An Internet-based data transmission encryption security protection system

By designing a system that includes data acquisition, encryption, identity verification, checking and security protection modules, the risks of data leakage and unauthorized access in Internet data transmission are solved, and efficient data transmission encryption and risk management are achieved.

CN119128947BActive Publication Date: 2025-06-17NINGBO LANYUAN HUMANOID ROBOT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411273203.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-12
Publication Date
2025-06-17
Estimated Expiration
2044-09-12

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect sensitive information during data transmission, especially in the Internet environment, where the risk of data leakage and unauthorized access is high.

Method used

A data transmission encryption security protection system based on the Internet is designed, including data acquisition module, data encryption module, identity verification module, data verification module and security protection module. The system ensures the security of data during transmission through technical means such as character matching text, geometric model encryption, digital signature and risk assessment.

Benefits of technology

By dynamically adjusting verification standards, identifying and evaluating risks, encrypting data transmission and verifying data integrity, the system can effectively reduce the risks of unauthorized access and data leakage, and improve the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119128947B_ABST
    Figure CN119128947B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data security protection, and particularly to an Internet data transmission encryption security protection system, which includes a data acquisition module, a server, a data encryption module, an identity authentication module, a data verification module, and a security protection module. By combining the permission level and access frequency, the system can dynamically adjust the verification criteria, thereby more accurately judging the risk of access requests and reducing the risk of unauthorized access. By analyzing the historical access behaviors of visiting users, combining factors such as the number of successful and failed verifications, access duration, and the number of risky accesses, the security value is dynamically calculated to evaluate the potential risk of user access. According to the security value, it is determined whether to allow the data to continue to be transmitted, and a warning is issued when the risk is relatively high, restricting access or notifying the administrator for further processing, achieving effective user behavior monitoring and risk management, and enhancing the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security protection, and particularly to an Internet data transmission encryption security protection system. Background Art

[0002] In industries such as finance, healthcare, and government, the data transmitted often involves highly sensitive information, such as personal identity information, financial data, health records, etc. Encryption is a key technology to ensure that this data is not stolen or leaked during transmission; with the deepening of the digital transformation of enterprises, more and more business activities and data need to be transmitted through the Internet, and encryption technology can ensure the security of data during transmission between different platforms; data leakage may lead to huge economic losses, including direct financial losses or customer loss due to trust crisis. Encryption of data transmission can significantly reduce these risks, thereby protecting the financial health of enterprises. Therefore, the security protection of data transmission encryption is very important;

[0003] The security protection of data transmission encryption is not only an effective means to protect data from being stolen and tampered with during transmission, but also a key technology to ensure the information security of enterprises and individuals, comply with regulatory requirements, protect reputation, and support modern digital businesses. It is an indispensable part of today's information security system. Summary of the Invention

[0004] To this end, the present invention provides an Internet data transmission encryption security protection system to overcome the problems mentioned in the above background art.

[0005] To achieve the above object, the present invention provides an Internet data transmission encryption security protection system, including: a data acquisition module, a server, a data encryption module, an identity authentication module, a data verification module, and a security protection module;

[0006] The data acquisition module is responsible for collecting user data and data information to be transmitted from the data source and sending them to the server for storage;

[0007] The data encryption module obtains the collected data from the database for conversion and encryption, and calculates the security value of user data transmission; the specific steps are as follows:

[0008] Set a character matching text, where the character matching text consists of characters and numerical values, and each character corresponds to a unique numerical value; when the transmitted data is text, match the transmitted data with all the set characters respectively to obtain the corresponding numerical values, and sort the numerical values according to their corresponding data timestamps to obtain a sequence of text numerical values to be converted; when the transmitted data is a video, divide the video into several frames for extraction, then generate separate image files, and then perform matching through an image conversion method to obtain a sequence of numerical values to be converted; when the transmitted data is a picture, divide the picture into several regions and convert the pixel block regions into byte streams, and merge the byte streams in the order from left to right and from top to bottom to obtain a sequence of picture numerical values to be converted;

