A data privacy security encryption method and system for communication operators
The method optimizes data encryption by predicting decryption times and splitting data into blocks for real-time, secure communication service provider data transfers, addressing encryption complexity and speed imbalances.
Patent Information
- Application Number
- CN202411084135.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-08
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-08-08
AI Technical Summary
In the prior art, the data privacy security encryption method of communication operators has problems with encryption complexity and long decryption time, which leads to the inability to meet the requirements during real-time communication or big data transmission, making it difficult to ensure data security.
By obtaining the data to be encrypted in real time, identifying the transmission scenario and data classification, predicting acceptable decryption time, selecting appropriate encryption algorithms, and determining the segmentation granularity based on the data size and the limiting standards of the encryption algorithm, dividing the data into multiple data blocks, and using the encryption algorithm to encrypt and transmit each data block.
Ensure that the encryption process is completed within an acceptable decryption time, maintain real-time and security of data transmission, reduce the risk of data leakage, and meet the needs of real-time communication or big data transmission.
Smart Images

Figure CN119052783B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of communication data processing, and particularly to a method and system for encrypting the data privacy and security of communication operators. Background Art
[0002] Data privacy and security encryption for communication operators is a technical means to ensure that data is not accessed without authorization during transmission and storage. It involves encrypting data so that only those who possess the correct key can decrypt and access the data. This encryption technology is crucial for protecting the user data of communication operators, as communication operators usually process a large amount of sensitive information, such as personal identity information, financial records, location data, etc.
[0003] In the existing technology of communication operators in terms of data privacy and security encryption, the complexity of encryption is relative to the difficulty of decryption. This means that the more complex the encryption, the more difficult the decryption, and vice versa. For example: Using traditional data encryption technologies, such as DES or 3DES, to encrypt the entire data set, the encryption process is relatively simple, only requiring one key, and the decryption process is also relatively simple, using the same key for decryption; when encrypting a large amount of data, the decryption time will be very long because the entire data set needs to be processed, and the long decryption time is likely to lead to failure to meet the requirements during real-time communication or large data transmission, and it is difficult to ensure the security of the data.
[0004] Therefore, there are deficiencies in the existing technology and improvements are needed. Summary of the Invention
[0005] In order to solve one or several problems in the existing technology, the main object of this application is to provide a method and system for encrypting the data privacy and security of communication operators.
[0006] To achieve the above-mentioned invention object, this application proposes a method for encrypting the data privacy and security of communication operators, and the method includes:
[0007] Obtain the data to be encrypted in real time, and identify the transmission scenario and data classification of the data to be encrypted;
[0008] According to the classification result and transmission scenario, predict the acceptable decryption time of the data to be encrypted after encryption;
[0009] According to the data classification and transmission scenario, obtain the encryption algorithm of the data to be encrypted, and determine whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time;
[0010] When the decryption time of the entire data after being encrypted by the encryption algorithm exceeds the acceptable decryption time range, obtain the limitation criteria of the encryption algorithm, and determine the segmentation granularity of the data according to the limitation criteria of the encryption algorithm and the data size;
[0011] Segment the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption;
[0012] Based on the segmentation result, encrypt and transmit each data block through the encryption algorithm.
[0013] The embodiment of the present application also provides a data privacy and security encryption system for a communication operator, including:
[0014] A first acquisition module, configured to acquire the data to be encrypted in real time, and identify the transmission scenario and data classification of the data to be encrypted;
[0015] A prediction module, configured to predict the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario;
[0016] A judgment module, configured to obtain the encryption algorithm of the data to be encrypted according to the data classification and the transmission scenario, and judge whether the decryption time of the encryption algorithm after encrypting the entire data is within the acceptable decryption time;
[0017] A second acquisition module, configured to, when the decryption time of the encryption algorithm after encrypting the entire data exceeds the acceptable decryption time range, obtain the limitation criteria of the encryption algorithm, and determine the segmentation granularity of the data according to the limitation criteria of the encryption algorithm and the data size;
[0018] A segmentation module, configured to segment the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption;
[0019] An encryption module, configured to encrypt and transmit each data block through the encryption algorithm based on the segmentation result.
[0020] The present application also provides a computer device, including a memory and a processor, where the memory stores a computer program, and the processor implements the steps of the method described in any one of the above when executing the computer program.
[0021] The present application also provides a computer-readable storage medium, on which a computer program is stored, and the computer program implements the steps of the method described in any one of the above when executed by a processor.
