A data encryption transmission method and device with an early warning mechanism
By presetting multiple encryption solutions in the data transmission system and dynamically selecting, the encrypted transmission system improves security and adaptability, solves the problems of easy cracking of encryption solutions and lacking early warning mechanisms in the existing technology, and achieves more effective data protection.
Patent Information
- Application Number
- CN202510193757.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-21
AI Technical Summary
The existing data encryption transmission technology has the potential to be cracked at rest, the predictability of dynamically selected encryption algorithm processes leads to security threats, and the lack of effective early warning mechanisms to deal with security issues in data transmission.
The front-end and back-end of the data transmission system are preset and stored in multiple sets of encryption schemes with unique names. The front-end randomly selects encryption schemes based on security requirements, and records and monitors transmission indicators during data transmission to detect potential security problems in real time.
Through dynamic selection of encryption schemes and real-time monitoring of transmission metrics, data transmission security and adaptability are improved, the ability to combat advanced persistent threats (APTs) is enhanced, and the risk of data loss or leakage is reduced.
Smart Images

Figure CN119676001B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encryption transmission technology, and particularly to a data encryption transmission method and device with a warning mechanism. Background Art
[0002] In existing data transmission technologies, encryption technologies are widely used to ensure the security and privacy of data transmitted over the network. These technologies typically involve using static, pre-set encryption schemes at the front-end and back-end of data transmission to protect data from unauthorized access or theft. Additionally, some systems employ methods of dynamically selecting encryption algorithms to adapt to the ever-changing network security environment and attack patterns, in order to increase the security and adaptability of the system.
[0003] However, despite these encryption measures, there are still some important problems in the prior art. First, static encryption schemes are prone to being gradually cracked over time, as attackers can continuously study the same algorithm to discover its weaknesses. Second, even in systems that dynamically select encryption algorithms, they are often subject to security threats due to the predictability of the algorithm selection process, especially when the algorithm selection depends on observable parameters. Moreover, these systems often lack an effective warning mechanism to address security issues discovered during data transmission, such as data tampering or latency anomalies, which limits their effectiveness in the face of advanced persistent threats (APT).
[0004] Therefore, it is necessary to develop a new data encryption transmission method. Summary of the Invention
[0005] This application provides a data encryption transmission method and device with a warning mechanism to improve the security and reliability of data transmission.
[0006] This application provides a data encryption transmission method with a warning mechanism, including:
[0007] Preset and store multiple sets of encryption schemes with unique names at the front-end and back-end of the data transmission system, where the unique names are only known within the system;
[0008] The front-end randomly selects a set of encryption schemes based on security requirements, and before sending the request data, encrypts it using the selected encryption scheme to generate encrypted request data; sends the encrypted request data and the unique name corresponding to the selected encryption scheme to the back-end; records the unique name corresponding to the selected encryption scheme and relevant transmission metrics; where the request data includes user authentication information, transaction instructions, and query requests; the relevant transmission metrics include the sending time and the limiting conditions for the returned message;
[0009] After the backend receives the encrypted request data and the unique name corresponding to the selected encryption scheme, it decrypts the data using the same encryption scheme as the frontend; processes the decrypted request data, and encrypts the processed result data again using the same encryption scheme as the frontend; and sends the encrypted processed result data back to the frontend.
[0010] After the frontend receives the encrypted data, it decrypts the encrypted data and verifies whether the encrypted data meets the time requirements of the recorded relevant transmission metrics and the limiting conditions of the returned message.
[0011] If an anomaly is found during data decryption or metric calculation, the frontend will record the anomaly, feedback the anomaly to the backend, and stop the current data processing; wherein, the anomaly includes decryption failure, data delay anomaly, data format and length mismatch.
[0012] After the backend receives the anomaly feedback from the frontend, it takes security measures to address potential data security threats.
[0013] Furthermore, the multiple encryption schemes include at least one symmetric encryption algorithm and at least one asymmetric encryption algorithm, and each algorithm has an independent naming and configuration parameter.
[0014] Furthermore, the frontend randomly selects a set of encryption schemes based on security requirements, including:
[0015] Define a set of security factors , where each security factor represents the th influencing parameter that affects the selection of the encryption scheme, and the influencing parameters include the security level of the current network environment, the computing power of the user device, and the data sensitivity score.
[0016] According to the following formula (1), calculate the comprehensive security index :
[0017]
[0018] where is the weight coefficient; represents the number of influencing parameters;
[0019] According to the following formula (2), obtain the index of the encryption scheme :
[0020]
[0021] where is the adjustment coefficient; is the total number of encryption schemes;
[0022] According to the index , determine the selected encryption scheme.
[0023] Furthermore, the unique names of the encrypted data and the encryption scheme are sent to the backend through a secure channel, and the secure channel encrypts all transmitted data using the TLS protocol.
[0024] Furthermore, after decrypting the request data, the backend performs an integrity check on the data content, and processes and re-encrypts it after confirming that there is no tampering.
[0025] Furthermore, after decrypting the encrypted data, the frontend verifies whether the data is received within a predetermined time window, and if it exceeds the time window, it is considered an abnormal data delay.
[0026] Furthermore, when the frontend discovers an anomaly, it also generates a security event log, which includes:
[0027] Anomaly type and severity;
[0028] A system state snapshot when the anomaly occurs;
[0029] Related network traffic characteristics.
[0030] Furthermore, when the frontend discovers an anomaly, it adjusts the local security policy according to the severity of the anomaly, and the local security policy includes increasing authentication requirements or restricting the use of specified functions.
[0031] Furthermore, after receiving the anomaly feedback from the frontend, the backend performs the following steps:
[0032] Compare the received anomaly information with the global security intelligence database in real time;
[0033] Based on the comparison result, use a pre-trained security expert system to evaluate the threat level;
[0034] According to the evaluated threat level, automatically generate and execute security response measures, where the security response measures include:
[0035] Dynamically adjust network firewall rules;
[0036] Start a deep packet inspection process;
[0037] Isolate suspicious network segments or devices.
[0038] This application provides a data encryption transmission device with an early warning mechanism, including:
[0039] A data storage unit configured to pre-store multiple sets of encryption schemes with unique names at the front end and the backend of the data transmission system, where the unique names are only known within the system;
[0040] An encryption selection unit, configured to randomly select a set of encryption schemes based on security requirements, and before sending the request data, encrypt the request data using the selected encryption scheme to generate encrypted request data, where the request data includes user authentication information, transaction instructions, and query requests;
[0041] A transmission control unit, configured to send the encrypted request data and the unique name corresponding to the selected encryption scheme to the backend, and record the unique name corresponding to the selected encryption scheme and relevant transmission metrics, where the relevant transmission metrics include the sending time and the limiting conditions for the returned message;
[0042] A receiving and processing unit, configured to receive the encrypted request data and the unique name corresponding to the selected encryption scheme at the backend, decrypt using the same encryption scheme as the frontend, process the decrypted request data, and encrypt the processed result data again using the same encryption scheme as the frontend, and send the encrypted processed result data back to the frontend;
[0043] A decryption verification unit, configured to decrypt the encryption after receiving the encrypted data at the frontend, and verify whether the encrypted data meets the time requirements of the recorded relevant transmission metrics and the limiting conditions for the returned message;
[0044] An exception handling unit, configured to record the exception and feedback the exception to the backend when an exception is found during data decryption or metric calculation, and stop the current data processing, where the exception includes decryption failure, data delay exception, data format and length mismatch;
[0045] A security response unit, configured to take security measures to address potential data security threats after the backend receives the exception feedback from the frontend.
[0046] The technical solution proposed in this application has the following beneficial technical effects:
[0047] (1) By presetting and storing multiple sets of encryption schemes with unique names at the frontend and backend of the data transmission system and ensuring that these names are only known within the system, this application significantly improves data security. The use of unique names reduces the possibility for external attackers to identify and exploit specific encryption schemes, thereby enhancing the confidentiality and security of the encrypted data.
