Network communication security guarantee system for real-time encryption transmission
By introducing dynamic sharded quantum resistance encryption module, adaptive encryption engine, zero-handshake continuous identity authentication module and hardware accelerated shard processing architecture into the network communication security guarantee system, security problems in traditional technologies are solved and efficient and real-time network communication security guarantee is achieved.
Patent Information
- Application Number
- CN202510185325.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-16
AI Technical Summary
Traditional network communication security guarantee technology has risks of static key management, poor adaptability of encryption algorithms, hidden dangers of data sharding encryption, disconnection between identity authentication and encryption, and incompatibility to quantum computing threats.
It adopts dynamic sharded quantum resistance encryption module, an adaptive encryption engine based on traffic perception, a zero-handshake continuous identity authentication module and a hardware accelerated sharding processing architecture to achieve real-time encrypted transmission and efficient security guarantees.
It significantly improves the security, real-time and reliability of network communication, and solves problems such as static key management, encryption algorithm adaptation, data shard encryption, identity authentication and encryption collaboration, and quantum computing threats.
Smart Images

Figure HDA0005278333390000011 
Figure HDA0005278333390000021 
Figure HDA0005278333390000031
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of network communication security, and in particular relates to a network communication security assurance system for real-time encrypted transmission. Background Art
[0002] In today's digital age, network communications have been deeply integrated into all aspects of social operations and economic development, becoming a critical infrastructure. From daily online shopping and social interactions for individuals to remote office collaboration for enterprises and online transaction processing for financial institutions, a large amount of sensitive information is continuously transmitted over the network. This makes the importance of network communication security increasingly prominent. It is not only related to the protection of personal privacy, but also has a far-reaching impact on the stable operation of enterprises and the economic security of the country.
[0003] Traditional network communication security technologies, such as SSL / TLS, have exposed a series of problems that need to be solved in long-term practical applications. In terms of key management, traditional SSL / TLS relies on fixed session keys, and long-term use will expose these keys to a high risk of being cracked by brute force. When trying to dynamically update static keys, communication has to be interrupted for re-handshake, which will cause a sharp increase in network latency. In online video conferencing scenarios, the screen may freeze and the sound may be interrupted during the re-handshake, seriously affecting the user experience.
[0004] In terms of encryption algorithms, a single encryption algorithm is difficult to adapt to the complex and ever-changing network threat environment. When transmitting ordinary data, the use of high-intensity encryption algorithms will consume excessive computing resources and network bandwidth, resulting in a waste of resources. For example, for some IoT devices with limited hardware computing power, the use of high-intensity encryption algorithms may cause the device to run slowly or even crash. However, when processing sensitive data, if the encryption algorithm is not strong enough, it cannot provide sufficient security protection.
[0005] In data sharding encryption, existing technologies usually encrypt the entire data packet as a whole, which poses a serious risk. Once part of the ciphertext is cracked, the attacker can infer more information by analyzing the context semantics, which poses a risk of chain cracking.
[0006] The disconnect between authentication and encryption is also a common problem. Most systems only perform authentication when establishing a connection, and lack a continuous verification mechanism during data transmission, which makes the system extremely vulnerable to session hijacking attacks.
[0007] With the rapid development of quantum computing technology, traditional asymmetric encryption algorithms, such as RSA, face a huge risk of being cracked by quantum computers. At present, most existing real-time systems lack compatibility with post-quantum encryption technology. Once quantum computers are widely used, the existing network communication security system will face severe challenges.
[0008] To sum up, the various defects of traditional network communication security assurance technology urgently need to be solved by an innovative, more efficient and secure real-time encrypted transmission network communication security assurance system. Summary of the invention
[0009] In order to solve the above problems, the present invention provides a network communication security assurance system for real-time encrypted transmission to solve the problems existing in the above background technology.
