An intelligent processing system for encrypted communication data
Through the intelligent processing system for communication data encryption, combining demand analysis, encryption configuration and encryption modules, encryption strategies are dynamically adjusted, which solves the problem of insufficient flexibility of existing encryption systems and improves the security and reliability of diversified encryption requirements.
Patent Information
- Application Number
- CN202411795954.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-12-09
AI Technical Summary
The existing encryption systems lack flexibility and are difficult to cope with diversified encryption needs. The lack of real-time analysis of the progress of encrypted data attack recording and decryption technology has made it difficult to adjust encryption strategies in a timely manner, increasing the risk of data leakage.
The intelligent processing system for communication data encryption is adopted, including requirements analysis module, encryption configuration module and encryption module. Through data background statistics, attack record analysis and encryption strategy model, the encryption method is dynamically adjusted, and a variety of encryption algorithms are combined to form complementary effects to improve the security and reliability of encryption.
It realizes dynamic encryption processing based on actual needs, meets the encryption needs of different application scenarios, improves the security and reliability of encryption, and enhances cracking difficulty and data confidentiality.
Smart Images

Figure CN119628930B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of communication data encryption, and specifically relates to an intelligent processing system for communication data encryption. Background Art
[0002] In the current digital age, the encryption requirements for communication data are becoming increasingly diverse and complex. With the rapid development of technologies such as cloud computing, big data, and the Internet of Things, the transmission and storage of communication data are facing unprecedented security challenges. Traditional static encryption methods and single encryption strategies can no longer meet the diverse encryption requirements. Especially when faced with evolving decryption technologies and potential attack methods, existing encryption systems often seem inadequate.
[0003] Most encryption systems in the prior art rely on fixed encryption algorithms and strategies and lack the ability to flexibly respond to different demand scenarios. For example, when using a device in a public place, if the encryption level can be improved, it will better ensure the security of data transmission. In addition, these systems often lack the analysis of real-time data such as encryption data attack records and the progress of existing decryption technologies, resulting in difficulty in timely adjusting and optimizing encryption strategies, thus increasing the risk of data leakage.
[0004] Based on this, the present invention provides an intelligent processing system for communication data encryption. Summary of the Invention
[0005] In order to solve the problems existing in the above solutions, the present invention provides an intelligent processing system for communication data encryption.
[0006] The object of the present invention can be achieved through the following technical solutions:
[0007] An intelligent processing system for communication data encryption includes a requirement analysis module, an encryption configuration module, and an encryption module;
[0008] The requirement analysis module is used to perform encryption requirement analysis to determine the user's encryption requirements and the encryption requirements corresponding to the encryption requirements.
[0009] Further, performing encryption requirement analysis includes:
[0010] The platform party sets up a data background statistical table, and the data background statistical table is used to count each data background;
[0011] According to the user, the communication data range is determined, and the communication data range is composed of various communication data types;
[0012] According to the data background statistical table, the data background corresponding to each communication data type within the communication data range is obtained and marked as the application background;
[0013] Form a user encryption analysis table according to the communication data range and application background; set encryption requirements and encryption specifications according to the user encryption analysis table.
[0014] Further, the setting of the data background includes:
[0015] Step SA1: Obtain various types of communication data within the service scope of the platform party, and count the attack record data corresponding to the types of communication data;
[0016] Identify each initial background corresponding to the attack record data, and count the attack representative values corresponding to the initial backgrounds;
[0017] Sort the initial backgrounds in descending order of the attack representative values to obtain a first sequence;
[0018] Step SA2: Mark the initial background ranked first in the first sequence as the base background, and mark the initial background adjacent to the benchmark background in the ranking as the candidate background;
[0019] When there is no base background, end the analysis;
[0020] When there is no candidate background, mark the base background as the data background, end the analysis;
[0021] Step SA3: Calculate the absolute value of the difference between the attack representative values of the base background and the candidate background, and mark it as the base difference;
[0022] Step SA4: Judge whether the base background and the candidate background meet the merging requirements according to the base difference;
[0023] When it is judged that the merging requirements are met, merge the base background and the candidate background to form a new base background, mark the initial background adjacent to the new benchmark background in the ranking as the candidate background, and return to step SA3; when there is no candidate background, mark the new base background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2;
[0024] When it is judged that the merging requirements are not met, mark the base background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2.
