A method and system for dynamic switching of secure encryption algorithms
By dynamically switching encryption algorithms and adjusting the strength and type of encryption algorithms in real time according to the server's operating parameters and threat level, the problems of high CPU resource usage and slow response speed caused by fixed encryption algorithms are solved, and stable operation and efficient performance of the server during attacks are achieved.
Patent Information
- Application Number
- CN202510177703.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-02-18
AI Technical Summary
When the existing fixed encryption algorithm is executed on the server, it causes high CPU resource usage, affecting response speed and data transmission delay, which is particularly evident when under attack, affecting user experience and system efficiency.
By dynamically switching encryption algorithms, the strength and type of encryption algorithms are adjusted in real time according to the server's operating parameters and threat level to balance the security and performance of the server.
It achieves rapid response and stable operation when the server is attacked, and reduces the impact on performance by dynamically adjusting encryption strategies, thereby improving user experience and system efficiency.
Smart Images

Figure CN120017381B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer encryption, and in particular to a method and system for dynamically switching a security encryption algorithm. Background Art
[0002] With the rapid development of information technology, particularly its widespread application in cutting-edge fields such as cloud computing, big data, and the Internet of Things (IoT), data security and privacy protection have become increasingly prominent, becoming a focus of concern for both the technology community and society at large. These fields process massive amounts of data daily, which contains a wealth of user privacy, business secrets, and even national security information. Therefore, it is crucial to implement strong encryption measures to protect this information from unauthorized access or leakage.
[0003] Existing servers generally use pre-configured fixed encryption algorithms (such as AES and RSA) to ensure data security. These algorithms are widely used in the industry due to their high security and maturity. However, while fixed encryption algorithms ensure data security, they also bring significant performance challenges:
[0004] High-intensity encryption algorithms consume significant CPU resources when performing encryption and decryption operations. This resource consumption is significantly exacerbated when servers process large datasets, slowing server response times and even impacting overall system performance. Especially when a system is under attack, CPU utilization rises dramatically, and the encryption and decryption processes further slow server response times. Furthermore, the processing of encrypted data takes time, which is particularly noticeable over network transmission. The packaging, transmission, and decryption of encrypted data at the receiving end all increase overall data transmission latency. For applications requiring real-time interaction or low-latency responses, this delay directly impacts user experience and system efficiency.
[0005] To address the above issues, it is necessary to design a dynamic switching method for secure encryption algorithms. When the server is attacked, the encryption method can be switched to achieve a balance between server security and server response speed, thereby improving the user experience. Summary of the Invention
[0006] In response to the problems existing in the prior art, the present invention provides a dynamic switching method for a security encryption algorithm, which dynamically cuts the encryption method according to the attack nodes and operating parameters of the server to achieve a balance between server security and server response speed.
[0007] The present invention is achieved through the following technical solutions:
[0008] In a first aspect, the present application provides a method for dynamically switching a security encryption algorithm, comprising:
[0009] When the server is attacked by hackers at various operation stages, obtain the operating parameters of the server in its current state;
[0010] Obtaining safe operation parameters of the server in each operation stage, and determining abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state;
[0011] Analyze the abnormal parameters to determine the threat level of the server and the response level of the server, assign security weights to the abnormal parameters according to the threat level, assign response weights to the abnormal parameters according to the response level, and calculate the comprehensive weights of the abnormal parameters based on the security weights and the response weights; fuse the comprehensive weights of all abnormal parameters to obtain a comprehensive indicator of the current server status, and switch the server's security encryption algorithm according to the comprehensive indicator.
[0012] Preferably, the various operation stages of the server include a server startup stage, an application loading stage, and a system authority attack stage.
[0013] Preferably, the operating parameters during the boot phase include CPU occupancy, CPU occupancy rate, memory occupancy rate, memory occupancy rate, network traffic usage rate, and server response rate;
[0014] The operating parameters of the application loading phase include application response speed, CPU occupancy, memory occupancy and network traffic usage;
[0015] The operating parameters during the stage when system permissions are attacked include memory usage and hard disk usage.
[0016] Preferably, determining abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state includes:
[0017] Determine the baseline of each parameter based on the safe operation parameters, compare the parameters in the current state with the corresponding baseline, and determine the abnormal parameters.
