Remote safety monitoring system and method
By adopting post-quantum cryptography hybrid encryption protocol and distributed ledger technology in the remote security monitoring system, the problems of insufficient user privacy protection and data leakage risks are solved, and efficient and secure data transmission and storage are achieved to ensure the system's privacy protection capabilities.
Patent Information
- Application Number
- CN202510150001.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-16
AI Technical Summary
There is a risk of insufficient user privacy protection and data leakage in the remote security monitoring system. It is difficult for the existing technology to achieve efficient data transmission while ensuring security, and continue to comply with the latest privacy protection requirements.
A hybrid encryption protocol based on post-quantum cryptography is adopted, combined with homomorphic encryption technology and zero-knowledge proof technology, and a data storage structure is constructed through distributed ledger technology, and a secure transmission protocol is set to prevent data from being intercepted or tampered during transmission.
Effectively protect user privacy, reduce the risk of data leakage, realize efficient data encryption and secure transmission, and ensure that the system continues to comply with the latest privacy protection requirements.
Smart Images

Figure CN120017349A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of remote monitoring technology, and in particular to a remote security monitoring system and method. Background Art
[0002] With the continuous advancement of information technology, remote security monitoring systems have been widely used in all walks of life, providing strong support for security protection. However, the industry faces severe challenges in data transmission. Data can be easily intercepted or tampered with during transmission, which not only threatens the accuracy of monitoring information, but also poses a major hidden danger to the overall security of the system. In addition, with the popularization of cloud computing and big data technology, user data faces unprecedented risks of privacy leakage when stored and processed in the cloud. These problems not only hinder the further development of remote security monitoring systems, but also cause the public to have deep concerns about data security.
[0003] In order to address the security and privacy protection issues in data transmission, the industry has widely adopted encryption technologies such as AES and RSA. These encryption technologies have improved the security of data transmission to a certain extent and provided strong protection for the confidentiality and integrity of data. However, in scenarios with large-scale data transmission and high real-time requirements, the efficiency issues of traditional encryption technologies have become increasingly prominent. How to achieve efficient transmission while ensuring security has become a difficult problem that needs to be solved urgently. In addition, with the continuous updating of privacy protection regulations and technical standards, how to ensure that the system can continue to meet the latest privacy protection requirements is also one of the problems that existing technologies have not been able to solve well. These limitations make traditional technologies seem powerless in dealing with the challenges of data transmission in modern remote security monitoring systems.
[0004] To sum up, how to solve the technical problems of insufficient user privacy protection and data leakage risks in remote security monitoring systems is an issue that needs to be solved urgently. Summary of the invention
[0005] The main purpose of the present invention is to provide a remote security monitoring system and method to at least solve the technical problems of insufficient user privacy protection and data leakage risk in the remote security monitoring system, thereby effectively protecting user privacy and reducing the risk of data leakage.
[0006] In order to achieve the above object, the present invention provides a remote security monitoring system and method.
[0007] In a first aspect, the present invention provides a remote security monitoring system, comprising:
[0008] An encryption processing module, which is deployed in the monitoring system and includes an encryption processing unit, which is used to obtain monitoring data and is further used to encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combined with homomorphic encryption technology and zero-knowledge proof technology;
[0009] A data transmission channel module, the data transmission channel module includes a data transmission channel unit, the data transmission channel unit is connected to the encryption processing module, and the data transmission channel unit is used to prevent the encrypted monitoring data from being intercepted or tampered with during the transmission process by setting a secure transmission protocol;
[0010] A distributed storage module, wherein the distributed storage module comprises a distributed storage unit, wherein the distributed storage unit is connected to the data transmission channel module, and wherein the distributed storage unit is used to construct a data storage structure using distributed ledger technology to perform distributed storage on the encrypted monitoring data.
[0011] Optionally, the encryption processing module further includes:
[0012] An algorithm adaptation unit, the algorithm adaptation unit is connected to the encryption processing unit, and the algorithm adaptation unit is used to automatically adjust the configuration of the encryption algorithm according to the real-time requirements and scale of the monitoring data transmission.
[0013] Optionally, the distributed storage module further includes:
[0014] A consensus mechanism unit, wherein the consensus mechanism unit is connected to the distributed storage unit, and the consensus mechanism unit is used to adopt a non-complete blockchain technology to ensure the consistency and reliability of the monitoring data in the distributed storage through a consensus mechanism.
[0015] Optionally, the data transmission channel module further includes:
[0016] A dynamic encryption adjustment unit is connected to the data transmission channel unit, and is used to dynamically adjust the encryption strength according to the security status of the transmission environment of the monitoring data.
[0017] Optionally, the monitoring system further includes:
[0018] A privacy compliance checking module, wherein the privacy compliance checking module includes a periodic scanning and elimination unit, wherein the periodic scanning and elimination unit is connected to the distributed storage module, and the periodic scanning and elimination unit is used to periodically scan the stored and transmitted monitoring data, and eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results.
[0019] Optionally, the privacy compliance checking module further includes:
[0020] A regulation update interface, the regulation update interface is connected to the periodic scanning and rejection unit, and the regulation update interface is used to receive and parse the latest privacy protection regulations and technical standards.
[0021] Optionally, the monitoring system further includes:
[0022] A security audit module, which is connected to the encryption processing module, the data transmission channel module and the distributed storage module. The security audit module is used to record and audit the encryption, storage, transmission and access operations of all the monitoring data in the monitoring system, and provide a detailed security log to facilitate tracing and troubleshooting of potential safety hazards.
[0023] In a second aspect, the present invention provides a remote security monitoring method, which is applied to the monitoring system described in the first aspect, and comprises:
[0024] Acquire monitoring data, and encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combined with homomorphic encryption technology and zero-knowledge proof technology;
[0025] By setting up a secure transmission protocol, the encrypted monitoring data can be prevented from being intercepted or tampered with during transmission;
[0026] Distributed ledger technology is used to build a data storage structure to distribute the encrypted monitoring data.
[0027] Optionally, after constructing a data storage structure using distributed ledger technology to perform distributed storage on the encrypted monitoring data, the method further includes:
[0028] Regularly scan the stored and transmitted monitoring data, and based on the scan results, eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards.
[0029] Optionally, the monitoring method further includes:
[0030] Record and audit all encryption, storage, transmission and access operations of the monitoring data within the monitoring system, and provide detailed security logs to facilitate tracing and troubleshooting of security risks.
[0031] The remote security monitoring system and method provided by the present application are designed to provide efficient data encryption, secure transmission channels and reliable distributed storage solutions to fully protect user privacy and security. The system mainly includes an encryption processing module, a data transmission channel module and a distributed storage module. The encryption processing module contains an encryption processing unit, which is responsible for obtaining monitoring data and using a hybrid encryption protocol based on post-quantum cryptography, combined with homomorphic encryption and zero-knowledge proof technology, to perform high-intensity encryption on the data. The data transmission channel module includes a data transmission channel unit, which is connected to the encryption processing module. By setting a secure transmission protocol, the security of encrypted data during transmission is ensured to prevent interception and tampering. The distributed storage module includes a distributed storage unit, which is connected to the data transmission channel module, and uses distributed ledger technology to build a data storage architecture to achieve distributed storage of encrypted data. The system solves the technical problems of insufficient user privacy protection and data leakage risks in the remote security monitoring system, thereby effectively protecting user privacy and reducing data leakage risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The drawings constituting a part of the present application are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0033] Figure 1 A schematic diagram of the remote security monitoring system provided for this application;
[0034] Figure 2 A flowchart of the remote security monitoring method provided in this application.
[0035] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0036] In order to make the purpose, technical solutions and advantages of this application clearer, the technical solutions in this application will be clearly and completely described below in conjunction with the drawings in this application. Obviously, the described embodiments are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0037] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in sequences other than those illustrated or described herein.
