A data security protection method and system

By solving the shortest vector problem on the grid and generating encryption parameters in combination with the parameter generator, the problem of data security protection methods in the prior art being easily cracked by quantum computing and lack of flexibility is solved, and data protection with security in both classical and quantum computing environments is realized to meet different application needs.

CN119203179BActive Publication Date: 2025-06-03SHENZHEN RONGQI DONGXIAN DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411240750.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-05
Publication Date
2025-06-03
Estimated Expiration
2044-09-05

AI Technical Summary

Technical Problem

Existing data security protection methods rely on difficult-to-solve mathematical problems, are easily cracked by quantum computing, and lack flexibility, making it difficult to adapt to different application scenarios.

Method used

By solving the shortest vector problem (SVP) on the grid, it is difficult in both classical and quantum computing environments. The parameter generator is used to automatically output dimensional parameters, modulus parameters and noise parameters, generate random matrix and secret key vector, calculate public key vectors, and use them to encrypt and decrypt data.

Benefits of technology

It realizes data protection that is secure in both classical and quantum computing environments, supports a variety of cryptographic applications, adapts to different application needs, and improves the security and storage efficiency of data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119203179B_ABST
    Figure CN119203179B_ABST
Patent Text Reader

Abstract

The present invention discloses a data security protection method and system, which relates to the technical field of data protection. The parameter generator automatically outputs dimension parameters, modulus parameters, and noise parameters, obtains a random matrix and a secret key vector according to the dimension parameters and modulus parameters, calculates a public key vector through the random matrix, the secret key vector, and the noise. After converting the data to be encrypted into a binary vector, the ciphertext is calculated by combining the public key vector and the binary vector, and the data in the storage medium is encrypted by the ciphertext. When the user needs to read the data, after receiving the ciphertext, decryption and data recovery are performed through the secret key vector. This protection system relies on solving the shortest vector problem on a lattice, which is quite difficult in both classical and quantum computing environments, and can support a variety of cryptographic applications. This flexibility enables the security protection method to adapt to different application requirements and ensure the secure storage of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data protection, and particularly relates to a data security protection method and system. Background Art

[0002] Data security protection involves ensuring the confidentiality, integrity, and availability of data during storage, transmission, and processing to prevent unauthorized access, leakage, tampering, or loss.

[0003] The prior art has the following deficiencies:

[0004] 1. Traditional protection methods such as RSA, ECC (Elliptic Curve Cryptography), etc. rely on mathematical problems such as integer factorization and discrete logarithms, which are difficult to solve on classical computers, but quantum computers can effectively crack these encryption algorithms in polynomial time through Shor's algorithm, making the secure storage of data not guaranteed;

[0005] 2. Traditional protection is usually designed for specific application scenarios and lacks flexibility. For example, RSA performs well in key exchange but poorly in emerging applications such as homomorphic encryption.

[0006] Based on this, the present invention proposes a data security protection method and system, which rely on solving the Shortest Vector Problem (SVP) on lattices, are quite difficult in both classical and quantum computing environments, and can support a variety of cryptographic applications. This flexibility enables the security protection method to adapt to different application requirements and ensure the secure storage of data. Summary of the Invention

[0007] The purpose of the present invention is to provide a data security protection method and system to solve the deficiencies in the background art.

[0008] To achieve the above purpose, the present invention provides the following technical solution: A data security protection method, the protection method includes the following steps:

[0009] The protection system obtains the dataset information to be securely protected and the corresponding storage medium information, generates a storage difference index based on the dataset information and the corresponding storage medium information, calculates the importance index of the dataset based on the dataset information, and obtains an adjustment coefficient by combining the storage difference index and the importance index;

[0010] Input the adjustment coefficient into the parameter generator, the parameter generator automatically outputs the dimension parameter, modulus parameter, and noise parameter, obtains a random matrix and a secret key vector according to the dimension parameter and modulus parameter, calculates the public key vector through the random matrix, secret key vector, and noise, converts the data to be encrypted into a binary vector, calculates the ciphertext by combining the public key vector and the binary vector, and encrypts the data in the storage medium with the ciphertext;

[0011] When the user needs to read data, after receiving the ciphertext, decrypt and recover the data through the secret key vector.

