An Encryption Communication Method and System for Multi-Application Environment with User Privacy Protection
The method and system provide secure and flexible encryption in multi-application environments by identifying risk factors, determining data attributes and topology, and applying multi-level attack strength-based encryption to protect user privacy.
Patent Information
- Application Number
- CN202411573973.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-11-06
AI Technical Summary
In a multi-application environment, user privacy data faces the risk of leakage and theft. Traditional communication encryption methods cannot adapt to the characteristics and needs of different applications, resulting in low security and inflexibility.
By identifying the risk factors and risk factors in the application environment, determining the topological relationship of unit data and multi-level attack strength, and reasonably choosing encrypted communication methods to protect user privacy data.
It improves the security and flexibility of user privacy data communication and adapts to the communication needs and characteristics of different application environments.
Smart Images

Figure CN119382995B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to an encrypted communication method and system for user privacy protection in a multi-application environment. Background Art
[0002] Currently, with the rapid development of information technology, people conduct a large amount of information interaction in different application environments. However, in a multi-application environment, users' privacy faces many risks and challenges;
[0003] On the one hand, different applications may collect and process a large amount of user data. If this data is not properly protected, it is easily leaked or misused. On the other hand, the network environment is becoming increasingly complex, and security threats such as hacker attacks and data theft always exist;
[0004] However, traditional communication encryption methods may have limitations in multi-application scenarios. For example, they cannot well adapt to the characteristics and requirements of different applications, or the encryption security is not high enough and not flexible enough, etc., resulting in the leakage or theft of users' private data during communication, greatly reducing the communication security;
[0005] Therefore, the present invention provides an encrypted communication method and system for user privacy protection in a multi-application environment. Summary of the Invention
[0006] The present invention provides an encrypted communication method and system for user privacy protection in a multi-application environment, which is used to identify the types and risk coefficients of risk factors in the current application environment, so as to facilitate the evaluation of the degree of attack on communication data by different risk factors. At the same time, the privacy data to be communicated is analyzed to determine the topological relationship between different unit data, so as to accurately and effectively determine the multi-level attack intensity of each unit data. Finally, based on the multi-level attack intensity of the unit data being attacked by risk factors in the current application environment, a reasonable encrypted communication method for the privacy data to be communicated is determined, and different encrypted communication methods are used for different application environments to achieve the privacy protection of users, improve the security of users' private data communication, and at the same time, improve the flexibility of encrypting communication data in different application environments, greatly adapting to the communication requirements and characteristics in different application environments.
[0007] The present invention provides an encrypted communication method for user privacy protection in a multi-application environment, including:
[0008] Step 1: Identify the existing risk factors and types in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system;
[0009] Step 2: Receive the privacy data to be communicated, parse the privacy data to be communicated, and determine the data attributes of each unit data in the privacy data to be communicated and the topological relationship between all unit data;
[0010] Step 3: Determine the multi-level attack intensity of the current application environment on each unit data based on the type, risk coefficient of risk factors in the current application environment, and the data attributes and topological relationship of each unit data;
[0011] Step 4: Determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the privacy data to be communicated based on the encrypted communication method.
[0012] Preferably, for a multi-application environment encrypted communication method for user privacy protection, in step 1, identifying the existing risk factors and types in the current application environment, including:
[0013] Obtain the environmental composition of the current application environment, and determine the detection dimension for detecting risks in the current application environment based on the environmental composition;
[0014] Extract the detection object nodes corresponding to each detection dimension, and retrieve the corresponding detection protocols from the preset management library based on the detection dimension;
[0015] Globally traverse the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process operation status of each detection object node based on the global traversal result;
[0016] Obtain the risk factors existing in the current application environment based on the full-process operation status, and obtain the types of risk factors based on the status representations of the risk factors.
[0017] Preferably, for a multi-application environment encrypted communication method for user privacy protection, in step 1, evaluating the risk coefficient of each risk factor based on the communication knowledge system, including:
[0018] Obtain the communication knowledge system and risk coefficient evaluation indicators, and determine the influence range of each risk factor on communication based on the communication knowledge system;
[0019] Retrieve the historical data under the action of each risk factor from the corresponding preset database based on the influence range, and parse the historical data to obtain the communication anomaly characteristics caused by each risk factor;
[0020] Evaluate the risk levels of each risk factor respectively based on the communication anomaly characteristics according to the risk coefficient evaluation indicators, and obtain the corresponding sub-risk evaluation coefficients;
[0021] Determine the weights of each risk factor evaluation index based on the communication knowledge system, and comprehensively analyze the sub-risk evaluation coefficients of each risk factor under different risk factor evaluation indexes based on the weights to obtain the risk coefficient of each risk factor.
[0022] Preferably, a multi-application environment encrypted communication method for user privacy protection, obtaining the risk coefficient of each risk factor, includes:
[0023] Obtain the obtained risk coefficient and record the risk coefficient of each current risk factor;
[0024] Track the real-time status of each risk factor based on the recording result, and determine the status change trend of each risk factor over time based on the tracking result;
[0025] Dynamically adjust the weights of each risk factor evaluation index based on the status change trend, and synchronously update the risk coefficient of each risk factor based on the dynamic adjustment result.
[0026] Preferably, in step 2 of a multi-application environment encrypted communication method for user privacy protection, receive the privacy data to be communicated, and parse the privacy data to be communicated to determine the data attributes of each unit data in the privacy data to be communicated and the topological relationship between all unit data, including:
[0027] Receive the privacy data to be communicated, and parse the privacy data to be communicated to determine the data source of the privacy data to be communicated;
[0028] Build a data interaction channel between the main control center and the data source terminal based on the data source, and obtain the document specifications of the privacy data to be communicated based on the data interaction channel;
[0029] Determine the key summary of the privacy data to be communicated based on the document specifications, and obtain the data attributes of each unit data based on the key summary;
[0030] Analyze the basic parameter characterization of each unit data based on the data attributes to obtain the corresponding structure tree of each unit data, and determine the branch status of each unit data based on the structure tree;
[0031] Determine the data service execution logic between the branches of different unit data based on the branch status, and obtain the association relationship between different unit data based on the data service execution logic;
[0032] Visually display the association relationship to obtain the topological relationship between all unit data.