[0038] In the present invention, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0039] The remote security monitoring system and method provided by the present application include an encryption processing module, a data transmission channel module and a distributed storage module. The encryption processing module obtains monitoring data and encrypts it using a post-quantum cryptography hybrid encryption protocol combined with homomorphic encryption and zero-knowledge proof technology. The data transmission channel module sets a security protocol to prevent interception and tampering. The distributed storage module uses distributed ledger technology to store encrypted data, strengthen user privacy protection, and reduce the risk of data leakage.
[0040] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0041] Figure 1 The schematic diagram of the remote security monitoring system provided for this application is intended to provide a detailed description of the remote security monitoring system, such as Figure 1 As shown, the remote security monitoring system provided in this embodiment includes:
[0042] An encryption processing module, which is deployed in the monitoring system and includes an encryption processing unit, which is used to obtain monitoring data and is further used to encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combined with homomorphic encryption technology and zero-knowledge proof technology;
[0043] A data transmission channel module, the data transmission channel module includes a data transmission channel unit, the data transmission channel unit is connected to the encryption processing module, and the data transmission channel unit is used to prevent the encrypted monitoring data from being intercepted or tampered with during the transmission process by setting a secure transmission protocol;
[0044] A distributed storage module, wherein the distributed storage module comprises a distributed storage unit, wherein the distributed storage unit is connected to the data transmission channel module, and wherein the distributed storage unit is used to construct a data storage structure using distributed ledger technology to perform distributed storage on the encrypted monitoring data.
[0045] Optionally, the encryption processing module further includes:
[0046] An algorithm adaptation unit, the algorithm adaptation unit is connected to the encryption processing unit, and the algorithm adaptation unit is used to automatically adjust the configuration of the encryption algorithm according to the real-time requirements and scale of the monitoring data transmission.
[0047] Optionally, the distributed storage module further includes:
[0048] A consensus mechanism unit, wherein the consensus mechanism unit is connected to the distributed storage unit, and the consensus mechanism unit is used to adopt a non-complete blockchain technology to ensure the consistency and reliability of the monitoring data in the distributed storage through a consensus mechanism.
[0049] Optionally, the data transmission channel module further includes:
[0050] A dynamic encryption adjustment unit is connected to the data transmission channel unit, and is used to dynamically adjust the encryption strength according to the security status of the transmission environment of the monitoring data.
[0051] Optionally, the monitoring system further includes:
[0052] A privacy compliance checking module, wherein the privacy compliance checking module includes a periodic scanning and elimination unit, wherein the periodic scanning and elimination unit is connected to the distributed storage module, and the periodic scanning and elimination unit is used to periodically scan the stored and transmitted monitoring data, and eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results.
[0053] Optionally, the privacy compliance checking module further includes:
[0054] A regulation update interface, the regulation update interface is connected to the periodic scanning and rejection unit, and the regulation update interface is used to receive and parse the latest privacy protection regulations and technical standards.
[0055] Optionally, the monitoring system further includes:
[0056] A security audit module, which is connected to the encryption processing module, the data transmission channel module and the distributed storage module. The security audit module is used to record and audit the encryption, storage, transmission and access operations of all the monitoring data in the monitoring system, and provide a detailed security log to facilitate tracing and troubleshooting of potential safety hazards.
[0057] The remote security monitoring system provided in this embodiment specifically includes:
[0058] An encryption processing module is deployed in the monitoring system, and the encryption processing module includes an encryption processing unit. The encryption processing unit is used to obtain monitoring data and adopts a hybrid encryption protocol based on post-quantum cryptography, which combines the encryption algorithm of homomorphic encryption technology and zero-knowledge proof technology to encrypt the monitoring data. In addition, the encryption processing module also includes an algorithm adaptation unit, which is connected to the encryption processing unit and is used to automatically adjust the configuration of the encryption algorithm, such as encryption strength, key length, etc., according to the real-time requirements and scale of monitoring data transmission to adapt to different security requirements. In the remote security monitoring system, the encryption processing module is the core component for data security protection and is responsible for the encryption processing of monitoring data. This embodiment will describe in detail the specific implementation of the encryption processing module, including the functions of the encryption processing unit and the algorithm adaptation unit and their working principles.
[0059] 1. Encryption Processing Unit
[0060] The encryption processing unit is the core part of the encryption processing module, responsible for acquiring monitoring data and performing encryption processing. Its workflow is as follows:
[0061] 1. Data acquisition: The encryption processing unit first obtains monitoring data from the monitoring system through a preset data interface or network protocol. These data may include video streams, audio signals, sensor readings, and other types.
[0062] 2. Encryption algorithm selection: To ensure data security, the encryption processing unit adopts a hybrid encryption protocol based on post-quantum cryptography. This protocol combines homomorphic encryption technology and zero-knowledge proof technology to achieve data confidentiality, integrity and availability.
[0063] Homomorphic encryption technology: using a specific homomorphic encryption algorithm, such as Gentry's fully homomorphic encryption algorithm (FHE) or Brakerski / Gentry / Vaikuntanathan (BGV) algorithm. These algorithms allow specific types of calculations to be performed on encrypted data without decrypting the data itself.
[0064] Zero-knowledge proof technology: Use specific zero-knowledge proof protocols, such as the Schnorr protocol or the Fiat-Shamir protocol. These protocols allow the authenticity of a fact to be proven without revealing any specific information about the fact.
[0065] 3. Encryption processing: According to the selected encryption algorithm, the encryption processing unit encrypts the monitoring data. The encryption process may involve multiple steps such as key generation, data encryption and data encapsulation.
[0066] Key generation: Generates a key pair for encryption and decryption, including a public key and a private key.
[0067] Data encryption: Use the public key to encrypt the monitoring data and generate encrypted data.
[0068] Data encapsulation: Encapsulate the encrypted data with necessary metadata (such as encryption algorithm identifier, key information, etc.) to facilitate subsequent data transmission and storage.
[0069] 2. Algorithm Adaptive Unit
[0070] The algorithm adaptation unit is connected to the encryption processing unit and is responsible for automatically adjusting the configuration of the encryption algorithm according to the real-time requirements and scale of the monitoring data transmission. Its working principle is as follows:
[0071] 1. Monitor data transmission: The algorithm adaptive unit monitors data transmission rate, transmission delay and other parameters in real time through a preset monitoring mechanism.
[0072] 2. Algorithm configuration adjustment: According to the monitored data transmission situation, the algorithm adaptive unit automatically adjusts the configuration of the encryption algorithm. This includes adjusting parameters such as encryption strength (such as key length, encryption algorithm complexity, etc.) and key update frequency.
[0073] Encryption strength adjustment: When the data transmission rate is high, the algorithm adaptive unit may choose a lower encryption strength to reduce the impact on system performance. When the data transmission delay is high or the data sensitivity is high, it may choose a higher encryption strength to ensure data security.
[0074] Key update frequency adjustment: According to the real-time requirements of data transmission and potential security threats, the algorithm adaptive unit will dynamically adjust the key update frequency. For example, in scenarios where data transmission is frequent and security requirements are high, it may increase the key update frequency to reduce the risk of data being cracked.
[0075] 3. Configuration update notification: After adjusting the encryption algorithm configuration, the algorithm adaptive unit will send a configuration update notification to the encryption processing unit. The encryption processing unit encrypts the monitoring data according to the new configuration.
[0076] Through the description of the above embodiments, those skilled in the art can clearly understand the specific implementation method and working principle of the encryption processing module. The encryption processing unit uses a hybrid encryption protocol based on post-quantum cryptography to encrypt the monitoring data, and the algorithm adaptation unit automatically adjusts the configuration of the encryption algorithm according to the real-time requirements and scale of data transmission to adapt to different security requirements. This design ensures the data security of the remote security monitoring system during data transmission and storage.
