An Internet data encryption method and system
Through distributed ledger and random key generation combined with abnormal behavior analysis, the problems of insufficient security and inflexible strategies in traditional encryption methods are solved, efficient and dynamic encryption of Internet data is achieved, and data integrity and security are ensured.
Patent Information
- Application Number
- CN202411796377.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Traditional encryption methods have security vulnerabilities in key management and policy adjustment, and cannot flexibly respond to changes in the network environment, and insufficient protection against data integrity and potential tampering risks during transmission.
The distributed ledger technology is used to store data, random number generator and multi-party secure calculations are used to generate random number keys, and the Internet abnormal behavior analysis model is used to combine the abnormal behavior analysis model to build a dynamic encryption strategy.
It improves the integrity and security of data, realizes accurate identification of abnormal traffic behavior and dynamic encryption configuration, and improves the security, dynamicity and reliability of Internet data encryption.
Smart Images

Figure CN119449471B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and in particular to an Internet data encryption method and system. Background Art
[0002] Traditional encryption methods (such as symmetric and asymmetric encryption) rely on fixed encryption algorithms and key management strategies during data transmission, leading to security vulnerabilities during key exchange, update, and storage. Key management mechanisms in traditional encryption methods generally rely on centralized key distribution centers or trusted third parties, making them particularly vulnerable to attacks in distributed network environments. Centralized key storage and distribution can be easily exploited by malicious attackers, leading to key leakage or misuse, which in turn compromises the security of the entire system. Furthermore, existing systems lack the ability to dynamically adjust encryption policies and implement fine-grained management, particularly in the face of constantly changing network traffic and potential security threats. These systems lack the flexibility to adjust encryption policies or implement real-time security monitoring and response. Such static encryption strategies are unable to adapt to emerging attack patterns. Existing encryption methods mostly focus on ensuring data confidentiality, but provide insufficient consideration for data integrity and potential tampering during transmission. While some encryption protocols employ integrity checks (such as hash value verification), these measures cannot effectively protect against sophisticated attacks during data transmission. Existing technologies generally lack monitoring and response mechanisms for dynamic traffic and abnormal behavior. Traditional encryption methods assume that the network environment is stable and secure when encrypting and transmitting data. However, in actual applications, Internet traffic often experiences abnormal fluctuations or potential security threats. Summary of the Invention
[0003] Based on this, it is necessary to provide an Internet data encryption method and system to solve at least one of the above technical problems.
[0004] To achieve the above object, a method for encrypting Internet data is provided, the method comprising the following steps:
[0005] Step S1: Obtain Internet participating node data; store the Internet participating node data in a distributed ledger to generate basic storage data of the Internet participating nodes;
[0006] Step S2: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate Internet node random number keys; distribute the Internet node random number keys through a secure channel to generate random key recipient data;
[0007] Step S3: Obtain historical network traffic data; perform abnormal traffic detection based on the historical network traffic data, and construct an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model;
[0008] Step S4: Based on the Internet abnormal behavior analysis model, abnormal traffic behavior analysis is performed on the Internet participating node data to generate abnormal traffic behavior data; behavior encryption information strategy is generated based on the abnormal traffic behavior data and random key recipient data to generate an Internet data encryption strategy; an Internet encryption strategy report is generated for the Internet data encryption strategy, thereby completing the Internet encryption method operation.
[0009] The beneficial effects of the present invention are that, by storing data from participating Internet nodes through distributed ledger technology, the integrity and immutability of the data are significantly improved, ensuring the reliability of the basic stored data of participating nodes. At the same time, random number generators and multi-party secure computation are used to generate node random keys, which are distributed through secure channels, making the key generation and transmission process more secure and effectively avoiding the risks of single-point leakage and tampering. Based on historical network traffic data, this method combines anomaly detection algorithms and behavioral analysis techniques to construct an efficient Internet abnormal behavior analysis model. By extracting abnormal features, it can accurately identify abnormal traffic behavior and provide a reliable foundation for subsequent policy generation. In addition, by jointly processing abnormal traffic behavior data and random key recipient data, a behavioral encryption information strategy is generated and an Internet data encryption strategy is formulated, thereby achieving targeted and dynamic encryption configuration in the data encryption process, significantly improving the security and adaptability of Internet data. Finally, the generation of an Internet encryption policy report integrates the data processing results of the entire process, providing structured support for the verification and improvement of security policies, while reducing the complexity and errors of manual intervention. The entire process creates an efficient closed loop across data collection, processing, encryption, and verification, ensuring the security and availability of data during transmission and storage. Therefore, through the innovative combination of distributed ledgers, random key generation and distribution, and abnormal behavior analysis, this invention addresses the security deficiencies, inflexible policies, and data vulnerability inherent in traditional encryption methods, thereby improving the security, dynamism, and reliability of internet data encryption.
[0010] Preferably, step S1 includes the following steps:
[0011] Step S11: Obtain Internet participating node data;
[0012] Step S12: Generate a unique identifier for the Internet participating node data to generate an Internet participating node UID;
[0013] Step S13: Use the distributed ledger to store the Internet participating node UID and Internet participating node data to generate basic storage data of the Internet participating node.
[0014] This invention achieves precise identification and differentiation of internet participating nodes by acquiring data from participating internet nodes and generating unique identifiers (UIDs) based on this data. At the data level, the introduction of UIDs provides an efficient identification mechanism for managing and tracking participating node data, effectively avoiding node identification errors caused by data redundancy or conflicts. Furthermore, the use of distributed ledger technology to store participating internet node UIDs alongside corresponding data ensures data integrity, traceability, and immutability, significantly enhancing the security and reliability of the system. Distributed ledger storage disperses data across multiple nodes, avoiding single points of failure through a decentralized approach and enhancing the system's fault tolerance and data availability. Furthermore, the combination of distributed ledgers and UIDs ensures a one-to-one correspondence between participating internet node data and their identifiers, simplifying data retrieval and updating processes and providing reliable foundational data support for subsequent encryption processing, behavioral analysis, and policy generation. This entire process, through innovative data identification and storage methods, provides an efficient and reliable technical framework for the management and security of participating internet nodes.
[0015] Preferably, step S2 includes the following steps:
[0016] Step S21: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate an Internet node random number key;
[0017] Step S22: Timestamp the Internet node random number key to generate random key timestamp-limited data;
[0018] Step S23: Establish a secure channel through the ECDH protocol, distribute the Internet node random number key and random key timestamp limiting data, and generate random key recipient data.
[0019] The present invention generates random numbers for Internet participating node data using a random number generator and combines it with multi-party secure computing technology to ensure the security and unpredictability of the random number key generation process, effectively reducing the risk of attacks during the key generation process from the data level. At the same time, the generated random number key is timestamped, further enhancing the timeliness and dynamism of the key, so that the key has clear validity during its life cycle. This mechanism not only improves the efficiency of key management, but also effectively reduces the long-term risk of key leakage. In addition, the random number key and timestamp-limited data are distributed through a secure channel established based on the ECDH protocol, ensuring the security of key transmission and avoiding eavesdropping or tampering during the distribution process. Combined with the characteristics of random key timestamp-limited data, the distribution process can achieve accurate reception and dynamic verification of the key, ensuring the reliability and real-time performance of the key recipient's data. The overall process provides a highly secure and intelligent technical framework for data encryption and key management of Internet participating nodes through the organic combination of random number generation, multi-party secure computing, timestamp limitation and secure channel transmission.
[0020] Preferably, step S21 includes the following steps:
[0021] Step S211: collecting the noise sources of the mechanical energy nodes of the Internet participating node data to generate Internet node noise source data; performing time jitter processing on the Internet node noise source data to generate Internet node time jitter data;
[0022] Step S212: Adding hardware random noise according to the Internet node time jitter data to generate Internet node time-hardware noise data;
[0023] Step S213: Perform distributed entropy pool synthesis processing on the Internet node time-hardware noise data to generate Internet node distributed entropy pool data; generate random numbers for the Internet node distributed entropy pool data, and perform multi-party secure calculation to generate the Internet node random number key.
