A communication data leakage protection method in cloud computing environment

By obtaining communication instructions in the cloud computing platform for risk inspection and real-time protection parameters collection, combining risk prediction channels and constraint step adjustment, an optimized communication protection mechanism is built, which solves the problem of poor communication link protection in the cloud computing environment, and reduces the risk of data leakage and improves security.

CN119892453BActive Publication Date: 2025-08-15WUXI HUAFAN INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510041792.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-08-15
Estimated Expiration
2045-01-10

AI Technical Summary

Technical Problem

The communication links in cloud computing environments have poor protection, which makes communication data susceptible to leakage.

Method used

By obtaining communication instructions from the cloud computing platform, conducting data leakage risk inspection, collecting real-time protection parameters, introducing risk prediction channels, combining risk coefficients and constraint steps to optimize the protection mechanism, and building an optimized communication protection mechanism.

Benefits of technology

It improves the protection performance of communication links in cloud computing environments, reduces the risk of data leakage, and ensures the security of communication data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892453B_ABST
    Figure CN119892453B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for preventing communication data leakage in a cloud computing environment, which relates to the field of cloud computing security technology. The method comprises: obtaining a communication instruction containing a communication task to be executed and a corresponding communication link from a cloud computing platform, performing a data leakage risk test according to the task, collecting real-time protection parameters of the link to establish a protection mechanism if the test passes, introducing a risk prediction channel and combining the mechanism to predict the communication data leakage risk coefficient of the task to be executed, then optimizing and adjusting the protection mechanism based on the risk coefficient, threshold value and different constraint step sizes to construct an optimization mechanism, finally optimizing the communication link protection to obtain an optimized link, and executing the task in combination with the cloud computing platform. The method solves the technical problem in the prior art that the communication link in a cloud computing environment is poorly protected, resulting in communication data being vulnerable to leakage threats, and achieves the technical effect of improving the protection performance of the communication link in a cloud computing environment and reducing the risk of data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing security technology, and in particular to a method for preventing communication data leakage in a cloud computing environment. Background Art

[0002] With the widespread adoption of cloud computing, massive amounts of data are being transmitted and processed in distributed, multi-tenant cloud environments. Traditional protection methods that rely on static security policies and manual risk assessments struggle to keep pace with the ever-changing resource scheduling and data flow demands of cloud platforms. Coupled with the complex cross-regional and cross-system interactions and the demands for real-time performance and high availability, sensitive data faces an increased threat of leakage during transmission. There is an urgent need to develop a technology that can assess risks in real time and dynamically adjust protection policies to effectively enhance the security of communication links in cloud computing environments and prevent data leaks.

[0003] At present, relevant technologies have a technical problem in which the communication links in cloud computing environments have poor protection, making communication data vulnerable to leakage threats. Summary of the Invention

[0004] This application solves the technical problem in the prior art that communication links in cloud computing environments have poor protection, resulting in communication data being vulnerable to leakage threats, by providing a communication data leakage protection method in a cloud computing environment.

[0005] This application provides a method for preventing communication data leakage in a cloud computing environment, including:

[0006] Obtain a communication instruction of a cloud computing platform, wherein the communication instruction includes a communication task to be executed and a communication link corresponding to the communication task to be executed; perform a data leakage risk test according to the communication task to be executed to obtain a task leakage risk test result; when the task leakage risk test result is passed, collect real-time protection parameters of the communication link and establish a communication protection mechanism; introduce a communication leakage risk prediction channel, and perform a communication data leakage risk prediction on the communication task to be executed in combination with the communication protection mechanism to obtain a communication leakage risk coefficient; based on the communication leakage risk coefficient, optimize the communication protection mechanism according to a communication leakage risk threshold, a first constraint step for protection adjustment, and a second constraint step for protection adjustment to construct an optimized communication protection mechanism, wherein the first constraint step for protection adjustment is greater than the second constraint step for protection adjustment; perform protection optimization on the communication link according to the optimized communication protection mechanism to obtain an optimized communication link, and execute the communication task to be executed in combination with the cloud computing platform.

[0007] The present application proposes a method for preventing communication data leakage in a cloud computing environment. First, communication instructions containing communication tasks to be executed and corresponding communication links are obtained from the cloud computing platform. A data leakage risk test is performed according to the task to obtain the result. If the result is passed, the real-time protection parameters of the link are collected to establish a protection mechanism. A risk prediction channel is introduced and combined with the mechanism to predict the communication data leakage risk coefficient of the task to be executed. Then, the protection mechanism is optimized and adjusted according to the risk coefficient, threshold and different constraint step sizes to construct an optimization mechanism. Finally, the communication link protection is optimized according to the optimization mechanism to obtain an optimized link. The task is executed in combination with the cloud computing platform, thereby achieving the technical effect of improving the protection performance of the communication link in the cloud computing environment and reducing the risk of data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments of the present disclosure are briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in precise order. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.

[0009] Figure 1 A flowchart of a method for preventing communication data leakage in a cloud computing environment provided by an embodiment of the present application;

[0010] Figure 2 A schematic diagram of the inspection result output process of a communication data leakage protection method in a cloud computing environment provided in an embodiment of the present application. DETAILED DESCRIPTION

[0011] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.

[0012] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0013] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict, and the terms “first\second” involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. The terms “including” and “having” and any variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only.

[0014] The embodiment of the present application provides a method for preventing communication data leakage in a cloud computing environment, such as Figure 1 As shown, the method includes:

[0015] Step S100, obtain the communication instructions of the cloud computing platform, wherein the communication instructions include the communication tasks to be executed and the communication links corresponding to the communication tasks to be executed. Specifically, in the architecture of the cloud computing platform, the instruction management and distribution subsystem is connected to each core component through a high-speed and reliable internal network (such as Ethernet, Infiniband, etc.), and a redundant design is used to ensure stability. The system monitors the communication instruction requests from various parts of the platform in real time through a specific listening port and a protocol parsing module, parses the data according to the predefined instruction protocol format (such as XML, JSON, etc.), extracts the key information of the communication tasks to be executed and the corresponding communication links, and then verifies the format, integrity (through checksum comparison) and source legitimacy of the instructions. If there are any errors, feedback is given to the sender or retransmission is made. After confirmation, it is passed to the subsequent process, providing a basis for communication data leakage protection, ensuring the security and stability of the communication operations of the cloud computing platform, promoting its development and application, meeting social needs, and helping users achieve business and data management goals.

[0016] Step S200 involves performing a data leakage risk check based on the pending communication task to obtain a task leakage risk check result. Specifically, a task leakage risk check system is deployed within the cloud computing platform's security architecture, integrating technical tools such as encryption technology analysis, data access rights auditing, network vulnerability scanning, and machine learning anomaly detection. It is connected to other platform components and relies on a regularly updated security database to ensure accuracy. Data collection tools are used to mine encryption parameters and information related to the pending communication task, including encryption algorithms, key information, and encryption status, to provide a preliminary assessment of encryption security. This information is then input into a task leakage risk prediction model built based on historical data and machine learning algorithms to calculate a task leakage risk coefficient. The numerical value reflects the level of risk, and multiple factors are analyzed to ensure an objective and accurate assessment. Finally, the coefficient is input into a leakage risk check model with risk judgment rules and a threshold system. The task leakage risk check result is determined by comparing the coefficient with the threshold. If it passes, the risk is acceptable; otherwise, remediation and optimization measures are required. This result provides risk information to platform security management and users, ensuring the security of communication tasks, improving platform security, reliability, and user trust, promoting the application and development of cloud computing technology, and providing support for information security.

