Data security encryption transmission system and method in cloud computing environment

By using multi-factor authentication, dynamic encryption algorithms, quantum encryption technology and distributed key management in the cloud computing environment, the problem that existing solutions cannot cope with complex network attacks and quantum computing security threats is solved, and high security and rapid recovery capabilities of data transmission are achieved.

CN119945785AInactive Publication Date: 2025-05-06ZHOUKOU VOCATIONAL & TECHN COLLEGE
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510110352.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Data security encryption transmission solutions in existing cloud computing environments cannot effectively deal with security threats brought by complex network attacks and quantum computing, and key management and data recovery mechanisms are insufficient.

Method used

Multi-factor authentication, dynamic encryption algorithms, quantum encryption technology and distributed key management are adopted, and virtual private network and real-time network traffic analysis technology are combined to dynamically build secure channels, and real-time anomaly detection and protection are carried out through artificial intelligence and machine learning.

Benefits of technology

It effectively improves the security protection capabilities during data transmission, prevents attacks by man-in-the-middles, data tampering and leakage, and realizes the rapid recovery of data in the event of catastrophic events, ensuring the integrity and timeliness of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945785A_ABST
    Figure CN119945785A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data encryption transmission, and particularly discloses a data security encryption transmission system and method in a cloud computing environment, and the system comprises an identity authentication module which is used for verifying the identity of each transmission party through at least two authentication modes, and authorizing a legal user to carry out data transmission; the data encryption module is used for encrypting to-be-transmitted data by adopting a mode of combining symmetric encryption and asymmetric encryption, and automatically adjusting an encryption strategy based on a dynamic encryption algorithm selection mechanism and a quantum encryption technology; the key management module is used for dynamically generating and managing a key in an encryption transmission process, performing multi-level key storage and access control by adopting a distributed key management scheme, and tracking the life cycle of the key by utilizing a block chain technology; not only is the security of data transmission in the cloud computing environment enhanced, but also the flexibility and the strain capacity of data transmission are improved, and the challenge of network attacks is fully dealt with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption transmission, and specifically relates to a data security encryption transmission system and method in a cloud computing environment. Background Art

[0002] With the rapid development of cloud computing technology, the demand for data transmission and storage is growing. However, with the increase in data volume and the complexity of the network environment, data security is facing more and more challenges. During the transmission process, data is vulnerable to various attacks, such as man-in-the-middle attacks, data tampering, and leakage, which poses a serious threat to the information security of enterprises and individuals.

[0003] The existing cloud computing data security encryption transmission scheme mainly relies on traditional encryption algorithms and key management technologies. Although they can guarantee data security to a certain extent, they still have some shortcomings. For example, traditional encryption technology cannot cope with increasingly complex network attacks, and cannot effectively solve the security threats brought by quantum computing; at the same time, the key management and update mechanism is relatively simple, which is prone to the risk of key leakage; and in the data transmission process, there is a lack of sufficient intelligent means to detect and defend against abnormal behavior in real time, and it is impossible to quickly recover lost or tampered data. At the same time, with the continuous escalation of network attack methods, the existing security audit, anomaly detection and key management schemes are also unable to cope with the situation. In addition, with the continuous advancement of quantum computing technology, traditional encryption technology has gradually exposed vulnerable vulnerabilities.

[0004] Therefore, it is necessary to propose a data security encryption transmission system and method in a cloud computing environment to solve the problem of how to ensure the security, confidentiality and integrity of data transmission in a cloud computing environment in the prior art. Summary of the invention

[0005] The purpose of the present invention is to provide a data security encryption transmission system and method in a cloud computing environment to solve the problems raised in the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A data security encryption transmission system in a cloud computing environment, comprising:

[0008] An identity authentication module, used to verify the identities of the transmission parties through at least two authentication methods and authorize legitimate users to transmit data;

[0009] The data encryption module is used to encrypt the data to be transmitted by combining symmetric encryption and asymmetric encryption, and automatically adjust the encryption strategy based on the dynamic encryption algorithm selection mechanism and quantum encryption technology;

[0010] The key management module is used to dynamically generate and manage keys during encrypted transmission. It uses a distributed key management solution for multi-level key storage and access control, and uses blockchain technology to track the life cycle of keys.