[0022] The data privacy security encryption method and system for communication operators in the embodiments of the present application predict the acceptable decryption time, ensure that the encryption process will not lead to an overly long decryption time, and maintain the real-time nature of data transmission. Judging whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time can avoid using an encryption algorithm that causes an overly long decryption time and improve the real-time nature of data transmission. Determining the segmentation granularity of the data can shorten the decryption time and improve the real-time nature of data transmission. Segmenting the entire data can reduce the encryption complexity of each data block, shorten the decryption time, and improve the real-time nature of data transmission. Encrypted transmission ensures the security of data during transmission while maintaining the efficiency and real-time nature of data transmission. Encrypting and transmitting data in real time reduces the risk of data leakage. Selecting an appropriate encryption algorithm according to the data characteristics and transmission requirements improves the encryption efficiency. Ensuring that the encryption process will not lead to an overly long decryption time meets the requirements of real-time communication or large data transmission. Reducing the encryption complexity of each data block through data segmentation improves the real-time nature of data transmission. Based on the segmentation result, each data block is encrypted and transmitted to ensure the security of data during transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a schematic flowchart of the data privacy security encryption method for communication operators in an embodiment of the present application;
[0024] Figure 2 is a schematic flowchart of the data privacy security encryption method for communication operators in an embodiment of the present application;
[0025] Figure 3 is a schematic block diagram of the structure of the data privacy security encryption system for communication operators in an embodiment of the present application;
[0026] Figure 4 is a schematic block diagram of the structure of a computer device in an embodiment of the present application.
[0027] The implementation, functional features, and advantages of the purpose of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] In order to make the purpose, technical solution, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0029] Referring to Figure 1 , an embodiment of the present application provides a data privacy security encryption method for communication operators. The method includes:
[0030] S1. Obtain the data to be encrypted in real time, and identify the transmission scenario and data classification of the data to be encrypted;
[0031] S2. Predict the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario;
[0032] S3. Obtain the encryption algorithm for the data to be encrypted according to the data classification and the transmission scenario, and determine whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time;
[0033] S4. When the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time range, obtain the limitation standard of the encryption algorithm, and determine the segmentation granularity of the data according to the limitation standard of the encryption algorithm and the data size;
[0034] S5. Segment the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption;
[0035] S6. Based on the segmentation result, encrypt and transmit each data block through the encryption algorithm.
[0036] As described in the above steps S1 - S2, by obtaining the data to be encrypted in real time, it can ensure that the data is encrypted immediately before transmission, reducing the time when the data is exposed in the unencrypted state. Improve data security and reduce the risk of data leakage. Classifying according to the data transmission method (such as real - time transmission or non - real - time transmission) and data type (such as voice data, SMS data, etc.) helps to select an appropriate encryption strategy. Optimize the selection of the encryption algorithm to ensure that the encryption strategy matches the data characteristics and transmission requirements, and improve the encryption efficiency.
[0037] As described in the above steps S3 - S4, by analyzing the transmission scenario and data classification, predict the decryption time after encryption to ensure the encryption efficiency. Ensure that the encryption process does not result in an overly long decryption time, thereby maintaining the real - time nature of data transmission. Select a suitable encryption algorithm according to the data classification and transmission scenario. Improve data security while maintaining the encryption efficiency. By evaluating the encryption and decryption time of the entire data by the encryption algorithm, ensure the encryption efficiency. Avoid using encryption algorithms that cause an overly long decryption time and improve the real - time nature of data transmission. When the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time, reduce the encryption complexity of each data block by segmenting the data. Shorten the decryption time and improve the real - time nature of data transmission.
[0038] As described in the above steps S5 - S6, the data is split into multiple data blocks, and each data block is encrypted and transmitted using an encryption algorithm. This reduces the encryption complexity of each data block, shortens the decryption time, and improves the real - time performance of data transmission. Based on the splitting result, each data block is encrypted and transmitted to ensure the security of the data during transmission while maintaining the efficiency and real - time performance of data transmission.
[0039] Specifically, predict the acceptable decryption time to ensure that the encryption process does not result in an overly long decryption time and maintain the real - time performance of data transmission. Judge whether the decryption time after encrypting the entire data with the encryption algorithm is within the acceptable decryption time, which can avoid using encryption algorithms that cause overly long decryption times and improve the real - time performance of data transmission. Determine the splitting granularity of the data, which can shorten the decryption time and improve the real - time performance of data transmission. Splitting the entire data can reduce the encryption complexity of each data block, shorten the decryption time, and improve the real - time performance of data transmission. Encrypted transmission ensures the security of the data during transmission while maintaining the efficiency and real - time performance of data transmission. Encrypt and transmit data in real - time to reduce the risk of data leakage. Select a suitable encryption algorithm according to the data characteristics and transmission requirements to improve the encryption efficiency. Ensure that the encryption process does not result in an overly long decryption time to meet the requirements of real - time communication or large - data transmission. Reduce the encryption complexity of each data block through data splitting and improve the real - time performance of data transmission. Based on the splitting result, encrypt and transmit each data block to ensure the security of the data during transmission.
[0040] In a feasible embodiment, assume real - time voice data encryption and transmission.
