An archival data secure transmission method based on a two-way encryption algorithm
By using a two-way encryption algorithm method in archive data transmission, the key and slice data are dynamically managed, data security and transmission reliability are strengthened, the problem of high cost of key distribution and data transmission is solved, and efficient and secure archive data transmission is achieved.
Patent Information
- Application Number
- CN202510147010.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-11
AI Technical Summary
In the archive data transmission collaboratively with multiple institutions, key distribution is secure and compatibility is difficult to guarantee. Long-term use of keys leads to brute-force cracking risks, and the cost of data slicing transmission and encryption time is high, and the security of encryption algorithms decreases with the key management time.
The archive data security transmission method based on the two-way encryption algorithm is adopted. By collecting historical and real-time data, dynamic security policies are designed, input packages are built, key and key generation models are designed, data is sliced and encryption is used by keys and keys, multivariate encryption groups and multipath transmission are designed, and the receiving end decrypts and restores data through dynamic keys.
It significantly improves data security, realizes dynamic key management and data encryption protection, improves the robustness and reliability of the transmission process, reduces the risk of data leakage, and optimizes transmission performance and user experience.
Smart Images

Figure CN119628964B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure transmission of archival data. More specifically, the present invention relates to a method for secure transmission of archival data based on a two-way encryption algorithm. Background Art
[0002] The two-way encryption algorithm includes symmetric encryption and asymmetric encryption. The present invention mainly focuses on the secure transmission of archival data during the symmetric encryption process. During the specific transmission process, the following problems and difficulties may be faced:
[0003] In the transmission of archival data, cooperation among multiple institutions or departments may be involved. Key distribution is one of the most critical links in the encryption system. Especially in the cooperation among multiple institutions or departments, each institution may have different key management mechanisms. How to ensure the secure and compatible key distribution among different institutions is a major problem. Moreover, if the key is accidentally lost (such as hardware failure or misoperation), the encrypted data cannot be decrypted, resulting in irrecoverable data.
[0004] When the key is used for a long time, an attacker may try to brute-force the key by continuously analyzing the data stream encrypted by the key. It is necessary to replace (rotate) the key regularly to avoid risks caused by long-term use. However, how to efficiently manage the generation, update, and destruction of the key is a complex problem.
[0005] Archival data usually involves a large number of data files, and archival data may contain various formats (text, pictures, videos, etc.). The overall time cost of transmission and encryption is relatively high. Therefore, how to perform sliced transmission processing on the data is a difficult problem. Especially, the security of the encryption algorithm may decrease over time with the preservation and management of the key. Therefore, it is necessary to comprehensively consider the adaptability of the data itself and the encryption algorithm to data in different forms.
[0006] In view of this, the present invention proposes a method for secure transmission of archival data based on a two-way encryption algorithm to solve the above problems. Summary of the Invention
[0007] In order to overcome the above-mentioned defects of the prior art and to achieve the above object, the present invention provides the following technical solution: A method for secure transmission of archival data based on a two-way encryption algorithm, including: Step S1: Collect historical comprehensive data and real-time data information, design a security policy according to the historical comprehensive data, and deploy it to all archival data, and then dynamically update the sensitivity level of the real-time data information;
[0008] Step S2: Construct an input packet according to the real-time data information, design a key and a key generation model, import the input packet into the model, and obtain the real-time generated key and key;
[0009] Step S3: Segment the real-time data information through a slicing strategy and encrypt it using a key and a cipher key;
[0010] Step S4: Design a multivariate encryption group based on the ciphertext fragments and use multi-path transmission. The receiving end decrypts and restores the data using a dynamic key;
[0011] Step S5: Display the transmission report on the computer terminal page and perform interface interaction with the user.
[0012] Preferably, the method for designing a security policy based on historical comprehensive data, deploying it to all archive data, and then dynamically updating the sensitivity level of real-time data information includes:
[0013] The historical comprehensive data includes the data of the archive data retrieved and transmitted over historical time, and the real-time data information refers to the archive data transmitted at the current time;
[0014] Perform a preliminary classification of the sensitivity levels of the historical comprehensive data and the archive data through manual annotation;
[0015] Use a dynamic classification method to update the sensitivity level of the preliminarily classified data within a cycle time. Set the dynamic classification method as , where represents the sensitivity level after data update, represents the sensitivity level after preliminary classification of the data, represents the data access frequency, represents the life cycle of the data, represents the maximum value of the data life cycle, and represent the weight coefficients, and represent the adjustment factors, represents the adjustment item;
[0016] Set a time period D_G, use the cycle time as the window size, and extract the real sensitivity levels of the historical comprehensive data at the start time and the end time within each window. Take the real sensitivity level at the start time as the sensitivity level after preliminary classification, and the real sensitivity level at the end time as the sensitivity level after update. And use the sensitivity levels after preliminary classification and after update as a group of samples. Slide the window over the time period D_G, collect all the generated samples, and train the dynamic classification method in batches until the sensitivity level output by the dynamic classification method converges with the real sensitivity level at the end time. At this time, the weight coefficients and 、the adjustment factors and 、the adjustment item Arrange in a dynamic grading manner to obtain the final expression of the dynamic grading manner;
[0017] Deploy the final expression of the dynamic grading manner to all archive data, and extract the sensitivity level of the real-time data information for dynamic update to obtain the sensitivity level of the data information at the current time.
