A distributed network-based encryption and decryption verification method and system
By deploying multiple sets of execution nodes in a distributed network, monitoring and analyzing node behavior data, initially judging abnormal nodes using the majority voting principle, and building a comprehensive performance evaluation function by testing the performance status of redundant nodes, generating an alternative set, dynamically adjusting the polling frequency to automatically select adapted redundant nodes, the shortcomings in the implementation of node management and optimization in the existing technology are solved, and more accurate abnormal node identification and efficient system recovery are achieved.
Patent Information
- Application Number
- CN202510331121.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2045-03-20
AI Technical Summary
The prior art has shortcomings in the management and optimization of nodes for distributed network encryption and decryption verification, including the deviation of the reputation scoring mechanism to analyze malicious nodes and the lack of response to node performance changes by the polling mechanism.
By deploying multiple sets of execution nodes in a distributed network, monitoring and analyzing node behavior data, initially judging abnormal nodes using the majority voting principle, and building a comprehensive performance evaluation function by testing the performance status of redundant nodes, generating an alternative set, dynamically adjusting the polling frequency to automatically select adapted redundant nodes.
It realizes a more accurate analysis of the behavior of the execution node, reduces the misjudgment rate, ensures that the system can recover quickly when facing node failures, and improves the system's fault tolerance and overall performance.
Smart Images

Figure CN119865379B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an encryption and decryption verification method and system based on a distributed network. Background Art
[0002] As the core architecture of distributed computing, the distributed network is widely used in multiple fields such as finance, medical care, and cloud computing. It effectively improves the processing capacity and resource utilization rate of the system by dispersing tasks to multiple nodes for execution. In a distributed network environment, the security and integrity of data become key considerations. The encryption and decryption verification technology, as the core link to ensure the secure transfer of data, is responsible for encrypting and protecting data, decrypting and restoring it, and verifying its accuracy. Moreover, the behavior analysis and adjustment of the execution nodes during the encryption and decryption verification process are the key to ensuring the stable and efficient operation of the entire system.
[0003] However, there are many deficiencies in the management and optimization of the execution nodes for encryption and decryption verification in the current distributed network. Most of the existing technologies are based on the evaluation of the reputation system, establishing a reputation score for each node, and giving different reputation scores according to the historical performance of the node. When a node completes a correct encryption, decryption, or verification operation, its reputation score is increased; conversely, when an error or abnormal behavior occurs, its reputation score is decreased. However, malicious nodes often exhibit randomness, and based on the past performance of each node, it cannot represent the future performance of the node. Therefore, there is a certain deviation in the analysis of abnormal or malicious nodes. On the other hand, in the face of abnormal execution nodes, the selection mechanism of redundant nodes lacks scientificity and flexibility. Since the performance and availability of nodes may change over time or due to external factors, for example, a node may experience a performance decline or become unavailable due to hardware aging, network failures, or software updates. If the polling mechanism does not consider these changes and still selects nodes in a fixed order, it may frequently select unavailable or poorly performing nodes. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides an encryption and decryption verification method and system based on a distributed network, which solves the problems in the above background art.
[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: An encryption and decryption verification method based on a distributed network includes the following steps.
[0006] S1. Deploy a number of groups of execution nodes in the distributed network in advance, and interconnect each execution node for communication operations. Based on the number of groups of execution nodes, perform corresponding data acquisition, data encryption and decryption, and data verification.
[0007] S2. During the data encryption and decryption process, monitor the relevant behavioral data information of each execution node. After data processing, analyze the behavioral status of each execution node under the corresponding environmental conditions, and use the majority voting principle to initially judge the abnormal conditions of each execution node and determine the abnormal execution nodes;
[0008] S3. According to the abnormal execution nodes obtained in S2, extract the redundant node status corresponding to the abnormal execution nodes. By performing test operations on the redundant nodes, analyze the performance status of each redundant node during the current period to construct a comprehensive performance evaluation function X and generate an alternative set;
[0009] S4. According to the alternative set, start a polling mechanism to automatically select suitable redundant nodes, and dynamically adjust the polling frequency Fc according to the load-bearing situation of the selected suitable redundant nodes.
[0010] Preferably, the specific steps of S1 include:
[0011] S11. Deploy several groups of execution nodes in the distributed network in advance. Among them, several groups of execution nodes are divided according to functions to divide data owner nodes, encryption nodes, decryption nodes, and verification nodes, and use the TCP protocol in network communication technology to interconnect each execution node and set the communication parameters between nodes. The communication parameters include IP address allocation and port number setting;
[0012] S12. Initialize the functions of each execution node, clarify the role of each execution node in the entire encryption, decryption, and verification processes, configure a data acquisition interface for the data acquisition node, and at the same time configure the corresponding encryption algorithm library and key management module for the encryption node, set the decryption algorithm and key acquisition mechanism for the decryption node, configure the verification rules and algorithms for data integrity and correctness for the verification node, and then establish the data transmission and interaction processes between each execution node.
[0013] Preferably, the specific steps of S2 include:
[0014] S21. During the data encryption and decryption process, monitor the relevant behavioral data information of each execution node. Among them, the relevant behavioral data information of each execution node includes collecting the processing duration Csc and processing error rate Cz of each execution node in the normal working state, and the processing duration of each execution node in the current working state and the processing error rate ;
[0015] S22. Based on the relevant behavioral data information of each execution node obtained in S21, eliminate outliers and fill in missing values for the relevant behavioral data information of each execution node, and use statistical algorithms to calculate the standard deviation of the relevant behavioral data information of each execution node to respectively obtain the average processing duration , standard deviation of processing duration , average processing error rate and standard deviation of processing error rate , based on the average processing duration , standard deviation of processing duration , average processing error rate and standard deviation of processing error rate , respectively set the first threshold and the second threshold , the first threshold and the second threshold are expressed as: where K is a constant;
[0016] S23. According to the first threshold and the second threshold obtained in S22, combined with the processing duration and processing error rate of each execution node in the current working state obtained in S21, obtain the difference factor Y of each execution node, which is specifically obtained through the following formula:
[0017]
[0018] In the formula, and are both indicator functions.
