Alliance encryption method and node management system
By adopting alliance encryption methods in dynamic network environments, combining elliptic curve algorithms and chunking processing, the shortcomings in existing encryption methods in key management, computing efficiency and security are solved, and more efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510145373.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-13
AI Technical Summary
Existing encryption methods have problems in dynamic network environments where key management complexity, insufficient computing efficiency and security dependence on a single algorithm.
A alliance encryption method is adopted to obtain the scene type data and feature data of the data to be transmitted, determine the elliptic curve algorithm and curve parameters, and perform chunking processing and quadratic encryption, and dynamically adjust the encryption algorithm and curve parameters to improve security and efficiency.
It improves the computing efficiency of data processing, adapts to large-scale data applications, and reduces the security risks caused by the breach of a single algorithm through multiple encryption mechanisms and dynamic adjustment strategies.
Smart Images

Figure CN119995988A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain encryption technology, and in particular to an alliance encryption method and a node management system. Background Art
[0002] With the rapid development of blockchain technology, data privacy protection and security have become urgent issues to be resolved. Existing encryption methods, such as elliptic curve encryption and homomorphic encryption, have certain advantages in security and efficiency, but still have the following problems in dynamic network environments:
[0003] Complexity of key management: In a dynamic environment, the generation, update and management of keys are complex, which can easily lead to security risks.
[0004] Insufficient computational efficiency: Existing homomorphic encryption algorithms have low encryption and decryption efficiency under high-bit keys, which limits their application in large-scale data processing.
[0005] Security depends on a single algorithm: The security of existing solutions is highly dependent on a specific encryption algorithm. Once the algorithm is cracked, the security of the entire system will be threatened. Summary of the invention
[0006] In order to overcome the deficiencies of the prior art, the purpose of the present invention is to provide an alliance encryption method and a node management system, which solves the problems of security risks and low computational efficiency of encryption algorithms in the prior art in a dynamic network environment.
[0007] To achieve the above object, the present invention provides the following solutions:
[0008] A federated encryption method, comprising:
[0009] Acquire scenario type data and feature data corresponding to the data to be transmitted, wherein the scenario type data includes: data sensitivity, data transmission frequency and network environment dynamics, and the feature data includes: size of the data to be transmitted, type of the data to be transmitted and structure of the data to be transmitted;
[0010] Determine an elliptic curve algorithm and corresponding curve parameters according to the scenario type data and the feature data;
[0011] Encrypting the data to be transmitted using a determined elliptic curve algorithm to obtain first encrypted data and a first secret key;
[0012] Segmenting the first encrypted data to obtain block data sets;
[0013] Performing secondary encryption on each data block in the block data set to obtain an encrypted data block set;
[0014] Merging each data block in the encrypted data block set to obtain second encrypted data and a corresponding second secret key;
[0015] The second encrypted data, the first secret key, the second secret key and the curve parameter are sent to a receiving party and decrypted to obtain decrypted data.
[0016] Preferably, the method for determining the scene type data is:
[0017] Calculate a scenario type data score set and a feature data score set, wherein the scenario type data score set includes: a data sensitivity score, a data transmission frequency score, and a network environment dynamics score, and the feature data score set includes: a transmission data size score, a to-be-transmitted data type score, and a to-be-transmitted data structure score;
[0018] Determine an initial comprehensive score based on the scenario type data set score and the feature data score set;
[0019] Setting a first scoring threshold and a second scoring threshold, and comparing them with the initial comprehensive score to obtain a comparison result;
[0020] Obtaining a final comprehensive score according to the comparison results;
[0021] An elliptic curve algorithm and corresponding curve parameters are determined according to the final comprehensive score.
