A network security protection encryption method and device

By evaluating and screening the performance and security of each target algorithm in the network security protection encryption method, and selecting efficient encryption algorithms, the problems of high complexity and low efficiency of the encryption process in the existing technology are solved, and more efficient, stable and reliable network security protection encryption effects are achieved.

CN119324820BActive Publication Date: 2025-06-24JIANGSU YISHANG INFORMATION TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411448619.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-17
Publication Date
2025-06-24
Estimated Expiration
2044-10-17

AI Technical Summary

Technical Problem

Although the existing encryption methods for network security protection are highly complex in computing, and the encryption and decryption processes are relatively slow, which may affect the real-time and efficiency of network communication.

Method used

By obtaining the data to be tested and the encryption algorithm, marking it as each target algorithm, and using each target algorithm to encrypt and decrypt the data to be tested, collecting performance data and security data, processing to obtain the performance evaluation index and security evaluation index of each target algorithm, comprehensive analysis obtains the comprehensive energy efficiency evaluation index of each target algorithm, and the encryption algorithm is filtered based on these indicators.

Benefits of technology

Choose an encryption algorithm that is more efficient in resource utilization, reduce system resource waste, improve overall efficiency and response speed, reduce the risk of system failures caused by algorithm defects or insufficient, improve system stability and reliability, and ensure business continuity and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119324820B_ABST
    Figure CN119324820B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of digital information transmission technology, and specifically provides a network security protection encryption method and device. The method includes: obtaining the data to be tested and encryption algorithms, marking them as each target algorithm, collecting the test data of each target algorithm, and obtaining the performance evaluation index and security evaluation index of each target algorithm through processing; obtaining the basic characteristic data of the data to be encrypted, and obtaining the data demand performance parameter and data demand security parameter of the data to be encrypted through processing; comprehensively analyzing to obtain the comprehensive energy efficiency evaluation index of each target algorithm, and screening the encryption algorithms. By providing a network security protection encryption method and device, the present invention comprehensively analyzes to obtain the comprehensive energy efficiency evaluation index of each target algorithm, which helps to select a more efficient algorithm in terms of resource utilization, thereby reducing the waste of system resources, improving the overall efficiency and response speed, and also reducing the risk of system failures caused by algorithm defects or deficiencies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information transmission, and particularly to a network security protection encryption method and device. Background Art

[0002] With the popularization of the Internet, the value of data has become increasingly prominent. Individuals and organizations are increasingly relying on the network for daily activities, making it crucial to protect the network, data, and devices from unauthorized access and damage. Therefore, network security protection has become an important issue that cannot be ignored and requires continuous attention and updates to protect the confidentiality, integrity, and availability of information.

[0003] For example, the invention patent with the publication number: CN117294537B is a computer network security protection method and system applying quantum encryption, which relates to the technical field of network security. In this method, a random and unpredictable security key is generated through a quantum key distribution protocol, and then the security key is transmitted to both communication parties through a quantum channel respectively. The received security key is converted into quantum bits, and fixed-period timeline cutting is performed to form N1, N2, N3 to Nx groups of measurement and screening information sets, and the calculation methods are the same. Taking the N1 group of measurement and screening information sets as an example, the first data set of spin states and the second data set of polarization states are counted and calculated to obtain the measurement index Clzs of the quantum bits. The measurement index Clzs is compared with a preset measurement threshold T, and according to the comparison result, a channel is established or an abnormal feedback is given, and the generated shared quantum key is used to perform quantum encryption on the communication content.

[0004] For example, the invention patent with the publication number: CN114389809B is an information-based network security protection method for encrypting the https protocol, including generating an https request to be transmitted by the host server; the host server sending the https request to the network security protection server; the network security protection server using a detection program to perform intrusion detection on the https request; if it is found that this https request has been invaded, it is destroyed and a message is transmitted back to the host server, otherwise the next step is performed; the network security protection server using an encryption program to encrypt the https request; the network security protection server sending the encrypted https request to the receiving client; the receiving client decrypting the https request and querying the local database for the decrypted request; and returning the query result to the host server along the original path.

[0005] However, in the process of implementing the inventive technical solution in the embodiments of the present application, it is found that the above technologies have at least the following technical problems: The current network security protection encryption methods include quantum encryption technology and asymmetric encryption methods. Although they have high security, their computational complexity is relatively high, and the encryption and decryption processes are relatively slow, which may affect the real-time performance and efficiency of network communication. Summary of the Invention

[0006] In view of the deficiencies of the prior art, the present invention provides a network security protection encryption method and device, which can effectively solve the problems involved in the above background technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: In the first aspect of the present invention, a network security protection encryption method is provided, including: obtaining the data to be tested and encryption algorithms, marking them as each target algorithm, and using each target algorithm to perform encryption and decryption operations on the data to be tested, collecting the test data of each target algorithm, including performance data and security data, and obtaining the performance evaluation index and security evaluation index of each target algorithm through processing.

[0008] Obtain the basic characteristic data of the data to be encrypted, and obtain the data demand performance parameter and data demand security parameter of the data to be encrypted through processing.

[0009] According to the data demand performance parameter and data demand security parameter of the data to be encrypted, as well as the performance evaluation index and security evaluation index of each target algorithm, comprehensively analyze to obtain the comprehensive energy efficiency evaluation index of each target algorithm, screen the encryption algorithm according to the comprehensive energy efficiency evaluation index of each target algorithm, obtain the screening result and give feedback.

[0010] As a further method, the process of collecting the test data of each target algorithm, including performance data and security data, is specifically as follows: Deploy a number of time monitoring points, and collect the test data during the period when each target algorithm performs encryption and decryption operations on the data to be tested, including performance data and security data.