[0011] Channel construction module, which is used to dynamically build a secure data transmission channel based on virtual private network and real-time network traffic analysis technology to prevent data from being attacked or monitored by external parties during transmission;

[0012] Anomaly detection module, which is used to monitor anomalies in the data transmission process in real time and apply artificial intelligence and machine learning algorithms for automatic protection;

[0013] The security audit module is used to record and monitor security logs during data transmission, track related security events, and ensure the immutability of audit logs through blockchain technology;

[0014] The data recovery module is used to restore the original data in case of data loss or error, and combines cross-regional cloud storage backup and disaster recovery mechanisms to ensure the integrity and timeliness of data recovery.

[0015] Preferably, the identity authentication module is also used to strictly control data access during the transmission process based on the role permissions of the transmitting parties;

[0016] Introducing a hierarchical management system based on data sensitivity, automatically adjusting encryption strength and access control policies by classifying and labeling data content according to sensitivity;

[0017] At least two authentication methods are a combination of two or more of username / password, digital certificate, fingerprint or facial recognition, biometric authentication or dynamic token.

[0018] Preferably, the data encryption module is also used to automatically select the most suitable encryption algorithm according to the sensitivity classification of the transmitted data, the transmission speed requirement and the network environment;

[0019] The differential privacy algorithm is used to protect private data when transmitting data. The formula is as follows:

[0020] P(O|X)≤exp(ε)·P(O|X′)

[0021] Where P(O|X) is the observed event probability, ε is the privacy budget, and X and X′ are the data inputs;

[0022] Integrate quantum encryption technology to encrypt data in quantum computing environments.

[0023] Preferably, the key management module is also used to exchange asymmetric encryption keys using the Diffie-Hellman key exchange protocol, and the formula is as follows:

[0024] K=g ab modp

[0025] In the formula, g is the generator, a and b are private keys, p is a prime number, and K is the shared key;

[0026] Introducing a dynamic key generation mechanism based on timestamp to generate new encryption keys each time data is transmitted;

[0027] G(t)=H(t,S)modN

[0028] Where G(t) is the key generated at timestamp t, H is the hash function, S is the session information, and N is the size of the key space;

[0029] Using the adaptive key update strategy, the key update frequency is dynamically adjusted according to the network load, attack risk, and data transmission frequency. The dynamic adjustment formula is as follows:

[0030] T update =f(λ,L,F,ω)

[0031] Where, T update is the key update frequency, λ is the network load, L is the transmission delay, F is the transmission frequency, and ω is the attack risk.

[0032] Preferably, the channel construction module is also used to dynamically construct a secure data transmission channel based on a virtual private network and a transmission security protocol technology;

[0033] Automatically adjust data transmission channels based on real-time analysis of network traffic, load monitoring, and multi-point fault detection;

[0034] During data transmission, the integrity of the transmitted data is checked through a hash algorithm to prevent the data from being tampered with during transmission.

[0035] Preferably, the security audit module is also used to record all operation logs of data transmission using blockchain technology and generate log files for subsequent tracing, in which the hash chain formula can be used to prevent tampering:

[0036] H(B i )=H(B i-1 ||Data)

[0037] In the formula, B i is a block, B i-1 It is the previous block;

[0038] Analyze log files through artificial intelligence to identify abnormal behaviors and trigger protective measures in time.

[0039] Preferably, the anomaly detection module is also used to analyze abnormal behaviors in the data transmission process in real time through a machine learning algorithm, and automatically take protective measures to prevent data from being tampered with or lost;

[0040] Use artificial intelligence technology to automatically identify potential security threats and adjust security policies in real time based on behavioral patterns and historical data during data transmission;

[0041] Integrate deep learning models to perform real-time analysis of network traffic during transmission, identify and block potential network attacks.

