A multi-level encryption method and system under 5G network

By adopting a multi-level encryption method in 5G network, the data content is compressed and changed using replacement encoding and encryption logic, and the verification key is generated through marking, replacement stamps and dynamic key virtual cabinets, data transmission efficiency and security issues in 5G networks are solved, and efficient and secure data transmission is achieved.

CN119653356BActive Publication Date: 2025-06-03CHENGDU VISION FANSHI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510157759.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-06-03
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

During the encryption process of the existing 5G network, due to the large amount of data transmitted in the encryption process, the transmission efficiency in the 5G network channel is reduced, and it is difficult to effectively prevent data from being illegally intercepted and tampered during the transmission process.

Method used

A multi-level encryption method under 5G network is proposed. By analyzing the volume of transmitted data, setting the replacement encoding, compressing the transmission data, and changing the data content through encryption logic during the transmission process, generating a marker and replacement stamp, combining the dynamic key virtual cabinet to generate verification keys to ensure the security and transmission efficiency of data.

Benefits of technology

It improves the security and efficiency of data transmission, ensures efficient data transmission within 5G network channels, and at the same time enhances the unpredictability and complexity of data, effectively preventing data from being illegally intercepted and tampered.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119653356B_ABST
    Figure CN119653356B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-level encryption method and system under a 5G network, which relates to the technical field of digital information transmission security. It includes artificially setting a replacement code based on the coding volume of the transmitted data, transferring and compressing the data items in the transmitted data that match the content of the replacement code, and generating a marker suffix. The transmitted data generates a first-level data arrangement set based on the replacement code and the marker suffix, obtains a marker stamp based on the position of the replacement code in the transmitted data, the marker stamp acts on the first-level data arrangement set to generate a second-level data arrangement set, and the second-level data arrangement set generates an ultimate data arrangement set according to the encryption logic. The present invention sets the replacement code by analyzing the volume of the transmitted data, so that the replacement code compresses the volume of the transmitted data at the initial end of the upstream direction of the 5G network transmission channel, and to a certain extent alleviates the situation that the transmission efficiency in the 5G network channel is reduced due to the too large volume of the transmitted data during the encryption process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information transmission security, and particularly to a multi-level encryption method and system under a 5G network. Background Art

[0002] With the rapid development and wide application of 5G technology, network attack means are also constantly evolving. For the 5G network, due to the high speed and low latency characteristics of the 5G network, the response time of network attacks is shorter. Attackers can take advantage of this feature to launch more rapid and accurate attacks, thereby quickly obtaining communication data. Therefore, a new multi-level encryption method and system under a 5G network are needed.

[0003] After retrieval, the Chinese invention patent with the publication number "CN110691074A" discloses "an IPv6 data encryption method and an IPv6 data decryption method". This application encrypts the payload, without changing the frame header structure of the network data frame, without affecting network performance. The encrypted network data frame has exactly the same structure as the network data frame before encryption, and it is impossible to distinguish externally whether it is an encrypted network data frame or a network data frame before encryption, making it not easily vulnerable to attacks and having stronger network security.

[0004] In addition, the Chinese invention patent with the publication number "CN117955712A" discloses "a communication information security risk early warning and control method and system based on big data". This application greatly improves the recognition and prevention capabilities of various network threats (such as phishing attacks, malware, internal threats) through real-time monitoring, anomaly detection, and in-depth analysis. The automated response mechanism and dynamic access control strategy effectively reduce the exploitation of security vulnerabilities and data leakage incidents.

[0005] When encrypting data, the above two disclosed methods and similar methods encrypt the payload of the data packet while keeping the header structure of the data packet unchanged. Although this improves the security of data transmission to a certain extent, in actual scenarios, the payload in the transmitted data will become more and more as the volume of the transmitted data increases. Therefore, the transmission efficiency of data in the 5G network channel will be reduced during the encryption process. Summary of the Invention

[0006] The purpose of the present invention is to provide a multi-level encryption method and system under a 5G network to solve the problems raised in the above background art.