[0019] Preferably, the specific steps of S2 further include:
[0020] S24. Send the data to be encrypted obtained by the data owner node to multiple groups of encryption nodes to obtain multiple groups of encryption results, and count the occurrence frequency of each group of encryption results. Using the majority voting principle, judge the normal situation of the encryption results. If the occurrence frequency of the encryption results exceeds the of the encryption nodes, it indicates that the encryption results of the corresponding encryption nodes are normal results; if the occurrence frequency of the encryption results does not exceed the of the encryption nodes, it indicates that the encryption results of the corresponding encryption nodes are abnormal results, and mark the corresponding encryption nodes as preliminary abnormal nodes;
[0021] S25. Extract the encryption results with normal results from S24, and send the encryption results with normal results to multiple groups of decryption nodes to obtain multiple groups of decryption results, and count the occurrence frequency of each group of decryption results. Using the majority voting principle again, judge the normal situation of the decryption results. If the occurrence frequency of the decryption results exceeds the of the decryption nodes, it indicates that the decryption results of the corresponding decryption nodes are normal results; if the occurrence frequency of the decryption results does not exceed the When it is, it indicates that the decryption result of the corresponding decryption node is an abnormal result, and the corresponding decryption node is marked as a preliminary abnormal node together;
[0022] S26. Extract the decryption results with normal results from S25, and send the decryption results with normal results to multiple groups of verification nodes to obtain multiple groups of verification results, and count the occurrence frequency of each group of verification results. Once again, use the majority voting principle to judge the normal situation of the verification results. If the occurrence frequency of the verification results exceeds the When it is, it indicates that the verification result of the corresponding verification node is a normal result; if the occurrence frequency of the verification results does not exceed the When it is, it indicates that the verification result of the corresponding verification node is an abnormal result, and the corresponding verification node is marked as a preliminary abnormal node together.
[0023] Preferably, the specific steps of S2 further include:
[0024] S27. Based on the preliminary abnormal nodes obtained in S24 to S26, and combined with the difference factor Y of each execution node in S23, extract the difference factor Y of each preliminary abnormal node, and according to the numerical size of the difference factor Y of each preliminary abnormal node, secondarily judge the abnormal situation of each preliminary abnormal node. If the numerical size of the difference factor Y of the preliminary abnormal node is 2, then judge the corresponding preliminary abnormal node as an abnormal execution node.
[0025] Preferably, the specific steps of S3 include:
[0026] S31. According to the abnormal execution nodes obtained in S2, determine multiple groups of redundant nodes corresponding to the abnormal execution nodes. By performing test operations on each redundant node, monitor the performance data of each redundant node, where the performance data includes the encryption speed Js of each redundant node for processing files of different sizes and the encryption efficiency Jx of each redundant node for different types of data.
[0027] Preferably, the specific steps of S3 further include:
[0028] S32. Based on the performance data, analyze the performance status of each redundant node in the current period, and after dimensionless processing, construct a comprehensive performance evaluation function X. The comprehensive performance evaluation function X is obtained through the following formula:
[0029]
[0030] In the formula, represents the encryption speed of the corresponding file processed in the current period, represents the maximum encryption speed, represents the priority of data encryption, and both represent weight values, where, and The specific numerical value is set by the user according to the situation.
[0031] Preferably, the specific steps of S3 further include:
[0032] S33. Preset an evaluation threshold Q, and compare the evaluation threshold Q with the comprehensive performance evaluation function X to generate an alternative set, which has the following content:
[0033] If the comprehensive performance evaluation function X ≥ the evaluation threshold Q, at this time, the corresponding redundant nodes are included in the alternative set to prepare for the subsequent screening of alternative nodes;
[0034] If the comprehensive performance evaluation function X < the evaluation threshold Q, at this time, the corresponding redundant nodes are not included in the alternative set for the time being.
[0035] Preferably, the specific steps of S4 include:
[0036] S41. By maintaining a usage counter for each group of redundant nodes in advance, which is initialized to 0, each time a redundant node is selected as an alternative node, the value of the corresponding usage counter will be incremented by one. Combining with the alternative set, determine the value size of the usage counter corresponding to each redundant node in the alternative set, and extract the redundant node with the smallest usage counter value as the alternative node to replace the abnormal execution node in S27;
[0037] S42. Based on the alternative node obtained in S41, monitor the load-bearing situation of the alternative node in real time, and dynamically adjust the polling frequency Fc according to the load-bearing situation. The specific adjustment content is as follows:
[0038]
[0039] In the formula, represents the average polling frequency of the alternative node in the historical period, represents the current load of the alternative node, represents the average load of the alternative node in the historical period, represents the load imbalance threshold, represents the correction constant.
[0040] An encryption and decryption verification system based on a distributed network includes a preparation unit, an anomaly analysis unit, an alternative unit, and an optimization and adjustment unit;
[0041] The preparation unit is used to deploy several groups of execution nodes in the distributed network in advance, and interconnect each execution node to perform communication operations, and perform corresponding data acquisition, data encryption and decryption, and data verification based on the several groups of execution nodes;
[0042] The anomaly analysis unit is used to monitor the relevant behavior data information of each execution node during the data encryption and decryption process. After data processing, it analyzes the behavior status of each execution node under the corresponding environmental conditions, and uses the majority voting principle to preliminarily judge the anomaly situation of each execution node and determine the abnormal execution node;
[0043] The replacement unit is used to extract the redundant node status corresponding to the abnormal execution node according to the obtained abnormal execution node. By performing test operations on the redundant nodes, it analyzes the performance status of each redundant node during the current period to construct a comprehensive performance evaluation function X and generate a replacement set;
[0044] The optimization and adjustment unit is used to start a polling mechanism according to the replacement set, automatically select the appropriate redundant nodes, and dynamically adjust the polling frequency Fc according to the load-bearing situation of the selected appropriate redundant nodes.