[0022] Preferably, the calculation formula of the scene type data scoring set is:
[0023]
[0024] Where S is the data sensitivity score, T is the total number of data types, and w i is the weight of the i-th data type, r i is the sensitivity assessment value of the i-th data, F is the data transmission frequency score, and D freq is the frequency of actual data transmission, D max is the highest considered frequency, T avg is the average value of the effective data transmission time window, T total is the total recording time window, N is the network environment dynamic score, L avg is the average value of actual network delay, L max is the maximum acceptable delay value, U avg is the average value of network instability, U max is the maximum acceptable instability.
[0025] Preferably, the calculation formula of the feature data scoring set is:
[0026]
[0027] B score Score the data size, T score Scoring data types, R score Score the data structure.
[0028] Preferably, the calculation formula for the final comprehensive score is:
[0029]
[0030] Among them, C raw is the initial score, T low is the first scoring threshold, T high is the second scoring threshold.
[0031] Preferably, the calculation formula of the initial score is:
[0032] C raw =αS+βF+γN+δB score +∈T score +ζR score +η(S·F)+θ(N·T score );
[0033] Among them, α, β, γ, δ, ∈, η and θ are respectively the first weight coefficient, the second weight coefficient, the third weight coefficient, the fourth weight coefficient, the fifth weight coefficient, the sixth weight coefficient, the seventh weight coefficient and the eighth weight coefficient, among them, S norm is the multiple data sensitivity scoring standard value, F norm N is the standard value for the frequency of multiple data transmissions. norm It is a standard value for dynamic scoring of multiple network environments.
[0034] Preferably, the performing secondary encryption on each data block in the block data set to obtain an encrypted data block set includes:
[0035] Using a random number generator to generate a random seed for each data block in the block data set;
[0036] Generate an initialization vector according to the random seed;
[0037] Encryption is performed using a symmetric encryption algorithm and the generated initialization vector to obtain an encrypted data block set.
[0038] A node management system, the node management system comprising:
[0039] Node registration module, node database module, node monitoring module, response module and alarm module;
[0040] The node registration module is used to register new nodes, the node database module is used to store all node information, the node monitoring module is used to monitor the node behavior and traffic data of each module, the response module is used to generate detection results based on the node behavior and traffic data, and adjust the encryption algorithm and curve parameters based on the detection results, and the alarm module is used to issue an alarm based on the monitoring results.
[0041] Preferably, the response module comprises:
[0042] Data receiving submodule, anomaly detection submodule, adjustment submodule;
[0043] The data receiving submodule is used to receive node behavior, traffic data and node information; the anomaly detection submodule is used to perform fluctuation detection on the traffic data and node information according to the node information to obtain fluctuation results, and obtain detection results according to the fluctuation results; the adjustment submodule is used to adjust the encryption algorithm and curve parameters according to the detection results.
[0044] Preferably, the adjustment submodule includes:
[0045] Level determination unit, allocation unit, algorithm adjustment unit, parameter update unit and key rotation unit;
[0046] The level judgment unit is used to judge the abnormality level of the detection result, and the allocation unit is used to control the algorithm adjustment unit, parameter updating unit and key rotation unit to perform algorithm adjustment, parameter update and key rotation according to the abnormality level.
