Data encryption method and device, computer device, storage medium and program product
By acquiring data sensitivity, threat level, and resource usage, and using a fuzzy rule base to determine encryption strategies, the problem of insufficient flexibility in traditional data encryption methods is solved, achieving flexible and accurate data encryption and improving data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CLOUD TECH CO LTD
- Filing Date
- 2024-11-27
- Publication Date
- 2026-05-01
AI Technical Summary
Traditional data encryption methods cannot cope with diverse attacks and ever-changing security requirements, resulting in insufficient flexibility in data encryption and an inability to effectively improve data security.
By acquiring information on the data sensitivity, current threat level, and resource usage of the data encryption system, and utilizing fuzzy rules in a pre-defined rule base, an encryption strategy is determined for the data to be encrypted, including the encryption algorithm, encryption key, and encryption strength, thus achieving flexible data encryption.
It improves the flexibility and accuracy of data encryption, avoids the decline in data security caused by uniform encryption of all data, and ensures the security and reliability of data.
Smart Images

Figure CN119602952B_ABST
Abstract
Description
Data encryption methods, devices, computer equipment, storage media and software products Technical Field
[0001] This application relates to the field of network security technology, and in particular to a data encryption method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Technology
[0002] In the field of network security technology, data encryption ensures the confidentiality of data by converting information into ciphertext, preventing unauthorized access; at the same time, it ensures the integrity and authenticity of data, preventing data from being tampered with or forged; it supports authentication and non-repudiation, ensuring the authenticity of the identities of both parties in communication and the traceability of their behavior, which is conducive to maintaining information security, protecting privacy, and ensuring the reliability of network services.
[0003] Traditional technologies primarily encrypt all data using a uniform encryption method, which fails to address diverse attacks and evolving security needs, hindering the improvement of data encryption flexibility. Summary of the Invention
[0004] Therefore, it is necessary to provide a data encryption method, apparatus, computer equipment, computer-readable storage medium, and computer program product that can improve the flexibility of data encryption in response to the above-mentioned technical problems.
[0005] Firstly, this application provides a data encryption method, including:
[0006] The system acquires data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system; the data encryption system is used to encrypt the data.
[0007] Based on the data sensitivity information, the current threat level information, and the system resource usage information, an encryption strategy is determined for the data to be encrypted from a preset rule base; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted.
[0008] The data encryption system encrypts the data to be encrypted according to the encryption strategy information.
[0009] In one embodiment, the preset rule base includes fuzzy rules, which characterize the correspondence between data sensitivity, current threat level, system resource usage, and encryption strategies. The step of determining encryption strategy information for the data to be encrypted based on the data sensitivity information, the current threat level information, and the system resource usage information in the preset rule base includes:
[0010] Based on the data sensitivity information, the current threat level information, and the system resource usage information, target fuzzy rules are selected from the fuzzy rules in the preset rule base; the data sensitivity, current threat level, and system resource usage information corresponding to the target fuzzy rules are matched with the data sensitivity information, current threat level information, and system resource usage information.
[0011] The encryption strategy corresponding to the target fuzzy rule is determined to be the encryption strategy information for the data to be encrypted.
[0012] In one embodiment, the step of filtering target fuzzy rules from fuzzy rules in the preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information includes:
[0013] The data sensitivity, current threat level, and system resource usage corresponding to the fuzzy rules in the preset rule base are compared one by one with the data sensitivity information, the current threat level information, and the system resource usage information.
[0014] The fuzzy rules in the preset rule base that are consistent with the data sensitivity information, the current threat level, and the system resource usage information are consistent with the system resource usage information are used as target fuzzy rules.
[0015] In one embodiment, the step of filtering target fuzzy rules from fuzzy rules in the preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information includes:
[0016] Based on the data sensitivity corresponding to the fuzzy rules in the preset rule base, determine the data sensitivity range information of the fuzzy rules; based on the current threat level corresponding to the fuzzy rules in the preset rule base, determine the current threat level range information of the fuzzy rules; and based on the system resource usage corresponding to the fuzzy rules in the preset rule base, determine the system resource usage range information of the fuzzy rules.
[0017] The target fuzzy rule is selected from the fuzzy rules by comparing the data sensitivity information with the data sensitivity interval information of the fuzzy rule, the current threat level information with the pre-threat level interval information of the fuzzy rule, and the system resource usage information with the system resource usage interval information of the fuzzy rule.
[0018] In one embodiment, the step of comparing the data sensitivity information with the data sensitivity interval information of the fuzzy rule, the current threat level information with the pre-threat level interval information of the fuzzy rule, and the system resource usage information with the system resource usage interval information of the fuzzy rule, to filter out target fuzzy rules from the fuzzy rules in the preset rule base, includes:
[0019] A first fuzzy rule set is generated based on the fuzzy rules in which the data sensitivity interval information contains the data sensitivity information.
[0020] A second set of fuzzy rules is generated based on the fuzzy rules in which the current threat level interval information contains the current threat level information.
[0021] A third set of fuzzy rules is generated based on the fuzzy rules in which the system resource usage interval information includes the system resource usage information.