[0017] In one possible implementation, Figure 2 In the aforementioned step S200, a data leakage risk test is performed based on the communication task to be executed to obtain a task leakage risk test result. Step S210 further includes constructing a task leakage risk test channel, wherein the task leakage risk test channel includes a task leakage risk prediction model and a leakage risk test model. Specifically, at the security architecture layer of the cloud computing platform, modeling software and big data analysis tools are used to construct the task leakage risk test channel. This channel is constructed based on the mining and analysis of a large amount of historical communication task data to identify key factors and characteristic patterns closely related to data leakage risks, laying the foundation for subsequent risk assessment. The task leakage risk prediction model adopts machine learning algorithms such as the neural network architecture in deep learning. By learning the attributes of tasks in historical data, such as type, data volume, sensitivity, execution time and frequency, as well as whether data leakage has occurred, it continuously adjusts internal weights and parameters, so that it can accurately predict the potential data leakage risk level based on the input task characteristics, and is highly adaptable and accurate; the leakage risk detection model is based on industry standards, security best practices, and the cloud computing platform's own security policies and risk tolerance. It sets clear risk judgment rules and thresholds, such as determining different acceptable risk ranges based on the confidentiality level of task data. When the input risk coefficient exceeds the corresponding threshold, the task is judged to be high-risk, otherwise the risk is controllable. The final task leakage risk detection result is output to ensure the scientificity and reliability of the entire detection process, and to build an effective security protection mechanism for the communication tasks of the cloud computing platform.

[0018] Step S220, collect the encryption parameters of the communication task to be executed and obtain the task encryption scheme. Specifically, first clarify the data source (such as database, storage system, etc.) and transmission path involved in the communication task to be executed, and determine the scope of encryption parameter collection, such as the storage encryption method of the database, the encryption protocol of the network transmission, etc. Then, deploy lightweight, high-performance collection tools and agent programs at the key nodes of the cloud computing platform (such as switches, servers, etc.), which are deeply integrated with the system kernel, network protocol stack, etc., and use deep packet inspection and other technologies to monitor encryption-related events in real time and extract parameters. Then use the parsing engine to deeply analyze the original data, standardize the extracted parameters, and unify the naming conventions, data types and value ranges. Finally, integrate the standardized parameters into a complete task encryption scheme according to the logical structure, covering data source, transmission, authentication and authorization, and storage encryption, providing accurate input for risk assessment, ensuring the data security of the platform communication tasks, and promoting the development of cloud computing technology.

[0019] In step S230, the task encryption scheme is input into the task leakage risk prediction model to obtain the task leakage risk coefficient. Specifically, the operating environment of the task leakage risk prediction model is set up, and the parameters obtained after in-depth analysis and learning of a large amount of historical communication task data and corresponding data leakage incidents are loaded, and their integrity and accuracy are verified. Then, the input task encryption scheme is adapted and converted, such as converting text data into a numerical format using methods such as one-hot encoding, normalizing numerical data, parsing and simplifying complex structure data, and arranging it into an input vector according to model requirements. It is then input into the model, and the model extracts high-level features related to risk through convolution, pooling, and fully connected layers, and performs nonlinear transformations and calculations based on neuron connection weights, activation functions, etc. to obtain preliminary assessment results. Afterwards, a conversion algorithm based on probability distribution is used to generate the task leakage risk coefficient, such as the probability value output by logistic regression or the comprehensive calculation value of a multi-classification decision tree model, with a value of 0 to 1 reflecting the level of risk. Finally, the risk factor is output and stored in a specific structure or transmitted to the security management system via a network interface for visual display, providing support for security decision-making, helping to prevent data leakage, improve the platform's security protection level and user trust, and promote the application and development of cloud computing technology. Continuous optimization of the model is required to respond to security challenges, ensure platform and data security, and promote the construction of a digital ecosystem.

[0020] In step S240, the task leakage risk coefficient is input into the leakage risk verification model, and the task leakage risk verification result is output. Specifically, the leakage risk verification model, which is constructed based on the cloud computing platform security policy, analysis of past data leakage incidents, and industry standards, is ensured to be in an operational state, and its internal risk thresholds, judgment rules, and related parameters set based on data type, sensitivity, and platform risk tolerance are checked and calibrated. The risk coefficient received from the task leakage risk prediction model is then data-verified to confirm that the format and value range meet the requirements. If there are any errors, an alarm is issued and a correction is notified. Only when there are no errors will the risk assessment be initiated. The risk coefficient is then compared with the preset threshold. If it is less than the threshold, it is judged as "passed", reflecting that the risk is acceptable and the task can proceed as planned; if it is greater than or equal to the threshold, it is judged as "failed", indicating that the risk is high and measures such as optimizing the encryption scheme need to be taken. The model will also provide suggestions based on the situation. Finally, the model outputs the results in a clear manner, which may be text labels or detailed reports, and feeds back to the security management system. If it "fails", the system will trigger the response process, including notifying personnel, recording events, adjusting configurations, etc. In actual applications, the model needs to be continuously optimized to adapt to changes, ensure platform and data security, and promote technological development and ecological construction.

[0021] In one possible implementation, a task leakage risk verification channel is constructed, wherein the task leakage risk verification channel includes a task leakage risk prediction model and a leakage risk verification model, and step S210 further includes step S211, using the task encryption scheme sample set as input information and the task leakage risk sample set as output information to train the fully connected neural network, and obtaining the leakage risk prediction loss coefficient after each predetermined number of trainings. Specifically, historical communication task data from different fields, scenarios, and periods are collected, and the task encryption scheme (including encryption algorithm, key information, encryption mode, etc.) and the corresponding actual data leakage situation (quantified as risk level or value) are recorded to form a sample set. The sample data is then preprocessed by cleaning, denoising, and normalization to ensure that the data is accurate and complete and that the magnitude of each feature is uniform. Then, a fully connected neural network is constructed, whose input layer neurons correspond to the number of encryption scheme features, the hidden layer is set with multiple layers and the corresponding number of neurons according to the complexity of the problem, and the output layer determines the number of neurons and activation function according to the risk result representation method. After that, the encryption scheme sample set is input into the network, and the predicted leakage risk value is obtained through weighted summation of neurons and nonlinear transformation of activation function. After each predetermined number of training (such as 100 times or 500 times), the error between the predicted value and the true value is calculated using loss functions such as mean square error or cross entropy, thereby obtaining the leakage risk prediction loss coefficient. This is used to monitor the learning progress and performance of the model and provide a basis for subsequent optimization and adjustment to cope with the data leakage risk in the communication tasks of the cloud computing platform, ensure data security and platform protection level, promote the application and development of cloud computing technology, and assist in digital transformation and security ecosystem construction.

[0022] Step S212: If the leakage risk prediction loss coefficient is less than the leakage risk prediction loss threshold, the task leakage risk prediction model is generated. Specifically, after the fully connected neural network completes each predetermined number of rounds of training, the leakage risk prediction loss coefficient is obtained, and it is compared with the leakage risk prediction loss threshold set based on the model performance expectations and business needs. If the coefficient is less than the threshold, it means that the model has achieved the expected performance. At this time, a task leakage risk prediction model is generated, and its neuron connection weights, bias parameters and architecture information are saved to facilitate leakage risk assessment of new communication tasks. In addition, an independent test data set can be used to verify the model. If performance problems are found, such as large prediction deviations on specific tasks, the model's generalization ability and accuracy can be improved by adjusting the network structure, adopting new training algorithms, increasing training data and other optimization measures, so that it can better adapt to business scenarios, provide technical support for communication data leakage protection on cloud computing platforms, ensure data security, promote the safe development of cloud computing technology, meet the security needs of digital business, and contribute to high-quality economic and social development and digital transformation of the industry.

[0023] Step S213 constructs the leakage risk verification model. The leakage risk verification model includes a leakage risk verification operator. If the task leakage risk coefficient is less than a task leakage risk threshold, the task leakage risk verification result is a pass; if the task leakage risk coefficient is greater than or equal to the task leakage risk threshold, the task leakage risk verification result is a fail. Specifically, a leakage risk verification model framework is constructed, integrating it into the cloud computing platform security assessment system as an independent module, focusing on interface compatibility and data interaction with other modules. Next, task leakage risk thresholds are determined based on the platform task nature, data sensitivity, and security policies. For example, a lower threshold is set for sensitive data tasks, while a higher threshold is appropriately relaxed for common business data tasks, to flexibly adapt to different risk assessment requirements. A leakage risk verification operator is then constructed, with the comparison of the risk coefficient with the threshold as its core logic. If the value is less than the threshold, the test result is considered "pass," and the task can proceed normally. If the value is greater than or equal to the threshold, the test result is considered "fail," and emergency mechanisms must be activated to strengthen security. The operator is then integrated into the model and fully tested. Simulated data is used to verify the accuracy of the results and evaluate performance. Vulnerabilities or performance issues are debugged and optimized to ensure efficient and stable model operation. After being fully tested and optimized, it will be deployed to the platform and will require regular updates and maintenance to respond to changes, ensure platform security, promote technological development and ecosystem construction, protect data security and user rights, and contribute to high-quality economic and social development.