[0045] The present invention provides a method and system for encryption and decryption verification based on a distributed network, having the following beneficial effects:
[0046] (1) During the data encryption and decryption process, comprehensively monitor the relevant behavior data of the execution nodes. After data processing, deeply analyze their behavior status under specific environments. Using the majority voting principle, comprehensively judge based on multiple aspects of information. Compared with single-index judgment, it can more accurately identify abnormal execution nodes, greatly reduce the misjudgment probability, and provide strong support for timely discovery and solution of potential problems. For the identified abnormal execution nodes, extract their corresponding redundant node status, and through test operations, carefully analyze the performance status of the redundant nodes during the current period, and then construct a comprehensive performance evaluation function X. This function comprehensively considers various performance factors, objectively and scientifically evaluates the capabilities of redundant nodes, and the generated replacement set lays a solid foundation for subsequent selection of appropriate replacement nodes. Based on the replacement set, start a polling mechanism, automatically select the appropriate redundant nodes as replacement nodes, and dynamically adjust the polling frequency Fc according to the load-bearing situation of the selected redundant nodes. This mechanism fully considers the real-time load of the nodes, further reduces the overloading of some nodes, rationally utilizes the resources of other nodes, and achieves load balancing. At the same time, it can be flexibly adjusted according to the actual situation to ensure that the system can operate efficiently under different load conditions, improving the overall performance and adaptability of the system.
[0047] (2) Distribute the data to be encrypted to multiple groups of encryption nodes. By statistically analyzing the occurrence frequency of the encryption results, determine their normality based on the majority voting principle. If the occurrence frequency of a certain encryption result exceeds a certain proportion of the encryption nodes, it is considered normal; otherwise, mark the corresponding encryption node as preliminarily abnormal. This prepares for subsequent problems where the encryption results may be unreliable due to the failure or error of a single encryption node, ensuring the quality of the encrypted data from the source. The decryption and verification links are strictly controlled: send the normal encryption results to multiple groups of decryption nodes, and also perform frequency statistics and majority voting judgment on the decryption results. After screening out the normal decryption results, send them to multiple groups of verification nodes, and repeat this process to ensure the accuracy of the decryption and verification links, and promptly detect and isolate abnormal decryption and verification nodes, ensuring the reliability of the data at each processing stage and reducing the risk of incorrect data entering the next link. Comprehensive analysis to avoid misjudgment: After obtaining the preliminarily abnormal nodes in the encryption, decryption, and verification links, perform a secondary judgment in combination with the previously calculated difference factor Y. This multi-dimensional analysis method avoids misjudgments that may occur by simply relying on majority voting, as majority voting may be affected by the number of nodes or accidental factors. Precise positioning and efficient maintenance: Based on the value of the difference factor Y of the preliminarily abnormal nodes, determine that when the difference factor Y is 2, it is an abnormal execution node. Precise positioning of abnormal nodes helps the operation and maintenance personnel quickly lock down the problem.
[0048] (3) Quickly lock in backup resources: When an abnormal execution node is detected, it is possible to quickly determine its corresponding multiple groups of redundant nodes, which ensures that the system can promptly call backup resources in the face of node failures, maintaining the continuity of the encryption and decryption operations, further enhancing the fault tolerance of the system, and avoiding service interruptions caused by single-point failures. Multi-dimensional performance data collection: Conduct test operations on the redundant nodes to collect the encryption speed for processing files of different sizes and the encryption efficiency for different types of data. This multi-dimensional performance monitoring comprehensively reflects the performance of the redundant nodes in actual application scenarios, providing a rich and accurate data basis for subsequent performance evaluations and helping to deeply understand the characteristics of each redundant node. Deeply analyze the performance status: Based on the collected performance data, deeply analyze the performance status of the redundant nodes in the current period, not only to know the current performance of the nodes but also to understand the performance change trends under different task conditions, providing strong support for reasonably evaluating the node performance.
[0049] (4) By setting the evaluation threshold Q and comparing it with the comprehensive performance evaluation function X, only the redundant nodes for which the comprehensive performance evaluation function X ≥ evaluation threshold Q will be included in the replacement set. This operation is like a strict quality checkpoint, ensuring that the redundant nodes entering the replacement set have sufficient performance to meet the basic requirements of the system for replacement nodes when a node fails, providing guarantee for the stable operation of the system from the source and avoiding the decline of system performance caused by including low-performance redundant nodes. Optimize the reserve of replacement nodes: To make full preparations for screening suitable replacement nodes subsequently, a high-quality candidate node library is constructed. In this way, when the system faces abnormal execution nodes, it can quickly select a suitable replacement from this set, reducing the time cost of finding a suitable replacement node and ensuring that the encryption and decryption verification process of the system can quickly return to normal, enhancing the fault tolerance and recovery ability of the system. Balance the use of redundant nodes: Maintain a usage counter for each group of redundant nodes, with an initial value of 0. Each time a redundant node is selected as a replacement node, the counter is incremented by one. In this way, the system preferentially selects the redundant node with the smallest counter value of the usage counter as the replacement node, effectively avoiding excessive wear of some redundant nodes due to frequent use, while also enabling other redundant nodes to be fully utilized, achieving the equalization of the usage frequency of redundant nodes, extending the service life of the entire redundant node system, and improving the utilization rate of system resources. Dynamically adapt to load changes: Real-time monitor the load-bearing situation of replacement nodes and dynamically adjust the polling frequency Fc according to load changes. When the load changes, the system can automatically adjust the usage frequency of replacement nodes, reducing the task allocation for nodes with heavy loads and increasing the task processing for nodes with light loads, thus effectively avoiding performance bottlenecks or failures of nodes due to overloading and ensuring that the system can maintain efficient and stable operation under different load conditions, enhancing the adaptive ability and overall stability of the system. Description of the Drawings
[0050] Figure 1 It is a schematic flowchart of a method for encryption and decryption verification based on a distributed network according to the present invention.
