Adaptive classification method and system for data streams

By segmenting the data stream and calculating the characteristics of the segmented data, adaptive encryption and classification are realized, which solves the problem that traditional methods are difficult to adapt to diversified data, and improves the efficiency and security of data classification.

CN120017366AActive Publication Date: 2025-05-16CHENGDU UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510166563.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-16
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

Traditional data classification methods are difficult to adapt to data of different types and lengths, resulting in low efficiency and low accuracy, lack of flexibility and unified framework.

Method used

By segmenting the data stream, calculating the characteristics of the segmented data using algorithms, and adaptively encrypting or classification based on the characteristic values, the efficiency and security of data classification are improved.

Benefits of technology

It realizes the efficiency and accuracy of data classification, while improving data security, and is suitable for the processing of diversified data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017366A_ABST
    Figure CN120017366A_ABST
Patent Text Reader

Abstract

The invention provides a self-adaptive classification method and system for data streams, and relates to the technical field of data processing, and the method comprises the following steps: sending secret keys to respective adaptive encryption / decryption equipment through data links, and managing the switching and replacement of various secret keys; during power-on, a secret key in a storage medium of the device is read to serve as a secret key of the self-adaptive encryption / decryption device; during normal work, a new secret key received through the data link is decrypted, a decrypted new secret key is obtained, an original secret key is discarded, and the new secret key serves as the secret key of the self-adaptive encryption / decryption equipment; or the self-adaptive encryption module is used for closing all communication ports by default after being powered on, decrypting data on the ports only by using an asymmetrically encrypted private key until the decrypted data of a certain port corresponds to the port number, and then carrying out self-adaptive encryption on the data sent by the port. The problem that data classification is time-consuming and labor-consuming is solved, data can be accurately classified, and the security of the data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data processing, and in particular relates to a method and system for adaptively classifying data streams. Background Art

[0002] Data classification technology is a key technology in data management and analysis. It aims to classify data into different categories based on its attributes and characteristics so as to manage and use data more efficiently. With the explosive growth of data volume and the diversification of data types, the complexity of these data scales and types has posed severe challenges to traditional data classification technology, making high efficiency and high accuracy the focus of data classification technology.

[0003] The difference in length and type of data makes the original data classification method inflexible when facing diversified data. Traditional classification methods are usually based on fixed data structures and assumptions, and are difficult to adapt to data of different types and lengths. For example, text data, image data, time series data, etc. have significantly different characteristics and structures. Traditional methods often need to design models and algorithms separately when processing these data, resulting in various classification methods being relatively independent and lacking a unified framework. This limitation not only increases the complexity of model design and maintenance, but also limits the generalization ability and adaptability of the model in practical applications.

[0004] Currently, manual classification technology and existing classification technology have many problems when processing more flexible data, including but not limited to low efficiency and low accuracy. Summary of the invention

[0005] The present invention provides an adaptive classification method and system for data streams. The present invention can segment data streams, reduce the size of data, improve computing efficiency and reduce resource usage, and use an algorithm to calculate the characteristics of segmented data for accurate classification, thereby improving the efficiency of data classification. The present invention can accurately classify data while improving data security.

[0006] In order to achieve the above objectives, the technical solution adopted by the present invention is: a data stream adaptive classification method, comprising:

[0007] S1. Control host: Send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key.

[0008] S2, adaptive encryption / decryption device side: when powered on, the key in its own storage medium is read as the key of the adaptive encryption / decryption device; when working normally, the new key received through the data link is decrypted to obtain the decrypted new key, and the original key is discarded, and the new key is used as the key of the adaptive encryption / decryption device, wherein, when the new key transmitted from the data link is received, the data is operated, and the data characteristics of the operation result are used as the characteristic value of the data segment, and the characteristic value is used as the basis to realize adaptive encryption of different data according to the different characteristics of different data check values; or

[0009] After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

[0010] The beneficial effects of the present invention are as follows: the present invention first segments the data, sums and modulos the first and second bits of the segmented data, and classifies the data according to different remainders to improve the efficiency of data classification and accurately classify the data; in a multi-encryption system, the present invention puts this technology into practical application, adopts different encryption methods according to data characteristics, and improves the security of data encryption.