[0033] Preferably, in a multi-application environment encryption communication method for user privacy protection, in step 3, determining the multi-level attack intensity of the current application environment on each unit of data based on the type, risk coefficient of risk factors in the current application environment, and the data attributes and topological relationships of each unit of data, including:
[0034] Obtaining the type, risk coefficient of risk factors in the current application environment, and the data attributes of each unit of data. At the same time, obtaining the basic communication parameters of the current application environment, and constructing a virtual application environment of the current application environment in the computer based on the basic communication parameters;
[0035] Configuring the basic operating parameters of the virtual application environment in the running background of the computer based on the type and risk coefficient of risk factors, and obtaining the simulated communication environment of the current application environment based on the configuration result;
[0036] Performing simulated communication on each unit of data based on the simulated communication environment according to the data attributes of each unit of data, and obtaining the operation log of each unit of data in the simulated communication environment based on the simulated communication result;
[0037] Parsing the operation log to obtain the behavior state of each unit of data, and determining the state change threshold of each unit of data based on the behavior state;
[0038] Determining the attack range and attack traces of each unit of data based on the state change threshold, and analyzing the attack range and attack traces based on preset evaluation indicators to obtain the initial personalized attack intensity of the current application environment on each unit of data;
[0039] Obtaining the topological relationship between all units of data, and splitting the unit data with associated relationships into multiple unit data groups based on the topological relationship;
[0040] Determining the logical characteristics between the unit data in each unit data group based on the associated relationship, and determining the business dependence range between the unit data in each unit data group based on the logical characteristics;
[0041] Correcting the initial personalized attack intensity between the unit data in each unit data group based on the business dependence range, and obtaining the initial macro attack intensity of each unit data in the topological relationship based on the correction result;
[0042] Obtaining the multi-level attack intensity of each unit of data based on the initial personalized attack intensity and the initial macro attack intensity of each unit of data.
[0043] Preferably, in a multi-application environment encryption communication method for user privacy protection, in step 4, determining the encryption communication method for the communication privacy data to be transmitted based on the multi-level attack intensity, and performing encryption communication on the communication privacy data to be transmitted based on the encryption communication method, including:
[0044] Obtain the multi-level attack intensity of the current application environment for each unit of data, and determine the vulnerable data range and attack type of each unit of data based on the multi-level attack intensity;
[0045] Extract the target data segments within the vulnerable data range, and extract the basic parameters of the target data segments;
[0046] Determine the user permissions and application scenarios of each unit of data based on the basic parameters, and determine the generalization parameter range for the target data segments based on the user permissions and application scenarios;
[0047] Perform desensitization processing on the target data segments based on the generalization parameter range, and match the attack type of each unit of data with the reference encryption method comparison table to obtain the encrypted communication method for each unit of data;
[0048] Perform encrypted communication on the desensitized unit data based on the encrypted communication method.
[0049] Preferably, for a multi-application environment encrypted communication method for user privacy protection, in step 4, determining the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity includes:
[0050] Obtain the encrypted communication methods of the multi-level attack intensity for the privacy data to be communicated in different application environments, and perform simulation tests on the encrypted communication methods in different application environments in the computer;
[0051] Determine the encryption performance of the encrypted communication methods in different application environments based on the simulation test results, and record the application environments that meet the encryption performance and the corresponding encrypted communication methods;
[0052] Determine the mapping relationship between different application environments and encrypted communication methods based on the recording results, and construct a reference table for the encrypted communication methods of the privacy data to be communicated in different application environments based on the mapping relationship;
[0053] Feed back the obtained reference table of encrypted communication methods to the management terminal for recording and filing, and update the recorded objects in the reference table of encrypted communication methods in real time.
[0054] The present invention provides a multi-application environment encrypted communication system for user privacy protection, including:
[0055] A risk factor and risk coefficient determination module, configured to identify the risk factors and types existing in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system;
[0056] An attribute and topology relationship determination module, configured to receive the privacy data to be communicated, parse the privacy data to be communicated, and determine the data attributes of each unit data in the privacy data to be communicated and the topology relationship among all unit data;
[0057] An attack intensity determination module, configured to determine the multi-level attack intensity of the current application environment on each unit data based on the type of risk factors, the risk coefficient, the data attributes of each unit data, and the topology relationship in the current application environment;
[0058] An encrypted communication module, configured to determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the privacy data to be communicated based on the encrypted communication method.
[0059] Preferably, a multi-application environment encrypted communication system for user privacy protection, the risk factor and risk coefficient determination module includes:
[0060] A dimension determination unit, configured to obtain the environmental composition of the current application environment, and determine the detection dimension for performing risk detection on the current application environment based on the environmental composition;
[0061] A protocol determination unit, configured to extract the detection object nodes corresponding to each detection dimension, and retrieve the corresponding detection protocols from the preset management library based on the detection dimension;
[0062] A parameter determination unit, configured to globally traverse the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process running status of each detection object node based on the global traversal result;
[0063] A risk factor determination unit, configured to obtain the risk factors existing in the current application environment based on the full-process running status, and obtain the type of risk factors based on the status representation of the risk factors.
[0064] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0065] 1. By identifying the type and risk coefficient of risk factors in the current application environment, it is convenient to evaluate the attack degree of different risk factors on communication data. At the same time, the privacy data to be communicated is parsed to determine the topology relationship between different unit data, so as to accurately and effectively determine the multi-level attack intensity of each unit data. Finally, based on the multi-level attack intensity of the unit data being attacked by risk factors in the current application environment, the encrypted communication method of the privacy data to be communicated is reasonably determined, and different encrypted communication methods are used for different application environments to achieve the privacy protection of users, improve the security of user privacy data communication, and at the same time, improve the flexibility of encrypting communication data in different application environments, greatly adapting to the communication requirements and characteristics in different application environments.