[0022] The target fuzzy rule is determined based on the intersection of the first fuzzy rule set, the second fuzzy rule set, and the third fuzzy rule set.
[0023] In one embodiment, after the step of encrypting the data to be encrypted by the data encryption system according to the encryption policy information, the method further includes:
[0024] Obtain the encrypted data corresponding to the data to be encrypted;
[0025] Obtain the storage location and / or transmission location corresponding to the encrypted data;
[0026] The encrypted data is stored in the storage location, and / or the encrypted data is sent to the transmission location.
[0027] Secondly, this application also provides a data encryption device, comprising:
[0028] The acquisition module is used to acquire data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system; the data encryption system is used to encrypt the data.
[0029] The determination module is used to determine encryption strategy information for the data to be encrypted based on the data sensitivity information, the current threat level information, and the system resource usage information in a preset rule base; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted.
[0030] An encryption module is used to encrypt the data to be encrypted according to the encryption strategy information through the data encryption system.
[0031] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program that, when executed by the processor, implements the steps of the method described above.
[0032] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of the above-described method.
[0033] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the above-described method.
[0034] The aforementioned data encryption methods, devices, computer equipment, computer-readable storage media, and computer program products acquire data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system. The data encryption system is used to encrypt data, thereby accurately analyzing the data sensitivity, current threat level, and resource usage of the data to be encrypted, so as to accurately determine the encryption method for the data to be encrypted from multiple perspectives such as data sensitivity, threat level, and system resources. Based on the data sensitivity information, current threat level information, and system resource usage information, an encryption strategy is determined for the data to be encrypted from a preset rule base. The encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted. By combining multiple perspectives such as data sensitivity, threat level, and system resources, and based on a rule base, it accurately analyzes the appropriate encryption algorithm, encryption key, and encryption strength for the data to be encrypted, improving the accuracy of the encryption strategy information. Through the data encryption system encrypting the data to be encrypted according to the encryption strategy information, it can adaptively determine the corresponding encryption algorithm, encryption key, and encryption strength from multiple perspectives such as data sensitivity, threat level, and system resources, achieving flexible encryption of information and avoiding the data security degradation caused by uniform encryption of all data, thus improving the flexibility of data encryption. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0036] Figure 1 is an application environment diagram of a data encryption method in one embodiment;
[0037] Figure 2 is a flowchart illustrating a data encryption method in one embodiment;
[0038] Figure 3 is a schematic diagram of the architecture of an adaptive data encryption system based on fuzzy logic in one embodiment;
[0039] Figure 4 is a structural block diagram of a data encryption device in one embodiment;
[0040] Figure 5 is an internal structure diagram of a computer device in one embodiment. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0042] The data encryption method provided in this application embodiment can be applied to the application environment shown in Figure 1. The terminal 102 communicates with the server 104 via a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104 or placed on the cloud or other network servers. The server 104 obtains the data sensitivity information and current threat level information of the data to be encrypted, as well as the system resource usage information of the data encryption system. The data encryption system is used to encrypt the data. The server 104 determines the encryption strategy information for the data to be encrypted based on the data sensitivity information, current threat level information, and system resource usage information in a preset rule base. The encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted. The server 104 encrypts the data to be encrypted according to the encryption strategy information through the data encryption system. The terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted devices, etc. Headset devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. Server 104 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server providing cloud computing services.
[0043] In an exemplary embodiment, as shown in FIG2, a data encryption method is provided. Taking the application of this method to a server as an example, the method includes the following steps S202 to S206. Wherein:
[0044] Step S202: Obtain the data sensitivity information and current threat level information of the data to be encrypted, as well as the system resource usage information of the data encryption system; the data encryption system is used to encrypt the data.
[0045] The data to be encrypted can refer to data that requires encryption. In practical applications, the data to be encrypted can come from any source (such as business data, user data, etc.) and is not limited to a specific industry, application, or data generation environment. The data types of the data to be encrypted can include, but are not limited to, text, images, audio, video, database records, network transmission data packets, and any combination of these forms.
[0046] Data sensitivity information refers to the degree of security protection required for the data to be encrypted. It reflects the potential harm that unauthorized access, use, disclosure, loss, or alteration of the data could cause. The level of data sensitivity indicated by this information determines the level of protection measures needed to ensure data security.
[0047] The current threat level information can refer to information that characterizes the severity of data security incidents targeting the data to be encrypted. In practical applications, data security incidents targeting the data to be encrypted can include data leakage of the data to be encrypted.
[0048] Among them, a data encryption system can refer to a system used to encrypt data.
[0049] Among them, system resource usage information can refer to information that characterizes the current usage status of various resources (such as CPU, memory, disk, network, etc.) of the data encryption system.
[0050] As an example, a server can encrypt data using a data encryption system. When the server obtains the data to be encrypted, it can analyze the data sensitivity and current threat level of the data to be encrypted, and determine the data sensitivity information and current threat level information of the data to be encrypted. At the same time, since the resource usage of the data encryption system affects the performance of the data encryption system, and the performance of the data encryption system affects whether the data encryption operation is completed accurately, the server can also obtain system resource usage information to characterize the resource usage of the data encryption system at the current moment, so as to combine the data sensitivity information, current threat level information, and system resource usage information to determine the data encryption method for the data to be encrypted.
