An Encryption Method and System for SATA-PCIe Mixed Insertion Data Based on the Pisces Algorithm
Through the encryption method based on Pisces algorithm, key parameters of interface interaction of mixed data are collected and analyzed, timing calibration and data grading are performed, cryptographic elliptic curve base point operation and high-dimensional structure initial encryption, combined with quantum random and asymmetric encryption, the problems of inefficient and insufficient security of mixed data encryption in the existing technology are solved, and efficient and secure data transmission and storage are achieved.
Patent Information
- Application Number
- CN202510287902.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-12
AI Technical Summary
The prior art has problems of inefficient encryption efficiency and insufficient security when processing SATA and PCIe data interpolation, especially when facing large-scale and high-frequency data transmission, key management is chaotic and encryption and decryption processes are delayed.
Using the encryption method based on Pisces algorithm, by collecting and analyzing the interface interaction key parameters of mixed data, a data buffering strategy is constructed and time-series calibration is performed, word frequency-inverse document frequency is calculated for initial diversion, link channel characteristics are identified and data priority is divided, high-priority key seeds are configured for encrypted elliptic curve base point operation, initial encryption is combined with high-dimensional structure, and the data is subjected to quantum random encryption and asymmetric encryption.
Improve the data security of SATA-PCIe hybrid data, ensures the confidentiality and integrity of data during transmission and storage, reduces the complexity of key management and encryption and decryption delay, and improves system performance and reliability.
Smart Images

Figure CN119788441B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an encryption method and system for SATA-PCIe mixed-insertion data based on the Pisces algorithm, belonging to the technical field of data encryption. Background Art
[0002] In the current era of rapid development of digital information, the security of data storage and transmission has become the focus of attention in various fields. With the wide application of computer technology, SATA (Serial ATA) and PCIe (Peripheral Component Interconnect Express) interfaces are widely used in various devices, such as servers, storage arrays, and high-performance computing systems, etc., to meet different data transmission requirements. In the process of data processing, the situation of SATA and PCIe mixed-insertion data is often faced. These data cover a large number of sensitive information, including enterprise business secrets, personal privacy data, and key business data, etc. The security protection of these data is crucial. Once data leakage occurs, it may lead to serious economic losses, privacy violations, and business interruptions, etc.
[0003] Currently, traditional data encryption methods have many limitations when dealing with SATA-PCIe mixed-insertion data. Some conventional encryption technologies are only designed for single-type interface data or specific data formats, lacking the effective ability to cope with the diversity and complexity of the two interface mixed-insertion data. For example, some encryption algorithms cannot flexibly adjust the encryption strategy when dealing with data with different transmission rates and protocols, resulting in low encryption efficiency or poor encryption effect. Moreover, the existing encryption systems often rely on fixed key generation and management mechanisms, and it is difficult to adapt to complex and changeable security environments and data characteristics. When facing large-scale and high-frequency SATA-PCIe mixed-insertion data, traditional encryption methods are prone to problems such as chaotic key management, delays in the encryption and decryption processes, etc., resulting in insufficient data security. Summary of the Invention
[0004] In order to solve the above problems, the present invention provides an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm, which can improve the data security of SATA-PCIe mixed-insertion data.
[0005] To achieve the above object, an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm provided by the present invention includes:
[0006] Collect the mixed insertion data of the SATA interface and the PCIe interface, analyze the key parameter characteristics of the interface interaction key parameters of the mixed insertion data, based on the key parameter characteristics, construct the data buffering strategy of the mixed insertion data, based on the data buffering strategy, perform data buffering on the mixed insertion data to obtain buffered data, construct the atomic energy level transition benchmark of the buffered data, and use the atomic energy level transition benchmark to perform timing calibration on the buffered data to obtain calibrated data;
[0007] Calculate the term frequency-inverse document frequency of the calibrated data, based on the term frequency-inverse document frequency, perform preliminary shunting on the calibrated data to obtain preliminary shunted data, identify the link channel characteristics of the calibrated data, and based on the link channel characteristics, perform priority division on the preliminary shunted data to obtain high-priority data and low-priority data;
[0008] Use the preset security mapping rule to configure the high-priority key seed of the high-priority data, query the encryption level requirement of the high-priority data to construct the encryption elliptic curve of the high-priority data, perform base point operation in the encryption elliptic curve using the high-priority key seed to obtain the encryption key, construct the high-dimensional lattice structure of the high-priority data, and use the high-dimensional lattice structure and the encryption key to perform initial encryption on the high-priority data to obtain the initially encrypted data;
[0009] Perform data core division on the initially encrypted data to obtain first-level encrypted data and second-level encrypted data, construct the quantum random number of the first-level encrypted data, based on the quantum random number, perform quantum random encryption on the first-level encrypted data to obtain quantum random encrypted data, identify the digital certificate and identity identifier of the metadata corresponding to the second-level encrypted data, and based on the digital certificate and the identity identifier, perform asymmetric encryption on the second-level encrypted data to obtain asymmetric encrypted data, and use the quantum random encrypted data and the asymmetric encrypted data as high-priority encrypted data;
[0010] Perform simplified dual-track encryption on the low-priority data to obtain dual-track encrypted data, and perform hierarchical storage on the high-priority encrypted data and the dual-track encrypted data to obtain the target encrypted data.
[0011] Optionally, the analyzing the key parameter characteristics of the interface interaction key parameters of the mixed insertion data includes:
[0012] Extract the electrical signals of the mixed insertion data;
[0013] Query the clock signal period, level start-end time, level rising edge start-end voltage, and level falling edge start-end voltage of the electrical signals;
[0014] Analyze the clock signal frequency of the electrical signal based on the clock signal period;
[0015] Analyze the level conversion frequency of the electrical signal based on the level start - end time;
[0016] Analyze the electrical rising edge slope of the electrical signal based on the start - end voltage of the level rising edge;
[0017] Analyze the electrical falling edge slope of the electrical signal based on the start - end voltage of the level falling edge;
[0018] Determine the key parameter characteristics of the interface interaction key parameters corresponding to the mixed - inserted data based on the clock signal frequency, the level conversion frequency, the electrical rising edge slope, and the electrical falling edge slope.
[0019] Optionally, constructing the data buffering strategy for the mixed - inserted data based on the key parameter characteristics includes:
[0020] Analyze the traffic peak and data unit size of the mixed - inserted data based on the key parameter characteristics;
[0021] Construct the buffer interval for the mixed - inserted data based on the traffic peak and the data unit size;
[0022] Calculate the timing weight and priority weight of the mixed - inserted data;
[0023] Construct the data storage scheme for the mixed - inserted data based on the timing weight and priority weight;
[0024] Formulate the data reading and writing rules for the mixed - inserted data based on the storage rules corresponding to the data storage scheme;
[0025] Construct the data buffering strategy for the mixed - inserted data based on the buffer interval, the data storage scheme, and the data reading and writing rules.
[0026] Optionally, calculating the term frequency - inverse document frequency of the calibration data includes:
[0027] Construct the data text of the calibration data;
[0028] Perform document classification on the data text to obtain classified documents;
[0029] Calculate the term frequency - inverse document frequency of the classified documents using the following formula:
[0030] P=n_(w,d) / (∑_k n_(k,d) )×logN / n_w ;
[0031] Among them, P represents the term frequency - inverse document frequency, n_(w,d) represents the number of times the word w appears in the document d, N represents the number of classified documents, n_w represents the number of times the word w appears in all classified documents, k represents the index variable, and ∑_k n_(k,d) represents the sum of the number of times all words appear in the document d.
[0032] Optionally, the initial encryption of the high - priority data using the high - dimensional lattice structure and the encryption key to obtain the initial encrypted data includes:
[0033] Convert the encryption key into a binary sequence;
[0034] Perform unit segmentation on the binary sequence to obtain encrypted segmentation units;
[0035] Convert the basis vectors of the high - dimensional lattice structure into a basis vector matrix;
[0036] Perform a linear transformation on the basis vector matrix using vector subtraction to obtain a target basis vector matrix;
[0037] Map the encrypted segmentation units into the target basis vector matrix to obtain encrypted vectors;
[0038] Perform data conversion on the encrypted vectors to obtain the initial encrypted data.