[0009] Identify the positions of zeros in the sequence of text numerical values to be converted and the sequence of picture numerical values to be converted, randomly select a number from 1 to 9 as the conversion value, and replace the zeros in the sequence of text numerical values to be converted and the sequence of picture numerical values to be converted with the conversion value, thereby obtaining the sequence of text numerical values to be converted and the sequence of picture numerical values to be converted after zero removal; respectively count the number of bytes in the sequence of text numerical values to be converted and the sequence of picture numerical values to be converted, and evenly divide them into 5 groups according to the same number of bytes. If the number of numerical values cannot be divided by 5, randomly add a number from 1 to 9 at the end of the last byte of the sequence of text numerical values to be converted and the sequence of picture numerical values to be converted until the sequence of numerical values to be converted can be divided by 5, thereby obtaining the grouped sequence of text numerical values to be converted and the grouped sequence of picture numerical values to be converted; use the first three numerical value groups of the grouped sequence of text numerical values to be converted and the grouped sequence of picture numerical values to be converted as the length, width, and height to construct a cuboid, and connect the two diagonal points of the top surface of the obtained cuboid to obtain the midpoint of the top surface of the cuboid; take the midpoint of the top surface of the cuboid as the center, and use the fourth numerical value of the grouped sequence of text numerical values to be converted and the grouped sequence of picture numerical values to be converted as the radius to draw a circle, and use the fifth numerical value of the grouped sequence of text numerical values to be converted and the grouped sequence of picture numerical values to be converted as the height to draw a cone; thus, each grouped sequence of text numerical values to be converted and the grouped sequence of picture numerical values to be converted respectively correspond to a cuboid and a cone; respectively calculate the volumes of each cuboid and cone, add the volumes of the obtained cuboid and cone, and then match them in the character matching text according to the corresponding numerical values to obtain the encrypted ciphertext of the converted text and the encrypted ciphertext of the converted picture, and send them to the server for storage;

[0010] The identity authentication module is used to verify the user's identity, perform identity authentication according to the user's permission level and access frequency, and manage the user's operations;

[0011] The data verification module ensures the integrity and authenticity of the data during transmission through digital signatures, and confirms that the data comes from a trusted source;

[0012] The security protection module protects data security by identifying and evaluating risks in user data transmission.

[0013] As a preferred embodiment of the present invention, the user data in the data acquisition module includes the number of user accesses, the number of verifications, the access duration, and the access device; the data information to be transmitted includes the source of the transmitted data, the timestamp, and the transmission log.

[0014] As a preferred embodiment of the present invention, the steps for converting a picture into a sequence of numerical values of the picture to be converted are as follows:

[0015] When the transmitted data is a picture, the picture is divided into several pixel blocks, and the pixel blocks are opened using an image processing library and loaded as manipulable objects to obtain the pixel data of the area, including the height, width, and color channels of the image; pixel data is obtained from the pixel block area, the cropped pixel block area is converted into a pixel array, and the NumPy library is used to represent the pixels of the image in matrix form, where each pixel point is represented as an RGB value or an RGBA value, depending on the color mode of the image; the matrix of the pixel block area is expanded into a continuous byte stream, and each element in the byte stream represents the color value (red, green, blue) of a pixel, and the generated byte data is arranged in the order of the pixels; the byte stream obtained by converting the above pixel block area is merged in the order from left to right and from top to bottom to obtain the sequence of numerical values of the picture to be converted.

[0016] As a preferred embodiment of the present invention, identity verification is performed and user operations are managed according to the user's privilege level and access frequency. The specific steps are as follows:

[0017] When a user requests access, the privilege level of the visiting user is identified and the corresponding access privilege is granted. Each user has a different privilege value according to their privilege level; the set privilege value is denoted as Qi; where i = 1, 2, 3... I, I takes positive integer values, I represents the total number of users, and i represents the number of any one visiting user. The higher the privilege level, the larger the privilege value Qi and the wider the access range; the number of times a user accesses more than once on the same day is recorded and denoted as Ci; the numerical values of the privilege value Qi and the excess number value Ci are substituted into the formula to calculate the verification value Yi;

[0018] A verification threshold T is set. When the verification value Yi is greater than or equal to the set verification threshold T, it means that the user passes the identity verification and can access normally, and the verification log is sent to the server for storage; when the verification value Yi is less than the set verification threshold T, it means that there may be risks, the user's access request will be rejected, and the administrator will be notified for authorization or further verification, and the verification log is sent to the server for storage.