[0041] Parameter settings:
[0042] Data type: Voice data
[0043] Transmission method: Real - time transmission
[0044] Encryption algorithm: AES - 256
[0045] Splitting granularity: 1000 bytes
[0046] Decryption time threshold: 500 milliseconds
[0047] It is possible to prepare for encryption by capturing voice data in real time. Determine that the data is voice data for real-time transmission and requires high-security encryption. Predict the acceptable decryption time: According to the characteristics of real-time transmission, it is predicted that the decryption time after encryption should be within 500 milliseconds. Obtain an encryption algorithm. AES-256 can be selected as the encryption algorithm because it provides high security and has a relatively fast encryption and decryption speed in the current hardware environment. Determine whether the decryption time after encrypting the entire data with the encryption algorithm is within the acceptable decryption time: Since the voice data volume is large, it is predicted that the decryption time after encryption may exceed 500 milliseconds. Therefore, data segmentation is required. According to the limitation standard of the AES-256 algorithm (supporting a maximum block length of 1024 bytes) and the size of the voice data, determine the segmentation granularity to be 1000 bytes. Segment the voice data into multiple data blocks of 1000 bytes each, and assign a unique identifier to each data block. Use the AES-256 algorithm to encrypt each data block and transmit the encrypted data blocks in real time. From the above analysis, the data privacy security encryption method of the communication operator optimizes the encryption efficiency and decryption speed while ensuring the security of voice data, ensuring that the decryption time of the encrypted real-time transmission voice data is within an acceptable range.
[0048] In another embodiment, when the decryption time after encrypting the entire data with the encryption algorithm does not exceed the acceptable decryption time range, the method includes: monitoring the performance of the encryption process in real time to ensure that the encryption algorithm completes decryption within the acceptable decryption time, promptly discovering and solving problems in the encryption process, and ensuring the efficiency of the encryption process. The communication operator can ensure that when the encryption algorithm can meet the preset decryption time threshold, the efficiency and security of the encryption process can still be maintained. These steps help improve the real-time performance of data transmission while ensuring data security.
[0049] Refer to Figure 2 , in one embodiment, for obtaining the limitation standard of the encryption algorithm and determining the segmentation granularity of the data according to the limitation standard of the encryption algorithm and the data size, the method includes:
[0050] S41. Set benchmark test data according to the data to be encrypted, and use the benchmark test data to test the average speed and data volume limit value of the encryption algorithm during processing;
[0051] S42. Calculate the segmentation quantity of the data and the size of each segmented data block according to the average speed of the encryption algorithm during decryption, the data volume limit value, and the data size of the data to be encrypted, and obtain the segmentation granularity of the data;
[0052] S43. Based on the segmentation granularity of the data, conduct a simulation test on the decryption time of each data block to verify whether the segmentation granularity is within the acceptable decryption time;
[0053] S44. When the segmentation granularity is within the acceptable decryption time range, output the segmentation granularity.
[0054] As described in the above steps, by using benchmark test data to test the average speed and data volume limit value of the encryption algorithm during processing, the efficiency of the encryption algorithm in actual applications can be evaluated. Ensure that the selected encryption algorithm can meet the efficiency requirements of data encryption and reduce the time consumption during the encryption and decryption processes. By calculating the number of data segments and the size of each segmented data block, the segmentation granularity of the data can be obtained, which can reduce the encryption complexity of each data block and thus shorten the decryption time. Optimize the data segmentation strategy to improve the real-time performance of data transmission and ensure that the decryption time of the encrypted data is within the acceptable range. By setting benchmark test data, the performance of the encryption algorithm when processing different data volumes can be evaluated, so as to select a suitable encryption algorithm. Ensure that the selected encryption algorithm can meet the performance requirements of data encryption and improve the real-time performance of data transmission. By calculating the number of data segments and the size of each segmented data block, the segmentation granularity of the data can be obtained, which can reduce the encryption complexity of each data block and shorten the decryption time. Optimize the data segmentation strategy to improve the real-time performance of data transmission and ensure that the decryption time of the encrypted data is within the acceptable range. Through simulation tests, it can be verified whether the segmentation granularity is within the acceptable decryption time, so as to ensure that the selected encryption algorithm can meet the performance requirements of data encryption. Ensure that the selected encryption algorithm can meet the performance requirements of data encryption and improve the real-time performance of data transmission.