[0012] In a preferred embodiment, obtaining an adjustment coefficient by combining the storage difference index and the importance index includes the following steps:

[0013] Comprehensively calculate the storage difference index and the importance index to obtain the adjustment coefficient. The expression is:

[0014] In the formula, tz x is the adjustment coefficient, Z storage is the storage difference index, Z data is the importance index, and α and β are the proportionality coefficients of the storage difference index and the importance index respectively, and both α and β are greater than 0.

[0015] In a preferred embodiment, input the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter, the modulus parameter, and the noise parameter, including the following steps:

[0016] Input the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter and the modulus parameter. The expression is: In the formula, n new represents the adjusted dimension parameter, q new represents the adjusted modulus parameter, n old represents the dimension parameter before adjustment, q old represents the modulus parameter before adjustment, and tz x is the adjustment coefficient;

[0017] Then generate the noise parameter range according to the adjusted dimension parameter and the adjusted modulus parameter: [-μ·q new ~μ·q new , where μ represents the adjustment amplitude, and randomly generate the noise parameter within the noise parameter range.

[0018] In a preferred embodiment, obtain the random matrix and the secret key vector according to the dimension parameter and the modulus parameter, and calculate the public key vector through the random matrix, the secret key vector, and the noise, including the following steps:

[0019] Generate a random matrix based on the dimension parameter, with the size of n new ×n new , generate the secret key vector with the size of n new , and calculate the public key vector according to the random matrix, the secret key vector, and the noise. The expression is: P = A×s + e. In the formula, P is the public key vector, A is the random matrix, s is the secret key vector, and e is the noise parameter.

[0020] In a preferred embodiment, the data in the storage medium is encrypted with ciphertext, including the following steps:

[0021] Convert the data set into a binary vector, and generate a random vector based on the dimension parameter with a size of n new , calculate the ciphertext, and the function expression is:

[0022] , where c 1 and c 2 are ciphertexts, m is the binary vector of the original data, r is the random vector, A is the random matrix, P is the public key vector, and A T represents the transposed matrix of the random matrix A, and q new is the modulus.

[0023] In a preferred embodiment, after receiving the ciphertext, decrypt and recover the data through the secret key vector, including the following steps:

[0024] The user decrypts and recovers the ciphertext using the secret key vector, and calculates the binary vector of the decrypted data. The expression is: where m * is the binary vector of the decrypted data, c 1 and c 2 are ciphertexts, s is the secret key vector, q new is the modulus, and c 1 T represents the transpose of the ciphertext vector c 1 ;

[0025] After obtaining the binary vector m of the decrypted data * , if the binary vector m * of the decrypted data is equal to the binary vector m of the original data, it is determined that the decryption is successful.

[0026] In a preferred embodiment, the acquisition logic of the storage difference index is as follows: Obtain the remaining capacity of the storage medium. The remaining capacity is obtained by subtracting the used capacity from the total capacity. Then obtain the data volume of the data set, subtract the data volume from the remaining capacity to get the storage margin. Based on the system log, obtain the read / write speed and redundancy of the storage medium. Normalize the storage margin, read / write speed, and redundancy so that the value ranges of the storage margin, read / write speed, and redundancy are mapped to between [0,1]. Obtain the normalized value of the storage margin, the normalized value of the read / write speed, and the normalized value of the redundancy. Add the normalized value of the storage margin, the normalized value of the read / write speed, and the redundancy to obtain the storage difference index;

[0027] The acquisition logic of the importance index is as follows: obtain the usage frequency and access frequency of the data set, and sum the usage frequency and access frequency to obtain the importance index.

[0028] A data security protection system includes a calculation module, a vector output module, and an encryption module;

[0029] Calculation module: Obtain the data set information to be protected securely and the corresponding storage medium information, generate a storage difference index based on the data set information and the corresponding storage medium information, calculate the importance index of the data set based on the data set information, and obtain an adjustment coefficient by combining the storage difference index and the importance index;

[0030] Vector output module: Input the adjustment coefficient into the parameter generator. The parameter generator automatically outputs dimension parameters, modulus parameters, and noise parameters. Obtain a random matrix and a secret key vector according to the dimension parameters and modulus parameters, and calculate the public key vector through the random matrix, the secret key vector, and the noise;

[0031] Encryption module: After converting the data to be encrypted into a binary vector, calculate the ciphertext by combining the public key vector and the binary vector, and encrypt the data in the storage medium with the ciphertext.