[0077] Data transmission channel module, the data transmission channel module includes a data transmission channel unit. The data transmission channel unit is connected to the encryption processing module, and the data transmission channel unit is used to prevent the encrypted monitoring data from being intercepted or tampered with during the transmission process by setting a secure transmission protocol, such as TLS / SSL protocol. In addition, the data transmission channel module also includes a dynamic encryption adjustment unit, which is connected to the data transmission channel unit. The dynamic encryption adjustment unit is used to dynamically adjust the encryption strength according to the security status of the transmission environment of the monitoring data, such as the frequency and intensity of network attacks, to ensure the security of data transmission. In a remote security monitoring system, the data transmission channel module is a key component to ensure that the encrypted monitoring data can be safely and reliably transmitted to the target location. This embodiment will describe in detail the specific implementation method of the data transmission channel module, including the functions of the data transmission channel unit and the dynamic encryption adjustment unit and their working principles.
[0078] 1. Data transmission channel unit
[0079] The data transmission channel unit is the core part of the data transmission channel module, which is responsible for setting up the security transmission protocol and transmitting the encrypted monitoring data. Its workflow is as follows:
[0080] 1. Security transmission protocol settings: The data transmission channel unit uses widely recognized security transmission protocols, such as Transport Layer Security (TLS) or its predecessor, Secure Sockets Layer (SSL), to ensure the security of data transmission. These protocols effectively prevent data from being intercepted or tampered with during transmission by providing encryption, data integrity verification, and identity verification.
[0081] TLS / SSL protocol implementation: The data transmission channel unit implements the specific details of the TLS / SSL protocol, including the handshake process, encryption algorithm selection, key exchange, etc. The handshake process is used to establish a secure communication channel between the client and the server and negotiate the encryption algorithm and key. The encryption algorithm can include symmetric encryption algorithms (such as AES) and asymmetric encryption algorithms (such as RSA or ECC). Key exchange is used to securely transfer keys between the two parties.
[0082] 2. Data transmission: After establishing a secure communication channel, the data transmission channel unit starts to transmit the encrypted monitoring data. The data is transmitted between the client and the server in an encrypted form to ensure the confidentiality and integrity of the data.
[0083] 2. Dynamic Encryption Adjustment Unit
[0084] The dynamic encryption adjustment unit is connected to the data transmission channel unit and is responsible for dynamically adjusting the encryption strength according to the security status of the transmission environment of the monitored data. Its working principle is as follows:
[0085] 1. Monitoring the transmission environment: The dynamic encryption adjustment unit monitors the security status of the data transmission environment in real time through a preset monitoring mechanism. This may include parameters such as the frequency, intensity, and type of network attacks.
[0086] 2. Encryption strength adjustment strategy: Based on the monitored data transmission environment security status, the dynamic encryption adjustment unit formulates an encryption strength adjustment strategy, which includes adjusting the encryption algorithm selection, key length, encryption mode and other parameters.
[0087] Encryption algorithm selection: Depending on the severity of the security threat, the dynamic encryption adjustment unit may select a stronger or more complex encryption algorithm. For example, when facing a complex attack such as an advanced persistent threat (APT), it may choose an encryption algorithm with higher security, such as AES-256 instead of AES-128.
[0088] Key length adjustment: Key length is one of the key factors affecting the security of encryption algorithms. The dynamic encryption adjustment unit may increase or decrease the key length according to the severity of the security threat. For example, when facing a high-intensity attack, it may choose a longer key length to improve the security of encryption.
[0089] Encryption mode adjustment: The encryption mode determines how data is processed during the encryption process. The dynamic encryption adjustment unit may select a more suitable encryption mode, such as CBC (Cipher Block Chaining) mode or GCM (Galois / Counter Mode) mode, based on security requirements.
[0090] 3. Encryption strength adjustment execution: The dynamic encryption adjustment unit sends the formulated encryption strength adjustment strategy to the data transmission channel unit. The data transmission channel unit encrypts the monitoring data to be subsequently transmitted according to the new encryption strength configuration.
[0091] Through the description of the above embodiments, those skilled in the art can clearly understand the specific implementation method and working principle of the data transmission channel module. The data transmission channel unit ensures that the encrypted monitoring data can be safely transmitted by setting a secure transmission protocol, and the dynamic encryption adjustment unit dynamically adjusts the encryption strength according to the security status of the transmission environment to further ensure the security of data transmission. This design enables the remote security monitoring system to maintain the security and reliability of data transmission under different security threat environments.
[0092] Distributed storage module, the distributed storage module includes a distributed storage unit. The distributed storage unit is connected to the data transmission channel module, and the distributed storage unit is used to use distributed ledger technology, such as blockchain or distributed hash table (DHT), to build a data storage structure to distribute the encrypted monitoring data. In this way, even if some storage nodes fail or are attacked, the monitoring data can still be recovered from other nodes, which improves the reliability and security of the data. In addition, the distributed storage module also includes a consensus mechanism unit, which is connected to the distributed storage unit. The consensus mechanism unit is used to adopt non-complete blockchain technology, through consensus mechanisms such as proof of work (PoW), proof of equity (PoS) or practical Byzantine fault tolerance (PBFT), etc., to ensure the consistency and reliability of monitoring data in distributed storage. In the remote security monitoring system, the distributed storage module is responsible for storing the encrypted monitoring data to ensure the high reliability and security of the data. This embodiment will describe in detail the specific implementation of the distributed storage module, including the functions and working principles of the distributed storage unit and the consensus mechanism unit.
[0093] 1. Distributed Storage Unit
[0094] The distributed storage unit is the core part of the distributed storage module, which is responsible for building a data storage structure using distributed ledger technology and performing distributed storage of encrypted monitoring data. Its workflow is as follows:
[0095] 1. Distributed ledger technology selection: Distributed storage units use distributed ledger technologies such as blockchain or distributed hash table (DHT) to build data storage structures. These technologies ensure high reliability and security of data through mechanisms such as decentralization, data redundancy, and distributed consensus.
[0096] Blockchain implementation: If blockchain technology is adopted, the distributed storage unit will create a blockchain network in which each node saves a complete copy of the data. Data is added to the chain in the form of blocks, and each block contains the hash value of the previous block to ensure the data is tamper-proof.
[0097] DHT implementation: If DHT technology is adopted, the distributed storage unit will use the DHT algorithm (such as Chord, Pastry or Kademlia) to build a distributed hash table, in which each node is responsible for storing a part of the data. The data is mapped to a specific node through a hash function to achieve distributed storage and retrieval of data.
[0098] 2. Distributed data storage: After the distributed ledger technology is selected, the distributed storage unit begins to receive and store the encrypted monitoring data from the data transmission channel module. The data is stored on multiple nodes in a distributed manner to ensure that even if some nodes fail or are attacked, the data can still be recovered from other nodes.
[0099] 2. Consensus Mechanism Unit
[0100] The consensus mechanism unit is connected to the distributed storage unit and is responsible for adopting the consensus mechanism in the non-complete blockchain technology to ensure the consistency and reliability of the monitoring data in the distributed storage. Its working principle is as follows:
[0101] 1. Consensus mechanism selection: The consensus mechanism unit selects a suitable consensus mechanism based on the specific implementation and performance requirements of the distributed storage unit. Consensus mechanisms include proof of work (PoW), proof of stake (PoS) or practical Byzantine fault tolerance (PBFT), etc. The specific mechanism to be used can be selected according to the actual situation and there is no restriction here.
[0102] Proof of Work (PoW): In the PoW mechanism, nodes compete for the right to generate new blocks by solving a mathematical problem. The PoW mechanism can prevent double-spending attacks by malicious nodes, but it consumes a lot of energy.
[0103] Proof of Stake (PoS): In the PoS mechanism, nodes compete for the right to generate new blocks based on the number and time of tokens they hold. The PoS mechanism reduces energy consumption, but may face the risk of equity centralization.
[0104] Practical Byzantine Fault Tolerance (PBFT): In the PBFT mechanism, nodes reach consensus through a series of message passing protocols. The PBFT mechanism is suitable for small-scale distributed systems and has high throughput and low latency.