[0010] In order to achieve the above-mentioned invention object, the present invention proposes a network communication security assurance system for real-time encrypted transmission, including a dynamic sharded quantum-resistant encryption module, an adaptive encryption engine based on traffic perception, a zero-handshake continuous identity authentication module and a hardware-accelerated sharding processing architecture; the dynamic sharded quantum-resistant encryption module is configured to divide the data stream into multiple shards according to the time window, and independently generate an unrelated key for each shard based on the quantum-safe NTRU algorithm, store the pre-generated key sharding index with the help of blockchain, integrate the SPHINCS+ hash signature algorithm to attach a one-time signature to each shard, and combine symmetric and asymmetric encryption in the shard for secondary encryption; the adaptive encryption engine based on traffic perception deploys a lightweight ML model to perform real-time analysis of traffic characteristics such as data sensitivity, network jitter, and historical attack frequency, and based on this, in AES-25 6. Seamless hot switching of encryption algorithms between ChaCha20 and NTRU algorithms, maintaining the continuity of data flow, and using distributed hash table (DHT) technology to implement distributed key management; the zero-handshake continuous identity authentication module embeds a dynamic fingerprint generated by device hardware characteristics and session random numbers in each data shard, and verifies end-to-end link control by randomly discarding 1% of data shards and requiring the sender to retransmit a specific hash value in the next shard, while introducing a deep learning model to monitor abnormal behavior during communication in real time; the hardware-accelerated shard processing architecture uses FPGA chips to be specifically responsible for shard encryption / decryption, and the CPU only performs key index allocation, allocates independent memory space for each shard, completes key generation and destruction through hardware instructions, and uses hardware redundancy technology to redundantly configure key hardware components such as FPGA chips and memory.
[0011] Furthermore, in the dynamic sharded quantum-resistant encryption module, the blockchain storage key shard index adopts a Merkle tree structure to ensure the integrity and non-tamperability of the index data.
[0012] Furthermore, the traffic-aware adaptive encryption engine can complete the analysis of network traffic characteristics and adjust the encryption strength within 10 milliseconds through a hardware-accelerated real-time threat assessment module.
[0013] Furthermore, the traffic-aware adaptive encryption engine ensures the accuracy of data transmission during the switching process through a cache mechanism when performing hot switching of algorithms, and the packet loss rate is less than 0.01%.
[0014] Furthermore, in the distributed key management, the DHT technology uses a consistent hashing algorithm to evenly distribute the keys among nodes, thereby improving storage and reading efficiency.
[0015] Furthermore, in the zero-handshake continuous identity authentication module, a dynamic fingerprint generation algorithm combines the device unique identification code, the current timestamp and the session random number to ensure the uniqueness and dynamism of the fingerprint.
[0016] Furthermore, the zero-handshake continuous authentication module uses a deep learning model to monitor abnormal behavior in real time, and the detection accuracy of DDoS attacks reaches over 98%.
[0017] Furthermore, in the hardware accelerated slicing processing architecture, a high-speed serial bus is used to connect the FPGA chip and the CPU, and the data transmission rate reaches more than 10 Gbps.
[0018] Furthermore, the hardware accelerated shard processing architecture adopts a paging management mechanism for the independent memory space allocated to each shard, thereby improving memory utilization.
[0019] Furthermore, in the hardware redundancy technology, a master-slave mode is adopted for the FPGA chip. When a master chip fails, switching to the backup chip is completed within 50 microseconds.
[0020] Compared with the prior art, the beneficial effects of the present invention are at least as follows:
[0021] The network communication security assurance system of the present invention comprehensively innovates the traditional network communication security assurance technology, successfully overcomes the difficulties in static key management, encryption algorithm adaptation, data sharding encryption, identity authentication and encryption coordination, and quantum computing threat response, and significantly improves the system's performance in key performance dimensions such as security, real-time, adaptability, reliability, and anti-attack capability.