[0011] Furthermore, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to an adaptive encryption / decryption device, which is specifically:

[0012] After power-on initialization, the address pointer of the key in the control host is set to a default value, wherein, through the key address, the control host can read the key written at the corresponding address in the storage medium in which the key group has been written, and the key in the storage medium only contains the symmetric key of the adaptive / decryption device after asymmetrical encryption;

[0013] A timing time for changing the key is set. When the timing time is met, the key address is changed and the key is read to obtain a new key, and the new key is sent to the adaptive encryption / decryption device to complete the key change.

[0014] The beneficial effects of the above further scheme are: asymmetric encryption algorithms have the characteristics of high security, and using asymmetric encryption algorithms to transmit symmetric keys can effectively prevent key leakage; at the same time, the time for setting key replacement can be determined by the system, which greatly reduces the risk of key leakage.

[0015] Furthermore, during normal operation, the new key received through the data link is decrypted to obtain the decrypted new key, which is specifically:

[0016] After power-on, use the data link to receive the new key;

[0017] Cache, group and decrypt the received key data in sequence;

[0018] Determine whether the decrypted data meets the basic characteristics of the required key. If so, the decrypted data is the required key. Otherwise, wait for the next key data.

[0019] The adaptive encryption / decryption device starts to work normally, encrypting / decrypting the new key received through the data link. At the same time, the adaptive encryption / decryption device caches and groups the received key, and performs asymmetric decryption when the fixed length is reached;

[0020] If the data decryption length reaches the key length requirement, a new key is obtained.

[0021] The beneficial effect of the above further solution is that verifying the new key can effectively detect errors in the transmission process.

[0022] Furthermore, after power-on, all communication ports are closed by default, and the data on the port is decrypted using only the private key of asymmetric encryption until the decrypted data of a certain port corresponds to the port number, and then the data sent by the port is adaptively encrypted, which is specifically:

[0023] After power-on, all communication ports are closed by default;

[0024] The encapsulated key is a data frame and sent to the adaptive encryption / decryption device through each communication interface;

[0025] After the data frame is retrieved, the data frame is asymmetrically decrypted;

[0026] After decryption, the data is retrieved from the pre-buried port list. If the port list contains a vector corresponding to the segment of data, the port is opened after confirming that the segment of data has corresponding properties to the physical port, and the data on the port is encrypted / decrypted accordingly; otherwise, the port will not perform the encryption / decryption function, and the above process will be repeated until the decrypted data of a certain port corresponds to the port number.

[0027] The beneficial effects of the above further solution are: random activation of communication ports greatly reduces the risks brought by network attacks; at the same time, enabling different communication ports according to different keys can also improve the security of the system.

[0028] Furthermore, before the adaptive encryption / decryption device is powered on, a public key of an asymmetric encryption algorithm and a port list are preset in its own storage medium.

[0029] The beneficial effect of the above further scheme is: according to the characteristics of the non-encryption algorithm, the leakage of the public key does not pose any threat to the asymmetric encryption algorithm. The preset port list and public key are stored in the storage medium of the adaptive encryption / decryption device to perform operations such as key replacement and selection of data transmission ports.

[0030] Furthermore, when a new key is received from the data link, the data is operated and the data characteristics of the operation result are used as the characteristic value of the data segment, which is specifically:

[0031] When receiving a new key from the data link, the key data is segmented;

[0032] The first and last digits of the key data of this segment are summed and remaindered, and the remainder value is used as the characteristic value of this segment of data.

[0033] The beneficial effects of the above further scheme are: using the first digit and the last digit to perform summation and modulus can effectively reduce the computing resources of the system; and classifying the data according to different characteristic values ​​so as to select different encryption algorithms.