[0047] The present invention discloses the following technical effects:
[0048] The present invention provides a federation encryption method and a node management system, wherein the algorithm includes: a federation encryption method, including: obtaining scene type data and feature data corresponding to the data to be transmitted, wherein the scene type data includes: data sensitivity, data transmission frequency and network environment dynamics, and the feature data includes: the size of the data to be transmitted, the type of the data to be transmitted and the structure of the data to be transmitted; determining the elliptic curve algorithm and the corresponding curve parameters according to the scene type data and the feature data; encrypting the data to be transmitted using the determined elliptic curve algorithm to obtain first encrypted data and a first secret key; segmenting the first encrypted data to obtain a block data set; performing secondary encryption on each data block in the block data set to obtain an encrypted data block set; merging each data block in the encrypted data block set to obtain second encrypted data and a corresponding second secret key; sending the second encrypted data, the first secret key, the second secret key and the curve parameter to a receiver and decrypting them to obtain decrypted data. The present invention effectively improves the processing speed through block processing, dynamic algorithm selection, secondary encryption and other measures, and adapts to large-scale data applications; through multiple encryption mechanisms and dynamic adjustment strategies, it is ensured that there is no single reliance on a certain algorithm, thereby reducing the security risk caused by the single algorithm being broken. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0050] Figure 1 A flow chart of an alliance encryption method provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0051] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0052] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0053] like Figure 1 As shown, the present invention provides a federation encryption method, comprising:
[0054] Step 100: Acquire scenario type data and feature data corresponding to the data to be transmitted, wherein the scenario type data includes: data sensitivity, data transmission frequency and network environment dynamics, and the feature data includes: size of the data to be transmitted, type of the data to be transmitted and structure of the data to be transmitted;
[0055] Step 200: Determine an elliptic curve algorithm and corresponding curve parameters according to the scene type data and feature data;
[0056] Step 300: Encrypt the data to be transmitted using a determined elliptic curve algorithm to obtain first encrypted data and a first secret key;
[0057] Step 400: Segment the first encrypted data to obtain block data sets;
[0058] Step 500: performing secondary encryption on each data block in the block data set to obtain an encrypted data block set;
[0059] Step 600: Merge each data block in the encrypted data block set to obtain second encrypted data and a corresponding second secret key;
[0060] Step 700: Send the second encrypted data, the first secret key, the second secret key and the curve parameter to the receiver and decrypt them to obtain decrypted data.
[0061] Specifically, the scene type data and feature data are divided in detail:
[0062] (1) Data sensitivity
[0063] Automated detection: Automatically identify and tag sensitive data such as personally identifiable information (PII), financial data, and medical records through rule-based detection systems (e.g., content keywords, data formats, etc.).
[0064] Classification standards: Establish grading standards for data sensitivity, such as classifying data into "low sensitivity", "medium sensitivity" and "high sensitivity".
[0065] (2) Data transmission frequency:
[0066] Build a real-time monitoring system to track the frequency of data transmission. This can be achieved through network traffic monitoring tools (such as using SNMP or NetFlow protocol); analyze historical transmission data and identify patterns in transmission frequency to determine the flow characteristics of data blocks.
[0067] (3) Dynamic nature of the network environment:
[0068] Use network monitoring tools (such as Wireshark and Nagios) to obtain network status information, including bandwidth, latency, packet loss rate, etc.
[0069] (4) Size of data to be transmitted:
[0070] Write a script to automatically measure the byte size of the data to ensure that the volume of each data block is accurately known.
[0071] (5) Type of data to be transmitted:
[0072] The MIME type of a file or data is used to identify the type of data to be transferred (e.g., text, image, video, application data, etc.).
[0073] (6) Structure of data to be transmitted
[0074] Analyze the structure of the data according to its format (such as JSON, XML, CSV, etc.) and extract the hierarchy and content details of the data.
[0075] Furthermore, the method for determining the scene type data is:
[0076] Calculate a scenario type data score set and a feature data score set, wherein the scenario type data score set includes: a data sensitivity score, a data transmission frequency score, and a network environment dynamics score, and the feature data score set includes: a transmission data size score, a to-be-transmitted data type score, and a to-be-transmitted data structure score;
[0077] Determine an initial comprehensive score based on the scenario type data set score and the feature data score set;
[0078] Setting a first scoring threshold and a second scoring threshold, and comparing them with the initial comprehensive score to obtain a comparison result;
[0079] Obtaining a final comprehensive score according to the comparison results;
[0080] An elliptic curve algorithm and corresponding curve parameters are determined according to the final comprehensive score.