[0055] In one embodiment, predicting the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario, the method includes:
[0056] Construct a Bayesian network model for predicting the acceptable decryption time of the data to be encrypted after encryption;
[0057] Identify the type and transmission method of the data to be encrypted, where the type of the data to be encrypted includes voice data and short message data, and the transmission method includes real-time transmission and non-real-time transmission;
[0058] When the type of the data to be encrypted is voice data, identify the sensitivity coefficient of the voice data according to the semantics of the voice data;
[0059] When the sensitivity coefficient of the voice data belongs to a preset high-sensitivity interval, determine that the classification result is high-sensitivity voice data;
[0060] When the transmission method of the high-sensitivity voice data is real-time transmission, obtain the target delivery location and the sending location of the data transmission;
[0061] Determine the transmission path according to the target delivery location and the sending location;
[0062] Based on the transmission path and real-time transmission, determine the transmission scenario;
[0063] Set variable nodes for the Bayesian network model, set voice data, real-time transmission, and highly sensitive voice data as variable parameters respectively, and substitute the variable parameters into the variable nodes respectively;
[0064] According to the variable nodes, identify the dependency relationships of the variable nodes, and connect the variable nodes with direct dependency relationships;
[0065] Set an initial probability for each variable node, and calculate the posterior probability of the acceptable decryption time according to each variable node and the connection through the Bayesian network model, and output the result of the posterior probability;
[0066] When the posterior probability meets the conditions of the normal distribution, calculate the mean value of the posterior probability as the acceptable decryption time.
[0067] As described above, the Bayesian network is a probabilistic graphical model that can represent the dependencies between variables. By learning these dependencies, it is possible to predict the decryption time of the data to be encrypted after encryption. It provides a probability-based prediction method that can consider the impact of multiple factors on the decryption time, thereby more accurately predicting the acceptable decryption time. According to the data type (such as voice data, SMS data) and the transmission method (such as real-time transmission, non-real-time transmission), the encryption strategy and transmission requirements of the data can be determined. It provides a basis for selecting the appropriate encryption algorithm and transmission path to ensure the security and transmission efficiency of the data. By analyzing the semantic content of voice data, its sensitivity level can be judged, thus determining the encryption strength and transmission path. It improves the accuracy of the encryption strategy and ensures that sensitive data is properly protected. According to the preset high-sensitivity interval, the sensitivity level of voice data can be quickly judged, and corresponding encryption measures can be taken. It simplifies the identification process of sensitive data and improves the execution efficiency of the encryption strategy. Real-time transmission requires ensuring the security of data during transmission, so relevant information about the transmission path needs to be obtained. It provides a basis for the path selection of real-time transmission to ensure the security of data during transmission. According to the information of the transmission path, the data transmission path can be determined, and corresponding encryption measures can be taken. It ensures the security of data during transmission and improves the transmission efficiency. According to the transmission path and the requirements of real-time transmission, the transmission scenario can be determined, and corresponding encryption measures can be taken. It improves the accuracy of the transmission strategy and ensures the security of data during transmission. By setting voice data, real-time transmission, and highly sensitive voice data as variable parameters respectively, the relationships between these variables can be represented. It provides a basis for the construction of the Bayesian network model. By learning these relationships, it is possible to predict the decryption time of the data to be encrypted after encryption. By identifying the dependencies between variables, a Bayesian network model can be constructed to predict the decryption time of the data to be encrypted after encryption. Constructing a Bayesian network model that can accurately represent the relationships between variables provides a basis for predicting the decryption time. By setting the initial probability for each variable node, it can represent the probability that the node takes a certain value in the absence of other information. It provides a basis for the construction of the Bayesian network model. By learning these relationships, it is possible to predict the decryption time of the data to be encrypted after encryption. Through the Bayesian network model, the dependencies between variables can be learned to predict the decryption time of the data to be encrypted after encryption. It provides a probability-based prediction method that can consider the impact of multiple factors on the decryption time, thereby more accurately predicting the acceptable decryption time. The normal distribution is a common probability distribution that can be used to represent the probability distribution of random variables. By calculating the mean of the posterior probability, an estimated value of the acceptable decryption time can be obtained, providing a basis for formulating the encryption strategy.
[0068] In a feasible embodiment, a Bayesian network model is constructed to predict the acceptable decryption time of the data to be encrypted after encryption:
[0069] Variable nodes: voice data, real-time transmission, highly sensitive voice data, transmission path, transmission scenario, acceptable decryption time.
[0070] Dependency relationships: The type of voice data and the transmission method affect the selection of the encryption algorithm. The transmission method of highly sensitive voice data affects the transmission path. The transmission path and real-time transmission determine the transmission scenario. The transmission scenario and the encryption algorithm affect the acceptable decryption time.
[0071] Identify the type and transmission method of the data to be encrypted:
[0072] Voice data: Voice data transmitted in real time.
[0073] Transmission method: Real-time transmission.
[0074] When the type of the data to be encrypted is voice data, identify the sensitivity coefficient of the voice data according to the semantics of the voice data:
[0075] Voice data: Voice data transmitted in real time.
[0076] Sensitivity coefficient: Highly sensitive.
[0077] When the sensitivity coefficient of the voice data belongs to the preset high-sensitivity interval, determine that the result of the classification is highly sensitive voice data:
[0078] Sensitivity coefficient: Belongs to the high-sensitivity interval.