[0034] The present invention provides an adaptive classification system for data streams, wherein the adaptive classification system is used to execute the adaptive classification method, and comprises:

[0035] The control host is used to send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key;

[0036] An adaptive encryption / decryption device is used to read a key in its own storage medium as a key of the adaptive encryption / decryption device when powered on; in normal operation, decrypt a new key received through a data link to obtain a decrypted new key, discard the original key, and use the new key as the key of the adaptive encryption / decryption device, wherein when receiving a new key from the data link, perform operations on the data, use the data characteristics of the operation result as the characteristic value of the data segment, and use the characteristic value as a basis to realize adaptive encryption of different data according to different characteristics of different data check values; or

[0037] After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

[0038] The beneficial effects of the present invention are as follows: the present invention first segments the data to reduce the length of the data and speed up the subsequent processing; the first and second bits of the segmented data are summed and remaindered, and classified according to different remainders, so as to facilitate the selection of a suitable encryption method for the data; the use of an asymmetric encryption algorithm to transmit a key can effectively improve the security of the key and reduce the risk of leakage; key verification can effectively prevent errors in the key transmission process; at the same time, for a system without a control host, different ports can be used to transmit data according to the port information implicit in the key to reduce network attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a flow chart of the method of the present invention.

[0040] Figure 2 It is a schematic flow chart of the normal operation of the control host part of the present invention.

[0041] FIG3( a ) is a schematic flow chart of the key management process of the present invention.

[0042] FIG3( b ) is a schematic flow chart of an alternative key management scheme of the present invention.

[0043] Figure 4 It is a schematic flow chart of the normal operation of the encryption / decryption device part of the present invention.

[0044] Figure 5 It is a system structure diagram of an embodiment of the present invention.

[0045] Figure 6 It is a schematic structural diagram of the system of the present invention. DETAILED DESCRIPTION

[0046] The specific implementation modes of the present invention are described below so that those skilled in the art can understand the present invention. However, it should be clear that the present invention is not limited to the scope of the specific implementation modes. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the attached claims, these changes are obvious, and all inventions and creations utilizing the concept of the present invention are protected.

[0047] Example 1

[0048] like Figure 1 As shown, the present invention provides an adaptive classification method for data streams, and its implementation method is as follows:

[0049] S1. Control host: Send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key.

[0050] S2, adaptive encryption / decryption device side: when powered on, the key in its own storage medium is read as the key of the adaptive encryption / decryption device; when working normally, the new key received through the data link is decrypted to obtain the decrypted new key, and the original key is discarded, and the new key is used as the key of the adaptive encryption / decryption device, wherein, when the new key transmitted from the data link is received, the data is operated, and the data characteristics of the operation result are used as the characteristic value of the data segment, and the characteristic value is used as the basis to realize adaptive encryption of different data according to the different characteristics of different data check values; or

[0051] After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

[0052] In this embodiment, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device, which is specifically:

[0053] After power-on initialization, the address pointer of the key in the control host is set to a default value, wherein, through the key address, the control host can read the key written at the corresponding address in the storage medium in which the key group has been written, and the key in the storage medium only contains the symmetric key of the adaptive / decryption device after asymmetrical encryption;

[0054] A timing time for changing the key is set. When the timing time is met, the key address is changed and the key is read to obtain a new key, and the new key is sent to the adaptive encryption / decryption device to complete the key change.

[0055] In this embodiment, during normal operation, the new key received through the data link is decrypted to obtain the decrypted new key, which is specifically:

[0056] After power-on, use the data link to receive the new key;

[0057] Cache, group and decrypt the received key data in sequence;

[0058] Determine whether the decrypted data meets the basic characteristics of the required key. If so, the decrypted data is the required key. Otherwise, wait for the next key data.

[0059] The adaptive encryption / decryption device starts to work normally, encrypting / decrypting the new key received through the data link. At the same time, the adaptive encryption / decryption device caches and groups the received key, and performs asymmetric decryption when the fixed length is reached;

[0060] If the data decryption length reaches the key length requirement, a new key is obtained.