[0019] As a preferred embodiment of the present invention, data verification is performed through digital signature. The specific steps are as follows:

[0020] Before data transmission, a hash algorithm (SHA-256) is used to generate a hash value of fixed length for the data to be transmitted, which is denoted as the data digest; the sender uses its own private key to encrypt the generated data digest to obtain a digital signature. This digital signature is bound to the data digest and can only be decrypted with the sender's public key; the generated digital signature is attached to the data packet and sent; after receiving the data packet, the receiver separates the original data and the digital signature generated by the sender from the data packet. The extracted data packet may contain other metadata, such as timestamps, sender identifiers, etc., to assist in verification and subsequent processing; the receiver runs the same hash function (SHA-256) as the sender on the received original data again to calculate the local data digest; the receiver uses the sender's public key to decrypt the received digital signature to obtain the original data digest generated by the sender. If the decryption fails, it indicates that the digital signature is invalid; the receiver compares the decrypted data digest with the locally generated digest. When the data digest and the local digest are exactly the same, it means that the data has not been tampered with and the signature source is trustworthy, and the receiver continues to process the data; when the data digest and the local digest are inconsistent, it means that the data has been tampered with or damaged during transmission and the verification fails. The receiver will reject the data packet, initiate a retransmission request, and send an alarm to notify the administrator to conduct a security check; after the verification is completed, the detailed information of each data verification is recorded and sent to the server for storage.

[0021] As a preferred embodiment of the present invention, the steps for identifying and evaluating risks in user data transmission are as follows:

[0022] Obtain the historical access records of the visiting user, where the historical access records include the number of successful authentication times and the corresponding access durations, and the number of failed authentication times; count the total number of successful authentication times and the number of failed authentication times of the visiting user, and denote it as K1; count the number of failed authentication times and denote it as K2; set a safe access duration, obtain the historical access duration of each visit of the visiting user, and compare it with the safe access duration. When the access duration is greater than the standard access duration, the access record is marked as a risky access. When the access duration is less than or equal to the standard access duration, the access record is marked as a normal access; count the total number of risky access times and the total number of normal access times and denote it as Z1; count the number of risky access times and denote it as Z2; substitute the values of the total number of user verification times K1, the number of failed verification times K2, the total number of access times Z1, the number of risky access times Z2, and the verification value Yi into the formula Calculate the safety value Fi of the visiting user, where b1, b2, and b3 are set weight factors;

[0023] Set a security value threshold G. When the security value Fi is greater than the set verification threshold G, it indicates that there is no potential security risk for the user's current access, and the security data is sent to the server for storage; when the security value Fi is less than or equal to the set verification threshold G, it indicates that there is a potential security risk for the user's current access, and the user's access is restricted for data transmission or reception, and an access log is generated, a warning is issued and sent to the server for storage and the administrator respectively; after receiving the warning signal, the administrator rejects or further verifies and passes the data transmission request.

[0024] Advantages of the present invention:

[0025] 1. By combining the permission level and access frequency, the system can dynamically adjust the verification standard, thereby more accurately judging the risk of access requests and reducing the risk of unauthorized access; the monitoring of access exceeding the number of times combined with the verification threshold helps to timely detect and prevent potential abnormal activities, avoiding data leakage or attack behaviors; the mechanism that new devices need additional verification can effectively prevent the access of unfamiliar devices and protect the user's account security; the operation duration management mechanism prevents users who have been inactive for a long time from retaining active operations, reducing the risk of operation hijacking, and at the same time automatically extending the session when the user is active, improving the user experience while maintaining security.