[0018] Preferably, the method for constructing an input packet according to the real-time data information, designing a secret key and a key generation model, and importing the input packet into the model to obtain the real-time generated secret key and key specifically includes:
[0019] Extract the timestamp, sensitivity level, data characteristics, and user ID of the real-time data information, and design them in the form of a one-dimensional matrix. Use the obtained one-dimensional matrix as an attribute label to mark the real-time data information to form an input packet;
[0020] Obtain a secret key and a key through designing a secret key and a key generation model. The master secret key is used for data encryption, and the dynamic key is used to control the distribution and access of sub-key fragments;
[0021] Store the dynamic key on a distributed node to control the access rights to sub-key fragments , and each dynamic key can only access the sub-key fragments it stores .
[0022] Preferably, the design method of the secret key and key generation model includes:
[0023] The secret key and key generation model is constructed based on the master secret key generation formula and the key generation formula;
[0024] Set the master secret key generation formula as , where represents the random seed generated by the hardware random number generator, represents the timestamp, represents the index data characteristics, including the file size of the real-time data information , file type and sensitivity level , represents the user identity characteristics, represents the splicing operation of the data, represents the secure hash function;
[0025] The generated master secret key is sliced into sub-key fragments through the secret sharing algorithm, and a reconstruction threshold ;
[0026] Generate a dynamic key based on the master key and the sub - key segments, and set the dynamic key generation formula as , where represents the dynamic key used to allocate and control the corresponding sub - key segment ; represents the sub - key segment with label in the master key; represents the dynamic data characteristics, including the file size of each data block , file type , sensitivity level , user identity characteristics and dynamic environment characteristics , and ;
[0027] Set a dynamic update and adjustment mechanism for the generated master key and dynamic key. The dynamic update and adjustment mechanism stipulates that the dynamic key is dynamically adjusted with the update of the master key. The update method of the master key is to collect a timestamp , sensitivity level and dynamic environment characteristics at intervals of the update period, and regenerate through the master key generation formula;
[0028] Among them, the update period , represents the base period, represents the data transmission frequency, represents the data access frequency.
[0029] Preferably, the master key is divided into sub - key segments through the secret sharing algorithm, and the method of setting the reconstruction threshold includes:
[0030] Extract the value range of the sensitivity level, use the clustering algorithm to dynamically divide the value range, discretize the value range into continuous value segments. Based on the current time, collect the number of key slices and the reconstruction threshold of each data in each value segment at S_o time points forward, and take the average value as the number of key slices and the reconstruction threshold at the current time, denoted as and ;
[0031] Set the polynomial expression of the secret sharing algorithm as , where is the constant term, equal to the master key , , …, , …, represents a coefficient represents a variable, and by calculating the value in the storage node i, obtain the fragment with the label in the master key .
[0032] Preferably, the method of dynamically dividing the value range by using a clustering algorithm and discretizing the value range into continuous value segments includes:
[0033] Step Q1: Taking the current time as the base point, collect the sensitivity levels of the data in the previous S_o time, and collect all the sensitivity level values to form a data set;
[0034] Step Q2: Randomly select L - N values as the initial clustering centers, calculate the distances between the remaining values and the initial clustering centers, and assign them to the clusters corresponding to the nearest initial clustering centers;
[0035] Step Q3: Use the average value of all the values in the cluster as the new clustering center, repeat Step Q2 until the clustering centers of two adjacent iterations are the same and then stop, and obtain the values divided into L - N clusters;
[0036] Step Q4: Calculate the density of the values in each cluster , calculate the number of segments according to the density , extract the maximum and minimum values in each cluster to form a preliminary range, and evenly divide the preliminary range into value segments;
[0037] Step Q5: Collect the value segments in all the clusters and arrange them in ascending or descending order, which is denoted as the value segments after discretizing the value range;
[0038] Among them, represents the density of the values in the th cluster, represents the maximum value of the values in the th cluster, represents the minimum value of the values in the th cluster, represents the number of values in the th cluster, represents the standard segmentation value.
[0039] Preferably, the method of segmenting the real - time data information by using a slicing strategy and encrypting it with a key and a secret key includes:
[0040] Design a slicing strategy, which is constructed based on the slicing size strategy formula and the slicing number strategy formula, and obtain the slicing size according to the slicing strategy And the number of slices ;
[0041] The slice size output using the slicing strategy And the number of slices Split the real-time data information to form data blocks;
[0042] For each data block, allocate a sub-key fragment, and use the allocated sub-key fragment to encrypt the data block to generate a ciphertext fragment;
[0043] Among them, the slice size strategy formula is , and the slice number strategy formula is , represents the file size of the real-time data information, represents the maximum number of slices, represents the network bandwidth, represents the transmission delay, represents the standard number of slices, represents the standard file size, represents the adjustment step size.
[0044] Preferably, the method for designing a multi-element encryption group according to the ciphertext fragment and using multi-path transmission, and decrypting and restoring the data at the receiving end through a dynamic key includes:
[0045] For each ciphertext fragment, introduce a check value, which is generated by HMAC. The ciphertext fragment after adding the check value and the dynamic key form a multi-element encryption group;
[0046] The multi-element encryption group is transmitted from the sending end to the receiving end through multi-path transmission. After the receiving end receives it, it first recalculates the check value of each ciphertext fragment and compares it with that provided by the sending end: if they are inconsistent, a retransmission request is sent to the sending end; if they are consistent, the receiving end reconstructs the main key from the dynamic key, decrypts the data block using the main key, and reorganizes the decrypted data blocks in order into the complete real-time data information.