[0061] In this embodiment, after power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a certain port corresponds to the port number, then the data sent by the port is adaptively encrypted, which is specifically:

[0062] After power-on, all communication ports are closed by default;

[0063] The encapsulated key is a data frame and sent to the adaptive encryption / decryption device through each communication interface;

[0064] After the data frame is retrieved, the data frame is asymmetrically decrypted;

[0065] After decryption, the data is retrieved from the pre-buried port list. If the port list contains a vector corresponding to the segment of data, the port is opened after confirming that the segment of data has corresponding properties to the physical port, and the data on the port is encrypted / decrypted accordingly; otherwise, the port will not perform the encryption / decryption function, and the above process will be repeated until the decrypted data of a certain port corresponds to the port number.

[0066] In this embodiment, the adaptive encryption / decryption device presets a public key of an asymmetric encryption algorithm and a port list in its own storage medium before being powered on.

[0067] In this embodiment, when a new key is received from the data link, the data is operated, and the data feature of the operation result is used as the feature value of the data segment, which is specifically:

[0068] When receiving a new key from the data link, the key data is segmented;

[0069] The first and last digits of the key data of this segment are summed and remaindered, and the remainder value is used as the characteristic value of this segment of data.

[0070] In this embodiment, the proposed adaptive classification technology is actually applied in a multi-encryption system to produce an adaptive encryption system, which mainly includes: a control host, an adaptive encryption device and an adaptive decryption device.

[0071] The control host part includes: a key management module, which is used to manage the switching and replacement of various keys. If the key needs to be replaced, the control host will read the new key from the previously written key, and use the asymmetric encryption algorithm to encrypt the key to be replaced, and then send it to the encryption / decryption device through the data link to complete the key replacement; the interface part is used to access the data link to remotely manage the keys of the encryption device and decryption device.

[0072] The encryption device and decryption device include: various interfaces for information exchange with the data link, mainly full-duplex interfaces such as RS422 and Ethernet; a key management module for securely storing or updating keys, the main functions of which are as follows: when powered on, the key in its own storage medium is read as the key of the adaptive encryption / decryption algorithm module. During normal operation, if a new key is received through the data link, the key management module will first decrypt the encrypted key, and after obtaining the decrypted new key, the original key will be discarded and the new key will be used as the key of the adaptive encryption / decryption algorithm; the adaptive encryption / decryption module for the encryption / decryption algorithm, after receiving the data from the data link, this adaptive encryption / decryption module will first perform a specific operation on the data, and some digital features of the operation result will be used as the feature value of the data segment, and the detailed process of the subsequent adaptive encryption / decryption will be based on the feature value of the data segment.

[0073] In the key management method according to the present invention, the control host stores the symmetric key of the encryption device in the entire system and the asymmetric key used to encrypt the symmetric key. Due to the particularity of the military encryption system, the key can be stored in a storage medium or directly input into the internal storage module of the control host.

[0074] In the key management method according to the present invention, the encryption / decryption device does not need to hold the key of the adaptive encryption / decryption algorithm. It only needs to hold the asymmetric key used by the control host to encrypt the adaptive encryption / decryption algorithm. The disclosure of this key will not affect the security of the encryption system.

[0075] According to the key management mode of the present invention, one encryption / decryption device can integrate all data links on a combat weapon; one control host can manage the keys of encryption / decryption devices on multiple combat weapons through the existing data link as a medium.

[0076] The communication interface part of the present invention mainly adopts a full-duplex communication interface.

[0077] The adaptive encryption algorithm of the present invention mainly includes: information verification algorithms and multiple symmetric encryption / decryption algorithms. In the information verification algorithm, after the data to be encrypted / decrypted is input into the algorithm, the data is first segmented, and the remainder is summed according to the first and last bits of the segment, and the remainder value is used as the characteristic value of the segment data. Using this feature as the basis of the adaptive encryption algorithm, adaptive encryption of different data can be achieved according to the different characteristics of different data verification values. The encryption / decryption algorithm mainly selects a symmetric encryption algorithm suitable for high-speed hardware. When there are two or more symmetric encryption / decryption algorithms in the system, one of the existing encryption / decryption algorithms can be selected according to the different results of the information verification algorithm to encrypt / decrypt the information.