[0051] Step S204: Based on data sensitivity information, current threat level information, and system resource usage information, determine the encryption strategy information for the data to be encrypted in the preset rule base; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted.
[0052] The preset rule base can refer to a pre-set database containing several preset rules. In practical applications, each preset rule can be used to describe specific data sensitivity information, current threat level information, and system resource usage information.
[0053] The encryption strategy information can refer to the information that characterizes the encryption algorithm, encryption key and encryption strength for the data to be encrypted. In practical applications, each preset rule can have corresponding encryption strategy information.
[0054] As an example, to determine the data encryption method to be used when encrypting data to be encrypted, the server can obtain a preset rule base. The preset rule base contains several preset rules. Since each preset rule can describe specific data sensitivity information, current threat level information, and system resource usage information, the server can compare each preset rule with the data sensitivity information, current threat level information, and system resource usage information obtained by the server. The encryption policy corresponding to the selected preset rule is used as the encryption policy information for the data to be encrypted. Based on the encryption policy information for the data to be encrypted, the data encryption method for the data to be encrypted is determined.
[0055] Step S206: The data to be encrypted is encrypted by the data encryption system according to the encryption strategy information.
[0056] As an example, the server can analyze the encryption algorithm, encryption key, and encryption strength described / represented by the encryption policy information for the data to be encrypted, and then encrypt the data according to the encryption key and encryption strength described / represented by the encryption policy information for the data to be encrypted, using the encryption algorithm described / represented by the encryption policy information for the data to be encrypted.
[0057] In the aforementioned data encryption method, the data sensitivity information and current threat level information of the data to be encrypted, as well as the system resource usage information of the data encryption system, are obtained. The data encryption system is used to encrypt the data, thereby accurately analyzing the data sensitivity, current threat level, and system resource usage of the data to be encrypted, so as to accurately determine the encryption method for the data to be encrypted from multiple perspectives such as data sensitivity, threat level, and system resources. Based on the data sensitivity information, current threat level information, and system resource usage information, the encryption strategy information for the data to be encrypted is determined in a preset rule base. The encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted. Thus, by combining multiple perspectives such as data sensitivity, threat level, and system resources, the rule base is used to accurately analyze the encryption algorithm, encryption key, and encryption strength suitable for encrypting the data to be encrypted, improving the accuracy of the encryption strategy information. By encrypting the data to be encrypted according to the encryption strategy information, the corresponding encryption algorithm, encryption key, and encryption strength can be adaptively determined from multiple perspectives such as data sensitivity, threat level, and system resources, achieving flexible encryption of information and avoiding the data security degradation caused by uniform encryption of all data, thereby improving the flexibility of data encryption.
[0058] In an exemplary embodiment, a preset rule base includes fuzzy rules. These fuzzy rules characterize the correspondence between data sensitivity, current threat level, system resource usage, and encryption policies. Based on data sensitivity information, current threat level information, and system resource usage information, encryption policy information for the data to be encrypted is determined within the preset rule base. This includes: filtering target fuzzy rules from the fuzzy rules in the preset rule base based on the data sensitivity information, current threat level information, and system resource usage information; matching the data sensitivity, current threat level, and system resource usage information corresponding to the target fuzzy rule with the data sensitivity information, current threat level information, and system resource usage information; and determining the encryption policy corresponding to the target fuzzy rule as the encryption policy information for the data to be encrypted.
[0059] Here, fuzzy rules refer to information that characterizes the correspondence between data sensitivity, current threat level, system resource usage, and encryption policies. In practical applications, each fuzzy rule can have a corresponding encryption policy. In the specific implementation, the fuzzy rules in the preset rule base can be updated in real time.
[0060] Among them, target fuzzy rules can refer to fuzzy rules in a preset rule base that match data sensitivity, current threat level, and system resource usage with data sensitivity information, current threat level information, and system resource usage information.
[0061] As an example, a pre-defined rule base can contain several fuzzy rules. Each fuzzy rule can be used to characterize the correspondence between data sensitivity, current threat level, system resource usage, and encryption policy. For example, fuzzy rule M1 can be used to characterize the correspondence between data sensitivity A1, current threat level B1, and system resource usage C1 and encryption policy D1, and fuzzy rule M2 can be used to characterize the correspondence between data sensitivity A2, current threat level B2, and system resource usage C2 and encryption policy D2. Therefore, in order to accurately analyze the appropriate encryption method for the data to be encrypted, the server can, based on the data sensitivity information, current threat level information, and system resource usage information obtained by the server, select fuzzy rules from the fuzzy rules in the pre-defined rule base that match the data sensitivity, current threat level, and system resource usage information as target fuzzy rules, and determine the encryption policy corresponding to the target fuzzy rule as the encryption policy information for the data to be encrypted.