[0047] Preferably, the method for transmitting the multi-element encryption group from the sending end to the receiving end through multi-path transmission includes: the ciphertext fragment and the dynamic key are transmitted through independent transmission paths respectively.
[0048] Preferably, the transmission report includes transmission status and identification information. The transmission status includes normal and abnormal. If the check value is inconsistent, the transmission status is displayed as abnormal, and the identification information sent is a retransmission request. If the check value is consistent, the transmission status is displayed as normal, and the identification information sent is transmission success.
[0049] The technical effects and advantages of a method for secure transmission of archive data based on a two-way encryption algorithm according to the present invention:
[0050] 1. Significantly improved data security
[0051] A dual encryption mechanism of the master key and dynamic keys is designed. It not only encrypts data blocks but also controls the distribution of dynamic keys for their ciphertext segments. The generation and update mechanism of dynamic keys is based on various dynamic characteristics such as sensitivity level, timestamp, user ID, etc., ensuring the security and real-time nature of the keys.
[0052] The master key is segmented into multiple sub-key segments through the secret sharing algorithm, and a reconstruction threshold is set. Only sub-key segments that meet the reconstruction conditions can reconstruct the master key, thus preventing key leakage. The ciphertext segment and the dynamic key are transmitted through independent transmission paths. Even if one path is attacked, the attacker cannot obtain both the key and the ciphertext at the same time, greatly reducing the risk of data leakage.
[0053] 2. Precise evaluation of dynamic sensitivity levels
[0054] Design dynamic security policies based on historical comprehensive data and real-time data information. Optimize the dynamic grading method through periodic updates and training, making the sensitivity level more precise. Use the dynamic grading formula to comprehensively consider various factors such as data access frequency, life cycle, weight coefficient, etc., and dynamically adjust the sensitivity level to ensure that the security level of data can be updated in a timely manner following the actual situation. Use the clustering algorithm to dynamically divide the value range of the sensitivity level and discretize the sensitivity level to ensure the flexibility and accuracy of grading.
[0055] 3. Efficient key management and encryption mechanism
[0056] Generate the master key and dynamic keys dynamically based on real-time data information through the key and key generation model, ensuring the timeliness and uniqueness of the keys. The keys and keys are adjusted in real time according to dynamic characteristics such as data transmission frequency and access frequency, avoiding the security risks of fixed keys. By designing the slicing strategy formula, optimizing the slice size and the number of slices, and combining the distribution of sub-key segments to achieve efficient encryption, the data transmission speed is accelerated.
[0057] 4. Robustness and reliability during the transmission process
[0058] Introduce a check value for each ciphertext segment. The receiving end verifies the integrity of the data through the check value to avoid data being tampered with or lost during transmission. Display the transmission status and identification information in real time on the computer side, providing users with an intuitive transmission progress and abnormal feedback for timely problem handling.
[0059] 5. Performance advantages
[0060] The efficient sharding strategy optimizes the transmission performance. Multipath transmission not only improves the transmission security, but also disperses the network load, enhancing the efficiency and reliability of data transmission. Distributed key storage avoids single-point failures, improving the fault tolerance and scalability of the system. It is highly adaptable and can be adapted to different application scenarios.
[0061] Each module (such as sensitive level assessment, key generation, slice encryption, transmission, and decryption) is relatively independent, facilitating flexible expansion and function upgrade.
[0062] 6. Intelligent sensitive level assessment and training
[0063] The dynamic grading method conducts a periodic training mechanism on historical comprehensive data through a sliding window, and continuously optimizes the weight coefficient, adjustment factor, and adjustment term to make the sensitive level assessment more accurate. By combining manual annotation and dynamic grading, intelligent sensitive level assessment of data is achieved, reducing manual intervention and improving efficiency.
[0064] 7. User experience optimization
[0065] Through the real-time interactive interface, reports are transmitted to interact with users, enabling them to intuitively understand the transmission status, abnormal information, and dynamic changes in the sensitive level. The system can promptly feedback abnormal information and automatically initiate a retransmission request, reducing user intervention and enhancing the operation experience. Description of the drawings
[0066] Figure 1 It is a schematic structural diagram of a method for secure transmission of archive data based on a two-way encryption algorithm according to the present invention;
[0067] Figure 2 It is a schematic step diagram of a method for secure transmission of archive data based on a two-way encryption algorithm according to the present invention. Detailed implementation manners
[0068] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0069] Embodiment 1
[0070] Please refer to Figure 1 and Figure 2 As shown, a method for secure transmission of archive data based on a two-way encryption algorithm in this embodiment includes:
[0071] The two-way encryption algorithm includes symmetric encryption and asymmetric encryption. This invention mainly focuses on the secure transmission of archival data during the symmetric encryption process. During the specific transmission process, the following problems and difficulties may be faced:
[0072] 1. Key management issues
[0073] In the transmission of archival data, collaboration among multiple institutions or departments may be involved. Key distribution is one of the most critical links in the encryption system. Especially in the collaboration among multiple institutions or departments, each institution may have different key management mechanisms. How to ensure the secure and compatible key distribution among different institutions is a major problem. Moreover, if the key is accidentally lost (such as due to hardware failure or misoperation), the encrypted data cannot be decrypted, resulting in irrecoverable data.