[0039] Optionally, the data core division of the initial encrypted data to obtain first - level encrypted data and second - level encrypted data includes:
[0040] After performing data scanning on the initial encrypted data using a pre - configured sensitivity label, perform sensitivity marking on the initial encrypted data to obtain sensitivity - marked data;
[0041] Query the data flow direction of the sensitivity - marked data, based on the data flow direction;
[0042] Analyze the data usage of the sensitivity - marked data;
[0043] Based on the data usage, set access permissions for the initial encrypted data to obtain set permissions;
[0044] Based on the set permissions, perform data core division on the initial encrypted data to obtain first - level encrypted data and second - level encrypted data.
[0045] Optionally, the quantum random encryption of the first - level encrypted data based on the quantum random number to obtain quantum - randomly encrypted data includes:
[0046] Construct a random sequence number set of the quantum random number, where the sequence number set can be represented in the following form:
[0047] R = {r_1, r_2, ⋯, r_n}, where r_i ∈ {0, 1};
[0048] Among them, R represents the set of sequence numbers, r_1 represents the first random sequence number in the random sequence number set, r_2 represents the second random sequence number in the random sequence number set, r_n represents the nth random sequence number in the random sequence number set, and r_i represents the ith sequence number in the random sequence number set;
[0049] Construct the encrypted sequence number set of the first-level encrypted data, where the encrypted sequence number set can be represented in the following form:
[0050] D = {d_1, d_2, ⋯, d_n}, where d_i ∈ {0, 1};
[0051] Among them, D represents the encrypted sequence number set, d_1 represents the first random sequence number in the encrypted sequence number set, d_2 represents the second random sequence number in the encrypted sequence number set, d_n represents the nth random sequence number in the encrypted sequence number set, and d_i represents the ith sequence number in the encrypted sequence number set;
[0052] Use the following formula to perform quantum transposition operation on the random sequence number set and the encrypted sequence number set to obtain the encrypted data bit:
[0053] e_i = d_i ⊕ r_i;
[0054] Among them, e_i represents the encrypted data bit, d_i represents the ith sequence number in the encrypted sequence number set, r_i represents the ith sequence number in the random sequence number set, and ⊕ represents the quantum transposition operation;
[0055] Based on the encrypted data bit, perform data encryption on the first-level encrypted data to obtain quantum random encrypted data.
[0056] Optionally, the asymmetric encryption of the second-level encrypted data based on the digital certificate and the identity identifier to obtain the asymmetric encrypted data includes:
[0057] Obtain the encryption public key of the level encrypted data according to the digital certificate and the identity identifier;
[0058] Construct the modulus of the second-level encrypted data;
[0059] Calculate the relatively prime number of the modulus;
[0060] Use the relatively prime number to construct the public key exponent of the second-level encrypted data;
[0061] Based on the public key exponent, determine the private key exponent of the second-level encrypted data;
[0062] Based on the public key exponent, use the following formula to encrypt the secondary encrypted data to obtain initial asymmetric encrypted data:
[0063] C = M^e mod n;
[0064] Where C represents the initial asymmetric encrypted data, M represents the byte sequence corresponding to the secondary encrypted data, e represents the public key exponent, and n represents the modulus;
[0065] Based on the private key exponent, use the following formula to decrypt the initial asymmetric encrypted data to obtain decrypted data:
[0066] E = C^d mod n;
[0067] Where E represents the decrypted data, C represents the initial asymmetric encrypted data, d represents the private key exponent, and n represents the modulus;
[0068] Perform data consistency verification on the secondary encrypted data and the decrypted data. If the result of the data consistency verification is consistent, use the initial asymmetric encrypted data as the asymmetric encrypted data of the secondary encrypted data.
[0069] Optionally, the simplifying double-track encryption of the low-priority data to obtain double-track encrypted data includes:
[0070] Perform binary conversion on the low-priority data to obtain binary data;
[0071] Perform data grouping on the binary data to obtain grouped data;
[0072] Construct an encrypted pseudo-random number for the grouped data;
[0073] Use the encrypted pseudo-random number to perform XOR operation on the grouped data to obtain the first-track encrypted data;
[0074] Configure the pseudo-random encryption seed for the grouped data;
[0075] Perform element permutation on the grouped data to obtain element permutation data;
[0076] Use the pseudo-random encryption seed to perform element substitution on the element permutation data to obtain the second-track encrypted data;
[0077] Perform alternating splicing on the first-track encrypted data and the second-track encrypted data to obtain double-track encrypted data.
[0078] In a second aspect, the present invention provides an encryption system for SATA-PCIe mixed-insertion data based on the double fish algorithm. The system includes:
[0079] A data calibration module, which is used to collect the mixed insertion data of the SATA interface and the PCIe interface, analyze the key parameter features of the interface interaction key parameters of the mixed insertion data, construct a data buffering strategy for the mixed insertion data based on the key parameter features, buffer the mixed insertion data based on the data buffering strategy to obtain buffered data, construct an atomic energy level transition benchmark for the buffered data, and use the atomic energy level transition benchmark to perform timing calibration on the buffered data to obtain calibrated data;
[0080] A data classification module, which is used to calculate the term frequency-inverse document frequency of the calibrated data, perform preliminary shunting on the calibrated data based on the term frequency-inverse document frequency to obtain preliminarily shunted data, identify the link channel features of the calibrated data, and perform priority division on the preliminarily shunted data based on the link channel features to obtain high-priority data and low-priority data;
[0081] Data initial encryption, which is used to configure a high-priority key seed for the high-priority data by using a preset security mapping rule, query the encryption level requirement of the high-priority data to construct an encryption elliptic curve for the high-priority data, perform a base point operation in the encryption elliptic curve by using the high-priority key seed to obtain an encryption key, construct a high-dimensional lattice structure for the high-priority data, and use the high-dimensional lattice structure and the encryption key to perform initial encryption on the high-priority data to obtain initially encrypted data;
[0082] A data priority encryption module, which is used to perform data core division on the initially encrypted data to obtain primary encrypted data and secondary encrypted data, construct a quantum random number for the primary encrypted data, perform quantum random encryption on the primary encrypted data based on the quantum random number to obtain quantum randomly encrypted data, identify the digital certificate and identity identifier of the metadata corresponding to the secondary encrypted data, and perform asymmetric encryption on the secondary encrypted data based on the digital certificate and the identity identifier to obtain asymmetrically encrypted data, and use the quantum randomly encrypted data and the asymmetrically encrypted data as high-priority encrypted data;
[0083] A data storage module, which is used to perform simplified dual-rail encryption on the low-priority data to obtain dual-rail encrypted data, and perform hierarchical storage on the high-priority encrypted data and the dual-rail encrypted data to obtain target encrypted data.
[0084] Compared with the prior art, the present invention first collects the mixed - inserted data, which can provide the original material for the whole process, lay the foundation for subsequent operations, and analyze the key parameter characteristics of the interface interaction of the mixed - inserted data to deeply understand the law of data interaction mode, providing a basis for constructing a data buffering strategy. This strategy can ensure the smooth transition of data, reduce the delay or loss caused by transmission problems, and improve the system performance and reliability. Based on this data buffering operation, the data reception and processing are more flexible. Using the atomic energy level transition benchmark for timing calibration ensures the correct causality of the data and avoids the faults caused by time chaos. Then, the present invention calculates the term frequency - inverse document frequency of the calibration data, which helps to extract key information. Preliminary data shunting based on this can improve the processing efficiency, and identifying the link channel characteristics and dividing the data priority can reasonably allocate system resources to ensure the timely and accurate processing of high - priority data, enhancing the overall system performance and response ability. Then, for high - priority data, configuring the key seed increases the encryption pertinence and security foundation, constructing an encryption elliptic curve to clarify the encryption standard, generating an encryption key through base - point operation to ensure confidentiality, and combining with a high - dimensional lattice structure for initial encryption to construct a multi - layer encryption system to further strengthen data security. Core division of the initially encrypted data, using quantum random encryption and asymmetric encryption for data of different importance levels, takes into account the high - level protection of key data and the reasonable encryption of less important data, avoiding resource waste, and can also ensure the encryption accuracy through verification, providing multi - layer encryption protection as a whole, and thus improving the data security of SATA - PCIe mixed - inserted data. BRIEF DESCRIPTION OF THE DRAWINGS
[0085] Figure 1 FIG. is a schematic flowchart of an encryption method for SATA - PCIe mixed - inserted data implemented based on the Pisces algorithm provided by an embodiment of the present invention;
[0086] Figure 2 FIG. is a schematic module diagram of an encryption system for SATA - PCIe mixed - inserted data implemented based on the Pisces algorithm provided by an embodiment of the present invention.