[0105] 2. Consensus process execution: The consensus mechanism unit executes the consensus process according to the selected consensus mechanism. In the PoW or PoS mechanism, the consensus process includes mining competition or equity voting among nodes; in the PBFT mechanism, the consensus process includes message transmission stages such as pre-preparation, preparation, and submission.
[0106] 3. Data consistency verification: After the consensus process is completed, the consensus mechanism unit verifies the consistency of the data. Data consistency verification includes checking the validity of new blocks (such as puzzle solving in PoW or stake verification in PoS) and ensuring that the data copies on all nodes remain consistent.
[0107] 4. Fault recovery and fault tolerance: If some nodes fail or are attacked, resulting in data loss or inconsistency, the consensus mechanism unit will trigger the fault recovery and fault tolerance mechanism. Fault recovery and fault tolerance include copying data from other healthy nodes, re-executing the consensus process, or using other fault tolerance technologies to restore data consistency and reliability.
[0108] Through the description of the above embodiments, those skilled in the art can clearly understand the specific implementation method and working principle of the distributed storage module. The distributed storage unit uses distributed ledger technology to build a data storage structure and distributes the encrypted monitoring data; the consensus mechanism unit uses the consensus mechanism in the non-complete blockchain technology to ensure the consistency and reliability of the data. This design enables the remote security monitoring system to achieve high reliability and security of data in a distributed environment.
[0109] Privacy compliance check module, the privacy compliance check module includes a periodic scanning and elimination unit and a regulatory update interface. The periodic scanning and elimination unit is connected to the distributed storage module, and is used to periodically scan the stored and transmitted monitoring data, and eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results, such as personal sensitive information without user consent. The regulatory update interface is connected to the periodic scanning and elimination unit, and the regulatory update interface is used to receive and parse the latest privacy protection regulations and technical standards, such as GDPR, CCPA, etc., to ensure that the privacy protection strategy of the monitoring system always complies with the requirements of laws and regulations.
[0110] Specific implementation of the privacy compliance check module:
[0111] 1. System Architecture Description
[0112] The privacy compliance check module in this embodiment is a key component in the monitoring system, which is designed to ensure that the stored and transmitted monitoring data complies with the latest privacy protection regulations and technical standards. The module mainly includes two core units: a regular scanning and elimination unit and a regulatory update interface, as well as a distributed storage module connected to it.
[0113] 2. Detailed implementation of the module
[0114] 1. Distributed storage module
[0115] Function description: The distributed storage module is responsible for storing and transmitting all data of the monitoring system, including video streams, images, audio, etc.
[0116] Technical implementation: Hadoop Distributed File System (HDFS) is used as the storage backend to support distributed storage and processing of large-scale data.
[0117] 2. Scan the rejection unit regularly
[0118] Functional description: The periodic scanning and elimination unit is connected to the distributed storage module to periodically scan the stored and transmitted monitoring data, and eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results.
[0119] Technical implementation: Scanning algorithm: A text matching algorithm based on regular expressions is used to perform keyword scanning on the stored data. For example, for personal sensitive information (such as name, ID number, phone number, etc.), a set of regular expressions is pre-defined to match this sensitive information.
[0120] Data elimination strategy: After scanning sensitive information, data processing is performed according to preset rules (such as personal sensitive information without user consent must be eliminated). In specific implementation, data elimination can be achieved by deleting the corresponding file blocks or records in HDFS.
[0121] Regular scheduling: Use the Cron job scheduler to set a scheduled task to perform a scan and removal operation at 2 a.m. every day.
[0122] 3. Regulatory update interface
[0123] Function description: The regulatory update interface is used to receive and parse the latest privacy protection regulations and technical standards, such as GDPR (EU General Data Protection Regulation), CCPA (California Consumer Privacy Act), etc., to ensure that the privacy protection strategy of the monitoring system always complies with the requirements of laws and regulations.
[0124] Technical implementation: Data reception: Receive data push from the regulatory update service through the RESTful API interface. The data format is JSON, which contains the latest regulatory provisions and interpretations.
[0125] Parsing algorithm: Use a JSON parsing library (such as Jackson or Gson) to parse the received JSON data and extract key regulatory provisions and corresponding explanations.
[0126] Strategy update: The parsed regulations and interpretations are stored in the local database. The regular scanning and rejection unit will first read the latest regulations and interpretations from the local database each time it performs a scan, and then update the scanning and rejection strategies based on these regulations and interpretations.
[0127] 3. Implementation Effect
[0128] Through the above embodiments, the privacy compliance check module can implement regular scanning and elimination of monitoring data to ensure that the stored and transmitted data complies with the latest privacy protection laws and technical standards. At the same time, through the regulatory update interface, the module can receive and parse the latest regulatory provisions and interpretations in real time to ensure that the privacy protection strategy always complies with the requirements of laws and regulations.
[0129] Security audit module, the security audit module is connected with the encryption processing module, the data transmission channel module and the distributed storage module. The security audit module is used to record and audit the encryption, storage, transmission and access operations of all monitoring data in the monitoring system, such as the use of encryption algorithms, the starting and ending points of data transmission, the location of storage nodes, etc., and provide detailed security logs. These logs can be used to trace and troubleshoot security risks, such as unauthorized access, data leakage, etc., so as to further improve the security of the monitoring system.
[0130] The following is the specific implementation of the security audit module:
[0131] 1. System Overview
[0132] This embodiment describes in detail the specific implementation of the security audit module in the monitoring system. The security audit module is closely connected with the encryption processing module, the data transmission channel module and the distributed storage module, and is responsible for recording and auditing the encryption, storage, transmission and access operations of all monitoring data in the monitoring system to ensure the security of the monitoring system.
[0133] 2. Module connection and function description
[0134] 1. Encryption processing module connection
[0135] Connection method: The security audit module is connected to the encryption processing module through the API interface.
[0136] Functional description: The security audit module records the encryption algorithm (such as AES-256) used by the encryption processing module, encryption key management operations (such as key generation, distribution, update and destruction), and the timestamp and operator information of the encryption operation.
[0137] 2.Data transmission channel module connection
[0138] Connection method: The security audit module achieves connection by monitoring the network traffic of the data transmission channel.
[0139] Functional description: The security audit module records the starting and ending IP addresses, port numbers, transmission protocols (such as TCP / IP), transmission data volume, transmission timestamp, and any abnormal or error information during the data transmission process.
[0140] 3. Distributed storage module connection
[0141] Connection method: The security audit module is connected to the distributed storage module through file system monitoring or database query.
[0142] Functional description: The security audit module records the location of storage nodes (such as specific nodes in the HDFS cluster), the file name of the stored data, the file size, the storage timestamp, and the success or failure status of the storage operation.
[0143] 3. Security Logging and Auditing
[0144] 1. Log Record Content
[0145] Encryption algorithm usage log: records the encryption algorithm name, encryption key ID, encryption operation timestamp, and operator information.
[0146] Data transmission log: records the starting and ending information of data transmission, transmission protocol, transmission data volume and transmission timestamp.
[0147] Storage operation log: records the location of the storage node, the file name of the stored data, the file size, and the storage timestamp.
[0148] Access operation log: records the access requester information, access timestamp, accessed data range and access result (success or failure) of the monitored data.
[0149] 2. Log storage and management
[0150] Log storage format: Logs are stored in JSON format for easy parsing and querying.
[0151] Log storage location: Logs are stored on a dedicated log server, using a distributed file system (such as Elasticsearch) for efficient storage and management.
[0152] Log backup and recovery: Back up log data regularly to ensure that log data can be quickly restored when the log server fails.
[0153] 3. Log audit and analysis
[0154] Log query: Provides log query functions based on time range, operation type, operator information and other conditions, allowing administrators to quickly locate specific events.