[0051] Figure 2 It is a block diagram of a system for encryption and decryption verification based on a distributed network according to the present invention. Detailed Embodiments
[0052] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0053] Embodiment 1
[0054] Please refer toFigure 1 , the present invention provides an encryption and decryption verification method based on a distributed network, including the following steps,
[0055] S1. Deploy a number of groups of execution nodes in the distributed network in advance, and interconnect each execution node to perform communication operations. Based on the number of groups of execution nodes, perform corresponding data acquisition, data encryption and decryption, and data verification;
[0056] S2. During the data encryption and decryption process, monitor the relevant behavior data information of each execution node. After data processing, analyze the behavior status of each execution node under the corresponding environmental conditions, and use the majority voting principle to initially judge the abnormal conditions of each execution node and determine the abnormal execution nodes;
[0057] S3. According to the abnormal execution nodes obtained in S2, extract the redundant node status corresponding to the abnormal execution nodes. By performing test operations on the redundant nodes, analyze the performance status of each redundant node during the current period to construct a comprehensive performance evaluation function X and generate an alternative set;
[0058] S4. According to the alternative set, start a polling mechanism, automatically select an adapted redundant node (replacement node), and dynamically adjust the polling frequency Fc according to the load-bearing situation of the selected adapted redundant node.
[0059] In this embodiment, the stability of the system is ensured as follows: By pre-deploying multiple groups of execution nodes in a distributed network and enabling interconnection and communication, a relatively complete distributed architecture is constructed. Under this architecture, each execution node collaborates to perform data acquisition, encryption / decryption, and verification tasks, forming an organic whole. When some nodes encounter abnormalities, the entire system can still rely on other normal nodes to maintain operation, maximizing the stability and fault tolerance of the system and avoiding the interruption of the entire encryption / decryption and verification process due to the failure of a single node. Accurately identifying abnormal nodes: During the data encryption / decryption process, the relevant behavioral data of each execution node is monitored, and through data processing, its behavioral state under corresponding environmental conditions is analyzed in depth. The majority voting principle is used for preliminary judgment, which can accurately identify abnormal execution nodes. Compared with the traditional single-index judgment method, this method can consider node behaviors more comprehensively and comprehensively, effectively reducing the misjudgment rate, ensuring the timely discovery and location of potential problem nodes, and providing an accurate basis for subsequent processing. Scientifically evaluating redundant nodes: For the identified abnormal execution nodes, the corresponding redundant node status is extracted, and the redundant nodes are tested. The performance status of the redundant nodes during the current period is comprehensively analyzed, and then a comprehensive performance evaluation function X is constructed. This function comprehensively considers various performance factors of the redundant nodes and can evaluate the actual capabilities of the redundant nodes more scientifically and objectively. The generated alternative set based on this provides a high-quality candidate range for selecting appropriate alternative nodes in the future. Dynamically optimizing node selection: Based on the alternative set, a polling mechanism is started to automatically select suitable redundant nodes as alternative nodes, and the polling frequency Fc is dynamically adjusted according to the load-bearing capacity of the selected redundant nodes. This method fully considers the real-time load conditions of the nodes, avoids over-relying on some nodes with better performance and causing their overloading, and also enables other nodes to be reasonably utilized, achieving load balancing. This not only improves the utilization rate of system resources but also can be flexibly adjusted according to the actual situation to ensure that the system can maintain efficient operation under different load conditions, further enhancing the overall performance and adaptability of the system. In summary, through the collaborative operation of multiple steps, from system architecture construction, abnormal node identification, redundant node evaluation to dynamic node selection, this method comprehensively ensures the stability, accuracy, and efficiency of the encryption / decryption and verification process in a distributed network, and has extremely high practical value and application prospects.
[0060] Embodiment 2
[0061] Please refer to Figure 1 , specifically: The specific steps of S1 include:
[0062] S11. Pre-deploy several groups of execution nodes in the distributed network. Among them, the several groups of execution nodes are divided according to functions to divide out data owner nodes, encryption nodes, decryption nodes, and verification nodes. Then, use the TCP protocol in network communication technology to interconnect each execution node and set the communication parameters between nodes. The communication parameters include IP address allocation and port number setting to build a stable communication network, providing a basis for subsequent data interaction.
[0063] S12. Initialize the functions of each execution node, clarify the role of each execution node in the entire encryption, decryption, and verification process, and configure a data acquisition interface for the data acquisition node so that it can obtain the data to be processed from a specified data source (such as a database, file system, etc.). At the same time, configure the corresponding encryption algorithm library and key management module for the encryption node so that it can perform encryption operations after receiving the data; set the decryption algorithm and key acquisition mechanism for the decryption node, and configure the verification rules and algorithms for data integrity and correctness for the verification node. Then, establish the data transmission and interaction process between each execution node to ensure that the data flows between each execution node in a predetermined logical order to smoothly execute data acquisition, data encryption / decryption, and data verification tasks.
[0064] Among them, the key management module is responsible for securely storing the keys required for encryption and decryption. In the symmetric encryption algorithm, it stores the symmetric key; in the asymmetric encryption algorithm, it stores the public key and private key pair. To ensure the security of the keys, the storage method usually uses a variety of encryption technologies. For example, use a hardware security module (HSM) to store the keys in a dedicated hardware device, which has physical and logical protection mechanisms to prevent unauthorized access, or use software encryption storage to encrypt the keys and store them in a protected storage area, and only access can be obtained through specific authentication and authorization procedures.
[0065] The specific steps of S2 include:
[0066] S21. During the data encryption and decryption process, monitor the relevant behavior data information of each execution node. Among them, the relevant behavior data information of each execution node includes collecting the processing duration Csc and processing error rate Cz of each execution node in the normal working state, and the processing duration and processing error rate ;
[0067] Among them, the processing duration Csc is the time taken for an execution node to complete an encryption / decryption or verification task, which is the time difference between the start time point of processing the task and the completion time point of the task, and is monitored and obtained through a software timer.