[0066] 2. By determining the environmental composition of the current application environment, the detection dimensions for detecting hazards in the current application environment are determined. Secondly, the detection object nodes corresponding to each detection dimension are determined, and effective global traversal of the detection object nodes is achieved according to the detection protocol under the corresponding dimension, so as to accurately and effectively identify and determine the risk factors existing in the current application environment. Finally, the type of the risk factor is locked according to the state representation of the risk factor, which facilitates the subsequent determination of the attack intensity of the risk factor on the data.
[0067] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structure specifically pointed out in this application document.
[0068] The technical solution of the present invention will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings
[0069] The accompanying drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the accompanying drawings:
[0070] Figure 1 is a flowchart of a multi-application environment encryption communication method for user privacy protection in an embodiment of the present invention;
[0071] Figure 2 is a flowchart of step 1 in a multi-application environment encryption communication method for user privacy protection in an embodiment of the present invention;
[0072] Figure 3 is a structural diagram of a multi-application environment encryption communication system for user privacy protection in an embodiment of the present invention. Detailed Embodiments
[0073] The following describes the preferred embodiments of the present invention with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0074] Embodiment 1:
[0075] This embodiment provides a multi-application environment encryption communication method for user privacy protection, as Figure 1 shown, including:
[0076] Step 1: Identify the risk factors and types existing in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system;
[0077] Step 2: Receive the privacy data to be communicated, parse the privacy data to be communicated, and determine the data attributes of each unit data in the privacy data to be communicated and the topological relationship between all unit data;
[0078] Step 3: Determine the multi-level attack intensity of the current application environment on each unit data based on the type of risk factors, the risk coefficient, and the data attributes and topological relationship of each unit data in the current application environment;
[0079] Step 4: Determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the privacy data to be communicated based on the encrypted communication method.
[0080] In this embodiment, the risk factors refer to risk factors such as network congestion, vulnerabilities, malware, and equipment failures existing in the application environment.
[0081] In this embodiment, the communication knowledge system is known in advance and is used to record the composition of the communication mechanism and the impact of each risk factor on the communication effect, etc.
[0082] In this embodiment, the risk coefficient is used to characterize the impact of different risk factors on the privacy data to be communicated during the communication process. The larger the value, the greater the impact on the communication.
[0083] In this embodiment, the privacy data to be communicated refers to the data that needs to be encrypted and transmitted.
[0084] In this embodiment, the unit data refers to the data sequence in the privacy data to be communicated.
[0085] In this embodiment, the data attribute refers to information such as the data type corresponding to the single data, the transmission security requirements corresponding during the transmission process, and the corresponding component composition, etc.
[0086] In this embodiment, the topological relationship refers to the interaction relationship and association relationship, etc. between all unit data.
[0087] In this embodiment, the multi-level attack intensity refers to the attack intensity that each unit data suffers respectively in the application environment and the attack intensity that each unit data suffers under the action of the topological relationship determined according to the type of risk factors, the risk coefficient, and the data attributes and topological relationship of each unit data.
[0088] In this embodiment, the encrypted communication method is determined according to the multi-level attack intensity and includes other encryption methods such as asymmetric encryption.
[0089] The working principle and beneficial effects of the above technical solution are as follows: By identifying the types and risk coefficients of risk factors in the current application environment, it is convenient to evaluate the degree of attack on communication data caused by different risk factors. At the same time, the communication privacy data to be processed is analyzed to determine the topological relationship between different unit data, so as to accurately and effectively determine the multi-level attack intensity of each unit data. Finally, based on the multi-level attack intensity of the unit data being attacked by risk factors in the current application environment, the encrypted communication method for the communication privacy data to be processed is reasonably determined, and different encrypted communication methods are used for different application environments to achieve the privacy protection of users, improve the security of user privacy data communication, and at the same time, improve the flexibility of encrypting communication data in different application environments, greatly adapting to the communication requirements and characteristics in different application environments.
[0090] Embodiment 2
[0091] Based on Embodiment 1, this embodiment provides a multi-application environment encrypted communication method for user privacy protection, as Figure 2 shown. In step 1, identify the existing risk factors and their types in the current application environment, including:
[0092] Step 101: Obtain the environmental composition of the current application environment, and determine the detection dimensions for performing risk detection on the current application environment based on the environmental composition;
[0093] Step 102: Extract the detection object nodes corresponding to each detection dimension, and retrieve the corresponding detection protocols from the preset management library based on the detection dimensions;
[0094] Step 103: Perform a global traversal on the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process running status of each detection object node based on the global traversal result;
[0095] Step 104: Obtain the risk factors existing in the current application environment based on the full-process running status, and obtain the types of risk factors based on the status representations of the risk factors.
[0096] In this embodiment, the environmental composition refers to the components of the current application environment, including the network and hardware devices, etc.
[0097] In this embodiment, the detection dimension refers to the type of risk detection for the current application environment. For example, it can be the network operation status, whether there are device failures, and software compatibility, etc.
[0098] In this embodiment, the detection object node refers to the specific detection object corresponding to each detection dimension.
[0099] In this embodiment, the preset management library is set in advance and is used to store a variety of different detection protocols. Among them, the detection protocol refers to the methods and the degree of rigor required for performing risk detection under different detection dimensions, etc.
[0100] In this embodiment, global traversal refers to detecting all parameters or running links of the detection object node.
[0101] In this embodiment, the full-process running state refers to the running conditions corresponding to all running links of the detection object node.
[0102] In this embodiment, the state representation refers to the phenomena presented by risk factors. For example, it can be the specific fault conditions that occur in the device.
[0103] The working principle and beneficial effects of the above technical solution are as follows: By determining the environmental composition of the current application environment, the detection dimensions for performing risk detection on the current application environment are determined. Secondly, the detection object nodes corresponding to each detection dimension are determined, and effective global traversal of the detection object nodes is achieved according to the detection protocols under the corresponding dimensions, so as to accurately and effectively identify and determine the risk factors existing in the current application environment. Finally, the types of risk factors are locked according to the state representations of the risk factors, which provides convenience for determining the attack intensity of the risk factors on the data subsequently.