[0078] As an alternative, the present invention may not use the control host to distribute keys according to the situation, and directly load the private keys of the symmetric encryption / decryption algorithm and the asymmetric encryption algorithm into the encryption / decryption device, and then number the communication ports of the access device in sequence. Take the encryption device as an example: after power-on, all communication ports are closed by default, and the data on the port is only decrypted using the asymmetric encryption private key. Only when the decrypted data of a certain port corresponds to the port number of the port, the port is considered to be open, and the data sent from the port is adaptively encrypted. Except that the adaptive decryption operation is performed after the port is opened, the rest of the process of the decryption device is the same as that of the encryption device.

[0079] The encryption machine is a secure encryption device, which usually includes an encryption module for implementing encryption algorithms and safely storing keys. Since it works as a separate computer (for example, as a server) to communicate with the client, its hardware structure includes components such as a CPU, a motherboard or a hard disk that constitute a computer. In addition, according to an embodiment of the present invention, the control host part may also include a storage medium in which various keys are pre-written for easy replacement by humans.

[0080] For example, the control host reserves pluggable storage media interfaces such as USB and SDIO, which are regularly replaced by a dedicated person who keeps the keys.

[0081] According to an alternative to the invention, the storage medium may be present in the encryption / decryption device.

[0082] For example, a simple serial interface is reserved on the encryption / decryption device, and a data frame in a specific format is input through the serial interface to replace the key.

[0083] The above description of key storage / management of encryption / decryption devices is merely illustrative and not restrictive.

[0084] Figure 6 It is a schematic structural diagram of an example system of the present invention. Figure 6 The arrow in the middle points to the direction of data flow. Figure 6 , the system level of the present invention is mainly composed of the following parts:

[0085] In this schematic structure diagram, there is a control host and four encryption / decryption devices that communicate by accessing the data link. The control host sends the system key to each encryption / decryption device through the data link, and theoretically only needs a simplex communication interface; the encryption / decryption device obtains the key sent by the control host and the data to be encrypted in the data link from the data link, using a full-duplex communication interface. In this schematic structure diagram, the number of encryption / decryption devices is not limited to four, and can be changed according to actual conditions such as data link capacity and bandwidth.

[0086] Figure 2 This is a schematic flow chart of the normal operation of the control host part of a certain example of the present invention. After power-on initialization, the address pointer of the key inside the control host should be a default value. Through this address, the control host can read the key written at the corresponding address in the storage medium where the key group has been written.

[0087] In this example, the key in the storage medium should only contain the symmetric key of the encryption / decryption device after asymmetric encryption. In another example, the storage medium should also contain the private key of the asymmetric encryption and the asymmetric encryption module for encrypting the key of the symmetric encryption.

[0088] In this example, a key replacement timing module is provided. For example, for security reasons, the encryption system needs to replace the key every hour. In this example, the key replacement timing module will set the timing time to one hour. Every time the count reaches one hour, the key timing module will control the behavior of replacing the key address and reading the key. After obtaining the new key, the control host will publish the key to the data link again in the same way as when it is powered on and initialized.

[0089] In this example, the release of the key can be conditionally triggered: when the key address or key replacement timing module is full, the process of reading the key and releasing the key to the data chain is executed once; it can also be cyclical, that is, the key is read once according to the current address at a certain interval and released to the data chain.

[0090] Fig. 3(a) is a schematic flow chart of a key management process of the present invention. This example mainly describes the key management mechanism of the encryption / decryption device.

[0091] In this example, the encryption / decryption device does not need to hold the symmetric encryption key when it is just powered on, but only needs to hold the asymmetric encryption public key used by the system. By continuously receiving data uploaded from the data link, caching, grouping, and decrypting it, it determines whether it may be the key based on the basic characteristics of the key.

[0092] For example, the length of data encrypted by RSA is 2048 bits, while the length of many symmetric encryption keys does not reach this length. After decrypting a piece of data, if the length does not match the length of the symmetric encryption key used by the system, it is considered that the data is not the encrypted key; otherwise, it is considered that the decrypted data is the required key.