[0018] Preferably, the method for determining the baseline of the parameter is as follows:
[0019] Calculate the average value of each parameter in the historical time series and use the average value as the baseline.
[0020] Preferably, analyzing the abnormal parameters to determine the threat level of the server and the response level of the server includes:
[0021] Determine the type of attack the server is subjected to based on the abnormal parameters, determine the threat level of the server based on the attack type, determine the response rate of the server based on the abnormal parameters, and determine the response level of the server based on the response rate.
[0022] Preferably, the switching of the server's security encryption algorithm according to the comprehensive indicators includes: in the server's stuck stage, when the CPU occupancy rate, network traffic usage rate and occupancy rate increase, the server adopts a reversible encryption algorithm or an irreversible encryption algorithm;
[0023] During the server application loading phase, CPU usage, network traffic usage, and memory usage increase, and the server uses a symmetric irreversible encryption algorithm.
[0024] When the system permissions of the service are attacked, an asymmetric irreversible encryption algorithm is used to protect the server based on the increase in memory usage and hard disk usage.
[0025] In a second aspect, the present application provides a dynamic switching system for a security encryption algorithm, including:
[0026] The first acquisition module is used to obtain the operating parameters of the server in its current state when the server is attacked by hackers at various operating stages;
[0027] A second acquisition module is used to obtain safe operation parameters of the server in each operation stage, and determine abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state;
[0028] The analysis and switching module is used to analyze abnormal parameters to determine the threat level of the server and the response level of the server, assign security weights to the abnormal parameters according to the threat level, assign response weights to the abnormal parameters according to the response level, and calculate the comprehensive weights of the abnormal parameters based on the security weights and the response weights; the comprehensive weights of all abnormal parameters are integrated to obtain a comprehensive indicator of the current server status, and the server's security encryption algorithm is switched according to the comprehensive indicator.
[0029] In a third aspect, the present application provides an electronic device, comprising:
[0030] Memory for storing computer programs;
[0031] A processor is used to implement the steps of the dynamic switching method of the security encryption algorithm when executing the computer program.
[0032] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the dynamic switching method of the security encryption algorithm are implemented.
[0033] Compared with the prior art, the present invention has the following beneficial technical effects:
[0034] This application provides a dynamic switching system for secure encryption algorithms. This method can acquire server operating parameters in real time at different stages and compare them with parameters in a secure operating state, thereby quickly identifying abnormal parameters. This real-time and dynamic nature enables the server to respond immediately to hacker attacks, effectively addressing potential security threats. By analyzing abnormal parameters, the method automatically determines the server's threat level and response level, and adjusts the strength and type of encryption algorithm accordingly. This intelligent and automated process reduces the need for manual intervention, improving system efficiency and accuracy. The method not only considers the threat posed by abnormal parameters to server security, but also their impact on server performance. By assigning security and response weights to abnormal parameters and calculating a combined weight, it can more comprehensively assess the server's overall security status, enabling more appropriate encryption strategy selection. The method can adopt different encryption algorithms for different server operating stages and attack types. For example, different encryption strategies can be adopted during the boot phase and application loading phase to balance security and performance; when system permissions are attacked, a stronger encryption algorithm can be used to protect the server. This targeted and flexible approach improves the effectiveness and adaptability of encryption strategies. This method dynamically adjusts the strength and type of encryption algorithms to ensure server security while minimizing the impact on server performance. This helps improve the user experience and ensures that the server remains stable even under attack. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 This is a flow chart of the dynamic switching method of the security encryption algorithm of the present invention. DETAILED DESCRIPTION
[0036] The present invention will be further described in detail below with reference to the accompanying drawings, which are intended to explain rather than limit the present invention.
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0038] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0039] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0040] In the description of the embodiments of the present application, it should be noted that if the terms "upper", "lower", "horizontal", "inner", etc. appear, the orientation or position relationship indicated is based on the orientation or position relationship shown in the accompanying drawings, or the orientation or position relationship in which the product of the invention is usually placed when in use. This is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation. Therefore, it should not be understood as a limitation on the present application. In addition, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.
[0041] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly tilted. For example, "horizontal" only means that its direction is more horizontal than "vertical", and does not mean that the structure must be completely horizontal, but can be slightly tilted.
[0042] In the description of the embodiments of this application, it should also be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to internal connections between two components. Those skilled in the art can understand the specific meanings of the above terms in this application based on specific circumstances.