[0024] This invention collects mechanical energy node noise sources from participating internet node data to generate internet node noise source data, providing a reliable hardware foundation for random number generation. At the data level, the introduction of mechanical energy noise sources increases the randomness and unpredictability of the data, effectively reducing the impact of external interference on random number generation. By performing time jitter processing on the noise source data, the uncertainty of the data is further enhanced, thereby improving the entropy level and security of the random number generation process. Subsequently, the time jitter data is combined with hardware random noise to generate time-hardware noise data, making the source of randomness more diverse and difficult to replicate. Time-hardware noise data is processed using distributed entropy pool synthesis technology, and distributed entropy pool data is constructed through multi-node collaboration. This method ensures the distributed security and redundancy of the entropy source, effectively avoiding the problem of single-point entropy pool failure or compromise. Finally, random number generation based on the distributed entropy pool data is combined with multi-party secure computation to generate internet node random number keys, thereby achieving high-intensity and high-security key generation at the data level. This method demonstrates significant advantages in randomness, unpredictability, and distributed security, providing solid technical support for data security and communication confidentiality of internet nodes.
[0025] Preferably, step S3 includes the following steps:
[0026] Step S31: Obtain historical network traffic data;
[0027] Step S32: performing abnormal traffic detection based on historical network traffic data to generate historical traffic abnormal behavior data;
[0028] Step S33: construct an abnormal behavior analysis model for the historical traffic abnormal behavior data to generate an Internet abnormal behavior analysis model.
[0029] The present invention provides a comprehensive and high-quality raw data foundation for the identification and analysis of abnormal behavior by acquiring historical network traffic data. From a data perspective, the collection and integration of historical network traffic data can fully reflect the dynamic changes in traffic during the operation of the Internet, including normal traffic patterns and potential abnormal traffic characteristics. On this basis, the historical network traffic data is deeply processed through abnormal traffic detection technology to generate historical traffic abnormal behavior data, thereby achieving accurate capture and classification of traffic anomalies, providing high-confidence data support for subsequent behavior analysis. Furthermore, the historical traffic abnormal behavior data is used to construct an abnormal behavior analysis model to form an Internet abnormal behavior analysis model. The model can generate behavior analysis mechanisms for different types of anomalies by extracting key features of abnormal behavior, effectively improving the ability to identify, predict and warn of abnormal traffic. This method not only enhances the depth of historical data mining during data processing, but also provides strong technical support for real-time monitoring and analysis of future traffic anomalies, significantly improving the security and robustness of the network system.
[0030] Preferably, step S33 includes the following steps:
[0031] Step S331: performing fluctuation analysis on the historical traffic abnormal behavior data to generate historical traffic abnormal fluctuation data; drawing a two-dimensional traffic fluctuation graph on the historical traffic abnormal fluctuation data to generate a historical traffic abnormal fluctuation graph; performing abnormal peak detection based on the historical traffic abnormal fluctuation graph to generate historical traffic fluctuation peak data; tracing the timestamp of the historical traffic fluctuation peak data to generate historical traffic abnormal behavior timestamp data;
[0032] Step S332: The first layer of the model is constructed based on the historical traffic fluctuation anomaly data, and an abnormal traffic matrix analysis is performed to generate an Internet abnormal behavior-traffic anomaly layer. The second layer of the model is constructed based on the historical traffic fluctuation peak data, and point cloud computing processing is performed to generate an Internet abnormal behavior-fluctuation peak layer. The third layer of the model is constructed based on the historical traffic abnormal behavior timestamp data, and timestamp comparison is performed to generate an Internet abnormal behavior-timestamp layer.
[0033] Step S333: construct an abnormal behavior analysis model for the Internet abnormal behavior-traffic abnormality layer, the Internet abnormal behavior-fluctuation peak layer, and the Internet abnormal behavior-timestamp layer to generate an Internet abnormal behavior analysis model.
[0034] By performing fluctuation analysis on historical traffic anomaly behavior data, this invention effectively captures the fluctuation characteristics of network traffic at the data level, providing a more refined perspective for identifying abnormal behavior. The historical traffic fluctuation anomaly data generated by the fluctuation analysis, along with the subsequent two-dimensional traffic fluctuation graph, provides an intuitive data representation for identifying abnormal behavior, helping to detect subtle fluctuations missed by traditional methods. Abnormal peak detection based on historical traffic fluctuation anomaly data further enhances the ability to capture significant abnormal events in network traffic. The generated historical traffic fluctuation peak data can help identify sudden changes in traffic, providing efficient data support for more in-depth abnormal behavior analysis. Timestamp tracing allows the precise marking of the occurrence time of abnormal behavior, allowing subsequent analysis to trace the specific moment of the traffic anomaly, enhancing the time sensitivity and real-time nature of the analysis process. Furthermore, by constructing models at different levels and performing different types of analysis and processing on historical traffic fluctuation anomaly data, historical traffic fluctuation peak data, and historical traffic anomaly behavior timestamp data, it is possible to conduct in-depth exploration of abnormal network traffic behavior from multiple dimensions. The model's first-layer abnormal traffic matrix analysis, second-layer point cloud computing processing, and third-layer timestamp comparison enable a comprehensive assessment of abnormal behavior from multiple perspectives, thereby improving the accuracy and comprehensiveness of abnormal behavior identification. Ultimately, the integration of these three layers forms a comprehensive, multi-layered analysis model for abnormal internet behavior, capable of accurately identifying and predicting abnormal behavior in network traffic and providing strong support for subsequent security protection and traffic management.
[0035] Preferably, step S4 includes the following steps:
[0036] Step S41: performing abnormal traffic behavior analysis on Internet participating node data based on an Internet abnormal behavior analysis model to generate traffic abnormal behavior data;
[0037] Step S42: Generate a behavior encryption information strategy based on the traffic abnormal behavior data and the random key recipient data to generate an Internet data encryption strategy;
[0038] Step S43: Encrypt and transmit the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data; generate an Internet encryption policy report based on the Internet information recipient transmission data, thereby completing the Internet encryption method operation.
[0039] By analyzing abnormal traffic behavior on internet node data, the present invention can effectively identify potential risks and irregular traffic behavior within the network, accurately capturing abnormal fluctuations and potential attacks in network traffic at the data level. First, by analyzing abnormal traffic behavior based on an internet abnormal behavior analysis model, the differences between normal and abnormal traffic patterns can be quickly identified, providing efficient and accurate data support for subsequent encryption strategy generation. The generated abnormal traffic behavior data provides a key basis for the development of behavioral encryption information strategies. By analyzing the characteristics of abnormal traffic behavior, a highly targeted and adaptable data encryption strategy can be developed to improve the security and privacy protection of network transmission. By combining abnormal traffic behavior data with random key recipient data to generate encryption information strategies, the security of information transmission within the network is guaranteed and the risk of key leakage or tampering is prevented. Next, the random key recipient data is encrypted and transmitted based on the internet data encryption strategy, ensuring the confidentiality, integrity, and availability of the data during transmission. Furthermore, the encryption strategy report generated by the internet information recipient transmission data further provides detailed strategy guidance for network security protection. Through this series of refined data processing and security measures, we were able to effectively encrypt Internet information, improving the security of data transmission and system protection capabilities.
