Encrypted information management system based on big data

By combining symmetric algorithms and asymmetric algorithms in the encrypted information management system and dynamically allocating encryption tasks, the problem of difficult to balance the practicality and efficiency of existing systems is solved, and the speed of encryption algorithms and the optimization of server resources is improved.

CN119938244APending Publication Date: 2025-05-06冯小龙
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411736460.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-04-21
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing encrypted information management system is difficult to balance between practicality and efficiency, resulting in slow algorithm speed and high server resource consumption.

Method used

A large data-based encryption information management system is designed, combining symmetric algorithms and asymmetric algorithms, and dynamically allocates encryption tasks through the response time calculation module, and uses symmetric algorithm encryption modules and asymmetric algorithm encryption module to work together to allocate the encryption workload ratio according to the information volume and response time requirements.

Benefits of technology

While improving the speed of encryption algorithms, it reduces the consumption of server resources and achieves both practicality and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938244A_ABST
    Figure CN119938244A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted information management system based on big data, which comprises a symmetric algorithm encryption module, an asymmetric algorithm encryption module, an information receiving module, a data storage module and a response time calculation module, and is characterized in that the information receiving module and the data storage module are electrically connected with the symmetric algorithm encryption module and the asymmetric algorithm encryption module; the information receiving module is electrically connected with the response time calculation module; the symmetric algorithm encryption module is used for carrying out encryption by utilizing a unique key, the asymmetric algorithm encryption module is used for carrying out encryption by adopting double keys, the information receiving module is used for receiving information needing to be encrypted, and the data storage module is used for storing the encrypted information. The response time calculation module is used for estimating the decryption time of the two encryption modes according to the number of information bytes, and the system further comprises a server resource allocation module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of big data, and in particular to an encrypted information management system based on big data. Background Art

[0002] Information management involves information encryption, which involves symmetric algorithms and asymmetric algorithms. A special case of symmetric algorithms is the "one-time garbled book". This method provides a long and unique key for each message sent for encryption and decryption. The algorithm is fast but the key management cost is high and server resources are required. Asymmetric algorithms use different keys for encrypting and decrypting information. The characteristic is that they use dual keys, and the key management cost is extremely low. They are suitable for large-scale network applications, but the algorithm is slow and has poor practicality. Therefore, it is necessary to design a practical encryption information management system based on big data. Summary of the invention

[0003] The purpose of the present invention is to provide an encrypted information management system based on big data to solve the problems raised in the above background technology.

[0004] In order to solve the above technical problems, the present invention provides the following technical solutions: an encrypted information management system based on big data, comprising a symmetric algorithm encryption module, an asymmetric algorithm encryption module, an information receiving module, a data storage module, and a response time calculation module, wherein the information receiving module and the data storage module are both electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module, and the information receiving module is electrically connected to the response time calculation module;

[0005] The symmetric algorithm encryption module is used to encrypt using a unique key, the asymmetric algorithm encryption module is used to encrypt using a dual key, the information receiving module is used to receive information to be encrypted, the data storage module is used to store the encrypted information, and the response time calculation module is used to estimate the decryption time of the two encryption methods based on the number of information bytes.

[0006] According to the above technical solution, it also includes a server resource allocation module, and the server resource allocation module is electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module;

[0007] The server resource allocation module is used to coordinate the server resources occupied by symmetric algorithm encryption and asymmetric algorithm encryption.

[0008] According to the above technical solution, the work of the system is specifically divided into the following steps:

[0009] S1. When the server starts working, the data to be encrypted is received by the information receiving module;

[0010] S2, using the response time calculation module to calculate the storage volume of the current information, using the two encryption methods to decrypt the time, if it does not exceed the set value, then use the asymmetric algorithm encryption module to encrypt, if it exceeds the set value, then use the symmetric algorithm encryption module to encrypt;

[0011] S3. The encrypted information is transferred to the data storage module for storage, so as to facilitate subsequent processing of the information.

[0012] According to the above technical solution, the working process of the server resource allocation module is:

[0013] S4. Allocate the encryption workload ratio between the symmetric algorithm encryption module and the asymmetric algorithm encryption module according to the corresponding time calculated by the response time calculation module, and transmit the information to be encrypted to the symmetric algorithm encryption module and the asymmetric algorithm encryption module for collaborative encryption.

[0014] According to the above technical solution, in the above step S4, the specific method for allocating the encryption workload ratio is:

[0015] S4-1, when the volume of information to be encrypted is small, that is, when the decryption time estimated by the response time calculation module is less than the first-order set value, the asymmetric algorithm encryption module is used for encryption;

[0016] S4-2, when the amount of information to be encrypted begins to increase, that is, when the decryption time estimated by the response time calculation module is greater than the first-order set value and less than the second-order set value, the proportion of encryption tasks processed by the asymmetric algorithm encryption module is reduced, and the proportion of encryption tasks processed by the symmetric algorithm encryption module is increased;

[0017] S4-3. When the amount of information to be encrypted is large, that is, when the decryption time estimated by the response time calculation module is greater than the second-order set value, the encryption task is completely processed by the symmetric algorithm encryption module.