[0081] Furthermore, the calculation formula of the scene type data scoring set is:
[0082]
[0083] Where S is the data sensitivity score, T is the total number of data types, and w i is the weight of the i-th data type, r i is the sensitivity assessment value of the i-th data, F is the data transmission frequency score, and D freq is the frequency of actual data transmission, D maxis the highest considered frequency, T avg is the average value of the effective data transmission time window, T total is the total recording time window, N is the network environment dynamic score, L avg is the average value of actual network delay, L max is the maximum acceptable delay value, U avg is the average value of network instability, U max is the maximum acceptable instability. For highly sensitive data such as financial data and medical data, set higher weights and evaluation values; for public data or low-sensitivity data, set lower weights and evaluation values. Frequently transmitted data (such as real-time video streaming) can get a high score close to 1; infrequently transmitted data (such as daily backups) will get a relatively low score. If the network latency is low and the stability is high, it means that the network environment is stable; if the network latency is high and the packet loss is severe, N is close to 1, indicating a highly dynamic network environment.
[0084] Furthermore, the calculation formula of the feature data scoring set is:
[0085]
[0086] B score Score the data size, T score Scoring data types, R score Score the data structure.
[0087] Specifically, the impact of data size scoring is as follows: Establish a mapping model to evaluate the impact of data size on encryption performance. For example: Data less than 1MB uses a lightweight curve (such as SECP192R1). Data larger than 1MB but less than 5MB requires the use of a stronger curve (such as SECP256R1). Data larger than 5MB may require the use of a high-performance curve (such as Curve25519) to maintain processing efficiency.
[0088] Data type impact: Different data types may have different requirements for algorithms. For example, structured data (such as database content) may focus more on speed, while unstructured data (such as images and videos) may emphasize security.
[0089] Data structure impact: Generally speaking, structured data is more efficient to encrypt, while unstructured data may require more processing time.
[0090] Furthermore, the calculation formula for the final comprehensive score is:
[0091]
[0092] Among them, C raw is the initial score, T lowis the first scoring threshold, T high is the second scoring threshold.
[0093] 6. A consortium encryption method according to claim 5, characterized in that the calculation formula of the initial score is:
[0094] C raw =αS+βF+γN+δB score +∈T score +ζR score +η(S·F)+θ(N·T score );
[0095] Among them, α, β, γ, δ, ∈, η and θ are respectively the first weight coefficient, the second weight coefficient, the third weight coefficient, the fourth weight coefficient, the fifth weight coefficient, the sixth weight coefficient, the seventh weight coefficient and the eighth weight coefficient, among them, S norm is the multiple data sensitivity scoring standard value, F norm N is the standard value for the frequency of multiple data transmissions. norm For multiple network environment dynamics scoring standard values, the product term of data sensitivity and transmission frequency is introduced to reflect the significant increase in the required encryption strength when both are high. The product term of network dynamics and data type score is introduced to indicate the processing requirements of different data types in unstable network environments. The weights can be dynamically adjusted based on actual usage. For example, normalized historical data is used to update the weights to adapt to changing scenarios and needs.
[0096] Furthermore, the process of determining the elliptic curve algorithm and the corresponding curve parameters according to the final comprehensive score is as follows:
[0097] Create an elliptic curve database containing different elliptic curve algorithms and their corresponding parameters. This can include the following information:
[0098] Curve name, security strength, performance score (evaluated based on existing processing speed, encryption and decryption time, etc.), applicable scenarios (suitable data types, sensitivity, etc.), curve parameters (such as base point, curve coefficient and order);
[0099] Based on the score, set thresholds for each elliptic curve algorithm and its parameters. The following conditions can be set:
[0100] Choose a high-intensity algorithm (such as Curve25519) with a high score;
[0101] Choose a standard algorithm (such as SECP256R1) at a medium score;
[0102] Select a performance-first algorithm (such as SECP192R1) when the score is low;
[0103] After the curve and its parameters are determined, further processing is required, such as:
[0104] For key generation: Generates keys using the selected curve parameters.