[0040] Preferably, step S42 includes the following steps:
[0041] Step S421: Using a preset abnormal behavior threshold, the traffic abnormal behavior data is judged to generate traffic abnormal behavior result data, wherein the traffic abnormal behavior result data includes high abnormal behavior result data and low abnormal behavior result data; based on the traffic abnormal behavior result data, a behavior encryption information strategy is generated to generate an Internet data encryption strategy, wherein the Internet data encryption strategy includes an Internet high abnormality processing strategy and an Internet low abnormality processing strategy;
[0042] Step S422: When the traffic abnormality behavior result data is highly abnormal behavior result data, the Internet high abnormality processing strategy is applied to perform data sharding on the Internet node random number key to generate a multi-shard random number key, and perform a one-time key generation to generate a dynamic key enhanced data set; random noise is added to the traffic abnormality behavior data using block encryption to generate obfuscated traffic data; the dynamic key enhanced data set and the obfuscated traffic data are sent through two-way identity authentication, thereby completing the Internet high abnormality processing strategy;
[0043] Step S423: When the traffic abnormal behavior result data is low abnormal behavior result data, the Internet low abnormality processing strategy is applied to perform lightweight encryption on the Internet node random number key to generate a lightweight key data set; the lightweight key data set is sent to complete the Internet low abnormality processing strategy.
[0044] The present invention uses preset abnormal behavior thresholds to judge traffic anomaly data and generates high- and low-abnormal behavior result data, providing an accurate basis for subsequent policy formulation. This classification of high- and low-abnormal behavior result data enables differentiated encryption strategies based on the severity of abnormal traffic, improving processing efficiency and security. The Internet data encryption strategy generated based on the traffic anomaly result data clarifies the handling measures for high- and low-abnormal scenarios, ensuring that network traffic receives appropriate encryption protection under different types of abnormal events. Specifically, when the traffic anomaly result data is high-abnormal, the Internet high-abnormal handling strategy is applied to shard the Internet node random key and generate multi-shard random keys and one-time keys, thereby creating a dynamic key-enhanced dataset. This process effectively avoids the key leakage risks associated with traditional key generation methods and adds random noise to the traffic anomaly data through block encryption to generate obfuscated traffic data, further enhancing data confidentiality and security. The dynamic key-enhanced dataset and obfuscated traffic data, transmitted via two-way authentication, ensure data integrity and confidentiality during transmission. When processing low-abnormal behavior result data, we employ an internet-based low-abnormality processing strategy, generating a lightweight key dataset through lightweight encryption technology. This reduces the encryption load, improves processing speed and system efficiency, and ensures secure transmission in low-risk situations. This differentiated processing strategy enables the system to flexibly respond to different levels of abnormal behavior, enhancing the targeted and intelligent nature of encryption.
[0045] Preferably, step S43 includes the following steps:
[0046] Step S431: Encrypting the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data;
[0047] Step S432: Compare the Internet information receiver's transmission data with the basic storage data of the Internet participating nodes to generate transmission channel integrity comparison data;
[0048] Step S433: Generate an Internet encryption strategy report based on the transmission channel integrity comparison data, thereby completing the Internet encryption method operation.
[0049] The present invention ensures a high degree of confidentiality and tamper resistance during network information transmission by encrypting random key recipient data based on an internet data encryption policy. This encrypted transmission process not only protects data privacy during transmission but also effectively prevents potential external attacks and data leaks, enhancing the security of the information system. In step S432, the method compares the internet information recipient's transmitted data with the basic stored data of participating internet nodes to generate transmission channel integrity comparison data. The key to this step is that by comparing the data integrity, any inconsistencies or anomalies that occur during data transmission can be promptly identified, ensuring that the integrity of the transmission channel is not compromised. This measure effectively prevents potential security threats such as man-in-the-middle attacks and data loss, providing additional protection for data transmission security. Finally, in step S433, an internet encryption policy report is generated based on the transmission channel integrity comparison data, further summarizing and providing feedback on the security status of data transmission. This report not only provides a detailed record of the encryption policy's implementation but also provides data support for future data transmission optimization. Through this series of steps, the system can provide comprehensive security protection in encryption, verification and report generation, ensuring the confidentiality, integrity and availability of data during transmission, thereby improving the security protection capabilities of the overall network system.
[0050] In this specification, an Internet data encryption system is provided for executing the above-mentioned Internet data encryption method. The Internet data encryption system includes:
[0051] The node data management module is used to obtain the data of Internet participating nodes; store the data of Internet participating nodes in a distributed ledger and generate basic storage data of Internet participating nodes;
[0052] The random key generation and distribution module is used to generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate random number keys for Internet nodes; distribute the Internet node random number keys through a secure channel to generate random key recipient data;
[0053] The abnormal behavior modeling module is used to obtain historical network traffic data; perform abnormal traffic detection based on historical network traffic data, and build an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model;
[0054] The traffic anomaly analysis and encryption strategy module is used to analyze the abnormal traffic behavior of Internet participating node data based on the Internet abnormal behavior analysis model to generate traffic abnormal behavior data; generate behavior encryption information strategy based on traffic abnormal behavior data and random key recipient data to generate Internet data encryption strategy; generate Internet encryption strategy report for Internet data encryption strategy, thereby completing Internet encryption method operation.
[0055] The beneficial effects of the present invention are that, by storing data from participating Internet nodes through distributed ledger technology, the integrity and immutability of the data are significantly improved, ensuring the reliability of the basic stored data of participating nodes. At the same time, random number generators and multi-party secure computation are used to generate node random keys, which are distributed through secure channels, making the key generation and transmission process more secure and effectively avoiding the risks of single-point leakage and tampering. Based on historical network traffic data, this method combines anomaly detection algorithms and behavioral analysis techniques to construct an efficient Internet abnormal behavior analysis model. By extracting abnormal features, it can accurately identify abnormal traffic behavior and provide a reliable foundation for subsequent policy generation. In addition, by jointly processing abnormal traffic behavior data and random key recipient data, a behavioral encryption information strategy is generated and an Internet data encryption strategy is formulated, thereby achieving targeted and dynamic encryption configuration in the data encryption process, significantly improving the security and adaptability of Internet data. Finally, the generation of an Internet encryption policy report integrates the data processing results of the entire process, providing structured support for the verification and improvement of security policies, while reducing the complexity and errors of manual intervention. The entire process creates an efficient closed loop across data collection, processing, encryption, and verification, ensuring the security and availability of data during transmission and storage. Therefore, through the innovative combination of distributed ledgers, random key generation and distribution, and abnormal behavior analysis, this invention addresses the security deficiencies, inflexible policies, and data vulnerability inherent in traditional encryption methods, thereby improving the security, dynamism, and reliability of internet data encryption. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A flowchart of a method for encrypting Internet data;
[0057] Figure 2 for Figure 1 Detailed implementation steps of step S2 in FIG.
[0058] Figure 3 for Figure 1 Detailed implementation steps of step S3 in FIG.
[0059] Figure 4 for Figure 1 Detailed implementation steps of step S4 in FIG.
[0060] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0061] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. Obviously, the embodiments described are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative work are within the scope of protection of the present invention.
[0062] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor and / or microcontroller approaches.
[0063] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.
[0064] To achieve this, please refer to Figures 1 to 4 , an Internet data encryption method, the method comprising the following steps:
[0065] Step S1: Obtain Internet participating node data; store the Internet participating node data in a distributed ledger to generate basic storage data of the Internet participating nodes;
[0066] Step S2: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate Internet node random number keys; distribute the Internet node random number keys through a secure channel to generate random key recipient data;
[0067] Step S3: Obtain historical network traffic data; perform abnormal traffic detection based on the historical network traffic data, and construct an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model;
[0068] Step S4: Based on the Internet abnormal behavior analysis model, abnormal traffic behavior analysis is performed on the Internet participating node data to generate abnormal traffic behavior data; behavior encryption information strategy is generated based on the abnormal traffic behavior data and random key recipient data to generate an Internet data encryption strategy; an Internet encryption strategy report is generated for the Internet data encryption strategy, thereby completing the Internet encryption method operation.