[0032] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:

[0033] 1. The present invention automatically outputs dimension parameters, modulus parameters, and noise parameters through the parameter generator, obtains a random matrix and a secret key vector according to the dimension parameters and modulus parameters, calculates the public key vector through the random matrix, the secret key vector, and the noise, converts the data to be encrypted into a binary vector, calculates the ciphertext by combining the public key vector and the binary vector, and encrypts the data in the storage medium with the ciphertext. When the user needs to read the data, after receiving the ciphertext, decrypt and recover the data through the secret key vector. This protection system relies on solving the shortest vector problem (SVP) on the lattice, which is quite difficult in both classical and quantum computing environments, and can support a variety of cryptographic applications. This flexibility enables the security protection method to adapt to different application requirements and ensures the secure storage of data.

[0034] 2. The present invention obtains the data set information to be protected securely and the corresponding storage medium information, generates a storage difference index based on the data set information and the corresponding storage medium information, calculates the importance index of the data set based on the data set information, obtains an adjustment coefficient by combining the storage difference index and the importance index, and inputs the adjustment coefficient into the parameter generator. The parameter generator automatically outputs dimension parameters, modulus parameters, and noise parameters, making the generated public parameters more suitable for the current data set and storage medium environment. While improving the data storage security, it ensures the storage efficiency of the storage medium. Brief Description of the Drawings

[0035] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0036] Figure 1 It is a flowchart of the method of the present invention. Detailed Embodiments

[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0038] Embodiment 1: Please refer to Figure 1 As shown, a data security protection method in this embodiment includes the following steps:

[0039] The protection system obtains the dataset information to be securely protected and the corresponding storage medium information, generates a storage difference index based on the dataset information and the corresponding storage medium information, calculates the importance index of the dataset based on the dataset information, obtains an adjustment coefficient by combining the storage difference index and the importance index, inputs the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter, modulus parameter, and noise parameter. According to the dimension parameter and modulus parameter, a random matrix and a secret key vector are obtained, and a public key vector is calculated through the random matrix, secret key vector, and noise. After converting the data to be encrypted into a binary vector, the ciphertext is calculated by combining the public key vector and the binary vector, and the data in the storage medium is encrypted with the ciphertext. When the user needs to read the data, after receiving the ciphertext, it is decrypted and the data is restored through the secret key vector.

[0040] Dynamically generating encryption parameters based on the importance index and storage difference index: By calculating the importance index and storage difference index of the dataset, the system can generate a suitable adjustment coefficient and dynamically adjust the encryption parameters (such as dimension parameter, modulus parameter, and noise parameter) based on this coefficient. This enables the encryption scheme to be adaptively adjusted according to the importance of the data and the characteristics of the storage medium, ensuring that different types of data can be protected most appropriately and preventing security vulnerabilities or resource waste caused by a one-size-fits-all encryption strategy.

[0041] Enhance the security protection ability of data: By selecting appropriate dimension and modulus parameters, especially for data with a higher importance index, the system can significantly improve the security of data encryption and prevent attackers from cracking the ciphertext through conventional means. At the same time, the introduction of noise parameters further increases the ambiguity of the ciphertext and enhances the ability to resist side-channel attacks and statistical analysis attacks.

[0042] Optimize encryption according to storage medium characteristics: Before encrypting data, the system analyzes the read / write speed, storage capacity, and redundancy of the storage medium, measures the characteristics of the storage medium through the storage difference index, and adjusts the encryption parameters accordingly. This can ensure that, without sacrificing security, the storage resources are fully utilized and performance degradation or resource waste caused by excessive encryption is avoided.

[0043] Reduce storage and computing overhead: By optimizing the encryption parameters, the system can reduce the size of keys and ciphertext, thereby reducing storage requirements. At the same time, appropriately selecting the noise parameters to ensure a balance between computational complexity and security, reducing the computational overhead during the decryption process, and improving the efficiency of data reading and writing.

[0044] Accurate data recovery: Through appropriate parameter settings, the system can effectively reduce errors during decryption and ensure the integrity and accuracy of data. Especially in high-noise situations, through a carefully designed decryption process, the impact of noise on data recovery can be effectively offset.

[0045] Enhance the robustness of the system: When processing data of different importance levels, the system can automatically adjust the encryption intensity and strategy, and this self-adaptability enhances the robustness and flexibility of the system in the face of various threats and attack scenarios.