[0105] Encryption / decryption operations: Use the selected curve to perform encryption and decryption operations.
[0106] Furthermore, the specific process of encrypting the data to be transmitted using the determined elliptic curve algorithm includes selecting a suitable encryption method, generating a secret key, performing encryption operations, and generating the final encrypted data:
[0107] 1. Select elliptic curve encryption algorithm
[0108] We use the elliptic curve algorithm and its parameters determined in the previous step. Assume that we have chosen a specific algorithm, such as Curve25519.
[0109] 2. Data Preparation
[0110] 2.1 Collecting data to be transmitted
[0111] Data to be transmitted: Prepare the data that needs to be encrypted, which can be any type of file, text information, etc.
[0112] 3. Generate a secret key
[0113] 3.1 Key Pair Generation
[0114] Generate a public-private key pair using an elliptic curve algorithm. The following is an example using Curve25519:
[0115] 3.2 Export the secret key
[0116] In the app, you can choose to export the public key and private key, so that the public key can be shared with the recipient who needs to encrypt data, and the private key must be kept properly.
[0117] 4. Data encryption
[0118] 4.1 Import the required encryption library
[0119] To ensure security and ease of use, the necessary encryption library is introduced. Here, the Cryptography library is taken as an example.
[0120] 4.2 Encrypting Data Using Public Key
[0121] Generate the first encrypted data and the first secret key
[0122] First encrypted data: The encrypted data will be used as the first encrypted data.
[0123] First key: The public key and the secret key can be combined to generate the first key, which can be kept in a safe place.
[0124] Furthermore, the second encryption of each data block in the block data set to obtain an encrypted data block set includes:
[0125] Using a random number generator to generate a random seed for each data block in the block data set;
[0126] Generate an initialization vector according to the random seed;
[0127] Encryption is performed using a symmetric encryption algorithm and the generated initialization vector to obtain an encrypted data block set.
[0128] Specifically, data preparation
[0129] 1.1 Get the data to be transmitted
[0130] Collect the data to be transmitted and ensure that the data format meets the requirements and can be processed in blocks.
[0131] 1.2 Determine the block strategy
[0132] Determine a reasonable block size based on the data size and business logic. For example, divide the data into blocks of a fixed size (such as 128KB) to facilitate subsequent processing and encryption.
[0133] 2. Initialize encryption algorithm and key generation
[0134] In the previous steps, the data has been initially encrypted using the elliptic curve algorithm to generate the first encrypted data and the first secret key. Based on this, secondary encryption is performed:
[0135] 2.1 Choose an encryption algorithm
[0136] For secondary encryption, choose an efficient and secure symmetric encryption algorithm, such as AES (Advanced Encryption Standard), and decide on an encryption mode, such as GCM (Galois / Counter Mode) to ensure data integrity and confidentiality.
[0137] 2.2 Dynamically generate secondary keys
[0138] Generate a unique secondary encryption key for each data block. This can be derived from the initial key or a new key can be generated using a pseudo-random number generator to ensure the uniqueness of each secondary encryption.
[0139] 3. Data block after initial encryption
[0140] 3.1 Dividing Encrypted Data
[0141] The first encrypted data is processed into blocks to obtain a block data set.
[0142] 4. Secondary encryption process
[0143] 4.1 Initialization Parameters
[0144] A new initialization vector (IV) is generated for each data block to ensure that the input is randomized each time it is encrypted, thus preventing the same plaintext from being encrypted with the same result.
[0145] 4.2 Perform secondary encryption
[0146] Encrypt using the AES cipher with the secondary key and IV corresponding to each data block.
[0147] 5. Assemble the encrypted data block set
[0148] 5.1 Merging Encrypted Data Blocks
[0149] All encrypted data blocks are combined into a complete secondary encrypted data for transmission.
[0150] 5.2 Storing Keys and Metadata
[0151] Maintains metadata related to secondary encryption, including secondary key index, IV, and authentication tag, for decryption.