[0026] 2. By analyzing the historical access behaviors of the visiting users, combining factors such as the number of successful and failed verifications, access duration, and the number of risky accesses, the security value is dynamically calculated, thereby evaluating the potential risk of the user's access. According to the security value, it is decided whether to allow continued data transmission, and a warning is issued when the risk is relatively high, restricting access or notifying the administrator for further processing, realizing effective user behavior monitoring and risk management, and enhancing the security of data transmission; the system can automatically record the security event logs of each access, and the administrator can conduct in-depth analysis based on these data to further optimize the security policy of the system; by identifying and restricting risky accesses, the system can effectively prevent the abuse behaviors of malicious users and protect the data security of legitimate users. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 is a schematic diagram of the connection of the system modules of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0028] In order to make the purpose and advantages of the present invention clearer, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0029] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principle of the present invention and do not limit the protection scope of the present invention.

[0030] It should be noted that in the description of the present invention, the terms indicating the direction or positional relationship such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the direction or positional relationship shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention.

[0031] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and defined, the terms "installed", "connected", "connected to" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0032] Please refer to Figure 1 As shown, the present invention is an Internet data transmission encryption security protection system, including: a data acquisition module, a server, a data encryption module, an identity authentication module, a data verification module, and a security protection module;

[0033] The data acquisition module is responsible for collecting user data and data information to be transmitted from the data source and sending them to the server for storage; the user data includes the number of user accesses, the number of verification times, the access duration, and the access device; the data information to be transmitted includes the source of the transmitted data, the timestamp, and the transmission log;

[0034] The data encryption module obtains the collected data from the database for conversion and encryption, and calculates the security value of the user data transmission; the specific steps are as follows:

[0035] Set a character matching text, where the character matching text consists of characters and numerical values, and each character corresponds to a unique numerical value; when the transmitted data is text, match the transmitted data with all the set characters respectively to obtain the corresponding numerical values, and sort the numerical values according to their corresponding data timestamps to obtain a sequence of text numerical values to be converted; when the transmitted data is a video, divide the video into several frames for extraction, then generate separate image files, and then perform matching through an image conversion method to obtain a sequence of numerical values to be converted; when the transmitted data is a picture, divide the picture into several regions (for example, each region is a 50*50 pixel block, and the size of different pixel blocks is flexibly selected according to the complexity of the picture), and use an image processing library to open the pixel block and load it as an operable object, and obtain the pixel data of the region, including the height, width and color channels of the image; obtain pixel data from the pixel block region, convert the cropped pixel block region into a pixel array, and use the NumPy library to represent the pixels of the image in matrix form, where each pixel point will be represented as an RGB value or an RGBA value, depending on the color mode of the image; it should be noted that in the RGB mode, each pixel is represented by 3 integer values, representing the red, green and blue channels respectively, and in the RGBA mode, each pixel is represented by 4 integer values, representing the red, green, blue and transparency channels respectively; expand the pixel block region matrix into a continuous byte stream, and each element in the byte stream represents the color value (red, green, blue) of a pixel, and arrange the generated byte data in the order of pixels. For example, the bytes of the RGB value of the first pixel will be stored in the first three positions of the byte stream in sequence, and the length of the byte data is: when a 10*10 pixel block region is extracted and the image is in the RGB mode, the length of the generated byte data is 50*50*3 = 7500 bytes, where 3 represents the 3 channels of RGB. If the image is in the RGBA mode, each pixel occupies 4 bytes, then the corresponding length of the generated byte data is 50*50*4 = 10000 bytes; merge the byte streams obtained by converting the above pixel block regions in the order from left to right and from top to bottom to obtain a sequence of picture numerical values to be converted;