[0048] (2) This application allows the frontend to randomly select an encryption scheme based on the current security requirements and encrypt before sending the request data. This dynamic selection mechanism adapts to the ever-changing security threats, enabling the system to more effectively counter attacks against specific encryption algorithms, thereby protecting the data from advanced persistent threats (APTs) and other malicious attacks.
[0049] (3) By recording and monitoring key transmission metrics (such as the sending time and the limiting conditions of the returned messages), this application can detect potential security issues in real time during data transmission. Once an abnormal situation is detected, such as decryption failure, data delay, or data format and length mismatch, the system can immediately take actions, such as notifying the backend through a feedback mechanism and pausing the current data processing, thereby preventing data leakage or damage.
[0050] (4) After the backend receives the abnormal feedback from the frontend, this application allows the backend to quickly take appropriate security measures to address potential data security threats. This rapid response mechanism not only reduces the risk of data loss or leakage, but also increases the overall resilience of the system, enabling the data transmission environment to maintain a high level of security and stability in the face of various threats. Description of the Drawings
[0051] Figure 1 is a flowchart of a data encryption transmission method with an early warning mechanism provided by the first embodiment of this application.
[0052] Figure 2 is a schematic diagram of a data encryption transmission device with an early warning mechanism provided by the second embodiment of this application. Detailed Embodiments
[0053] Many specific details are set forth in the following description in order to provide a thorough understanding of this application. However, this application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of this application. Therefore, this application is not limited by the specific embodiments disclosed below.
[0054] The first embodiment of this application provides a data encryption transmission method with an early warning mechanism. Please refer to Figure 1 , which is a schematic diagram of the first embodiment of this application. The following will describe in detail a data encryption transmission method with an early warning mechanism provided by the first embodiment of this application in combination with Figure 1 .
[0055] Step S101: Preset and store multiple sets of encryption schemes with unique names at the front end and the back end of the data transmission system, where the unique names are only known within the system.
[0056] The concepts of the front end and the back end in this embodiment are key components, which represent the two main stages and locations for processing data in the system. These terms may have different meanings in different contexts, but in this embodiment, they specifically refer to the starting point and the ending point in the data security processing flow.
[0057] The front end usually refers to the part of the system that directly interacts with users, and it acts as the data sender during the data transmission process. For example, consider an online banking system. The front end might be the banking app or website used by customers through which they submit transaction requests such as money transfers or bill payments. This part of the system is responsible for collecting user inputs like account information and transaction details, and then encrypting this data to ensure its secure transmission over the internet to the bank's server, i.e., the back end.
[0058] The back end, on the other hand, refers to the part that runs on the server and typically acts as the receiver in the data transmission process. Continuing with the online banking example, the back end is the server system that processes customer requests. It is responsible for receiving the encrypted data from the front end, decrypting it to obtain the actual request content, and processing it, such as updating account balances, recording transaction histories, etc. After processing, the back end may also need to encrypt the confirmation information or other response data again and send it back to the front end to inform the user that the transaction has been successfully processed.
[0059] First, system administrators or developers need to deploy encryption schemes at both the front end and the back end of the data transmission system. These encryption schemes may include various public - key and private - key systems, symmetric - key systems, or any other encryption technologies suitable for ensuring data security. Each encryption scheme will have a complete set of configurations, including the encryption algorithms used, key lengths, operating modes, etc.
[0060] Public - key systems and private - key systems are two major categories in the field of data encryption, and they use different techniques to ensure the secure transmission of electronic data. Public - key systems, also known as asymmetric encryption systems, involve two keys: a public key for encrypting data and a private key for decrypting. A typical example is RSA. This algorithm is based on the difficulty of factoring large numbers, and common key lengths include 1024 bits, 2048 bits, and 4096 bits. RSA is usually used to encrypt small chunks of data or encrypt session keys, which are symmetric keys. Another popular public - key encryption technology is Elliptic Curve Cryptography (ECC), which offers relatively short key lengths (such as 256 bits, 384 bits, 521 bits) and higher computational efficiency while providing the same level of security.
[0061] On the other hand, a private key system, or symmetric encryption system, uses the same key to encrypt and decrypt data. Among such systems, the Advanced Encryption Standard (AES) is the most widely used, supporting key lengths of 128 bits, 192 bits, and 256 bits. AES can operate in multiple modes of operation, such as Electronic Codebook Mode (ECB), Cipher Block Chaining Mode (CBC), and Galois / Counter Mode (GCM), where the GCM mode also provides encryption and authentication functions. The Data Encryption Standard (DES) and its successor Triple DES are older but still in use. In particular, Triple DES increases security by using a triple-length key, although its key length is 168 bits and it actually uses 112 bits or 168 bits.
[0062] The mode of operation refers to how to repeatedly use an encryption algorithm (such as AES, DES) to process data blocks in symmetric encryption. The symmetric encryption algorithm itself is usually designed to encrypt only data blocks of a fixed size (such as 128 bits for AES), but the actual data often exceeds this size. Therefore, a mechanism is needed to securely process data of any length. The mode of operation is such a mechanism that defines how to encrypt data blocks and the rules for linking these data blocks to ensure the encryption security and integrity of the overall data.
[0063] The following are some basic modes of operation, each with its specific uses and characteristics:
[0064] 1. Electronic Codebook Mode (ECB):
[0065] In this mode, each data block is encrypted independently. When the same content of the same data block is encrypted with the same key, the same encryption result will be produced. The main disadvantage of this mode is that it may expose the pattern, making the encryption process vulnerable to attacks. Therefore, it is not recommended for encrypting information longer than one data block.
[0066] 2. Cipher Block Chaining Mode (CBC):
[0067] The CBC mode increases the dependence between data blocks by performing an XOR operation on each data block with the encryption result of the previous block before encryption. This mode requires an Initialization Vector (IV) and ensures that each block in the encryption process depends on all previous blocks, improving security.
[0068] 3. Cipher Feedback Mode (CFB):
[0069] The CFB mode turns a symmetric encryption algorithm into a self - synchronizing stream cipher. It uses part of the output of the previous encrypted block as the input for the next block. This mode allows data to be encrypted into an output of the same size as the input data.
[0070] 4. Output Feedback Mode (OFB):
[0071] The OFB mode is similar to CFB, but provides a true stream mode. It generates a key stream, which is XORed with the plaintext data to produce the ciphertext. The advantage of the OFB mode is that an error during the encryption or decryption process does not propagate to subsequent data blocks.
[0072] 5. Counter Mode (CTR):
[0073] In the CTR mode, each data block position corresponds to a counter, which is encrypted together with the key, and then its output is XORed with the data block to generate the ciphertext. This mode turns a symmetric encryption algorithm into a stream cipher, enabling the encryption and decryption processes to be fully parallelized.
[0074] Each mode has its advantages and limitations. The choice of which mode to use depends on the specific application scenario and security requirements. For example, the CBC mode is widely used in applications that require high security due to its enhanced security, while the CTR is suitable for high - performance requirements due to its fast processing speed and parallel processing capabilities.
[0075] In practical applications, public - key encryption is usually used to securely transmit the key itself. For example, in the SSL / TLS handshake process, RSA or ECC may be used to securely transmit the symmetric key. Symmetric encryption is usually used to encrypt large amounts of data due to its high efficiency, such as for online data transmission or large - scale data storage encryption. The choice of these encryption technologies depends on specific security requirements, performance requirements, and the implementation environment, and each technology has its unique advantages and best application scenarios.
[0076] Next, generate a unique name for each set of encryption schemes. The generation of these names can be based on various factors, such as the specific configuration details of the encryption scheme or the creation timestamp, and then process this information through a cryptographic hash function to generate a unique name. Importantly, these unique names must remain internal system information and not be made public to prevent potential security threats. This can be achieved by encrypting and storing these names in the system's security database, ensuring that only authorized system components can access these names.