[0007] To achieve the above purpose, the present invention provides the following technical solutions:

[0008] In the first aspect, a multi-level encryption method under a 5G network is proposed, including:

[0009] Artificially set a replacement code based on the encoded volume of the transmitted data;

[0010] The replacement code transfers and compresses the data items in the transmitted data that match the content of the replacement code, and generates a marker suffix;

[0011] The transmitted data generates a first-level data arrangement set according to the replacement code and the marker suffix;

[0012] Obtain a marker stamp based on the position of the replacement code in the transmitted data;

[0013] The marker stamp acts on the first-level data arrangement set and generates a second-level data arrangement set;

[0014] The second-level data arrangement set generates an ultimate data arrangement set according to the encryption logic. The ultimate data arrangement set forms a replacement stamp during the shuffling and reorganization process relative to the second-level data arrangement set;

[0015] Obtain the values of the marker stamp and the replacement stamp, and convert them into a verification key, which is used to restore the transmitted data.

[0016] As a further optimization of this technical solution, respectively obtain the encoding information of the transmitted data and the encoding information of the replacement code;

[0017] Mark the encoding items in the transmitted data that are consistent with the content of the replacement code;

[0018] According to the marked encoding items, divide the transmitted data into multiple data sets;

[0019] Pack and compress the data sets corresponding to the marked encoding items;

[0020] Generate a corresponding marker suffix based on the number of data sets;

[0021] Obtain the type characteristics of the transmitted data;

[0022] Based on the type characteristics, limit the data reading direction;

[0023] Obtain a primary data sequence set, which is a data set integrated by removing the data sets corresponding to the marked encoding items from multiple data sets;

[0024] Sort the primary data sequence set according to the data reading direction;

[0025] Combine the marker suffix to generate a first-level data sequence set.

[0026] As a further optimization of this technical solution, the method for obtaining the marker stamp includes:

[0027] Obtain the arrangement position of the encoding items in the transmitted data that are the same as the content of the replacement code;

[0028] Obtain the coding sequence of the original transmission data based on the arrangement position of the coding items;

[0029] Obtain the type characteristics of the transmission data;

[0030] Limit the data reading direction based on the type characteristics;

[0031] Obtain the marking stamp based on the data reading direction and the coding sequence of the original transmission data.

[0032] As a further preference of this technical solution, the encryption logic includes:

[0033] Obtain the data sequence of the secondary data arrangement set;

[0034] Construct a pseudo-random sequence generation formula based on the number of data sequences;

[0035] The pseudo-random sequence generation formula generates a pseudo-random number sequence based on the numerical values of the data sequences, converts the numerical base of the pseudo-random number sequence, and replaces the data content of the secondary data arrangement set with the number of data items.

[0036] As a further preference of this technical solution, the pseudo-random sequence generation formula is: The pseudo-random sequence generation formula is:

[0037] , where the X N is the number of items at the Nth position in the data sequence, and K 1 is a multiplication constant, artificially established, so that the generated sequence has uniformity in the way of multiplication, avoiding a large number of identical numbers generated within the generation period. K 2 is an artificially set addition constant, used to make the generated sequence unpredictable. 2 32 is the modulus, representing the maximum value in a 32-bit computer system, used to enable the generation of a pseudo-random number sequence to cycle within a 32-bit data structure.

[0038] As a further preference of this technical solution, the generation method of the replacement stamp includes:

[0039] Obtain the item value of the data sequence in the secondary data arrangement set;

[0040] Generate a replacement stamp value sequence based on the item value;

[0041] Move the replacement stamp value sequence to a position outside the final data arrangement set and close to the data reading direction.

[0042] As a further preference of this technical solution, the generation method of the verification key includes:

[0043] Construct a dynamic key virtual cabinet that changes based on a time series. The dynamic key virtual cabinet stores multiple dynamic keys, and each dynamic key corresponds to a different numerical combination formula. The numerical combination formula is used to combine a marker timestamp value and a replacement timestamp value;

[0044] Select a dynamic key based on the encryption requirement;

[0045] Combine the marker timestamp value and the replacement timestamp value based on the numerical combination formula corresponding to the dynamic key, and generate a final verification key.

[0046] As a further preferred embodiment of this technical solution, the dynamic key virtual cabinet includes:

[0047] Multiple timestamps, each timestamp corresponding to a time interval and a numerical combination formula;

[0048] Establish a cycle period based on the number of timestamps;

[0049] Adjust the constant value in the numerical combination formula based on the cycle period.