[0079] When the transmission method of the highly sensitive voice data is real-time transmission, obtain the target delivery location and the sending location of the data transmission:
[0080] Target delivery location: City A.
[0081] Sending location: City B.
[0082] Determine the transmission path according to the target delivery location and the sending location:
[0083] Transmission path: From City B to City A.
[0084] Based on the transmission path and real-time transmission, determine the transmission scenario:
[0085] Transmission scenario: Real-time transmission, from City B to City A.
[0086] Set variable nodes for the Bayesian network model: Voice data: Voice data transmitted in real time. Real-time transmission: Real-time transmission. Highly sensitive voice data: Belongs to the highly sensitive range. Transmission path: From City B to City A. Transmission scenario: Real-time transmission, from City B to City A. Acceptable decryption time: 500 milliseconds.
[0087] According to the variable nodes, identify the dependency relationships among the variable nodes, and connect the variable nodes with direct dependency relationships:
[0088] Voice data -> Real-time transmission -> Highly sensitive voice data -> Transmission path -> Transmission scenario -> Acceptable decryption time.
[0089] Set initial probabilities for each variable node: Voice data: Voice data transmitted in real time. Real-time transmission: Real-time transmission. Highly sensitive voice data: Belongs to the highly sensitive range. Transmission path: From City B to City A. Transmission scenario: Real-time transmission, from City B to City A. Acceptable decryption time: 500 milliseconds. Posterior probability: Conforms to the normal distribution. When the posterior probability conforms to the condition of the normal distribution, calculate the mean value of the posterior probability as the acceptable decryption time: Acceptable decryption time: 500 milliseconds. Achieve accurate prediction of the decryption time, thereby providing a basis for formulating encryption strategies and ensuring data security and transmission efficiency.
[0090] In one embodiment, after the step of splitting the entire data according to the splitting granularity, the method further includes:
[0091] Real-time monitor the network conditions during the splitting of the entire data;
[0092] Analyze whether the network conditions affect the splitting of the entire data according to the network conditions, where the influencing factors include data integrity and transmission speed;
[0093] When the network conditions will affect the splitting of the entire data, adjust the splitting strategy of the entire data according to the influencing factors.
[0094] As described above, real-time monitoring of network conditions can timely understand the changes in network conditions, provide real-time basis for adjusting data splitting strategies. Improve the flexibility and adaptability of data splitting strategies, ensure that data splitting strategies can adapt to the changing network environment. By analyzing the impact of network conditions on data splitting, it can be determined whether the network conditions require adjusting the data splitting strategy. Ensure that data splitting strategies can adapt to the fluctuations of network conditions and improve the adaptability of data splitting strategies. Adjust the data splitting strategy according to the influencing factors of network conditions, such as data integrity and transmission speed. Optimize the data splitting strategy, improve the real-time performance of data transmission, and ensure that the decryption time of the data after encryption is within the acceptable range.
[0095] In one embodiment, when the network conditions affect the segmentation of the entire data, the segmentation strategy of the entire data is adjusted according to the influencing factors. The method further includes:
[0096] When the network condition is that the security index is lower than a preset security threshold, resulting in the data security index of the influencing factor of data integrity being too low, increase the segmentation granularity in a preset manner, add redundant coding to each data block, and monitor in real time whether the segmented data blocks are intercepted during transmission;
[0097] When data interception occurs during the transmission of the data block, immediately stop the segmentation of the data block and stop transmitting the data;
[0098] When the network condition is that the security index is greater than a preset security threshold, resulting in the influencing factor of low transmission speed, increase the segmentation granularity in a preset manner.
[0099] As described above, when the network conditions change, it may affect the efficiency and security of data segmentation. By analyzing the influencing factors of the network conditions, the data segmentation strategy can be adjusted to adapt to these changes. Ensure that the data segmentation strategy can adapt to the changes in the network conditions, improve the efficiency and security of data segmentation. When the security index of the network conditions is lower than the preset security threshold, there may be a risk of data integrity. By increasing the segmentation granularity and redundant coding, the integrity of the data can be improved and the risk of data being intercepted can be reduced. Improve the security of data transmission, reduce the possibility of data being intercepted, and ensure the integrity of data during transmission. By increasing the segmentation granularity and redundant coding, the integrity of the data can be improved and the risk of data being intercepted can be reduced. Monitor the status of data blocks in real time during transmission, and data interception can be detected and processed in a timely manner. Improve the security of data transmission, reduce the possibility of data being intercepted, and ensure the integrity of data during transmission. When it is found that a data block is intercepted during transmission, immediately stop the segmentation and transmission of the data block, which can prevent further data leakage and loss. Prevent data leakage in a timely manner, protect data security, and avoid further interception and leakage of data. When the security index of the network conditions is higher than the preset security threshold but the transmission speed is too low, it may affect the real-time performance of data transmission. By increasing the segmentation granularity, the delay of data transmission can be reduced and the transmission speed can be increased. Improve the real-time performance of data transmission, reduce the delay of data transmission, and ensure the efficiency of data transmission.