[0077] In addition, the system should have a mechanism to ensure the synchronous update and management of these encryption schemes and their unique names on the front-end and back-end. This may be implemented through a central management system that is responsible for pushing updates to all relevant front-end and back-end devices to ensure the consistency and up-to-date status of the encryption policies.
[0078] Through the implementation of step S101, the data transmission system can maintain a high level of security and flexibility. Each component in the system can select the most suitable encryption scheme according to needs, while ensuring the uniqueness and privacy of these encryption schemes. Such a setting provides a solid security foundation for data transmission, effectively preventing unauthorized access or identification of the encryption schemes.
[0079] Furthermore, the multiple sets of encryption schemes include at least one symmetric encryption algorithm and at least one asymmetric encryption algorithm, and each algorithm has independent naming and configuration parameters.
[0080] This embodiment provides multiple sets of encryption schemes used in the data encryption transmission method. These encryption schemes include not only symmetric encryption algorithms and asymmetric encryption algorithms, but also each algorithm has independent naming and configuration parameters. Such a design allows the system to select the most suitable encryption method according to different security requirements and scenarios, while maintaining a high level of flexibility and security.
[0081] First, it is necessary to ensure that both the front-end and back-end of the system can store and manage multiple encryption algorithms. These algorithms include but are not limited to:
[0082] Symmetric encryption algorithms: These algorithms use the same key for data encryption and decryption. Common symmetric encryption algorithms include AES (Advanced Encryption Standard), DES (Data Encryption Standard), and its more secure version Triple DES. For each symmetric algorithm, the system needs to configure relevant key lengths, block sizes, and possible operation modes (such as CBC, ECB, CFB, etc.).
[0083] Asymmetric encryption algorithms: These algorithms use a pair of keys, namely the public key and the private key. The public key is used to encrypt data, and the private key is used to decrypt. Common asymmetric encryption algorithms include RSA, ECC (Elliptic Curve Cryptography), and DSA (Digital Signature Algorithm). For each asymmetric algorithm, parameters such as key length and encryption strength need to be configured.
[0084] Furthermore, the unique names of the multiple sets of encryption schemes are generated through the following steps:
[0085] Encode the key attributes of each set of encryption schemes to generate a string representation; perform a hash operation on the generated string to obtain a hash value H; where the key attributes include algorithm type, key length, and operation mode;
[0086] Generate a random seed S generated by a dynamic factor based on the system operating environment, together with a preset key K, and generate a time key TK through a secure hashing algorithm;
[0087] Concatenate the hash value H with the time key TK, and perform a single hashing process using a secure hash function to obtain an intermediate value M;
[0088] Map the intermediate value M to a phrase consisting of an adjective and a noun, where the adjective and noun are from a predefined thesaurus related to the security protocol; among them, the mapping rules include: using different bit segment values of M to determine the selection of adjectives and nouns in the thesaurus to ensure the diversity and uniqueness of the name.
[0089] First, encode the key attributes of each encryption scheme. These key attributes include the type of encryption algorithm (such as AES or RSA), the length of the key (such as 128 bits, 256 bits, etc.), and the operating mode (such as CBC, GCM, etc.). These attributes are the basis for the performance and security of the encryption scheme, so they are selected as the source information for generating unique names. These attributes are encoded into a string representation to ensure that every detail is converted into an easy-to-process text format.
[0090] Next, perform a hashing process on the generated string above to obtain a hash value H. The hashing process is to ensure the uniqueness of the name, and even a slight change in the attributes will result in significant differences in the hash value. In addition, generate a random seed S generated by a dynamic factor based on the system operating environment, and combine it with a preset key K to generate a time key TK through a secure hashing algorithm (such as SHA-256). This time key TK utilizes the current system environment and time variables to ensure that the key generated each time has timeliness and randomness, enhancing security.
[0091] Concatenate the obtained hash value H with the time key TK, and then perform another hashing process using another secure hash function to obtain an intermediate value M. This step is to further increase the complexity and randomness of the generation process to ensure that even extremely similar encryption schemes can obtain different unique names.
[0092] Finally, map the intermediate value M to a phrase consisting of an adjective and a noun. The adjective and noun here are from a predefined thesaurus related to the security protocol, and the mapping rule is to determine the selection of adjectives and nouns in the thesaurus according to different bit segment values of M. This method not only ensures the diversity and uniqueness of the name, but also makes the name easy to remember and express, while retaining a metaphorical description of the encryption scheme attributes.
[0093] Through this complex generation process, each encryption scheme can be given a name that is both secure and unique, as well as expressive, which helps users and technicians clearly distinguish and reference each scheme when using and managing multiple encryption schemes.
[0094] The following is an example to illustrate how to generate an encryption name:
[0095] 1. Selection and Encoding of Encryption Scheme Attributes
[0096] Suppose there is an encryption scheme with the following key attributes:
[0097] Algorithm type: AES
[0098] Key length: 256 bits
[0099] Operating mode: CBC
[0100] First, encode these attributes into a string representation, for example: "AES-256-CBC".
[0101] 2. Hashing and Generation of Time Key
[0102] Next, perform hashing on the "AES-256-CBC" string, using the SHA-256 algorithm to obtain the hash value H. For example, the hash value may be a string of hexadecimal numbers.
[0103] Suppose the current time of the system is "September 7, 2023, 10:15". Combine this time information with a preset key K (assumed to be "my_secret_key") and use the SHA-256 algorithm to generate the time key TK.
[0104] 3. Generation of the Final Hash Value
[0105] Concatenate the obtained hash value H and the time key TK, and perform SHA-256 hashing again to obtain the intermediate value M.
[0106] 4. Mapping of the Name
[0107] Now it is necessary to map the intermediate value M to a phrase composed of an adjective and a noun in Chinese. Suppose the thesaurus includes the following words:
[0108] Adjectives: ["secure", "rapid", "stable", "efficient"]
[0109] Nouns: ["shield", "matrix", "lock", "net"]
[0110] Assume that the first segment value of the intermediate value M points to "safe" and the second segment value of the intermediate value M points to "lock", then the generated unique name can be "safety lock".
[0111] Step S102: The front end randomly selects an encryption scheme based on security requirements, and before sending the request data, encrypts it using the selected encryption scheme to generate encrypted request data; sends the encrypted request data and the unique name corresponding to the selected encryption scheme to the back end; records the unique name corresponding to the selected encryption scheme and relevant transmission metrics; wherein, the request data includes user authentication information, transaction instructions, and query requests; the relevant transmission metrics include the sending time and the limiting conditions for the returned message.
[0112] In step S102, the steps for how the front end selects an encryption scheme according to security requirements are provided, and the encryption process for processing the request data is detailed. This step involves several key operations, including the selection of the encryption scheme, the encryption of the request data, the sending of the encrypted data, and the recording of relevant transmission metrics. The following are the detailed implementation methods of these operations:
[0113] First, the front-end system needs to evaluate the current security requirements, which may be based on various factors, such as the security level of the network, the sensitivity of the data, and the latest threat intelligence. According to these security requirements, the front-end system randomly selects an encryption scheme from multiple pre-stored encryption schemes. This selection not only depends on security requirements but may also consider the performance of the algorithm to adapt to different operating environments. The selection process can be implemented through an algorithm, for example, using a random number generator combined with weight evaluation to select the most suitable encryption scheme for the current situation.
[0114] After selecting the encryption scheme, the front-end system will use this scheme to encrypt the request data. The request data may include user authentication information, transaction instructions, query requests, etc. These data usually contain sensitive information and must be encrypted before transmission to ensure security. The encryption process involves taking these data as input and converting them into ciphertext through an encryption algorithm, ensuring that only the recipient with the appropriate key can decrypt it.
[0115] After encryption is completed, the front-end system packs and sends the encrypted request data and the unique name of the encryption scheme to the back end. The unique name is used to confirm the use of the same encryption scheme for decryption at the back end. At the same time, the front-end system also records the metrics related to this transmission, such as the sending time and specific limiting conditions for the returned message. These metrics are crucial for subsequent data security analysis and verification.
