original identifier, and T is the time value used to represent the current time, occurrence time, and preset time. is a transformation function based on the time value. is the natural logarithm function with the base of the natural constant (e). is the modulo operation. is a large prime number used for the modulo operation.

[0042] In this embodiment, it should be noted that the counting function depends not only on the current identifier but also on the time value, thus ensuring the uniqueness and security of the generated new identifier. If there is no current identifier, the value of I is taken as zero or a preset value. In addition, the accuracy and range of the time value T also need to be reasonably selected according to the actual application scenario. is a transformation function based on the time value, which can be hashing the time value, taking the logarithm, applying the sine function, etc., to ensure that the output generated by each time value is unique. is mainly used to introduce non-linear factors, so that the counting function is not easily cracked and the anti-tampering ability is improved. The modulo operation of can ensure that the numerical value always falls within a specific range. To ensure security, the selected large prime number M should be large enough to resist possible brute-force attacks.

[0043] Specifically, the transformation function includes: ; where is the hash value obtained by hashing the time value using the SHA-256 hash algorithm. To extract the result from the hash value.

[0044] In this embodiment, it should be noted that by applying the SHA-256 hash algorithm to the time value, a hash value with a fixed length (256 bits) is generated. Represents the operation of extracting a part from the hash value. In practical applications, it is not necessary to use the complete hash value, but only a part of it; the extraction method can be truncation, bitwise operation, or modulo operation, etc.

[0045] Such as Figure 2 and Figure 3 As shown, specifically, the hashing method includes:

[0046] S01. Accept a string S of a preset length;

[0047] S02. Pad the string S and assign the padded data to the variable padded;

[0048] S03. Split the variable padded into multiple data blocks of a specified size and store the data blocks in the array blocks;

[0049] S04. Perform a hash calculation on the array blocks to obtain a hash value.

[0050] Specifically, S04 includes:

[0051] S041. Initialize the hash state hash_state;

[0052] S042. Perform multiple rounds of cyclic hash calculation based on the round constants, hash_state, and blocks to obtain and update the hash state;

[0053] S043. Obtain the hash value through the current hash state.

[0054] In this embodiment, it should be noted that the hashing process can be completed through simplified code:

[0055] 1 padded = pad(s)

[0056] 2 blocks = split(s_padded, block_size)

[0057] 3 hash_state = initial_hash_value

[0058] 4 for block in blocks:

[0059] 5 for round in range(number_of_rounds):

[0060] 6 hash_state = update_function(hash_state, block, round_constants)

[0061] 7 return finalize(hash_state)

[0062] Among them, the first line of code corresponds to S02, which means padding the string S to meet the requirements of the hash function processing and assigning the padded data to the variable padded; different input data may have different lengths, while hash functions usually require the input data to have a specific length or the length to be a multiple of a fixed value. By padding, the lengths of all input data can be adjusted to meet this requirement.

[0063] The second line of code corresponds to S03. split is a function whose role is to split the padded data s_padded into multiple data blocks of a fixed size, and the size of each data block is specified by block_size; these split data blocks are stored in the variable blocks, usually a list or an array.

[0064] The third line of code corresponds to S041, which means initializing the hash state; here, hash_state is a variable used to store the hash state value during the calculation process, and initial_hash_value is a set of predefined initial values, which serve as the starting point for the hash calculation.

[0065] The code from the fourth line to the sixth line corresponds to S042. Specifically: range(number_of_rounds) generates a sequence of integers from 0 to number_of_rounds - 1. The for round in... loop will iterate through this sequence, and in each iteration, the round variable will be assigned the next value in the sequence. Inside the loop, a series of calculations or transformations will be performed, and these calculations or transformations may depend on the current round number (i.e., the value of the round variable). In hash calculation, multiple rounds of calculation are an important means to increase complexity and security. In each round, a series of operations such as non-linear transformation, displacement, and logical operation will be performed based on the current hash state and input data to update the hash state.

[0066] The seventh line of code corresponds to S043, which calls the finalize function to convert the final hash state into a hash value.

[0067] Specifically, the sender matching the comprehensive function according to the transmission data includes: obtaining the length of the transmission data at the sender and matching the hashing processing method according to the length.