[0104] Embodiment 3:
[0105] Based on Embodiment 1, this embodiment provides a multi-application environment encryption communication method for user privacy protection. In step 1, the risk coefficient of each risk factor is evaluated based on the communication knowledge system, including:
[0106] Obtain the communication knowledge system and risk coefficient evaluation indicators, and determine the influence range of each risk factor on communication based on the communication knowledge system;
[0107] Based on the influence range, retrieve the historical data under the action of each risk factor from the corresponding preset database, and analyze the historical data to obtain the communication anomaly characteristics caused by each risk factor;
[0108] Based on the risk coefficient evaluation indicators, respectively evaluate the risk levels of each risk factor according to the communication anomaly characteristics, and obtain the corresponding sub-risk evaluation coefficients;
[0109] Determine the weights of each risk coefficient evaluation indicator based on the communication knowledge system, and comprehensively analyze the sub-risk evaluation coefficients of each risk factor under different risk coefficient evaluation indicators based on the weights to obtain the risk coefficient of each risk factor.
[0110] In this embodiment, the risk factor evaluation index is known in advance and is the standard and value requirement for evaluating the risk level of risk factors.
[0111] In this embodiment, the influence range refers to the influence types of different risk factors when communicating with respect to communication privacy data, such as network congestion and the like.
[0112] In this embodiment, the preset database is known in advance and is used to record the historical data corresponding to different risk factors, where the historical data is the specific operation situation corresponding to the communication privacy data during the communication process.
[0113] In this embodiment, the communication anomaly feature refers to the specific abnormal communication situation generated by the historical data under the influence of risk factors, such as the specific degree of delay or the amount of leaked data and the like.
[0114] In this embodiment, the sub-risk evaluation coefficient refers to the result obtained by respectively evaluating the risk situations of each risk factor through the risk factor evaluation index and the communication anomaly feature, that is, the evaluation result corresponding to each risk factor evaluation index.
[0115] The working principle and beneficial effects of the above technical solution are as follows: By accurately and effectively determining the influence range of each risk factor on communication according to the communication knowledge system and the risk factor evaluation index, secondly, retrieving the corresponding historical data from the corresponding database according to the influence range and analyzing the historical data to accurately and effectively determine the communication anomaly features caused by the risk factors to the communication data, and finally, accurately and effectively determining the risk coefficient of each risk factor according to the risk factor evaluation index and the communication anomaly feature, which provides a reference basis for determining the encrypted communication method for the communication privacy data to be communicated.
[0116] Embodiment 4:
[0117] Based on Embodiment 1, this embodiment provides a multi-application environment encrypted communication method for user privacy protection, obtaining the risk coefficient of each risk factor, including:
[0118] Obtain the obtained risk coefficient and record the risk coefficient of each current risk factor;
[0119] Track the real-time status of each risk factor based on the recording result, and determine the status change trend of each risk factor over time based on the tracking result;
[0120] Dynamically adjust the weights of each risk factor evaluation index based on the status change trend, and synchronously update the risk coefficient of each risk factor based on the dynamic adjustment result.
[0121] In this embodiment, the state change trend refers to the change in the severity of the impact of different risk factors on communication data during the communication process as the application environment changes.
[0122] The working principle and beneficial effects of the above technical solution are as follows: By real-time monitoring the real-time state of each risk factor, it is convenient to adjust the corresponding weight value in a timely manner when the state of the risk factor changes, thus ensuring the accuracy and reliability of the risk coefficients of each risk factor.
[0123] Embodiment 5:
[0124] Based on Embodiment 1, this embodiment provides a multi-application environment encryption communication method for user privacy protection. In step 2, receive the privacy data to be communicated, and parse the privacy data to be communicated to determine the data attributes of each unit data in the privacy data to be communicated and the topological relationship between all unit data, including:
[0125] Receive the privacy data to be communicated, and parse the privacy data to be communicated to determine the data source of the privacy data to be communicated;
[0126] Based on the data source, construct a data interaction channel between the main control center and the data source terminal, and obtain the document specifications of the privacy data to be communicated based on the data interaction channel;
[0127] Based on the document specifications, determine the key summary of the privacy data to be communicated, and obtain the data attributes of each unit data based on the key summary;
[0128] Analyze the basic parameter representations of each unit data based on the data attributes to obtain the structure tree corresponding to each unit data, and determine the branch state of each unit data based on the structure tree;
[0129] Based on the branch state, determine the data service execution logic between the branches of different unit data, and obtain the association relationship between different unit data based on the data service execution logic;
[0130] Visually display the association relationship to obtain the topological relationship between all unit data.
[0131] In this embodiment, the data source refers to the device terminal corresponding to the privacy data to be communicated.
[0132] In this embodiment, the data interaction channel is a communication link used to connect the main control center and the data source terminal.
[0133] In this embodiment, the document specifications refer to information such as the composition of the privacy data to be communicated obtained from the data source terminal.
[0134] In this embodiment, the key summary refers to the summary data information corresponding to the privacy data to be communicated.
[0135] In this embodiment, the basic parameter characterization refers to the specific value range corresponding to each unit of data, as well as information such as the corresponding data characteristics and composition.
[0136] In this embodiment, the structure tree refers to the display of the composition of each unit of data and the relationship between data in a structural manner.
[0137] In this embodiment, the branch state refers to the distribution and structure of each data component in each unit of data.
[0138] In this embodiment, the data service execution logic refers to the associated relationships, etc., existing between the branches of different units of data.
[0139] The working principle and beneficial effects of the above technical solution are as follows: By parsing the privacy data to be communicated, the data source of the privacy data to be communicated is effectively determined. At the same time, according to the determined data source, a data interaction channel between the main control center and the data source terminal is constructed, and the key summary of the privacy data to be communicated is determined from the data source terminal according to the data interaction channel. Secondly, according to the obtained key summary, the data attributes of each unit of data are locked, and the structure tree corresponding to each unit of data is determined according to the data attributes. Finally, according to the structure tree, the associated relationships between different units of data are determined, and the topological structure between different units of data is determined according to the associated relationships, which is convenient for determining the degree of being attacked by different units of data in the current application environment according to the topological structure, thereby facilitating reliable data encryption of the privacy data to be communicated.