[0068] The processing error rate Cz represents the probability that an execution node makes an error when processing encryption / decryption or verification tasks, and can be monitored and obtained through a built-in error counter;
[0069] S22. Based on the relevant behavior data information of each execution node obtained in S21, eliminate outliers and fill in missing values for the relevant behavior data information of each execution node, and use statistical algorithms to calculate the standard deviation of the relevant behavior data information of each execution node to respectively obtain the average processing duration , the standard deviation of the processing duration , the average processing error rate and the standard deviation of the processing error rate . Based on the average processing duration , the standard deviation of the processing duration , the average processing error rate and the standard deviation of the processing error rate , respectively set the first threshold and the second threshold . The first threshold and the second threshold are expressed in the form of: where K is a constant, usually taking values from 1 to 3, corresponding to different confidence levels respectively, and the specific values are set by the user (according to the actual situation);
[0070] S23. According to the first threshold and the second threshold obtained in S22, combined with the processing duration and the processing error rate of each execution node in the current working state obtained in S21, obtain the difference factor Y of each execution node, which is specifically obtained through the following formula:
[0071]
[0072] In the formula, and are both indicator functions. When , = 1; when , = 1.
[0073] In this embodiment, precise node function division: in a distributed network, the execution nodes are carefully divided into data owner nodes, encryption nodes, decryption nodes and verification nodes, and each node performs its own duties, providing a clear architecture for the data encryption, decryption and verification process. The TCP protocol is used to interconnect nodes and carefully set communication parameters to build a stable communication network to ensure efficient data transmission between nodes, laying a solid foundation for subsequent operations. Comprehensive functional initialization: each execution node is functionally initialized, roles are clarified, and functional modules are configured for different nodes in a targeted manner, such as configuring corresponding algorithm libraries and key management mechanisms for encryption and decryption nodes, setting verification rules and algorithms for verification nodes, and establishing a data transmission process to ensure that data flows according to the predetermined logic, so that the entire encryption, decryption and verification tasks can be smoothly executed. Comprehensive data collection: in the process of data encryption and decryption, key behavioral data such as processing time and processing error rate of each execution node in normal and current working states are comprehensively collected to provide rich information for subsequent analysis. Accurate difference factor calculation: Based on the threshold and current working status data, the difference factor Y of each execution node is calculated, and the difference between the node operation status and the normal status is accurately quantified, which helps to timely and accurately discover the abnormal situation of the execution node and ensure the stable operation of the encryption, decryption and verification process.
[0074] Example 3
[0075] Please refer to Figure 1 , specifically: S2 specific steps also include:
[0076] S24, send the encrypted data obtained by the data owner node to multiple groups of encryption nodes to obtain multiple groups of encryption results, and count the frequency of occurrence of each group of encryption results, and use the majority voting principle to judge the normal situation of the encryption results. If the frequency of occurrence of the encryption result exceeds the encryption node's , it indicates that the encryption result of the corresponding encryption node is normal; if the frequency of the encryption result does not exceed the encryption node's , it indicates that the encryption result of the corresponding encryption node is an abnormal result, and the corresponding encryption node is marked as a preliminary abnormal node;
[0077] S25, extract the encryption results with normal results from S24, and send the encryption results with normal results to multiple groups of decryption nodes to obtain multiple groups of decryption results, and count the frequency of occurrence of each group of decryption results, and use the majority voting principle again to judge the normality of the decryption results. If the frequency of occurrence of the decryption results exceeds the decryption node's , it indicates that the decryption result of the corresponding decryption node is normal; if the occurrence frequency of the decryption result does not exceed the of the decryption node , it indicates that the decryption result of the corresponding decryption node is an abnormal result, and the corresponding decryption node is also marked as a preliminary abnormal node;
[0078] S26. Extract the decryption results with normal results from S25, send the decryption results with normal results to multiple groups of verification nodes to obtain multiple groups of verification results, and count the occurrence frequencies of each group of verification results. Then, use the majority voting principle again to judge the normal situation of the verification results. If the occurrence frequency of the verification results exceeds the of the verification nodes, it indicates that the verification results of the corresponding verification nodes are normal results; if the occurrence frequency of the verification results does not exceed the of the verification nodes, it indicates that the verification results of the corresponding verification nodes are abnormal results, and mark the corresponding verification nodes as preliminary abnormal nodes together.
[0079] The specific steps of S2 also include:
[0080] S27. Based on the preliminary abnormal nodes obtained in S24 to S26, and combined with the difference factor Y of each execution node in S23, extract the difference factor Y of each preliminary abnormal node, and according to the numerical size of the difference factor Y of each preliminary abnormal node, judge the abnormal situation of each preliminary abnormal node again. If the numerical size of the difference factor Y of the preliminary abnormal node is 2, then judge the corresponding preliminary abnormal node as an abnormal execution node.
[0081] In this embodiment, the reliability judgment of the encryption result: The data to be encrypted of the data owner node is sent to multiple groups of encryption nodes. By counting the frequency of the encryption results and using the majority voting principle to judge whether the encryption results are normal. If the frequency exceeds a certain proportion of the encryption nodes, it is considered a normal result; otherwise, it is an abnormal result and the corresponding encryption nodes are marked as preliminary abnormal nodes. This process can timely detect possible errors in the encryption link, ensure the reliability of the encrypted data, and prevent incorrectly encrypted data from flowing into the subsequent process. Precise determination of decryption and verification results: When decrypting and verifying the normal encryption results, the majority voting principle is also used to judge the normality of the decryption and verification results. By sending the normal encryption results to multiple groups of decryption nodes and the normal decryption results to multiple groups of verification nodes, counting the frequency of the results, and judging the working status of the corresponding nodes, this multi-round detection mechanism ensures the accuracy of the data in each link of encryption, decryption, and verification layer by layer, and effectively reduces the risk of incorrect data passing through. Secondary judgment combined with the difference factor: Based on the preliminary abnormal nodes marked in the encryption, decryption, and verification links, combined with the difference factor Y of each execution node calculated previously, the difference factor Y of the preliminary abnormal nodes is extracted. According to the magnitude of the difference factor Y value, the abnormal situation is judged secondly. If the difference factor Y value is 2, the corresponding preliminary abnormal node is determined as an abnormal execution node. This method of comprehensively considering the difference factor of behavioral data and the majority voting result avoids the limitations of a single judgment method, improves the accuracy and reliability of abnormal node identification, can more accurately locate the nodes with real problems, provides a reliable basis for taking targeted measures subsequently, and ensures the stable operation of the distributed network encryption, decryption, and verification system.