[0155] Log analysis: Use data analysis tools (such as Kibana) to visualize log data and identify potential security risks and abnormal behaviors.
[0156] Alarm mechanism: Set alarm rules. When unauthorized access, data leakage and other security risks are detected, the alarm mechanism will be automatically triggered to notify the administrator for processing.
[0157] 4. Implementation Effect and Security Improvement
[0158] Through the security audit module of this embodiment, the monitoring system can comprehensively record and audit the encryption, storage, transmission and access operations of the monitoring data, and provide detailed security logs. These logs can not only be used to trace and troubleshoot security risks, such as unauthorized access and data leakage, but also provide administrators with real-time security monitoring and early warning functions, thereby significantly improving the security of the monitoring system.
[0159] Through the above embodiments, the system solves the technical problems of insufficient user privacy protection and data leakage risks in the remote security monitoring system, so that user privacy is fully protected.
[0160] Figure 2 A flow chart of the remote security monitoring method provided in this application, such as Figure 2 As shown, the remote security monitoring method provided by this embodiment is applied to Figure 1 The monitoring system of the embodiment, the method comprises:
[0161] S101: Acquire monitoring data, and encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combining homomorphic encryption technology and zero-knowledge proof technology.
[0162] The specific implementation process and principles are as follows:
[0163] 1. Obtain monitoring data
[0164] Source of monitoring data: Monitoring data is collected through cameras, temperature sensors, humidity sensors, infrared sensors and other devices, including video stream data (H.264 encoding format), audio stream data (AAC encoding format), temperature data (Celsius value), humidity data (percentage value), etc.
[0165] Data format: Monitoring data is stored in binary format and transmitted to the central processing unit (CPU) or a dedicated encryption processor (such as Intel SGX) via Ethernet or Wi-Fi networks.
[0166] 2. Adopt hybrid encryption protocol based on post-quantum cryptography
[0167] Post-quantum cryptography algorithm selection: Use the CRYSTALS-Kyber algorithm (a lattice-based post-quantum public key encryption algorithm) to generate public and private key pairs. The specific parameters are set to:
[0168] Security level: Kyber-768, providing 192 bits of quantum security.
[0169] Public key length: 1184 bytes.
[0170] Private key length: 2400 bytes.
[0171] Symmetric encryption algorithm selection: Use AES-256 (Advanced Encryption Standard, 256-bit key) as the symmetric encryption algorithm to generate a 256-bit symmetric key.
[0172] Hybrid encryption protocol implementation:
[0173] Use the public key of the CRYSTALS-Kyber algorithm to encrypt the AES-256 symmetric key to generate an encrypted symmetric key.
[0174] The encrypted symmetric key is transmitted together with the monitoring data.
[0175] 3. Combined with homomorphic encryption technology
[0176] Homomorphic encryption algorithm selection: Use the Paillier homomorphic encryption algorithm (an additive homomorphic encryption algorithm based on composite residue classes) to encrypt monitoring data.
[0177] Key generation: Select two large prime numbers p and q, calculate n = p × q and λ = lcm (p-1, q-1), and generate a public key (n, g) and a private key (λ, μ). Among them, lcm represents the least common multiple, g is a public key parameter in the Paillier homomorphic encryption algorithm, used for calculations in the encryption process, g = n + 1, and μ is a private key parameter in the Paillier decryption algorithm, used for calculations in the decryption process, μ = λ -1 modn, "mod" is the abbreviation of "Modulo Operation". The Paillier decryption algorithm is a conventional decryption method for those skilled in the art, so it will not be described in detail here.
[0178] Encryption process: For monitoring data m, calculate the ciphertext c = g m × n modn 2 , where r is a random number.
[0179] Homomorphic addition: For two ciphertexts c1 and c2, calculate c3 = c1 × c2 modn 2, after decryption, you get m1+m2. Specifically, for example, you have two encrypted ciphertexts c1 and c2, corresponding to plaintexts m1 and m2 respectively, then homomorphic addition allows you to directly operate on c1 and c2 to get a new ciphertext c3, and c3 will be decrypted to get m1+m2. For the specific calculation process and principle, please refer to the basic principle of the Paillier homomorphic encryption algorithm. The Paillier homomorphic encryption algorithm is a conventional encryption method for those skilled in the art, so it will not be described here.
[0180] 4. Combined with zero-knowledge proof technology
[0181] Zero-knowledge proof algorithm selection: Use zk-SNARKs (Zero-knowledge Succinct Non-interactive Argument of Knowledge) technology to generate zero-knowledge proof.
[0182] Circuit Design: Design arithmetic circuits and define integrity verification rules for monitoring data.
[0183] Proof generation: Use the libsnark library to generate proofs to prove that the monitoring data meets the preset rules without revealing the specific content.
[0184] Verification process: Use the verification key to verify the generated certificate to ensure the integrity and authenticity of the monitoring data.
[0185] 5. Encryption
[0186] Symmetric encryption: The monitoring data is symmetrically encrypted using the AES-256 algorithm. The specific steps are:
[0187] The monitoring data is divided into 128-bit plaintext blocks.
[0188] Each plaintext block is encrypted using the AES-256 algorithm and the generated symmetric key to generate a ciphertext block.
[0189] Homomorphic encryption: The ciphertext encrypted by AES-256 is re-encrypted using the Paillier homomorphic encryption algorithm.
[0190] Attach zero-knowledge proof: Use zk-SNARKs technology to generate zero-knowledge proof and attach the proof to the encrypted monitoring data.
[0191] 6. Output encryption results
[0192] The encrypted monitoring data finally output includes:
[0193] CRYSTALS - AES-256 symmetric key encrypted by Kyber algorithm.
[0194] AES-256 ciphertext encrypted by the Paillier homomorphic encryption algorithm.
[0195] Zero-knowledge proofs generated by zk-SNARKs.
[0196] 7. Examples
[0197] Assume that the monitoring data is temperature data m = 25 (degrees Celsius):
[0198] After encryption using AES-256, the ciphertext C is obtained AES .
[0199] Encrypt C using the Paillier homomorphic encryption algorithm AES Get the ciphertext C Paillier .
[0200] Use zk-SNARKs to generate proof π and verify C Paillier integrity.
[0201] The final output is (Encrypted Key, C Paillier ,π). Among them, Encrypted Key is the AES-256 symmetric key encrypted by the CRYSTALS-Kyber algorithm.
[0202] Through the above steps, the monitoring data has post-quantum security, homomorphic computing capabilities and zero-knowledge verification capabilities after encryption, which effectively protects user privacy and reduces the risk of data leakage.
[0203] S102: A secure transmission protocol is set to prevent the encrypted monitoring data from being intercepted or tampered with during transmission.
[0204] The specific implementation process or principle is as follows:
[0205] 1. Choose a secure transmission protocol
[0206] Protocol selection: Use TLS1.3 (Transport Layer Security 1.3) as the secure transmission protocol. TLS1.3 is currently the most widely recognized and secure transport layer protocol, which can effectively prevent data from being intercepted or tampered with during transmission.
[0207] Protocol version: Ensure that the TLS 1.3 version used is in accordance with the RFC8446 standard.
[0208] 2. Configure TLS 1.3 protocol
[0209] Cipher suite selection:
[0210] The encryption suite configured for TLS1.3 is TLS_AES_256_GCM_SHA384. This encryption suite uses the AES-256-GCM algorithm for symmetric encryption and the SHA-384 algorithm for message authentication, providing high-strength data confidentiality and integrity protection.
[0211] Key exchange algorithm: ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) is used as the key exchange algorithm to ensure forward secrecy (PFS). The specific curve is secp384r1, which provides 192 bits of security.
[0212] Certificate configuration: Use X.509 digital certificate, the certificate signature algorithm is ECDSA-SHA384, and the certificate public key algorithm is EC secp384r1.
[0213] 3. Establish a secure transmission channel
[0214] Client and server handshake:
[0215] The client sends a ClientHello message to the server, which contains the supported TLS version, cipher suite list, and random number.