[0140] Embodiment 6:
[0141] Based on Embodiment 1, this embodiment provides a multi-application environment encryption communication method for user privacy protection. In step 3, based on the type, risk coefficient of the risk factors in the current application environment, and the data attributes and topological relationships of each unit of data, the multi-level attack intensity of the current application environment on each unit of data is determined, including:
[0142] Obtain the type, risk coefficient of the risk factors in the current application environment, and the data attributes of each unit of data. At the same time, obtain the basic communication parameters of the current application environment, and construct a virtual application environment of the current application environment in the computer based on the basic communication parameters;
[0143] Configure the basic operating parameters of the virtual application environment in the operating background of the computer based on the type and risk coefficient of the risk factors, and obtain the simulated communication environment of the current application environment based on the configuration result;
[0144] Simulate the communication of each unit of data according to the data attributes of each unit of data based on a simulated communication environment, and obtain the operation log of each unit of data in the simulated communication environment based on the simulation communication result;
[0145] Parse the operation log to obtain the behavior state of each unit of data, and determine the state change threshold of each unit of data based on the behavior state;
[0146] Determine the attack range and attack trace of each unit of data based on the state change threshold, and analyze the attack range and attack trace based on a preset evaluation index to obtain the initial personalized attack intensity of the current application environment for each unit of data;
[0147] Obtain the topological relationship between all units of data, and split the units of data with an associated relationship into multiple units of data groups based on the topological relationship;
[0148] Determine the logical characteristics between the units of data in each unit of data group based on the associated relationship, and determine the business dependency range between the units of data in each unit of data group based on the logical characteristics;
[0149] Correct the initial personalized attack intensity between the units of data in each unit of data group based on the business dependency range, and obtain the initial macro attack intensity of each unit of data in the topological relationship based on the correction result;
[0150] Obtain the multi-level attack intensity of each unit of data based on the initial personalized attack intensity and the initial macro attack intensity of each unit of data.
[0151] In this embodiment, the basic communication parameters refer to the communication method, communication rate, network condition, etc. in the current application environment.
[0152] In this embodiment, the virtual application environment refers to constructing a virtual environment in the computer that is consistent with the current application environment, aiming to facilitate the determination of the influence of risk factors in the current application environment.
[0153] In this embodiment, the basic operation parameters refer to improving the parameters of the virtual application environment in the computer according to the type and risk coefficient of the risk factors, that is, constructing the corresponding risk factors and the risk degree of the risk factors in the virtual application environment.
[0154] In this embodiment, the operation log refers to the specific operation situation of each unit of data in the simulated communication environment.
[0155] In this embodiment, the behavior state refers to the specific communication situation presented by each unit of data under the influence of risk factors.
[0156] In this embodiment, the state change threshold refers to the specific procedure in which the communication situation of each unit of data changes under the influence of risk factors.
[0157] In this embodiment, the attack range and attack trace are used to characterize the data influence range caused by risk factors on each unit of data and the attack marks left when being attacked, facilitating the determination of the attack intensity on each unit of data.
[0158] In this embodiment, the preset evaluation index is known in advance and is used to analyze the attack range and attack trace to determine the initial personalized attack intensity of the current application environment on each unit of data. Among them, the initial personalized attack intensity refers to the attack situation of the current application environment on each unit of data without considering the association relationship between units of data.
[0159] In this embodiment, the unit data group refers to the grouping of units of data with an association relationship, that is, the units of data with an association relationship are divided into a group, so as to facilitate the determination of the initial macroscopic attack intensity of each unit of data in the topological relationship.
[0160] In this embodiment, the logical feature refers to the data association logic or business execution logic between each unit of data.
[0161] In this embodiment, the business dependence range refers to the degree of mutual limitation of data between the units of data in each unit data group, that is, the causal intensity of the result of each unit of data on the next unit of data.
[0162] In this embodiment, the initial macroscopic attack intensity refers to the attack intensity corresponding to each unit of data under the limitation of the current topological relationship after considering the initial personalized attack intensity of each unit of data in the topological relationship.
[0163] The working principle and beneficial effects of the above technical solution are as follows: By obtaining the basic communication parameters of the current application environment, a virtual application environment of the current application environment is constructed in the computer according to the basic communication parameters, which facilitates determining the attack intensity of different risk factors on unit data. Secondly, the specific parameters of the risk factors are perfectly configured in the virtual application environment, and after the perfect configuration, the unit data are simulated for communication according to the data attributes of each unit data. During the simulated communication, the running logs of each unit data in the simulated communication environment are obtained in real time, so as to facilitate the analysis of the running logs, determine the state change threshold of each unit data, and then lock the attack range and attack traces of each unit data according to the state change threshold. Finally, based on the attack range and attack traces, the initial personalized attack intensity of each unit data is accurately and reliably determined. At the same time, considering the topological relationship between all unit data, the initial personalized attack intensity of each unit data is corrected according to the topological relationship to determine the initial macroscopic attack intensity of each unit data in the topological relationship. Finally, the multi-level attack intensity of each unit data is obtained based on the initial personalized attack intensity and the initial macroscopic attack intensity of each unit data, which facilitates reasonably determining the encrypted communication method of the privacy data to be communicated, and greatly adapts to the communication requirements and characteristics in different application environments.