[0050] In a second aspect, to improve the above technical solution, the present invention also proposes a multi-level encryption system under a 5G network. It should be added that a multi-level encryption system under a 5G network uses the above-mentioned multi-level encryption method under a 5G network and includes:

[0051] A data encryption module for performing encryption operations on transmitted data;

[0052] A marker timestamp and replacement timestamp generation module for generating a marker timestamp and a replacement timestamp for identifying and verifying data integrity;

[0053] A derivative replacement module for replacing the content of the secondary data arrangement set to increase the complexity of the data;

[0054] A verification key generation module for generating a verification key for restoring transmitted data;

[0055] An auxiliary module for providing auxiliary functions in the data encryption and decryption processes, including type feature recognition, data reading direction limitation, and data integrity verification.

[0056] As a further preferred embodiment of this technical solution, the data encryption module includes:

[0057] A replacement coding unit for artificially setting a replacement code and applying it to the transmitted data to replace matching data items;

[0058] A data compression and packaging unit for retrieving data items in the transmitted data that match the replacement code content and performing compression and packaging processing;

[0059] A marking suffix generation unit, configured to generate a marking suffix for the data generated by the data compression and packaging unit;

[0060] A data arrangement set generation unit, configured to replace the encoding and generate a first-level data arrangement set with the marking suffix, and further generate a second-level and a final-level data arrangement set;

[0061] The marking stamp and replacement stamp generation module includes:

[0062] A marking stamp generation unit, configured to obtain the position of the replacement encoding in the transmitted data and generate a corresponding marking stamp;

[0063] A replacement stamp generation unit, configured to identify the final arrangement order of the data;

[0064] The derivative replacement module includes:

[0065] A pseudo-random sequence generation unit, configured to generate a pseudo-random number sequence based on the number of data sequences;

[0066] A data recombination unit, configured to replace the data content of the second-level data arrangement set according to the pseudo-random number sequence to generate a final-level data arrangement set;

[0067] The verification key generation module includes:

[0068] A dynamic key virtual cabinet unit, configured to store multiple dynamic keys, each key corresponding to a different numerical combination formula;

[0069] A numerical combination formula selection unit, configured to select a corresponding numerical combination formula according to the encryption requirement;

[0070] A verification key generation unit, configured to combine the marking stamp value and the replacement stamp value to generate a final verification key;

[0071] The auxiliary module includes:

[0072] A type feature recognition unit, configured to recognize the type feature of the transmitted data;

[0073] A data reading direction limiting unit, configured to limit the data reading direction according to the type feature of the data;

[0074] A data integrity verification unit, configured to verify the integrity of the data during data transmission and reception.

[0075] Compared with the prior art, the beneficial effects of the present invention are:

[0076] The multi-level encryption method and system under the 5G network set replacement codes by analyzing the volume of transmitted data, so that the replacement codes compress the volume of transmitted data at the initial end of the upstream direction of the 5G network transmission channel, which alleviates to a certain extent the situation that the transmission efficiency in the 5G network channel is reduced due to the too large volume of transmitted data during the encryption process;

[0077] In addition, the encryption logic is used to change the transmission content of the compressed transmitted data based on the 5G network transmission channel, and the transmitted data is recombined and decompressed at the end of the upstream direction of the 5G network transmission channel. While ensuring that the transmitted data is completely transmitted from the 5G user equipment to the 5G terminal equipment, the security of data transmission is also improved;

[0078] Furthermore, by obtaining the marker stamp value and the replacement stamp value during the replacement process and the scrambling process to generate a verification key, the complexity and unpredictability of data encryption are further enhanced, thereby effectively preventing the data from being illegally intercepted and tampered with during the transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0079] Figure 1 It is a diagram of the step composition of the method of the present invention;

[0080] Figure 2 It is a running logic diagram of the method of the present invention;

[0081] Figure 3 It is a running logic diagram of the dynamic key virtual cabinet of the present invention;

[0082] Figure 4 It is a diagram of the module composition of the system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0083] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0084] Before understanding the specific implementation method proposed by the present invention, it should be clear that in the 5G network transmission channel, the initial end of the upstream direction refers to the 5G user equipment, and the end of the upstream direction refers to the 5G terminal equipment. In addition, it should be added that since in the 5G network, the underlying composition of data is generally a binary combination of "0" and "1", therefore, the replacement code content of the present invention is specifically to replace the underlying combination of "0" and "1" of the data to ensure the security of the data during the transmission process. Specifically in the actual solution, the present invention proposes a multi-level encryption method under the 5G network, as Figure 1It can be seen that the technical solution proposed by the present invention includes: step S100 - step S700.