[0025] Further, judging whether the base background and the candidate background meet the merging requirements includes:
[0026] Establish a merging judgment formula, and the expression of the merging judgment formula is:
[0027]
[0028] Where: q is the reference difference value; p is the merging requirement; q→p means that the reference difference value meets the merging requirement; HP(q, p) is the merging judgment value;
[0029] Calculate the merging judgment value between the basic background and the candidate background through the merging judgment formula;
[0030] When the merging judgment value is 1, it is judged that the merging requirement is met;
[0031] When the merging judgment value is 0, it is judged that the non-merging requirement is met.
[0032] Furthermore, the calculation of the attack representative value includes:
[0033] The platform party establishes a sensitive statistical table, and the sensitive statistical table is used to count the sensitive values of corresponding communication data types;
[0034] Match the corresponding sensitive value from the sensitive statistical table according to the initial background; identify the frequency representative value of the initial background;
[0035] Calculate the attack representative value of the corresponding initial background according to the attack representative value formula; the attack representative value formula is:
[0036] GB = MZ × log 10 (C + 1);
[0037] Where: GB is the attack representative value; MZ is the sensitive value of the corresponding initial background; C is the frequency representative value, and C≠0.
[0038] The encryption configuration module is used for the platform party to set up an encryption library and an encryption policy model according to the user's encryption requirements and encryption requirements; the encryption library is used to store encryption algorithms and encryption methods; the encryption policy model is used to determine the encryption policy that meets the encryption requirements according to the communication data type and application background.
[0039] The encryption module is used to encrypt communication data, identify the communication data that needs to be encrypted, mark it as target data, identify the communication data type and application background corresponding to the target data; mark the communication data type and application background corresponding to the target data as the target type and target background respectively;
[0040] Analyze the target type and target background through the encryption policy model to obtain the corresponding encryption policy;
[0041] Obtain the correlation analysis data according to the target type; screen the encryption policy according to the correlation analysis data to obtain the target encryption policy, and encrypt the target data according to the target encryption policy.
[0042] Furthermore, screening the encryption policy according to the correlation analysis data includes:
[0043] Generate a frequency representative value curve based on the associated analysis data. The horizontal axis of the frequency representative value curve is time, and the vertical axis is the frequency representative value; fit the frequency representative value curve to obtain a frequency representative function; determine the frequency representative value at the current time according to the frequency representative function, mark it as the monitoring representative value, and mark the monitoring representative value as QB.
[0044] Identify the frequency representative value corresponding to the communication data type, mark it as the reference representative value, and mark the reference representative value as QD.
[0045] Identify the cracking probability of the encryption policy according to the associated analysis data, and mark the cracking probability of the encryption policy as μ i , where i represents the corresponding encryption policy, i = 1, 2,..., n, and n is the number of encryption policies;
[0046] Calculate the screening value of the corresponding encryption policy according to the evaluation formula. The evaluation formula is:
[0047] YR i = [b1 × QA(QB, QD)] × [b2 × (exp(μ i ) - 1)];
[0048] In the formula: YR i is the screening value of the corresponding encryption policy; b1 and b2 are both proportionality coefficients, and the value range is 0 < b1 ≤ 1, 0 < b2 ≤ 1; exp() is the exponential function with the natural constant e as the base; QA(QB, QD) is a piecewise function.
[0049] Mark the encryption policies with screening values less than the threshold X1 as candidate policies, and determine the target encryption policy according to the candidate policies.
[0050] Furthermore,
[0051] Furthermore, when the screening values of all encryption policies are less than the threshold X1, an encryption library optimization warning is issued.