[0042] Preferably, the data recovery module is also used to introduce a cross-regional data encryption transmission mechanism to encrypt the transmission between different regions;

[0043] Utilize the cross-regional backup and disaster recovery mechanism of cloud storage services to quickly restore original data when a disaster occurs.

[0044] A data security encryption transmission method in a cloud computing environment, comprising:

[0045] Step 1: Use multi-factor authentication to verify the identities of all parties involved in data transmission and implement strict role-based permission control on the data being transmitted;

[0046] Step 2: Exchange keys through asymmetric encryption algorithms and encrypt data using symmetric encryption algorithms, combined with dynamic encryption algorithm selection mechanisms and quantum encryption technology;

[0047] Step 3: Automatically generate new encryption keys through a timestamp-based dynamic key generation mechanism, and introduce an adaptive key update strategy to dynamically adjust the key update frequency;

[0048] Step 4: Use secure transmission protocols combined with encrypted transmission channels to prevent man-in-the-middle attacks and perform integrity checks on transmitted data;

[0049] Step 5: Record and monitor security events during data transmission in real time, conduct security audits, and identify abnormal behaviors through artificial intelligence technology;

[0050] Step 6: Use artificial intelligence and deep learning algorithms to monitor abnormal situations during data transmission in real time and automatically take protective measures.

[0051] Preferably, the method introduces an encryption module based on trusted computing technology to perform hardware acceleration on the data encryption and decryption process, and adds real-time data snapshot and differential backup technology during data transmission to restore to the previous safe state in real time when an abnormality or transmission interruption occurs. The recovery formula of differential backup is as follows:

[0052]

[0053] In the formula, R is the restored data, Backup t-1 is the last backup data, and ΔD is the current difference data.

[0054] Compared with the prior art, the present invention has the following beneficial effects:

[0055] The present invention combines multiple authentication mechanisms, dynamic encryption algorithms, quantum encryption technology, and distributed key management to effectively improve the security protection capabilities of data during transmission, prevent security threats such as man-in-the-middle attacks, data tampering, and leakage; intelligent anomaly detection and real-time protection mechanisms can timely identify and respond to potential network attacks or data anomalies; introduce adaptive key update strategies and cross-regional data backup and recovery solutions to enable rapid data recovery in the event of a catastrophic event, ensuring data integrity and timeliness. This not only enhances the security of data transmission in a cloud computing environment, but also improves the flexibility and adaptability of data transmission, fully responding to the challenges of network attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 This is a framework diagram of the data security encryption transmission system in the cloud computing environment of the present invention;

[0057] Figure 2 This is a flow chart of the data security encryption transmission method in the cloud computing environment of the present invention. DETAILED DESCRIPTION

[0058] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0059] Embodiment 1:

[0060] See also Figure 1 As shown, a data security encryption transmission system in a cloud computing environment includes:

[0061] An identity authentication module, used to verify the identities of the transmission parties through at least two authentication methods and authorize legitimate users to transmit data;

[0062] The data encryption module is used to encrypt the data to be transmitted by combining symmetric encryption and asymmetric encryption, and automatically adjust the encryption strategy based on the dynamic encryption algorithm selection mechanism and quantum encryption technology;

[0063] The key management module is used to dynamically generate and manage keys during encrypted transmission. It uses a distributed key management solution for multi-level key storage and access control, and uses blockchain technology to track the life cycle of keys.

[0064] Channel construction module, which is used to dynamically build a secure data transmission channel based on virtual private network and real-time network traffic analysis technology to prevent data from being attacked or monitored by external parties during transmission;

[0065] Anomaly detection module, which is used to monitor anomalies in the data transmission process in real time and apply artificial intelligence and machine learning algorithms for automatic protection;

[0066] The security audit module is used to record and monitor security logs during data transmission, track related security events, and ensure the immutability of audit logs through blockchain technology;

[0067] The data recovery module is used to restore the original data in case of data loss or error, and combines cross-regional cloud storage backup and disaster recovery mechanisms to ensure the integrity and timeliness of data recovery.