[0087] The implementation, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0088] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0089] The embodiments of the present application provide an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm. The execution subject for an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiments of the present application. In other words, the encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc.
[0090] Embodiment 1:
[0091] Refer to Figure 1 As shown, it is a schematic flowchart of an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm provided by an embodiment of the present invention. In this embodiment, the encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm includes:
[0092] S1. Collect the mixed-insertion data of the SATA interface and the PCIe interface, analyze the key parameter features of the key parameters of the interface interaction of the mixed-insertion data, based on the key parameter features, construct a data buffering strategy for the mixed-insertion data, based on the data buffering strategy, buffer the mixed-insertion data to obtain buffered data, construct an atomic energy level transition benchmark for the buffered data, and use the atomic energy level transition benchmark to perform timing calibration on the buffered data to obtain calibrated data.
[0093] In the embodiments of the present invention, the original data can be obtained by collecting the mixed-insertion data of the SATA interface and the PCIe interface, providing materials for the entire data processing and encryption process.
[0094] Among them, the SATA interface refers to a computer bus interface, mainly used to connect storage devices (such as hard disks, optical drives, etc.) to the motherboard. The PCIe interface refers to a high-speed serial computer expansion bus standard, used to connect various peripheral devices, such as graphics cards, network cards, solid-state drives (SSDs through the PCIe interface), etc., to achieve high-speed data transmission and communication interfaces between devices. The mixed-insertion data refers to data transmitted through the SATA interface and the PCIe interface simultaneously in a computer system or a data processing environment.
[0095] In the embodiments of the present invention, analyzing the key parameter features of the key parameters of the interface interaction of the mixed-insertion data can help users deeply understand the data interaction mode and rules, and can also provide a basic basis for subsequent buffering of the data.
[0096] As an embodiment of the present invention, the key parameter features for analyzing the key parameters of interface interaction of the mixed insertion data include: extracting the electrical signal of the mixed insertion data, querying the clock signal period, level start - end time, rising edge start - end voltage and falling edge start - end voltage of the electrical signal, analyzing the clock signal frequency of the electrical signal based on the clock signal period, analyzing the level conversion frequency of the electrical signal based on the level start - end time, analyzing the electrical rising edge slope of the electrical signal based on the rising edge start - end voltage, analyzing the electrical falling edge slope of the electrical signal based on the falling edge start - end voltage, and determining the key parameter features of the key parameters of interface interaction corresponding to the mixed insertion data based on the clock signal frequency, the level conversion frequency, the electrical rising edge slope and the electrical falling edge slope.
[0097] Among them, the electrical signal refers to the electrical signal corresponding to the data transmitted in the interface circuit, including signals such as voltage and current, which carries information such as data and clock. The clock signal period refers to the time experienced by the clock signal to complete a full cycle (such as from a rising edge to the next rising edge). The level start - end time refers to the time interval during which the level changes from one state (such as low level) to the end of the change (such as changing to high level). The rising edge start - end voltage refers to the voltage values corresponding to the start time and the end time during the process of the signal level changing from low level to high level. The falling edge start - end voltage refers to the voltage values corresponding to the start time and the end time during the process of the signal level changing from high level to low level.
[0098] Optionally, the electrical signal can be obtained by placing high-precision sensors (such as voltage sensors, current sensors) in the interface circuit. The level start-end time, the level rising edge start-end voltage, and the level falling edge start-end voltage can be directly read and recorded by connecting a probe to the corresponding position of the interface circuit using an oscilloscope or professional signal acquisition equipment. The clock signal frequency can be obtained by dividing 1 by the clock signal period. For example, if the clock signal period is 10 nanoseconds, then the frequency is 100 MHz (1 / 10 ns). The level conversion frequency can be obtained by calculating the number of occurrences of the level start-end time within a unit time, which gives the level conversion frequency. For instance, if there are 100 level conversions in 1 second, the level conversion frequency is 100 Hz. The electrical rising edge slope can be calculated by using (level rising edge end voltage - level rising edge start voltage) divided by (rising edge end time - rising edge start time), and the electrical falling edge slope can be calculated by using (level falling edge end voltage - level falling edge start voltage) divided by (falling edge end time - falling edge start time).
[0099] In the embodiment of the present invention, by constructing the data buffering strategy for the mixed insertion data based on the key parameter features, it can ensure the smooth transition of data between the interface and the processing system, reduce processing delays or data loss caused by problems such as mismatched data transmission rates, thereby improving the performance and reliability of the entire system.
[0100] As an embodiment of the present invention, constructing the data buffering strategy for the mixed insertion data based on the key parameter features includes: analyzing the traffic peak and data unit size of the mixed insertion data based on the key parameter features, constructing the buffer interval of the mixed insertion data based on the traffic peak and the data unit size, calculating the timing weight and priority weight of the mixed insertion data, constructing the data storage scheme of the mixed insertion data based on the timing weight and priority weight, formulating the data read-write rules of the mixed insertion data based on the storage rules corresponding to the data storage scheme, and constructing the data buffering strategy of the mixed insertion data based on the buffer interval, the data storage scheme, and the data read-write rules.
[0101] Among them, the traffic peak refers to the maximum value of the data volume transmitted per unit time during data transmission, and the data unit size refers to the size of the data transmitted as a basic unit during data transmission.
[0102] Optionally, the traffic peak value can be obtained by inferring the data transmission rate from key parameter characteristics such as clock signal frequency and level conversion frequency, combined with the data volume statistics within a period of time. The data unit size can be estimated by estimating the transmission duration of the data unit based on characteristics such as electrical rising edge slope, falling edge slope and level change time, and then the data unit size is obtained in combination with the transmission rate. The buffer space can be determined by determining the lower limit of the size of the buffer space according to the traffic peak value to ensure that it can accommodate the amount of data during the peak traffic period. For example, if the traffic peak is 50MB per second, the buffer space must be able to accommodate at least 50MB of data, and then consider the data unit size. If the data unit size varies greatly and small units appear frequently, additional space is appropriately added to reduce the overhead of small unit data frequently entering and exiting the buffer, thereby constructing a suitable buffer space. The timing weight can be evaluated based on the stability of the clock signal. For example, by analyzing the electrical signal of the hybrid data, the standard deviation of the clock signal period is u. If u is very small, such as u=0.01 ns (nanoseconds), it means that the clock signal is very stable. A reference value can be set. When u is less than this reference value (such as 0.1 ns), the timing weight is initially divided into 80 points (out of 100), and then the score is adjusted according to the ratio of the actual u value to the reference value. For example, the actual u=0.01 ns is very stable relative to the reference value of 0.1 ns. At this time, the timing weight can be increased to 90 points. The priority weight can be judged according to the importance of the electrical signal characteristics. For example, there is a specific level combination in the hybrid data that represents an important control instruction. Through analysis, it is found that the frequency of this level combination in all data is p. If p is very low, such as p=0.01 (i.e., a probability of 1%), but these instructions are critical to the system, then a higher basic score can be set, such as 60 points (out of 100). The data storage scheme for intermixed data constructed based on timing weight and priority weight can be determined by comparing timing weight and priority weight. If the timing weight is high, the first-in-first-out (FIFO) storage method is preferred to ensure that the data is processed in chronological order. When the priority weight is high, a special high-priority storage area is set to store high-priority data in this area in priority so that it can be quickly obtained and processed. The data read and write rules for intermixed data formulated based on the storage rules corresponding to the data storage scheme can be made by reading data from the head in sequence for the first-in-first-out storage area, and adding data at the tail for the write operation. For the high-priority storage area, the read operation first checks the area, and if there is data, it is read first. The write operation inserts the data setting according to the priority rule. The data buffering strategy for intermixed data constructed based on the buffer area, data storage scheme and data read and write rules can integrate the buffer size setting, the layout of the data storage scheme (such as the division of different priority areas, the arrangement of timing queues) and the data read and write rules to form a complete data buffering strategy.