[0152] 6. Result Output
[0153] The generated second encrypted data, the first key, the second key and the curve parameters are prepared to be sent to a recipient.
[0154] 7. Decryption process (receiver)
[0155] After receiving the data packet, the receiver performs the following steps to decrypt the data:
[0156] Each encrypted block is decrypted using the corresponding secondary key and its IV and tag are used to verify data integrity.
[0157] Merge the decrypted data blocks.
[0158] The combined data is initially decrypted using the initial key to obtain the original data.
[0159] More specifically, the requirements for determining the initialization vector:
[0160] 1. Characteristics of IV
[0161] Randomness: The IV must be randomly generated and should not be reused to ensure that the same plaintext generates different ciphertexts in different encryption processes.
[0162] Length matching: The length of the IV should match the encryption algorithm and mode used (for example, the IV length for AES needs to be 16 bytes).
[0163] 2. Generate a random seed
[0164] 2.1 Source of seeds
[0165] True Random Number Generator (TRNG): Uses a hardware randomness generator to obtain a highly secure random seed.
[0166] Pseudo-random number generator (PRNG): Generates seeds from secure sources, such as the current timestamp, system status (memory, CPU status), etc., and combines multiple system information to generate random seeds to ensure the complexity of the seeds.
[0167] This embodiment also provides a node management system, which includes:
[0168] Node registration module, node database module, node monitoring module, response module and alarm module;
[0169] The node registration module is used to register new nodes, the node database module is used to store all node information, the node monitoring module is used to monitor the node behavior and traffic data of each module, the response module is used to generate detection results based on the node behavior and traffic data, and adjust the encryption algorithm and curve parameters based on the detection results, and the alarm module is used to issue an alarm based on the monitoring results.
[0170] Furthermore, the response module includes:
[0171] Data receiving submodule, anomaly detection submodule, adjustment submodule;
[0172] The data receiving submodule is used to receive node behavior, traffic data and node information; the anomaly detection submodule is used to perform fluctuation detection on the traffic data and node information according to the node information to obtain fluctuation results, and obtain detection results according to the fluctuation results; the adjustment submodule is used to adjust the encryption algorithm and curve parameters according to the detection results.
[0173] Furthermore, the adjustment submodule includes:
[0174] Level determination unit, allocation unit, algorithm adjustment unit, parameter update unit and key rotation unit;
[0175] The level judgment unit is used to judge the abnormality level of the detection result, and the allocation unit is used to control the algorithm adjustment unit, parameter updating unit and key rotation unit to perform algorithm adjustment, parameter update and key rotation according to the abnormality level.
[0176] Furthermore, the following is a detailed introduction to each module:
[0177] 1: Node registration module
[0178] Function: Responsible for registering new nodes. Whenever a new device or user joins the network, the node registration module collects relevant information and interacts with the database. Self-service registration: Users can self-register nodes through a compliant process to reduce management burden. Authentication mechanism: Implement multi-factor authentication to ensure that legitimate users and devices are registered.
[0179] 2. Node database module
[0180] Function: Store information of all nodes, including node ID, registration time, status, behavior records, etc.
[0181] High availability: The database can be designed as a distributed architecture to ensure data persistence and high availability.
[0182] Permission management: Set access permissions based on the node's role and authorization level to ensure data security.
[0183] 3. Node monitoring module
[0184] Function: Responsible for monitoring the behavior and traffic data of each node to obtain real-time status and analyze trends.
[0185] Traffic analysis: Use machine learning algorithms to analyze traffic patterns and identify normal and abnormal traffic behavior.
[0186] Real-time data visualization: Provides a dashboard to display node performance data and traffic in real time. While visualizing, it also supports comparative analysis of historical data.
[0187] 4. Response Module
[0188] Function: Generate detection results based on node behavior and traffic data, and adjust encryption algorithms and curve parameters.