[0068] The identity authentication module is also used to strictly control data access during the transmission process based on the role permissions of the two parties to the transmission; introduce a hierarchical management system based on data sensitivity, and automatically adjust the encryption strength and access control strategy by classifying and labeling the data content according to sensitivity; at least two authentication methods are username / password, digital certificate, fingerprint or facial recognition, biometric authentication or a combination of two or more of dynamic tokens.

[0069] Furthermore, multi-factor authentication is adopted, combined with role-based permission management to strictly control data access. A hierarchical management system based on data sensitivity is also introduced to automatically adjust encryption strength and access control strategies according to different roles and data sensitivity, thereby achieving more detailed and flexible permission management.

[0070] The data encryption module is also used to automatically select the most suitable encryption algorithm based on the sensitivity classification of the transmitted data, the transmission speed requirements and the network environment; use the differential privacy algorithm to protect privacy data when transmitting data; and integrate quantum encryption technology for data encryption processing in the quantum computing environment.

[0071] Example: Symmetric encryption uses the AES algorithm, and asymmetric encryption uses the RSA algorithm. When using the symmetric encryption algorithm, the AES algorithm is used with a key length of 256 bits; when using the asymmetric encryption algorithm, the RSA algorithm is used with a key length of 2048 bits.

[0072] Furthermore, a combination of symmetric and asymmetric encryption is adopted, and based on a dynamic encryption algorithm selection mechanism and quantum encryption technology, it can flexibly respond to security requirements in different transmission scenarios, improve the strength and flexibility of data encryption, and consider resisting security threats brought by quantum computing.

[0073] The key management module is also used to exchange asymmetric encryption keys using the Diffie-Hellman key exchange protocol; a timestamp-based dynamic key generation mechanism is introduced to generate new encryption keys each time data is transmitted; and an adaptive key update strategy is used to dynamically adjust the key update frequency based on network load, attack risk, and data transmission frequency.

[0074] Furthermore, a distributed key management solution is adopted, and blockchain technology is used to track and manage the key life cycle to ensure the security and non-tamperability of the key, and effectively prevent key leakage and abuse.

[0075] The channel construction module is also used to dynamically build a secure data transmission channel based on virtual private network and transmission security protocol technology; automatically adjust the data transmission channel based on real-time analysis of network traffic, load monitoring and multi-point fault detection; during the data transmission process, the transmitted data is checked for integrity through a hash algorithm to prevent data tampering during transmission.

[0076] Furthermore, dynamically building a secure data transmission channel can effectively prevent data from being attacked or monitored by the outside world during transmission, while performing integrity verification through a hash algorithm to ensure the accuracy and reliability of the data.

[0077] The security audit module is also used to record all operation logs of data transmission using blockchain technology and generate log files for subsequent tracing, where hash chain formulas can be used to prevent tampering; log files are analyzed through artificial intelligence to identify abnormal behaviors and trigger protective measures in a timely manner.

[0078] Furthermore, blockchain technology is used to record all operation logs to ensure the immutability of audit logs, and log files are analyzed through artificial intelligence to identify and respond to abnormal behaviors in a timely manner, thereby enhancing the audit capabilities and security of data transmission.

[0079] The anomaly detection module is also used to analyze abnormal behaviors in the data transmission process in real time through machine learning algorithms, and automatically take protective measures to prevent data tampering or loss; use artificial intelligence technology to automatically identify potential security threats based on behavioral patterns and historical data in the data transmission process, and adjust security policies in real time; integrate deep learning models to perform real-time analysis of network traffic in the transmission process, identify and block potential network attacks.

[0080] Furthermore, artificial intelligence and machine learning algorithms were introduced to monitor and analyze abnormal behaviors during data transmission in real time, automatically identify potential security threats and trigger protective measures, greatly enhancing the system's defense capabilities against unknown attacks.