[0062] In this embodiment, a target fuzzy rule is selected from fuzzy rules in a preset rule base based on data sensitivity information, current threat level information, and system resource usage information. The data sensitivity, current threat level, and system resource usage information corresponding to the target fuzzy rule match the data sensitivity information, current threat level information, and system resource usage information. The encryption strategy corresponding to the target fuzzy rule is determined to be the encryption strategy information for the data to be encrypted. This method can accurately select the target fuzzy rule from the fuzzy rules in the preset rule base based on data sensitivity information, current threat level information, and system resource usage information, and determine the encryption strategy corresponding to the target fuzzy rule as the encryption strategy information for the data to be encrypted. This improves the accuracy of the encryption strategy information, enabling adaptive data encryption based on the encryption strategy information and improving the flexibility of data encryption.
[0063] In some embodiments, target fuzzy rules are selected from fuzzy rules in a preset rule base based on data sensitivity information, current threat level information, and system resource usage information. This includes: comparing the data sensitivity, current threat level, and system resource usage corresponding to the fuzzy rules in the preset rule base with the data sensitivity information, current threat level information, and system resource usage information; and selecting fuzzy rules in the preset rule base that are consistent with the data sensitivity information, the current threat level information, and the system resource usage information as target fuzzy rules.
[0064] As an example, the precision of the data sensitivity, current threat level, and system resource usage described / represented by the fuzzy rule will affect the selection method of the target fuzzy rule. In practical applications, when the precision of the data sensitivity, current threat level, and system resource usage described / represented by the fuzzy rule meets the first precision requirement (e.g., each fuzzy rule only describes / represents a specific data sensitivity information, a specific current threat level information, and a specific system resource usage information), the server can compare the data sensitivity, current threat level, and system resource usage corresponding to the fuzzy rules in the preset rule base with the data sensitivity information, current threat level information, and system resource usage information, and select the fuzzy rules in the preset rule base that are consistent with the data sensitivity information, the current threat level information, and the system resource usage information as the target fuzzy rules. For example, the server can construct virtual fuzzy rules based on the data sensitivity information, current threat level information, and system resource usage information obtained by the server, and search in the preset rule base whether there is a fuzzy rule with the same content as the virtual fuzzy rule. If there is a fuzzy rule with the same content as the virtual fuzzy rule in the preset rule base, the server can use that fuzzy rule as the target fuzzy rule.
[0065] In this embodiment, by comparing the data sensitivity, current threat level, and system resource usage of the fuzzy rules in the preset rule base with the data sensitivity information, current threat level information, and system resource usage information, the fuzzy rules in the preset rule base that are consistent with the data sensitivity information, current threat level information, and system resource usage information are selected as target fuzzy rules. This allows for accurate selection of target fuzzy rules from the preset rule base, improving the accuracy of the target fuzzy rules. Based on the target fuzzy rules, accurate encryption strategy information can be determined, thereby improving the flexibility of data encryption.
[0066] In some embodiments, target fuzzy rules are selected from fuzzy rules in a preset rule base based on data sensitivity information, current threat level information, and system resource usage information. This includes: determining the data sensitivity interval information of the fuzzy rules based on the data sensitivity corresponding to the fuzzy rules in the preset rule base; determining the current threat level interval information of the fuzzy rules based on the current threat level corresponding to the fuzzy rules in the preset rule base; and determining the system resource usage interval information of the fuzzy rules based on the system resource usage corresponding to the fuzzy rules in the preset rule base. The target fuzzy rules are then selected by comparing the data sensitivity information with the data sensitivity interval information of the fuzzy rules, the current threat level information with the current threat level interval information of the fuzzy rules, and the system resource usage information with the system resource usage interval information of the fuzzy rules.
[0067] Among them, the data sensitivity interval information can refer to the information that characterizes the range of data sensitivity corresponding to / described by the fuzzy rule.
[0068] Here, the current threat level range information can refer to information that characterizes the range of the current threat level corresponding to / described by the fuzzy rule.
[0069] Among them, the system resource usage interval information can refer to information that characterizes the range of system resource usage corresponding to / described by the fuzzy rule.
[0070] As an example, the precision of the data sensitivity, current threat level, and system resource usage described / represented by fuzzy rules affects the selection method of target fuzzy rules. In practical applications, when the precision of the data sensitivity, current threat level, and system resource usage described / represented by fuzzy rules meets the second precision requirement (e.g., each fuzzy rule only describes / represents one range of data sensitivity, one range of current threat level, and one range of system resource usage), the server can first analyze the range of data sensitivity, current threat level, and system resource usage described / represented by each fuzzy rule in the preset rule base, and then select the appropriate rule based on the data sensitivity described / represented by the fuzzy rule. The server can determine the data sensitivity range of the fuzzy rule based on the range of the current threat level described / represented by the fuzzy rule, and the system resource usage range of the fuzzy rule based on the range of system resource usage described / represented by the fuzzy rule. Then, the server can compare the data sensitivity information obtained by the server with the data sensitivity range of the fuzzy rule, the current threat level information with the previous threat level range of the fuzzy rule, and the system resource usage information with the system resource usage range of the fuzzy rule, and select the target fuzzy rule from the fuzzy rules in the preset rule base.