[0069] The beneficial effects of the present invention are that, by storing data from participating Internet nodes through distributed ledger technology, the integrity and immutability of the data are significantly improved, ensuring the reliability of the basic stored data of participating nodes. At the same time, random number generators and multi-party secure computation are used to generate node random keys, which are distributed through secure channels, making the key generation and transmission process more secure and effectively avoiding the risks of single-point leakage and tampering. Based on historical network traffic data, this method combines anomaly detection algorithms and behavioral analysis techniques to construct an efficient Internet abnormal behavior analysis model. By extracting abnormal features, it can accurately identify abnormal traffic behavior and provide a reliable foundation for subsequent policy generation. In addition, by jointly processing abnormal traffic behavior data and random key recipient data, a behavioral encryption information strategy is generated and an Internet data encryption strategy is formulated, thereby achieving targeted and dynamic encryption configuration in the data encryption process, significantly improving the security and adaptability of Internet data. Finally, the generation of an Internet encryption policy report integrates the data processing results of the entire process, providing structured support for the verification and improvement of security policies, while reducing the complexity and errors of manual intervention. The entire process creates an efficient closed loop across data collection, processing, encryption, and verification, ensuring the security and availability of data during transmission and storage. Therefore, through the innovative combination of distributed ledgers, random key generation and distribution, and abnormal behavior analysis, this invention addresses the security deficiencies, inflexible policies, and data vulnerability inherent in traditional encryption methods, thereby improving the security, dynamism, and reliability of internet data encryption.
[0070] In the embodiment of the present invention, reference Figure 1 FIG. 1 is a flow chart showing the steps of an Internet data encryption method according to the present invention. In this example, the Internet data encryption method includes the following steps:
[0071] Step S1: Obtain Internet participating node data; store the Internet participating node data in a distributed ledger to generate basic storage data of the Internet participating nodes;
[0072] In this embodiment of the present invention, the process of acquiring internet node data and storing it in a distributed ledger utilizes modern blockchain technology, aiming to ensure decentralized data storage, immutability, and high availability. From a data perspective, internet node data is first collected and preliminarily organized to ensure data validity and accuracy. This data includes key information such as communication information, operation records, and status of each node. Converting this data into a standardized format ensures compatibility and consistency in subsequent processing. Next, this node data is stored using distributed ledger technology. A distributed ledger is a decentralized database structure in which data is not stored in a single location but distributed across multiple nodes. Each node maintains a copy of the data, enhancing fault tolerance and attack resistance. Furthermore, distributed ledger technology utilizes a consensus algorithm to ensure data consistency. This ensures data consistency and integrity even in the event of network delays or node failures between nodes. To further enhance security and prevent tampering, all data is encrypted and linked to the previous block in the ledger. Each record (or "block") is linked to the previous block using a hash algorithm, forming an irreversible chain.
[0073] Step S2: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate Internet node random number keys; distribute the Internet node random number keys through a secure channel to generate random key recipient data;
[0074] In this embodiment of the present invention, a random number generator (RNG) is used to generate random numbers from data of participating internet nodes. The generated random numbers serve as random keys for internet nodes, ensuring the unpredictability and security of the keys. Specifically, the random number generator (RNG) employs algorithmic random number generation methods, such as those based on physical phenomena (e.g., hardware noise sources) or pseudorandom algorithms (e.g., algorithms based on pseudorandom number generators). To further enhance the security of random number generation, a high-quality entropy source is used to ensure statistical uniformity and unpredictability of the generated random numbers, preventing attackers from predicting the key generation process by analyzing vulnerabilities. Next, multi-party secure computation (MPC) is performed. This is a secure computation protocol that utilizes multiple participants to jointly compute without exposing their inputs. The goal of MPC is to generate a shared, secure key without disclosing the private data of each participant. In this protocol, data is not centrally stored or computed, but encrypted through distributed computing, ensuring the data privacy of each node. Through this process, multiple internet nodes collaborate to generate a common key that is unknowable to any single party, enhancing the security of the data generation process. The generated random key for each internet node is then distributed over a secure channel using an encrypted transport protocol (such as TLS or SSL) to ensure it cannot be intercepted or tampered with during transmission. During distribution, the key is encrypted to prevent leakage, and an authentication mechanism is employed to ensure the key recipient is an authorized entity, preventing the key from being received by mistake or maliciously. Ultimately, the key distributed over the secure channel generates "random key recipient data," which lays the foundation for subsequent cryptographic operations.
[0075] Step S3: Obtain historical network traffic data; perform abnormal traffic detection based on the historical network traffic data, and construct an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model;
[0076] In this embodiment of the present invention, historical network traffic data includes various network traffic metrics, such as packet size, transmission rate, IP address distribution, port usage, and time distribution of traffic. This data can reflect normal network behavior patterns and provide a reference for detecting abnormal behavior. To detect abnormal traffic, the system utilizes a variety of data analysis and pattern recognition techniques, including statistical analysis, machine learning algorithms, and deep learning models. By preprocessing historical traffic data, the system first extracts key features, identifies common patterns in traffic, and then builds a statistical model of normal traffic based on these patterns. Common anomaly detection methods include threshold-based detection, clustering-based anomaly detection, and classification models based on supervised and unsupervised learning. Using these algorithms, the system can automatically identify traffic patterns that significantly deviate from the historical data distribution, thereby detecting potential abnormal traffic. This abnormal traffic can be caused by network attacks, traffic overloads, hardware failures, and other reasons. Secondly, for the detected abnormal portions of traffic, the system constructs an abnormal behavior analysis model to further analyze the characteristics, impact, and causes of the abnormal behavior. Model construction relies on machine learning algorithms such as decision trees, support vector machines (SVMs), and neural networks. By training on historical data, the model's accuracy is optimized, enabling it to identify underlying patterns in various abnormal behaviors. By analyzing abnormal behavior, the system not only identifies abnormal traffic but also uses the learned model to predict future abnormal traffic.
[0077] Step S4: Based on the Internet abnormal behavior analysis model, abnormal traffic behavior analysis is performed on the Internet participating node data to generate abnormal traffic behavior data; behavior encryption information strategy is generated based on the abnormal traffic behavior data and random key recipient data to generate an Internet data encryption strategy; an Internet encryption strategy report is generated for the Internet data encryption strategy, thereby completing the Internet encryption method operation.
[0078] In this embodiment of the present invention, an abnormal traffic behavior analysis model is used to analyze data from participating internet nodes for abnormal traffic behavior. The system utilizes the previously constructed abnormal behavior analysis model to analyze real-time traffic data from participating internet nodes and identify abnormal behavior. This process extracts features and performs pattern recognition on network traffic. Based on the model's training data and prediction algorithms, it identifies behavioral characteristics that deviate from normal traffic patterns, such as abnormal packet traffic peaks, unusual transmission rates, or atypical protocol usage. This data-driven analysis approach allows the system to effectively distinguish normal traffic from potential attack or fault traffic, thereby generating abnormal traffic behavior data. The generation of abnormal traffic behavior data relies primarily on a variety of statistical learning and machine learning algorithms. These algorithms, by learning from historical and real-time traffic data, automatically adjust model parameters to improve accuracy, effectively identifying abnormal network behavior. Next, the system generates a behavioral encryption information policy based on the abnormal traffic behavior data and random key recipient data. During this process, the system analyzes the abnormal behavior characteristics exhibited in network traffic and compares them with the random key recipient data to generate encryption policies tailored to different types of abnormal behavior. The design of these encryption strategies needs to consider factors such as the degree of traffic anomaly, the type of attack, and the importance of data transmission, to ensure that different types of abnormal traffic can be protected by corresponding encryption methods. Specifically, different encryption strengths or encryption methods will be selected based on the dangerousness of the traffic. For example, for serious abnormal behavior, more complex encryption algorithms such as fragmented encryption and obfuscation encryption can be applied. For mild abnormal behavior, lightweight encryption is used. Finally, the system generates an Internet encryption policy report based on the generated Internet data encryption policy. The report generation process provides a detailed description of the encryption policy, including the selection of encryption technology, key management schemes, encryption strength requirements, data security assessments, etc., thereby providing a reference and basis for subsequent network defense strategies.