[0085] Specifically, step S100: Artificially set a replacement code based on the encoded volume of the transmitted data.

[0086] It should be clear that in the present invention, step S100 is used to initialize the encryption process to ensure that each data packet has undergone a preset encoding replacement before entering the 5G network.

[0087] Step S200: Replace the data items in the compressed transmitted data that match the replacement code content and generate a marker suffix.

[0088] It should be noted that in the present invention, step S200 is used to replace "0" and "1" in the data items according to the replacement code in step S100 to achieve the purpose of compressing the data. Specifically, in the specific implementation process of step S200, refer to Figure 2 It can be seen that when the encoded volume of the transmitted data input by the 5G user equipment is "0110101110010", the replacement code is "010". At this time, the replacement code is "010". Therefore, the original data "0110101110010" becomes "0111110" after being processed by the replacement code.

[0089] Step S300: The transmitted data generates a first-level data arrangement set based on the replacement code and the marker suffix.

[0090] It should be clear that in the present invention, step S300 is used to generate a first-level data arrangement set for subsequent data encryption processing. In the process of step S300, the generation of the first-level data arrangement set is based on the replacement code and the marker suffix, ensuring the security and unpredictability of the data during transmission. Specifically, the generation method of the first-level data arrangement set in step S300 includes: step S301 - step S310.

[0091] Step S301: Obtain the encoding information of the transmitted data and the encoding information of the replacement code respectively.

[0092] It should be clear that in the present invention, step S301 is used to obtain the detailed information of the transmitted data and the replacement code for the subsequent step processing.

[0093] Step S302: Mark the encoding items in the transmitted data that are consistent with the replacement code content.

[0094] Step S303: Divide the transmitted data into multiple data sets according to the marked encoding items.

[0095] It should be clear that in the present invention, step S303 is used to split the transmitted data into multiple data sets for the next encryption operation. Specifically, during the splitting process, each data set contains a part of the original data, and each data set is attached with a marker suffix, which ensures that even if the data is intercepted during data transmission, the original data content cannot be directly restored.

[0096] Step S304: Pack and compress the data sets corresponding to the marked coding items.

[0097] Step S305: Generate corresponding marker suffixes based on the number of data sets.

[0098] It should be clear that, referring to Figure 2 it can be known that in steps S304 and S305 of the present invention, the obtained marker suffix is "010 2 ", where "010" is the coded content after packing and compression, and the superscript "2" is the number of occurrences.

[0099] Step S306: Obtain the type characteristics of the transmitted data.

[0100] Step S307: Limit the data reading direction based on the type characteristics.

[0101] It should be clear that in the present invention, steps S306 and S307 are used to determine the data reading order to ensure the correctness and security of the data during transmission. Specifically, in step S307, the limitation of the data reading direction is based on the type characteristics of the transmitted data. For example, for text data, the reading direction may be from left to right, while for image data, different reading orders such as from top to bottom or from bottom to top may be required. Such a limitation helps to correctly restore the data at the data receiving end and at the same time prevents the data from being misinterpreted or tampered with during transmission.

[0102] Step S308: Obtain the primary data sequence set.

[0103] It should be added that in the present invention, the primary data sequence set is an integrated data set formed by removing the data sets corresponding to the marked coding items from multiple data sets. Specifically, in the content of Figure 2 it is the data set after removing the marker suffix from the first-level data sequence set.

[0104] Step S309: Sort the primary data sequence set according to the data reading direction.

[0105] Step S310: Combine the marker suffixes to generate the first-level data sequence set.

[0106] It should be clear that in the present invention, the generation of the primary data arrangement set is based on the coding information of the transmitted data, the coding information of the replacement coding, and the marking suffix. This makes it difficult for unauthorized third parties to restore the original data content even if the data is intercepted during transmission.

[0107] Step S400: Obtain a marking stamp based on the position of the replacement coding in the transmitted data.