[0052] Compared with the prior art, the beneficial effects of the present invention are:
[0053] Through the mutual cooperation among the requirement analysis module, the encryption configuration module, and the encryption module, intelligent encryption processing of communication data is achieved, enabling dynamic adjustment of the encryption method according to actual needs, thus avoiding the disadvantages of single encryption method and insufficient flexibility in traditional encryption methods. This can not only meet the encryption requirements in different application scenarios but also improve the security and reliability of the encryption process. By adopting the strategy of combining multiple encryption methods for encryption, the advantages of different encryption algorithms can be fully utilized to form a complementary effect, thereby improving the overall encryption effect. This combined encryption method not only increases the cracking difficulty but also enhances the confidentiality and integrity of the encrypted data. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0055] Figure 1 It is a block diagram of the principle of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0056] The following will clearly and completely describe the technical solutions of the present invention in combination with the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0057] As Figure 1 shown, a communication data encryption intelligent processing system includes a requirement analysis module, an encryption configuration module, and an encryption module;
[0058] The requirement analysis module is used to conduct encryption requirement analysis to determine each encryption requirement and the corresponding encryption requirements.
[0059] In one embodiment, the encryption requirements and encryption requirements can be directly determined based on the prior art. For example, when the user has corresponding experience and knowledge, the user can directly inform the platform party of the encryption requirements and encryption requirements; or it can also be directly determined by the staff of the platform party through communication with the user.
[0060] In one embodiment, determining the encryption requirements and encryption requirements in the above manner requires the platform party to spend a certain amount of time and manpower for communication, with low efficiency. Therefore, in this embodiment, the process of conducting encryption requirement analysis is as follows:
[0061] Various communication data to be encrypted are uploaded by users, and then the range of communication data to be encrypted is determined by summarization. The range of communication data consists of various types of communication data.
[0062] The platform party presets various data backgrounds based on encryption experience, common sense, and service scope. The data backgrounds are set according to the risk differences that communication data may encounter, that is, the data backgrounds are set according to the corresponding risks such as transmission methods, storage environments, and potential security threats. A type of background that can be regarded as having the same risk difference forms a data background, such as communicating using a wireless network in public places such as cafes, libraries, and airports, communicating using a public Wi-Fi hotspot in public places, and internal enterprise communication, etc. It can be directly set by professional personnel of the platform party to form a data background statistical table.
[0063] According to the data background statistical table, obtain the data backgrounds corresponding to various types of communication data within the range of communication data, and mark them as application backgrounds.
[0064] Form a user encryption analysis table based on the range of communication data and the application background; set encryption requirements and encryption specifications according to the user encryption analysis table; display the user encryption analysis table to the platform staff and users to understand the application backgrounds faced by various types of communication data, and then set different encryption requirements and encryption specifications according to the risks under different application backgrounds. The encryption requirement is what conditions need to be met for encryption, and the encryption specification is what degree of security requirements need to be achieved, such as a security rate of 99%, etc. Setting the encryption requirements and encryption specifications according to the user encryption analysis table will greatly assist the platform party in determining the encryption requirements and encryption specifications for users.
[0065] In one embodiment, the method for setting the data background further includes:
[0066] Step SA1: Obtain various types of communication data within the service scope of the platform party, and count the attack record data corresponding to various types of communication data. The attack record data is the record data of malicious behaviors such as the communication data of this type being attacked and cracked.
[0067] Identify various backgrounds existing in the attack record data, and mark the initial backgrounds, such as sending communication data with a mobile phone in the subway station; count the attack representative values corresponding to each initial background.
[0068] Sort all the initial backgrounds in descending order of the attack representative value, referring to all the initial backgrounds of each type of communication data; obtain the first sequence.
[0069] Step SA2: Mark the initial background ranked first in the first sequence as the base background, and mark the initial background adjacent to the benchmark background in the ranking as the candidate background.