[0036] Identify the positions of zeros in the numerical sequence of the text to be converted and the numerical sequence of the image to be converted. Randomly select a number from 1 to 9 as the conversion value, and replace the zeros in the numerical sequence of the text to be converted and the numerical sequence of the image to be converted with the conversion value, thus obtaining the numerical sequence of the text to be converted and the numerical sequence of the image to be converted after zero removal; respectively count the number of bytes in the numerical sequence of the text to be converted and the numerical sequence of the image to be converted, and evenly divide them into 5 groups according to the same number of bytes. If the number of values cannot be divided by 5, randomly add a number from 1 to 9 at the end of the last byte of the numerical sequence of the text to be converted and the numerical sequence of the image to be converted until the numerical sequence to be converted can be divided by 5, thus obtaining the numerical group of the text to be converted and the numerical group of the image to be converted after being divided into 5 groups; it should be noted that if the byte length is 7901 bytes and this length byte cannot be divided by 5, then keep adding numbers until 7905 bytes, with each group of bytes being 181; use the first three numerical groups of the numerical group of the text to be converted and the numerical group of the image to be converted to construct a cuboid for length, width, and height, and connect the two diagonal points of the top surface of the obtained cuboid to get the midpoint of the top surface of the cuboid; with the midpoint of the top surface of the cuboid as the center, use the fourth numerical value of the numerical group of the text to be converted and the numerical group of the image to be converted as the radius to draw a circle, and use the fifth numerical value of the numerical group of the text to be converted and the numerical group of the image to be converted as the height to draw a cone; thus, each numerical group of the text to be converted and the numerical group of the image to be converted corresponds to a cuboid and a cone respectively; calculate the volumes of each cuboid and cone respectively, add the volumes of the obtained cuboid and cone, and then match them in the character matching text according to the corresponding numerical values to obtain the encrypted ciphertext of the converted text and the encrypted ciphertext of the converted image, and send them to the server for storage;

[0037] The encryption method through character matching and numerical conversion increases the complexity and unpredictability of data transmission. Combining the encryption process of the geometric model makes the encrypted data difficult to be decoded or tampered with; different processing methods are adopted according to the data type (text, video, picture), and the most suitable encryption method is applied to different types of data, optimizing the data processing process; evenly dividing the data into 5 groups and performing encryption processing by drawing different superimposed geometric models can improve the security of the data and avoid security vulnerabilities that may be brought by a single encryption method;

[0038] The identity authentication module is used to verify the user's identity, perform identity authentication and manage user operations according to the user's permission level and access frequency; the specific steps are as follows:

[0039] When a user requests access, identify the permission level of the visiting user and grant the corresponding access permission. Each user has a different permission value according to their permission level; the set permission value is denoted as Qi; where i = 1, 2, 3... I, I takes positive integer values, I represents the total number of users, and i represents the number of any one visiting user. The higher the permission level, the larger the permission value Qi and the wider the access range; record the number of times each user accesses more than once a day and denote it as Ci. The number of times each user accesses more than once a day is used to measure the user's access frequency. An excessive number of accesses may indicate abnormal activities or high-risk operations; substitute the numerical values of the permission value Qi and the excessive number value Ci into the set formula Calculate the verification value Yi, where a1 and a2 are set weight factors; from the formula, it can be seen that the larger the permission value Qi, the higher the permission level and the higher the access security, and the larger the verification value Yi; the larger the excessive number value Ci, the more frequent the accesses and the possible risks, and the verification value Yi will decrease accordingly; set a verification threshold T. When the verification value Yi is greater than or equal to the set verification threshold T, it means that the user has passed the identity verification and can access normally, and send the verification log to the server for storage; when the verification value Yi is less than the set verification threshold T, it means that there may be risks, the user's access request will be rejected, and the administrator will be notified for authorization or further verification, and the verification log will be sent to the server for storage;

[0040] Identify whether the device used by the visiting user is a trusted device. For a device accessing for the first time, the user needs to pass an additional verification through SMS or email verification code to ensure that the user operates on a trusted device; if the device is a registered trusted device, the system will skip the additional device verification step and directly authorize the access; once the visiting user passes all verifications, the system will manage the user's operation duration according to their permission level and security policy; if the user does not perform any operations within a set period of time (such as 30 minutes), the system will automatically lock the operation and require re-verification; whenever the user has a valid operation, the system will extend the operation duration and refresh the operation lock timer to avoid unnecessary operation interruptions;