[0081] The data recovery module is also used to introduce a cross-regional data encryption transmission mechanism to encrypt the transmission between different regions; and to use the cross-regional backup and disaster recovery mechanism of the cloud storage service to quickly restore the original data when a disaster occurs.

[0082] Embodiment 2:

[0083] See also Figure 2 As shown, a data security encryption transmission method in a cloud computing environment includes:

[0084] Step 1: Use multi-factor authentication to verify the identities of all parties involved in data transmission and implement strict role-based permission control on the data being transmitted;

[0085] Step 2: Exchange keys through asymmetric encryption algorithms and encrypt data using symmetric encryption algorithms, combined with dynamic encryption algorithm selection mechanisms and quantum encryption technology;

[0086] Step 3: Automatically generate new encryption keys through a timestamp-based dynamic key generation mechanism, and introduce an adaptive key update strategy to dynamically adjust the key update frequency;

[0087] Step 4: Use secure transmission protocols combined with encrypted transmission channels to prevent man-in-the-middle attacks and perform integrity checks on transmitted data;

[0088] Step 5: Record and monitor security events during data transmission in real time, conduct security audits, and identify abnormal behaviors through artificial intelligence technology;

[0089] Step 6: Use artificial intelligence and deep learning algorithms to monitor abnormal situations during data transmission in real time and automatically take protective measures.

[0090] An encryption module based on trusted computing technology is introduced to perform hardware acceleration on the data encryption and decryption process. In addition, real-time data snapshot and differential backup technology are added during data transmission to restore to the previous secure state in real time when an abnormality or transmission interruption occurs.

[0091] Application example: Encrypted transmission of sensitive data between enterprises

[0092] In a multinational company, various branches and partners of the company need to frequently exchange sensitive information, such as financial data, employee personal information, product design information, etc. Due to the high sensitivity of this data, it is necessary to ensure that the data is not leaked or tampered with during transmission. At the same time, with the continuous development of network attack technology, companies need to strengthen the security of data transmission.

[0093] The data transmission process is as follows:

[0094] (1) Identity Authentication and Authorization

[0095] At the beginning of data transmission, the transmitter and receiver verify their identities through multi-factor authentication to ensure that only legitimate users can exchange data; at the same time, strict access rights control is performed on the transmitted data to limit the user's access rights to sensitive data based on their role.

[0096] (2) Key exchange and encryption

[0097] After authentication, both parties use the Diffie-Hellman protocol to exchange keys and ensure the security of the keys through asymmetric encryption technology; select appropriate encryption algorithms based on the type and sensitivity of the transmitted data, such as AES symmetric encryption; the encryption process takes into account the threat posed to encrypted data by the development of quantum computing.

[0098] (3) Data transmission

[0099] The encrypted data is transmitted in the established secure channel through VPN and transmission security protocol; during the transmission process, real-time monitoring and traffic analysis technology ensures that the data will not be attacked or tampered with by man-in-the-middle attacks.

[0100] (4) Anomaly detection and protection

[0101] Continuously monitor the data transmission process, apply machine learning and artificial intelligence technologies to detect any abnormal behavior, and automatically take protective measures; if an abnormality is found, such as an abnormal data transmission rate or an unauthorized user attempting to access sensitive data, the connection will be automatically disconnected and an alarm will be issued.

[0102] (5) Security Audit

[0103] The operation logs of all data transmissions will be recorded through blockchain technology to ensure that the log contents cannot be tampered with. The operation logs will be regularly analyzed through artificial intelligence technology to identify potential risks and trigger corresponding security response measures.

[0104] (6) Data recovery

[0105] If data loss or tampering occurs, the cross-regional cloud backup and disaster recovery mechanism will be used to restore the data to the latest security state; the data during the recovery process will be checked for integrity to ensure that the recovered data has not been tampered with.