[0070] When there is no basic background, end the analysis;
[0071] When there is no candidate background, mark the basic background as the data background and end the analysis;
[0072] Step SA3: Calculate the absolute value of the difference between the attack representative values of the basic background and the candidate background, and mark it as the basic difference;
[0073] Step SA4: Determine whether the merging requirement is met according to the basic difference. The merging requirement is set by the platform side and is a preset maximum difference of the attack representative value that cannot be exceeded. Specifically, it is set by those skilled in the art according to the actual situation or obtained through a large amount of data simulation; a value greater than the corresponding value of the merging requirement means that the merging requirement is not met, and vice versa;
[0074] A merging judgment formula can also be established. The expression of the merging judgment formula is:
[0075]
[0076] In the formula: q is the reference difference; p is the merging requirement; q→p means that the reference difference meets the merging requirement, that is, the reference difference is not greater than the corresponding value of the merging requirement; HP(q, p) is the merging judgment value;
[0077] Calculate the merging judgment value between the basic background and the candidate background through the merging judgment formula; determine whether the merging requirement is met according to the merging judgment value;
[0078] When it is judged that the merging requirement is met, merge the basic background and the candidate background to form a new basic background. Mark the initial background adjacent to the new reference background in the sorting as the candidate background, and return to step SA3; where the attack representative value corresponding to the new reference background remains unchanged, that is, the maximum attack representative value; when there is no candidate background, mark the basic background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2.
[0079] When it is judged that the merging requirement is not met, mark the basic background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2.
[0080] In one embodiment, the attack representative value is a representative value such as the average or mode of the number of attacks corresponding to the initial background within the corresponding time period.
[0081] In one embodiment, the calculation method of the attack representative value is:
[0082] Set the sensitivity values for each type of communication data. The sensitivity values are set according to the sensitivity of the communication data type, and are generally determined based on existing data sensitivity analysis methods. Organize each type of communication data and its sensitivity value to establish a sensitivity statistics table.
[0083] Identify the type of communication data corresponding to the initial background, and match the corresponding sensitivity value from the sensitivity statistics table according to the type of communication data. Use this sensitivity value as the sensitivity value of each initial background corresponding to this type of communication data.
[0084] Identify the attack count data of each initial background within the corresponding time period, set its representative value, and mark it as the count representative value, that is, the attack representative value in the previous embodiment. Take representative values such as the average or mode of the attack counts.
[0085] Calculate the attack representative value of the corresponding initial background according to the attack representative value formula. The attack representative value formula is:
[0086] GB = MZ × log 10 (C + 1);
[0087] In the formula: GB is the attack representative value; MZ is the sensitivity value of the corresponding initial background; C is the count representative value, and C ≠ 0.
[0088] For the setting of sensitivity values, data can be classified into different categories according to the sensitivity of the data, such as public data, internal data, confidential data, etc. Each category can be further subdivided into different sub-categories to more precisely represent the sensitivity of the data. Define a sensitivity value for each data category or sub-category. This value can be an integer or a floating point number, used to quantify the sensitivity of the data. The range of sensitivity values can be set according to actual needs, for example, from 0 (completely insensitive) to 100 (extremely sensitive). Assign a corresponding sensitivity value to each data item according to the characteristics and application scenarios of the data. Map the sensitivity value to a specific sensitivity level or category to more intuitively represent the sensitivity of the data. For example, sensitivity values 0 - 20 can be mapped to "low sensitivity", 21 - 50 to "medium sensitivity", 51 - 80 to "high sensitivity", and 81 - 100 to "extremely high sensitivity".
[0089] Exemplarily, a financial institution needs to process a large amount of customer data, including names, ID numbers, bank card numbers, transaction records, etc. This data is crucial for the business, but at the same time, it faces the risks of leakage and abuse. Therefore, it is necessary to classify the sensitivity of this data and set corresponding sensitivity values. The classification is as follows: Very low sensitivity: Data that will not cause serious impacts on individuals or institutions after leakage, such as the ordinary names of customers (without sensitive information such as ID numbers and addresses), and the sensitivity value range is 1 - 10. Low sensitivity: Data that may cause certain impacts on individuals or institutions after leakage, but the impacts are limited, such as the ordinary contact information of customers (phone numbers, email addresses, etc.), and the sensitivity value range is 11 - 30. Medium sensitivity: Data that will cause relatively large impacts on individuals or institutions after leakage, such as the ID numbers of customers, some transaction records (not involving large amounts of funds), and the sensitivity value range is 31 - 70. High sensitivity: Data that will cause serious impacts on individuals or institutions after leakage, such as the bank card numbers, passwords, large - amount transaction records of customers, etc., and the sensitivity value range is 71 - 100. Subsequently, matching is performed according to the actual data.