[0093] After decrypting the key, the encryption / decryption device starts to work normally and encrypts / decrypts the data in the data chain. At the same time, in order to receive the new key immediately, the encryption / decryption device will also cache and group the received data, and perform corresponding asymmetric decryption after reaching a certain length. Similarly, in this example, after decrypting a piece of data, if the data length meets the key length, it will be considered a new key.

[0094] In this example, after obtaining the first key, the encryption / decryption device starts to encrypt / decrypt all data transmitted on the data link, even if it is possible that the key of the data segment needs to be replaced.

[0095] For this example, the present invention also provides another solution.

[0096] The control host encapsulates the key to be replaced in a data frame of a specific format and then sends it to the data link. The encryption / decryption device only needs to detect in real time whether the data contains this specific frame. If yes, the data of this segment of encapsulation is asymmetrically decrypted. If no, no processing is performed. The present invention can also ensure that the encryption / decryption device can correctly receive the key required for normal operation after power-on.

[0097] FIG3( b ) is a schematic flow chart of an example of the key management alternative of the present invention. In this example, before the encryption / decryption device is powered on, the public key of the asymmetric encryption algorithm should be pre-embedded in the storage medium. In addition, a port list should also be pre-embedded therein to control the opening and closing of each port.

[0098] In this example, the control host in the previous example is no longer necessary; the key or key data frame sent by the control host will be sent by each port. The function of the control host is replaced by the authentication between the data source and the encryption / decryption device.

[0099] In this example, the key is encapsulated as a data frame and sent to the encryption / decryption device through various communication interfaces. After retrieving the data frame, in this example, the data frame is asymmetrically decrypted; after the decryption is completed, the data is retrieved from the pre-buried port list. If there is a vector corresponding to the data segment in the port list, the port is opened after confirming that the data segment has corresponding properties with the physical port, that is, the data of the port is encrypted / decrypted accordingly; otherwise, the port will not perform any encryption / decryption function, and the above process will be repeated until the conditions for opening the port are met.

[0100] Figure 4 This is a schematic flow chart of the normal operation of a certain example of the encryption / decryption device part of the present invention. This example adopts the control host solution. Figure 4 It can be seen that this example mainly consists of three parts: control host, data link, encryption / decryption device. The data link part is not involved in this invention, and the existing data link structure is adopted.

[0101] Control the host part, according to Figure 2 The process described above sends the key to the data chain. This diagram mainly describes the encryption / decryption device process.

[0102] In this example, after the encryption / decryption device is powered on, the key is obtained according to the process shown in Figure 3(a). In this example, the encryption / decryption device is connected to the data link through a full-duplex communication interface, and the received or sent data passes through a buffer to match the communication rate between the encryption / decryption and the data link. After entering the normal working state, the encryption / decryption device will first send the data to be encrypted into the verification algorithm to obtain the correctness of the characteristic value and the verification data; in this example, two encryption algorithms are used to implement adaptive encryption, and correspondingly, the characteristic value needs to have two different situations. Here, 1 and 0 are used as examples: if the characteristic value of a piece of data with a length of n is 1 after the verification algorithm, the piece of data is sent to encryption / decryption algorithm 1 for encryption / decryption; if it is 0, it is sent to encryption / decryption algorithm 2.

[0103] According to the distinctiveness and uniqueness of the characteristic value of each segment of data, the received data will be randomly and discretely sent to encryption / decryption algorithm 1 and encryption / decryption algorithm 2 respectively; and because the data is input into the verification algorithm sequentially, the encrypted / decrypted data is sent to the buffer in sequence, which is the encryption / decryption result of the data segment.

[0104] In this example, the directions indicated by the arrows represent the possible flows of data. Figure 5 It is a system structure diagram of an embodiment of the present invention.

[0105] This embodiment is an encryption device embodiment.