[0024] Step S214 connects the task leakage risk prediction model and the leakage risk verification model to generate the task leakage risk verification channel. Specifically, the output interface of the task leakage risk prediction model and the input interface of the leakage risk verification model are designed and adapted. The output format, data type, and precision of the risk coefficient are clarified, and the transmission process is optimized. Verification and exception handling are also performed on the input interface, laying the foundation for model connection. A reliable data transmission channel and synchronization mechanism are then established, using message queue asynchronous transmission and data synchronization confirmation mechanisms to ensure real-time and accurate transmission of risk coefficients, avoiding data blockage, loss, and inconsistencies. The two models are then physically connected and logically integrated, optimizing business logic for collaborative operation. This completes the entire process from encryption scheme input to risk verification result output, ensuring a stable and reliable model connection and leveraging synergy. Finally, the task leakage risk verification channel is comprehensively tested and optimized, with results verified using simulated data. Deviations are analyzed for causes, such as data transmission, parameter settings, or algorithmic flaws, and corresponding optimization measures are implemented. Regular maintenance and updates are carried out as business and environmental changes evolve, enhancing the platform's security capabilities, ensuring data security, promoting technological innovation and the digital transformation of the industry, and contributing to high-quality economic and social development.

[0025] In one possible implementation, the leakage risk verification model is constructed, wherein the leakage risk verification model includes a leakage risk verification operator, and the leakage risk verification operator includes: if the task leakage risk coefficient is less than the task leakage risk threshold, the task leakage risk verification result is passed; if the task leakage risk coefficient is greater than or equal to the task leakage risk threshold, the task leakage risk verification result is failed; step S213 further includes step S2131, when the task leakage risk verification result is failed, the task encryption scheme is adjusted to establish a task encryption adjustment scheme space. Specifically, upon receiving a notification that the task leakage risk verification result is "failed", a comprehensive risk assessment is first carried out to review various parts of the task encryption scheme, including encryption algorithms, key management, encryption modes, network transmission security protocols, and system access control settings, etc., to identify security vulnerabilities and weak links, clarify the causes of the risk, and indicate the direction for subsequent adjustments. Based on the diagnostic results, a multi-dimensional encryption scheme adjustment strategy is then formulated, such as upgrading encryption algorithms, optimizing key management, switching encryption modes, strengthening network transmission encryption and system access control, etc. This builds a rich space of task encryption adjustment solutions, and fully analyzes the platform's business, performance, and technical feasibility to balance security and performance. Finally, the various strategies are integrated and organized, presenting the solution space using a structured data model. The implementation steps and parameters of each solution are described in detail, and information such as expected results, implementation difficulty, and performance impact is marked. This provides strong support for subsequent extraction and verification, allowing for efficient response to data leakage risks, improving the platform's security protection level, promoting the development of cloud computing technology, protecting data security and user rights, facilitating digital transformation and high-quality development, and playing a significant role in the field of information security.

[0026] Step S2132 randomly extracts the nth task encryption adjustment scheme according to the task encryption adjustment scheme space, where n is a positive integer. Specifically, a unique index or identifier is set for each scheme in the task encryption adjustment scheme space, and an index directory is established, which is associated with the detailed content and attributes of the scheme to facilitate subsequent search. Then, a random number generation algorithm (such as the linear congruential method, the Mersenne twister algorithm, etc.) is used to generate a random number corresponding to the number of schemes, ensuring that it is within the valid range and evenly distributed, so that each scheme has an equal probability of being selected, and the parameters of the random number generator are set to ensure randomness. Then, based on the generated random number, the nth task encryption adjustment scheme is extracted from the scheme space through the index directory, and its encryption parameter adjustment, implementation steps and configuration information are fully obtained, and the extracted scheme index, time and operating environment information are recorded. The above records are of great significance for subsequent testing, evaluation and problem troubleshooting, and help optimize the scheme selection strategy, improve the efficiency and accuracy of the entire encryption scheme adjustment process, ensure platform security, promote the development of cloud computing technology, help various industries digital transformation and high-quality development, and play an important role in the field of information security.

[0027] In step S2133, the nth task encryption adjustment scheme is input into the task leakage risk verification channel to obtain the leakage risk verification result for the nth scheme. Specifically, the nth task encryption adjustment scheme is preprocessed and formatted, its encryption parameters are checked and corrected, and it is organized and arranged according to the requirements of the task leakage risk verification channel to ensure input compliance. Next, it is input into the channel. The task leakage risk prediction model first extracts the scheme's key encryption features and converts them into numerical vectors. Based on the pre-trained neural network structure and parameters, the corresponding task leakage risk coefficient is calculated and output. This coefficient is then input into the leakage risk verification model and compared with a pre-set risk threshold. A verification operator is used to determine if the coefficient is less than the threshold, resulting in a "pass" test; otherwise, a "fail" test result is obtained. Finally, the test result is output from the channel and recorded and stored, including scheme details, input time, risk coefficient value, results, and environmental information, for subsequent analysis and decision-making. If any issues are found, targeted optimization of the scheme, adjustment of the environment, or improvement of the model can be implemented. This improves the accuracy and reliability of risk verification, ensures platform security, promotes the development of cloud computing technology and the digital transformation of the industry, contributes to high-quality economic and social development, and plays a significant role in the field of information security.

[0028] Step S2134, when the leakage risk test result of the nth scheme is passed, the communication task to be executed is encrypted and optimized according to the task encryption adjustment nth scheme. Specifically, after receiving the feedback that the leakage risk test result of the nth scheme is "passed", the result is first confirmed and verified, the risk inspection data and process are checked, and the encryption measures and parameters of the task encryption adjustment nth scheme are reviewed to ensure that the result is accurate and the scheme is compliant. The encryption parameters of the communication task to be executed are updated and configured according to the scheme, such as replacing and correctly initializing the encryption algorithm in the code and system configuration when changing the encryption algorithm, adjusting the key management system, including generating new keys and updating the storage and distribution mechanism, and optimizing parameters such as encryption mode, network transmission encryption settings and system access control to ensure accuracy. Afterwards, the encryption optimization effect is verified, and functional testing is used to check whether the business functions are affected. Security testing is used to resist simulated attacks, and system performance is evaluated to avoid excessive negative impact on the overall performance of the platform. In addition, a continuous monitoring and optimization adjustment mechanism can be established to collect encryption-related data during task operation, monitor the status in real time, promptly investigate and deal with problems when they are discovered, and optimize and adjust the plan again when necessary to adapt to security challenges and ensure the long-term effectiveness and stability of the encryption plan, providing security for the communication tasks of the cloud computing platform. At the same time, it is necessary to continuously optimize and improve the plan process, enhance the platform's security protection capabilities, ensure data security and user rights, promote the innovative development of cloud computing technology and the digital transformation of the industry, assist in high-quality economic and social development, and play an important role in information security.