[0071] In this embodiment, the data sensitivity range information of fuzzy rules is determined based on the data sensitivity corresponding to fuzzy rules in a preset rule base; the current threat level range information of fuzzy rules is determined based on the current threat level corresponding to fuzzy rules in the preset rule base; and the system resource usage range information of fuzzy rules is determined based on the system resource usage corresponding to fuzzy rules in the preset rule base. The data sensitivity information is compared one by one with the data sensitivity range information of fuzzy rules, the current threat level information is compared with the current threat level range information of fuzzy rules, and the system resource usage information is compared with the system resource usage range information of fuzzy rules. This allows for the selection of target fuzzy rules from the preset rule base. This process accurately analyzes the range described / represented by each fuzzy rule and, by combining the data sensitivity information, current threat level information, and system resource usage information, selects accurate target fuzzy rules from the preset rule base, improving the accuracy of the target fuzzy rules. This enables the determination of accurate encryption strategy information based on the target fuzzy rules, thereby enhancing the flexibility of data encryption.
[0072] In some embodiments, the data sensitivity information is compared one by one with the data sensitivity interval information of the fuzzy rules, the current threat level information is compared with the pre-threat level interval information of the fuzzy rules, and the system resource usage information is compared with the system resource usage interval information of the fuzzy rules. Target fuzzy rules are then selected from the fuzzy rules in a preset rule base. This includes: generating a first set of fuzzy rules based on fuzzy rules whose data sensitivity interval information contains data sensitivity information; generating a second set of fuzzy rules based on fuzzy rules whose current threat level interval information contains current threat level information; generating a third set of fuzzy rules based on fuzzy rules whose system resource usage interval information contains system resource usage information; and determining the target fuzzy rule based on the intersection of the first, second, and third sets of fuzzy rules.
[0073] The first fuzzy rule set can refer to a set of fuzzy rules in a preset rule base that contain data sensitivity information within the data sensitivity interval.
[0074] The second fuzzy rule set can refer to the set of fuzzy rules in the preset rule base that contain the current threat level range information.
[0075] The third fuzzy rule set can refer to the set of fuzzy rules in the preset rule base that contain information on the system resource usage interval.
[0076] As an example, the server can first filter out fuzzy rules whose data sensitivity interval information contains data sensitivity information to generate a first fuzzy rule set. Then, the server can filter out fuzzy rules whose current threat level interval information contains current threat level information to generate a second fuzzy rule set. Then, the server can filter out fuzzy rules whose system resource usage interval information contains system resource usage information to generate a third fuzzy rule set. After that, the server can calculate the intersection of the first, second, and third fuzzy rule sets, and the fuzzy rules in this intersection can be used as target fuzzy rules. In practical applications, during the process of filtering fuzzy rules and generating a fuzzy rule set based on data sensitivity information, current threat level information, and system resource usage information, the server can first filter out fuzzy rules whose current threat level range information contains the current threat level information, generating a fourth fuzzy rule set. Then, the server can filter out fuzzy rules whose data sensitivity range information contains data sensitivity information, generating a fifth fuzzy rule set. Afterward, the server can filter out fuzzy rules whose system resource usage range information contains system resource usage information, generating a sixth fuzzy rule set. Finally, the server can calculate the intersection of the fourth, fifth, and sixth fuzzy rule sets, and the fuzzy rules in this intersection can be used as the target fuzzy rules. It is understandable that the order in which these three information are filtered can be flexibly adjusted during the process of filtering and generating a fuzzy rule set based on data sensitivity information, current threat level information, and system resource usage information.
[0077] In this embodiment, a first set of fuzzy rules is generated based on fuzzy rules where the data sensitivity interval information contains data sensitivity information; a second set of fuzzy rules is generated based on fuzzy rules where the current threat level interval information contains current threat level information; and a third set of fuzzy rules is generated based on fuzzy rules where the system resource usage interval information contains system resource usage information. The target fuzzy rule is determined based on the intersection of the first, second, and third sets of fuzzy rules. This approach allows for the initial screening of fuzzy rule sets and the calculation of the intersection between these sets to determine the target fuzzy rule, improving the accuracy of the target fuzzy rule. This enables the determination of accurate encryption strategy information based on the target fuzzy rule, thereby enhancing the flexibility of data encryption.
[0078] In some embodiments, after the step of encrypting the data to be encrypted by the data encryption system according to the encryption policy information, the above method further includes: obtaining the encrypted data corresponding to the data to be encrypted; obtaining the storage location and / or transmission location corresponding to the encrypted data; storing the encrypted data in the storage location; and / or sending the encrypted data to the transmission location.
[0079] The encrypted data can refer to the data obtained by encrypting the data according to the encryption key and encryption strength described / characterized by the encryption strategy information for the data to be encrypted, and using the encryption algorithm described / characterized by the encryption strategy information for the data to be encrypted.
[0080] The storage location can refer to the location used to store the encrypted data.
[0081] The transmission location can refer to the location used to receive encrypted data.