[0041] By combining the permission level and access frequency, the system can dynamically adjust the verification criteria, thereby more accurately judging the risks of access requests and reducing the risk of unauthorized access; the monitoring of excessive accesses combined with the verification threshold helps to detect and prevent potential abnormal activities in a timely manner, avoiding data leakage or attack behaviors; the mechanism that new devices require additional verification can effectively prevent access from unfamiliar devices and protect the user's account security; the operation duration management mechanism prevents users who have been inactive for a long time from retaining active operations, reducing the risk of operation hijacking, and at the same time automatically extending the session when the user is active, improving the user experience while maintaining security;

[0042] The data verification module ensures the integrity and authenticity of data during transmission through digital signatures, confirming that the data comes from a trusted source. The specific steps are as follows:

[0043] Before data transmission, a fixed-length hash value is generated for the data to be transmitted using a hash algorithm (SHA-256), and it is recorded as the data digest. The sender encrypts the generated data digest using its own private key to obtain the digital signature. This digital signature is bound to the data digest and can only be decrypted using the sender's public key. The generated digital signature is attached to the data packet and sent. After receiving the data packet, the receiver separates the original data and the digital signature generated by the sender from the data packet. The extracted data packet may contain other metadata, such as timestamps, sender identifiers, etc., to assist in verification and subsequent processing. The receiver runs the same hash function (SHA-256) as the sender on the received original data again to calculate the local data digest. The receiver decrypts the received digital signature using the sender's public key to obtain the original data digest generated by the sender. If the decryption fails, it indicates that the digital signature is invalid. The receiver compares the decrypted data digest with the locally generated digest. When the data digest and the local digest are exactly the same, it means that the data has not been tampered with and the signature source is trusted, and the receiver continues to process the data. When the data digest and the local digest are inconsistent, it means that the data has been tampered with or damaged during transmission, and the verification fails. The receiver will reject the data packet, initiate a retransmission request, and send an alert to notify the administrator for a security check. After the verification is completed, the detailed information of each data verification is recorded and sent to the server for storage. The detailed information of data verification includes verification results, timestamps, sender identities, abnormal situations during the digital signature verification process, etc.;

[0044] By binding the digital signature to the data digest, any tampering will change the data digest. By comparing the decrypted data digest with the locally generated digest, it can effectively detect whether the data has been tampered with during transmission, ensuring the integrity of the data. The digital signature ensures that the data cannot be modified during transmission. Even if there is a middle attacker during the transmission process, the data cannot be changed without being detected, significantly enhancing the security of data transmission. The detailed information of each data verification is recorded in the log and stored on the server, facilitating subsequent security audits and problem tracking by system administrators, providing a high-level security protection mechanism that can effectively protect the integrity, authenticity, and credibility of the data;

[0045] The security protection module protects data security by identifying and evaluating risks in user data transmission. The specific steps are as follows:

[0046] Obtain the historical access records of the visiting user, where the historical access records include the number of successful authentication times and the corresponding access durations, as well as the number of failed authentication times; count the total sum of the number of successful authentication times and the number of failed authentication times of the visiting user, and record it as K1; count the number of failed authentication times, and record it as K2; set a safe access duration, and the specific duration is set by professionals in this field; obtain the historical access duration of each visit of the visiting user, and compare it with the safe access duration. When the access duration is greater than the standard access duration, then record this access record as a risky access. When the access duration is less than or equal to the standard access duration, then record this access record as a normal access; count the total sum of the number of risky access times and the number of normal access times and record it as Z1, count the number of risky access times, and record it as Z2; substitute the values of the total number of user authentication times K1, the number of failed authentication times K2, the total number of access times Z1, the number of risky access times Z2, and the verification value Yi into the set formula

[0047] Calculate the safety value Fi of the visiting user, where b1, b2, and b3 are set weight factors; it can be seen from the formula that when the number of failed authentication times is smaller and the number of successful authentication times is larger, the safety value is larger; when the number of risky access times is smaller and the number of normal access times is larger, the safety value is larger; when the verification value is larger, the safety value is larger;