[0029] Step S300, when the task leakage risk test result is passed, the real-time protection parameters of the communication link are collected and a communication protection mechanism is established. Specifically, after receiving the notification that the task leakage risk test result is "passed", it is necessary to rigorously confirm the result, check the operation logs and data records of each link of the inspection channel, ensure that the risk coefficient is calculated accurately, the threshold setting is reasonable and not interfered with by abnormal factors, and ensure that the result is true and reliable. Then immediately start the collection of real-time protection parameters of the communication link, and collect network traffic (size, rate, direction, etc.), connection status (duration, source and destination address, port number, etc.), data packets (size, protocol type, content, etc.) and equipment operation status (CPU usage, memory usage, interface error rate, etc.) parameters through monitoring tools and sensors deployed at key nodes such as source servers, switches, routers and destination devices to provide data support for the establishment of a protection mechanism. Finally, a multi-level communication protection mechanism is constructed based on these parameters. Thresholds and detection rules are set based on traffic data, and restrictions or redirections are triggered in case of anomalies; white and black lists are established for connection status to prevent illegal connections; data packets are protected with encryption, verification and filtering; thresholds and warnings are set according to device status, and corresponding measures are taken in case of failure to ensure the security and stability of communication links in all aspects. The solution process is continuously optimized and improved as business and technology develop, to enhance the platform's security protection capabilities, protect data security and user rights, promote the development of cloud computing technology and the digital transformation of the industry, assist in high-quality economic and social development, and play an important role in the field of information security.

[0030] Step S400 introduces a communication leakage risk prediction channel, and combines the communication protection mechanism to predict the communication data leakage risk of the communication task to be executed, and obtains a communication leakage risk coefficient. Specifically, the communication leakage risk prediction channel architecture is first determined, and a machine learning or deep learning model is selected to clearly cover the input data source of communication protocols, data transmission, sensitivity, authentication methods, network environment, etc., and then collect and pre-process them to build a prediction channel framework. Then, the communication protection mechanism is organically integrated with the prediction channel, and the real-time protection parameters of the protection mechanism, such as network traffic, connection status, data packets and device operation status, are used as supplementary feature input channels. The risk coefficient output by the channel is also fed back to the protection mechanism to dynamically adjust the strategy to achieve synergy and complementarity. After the communication task is started, its characteristic data and real-time parameters of the protection mechanism are input into the prediction channel. After model analysis and processing, the risk characteristics are extracted and calculated, and the communication leakage risk coefficient reflecting the degree of data leakage risk is output. If the coefficient is high, it is necessary to strengthen protection or optimize the task. The prediction process must ensure that the data and model run accurately and efficiently. After optimization and improvement, this solution can enhance the platform's security protection capabilities, ensure data security and user rights, promote the development of cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0031] In one possible implementation, a communication leakage risk prediction channel is introduced. The communication data leakage risk prediction for the communication task to be executed is combined with the communication protection mechanism to obtain a communication leakage risk coefficient. Step S400 further includes step S410. The communication leakage risk prediction channel includes Q communication leakage risk prediction models, where Q is a positive integer greater than 1. Specifically, based on the characteristics of the cloud computing platform communication tasks and data leakage risk factors, Q communication leakage risk prediction models of different types, such as decision trees, neural networks, and support vector machines, are selected. For each model, the architecture of the input layer (determining the reception of quantized and encoded feature data such as network traffic, identity information, transmission characteristics, and encryption methods), the hidden layer (determining the number of neurons and activation functions based on the complexity and data characteristics), and the output layer (outputting risk level numerical values or category labels) are designed to complete the model selection and architecture design. Subsequently, historical communication and leakage event data is collected and preprocessed through cleaning, denoising, and padding, as well as feature engineering (such as calculating traffic statistics, quantizing identity and encryption information, and analyzing transmission time and frequency characteristics) to prepare high-quality data for model training. Afterwards, algorithms (such as decision tree algorithms, backpropagation algorithms, and solving quadratic programming problems) are used to train each model separately. Cross-validation and regularization techniques are used to prevent overfitting, and adjustments and optimizations are made based on performance indicators such as accuracy and recall to ensure that each model achieves better prediction performance. Finally, the trained Q models are integrated into the communication leakage risk prediction channel. Based on the independent test performance of the models, the weight distribution or fusion strategy is determined (for example, models with good performance have higher weights). A monitoring and update mechanism is established to regularly evaluate performance and retrain or update the model when necessary to ensure that the channel is effective and reliable. This provides strong support for communication risk prediction on cloud computing platforms, and is continuously optimized and improved as business and technology develop, ensuring platform security, promoting technological development and industry digital transformation, contributing to high-quality economic and social development, and playing an important role in information security.

[0032] In step S420, the communication protection mechanism and the communication task to be executed are input into the Q communication leakage risk prediction models to obtain Q communication leakage risk prediction coefficients. Specifically, real-time protection parameters such as network traffic, connection status, data packets, and device operating status are extracted from the communication protection mechanism, organized and standardized, and their formats and types are unified, and outliers are processed. At the same time, characteristics such as the communication protocol, transmission scale, data sensitivity, and authentication method of the communication task to be executed are extracted and quantified, and integrated into structured data. Next, these integrated and pre-processed data are respectively input into the Q communication leakage risk prediction models. The models analyze and process based on their own algorithmic structures, such as decision trees according to branching rules, neural networks through neuron transmission calculations, and support vector machines mapping high-dimensional spaces to find hyperplanes, and independently output Q communication leakage risk prediction coefficients. Finally, before receiving the coefficients, conduct a quality check on the model output results, verify the value range and stability, and compare different model coefficients to troubleshoot possible problems and ensure that the coefficients are reasonable and reliable, providing key data support for subsequent risk assessment decisions. Continuously optimize and improve the process based on actual conditions, enhance the platform's security protection capabilities, ensure data security and user rights, promote the development of cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0033] Step S430: Perform a weighted calculation based on the Q communication leakage risk prediction accuracies corresponding to the Q communication leakage risk prediction models to establish leakage risk prediction incentive conditions, wherein the leakage risk prediction incentive conditions include Q leakage risk prediction incentive coefficients. Specifically, the Q communication leakage risk prediction models are evaluated using a test data set independent of the training set. The prediction results are obtained by inputting the test samples into the model and compared with the true labels. Indicators such as accuracy, recall, F1 value, and precision are calculated to quantify the model prediction accuracy from multiple dimensions, providing basic data for subsequent weighted calculations. Next, the weighted calculation method and weight distribution principle are determined based on business needs and risk assessment priorities. A common method is to use the model's comprehensive performance indicators (such as F1 value) after normalization as the initial weight. At the same time, the weights are adjusted based on a comprehensive analysis of factors such as model stability, computational complexity, and adaptability to specific data. This ensures that the weight distribution is more in line with actual business and security needs, ensures that the weighted calculation is scientific and reasonable, fully utilizes the advantages of each model, and improves the robustness and adaptability of the risk prediction system. Finally, according to the determined weighting method and weight, Q leakage risk prediction incentive coefficients are calculated. This coefficient will be used as the weight for the subsequent weighted calculation of the communication leakage risk prediction coefficient. In actual operation, these incentive coefficients can guide the risk prediction process, so that models with high prediction accuracy and good stability can play a greater role in the final risk assessment, improve the overall prediction accuracy and reliability, help the platform accurately identify risks, take security measures, and ensure data security and user rights. In addition, the solution process is continuously optimized and improved with the development of business and technology, promoting cloud computing technology and industry digital transformation, helping high-quality economic and social development, and giving play to the important value of information security.