[0011] The performance data includes the encryption speed at each time monitoring point within the encryption operation cycle, the resource consumption amounts within the encryption operation cycle, and the data throughput, where the resource consumption amounts within the encryption operation cycle include CPU usage rate, memory occupancy rate, disk occupancy rate, and network IO occupancy rate.

[0012] The security data includes the number of brute-force attacks on each target algorithm, the time required for successful cracking, and the number of vulnerabilities within the encryption operation cycle.

[0013] As a further method, the performance evaluation index and security evaluation index of each target algorithm are obtained through processing, specifically including: according to the encryption speed, various resource consumption amounts, and data throughput at each time monitoring point during the encryption operation cycle, the critical encryption speed, various critical resource consumption amounts, and critical data throughput are extracted from the data encryption database, and the performance evaluation index of each target algorithm is obtained through comprehensive analysis. The performance evaluation index of each target algorithm is used to quantitatively evaluate the performance of each target algorithm and provide a basis for evaluating the comprehensive energy efficiency of each target algorithm.

[0014] As a further method, the performance evaluation index and security evaluation index of each target algorithm obtained through processing further include: according to the number of brute-force cracking attempts on each target algorithm, the time required for successful cracking, and the number of vulnerabilities during the encryption operation cycle, the critical number of brute-force cracking attempts, critical successful cracking time, and critical number of vulnerabilities are extracted from the data encryption database, and the security evaluation index of each target algorithm is obtained through comprehensive analysis. The security evaluation index of each target algorithm is used to quantitatively evaluate the security level of each target algorithm and provide a basis for evaluating the comprehensive energy efficiency of each target algorithm.

[0015] As a further method, the basic characteristic data of the data to be encrypted includes the byte length and basic security requirement data.

[0016] The basic security requirement data specifically includes the number of allowed access systems for the data to be encrypted and the historical cumulative number of access times.

[0017] As a further method, the data requirement performance parameter and data requirement security parameter of the data to be encrypted are obtained through processing. The specific process is as follows: according to the byte length of the data to be encrypted, the data requirement performance parameter corresponding to the byte length range is extracted from the data encryption database. The data requirement performance parameter of the data to be encrypted is used to quantitatively evaluate the performance requirement of the data to be encrypted for the encryption system and provide a basis for the comprehensive energy efficiency evaluation index of each target algorithm.

[0018] According to the number of allowed access systems for the data to be encrypted and the historical cumulative number of access times, the critical number of allowed access systems and critical historical cumulative number of access times are extracted from the data encryption database, and the data requirement security parameter of the data to be encrypted is obtained through comprehensive analysis. The data requirement security parameter of the data to be encrypted is used to quantitatively evaluate the security of the data to be encrypted and provide a basis for the comprehensive energy efficiency evaluation index of each target algorithm.

[0019] As a further method, the comprehensive analysis obtains the comprehensive energy efficiency evaluation indexes of each target algorithm. The specific analysis process is as follows: According to the data demand performance parameters and data demand security parameters of the data to be encrypted, as well as the performance evaluation indexes and security evaluation indexes of each target algorithm, the comprehensive energy efficiency evaluation indexes of each target algorithm are obtained through comprehensive analysis. The comprehensive energy efficiency evaluation indexes of each target algorithm are used to quantitatively evaluate the comprehensive energy efficiency of each target algorithm.

[0020] As a further method, the encryption algorithms are screened according to the comprehensive energy efficiency evaluation indexes of each target algorithm, and the screening results are obtained and fed back. The specific screening process is as follows: The comprehensive energy efficiency evaluation indexes of each target algorithm are sorted in ascending order to obtain the comprehensive energy efficiency evaluation index sequence of each target algorithm. The target algorithm with the largest comprehensive energy efficiency evaluation index among each target algorithm is extracted and marked as the optimal algorithm of the test system.

[0021] As a further method, the specific numerical expression of the comprehensive energy efficiency evaluation index of each target algorithm is:

[0022] ;

[0023] In the formula, represents the comprehensive energy efficiency evaluation index of the r-th target algorithm, represents the performance evaluation index of the r-th target algorithm, represents the security evaluation index of the r-th target algorithm, represents the data demand performance parameter of the data to be encrypted, represents the data demand security parameter of the data to be encrypted.

[0024] The second aspect of the present invention provides a network security protection encryption device, which is characterized in that it includes: a processor, a memory and a network interface connected to the processor; the network interface is connected to a non-volatile memory in the server; when running, the processor retrieves a computer program from the non-volatile memory through the network interface and runs the computer program through the memory to execute the above method.

[0025] Compared with the prior art, the embodiments of the present invention at least have the following advantages or beneficial effects:

[0026] (1) By providing a network security protection encryption method and device, the present invention comprehensively considers the data demand performance and data demand security of the data to be encrypted, as well as the performance and security of each target algorithm, which helps to select a more efficient algorithm in resource utilization, thereby reducing the waste of system resources, improving the overall efficiency and response speed, and can also reduce the risk of system failures caused by algorithm defects or deficiencies, enhance the stability and reliability of the system, and ensure business continuity and data integrity.

[0027] (2) By comparing the performance of different algorithms, the advantages and disadvantages of each algorithm can be intuitively seen, so as to select the algorithm most suitable for the current application scenario. At the same time, screening the encryption algorithm based on the performance evaluation index can also significantly improve the overall performance of data encryption and ensure the stability of data transmission.