[0082] Embodiment 4
[0083] Please refer to Figure 1 , specifically: The specific steps of S3 include:
[0084] S31. According to the abnormal execution nodes obtained in S2, determine multiple groups of redundant nodes corresponding to the abnormal execution nodes. By performing test operations on each redundant node, monitor the performance data of each redundant node. Among them, the performance data includes the encryption speed Js of each redundant node for processing files of different sizes and the encryption efficiency Jx of each redundant node for different types of data.
[0085] The specific steps of S3 also include:
[0086] S32. Based on the performance data, analyze the performance status of each redundant node in the current period, and after dimensionless processing, construct a comprehensive performance evaluation function X. The comprehensive performance evaluation function X is obtained through the following formula:
[0087]
[0088] In the formula, Indicates the encryption speed of the corresponding file processed in the current period. Indicates the maximum encryption speed. Indicates the priority of data encryption. And Both represent weight values, where 0 < < 1, 0 < < 1, And The specific values are set by the user according to the situation.
[0089] The above-mentioned encryption speed of the corresponding file processed in the current period Refers to the amount of data processed per unit time when the execution node encrypts the file within the current time range. When the encryption node starts to process the file, the start timestamp and the initial number of bytes of the processed file are recorded. When a part of the file is processed, the end timestamp and the number of bytes of the currently processed file are recorded. The encryption speed is obtained by calculating the difference in the number of bytes divided by the time difference.
[0090] The priority of data encryption Indicates the urgency of different encryption tasks. In the task scheduling system, a priority field can be set for each encryption task, and the priority is assigned according to the urgency of the task when the task is generated.
[0091] In this embodiment, accurately locate redundant nodes: According to the detected abnormal execution nodes, quickly determine multiple groups of corresponding redundant nodes, providing a strong guarantee for the rapid recovery and continuous stable operation of the system. This process can promptly start backup resources to ensure that data encryption and decryption tasks are not affected. Multi-dimensional performance monitoring: Conduct test operations on each redundant node, and carefully monitor its encryption speed for processing files of different sizes and the encryption efficiency for different types of data. Comprehensive data collection helps to deeply understand the performance of redundant nodes in different scenarios, providing rich and accurate basis for subsequent evaluation and selection. In-depth analysis of performance status: Based on the collected performance data, deeply analyze the performance status of each redundant node in the current period. Through this detailed analysis, the changing trend of node performance over time and task types can be grasped, providing support for reasonably evaluating node performance. Dimensionless processing and comprehensive evaluation: After dimensionless processing, a comprehensive performance evaluation function is constructed, eliminating the influence brought by the dimensional differences of different performance indicators, making each indicator comparable. This function comprehensively evaluates the performance of redundant nodes by considering the proportional relationship between the encryption speed of the corresponding file processed in the current period and the maximum encryption speed, as well as factors such as the priority of data encryption, providing a reliable basis for selecting relatively suitable redundant nodes to replace abnormal execution nodes, ensuring that the system can still operate efficiently in a complex and changeable task environment.
[0092] Example 5
[0093] Please refer to Figure 1 , specifically: The specific steps of S3 also include:
[0094] S33. Preset an evaluation threshold Q, and compare the evaluation threshold Q with the comprehensive performance evaluation function X to generate an alternative set, which has the following content:
[0095] When the comprehensive performance evaluation function X ≥ the evaluation threshold Q, at this time, incorporate the corresponding redundant nodes into the alternative set to prepare for the subsequent screening of alternative nodes;
[0096] When the comprehensive performance evaluation function X < the evaluation threshold Q, at this time, do not incorporate the corresponding redundant nodes into the alternative set for the time being.
[0097] The specific steps of S4 include:
[0098] S41. By maintaining a usage counter for each group of redundant nodes in advance, initialized to 0, each time a redundant node is selected as an alternative node, the value of the corresponding usage counter will be incremented by one. Combine with the alternative set to determine the magnitude of the values of the usage counters corresponding to each redundant node in the alternative set, and extract the redundant node with the smallest usage counter value as the alternative node to replace the abnormal execution node in S27;
[0099] S42. Based on the alternative node obtained in S41, monitor the load-bearing situation of the alternative node in real time, and dynamically adjust the polling frequency Fc according to the load-bearing situation. The specific adjustment content is as follows:
[0100]
[0101] In the formula, represents the average polling frequency of the alternative node in the historical period, represents the current load of the alternative node, represents the average load of the alternative node in the historical period, represents the load imbalance threshold, represents a correction constant to avoid the denominator being zero, represents the adjustment coefficient;
[0102] The above-mentioned current load of the alternative node refers to the number of tasks currently being processed by the alternative node. Use specialized distributed monitoring tools, such as Zabbix, Nagios, etc., to detect the number of tasks currently being processed by the alternative node.
[0103] When the current load of the alternative node is equal to the average load of the alternative node in the historical period (i.e., ), = 0, the adjustment coefficient is 1, and at this time = , the polling frequency of the replacement node remains unchanged; when the current load of the replacement node is greater than the average load of the replacement node in the historical period, the adjustment coefficient is less than 1, and the polling frequency of the replacement node decreases. Moreover, the more the load deviates from the average load, the more the polling frequency decreases. Conversely, when the current load of the replacement node is less than the average load of the replacement node in the historical period, the adjustment coefficient is greater than 1, and the polling frequency of the replacement node increases.