[0068] In this embodiment, it should be noted that different data lengths may require different padding and segmentation strategies, and may affect the efficiency and security of hash calculation. For example, if the data length is short, a hash function with relatively high calculation efficiency and a moderate hash value length may be selected. If the data length is long, it may be necessary to consider using a hash function that can handle large amounts of data, or splitting the data into multiple small pieces and performing hash processing on them separately. Once the specific hashing processing method is determined, the sender will process the transmission data according to this method, which usually includes steps such as data padding, segmentation, and hash calculation, and finally generates a hash value.

[0069] There is also provided an information security protection system based on big data, which is used to implement the above-mentioned information security protection method based on big data. The system includes:

[0070] A path confirmation module, which is used to obtain the transmission data and the preset transmission path from the sender to the receiver. The preset transmission path includes the first transmission node, the second transmission node,..., the nth transmission node that the transmission data needs to pass through in sequence;

[0071] A sending module, which is used to match the comprehensive function according to the transmission data at the sender, process the transmission data based on the comprehensive function and output the original digest data, associate the comprehensive function and the original digest data with the transmission data and generate an original data set, and send the original data set to the first transmission node;

[0072] The first node module is used to receive the original data set at the first transmission node, process the transmission data based on the comprehensive function and output the first node digest data, verify whether the first node digest data is consistent with the original digest data. If not, a security protection warning is issued. If they are consistent, a first identifier is generated based on the comprehensive function, the first identifier is associated with the original data set and a first data set is formed, and the first data set is sent to the second transmission node;

[0073] The second node module is used to receive the first data set at the second transmission node, process the transmission data based on the comprehensive function and output the second node digest data, verify whether the second node digest data is consistent with the original digest data. If not, a security protection warning is issued. If they are consistent, a second identifier is generated based on the comprehensive function and the first identifier, the second identifier is associated with the original data set and a second data set is formed, and the second data set is sent to the next transmission node;

[0074] The nth node module is used to receive the ith data set at the nth transmission node. The ith data set includes the ith identifier and the original data set. It processes the transmitted data based on a comprehensive function and outputs the nth node summary data. It verifies whether the nth node summary data is consistent with the original summary data. If not, it issues a security protection warning. If consistent, it generates the mth identifier based on the comprehensive function and the ith identifier, associates the mth identifier with the original data set to form the mth data set, and sends the mth data set to the recipient.

[0075] The receiving module is used to receive the mth data set at the recipient, process the transmitted data based on a comprehensive function and output the end summary data. It verifies whether the end summary data is consistent with the original summary data. If not, it issues a security protection warning. If consistent, it inversely obtains the actual transmission path based on the comprehensive function and the mth identifier, compares the actual transmission path with the preset transmission path. If not consistent, it checks the comparison information and issues a security protection warning.

[0076] Regarding the information security protection system based on big data in the above embodiments, the specific manner of performing operations has been described in detail in the embodiments of the information security protection method based on big data, and will not be elaborated here.

[0077] Figure 4 is a block diagram of an electronic device for an information security protection method based on big data shown according to an exemplary embodiment. As Figure 4 shown, the electronic device 700 may include: a processor 701, a memory 702. The electronic device 700 may also include one or more of a multimedia component 703, an input / output (I / O) interface 704, and a communication component 705.

[0078] Among them, the processor 701 is used to control the overall operation of the electronic device 700 to complete all or part of the steps in the above-mentioned information security protection method based on big data. The memory 702 is used to store various types of data to support the operation of the electronic device 700. These data may include, for example, instructions for any application or method operating on the electronic device 700, as well as application-related data, such as contact data, received and sent messages, pictures, audio, video, and so on. The memory 702 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The multimedia component 703 may include a screen and an audio component. The screen can be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signal can be further stored in the memory 702 or sent through the communication component 705. The audio component also includes at least one speaker for outputting audio signals. The I / O interface 704 provides an interface between the processor 701 and other interface modules, and the above-mentioned other interface modules can be a keyboard, a mouse, buttons, etc. These buttons can be virtual buttons or physical buttons. The communication component 705 is used for wired or wireless communication between the electronic device 700 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, NB-IOT, eMTC or other 5G, etc., or a combination of one or more of them, is not limited here. Therefore, the corresponding communication component 705 may include: a Wi-Fi module, a Bluetooth module, an NFC module, and so on.