[0079] Preferably, step S1 includes the following steps:
[0080] Step S11: Obtain Internet participating node data;
[0081] Step S12: Generate a unique identifier for the Internet participating node data to generate an Internet participating node UID;
[0082] Step S13: Use the distributed ledger to store the Internet participating node UID and Internet participating node data to generate basic storage data of the Internet participating node.
[0083] In this embodiment of the present invention, data of participating internet nodes is acquired. This process collects basic node information from multiple data sources, including but not limited to the network device's IP address, MAC address, device type, geographic location, operating status, communication protocol, and communication frequency. This information provides the foundation for subsequent node management, data storage, and security analysis. During the data acquisition phase, efficient data collection technologies, such as web crawlers, traffic monitoring tools, and network protocol analyzers, are employed to ensure real-time or periodic capture of the status and behavior data of participating internet nodes. Unique identifiers (UIDs) are generated for the acquired participating internet node data. UID generation involves using an algorithm to convert each node's data into a unique and non-repeatable identifier, ensuring that each node can be independently identified within the system. Common UID generation methods include hashing algorithms (such as SHA-256) and UUIDs (Universally Unique Identifiers), which ensure the generated identifiers are highly unique and unpredictable. UID generation not only facilitates subsequent data storage and retrieval but also enables authentication and secure isolation between multiple nodes, preventing identity impersonation and data tampering. Distributed ledger technology is used to store the UIDs and data of participating internet nodes. Distributed ledger technologies (such as blockchain) offer decentralization, data immutability, transparency, and trustworthiness, ensuring the security and consistency of data stored on each node. At this stage, by recording the node's UID and related data in a distributed ledger, data immutability and decentralized management are ensured. Furthermore, distributed ledgers provide real-time data updates and synchronization, ensuring that multiple parties can store and share data on the same ledger without data conflicts or loss. A node's basic stored data includes all associated information, such as device configuration, connection history, and status monitoring data. This information is stored on the blockchain as blocks. Each block contains complete node data and a unique identifier, ensuring data security, integrity, and immutability.
[0084] As an example of the present invention, refer to Figure 2 As shown, in this example, step S2 includes:
[0085] Step S21: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate an Internet node random number key;
[0086] Step S22: Timestamp the Internet node random number key to generate random key timestamp-limited data;
[0087] Step S23: Establish a secure channel through the ECDH protocol, distribute the Internet node random number key and random key timestamp limiting data, and generate random key recipient data.
[0088] In this embodiment of the present invention, a random number generator (RNG) is used to generate random numbers for internet node data. This process utilizes high-quality cryptographic algorithms to generate random numbers, providing the foundation for subsequent key generation. At the data level, the random number generator design is based on true random number generation (TRNG) or pseudo-random number generation (PRNG) technology. True random number generation relies on physical processes such as thermal noise and the photoelectric effect, while pseudo-random number generation relies on mathematical algorithms such as the linear congruential method (LCG). Through these techniques, the generated random numbers not only meet statistical randomness requirements but also enhance security through cryptographic algorithms. Furthermore, to ensure the consistency of the generated random numbers in multi-party computations, multi-party secure computation (MPC) technology is employed. This allows multiple parties to jointly compute and verify the random number generation process without leaking any single party's data. This technology ensures the security and fairness of the random number keys generated for internet nodes in a distributed environment, preventing the tampering or manipulation of the random number generation process by a single party. The generated random key for the internet node is further processed and timestamped to ensure its validity and timeliness. Timestamp-based technology, by adding time information to the random key, ensures that each key is associated with a specific time. This is crucial in practical applications, particularly during multiple communications or long-term data exchange, effectively preventing key reuse and increasing the frequency of key updates. Timestamps not only provide key validity but also facilitate traceability and tracing during anomaly detection, improving the overall security of the system. The Elliptic Curve Diffie-Hellman (ECDH) protocol is used to establish a secure channel for key exchange between internet nodes. The ECDH protocol utilizes elliptic curve cryptography, providing strong cryptographic guarantees based on the mathematical discrete logarithm problem. At the data level, the ECDH protocol enables secure key exchange between communicating parties, ensuring that the key cannot be deciphered even by third-party eavesdroppers. During this process, the internet node random key and random key timestamp data are distributed to the recipient, generating the final random key recipient data.
[0089] Preferably, step S21 includes the following steps:
[0090] Step S211: collecting the noise sources of the mechanical energy nodes of the Internet participating node data to generate Internet node noise source data; performing time jitter processing on the Internet node noise source data to generate Internet node time jitter data;
[0091] Step S212: Adding hardware random noise according to the Internet node time jitter data to generate Internet node time-hardware noise data;
[0092] Step S213: Perform distributed entropy pool synthesis processing on the Internet node time-hardware noise data to generate Internet node distributed entropy pool data; generate random numbers for the Internet node distributed entropy pool data, and perform multi-party secure calculation to generate the Internet node random number key.
[0093] In this embodiment of the present invention, mechanical energy node noise sources are collected from participating internet node data to generate internet node noise source data. This process utilizes physical noise sources, such as environmental vibration, temperature fluctuations, and wind, to extract mechanical energy noise. This noise is highly random and can serve as the initial data source for random number generation. To further enhance the randomness of the data, the noise source data undergoes time dithering. This temporal perturbation of the collected mechanical energy data increases the uncertainty of the data, making the time series data more random and reducing the impact of periodic fluctuations. This process ensures that the resulting time dithering data reflects more unpredictable random characteristics, increasing the encryption strength of the data. The internet node time dithering data is further processed to add hardware random noise. Hardware random noise originates from dedicated hardware devices, such as physical noise generators or electromagnetic noise generated by circuit design. This hardware random noise is more unpredictable than software-generated pseudo-random numbers and can effectively enhance the randomness of the generated data. Combining hardware noise with time-dithered data ensures high randomness across multiple levels of the generated data, enhancing the security of the key generation process and reducing its vulnerability to prediction or attack. After the time dithering and hardware random noise addition, the data is then synthesized in a distributed entropy pool. The entropy pool combines random data from various sources to increase the overall entropy value, ensuring that the generated data is more random and less predictable. This entropy pool synthesis process is performed in a distributed manner, meaning that the calculation and storage are distributed across multiple participating nodes. This not only increases data redundancy but also improves the system's fault tolerance and security. Based on this, random numbers are generated from the generated distributed entropy pool data. Finally, multi-party secure computation technology is used to ensure that no single party can obtain complete random numbers or key information during computations between multiple participants, ensuring the fairness and security of key generation.
[0094] As an example of the present invention, refer to Figure 3 As shown, in this example, step S3 includes:
[0095] Step S31: Obtain historical network traffic data;
[0096] Step S32: performing abnormal traffic detection based on historical network traffic data to generate historical traffic abnormal behavior data;
[0097] Step S33: construct an abnormal behavior analysis model for the historical traffic abnormal behavior data to generate an Internet abnormal behavior analysis model.