[0046] Diverse application scenarios: This solution can be applied to different application scenarios, providing flexible encryption solutions from personal data protection to enterprise-level data security. Whether it is important data stored on high-performance storage media or a large amount of data that needs to be stored for a long time, the encryption intensity and resource allocation can be adjusted according to actual needs.

[0047] Meet compliance requirements: By dynamically adjusting the encryption parameters, the system can more easily meet the compliance requirements of different regions and industries, such as GDPR or HIPAA. This flexibility makes this encryption solution widely applicable globally.

[0048] Comprehensive data protection: The encryption parameters generated by combining the storage difference index and the importance index ensure the maximization of the security of different data in different storage environments and reduce the risk of data leakage.

[0049] Enhanced Data Management and Monitoring Capabilities: The system can adjust the encryption policy in real time according to the importance of the data and the characteristics of the storage medium. This not only improves the security of the data but also enhances the data management and monitoring capabilities, enabling managers to more effectively deploy and adjust data security policies.

[0050] This application automatically outputs dimension parameters, modulus parameters, and noise parameters through a parameter generator. Based on the dimension parameters and modulus parameters, a random matrix and a secret key vector are obtained. The public key vector is calculated through the random matrix, the secret key vector, and the noise. After converting the data to be encrypted into a binary vector, the ciphertext is calculated by combining the public key vector and the binary vector. The data in the storage medium is encrypted with the ciphertext. When the user needs to read the data, after receiving the ciphertext, it is decrypted and the data is restored through the secret key vector. This protection system relies on solving the shortest vector problem (SVP) on a lattice, which is quite difficult in both classical and quantum computing environments and can support multiple cryptographic applications. This flexibility enables the security protection method to adapt to different application requirements and ensures the secure storage of data.

[0051] This application obtains the dataset information to be securely protected and the corresponding storage medium information, generates a storage difference index based on the dataset information and the corresponding storage medium information, calculates the importance index of the dataset based on the dataset information, obtains an adjustment coefficient by combining the storage difference index and the importance index, and inputs the adjustment coefficient into the parameter generator. The parameter generator automatically outputs dimension parameters, modulus parameters, and noise parameters, making the generated common parameters more suitable for the current dataset and storage medium environment, improving the data storage security while ensuring the storage efficiency of the storage medium.

[0052] Example 2: The protection system obtains the dataset information to be securely protected and the corresponding storage medium information, generates a storage difference index based on the dataset information and the corresponding storage medium information, and calculates the importance index of the dataset based on the dataset information, including the following steps:

[0053] Obtain the dataset information, including information such as the name, size, data type, data structure, and data source of the dataset;

[0054] Obtain the storage medium information, including the type of the storage medium (such as hard disk, SSD, cloud storage, etc.), the storage location (local or remote), the storage capacity, the read and write speed, etc.;

[0055] The acquisition logic of the storage difference index is as follows: Obtain the remaining capacity of the storage medium, which is obtained by subtracting the used capacity from the total capacity. Then obtain the data volume of the data set, and subtract the data volume from the remaining capacity to get the storage margin. Based on the system log, obtain the read / write speed and redundancy of the storage medium, and perform normalization processing on the storage margin, read / write speed, and redundancy, so that the value ranges of the storage margin, read / write speed, and redundancy are mapped to between [0,1]. Obtain the normalized value of the storage margin, the normalized value of the read / write speed, and the normalized value of the redundancy. Add the normalized value of the storage margin, the normalized value of the read / write speed, and the redundancy to obtain the storage difference index. The smaller the storage difference index, the worse the overall performance of the storage medium, indicating that the storage medium is less supportive of larger dimension parameters and modulus parameters.

[0056] The corresponding relationships between the dimension parameters, modulus parameters, and storage margin are as follows:

[0057] Dimension (n): Larger dimensions usually mean greater security and computational complexity, but they also increase the storage requirements for data. A larger n may reduce the storage margin because the storage occupancy of data such as keys and ciphertext will increase;

[0058] Modulus (q): A larger modulus q will cause an increase in the size of the key and ciphertext, thereby consuming more storage space. Therefore, a larger q value may reduce the storage margin.