[0189] Adaptive adjustment: Evaluate the security level of nodes based on AI models and dynamically adjust encryption strategies.
[0190] Intelligent decision-making: Use historical data to train models, make predictions in advance, and prepare corresponding adjustment strategies.
[0191] 4.1 Data receiving submodule
[0192] Function: Receive behavior, traffic data and node information from nodes.
[0193] Data aggregation and filtering: Algorithms automatically filter out important data, reduce redundancy, and optimize network bandwidth and storage requirements.
[0194] 4.2 Anomaly Detection Submodule
[0195] Function: Perform fluctuation detection on traffic data and node information and generate detection results.
[0196] Threshold or model-based detection: Combines the threshold method with the machine learning model to detect abnormal events and can adapt to new attack patterns.
[0197] 4.3 Adjust submodules
[0198] Function: Adjust the encryption algorithm and curve parameters according to the detection results.
[0199] Real-time feedback: The system obtains the behavior changes of nodes in real time, adjusts encryption algorithms and parameters in time, and improves data security.
[0200] 5. Alert Module
[0201] Function: Issue an alarm based on the monitoring results to notify the system administrator or relevant personnel.
[0202] Multi-channel alerts: Alerts are sent through multiple channels such as email, mobile phone notifications, instant messages, etc. to ensure that information can be delivered in a timely manner.
[0203] Intelligent alerts: Alerts are classified and managed according to their severity to avoid information overwhelm and improve response efficiency.
[0204] 5.1 Level Judgment Unit
[0205] Function: Determine the abnormal level of test results and assess risks.
[0206] Multi-level assessment system: Classification based on different types of attacks or abnormal behaviors.
[0207] 5.2 Allocation Unit
[0208] Function: Controls the execution of algorithm adjustments, parameter updates, and key rotations based on the anomaly level.
[0209] Automated execution: Pre-map abnormal levels with specific action strategies to reduce manual intervention.
[0210] 5.3 Algorithm Adjustment Unit
[0211] Function: Dynamically select a suitable encryption algorithm based on the evaluation results.
[0212] Algorithm library management: Maintain an algorithm library and select the optimal encryption algorithm based on application scenarios, network environment, etc.
[0213] 5.4 Parameter Update Unit
[0214] Function: Adjust the parameters of the encryption algorithm in real time and optimize the security strategy according to the current situation.
[0215] Intelligent settings: Combine AI and historical data to predict the optimal parameter combination.
[0216] 5.5 Key Rotation Unit
[0217] Function: Change the secret key regularly or under abnormal circumstances to enhance security.
[0218] Secure rotation plan: Automatically generate new keys and securely revoke old keys to prevent reverse engineering.
[0219] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0220] The principles and implementation methods of the present invention are described in this article using specific examples. The description of the above embodiments is only used to help understand the method and core idea of the present invention. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A federated encryption method, characterized in that: include: Acquire scenario type data and feature data corresponding to the data to be transmitted, wherein the scenario type data includes: data sensitivity, data transmission frequency and network environment dynamics, and the feature data includes: size of the data to be transmitted, type of the data to be transmitted and structure of the data to be transmitted; Determine an elliptic curve algorithm and corresponding curve parameters according to the scenario type data and the feature data; Encrypting the data to be transmitted using a determined elliptic curve algorithm to obtain first encrypted data and a first secret key; Segmenting the first encrypted data to obtain block data sets; Performing secondary encryption on each data block in the block data set to obtain an encrypted data block set; Merging each data block in the encrypted data block set to obtain second encrypted data and a corresponding second secret key; The second encrypted data, the first secret key, the second secret key and the curve parameter are sent to a receiving party and decrypted to obtain decrypted data.