[0108] It should be noted that in step S400 of the present invention, the method for obtaining the marking stamp includes: step S401 - step S405.

[0109] Step S401: Obtain the arrangement positions of the coding items in the transmitted data that are the same as the content of the replacement coding.

[0110] Step S402: Obtain the coding sequence of the original transmitted data based on the arrangement positions of the coding items.

[0111] Step S403: Obtain the category characteristics of the transmitted data.

[0112] Step S404: Define the data reading direction based on the category characteristics.

[0113] Step S405: Obtain the marking stamp based on the data reading direction and the coding sequence of the original transmitted data.

[0114] It should be noted that in the present invention, the acquisition of the marking stamp is to provide an additional security level during data transmission to ensure the integrity of the data and the verifiability of the source.

[0115] Step S500: The marking stamp acts on the primary data arrangement set to generate a secondary data arrangement set.

[0116] It should be clear that in the present invention, step S500 is used to combine the marking stamp with the primary data arrangement set to further enhance the security of the data. In step S500, the marking stamp, as additional information of the data, is bound to the data items in the primary data arrangement set, thereby providing an additional verification mechanism during data transmission. Specifically, step S500 includes the following operations: step S501 - step S502.

[0117] Step S501: Perform the additional operation of the marking stamp on each data item in the primary data arrangement set. This step ensures that each data item carries the marking stamp information, providing a basis for subsequent data verification.

[0118] Step S502: Generate a secondary data arrangement set. After the marking stamp is added, the data items in the primary data arrangement set are rearranged and combined to form a secondary data arrangement set. Step S502 not only increases the complexity of the data but also improves the security of the data during transmission.

[0119] Step S600: The secondary data permutation set generates the ultimate data permutation set according to the encryption logic.

[0120] It should be added that in step S600, the secondary data permutation set generates the ultimate data permutation set according to the encryption logic. In addition, a replacement stamp is formed during the scrambling and recombination process of the ultimate data permutation set relative to the secondary data permutation set.

[0121] It should be added that in step S600, the encryption logic includes: step S601 - step S603.

[0122] Step S601: Obtain the data sequence of the secondary data permutation set.

[0123] Step S602: Construct a pseudo-random sequence generation formula based on the number of data sequences.

[0124] It should be noted that the pseudo-random sequence generation formula is:

[0125] , X N is the number of items at the Nth position in the data sequence, K 1 is a multiplication constant, artificially established, so that the generated sequence has uniformity in the form of a product, avoiding a large number of identical numbers generated within the generation period, K 2 is an artificially set addition constant, used to make the generated sequence unpredictable, 2 32 is the modulus, representing the maximum value in a 32-bit computer system, used to enable the generation of a pseudo-random number sequence to cycle within a 32-bit data structure.

[0126] Step S603: The pseudo-random sequence generation formula generates a pseudo-random number sequence based on the value of the data sequence, converts the numerical base of the pseudo-random number sequence, and replaces the data content of the secondary data permutation set with the number of data items.

[0127] It should be further noted that when the pseudo-random sequence generation formula is actually running, when the data sequence of the secondary data permutation set is "3 - 10,0111110 - 010 2 ", since the number of items of "0111110" is 7 at this time, the random value is X N takes the value of 7, and at this time, K 1 is artificially given as 50, K 2 is 13, and X N is 7, K 1 is 50, K 2 is 13 and substituted into the pseudo-random sequence generation formula to get Y = (350 + 13) mod 2 32= 131. Since the data base at this time is different from the original data sequence, when the binary value of the obtained value 131 is 10000011 during actual conversion, it should be noted that the randomly generated value items at this time are more than the data sequence items in the secondary data arrangement set. Therefore, in order to ensure data consistency and the correct generation of the pseudo-random sequence, the generated binary value needs to be truncated during actual use. The specific operation is to take the first N bits of the binary value, where N is the number of items in the data sequence of the secondary data arrangement set. In this example, since the data sequence of the secondary data arrangement set is "3 - 10,10000011 - 010 2 ", and the number of its items is 7, so the first 7 bits of the binary value need to be intercepted, that is, the first 7 bits of 10000011 are taken to get 1000001. The finally obtained data sequence of the secondary data arrangement set is "3 - 10,1000001 - 010 2 ".