[0043] See Figure 1 , a method for dynamically switching a security encryption algorithm, comprising the following steps:
[0044] Step 1: When the server is attacked by hackers in various operating states, the operating parameters of the server in the current state are obtained.
[0045] The server's running status indicates that the server is running in different stages, including the server's startup stage, the server's application loading stage, and the server's running stage.
[0046] 1. The server is attacked by hackers during the startup phase. The operating parameters include the central processing unit (CPU) occupancy rate, CPU occupancy rate, memory occupancy rate, memory occupancy rate, network traffic usage rate and server response rate. The operating parameters are analyzed and the security encryption algorithm is switched based on the characteristics of the server's startup state to improve the server's response rate.
[0047] 2. The server is attacked by hackers during the application loading phase, and the operating parameters of the server in the current state are obtained, including application response speed, CPU usage, CPU usage rate, memory usage, memory usage rate and network traffic usage.
[0048] 3. If the server is attacked by hackers during operation, the main manifestation is that the system permissions are attacked. The operating parameters include memory usage and hard disk usage.
[0049] Step 2: Obtain the safe operation parameters of each operation stage of the server in a safe operation state, compare the safe operation parameters of each stage with the current operation parameters, and obtain the abnormal parameters of each stage of the service.
[0050] Determine the baseline for each parameter based on safe operating parameters. The baseline can be the parameter mean, median, or expected value. Calculate the mean of each parameter in the historical time series and use the mean as the baseline. Compare the current parameter to the corresponding baseline to identify abnormal parameters.
[0051] Step 3: Analyze the abnormal parameters, assign weights to the abnormal parameters according to the analysis results, fuse the weights of the abnormal parameters, and switch the encryption method of the server according to the fused weights.
[0052] Analyze abnormal parameters to determine the threat level of the server and the response level of the server.
[0053] For example, a sharp increase in CPU usage may indicate malware, while a surge in network traffic could indicate a DDoS attack. Based on the characteristics of the abnormal parameters and historical experience, determine the threat level to system security. Analyze how the abnormal parameters affect server performance. High memory usage may cause slow application response and affect user experience; an increase in CPU usage may directly affect server processing capacity and response rate.
[0054] According to the analysis results of abnormal parameters, safety weight and response weight are assigned to them, and then the comprehensive weight of each abnormal parameter is determined.
[0055] Each abnormal parameter is assigned a weight based on its security threat level. Parameters with greater threats receive higher weights. In addition to security threats, the impact of abnormal parameters on server performance is also considered and weighted accordingly. Parameters with greater performance impact should also receive higher weights. Taking both the security threat weight and the performance impact weight into account, a comprehensive weight for each abnormal parameter is calculated. This can be achieved through weighted summation, weighted average, or other appropriate mathematical methods.
[0056] The combined weights of all abnormal parameters are combined to create a comprehensive indicator reflecting the current server status. This indicator comprehensively considers the impact of security and performance. Based on this combined weight, an appropriate encryption strength is selected. If the comprehensive indicator indicates that the server faces a serious security threat, a stronger encryption algorithm is selected to improve security. If performance is the primary consideration, a lower-strength algorithm may be selected to improve response speed while ensuring basic security.
[0057] The type of attack suffered by the server is determined according to the abnormal parameters, and the threat level of the server is determined according to the attack type; the response rate of the server is determined according to the abnormal parameters, and the response level of the server is determined according to the response rate.
[0058] During the server freezing phase, CPU usage, network traffic usage, and occupancy rates rise rapidly, so a reversible encryption algorithm or an irreversible encryption algorithm is used.
[0059] During the server application loading phase, the CPU usage, network traffic usage, and memory usage increase, and the current encryption algorithm is switched to a symmetric irreversible encryption algorithm.
[0060] When the system permissions of the service are attacked, the current encryption algorithm is switched according to the memory usage and hard disk usage, and an asymmetric irreversible encryption algorithm is used to protect the server.
[0061] The advantages of the dynamic switching method of the security encryption algorithm are mainly reflected in the following aspects:
[0062] Real-time responsiveness and adaptability: By capturing server operating parameters in real time at different stages and comparing them against a baseline of secure operation, this method can quickly identify abnormal parameters and respond promptly to hacker attacks. This real-time nature ensures that servers can quickly adjust encryption strategies in the face of security threats, enhancing security protection.