[0074] When the key is used for a long time, attackers may try to brute-force crack the key by continuously analyzing the data stream encrypted by the key. It is necessary to replace (rotate) the key regularly to avoid risks caused by long-term use. However, how to efficiently manage the generation, update, and destruction of keys is a complex problem.
[0075] 2. Characteristics of archival data itself
[0076] Archival data usually involves a large number of data files, and archival data may contain various formats (text, pictures, videos, etc.). The overall time cost of transmission and encryption is relatively high. Therefore, how to perform sliced transmission processing on the data is a difficult problem. Especially, the security of the encryption algorithm may decrease over time with the preservation and management of the key. Therefore, it is necessary to comprehensively consider the adaptability of the data itself and the encryption algorithm to data in different forms.
[0077] During the transmission process of archival data, problems such as multi-institution collaboration, complex data formats, and high transmission security requirements are involved. To address the complexity of key management and various challenges of data security, the following design processes are proposed in this technical solution:
[0078] Security policy formulation: Design a set of dynamic security policies according to data characteristics and transmission security requirements.
[0079] Key and key generation model: Design a dynamic key generation and slicing model based on the security policy.
[0080] Data slicing and key adaptive allocation: Perform adaptive slicing and allocation of keys according to the characteristics of data slices (file type, importance, size, etc.).
[0081] Transmission and decryption: Combine the multi-path transmission and recombination mechanism of data and key slices to ensure the integrity and security of data during the transmission process.
[0082] This solution aims to achieve dynamic key management, targeted data encryption protection, and efficient secure transmission.
[0083] Step S1: Collect historical comprehensive data and real-time data information, design security policies based on the historical comprehensive data, and deploy them to all archival data, and then dynamically update the sensitivity levels of the real-time data information.
[0084] Data dynamic update module: Used to collect historical comprehensive data and real-time data information, design security policies based on the historical comprehensive data, and dynamically update the sensitivity levels of the real-time data information.
[0085] The security policy is the foundation of the entire technical solution, which is used to guide key generation, data encryption, and transmission methods. The main contents include:
[0086] The method of designing security policies based on historical comprehensive data, deploying them to all archival data, and then dynamically updating the sensitivity levels of the real-time data information includes:
[0087] The historical comprehensive data includes the data of archival data retrieved and transmitted in historical time, and the real-time data information refers to the archival data transmitted at the current time.
[0088] Manually label the sensitivity levels of the historical comprehensive data and archival data for preliminary classification.
[0089] For example, assume that there are 5 classification levels, from high to low are S_1, S_2, S_3, S_4, and S_5. Then, S_1 represents extremely highly sensitive data (personal privacy, biometric data); S_2 represents highly sensitive data (such as enterprise core technology documents, financial data); S_3 represents moderately sensitive data (such as department-level internal materials); S_4 represents low-sensitive data (such as ordinary internal documents); S_5 represents public data (such as press releases, promotional materials). Among them, the sensitivity level can be the importance level or confidentiality level of the data or file.
[0090] Use dynamic classification methods to update the sensitivity levels of the preliminarily classified data within the cycle time. Set the dynamic classification method as , where represents the sensitivity level of the data after update, represents the sensitivity level of the data after preliminary classification, represents the data access frequency, that is, the frequency of data access. Data with high access frequency may contain more sensitive information or be crucial to business operations, so it may require a higher security level. represents the data life cycle, that is, the time span from data creation to deletion. Data that has not been accessed for a long time may no longer require high-level protection, so its security level can be reduced. Represents the maximum value of the data life cycle, used to normalize the impact of the life cycle. and Represents the weight coefficient; used to adjust the degree of influence of access frequency and life cycle on the security level. Used to adjust the degree of influence of data access frequency and data life cycle on the security level. and Represents the adjustment factor, Represents the adjustment item;
[0091] Set the time period D_G, use the cycle time as the window size, and extract the true sensitivity levels at the start time and end time within each window of the historical comprehensive data. Take the true sensitivity level at the start time as the sensitivity level after preliminary classification, and the true sensitivity level at the end time as the updated sensitivity level. And take the sensitivity levels after preliminary classification and updated as a group of samples. Slide the window on the time period D_G, collect all the generated samples, and train the dynamic classification method batch by batch until the sensitivity level output by the dynamic classification method converges (is the same) with the true sensitivity level at the end time. At this time, the weight coefficient and and the adjustment factor and and the adjustment item Are arranged on the dynamic classification method to obtain the final expression of the dynamic classification method;
[0092] Deploy the final expression of the dynamic classification method to all archival data, realize the dynamic update of all archival data stored in the database, and extract the sensitivity level of the real-time data information dynamic update to obtain the sensitivity level of the data information at the current time.