[0164] Embodiment 7:
[0165] Based on Embodiment 1, this embodiment provides a multi-application environment encrypted communication method for user privacy protection. In step 4, based on the determined multi-level attack intensity, the encrypted communication method for the privacy data to be communicated is determined, and the privacy data to be communicated is encrypted and communicated based on the encrypted communication method, including:
[0166] Obtain the multi-level attack intensity of the current application environment for each unit data, and determine the vulnerable data range and attack type of each unit data based on the multi-level attack intensity;
[0167] Extract the target data segments within the vulnerable data range, and extract the basic parameters of the target data segments;
[0168] Determine the user permissions and application scenarios of each unit data based on the basic parameters, and determine the generalization parameter interval for the target data segments based on the user permissions and application scenarios;
[0169] Perform desensitization processing on the target data segments based on the generalization parameter interval, and match the attack type of each unit data with the reference encryption method comparison table to obtain the encrypted communication method for each unit data;
[0170] Perform encrypted communication on the desensitized unit data based on the encrypted communication method.
[0171] In this embodiment, the vulnerable data range refers to the part of each unit of data that is vulnerable to attack in the current application environment.
[0172] In this embodiment, the target data segment refers to the specific data information corresponding within the vulnerable data range.
[0173] In this embodiment, the basic parameter refers to the core content of the target data segment and the problems that can be solved.
[0174] In this embodiment, the generalization parameter interval refers to the reference interval when generalizing the core content of the target data segment, that is, desensitizing the target data segment through the generalization parameter interval to reduce the attack intensity and attack sensitivity.
[0175] In this embodiment, the reference encryption method comparison table is set in advance and is used to record the encryption methods corresponding to different attack types.
[0176] The working principle and beneficial effects of the above technical solution are as follows: By analyzing the multi-level attack intensity, the vulnerable data range and attack type of each unit of data can be accurately and effectively determined. Secondly, according to the vulnerable data range, the corresponding target data segment is determined, and the generalization parameter interval for the target data segment is determined according to the basic parameters of the target data segment. Finally, the target data segment is desensitized according to the generalization parameter interval, effectively reducing the attack intensity and attack sensitivity. At the same time, according to the attack type of each unit of data, the encryption communication method is selected from the reference encryption method comparison table, and the encrypted communication of the desensitized unit data is realized according to the selected encryption communication method, improving the flexibility of encrypting communication data in different application environments and ensuring the security of user privacy data communication.
[0177] Embodiment 8:
[0178] Based on Embodiment 1, this embodiment provides a multi-application environment encrypted communication method for user privacy protection. In step 4, determining the encrypted communication method for the communication privacy data to be processed based on the multi-level attack intensity includes:
[0179] Obtain the encrypted communication methods for the communication privacy data to be processed under the multi-level attack intensity in different application environments, and conduct simulation tests on the encrypted communication methods in different application environments in the computer;
[0180] Based on the simulation test results, determine the encryption performance of the encrypted communication methods in different application environments, and record the application environments that meet the encryption performance and the corresponding encrypted communication methods;
[0181] Determine the mapping relationship between different application environments and encryption communication methods based on the recorded results, and construct a reference table for the encryption communication methods of the privacy data to be communicated in different application environments based on the mapping relationship;
[0182] Feed back the obtained reference table of encryption communication methods to the management terminal for record keeping, and update the recorded objects in the reference table of encryption communication methods in real time.
[0183] In this embodiment, the simulation test can be a performance test of the encryption communication method in different application environments in a computer, specifically including: encryption strength test, which is used to measure the difficulty of the encryption algorithm to resist cracking; encryption efficiency test, that is, the consumption of resources and processing speed during the encryption and decryption processes; encryption reliability test and encryption stability test, etc.
[0184] In this embodiment, the encryption performance can be used to describe the ability and effect of the encryption communication method in protecting data security, specifically including: encryption strength, encryption efficiency, and encryption reliability and encryption stability, etc.
[0185] In this embodiment, the application environment that meets the encryption performance may be that the encryption performance of the encryption communication method is different in different application environments. When the parameters involved in the encryption performance reach the preset threshold in the application environment, it is the application environment that meets the encryption performance. For example, when the encryption performance is encryption strength, when there is an application environment where the encryption strength is equal to or greater than the preset threshold, then this application environment is the application environment that meets the encryption performance.
[0186] In this embodiment, the mapping relationship may be information such as which encryption communication method performs best in different application environments, clarifying the corresponding relationship between different application environments (such as specific software, systems, scenarios, etc.) and the most suitable encryption communication method corresponding to the application environment.
[0187] In this embodiment, the reference table of encryption communication methods may list different application environments and the encryption communication methods that should be used for the privacy data to be communicated in different application environments in a table. The purpose of doing this is to be able to quickly and accurately find the most suitable encryption communication method according to the specific application environment to ensure the security and privacy of data in actual applications.
[0188] The working principle and beneficial effects of the above technical solution are as follows: By obtaining the encrypted communication methods for communication privacy data under multi-level attack intensities in different application environments and conducting simulation tests on the encrypted communication methods in different application environments in a computer, it is beneficial to determine the encryption performance of the encrypted communication methods in different application environments based on the simulation test results, record the application environments that meet the encryption performance and the corresponding encrypted communication methods, effectively determine the mapping relationship between different application environments and encrypted communication methods, and thus construct a reference table for the encrypted communication methods of communication privacy data in different application environments through the mapping relationship. By feeding back the obtained reference table for encrypted communication methods to the management terminal for record keeping and updating the recorded objects in the reference table for encrypted communication methods in real time, it not only effectively improves data security, ensures reliable protection of privacy data in various application environments, but also enhances the pertinence and efficiency of encryption, strengthens the overall security and stability of the system, and guarantees the smooth and secure communication in different application scenarios.
[0189] Embodiment 9:
[0190] This embodiment provides a multi-application environment encrypted communication system for user privacy protection, as Figure 3 shown, including:
[0191] A risk factor and risk coefficient determination module, configured to identify the risk factors and types existing in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system;
[0192] An attribute and topological relationship determination module, configured to receive the communication privacy data to be communicated, parse the communication privacy data to be communicated, and determine the data attributes of each unit data in the communication privacy data to be communicated and the topological relationship between all unit data;
[0193] An attack intensity determination module, configured to determine the multi-level attack intensity of the current application environment on each unit data based on the type, risk coefficient of the risk factors in the current application environment, and the data attributes and topological relationship of each unit data;
[0194] An encrypted communication module, configured to determine the encrypted communication method for the communication privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the communication privacy data to be communicated based on the encrypted communication method.