[0079] In an exemplary embodiment, the electronic device 700 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components, and is used to execute the above-mentioned information security protection method based on big data.

[0080] In another exemplary embodiment, a computer-readable storage medium including program instructions is further provided. When the program instructions are executed by a processor, the steps of the above-mentioned information security protection method based on big data are implemented. For example, the computer-readable storage medium may be the above-mentioned memory 702 including program instructions, and the above-mentioned program instructions may be executed by the processor 701 of the electronic device 700 to complete the above-mentioned information security protection method based on big data.

[0081] In another exemplary embodiment, a computer program product is further provided. The computer program product includes a computer program that can be executed by a programmable device, and the computer program has a code portion for executing the above-mentioned information security protection method based on big data when executed by the programmable device.

[0082] The preferred embodiments of the present disclosure have been described in detail above in conjunction with the accompanying drawings. However, the present disclosure is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all fall within the protection scope of the present disclosure.

[0083] In addition, it should be noted that, in the above specific embodiments, the various specific technical features described can be combined in any suitable manner without conflict. To avoid unnecessary repetition, the present disclosure does not separately describe various possible combination methods.

[0084] In addition, any combination can be made between various different embodiments of the present disclosure, as long as it does not violate the idea of the present disclosure, and it should also be regarded as the content disclosed by the present disclosure.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the description of the present invention.

Claims

1. An information security protection method based on big data, characterized in that: include: Acquire transmission data and a preset transmission path from a sender to a receiver, wherein the preset transmission path includes a first transmission node, a second transmission node, ..., an nth transmission node that the transmission data needs to pass through in sequence; At the sender, a comprehensive function is matched according to the transmission data, the transmission data is processed based on the comprehensive function and original summary data is output, the comprehensive function and the original summary data are associated with the transmission data to generate an original data set, and the original data set is sent to the first transmission node; Receiving the original data set at the first transmission node, processing the transmission data based on the comprehensive function and outputting the first node summary data, verifying whether the first node summary data is consistent with the original summary data, if not, issuing a security protection warning, if consistent, generating a first identifier based on the comprehensive function, associating the first identifier with the original data set to form a first data set, and sending the first data set to the second transmission node; Receive the first data set at the second transmission node, process the transmission data based on the comprehensive function and output the second node summary data, verify whether the second node summary data is consistent with the original summary data, if not, issue a security protection warning, if consistent, generate a second identifier based on the comprehensive function and the first identifier, associate the second identifier with the original data set to form a second data set, and send the second data set to the next transmission node; Receive the i-th data set at the n-th transmission node, the i-th data set includes the i-th identifier and the original data set, process the transmission data based on the comprehensive function and output the n-th node summary data, verify whether the n-th node summary data is consistent with the original summary data, if not, issue a security protection warning, if consistent, generate the m-th identifier based on the comprehensive function and the i-th identifier, associate the m-th identifier with the original data set to form the m-th data set, and send the m-th data set to the receiver; Receive the mth data set at the receiving end, process the transmission data based on the comprehensive function and output the terminal summary data, verify whether the terminal summary data is consistent with the original summary data, if not, issue a security warning, if consistent, invert the actual transmission path based on the comprehensive function and the mth identifier, compare the actual transmission path with the preset transmission path, if not consistent, check the comparison information and issue a security warning; The comprehensive function includes a hash processing method and a counting function; wherein the hash processing is used to map the transmission data and output summary data; the counting function is used to obtain an identifier and generate a new identifier based on the identifier; Among them, the counting function includes: C(I, T)=[I+f(T)+ln(I+T+1)]mod M; wherein I is the original identifier, T is the time value used to represent the current time, the occurrence time and the preset time, f(T) is a transformation function based on the time value, ln(I+T+1) is a logarithmic function with the natural constant (e) as the base, mod M is a modulo operation, and M is a large prime number used for the modulo operation.