[0034] Step S440, weighted calculation is performed on the Q communication leakage risk prediction coefficients according to the Q leakage risk prediction incentive coefficients to generate the communication leakage risk coefficient. Specifically, the Q communication leakage risk prediction coefficients and the corresponding Q leakage risk prediction incentive coefficients are checked to ensure that they are accurate and not affected by any interference factors, laying the foundation for subsequent calculations. Next, each communication leakage risk prediction coefficient is multiplied by the corresponding leakage risk prediction incentive coefficient. For a given plurality of prediction coefficients and incentive coefficients, their products are calculated respectively, and then these products are accumulated and summed to obtain the final communication leakage risk coefficient. This process integrates the prediction results of each model and weights them according to their accuracy, which can more accurately reflect the degree of task leakage risk. Finally, the communication leakage risk coefficient obtained is verified and rationally evaluated to check whether its value range is consistent with business logic and expectations, and compared with historical data and similar task coefficients. If it exceeds the reasonable range or there is a deviation, the weighted calculation links are checked and possible influencing factors are analyzed to ensure that the coefficient is reliable and effective, providing an accurate basis for platform security decision-making. In actual applications, it is necessary to continuously optimize and improve the solution process according to the platform's business and security needs, enhance security protection capabilities, ensure data security and user rights, promote the development of cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0035] In step S500, based on the communication leakage risk coefficient, the communication protection mechanism is optimized and adjusted according to the communication leakage risk threshold, the first protection adjustment constraint step size, and the second protection adjustment constraint step size to construct an optimized communication protection mechanism. Specifically, the communication leakage risk coefficient is obtained and compared with a preset communication leakage risk threshold to determine whether the communication protection mechanism needs to be optimized. If the coefficient is greater than the threshold, the step size is selected based on the risk level: a larger first protection adjustment constraint step size is used for high risk, and a smaller second protection adjustment constraint step size is used for relatively low risk, to determine the direction and magnitude of the adjustment. Next, precise adjustments are made to various parameters of the communication protection mechanism, such as enhanced network traffic monitoring and filtering, upgraded encryption algorithms and management, strengthened identity authentication and authorization, and optimized network connection management, to ensure that all parameters are coordinated and conflict-free. The adjusted parameters are then combined to construct an optimized communication protection mechanism. The effectiveness is verified by re-predicting the risk coefficient, simulating attacks to test security, and evaluating the impact on platform performance. If the performance does not meet the requirements, the optimization process is repeated until the risk coefficient meets the requirements. In actual applications, we will continue to improve this solution based on the platform's business and security needs, enhance protection capabilities, ensure data security and user rights, promote cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0036] In one possible implementation, based on the communication leakage risk coefficient, the communication protection mechanism is optimized and adjusted according to the communication leakage risk threshold, the first constraint step of the protection adjustment, and the second constraint step of the protection adjustment to construct an optimized communication protection mechanism, wherein the first constraint step of the protection adjustment is greater than the second constraint step of the protection adjustment, and step S500 further includes step S510, determining whether the communication leakage risk coefficient is greater than or equal to the communication leakage risk threshold. Specifically, the communication leakage risk coefficient is obtained by comprehensively calculating the real-time parameters of the communication protection mechanism and the characteristic data of the communication task to be executed through the communication leakage risk prediction model, while ensuring that the communication leakage risk threshold reasonably set according to the cloud computing platform security policy, data sensitivity level, industry security standards and past experience is accurate and effective, and the data format and accuracy of the two are checked and unified. Next, the communication leakage risk coefficient is compared with the threshold. If the coefficient is less than the threshold, the existing protection measures can be maintained or gently optimized and fine-tuned to improve efficiency and reduce resource consumption; if the coefficient is greater than or equal to the threshold, it indicates that the current protection mechanism is insufficient, and it is necessary to initiate optimization measures such as parameter adjustment and function enhancement of the communication protection mechanism according to the preset protection adjustment strategy to reduce the risk coefficient to an acceptable range. This comparison and judgment process must ensure that the algorithm is accurate and stable to avoid erroneous results affecting the effectiveness of the protection system. In actual applications, the process should be continuously optimized and improved according to the platform situation to enhance protection capabilities, ensure data security and user rights, promote cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0037] In step S520, if the communication leakage risk coefficient is greater than or equal to the communication leakage risk threshold, the communication protection mechanism is adjusted according to the first constraint step of the protection adjustment to obtain a first space of the protection mechanism adjustment scheme. Specifically, after determining that the communication leakage risk coefficient is greater than or equal to the communication leakage risk threshold, the adjustment range of each parameter is first determined based on the first constraint step of the protection adjustment (e.g., 20%). Parameters such as the key length of network traffic encryption, the network connection timeout, the packet verification frequency, and the device access control policy are all determined within a range less than or equal to the step. For example, the key length can be adjusted from 128 bits to 153 bits (approximately a 20% increase), 144 bits (approximately a 12.5% increase), etc., and the timeout period can be adjusted from 60 seconds to 48 seconds (20% decrease), 50 seconds (approximately a 16.7% decrease), etc. Next, based on the value range of each parameter, a combination adjustment is performed to generate a series of adjustment schemes. For example, network traffic encryption has multiple key length adjustment methods, and network connection timeout has multiple adjustment methods. Through permutations and combinations, many different communication protection mechanism adjustment schemes are formed. These schemes constitute the first space of protection mechanism adjustment schemes, while fully considering the interaction between parameters to ensure their feasibility and synergy. Finally, all adjustment schemes are integrated and stored in a suitable data structure. Unreasonable schemes, such as those that lead to excessive resource consumption or parameter conflicts, are preliminarily screened and removed to form a complete, orderly and reasonable first space of protection mechanism adjustment schemes. This provides a basis for subsequent optimization analysis, and the process is continuously optimized and improved in actual applications to enhance the platform's security protection capabilities, safeguard data security and user rights, promote cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0038] In step S530, the first space of protection mechanism adjustment solutions is optimized based on the communication leakage risk threshold to obtain a second space of protection mechanism adjustment solutions. Specifically, the communication leakage risk threshold and the first space of protection mechanism adjustment solutions generated by the first constraint step size are accurately determined. Furthermore, assessment tools such as the communication leakage risk prediction model are ensured to be readily available and reliable. Next, each adjustment solution is sequentially selected from the first space of protection mechanism adjustment solutions and applied to the communication protection mechanism. The risk prediction model is used to calculate its communication leakage risk coefficient and compare it with the risk threshold. If a solution's risk coefficient falls below the threshold, it is considered a potentially superior solution because it meets the basic platform data security requirements. This process ensures that the solution application and coefficient calculation are accurate. Finally, all solutions meeting the risk coefficient requirement below the threshold are screened and integrated to form the second space of protection mechanism adjustment solutions. These solutions are further organized and categorized, such as by protection parameter adjustment method, and basic statistical analysis is performed, such as calculating the number of solutions and analyzing the percentage to understand their distribution characteristics. In actual applications, we will continue to optimize and improve this process, enhance the platform's security protection capabilities, ensure data security and user rights, promote cloud computing technology and industry digital transformation, assist in high-quality economic and social development, and play an important role in information security.

[0039] Step S540: Minimize the communication leakage risk based on the second space of the protection mechanism adjustment scheme to generate the optimized communication protection mechanism. Specifically, the goal of optimizing the communication leakage risk based on the second space of the protection mechanism adjustment scheme is clarified, and the use of intelligent algorithms such as simulated annealing, genetic optimization, or particle swarm optimization is determined. Taking the genetic algorithm as an example, parameters such as population size, crossover and mutation probability must be reasonably set to ensure a balance between global and local search capabilities. Next, the second space is initialized according to the selected algorithm. For example, in the genetic algorithm, a random scheme is selected as the initial population, and its genetic encoding corresponds to the protection mechanism parameters. The communication leakage risk coefficient under each scheme is then calculated as the basis for evaluation to ensure accurate and efficient evaluation. After that, iterative optimization is performed. Taking the genetic algorithm as an example, offspring individuals are generated through crossover and mutation, and their risk coefficients are evaluated. Individuals are selected to enter the next generation based on their fitness (related to the risk coefficient). Convergence is closely monitored, and algorithm parameters are adjusted as necessary to prevent premature or slow convergence. When the preset termination conditions are met, such as reaching the maximum number of iterations or the optimal individual risk coefficient being stable, iterations are stopped. The solution represented by the optimal individual is the solution that minimizes risk, and this solution is applied to the communication protection mechanism to generate an optimized protection mechanism. Finally, the optimization mechanism is verified and tested, simulating actual attack scenarios to observe the prevention and control effects and the impact on platform performance. If any problems are found, the optimization process is reviewed and analyzed, and further optimization is carried out by adjusting algorithm parameters, expanding the solution space, or improving the risk prediction model. In practice, this process is continuously improved according to the platform situation, enhancing security protection capabilities, ensuring data security and user rights, promoting cloud computing technology and the digital transformation of the industry, contributing to the high-quality development of the economy and society, and playing an important role in information security.