[0106] As can be seen from the above, the present invention effectively improves the security protection capability of data during transmission by combining multiple authentication mechanisms, dynamic encryption algorithms, quantum encryption technology and distributed key management, preventing security threats such as man-in-the-middle attacks, data tampering and leakage; intelligent anomaly detection and real-time protection mechanisms timely identify and respond to potential network attacks or data anomalies; introduces adaptive key update strategies and cross-regional data backup and recovery solutions to enable rapid data recovery in the event of a catastrophic event, ensuring data integrity and timeliness. This not only enhances the security of data transmission in a cloud computing environment, but also improves the flexibility and adaptability of data transmission, fully responding to the challenges of network attacks.

[0107] Embodiment 3:

[0108] The embodiment of the present invention also provides a computer-readable storage medium, on which is stored a program of a data security encryption transmission system in a cloud computing environment as described above, and when the program is executed by a processor, each process of the above encryption transmission system embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. Among them, the computer-readable storage medium, such as read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), a disk or an optical disk, etc.

[0109] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples" or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification and the features of different embodiments or examples, unless they are contradictory.

[0110] In the drawings of the embodiments disclosed in the present invention, only the structures involved in the embodiments disclosed in the present invention are involved, and other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of the present invention can be combined with each other.

[0111] The flowcharts shown in the accompanying drawings are only examples and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may also be decomposed, combined or partially merged, so the actual execution order may change according to actual conditions.

[0112] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A data security encryption transmission system in a cloud computing environment, characterized in that: include: An identity authentication module, used to verify the identities of the transmission parties through at least two authentication methods and authorize legitimate users to transmit data; The data encryption module is used to encrypt the data to be transmitted by combining symmetric encryption and asymmetric encryption, and automatically adjust the encryption strategy based on the dynamic encryption algorithm selection mechanism and quantum encryption technology; The key management module is used to dynamically generate and manage keys during encrypted transmission. It uses a distributed key management solution for multi-level key storage and access control, and uses blockchain technology to track the life cycle of keys. Channel construction module, which is used to dynamically build a secure data transmission channel based on virtual private network and real-time network traffic analysis technology to prevent data from being attacked or monitored by external parties during transmission; Anomaly detection module, which is used to monitor anomalies in the data transmission process in real time and apply artificial intelligence and machine learning algorithms for automatic protection; The security audit module is used to record and monitor security logs during data transmission, track related security events, and ensure the immutability of audit logs through blockchain technology; The data recovery module is used to restore the original data in case of data loss or error, and combines cross-regional cloud storage backup and disaster recovery mechanisms to ensure the integrity and timeliness of data recovery.

2. According to the data security encryption transmission system in a cloud computing environment of claim 1, it is characterized in that: The identity authentication module is also used for: Strictly control data access during the transmission process based on the role permissions of both parties; Introducing a hierarchical management system based on data sensitivity, automatically adjusting encryption strength and access control policies by classifying and labeling data content according to sensitivity; The at least two authentication methods are a combination of two or more of username / password, digital certificate, fingerprint or facial recognition, biometric authentication or dynamic token.

3. According to the data security encryption transmission system in a cloud computing environment of claim 2, it is characterized in that: The data encryption module is also used for: Automatically select the most suitable encryption algorithm based on the sensitivity classification of the transmitted data, the transmission speed requirements and the network environment; The differential privacy algorithm is used to protect private data when transmitting data. The formula is as follows: P(O|X)≤exp(ε)·P(O|X′) Where P(O|X) is the observed event probability, ε is the privacy budget, and X and X′ are the data inputs; Integrate quantum encryption technology to encrypt data in quantum computing environments.

4. According to the data security encryption transmission system in a cloud computing environment of claim 3, it is characterized in that: The key management module is also used for: The Diffie-Hellman key exchange protocol is used to exchange asymmetric encryption keys. The formula is as follows: K=g ab mod p In the formula, g is the generator, a and b are private keys, p is a prime number, and K is the shared key; Introducing a dynamic key generation mechanism based on timestamp to generate new encryption keys each time data is transmitted; G(t)=H(t,S)modN Where G(t) is the key generated at timestamp t, H is the hash function, S is the session information, and N is the size of the key space; Using the adaptive key update strategy, the key update frequency is dynamically adjusted according to the network load, attack risk, and data transmission frequency. The dynamic adjustment formula is as follows: T update =f(λ,L,F,ω) Where, T update is the key update frequency, λ is the network load, L is the transmission delay, F is the transmission frequency, and ω is the attack risk.