[0059] The corresponding relationships between the dimension parameters, modulus parameters, and read / write speed are as follows:

[0060] Dimension (n): Larger dimensions usually increase the computational amount, resulting in more frequent read / write operations. If the read / write speed of the storage medium is slow, it may become a performance bottleneck. Therefore, when choosing a larger n, it is recommended to choose a storage medium with a higher read / write speed;

[0061] Modulus (q): A larger modulus will increase the size of the ciphertext and key, resulting in an increase in the amount of data that needs to be transmitted and stored, thereby possibly reducing the read / write efficiency. Therefore, when the modulus is large, a storage medium with a higher read / write speed should also be selected.

[0062] The corresponding relationships between the dimension parameters, modulus parameters, and redundancy are as follows:

[0063] Dimension (n): In data encryption, larger dimensions can enhance security but also lead to an increase in the amount of data. To ensure data security, a storage medium with a higher redundancy can be used;

[0064] Modulus (q): A larger modulus will also increase the size of the data. Therefore, when using a larger modulus, it is also possible to consider increasing the redundancy of the storage medium to ensure data integrity and security.

[0065] In summary, the smaller the storage margin, the more necessary it is to reduce the values of the dimension parameter and the modulus parameter; the smaller the read / write speed, the more necessary it is to reduce the values of the dimension parameter and the modulus parameter; the smaller the redundancy, the more necessary it is to reduce the values of the dimension parameter and the modulus parameter.

[0066] The logic for obtaining the importance index is as follows: Obtain the usage frequency and the accessed frequency of the data set, sum up the usage frequency and the accessed frequency to obtain the importance index. The smaller the importance index, the fewer the access and usage times of the data set in the enterprise, and the less important it is for the enterprise, and larger dimension parameters and modulus parameters are not required.

[0067] The larger the importance index of the data set, the higher the value or sensitivity of the data set in the system. In this case, choosing larger dimensions and moduli helps to enhance the security of the data. The following is the reason explanation:

[0068] The larger the importance index of the data set, the higher the criticality and sensitivity of the data set in the business or application scenario. To ensure its security, larger dimensions and moduli are usually required. The dimension n and the modulus q directly affect the security and anti-attack ability of the encryption system. The following are the specific reasons:

[0069] Enhance the complexity of encryption: The dimension n represents the dimension of the lattice. The higher the dimension of the lattice, the greater the difficulty for the attacker to crack the system. Higher dimensions increase the size of the key space, making brute-force cracking and other attack methods more difficult. Therefore, for data sets with a large importance index, in order to prevent potential attacks, larger dimensions are usually required to enhance the complexity of encryption;

[0070] Improve the anti-attack ability: Larger dimensions mean a more complex mathematical structure, which makes some known attack methods (such as the shortest vector problem (SVP), the closest vector problem (CVP)) difficult to effectively attack in high-dimensional lattices. This is particularly important for protecting sensitive data.

[0071] Increase the security of the ciphertext: The modulus q controls the range of integers used in the encryption process. A larger modulus q makes the ciphertext have higher ambiguity (that is, the possibility of different ciphertexts corresponding to the same plaintext is higher), thereby improving the security of the encryption scheme. For data sets with a relatively large importance index, using a larger q can prevent attackers from inferring the plaintext by analyzing the relationships between ciphertexts;

[0072] Effectiveness of resisting attacks: A large modulus q makes the attacker face more possibilities during the reverse calculation process, increasing the difficulty of cracking the ciphertext. This is particularly crucial for protecting highly sensitive and important data sets.

[0073] Obtain the adjustment coefficient by combining the storage difference index and the importance index, including the following steps:

[0074] The storage difference index and the importance index are comprehensively calculated to obtain an adjustment coefficient, and the expression is:

[0075] In the formula, tz x is the adjustment coefficient, Z storage is the storage difference index, Z data is the importance index, and α and β are the proportionality coefficients of the storage difference index and the importance index respectively, and both α and β are greater than 0.

[0076] The larger the storage difference index and the importance index are, the larger the values of the dimension parameter and the modulus parameter initially generated by the protection system are. In this application, the larger the adjustment coefficient is, the smaller the storage difference index and the importance index are, and the more necessary it is to reduce the values of the initially generated dimension parameter and modulus parameter.