[0040] In one possible implementation, an optimization analysis is performed on the first space of protection mechanism adjustment solutions based on the communication leakage risk threshold to obtain a second space of protection mechanism adjustment solutions. Step S530 further includes step S531, randomly extracting the kth protection mechanism adjustment solution from the first space of protection mechanism adjustment solutions, where k is a positive integer. Specifically, all solutions in the first space of protection mechanism adjustment solutions are organized into an array or list, and the total number of solutions N is recorded. A data structure system is established to access each solution via an index, laying the foundation for random extraction. This can ensure improved solution management efficiency in the complex communication environment of the cloud computing platform, ensure the secure and stable operation of the platform, promote the application and development of cloud computing technology, protect user data security and privacy, and help build a digital ecosystem. Next, a reliable random number generation algorithm (such as random.randint(1,N) in Python) is used to generate a positive integer k between 1 and N. This process must ensure the randomness and uniformity of the random number to avoid distribution bias that affects the comprehensive and objective selection of solutions. This is the key to achieving fair and unbiased selection from a large number of solutions. Finally, based on the generated random number k and the previously established data structure, the kth protection mechanism adjustment plan is accurately and completely extracted from the first space of the protection mechanism adjustment plan, providing samples for subsequent risk assessment and other operations, and continuously optimizing and improving the process in actual applications, thereby enhancing the security protection capabilities of the cloud computing platform, promoting the digital transformation of the industry, assisting the high-quality development of the economy and society, and playing an important role in information security.

[0041] In step S532, the kth protection mechanism adjustment plan and the pending communication task are input into the communication leakage risk prediction channel to obtain the kth communication leakage risk coefficient. Specifically, various parameters in the kth protection mechanism adjustment plan are verified and organized, such as those related to network traffic monitoring and filtering, data encryption, identity authentication and authorization, and network connection management. Furthermore, characteristic data of the pending communication task, such as the communication protocol, data volume, data sensitivity, and information about the communicating parties, is organized to ensure data integrity, accuracy, and consistent formatting. This is the foundation for accurate risk assessment, helping to ensure the security and stability of the cloud computing platform, promote technological application development, protect user data rights, and build a digital ecosystem. Next, both data and the kth protection mechanism adjustment plan are input into the communication leakage risk prediction channel, which is comprised of multiple models based on different algorithmic principles. These models analyze the data from multiple perspectives, including network traffic, data encryption, and identity authentication. For example, some models identify anomalies based on traffic parameters and characteristics, others consider encryption strength and data sensitivity, and others analyze risks in the authentication and authorization process. Each model independently and collaboratively analyzes the input data comprehensively. Finally, each model outputs a preliminary risk assessment value based on its own algorithm, and then integrates it through a specific fusion algorithm (such as the weighted average method, summing weights based on model accuracy, etc.) to obtain the communication leakage risk coefficient of the kth solution. The value range is determined according to the platform standard, such as 0 to 1, and the value reflects the degree of risk. Subsequently, it is compared with the threshold to determine whether the solution meets the security requirements. In practice, this process should be continuously optimized and improved to enhance the platform's protection capabilities, promote the digital transformation of the industry, assist in high-quality economic and social development, and play an important role in information security.

[0042] Step S533 determines whether the k-th solution's communication leakage risk coefficient is less than the communication leakage risk threshold. Specifically, the k-th solution's communication leakage risk coefficient and the communication leakage risk threshold, determined based on the cloud computing platform's security policy, data sensitivity, industry standards, and past experience, are obtained. The data type and precision of the two are then verified and unified to prepare for subsequent comparison. This step is crucial, as its accuracy impacts the reliability and effectiveness of the entire protection mechanism optimization process and is the cornerstone for ensuring platform security and stability, promoting the application and development of cloud computing technology, and protecting user data rights. Next, a comparison is performed between the two, which is a key decision point. If the k-th solution's communication leakage risk coefficient is less than the threshold, it indicates that the solution effectively controls risk and can be considered a potentially superior solution, such as being included in the second space of the protection mechanism adjustment solution for further research and optimization. Conversely, if it is greater than or equal to the threshold, it indicates that the solution does not meet security requirements and needs to be adjusted or abandoned. A new solution may need to be reevaluated or the current solution may need to be optimized and reevaluated. The entire comparison process must ensure that the algorithm is accurate and stable, avoid errors that affect the optimization efficiency and quality of the protection mechanism, provide a basis for platform security decisions, assist in the continuous development of cloud computing technology in various fields, promote high-quality economic and social development, and highlight the important value of information security. In practice, this process should be continuously improved to enhance the platform's security protection capabilities.

[0043] In step S534, if the communication leakage risk coefficient of the kth solution is less than the communication leakage risk threshold, the protection mechanism adjustment solution kth is added to the second space of the protection mechanism adjustment solution. Specifically, verifying that the communication leakage risk coefficient of the kth solution is less than the communication leakage risk threshold is directly related to the optimization direction of the protection mechanism and is fundamental to ensuring the security and stability of the cloud computing platform, protecting user data privacy, and promoting technological development. Next, the second space of the protection mechanism adjustment solution is prepared and its data structure and storage status are checked. For example, if it is a list structure, the capacity and scalability must be confirmed. If it is in the form of a database table, the links must be normal and the table structure must be complete to ensure that it can smoothly accept the new solution and related information storage, providing a solid data foundation for subsequent operations. Finally, the kth protection mechanism adjustment plan is added to the second space completely and accurately, and the various parameter adjustment details in the plan are recorded, such as network traffic encryption, identity authentication enhancement, connection timeout adjustment and other information. At the same time, metadata such as the addition time and plan source are attached for subsequent tracing and analysis, and added to the second space plan reserve to provide more high-quality options for optimizing the protection mechanism. In actual applications, this process should be continuously improved according to the platform situation to enhance security protection capabilities, assist cloud computing technology and industry digital transformation, promote high-quality economic and social development, and highlight the important value of information security.

[0044] In one possible implementation, if the kth scheme's communication leakage risk coefficient is less than the communication leakage risk threshold, the kth protection mechanism adjustment scheme is added to the second space of the protection mechanism adjustment scheme. Step S534 further includes step S5341: if the communication leakage risk coefficient is less than the communication leakage risk threshold, the communication protection mechanism is added to the third space of the protection mechanism adjustment scheme. Specifically, obtaining the communication leakage risk coefficient, verifying the communication leakage risk threshold determined based on the cloud computing platform's security policy, data sensitivity, industry standards, and past experience, and then comparing the data to ensure data accuracy and comparison algorithm reliability are key prerequisites for ensuring platform security and subsequent decision-making, and are of great significance for improving platform security and stability and promoting the application and development of cloud computing technology. When the risk coefficient is determined to be less than the threshold, the communication protection mechanism is prepared to be added to the third space of the protection mechanism adjustment scheme, and its data structure and storage status are checked. For example, if the list format is used, sufficient space must be confirmed. For database storage, proper links and table structure compatibility must be ensured to fully and accurately record information such as the communication protection mechanism's network traffic monitoring rules, data encryption details, identity authentication methods, and network connection parameters. Existing schemes are also organized and indexes updated. Next, the communication protection mechanism should be accurately added to the third space strictly according to the predetermined format, a unique identifier should be generated for easy retrieval, and metadata such as the addition time, risk factor assessment results, and the type of communication task should be recorded to enrich the content of the third space and provide more possibilities for the optimization of the protection mechanism. In practice, this process should be continuously improved according to the platform situation, to enhance security protection capabilities, promote the digital transformation of the industry, assist in high-quality economic and social development, and play an important role in information security.