5. According to the data security encryption transmission system in a cloud computing environment of claim 4, it is characterized in that: The channel building module is also used to: Dynamically build a secure data transmission channel based on virtual private network and transmission security protocol technology; Automatically adjust data transmission channels based on real-time analysis of network traffic, load monitoring, and multi-point fault detection; During data transmission, the integrity of the transmitted data is checked through a hash algorithm to prevent the data from being tampered with during transmission.

6. The data security encryption transmission system in a cloud computing environment according to claim 5 is characterized in that: The security audit module is also used to: Use blockchain technology to record all operation logs of data transmission and generate log files for later tracing, in which the hash chain formula can be used to prevent tampering: H(B i )=H(B i-1 ||Data) In the formula, B i is a block, B i-1 It is the previous block; The log files are analyzed through artificial intelligence to identify abnormal behaviors and trigger protective measures in a timely manner.

7. The data security encryption transmission system in a cloud computing environment according to claim 6 is characterized in that: The anomaly detection module is also used for: Use machine learning algorithms to analyze abnormal behaviors during data transmission in real time and automatically take protective measures to prevent data from being tampered with or lost; Use artificial intelligence technology to automatically identify potential security threats and adjust security policies in real time based on behavioral patterns and historical data during data transmission; Integrate deep learning models to perform real-time analysis of network traffic during transmission, identify and block potential network attacks.

8. The data security encryption transmission system in a cloud computing environment according to claim 7 is characterized in that: The data recovery module is also used for: Introduce a cross-region data encryption transmission mechanism to encrypt transmission between different regions; The cross-regional backup and disaster recovery mechanism of the cloud storage service is utilized to quickly restore the original data when a disaster occurs.

9. A data security encryption transmission method in a cloud computing environment, characterized in that: include: Step 1: Use multi-factor authentication to verify the identities of all parties involved in data transmission and implement strict role-based permission control on the data being transmitted; Step 2: Exchange keys through asymmetric encryption algorithms and encrypt data using symmetric encryption algorithms, combined with dynamic encryption algorithm selection mechanisms and quantum encryption technology; Step 3: Automatically generate new encryption keys through a timestamp-based dynamic key generation mechanism, and introduce an adaptive key update strategy to dynamically adjust the key update frequency; Step 4: Use secure transmission protocols combined with encrypted transmission channels to prevent man-in-the-middle attacks and perform integrity checks on transmitted data; Step 5: Record and monitor security events during data transmission in real time, conduct security audits, and identify abnormal behaviors through artificial intelligence technology; Step 6: Use artificial intelligence and deep learning algorithms to monitor abnormal situations during data transmission in real time and automatically take protective measures.

10. The method for secure data encryption transmission in a cloud computing environment according to claim 9, characterized in that: The method introduces an encryption module based on trusted computing technology to perform hardware acceleration on the data encryption and decryption process, and adds real-time data snapshot and differential backup technology during data transmission to restore to the previous safe state in real time when an abnormality or transmission interruption occurs. The recovery formula of differential backup is as follows: In the formula, R is the restored data, Backup t-1 is the last backup data, and ΔD is the current difference data.

Citation Information

Cited By

  • Intelligent analysis system and method for secure transmission of chip data

    CN120434049A

  • Supply chain data encryption storage method based on edge calculation

    CN120474839A

  • Edge computing-based encrypted storage method for supply chain data

    CN120474839B

  • Security guarantee system for cross-domain communication and data sharing of network platform software

    CN120567551A

  • Security system for cross-domain communication and data sharing of network platform software

    CN120567551B