[0216] The server responds with a ServerHello message, confirming the use of TLS 1.3 and the cipher suite TLS_AES_256_GCM_SHA384, and sending the server's random number and digital certificate.
[0217] The client verifies the server's digital certificate, generates a pre-master secret, encrypts it with the server's public key, and sends it to the server.
[0218] The server uses the private key to decrypt the pre-master secret, and the client and server generate the master secret based on the pre-master secret and the random number, respectively.
[0219] The client and server use the master key to generate a symmetric encryption key and a message authentication code (MAC) key to complete the handshake.
[0220] Data transmission:
[0221] The monitoring data encrypted in step S101 is encrypted using the AES-256-GCM algorithm. The specific process is as follows:
[0222] The monitoring data is divided into 128-bit plaintext blocks.
[0223] Each plaintext block is encrypted using the AES-256-GCM algorithm and the generated symmetric key to generate a ciphertext block.
[0224] The Authentication Tag of the ciphertext block is calculated using the SHA-384 algorithm and appended to the ciphertext block.
[0225] The encrypted monitoring data is transmitted to the target server via the TLS1.3 protocol.
[0226] 4. Prevent data interception and tampering
[0227] Data confidentiality: The AES-256-GCM algorithm ensures that monitoring data cannot be intercepted and decrypted during transmission.
[0228] Data integrity: The authentication tag generated by the SHA-384 algorithm ensures that the monitoring data has not been tampered with during transmission.
[0229] Forward secrecy: The ECDHE algorithm ensures that even if the long-term private key is leaked, historical transmission data cannot be decrypted.
[0230] 5. Examples
[0231] Monitoring data: Assume that the monitoring data is video stream data, and its size is 1MB.
[0232] Encryption process:
[0233] The video stream data is divided into 128-bit plaintext blocks.
[0234] Each plaintext block is encrypted using the AES-256-GCM algorithm and a symmetric key to generate a ciphertext block.
[0235] Compute the authentication tag of the ciphertext block using the SHA-384 algorithm.
[0236] Transmission process:
[0237] The client and server complete the TLS1.3 handshake and generate a symmetric key.
[0238] The client transmits the encrypted video stream data to the server via the TLS1.3 protocol.
[0239] After receiving the data, the server uses the symmetric key to decrypt and verify the authentication tag to ensure data integrity and confidentiality.
[0240] 6. Summary
[0241] Secure transmission protocol: Use TLS1.3 protocol, configure encryption suite TLS_AES_256_GCM_SHA384 and key exchange algorithm ECDHE secp384r1.
[0242] Data encryption: Use the AES-256-GCM algorithm to encrypt monitoring data to ensure data confidentiality.
[0243] Data integrity: The SHA-384 algorithm is used to generate authentication tags to ensure that the data has not been tampered with.
[0244] Forward secrecy: Use the ECDHE algorithm to ensure the security of historical transmission data.
[0245] Through the above steps, the encrypted monitoring data can be effectively prevented from being intercepted or tampered with during transmission, ensuring the security and privacy of the data.
[0246] S103: Use distributed ledger technology to build a data storage structure to perform distributed storage on the encrypted monitoring data.
[0247] The following is the specific implementation process or principle of this step:
[0248] 1. Choose a distributed ledger technology
[0249] Technology selection: Use Hyperledger Fabric as the distributed ledger technology. Hyperledger Fabric is an enterprise-level distributed ledger platform that supports modular architecture and pluggable consensus mechanism, suitable for building secure and scalable data storage structures.
[0250] Version selection: Use Hyperledger Fabric 2.3 to support the latest privacy protection and data management features.
[0251] 2. Configure the Hyperledger Fabric network
[0252] Network node configuration:
[0253] Orderer node: responsible for transaction sorting and block generation, using the Raft consensus algorithm (based on etcd's Raft implementation) to ensure consistency.
[0254] Peer nodes: divided into endorser nodes (EndorserPeer) and committer nodes (CommitterPeer), responsible for executing smart contracts and storing ledger data.
[0255] CA node: responsible for issuing and managing digital certificates to ensure node identity authentication.
[0256] Channel configuration: Create a dedicated channel "monitoring data channel" to ensure the isolation and privacy of monitoring data.
[0257] 3. Design data storage structure
[0258] Smart contract design:
[0259] Write a smart contract "DataStorageContract" to define the storage rules and access rights of monitoring data.
[0260] Smart contract functions include:
[0261] 1. Store monitoring data: Write the encrypted monitoring data into the distributed ledger.
[0262] 2. Query monitoring data: Query the stored monitoring data based on permissions.
[0263] 3. Update monitoring data: Update or delete data in accordance with privacy protection regulations.
[0264] Data structure design:
[0265] Use key-value pairs to store monitoring data.
[0266] Example JSON data structure:
[0267] {
[0268] "DataID":"Monitoring data unique identifier",
[0269] "EncryptedData":"Encrypted monitoring data",
[0270] "Timestamp": "Data storage timestamp",
[0271] "Owner":"Data owner",
[0272] "AccessControl":"Access Control List"
[0273] }
[0274] 4.Store encrypted monitoring data
[0275] Data Encryption:
[0276] Before being transmitted to the Hyperledger Fabric network, the monitoring data is encrypted using a hybrid encryption protocol based on post-quantum cryptography (such as CRYSTALS-Kyber and AES-256).
[0277] Data Storage:
[0278] (1) The client packages the encrypted monitoring data into a transaction proposal and sends it to the endorsing node.
[0279] (2) The endorsing node executes the smart contract DataStorageContract to verify the validity of the transaction proposal.
[0280] (3) The endorsing node returns the signed transaction proposal to the client.
[0281] (4) The client submits the transaction proposal to the Orderer node.
[0282] (5) The Orderer node uses the Raft consensus algorithm to sort transactions and generate blocks.
[0283] (6) The submitting node writes the block into the distributed ledger to complete data storage.
[0284] 5. Data query and verification
[0285] Data query:
[0286] The client queries monitoring data through the smart contract DataStorageContract.
[0287] The query results include encrypted monitoring data and related metadata (such as timestamp, owner, etc.).
[0288] Data Validation:
[0289] Use zero-knowledge proof technology (such as zk-SNARKs) to verify the integrity and authenticity of monitoring data without revealing the specific content.
[0290] 6. Examples
[0291] Monitoring data: Assume that the encrypted monitoring data is EncryptedData = "a1b2c3d4e5f6".
[0292] Stored Procedure:
[0293] 1. The client generates a transaction proposal:
[0294] {
[0295] "DataID":"12345",
[0296] "EncryptedData":"a1b2c3d4e5f6",
[0297] "Timestamp":"2023-10-01T12:00:00Z",
[0298] "Owner":"UserA",
[0299] "AccessControl":["UserA","Admin"]
[0300] }
[0301] 2. The endorsing node executes the smart contract, verifies the transaction proposal and returns a signature.
[0302] 3. The client submits the transaction proposal to the Orderer node.
[0303] 4. The Orderer node generates blocks and writes them into the distributed ledger.
[0304] Query process:
[0305] 1. The client queries the monitoring data with DataID 12345.
[0306] 2. Smart contract returns:
[0307] {
[0308] "DataID":"12345",
[0309] "EncryptedData":"a1b2c3d4e5f6",
[0310] "Timestamp":"2023-10-01T12:00:00Z",
[0311] "Owner":"UserA",
[0312] "AccessControl":["UserA","Admin"]
[0313] }
[0314] 7. Summary
[0315] Distributed Ledger Technology: Use Hyperledger Fabric 2.3 to build a data storage structure.
[0316] Smart contract: Write the smart contract DataStorageContract to define data storage, query and update rules.
[0317] Data storage: The encrypted monitoring data is written into the distributed ledger through transaction proposals.
[0318] Data query and verification: Query data through smart contracts and verify data integrity using zero-knowledge proof technology.