[0022] Specific:
[0023] Solving the defects of static key management: The dynamic sharded quantum-resistant encryption module abandons the traditional fixed session key mode and uses the quantum-safe NTRU algorithm to independently generate keys for each data shard. It combines blockchain storage of key shard indexes with lightweight negotiation acquisition methods to avoid the risk of keys being cracked due to long-term use, and eliminates communication interruptions and increased delays caused by key updates. It effectively guarantees the stability and security of communications and ensures smooth operation of application scenarios with high real-time requirements such as online video conferencing.
[0024] Matching encryption algorithms and scenarios: The traffic-aware adaptive encryption engine uses lightweight ML models to analyze traffic characteristics in real time, and implements millisecond-level seamless hot switching between algorithms such as AES-256, ChaCha20, and NTRU based on factors such as data sensitivity, network jitter, and historical attack frequency. It can avoid the waste of resources caused by high-intensity encryption during ordinary data transmission, and provide sufficient security protection when processing sensitive data. For example, in the data transmission of IoT devices, the encryption algorithm can be dynamically adjusted according to the computing power of the device hardware to achieve efficient and secure transmission.
[0025] Filling the gap in data sharding encryption: The dynamic sharding quantum-resistant encryption module shards the data stream and encrypts it independently. The keys of each shard are unrelated, effectively blocking the semantic inference path between ciphertexts. Even if a single shard ciphertext is cracked, the attacker cannot infer the overall data content, greatly reducing the risk of chain cracking and providing reliable security for government departments, financial institutions, etc. to transmit important sensitive data.
[0026] Integration of identity authentication and encryption: The zero-handshake continuous identity authentication module innovatively integrates identity authentication into the encrypted data stream, embeds dynamic fingerprints based on device hardware features and session random numbers in data shards, and uses a two-way silent challenge mechanism to verify end-to-end link control. At the same time, it uses a deep learning model to monitor abnormal behavior in real time, completely eliminating the risk of session hijacking. In scenarios such as online bank transfers and e-commerce transactions, it can effectively protect user information and financial security.
[0027] Responding to the threat of quantum computing: This system introduces the quantum-safe NTRU algorithm and the quantum-resistant SPHINCS+ hash signature algorithm into the core encryption technology, giving the system post-quantum encryption compatibility, effectively resisting the potential cracking threat of quantum computers on traditional asymmetric encryption algorithms, and ensuring the information security of key areas such as encrypted communications of financial institutions and transmission of government confidential information in the quantum computing era.
[0028] Improve system performance and reliability: The hardware-accelerated sharding processing architecture uses FPGA chips to specifically take charge of sharding encryption / decryption, and combines with the CPU to execute key index allocation, reducing end-to-end latency to the μs level; through memory sandbox isolation and paging management mechanisms, it ensures secure key storage and efficient memory utilization; using hardware redundancy technology, redundant configuration of key hardware components such as FPGA chips and memory, and completes fault switching within 50 microseconds in the active-standby mode, ensuring the continuity and stability of communication, and meeting various application scenarios with extremely high requirements for communication real-time and reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 This is the overall architecture diagram of the system in the present invention;
[0030] Figure 2 This is a flow chart of the dynamic sharding quantum-resistant encryption module in the present invention;
[0031] Figure 3 This is a flow chart of the adaptive encryption engine based on traffic perception in the present invention;
[0032] Figure 4 This is a flow chart of the zero-handshake continuous identity authentication module in the present invention. DETAILED DESCRIPTION
[0033] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0034] It can be understood that the terms "first", "second", etc. used in the present application can be used in this article to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish the first element from another element.
[0035] Embodiment 1
[0036] The present invention has carefully created a real-time encrypted transmission network communication security system, which aims to overcome the many difficulties in traditional network communication security technology in key management, encryption algorithm adaptation, identity authentication, and coping with quantum computing threats, thereby significantly improving the security, real-time and reliability of network communications. This system is composed of multiple core modules, each of which performs its own duties and jointly builds a solid network communication security line of defense.