[0090] In other embodiments, an intelligent model can also be based on existing intelligent algorithms such as deep neural networks, and the corresponding sensitivity value can be intelligently determined through the intelligent model; it can also be directly set manually by the staff of the platform side.
[0091] The encryption configuration module is used for the platform side to set an encryption library according to the encryption requirements and encryption demands of users. The encryption library is used to store various encryption algorithms and encryption methods; the platform side sets an encryption policy model according to the encryption library, encryption requirements, and encryption demands. The encryption policy model is used to determine an encryption policy that meets the corresponding encryption requirements according to the types of communication data to be encrypted and the application background. The encryption policy is how to perform encryption under the current conditions, such as using a combination of symmetric encryption and asymmetric encryption for hybrid encryption; the encryption policy model is specifically established by the platform side based on existing intelligent technologies.
[0092] Exemplarily, the establishment of the encryption policy model includes:
[0093] Collect a large number of communication data samples, and these samples should cover different types of communication data and application backgrounds. Pre - process the collected data, including data cleaning, format conversion, feature extraction, etc., for subsequent training of the neural network.
[0094] Design a deep neural network structure that can process the input data features and output the corresponding encryption policy. The neural network can include an input layer, multiple hidden layers, and an output layer. The input layer is used to receive the pre - processed data features; the hidden layer performs non - linear transformations through multiple neurons and activation functions; the output layer outputs the classification results or specific parameters of the encryption policy.
[0095] According to the encryption library and encryption requirements, corresponding encryption policy tags are labeled for each data sample. The labeled data samples are divided into a training set, a validation set, and a test set for the training, validation, and testing of the neural network.
[0096] The neural network is trained using the training set data, and the weights and biases of the neural network are adjusted through the backpropagation algorithm to minimize the loss function. During the training process, appropriate optimization algorithms (such as Adam, SGD, etc.) can be used to accelerate the training process and improve the performance of the model. At the same time, the validation set data can be used to validate the neural network to evaluate the generalization ability and performance of the model. According to the validation results, the structure, parameters, or training strategy of the neural network is adjusted and optimized.
[0097] When generating an encryption policy for new communication data, the input data is preprocessed and then input into the trained neural network. The neural network will output corresponding encryption policy candidate solutions, which may include combinations of multiple encryption methods.
[0098] The encryption module is used to encrypt communication data, identify the communication data that needs to be encrypted, mark it as target data, identify the corresponding communication data type and application background of the target data, and the application background is determined based on existing methods, such as determining according to the sending and receiving locations, content, user behavior, etc.; the communication data type and application background corresponding to the target data are respectively marked as the target type and the target background;
[0099] The target type and the target background are analyzed through the encryption policy model to obtain the corresponding encryption policy;
[0100] The correlation analysis data of each communication data type is statistically analyzed in real time. The correlation analysis data is various encryption information related to the communication data type, such as the frequency representative value record data in a recent period of time and the probability of each encryption policy being cracked in the current encryption field, which is marked as the cracking probability, that is, the correlation analysis data includes the frequency representative value record data and the cracking probability of the communication data type under different encryption policies, and the cracking probability can be statistically analyzed according to the decryption technology and decryption history records in the current encryption field.
[0101] The obtained encryption policy is screened according to the correlation analysis data to determine the applied encryption policy, which is marked as the target encryption policy, and the target data is encrypted according to the target encryption policy.
[0102] In one embodiment, when screening the obtained encryption policy according to the correlation analysis data, it can be screened based on existing screening methods, such as directly screening according to the cracking probability, and selecting the encryption policy with the highest cracking probability for output.