[0195] The working principle and beneficial effects of the above technical solution are: by identifying the types and risk factors of risk factors in the current application environment, it is convenient to evaluate the degree of attack caused by different risk factors on communication data. At the same time, the privacy data to be communicated is analyzed to determine the topological relationship between different unit data, so as to accurately and effectively determine the multi-level attack strength of each unit data. Finally, based on the multi-level attack strength of the unit data attacked by risk factors in the current application environment, the encryption communication method of the privacy data to be communicated is reasonably determined, so as to achieve user privacy protection through different encryption communication methods for different application environments, improve the security of user privacy data communication, and at the same time, improve the flexibility of encrypting communication data in different application environments, which greatly adapts to the communication needs and characteristics in different application environments.
[0196] Embodiment 10:
[0197] Based on Example 9, this embodiment provides a multi-application environment encrypted communication system for user privacy protection, and a risk factor and risk coefficient determination module, including:
[0198] A dimension determination unit, used to obtain the environment composition of the current application environment, and determine the detection dimension for performing danger detection on the current application environment based on the environment composition;
[0199] A protocol determination unit, used to extract the detection object node corresponding to each detection dimension, and retrieve the corresponding detection protocol from a preset management library based on the detection dimension;
[0200] A parameter determination unit, used to perform a global traversal of the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process operation status of each detection object node based on the global traversal result;
[0201] The risk factor determination unit is used to obtain the risk factors existing in the current application environment based on the full process operation status, and obtain the type of the risk factor based on the state representation of the risk factor.
[0202] The working principle and beneficial effects of the above technical solution are: by determining the environmental composition of the current application environment, the detection dimension for danger detection in the current application environment is determined; secondly, the detection object node corresponding to each detection dimension is determined, and an effective global traversal of the detection object node is achieved according to the detection protocol under the corresponding dimension, thereby achieving accurate and effective identification and determination of the dangerous factors existing in the current application environment; finally, the type of dangerous factors is locked according to the state representation of the dangerous factors, which provides convenience for the subsequent determination of the attack intensity of the dangerous factors on the data.
[0203] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A multi-application environment encryption communication method for user privacy protection, characterized in that, Including: Step 1: Identify the risk factors and their types existing in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system. Here, the risk coefficient is used to characterize the impact of different risk factors on communication privacy data during communication, and the larger the value, the greater the impact on communication; Step 2: Receive the communication privacy data to be transmitted, and parse the communication privacy data to be transmitted to determine the data attributes of each unit data in the communication privacy data to be transmitted and the topological relationship between all unit data. Here, the communication privacy data to be transmitted refers to the data that needs to be encrypted and transmitted, the unit data refers to the data sequence in the communication privacy data to be transmitted, the data attribute refers to the data type corresponding to the unit data, the transmission security requirements corresponding during the transmission process, and the corresponding component composition, and the topological relationship refers to the interaction relationship and association relationship between all unit data; Step 3: Determine the multi-level attack intensity of the current application environment on each unit data based on the type, risk coefficient of the risk factors in the current application environment, and the data attributes and topological relationship of each unit data; Step 4: Determine the encrypted communication method for the communication privacy data to be transmitted based on the multi-level attack intensity, and perform encrypted communication on the communication privacy data to be transmitted based on the encrypted communication method; Among them, in Step 3, determining the multi-level attack intensity of the current application environment on each unit data based on the type, risk coefficient of the risk factors in the current application environment, and the data attributes and topological relationship of each unit data includes: Obtain the type, risk coefficient of the risk factors in the current application environment, and the data attributes of each unit data. At the same time, obtain the basic communication parameters of the current application environment, and construct a virtual application environment of the current application environment in the computer based on the basic communication parameters. Here, the basic communication parameters refer to the communication method, communication rate, and network condition in the current application environment; Configure the basic operation parameters of the virtual application environment in the running background of the computer based on the type and risk coefficient of the risk factors, and obtain the simulated communication environment of the current application environment based on the configuration result. Here, the basic operation parameters refer to improving the parameters of the virtual application environment in the computer according to the type and risk coefficient of the risk factors, that is, constructing the corresponding risk factors and the risk degree of the risk factors in the virtual application environment; Perform simulated communication on each unit data based on the simulated communication environment according to the data attributes of each unit data, and obtain the operation log of each unit data in the simulated communication environment based on the simulated communication result; Parse the operation log to obtain the behavior state of each unit data, and determine the state change threshold of each unit data based on the behavior state; Determine the attack range and attack trace of each unit data based on the state change threshold, and analyze the attack range and attack trace based on the preset evaluation index to obtain the initial personalized attack intensity of the current application environment on each unit data; Obtain the topological relationship between all unit data, and split the unit data with an association relationship into multiple unit data groups based on the topological relationship; Determine the logical characteristics between each unit of data in each unit data group based on the association relationship, and determine the business dependence scope between each unit of data in each unit data group based on the logical characteristics; Modify the initial personalized attack intensity between each unit of data in each unit data group based on the business dependence scope, and obtain the initial macro attack intensity of each unit of data in the topological relationship based on the modification result; Obtain the multi-level attack intensity of each unit of data based on the initial personalized attack intensity and the initial macro attack intensity of each unit of data.
2. The multi-application environment encryption communication method for user privacy protection according to claim 1, characterized in that, In step 1, identify the existing risk factors and types in the current application environment, including: Obtain the environmental composition of the current application environment, and determine the detection dimension for detecting risks in the current application environment based on the environmental composition; Extract the detection object nodes corresponding to each detection dimension, and retrieve the corresponding detection protocol from the preset management library based on the detection dimension; Globally traverse the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process running status of each detection object node based on the global traversal result; Obtain the risk factors existing in the current application environment based on the full-process running status, and obtain the types of risk factors based on the status representation of the risk factors.