[0028] (3) By quantitatively evaluating the security of the algorithm, the security risks of each encryption algorithm in different application scenarios can be more accurately evaluated. This helps to avoid serious consequences such as data leakage and system being controlled due to insufficient algorithm security. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to the following drawings without creative efforts.

[0030] Figure 1 It is a schematic flowchart of the method of the present invention.

[0031] Figure 2 It is a schematic diagram of the functional relationship between the historical cumulative access times of the data to be encrypted and the data requirement security parameter of the data to be encrypted involved in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0033] Referring to Figure 1 As shown, the first aspect of the present invention provides a network security protection encryption method, including: obtaining the data to be tested and the encryption algorithm, marking them as each target algorithm, and using each target algorithm to perform encryption and decryption operations on the data to be tested, collecting the test data of each target algorithm, including performance data and security data, and obtaining the performance evaluation index and security evaluation index of each target algorithm through processing.

[0034] Specifically, the process of collecting the test data of each target algorithm, including performance data and security data, is as follows: deploying several time monitoring points, and collecting the test data during the period when each target algorithm performs encryption and decryption operations on the data to be tested, including performance data and security data;

[0035] The performance data includes the encryption speed at each time monitoring point during the encryption operation cycle, the consumption of various resources during the encryption operation cycle, and the data throughput. Among them, the consumption of various resources during the encryption operation cycle includes the consumption of CPU resources, memory resources, disk resources, and network IO resources;

[0036] The security data includes the number of brute-force attacks on each target algorithm, the time required for successful cracking, and the number of vulnerabilities during the encryption operation cycle.

[0037] Further, the performance evaluation index and security evaluation index of each target algorithm are obtained through processing, specifically including: according to the encryption speed, the consumption of various resources, and the data throughput at each time monitoring point during the encryption operation cycle, the critical encryption speed, the critical consumption of various resources, and the critical data throughput are extracted from the data encryption database, and the performance evaluation index of each target algorithm is obtained through comprehensive analysis. The performance evaluation index of each target algorithm is used to quantitatively evaluate the performance of each target algorithm and provide a basis for evaluating the comprehensive energy efficiency of each target algorithm.

[0038] It should be noted that in this embodiment, the encryption speed, the consumption of various resources, and the data throughput at each time monitoring point during the encryption operation cycle respectively represent the encryption speed, the consumption of various resources, and the data throughput from the previous time monitoring point to the current time monitoring point.

[0039] It should be noted that the critical encryption speed, the critical consumption of various resources, and the critical data throughput respectively represent the minimum encryption speed, the maximum consumption of various resources, and the minimum data throughput during the encryption operation cycle. Under this condition, the performance of the target algorithm on the encryption system is far lower than the expected value.

[0040] In a specific embodiment, the numerical expression of the performance evaluation index of each target algorithm is:

[0041] ;

[0042] In the formula, represents the performance evaluation index of the r-th target algorithm, r represents the number of each target algorithm, , h represents the total number of target algorithms, represents the encryption speed of the r-th target algorithm at the i-th time monitoring point, i represents the number of each time monitoring point, , t represents the total number of time monitoring points, represents the consumption of the n-th resource of the r-th target algorithm at the i-th time monitoring point, n represents the number of each resource, ,, represents the data throughput of the r-th target algorithm at the i-th time monitoring point, represents the critical encryption speed, represents the critical consumption of the nth resource represents the critical data throughput represents the algorithm performance impact factor corresponding to the preset encryption speed represents the algorithm performance impact factor corresponding to the preset resource consumption represents the algorithm performance impact factor corresponding to the preset data throughput

[0043] It should be understood that from the above formula, when the encryption speed and data throughput of the target algorithm are larger and the resource consumption is smaller, the corresponding performance evaluation index of the target algorithm is larger, indicating that the performance of the target algorithm on the encryption system is better.

[0044] It should be explained that in this embodiment is the algorithm performance impact factor corresponding to the preset encryption speed, which represents the value of the impact degree of the unit value of the encryption speed on the system operation performance of the target algorithm. When used, the algorithm performance impact factor corresponding to the encryption speed can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the encryption speed of the target algorithm at the current time point and the algorithm performance impact factor corresponding to the preset encryption speed in the data encryption database form a mapping set, and the real-time encryption speed is input into the mapping set to obtain the algorithm performance impact factor corresponding to the encryption speed, and the mapping relationship therein can be one-to-one or a many-to-one relationship.

[0045] It should be explained that in this embodiment is the algorithm performance impact factor corresponding to the preset resource consumption, which represents the value of the impact degree of the unit value of the resource consumption on the system operation performance of the target algorithm. When used, the algorithm performance impact factor corresponding to the resource consumption can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the resource consumption of the target algorithm at the current time point and the algorithm performance impact factor corresponding to the preset resource consumption in the data encryption database form a mapping set, and the real-time resource consumption is input into the mapping set to obtain the algorithm performance impact factor corresponding to the resource consumption, and the mapping relationship therein can be one-to-one or a many-to-one relationship.

[0046] It should be explained that in this embodiment It is the algorithm performance impact factor corresponding to the preset data throughput, representing the numerical value of the impact of the unit value of data throughput on the system operation performance of the target algorithm. When used, the algorithm performance impact factor corresponding to the data throughput can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the data throughput of the target algorithm at the current time point and the algorithm performance impact factor corresponding to the preset data throughput in the data encryption database form a mapping set. The real-time data throughput is input into the mapping set to obtain the algorithm performance impact factor corresponding to the data throughput, and the mapping relationship therein can be one-to-one or many-to-one.