2. A consortium encryption method according to claim 1, characterized in that: The method for determining the scene type data is: Calculate a scenario type data score set and a feature data score set, wherein the scenario type data score set includes: a data sensitivity score, a data transmission frequency score, and a network environment dynamics score, and the feature data score set includes: a transmission data size score, a to-be-transmitted data type score, and a to-be-transmitted data structure score; Determine an initial comprehensive score based on the scenario type data set score and the feature data score set; Setting a first scoring threshold and a second scoring threshold, and comparing them with the initial comprehensive score to obtain a comparison result; Obtaining a final comprehensive score according to the comparison results; An elliptic curve algorithm and corresponding curve parameters are determined according to the final comprehensive score.
3. The alliance encryption method according to claim 1, characterized in that: The calculation formula for the scene type data scoring set is: Where S is the data sensitivity score, T is the total number of data types, and w i is the weight of the i-th data type, r i is the sensitivity assessment value of the i-th data, F is the data transmission frequency score, and D freq is the frequency of actual data transmission, D max is the highest considered frequency, T avg is the average value of the effective data transmission time window, T total is the total recording time window, N is the network environment dynamic score, L avg is the average value of actual network delay, L max is the maximum acceptable delay value, U avg is the average value of network instability, U max is the maximum acceptable instability.
4. A consortium encryption method according to claim 3, characterized in that: The calculation formula of the feature data scoring set is: B score Score the data size, T score Scoring data types, R score Score the data structure.
5. A consortium encryption method according to claim 4, characterized in that: The final comprehensive score is calculated as follows: Among them, C raw is the initial score, T low is the first scoring threshold, T high is the second scoring threshold.
6. A consortium encryption method according to claim 5, characterized in that: The calculation formula of the initial score is: C raw =αS+βF+γN+δB score +∈T score +ζR score +η(S·F)+θ(N·T score ); Among them, α, β, γ, δ, ∈, η and θ are respectively the first weight coefficient, the second weight coefficient, the third weight coefficient, the fourth weight coefficient, the fifth weight coefficient, the sixth weight coefficient, the seventh weight coefficient and the eighth weight coefficient, among them, S norm is the multiple data sensitivity scoring standard value, F norm N is the standard value for the frequency of multiple data transmissions. norm It is a standard value for dynamic scoring of multiple network environments.
7. The alliance encryption method according to claim 1, characterized in that: The second encryption of each data block in the block data set to obtain an encrypted data block set includes: Using a random number generator to generate a random seed for each data block in the block data set; Generate an initialization vector according to the random seed; Encryption is performed using a symmetric encryption algorithm and the generated initialization vector to obtain an encrypted data block set.
8. A node management system, applied to the alliance encryption algorithm according to any one of claims 1 to 7, characterized in that: The node management system comprises: Node registration module, node database module, node monitoring module, response module and alarm module; The node registration module is used to register new nodes, the node database module is used to store all node information, the node monitoring module is used to monitor the node behavior and traffic data of each module, the response module is used to generate detection results based on the node behavior and traffic data, and adjust the encryption algorithm and curve parameters based on the detection results, and the alarm module is used to issue an alarm based on the monitoring results.
9. A node management system according to claim 8, characterized in that: The response module comprises: Data receiving submodule, anomaly detection submodule, adjustment submodule; The data receiving submodule is used to receive node behavior, traffic data and node information; the anomaly detection submodule is used to perform fluctuation detection on the traffic data and node information according to the node information to obtain fluctuation results, and obtain detection results according to the fluctuation results; the adjustment submodule is used to adjust the encryption algorithm and curve parameters according to the detection results.
10. A node management system according to claim 9, characterized in that: The adjustment submodule comprises: Level determination unit, allocation unit, algorithm adjustment unit, parameter update unit and key rotation unit; The level judgment unit is used to judge the abnormality level of the detection result, and the allocation unit is used to control the algorithm adjustment unit, parameter updating unit and key rotation unit to perform algorithm adjustment, parameter update and key rotation according to the abnormality level.
Citation Information
Cited By
User database information anti-divulging protection system and device based on big data
CN120223434A