[0319] Through the above steps, the encrypted monitoring data can be securely stored in the distributed ledger to ensure the privacy, integrity and traceability of the data.
[0320] Optionally, after using the distributed ledger technology to construct a data storage structure to distribute the encrypted monitoring data, it also includes: regularly scanning the stored and transmitted monitoring data, and eliminating the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results.
[0321] The following is a specific embodiment of regularly scanning the stored and transmitted monitoring data, and removing the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results:
[0322] 1. Trigger mechanism for periodic scanning
[0323] Scan frequency: Set the scan task to be automatically executed at 2:00 am every day to ensure that the scan is performed during a time period that does not affect system performance.
[0324] Trigger condition: When the storage volume of monitoring data reaches 1TB or the time since the last scan exceeds 24 hours, the scan task is triggered.
[0325] 2. Scanning tools and algorithms
[0326] Scanning tool: Use the ClamAV open source antivirus engine and the YARA rule engine for data scanning.
[0327] ClamAV is used to detect malware and anomalous data.
[0328] YARA is used to match violation patterns in privacy protection regulations and technical standards.
[0329] Scanning algorithm:
[0330] Regular expression matching: Use regular expressions to match sensitive information in monitoring data (such as ID card number, bank card number, etc.).
[0331] Example: The regular expression for ID number is \d{17}[\dXx].
[0332] Keyword filtering: Use a list of keywords (such as "confidential", "privacy", etc.) to detect sensitive content in monitoring data.
[0333] Hash value comparison: Calculate the SHA-256 hash value of the monitored data and compare it with the hash value library of known illegal data.
[0334] 3. Definition of privacy protection regulations and technical standards
[0335] Regulatory Basis: Privacy protection rules are defined in accordance with the General Data Protection Regulation (GDPR) and the Cybersecurity Law of the People's Republic of China.
[0336] Technical standards: Define technical standards based on the ISO / IEC 27001 information security standard and the NIST SP 800-53 security control framework.
[0337] Rule Base:
[0338] GDPR rules: Detect whether the monitored data contains personally identifiable information (PII), such as name, address, phone number, etc.
[0339] Cybersecurity Law Rules: Detect whether the monitoring data contains state secrets or sensitive information.
[0340] ISO / IEC 27001 rules: Detect whether monitoring data contains unencrypted sensitive information.
[0341] 4. Scanning process
[0342] Data reading:
[0343] Read encrypted monitoring data from the distributed ledger.
[0344] The Paillier decryption algorithm is used to decrypt the monitoring data and generate plaintext data.
[0345] Data Scanning:
[0346] Use ClamAV to scan plaintext data and detect whether there is malware or abnormal data.
[0347] Use the YARA rules engine to match violation patterns in privacy protection regulations and technical standards.
[0348] Use regular expressions to match sensitive information (such as ID card number, bank card number, etc.).
[0349] Use keyword filtering to detect sensitive content.
[0350] Calculate the SHA-256 hash value of the monitored data and compare it with the hash value library of the illegal data.
[0351] Results recorded:
[0352] The scan results are recorded in the security log, including the unique identifier of the violation data, violation type, scan time, etc.
[0353] Generate a scan report summarizing the number and type of data violations.
[0354] 5. Illegal data processing
[0355] Data elimination:
[0356] Based on the scan results, the offending data is deleted from the distributed ledger.
[0357] Update the access control list (ACL) of the distributed ledger to ensure that illegal data cannot be accessed.
[0358] Data backup:
[0359] Back up the offending data to an isolated storage area for subsequent audit and analysis.
[0360] Encrypt backup data to ensure data security.
[0361] 6. Examples
[0362] Monitoring data: Assume that the monitoring data is video stream data, which contains a sensitive conversation.
[0363] Scanning process:
[0364] The video stream data was scanned using ClamAV and no malware was detected.
[0365] The YARA rule engine is used to match GDPR rules and detect that the conversation contains personally identifiable information (PII).
[0366] Use regular expressions to match ID numbers.
[0367] The keyword "confidential" was detected using keyword filtering.
[0368] The SHA-256 hash value of the video stream data is calculated and compared with the hash value library of the illegal data, and no match is found.
[0369] Results recorded:
[0370] The unique identifier of the violation data is DataID=12345, and the violation type is "contains personal identity information".
[0371] Generate a scan report summarizing the number and type of data violations.
[0372] Illegal data processing:
[0373] Delete the monitoring data with DataID=12345 from the distributed ledger.
[0374] Update the access control list of the distributed ledger to ensure that DataID=12345 cannot be accessed.
[0375] The monitoring data with DataID=12345 is backed up to the isolated storage area and encrypted.
[0376] 7. Summary
[0377] Scanning tools: Use ClamAV and YARA rule engines for data scanning.
[0378] Scanning algorithm: Use regular expression matching, keyword filtering, and hash value comparison to detect illegal data.
[0379] Regulatory Basis: Privacy protection rules are defined according to GDPR, Cybersecurity Law and ISO / IEC27001.
[0380] Data processing: Delete illegal data from the distributed ledger and back it up to an isolated storage area.
[0381] Through the above steps, the stored and transmitted monitoring data can be scanned regularly, and illegal data can be eliminated according to privacy protection regulations and technical standards to ensure data compliance and security.
[0382] Optionally, the monitoring method further includes: recording and auditing the encryption, storage, transmission and access operations of all the monitoring data in the monitoring system, and providing a detailed security log to facilitate tracing and troubleshooting of potential safety hazards.
[0383] The following is the specific implementation process or principle of recording and auditing the encryption, storage, transmission and access operations of all the monitoring data in the monitoring system, and providing detailed security logs to facilitate tracing and troubleshooting of security risks:
[0384] 1. Logging module design
[0385] Logging tools: Use ELK Stack (Elasticsearch, Logstash, Kibana) as a logging and analysis platform.
[0386] Elasticsearch is used to store log data.
[0387] Logstash is used to collect and filter log data.
[0388] Kibana is used to visualize log data.
[0389] Log format: Logs are recorded in JSON format to ensure structure and scalability.
[0390] 2. Log content definition
[0391] Encryption operation log:
[0392] Logs details of cryptographic operations, including:
[0393] Encryption algorithms: CRYSTALS-Kyber and AES-256.
[0394] Encryption Time: The timestamp of the operation.
[0395] Encrypted data ID: The unique identifier of the encrypted data.
[0396] Encryption Key: The hash value (SHA-256) of the encryption key used. Example:
[0397] {
[0398] "Operation":"Encryption",
[0399] "Algorithm":"CRYSTALS-Kyber+AES-256",
[0400] "Timestamp":"2023-10-01T12:00:00Z",
[0401] "DataID":"12345",
[0402] "KeyHash":"a1b2c3d4e5f6..."
[0403] }
[0404] Storage operation log:
[0405] Records details of storage operations, including:
[0406] Storage location: Block ID in the distributed ledger.
[0407] Storage time: The timestamp of the operation.
[0408] Storage data ID: The unique identifier of the stored data.
[0409] Stores the result: success or failure.
[0410] Example:
[0411] {
[0412] "Operation":"Storage",
[0413] "BlockID":"Block123",
[0414] "Timestamp":"2023-10-01T12:05:00Z",
[0415] "DataID":"12345",
[0416] "Result":"Success"
[0417] }
[0418] Transfer operation log:
[0419] Records details of transfer operations, including:
[0420] Transport protocol: TLS1.3.
[0421] Transfer Time: The timestamp of the operation.
[0422] Transmission data ID: unique identifier of the data being transmitted. Transmission result: success or failure.
[0423] Example:
[0424] {
[0425] "Operation":"Transmission",
[0426] "Protocol":"TLS1.3",
[0427] "Timestamp":"2023-10-01T12:10:00Z","DataID":"12345",
[0428] "Result":"Success"
[0429] }
[0430] To access the operation log:
[0431] Records detailed information about access operations, including: Visitor: The visitor's identity.