[0047] It should be noted that the above impact factors are all extracted from the data encryption database, and their value ranges are all between 0 and 1.

[0048] It should be noted that during the data encryption process, the encryption speed can be directly measured by specialized performance testing tools or software. These tools can usually record the time required for the encryption operation from start to finish and calculate the encryption speed based on this. System monitoring tools (such as performance monitors, resource managers, etc.) can be used to monitor the consumption of resources such as CPU, memory, and disk during the data encryption process. These tools can display the resource usage in real time and can generate reports for subsequent analysis. Professional performance analysis tools (such as Profiler) can also be used to deeply analyze the resource consumption during the data encryption process. These tools can provide more detailed and accurate resource consumption data. When data encryption involves network transmission, network performance testing tools (such as Wireshark, Netperf, etc.) can be used to measure the data throughput. These tools can capture network packets and calculate the data transmission rate.

[0049] It should be noted that the encryption speed is one of the important indicators to measure the performance of encryption algorithms. The encryption speed refers to the amount of data encrypted per second, and the data volume is in megabits. The better the performance of the encryption algorithm or system, the faster its encryption speed usually is. This means that more data can be encrypted within the same time, or the time required to encrypt the same amount of data is shorter. The improvement of the encryption speed is particularly important for application scenarios that need to process a large amount of data or require quick responses. In many cases, the better the performance of the encryption algorithm or system, the more effectively it can utilize resources, thus reducing unnecessary resource consumption. The better the performance of the encryption algorithm or system, the higher its data throughput usually is. The data throughput refers to the amount of data that the system can process per unit time, which directly reflects the speed and efficiency of the system in processing data. Therefore, when the performance of the encryption algorithm or system is improved, they can process more data faster, thus increasing the data throughput. Therefore, when evaluating the performance of an encryption system, it is necessary to comprehensively consider various factors to improve the accuracy and comprehensiveness of the evaluation.

[0050] It should be understood that through monitoring the encryption speed at different time points in the above embodiments, the processing efficiency of the algorithm at different stages can be intuitively understood. Extracting the critical encryption speed helps to determine the fastest processing speed of the algorithm under specific conditions, providing a quantitative basis for the performance optimization of the algorithm. The resource consumption includes the consumption of CPU resources, memory resources, disk resources, and network IO resources. Monitoring and extracting the critical consumption of each resource can clearly reflect the occupation of system resources by the algorithm during operation, helping to evaluate the resource efficiency of the algorithm. The data throughput is a key indicator for measuring the processing capacity of the system. By monitoring and extracting the critical data throughput, the ability of the algorithm to process data per unit time can be evaluated, providing a basis for the expansion and upgrade of the system. When comparing multiple target algorithms, the above evaluation indicators can be used as objective evaluation criteria. By comparing the critical encryption speed, critical resource consumption, and critical data throughput of different algorithms, the advantages and disadvantages of each algorithm can be intuitively seen, so as to select the most suitable algorithm for the current application scenario.

[0051] Furthermore, the performance evaluation index and security evaluation index obtained by processing each target algorithm further include: extracting the critical brute-force cracking times, critical successful cracking time, and critical vulnerability number from the data encryption database according to the number of brute-force cracking times, the time required for successful cracking, and the number of vulnerabilities within the encryption operation cycle of each target algorithm, and comprehensively analyzing to obtain the security evaluation index of each target algorithm. The security evaluation index of each target algorithm is used to quantitatively evaluate the security level of each target algorithm, providing a basis for evaluating the comprehensive energy efficiency of each target algorithm.

[0052] In a specific embodiment, the numerical expression of the security evaluation index of each target algorithm is:

[0053] ;

[0054] In the formula, represents the security evaluation index of the r-th target algorithm, represents the number of brute-force cracking times for the r-th target algorithm, represents the number of vulnerabilities of the r-th target algorithm within the encryption operation cycle, represents the time required for successful brute-force cracking of the r-th target algorithm, represents the critical brute-force cracking times, represents the critical vulnerability number, represents the critical successful cracking time, represents the algorithm security impact factor corresponding to the preset number of brute-force cracking times, represents the algorithm security impact factor corresponding to the preset successful cracking time, Represents the algorithm security impact factor corresponding to the preset number of vulnerabilities.

[0055] It should be understood that from the above embodiments, when the number of brute-force cracking attempts of the target algorithm is more, the time required for successful cracking is longer, and the number of vulnerabilities of the target algorithm is smaller, the corresponding security evaluation index of the target algorithm is larger, indicating that the encryption security performance of the target algorithm is better.

[0056] Table 1 Data example of the security evaluation index of the target algorithm

[0057]

[0058] In a specific embodiment, the critical number of brute-force cracking attempts is set to 1,000,000 times, the critical successful cracking time is set to 60 seconds, the critical number of vulnerabilities is set to 5, the algorithm security impact factor corresponding to the number of brute-force cracking attempts is set to 0.5, the algorithm security impact factor corresponding to the successful cracking time is set to 0.3, and the algorithm security impact factor corresponding to the number of vulnerabilities is set to 0.2.

[0059] It should be explained that in this embodiment Is the algorithm security impact factor corresponding to the preset number of brute-force cracking attempts, representing the numerical value of the impact degree of the number of brute-force cracking attempts on the security of the target algorithm. When used, the algorithm security impact factor corresponding to the number of brute-force cracking attempts can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the number of brute-force cracking attempts of the target algorithm and the algorithm security impact factor corresponding to the preset number of brute-force cracking attempts in the data encryption database form a mapping set, and the real-time number of brute-force cracking attempts is input into the mapping set to obtain the algorithm security impact factor corresponding to the number of brute-force cracking attempts, where the mapping relationship can be one-to-one or many-to-one.