[0045] Step S5342: Adjust the communication protection mechanism based on the second constraint step size of the protection adjustment, establishing a fourth space for the protection mechanism adjustment scheme. Specifically, the specific value of the second constraint step size of the protection adjustment is determined, such as setting it to 15%. Based on this, the adjustment range of various parameters of the communication protection mechanism is determined. Parameters such as the key length for network traffic encryption, network connection timeout, packet verification frequency, and device access control policy are all set within a range less than or equal to this step size. For example, a 128-bit key can be adjusted to 147 bits (approximately a 14.8% increase) or 136 bits (approximately a 6.25% increase), and a 60-second timeout can be adjusted to 51 seconds (a 15% decrease) or 55 seconds (approximately an 8.33% decrease). By calculating the possible values of each parameter, preparation is made for the subsequent generation of a mediation scheme. This is the basis for ensuring system stability and exploring optimization solutions, and is crucial for improving platform security and promoting the application and development of cloud computing technology. Next, adjustments are made based on the range of each parameter's value. For example, network traffic encryption has multiple key length adjustment methods that can be combined with other parameter adjustment methods. This generates a series of, for example, 120 different adjustment schemes. These schemes optimize the communication protection mechanism within the constraints of the step size and fully analyze the interactions between parameters to ensure feasibility and coordination. This aims to improve communication security, provide diverse options for optimization analysis, increase the probability of finding the optimal mechanism, promote the secure development of cloud computing technology, and assist in the digital transformation of various industries. Finally, all adjustment schemes are integrated to form a fourth space for protection mechanism adjustment schemes. This space is stored in the form of a list, array, or database table, recording the parameter settings and adjustment instructions for each scheme. Unreasonable schemes, such as those that lead to excessive resource consumption or parameter conflicts, are initially screened and removed. This improves the efficiency and accuracy of subsequent optimization analysis, provides strong support for platform security decision-making, ensures the security and stability of platform communications, promotes the in-depth application and innovative development of cloud computing technology, builds a secure and efficient digital ecosystem, promotes high-quality economic and social development, and plays a vital role in information security. In practice, this process should be continuously improved based on the platform's situation to enhance security protection capabilities.

[0046] In step S5343, the fourth space of the protection mechanism adjustment solutions is optimized based on the communication leakage risk threshold to obtain a fifth space of protection mechanism adjustment solutions. Specifically, understanding the communication leakage risk threshold and the fourth space of the protection mechanism adjustment solutions generated by the second constraint step of the protection adjustment, while ensuring the availability of assessment tools such as a fully trained and validated communication leakage risk prediction model, is the foundation for subsequent optimization analysis. This ensures the scientific and reliable nature of the process, improves the security and stability of cloud computing platforms, promotes their widespread application and development, and is of great significance for protecting user data assets and privacy rights. Next, adjustment solutions are individually extracted from the fourth space and applied to the communication protection mechanism. Their communication leakage risk coefficients are calculated using the risk prediction model and compared with the threshold. This is a key evaluation step. If a solution reduces the risk coefficient below the threshold, such as through measures such as strengthening encryption strength, optimizing connection strategies, and increasing verification frequency, the solution is considered a potentially superior solution. During this process, the accuracy of the solution application and coefficient calculation must be ensured to avoid misjudgment. Finally, all solutions that meet the requirement of risk coefficient less than the threshold are screened out and integrated to form the fifth space of protection mechanism adjustment solution. The solutions are further sorted and classified, such as grouping by protection parameter adjustment method. Basic statistical analysis is also required to understand their distribution characteristics. This provides a more targeted and effective selection range for determining the optimization of communication protection mechanism, which can improve optimization efficiency and quality, ensure the security and stability of platform communication, promote the in-depth application and innovative development of cloud computing technology in various fields, and help build a safe and efficient digital ecosystem. In practice, this process should be continuously improved according to the platform situation to enhance security protection capabilities.

[0047] Step S5344 expands the third space of the protection mechanism adjustment solution based on the fifth space of the protection mechanism adjustment solution to obtain a sixth space of the protection mechanism adjustment solution. Specifically, data from the fifth space of the protection mechanism adjustment solution, selected through optimization analysis based on the communication leakage risk threshold, is extracted. Existing solution information from the third space of the protection mechanism adjustment solution is then obtained. A compatibility check is then performed on the two to ensure that parameter settings, such as those for network traffic monitoring, data encryption algorithms, and identity authentication modules, do not conflict with the protection mechanism. This is a crucial prerequisite for ensuring the effective implementation of the protection mechanism and is of great significance for improving the security and stability of the cloud computing platform, promoting technological application development, and protecting user data rights. Next, solutions in the fifth space are added one by one to expand the third space. During this process, similar solutions are optimized and merged based on factors such as communication leakage risk coefficients and system performance. For example, the optimal settings for similar solutions with different network traffic encryption strengths are selected and merged. The source of the new solution, as well as its differences and optimization points compared to the original solution, are recorded to enrich solution diversity, provide more possibilities for finding the optimal protection mechanism, promote the secure development of cloud computing technology, and assist in the digital transformation of various industries. Finally, the sixth space of the protection mechanism adjustment plan is constructed, and the plan is stored in the form of a database table, etc., which includes detailed parameters, risk assessment results, addition time, source space and other fields, and updates the index to facilitate rapid query and screening based on the risk factor range, specific protection parameter values, etc., to improve the efficiency of plan retrieval and use, provide support for determining and optimizing the communication protection mechanism, ensure the security and stability of platform communications, promote the in-depth application and innovative development of cloud computing technology, and build a safe and efficient digital ecosystem. In practice, this process should be continuously improved according to the platform situation to enhance security protection capabilities.

[0048] Step S5345: Optimize the communication leakage risk minimization within the sixth space of the protection mechanism adjustment scheme to generate the optimized communication protection mechanism. Specifically, minimize the communication leakage risk within the sixth space of the protection mechanism adjustment scheme. An appropriate optimization method, such as a genetic algorithm, is determined. Key parameters such as the population size (e.g., 50), crossover probability (e.g., 0.7), and mutation probability (e.g., 0.05) are set to balance the algorithm's global and local search capabilities. This is crucial for achieving risk minimization and is of great significance for improving cloud computing platform communication security and promoting technological application development. Next, the sixth space is initialized using the selected algorithm. For example, in the genetic algorithm, 50 solutions are randomly selected from this space as the initial population. The genetic encoding of each individual corresponds to the protection mechanism parameters. These individuals are then evaluated using the communication leakage risk prediction model to calculate the communication leakage risk coefficient, which serves as the basis for subsequent evolutionary operations. Accurate and efficient evaluation is crucial at this stage. Then, iterative optimization is carried out. Taking the genetic algorithm as an example, offspring individuals are generated through crossover and mutation, simulating the biological evolution process, increasing population diversity, and avoiding falling into local optimality. The risk coefficient of the offspring individuals is then evaluated, and excellent individuals are selected to enter the next generation based on fitness (related to the risk coefficient). During the process, close attention is paid to the algorithm convergence, and parameters are adjusted when necessary to prevent premature or slow convergence. When the preset termination conditions (such as reaching the maximum number of iterations) are met, the iteration stops. At this time, the solution represented by the optimal individual is the desired solution, which is applied to the communication protection mechanism to generate an optimized protection mechanism. Finally, the optimized mechanism is verified and tested, simulating actual attack scenarios, observing the prevention and control effects and the impact on platform performance. If there are any problems, the optimization process is reviewed and analyzed, and further optimization is carried out by adjusting algorithm parameters, expanding the solution space, or improving the risk prediction model. In practice, the process is continuously improved according to the platform situation, improving security protection capabilities, ensuring data security and user rights, promoting cloud computing technology and industry digital transformation, helping high-quality economic and social development, and playing an important role in information security.

[0049] Step S600, optimize the protection of the communication link according to the optimized communication protection mechanism, obtain the optimized communication link, and execute the communication task to be executed in conjunction with the cloud computing platform. Specifically, analyze and optimize the communication protection mechanism, clarify its various protection components and parameter settings, such as the algorithm, range, and timing of network traffic encryption, the rules of network access control, the parameters of the intrusion detection system, etc., to lay the foundation for subsequent applications, which is crucial to ensuring the communication security of the cloud computing platform and promoting technological development. Then, optimize each link of the communication link based on the analysis results, encrypt data and restrict access at the network layer, such as using a firewall to intercept illegal data packets according to rules; improve the error detection and correction mechanism at the data link layer and adopt an efficient verification algorithm; optimize the communication protocol and data processing method at the application layer, such as using the HTTPS protocol and verifying data signatures, to build an optimized communication link with significantly improved confidentiality, integrity and availability. Finally, the communication link will be optimized and seamlessly integrated with the cloud computing platform to execute the communication tasks to be executed, ensuring the compatibility and coordination of the link and platform software and hardware, reasonably allocating bandwidth resources, establishing a monitoring and management mechanism, monitoring performance and security status in real time, handling abnormalities in a timely manner, ensuring the smooth execution of tasks, and realizing safe and efficient communication on the platform. In practice, this process should be continuously improved according to the platform situation, enhancing security protection capabilities, promoting cloud computing technology and industry digital transformation, assisting high-quality economic and social development, and playing an important role in information security.