[0103] In the embodiment of the present invention, by buffering the mixed inserted data based on the data buffering strategy to obtain buffered data, the process of data reception and processing can be isolated to a certain extent, enabling the data receiving end and the processing end to work at different rhythms and making the data processing more flexible.
[0104] Optionally, the process of buffering the mixed inserted data based on the data buffering strategy to obtain buffered data is as follows: First, a storage area is allocated in the memory according to the size of the buffer interval determined by the data buffering strategy. Then, in accordance with the data storage scheme (determined based on the timing weight and priority weight of the data, such as first in first out, storing by priority, etc.), when the mixed inserted data arrives, it is stored in the corresponding buffer position. Then, data writing and reading operations are performed according to the data reading and writing rules, the data is stored in the buffer and taken out when needed and sent to the subsequent processing unit, thus completing the data buffering of the mixed inserted data and finally obtaining buffered data.
[0105] In the embodiment of the present invention, by constructing the atomic energy level transition reference of the buffered data, an accurate time reference standard can be provided for the buffered data.
[0106] Among them, the atomic energy level transition reference refers to a high-precision time reference, which can be constructed based on a high-precision atomic clock.
[0107] In the embodiment of the present invention, by using the atomic energy level transition reference to perform timing calibration on the buffered data to obtain calibrated data, the correct causal relationship of the data can be ensured, and wrong decisions or system failures caused by time chaos can be avoided.
[0108] Optionally, the process of using the atomic energy level transition reference to perform timing calibration on the buffered data to obtain calibrated data is as follows: An atomic clock pulse count is added to the buffered data unit to form a timestamp, the differences between the timestamps of each data unit and the reference time sequence are compared, and the order of the data units is adjusted according to the differences to achieve timing calibration and obtain calibrated data.
[0109] S2. Calculate the term frequency-inverse document frequency of the calibrated data, based on the term frequency-inverse document frequency, perform preliminary shunting on the calibrated data to obtain preliminary shunted data, identify the link channel characteristics of the calibrated data, and based on the link channel characteristics, perform priority division on the preliminary shunted data to obtain high-priority data and low-priority data.
[0110] In the embodiment of the present invention, calculating the term frequency-inverse document frequency of the calibrated data can help extract key information from the calibrated data, understand the theme and key content of the data, and provide a basis for subsequent data shunting and processing.
[0111] Among them, the term frequency - inverse document frequency is a statistical method that combines term frequency and inverse document frequency and is an index for measuring the importance of a word in a document.
[0112] As an embodiment of the present invention, calculating the term frequency - inverse document frequency of the calibration data includes: constructing a data text of the calibration data, classifying the data text to obtain classified documents, and calculating the term frequency - inverse document frequency of the classified documents using the following formula:
[0113] P = n_(w,d) / (∑_k n_(k,d) )×logN / n_w;
[0114] Among them, P represents the term frequency - inverse document frequency, n_(w,d) represents the number of times the word w appears in the document d, N represents the number of classified documents, n_w represents the number of times the word w appears in all classified documents, k represents an index variable, and ∑_k n_(k,d) represents the sum of the number of times all words appear in the document d.
[0115] Optionally, the data text of the calibration data can be constructed using a script generated by Java. Classifying the data text to obtain classified documents can be achieved by analyzing the content characteristics of the data text to determine appropriate classification criteria. Common classification bases can be according to data sources (such as data transmitted through SATA or PCIe interfaces from different devices), data uses (whether it is control instruction - type data or actual transmitted file content data, etc.), time ranges (classifying data collected in different time periods), etc. For example, if classified according to data sources, then the data text of hard disk read - write operations from the SATA interface can be marked as one category, and the data text of network card interactions from the PCIe interface can be marked as another category, and classification is carried out according to the above rules.
[0116] In the embodiment of the present invention, by performing preliminary shunting on the calibration data based on the term frequency - inverse document frequency to obtain preliminary shunted data, the data can be preliminarily sorted according to certain logic and characteristics, improving the efficiency of data processing.
[0117] Optionally, the preliminary shunted data can be obtained by separately calculating the term frequency and inverse document frequency of each text unit in the calibration data and multiplying them to obtain the TF - IDF value, then selecting the high - value topic keywords accordingly, and then classifying the calibration data according to the topic keywords, thereby obtaining the preliminary shunted data.
[0118] Furthermore, in the embodiment of the present invention, identifying the link channel characteristics of the calibration data can help users determine the priority and processing method of the data.
[0119] Optionally, the link channel characteristics can be obtained by using network monitoring technologies such as SNMP (Simple Network Management Protocol) and network traffic analysis software to collect bandwidth information of the calibration data transmission link, determining the latency by sending probe packets and measuring the round-trip time, analyzing the packet transmission situation to obtain the packet loss rate, and simultaneously determining details such as the source device type, importance level, and destination device usage of the link connection. By comprehensively analyzing this information, the link channel characteristics can be derived.
[0120] Furthermore, in the embodiment of the present invention, based on the link channel characteristics, the preliminary shunt data is divided into high-priority data and low-priority data. Through the division of priorities, system resources can be reasonably allocated to ensure that high-priority data can be processed promptly and accurately, improving the overall performance and response ability of the system.
[0121] Optionally, the process of dividing the preliminary shunt data into high-priority data and low-priority data based on the link channel characteristics is as follows: First, priority rules are formulated according to characteristics such as the bandwidth, latency, packet loss rate of the link channel, and the importance of the source device and the destination device. For example, if the link bandwidth is high, the latency is low, and the source device is a core business server, the transmitted data has a higher priority. Then, using data marking technology, the preliminary shunt data is evaluated, and the data that conforms to the high-priority rules is marked as high-priority data and stored in a specific high-priority data buffer, while the remaining data is marked as low-priority data and stored in a low-priority data buffer, thereby achieving the division of high-priority data and low-priority data.
[0122] S3. Configure the high-priority key seed of the high-priority data by using a preset security mapping rule, query the encryption level requirement of the high-priority data to construct the encryption elliptic curve of the high-priority data, perform base point operations in the encryption elliptic curve by using the high-priority key seed to obtain the encryption key, construct the high-dimensional lattice structure of the high-priority data, and use the high-dimensional lattice structure and the encryption key to perform initial encryption on the high-priority data to obtain the initially encrypted data.
[0123] In the embodiment of the present invention, by configuring the high-priority key seed of the high-priority data by using a preset security mapping rule, a unique initial encryption parameter associated with the data priority can be provided, increasing the pertinence and security basis of encryption, enabling different-priority data to have differential and secure encryption starting conditions, and preventing security risks brought by a common key seed. For example, in a multi-user and multi-data scenario, the risk of data leakage caused by the repeated cracking of the key seed can be reduced. Herein, the high-priority key seed refers to the initial value or basic parameter used to generate the encryption key of the high-priority data.