[0128] Step S700: Obtain the marker stamp value and the replacement stamp value, and convert them into a verification key.

[0129] It should be added that the method for obtaining the replacement stamp in step S700 includes: steps S710 - S730.

[0130] Specifically, step S710: Obtain the item value of the data sequence in the secondary data arrangement set.

[0131] Step S720: Generate a replacement stamp value sequence based on the item value.

[0132] Step S730: Move the replacement stamp value sequence to the position outside the final data arrangement set based on the data reading direction.

[0133] It should be added that since the number of items of "1000001" is 7 at this time, the item value is "7", so the final data arrangement set is specifically "3 - 10,1000001 - 010 2 -7".

[0134] It should be clear that the verification key in step S700 is used to restore the transmitted data.

[0135] Specifically, the method for generating the verification key in step S700 includes: steps S701 - S703.

[0136] Step S701: Construct a dynamic key virtual cabinet that changes based on the time series.

[0137] Reference Figure 3It can be known that the dynamic key virtual cabinet in step S701 stores multiple dynamic keys, and each dynamic key corresponds to a different numerical combination formula, which is used to combine the marker stamp value and the replacement stamp value.

[0138] Specifically, referring to Figure 3 It can be known that the numerical combination formula includes multiple mathematical operators and parameters, such as addition, subtraction, multiplication, and division. These operators are adjusted according to the dynamic changes of the time series to ensure that the verification keys generated in different time periods are unique. In this way, even if there are potential security threats during data transmission, it is difficult for attackers to predict or copy the keys, thus ensuring the security of data transmission.

[0139] Step S702: Select a dynamic key based on the encryption requirement.

[0140] For example, if the current time series indicates that a high-security-level key is required, then the system will select a key with complex operators from the virtual cabinet to ensure the security of data transmission, specifically the operator of the sum of squares.

[0141] Step S703: Combine the marker stamp value and the replacement stamp value based on the numerical combination formula corresponding to the dynamic key, and generate the final verification key.

[0142] It should be noted that when step S703 is actually running, since the marker stamp value is the operand for the operator to execute. Specifically, referring to Figure 3 It can be known that when it is the division operator, the actually obtained value is the marker stamp value divided by the replacement stamp value. It should be added that the obtained value is generally accurate to the units digit.

[0143] As a preferred implementation manner, the dynamic key virtual cabinet in step S701 actually includes: multiple timestamps, each timestamp corresponding to a time interval and a numerical combination formula. A cycle period is established based on the number of timestamps, and the constant value in the numerical combination formula is adjusted based on the cycle period.

[0144] It should be added that adjusting the constant value in the numerical combination formula based on the cycle period can adjust the constant value and the operator in the numerical combination formula through the input end of the dynamic key sequence cabinet. It should be emphasized that the dynamic key virtual cabinet is a program software in the 5G user equipment in the present invention, and its purpose is to provide real-time and dynamically changing keys to meet the security requirements of data transmission in the 5G network environment. The construction of the dynamic key virtual cabinet ensures the diversity and timeliness of the keys, enabling a unique key to be used for each data transmission, and improving the security of data transmission to a certain extent.

[0145] As a preferred embodiment, the present invention further improves the multi-level encryption method proposed in the 5G network environment. Specifically, as Figure 4 shown, the present invention relates to an encryption system, which is constructed based on the multi-level encryption method of the 5G network and includes the following modules:

[0146] Data Encryption Module: Responsible for performing encryption operations on the transmitted data.

[0147] Marker Stamp and Replacement Stamp Generation Module: Used to generate marker stamps and replacement stamps for identifying and verifying data integrity.

[0148] Derivative Replacement Module: By scrambling the order of the secondary data arrangement set, the complexity of the data is increased.

[0149] Verification Key Generation Module: Responsible for generating verification keys for restoring the transmitted data.

[0150] Auxiliary Module: Provides auxiliary functions in the data encryption and decryption processes, including type feature recognition, data reading direction limitation, and data integrity verification.