[0116] In data encryption and network communication, specific restrictions on returned messages usually specify a series of requirements or parameters for ensuring the security and integrity of data transmission. These restrictions help verify the status of the returned data and ensure that it has not been compromised or tampered with during transmission. The following are some specific examples to illustrate such restrictions:
[0117] 1. Response time limit:
[0118] In many sensitive data exchange scenarios, such as online transactions or real-time monitoring systems, the response time of messages is one of the key security measures. A maximum response time limit can be set. For example, all returned messages must reach the front end within 5 seconds after the request is sent. Messages that time out may be regarded as indications of network latency or potential replay attacks and will therefore be rejected by the system or marked as suspicious.
[0119] 2. Data integrity verification:
[0120] Returned messages usually contain a checksum or digital signature for verifying whether the data has been tampered with during transmission. Specific restrictions may stipulate that the message must contain a valid signature that matches the public key held by the front end. This ensures the origin and integrity of the data and is a key security measure to prevent data tampering.
[0121] 3. Message size limit:
[0122] To prevent malicious attempts to attack the system by sending abnormally sized data packets, a size limit for returned messages can be set. For example, the system may preset that any returned data packet should not exceed 1MB. This limit helps prevent denial-of-service (DoS) attacks and buffer overflow attacks and ensures that system resources are not maliciously consumed.
[0123] 4. Content security policy:
[0124] The content of returned messages may also be restricted, especially when transmitting data involving executable code or configuration information. For example, the returned message may need to comply with a specific content security policy (CSP), such as not containing JavaScript code or only allowing scripts to be loaded from specific sources. This helps prevent cross-site scripting (XSS) attacks and other forms of malicious content injection.
[0125] By setting these specific restrictions, the system can effectively enhance security protection measures and improve the security and reliability of data transmission. These measures ensure that the returned data is not only secure but also meets the real-time requirements of business processes and system operations.
[0126] These transmitted metrics can be used in subsequent steps to verify the integrity and timeliness of the returned data, helping to ensure that the data has not been tampered with during transmission and is not affected by network security threats such as latency attacks. If anomalies are detected during data decryption or metric calculation, these records will support the system in quickly and accurately locating the problem and taking corresponding countermeasures.
[0127] Furthermore, the front end randomly selects a set of encryption schemes based on security requirements, including:
[0128] Define a set of security factors , where each security factor represents the th influencing parameter affecting the selection of the encryption scheme. The influencing parameters include the security level of the current network environment, the computing power of the user device, and the data sensitivity score;
[0129] According to the following formula (1), calculate the comprehensive security index :
[0130]
[0131] where, is the weight coefficient; represents the number of influencing parameters;
[0132] According to the following formula (2), obtain the index of the encryption scheme :
[0133]
[0134] where, is the adjustment coefficient; is the total number of encryption schemes;
[0135] According to the said index , determine the selected encryption scheme.
[0136] In this embodiment, the front-end system adopts a method based on comprehensive security assessment when selecting an encryption scheme to ensure that the selected encryption strategy is most suitable for the current data security requirements.
[0137] First of all, the front end defines a set of security factors , where each security factor represents a specific parameter affecting the selection of the encryption scheme. These parameters include, but are not limited to, the security level of the current network environment, the computing power of the user device, and the data sensitivity score. Each parameter is derived from the actual security environment and system performance analysis to reflect the security requirements and device capabilities in a specific environment.
[0138] In the data encryption transmission method, it is crucial to accurately evaluate the security level of the current network environment, the computing power of the user device, and the data sensitivity score. These parameters directly affect the choice of encryption scheme to ensure the maximization of data security. The following details how these parameters are calculated and obtained.
[0139] The security level of the current network environment is usually evaluated by a network monitoring system based on abnormal activities in network traffic, known threat intelligence, recent security incident records, and alerts from the network intrusion detection system. For example, if unauthorized access attempts are frequently detected in a network environment or there is a large amount of malicious software communication, the security level of the network will be rated as low. On the contrary, if network monitoring shows few or no security threats and there are effective firewalls and intrusion detection systems running, the security level of the network will be rated as high. These evaluation results can be represented by a numerical value from 1 to 10, where 10 represents extremely high security and 1 represents extremely low security.
[0140] The computing power of the user device refers to the ability of the user device to process data and run encryption algorithms. This is usually determined by the processor speed of the device, the available memory, and the current system load. For example, a device equipped with the latest processor and a large amount of RAM will have a high computing power score, while an old mobile phone or a low - configured device will have a lower score. This score can be obtained by running benchmark testing software, which compares the performance of the device with standard performance metrics and gives a numerical representation, such as from 1 to 10, where 10 represents the highest computing power.
[0141] The data sensitivity score is rated according to the importance of the data and the security requirements. This usually involves a data classification process, where the data owner or administrator assigns a score based on the confidentiality, integrity, and availability requirements of the data. For example, data containing personal identity information, financial records, or corporate secrets will be given a high sensitivity score, while public news data or advertising content may receive a low sensitivity score. This score can be determined through a preset standard table, in which different types of data sensitivity levels are listed and a score range is specified for each level.
[0142] The comprehensive evaluation of these parameters provides a scientific basis for the selection of encryption strategies. In actual operation, the system will select the most appropriate encryption algorithm and configuration according to these dynamically calculated scores to adapt to specific security requirements and performance limitations. Through this method, the encryption transmission system can not only effectively protect data but also ensure the efficiency of system operation.
[0143] Next, the front - end uses formula (1) to calculate the comprehensive security index :
[0144]
[0145] In this formula, represents the weight coefficient, which determines the influence of each security factor in the total score. is the total number of influencing parameters. The choice of this formula is based on the intention to increase the computational complexity through logarithmic and exponential functions, thereby making a non-linear adjustment to the contribution of each security factor. This can make the score more sensitive to small security changes, thus providing a more refined security level judgment.
[0146] To obtain the final encryption scheme index from the comprehensive security index , formula (2) is adopted:
[0147]
[0148] In this formula, is the adjustment coefficient, which is used to adjust the output of the formula to match the range of available encryption schemes. It can be obtained through experimental data or set according to expert knowledge. is the total number of available encryption schemes. By introducing a combination of cubic, quadratic, and trigonometric functions, this formula further increases the randomness and complexity in the selection of encryption schemes, ensuring that the selection of encryption schemes is not only based on linear security scores but more complex calculation results, thus improving the security of the method. In formula 2, round is a mathematical function used to round the calculated numerical value to the nearest integer. This function is usually used when dealing with calculation results involving real numbers (i.e., floating-point numbers) with the aim of obtaining integer results, which are usually used in contexts such as indexing, counting, or other situations that require integer values.
[0149] Finally, according to the calculated index , the front-end system can select a specific encryption strategy from the preset list of encryption schemes for application. This selection process is automatic, ensuring that the most appropriate encryption method is used for each data transmission, thereby maximizing the security of data transmission.
[0150] Furthermore, the unique names of the encrypted data and encryption schemes are sent to the backend through a secure channel, and the secure channel encrypts all transmitted data using the TLS protocol.
[0151] The TLS protocol is a widely used protocol that provides privacy and data integrity during data transmission. TLS achieves this by performing encryption operations on the data packets transmitted over the network, ensuring that the data cannot be eavesdropped on or tampered with while being transmitted over the Internet. In the present invention, it is crucial to use the TLS protocol to establish a secure channel because it not only protects the content of the transmitted data but also the security of the data transmission process itself.
[0152] To implement this step, the following operations need to be carried out:
[0153] 1. Configure the TLS protocol: Configure the TLS protocol on the front-end and back-end systems, which includes installing valid security certificates and selecting an appropriate TLS version. Certificates are usually issued by a certified certificate authority (CA), which proves the identity of the server and provides the necessary public key information for establishing an encrypted connection.