[0082] As an example, the server encrypts the data to be encrypted using the encryption key and encryption strength described / represented by the encryption policy information for the data to be encrypted, and employs the encryption algorithm described / represented by the encryption policy information for the data to be encrypted. The encrypted data is then obtained. The server can then obtain information on how to process the encrypted data (such as storage and transmission). If the encrypted data needs to be stored, the server can obtain the corresponding storage location and store the encrypted data in that location. If the encrypted data needs to be transmitted, the server can obtain the corresponding transmission location / transmission target and transmit / send the encrypted data to / to the corresponding storage location / transmission target.
[0083] In this embodiment, by obtaining the encrypted data corresponding to the data to be encrypted; obtaining the storage location and / or transmission location corresponding to the encrypted data; storing the encrypted data in the storage location; and / or sending the encrypted data to the transmission location, it is possible to ensure that the encrypted data is securely stored or transmitted, thus guaranteeing the security of the encrypted data.
[0084] In some embodiments, an adaptive data encryption system based on fuzzy logic can be used to implement data encryption. Figure 3 shows a schematic diagram of the architecture of such a system. The system may include an input module, a fuzzy logic controller, an encryption module, and an output module. The input module receives and processes raw data, extracts and transmits key information such as data type and sensitivity. It is the starting point of the system, responsible for collecting the data to be encrypted and performing preliminary processing to extract key information such as data type and sensitivity level. This information serves as the basis for subsequent decisions by the fuzzy logic controller. The fuzzy logic controller dynamically adjusts the encryption strategy and parameters based on the information provided by the input module. As the core component of the system, it receives data from the input module and, through fuzzy logic reasoning, dynamically adjusts the encryption strategy and parameters according to a predefined fuzzy rule base, including selecting appropriate encryption algorithms and key lengths. The encryption module performs the actual data encryption operation. The encryption module, based on the output of the fuzzy logic controller, selects the most suitable encryption algorithm (such as AES, RSA, etc.) and key length according to the current data characteristics and security requirements, and performs data encryption to ensure data security during storage and transmission. The output module's functions include outputting encrypted data and storing or transmitting it. The output module is responsible for receiving encrypted data generated by the encryption module and outputting it to a designated location or transmitting it securely. The output module is also responsible for managing and monitoring encrypted data to ensure data security throughout the entire storage and transmission process.
[0085] The input variables of the fuzzy logic controller include data sensitivity, current threat level, and system resource usage. These input variables form the basis for the controller's decisions. Data sensitivity determines the importance of the data, the current threat level reflects the security status of the current network environment, and system resource usage affects the system's performance requirements when performing encryption operations. The fuzzy logic controller has a fuzzy rule base, which defines fuzzy rules based on the input variables and determines encryption strategies and parameters. The fuzzy rule base contains a series of predefined fuzzy rules that determine corresponding encryption strategies and parameters based on different combinations of input variables. For example, when data sensitivity is high and the current threat level is high, a high-strength encryption algorithm and a longer key are selected. The output variables of the fuzzy logic controller include encryption algorithm selection, key length, and encryption strength. These output variables determine the specific operations of the encryption module. Based on the inference results of the fuzzy rule base, appropriate encryption algorithms and parameters are dynamically generated to execute effective encryption operations.
[0086] The steps for implementing data encryption in an adaptive data encryption system based on fuzzy logic can include: (1) Data collection and preparation: Collect and prepare the data to be encrypted, and extract data type and sensitivity information. This step ensures that the system obtains sufficient information to make accurate encryption decisions. (2) Input variable evaluation: Evaluate input variables such as data sensitivity and current threat level through fuzzy logic. This step evaluates the current security requirements and environmental conditions, providing basic data for fuzzy inference. (3) Fuzzy inference: Use the fuzzy logic controller and rule base to perform fuzzy inference and determine the encryption strategy and parameters. Through fuzzy inference, the system can select the best encryption scheme under different circumstances. (4) Encryption operation: Based on the fuzzy inference results, select an appropriate encryption algorithm (such as AES, RSA, etc.) and key length to encrypt the data. Perform specific encryption operations to ensure the security of the data during storage and transmission. (5) Output processing: Output the encrypted data and store or transmit it. Ensure that the encrypted data is securely stored or transmitted to the target location to prevent data leakage or tampering.
[0087] In practical applications, fuzzy logic-based adaptive data encryption systems can also manage encryption keys. Specifically, these systems can dynamically generate encryption keys based on fuzzy logic evaluation results. The key generation process is based on the output of the fuzzy logic controller, ensuring that the key length and complexity match current security requirements. Furthermore, fuzzy logic-based adaptive data encryption systems can securely store and distribute encryption keys, ensuring key security. The key management system must ensure that keys are not accessed without authorization during generation, storage, and use.
[0088] In practical implementation, fuzzy logic-based adaptive data encryption systems can be used for security encryption in cloud storage systems. By dynamically adjusting encryption strategies, they ensure the security and privacy of cloud storage data, achieving secure cloud storage encryption. Fuzzy logic-based adaptive data encryption systems can also be used for data protection in mobile devices. Through adaptive encryption, they enhance the defense capabilities of mobile devices against diverse attacks, achieving data protection for mobile devices. Furthermore, fuzzy logic-based adaptive data encryption systems can be implemented in Internet of Things (IoT) devices, enhancing the overall security of IoT systems. They can also be applied to e-commerce platforms, protecting the security of transaction data, preventing data leakage and tampering, and ensuring the security of e-commerce transactions. Finally, fuzzy logic-based adaptive data encryption systems can be used for sensitive data protection for enterprises and other entities. Through intelligent encryption methods, they improve data security and management efficiency, ensuring enterprise data security.