[0104] In this embodiment, by comparing the threshold value with the comprehensive performance evaluation function, the redundant nodes that meet the requirements are included in the replacement set. This process ensures that the redundant nodes entering the replacement set meet certain performance standards, avoids nodes with poor performance from participating in the replacement, lays a foundation for screening high-quality replacement nodes subsequently, and effectively improves the overall performance of the system. Based on the counter, balanced use: By maintaining a usage counter for each group of redundant nodes, the counter is incremented by one each time a redundant node is selected as the replacement node. Selecting the redundant node with the smallest counter value in the replacement set as the replacement node can balance the usage frequency of each redundant node, prevent some nodes from being overused and accelerating aging or malfunctioning, and at the same time enable other nodes to be fully utilized, improving the overall utilization rate of system resources. Real-time monitoring and flexible adjustment: Real-time monitor the load-bearing situation of the replacement node, and dynamically adjust the polling frequency according to the formula. This formula takes into account factors such as the current load of the replacement node, the average load in the historical period, the load imbalance threshold, and the correction constant. In this way, the system can flexibly adjust the frequency at which the replacement node is selected to execute tasks according to the actual load situation of the replacement node, ensuring that the system can operate efficiently under different load conditions. Adaptive load changes and improved stability: When the current load of the replacement node is equal to the historical average load, the polling frequency remains unchanged; when the load is higher than the average, the polling frequency decreases, and the more it deviates, the more it decreases; when the load is lower than the average, the polling frequency increases. This adaptive adjustment mechanism can effectively prevent the node from experiencing performance degradation or malfunction due to excessive load, ensuring that the system always maintains stable operation in the face of various load changes, and improving the reliability and stability of the entire distributed network encryption and decryption verification system.
[0105] Embodiment 6
[0106] Please refer to Figure 2 , specifically: A distributed network-based encryption and decryption verification system, including a preparation unit, an anomaly analysis unit, a replacement unit, and an optimization and adjustment unit;
[0107] The preparation unit is used to pre-deploy several groups of execution nodes in the distributed network, and interconnect each execution node for communication operations, and based on the several groups of execution nodes, perform corresponding data acquisition, data encryption and decryption, and data verification;
[0108] The anomaly analysis unit is used to monitor the relevant behavioral data information of each execution node during the data encryption and decryption process. After data processing, it analyzes the behavioral status of each execution node under the corresponding environmental conditions, and uses the majority voting principle to preliminarily judge the anomaly situation of each execution node and determine the abnormal execution nodes;
[0109] The replacement unit is used to extract the redundant node status corresponding to the abnormal execution node according to the obtained abnormal execution node. By performing test operations on the redundant nodes, it analyzes the performance status of each redundant node during the current period to construct a comprehensive performance evaluation function X and generate a replacement set;
[0110] The optimization and adjustment unit is used to start a polling mechanism according to the replacement set, automatically select the appropriate redundant nodes, and dynamically adjust the polling frequency Fc according to the load-bearing situation of the selected appropriate redundant nodes.
[0111] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A distributed network-based encryption and decryption verification method, characterized in that: The following steps are included: S1. Deploy several groups of execution nodes in the distributed network in advance, and interconnect the execution nodes to perform communication operations. Based on the several groups of execution nodes, perform corresponding data acquisition, data encryption and decryption, and data verification; S2. During the data encryption and decryption process, monitor the relevant behavior data information of each execution node, and after data processing, set a threshold value and the second threshold , and calculate the difference factor Y of each execution node to analyze the behavior status of each execution node under the corresponding environmental conditions, and use the majority voting principle to preliminarily judge the abnormal situation of each execution node and determine the abnormal execution node; Among them, the relevant behavior data information of each execution node includes collecting the processing time Csc and processing error rate Cz of each execution node under normal working conditions, as well as the processing time of each execution node in the current working state. and processing error rate ;Data processing includes outlier removal and missing value filling; S3. According to the abnormal execution node obtained in S2, the redundant node status corresponding to the abnormal execution node is extracted, and the performance status of each redundant node in the current period is analyzed by testing the redundant node to construct a comprehensive performance evaluation function X. If the comprehensive performance evaluation function X ≥ the evaluation threshold Q, the corresponding redundant node is included in the replacement set and the replacement set is generated; S4. According to the alternative set, the polling mechanism is started to automatically select the adaptive redundant node, and the polling frequency Fc is dynamically adjusted according to the load bearing condition of the selected adaptive redundant node.
2. According to claim 1, a distributed network-based encryption and decryption verification method is characterized by: The specific steps of S1 include: S11. Deploy several groups of execution nodes in the distributed network in advance, wherein the several groups of execution nodes are divided according to functions to divide into data owner nodes, encryption nodes, decryption nodes and verification nodes, and use the TCP protocol in network communication technology to interconnect the execution nodes, and set communication parameters between the nodes, including IP address allocation and port number setting; S12. Initialize the functions of each execution node, clarify the role of each execution node in the entire encryption, decryption and verification process, configure the data collection interface for the data acquisition node, configure the corresponding encryption algorithm library and key management module for the encryption node, set the decryption algorithm and key acquisition mechanism for the decryption node, configure the verification rules and algorithms for data integrity and correctness for the verification node, and then establish the data transmission and interaction process between the execution nodes.
3. The encryption and decryption verification method based on a distributed network according to claim 2 is characterized in that: The specific steps of S2 include: S21. During the data encryption and decryption process, monitor the relevant behavior data information of each execution node; S22: Based on the relevant behavior data information of each execution node obtained in S21, outliers are removed and missing values are filled in for the relevant behavior data information of each execution node, and the standard deviation of the relevant behavior data information of each execution node is calculated using a statistical algorithm to obtain the average processing time. , Standard deviation of processing time , average processing error rate and standard deviation of processing error rate , based on the average processing time , Standard deviation of processing time , average processing error rate and standard deviation of processing error rate , set the threshold No. and the second threshold , threshold number one and the second threshold The expression is: Where K is a constant; S23, according to the No. 1 threshold value obtained in S22 and the second threshold , combined with the processing time of each execution node under the current working state obtained in S21 and processing error rate , obtain the difference factor Y of each execution node, which is obtained by the following formula: In the formula, and Both are indicator functions.