[0154] 2. Establish a TLS connection: When the front-end needs to send encrypted data and its unique name to the back-end, it first initiates a TLS handshake request. During the TLS handshake process, the front-end and back-end negotiate the encryption algorithm, exchange key information, and finally establish an encrypted connection. This handshake process ensures that both parties have verified each other's identity and agreed on the encryption parameters to be used during the communication process.
[0155] 3. Data encryption and transmission: Once the TLS connection is established, all data sent through this channel will be encrypted. This includes the encrypted request data and the unique name of the encryption scheme. The encryption process is automatic and is implemented by the TLS protocol, ensuring the privacy and integrity of the data during transmission.
[0156] 4. Data reception and decryption: After the back-end receives the data transmitted through the TLS channel, it will automatically decrypt the data. Due to the use of the same TLS protocol, the back-end can correctly parse and recover the original data content, including the encrypted request data and the unique name of the encryption scheme required for subsequent processing.
[0157] Through the above operations, the security of the encrypted data and its related information transmitted between the front-end and back-end is ensured, preventing the leakage and tampering of data during transmission. This security measure is extremely important for protecting sensitive data and maintaining the security of the entire system, making the data encryption transmission method more reliable and effective in practical applications.
[0158] Step S103: After the back-end receives the encrypted request data and the unique name corresponding to the selected encryption scheme, it decrypts using the same encryption scheme as the front-end; processes the decrypted request data, and encrypts the processed result data again using the same encryption scheme as the front-end; and sends the encrypted processed result data back to the front-end.
[0159] In step S103, it is explained how the backend system processes the received encrypted request data. This step involves three key operations: decrypting the received data, processing this data, and re-encrypting the data for transmission back to the front end. The detailed implementation method of this step ensures the security and integrity of the data throughout the transmission process.
[0160] First, when the backend system receives the encrypted data sent from the front end, this data includes the encrypted request content and its corresponding unique encryption scheme name. The backend system first determines which set of encryption schemes was used to encrypt the data based on the received unique name. This information enables the backend to decrypt the data using the same encryption scheme, ensuring the accuracy of the decryption process. The decryption operation requires the backend to have an appropriate decryption key, which corresponds to the key used by the front end to encrypt the data. This process typically involves retrieving the corresponding key from a secure key management system.
[0161] After decryption is completed, the backend will process this data in response to the front end's request. This may include operations such as performing database queries, processing transaction instructions, or verifying user identity information. During the data processing, the backend system must ensure the security of the operations and the accuracy of the data processing logic to avoid generating incorrect results or data leakage.
[0162] The processed data then needs to be encrypted again in order to be securely sent back to the front end. The backend uses the same encryption scheme as the initial encryption to encrypt the data again, ensuring that the front end can restore the data using the corresponding decryption scheme. This re-encryption process also involves the use of secure keys, which should be the same as the keys used during the initial encryption to ensure that the data can be successfully decrypted by the front end.
[0163] Finally, the encrypted data is sent back to the front end. During the sending process, the backend will also record necessary transmission metrics, such as the sending time and the packet size, etc. These metrics are crucial for the front end to verify the data integrity and real-time performance.
[0164] Furthermore, after decrypting the request data, the backend performs an integrity check on the data content, and only processes and re-encrypts it after confirming that there is no tampering.
[0165] Implementing this step first involves the decryption process. Once the data is successfully transmitted to the backend through a secure channel (such as TLS), the backend decrypts the data using the same decryption key and encryption algorithm as the front end. The decryption process needs to ensure the use of the correct key and parameters to restore the original state of the data.
[0166] After decryption is completed, the backend will perform an integrity check. This typically involves the following key operations:
[0167] 1. Checksum or Hash Verification: At the sending end (front - end), a checksum or hash value is usually appended to the data, which is generated before encryption. After decrypting the data, the back - end recalculates the checksum or hash value of the received data and compares it with the transmitted checksum or hash value. If the two match, it indicates that the data has not been changed since encryption and maintains its integrity.
[0168] 2. Digital Signature Verification: If the data is protected using digital signature technology, the back - end will use the sender's public key to verify the validity of the signature. Successful signature verification not only proves the integrity of the data but also verifies the authenticity of the data source.
[0169] 3. Anomaly Detection: The back - end system should also have the ability to detect data anomalies, such as checking whether the data content contains any predefined illogical or security - policy - violating patterns. This detection helps identify and prevent Advanced Persistent Threats (APTs) or internal tampering attempts.
[0170] Once the data passes the integrity check, the back - end can safely process the data, performing necessary business operations such as database updates, transaction processing, etc. After processing, if the data needs to be sent back to the front - end or other systems, the back - end will encrypt the processed result data again using the selected encryption scheme to ensure the security of the data during the return transmission.
[0171] This integrity check and confirmation step is crucial. It not only ensures the security of data processing but also enhances the entire system's defense against data tampering and external attacks.
[0172] Step S104: After receiving the encrypted data, the front - end decrypts the encrypted data and verifies whether the encrypted data meets the time requirements of the recorded relevant transmission metrics and the limiting conditions of the return message.
[0173] Step S104 is a key link to ensure the security of the encrypted data transmission process and data integrity. In this step, the front - end first receives the encrypted data sent back from the back - end. After receiving the data, the front - end uses the same encryption scheme as when sending for decryption, which requires the front - end to maintain the consistency of the encryption scheme and proper key management to ensure successful decryption of the data.
[0174] The decryption process should ensure accuracy so that the data content before sending can be accurately restored. After decryption, the front - end system will perform a series of verifications on the data to ensure that the data has not been tampered with during transmission and meets the preset transmission and security standards. These verifications include, but are not limited to, checking the integrity of the data, verifying whether the sending and receiving times of the data meet the set time window, and confirming whether the size and format of the data packet meet the predetermined parameters.
[0175] Specifically, the front end will evaluate the transmission time of the encrypted data to ensure that it arrives within an acceptable time range, which is particularly important for preventing and identifying latency attacks. The front end will also check whether the structure and length of the data are the same as before sending to rule out the possibility of data being truncated or additional content being added during transmission. The execution of this step requires the front-end system to access the relevant transmission metrics recorded during sending, such as the specific time of data sending and the specific requirements of data packets, which should be properly recorded in step S102 and used for verification here.
[0176] During implementation, the front end may use automated scripts or software tools to handle these verification tasks. These tools will automatically check various metrics of the data according to preset rules and parameters and generate verification results. If it is found during verification that the data does not meet the preset conditions, such as decryption failure, abnormal data latency, or data format and length not meeting the requirements, the front end should record these abnormal situations and handle them according to the set process. Possible handling measures may include feedback to the back end for investigation and problem-solving, or stopping the current data processing operation to protect system security.
[0177] In step S104, after the front-end system receives the encrypted data sent by the back end, it must perform a series of verifications on this data to ensure that it meets the predetermined transmission metrics and the restrictive conditions of the return message. These verification operations are to ensure the security and integrity of the data during transmission and prevent the data from being tampered with or misused. The following are some specific verification examples showing how to check whether the encrypted data meets these standards.
[0178] First, considering the response time limit, the front-end system will check whether the time from sending to receiving the data packet conforms to the preset time frame. For example, if a rule is set that all return data must arrive at the front end within 5 seconds, the system will compare the send and receive timestamps of the data packet to ensure that there is no timeout. If it is found that the data packet is delayed beyond this threshold, the system may reject the data packet or mark it as suspicious because such a delay may imply network problems or potential replay attacks.
[0179] Next, the front end will also perform data integrity verification to ensure that the returned data packet contains a valid checksum or digital signature. This step involves using the public key held by the front end to verify the signature in the data packet to confirm that the data has not been tampered with during transmission. If the signature verification fails, it indicates that the data may have been modified during transmission, so this data must be further reviewed or directly rejected.