[0060] It should be explained that in this embodiment Is the algorithm security impact factor corresponding to the preset successful cracking time, representing the numerical value of the impact degree of the successful cracking time on the security of the target algorithm. When used, the algorithm security impact factor corresponding to the successful cracking time can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the successful cracking time of the target algorithm for brute-force cracking and the algorithm security impact factor corresponding to the preset successful cracking time in the data encryption database form a mapping set, and the real-time successful cracking time is input into the mapping set to obtain the algorithm security impact factor corresponding to the successful cracking time, where the mapping relationship can be one-to-one or many-to-one.

[0061] It should be explained that in this embodiment It is the algorithm security impact factor corresponding to the preset number of vulnerabilities, which represents the numerical value of the impact degree of the number of vulnerabilities on the security of the target algorithm. When in use, the algorithm security impact factor corresponding to the number of vulnerabilities can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the number of vulnerabilities of the target algorithm and the algorithm security impact factor corresponding to the preset number of vulnerabilities in the data encryption database form a mapping set, and the real-time number of vulnerabilities is input into the mapping set to obtain the algorithm security impact factor corresponding to the number of vulnerabilities, where the mapping relationship can be one-to-one or many-to-one.

[0062] It should be explained that the above impact factors are all extracted from the data encryption database, and their value ranges are all between 0 and 1.

[0063] It should be explained that the number of brute-force cracking attempts refers to the number of attempts to try all possible password combinations, which depends on the complexity and length of the password. In theory, any password can be found through brute-force cracking, it's just a matter of time. The longer the password and the higher the complexity, the more attempts are required for brute-force cracking, and the higher the security. The number of brute-force cracking attempts is usually calculated based on the complexity of the password (including character type, length, etc.). For example, a 6-digit password consisting entirely of numbers may have 1 million combinations, that is, 1 million attempts are required. The time required for successful cracking is directly related to the number of brute-force cracking attempts and is also affected by computing resources (such as CPU, GPU). As the password complexity increases, the cracking time grows exponentially. The time required for successful password cracking can be obtained through simulation experiments. For example, using a cluster for cracking, billions of attacks can be performed per second, thereby calculating the approximate time required to crack a specific password. The number of vulnerabilities within the encryption operation cycle refers to the number of defects or weaknesses in the encryption algorithm itself discovered during this cycle. These vulnerabilities may be exploited by attackers to bypass encryption protection and directly obtain plaintext information. The number of vulnerabilities is usually obtained through security research, vulnerability disclosure platforms, or professional security tests. In the design and implementation process of the encryption algorithm, the number of vulnerabilities should be minimized as much as possible, and regular security audits and updates should be carried out.

[0064] Obtain the basic characteristic data of the data to be encrypted, and through processing, obtain the data demand performance parameters and data demand security parameters of the data to be encrypted.

[0065] Specifically, the basic characteristic data of the data to be encrypted includes the byte length and basic security requirement data.

[0066] The basic security requirement data specifically includes the number of systems allowed to access the data to be encrypted and the historical cumulative access times.

[0067] It is important to explain that the size of the data directly affects the complexity and time required for encryption operations. Larger data sets generally require more computing resources to complete the encryption process. Large files or data streams may require the use of more efficient encryption algorithms or hardware acceleration technology to increase encryption speed.

[0068] It should be understood that the above embodiment can quantify the ability of the algorithm to resist brute force cracking by recording the number of brute force cracking and the time required for successful cracking. The critical number of brute force cracking and the critical successful cracking time provide the security performance boundary of the algorithm under extreme conditions, which helps to evaluate the performance of the algorithm when facing high-intensity attacks. At the same time, monitoring the number of vulnerabilities in the encryption operation cycle and extracting the critical number of vulnerabilities can reflect the security weaknesses that may exist in the algorithm during implementation and deployment. This helps to identify and repair potential security vulnerabilities in a timely manner and improve the overall security of the algorithm. Based on the security assessment index, targeted security reinforcement strategies can be formulated. For example, for algorithms that are easily cracked by brute force, measures such as increasing password complexity and limiting the number of login attempts can be taken to improve their security; for algorithms with more vulnerabilities, code review and vulnerability repair work are required. The above embodiment can more accurately evaluate the security risks of algorithms in different application scenarios through quantitative evaluation of algorithm security. This helps enterprises and organizations to fully consider security factors when making business decisions and avoid serious consequences such as data leakage and system control caused by insufficient algorithm security. In the process of algorithm design and optimization, it is often necessary to make a trade-off between performance and security.

[0069] Furthermore, the data requirement performance parameters and data requirement security parameters of the data to be encrypted are obtained after processing. The specific process is: according to the byte length of the data to be encrypted, the data requirement performance parameters corresponding to the byte length interval are extracted from the data encryption database. The data requirement performance parameters of the data to be encrypted are used to quantitatively evaluate the performance requirements of the data to be encrypted for the encryption system, and provide a basis for evaluating the comprehensive energy efficiency evaluation indicators of each target algorithm.

[0070] It should be understood that the larger the byte length of the data to be encrypted, the larger the corresponding data requirement performance parameter of the data to be encrypted.

[0071] According to the number of systems allowed to access the data to be encrypted and the historical cumulative number of accesses, the critical number of systems allowed to access the data and the critical historical cumulative number of accesses are extracted from the data encryption database, and the data requirement security parameters of the data to be encrypted are obtained through comprehensive analysis. The data requirement security parameters of the data to be encrypted are used to quantitatively evaluate the security of the data to be encrypted, and provide a basis for evaluating the comprehensive energy efficiency evaluation indicators of each target algorithm.