[0093] Step S2: Construct an input package according to the real-time data information, design a key and key generation model, and import the input package into the model to obtain the real-time generated key and key;
[0094] Step S3: Segment the real-time data information through a slicing strategy and encrypt it using the key and key;
[0095] The method of segmenting the real-time data information through a slicing strategy and encrypting it using the key and key includes:
[0096] Design a slicing strategy, which is constructed based on the slicing size strategy formula and the slicing quantity strategy formula, and obtain the slicing size according to the slicing strategy and the slicing quantity ;
[0097] Use the slicing size and the slicing quantity Split the real-time data information to form data blocks;
[0098] For each data block, allocate sub-key fragments, and use the allocated sub-key fragments to encrypt the data block to generate ciphertext fragments; among them, one or more sub-key fragments can also be allocated. More sub-key fragments are allocated to highly sensitive data blocks, and fewer sub-key fragments are allocated to low-sensitivity data blocks. Moreover, the allocated sub-key fragments are greater than the number of key slices and less than or equal to the reconstruction threshold.
[0099] Among them, the slice size policy formula is , and the slice number policy formula is , represents the file size of the real-time data information, represents the maximum number of slices, which is set based on file complexity and format. For files with complex formats, more slices may be required to reduce the processing difficulty. represents the network bandwidth, which affects the data transmission rate. represents the transmission delay, which affects the time efficiency of data transmission. represents the standard number of slices, which can be set by averaging the number of slices after normal data transmission processing value, represents the standard file size, which can be set by averaging the file size after normal data transmission processing, represents the adjustment step; that is, the unit change amount during dynamic slice adjustment.
[0100] Model design module: used to design key and key generation models and construct input packets, and obtain the keys and keys generated in real time, split the real-time data information through the slicing policy, and encrypt it using the keys and keys;
[0101] Construct an input packet according to the real-time data information, design a key and key generation model, import the input packet into the model, and obtain the keys and keys generated in real time. The specific methods include:
[0102] Extract the timestamp, sensitivity level, data characteristics, and user ID of the real-time data information, and design them in the form of a one-dimensional matrix. Use the obtained one-dimensional matrix as an attribute label to mark the real-time data information to form an input packet;
[0103] Through designing a key and key generation model, obtain the key and key. The main key is used for data encryption, and the dynamic key is used to control the allocation and access of sub-key fragments;
[0104] Store the dynamic key on the distributed node for controlling the sub-key fragments The access permission requires any node to verify before accessing , and each dynamic key can only access the sub-key segments it stores ;
[0105] The design methods of the key and key generation model include:
[0106] The key and key generation model is constructed based on the master key generation formula and the key generation formula;
[0107] The generation of the master key depends on the random number generator, device characteristics, user characteristics, and dynamic environment characteristics. Set the master key generation formula as , where represents the random seed generated by the hardware random number generator, which is used to provide initial randomness, represents the timestamp, represents the index data characteristics, including the file size of the real-time data information , file type and sensitivity level , represents the user identity characteristics, such as user ID or login credentials, represents the concatenation operation of data, which is used to combine data from multiple sources, represents the secure hash function; such as SHA-256, which is used to generate a fixed-length key from the concatenated data.
[0108] The generated master key is split into sub-key segments through a secret sharing algorithm (such as the Shamir secret sharing scheme), and the reconstruction threshold A_l is set;
[0109] The generation of sub-keys combines the master key segments and dynamic data characteristics. Based on the master key and sub-key segments, dynamic keys are generated. Set the dynamic key generation formula as , where represents the dynamic key used to allocate and control the corresponding sub-key segment , represents the sub-key segment with label in the master key, represents the dynamic data characteristics, including the file size of each data block , file type , sensitivity level , user identity characteristics and dynamic environment characteristics , and ;
[0110] Set up a dynamic update and adjustment mechanism for the generated master key and dynamic key. The dynamic update and adjustment mechanism stipulates that the dynamic key is dynamically adjusted as the master key is updated. The master key is updated by collecting a timestamp at intervals of the update period. and sensitivity level and dynamic environment characteristics , and regenerate through the master key generation formula;
[0111] Among them, the update period , represents the base period, which is a preset period set based on the sensitivity classification of data. For example, for data with a lower sensitivity level, it may be set to 2 days, represents the data transmission frequency. For example, it can be the number of times transmitted per day, represents the data access frequency. For example, it can be the number of times the data is accessed per day.
[0112] By implementing this comprehensive key generation strategy, while ensuring data security, it can improve the flexibility and adaptability of the system and meet the key management requirements in different scenarios.
[0113] Among them, the file size can be obtained through the file system API or library functions provided by the programming language. For example, in the Linux system, the stat command or corresponding system calls can be used to obtain the file size; the file type can be determined through the file extension or file header information. In programming, the file type can be judged according to the file extension, or more complex file analysis tools can be used to determine the file type; the user ID can be obtained through the system user management tool, such as the id command in Linux, which can display the UID and GID of the user; the login credentials are usually obtained during the user login process and can be managed through a secure authentication framework, such as OAuth2.0 or JWT (JSON Web Tokens).
[0114] A hardware random number generator (HRNG) is a device that generates random numbers using physical phenomena. The hardware random number generator can generate random seeds, which can then be used as inputs for a faster cryptographically secure pseudo-random number generator to generate a pseudo-random number output sequence. For example, for the STM32 hardware random number generator, for STM32 models without a hardware random number generator, pseudo-random numbers can be generated through software simulation. For example, a time parameter can be generated through the system timer, or a dynamic random seed can be provided by measuring the AD (analog-to-digital conversion) value. Through these methods, the hardware random number generator can provide high-quality random numbers for applications that require high security, ensuring the reliability of encryption and secure communication.