[0106] This embodiment uses Xilinx's ZYNQ series chips as the system core. In this embodiment, the encryption device is mainly composed of three parts according to the function: interface part: using RS422, Ethernet interface to access the data link to realize the basic data exchange function; storage part: using DDR3 and ZYNQ built-in RAM unit. Among them, DDR3 is used as a buffer between the ZYNQ interface and the data link, and the main goal is high-speed, large amounts of real-time data. RAM is mainly used as the internal calculation cache area of ​​ZYNQ and the rate matching between various modules; calculation module: mainly includes CRC32 cyclic redundancy check algorithm, RSA decryption algorithm, AES encryption algorithm and 3DES encryption algorithm.

[0107] In the operation module of this embodiment, CRC32 is used to check the integrity and correctness of the received data. At the same time, according to the check value obtained by CRC32, according to its parity, the characteristic values ​​1 and 0 can be obtained respectively; the RSA decryption algorithm is used to asymmetrically decrypt the detected key frame. This algorithm belongs to the public key system, and the required key does not need to be kept confidential. It can be made public in the data link or can be pre-embedded in the encryption / decryption device. This embodiment uses the pre-embedded solution.

[0108] The adaptive encryption core part of this embodiment is based on AES and 3DES encryption algorithms.

[0109] In this embodiment, the parity of the check value obtained by CRC32 is used to select the data segment to be encrypted using AES or 3DES. The two algorithms have similar encryption efficiency and key length. In this embodiment, the two algorithms share a key.

[0110] According to the characteristics of probability distribution of parity probability of check value, in this embodiment, according to Figure 5 The structural block diagram of Figure 3(a) and Figure 4 The flowchart shown can well implement irregular ASE and 3DES cross-encryption of data in the data link; in the decryption device, according to the same process and the characteristics, adaptive decryption with low bit error rate can be implemented.

[0111] Example 2

[0112] like Figure 6 As shown, the present invention is an adaptive classification system for data streams, and the adaptive classification system is used to execute the adaptive classification method described in Example 1, including:

[0113] The control host is used to send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key;

[0114] An adaptive encryption / decryption device is used to read a key in its own storage medium as a key of the adaptive encryption / decryption device when powered on; in normal operation, decrypt a new key received through a data link to obtain a decrypted new key, discard the original key, and use the new key as the key of the adaptive encryption / decryption device, wherein when receiving a new key from the data link, perform operations on the data, use the data characteristics of the operation result as the characteristic value of the data segment, and use the characteristic value as a basis to realize adaptive encryption of different data according to different characteristics of different data check values; or

[0115] After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

[0116] like Figure 6 The adaptive classification system provided by the illustrated embodiment can execute the technical solution shown in the adaptive classification method of the above method embodiment, and its implementation principle and beneficial effects are similar and will not be repeated here.

[0117] In this example, the present application can divide the functional units according to the adaptive classification method. For example, each function can be divided into each functional unit, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the present invention is schematic and is only a logical division. There may be other division methods in actual implementation.

[0118] In this example, in order to realize the principles and beneficial effects of the adaptive classification method, the adaptive classification system includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the schematic units and algorithm steps described in the embodiments disclosed in the present invention, the present invention can be implemented in the form of hardware and / or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven manner depends on the specific application and design constraints of the technical solution. Different methods can be used for each specific application to implement the described function, but such implementation should not be considered to exceed the scope of this application.

[0119] The beneficial effects of the present invention are at least that: segmenting data reduces the resources required by the system and reduces the computational complexity; at the same time, the segmented data is classified according to the different characteristic values ​​of each segment, thereby improving the system's efficiency in using data.

Claims

1. A method for adaptive classification of data streams, characterized in that: include: S1. Control host: Send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key. S2, adaptive encryption / decryption device side: when powered on, the key in its own storage medium is read as the key of the adaptive encryption / decryption device; when working normally, the new key received through the data link is decrypted to obtain the decrypted new key, and the original key is discarded, and the new key is used as the key of the adaptive encryption / decryption device, wherein, when the new key transmitted from the data link is received, the data is operated, and the data characteristics of the operation result are used as the characteristic value of the data segment, and the characteristic value is used as the basis to realize adaptive encryption of different data according to the different characteristics of different data check values; or After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

2. The method for adaptive classification of data streams according to claim 1, characterized in that: The key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device, which is specifically: After power-on initialization, the address pointer of the key in the control host is set to a default value, wherein, through the key address, the control host can read the key written at the corresponding address in the storage medium in which the key group has been written, and the key in the storage medium only contains the symmetric key of the adaptive / decryption device after asymmetrical encryption; A timing time for changing the key is set. When the timing time is met, the key address is changed and the key is read to obtain a new key, and the new key is sent to the adaptive encryption / decryption device to complete the key change.