[0072] It should be explained that in this embodiment, the number of allowed access systems for the data to be encrypted refers to the number of systems or applications authorized to access the data to be encrypted. This number is usually set by the data owner or administrator according to business requirements and security policies. The purpose is to limit the scope of data access and ensure that only authorized systems or applications can access sensitive data, thereby improving data security and confidentiality. This can be achieved through methods such as data access control policies, access control lists, or role-based access control. The historical cumulative access count of the data to be encrypted refers to the total number of times the data to be encrypted has been accessed by different systems, applications, or users since its creation or the setting of access permissions. This indicator reflects the popularity, usage frequency, and potential security risks of the data. The purpose is to help the data owner or administrator understand the access situation of the data, evaluate the security status of the data, and adjust the access control policy or strengthen data protection measures accordingly. The historical cumulative access count is usually statistically analyzed through log records, monitoring tools, or data analysis platforms. These tools can record information such as the time, source, and operation type of each access and generate corresponding reports or charts for analysis.

[0073] In a specific embodiment, the numerical expression of the data requirement security parameter of the data to be encrypted is:

[0074] ;

[0075] In the formula, represents the data requirement security parameter of the data to be encrypted, e represents the natural constant, represents the number of allowed access systems for the data to be encrypted, represents the historical cumulative access count of the data to be encrypted, represents the critical number of allowed access systems, represents the critical historical cumulative access count, represents the data requirement security impact factor corresponding to the preset number of allowed access systems, represents the data requirement security impact factor corresponding to the preset historical cumulative access count.

[0076] It should be understood that the more the number of allowed access systems for the data to be encrypted and the fewer the historical cumulative access count of the data to be encrypted, the greater the corresponding data requirement security parameter of the data to be encrypted, indicating better data security of the data to be encrypted.

[0077] In a specific embodiment, the critical number of permitted access systems is set to 10, the critical cumulative number of historical accesses is set to 100, the security impact factor of the data encryption requirement corresponding to the number of permitted access systems is set to 0.5, and the security impact factor of the data encryption requirement corresponding to the cumulative number of historical accesses is set to 0.5.

[0078] It should be understood that, as Figure 2 shown, curve a represents the relationship between the cumulative number of historical accesses of the data to be encrypted and the security parameter of the data encryption requirement of the data to be encrypted when the number of permitted access systems for the data to be encrypted is 5, curve b represents the relationship between the cumulative number of historical accesses of the data to be encrypted and the security parameter of the data encryption requirement of the data to be encrypted when the number of permitted access systems for the data to be encrypted is 15, and curve c represents the relationship between the cumulative number of historical accesses of the data to be encrypted and the security parameter of the data encryption requirement of the data to be encrypted when the number of permitted access systems for the data to be encrypted is 25.

[0079] It should be explained that in this embodiment is the security impact factor of the data encryption requirement corresponding to the preset number of permitted access systems, which represents the numerical value of the impact degree of the number of permitted access systems on the security of the data to be encrypted. When in use, the security impact factor of the data encryption requirement corresponding to the number of permitted access systems can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the number of permitted access systems of the data to be encrypted and the security impact factor of the data encryption requirement corresponding to the preset number of permitted access systems in the data encryption database form a mapping set, and the real-time number of permitted access systems is input into the mapping set to obtain the security impact factor of the data encryption requirement corresponding to the number of permitted access systems, and the mapping relationship therein can be one-to-one or many-to-one.

[0080] It should be explained that in this embodiment is the security impact factor of the data encryption requirement corresponding to the preset cumulative number of historical accesses, which represents the numerical value of the impact degree of the cumulative number of historical accesses on the security of the data to be encrypted. When in use, the security impact factor of the data encryption requirement corresponding to the cumulative number of historical accesses can be directly obtained from the data encryption database, and its corresponding relationship can be a pre-set mapping relationship. For example, the cumulative number of historical accesses of the data to be encrypted and the security impact factor of the data encryption requirement corresponding to the preset cumulative number of historical accesses in the data encryption database form a mapping set, and the real-time cumulative number of historical accesses is input into the mapping set to obtain the security impact factor of the data encryption requirement corresponding to the cumulative number of historical accesses, and the mapping relationship therein can be one-to-one or many-to-one.

[0081] It should be noted that the above influence factors are all extracted from the data encryption database, and their value ranges are all between 0 and 1.

[0082] It should be noted that in most data management systems, there is an access control list or a similar mechanism to define which systems or users are authorized to access specific data. By querying this list, the number of systems authorized to access the data to be encrypted can be obtained. Similar to the query of the access control list, the log file is also an important source for obtaining historical access records. By analyzing the log file, the cumulative number of accesses to the data to be encrypted over a certain period of time can be counted. There are many third-party website traffic and access analysis tools on the market (such as Google Analytics, StatCounter, etc.), and these tools usually provide rich data analysis and reporting functions. If the access records of the data to be encrypted are captured by these tools, then the historical cumulative number of accesses can be obtained through these tools.

[0083] According to the data demand performance parameter and data demand security parameter of the data to be encrypted, as well as the performance evaluation index and security evaluation index of each target algorithm, the comprehensive energy efficiency evaluation index of each target algorithm is comprehensively analyzed. According to the comprehensive energy efficiency evaluation index of each target algorithm, the encryption algorithm is screened, and the screening result is obtained and fed back.