[0180] In addition, the front-end system will also verify whether the size of the returned data packet meets the predetermined limit. For example, if the system stipulates that the size of the returned data packet shall not exceed 1MB, the system will check whether the actual size of the data packet exceeds this limit. Such checks help prevent denial-of-service attacks or buffer overflow attacks that attempt to exhaust system resources by sending large amounts of data.
[0181] Finally, the front-end will check whether the content of the returned data complies with the content security policy. This includes verifying whether the data contains unauthorized code or scripts, and whether the data is loaded only from trusted sources. These checks help prevent cross-site scripting attacks or other types of malicious content injection, ensuring the security of data processing in the system.
[0182] Through these meticulous checking steps, the front-end system can effectively evaluate the security status of the returned data, ensure the integrity and compliance of the data, thereby protecting the entire data transmission process from various potential threats. These operations not only enhance the security of the system but also improve the reliability of data processing.
[0183] Furthermore, after decrypting the encrypted data, the front-end verifies whether the data is received within a predetermined time window. If it exceeds the time window, the data is considered to have an abnormal delay.
[0184] This process is to ensure the timeliness of data transmission and prevent potential replay attacks, where delayed received data may indicate network problems or signs of malicious tampering.
[0185] Implementing this step requires the front-end system to have accurate time tracking and data reception verification capabilities. This can be achieved in detail through the following steps:
[0186] 1. Set the time window: Before the data transmission starts, the system needs to define a clear time window, which refers to the maximum allowed time from when the data is sent until it should be received. For example, for a financial transaction, a time window of 30 seconds may be set for the data to be received.
[0187] 2. Record the sending time: Before the front-end sends the encrypted data, the exact timestamp of the data sending must be recorded. This timestamp should be encrypted along with the data and sent to the back-end to ensure the security and immutability of the timestamp throughout the transmission process.
[0188] 3. Decrypt and verify the timestamp: When the data arrives at the front-end and is decrypted, the system will extract the timestamp from it and compare it with the current time. This comparison operation determines whether the received data is within the predetermined time window.
[0189] 4. Handling Data Delay Exceptions: If the reception time of the data exceeds the set time window, the front-end system should identify this situation as a data delay exception. The system needs to have a clear set of response measures to handle such exceptions, such as immediately issuing an alarm, rejecting data processing, or conducting further security checks.
[0190] 5. Recording and Reporting: All time window verification results and any exception situations should be detailedly recorded for subsequent security analysis and auditing. These records are very important for identifying potential security threats and improving future security policies.
[0191] Through these steps, the front-end system can effectively verify whether the data is received within a secure time range, thereby preventing the data from being tampered with due to network latency or suffering other forms of attacks. This time window verification mechanism enhances the security of the data transmission process and ensures the timeliness and integrity of the data.
[0192] Step S105: If an exception is found during data decryption or metric calculation, the front-end will record the exception and feedback it to the back-end, and stop the current data processing; wherein, the exception includes decryption failure, data delay exception, data format and length mismatch.
[0193] Step S105 details how the front-end processes and responds to any exception situations found during data transmission. This step is crucial because it not only ensures the correctness and integrity of the data, but also enhances the system's ability to respond to potential security threats.
[0194] After the front-end receives and decrypts the encrypted data from the back-end, a series of checks will be performed to ensure that the data meets the expected security standards and operating specifications. This includes checking whether the data is successfully transmitted within the specified time (such as the response time check described in step S104 above), the integrity and format of the data packet are correct. These checks are performed based on the transmission metrics recorded in step S102 and the security standards set by the system.
[0195] If it is found that the data decryption fails at this stage, that is, the ciphertext fails to be correctly converted into the original plaintext, or the data shows abnormal delay during the verification process, it may indicate that the data has been intercepted or tampered with during transmission. Similarly, if it is detected that the data format and length do not match the records before sending, this may indicate that the data has been modified or truncated without authorization during transmission.
[0196] Once the front - end system identifies these anomalies, it will immediately perform the operation of recording the anomalies. This involves detailed recording of the nature of the anomalies, the time of occurrence, and the scope of data that may be affected for subsequent analysis. In addition, the front - end will feedback these anomaly situations to the back - end system through a secure channel. This communication is encrypted to ensure that any information about security vulnerabilities will not be leaked or exploited by third parties during transmission.
[0197] After reporting the anomalies, the front - end system usually stops the current data - processing operations. This is a preventive measure aimed at preventing potential data leakage or broader system impacts until the security and integrity of the data are confirmed. This operating mode ensures that no further data operations are carried out without a full understanding of the situation, thus protecting user and system security.
[0198] Furthermore, when the front - end discovers an anomaly, it also generates a security event log, which includes:
[0199] The type and severity of the anomaly;
[0200] A snapshot of the system state when the anomaly occurred;
[0201] The relevant network traffic characteristics.
[0202] This log not only records the details of the anomalies but also provides sufficient context information so that technicians can thoroughly analyze and respond to these security events.
[0203] When the front - end system discovers any anomalies during data encryption, transmission, or decryption, the system will automatically trigger a logging mechanism. The role of this mechanism is to capture and store various information about the anomalies, specifically including:
[0204] 1. The type and severity of the anomaly: The system first identifies the type of the anomaly, such as whether it is a decryption failure, data latency, data tampering, etc. Each type of anomaly is assigned a predefined severity level, which helps with subsequent processing and priority assignment. The severity may be evaluated based on the potential impact of the anomaly on system operation or data security. For example, the severity of data leakage will be higher than that of general performance anomalies.
[0205] 2. A snapshot of the system state when the anomaly occurred: To better understand the context in which the anomaly occurred, the system will automatically capture a snapshot of the system state when the anomaly occurred. This includes but is not limited to CPU usage, memory usage, the list of currently active processes, and system logs. This information provides the necessary background for analyzing the anomaly and helps technicians determine the specific working state and load of the system when the anomaly occurred.
[0206] 3. Related network traffic characteristics: In addition, the logs will also include network traffic characteristics related to anomalies. This may involve packet sizes, transmission frequencies, source and destination IP addresses, port information, and possibly transmission protocols before and after the anomaly occurs. This information is of great value for identifying whether network attacks such as DDoS attacks, network eavesdropping, or data interception have occurred.
[0207] All this information will be automatically collected by the system and stored in the security event log, which needs to be maintained in a secure and isolated storage location to prevent unauthorized access or tampering. In addition, the log files should be stored encrypted to ensure that the log content is protected even in the event of a data breach.
[0208] Authorized security analysts will have access to these logs for detailed security analysis and troubleshooting. Log analysis may involve finding the cause of the anomaly, assessing the scope of the impact, and formulating targeted solutions. An effective log management and analysis mechanism is the key to improving data transmission security and quickly responding to security events.
[0209] By implementing the above detailed steps, it is ensured that when an anomaly is detected at the front end, a security event log containing rich information can be generated. This not only enhances the system's monitoring ability but also greatly improves the response efficiency to security threats, ensuring the security of the entire data encryption transmission process.
[0210] Furthermore, when the front end discovers an anomaly, it adjusts the local security policy according to the severity of the anomaly, and the local security policy includes increasing authentication requirements or restricting the use of specified functions.
[0211] These measures not only involve generating detailed security event logs but also include adjusting the local security policy according to the nature and severity of the anomaly. This dynamic security management method can significantly enhance the system's adaptability and defense capabilities, ensuring that the system can take appropriate protection measures when facing potential security threats.
[0212] Implementation steps for adjusting the local security policy:
[0213] 1. Evaluate the severity of the anomaly:
[0214] When the front-end system detects a security anomaly, it first needs to evaluate the severity of the anomaly. This evaluation is based on the type of anomaly (such as data tampering, unauthorized access, excessive use of system resources, etc.), the degree of damage that may be caused to the system or data, and the impact on user services. For example, a high-severity anomaly may be data leakage, while a low-severity anomaly may only be a decrease in system performance.