[0100] It is worth noting that if a data block is intercepted during transmission, immediately stopping the transmission may result in the inability to complete decryption within an acceptable time. To ensure decryption is completed within an acceptable time, the communication operator needs to take additional remedial steps to protect the security and integrity of the data. The following are some possible remedial measures: If a data block is intercepted during transmission, the data block can be immediately retransmitted. Ensure that the data block can be transmitted to the destination completely. If a data block is intercepted during transmission, the data block can be immediately re-encrypted. Ensure the security of the data block during transmission. After the data block transmission is completed, immediately verify the integrity of the data block. Ensure that the data block has not been tampered with during transmission. After the data block transmission is completed, immediately decrypt the data block. Ensure that the data block can be decrypted in a timely manner, so as to complete decryption within an acceptable time.
[0101] In one embodiment, before the step of adjusting the segmentation strategy of the entire data according to the influencing factors, the method further includes:
[0102] Verify whether the decryption time after adjusting the segmentation strategy is within the acceptable decryption time range;
[0103] When the decryption time after adjusting the segmentation strategy is within the acceptable decryption time range, adjust the segmentation strategy based on the judgment result.
[0104] As described above, before adjusting the segmentation strategy, it is necessary to verify whether the adjusted strategy can meet the preset decryption time requirements. This helps to ensure that the adjustment of the segmentation strategy does not cause the decryption time to exceed the preset threshold. Avoid excessive decryption time caused by improper adjustment of the segmentation strategy, so as to ensure the real-time nature of data transmission. If the decryption time after adjusting the segmentation strategy is still within the acceptable range, the segmentation strategy can be continuously adjusted to further optimize the performance. This helps to find the optimal segmentation strategy and improve the efficiency and real-time nature of data transmission. By iteratively adjusting the segmentation strategy, find the optimal segmentation strategy, thereby improving the efficiency and real-time nature of data transmission.
[0105] In one embodiment, the encryption algorithms include symmetric encryption algorithms, asymmetric encryption algorithms, and hybrid encryption algorithms. Symmetric encryption algorithms use the same key for encryption and decryption, such as AES, DES, etc. Provide an efficient encryption and decryption process, suitable for encrypting a large amount of data. Asymmetric encryption algorithms use different keys for encryption and decryption, such as RSA, ECC, etc. Provide secure key exchange and digital signature functions, suitable for key exchange and digital signature. Hybrid encryption algorithms combine the advantages of symmetric encryption algorithms and asymmetric encryption algorithms, such as AES-GCM. Provide an efficient encryption and decryption process while ensuring the security of the data, suitable for encrypting a large amount of data and scenarios with high security requirements.
[0106] The data privacy security encryption method for a communication operator in this application predicts the acceptable decryption time to ensure that the encryption process will not result in an overly long decryption time and maintains the real-time nature of data transmission. Judging whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time can avoid using an encryption algorithm that causes an overly long decryption time and improve the real-time nature of data transmission. Determining the segmentation granularity of the data can shorten the decryption time and improve the real-time nature of data transmission. Segmenting the entire data can reduce the encryption complexity of each data block, shorten the decryption time, and improve the real-time nature of data transmission. Encrypted transmission ensures the security of data during transmission while maintaining the efficiency and real-time nature of data transmission. Encrypting and transmitting data in real time reduces the risk of data leakage. Selecting an appropriate encryption algorithm according to data characteristics and transmission requirements improves the encryption efficiency. Ensuring that the encryption process will not result in an overly long decryption time meets the requirements of real-time communication or large data transmission. Reducing the encryption complexity of each data block through data segmentation improves the real-time nature of data transmission. Based on the segmentation result, each data block is encrypted and transmitted to ensure the security of data during transmission.
[0107] Referring to Figure 3 , an embodiment of this application further provides a data privacy security encryption system for a communication operator, including:
[0108] The first acquisition module 1 is used to acquire the data to be encrypted in real time and identify the transmission scenario and data classification of the data to be encrypted;
[0109] The prediction module 2 is used to predict the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario;
[0110] The judgment module 3 is used to obtain the encryption algorithm of the data to be encrypted according to the data classification and the transmission scenario, and judge whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time;
[0111] The second acquisition module 4 is used to, when the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time range, obtain the limitation standard of the encryption algorithm, and determine the segmentation granularity of the data according to the limitation standard of the encryption algorithm and the data size;
[0112] The segmentation module 5 is used to segment the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption;
[0113] The encryption module 6 is used to, based on the segmentation result, encrypt and transmit each data block through an encryption algorithm.