[0037] Dynamically sharded quantum-resistant encryption module
[0038] Time window setting: The reasonable setting of the time window plays a decisive role in the quality of data sharding and the efficiency of subsequent encryption processing. This module is like a keen observer. According to the real-time rate of network communication and the fluctuation of data volume, it dynamically adjusts the time window between 100 milliseconds and 500 milliseconds. During the promotional activities of large e-commerce platforms, a large amount of order data in high-concurrency communication scenarios comes like a tide and needs to be transmitted in real time. At this time, in order to finely segment the data stream like a precision scalpel and ensure that the amount of data for each shard is just right for subsequent encryption processing, the system will decisively set the time window to 100 milliseconds. In daily ordinary data transmission scenarios, the data volume is relatively small and the transmission rate is relatively stable. The time window can be appropriately increased to 500 milliseconds, thereby reducing the processing overhead of the system and improving the overall operation efficiency.
[0039] Key generation: The quantum-safe NTRU algorithm based on lattice cryptography theory is used to generate keys. This algorithm is like a solid shield with good resistance to quantum computing attacks. In the actual generation process, the algorithm will take the shard number, timestamp, and random number seed as input parameters. The shard number is like the exclusive ID card of each data shard, which is used to distinguish different data shards and ensure that each shard has a unique identification; the timestamp adds timeliness to the key, so that the key has different values when generated at different times; the random number seed further enhances the randomness of the key. Through these input parameters, after a series of complex and rigorous mathematical operations, a unique and unrelated key is generated for each shard, ensuring that the generated key has a high degree of randomness and security, and effectively resists the potential threats brought by quantum computing.
[0040] Blockchain storage: With the distributed ledger feature of blockchain, the pre-generated key shard index is stored in the blockchain node. The distributed feature of blockchain enables each node to save a complete copy of the index, which is like backing up countless secure locations for data, increasing the reliability and security of the data. When the communicating parties need to obtain the key index, they can quickly and accurately obtain the latest index information through the consensus mechanism of blockchain, such as the proof-of-stake (PoS) algorithm. The proof-of-stake algorithm determines the power of a node to participate in the consensus by the proportion of its equity held. It can improve the efficiency of consensus while ensuring security, ensuring that the communicating parties can obtain the required key index in a timely manner, so as to smoothly perform data encryption and decryption operations.
[0041] Signature attachment: Integrates the SPHINCS+ hash signature algorithm built on a hash function, which has good security and efficiency. When processing each shard, the algorithm will perform a hash calculation on the data content of the shard to generate a hash value of a fixed length. This hash value can be regarded as the "fingerprint" of the shard data and can uniquely identify the data. Then, the hash value is signed in combination with the private key, and the signature result is attached to the shard data. In this way, after receiving the data, the recipient can use the public key to verify the signature to ensure that the data has not been tampered with during transmission, ensuring the integrity and non-tamperability of the data, just like putting a security seal on the data.
[0042] Secondary encryption: Within the shard, secondary encryption is used to further enhance data security. First, the symmetric encryption algorithm AES-128 is used to quickly encrypt the data. The AES-128 algorithm has the characteristics of fast encryption speed and high efficiency. It can initially encrypt a large amount of data in a short time to meet the needs of real-time communication, just like putting on the first layer of protective armor for the data. Then, the AES-128 key is encrypted using the RSA asymmetric encryption algorithm using the recipient's public key. Due to the asymmetric nature of the RSA algorithm, only the recipient can decrypt the AES-128 key using its private key, thereby ensuring the secure transmission of the encryption key and preventing the key from being stolen during transmission, adding another layer of solid protection lock to the data encryption key.
[0043] Traffic-aware adaptive encryption engine
[0044] ML model deployment: A lightweight TinyML model is selected. This model has been trained with a large amount of network traffic data. Like an experienced analyst, it can accurately identify different types of traffic characteristics. In order to reduce data transmission delays and achieve real-time analysis of traffic, the model is deployed on edge devices close to the data source, such as gateway devices in the enterprise's internal network. Edge devices can perform preliminary processing of traffic data locally without transmitting large amounts of data to remote servers for analysis, which greatly improves the real-time and efficiency of analysis, just like setting up a quick response station at the source of the data.