[0084] Specifically, the process of comprehensively analyzing to obtain the comprehensive energy efficiency evaluation index of each target algorithm is as follows: According to the data demand performance parameter and data demand security parameter of the data to be encrypted, as well as the performance evaluation index and security evaluation index of each target algorithm, the comprehensive energy efficiency evaluation index of each target algorithm is comprehensively analyzed. The comprehensive energy efficiency evaluation index of each target algorithm is used to quantitatively evaluate the comprehensive energy efficiency of each target algorithm.

[0085] In a specific embodiment, the numerical expression of the comprehensive energy efficiency evaluation index of each target algorithm is:

[0086] ;

[0087] In the formula, represents the comprehensive energy efficiency evaluation index of the r-th target algorithm, represents the performance evaluation index of the r-th target algorithm, represents the security evaluation index of the r-th target algorithm, represents the data demand performance parameter of the data to be encrypted, represents the data demand security parameter of the data to be encrypted.

[0088] It should be understood that in this embodiment, when the performance evaluation index and the security evaluation index of the target algorithm are larger, the corresponding comprehensive energy efficiency evaluation index of the target algorithm is larger, indicating that the comprehensive energy efficiency of the target algorithm is better. The data demand performance parameter and the data demand security parameter of the data to be encrypted respectively represent the influence degree of the performance evaluation index and the security evaluation index of the target algorithm on the comprehensive energy efficiency evaluation index of the target algorithm, which is equivalent to the role of a weight factor.

[0089] It should be explained that in the above embodiment, by analyzing the data demand performance parameters of the data to be encrypted, such as processing speed, throughput, etc., it can be ensured that the selected algorithm can meet the requirements of the actual application scenario in terms of performance. This avoids system bottlenecks or latency problems caused by insufficient algorithm performance. Similarly, by analyzing the data demand security parameters, it can be ensured that the selected algorithm meets or exceeds the expected security standards in terms of security. This helps to protect sensitive data from the risks of unauthorized access and leakage. By comprehensively considering the performance and security evaluation indexes of the algorithm, an algorithm that is more efficient in resource utilization can be selected. This helps to reduce the waste of system resources, improve the overall efficiency and response speed. On the premise of meeting the performance and security requirements, selecting an algorithm with a higher comprehensive energy efficiency evaluation index helps to reduce the costs of system construction and operation and maintenance. This includes multiple aspects such as hardware investment, energy consumption, and labor costs. By comprehensively evaluating and selecting the most suitable algorithm, the risk of system failures caused by algorithm defects or deficiencies can be reduced. This helps to improve the stability and reliability of the system, ensuring business continuity and data integrity. Good system stability and reliability can enhance the user experience. The comprehensive energy efficiency evaluation index can be used as a reference for algorithm optimization and improvement. By continuously iterating and optimizing the algorithm, its comprehensive energy efficiency evaluation index can be improved to meet higher-level requirements and challenges. The comprehensive energy efficiency evaluation index also provides an objective and comprehensive reference for decision-makers. This helps decision-makers to more accurately judge the advantages and disadvantages of each target algorithm, and thus make more scientific and reasonable decisions.

[0090] Furthermore, screening the encryption algorithms according to the comprehensive energy efficiency evaluation indexes of each target algorithm, obtaining a screening result and giving feedback. The specific screening process is as follows: Sort the comprehensive energy efficiency evaluation indexes of each target algorithm in ascending order to obtain the comprehensive energy efficiency evaluation index sequence of each target algorithm. Extract the target algorithm with the largest comprehensive energy efficiency evaluation index among each target algorithm, and mark it as the optimal algorithm of this test system.

[0091] The second aspect of the present invention provides an apparatus for a network security protection encryption method, characterized in that it includes: a processor, a memory connected to the processor, and a network interface; the network interface is connected to a non-volatile memory in a server; when running, the processor retrieves a computer program from the non-volatile memory through the network interface and runs the computer program through the memory to execute the above method.

[0092] In a specific embodiment, the data encryption database is used to store relevant data during the data encryption process, specifically including the critical encryption speed, the critical consumption of each resource, the critical data throughput, the algorithm security impact factor corresponding to the number of brute-force cracking attempts, the algorithm security impact factor corresponding to the successful cracking time, and the algorithm security impact factor corresponding to the number of vulnerabilities, etc., the data obtained from the data encryption database in the above embodiments. The data in the database can search and encrypt the encrypted data through searchable encryption technology, access the encrypted data through an identity authentication and access control mechanism, and obtain the plaintext data through the decryption process. In addition, cloud database services and third-party encryption tools can also be used to simplify the storage, search, and access processes of encrypted data.

[0093] The above content is only an example and explanation of the structure of the present invention. Those skilled in the art of the present technology can make various modifications or supplements to the described specific embodiments or use similar methods for substitution, as long as they do not deviate from the structure of the invention or exceed the scope defined by the claims of the present invention, they should all fall within the protection scope of the present invention.