[0077] Input the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter, the modulus parameter, and the noise parameter, including the following steps:

[0078] In this application, since data security protection is involved, therefore, the initially preset dimension parameter and modulus parameter are selected as the largest dimension parameter and modulus parameter (set on the premise of the optimal storage medium performance and the most important dataset);

[0079] Input the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter and the modulus parameter, and the expression is:

[0080] In the formula, n new represents the adjusted dimension parameter, q new represents the adjusted modulus parameter, n old represents the dimension parameter before adjustment, q old represents the modulus parameter before adjustment, and tz x is the adjustment coefficient;

[0081] Then, a noise parameter range: [-μ·q new ~μ·q new is generated based on the adjusted dimension parameter and the adjusted modulus parameter, where μ represents the adjustment amplitude, and a noise parameter is randomly generated within the noise parameter range.

[0082] Obtain a random matrix and a secret key vector based on the dimension parameter and the modulus parameter, and calculate the public key vector through the random matrix, the secret key vector, and the noise, including the following steps:

[0083] Generate a random matrix based on the dimension parameter, with the size of n new ×n new, generate a secret key vector, with a size of n new , calculate the public key vector based on the random matrix, secret key vector, and noise, and the expression is: P = A × s + e, where P is the public key vector, A is the random matrix, s is the secret key vector, and e is the noise parameter.

[0084] After converting the original data to be encrypted into a binary vector, calculate the ciphertext in combination with the public key vector and the binary vector, and encrypt the data in the storage medium with the ciphertext, including the following steps:

[0085] Convert the data set into a binary vector and generate a random vector based on the dimension parameter with a size of n new , calculate the ciphertext, and the function expression is:

[0086] , where c 1 、c 2 are the ciphertext, m is the binary vector of the original data, r is the random vector, A is the random matrix, P is the public key vector, A T represents the transpose matrix of the random matrix A, q new is the modulus.

[0087] When the user needs to read the data, after receiving the ciphertext, decrypt and recover the data through the secret key vector, including the following steps:

[0088] The user uses the secret key vector to decrypt and recover the ciphertext, and calculates the binary vector of the decrypted data. The expression is: where m * is the binary vector of the decrypted data, c 1 、c 2 are the ciphertext, s is the secret key vector, q new is the modulus, c 1 T represents the transpose of the ciphertext vector c 1 Because c 1 is a column vector, its transpose is a row vector, and after transposing, it can be multiplied by the secret key vector.

[0089] After obtaining the binary vector m of the decrypted data * , if the binary vector m of the decrypted data * is equal to the binary vector m of the original data, it is determined that the decryption is successful.

[0090] To better illustrate the technical solution of Embodiment 2, the present application is exemplified as follows:

[0091] Suppose the generated common parameters are as follows:

[0092] Modulus parameter: qnew = 24;

[0093] Dimension parameter: n new = 2.

[0094] Step 1: Generation of public key vector and secret key vector:

[0095] Random matrix:

[0096] Secret key vector:

[0097] Noise parameter:

[0098] Then the public key vector:

[0099] Step 2: Data encryption:

[0100] If the original data is 1, then the binary vector of the original data:

[0101] Random vector:

[0102] Calculate the ciphertext:

[0103] Step 2: Data decryption:

[0104] Binary vector of the decrypted data: Indicates successful recovery of the original data.

[0105] Example 3: A data security protection system described in this example includes a calculation module, a vector output module, and an encryption module;

[0106] Calculation module: Obtain the dataset information to be securely protected and the corresponding storage medium information, generate a storage difference index based on the dataset information and the corresponding storage medium information, calculate the importance index of the dataset based on the dataset information, obtain an adjustment coefficient by combining the storage difference index and the importance index, and send the adjustment coefficient to the vector output module;

[0107] Vector output module: Input the adjustment coefficient into the parameter generator, the parameter generator automatically outputs the dimension parameter, modulus parameter, and noise parameter, obtain a random matrix and a secret key vector based on the dimension parameter and modulus parameter, calculate the public key vector through the random matrix, secret key vector, and noise, and send the public key vector to the encryption module;

[0108] Encryption module: After converting the data to be encrypted into a binary vector, calculate the ciphertext by combining the public key vector and the binary vector, and encrypt the data in the storage medium with the ciphertext.

[0109] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0110] It should be understood that the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship. Specifically, it can be understood by referring to the context before and after.

[0111] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0112] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0113] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.