[0045] Traffic analysis: Real-time collection of network traffic data, including packet size, transmission frequency, source IP, destination IP and other information. Through in-depth analysis of these data, combined with the preset sensitivity threshold, the sensitivity of the current data is judged. For example, if the data packet contains sensitive content such as the user's personal identity information, financial transaction records, etc., it is judged as high-sensitivity data; if it is just ordinary text information or image data, it is judged as low-sensitivity data. At the same time, the stability of the network is evaluated based on the monitoring indicators of network jitter, such as delay change rate, packet loss rate, etc. If the delay change rate is large or the packet loss rate is high, it means that the network is unstable and corresponding measures need to be taken. In addition, by analyzing historical attack logs, the attack frequency of different time periods and IP addresses is counted to detect potential security threats in advance, just like setting up multiple monitoring and early warning devices for network security.
[0046] Algorithm switching: Based on the results of traffic analysis, seamless hot switching is performed between AES-256, ChaCha20, and NTRU algorithms. Different encryption algorithms have different characteristics and applicable scenarios. The system will select the most appropriate algorithm based on actual conditions. When it is detected that ordinary text data is being transmitted and the network is stable, switch to the ChaCha20 algorithm, which has high encryption efficiency and can increase the speed of data transmission while ensuring a certain level of security, just like choosing a fast channel. When transmitting sensitive financial data, switch to the AES-256 algorithm, which has high security and can effectively protect the confidentiality of data, providing a solid confidentiality barrier for sensitive data. In the face of potential scenarios of quantum computing threats, switch to the NTRU algorithm, which has the ability to resist quantum computing attacks, ensuring the security of data in the quantum era, just like wearing a quantum protective suit for the data.
[0047] Key management: Distributed hash table (DHT) technology is used to store encryption keys in multiple nodes. Each node determines the storage location based on its own ID and the hash value of the key. When the key needs to be obtained, the storage node is quickly located through the DHT routing algorithm to obtain the key. Distributed hash table technology has good scalability and fault tolerance, and can effectively manage a large number of encryption keys. Even if some nodes fail or go offline, it will not affect the key management and data encryption and decryption operations of the entire system, just like building a flexible and reliable distributed network for key management.
[0048] Zero handshake continuous authentication module
[0049] Dynamic fingerprint embedding: During the data sharding process, the hardware features of the device, such as the CPU serial number, MAC address, etc., are obtained. These hardware features are unique and can be used as the device's identity. Combined with the session random number, a dynamic fingerprint is generated through a specific hash algorithm. For example, the SHA-256 algorithm is used to hash the device hardware features and the session random number to generate a 256-bit dynamic fingerprint, which is then embedded in the header of the data shard. The generation of dynamic fingerprints gives each data shard a unique identity, which can effectively prevent data tampering and forgery, and ensure that the source of the data is reliable, just like attaching a unique identity label to each data shard.
[0050] Link verification: In order to verify the control of the end-to-end link, 1% of the data fragments are randomly discarded. When the receiving end receives the subsequent fragments, it requires the sending end to retransmit the specific hash value in the next fragment according to the preset rules. The sending end calculates the hash value of the data content of the discarded fragment, obtains the specific hash value, and includes it in the subsequent fragments and sends it to the receiving end. The receiving end verifies the correctness of the hash value. If the hash value matches, it confirms that the control of the end-to-end link has not been tampered with and the data transmission process is secure. This verification method increases the security of data transmission and prevents man-in-the-middle attacks, just like setting a secret verification checkpoint during the data transmission process.