[0114] As described above, it can be understood that each component of the data privacy and security encryption system of the communication operator proposed in the present application can implement the functions of any one of the data privacy and security encryption methods of the communication operator described above, and the specific structure will not be described in detail.
[0115] Referring to Figure 4 , an embodiment of the present application also provides a computer device, which may be a server, and its internal structure may be as Figure 4 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as monitoring data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data privacy and security encryption method for a communication operator.
[0116] The above-mentioned processor executes the above-mentioned data privacy and security encryption method for a communication operator, including: obtaining the data to be encrypted in real time, and identifying the transmission scenario and data classification of the data to be encrypted; predicting the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario; obtaining the encryption algorithm of the data to be encrypted according to the data classification and the transmission scenario, and judging whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time; when the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time range, obtaining the limitation standard of the encryption algorithm, and determining the segmentation granularity of the data according to the limitation standard of the encryption algorithm and the data size; segmenting the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption; based on the segmentation result, encrypting and transmitting each data block through the encryption algorithm.
[0117] The above data privacy and security encryption method for communication operators predicts the acceptable decryption time to ensure that the encryption process will not result in an overly long decryption time and maintain the real-time nature of data transmission. Judging whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time can avoid using encryption algorithms that cause overly long decryption times and improve the real-time nature of data transmission. Determining the segmentation granularity of the data can shorten the decryption time and improve the real-time nature of data transmission. Segmenting the entire data can reduce the encryption complexity of each data block, shorten the decryption time, and improve the real-time nature of data transmission. Encrypted transmission ensures the security of data during transmission while maintaining the efficiency and real-time nature of data transmission. Encrypting and transmitting data in real time reduces the risk of data leakage. Selecting an appropriate encryption algorithm according to data characteristics and transmission requirements improves the encryption efficiency. Ensuring that the encryption process will not result in an overly long decryption time meets the requirements of real-time communication or large data transmission. Reducing the encryption complexity of each data block through data segmentation improves the real-time nature of data transmission. Based on the segmentation result, each data block is encrypted and transmitted to ensure the security of data during transmission.
[0118] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a data privacy and security encryption method for communication operators, including the steps of: obtaining the data to be encrypted in real time and identifying the transmission scenario and data classification of the data to be encrypted; predicting the acceptable decryption time of the data to be encrypted after encryption according to the classification result and transmission scenario; obtaining the encryption algorithm of the data to be encrypted according to the data classification and transmission scenario, and judging whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time; when the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time range, obtaining the limitation criteria of the encryption algorithm, and determining the segmentation granularity of the data according to the limitation criteria of the encryption algorithm and the data size; segmenting the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the recombination order of each data block during decryption; based on the segmentation result, encrypting and transmitting each data block through the encryption algorithm.
[0119] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in the present application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0120] It should be noted that in this document, the term "including", "comprising", or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, device, article, or method including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such a process, device, article, or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, device, article, or method including that element.
[0121] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.
Claims
1. A data privacy and security encryption method for a communication operator, characterized in that, The method includes: Obtaining the data to be encrypted in real time, and identifying the transmission scenario and data classification of the data to be encrypted; Predicting the acceptable decryption time of the data to be encrypted after encryption according to the classification result and transmission scenario; Obtaining the encryption algorithm of the data to be encrypted according to the data classification and transmission scenario, and determining whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time; When the decryption time after encrypting the entire data by the encryption algorithm exceeds the acceptable decryption time range, obtain the limitation criteria of the encryption algorithm, and determine the segmentation granularity of the data according to the limitation criteria of the encryption algorithm and the data size; Segment the entire data according to the segmentation granularity to obtain a plurality of data blocks and the identifier of each data block, where the identifier is used for the reorganization order of each data block during decryption; Based on the segmentation result, encrypt and transmit each data block through the encryption algorithm; If a data block is intercepted during transmission, in order to ensure decryption within an acceptable time, the communication operator takes additional remedial steps to protect the security and integrity of the data, including: if a data block is intercepted during transmission, immediately re-transmit the data block so that the data block can be completely transmitted to the destination; if a data block is intercepted during transmission, immediately re-encrypt the data block; after the data block transmission is completed, immediately verify the integrity of the data block to ensure that the data block is not tampered with during transmission; after the data block transmission is completed, immediately decrypt the data block so that the data block can be decrypted in time, thus completing decryption within an acceptable time.