3. The multi-application environment encrypted communication method for user privacy protection according to claim 1, characterized in that, In step 1, evaluate the risk coefficient of each risk factor based on the communication knowledge system, including: Obtain the communication knowledge system and the risk coefficient evaluation indicators, and determine the influence scope of each risk factor on communication based on the communication knowledge system; Retrieve the historical data under the action of each risk factor from the corresponding preset database based on the influence scope, and analyze the historical data to obtain the communication anomaly characteristics caused by each risk factor; Evaluate the risk level of each risk factor respectively according to the communication anomaly characteristics based on the risk coefficient evaluation indicators, and obtain the corresponding sub-risk evaluation coefficients; Determine the weights of the risk coefficient evaluation indicators based on the communication knowledge system, and comprehensively analyze the sub-risk evaluation coefficients of each risk factor under different risk coefficient evaluation indicators based on the weights to obtain the risk coefficient of each risk factor.
4. A method for encrypted communication in a multi-application environment for user privacy protection according to claim 3, characterized in that, Obtain the risk coefficient of each risk factor, including: Obtain the obtained risk coefficient, and record the risk coefficient of each current risk factor; Track the real-time status of each risk factor based on the recording result, and determine the state change trend of each risk factor over time based on the tracking result; Dynamically adjust the weights of the risk coefficient evaluation indicators based on the state change trend, and synchronously update the risk coefficient of each risk factor based on the dynamic adjustment result.
5. A multi-application environment encryption communication method for user privacy protection according to claim 1, characterized in that, In step 2, receive the privacy data to be communicated, and analyze the privacy data to be communicated to determine the data attributes of each unit of data in the privacy data to be communicated and the topological relationship between all units of data, including: Receive the privacy data to be communicated, and analyze the privacy data to be communicated to determine the data source of the privacy data to be communicated; Build a data interaction channel between the main control center and the data source terminal based on the data source, and obtain the document specification of the privacy data to be communicated based on the data interaction channel, where the document specification refers to the component composition of the privacy data to be communicated obtained from the data source terminal; Determine the key summary of the privacy data to be communicated based on the document specifications, and obtain the data attributes of each unit data based on the key summary, where the key summary refers to the summary data information corresponding to the privacy data to be communicated; Analyze the basic parameter characterization of each unit data based on the data attributes, obtain the structure tree corresponding to each unit data, and determine the branch status of each unit data based on the structure tree, where the basic parameter characterization refers to the specific value range corresponding to each unit data, as well as the corresponding data characteristics and composition; Determine the data service execution logic between the branches of different unit data based on the branch status, and obtain the association relationship between different unit data based on the data service execution logic; Visualize the association relationship to obtain the topological relationship between all unit data.
6. A method for encrypted communication in a multi-application environment for user privacy protection according to claim 1, characterized in that, In step 4, determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the privacy data to be communicated based on the encrypted communication method, including: Obtain the multi-level attack intensity of each unit data in the current application environment, and determine the vulnerable data range and attack type of each unit data based on the multi-level attack intensity; Extract the target data segments within the vulnerable data range, and extract the basic parameters of the target data segments, where the basic parameters refer to the core content of the target data segments and the problems that can be solved; Determine the user permissions and application scenarios of each unit data based on the basic parameters, and determine the generalization parameter interval for the target data segments based on the user permissions and application scenarios; Perform desensitization processing on the target data segments based on the generalization parameter interval, and match the attack type of each unit data with the reference encryption method comparison table to obtain the encrypted communication method for each unit data; Perform encrypted communication on the desensitized unit data based on the encrypted communication method.
7. A multi-application environment encryption communication method for user privacy protection according to claim 1, characterized in that, In step 4, determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, including: Obtain the encrypted communication methods for the privacy data to be communicated under the multi-level attack intensity in different application environments, and perform simulation tests on the encrypted communication methods in different application environments in the computer; Determine the encryption performance of the encrypted communication methods in different application environments based on the simulation test results, and record the application environments that meet the encryption performance and the corresponding encrypted communication methods; Determine the mapping relationship between different application environments and encrypted communication methods based on the recorded results, and construct a reference table for the encrypted communication methods of the privacy data to be communicated in different application environments based on the mapping relationship; Feed back the obtained reference table of encrypted communication methods to the management terminal for record keeping, and update the recorded objects in the reference table of encrypted communication methods in real time.
8. A user privacy protection multi-application environment encrypted communication system for the method of user privacy protection in a multi-application environment according to claim 1, characterized in that, Including: A risk factor and risk coefficient determination module, which is used to identify the risk factors and types existing in the current application environment, and evaluate the risk coefficient of each risk factor based on the communication knowledge system; An attribute and topological relationship determination module, which is used to receive the privacy data to be communicated, analyze the privacy data to be communicated, and determine the data attributes of each unit data in the privacy data to be communicated and the topological relationship between all unit data; An attack intensity determination module, configured to determine the multi-level attack intensity of each unit data in the current application environment based on the type of risk factors, the risk coefficient, and the data attributes and topological relationships of each unit data in the current application environment; An encrypted communication module, configured to determine the encrypted communication method for the privacy data to be communicated based on the multi-level attack intensity, and perform encrypted communication on the privacy data to be communicated based on the encrypted communication method.
9. A multi-application environment encrypted communication system for user privacy protection according to claim 8, wherein, A risk factor and risk coefficient determination module, including: A dimension determination unit, configured to obtain the environmental composition of the current application environment, and determine the detection dimension for performing risk detection on the current application environment based on the environmental composition; A protocol determination unit, configured to extract the detection object nodes corresponding to each detection dimension, and retrieve the corresponding detection protocols from a preset management library based on the detection dimension; A parameter determination unit, configured to perform a global traversal on the detection object nodes corresponding to each detection dimension based on the detection protocol, and obtain the full-process operation status of each detection object node based on the global traversal result; A risk factor determination unit, configured to obtain the risk factors existing in the current application environment based on the full-process operation status, and obtain the types of risk factors based on the status representation of the risk factors.
Citation Information
Patent Citations
Network communication method, system and device based on virtual link enhanced confusion
CN117978522A
Computer network data storage encryption method and system
CN118194333A