[0051] Abnormal monitoring: Introduce deep learning models, such as the anomaly detection model based on convolutional neural network (CNN), to monitor multi-dimensional information such as data flow, transmission frequency, IP address changes, etc. during the communication process in real time. The model establishes a baseline model by learning the normal communication mode. When the data deviates from the baseline model, an abnormal warning is issued. For example, if the access frequency of a certain IP address suddenly increases abnormally, or the data flow fluctuates abnormally, the model will issue an alarm in time to remind the administrator to take corresponding measures to prevent potential security threats, just like equipping the network communication with an ever-vigilant smart guard.
[0052] Hardware-accelerated sharding architecture
[0053] FPGA chip application: Choose high-performance FPGA chips, such as Xilinx's Kintex series, which have rich logic resources and high-speed data processing capabilities. FPGA chips are programmed through hardware description language (HDL) to achieve efficient shard encryption / decryption functions. During the encryption process, the FPGA chip quickly processes the input shard data according to the preset encryption algorithm to generate ciphertext. Due to the parallel processing capability of the FPGA chip, it can encrypt and decrypt multiple data shards at the same time, greatly improving the processing efficiency and meeting the needs of real-time communication, just like an efficient parallel processing factory.
[0054] CPU task allocation: The CPU is mainly responsible for the allocation and management of key indexes. When receiving an encryption or decryption request, the CPU obtains the corresponding key shard index from the blockchain according to the request identifier, and sends the index information to the FPGA chip, instructing it to use the corresponding key for encryption / decryption operations. The CPU plays a role in coordination and management in the entire system, ensuring that the FPGA chip can correctly use the key for data processing, just like the command center of the system.
[0055] Memory management: Allocate independent memory space to each shard, and use memory mapping technology to efficiently map the memory space with the FPGA chip and CPU. During key generation and destruction, fast operations are achieved through hardware instructions to ensure the security of the key. Memory mapping technology enables the FPGA chip and CPU to directly access data in the memory, reducing the overhead of data transmission and improving the overall performance of the system. At the same time, the use of independent memory space and hardware instructions effectively protects the security of the key, prevents key leakage, and provides double protection for key security.
[0056] Embodiment 2
[0057] Embodiment 2 Based on Embodiment 1, further optimization and improvement are made on each module to comprehensively improve the performance, security and reliability of the system.
[0058] Dynamically sharded quantum-resistant encryption module
[0059] Blockchain storage structure: Merkle tree structure is used to store key shard indexes. In the process of building the Merkle tree, each key shard index is used as a leaf node. Through hash calculation, adjacent leaf nodes are merged into parent nodes, and so on, and finally a root node is generated. The structure of the Merkle tree has good verifiability and efficiency. When the index data changes, only the relevant leaf nodes and parent nodes need to be updated. Through the verification of the root node, the integrity and non-tamperability of the entire index data can be ensured. This structure makes data updating and verification more convenient and efficient, and improves the security and reliability of the system, just like building an efficient and reliable verification and storage system for key shard indexes.
[0060] Traffic-aware adaptive encryption engine
[0061] Hardware-accelerated analysis: Through the hardware-accelerated real-time threat assessment module, a dedicated digital signal processor (DSP) chip is used, combined with the parallel processing capability of the field programmable gate array (FPGA) to quickly analyze network traffic characteristics. The DSP chip has powerful digital signal processing capabilities and can quickly process large amounts of traffic data. The parallel processing capability of the FPGA can analyze multiple data at the same time, greatly improving the speed of analysis. The collection, analysis and processing of multi-dimensional information such as data sensitivity, network jitter, historical attack frequency, etc. are completed within 10 milliseconds, and the encryption strength is adjusted in time according to the analysis results. This rapid analysis and adjustment capability enables the system to respond to changes in the network environment in real time and ensure data security, just like installing a fast-response intelligent sensor for the system.
[0062] Cache mechanism guarantee: When performing hot switching of algorithms, the accuracy of data transmission during the switching process is guaranteed by the cache mechanism. Two levels of cache are set up. The first level cache is a high-speed cache (Cache) for temporarily storing data to be transmitted; the second level cache is a memory cache for storing recently transmitted data. When the algorithm is switched, the data is first read from the cache to ensure the continuity of data transmission. At the same time, the data during the switching process is backed up to the memory cache so that it can be retransmitted in the event of packet loss. Through this cache mechanism, the packet loss rate can be effectively reduced to less than 0.01%, ensuring the accuracy and reliability of data transmission, just like setting up double insurance for data transmission.