[0103] In one embodiment, the method for screening the obtained encryption policies according to the association analysis data includes:
[0104] Generate a frequency representative value curve based on the association analysis data, where the horizontal axis is time and the vertical axis is the frequency representative value; fit the frequency representative value curve to obtain a frequency representative function; determine the frequency representative value at the current time according to the frequency representative function, and mark it as the monitoring representative value. Due to various reasons such as data statistics, it may not be possible to obtain the frequency representative value at the current time in a timely manner, but based on the frequency representative function, the frequency representative value at the current time can be inferred, such as determined based on various existing common prediction algorithms and speculation techniques; mark the obtained monitoring representative value as QB;
[0105] Identify the frequency representative value corresponding to the type of communication data when setting the encryption policy model, and mark it as the reference representative value. The frequency representative value in the requirements analysis module can be applied; mark the reference representative value as QD;
[0106] Identify the cracking probability of each encryption policy according to the association analysis data, and mark the cracking probability of the corresponding encryption policy as μ i , where i represents the corresponding encryption policy, i = 1, 2,..., n, and n is the number of encryption policies;
[0107] Calculate the screening value of the corresponding encryption policy according to the evaluation formula. The evaluation formula is:
[0108] YR i = [b1 × QA(QB, QD)] × [b2 × (exp(μ i ) - 1)];
[0109] In the formula: YR i is the screening value of the corresponding encryption policy; b1 and b2 are both proportionality coefficients, and the value range is 0 < b1 ≤ 1, 0 < b2 ≤ 1; exp() is the exponential function with the natural constant e as the base; QA(QB, QD) is a piecewise function,
[0110] The platform party sets the threshold X1 according to user requirements. Specifically, it is set by those skilled in the art according to the actual situation or obtained through a large amount of data simulation. For example, set several sets of simulation data corresponding to the encryption policies in the critical state, calculate the corresponding screening values, and select the smallest evaluation value as the threshold X1;
[0111] Mark the encryption policies with screening values less than the threshold X1 as candidate policies, and select the target encryption policy from the candidate policies. Generally, select the one with the smallest cracking probability as the target encryption policy. However, for the purpose of improving security, the target encryption policy can also be determined by means of accidental random selection.
[0112] In one embodiment, when the screening values of all encryption policies are less than the threshold X1, an encryption library optimization warning is issued, that is, it is prompted that the encryption algorithms, encryption methods, etc. in the encryption library need to be optimized, better encryption algorithms and encryption methods with better encryption effects are added, and corresponding warning processing is performed, such as stopping the occurrence of corresponding data, applying the encryption policy with the lowest cracking probability or randomly selected as the target encryption policy after authorization, etc.
[0113] The above formulas are all calculated by removing the dimension and taking their numerical values. The formula is a formula obtained by collecting a large amount of data for software simulation to be closest to the actual situation. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained by simulating a large amount of data.
[0114] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A communication data encryption intelligent processing system, characterized in that, It includes a requirements analysis module, an encryption configuration module, and an encryption module; The requirements analysis module is used to conduct encryption requirements analysis to determine the user's encryption requirements and the encryption requirements for the corresponding encryption requirements; The encryption configuration module is used for the platform party to set an encryption library and an encryption policy model according to the user's encryption requirements and encryption requirements; the encryption library is used to store encryption algorithms and encryption methods; the encryption policy model is used to determine the encryption policy that meets the encryption requirements according to the types of communication data and the application background; The encryption module is used to encrypt communication data, identify the communication data that needs to be encrypted, mark it as target data, identify the types of communication data and the application background corresponding to the target data; mark the types of communication data and the application background corresponding to the target data as the target type and the target background respectively; Analyze the target type and the target background through the encryption policy model to obtain the corresponding encryption policy; obtain associated analysis data according to the target type; generate a frequency representative value curve based on the associated analysis data, where the horizontal axis of the frequency representative value curve is time and the vertical axis is the frequency representative value; Fit the frequency representative value curve to obtain a frequency representative function; Determine the frequency representative value at the current time according to the frequency representative function, mark it as the monitoring representative value, and mark the monitoring representative value as QB; Identify the frequency representative value corresponding to the type of communication data, mark it as the reference representative value, and mark the reference representative value as QD; Identify the cracking probability of the encryption policy according to the association analysis data, and mark the cracking probability of the encryption policy as μ i , where i represents the corresponding encryption policy, i = 1, 2, ……, n, and n is the number of encryption policies; Calculate the screening value of the corresponding encryption policy according to the evaluation formula. The evaluation formula is: ; where: YR i is the screening value of the corresponding encryption policy; b1 and b2 are both proportionality coefficients, and the value ranges are 0 < b1 ≤ 1, 0 < b2 ≤ 1; exp() is the exponential function with the natural constant e as the base; QA(QB, QD) is a piecewise function; Mark the encryption policy with a screening value less than the threshold X1 as the candidate policy, and determine the target encryption policy according to the candidate policy; The piecewise function is: ; Encrypt the target data according to the target encryption policy.