Claims

1. A network security protection encryption method, characterized in that: include: Obtain the data to be tested and the encryption algorithm, mark them as target algorithms, and use the target algorithms to encrypt and decrypt the data to be tested, collect the test data of the target algorithms, including performance data and security data, and obtain the performance evaluation index and security evaluation index of the target algorithms after processing; Obtain basic characteristic data of the data to be encrypted, and obtain data requirement performance parameters and data requirement security parameters of the data to be encrypted after processing; According to the data requirement performance parameters and data requirement security parameters of the data to be encrypted and the performance evaluation index and security evaluation index of each target algorithm, a comprehensive analysis is performed to obtain the comprehensive energy efficiency evaluation index of each target algorithm, and encryption algorithms are screened according to the comprehensive energy efficiency evaluation index of each target algorithm to obtain the screening results and provide feedback; The performance evaluation index and security evaluation index of each target algorithm obtained through processing specifically include: According to the encryption speed, resource consumption and data throughput at each time monitoring point in the encryption operation cycle, the critical encryption speed, critical resource consumption and critical data throughput are extracted from the data encryption database, and the performance evaluation index of each target algorithm is obtained through comprehensive analysis; According to the number of brute force cracking attempts on each target algorithm, the time required for successful cracking, and the number of vulnerabilities in the encryption operation cycle, the critical number of brute force cracking attempts, the critical successful cracking time, and the critical number of vulnerabilities are extracted from the data encryption database, and the security assessment index of each target algorithm is obtained through comprehensive analysis. The data requirement performance parameters and data requirement security parameters of the data to be encrypted are obtained through processing, and the specific process is: According to the byte length of the data to be encrypted, the data requirement performance parameter corresponding to the byte length interval is extracted from the data encryption database; According to the number of systems allowed to access the data to be encrypted and the historical cumulative number of accesses, the critical number of systems allowed to access the data and the critical historical cumulative number of accesses are extracted from the data encryption database, and the data security parameters required for the data to be encrypted are obtained through comprehensive analysis; The comprehensive analysis obtains the comprehensive energy efficiency evaluation index of each target algorithm. The specific analysis process is as follows: According to the data requirement performance parameters and data requirement security parameters of the data to be encrypted and the performance evaluation index and security evaluation index of each target algorithm, a comprehensive analysis is performed to obtain the comprehensive energy efficiency evaluation index of each target algorithm.

2. According to claim 1, a network security protection encryption method is characterized by: The test data of each target algorithm is collected, including performance data and security data, and the specific process is as follows: Deploy several time monitoring points to collect test data during the period when each target algorithm performs encryption and decryption operations on the test data, including performance data and security data; The performance data includes the encryption speed at each time monitoring point in the encryption operation cycle, the resource consumption in the encryption operation cycle and the data throughput, wherein the resource consumption in the encryption operation cycle includes the CPU usage rate, memory occupancy rate, disk occupancy rate and network IO occupancy rate; The security data includes the number of brute force cracking attempts on each target algorithm and the time required for successful cracking, as well as the number of loopholes in the encryption operation cycle.

3. According to claim 2, a network security protection encryption method is characterized in that: The performance evaluation index and the safety evaluation index of each target algorithm obtained through processing also include: The performance evaluation index of each target algorithm is used to quantitatively evaluate the performance of each target algorithm and provide a basis for evaluating the comprehensive energy efficiency of each target algorithm.

4. According to claim 2, a network security protection encryption method is characterized by: The performance evaluation index and the safety evaluation index of each target algorithm obtained through processing also include: The security evaluation index of each target algorithm is used to quantitatively evaluate the security level of each target algorithm and provide a basis for evaluating the comprehensive energy efficiency of each target algorithm.

5. According to claim 1, a network security protection encryption method is characterized by: The basic characteristic data of the data to be encrypted, including byte length and basic security requirement data; The basic security requirement data specifically includes the number of systems that are allowed to access the data to be encrypted and the historical cumulative number of accesses.

6. A network security protection encryption method according to claim 5, characterized in that: The data requirement performance parameter and data requirement security parameter of the data to be encrypted obtained through processing also include: The data requirement performance parameter of the data to be encrypted is used to quantitatively evaluate the performance requirement of the data to be encrypted on the encryption system, and provide a basis for evaluating the comprehensive energy efficiency evaluation index of each target algorithm; The data requirement security parameter of the data to be encrypted is used to quantitatively evaluate the security of the data to be encrypted, and provides a basis for evaluating the comprehensive energy efficiency evaluation index of each target algorithm.

7. A network security protection encryption method according to claim 6, characterized in that: The comprehensive analysis obtains comprehensive energy efficiency evaluation indicators of each target algorithm, including: The comprehensive energy efficiency evaluation index of each target algorithm is used to quantitatively evaluate the comprehensive energy efficiency of each target algorithm.

8. A network security protection encryption method according to claim 7, characterized in that: The encryption algorithm is screened according to the comprehensive energy efficiency evaluation index of each target algorithm, the screening result is obtained and feedback is given, and the specific screening process is as follows: The comprehensive energy efficiency evaluation indicators of each target algorithm are sorted in ascending order to obtain the comprehensive energy efficiency evaluation indicator sequence of each target algorithm, and the target algorithm with the largest comprehensive energy efficiency evaluation indicator among the target algorithms is extracted and marked as the optimal algorithm of the test system.

9. A network security protection encryption method according to claim 7, characterized in that: The comprehensive energy efficiency evaluation index of each target algorithm is expressed as follows: ; In the formula, represents the comprehensive energy efficiency evaluation index of the rth target algorithm, represents the performance evaluation index of the rth target algorithm, represents the security evaluation index of the rth target algorithm, represents the data requirement performance parameter of the data to be encrypted, The data security parameter that represents the data to be encrypted.

10. A device for applying a network security protection encryption method as described in any one of claims 1 to 9, characterized in that: include: Processor and memory and network interfaces connected to the processor; The network interface is connected to a non-volatile memory in the server; When running, the processor retrieves a computer program from the non-volatile memory through the network interface, and runs the computer program through the memory to execute the method described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • An information network security protection method for encrypted https protocol

    CN114389809B

  • A computer network security protection method and system using quantum encryption

    CN117294537B

  • Performance evaluation method of encryption algorithm and storage medium

    CN112039730A