[0151] It should be added that the modules involved in the encryption system are specifically software programs and hardware devices in the prior art to ensure the security and integrity of data transmission in the 5G network. Among them, the Data Encryption Module uses encryption algorithms such as AES or RSA to ensure the confidentiality of data during transmission. The Marker Stamp and Replacement Stamp Generation Module uses timestamp and random number generation technologies to provide a unique identifier for data packets to prevent data tampering. The Derivative Replacement Module rearranges the data through complex algorithms, increasing the difficulty of illegal interception and interpretation of the data. The Verification Key Generation Module generates specific keys for restoring encrypted data at the data receiving end. The Auxiliary Module provides necessary support, such as data type recognition to help the system correctly process different formats of data, data reading direction limitation to ensure that data is processed in a predetermined order, and data integrity verification to ensure that data is not damaged during transmission.

[0152] In the present invention, the data encryption module comprises the following parts: a substitution coding unit, responsible for setting substitution coding and applying it to the transmitted data to replace corresponding data items; a data compression and packaging unit, responsible for retrieving data items in the transmitted data that match the content of the substitution coding and performing compression and packaging processing; a marker suffix generation unit, responsible for adding a marker suffix to the data generated by the data compression and packaging unit; a data arrangement set generation unit, responsible for generating a primary data arrangement set based on the substitution coding and the marker suffix, and further generating a secondary and a final data arrangement set. In addition, the marker stamp and substitution stamp generation module includes: a marker stamp generation unit, responsible for determining the position of the substitution coding in the transmitted data and generating a corresponding marker stamp; a substitution stamp generation unit, responsible for identifying the final arrangement order of the data. The derivative substitution module includes: a pseudo-random sequence generation unit, generating a pseudo-random number sequence based on the number of data sequences; a data recombination unit, replacing the data content of the secondary data arrangement set according to the pseudo-random number sequence to generate a final data arrangement set. The verification key generation module includes: a dynamic key virtual cabinet unit, used for storing multiple dynamic keys, each key corresponding to a different numerical combination formula; a numerical combination formula selection unit, responsible for selecting a corresponding numerical combination formula according to the encryption requirements; a verification key generation unit, responsible for combining the marker stamp value and the substitution stamp value to generate a final verification key. Finally, the auxiliary module includes: a type feature recognition unit, used for recognizing the type features of the transmitted data; a data reading direction limiting unit, limiting the data reading direction according to the type features of the data; a data integrity verification unit, used for verifying the integrity of the data during data transmission and reception.

[0153] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended embodiments and their equivalents.

Claims

1. A multi-level encryption method under a 5G network, characterized in that: include: Setting replacement codes based on the code volume of the transmitted data; Replace the data items in the code transfer compression transmission data that match the replacement code content, and generate a tag suffix; The transmission data generates a first-level data arrangement set according to the replacement code and the tag suffix; Obtaining a marking stamp at a location of the transmitted data based on the replacement code; The marking stamp acts on the primary data arrangement set and generates a secondary data arrangement set; The secondary data arrangement set generates a final data arrangement set according to the encryption logic, and the final data arrangement set has a replacement stamp formed in the process of scrambling and reorganizing the secondary data arrangement set; Obtain the value of the mark stamp and the value of the replacement stamp, and convert them into a verification key, which is used to restore the transmitted data; The method for generating the first-level data arrangement set includes: Respectively obtain the encoding information of the transmission data and the encoding information of the replacement encoding; Marking the coded items in the transmitted data that are consistent with the replacement coded content; Dividing the transmission data into a plurality of data sets according to the marked coding items; Packing and compressing the data sets corresponding to the marked coding items; Based on the number of data sets, generate corresponding tag suffixes; Get the type characteristics of the transmitted data; Based on type characteristics, the data reading direction is limited; Obtaining a primary data series set, where the primary data series set is a data set formed by removing data sets corresponding to marked coding items from multiple data sets and integrating them; sorting the primary data sequence set according to the data reading direction; Combined with the tag suffix, a primary data sequence set is generated; Methods for obtaining the marking stamp include: Obtain the arrangement position of the coding items in the transmission data that are identical to the replacement coding content; Obtaining a coding sequence of the original transmission data based on the arrangement position of the coding items; Obtaining the type characteristics of the transmitted data; Limit the data reading direction based on the type characteristics; Obtaining a marking stamp based on the data reading direction and the encoding sequence of the original transmitted data; The encryption logic includes: Obtaining a data sequence of a secondary data arrangement set; Construct a pseudo-random sequence generation formula based on the number of data sequences; The pseudo-random sequence generation formula generates a pseudo-random number sequence based on the numerical value of the data sequence, the pseudo-random number sequence converts the numerical value system, and replaces the data content of the secondary data arrangement set based on the number of data items; The pseudo-random sequence generation formula is: , the X N is the number of N-position items in the data sequence, K1 is the multiplication constant, which makes the generated sequence uniform by multiplication to avoid a large number of identical numbers in the generation cycle, and K2 is the addition constant, which is used to make the generated sequence unpredictable. 32 The modulus represents the maximum value in a 32-bit computer system and is used to enable the pseudo-random number sequence to be generated cyclically in a 32-bit data structure. The method for generating the replacement stamp includes: Get the item value of the data sequence in the secondary data arrangement set; Generate a replacement stamp value sequence based on the item value; Move the replacement stamp value sequence to a position outside the final data arrangement set close to the data reading direction; The method for generating the verification key includes: Construct a dynamic key virtual cabinet that changes based on a time series. The dynamic key virtual cabinet stores multiple dynamic keys. Each dynamic key corresponds to a different numerical combination formula. The numerical combination formula is used to combine the marking stamp value and the replacement stamp value. Select dynamic keys based on encryption requirements; Based on the numerical value corresponding to the dynamic key, the marking stamp value and the replacement stamp value are combined with the formula to generate the final verification key; The dynamic key virtual cabinet comprises: Multiple timestamps, each timestamp corresponds to a time interval and a numerical value combined with a formula; Establishing a cycle period based on the number of timestamps; Adjust the value based on the cycle period and combine it with the constant value in the formula.