[0089] In this embodiment, by dynamically adjusting the encryption strategy, the encryption strategy can be dynamically selected and adjusted based on factors such as real-time data type, sensitivity, and current threat level. This allows for automatic optimization of its operation in different environments to address various security challenges. Whether facing sudden high-threat attacks or routine low-threat environments, the security measures can be automatically adjusted to ensure the most suitable encryption protection is always provided, thereby improving adaptability to environmental changes. By introducing fuzzy logic, uncertainties and complexities that traditional encryption methods struggle to handle can be addressed. This enables more accurate assessment of threats and data sensitivity, leading to the development of more intelligent encryption strategies, thus processing uncertainty based on fuzzy logic. The fuzzy logic controller can adjust its operation based on input variables (such as data...). The system adjusts encryption parameters (such as encryption algorithms and key lengths) in real time based on sensitivity and threat level to achieve intelligent encryption management, improve overall security performance, and realize intelligent parameter management. While ensuring security, it optimizes resource utilization to the maximum extent through intelligent encryption strategy selection. For example, it reduces encryption strength in low-threat environments to save computing resources and time, thereby optimizing resource utilization. By selecting the most suitable encryption method and key length, it ensures that encryption and decryption operations are performed with the highest efficiency under different conditions, reducing processing time, improving system performance, and enhancing encryption and decryption efficiency. Combining multiple encryption methods (such as symmetric and asymmetric encryption) and fuzzy logic technology provides multi-layered security protection. These technologies can be flexibly combined under different data and environmental conditions to maximize data security and achieve multi-layered security protection. Through the intelligent judgment and dynamic adjustment of the fuzzy logic system, it can effectively cope with various known and unknown attacks, increasing the difficulty for attackers to breach security defenses.
[0090] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0091] Based on the same inventive concept, this application also provides a data encryption device for implementing the data encryption method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more data encryption device embodiments provided below can be found in the limitations of the data encryption method described above, and will not be repeated here.
[0092] In an exemplary embodiment, as shown in FIG4, a data encryption device is provided, including: an acquisition module 402, a determination module 404, and an encryption module 406, wherein:
[0093] The acquisition module 402 is used to acquire data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system; the data encryption system is used to encrypt the data.
[0094] The determination module 404 is used to determine encryption strategy information for the data to be encrypted based on the data sensitivity information, the current threat level information, and the system resource usage information in a preset rule base; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted.
[0095] The encryption module 406 is used to encrypt the data to be encrypted by the data encryption system according to the encryption strategy information.
[0096] In one exemplary embodiment, the preset rule base includes fuzzy rules, which characterize the correspondence between data sensitivity, current threat level, system resource usage, and encryption strategy. The determining module 404 is further configured to filter out target fuzzy rules from the fuzzy rules in the preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information; the data sensitivity, current threat level, and system resource usage corresponding to the target fuzzy rule match the data sensitivity information, the current threat level information, and the system resource usage information; and determine that the encryption strategy corresponding to the target fuzzy rule is the encryption strategy information for the data to be encrypted.
[0097] In one exemplary embodiment, the determining module 404 is further configured to compare the data sensitivity, current threat level, and system resource usage corresponding to the fuzzy rules in the preset rule base with the data sensitivity information, the current threat level information, and the system resource usage information; and to select the fuzzy rules in the preset rule base that have the same data sensitivity as the data sensitivity information, the same current threat level as the current threat level information, and the same system resource usage information as the system resource usage information as the target fuzzy rules.
[0098] In one exemplary embodiment, the determining module 404 is further configured to determine the data sensitivity interval information of the fuzzy rule based on the data sensitivity corresponding to the fuzzy rule in the preset rule base, determine the current threat level interval information of the fuzzy rule based on the current threat level corresponding to the fuzzy rule in the preset rule base, and determine the system resource usage interval information of the fuzzy rule based on the system resource usage corresponding to the fuzzy rule in the preset rule base; compare the data sensitivity information with the data sensitivity interval information of the fuzzy rule, the current threat level information with the current threat level interval information of the fuzzy rule, and the system resource usage information with the system resource usage interval information of the fuzzy rule one by one, and filter out the target fuzzy rule from the fuzzy rules in the preset rule base.
[0099] In one exemplary embodiment, the determining module 404 is further configured to generate a first fuzzy rule set based on fuzzy rules in the fuzzy rules that contain the data sensitivity information within the data sensitivity interval information; generate a second fuzzy rule set based on fuzzy rules in the fuzzy rules that contain the current threat level information within the current threat level interval information; generate a third fuzzy rule set based on fuzzy rules in the fuzzy rules that contain the system resource usage information within the system resource usage interval information; and determine the target fuzzy rule based on the intersection of the first fuzzy rule set, the second fuzzy rule set, and the third fuzzy rule set.