[0098] In this embodiment of the present invention, network traffic data is collected from various sources, including Internet service providers (ISPs), enterprise networks, and cloud platforms. This data includes, but is not limited to, source IP addresses, destination IP addresses, transport protocol types, packet sizes, traffic timing, and traffic sources. To ensure comprehensiveness and accuracy, this data is cleaned and formatted to make it suitable for subsequent anomaly detection and analysis. The core purpose of this step is to establish a comprehensive historical traffic dataset, which serves as the foundation for subsequent anomaly detection. Anomaly detection is performed based on the acquired historical network traffic data. This process relies on statistical and machine learning methods, such as clustering algorithms, anomaly detection algorithms (e.g., Isolation Forest and One-Class Support Vector Machine), or rule-based detection systems. These methods enable the system to identify anomalous traffic that significantly deviates from normal traffic patterns. Specific technical approaches for anomaly detection include traffic timing analysis, distribution feature analysis, and frequent pattern detection. The goal is to identify security threats or network attack behaviors (e.g., DoS attacks, data leaks, and malicious scanning). The detection results generate historical traffic anomaly behavior data, which contains information such as the time of the anomaly, traffic characteristics, and the degree of deviation from normal traffic. An anomaly analysis model is constructed based on this historical traffic anomaly data. This process utilizes machine learning and statistical models to model and analyze abnormal behavior data. Methods employed include deep learning approaches such as autoencoders, generative adversarial networks (GANs), and ensemble learning methods, which can deeply uncover potential abnormal behaviors within complex traffic flows. Through training, the model learns normal patterns in historical traffic data and automatically identifies significantly different abnormal patterns. The construction of an abnormal behavior analysis model involves steps such as data feature selection, model training, cross-validation, and performance evaluation. During this process, historical traffic abnormal behavior data is used to train the model, enabling it to accurately predict abnormal behavior based on input traffic data and further generate an Internet abnormal behavior analysis model.
[0099] Preferably, step S33 includes the following steps:
[0100] Step S331: performing fluctuation analysis on the historical traffic abnormal behavior data to generate historical traffic abnormal fluctuation data; drawing a two-dimensional traffic fluctuation graph on the historical traffic abnormal fluctuation data to generate a historical traffic abnormal fluctuation graph; performing abnormal peak detection based on the historical traffic abnormal fluctuation graph to generate historical traffic fluctuation peak data; tracing the timestamp of the historical traffic fluctuation peak data to generate historical traffic abnormal behavior timestamp data;
[0101] Step S332: The first layer of the model is constructed based on the historical traffic fluctuation anomaly data, and an abnormal traffic matrix analysis is performed to generate an Internet abnormal behavior-traffic anomaly layer. The second layer of the model is constructed based on the historical traffic fluctuation peak data, and point cloud computing processing is performed to generate an Internet abnormal behavior-fluctuation peak layer. The third layer of the model is constructed based on the historical traffic abnormal behavior timestamp data, and timestamp comparison is performed to generate an Internet abnormal behavior-timestamp layer.
[0102] Step S333: construct an abnormal behavior analysis model for the Internet abnormal behavior-traffic abnormality layer, the Internet abnormal behavior-fluctuation peak layer, and the Internet abnormal behavior-timestamp layer to generate an Internet abnormal behavior analysis model.
[0103] In this embodiment of the present invention, fluctuation analysis is performed on historical abnormal traffic behavior data. Fluctuation analysis uses time series methods to model the fluctuation characteristics of traffic data to identify trends and amplitude changes in the data. This process uses mathematical tools such as sliding averages, volatility calculations, and Fourier transforms to process time series data and generate historical traffic fluctuation anomaly data. Furthermore, two-dimensional traffic fluctuation graphs are plotted to visualize the timing and amplitude of traffic changes, facilitating analysis of the temporal distribution and changing trends of abnormal traffic, and generating historical traffic fluctuation anomaly graphs. Based on these fluctuation graphs, the system uses abnormal peak detection methods (such as standard deviation-based anomaly detection and peak verification algorithms) to identify significant peaks of abnormal fluctuations and generate historical traffic fluctuation peak data. Furthermore, using timestamp traceability technology, abnormal peaks are associated with specific timestamps in historical traffic data to generate historical traffic abnormal behavior timestamp data, ensuring accurate recording and tracking of the moments when abnormal traffic behavior occurred. The first layer of the model is constructed based on historical traffic fluctuation anomaly data, employing an abnormal traffic matrix analysis method. This method uses matrix decomposition techniques (such as singular value decomposition and principal component analysis) to extract and reconstruct abnormal patterns in traffic data, generating an Internet abnormal behavior-traffic anomaly layer. This approach enables the model to capture potential abnormal behavior patterns from complex traffic data. Next, the second layer of the model is constructed based on historical traffic fluctuation peak data. Point cloud computing (such as k-means clustering and DBSCAN) is used to perform spatial analysis and distribution assessment of outliers and fluctuation peaks in the traffic data, generating an Internet abnormal behavior-fluctuation peak layer. This processing enables the system to identify clustering and distribution patterns of abnormal traffic in high-dimensional data space. Finally, the third layer of the model is constructed based on historical traffic abnormal behavior timestamp data. Timestamp comparison techniques are used to match abnormal events with specific time tags, generating an Internet abnormal behavior-timestamp layer. This layer primarily captures the temporal characteristics of abnormal traffic behavior, providing temporal support for subsequent analysis. The system comprehensively analyzes the abnormal behavior data at these three levels (Internet abnormal behavior-traffic anomaly layer, Internet abnormal behavior-fluctuation peak layer, and Internet abnormal behavior-timestamp layer) to construct a complete abnormal behavior analysis model.
[0104] As an example of the present invention, refer to Figure 4 As shown, in this example, step S4 includes:
[0105] Step S41: performing abnormal traffic behavior analysis on Internet participating node data based on an Internet abnormal behavior analysis model to generate traffic abnormal behavior data;
[0106] Step S42: Generate a behavior encryption information strategy based on the traffic abnormal behavior data and the random key recipient data to generate an Internet data encryption strategy;
[0107] Step S43: Encrypt and transmit the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data; generate an Internet encryption policy report based on the Internet information recipient transmission data, thereby completing the Internet encryption method operation.
[0108] In this embodiment of the present invention, abnormal traffic behavior analysis is performed on internet node data based on an internet abnormal behavior analysis model. This step relies on multidimensional data fusion technology, which involves feature extraction and pattern recognition of node traffic data. Leveraging historical traffic data, time series analysis, and machine learning models (such as classifiers and regression analysis), the model can identify potential abnormal behaviors in traffic, such as DDoS attacks, traffic spikes, or irregular data flows. Abnormal behaviors in the data are quantified using statistical methods, and clustering algorithms (such as K-means and DBSCAN) are used to classify abnormal behaviors in the traffic data, generating abnormal traffic behavior data. This data reveals patterns in traffic fluctuations and provides a basis for the subsequent generation of encryption strategies. Based on the abnormal traffic behavior data and random key recipient data, a behavior-based encryption information strategy is generated, which in turn generates an internet data encryption strategy. This process utilizes the behavior-driven strategy generation technology in encryption algorithms, combining data abnormality with information such as the frequency of access to key nodes, to generate a multi-level encryption strategy using encryption algorithms (such as AES and RSA). This strategy adopts different encryption measures of varying strengths and types based on the intensity of the abnormal traffic, the identity of the visitor, and the specific characteristics of the traffic behavior. For example, for instances of significant traffic anomalies, strong encryption strategies (such as dynamic key generation and updates) are employed, while for nodes with less significant traffic fluctuations, lighter encryption methods (such as symmetric encryption) are selected. The core of this process is the combination of real-time processing of abnormal behavior data and random key generation. The random key recipient's data is encrypted and transmitted based on the internet data encryption strategy, generating internet information recipient transmission data. This step uses the previously generated encryption strategy to encrypt and transmit the data. During the encrypted transmission process, a combination of asymmetric encryption methods (such as public / private key pairing) and symmetric encryption methods (such as key exchange mechanisms) is used to ensure the confidentiality and security of data transmission. Furthermore, secure transmission protocols (such as TLS and SSL) are used to protect data transmission within the network, preventing man-in-the-middle attacks and data leaks. Finally, an internet encryption policy report is generated based on the internet information recipient transmission data, completing the entire internet encryption method operation.