[0018] According to the above technical solution, in the above step S4-2, the allocation formula of the encryption task is:

[0019]

[0020] Among them, A0 is the total amount of information that needs to be encrypted, A is the amount of information of the encryption task processed by the symmetric algorithm encryption module, A1 is the maximum amount of information of the encryption task processed by the asymmetric algorithm encryption module, p0 is the decryption time of the second-order setting value, and p1 is the decryption time estimated by the response time calculation module.

[0021] According to the above technical solution, the data storage module includes a data compression module and a data decompression module, and the data compression module and the data decompression module are both electrically connected to the asymmetric algorithm encryption module and the symmetric algorithm encryption module;

[0022] The data compression module is used to compress the encrypted data and store it in the server to save space, and the data decompression module is used to decompress the data before decryption to facilitate decryption.

[0023] According to the above technical solution, the compressed information ratio α of the data compression module is related to the task ratio processed by the symmetric algorithm encryption module and the asymmetric algorithm encryption module, that is, the more information encrypted by the symmetric algorithm, the higher the information ratio α compressed by the data compression module, specifically:

[0024] α=A / A1k, where k is the proportionality coefficient.

[0025] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: the present invention adopts a technology that combines symmetric algorithms and asymmetric algorithms to give different instantaneous weights to the two encryption algorithms. The instantaneous weights are allocated according to the customer's response time requirements for the usage scenarios, and a suitable encryption information method allocation ratio is given to each scenario, which can reduce server resource consumption while improving the algorithm speed. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0027] Figure 1 It is a schematic diagram of the overall principle of the present invention; DETAILED DESCRIPTION

[0028] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0029] See also Figure 1 The present invention provides a technical solution: an encrypted information management system based on big data, including a symmetric algorithm encryption module, an asymmetric algorithm encryption module, an information receiving module, a data storage module, and a response time calculation module, wherein the information receiving module and the data storage module are both electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module, and the information receiving module is electrically connected to the response time calculation module;

[0030] The symmetric algorithm encryption module is used to encrypt using a unique key, the asymmetric algorithm encryption module is used to encrypt using a double key, the information receiving module is used to receive information to be encrypted, the data storage module is used to store the encrypted information, and the response time calculation module is used to estimate the decryption time of the two encryption methods based on the number of information bytes;

[0031] It also includes a server resource allocation module, which is electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module;

[0032] The server resource allocation module is used to coordinate the server resources occupied by symmetric algorithm encryption and asymmetric algorithm encryption;

[0033] The working of the system is specifically divided into the following steps:

[0034] S1. When the server starts working, the data to be encrypted is received by the information receiving module;

[0035] S2. Calculate the decryption time of the current information storage volume using the response time calculation module, and use the two encryption methods. If it does not exceed the set value, encrypt it using the asymmetric algorithm encryption module. If it exceeds the set value, encrypt it using the symmetric algorithm encryption module.

[0036] S3, transferring the encrypted information to the data storage module for storage, so as to facilitate subsequent processing of the information;

[0037] The working process of the server resource allocation module is as follows:

[0038] S4. Allocate the encryption workload ratio between the symmetric algorithm encryption module and the asymmetric algorithm encryption module according to the corresponding time calculated by the response time calculation module, and transmit the information to be encrypted to the symmetric algorithm encryption module and the asymmetric algorithm encryption module for collaborative encryption;

[0039] In the above step S4, the specific method for allocating the encryption workload ratio is:

[0040] S4-1, when the volume of information to be encrypted is small, that is, when the decryption time estimated by the response time calculation module is less than the first-order set value, the asymmetric algorithm encryption module is used for encryption;

[0041] S4-2, when the amount of information to be encrypted begins to increase, that is, when the decryption time estimated by the response time calculation module is greater than the first-order set value and less than the second-order set value, the proportion of encryption tasks processed by the asymmetric algorithm encryption module is reduced, and the proportion of encryption tasks processed by the symmetric algorithm encryption module is increased;

[0042] S4-3, when the amount of information to be encrypted is large, that is, when the decryption time estimated by the response time calculation module is greater than the second-order set value, the encryption task is completely processed by the symmetric algorithm encryption module;

[0043] In the above step S4-2, the encryption task allocation formula is:

[0044]