[0048] Set a safety value threshold G. When the safety value Fi is greater than the set verification threshold G, it means that there is no potential security risk for the user's current access, and send the security data to the server for storage; when the safety value Fi is less than or equal to the set verification threshold G, it means that there is a potential security risk for the user's current access, and restrict the user's access to perform data transmission or reception, and generate an access log, issue a warning and send it to the server for storage and the administrator respectively; after receiving the warning signal, the administrator rejects or further verifies and passes the data transmission request; establish a security incident response process to ensure that when a security threat is detected, it can be quickly and effectively responded to and disposed of;

[0049] By analyzing the historical access behaviors of the visiting user, combining factors such as the number of successful and failed authentications, access duration, and the number of risky access times, dynamically calculate the safety value, thereby evaluating the potential risks of the user's access. Decide whether to allow continued data transmission based on the safety value, and issue a warning when the risk is relatively large, restrict access or notify the administrator for further processing, realizing effective user behavior monitoring and risk management, and enhancing the security of data transmission; the system can automatically record the security event logs of each access, and the administrator can conduct in-depth analysis based on these data to further optimize the system's security strategy; by identifying and restricting risky access, the system can effectively prevent the abuse behavior of malicious users and protect the data security of legitimate users.

[0050] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0051] The above are only the preferred embodiments of the present invention and are not used to limit the present invention; for those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A security protection system based on Internet data transmission encryption, characterized in that: It includes a data encryption module and a security protection module; the characteristic is that the data encryption module obtains the collected data from the database, converts and encrypts it, and calculates the security value of user data transmission; the specific steps are as follows: The transmitted data is processed to obtain a text numerical sequence to be converted and a picture numerical sequence to be converted, the position of zero in the text numerical sequence to be converted and the picture numerical sequence to be converted is identified, a number is randomly selected from 1 to 9 as a conversion value, and the conversion value is used to replace the zero in the text numerical sequence to be converted and the picture numerical sequence to be converted, so as to obtain the text numerical sequence to be converted and the picture numerical sequence to be converted after de-zeroing; the number of bytes of the text numerical sequence to be converted and the picture numerical sequence to be converted are respectively counted, and they are evenly divided into 5 groups according to the same number of bytes. If the number of values ​​is not divisible by 5, a number from 1 to 9 is randomly added to the end of the last byte of the text numerical sequence to be converted and the picture numerical sequence to be converted until the text numerical sequence to be converted and the picture numerical sequence to be converted are divisible by 5, thereby obtaining 5 groups of text numerical sequences to be converted. and the value group of the picture to be converted; use the first three value groups of the text value group to be converted and the value group of the picture to be converted as the length, width and height to construct a cuboid, connect the two diagonal points of the top surface of the cuboid to obtain the midpoint of the top surface of the cuboid; use the midpoint of the top surface of the cuboid as the center, take the fourth value of the text value group to be converted and the value group of the picture to be converted as the radius to draw a circle, and use the fifth value of the text value group to be converted and the value group of the picture to be converted as the height to draw a cone; thus, each text value group to be converted and each picture value group to be converted corresponds to a cuboid and a cone respectively; calculate the volume of each cuboid and cone respectively, add the volumes of the obtained cuboid and cone, and then match the sum of the volumes of the obtained cuboid and cone in the character matching text according to the corresponding values ​​to obtain the converted text encrypted ciphertext and the converted picture encrypted ciphertext; The security protection module protects data security by identifying and evaluating risks in user data transmission.

2. According to claim 1, a security protection system for Internet data transmission encryption is characterized in that: It also includes a data collection module and a server. The data collection module is responsible for collecting user data and data information to be transmitted from the data source and sending them to the server for storage; user data includes user access times, verification times, access duration and access device; The information of the data to be transmitted includes the source, timestamp and transmission log of the transmitted data.

3. According to claim 1, a security protection system for Internet data transmission encryption is characterized in that: The steps to convert an image into a numerical sequence of images to be converted are: When the transmitted data is an image, the image is divided into several pixel blocks, and the image processing library is used to open the pixel blocks and load them as operable objects, and the pixel data of the pixel blocks is obtained, including the height, width, and color channels of the image; the pixel data is obtained from the pixel block area, and the cropped pixel block area is converted into a pixel array, and the NumPy library is used to represent the pixels of the image in a matrix form, where each pixel point is represented as an RGB value or an RGBA value, depending on the color mode of the image; Expand the pixel block area matrix into a continuous byte stream. Each element in the byte stream represents the color value of a pixel, including red, green and blue. Arrange the generated byte data in the order of pixels. Convert the above pixel block area to obtain the byte stream, and merge the byte streams in the order from left to right and from top to bottom to obtain the numerical sequence of the image to be converted.