[0124] Optionally, the process of configuring the high-priority key seed for the high-priority data using the preset security mapping rules is as follows: First, based on the security mapping rules pre-designed and stored in a secure area (such as an encrypted database or a hardware security module), analyze the key attributes of the high-priority data, such as data source, type, size, etc. Then, determine the corresponding key seed generation strategy from the rules according to these attributes. If the rule stipulates that part of the seed is generated based on the data hash value, perform a hash operation on the high-priority data (such as using the SHA-256 algorithm) to obtain a hash value segment of a specific length as part of the seed. Next, combine it with the random number generator built into the system (such as a hardware-based true random number generator or a cryptographically secure pseudo-random number generator) to generate another part of the seed content. Finally, combine the two parts and configure them into a high-priority key seed according to the mapping method in the rules (such as specific bit operations or splicing rules).
[0125] In an embodiment of the present invention, by querying the encryption level requirement of the high-priority data to construct the encryption elliptic curve of the high-priority data, the encryption strength or specific encryption standard required for the high-priority data can be clarified.
[0126] Among them, the encryption elliptic curve refers to a special mathematical structure, and data encryption is realized through the operation rules defined on it.
[0127] Optionally, the encryption elliptic curve can select appropriate elliptic curve parameters according to the encryption level requirement, such as secp256k1.
[0128] In an embodiment of the present invention, by performing a base point operation on the encryption elliptic curve using the high-priority key seed to obtain the encryption key, it can be ensured that the generation of the encryption key has randomness and unpredictability, and at the same time is closely related to the previously determined key seed and the encryption elliptic curve. Due to the characteristics of elliptic curve encryption, even if an attacker obtains part of the encrypted information, it is extremely difficult to reverse-derive the key seed or the original data, thus effectively protecting the confidentiality of the high-priority data. Moreover, the key generated based on the base point operation can be conveniently used for subsequent data encryption and decryption operations in the elliptic curve encryption system, ensuring the coherence and effectiveness of the encryption process.
[0129] Optionally, the process of obtaining the encrypted key by performing base point operations in the encrypted elliptic curve using the high-priority key seed is as follows: First, use the high-priority key seed as the initial parameter, and according to the relevant mathematical rules of elliptic curve cryptography, perform a point multiplication operation on the constructed encrypted elliptic curve (including the determined curve equation, finite field, base point, etc.), that is, perform multiple addition operations (according to the addition rules defined by the elliptic curve) on the value corresponding to the seed and the selected base point on the elliptic curve. Then, after a series of operations that conform to the operation logic of the elliptic curve, the resulting point (coordinate value and other information) is subjected to specific format conversion and processing, and finally an encrypted key that can be used to encrypt high-priority data is generated.
[0130] In the embodiment of the present invention, by constructing the high-dimensional lattice structure of the high-priority data, encryption can be achieved based on vector operations in the high-dimensional lattice structure.
[0131] Among them, the high-dimensional lattice structure refers to a discrete mathematical structure in a high-dimensional space and can be constructed based on the Gram-Schmidt method.
[0132] In the embodiment of the present invention, by using the high-dimensional lattice structure and the encrypted key to initially encrypt the high-priority data to obtain the initially encrypted data, a multi-layer encryption system can be constructed to further enhance the security of the data.
[0133] As an embodiment of the present invention, the process of using the high-dimensional lattice structure and the encrypted key to initially encrypt the high-priority data to obtain the initially encrypted data includes: converting the encrypted key into a binary sequence, performing unit segmentation on the binary sequence to obtain encrypted segmentation units, converting the basis vectors of the high-dimensional lattice structure into a basis vector matrix, performing a linear transformation on the basis vector matrix using vector subtraction to obtain a target basis vector matrix, mapping the encrypted segmentation units into the target basis vector matrix to obtain encrypted vectors, and performing data conversion on the encrypted vectors to obtain the initially encrypted data.
[0134] Among them, the binary sequence refers to a sequence composed of 0s and 1s obtained by converting the encryption key according to the binary coding rule, and the encrypted segmentation unit refers to a unit obtained by segmenting the binary sequence according to a certain rule. For example, when a relatively long binary sequence (such as 1010110011) is segmented into groups of 3 bits each, encrypted segmentation units such as 101, 011, 001, 1 (if the last group has less than 3 bits, it is also counted as a group) will be obtained.
[0135] Optionally, the conversion of the encryption key into a binary sequence can be achieved through ASCII codes. The encryption segmentation unit can divide the binary sequence into small segments of a fixed length (such as each group of 8 bits or 16 bits) by using programming means such as string segmentation functions or loop truncation according to a preset length standard. These small segments are the encryption segmentation units. The conversion of the basis vectors of the high-dimensional lattice structure into a basis vector matrix can be achieved through the vector-matrix conversion technology in linear algebra. The target basis vector matrix can determine the vectors to be subtracted according to specific algorithms or rules (which can be generated based on keys or other preset parameters, and specifically need to be combined with actual applications), and perform vector subtraction operations on the vectors in the basis vector matrix by subtracting the corresponding elements in the matrix to obtain the changed target basis vector matrix. The encrypted vector can be mapped through a custom mapping function.
[0136] S4. Perform data core partitioning on the initial encrypted data to obtain primary encrypted data and secondary encrypted data. Construct quantum random numbers for the primary encrypted data, and based on the quantum random numbers, perform quantum random encryption on the primary encrypted data to obtain quantum randomly encrypted data. Identify the digital certificates and identity identifiers of the metadata corresponding to the secondary encrypted data, and based on the digital certificates and the identity identifiers, perform asymmetric encryption on the secondary encrypted data to obtain asymmetrically encrypted data. Use the quantum randomly encrypted data and the asymmetrically encrypted data as high-priority encrypted data.
[0137] In the embodiment of the present invention, by performing data core partitioning on the initial encrypted data to obtain primary encrypted data and secondary encrypted data, the most core and sensitive data (primary encrypted data) can be separated from the relatively less important data (secondary encrypted data), enabling more reasonable allocation of subsequent encryption resources. For extremely critical data, more advanced and complex encryption technologies can be used, while for less important data, relatively appropriate encryption methods can be adopted to avoid resource waste caused by over-encryption and ensure the effectiveness and hierarchy of overall data security protection.
[0138] As an embodiment of the present invention, the performing data core partitioning on the initial encrypted data to obtain primary encrypted data and secondary encrypted data includes: after scanning the initial encrypted data with a pre-configured sensitivity label, performing sensitivity marking on the initial encrypted data to obtain sensitivity-marked data, querying the data flow of the sensitivity-marked data, analyzing the data usage of the sensitivity-marked data based on the data flow, setting access permissions for the initial encrypted data based on the data usage to obtain set permissions, and performing data core partitioning on the initial encrypted data based on the set permissions to obtain primary encrypted data and secondary encrypted data.
[0139] Among them, the pre-configured sensitivity label refers to a pre-set identification system for measuring the sensitivity of data. It is determined based on factors such as the nature, content, use of the data, and the possible impact on the organization.
[0140] Optionally, after using the pre-configured sensitivity label to perform a data scan on the initial encrypted data, a sensitivity mark is applied to the initial encrypted data to obtain sensitivity-marked data. This can be done by scanning the initial encrypted data through techniques such as text matching or feature recognition according to the label content corresponding to different pre-set sensitivity levels (such as labels containing words like confidential, important, general, etc.), and then applying the corresponding sensitivity mark according to the matching situation to form sensitivity-marked data. To query the data flow of the sensitivity-marked data, a log recording system (if any) can be used or monitoring points can be set in the data transmission link to trace each node, device, etc. that the sensitivity-marked data passes through since its generation. Based on the data flow, analyzing the data use of the sensitivity-marked data can be achieved according to the business processes, application scenarios, etc. involved in the data flow. For example, if it flows to the financial system, it may be used for account calculation, and if it flows to the R & D department, it may be used for product testing. By comprehensively judging its specific data use, based on the data use, access permissions are set for the initial encrypted data to obtain the set permissions. This can be done according to the different department and position requirements involved in the data use, referring to the enterprise's internal permission management rules, and using a permission configuration tool to set corresponding read, write, modify, etc. access permissions for the initial encrypted data for different user roles to form the set permissions. Based on the set permissions, the initial encrypted data is divided into first-level encrypted data and second-level encrypted data. According to the difference in importance reflected in the permission settings, the data subject to high-level permission control and core use is divided into first-level encrypted data, and the relatively less important data is divided into second-level encrypted data.