[0045] Where A0 is the total amount of information that needs to be encrypted, A is the amount of information in the encryption task processed by the symmetric algorithm encryption module, A1 is the maximum amount of information in the encryption task processed by the asymmetric algorithm encryption module, p0 is the decryption time of the second-order setting value, and p1 is the decryption time estimated by the response time calculation module;

[0046] The data storage module includes a data compression module and a data decompression module, and the data compression module and the data decompression module are both electrically connected to the asymmetric algorithm encryption module and the symmetric algorithm encryption module;

[0047] The data compression module is used to compress the encrypted data and store it in the server to save space, and the data decompression module is used to decompress the data before decryption to facilitate decryption;

[0048] The compressed information ratio α of the data compression module is related to the task ratio processed by the symmetric algorithm encryption module and the asymmetric algorithm encryption module. That is, the more information encrypted by the symmetric algorithm, the higher the information ratio α compressed by the data compression module. Specifically:

[0049] α=A / A1k, where k is the proportional coefficient. The technology combining symmetric and asymmetric algorithms is used to give different instantaneous weights to the two encryption algorithms. The instantaneous weights are allocated according to the customer's response time requirements for the usage scenarios, and the appropriate encryption information method allocation ratio is given to each scenario. This can reduce server resource consumption while improving the algorithm speed.

[0050] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.

[0051] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein by equivalents. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An encrypted information management system based on big data, characterized in that: It includes a symmetric algorithm encryption module, an asymmetric algorithm encryption module, an information receiving module, a data storage module, and a response time calculation module. The information receiving module and the data storage module are both electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module, and the information receiving module is electrically connected to the response time calculation module; the symmetric algorithm encryption module is used to encrypt using a unique key, the asymmetric algorithm encryption module is used to encrypt using a double key, the information receiving module is used to receive information to be encrypted, the data storage module is used to store the encrypted information, and the response time calculation module is used to estimate the decryption time of the two encryption methods according to the number of information bytes; It also includes a server resource allocation module, which is electrically connected to the symmetric algorithm encryption module and the asymmetric algorithm encryption module; the server resource allocation module is used to adjust the server resources occupied by the symmetric algorithm encryption and the asymmetric algorithm encryption; The work of the system is specifically divided into the following steps: S1. When the server starts working, the data to be encrypted is received by the information receiving module; S2. The response time calculation module is used to calculate the decryption time under the storage volume of the current information, and the decryption time under the two encryption methods is used. If it does not exceed the set value, the asymmetric algorithm encryption module is used for encryption. If it exceeds the set value, the symmetric algorithm encryption module is used for encryption; S3. The encrypted information is transferred to the data storage module for storage, which is convenient for subsequent processing of the information; The working process of the server resource allocation module is as follows: S4, according to the corresponding time calculated by the response time calculation module, the encryption workload ratio undertaken by the symmetric algorithm encryption module and the asymmetric algorithm encryption module is allocated, and the information to be encrypted is transmitted to the symmetric algorithm encryption module and the asymmetric algorithm encryption module for collaborative encryption; In the above step S4, the specific method for allocating the encryption workload ratio is as follows: S4-1, when the volume of information to be encrypted is small, that is, when the decryption time estimated by the response time calculation module is less than the first-order setting value, the asymmetric algorithm encryption module is used for encryption; S4-2, when the volume of information to be encrypted begins to increase, that is, when the decryption time estimated by the response time calculation module is greater than the first-order setting value and less than the second-order setting value, the proportion of encryption tasks processed by the asymmetric algorithm encryption module is reduced, and the proportion of encryption tasks processed by the symmetric algorithm encryption module is increased; S4-3, when the volume of information to be encrypted is large, that is, when the decryption time estimated by the response time calculation module is greater than the second-order setting value, the encryption tasks are completely processed by the symmetric algorithm encryption module; In the above step S4-2, the encryption task allocation formula is: Where A0 is the total amount of information that needs to be encrypted, A is the amount of information in the encryption task processed by the symmetric algorithm encryption module, A1 is the maximum amount of information in the encryption task processed by the asymmetric algorithm encryption module, p0 is the decryption time of the second-order setting value, and p1 is the decryption time estimated by the response time calculation module; The data storage module includes a data compression module and a data decompression module, and the data compression module and the data decompression module are both electrically connected to the asymmetric algorithm encryption module and the symmetric algorithm encryption module; The compressed information ratio α of the data compression module is related to the task ratio processed by the symmetric algorithm encryption module and the asymmetric algorithm encryption module, that is, the more information encrypted by the symmetric algorithm, the higher the information ratio α compressed by the data compression module, specifically: α=A / A1k, where k is the proportional coefficient.

2. The encryption information management system based on big data according to claim 1, characterized in that: The data compression module is used to compress the encrypted data and store it in the server to save space, and the data decompression module is used to decompress the data before decryption to facilitate decryption.