2. The data privacy and security encryption method for a communication operator according to claim 1, wherein, The method for obtaining the limitation criteria of the encryption algorithm and determining the segmentation granularity of the data according to the limitation criteria of the encryption algorithm includes: Setting benchmark test data according to the data to be encrypted, and using the benchmark test data to test the average speed and data volume limit value of the encryption algorithm during processing; Calculating the segmentation number of the data and the size of each segmented data block according to the average speed, data volume limit value of the encryption algorithm during decryption processing and the data size of the data to be encrypted, to obtain the segmentation granularity of the data; Based on the segmentation granularity of the data, perform a simulation test on the decryption time of each data block to verify whether the segmentation granularity is within the acceptable decryption time; When the segmentation granularity is within the acceptable decryption time range, output the segmentation granularity.
3. The data privacy security encryption method for a communication operator according to claim 1, characterized in that, The method for predicting the acceptable decryption time of the data to be encrypted after encryption according to the classification result and transmission scenario includes: Constructing a Bayesian network model for predicting the acceptable decryption time of the data to be encrypted after encryption; Identifying the type and transmission mode of the data to be encrypted, where the type of the data to be encrypted includes voice data and short message data, and the transmission mode includes real-time transmission and non-real-time transmission; When the type of the data to be encrypted is voice data, identifying the sensitivity coefficient of the voice data according to the semantics of the voice data; When the sensitivity coefficient of the voice data belongs to a preset high-sensitivity interval, it is determined that the classification result is high-sensitivity voice data; When the transmission mode of the high-sensitivity voice data is real-time transmission, obtain the target delivery location and the sending location of the data transmission; Determine the transmission path according to the target delivery location and the sending location; Based on the transmission path and real-time transmission, determine the transmission scenario; Set variable nodes for the Bayesian network model, set voice data, real-time transmission, and high-sensitivity voice data as variable parameters respectively, and substitute the variable parameters into the variable nodes respectively; According to the variable nodes, identify the dependency relationships of the variable nodes, and connect the variable nodes with direct dependency relationships; Set an initial probability for each variable node, and calculate the posterior probability of the acceptable decryption time through the Bayesian network model according to each variable node and the connection, and output the result of the posterior probability; When the posterior probability meets the conditions of the normal distribution, calculate the mean value of the posterior probability as the acceptable decryption time.
4. The data privacy and security encryption method for a communication operator according to claim 1, wherein After the step of splitting the entire data according to the splitting granularity, the method further includes: Real-time monitor the network conditions during the splitting of the entire data; Analyze whether the network conditions affect the splitting of the entire data, where the influencing factors include data integrity and transmission speed; When the network conditions will affect the splitting of the entire data, adjust the splitting strategy of the entire data according to the influencing factors.
5. The data privacy security encryption method of a communication operator according to claim 4, characterized in that, When the network conditions will affect the splitting of the entire data, and then adjust the splitting strategy of the entire data according to the influencing factors, the method further includes: When the network condition is that the security index is lower than the preset security threshold, resulting in too low a data security index for the influencing factor of data integrity, increase the splitting granularity in a preset manner, add redundant coding to each data block, and real-time monitor whether the transmitted data blocks are intercepted during transmission; When data interception occurs during the transmission of the data block, immediately stop the splitting of the data block and stop transmitting the data; When the network condition is that the security index is greater than the preset security threshold, resulting in too low a transmission speed for the influencing factor, increase the splitting granularity in a preset manner.
6. The data privacy and security encryption method for a communication operator according to claim 4, characterized in that Before the step of adjusting the splitting strategy of the entire data according to the influencing factors, the method further includes: Verify whether the decryption time after adjusting the splitting strategy is within the acceptable decryption time range; When the decryption time after adjusting the splitting strategy is within the acceptable decryption time range, adjust the splitting strategy based on the judgment result.
7. The data privacy and security encryption method for a communication operator according to claim 1, characterized in that The encryption algorithm includes symmetric encryption algorithm, asymmetric encryption algorithm, and hybrid encryption algorithm.
8. A data privacy and security encryption system for a communication operator, used for the method described in any one of claims 1-7, characterized in that, It includes: The first acquisition module is used to acquire the data to be encrypted in real time, and identify the transmission scenario and data classification of the data to be encrypted; The prediction module is used to predict the acceptable decryption time of the data to be encrypted after encryption according to the classification result and the transmission scenario; The judgment module is used to obtain the encryption algorithm of the data to be encrypted according to the data classification and the transmission scenario, and judge whether the decryption time after encrypting the entire data by the encryption algorithm is within the acceptable decryption time; A second acquisition module, configured to obtain a limitation criterion of an encryption algorithm when the decryption time after the entire data is encrypted by the encryption algorithm exceeds an acceptable decryption time range, and determine a segmentation granularity of the data according to the limitation criterion of the encryption algorithm and the data size; A segmentation module, configured to segment the entire data according to the segmentation granularity, to obtain a plurality of data blocks and an identifier for each data block, where the identifier is used for the recombination order of each data block during decryption; An encryption module, configured to perform encrypted transmission on each data block based on the segmentation result by using the encryption algorithm.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Remote fault monitoring system for electric valve
US11821542B1