2. A multi-level encryption system under a 5G network, using the multi-level encryption method under a 5G network according to claim 1, characterized in that: include: A data encryption module, used to perform encryption operations on transmitted data; A marking stamp and replacement stamp generating module, used to generate marking stamps and replacement stamps for identifying and verifying data integrity; A derivative replacement module is used to replace the content of the secondary data arrangement set to increase the complexity of the data; A verification key generation module, used to generate a verification key for restoring transmission data; The auxiliary module is used to provide auxiliary functions in the data encryption and decryption process, including type feature recognition, data reading direction limitation and data integrity verification.

3. A multi-level encryption system under a 5G network according to claim 2, characterized in that: The data encryption module comprises: A replacement code unit, which is used to manually set a replacement code and apply it to the transmitted data to replace the matching data item; A data compression and packaging unit, used to retrieve data items matching the replacement coded content in the transmission data, and perform compression and packaging processing; A marking suffix generating unit, used for marking suffixes on data generated by the data compression and packaging unit; A data arrangement set generating unit, used for replacing codes and marking suffixes to generate a primary data arrangement set, and further generating secondary and final data arrangement sets; The marking stamp and replacement stamp generating module comprises: A marker generating unit, used for obtaining the position of the replacement code in the transmission data and generating a corresponding marker; A replacement stamp generation unit, used to identify the final arrangement order of data; The derivative replacement module includes: A pseudo-random sequence generation unit generates a pseudo-random number sequence based on the number of data sequences; A data reorganization unit replaces the data content of the secondary data arrangement set according to the pseudo-random number sequence to generate a final data arrangement set; The verification key generation module comprises: A dynamic key virtual cabinet unit is used to store multiple dynamic keys, each key corresponding to a different numerical value combination formula; A numerical combination formula selection unit is used to select a corresponding numerical combination formula according to encryption requirements; A verification key generation unit, used to generate a final verification key by combining the marking stamp value and the replacement stamp value; The auxiliary module comprises: A type feature identification unit, used to identify the type features of the transmitted data; A data reading direction limiting unit, used to limit the data reading direction according to the type characteristics of the data; The data integrity verification unit is used to verify the integrity of data during data transmission and reception.

Citation Information

Patent Citations

  • IPv6 data encryption method and IPv6 data decryption method

    CN110691074A

  • Communication information security risk early warning management and control method and system based on big data

    CN117955712A

  • Data encryption communication method and system based on virtual private network technology

    CN117240626A

  • Internet of Things processing method and system for data exchange

    CN118487716A