[0141] Furthermore, in the embodiment of the present invention, by using the quantum random number, quantum random encryption is performed on the first-level encrypted data to obtain quantum randomly encrypted data. This can utilize the unique properties of quantum mechanics and the strong randomness of random numbers to provide a higher level of encryption protection for the first-level encrypted data. Among them, the quantum random number refers to a random number generated based on the principles of quantum mechanics.
[0142] As an embodiment of the present invention, performing quantum random encryption on the first-level encrypted data using the quantum random number to obtain quantum randomly encrypted data includes: constructing a random sequence number set of the quantum random number, where the sequence number set can be represented in the following form:
[0143] R = {r_1, r_2, ⋯, r_n}, r_i ∈ {0, 1};
[0144] Among them, R represents the set of sequence numbers, r_1 represents the first random sequence number in the set of random sequence numbers, r_2 represents the second random sequence number in the set of random sequence numbers, r_n represents the nth random sequence number in the set of random sequence numbers, and r_i represents the ith sequence number in the set of random sequence numbers;
[0145] Construct the set of encrypted sequence numbers of the first-level encrypted data, where the set of encrypted sequence numbers can be represented in the following form:
[0146] D = {d_1, d_2, ⋯, d_n}, d_i ∈ {0, 1};
[0147] Among them, D represents the set of encrypted sequence numbers, d_1 represents the first random sequence number in the set of encrypted sequence numbers, d_2 represents the second random sequence number in the set of encrypted sequence numbers, d_n represents the nth random sequence number in the set of encrypted sequence numbers, and d_i represents the ith sequence number in the set of encrypted sequence numbers;
[0148] Use the following formula to perform quantum transposition operation on the set of random sequence numbers and the set of encrypted sequence numbers to obtain encrypted data bits:
[0149] e_i = d_i ⊕ r_i;
[0150] Among them, e_i represents the encrypted data bit, d_i represents the ith sequence number in the set of encrypted sequence numbers, r_i represents the ith sequence number in the set of random sequence numbers, and ⊕ represents the quantum transposition operation;
[0151] Based on the encrypted data bits, perform data encryption on the first-level encrypted data to obtain quantum random encrypted data.
[0152] Furthermore, in the embodiment of the present invention, by identifying the digital certificate and identity identifier corresponding to the metadata of the second-level encrypted data, the legitimacy, authenticity of the data source and the relevant information of the data owner can be determined, providing a trust basis and identity verification basis for subsequent encryption operations.
[0153] Optionally, the digital certificate can be identified by extracting the digital certificate information in the metadata corresponding to the second-level encrypted data, verifying the legitimacy of its signature with the public key of the trusted CA and parsing the content to obtain relevant identity information. The identity identifier can be identified by searching the identity identifier storage, associating with the digital certificate according to the association rule, and then verifying the authenticity according to the system verification mechanism to complete the identification.
[0154] In an embodiment of the present invention, by using the digital certificate and the identity identifier to perform asymmetric encryption on the secondary encrypted data, the obtained asymmetric encrypted data can protect the confidentiality of the data during transmission and storage. At the same time, it facilitates the secure interaction of the data between multiple different trust domains or entities, promotes the sharing and collaboration of the data, and ensures the security of the data.
[0155] As an embodiment of the present invention, the process of using the digital certificate and the identity identifier to perform asymmetric encryption on the secondary encrypted data to obtain the asymmetric encrypted data includes: obtaining the encryption public key of the secondary encrypted data according to the digital certificate and the identity identifier, constructing the modulus of the secondary encrypted data, calculating the relatively prime number of the modulus, using the relatively prime number to construct the public key exponent of the secondary encrypted data, determining the private key exponent of the secondary encrypted data based on the public key exponent, and using the following formula to perform data encryption on the secondary encrypted data based on the public key exponent to obtain the initial asymmetric encrypted data.
[0156] C = M^e mod n;
[0157] Where, C represents the initial asymmetric encrypted data, M represents the byte sequence corresponding to the secondary encrypted data, e represents the public key exponent, and n represents the modulus;
[0158] Based on the private key exponent, use the following formula to perform data decryption on the initial asymmetric encrypted data to obtain the decrypted data:
[0159] E = C^d mod n;
[0160] Where, E represents the decrypted data, C represents the initial asymmetric encrypted data, d represents the private key exponent, and n represents the modulus;
[0161] Perform data consistency verification on the secondary encrypted data and the decrypted data. If the result of the data consistency verification is consistent, use the initial asymmetric encrypted data as the asymmetric encrypted data of the secondary encrypted data.
[0162] Where, the modulus refers to the number obtained by multiplying two large prime numbers in asymmetric encryption, the relatively prime number refers to an exponent used to determine the public key, the public key exponent refers to a part of the public key that forms the public key with the modulus for encrypting data, and the private key exponent refers to a part of the private key that forms the private key with the modulus for decrypting data.
[0163] Optionally, the encryption public key for obtaining the secondary encrypted data based on the digital certificate and the identity identifier can extract the public key information from the digital certificate (the corresponding public key is included in the certificate), determine the subject to which it belongs in combination with the identity identifier, and obtain the accurate encryption public key corresponding to the secondary encrypted data by association. The modulus for constructing the secondary encrypted data can be determined by the selected encryption algorithm rules (such as the relevant requirements of the RSA algorithm), and through appropriate mathematical operations (such as multiplying two large prime numbers). The relatively prime number of the calculated modulus can be found and determined within the range of integers that meet the condition of being relatively prime to the modulus by using algorithms in number theory (such as the Euclidean algorithm). Using the relatively prime number, the public key exponent for constructing the secondary encrypted data can appropriately process the found relatively prime number according to the established encryption algorithm logic (such as directly selecting a relatively prime number that meets the requirements or further performing arithmetic adjustments) to make it a public key exponent that meets the encryption requirements. Based on the public key exponent, the private key exponent for the secondary encrypted data can be calculated according to the public key exponent, modulus, and specific mathematical relationships (such as the public-private key correspondence based on modular exponentiation in the RSA algorithm).
[0164] Furthermore, in the embodiment of the present invention, by using the quantum random encrypted data and the asymmetric encrypted data as high-priority encrypted data, multi-layer encryption protection can be provided, enhancing data security to meet the high-security application requirements of users.
[0165] S5. Perform simplified double-track encryption on the low-priority data to obtain double-track encrypted data, and perform hierarchical storage on the high-priority encrypted data and the double-track encrypted data to obtain target encrypted data.
[0166] In the embodiment of the present invention, by performing simplified double-track encryption on the low-priority data to obtain double-track encrypted data, these data can be effectively protected without excessively increasing the calculation cost and storage cost.
[0167] As an embodiment of the present invention, performing simplified double-track encryption on the low-priority data to obtain double-track encrypted data includes: converting the low-priority data into binary data, performing data grouping on the binary data to obtain grouped data, constructing an encrypted pseudo-random number for the grouped data, using the encrypted pseudo-random number to perform bitwise XOR operation on the grouped data to obtain the first-track encrypted data, configuring a pseudo-random encryption seed for the grouped data, performing element permutation on the grouped data to obtain element-permuted data, using the pseudo-random encryption seed to perform element substitution on the element-permuted data to obtain the second-track encrypted data, and alternately splicing the first-track encrypted data and the second-track encrypted data to obtain double-track encrypted data.
[0168] Among them, the encrypted pseudo-random number refers to a sequence of numbers that seems random but is actually generated by a deterministic algorithm.