[0063] Distributed key management - DHT algorithm optimization: DHT technology uses a consistent hashing algorithm to map the key space into a ring-shaped hash space. Each node occupies a position on the ring according to its own hash value. When storing a key, the nearest node is searched clockwise on the ring according to the hash value of the key for storage. This algorithm makes the keys evenly distributed among the nodes, effectively improving the efficiency of key storage and reading. Compared with the traditional DHT algorithm, the consistent hashing algorithm can better cope with the addition and departure of nodes, reduce the migration and redistribution of data, and improve the stability and scalability of the system, just like building a more flexible and stable distributed storage network for key management.
[0064] Zero handshake continuous authentication module
[0065] Dynamic fingerprint algorithm: The dynamic fingerprint generation algorithm combines the device unique identification code, the current timestamp, and the session random number. During the generation process, the device unique identification code is first encrypted, then XORed with the current timestamp and the session random number, and then the final dynamic fingerprint is generated through the hash algorithm. This algorithm ensures the uniqueness and dynamism of the fingerprint. The device unique identification code ensures that the fingerprint of each device is unique, the current timestamp makes the fingerprint change over time, and the session random number increases the randomness of the fingerprint. Through these measures, the fingerprint is effectively prevented from being forged and tampered with, and the security of identity authentication is improved, just like creating a more solid protective lock for identity authentication.
[0066] Anomaly detection accuracy: When using deep learning models to monitor abnormal behaviors in real time, the detection accuracy of DDoS attacks reaches over 98% through training with a large amount of normal and abnormal communication data. The model uses a multi-layer neural network structure, including an input layer, a hidden layer, and an output layer, and accurately identifies DDoS attack behaviors by extracting and classifying the features of the input data. A large amount of training data enables the model to learn various normal and abnormal communication patterns, and the multi-layer neural network structure can extract the features of the data more deeply, improving the accuracy and reliability of detection, just like training a smart guard with sharp eyes for network security.
[0067] Hardware-accelerated sharding architecture
[0068] Bus connection: The FPGA chip and the CPU are connected by a high-speed serial bus, such as the PCI-Express 4.0 bus, with a data transmission rate of more than 10Gbps. During the data transmission process, the bus protocol is used to ensure accurate data transmission and synchronization, reducing data transmission delays. The high-speed serial bus can provide a higher data transmission rate to meet the system's requirements for data processing speed. The use of the bus protocol ensures accurate data transmission and synchronization, avoids data loss and errors, and improves system performance and reliability, just like building a high-speed and stable data transmission channel between the FPGA chip and the CPU.
[0069] Memory management mechanism: The independent memory space allocated for each shard uses a paging management mechanism. The memory is divided into pages of fixed size, and each shard occupies a number of pages. The allocation and recycling of pages is managed through the page table to improve memory utilization and reduce the generation of memory fragmentation. The paging management mechanism makes memory allocation and recycling more flexible and efficient, which can make full use of memory resources and improve the overall performance of the system, just like designing an efficient resource allocation solution for memory management.
[0070] Hardware redundancy technology: The FPGA chip adopts the master-slave mode. When the master chip fails, the working status of the master chip is detected in real time through the hardware monitoring circuit. Once a fault is detected, the switching mechanism is immediately triggered, and the switch to the backup chip is completed within 50 microseconds to ensure the normal operation of the system. Hardware redundancy technology increases the reliability and fault tolerance of the system. Even if the master chip fails, the backup chip can take over the work in time to ensure the continuity and stability of the system, just like equipping the system with a reliable backup power supply.