4. The Internet data transmission encryption security protection system according to claim 1 is characterized in that: It also includes an identity authentication module, which is used to verify the identity of the user, authenticate the user according to the user's permission level and access frequency, and manage user operations; the specific steps are: When a user requests access, the permission level of the visiting user is identified and the corresponding access rights are granted. Each user has a different permission value according to his or her permission level. The number of times each user visits more than once on the same day is recorded. The permission value and the value of the excess number are normalized to obtain the verification value. Set a verification threshold. When the verification value is greater than or equal to the set verification threshold, it means that the user has passed the identity authentication and has normal access, and the verification log will be sent to the server storage; when the verification value is less than the set verification threshold, it means there is a risk, the user's access request will be rejected, and the administrator will be notified to authorize or further verify, and the verification log will be sent to the server storage.

5. The Internet data transmission encryption security protection system according to claim 1 is characterized in that: It also includes a data verification module, which uses digital signatures to ensure the integrity and authenticity of data during transmission. The specific process of data verification through digital signatures is as follows: Before data transmission, a hash value of a fixed length is generated for the data to be transmitted using a hash algorithm and recorded as a data summary; the sender uses its own private key to encrypt the generated data summary to obtain a digital signature, which is bound to the data summary and can only be decrypted using the sender's public key. The generated digital signature is then attached to the data packet and sent; after receiving the data packet, the receiver separates the original data and the digital signature generated by the sender from the data packet. The extracted data packet contains other metadata to help with verification and subsequent processing; the receiver runs the same hash function as the sender on the received original data again to calculate the local data summary; the receiver The recipient uses the sender's public key to decrypt the received digital signature and obtains the original data summary generated by the sender. If the decryption fails, it means that the digital signature is invalid. The recipient compares the decrypted data summary with the locally generated summary. When the data summary and the local summary are exactly the same, it means that the data has not been tampered with and the signature source is credible, and the recipient continues to process the data. When the data summary and the local summary are inconsistent, it means that the data has been tampered with or damaged during transmission and the verification fails. The recipient will reject the data packet, initiate a retransmission request, and issue an alarm to notify the administrator to perform a security check. After the verification is completed, the detailed information of each data verification is recorded and sent to the server for storage.

6. The Internet data transmission encryption security protection system according to claim 1 is characterized in that: Identify and assess risks in user data transmission. The specific steps are: Obtain the historical access records of visiting users, where the historical access records include the number of times identity authentication is passed, the corresponding access duration for each authentication pass, and the number of times identity authentication fails; count the total number of times identity authentication is passed and the number of times identity authentication fails for visiting users; count the number of times identity authentication fails; set a safe access duration; obtain the historical duration of each visit of the visiting user, and compare it with the safe access duration. When the access duration is longer than the standard access duration, the access record is recorded as a risky access; when the access duration is less than or equal to the standard access duration, the access record is recorded as a normal access; The number of risky visits is counted together with the sum of the number of normal visits to count the number of risky visits; The total number of verifications for visiting users, the number of verification failures, the total number of visits, the number of risky visits, and the verification value are normalized to obtain the security value of the visiting user; Set a security value threshold. When the security value is greater than the set verification threshold, it means that the user's access has no potential security risks, and the security data will be sent to the server storage. When the security value is less than or equal to the set verification threshold, it means that the user's access has potential security risks, and the user's access to data transmission or reception is restricted, and an access log is generated, an early warning is issued and sent to the server storage and administrator respectively. After receiving the early warning signal, the administrator will reject or further verify the data transmission request.

Citation Information

Patent Citations

  • Household Internet of Things terminal and operation method thereof

    CN117097572A

  • Network security defense method and system based on data analysis

    CN118101269A