2. The intelligent processing system for encrypted communication data according to claim 1, wherein Conduct encryption requirements analysis, including: The platform party sets a data background statistical table, and the data background statistical table is used to count each data background; Determine the communication data range according to the user, and the communication data range consists of various types of communication data; Obtain the data background corresponding to each type of communication data within the communication data range according to the data background statistical table, and mark it as the application background; Form a user encryption analysis table according to the communication data range and the application background; set encryption requirements and encryption requirements according to the user encryption analysis table.
3. A communication data encryption intelligent processing system according to claim 2, characterized in that, The setting of the data background includes: Step SA1: Obtain various types of communication data within the service scope of the platform party, and count the attack record data corresponding to the types of communication data; Identify each initial background corresponding to the attack record data, and count the attack representative value corresponding to the initial background; Sort the initial backgrounds in descending order of the attack representative value to obtain the first sequence; Step SA2: Mark the initial ranked first in the first sequence as the base background, and mark the initial background adjacent to the benchmark background in the ranking as the candidate background; When there is no base background, end the analysis; When there is no candidate background, mark the base background as the data background and end the analysis; Step SA3: Calculate the absolute value of the difference between the attack representative values of the base background and the candidate background, and mark it as the base difference; Step SA4: Determine whether the base background and the candidate background meet the merging requirements according to the base difference; When it is determined that the merging requirement is met, merge the base background with the candidate background to form a new base background, mark the initial background adjacent to the new reference background in the sorting as the candidate background, and return to step SA3; when there is no candidate background, mark the new base background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2; When it is determined that the merging requirement is not met, mark the base background as the data background for output, and delete the initial background corresponding to the data background in the first sequence, and return to step SA2.
4. A communication data encryption intelligent processing system according to claim 3, characterized in that, Determine whether the merging requirement is met between the base background and the candidate background, including: Establish a merging judgment formula, and the expression of the merging judgment formula is: ; In the formula: q is the reference difference; p is the merging requirement; q→p means that the reference difference meets the merging requirement; HP(q, p) is the merging judgment value; Calculate the merging judgment value between the base background and the candidate background through the merging judgment formula; When the merging judgment value is 1, it is determined that the merging requirement is met; When the merging judgment value is 0, it is determined that the non-merging requirement is met.
5. A communication data encryption intelligent processing system according to claim 3, characterized in that, The calculation of the attack representative value includes: The platform party establishes a sensitive statistics table, and the sensitive statistics table is used to count the sensitive values of the corresponding communication data types; Match the corresponding sensitive value from the sensitive statistics table according to the initial background; identify the frequency representative value of the initial background; Calculate the attack representative value of the corresponding initial background according to the attack representative value formula; the attack representative value formula is: GB = MZ×log 10 (C + 1); In the formula: GB is the attack representative value; MZ is the sensitive value of the corresponding initial background; C is the frequency representative value of the initial background, and C≠0.
6. A communication data encryption intelligent processing system according to claim 1, characterized in that When the screening values of all encryption policies are less than the threshold X1, an encryption library optimization warning is issued.
Citation Information
Patent Citations
Internet-of-things data security sharing method and system
CN117792603A
Data processing strategy adjustment method, device and equipment
CN118194318A