[0109] Preferably, step S42 includes the following steps:
[0110] Step S421: Using a preset abnormal behavior threshold, the traffic abnormal behavior data is judged to generate traffic abnormal behavior result data, wherein the traffic abnormal behavior result data includes high abnormal behavior result data and low abnormal behavior result data; based on the traffic abnormal behavior result data, a behavior encryption information strategy is generated to generate an Internet data encryption strategy, wherein the Internet data encryption strategy includes an Internet high abnormality processing strategy and an Internet low abnormality processing strategy;
[0111] Step S422: When the traffic abnormality behavior result data is highly abnormal behavior result data, the Internet high abnormality processing strategy is applied to perform data sharding on the Internet node random number key to generate a multi-shard random number key, and perform a one-time key generation to generate a dynamic key enhanced data set; random noise is added to the traffic abnormality behavior data using block encryption to generate obfuscated traffic data; the dynamic key enhanced data set and the obfuscated traffic data are sent through two-way identity authentication, thereby completing the Internet high abnormality processing strategy;
[0112] Step S423: When the traffic abnormal behavior result data is low abnormal behavior result data, the Internet low abnormality processing strategy is applied to perform lightweight encryption on the Internet node random number key to generate a lightweight key data set; the lightweight key data set is sent to complete the Internet low abnormality processing strategy.
[0113] In this embodiment of the present invention, traffic anomaly data is identified using preset anomaly thresholds. This process relies on rule-based anomaly detection algorithms, such as statistical methods or machine learning models (e.g., support vector machines and decision trees). These algorithms can monitor and analyze traffic data in real time, identifying high- and low-anomaly data. The generation of traffic anomaly data is based on an anomaly scoring process, where different types of anomaly are categorized using thresholds. This classification process not only considers data traffic fluctuations but also factors such as traffic frequency, duration, and access patterns to generate accurate high- and low-anomaly data. Next, based on this categorized data, a behavior encryption information policy is generated. This policy applies different encryption strengths based on the level of abnormal traffic, thereby forming an Internet data encryption policy. High-anomaly data uses a high-strength encryption policy, while low-anomaly data uses a lightweight encryption policy. This hierarchical encryption approach ensures that the system can handle abnormal traffic while ensuring data security while not imposing excessive performance overhead on normal traffic. When the traffic anomaly data is highly abnormal, the system applies the Internet high-anomaly handling strategy to shard the random keys of the Internet nodes and generate multi-shard random keys. This process relies on data sharding technology, which enhances key security by dividing the key into multiple small parts for encrypted transmission and prevents single-point attacks. Subsequently, a dynamic key-enhanced dataset is generated using one-time key generation technology to meet the security requirements of high-risk environments. Furthermore, after the traffic anomaly data is encrypted, random noise is added to generate obfuscated traffic data. This process, implemented using encryption algorithms (such as AES and DES), aims to enhance the unpredictability of the transmitted data, making it more difficult for attackers to identify and analyze. Finally, the generated dynamic key-enhanced dataset and obfuscated traffic data are sent using two-way authentication. This mechanism ensures authentication and data integrity during transmission, preventing malicious tampering and man-in-the-middle attacks. When the traffic anomaly data is low abnormal, step S423 applies the Internet low-anomaly handling strategy to perform lightweight encryption on the random keys of the Internet nodes and generate a lightweight key dataset. This process relies on lightweight encryption algorithms (such as RC4, ChaCha, etc.), which have low computational overhead while ensuring encryption strength and are suitable for low-risk or low-load environments.
[0114] Preferably, step S43 includes the following steps:
[0115] Step S431: Encrypting the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data;
[0116] Step S432: Compare the Internet information receiver's transmission data with the basic storage data of the Internet participating nodes to generate transmission channel integrity comparison data;
[0117] Step S433: Generate an Internet encryption strategy report based on the transmission channel integrity comparison data, thereby completing the Internet encryption method operation.
[0118] In this embodiment of the present invention, based on the internet data encryption policy, the system encrypts the random key recipient's data for transmission, generating internet information recipient transmission data. The technical means of this step primarily rely on encrypted transmission mechanisms, such as public key encryption, symmetric encryption, or hybrid encryption. Encrypted transmission ensures the confidentiality and integrity of data during transmission, preventing malicious tampering or theft. During data transmission, encryption algorithms that comply with internet encryption policies (such as AES, RSA, or ECC) are employed. These algorithms ensure secure data transmission by selecting appropriate key management methods. Furthermore, security protocols (such as TLS / SSL and IPSec) are utilized during transmission to protect the encrypted data, ensuring the secure transmission of encryption keys and the data itself. The system compares the internet information recipient's transmission data with the basic stored data of participating internet nodes to generate transmission channel integrity comparison data. The key technical means of this process is to hash the transmitted data using hash algorithms and integrity verification mechanisms, such as the SHA family of algorithms, HMAC, and digital signatures, and compare the generated hash value with the hash value of the original data stored on the node. This comparison can detect whether data has been tampered with or lost during transmission, thereby verifying the integrity of the transmission channel. This hash-based data integrity verification method ensures that received data is consistent with the original data, preventing malicious attacks or tampering during data transmission. Based on the transmission channel integrity comparison data, the system generates an Internet encryption policy report. This report generation process relies on data analysis and report generation technology. Specifically, the system generates a detailed encryption policy execution report based on the transmission channel integrity verification results and any anomalies encountered during the encrypted transmission process. The report content includes the results of encryption policy execution, the integrity status of the transmitted data, logs of any anomalies or errors, and feedback on relevant security measures.
[0119] In this specification, an Internet data encryption system is provided for executing the above-mentioned Internet data encryption method. The Internet data encryption system:
[0120] The node data management module is used to obtain the data of Internet participating nodes; store the data of Internet participating nodes in a distributed ledger and generate basic storage data of Internet participating nodes;
[0121] The random key generation and distribution module is used to generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate random number keys for Internet nodes; distribute the Internet node random number keys through a secure channel to generate random key recipient data;
[0122] The abnormal behavior modeling module is used to obtain historical network traffic data; perform abnormal traffic detection based on historical network traffic data, and build an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model;
[0123] The traffic anomaly analysis and encryption strategy module is used to analyze the abnormal traffic behavior of Internet participating node data based on the Internet abnormal behavior analysis model to generate traffic abnormal behavior data; generate behavior encryption information strategy based on traffic abnormal behavior data and random key recipient data to generate Internet data encryption strategy; generate Internet encryption strategy report for Internet data encryption strategy, thereby completing Internet encryption method operation.
[0124] The beneficial effects of the present invention are that, by storing data from participating Internet nodes through distributed ledger technology, the integrity and immutability of the data are significantly improved, ensuring the reliability of the basic stored data of participating nodes. At the same time, random number generators and multi-party secure computation are used to generate node random keys, which are distributed through secure channels, making the key generation and transmission process more secure and effectively avoiding the risks of single-point leakage and tampering. Based on historical network traffic data, this method combines anomaly detection algorithms and behavioral analysis techniques to construct an efficient Internet abnormal behavior analysis model. By extracting abnormal features, it can accurately identify abnormal traffic behavior and provide a reliable foundation for subsequent policy generation. In addition, by jointly processing abnormal traffic behavior data and random key recipient data, a behavioral encryption information strategy is generated and an Internet data encryption strategy is formulated, thereby achieving targeted and dynamic encryption configuration in the data encryption process, significantly improving the security and adaptability of Internet data. Finally, the generation of an Internet encryption policy report integrates the data processing results of the entire process, providing structured support for the verification and improvement of security policies, while reducing the complexity and errors of manual intervention. The entire process creates an efficient closed loop across data collection, processing, encryption, and verification, ensuring the security and availability of data during transmission and storage. Therefore, through the innovative combination of distributed ledgers, random key generation and distribution, and abnormal behavior analysis, this invention addresses the security deficiencies, inflexible policies, and data vulnerability inherent in traditional encryption methods, thereby improving the security, dynamism, and reliability of internet data encryption.