2. The information security protection method based on big data according to claim 1 is characterized in that: The transformation function includes: f(T)=extract(SHA-256(T)); wherein SHA-256(T) is a hash value obtained by hashing the time value using the SHA-256 hash algorithm, and extract(·) is a result extracted from the hash value.

3. The information security protection method based on big data according to claim 1 is characterized in that: The hash processing method comprises: Accepts a string S of preset length; Fill the string S and assign the filled data to the variable padded; Split the variable padded into multiple data blocks of specified size and store the data blocks in the array blocks; Hash the array blocks and get the hash value.

4. The information security protection method based on big data according to claim 3 is characterized in that: The hash calculation of the array blocks and obtaining the hash value comprises: Initialize hash state hash_state; Perform multiple rounds of cyclic hash calculations based on round constants, hash_state, and blocks to obtain and update the hash state; Get the hash value through the current hash state.

5. The information security protection method based on big data according to claim 1 is characterized in that: The matching of the comprehensive function according to the transmission data at the sender includes: obtaining the length of the transmission data at the sender, and matching the hash processing method according to the length.

6. An information security protection system based on big data, characterized in that: The system is used to implement the information security protection method based on big data as described in any one of claims 1 to 5, and the system includes: A path confirmation module is used to obtain the transmission data and a preset transmission path from the sender to the receiver, wherein the preset transmission path includes a first transmission node, a second transmission node, ..., an nth transmission node that the transmission data needs to pass through in sequence; A sending module, configured to match the comprehensive function according to the transmission data at the sending side, process the transmission data based on the comprehensive function and output original summary data, associate the comprehensive function and the original summary data with the transmission data to generate an original data set, and send the original data set to the first transmission node; The first node module is used to receive the original data set at the first transmission node, process the transmission data based on the comprehensive function and output the first node summary data, verify whether the first node summary data is consistent with the original summary data, if not, issue a security protection warning, if consistent, generate a first identifier based on the comprehensive function, associate the first identifier with the original data set to form a first data set, and send the first data set to the second transmission node; The second node module is used to receive the first data set at the second transmission node, process the transmission data based on the comprehensive function and output the second node summary data, verify whether the second node summary data is consistent with the original summary data, if not, issue a security protection warning, if consistent, generate a second identifier based on the comprehensive function and the first identifier, associate the second identifier with the original data set to form a second data set, and send the second data set to the next transmission node; The nth node module is used to receive the i-th data set at the n-th transmission node, the i-th data set includes the i-th identifier and the original data set, process the transmission data based on the comprehensive function and output the n-th node summary data, verify whether the n-th node summary data is consistent with the original summary data, if not, issue a security protection warning, if consistent, generate the m-th identifier based on the comprehensive function and the i-th identifier, associate the m-th identifier with the original data set to form the m-th data set, and send the m-th data set to the receiver; A receiving module, used for receiving the mth data set at the receiving end, processing the transmission data based on the comprehensive function and outputting the terminal summary data, verifying whether the terminal summary data is consistent with the original summary data, and issuing a safety protection warning if they are inconsistent; if they are consistent, inverting the actual transmission path based on the comprehensive function and the mth identifier, and comparing the actual transmission path with the preset transmission path; if they are inconsistent, checking the comparison information and issuing a safety protection warning; The comprehensive function includes a hash processing method and a counting function; wherein the hash processing is used to map the transmission data and output summary data; the counting function is used to obtain an identifier and generate a new identifier based on the identifier; Among them, the counting function includes: C(I, T)=[I+f(T)+ln(I+T+1)]mod M; wherein I is the original identifier, T is the time value used to represent the current time, the occurrence time and the preset time, f(T) is a transformation function based on the time value, ln(I+T+1) is a logarithmic function with the natural constant (e) as the base, mod M is a modulo operation, and M is a large prime number used for the modulo operation.

7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, it implements the information security protection method based on big data as described in any one of claims 1 to 5.

8. An electronic device, characterized in that: include: a memory having a computer program stored thereon; A processor, used to execute the computer program in the memory to implement the information security protection method based on big data as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Message path tracing method and device based on equipment identifier calculation

    CN112995040A

  • Path verification method, device and system

    CN115996186A