[0215] 2. Adjust authentication requirements:
[0216] For anomalies evaluated as having a high severity level, the front-end system can increase the requirements for user authentication. This may include enabling multi-factor authentication, requiring users to re-login, or using a more complex password policy. For example, if a possible account hijacking or an abnormal login attempt is detected, the system can require all users to perform secondary verification or temporarily lock the affected account until the user's identity is confirmed.
[0217] 3. Restrict the use of functions:
[0218] Another adjustment strategy is to restrict or temporarily disable certain system functions. This is usually used to prevent abnormal behavior from causing a more extensive impact on the system. For example, if it is detected that a service module is infected with malware or under attack, the system may temporarily disable the operation of that module to prevent the problem from spreading to other parts of the system. Function restrictions can also be to reduce the operating permissions of the system, limit the ability to access and modify files, or reduce the responsiveness of network services to avoid overconsumption of resources.
[0219] Implementing these security policy adjustments requires the front-end system to have a high degree of configuration flexibility and a rapid response mechanism. The system should be able to quickly change security settings according to predefined rules or the instructions of the administrator and promptly notify all users of the changes in the security policy.
[0220] Step S106: After receiving the anomaly feedback from the front-end, the back-end takes security measures to address potential data security threats.
[0221] Step S106 includes the security measures taken by the back-end after receiving the anomaly feedback from the front-end to effectively address possible data security threats. This step ensures that the entire data transmission system can not only identify potential security issues but also respond quickly to prevent the problems from expanding and protect the system security.
[0222] When implementing this step, first of all, the back-end system must be set up to be able to receive and correctly parse the anomaly reports sent by the front-end. This includes parsing the detailed information of the anomaly from the encrypted messages received from the front-end, such as the type of anomaly (decryption failure, data latency, data format and length issues, etc.), the time when the anomaly occurred, and any data information that may be affected. The back-end system should have the function of automatically identifying and classifying various anomalies in order to determine the corresponding response measures.
[0223] Next, according to the type of anomaly received, the back-end needs to quickly decide on the security measures to take. These measures may include, but are not limited to:
[0224] 1. Immediately isolate the affected data: To prevent the spread of potential security threats, the back-end may need to immediately isolate the affected data to prevent it from being further processed or accessed.
[0225] 2. Review and strengthen security protocols: The backend may need to review the current security protocols to check for any vulnerabilities or weaknesses, especially those related parts that may have caused the current anomaly. Additionally, strengthening security measures such as updating encryption algorithms or adjusting security settings is also a necessary response.
[0226] 3. Initiate backup systems or recovery plans: In case of severe security incidents, the backend may need to start backup systems or execute data recovery plans to ensure business continuity and data integrity.
[0227] 4. Notify relevant personnel and departments: Ensure that all relevant security personnel and management are informed of the anomaly so that further actions can be taken. This may include the technical support team, security analysis team, and senior management.
[0228] 5. Record and analyze the incident: Record in detail all information related to the anomaly and subsequent handling measures, and conduct post - incident analysis to draw lessons and improve future security strategies and response processes.
[0229] All these measures require the backend system to have a high degree of flexibility and rapid response capabilities. The system should be designed to automatically handle common security incidents, while also allowing operators to intervene manually for more complex or severe situations. Additionally, the entire process should ensure the transparency and traceability of all operations for auditing and compliance assessment when needed.
[0230] Furthermore, after receiving the anomaly feedback from the front - end, the backend performs the following steps:
[0231] Compare the received anomaly information with the global security intelligence database in real - time;
[0232] Based on the comparison results, use a pre - trained security expert system to evaluate the threat level;
[0233] According to the evaluated threat level, automatically generate and execute security response measures, where the security response measures include:
[0234] Dynamically adjust network firewall rules;
[0235] Initiate a deep packet inspection process;
[0236] Isolate suspicious network segments or devices.
[0237] When the backend system receives the anomaly feedback sent from the front - end, it first compares this anomaly information with a global security intelligence database in real - time. The global security intelligence database stores a wide range of security threat data, including known malware signatures, IP address blacklists, abnormal behavior patterns, etc. This database is frequently updated to include the latest threat intelligence.
[0238] During the comparison process, the backend system uses an efficient matching algorithm to check whether the received abnormal information matches the known threat patterns in the database. This may include checking whether the IP address in the abnormal data appears in the blacklist, or whether the abnormal behavior conforms to the known attack patterns.
[0239] If a match is found in the global security intelligence database, the backend system will use a pre-trained security expert system to evaluate the level of the threat. The security expert system is an artificial intelligence-based analysis tool that can accurately evaluate the current threat by analyzing historical data and learning the impacts of different security events. The system may classify threats into three levels: low, medium, and high, and each level corresponds to a set of predefined response measures.
[0240] The pre-trained security expert system is an advanced artificial intelligence application that plays an increasingly important role in the security field. The system uses machine learning and artificial intelligence technologies and is trained with a large amount of historical security data, enabling it to effectively identify and evaluate complex security threats.
[0241] The core of the security expert system is one or more machine learning models that are "fed" with a large amount of security event data during the training phase. This data includes, but is not limited to, logs of network attacks, known malware behavior patterns, system vulnerability reports, and the consequences of security incidents. Through in-depth analysis of this data, the models learn which behavior patterns and metrics are most likely to indicate the presence of a security threat and the potential severity of these threats.
[0242] During the training process, various statistical and machine learning techniques, such as decision trees, neural networks, or ensemble learning methods, are used to optimize the prediction accuracy of the models. After the model training is completed, it can automatically analyze and rate new security events without manual intervention.
[0243] When the backend system finds a match in the global security intelligence database related to the current event, the security expert system is called to evaluate the potential threat level of the event. This evaluation process generally involves the following steps:
[0244] 1. Feature extraction: Extract key features from the received event data. These features are determined during the training phase and may include the type of event, occurrence frequency, system components involved, complexity of the attack, etc.
[0245] 2. Threat rating: Use the pre-trained model to analyze the extracted features, and the model will output a threat level. This level is usually based on the potential destructiveness and urgency of the event and is divided into several levels such as low, medium, and high.
[0246] 3. Response Suggestions: Based on the threat level, the system may also provide corresponding security response suggestions, which are designed to quickly and effectively mitigate or defend against possible security threats.
[0247] After the security expert system is deployed, its database needs to be updated regularly and the model needs to be retrained to include the latest threat intelligence and security technologies. This process ensures that the system's assessment capabilities can keep up with the rapidly changing security environment.
[0248] In addition, the performance and accuracy of the system need to be continuously monitored and evaluated to ensure that the expected effects are achieved in actual applications. By collecting data during the usage process through a feedback mechanism, the model can be further optimized and adjusted.
[0249] In this way, the pre-trained security expert system provides a powerful tool for network security management, capable of automatically processing and responding to security incidents, and significantly improving the efficiency and effectiveness of the security team.
[0250] According to the threat level evaluated by the security expert system, the backend system will automatically trigger corresponding security response measures. These measures include but are not limited to:
[0251] Dynamically adjust network firewall rules: The system may adjust firewall rules according to the nature and source of the threat to block attacks or limit attack traffic. For example, if a DDoS attack from a specific IP address is detected, the system can automatically update the firewall configuration to block all traffic from that address.
[0252] Initiate a deep packet inspection process: For medium to high-level threats, the system may initiate a deep packet inspection process to conduct a more in-depth analysis of network traffic. This process helps identify and block complex network attacks such as zero-day attacks and advanced persistent threats (APTs).
[0253] Isolate suspicious network segments or devices: In the case where a network segment or device is confirmed to be infected or controlled by malware, the system can automatically isolate these parts to prevent the threat from spreading to other parts of the network.
[0254] Through these detailed steps, the backend system can not only quickly respond to the anomalies discovered by the front end, but also automatically take effective security measures based on global security intelligence and advanced threat assessment technologies. This highly automated security response mechanism greatly improves the security and response capabilities of the entire data transmission system, enabling the system to resist various complex security threats.