3. The method for adaptive classification of data streams according to claim 1, characterized in that: During normal operation, the new key received through the data link is decrypted to obtain the decrypted new key, which is specifically: After power-on, use the data link to receive the new key; Cache, group and decrypt the received key data in sequence; Determine whether the decrypted data meets the basic characteristics of the required key. If so, the decrypted data is the required key. Otherwise, wait for the next key data. The adaptive encryption / decryption device starts to work normally, encrypting / decrypting the new key received through the data link. At the same time, the adaptive encryption / decryption device caches and groups the received key, and performs asymmetric decryption when the fixed length is reached; If the data decryption length reaches the key length requirement, a new key is obtained.

4. The method for adaptive classification of data streams according to claim 1, characterized in that: After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted, which is specifically: After power-on, all communication ports are closed by default; The encapsulated key is a data frame and sent to the adaptive encryption / decryption device through each communication interface; After the data frame is retrieved, the data frame is asymmetrically decrypted; After decryption, the data is retrieved from the pre-buried port list. If the port list contains a vector corresponding to the segment of data, the port is opened after confirming that the segment of data has corresponding properties to the physical port, and the data on the port is encrypted / decrypted accordingly; otherwise, the port will not perform the encryption / decryption function, and the above process will be repeated until the decrypted data of a certain port corresponds to the port number.

5. The method for adaptive classification of data streams according to claim 1, characterized in that: Before the adaptive encryption / decryption device is powered on, a public key of an asymmetric encryption algorithm and a port list are preset in its own storage medium.

6. The method for adaptive classification of data streams according to claim 1, characterized in that: When receiving the new key from the data link, the data is operated and the data characteristics of the operation result are used as the characteristic value of the data segment, which is specifically: When receiving a new key from the data link, the key data is segmented; The first and last digits of the key data of this segment are summed and remaindered, and the remainder value is used as the characteristic value of this segment of data.

7. An adaptive classification system for data streams, characterized in that: The adaptive classification system is used to execute the adaptive classification method according to any one of claims 1 to 6, comprising: The control host is used to send the key to each adaptive encryption / decryption device through the data link, and manage the switching and replacement of various keys. If the key needs to be replaced, the key to be replaced is encrypted using an asymmetric encryption algorithm and sent to the adaptive encryption / decryption device to complete the key replacement. The control host stores the symmetric key of the adaptive encryption device and the asymmetric key used to encrypt the symmetric key; An adaptive encryption / decryption device is used to read a key in its own storage medium as a key of the adaptive encryption / decryption device when powered on; in normal operation, decrypt a new key received through a data link to obtain a decrypted new key, discard the original key, and use the new key as the key of the adaptive encryption / decryption device, wherein when receiving a new key from the data link, perform operations on the data, use the data characteristics of the operation result as the characteristic value of the data segment, and use the characteristic value as a basis to realize adaptive encryption of different data according to different characteristics of different data check values; or After power-on, all communication ports are closed by default, and the data on the port is decrypted only using the asymmetric encryption private key until the decrypted data of a port corresponds to the port number, then the data sent by the port is adaptively encrypted.

Citation Information

Patent Citations

  • Method and device for adaptively switching key

    CN106357388A

  • Internet-of-Things big data security transmission and storage method and system

    CN107612898A

  • Dynamic key encryption method and dynamic distributed encryption system for network transmission data

    CN113660081A

  • Method, computing device and computer-readable medium for classification of encrypted data using neural network

    US20220405474A1