[0115] Dynamic environment characteristics include geographical location, source IP address, device information, etc. These characteristics can provide additional randomness and environmental context to enhance the security of the key. Geographical location can be obtained through IP address resolution services, and many services provide APIs to return geographical location information based on the user's IP address. The source IP address can be directly obtained from network requests, such as in the logs of a web server or by using library functions provided by programming languages to obtain the client IP address. Device information can be provided by the client. For example, on a mobile device, information such as device model and operating system version can be obtained through the operating system's API.
[0116] The master key is split into sub - keys in segments through a secret sharing algorithm, and a reconstruction threshold is set. The method includes:
[0117] Extract the value range of the sensitivity level. For example, if the lowest sensitivity level of the data is 0.7 and the highest is 11.4, then the value range of the sensitivity level is , use a clustering algorithm to dynamically divide the value range, discretize the value range into continuous value segments. Taking the current time as the base point, collect the number of key slices and the reconstruction threshold of each data in each value segment at S_o time points forward, and take the average as the number of key slices and the reconstruction threshold at the current time, denoted as and ; realize the dynamic adjustment of the number of key slices and the reconstruction threshold according to the sensitivity level range.
[0118] The secret sharing algorithm is a method of splitting the master key into multiple segments and ensuring that the original secret can be restored only when a certain number of segments are combined. Set the polynomial expression of the secret sharing algorithm as , where is the constant term, equal to the master key , , …, , …, represent coefficients, which are randomly selected, represents the variable. For each segment of each slice, takes a different value, usually from 1 to . By calculating the value in storage node i, obtain the segment with label in the master key.
[0119] The specific process of generating slices includes:
[0120] Select coefficients: Randomly select coefficients , …, , …, ;
[0121] Compute slices: For each value (usually corresponding to each storage node), compute the value, which is the corresponding key slice ;
[0122] Distribute slices: Distribute each computed to the node where it is correspondingly stored ;
[0123] Recover the key: When the master key needs to be recovered, collect at least slices, and use an interpolation algorithm (such as Lagrange interpolation) to compute the original polynomial , thus obtaining = .
[0124] By this method, even if some slices are lost or obtained by an attacker, as long as no more than slices are leaked, the master key remains secure. This strategy improves the flexibility and security of key management, especially in environments that require high security and reliability.
[0125] Use a clustering algorithm to dynamically partition the value range, discretizing the value range into continuous value segments. The specific method includes:
[0126] Step Q1: Taking the current time as a base point, collect the sensitivity levels of the data in the previous S_o time periods, and collect all the sensitivity level values to form a data set;
[0127] Step Q2: Randomly select L - N values as the initial clustering centers, compute the distances between the remaining values and the initial clustering centers, and assign them to the clusters corresponding to the nearest initial clustering centers;
[0128] Among them, the value of L - N can be set according to the work requirements. For example, when more detailed data partitioning is desired, a larger value is assigned to L - N. For example, L - N is set to 11. Conversely, a smaller value is taken.
[0129] Step Q3: Use the average value of all the values in the cluster as the new clustering center, repeat Step Q2 until the clustering centers of two adjacent iterations are the same and then stop, obtaining the values partitioned into L - N clusters;
[0130] Step Q4: Compute the density of the values in each cluster, and compute the number of partitions according to the density , extract the maximum and minimum values in each cluster to form a preliminary range, and evenly divide the preliminary range into value segments according to the number of divisions;
[0131] Step Q5: Collect the value segments in all clusters and arrange them in ascending or descending order, denoted as the value segments after discretizing the value range;
[0132] Among them, represents the density of the values in the th cluster, represents the maximum value of the values in the th cluster, represents the minimum value of the values in the th cluster, represents the number of values in the th cluster, represents the standard segmentation value; the standard segmentation value can be set by analyzing the data. For example, if the number of values in each cluster is too large, then assign a larger value to such as 3 or 4, and the value of
[0133] Step S4: Design a multi - element encryption group according to the ciphertext segment and use multi - path transmission. The receiving end decrypts and restores the data through a dynamic key;
[0134] The method of designing a multi - element encryption group according to the ciphertext segment and using multi - path transmission, and the receiving end decrypting and restoring the data through a dynamic key includes:
[0135] For each ciphertext segment, introduce a check value. The check value is generated through HMAC (Hash - based Message Authentication Code). Combine the ciphertext segment after adding the check value and the dynamic key to form a multi - element encryption group;
[0136] The multi - element encryption group is transmitted from the sending end to the receiving end through multi - path transmission. After the receiving end receives it, first recalculate the check value of each ciphertext segment and compare it with the one provided by the sending end: if they are inconsistent, it means the file has been tampered with or there is an error in transmission, then send a re - transmission request to the sending end. If they are consistent, it means the transmission is secure. The receiving end reconstructs the master key from the dynamic key, uses the master key to decrypt the data block, and reorganizes the decrypted data blocks in order into a complete real - time data message, completing the transmission of data from the sending end to the receiving end.
[0137] The method for a multi - element encryption group to be transmitted from a sender to a receiver through multi - path transmission includes: ciphertext segments and dynamic keys are transmitted through independent transmission paths respectively. Different transmission protocols and network channels are used (such as one channel for data and another channel for keys), ensuring that even if a single channel is hijacked, an attacker cannot obtain both the complete data and the key simultaneously.
[0138] Step S5: Display the transmission report on the computer terminal page and conduct interface interaction with the user.