[0063] Flexibility and efficiency: According to the analysis results of abnormal parameters, this method can dynamically adjust the strength and type of encryption algorithm. This flexibility not only helps to maintain good performance while ensuring server security, but also makes the best choice of encryption strategy according to different threat types and severity. At the same time, by assigning weights to abnormal parameters and fusion, the overall security state of the server can be more accurately evaluated, and the decision efficiency can be improved.
[0064] Performance and security balance: In the process of switching encryption algorithms, this method fully considers the balance between server performance and security. By comprehensively analyzing the influence of abnormal parameters on server performance and the severity of security threats, it can select an encryption strategy that meets security requirements without seriously affecting server performance. This balance helps to improve user experience and ensure that the server can maintain stable operation state when attacked.
[0065] Prevention and response ability: By setting the security running parameters and baseline of each running stage in advance, this method has a certain prevention ability. When the server running parameters deviate from the baseline, it can give an early warning and take appropriate encryption measures to effectively prevent potential security threats. At the same time, when attacked, it can quickly switch to higher level encryption algorithm to enhance the response ability of the server.
[0066] Extensibility and maintainability: The framework design of this method has strong extensibility and maintainability. With the change of server running environment and the emergence of new security threats, the acquisition method of running parameters, the setting method of baseline and the switching logic of encryption algorithm can be easily adjusted and optimized. This flexibility helps to maintain the long-term effectiveness and security of the system.
[0067] Based on the above-mentioned dynamic switching method of security encryption algorithm, the present application also proposes a dynamic switching system of security encryption algorithm, comprising:
[0068] The first acquisition module is used to acquire the running parameters of the server under the current state when the server is attacked by hackers in each running stage;
[0069] The second acquisition module is used to acquire the security running parameters of the server in each running state in the security running stage, compare the security running parameters of each stage with the current running parameters, and acquire the abnormal parameters of each stage of the service;
[0070] The analysis switching module is configured to analyze the abnormal parameters to determine a threat level of the server and a response level of the server, assign a security weight and a response weight to each abnormal parameter according to the threat level and the response level, determine a comprehensive weight of each abnormal parameter, fuse the comprehensive weights of all the abnormal parameters to obtain a comprehensive index of the current server state, and switch the security encryption algorithm of the server according to the comprehensive index.
[0071] It should be noted that, in several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the above-described apparatus embodiments are merely illustrative, and the division of modules can be different, for example, the division of modules can be combined or integrated into another apparatus, or some features can be ignored or not executed. The modules illustrated as separate components can be or can not be physically separate, and the components illustrated as modules can be one physical unit or multiple physical units, i.e., can be located in one place or distributed to multiple different places. Some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments.
[0072] In addition, each module in the various embodiments of the present application can be integrated in one processing unit, or each module can be physically present separately, or two or more modules can be integrated in one unit. The above-mentioned integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0073] The electronic device provided in the embodiments of the present application includes a memory and a processor, the memory stores a computer program, and the processor implements the steps of the dynamic switching method of the security encryption algorithm described in any of the above embodiments when executing the computer program.
[0074] The electronic device provided in another embodiment of the present application can further include: an input port connected to the processor, configured to transmit the multi-modal data collected by an external collection device to the processor; a display unit connected to the processor, configured to display the processing result of the processor to the outside world; and a communication module connected to the processor, configured to realize the communication between the electronic device and the outside world. The display unit can be a display panel, a laser scanning display, etc. The communication mode adopted by the communication module includes but is not limited to mobile high-definition link technology (HML), universal serial bus (USB), high-definition multimedia interface (HDMI), wireless connection (including wireless fidelity technology (WiFi), Bluetooth communication technology, low-power Bluetooth communication technology, and IEEE 802.11s-based communication technology).
[0075] The embodiment of the present application provides a computer readable storage medium, the computer readable storage medium stores a computer program, and the computer program is executed by a processor to realize the steps of the dynamic switching method of the secure encryption algorithm described in any one of the above embodiments.
[0076] The computer readable storage medium involved in the present application includes random access memory (RAM), memory, read only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the technical field.