[0071] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0072] The above embodiments only express several implementation methods of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for those of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
[0073] The above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A network communication security assurance system for real-time encrypted transmission, characterized in that: It includes a dynamic sharded quantum-resistant encryption module, a traffic-aware adaptive encryption engine, a zero-handshake continuous authentication module, and a hardware-accelerated sharding processing architecture; The dynamic sharded quantum-resistant encryption module is configured to divide the data stream into multiple shards according to the time window, independently generate unrelated keys for each shard based on the quantum-safe NTRU algorithm, use the blockchain to store the pre-generated key shard index, integrate the SPHINCS+ hash signature algorithm to attach a one-time signature to each shard, and combine symmetric and asymmetric encryption for secondary encryption in the shard; the traffic-aware adaptive encryption engine deploys a lightweight ML model to perform real-time analysis of traffic characteristics such as data sensitivity, network jitter, and historical attack frequency, and seamlessly hot-switch encryption algorithms between AES-256, ChaCha20, and NTRU algorithms, maintain the continuity of the data stream, and implement distributed key management using distributed hash table (DHT) technology; the zero-handshake continuous identity authentication module embeds a dynamic fingerprint generated by device hardware characteristics and session random numbers in each data shard, verifies end-to-end link control by randomly discarding 1% of the data shards and requiring the sender to retransmit a specific hash value in the next shard, and introduces a deep learning model to monitor abnormal behavior during communication in real time; The hardware accelerated sharding processing architecture uses FPGA chips to be responsible for sharding encryption / decryption, and the CPU only performs key index allocation work, allocates independent memory space to each shard, completes key generation and destruction through hardware instructions, and uses hardware redundancy technology to redundantly configure key hardware components such as FPGA chips and memory.
2. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: In the dynamic sharded quantum-resistant encryption module, the blockchain storage key shard index adopts a Merkle tree structure to ensure the integrity and non-tamperability of the index data.
3. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: The traffic-aware adaptive encryption engine, through a hardware-accelerated real-time threat assessment module, completes the analysis of network traffic characteristics and adjusts encryption strength within 10 milliseconds.
4. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: The traffic-aware adaptive encryption engine ensures the accuracy of data transmission during the switching process through a cache mechanism when performing hot switching of algorithms, and the packet loss rate is less than 0.01%.
5. The network communication security guarantee system for real-time encrypted transmission according to claim 1 is characterized by: In the distributed key management, the DHT technology uses a consistent hashing algorithm to evenly distribute keys among nodes, thereby improving storage and reading efficiency.
6. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: In the zero-handshake continuous identity authentication module, the dynamic fingerprint generation algorithm combines the device unique identification code, the current timestamp and the session random number to ensure the uniqueness and dynamism of the fingerprint.
7. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: The zero-handshake continuous identity authentication module uses a deep learning model to monitor abnormal behavior in real time, and the detection accuracy of DDoS attacks reaches over 98%.
8. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: In the hardware accelerated slicing processing architecture, a high-speed serial bus is used to connect the FPGA chip and the CPU, and the data transmission rate reaches more than 10 Gbps.
9. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: The hardware accelerated shard processing architecture adopts a paging management mechanism for the independent memory space allocated to each shard, thereby improving memory utilization.
10. A network communication security assurance system for real-time encrypted transmission according to claim 1, characterized in that: In the hardware redundancy technology, the FPGA chip adopts a master-slave mode, and when the master chip fails, the switch to the backup chip is completed within 50 microseconds.
Citation Information
Cited By
Electronic seal verification method based on quantum true random number and anti-quantum multi-dimensional dynamic code
CN120429900A
Electronic seal verification method based on quantum true random numbers and quantum-resistant multi-dimensional dynamic codes
CN120429900B
Article anti-counterfeiting verification method, device and equipment based on radio frequency identification anti-counterfeiting system
CN120671694A
Wireless fast ad hoc network node security access and key management method based on quantum random number
CN121463034A
Distributed data storage and transmission method and system based on quantum security and dynamic fragmentation combination
CN122160054A