[0125] The present invention is therefore intended to be illustrative and non-restrictive in all respects, with the scope of the invention being defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the application documents are intended to be embraced therein.
[0126] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.
Claims
1. A method for encrypting Internet data, characterized in that: The following steps are involved: Step S1: Obtain Internet participating node data; Distributed ledger storage of Internet participating node data to generate basic storage data of Internet participating nodes; Step S2: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate Internet node random number keys; distribute the Internet node random number keys through a secure channel to generate random key recipient data; Step S3: Obtain historical network traffic data; perform abnormal traffic detection based on the historical network traffic data, and construct an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model; Step S4: Analyze abnormal traffic behavior of Internet participating node data based on the Internet abnormal behavior analysis model to generate abnormal traffic behavior data; Generate behavior encryption information strategy based on traffic abnormal behavior data and random key recipient data, and generate Internet data encryption strategy; Generate an Internet encryption policy report for the Internet data encryption policy, thereby completing the Internet encryption method operation; step S4 includes: Step S41: performing abnormal traffic behavior analysis on Internet participating node data based on an Internet abnormal behavior analysis model to generate traffic abnormal behavior data; Step S42: Generate a behavior encryption information strategy based on the traffic abnormal behavior data and the random key recipient data, and generate an Internet data encryption strategy; wherein step S42 includes: Step S421: Using a preset abnormal behavior threshold, the traffic abnormal behavior data is judged to generate traffic abnormal behavior result data, wherein the traffic abnormal behavior result data includes high abnormal behavior result data and low abnormal behavior result data; based on the traffic abnormal behavior result data, a behavior encryption information strategy is generated to generate an Internet data encryption strategy, wherein the Internet data encryption strategy includes an Internet high abnormality processing strategy and an Internet low abnormality processing strategy; Step S43: Encrypting the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data; generating an Internet encryption policy report based on the Internet information recipient transmission data, thereby completing the Internet encryption method operation; Step S43 includes: Step S431: Encrypting the random key recipient data based on the Internet data encryption policy to generate Internet information recipient transmission data; Step S432: Compare the Internet information receiver's transmission data with the basic storage data of the Internet participating nodes to generate transmission channel integrity comparison data; Step S433: Generate an Internet encryption strategy report based on the transmission channel integrity comparison data, thereby completing the Internet encryption method operation.
2. The Internet data encryption method according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: Obtain Internet participating node data; Step S12: Generate a unique identifier for the Internet participating node data to generate an Internet participating node UID; Step S13: Use the distributed ledger to store the Internet participating node UID and Internet participating node data to generate basic storage data of the Internet participating node.
3. The Internet data encryption method according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate an Internet node random number key; Step S22: Timestamp the Internet node random number key to generate random key timestamp-limited data; Step S23: Establish a secure channel through the ECDH protocol, distribute the Internet node random number key and random key timestamp limiting data, and generate random key recipient data.
4. The Internet data encryption method according to claim 3, characterized in that: Step S21 includes the following steps: Step S211: collecting the noise sources of the mechanical energy nodes of the Internet participating node data to generate Internet node noise source data; performing time jitter processing on the Internet node noise source data to generate Internet node time jitter data; Step S212: Adding hardware random noise according to the Internet node time jitter data to generate Internet node time-hardware noise data; Step S213: Perform distributed entropy pool synthesis processing on the Internet node time-hardware noise data to generate Internet node distributed entropy pool data; generate random numbers for the Internet node distributed entropy pool data, and perform multi-party secure calculation to generate the Internet node random number key.
5. The Internet data encryption method according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: Obtain historical network traffic data; Step S32: performing abnormal traffic detection based on historical network traffic data to generate historical traffic abnormal behavior data; Step S33: construct an abnormal behavior analysis model for the historical traffic abnormal behavior data to generate an Internet abnormal behavior analysis model.
6. The Internet data encryption method according to claim 5, characterized in that: Step S33 includes the following steps: Step S331: performing fluctuation analysis on the historical traffic abnormal behavior data to generate historical traffic abnormal fluctuation data; drawing a two-dimensional traffic fluctuation graph on the historical traffic abnormal fluctuation data to generate a historical traffic abnormal fluctuation graph; performing abnormal peak detection based on the historical traffic abnormal fluctuation graph to generate historical traffic fluctuation peak data; tracing the timestamp of the historical traffic fluctuation peak data to generate historical traffic abnormal behavior timestamp data; Step S332: The first layer of the model is constructed based on the historical traffic fluctuation anomaly data, and an abnormal traffic matrix analysis is performed to generate an Internet abnormal behavior-traffic anomaly layer. The second layer of the model is constructed based on the historical traffic fluctuation peak data, and point cloud computing processing is performed to generate an Internet abnormal behavior-fluctuation peak layer. The third layer of the model is constructed based on the historical traffic abnormal behavior timestamp data, and timestamp comparison is performed to generate an Internet abnormal behavior-timestamp layer. Step S333: construct an abnormal behavior analysis model for the Internet abnormal behavior-traffic abnormality layer, the Internet abnormal behavior-fluctuation peak layer, and the Internet abnormal behavior-timestamp layer to generate an Internet abnormal behavior analysis model.
7. The Internet data encryption method according to claim 1, characterized in that: Step S42 further includes the following steps: Step S422: When the traffic abnormality behavior result data is highly abnormal behavior result data, the Internet high abnormality processing strategy is applied to perform data sharding on the Internet node random number key to generate a multi-shard random number key, and perform a one-time key generation to generate a dynamic key enhanced data set; random noise is added to the traffic abnormality behavior data using block encryption to generate obfuscated traffic data; the dynamic key enhanced data set and the obfuscated traffic data are sent through two-way identity authentication, thereby completing the Internet high abnormality processing strategy; Step S423: When the traffic abnormal behavior result data is low abnormal behavior result data, the Internet low abnormality processing strategy is applied to perform lightweight encryption on the Internet node random number key to generate a lightweight key data set; the lightweight key data set is sent to complete the Internet low abnormality processing strategy.
8. An Internet data encryption system, characterized in that: For executing the Internet data encryption method according to claim 1, the Internet data encryption system comprises: The node data management module is used to obtain the data of Internet participating nodes; store the data of Internet participating nodes in a distributed ledger and generate basic storage data of Internet participating nodes; The random key generation and distribution module is used to generate random numbers for Internet participating node data using a random number generator and perform multi-party secure computation to generate random number keys for Internet nodes; distribute the Internet node random number keys through a secure channel to generate random key recipient data; The abnormal behavior modeling module is used to obtain historical network traffic data; perform abnormal traffic detection based on historical network traffic data, and build an abnormal behavior analysis model to generate an Internet abnormal behavior analysis model; The traffic anomaly analysis and encryption strategy module is used to analyze the abnormal traffic behavior of Internet participating node data based on the Internet abnormal behavior analysis model to generate traffic abnormal behavior data; generate behavior encryption information strategy based on traffic abnormal behavior data and random key recipient data to generate Internet data encryption strategy; generate Internet encryption strategy report for Internet data encryption strategy, thereby completing Internet encryption method operation.
Citation Information
Patent Citations
Processing method and device for multi-party security computing
CN115765985A
Data transmission information security management method and system based on Internet of Things
CN117914481A