[0050] The embodiment of the present application adopts the method of obtaining communication instructions containing communication tasks to be executed and corresponding communication links from a cloud computing platform, performing data leakage risk inspection according to the task, and if it passes, collecting real-time protection parameters of the link to establish a protection mechanism, introducing a risk prediction channel and combining the mechanism to predict the communication data leakage risk coefficient of the task to be executed, and then optimizing and adjusting the protection mechanism according to the risk coefficient, threshold and different constraint step sizes to construct an optimization mechanism, and finally optimizing the communication link protection to obtain an optimized link, and combining the cloud computing platform to execute the task, thereby achieving the technical effect of improving the protection performance of the communication link in the cloud computing environment and reducing the risk of data leakage.

[0051] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention.

[0052] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.

Claims

1. A method for preventing communication data leakage in a cloud computing environment, characterized in that: The method comprises: Obtaining a communication instruction from a cloud computing platform, wherein the communication instruction includes a communication task to be executed and a communication link corresponding to the communication task to be executed; Performing a data leakage risk test on the communication task to be executed to obtain a task leakage risk test result, including: collecting encryption parameters of the communication task to be executed to obtain a task encryption scheme, performing a data leakage risk test on the communication task to be executed based on the task encryption scheme to obtain a task leakage risk coefficient, and obtaining the task leakage risk test result according to the task leakage risk coefficient; When the task leakage risk test result is passed, collecting real-time protection parameters of the communication link and establishing a communication protection mechanism; Introducing a communication leakage risk prediction channel, combining the communication protection mechanism to predict the communication data leakage risk of the communication task to be executed, and obtaining a communication leakage risk coefficient; Based on the communication leakage risk coefficient, the communication protection mechanism is optimized and adjusted according to the communication leakage risk threshold, the first constraint step size of the protection adjustment, and the second constraint step size of the protection adjustment to construct an optimized communication protection mechanism, wherein the first constraint step size of the protection adjustment is greater than the second constraint step size of the protection adjustment; The communication link is protected and optimized according to the optimized communication protection mechanism to obtain an optimized communication link, and the communication task to be executed is executed in conjunction with the cloud computing platform.

2. The method according to claim 1, wherein Performing a data leakage risk test based on the communication task to be executed to obtain a task leakage risk test result includes: Constructing a task leakage risk verification channel, wherein the task leakage risk verification channel includes a task leakage risk prediction model and a leakage risk verification model; Collecting encryption parameters of the communication task to be executed to obtain a task encryption scheme; Inputting the task encryption scheme into the task leakage risk prediction model to obtain a task leakage risk coefficient; The task leakage risk coefficient is input into the leakage risk verification model, and the task leakage risk verification result is output.

3. The method according to claim 2, wherein Build a task leakage risk inspection channel, including: The fully connected neural network is trained with a sample set of task encryption schemes as input information and a sample set of task leakage risk as output information. After each predetermined number of trainings, the leakage risk prediction loss coefficient is obtained. If the leakage risk prediction loss coefficient is less than the leakage risk prediction loss threshold, generating the task leakage risk prediction model; Constructing the leakage risk verification model, wherein the leakage risk verification model includes a leakage risk verification operator, wherein the leakage risk verification operator includes: if the task leakage risk coefficient is less than the task leakage risk threshold, the task leakage risk verification result is passed; if the task leakage risk coefficient is greater than or equal to the task leakage risk threshold, the task leakage risk verification result is failed; The task leakage risk prediction model and the leakage risk verification model are connected to generate the task leakage risk verification channel.

4. The method according to claim 2, wherein When the task leakage risk test result is failed, adjusting the task encryption scheme and establishing a task encryption adjustment scheme space; According to the task encryption adjustment scheme space, randomly extracting the task encryption adjustment scheme n, where n is a positive integer; Inputting the task encryption adjustment nth solution into the task leakage risk verification channel to obtain the leakage risk verification result of the nth solution; When the leakage risk test result of the nth solution is passed, encryption optimization is performed on the communication task to be executed according to the task encryption adjustment nth solution.

5. The method according to claim 1, wherein Introducing a communication leakage risk prediction channel, combining the communication protection mechanism to predict the communication data leakage risk of the communication task to be executed, and obtaining a communication leakage risk coefficient, including: The communication leakage risk prediction channel includes Q communication leakage risk prediction models, where Q is a positive integer greater than 1; Inputting the communication protection mechanism and the communication task to be executed into the Q communication leakage risk prediction models to obtain Q communication leakage risk prediction coefficients; Performing weighted calculation based on the Q communication leakage risk prediction accuracies corresponding to the Q communication leakage risk prediction models to establish leakage risk prediction incentive conditions, wherein the leakage risk prediction incentive conditions include Q leakage risk prediction incentive coefficients; The Q communication leakage risk prediction coefficients are weightedly calculated according to the Q leakage risk prediction incentive coefficients to generate the communication leakage risk coefficient.

6. The method according to claim 1, wherein Based on the communication leakage risk coefficient, the communication protection mechanism is optimized and adjusted according to the communication leakage risk threshold, the first protection adjustment constraint step size, and the second protection adjustment constraint step size to construct an optimized communication protection mechanism, wherein the first protection adjustment constraint step size is greater than the second protection adjustment constraint step size, including: Determining whether the communication leakage risk coefficient is greater than or equal to the communication leakage risk threshold; If the communication leakage risk coefficient is greater than or equal to the communication leakage risk threshold, adjusting the communication protection mechanism according to the first protection adjustment constraint step to obtain a first space of the protection mechanism adjustment scheme; Performing an optimization analysis on the first space of the protection mechanism adjustment solution according to the communication leakage risk threshold to obtain a second space of the protection mechanism adjustment solution; According to the protection mechanism adjustment scheme, the second space is optimized to minimize the risk of communication leakage and generate the optimized communication protection mechanism.

7. The method according to claim 6, wherein Performing an optimization analysis on the first space of the protection mechanism adjustment solution according to the communication leakage risk threshold to obtain a second space of the protection mechanism adjustment solution, including: Randomly extracting a k-th protection mechanism adjustment solution from the first protection mechanism adjustment solution space, where k is a positive integer; Inputting the protection mechanism adjustment scheme k and the communication task to be executed into the communication leakage risk prediction channel to obtain the communication leakage risk coefficient of the k scheme; Determining whether the communication leakage risk coefficient of the k-th solution is less than the communication leakage risk threshold; If the communication leakage risk coefficient of the k-th solution is less than the communication leakage risk threshold, the protection mechanism adjustment k-th solution is added to the second space of the protection mechanism adjustment solution.

8. The method according to claim 6, wherein If the communication leakage risk coefficient is less than the communication leakage risk threshold, adding the communication protection mechanism to the third space of the protection mechanism adjustment scheme; Adjusting the communication protection mechanism according to the second constraint step of the protection adjustment to establish a fourth space of the protection mechanism adjustment scheme; performing an optimization analysis on the fourth space of the protection mechanism adjustment scheme according to the communication leakage risk threshold to obtain a fifth space of the protection mechanism adjustment scheme; Based on the fifth space of the protection mechanism adjustment scheme, the third space of the protection mechanism adjustment scheme is expanded to obtain a sixth space of the protection mechanism adjustment scheme; According to the protection mechanism adjustment scheme, the sixth space is optimized to minimize the risk of communication leakage and generate the optimized communication protection mechanism.

Citation Information

Patent Citations

  • Data leakage prevention method and system based on large language model

    CN118312950A

  • Automobile EDR data encryption protection method and system

    CN118785147A