[0255] In the above embodiments, a data encryption transmission method with an early warning mechanism is provided. Correspondingly, the present application also provides a data encryption transmission device with an early warning mechanism. Please refer to Figure 2, which is a schematic diagram of an embodiment of a data encryption transmission device with a warning mechanism according to the present application. Since this embodiment, that is, the second embodiment, is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment. The following-described embodiments are merely illustrative.
[0256] The second embodiment of the present application provides a data encryption transmission device with a warning mechanism, including:
[0257] A data storage unit 201, configured to pre-store multiple sets of encryption schemes with unique names at the front end and the back end of the data transmission system, where the unique names are only known inside the system;
[0258] An encryption selection unit 202, configured to randomly select a set of encryption schemes based on security requirements, and before sending the request data, encrypt the request data using the selected encryption scheme to generate encrypted request data, where the request data includes user authentication information, transaction instructions, and query requests;
[0259] A transmission control unit 203, configured to send the encrypted request data and the unique name corresponding to the selected encryption scheme to the back end, and record the unique name corresponding to the selected encryption scheme and related transmission metrics, where the related transmission metrics include the sending time and the restriction conditions for the returned message;
[0260] A receiving and processing unit 204, configured to receive the encrypted request data and the unique name corresponding to the selected encryption scheme at the back end, decrypt the encrypted request data using the same encryption scheme as the front end, process the decrypted request data, and encrypt the processed result data again using the same encryption scheme as the front end, and send the encrypted processed result data back to the front end;
[0261] A decryption verification unit 205, configured to decrypt the encryption after receiving the encrypted data at the front end, and verify whether the encrypted data meets the time requirements of the recorded related transmission metrics and the restriction conditions for the returned message;
[0262] An exception handling unit 206, configured to record the exception and feedback the exception to the back end when an exception is found during data decryption or metric calculation, and stop the current data processing, where the exception includes decryption failure, data delay exception, data format and length mismatch;
[0263] A security response unit 207, configured to take security measures to deal with potential data security threats after the back end receives the exception feedback from the front end.
[0264] The third embodiment of the present application provides an electronic device, and the electronic device includes:
[0265] Processor;
[0266] A memory for storing a program which, when read and executed by the processor, executes the data encryption transmission method with a warning mechanism provided in the first embodiment of the present application.
[0267] The fourth embodiment of the present application provides a computer-readable storage medium with a computer program stored thereon, which, when executed by a processor, executes the data encryption transmission method with a warning mechanism provided in the first embodiment of the present application.
[0268] Although the present application is disclosed above in preferred embodiments, it is not intended to limit the present application. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be defined by the scope defined in the claims of the present application.
Claims
1. A data encryption transmission method with an early warning mechanism, characterized in that: include: Preset and store multiple sets of encryption schemes with unique names at the front end and back end of the data transmission system, wherein the unique names are only known within the system; The front end randomly selects a set of encryption schemes based on security requirements, and uses the selected encryption scheme to encrypt the request data before sending it to generate encrypted request data; the encrypted request data and the unique name corresponding to the selected encryption scheme are sent to the back end; the unique name corresponding to the selected encryption scheme and related transmission indicators are recorded; wherein the request data includes user identity authentication information, transaction instructions and query requests; the related transmission indicators include sending time and restrictions on return messages; After receiving the encrypted request data and the unique name corresponding to the selected encryption scheme, the backend uses the same encryption scheme as the frontend to decrypt the data; processes the decrypted request data, and encrypts the processing result data again using the same encryption scheme as the frontend; and sends the encrypted processing result data back to the frontend; After receiving the encrypted data, the front end decrypts the encrypted data and verifies whether the encrypted data meets the time requirements of the relevant transmission indicators recorded and the restriction conditions of the returned message; If an abnormality is found during data decryption or index calculation, the front end will record the abnormality and feedback the abnormality to the back end, and stop the current data processing; wherein the abnormality includes decryption failure, data delay abnormality, data format and length inconsistency; After receiving abnormal feedback from the front end, the back end takes security measures to deal with potential data security threats.
2. The data encryption transmission method according to claim 1, characterized in that: The multiple encryption schemes include at least one symmetric encryption algorithm and at least one asymmetric encryption algorithm, and each algorithm has independent naming and configuration parameters.
3. The data encryption transmission method according to claim 1, characterized in that: The front end randomly selects a set of encryption schemes based on security requirements, including: Define a safety factor set , where each safety factor Representative Influencing parameters that affect the selection of encryption schemes, including the security level of the current network environment, the computing power of the user's device, and the data sensitivity score; According to the following formula (1), the comprehensive safety index is calculated : in, is the weight coefficient; Indicates the number of influencing parameters; According to the following formula (2), the index of the encryption scheme is obtained : in, is the adjustment coefficient; is the total number of encryption schemes; According to the index , determine the encryption scheme you choose.
4. The data encryption transmission method according to claim 1, characterized in that: The encrypted data and the unique name of the encryption scheme are sent to the backend via a secure channel, and the secure channel uses the TLS protocol to encrypt all transmitted data.
5. The data encryption transmission method according to claim 1, characterized in that: After decrypting the request data, the backend performs an integrity check on the data content and processes and re-encrypts it after confirming that it has not been tampered with.
6. The data encryption transmission method according to claim 1, characterized in that: After decrypting the encrypted data, the front end verifies whether the data is received within the predetermined time window. If the time window is exceeded, it is considered as data delay abnormality.
7. The data encryption transmission method according to claim 1, characterized in that: When the front end finds an abnormality, it also generates a security event log, which includes: type and severity of abnormality; A snapshot of the system status when an anomaly occurs; Related network traffic characteristics.
8. The data encryption transmission method according to claim 7, characterized in that: When the front end finds an exception, it adjusts the local security policy according to the severity of the exception. The local security policy includes increasing the authentication requirements or limiting the use of specified functions.
9. The data encryption transmission method according to claim 1, characterized in that: After receiving the abnormal feedback from the front end, the back end performs the following steps: Compare the received abnormal information with the global security intelligence database in real time; Based on the comparison results, the threat level is assessed using a pre-trained security expert system; Automatically generate and execute security response measures based on the assessed threat level, where the security response measures include: Dynamically adjust network firewall rules; Start the deep packet inspection process; Isolate suspicious network segments or devices.
10. A data encryption transmission device with an early warning mechanism, characterized in that: include: A data storage unit configured to pre-store multiple sets of encryption schemes with unique names at the front end and the back end of the data transmission system, wherein the unique names are only known within the system; an encryption selection unit, configured to randomly select a set of encryption schemes based on security requirements, and to encrypt the request data using the selected encryption scheme before sending the request data to generate encrypted request data, wherein the request data includes user identity authentication information, transaction instructions, and query requests; A transmission control unit configured to send the encrypted request data and the unique name corresponding to the selected encryption scheme to the back end, and record the unique name corresponding to the selected encryption scheme and related transmission indicators, wherein the related transmission indicators include the sending time and the restriction conditions on the return message; A receiving processing unit, configured to receive the encrypted request data and the unique name corresponding to the selected encryption scheme at the back end, decrypt the data using the same encryption scheme as the front end, process the decrypted request data, encrypt the processing result data again using the same encryption scheme as the front end, and send the encrypted processing result data back to the front end; A decryption verification unit, configured to decrypt the encrypted data after receiving the encrypted data at the front end, and verify whether the encrypted data meets the time requirements of the relevant transmission indicators recorded and the restriction conditions of the returned message; An exception handling unit is configured to record an exception and feed it back to the backend when an exception is found during data decryption or index calculation, and stop current data processing, wherein the exception includes decryption failure, data delay exception, and data format and length inconsistency; The security response unit is configured to take security measures to deal with potential data security threats after receiving abnormal feedback from the front end at the back end.
Citation Information
Patent Citations
System for the identification and prevention of Advanced Persistent Threats (APT) using big data analysis
DE202024106159U1
Protection of cloud storage devices from anomalous encryption operations
US20240205249A1