4. The encryption and decryption verification method based on a distributed network according to claim 3 is characterized in that: The specific steps of S2 also include: S24, sending the data to be encrypted obtained by the data owner node to multiple groups of encryption nodes to obtain multiple groups of encryption results, and counting the frequency of occurrence of each group of encryption results, using the majority voting principle to determine the normality of the encryption results, if the frequency of occurrence of the encryption result exceeds the encryption node , it indicates that the encryption result of the corresponding encryption node is normal; If the frequency of occurrence of the encrypted result does not exceed the frequency of the encrypted node When , it indicates that the encryption result of the corresponding encryption node is an abnormal result, and the corresponding encryption node is marked as a preliminary abnormal node; S25, extract the encryption result with normal result from S24, and send the encryption result with normal result to multiple groups of decryption nodes to obtain multiple groups of decryption results, and count the occurrence frequency of each group of decryption results, and use the majority voting principle again to judge the normality of the decryption result. If the occurrence frequency of the decryption result exceeds the decryption node , it indicates that the decryption result of the corresponding decryption node is normal; If the occurrence frequency of the decryption result does not exceed the decryption node , it indicates that the decryption result of the corresponding decryption node is an abnormal result, and the corresponding decryption node is also marked as a preliminary abnormal node; S26, extract the normal decryption result from S25, and send the normal decryption result to multiple groups of verification nodes to obtain multiple groups of verification results, and count the frequency of occurrence of each group of verification results, and use the majority voting principle again to judge the normality of the verification results. If the frequency of occurrence of the verification result exceeds the verification node When , it indicates that the verification result of the corresponding verification node is normal; If the frequency of the verification result does not exceed the verification node , it indicates that the verification result of the corresponding verification node is an abnormal result, and the corresponding verification node is also marked as a preliminary abnormal node.
5. The encryption and decryption verification method based on a distributed network according to claim 4 is characterized in that: The specific steps of S2 also include: S27. Based on the preliminary abnormal nodes obtained in S24 to S26 and in combination with the difference factor Y of each execution node in S23, the difference factor Y of each preliminary abnormal node is extracted, and according to the numerical value of the difference factor Y of each preliminary abnormal node, the abnormal situation of each preliminary abnormal node is judged twice. If the numerical value of the difference factor Y of the preliminary abnormal node is 2, the corresponding preliminary abnormal node is judged to be an abnormal execution node.
6. The encryption and decryption verification method based on a distributed network according to claim 5 is characterized in that: The specific steps of S3 include: S31. According to the abnormal execution nodes obtained in S2, multiple groups of redundant nodes corresponding to the abnormal execution nodes are determined, and the performance data of each redundant node is monitored by testing each redundant node, wherein the performance data includes the encryption speed Js of each redundant node for processing files of different sizes and the encryption efficiency Jx of each redundant node for different types of data.
7. The encryption and decryption verification method based on a distributed network according to claim 6 is characterized in that: The specific steps of S3 also include: S32. Based on the performance data, the performance status of each redundant node in the current period is analyzed, and after dimensionless processing, a comprehensive performance evaluation function X is constructed. The comprehensive performance evaluation function X is obtained by the following formula: In the formula, Indicates the encryption speed of the corresponding files processed in the current period. Indicates the maximum encryption speed, Indicates the priority of data encryption. and All represent weight values, among which, and The specific value is set by the user according to the situation.
8. The encryption and decryption verification method based on a distributed network according to claim 7, characterized in that: The specific steps of S3 also include: S33, pre-set an evaluation threshold Q, and compare the evaluation threshold Q with the comprehensive performance evaluation function X to generate a replacement set, which has the following content: If the comprehensive performance evaluation function X ≥ the evaluation threshold Q, the corresponding redundant nodes are included in the replacement set to prepare for the subsequent selection of replacement nodes; If the comprehensive performance evaluation function X is less than the evaluation threshold Q, the corresponding redundant node will not be included in the replacement set temporarily.
9. The encryption and decryption verification method based on a distributed network according to claim 8, characterized in that: The specific steps of S4 include: S41, by pre-maintaining a usage counter for each group of redundant nodes, initialized to 0, each time a redundant node is selected as a replacement node, the value of the corresponding usage counter will be increased by one, combined with the replacement set, the value of the usage counter corresponding to each redundant node in the replacement set is determined, and the redundant node with the smallest usage counter value is extracted as the replacement node to replace the abnormal execution node in S27; S42, based on the alternative node obtained in S41, monitor the load bearing condition of the alternative node in real time, and dynamically adjust the polling frequency Fc according to the load bearing condition. The specific adjustment content is as follows: In the formula, represents the average polling frequency of the alternative node in the historical period, Indicates the current load of the alternative node, represents the average load of the replacement node in the historical period, Indicates the load imbalance threshold. Represents the correction constant.
10. An encryption and decryption verification system based on a distributed network, used to implement an encryption and decryption verification method based on a distributed network as described in any one of claims 1 to 9 above, characterized in that: It includes preparation unit, abnormality analysis unit, substitution unit and optimization and adjustment unit; The preparation unit is used to deploy several groups of execution nodes in the distributed network in advance, and interconnect the execution nodes to perform communication operations, and perform corresponding data acquisition, data encryption and decryption, and data verification based on the several groups of execution nodes; The abnormal analysis unit is used to monitor the relevant behavior data information of each execution node during the data encryption and decryption process, analyze the behavior status of each execution node under the corresponding environmental conditions after data processing, and use the majority voting principle to preliminarily judge the abnormal situation of each execution node and determine the abnormal execution node; The replacement unit is used to extract the redundant node status corresponding to the abnormal execution node according to the acquired abnormal execution node, and analyze the performance status of each redundant node in the current period by testing the redundant node, so as to construct a comprehensive performance evaluation function X and generate a replacement set; The optimization and adjustment unit is used to start the polling mechanism according to the alternative set, automatically select the adaptive redundant node, and dynamically adjust the polling frequency Fc according to the load bearing condition of the selected adaptive redundant node.
Citation Information
Patent Citations
Information processing method and device
CN108769073A
Access endpoint switching method and device, electronic equipment and storage medium
CN116647572A