[0432] Access Time: The timestamp of the operation.
[0433] Access data ID: unique identifier of the accessed data. Access result: success or failure.
[0434] Example:
[0435] {
[0436] "Operation":"Access",
[0437] "User":"UserA",
[0438] "Timestamp":"2023-10-01T12:15:00Z","DataID":"12345",
[0439] "Result":"Success"
[0440] }
[0441] 3. Log collection and storage
[0442] Log collection:
[0443] Use Logstash to collect log data from the encryption module, storage module, transmission module, and access control module.
[0444] Filter and format log data to ensure that it complies with the JSON format.
[0445] Log storage:
[0446] Store the formatted log data in Elasticsearch.
[0447] Use the indexing function of Elasticsearch to classify and retrieve log data.
[0448] 4. Log audit and analysis
[0449] Audit tool: Use Kibana for log auditing and analysis.
[0450] Audit process:
[0451] Create dashboards in Kibana to visualize log data.
[0452] Use Kibana's query language (KQL) to retrieve log data for a specific time range.
[0453] Analyze log data to identify abnormal operations and security threats.
[0454] Audit Report:
[0455] Generate audit reports that summarize abnormal operations and security events in log data.
[0456] Provides detailed security logs to facilitate tracing and troubleshooting of potential safety hazards.
[0457] 5. Examples
[0458] Encryption operation log:
[0459] {
[0460] "Operation":"Encryption",
[0461] "Algorithm":"CRYSTALS-Kyber+AES-256",
[0462] "Timestamp":"2023-10-01T12:00:00Z",
[0463] "DataID":"12345",
[0464] "KeyHash":"a1b2c3d4e5f6..."
[0465] }
[0466] Storage operation log:
[0467] {
[0468] "Operation":"Storage",
[0469] "BlockID":"Block123",
[0470] "Timestamp":"2023-10-01T12:05:00Z",
[0471] "DataID":"12345",
[0472] "Result":"Success"
[0473] }
[0474] Transfer operation log:
[0475] {
[0476] "Operation":"Transmission",
[0477] "Protocol":"TLS1.3",
[0478] "Timestamp":"2023-10-01T12:10:00Z",
[0479] "DataID":"12345",
[0480] "Result":"Success"
[0481] }
[0482] To access the operation log:
[0483] {
[0484] "Operation":"Access",
[0485] "User":"UserA",
[0486] "Timestamp":"2023-10-01T12:15:00Z",
[0487] "DataID":"12345",
[0488] "Result":"Success"
[0489] }
[0490] 6. Summary
[0491] Logging tools: Use ELK Stack to record and analyze log data.
[0492] Log content: Records detailed information about encryption, storage, transmission, and access operations.
[0493] Log collection and storage: Use Logstash to collect log data and store it in Elasticsearch.
[0494] Log auditing and analysis: Use Kibana to audit and analyze logs and generate audit reports.
[0495] Through the above steps, the encryption, storage, transmission and access operations of all monitoring data in the monitoring system can be recorded and audited, and a detailed security log can be provided to facilitate the tracing and troubleshooting of security risks.
[0496] The remote security monitoring method provided by the present application obtains monitoring data and uses a hybrid encryption protocol based on post-quantum cryptography (such as CRYSTALS-Kyber combined with AES-256), homomorphic encryption technology (such as Paillier algorithm) and zero-knowledge proof technology (such as zk-SNARKs) to encrypt the data to ensure data confidentiality and privacy. Prevent data from being intercepted or tampered with during transmission by setting a secure transmission protocol (such as TLS1.3). Use distributed ledger technology (such as Hyperledger Fabric) to build a data storage structure to achieve distributed storage and traceability of data. In addition, regularly scan the stored and transmitted data, eliminate monitoring data that does not comply with privacy protection regulations and technical standards, and provide detailed security logs by recording and auditing all encryption, storage, transmission and access operations to facilitate tracing and troubleshooting of security risks. This method significantly improves the privacy protection capabilities and data security of the remote monitoring system.
[0497] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the claims.
[0498] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A remote security monitoring system, characterized in that: The monitoring system comprises: An encryption processing module, which is deployed in the monitoring system and includes an encryption processing unit, which is used to obtain monitoring data and is further used to encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combined with homomorphic encryption technology and zero-knowledge proof technology; A data transmission channel module, the data transmission channel module includes a data transmission channel unit, the data transmission channel unit is connected to the encryption processing module, and the data transmission channel unit is used to prevent the encrypted monitoring data from being intercepted or tampered with during the transmission process by setting a secure transmission protocol; A distributed storage module, wherein the distributed storage module comprises a distributed storage unit, wherein the distributed storage unit is connected to the data transmission channel module, and wherein the distributed storage unit is used to construct a data storage structure using distributed ledger technology to perform distributed storage on the encrypted monitoring data.
2. The remote security monitoring system according to claim 1, characterized in that: The encryption processing module also includes: An algorithm adaptation unit, the algorithm adaptation unit is connected to the encryption processing unit, and the algorithm adaptation unit is used to automatically adjust the configuration of the encryption algorithm according to the real-time requirements and scale of the monitoring data transmission.
3. The remote security monitoring system according to claim 1, characterized in that: The distributed storage module also includes: A consensus mechanism unit, wherein the consensus mechanism unit is connected to the distributed storage unit, and the consensus mechanism unit is used to adopt a non-complete blockchain technology to ensure the consistency and reliability of the monitoring data in the distributed storage through a consensus mechanism.
4. The remote security monitoring system according to claim 1, characterized in that: The data transmission channel module also includes: A dynamic encryption adjustment unit is connected to the data transmission channel unit, and is used to dynamically adjust the encryption strength according to the security status of the transmission environment of the monitoring data.
5. The remote security monitoring system according to claim 1, characterized in that: The monitoring system also includes: A privacy compliance checking module, wherein the privacy compliance checking module includes a periodic scanning and elimination unit, wherein the periodic scanning and elimination unit is connected to the distributed storage module, and the periodic scanning and elimination unit is used to periodically scan the stored and transmitted monitoring data, and eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards based on the scanning results.
6. The remote security monitoring system according to claim 5, characterized in that: The privacy compliance checking module also includes: A regulation update interface, the regulation update interface is connected to the periodic scanning and rejection unit, and the regulation update interface is used to receive and parse the latest privacy protection regulations and technical standards.
7. The remote security monitoring system according to claim 1, characterized in that: The monitoring system also includes: A security audit module, which is connected to the encryption processing module, the data transmission channel module and the distributed storage module. The security audit module is used to record and audit the encryption, storage, transmission and access operations of all the monitoring data in the monitoring system, and provide a detailed security log to facilitate tracing and troubleshooting of potential safety hazards.
8. A remote security monitoring method, characterized in that: The monitoring method is applied to the monitoring system according to any one of claims 1 to 7, and the monitoring method comprises: Acquire monitoring data, and encrypt the monitoring data using an encryption algorithm based on a hybrid encryption protocol based on post-quantum cryptography and combined with homomorphic encryption technology and zero-knowledge proof technology; By setting up a secure transmission protocol, the encrypted monitoring data can be prevented from being intercepted or tampered with during transmission; Distributed ledger technology is used to build a data storage structure to distribute the encrypted monitoring data.
9. The remote security monitoring method according to claim 8, characterized in that: After the distributed ledger technology is used to construct a data storage structure to perform distributed storage on the encrypted monitoring data, the method further includes: Regularly scan the stored and transmitted monitoring data, and based on the scan results, eliminate the monitoring data that does not comply with the latest privacy protection regulations and technical standards.
10. The remote security monitoring method according to claim 8, characterized in that: The monitoring method further comprises: Record and audit all encryption, storage, transmission and access operations of the monitoring data within the monitoring system, and provide detailed security logs to facilitate tracing and troubleshooting of security risks.