[0077] The related parts of the power load prediction system, the electronic device and the computer readable storage medium provided by the embodiment of the present application are described in detail in the corresponding part of the power load prediction method provided by the embodiment of the present application, and will not be described here. In addition, the part of the above technical solution provided by the embodiment of the present application which is consistent with the implementation principle of the corresponding technical solution in the prior art is not described in detail, so as not to be too redundant.
[0078] The above content only illustrates the technical idea of the present application, and cannot limit the protection scope of the present application. Any modification made according to the technical idea of the present application on the basis of the technical solution falls within the protection scope of the claims of the present application.
Claims
1. A method for dynamically switching a security encryption algorithm, characterized in that: include: When the server is attacked by hackers at various operation stages, obtain the operating parameters of the server in its current state; Obtaining safe operation parameters of the server in each operation stage, and determining abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state; Determine the type of attack the server is experiencing based on the abnormal parameters, determine the threat level of the server based on the attack type, determine the response rate of the server based on the abnormal parameters, and determine the response level of the server based on the response rate; assigning a security weight to the abnormal parameter according to the threat level, assigning a response weight to the abnormal parameter according to the response level, and calculating a comprehensive weight of the abnormal parameter based on the security weight and the response weight; The comprehensive weights of all abnormal parameters are integrated to obtain a comprehensive indicator of the current server status, and the server's security encryption algorithm is switched according to the comprehensive indicator.
2. The method for dynamically switching a security encryption algorithm according to claim 1, wherein: The various operation stages of the server include a server startup stage, an application loading stage, and a system authority attack stage.
3. The method for dynamically switching a security encryption algorithm according to claim 2, wherein: The operating parameters of the boot phase include central processing unit (CPU) occupancy rate, CPU occupancy rate, memory occupancy rate, memory occupancy rate, network traffic usage rate and server response rate; The operating parameters of the application loading phase include application response speed, CPU occupancy, memory occupancy and network traffic usage; The operating parameters during the stage when system permissions are attacked include memory usage and hard disk usage.
4. The method for dynamically switching a security encryption algorithm according to claim 1, wherein: The determining of abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state includes: Determine the baseline of each parameter based on the safe operation parameters, compare the parameters in the current state with the corresponding baseline, and determine the abnormal parameters.
5. The method for dynamically switching a security encryption algorithm according to claim 4, wherein: The method for determining the baseline of the parameters is as follows: Calculate the average value of each parameter in the historical time series and use the average value as the baseline.
6. The method for dynamically switching a security encryption algorithm according to claim 1, wherein: The method of switching the server's security encryption algorithm according to the comprehensive indicators includes: During the server freezing phase, when CPU usage, network traffic usage, and occupancy rates increase, the server uses a reversible encryption algorithm or an irreversible encryption algorithm; During the server application loading phase, CPU usage, network traffic usage, and memory usage increase. The server uses a symmetric irreversible encryption algorithm. When the system permissions of the service are attacked, an asymmetric irreversible encryption algorithm is used to protect the server based on the increase in memory usage and hard disk usage.
7. A dynamic switching system for a security encryption algorithm, characterized in that: include: The first acquisition module is used to obtain the operating parameters of the server in its current state when the server is attacked by hackers at various operating stages; A second acquisition module is used to obtain safe operation parameters of the server in each operation stage, and determine abnormal parameters of each operation stage of the service based on the safe operation parameters of each operation stage and the operation parameters in the current state; An analysis and switching module is used to determine the type of attack suffered by the server based on the abnormal parameters, determine the threat level of the server based on the attack type, determine the response rate of the server based on the abnormal parameters, and determine the response level of the server based on the response rate; assigning a security weight to the abnormal parameter according to the threat level, assigning a response weight to the abnormal parameter according to the response level, and calculating a comprehensive weight of the abnormal parameter based on the security weight and the response weight; The comprehensive weights of all abnormal parameters are integrated to obtain a comprehensive indicator of the current server status, and the server's security encryption algorithm is switched according to the comprehensive indicator.
8. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the method for dynamically switching the security encryption algorithm as described in any one of claims 1 to 6 when executing the computer program.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the dynamic switching method of the security encryption algorithm according to any one of claims 1 to 6.
Citation Information
Patent Citations
Cloud-based EMM encryption method and system
CN119155065A
Variable encryption algorithm management apparatus and method based on the security environment changes
KR101613572B1