Claims

1. A data security protection method, characterized in that: The protection method comprises the following steps: The protection system obtains the data set information and the corresponding storage medium information that need to be securely protected, and generates a storage difference index based on the data set information and the corresponding storage medium information. The logic for obtaining the storage difference index is: add the normalized value of the storage margin plus the normalized value of the read and write speed plus the normalized value of the redundancy to obtain the storage difference index. The importance index of the data set is calculated based on the data set information. The logic for obtaining the importance index is: obtain the importance index by summing the usage frequency and the access frequency. Combine the storage difference index and the importance index to obtain the adjustment coefficient. The expression is: , where is the adjustment factor, To store the difference index, is the importance index, , is the proportionality coefficient, and , All are greater than 0; Input the adjustment coefficient into the parameter generator, and the parameter generator automatically outputs the dimension parameter, modulus parameter, and noise parameter. The expression is: , where represents the adjusted dimension parameter, represents the adjusted modulus parameter, Represents the dimension parameter before adjustment, Indicates the modulus parameter before adjustment, is the adjustment factor; Generate a noise parameter range based on the adjusted dimension parameter and the adjusted modulus parameter: ,in, , Represents the adjustment amplitude, randomly generating noise parameters within the noise parameter range; According to the adjusted dimension parameters and modulus parameters, the random matrix and secret key vector are obtained. The public key vector is obtained by calculating the random matrix, secret key vector and noise. The random matrix is ​​generated based on the dimension parameters, and the size is , generate a secret key vector with size , the public key vector is calculated based on the random matrix, secret key vector and noise, and the expression is: , where is the public key vector, is a random matrix, is the key vector, The noise parameter is used to convert the data to be encrypted into a binary vector, and then the ciphertext is calculated by combining the public key vector and the binary vector. The data in the storage medium is encrypted by the ciphertext, and the data set is converted into a binary vector. A random vector is generated based on the dimension parameter. , size is , calculate the ciphertext, the function expression is: , where , is the ciphertext, is the binary vector of the original data, is a random vector, is a random matrix, is the public key vector, Represents a random matrix The transposed matrix of is the modulus; When the user needs to read the data, after receiving the ciphertext, the key vector is used to decrypt and recover the data.

2. A data security protection method according to claim 1, characterized in that: After receiving the ciphertext, decryption and data recovery are performed using the secret key vector, including the following steps: The user uses the secret key vector to decrypt the ciphertext and recover the data, and calculates the binary vector of the decrypted data, which is expressed as: , where is the binary vector of the decrypted data, , is the ciphertext, is the key vector, is the modulus, Represents the ciphertext vector The transpose of Get the binary vector of the decrypted data After that, if the binary vector of the decrypted data Binary vector with original data If they are equal, the decryption is successful.

3. A data security protection method according to claim 2, characterized in that: The acquisition logic of the storage margin normalized value, the read / write speed normalized value, and the redundancy normalized value is as follows: the remaining capacity of the storage medium is obtained, the remaining capacity is obtained by subtracting the used capacity from the total capacity, and then the data volume of the data set is obtained, and the storage margin is obtained by subtracting the data volume from the remaining capacity, and the read / write speed and redundancy of the storage medium are obtained based on the system log, and the storage margin, read / write speed, and redundancy are normalized so that the value range of the storage margin, read / write speed, and redundancy is mapped to between [0,1], and the storage margin normalized value, the read / write speed normalized value, and the redundancy normalized value are obtained.

4. A data security protection system, used to implement the protection method according to any one of claims 1 to 3, characterized in that: Including calculation module, vector output module and encryption module; Calculation module: obtains the data set information and corresponding storage medium information that need to be securely protected, generates a storage difference index based on the data set information and the corresponding storage medium information, calculates the importance index of the data set based on the data set information, and obtains an adjustment coefficient by combining the storage difference index and the importance index; Vector output module: input the adjustment coefficient into the parameter generator, the parameter generator automatically outputs the dimension parameter, modulus parameter and noise parameter, obtains the random matrix and secret key vector according to the dimension parameter and modulus parameter, and obtains the public key vector through the random matrix, secret key vector and noise calculation; Encryption module: After converting the data to be encrypted into a binary vector, the ciphertext is calculated by combining the public key vector and the binary vector, and the data in the storage medium is encrypting the ciphertext.

Citation Information

Patent Citations

  • Service quality parameter management method, node and storage medium

    CN117135699A

  • Anti-quantum ciphertext equivalent test public key encryption method and system based on lattice

    CN118400197A