[0100] In one exemplary embodiment, the apparatus further includes a transmission module, which is specifically configured to: acquire encrypted data corresponding to the data to be encrypted; acquire a storage location and / or transmission location corresponding to the encrypted data; store the encrypted data in the storage location; and / or send the encrypted data to the transmission location.
[0101] Each module in the aforementioned data encryption device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0102] In an exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram is shown in Figure 5. The computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is connected to the system bus via the I / O interfaces. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the computer device stores data sensitivity information, current threat level information, system resource usage information, and preset rule bases, etc. The I / O interfaces of the computer device are used for exchanging information between the processor and external devices. The communication interface of the computer device is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a data encryption method.
[0103] Those skilled in the art will understand that the structure shown in Figure 5 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or may combine certain components, or may have different component arrangements.
[0104] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0105] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0106] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0107] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0108] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0109] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0110] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A data encryption method, characterized in that, The method includes: acquiring data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system; the data encryption system is used to encrypt the data; when the accuracy of the data sensitivity, current threat level, and system resource usage described by the fuzzy rule meets the accuracy requirements, a target fuzzy rule is selected from the fuzzy rules in a preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information; the data sensitivity, current threat level, and system resource usage corresponding to the target fuzzy rule match the data sensitivity information, the current threat level information, and the system resource usage information; the fuzzy rule represents the correspondence between the data sensitivity, current threat level, and system resource usage and the encryption strategy; the encryption strategy corresponding to the target fuzzy rule is determined as the encryption strategy information for the data to be encrypted; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted; and the data encryption system encrypts the data to be encrypted according to the encryption strategy information.
2. The method according to claim 1, characterized in that, The step of selecting target fuzzy rules from the fuzzy rules in the preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information includes: comparing the data sensitivity, current threat level, and system resource usage corresponding to the fuzzy rules in the preset rule base with the data sensitivity information, the current threat level information, and the system resource usage information; and selecting the fuzzy rules in the preset rule base that have the same data sensitivity as the data sensitivity information, the same current threat level as the current threat level information, and the same system resource usage information as the system resource usage information as the target fuzzy rules.
3. The method according to claim 1, characterized in that, The step of selecting target fuzzy rules from fuzzy rules in the preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information includes: determining the data sensitivity interval information of the fuzzy rule based on the data sensitivity corresponding to the fuzzy rule in the preset rule base; determining the current threat level interval information of the fuzzy rule based on the current threat level corresponding to the fuzzy rule in the preset rule base; and determining the system resource usage interval information of the fuzzy rule based on the system resource usage corresponding to the fuzzy rule in the preset rule base; comparing the data sensitivity information with the data sensitivity interval information of the fuzzy rule, the current threat level information with the previous threat level interval information of the fuzzy rule, and the system resource usage information with the system resource usage interval information of the fuzzy rule, and selecting target fuzzy rules from the fuzzy rules in the preset rule base.
4. The method according to claim 3, characterized in that, The step of comparing the data sensitivity information with the data sensitivity interval information of the fuzzy rules, the current threat level information with the pre-threat level interval information of the fuzzy rules, and the system resource usage information with the system resource usage interval information of the fuzzy rules, and filtering the target fuzzy rule from the fuzzy rules in the preset rule base, includes: generating a first fuzzy rule set based on fuzzy rules whose data sensitivity interval information contains the data sensitivity information; generating a second fuzzy rule set based on fuzzy rules whose current threat level interval information contains the current threat level information; generating a third fuzzy rule set based on fuzzy rules whose system resource usage interval information contains the system resource usage information; and determining the target fuzzy rule based on the intersection of the first fuzzy rule set, the second fuzzy rule set, and the third fuzzy rule set.
5. The method according to claim 1, characterized in that, After the step of encrypting the data to be encrypted by the data encryption system according to the encryption strategy information, the method further includes: obtaining the encrypted data corresponding to the data to be encrypted; obtaining the storage location and / or transmission location corresponding to the encrypted data; storing the encrypted data in the storage location; and / or sending the encrypted data to the transmission location.
6. A data encryption device, characterized in that, The device includes: an acquisition module, configured to acquire data sensitivity information and current threat level information of the data to be encrypted, as well as system resource usage information of the data encryption system; the data encryption system is used to encrypt the data; a determination module, configured to, when the accuracy of the data sensitivity, current threat level, and system resource usage described by the fuzzy rule meets the accuracy requirements, filter out a target fuzzy rule from the fuzzy rules in a preset rule base based on the data sensitivity information, the current threat level information, and the system resource usage information; the data sensitivity, current threat level, and system resource usage corresponding to the target fuzzy rule match the data sensitivity information, the current threat level information, and the system resource usage information; the fuzzy rule represents the correspondence between the data sensitivity, current threat level, and system resource usage and the encryption strategy; determine the encryption strategy corresponding to the target fuzzy rule as encryption strategy information for the data to be encrypted; the encryption strategy information represents the encryption algorithm, encryption key, and encryption strength for the data to be encrypted; and an encryption module, configured to encrypt the data to be encrypted according to the encryption strategy information through the data encryption system.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Data asset processing method and system based on multilayer encryption auditing
CN118036035A