[0169] Optionally, the binary conversion of the low-priority data to obtain binary data can be converted through ASCII code. The grouping of the binary data to obtain grouped data can be achieved by determining the length of the group. For example, the binary data is divided into groups of 8 bits, 16 bits, or 32 bits. The encrypted pseudo-random number can be set by a linear congruential generator. The process of using the encrypted pseudo-random number to perform an exclusive OR operation on the grouped data to obtain the first-track encrypted data is as follows: The generated encrypted pseudo-random number and the grouped data are subjected to an exclusive OR operation bit by bit, starting from the highest bit of the binary data and performing the exclusive OR operation bit by bit. For example, if the grouped data is 10101010 and the encrypted pseudo-random number is 01010101, after the exclusive OR operation, 11111111 is obtained. The pseudo-random encryption seed can extract a part of the information such as the system timestamp and the password hash value input by the user as the seed. The permutation of elements of the grouped data to obtain the element-permuted data can determine the rule of element permutation according to the pseudo-random encryption seed. For example, the seed can be used as the generation parameter of an index sequence, and this index sequence is used to determine the new positions of the elements in the grouped data. If the grouped data has 8 elements, the index sequence generated by the seed may be [3, 7, 1, 5, 0, 2, 6, 4], then the first element of the grouped data is placed in the 3rd position, the second element is placed in the 7th position, and so on. The use of the pseudo-random encryption seed to perform element substitution on the element-permuted data to obtain the second-track encrypted data can construct an element substitution table based on the pseudo-random encryption seed, and after substituting the element-permuted data using the element substitution table, the encrypted data is obtained. The alternating splicing of the first-track encrypted data and the second-track encrypted data to obtain the double-track encrypted data can sequentially extract fragments of the same length from the first-track encrypted data and the second-track encrypted data. For example, first take the first 8 bits of the first-track encrypted data, then take the first 8 bits of the second-track encrypted data, and then splice them together. Repeat in this order continuously until all the data fragments are spliced.
[0170] Furthermore, in the embodiment of the present invention, by hierarchically storing the high-priority encrypted data and the double-track encrypted data to obtain the target encrypted data, the high-priority encrypted data and the double-track encrypted data can be distinguished according to the importance and encryption degree of the data, making data management more orderly and further improving the security of the data.
[0171] Optionally, the target encrypted data can be obtained by storing the high-priority encrypted data and the dual-track encrypted data using a pre-configured data repository.
[0172] Embodiment 2:
[0173] As Figure 2 shown, it is a system function module diagram for implementing an encryption method for SATA-PCIe mixed-insertion data based on the Pisces algorithm according to an embodiment of the present invention.
[0174] The encryption system 200 for SATA-PCIe mixed-insertion data based on the Pisces algorithm according to the present invention can be installed in an electronic device. According to the implemented functions, the encryption system for SATA-PCIe mixed-insertion data based on the Pisces algorithm can include a data calibration module 201, a data grading module 202, an initial data encryption 203, a data priority encryption module 204, and a data storage module 205. The modules in the present invention can also be referred to as units, which refer to a series of computer program segments that can be executed by a processor of an electronic device and can complete fixed functions, and are stored in the memory of the electronic device.
[0175] In the embodiment of the present invention, the functions of each module / unit are as follows:
[0176] The data calibration module 201 is used to collect the mixed-insertion data of the SATA interface and the PCIe interface, analyze the key parameter characteristics of the interface interaction key parameters of the mixed-insertion data, based on the key parameter characteristics, construct a data buffering strategy for the mixed-insertion data, based on the data buffering strategy, buffer the mixed-insertion data to obtain buffered data, construct an atomic energy level transition benchmark for the buffered data, and use the atomic energy level transition benchmark to perform timing calibration on the buffered data to obtain calibrated data;
[0177] The data grading module 202 is used to calculate the term frequency-inverse document frequency of the calibrated data, based on the term frequency-inverse document frequency, perform a preliminary diversion on the calibrated data to obtain preliminary diversion data, identify the link channel characteristics of the calibrated data, and based on the link channel characteristics, perform a priority division on the preliminary diversion data to obtain high-priority data and low-priority data;
[0178] The initial data encryption 203 is used to configure the high-priority key seed of the high-priority data by using a preset security mapping rule, query the encryption level requirement of the high-priority data, construct the encryption elliptic curve of the high-priority data, perform a base point operation in the encryption elliptic curve by using the high-priority key seed to obtain an encryption key, construct the high-dimensional lattice structure of the high-priority data, and use the high-dimensional lattice structure and the encryption key to perform initial encryption on the high-priority data to obtain initially encrypted data;
[0179] The data priority encryption module 204 is used to perform data core division on the initially encrypted data to obtain first-level encrypted data and second-level encrypted data, construct the quantum random number of the first-level encrypted data, perform quantum random encryption on the first-level encrypted data based on the quantum random number to obtain quantum randomly encrypted data, identify the digital certificate and identity identifier of the metadata corresponding to the second-level encrypted data, and perform asymmetric encryption on the second-level encrypted data based on the digital certificate and the identity identifier to obtain asymmetrically encrypted data, and use the quantum randomly encrypted data and the asymmetrically encrypted data as high-priority encrypted data;
[0180] The data storage module 205 is used to perform simplified dual-rail encryption on the low-priority data to obtain dual-rail encrypted data, and perform hierarchical storage on the high-priority encrypted data and the dual-rail encrypted data to obtain target encrypted data.
[0181] Specifically, each module in the encryption system 200 for SATA-PCIe mixed plug data based on the Pisces algorithm in the embodiments of the present invention adopts the same technical means as those in the Figure 1 encryption method for SATA-PCIe mixed plug data based on the Pisces algorithm described above, and can produce the same technical effects, which will not be elaborated here.
[0182] In several embodiments provided by the present invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.
[0183] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0184] In addition, in each embodiment of the present invention, each functional module can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware, or in the form of a combination of hardware and software functional modules.
[0185] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.
[0186] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the said element.
[0187] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm, characterized in that: The method comprises: Collecting mixed insertion data of the SATA interface and the PCIe interface, analyzing key parameter characteristics of the interface interaction key parameters of the mixed insertion data, constructing a data buffering strategy for the mixed insertion data based on the key parameter characteristics, buffering the mixed insertion data based on the data buffering strategy to obtain buffered data, constructing an atomic energy level transition benchmark for the buffered data, and using the atomic energy level transition benchmark to perform timing calibration on the buffered data to obtain calibration data; Calculating the word frequency-inverse document frequency of the calibration data, preliminarily diverting the calibration data based on the word frequency-inverse document frequency to obtain preliminary diverted data, identifying link channel characteristics of the calibration data, and prioritizing the preliminary diverted data based on the link channel characteristics to obtain high priority data and low priority data; Using a preset security mapping rule, a high-priority key seed of the high-priority data is configured, and the encryption level requirement of the high-priority data is queried to construct an encryption elliptic curve for the high-priority data, and base point operations are performed in the encryption elliptic curve using the high-priority key seed to obtain an encryption key, and a high-dimensional lattice structure of the high-priority data is constructed, and the high-dimensional lattice structure and the encryption key are used to initially encrypt the high-priority data to obtain initial encrypted data; Divide the initial encrypted data into data cores to obtain primary encrypted data and secondary encrypted data, construct a quantum random number for the primary encrypted data, perform quantum random encryption on the primary encrypted data based on the quantum random number to obtain quantum random encrypted data, identify the digital certificate and identity identifier of metadata corresponding to the secondary encrypted data, perform asymmetric encryption on the secondary encrypted data based on the digital certificate and the identity identifier to obtain asymmetric encrypted data, and use the quantum random encrypted data and the asymmetric encrypted data as high-priority encrypted data; The low-priority data is simplified with dual-track encryption to obtain dual-track encrypted data, and the high-priority encrypted data and the dual-track encrypted data are hierarchically stored to obtain target encrypted data.
2. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The key parameter characteristics of the key interface interaction parameters of the mixed insertion data are analyzed, including: Extracting an electrical signal of the mixed-insertion data; Querying the clock signal period, level start-end time, level rising edge start-end voltage and level falling edge start-end voltage of the electrical signal; Analyzing a clock signal frequency of the electrical signal based on the clock signal period; Analyzing a level transition frequency of the electrical signal based on the level start-end time; Analyzing the electrical rising edge slope of the electrical signal based on the level rising edge start-end voltage; Analyzing the electrical falling edge slope of the electrical signal based on the starting and ending voltages of the falling edge; Based on the clock signal frequency, the level conversion frequency, the electrical rising edge slope, and the electrical falling edge slope, key parameter characteristics of the interface interaction key parameters corresponding to the intermixed data are determined.
3. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The step of constructing a data buffering strategy for the intermixed data based on the key parameter characteristics includes: Based on the key parameter characteristics, analyzing the traffic peak and data unit size of the mixed insertion data; Based on the traffic peak value and the data unit size, construct a buffer space for the mixed insertion data; Calculating the timing weight and priority weight of the mixed insertion data; Based on the timing weight and the priority weight, construct a data storage solution for the mixed insertion data; Formulate data reading and writing rules for the intermixed data based on storage rules corresponding to the data storage solution; A data buffering strategy for the intermixed data is constructed based on the buffer space, the data storage solution, and the data reading and writing rules.
4. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The calculating the term frequency-inverse document frequency of the calibration data includes: Constructing a data text of the calibration data; Performing document classification on the data text to obtain classified documents; The term frequency-inverse document frequency of the classified document is calculated using the following formula: ; Among them, the represents term frequency-inverse document frequency, represents the number of times word w appears in document d, Represents the number of classified documents, represents the number of times word w appears in all classified documents, k represents the index variable, It means summing the occurrence times of all words in document d.
5. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The method of using the high-dimensional grid structure and the encryption key to initially encrypt the high-priority data to obtain initial encrypted data includes: Converting the encryption key into a binary sequence; Performing unit segmentation on the binary sequence to obtain encrypted segmentation units; Converting the basis vectors of the high-dimensional lattice structure into a basis vector matrix; Performing a linear transformation on the basis vector matrix using vector subtraction to obtain a target basis vector matrix; Mapping the encrypted segmentation unit to the target basis vector matrix to obtain an encrypted vector; Perform data conversion on the encryption vector to obtain initial encrypted data.
6. A method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The step of dividing the initial encrypted data into data cores to obtain primary encrypted data and secondary encrypted data includes: After performing data scanning on the initial encrypted number using a preconfigured sensitivity label, the initial encrypted number is sensitivity labeled to obtain sensitivity labeled data; Querying the data flow direction of the sensitivity label data, based on the data flow direction; Analyzing the data usage of the sensitivity labeled data; Based on the data usage, access permission is set for the initial encrypted data to obtain setting permission; Based on the setting authority, the initial encrypted data is divided into data cores to obtain primary encrypted data and secondary encrypted data.
7. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The step of performing quantum random encryption on the primary encrypted data based on the quantum random number to obtain quantum random encrypted data includes: Construct a random sequence number set of the quantum random number, wherein the random sequence number set can be expressed in the following form: , ; in, represents a random sequence number set, Represents the first random sequence number in the random sequence number set, Represents the second random sequence number in the random sequence number set, represents the nth random sequence number in the random sequence number set, Represents the i-th sequence number in the random sequence number set; Construct an encryption sequence number set of the primary encrypted data, wherein the encryption sequence number set can be expressed in the following form: , ; in, represents the set of encrypted sequence numbers, Represents the first random sequence number in the encrypted sequence number set, Represents the second random sequence number in the encrypted sequence number set, Represents the nth random sequence number in the encrypted sequence number set, Represents the i-th sequence number in the encrypted sequence number set; The random sequence number set and the encrypted sequence number set are subjected to quantum heterogeneous operation using the following formula to obtain encrypted data bits: ; in, Indicates the encrypted data bit, represents the i-th sequence number in the encrypted sequence number set, represents the i-th sequence number in the random sequence number set, represents quantum heterogeneous operation; Based on the encrypted data bits, the primary encrypted data is encrypted to obtain quantum random encrypted data.
8. The method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The step of asymmetrically encrypting the secondary encrypted data based on the digital certificate and the identity identifier to obtain asymmetrically encrypted data includes: Obtaining the encryption public key of the encrypted data according to the digital certificate and the identity identifier; constructing a modulus of the secondary encrypted data; Calculating coprime numbers of the modulus; Using the coprime numbers, constructing a public key exponent of the secondary encrypted data; Based on the public key index, determining a private key index of the secondary encrypted data; Based on the public key index, the secondary encrypted data is encrypted using the following formula to obtain initial asymmetric encrypted data: ; in, represents the initial asymmetric encrypted data, M represents the byte sequence corresponding to the secondary encrypted data, e represents the public key exponent, and n represents the modulus; Based on the private key index, the initial asymmetrically encrypted data is decrypted using the following formula to obtain decrypted data: ; in, Indicates decrypted data. Represents the initial asymmetrically encrypted data, represents the private key exponent, and n represents the modulus; The secondary encrypted data and the decrypted data are subjected to data consistency verification. If the result of the data consistency verification is consistent, the initial asymmetric encrypted data is used as the asymmetric encrypted data of the secondary encrypted data.
9. A method for encrypting SATA-PCIe mixed insertion data based on the Pisces algorithm as claimed in claim 1, characterized in that: The step of performing simplified dual-track encryption on the low-priority data to obtain dual-track encrypted data includes: Performing binary conversion on the low priority data to obtain binary data; Grouping the binary data to obtain grouped data; Constructing an encrypted pseudo-random number for the packet data; Using the encrypted pseudo-random number, performing an out-of-place operation on the grouped data to obtain first-track encrypted data; Configuring a pseudo-random encryption seed for the grouped data; Performing element replacement on the grouped data to obtain element replacement data; Using the pseudo-random encryption seed, performing element substitution on the element replacement data to obtain second-track encrypted data; The first track encrypted data and the second track encrypted data are alternately spliced to obtain dual-track encrypted data.
10. A SATA-PCIe mixed insertion data encryption system based on the Pisces algorithm, characterized in that: The system comprises: A data calibration module, used for collecting mixed insertion data of the SATA interface and the PCIe interface, analyzing key parameter characteristics of the interface interaction key parameters of the mixed insertion data, constructing a data buffering strategy for the mixed insertion data based on the key parameter characteristics, buffering the mixed insertion data based on the data buffering strategy to obtain buffered data, constructing an atomic energy level transition benchmark for the buffered data, and performing timing calibration on the buffered data using the atomic energy level transition benchmark to obtain calibration data; A data classification module, used for calculating the word frequency-inverse document frequency of the calibration data, preliminarily dividing the calibration data based on the word frequency-inverse document frequency to obtain preliminary divided data, identifying the link channel characteristics of the calibration data, and prioritizing the preliminary divided data based on the link channel characteristics to obtain high priority data and low priority data; Data initial encryption, used to configure a high-priority key seed of the high-priority data using a preset security mapping rule, query the encryption level requirement of the high-priority data to construct an encryption elliptic curve for the high-priority data, perform base point operations in the encryption elliptic curve using the high-priority key seed to obtain an encryption key, construct a high-dimensional lattice structure of the high-priority data, and perform initial encryption on the high-priority data using the high-dimensional lattice structure and the encryption key to obtain initial encrypted data; A data priority encryption module is used to divide the initial encrypted data into data cores to obtain primary encrypted data and secondary encrypted data, construct a quantum random number for the primary encrypted data, perform quantum random encryption on the primary encrypted data based on the quantum random number to obtain quantum random encrypted data, identify a digital certificate and an identity identifier corresponding to metadata of the secondary encrypted data, perform asymmetric encryption on the secondary encrypted data based on the digital certificate and the identity identifier to obtain asymmetric encrypted data, and use the quantum random encrypted data and the asymmetric encrypted data as high priority encrypted data; The data storage module is used to perform simplified dual-track encryption on the low-priority data to obtain dual-track encrypted data, and hierarchically store the high-priority encrypted data and the dual-track encrypted data to obtain target encrypted data.
Citation Information
Patent Citations
Contract data protection method and device based on SM4 algorithm
CN118709233A
Data read-write method and system based on SATA (Serial Advanced Technology Attachment) and PCIe mixed plug interface
CN118915975A