[0139] Visualization module: Used to arrange the transmission report on the computer terminal page and conduct interface interaction with the user.
[0140] The transmission report includes transmission status and identification information. The transmission status includes normal and abnormal. If the verification values do not match, the transmission status is displayed as abnormal, and the issued identification information is a re - transmission request. If the verification values match, the transmission status is displayed as normal, and the issued identification information is transmission success.
[0141] The user conducts interactive operations such as clicking, querying, and downloading on the insurance analysis report through the computer terminal page (the computer display screen, where the computer refers to an intelligent device, which can be a mobile phone or a tablet).
[0142] Embodiment 2
[0143] Please refer to Figure 1 As shown, for the parts not described in detail in this embodiment, refer to the description content of Embodiment 1. Provide a file data security transmission platform based on a two - way encryption algorithm, including:
[0144] Data dynamic update module: Used to collect historical comprehensive data and real - time data information, design security policies according to historical comprehensive data, and dynamically update the sensitivity level of real - time data information.
[0145] Model design module: Used to design key and key generation models, construct input packages, obtain real - time generated keys and keys, segment real - time data information through slicing strategies, and encrypt using keys and keys.
[0146] Data transmission module: Used to design a multi - element encryption group according to ciphertext segments and use multi - path transmission. The receiving end decrypts and restores the data through dynamic keys.
[0147] Visualization module: Used to arrange the transmission report on the computer terminal page and conduct interface interaction with the user.
[0148] Embodiment 3
[0149] This embodiment discloses an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the operation mode of the above-provided method for secure transmission of archive data based on a two-way encryption algorithm.
[0150] Since the electronic device introduced in this embodiment is the electronic device used to implement the method for secure transmission of archive data based on a two-way encryption algorithm in the embodiments of the present application, based on the method for secure transmission of archive data based on a two-way encryption algorithm introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device used in the method for secure transmission of archive data based on a two-way encryption algorithm in the embodiments of the present application, it falls within the scope of protection of the present application.
[0151] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain a formula that is closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0152] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. Any technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for ordinary technical users in the technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.
Claims
1. A method for secure transmission of archive data based on a two-way encryption algorithm, characterized in that: include: Step S1: Collect historical comprehensive data and real-time data information, design security strategies based on historical comprehensive data, and deploy them to all archival data, and then dynamically update the sensitivity level of real-time data information; The method of designing a security strategy based on historical comprehensive data and deploying it to all archival data, thereby dynamically updating the sensitivity level of real-time data information includes: Historical comprehensive data includes data on the archival data retrieved and transmitted at historical time, and real-time data information refers to the archival data transmitted at the current time; Conduct preliminary classification of the sensitivity of historical comprehensive data and archival data through manual labeling; Use dynamic classification to update the sensitivity level of the data after preliminary classification within the cycle time. Set the dynamic classification method as ,in, Indicates the sensitivity level of the data after update. Indicates the sensitivity level of the data after preliminary classification. Indicates the frequency of data access, Indicates the life cycle of data. Indicates the maximum value of the data life cycle. and represents the weight coefficient, and represents the adjustment factor, Indicates adjustment item; Set the time period D_G, and use the cycle time as the window size, and extract the real sensitivity level of the historical comprehensive data at the start time and the end time in each window, and use the real sensitivity level at the start time as the sensitivity level after preliminary classification, and the real sensitivity level at the end time as the updated sensitivity level. Take the sensitivity levels after preliminary classification and the updated sensitivity level as a group of samples, slide the window over the time period D_G, collect all the output samples and train the dynamic classification method in batches until the sensitivity level output by the dynamic classification method converges with the real sensitivity level at the end time, and then use the weight coefficient at this time and , adjustment factor and , Adjustment items Arrange it on the dynamic grading method to obtain the final dynamic grading method expression; Deploy the final dynamic classification expression to all archival data, extract the sensitivity level of the dynamically updated real-time data information, and obtain the sensitivity level of the data information at the current time; Step S2: construct an input package according to real-time data information, design a key and secret key generation model, import the input package into the model, and obtain the key and secret key generated in real time; Step S3: Slice the real-time data information through the slicing strategy and encrypt it using the key and encryption key; Keys include master key , master key Used for data encryption, dynamic key Used to control the distribution and access of subkey fragments; the generated master key The secret sharing algorithm is used to split subkey segments; Step S4: Design a multi-encryption group based on the ciphertext fragments and use multi-path transmission. The receiving end uses a dynamic key to decrypt and restore the data. Step S5: Display the transmission report on the computer end page and interact with the user interface.
2. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 1, characterized in that: The method of constructing an input package according to real-time data information, designing a key and a secret key generation model, importing the input package into the model, and obtaining the key and secret key generated in real time includes: The timestamp, sensitivity level, data characteristics and user ID of the real-time data information are extracted and designed into a one-dimensional matrix. The obtained one-dimensional matrix is used as an attribute label to mark the real-time data information to form an input package. Obtain keys and secret keys by designing key and secret key generation models; Dynamic Key Stored on distributed nodes On, used to control the sub-key fragment access rights, and each dynamic key Can only access its stored subkey fragments .
3. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 2, characterized in that: The design method of the key and key generation model includes: The key and secret key generation model is constructed based on the master key generation formula and secret key generation formula; Set the master key generation formula to ,in, Represents the random seed generated by the hardware random number generator. Indicates the timestamp, Indicates the characteristics of indicator data, including the file size of real-time data information , File Type and sensitivity level , Indicates the user identity characteristics. Represents the data concatenation operation, represents a secure hash function; Generated master key The secret sharing algorithm is used to split subkey fragments and set the reconstruction threshold ; Based on master key The dynamic key is generated by the subkey fragment and the dynamic key generation formula is set as ,in, Indicates the sub-key fragment used to distribute and control the corresponding sub-key fragment The dynamic key of Indicates that the master key is numbered The subkey fragment of Represents dynamic data characteristics, including the file size of each data block , File Type , Sensitivity Level , User identity characteristics and dynamic environmental characteristics ,and ; A dynamic update adjustment mechanism is set for the generated master key and dynamic key. The dynamic update adjustment mechanism stipulates that the dynamic key is dynamically adjusted as the master key is updated. The master key is updated by collecting a timestamp once at the update cycle. , Sensitivity Level and dynamic environmental characteristics , regenerate through the master key generation formula; The update cycle , represents the basic period, Indicates the data transmission frequency, Indicates the frequency of data access.
4. The method for securely transmitting archive data based on a two-way encryption algorithm according to claim 3 is characterized in that: The master key The secret sharing algorithm is used to split subkeys of fragments and set reconstruction threshold The methods include: Extract the value range of the sensitivity level, use the clustering algorithm to dynamically divide the value range, discretize the value range into continuous value segments, take the current time as the base point, collect the number of key slices and reconstruction thresholds of each data in each value segment in the previous S_o time, and take the average value as the number of key slices and reconstruction threshold at the current time, denoted as and ; Suppose the polynomial expression of the secret sharing algorithm is ,in, is a constant term, equal to the master key , , …, , …, represents the coefficient, Represents a variable, by calculating the storage node i value Get the master key numbered Fragment .
5. The method for securely transmitting archive data based on a two-way encryption algorithm according to claim 4 is characterized in that: The method of using a clustering algorithm to dynamically divide the value range and discretize the value range into continuous value segments includes: Step Q1: Taking the current time as the base point, collect the sensitivity levels of the data at the previous S_o times, and collect the values of all sensitivity levels to form a data set; Step Q2: Randomly select LN values as the initial cluster centers, calculate the distances between the remaining values and the initial cluster centers, and assign them to the cluster corresponding to the nearest initial cluster center; Step Q3: Use the average value of all values in the cluster as the new cluster center, repeat step Q2 until the cluster centers of all two adjacent iterations are the same, and obtain the values divided into LN clusters; Step Q4: Calculate the density of values in each cluster , calculate the number of divisions based on density , extract the maximum and minimum values in each cluster to form a preliminary range, and divide the preliminary range into value range; Step Q5: Collect the value segments in all clusters and arrange them in order of size (ascending or descending), and record them as the value segments after the value range is discretized; in, Indicates the density of values in the cluster, Indicates The maximum value in the cluster. Indicates The minimum value of the cluster. Indicates the number of values in the cluster, Indicates the standard split value.
6. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 5, characterized in that: The method of segmenting the real-time data information by a slicing strategy and encrypting it by using a key and a secret key includes: Design a slice strategy, which is based on the slice size strategy formula and the slice quantity strategy formula, and obtain the slice size according to the slice strategy and number of slices ; The slice size output using the slice strategy and number of slices Segment the real-time data information to form data blocks; Allocate a subkey fragment to each data block, encrypt the data block using the allocated subkey fragment, and generate a ciphertext fragment; The slice size strategy formula is: , the slice quantity strategy formula is , Indicates the file size of real-time data information, Indicates the maximum number of slices, Indicates the network bandwidth. Indicates the transmission delay, Indicates the number of standard slices, Indicates the standard file size, Indicates the adjustment step size.
7. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 6, characterized in that: The method of designing a multi-encryption group according to the ciphertext fragment and using multi-path transmission, and the receiving end decrypting and restoring the data by using a dynamic key includes: A checksum is introduced for each ciphertext segment. The checksum is generated by HMAC. The ciphertext segment with the checksum added and the dynamic key are combined into a multi-element encryption group. The multiple encryption group is transmitted from the sender to the receiver through multi-path transmission. After receiving it, the receiver first recalculates the check value of each ciphertext fragment and compares it with the one provided by the sender: if they are inconsistent, a retransmission request is sent to the sender. If they are consistent, the receiver reconstructs the master key from the dynamic key, uses the master key to decrypt the data block, and reassembles the decrypted data blocks in sequence into complete real-time data information.
8. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 7, characterized in that: The method for transmitting the multi-encryption group from the sending end to the receiving end through multi-path transmission includes: the ciphertext fragment and the dynamic key are transmitted through independent transmission paths respectively.
9. A method for securely transmitting archive data based on a two-way encryption algorithm according to claim 8, characterized in that: The transmission report includes transmission status and identification information. The transmission status includes normal and abnormal. If the check values are inconsistent, the transmission status is displayed as abnormal, and the identification information sent is a retransmission request. If the check values are consistent, the transmission status is displayed as normal, and the identification information sent is successful transmission.
Citation Information
Patent Citations
Quantum distributed data storage and recovery method
CN117318943A
Archive data protection method based on block chain
CN118228312A