Company information encryption method combined with chaotic public key encryption algorithm

By combining the chaotic public key encryption algorithm and the priority and historical key generation time stamps of the authorization subject, a pseudo-random number sequence is generated to determine the key generation order, which solves the problem of key conflict in the parallel authorization environment of multiple devices, and improves the security and efficiency of the system.

CN120034313AActive Publication Date: 2025-05-23ZHUHAI COLLEGE OF JILIN UNIV

Patent Information

Application Number
CN202510159806.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-23
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

In the environment of multi-device parallel authorization, it is difficult for the prior art to effectively coordinate the key generation order, resulting in key conflict problems and affecting the security and efficiency of the system.

Method used

By combining the chaotic public key encryption algorithm, the authorized subject's priority and historical key generation time stamp generate a pseudo-random number sequence as sort weights, determine the key generation order, and use the authorized subject's identity information and timestamp as the initial parameters of the chaotic algorithm to generate a chaotic feature sequence for key generation.

Benefits of technology

It effectively solves the problem of key conflict in a multi-device parallel authorization environment, improves the security and efficiency of the system, and optimizes the system performance by dynamically adjusting the key update frequency and conflict judgment threshold.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034313A_ABST
    Figure CN120034313A_ABST
Patent Text Reader

Abstract

The invention provides a company information encryption method combined with a chaotic public key encryption algorithm, which comprises the following steps: comparing the time difference of key generation of a first priority level authorization subject and a second priority level authorization subject, and if the time difference is smaller than a preset time difference threshold, generating a timestamp according to the priority level of the authorization subject and a historical key, generating a group of pseudo-random number sequences as sorting weights; sorting the authorization subjects according to the sorting weight, and determining a key generation sequence of the authorization subjects in the key conflict coordination process; after the secret key is generated, a new secret key is distributed to a corresponding authorization object, a secret key state table in the secret key is updated, a timestamp and authorization main body information of the secret key updating are recorded, and meanwhile a secret key updating process is triggered regularly; all actions in the key coordination process are audited and recorded, including triggering conditions, chaotic mapping and encryption parameters, sorting results and key distribution and updating, and the process is continuously improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a company information encryption method combined with a chaotic public key encryption algorithm. Background Art

[0002] In an IoT system, when multiple devices can be authorized to access the data of the same server, there will be a situation where multiple authorized subjects assign permissions to the same object. In order to avoid conflicts between keys generated by different authorized subjects, the system needs to coordinate the order of key generation. If the order is different, multiple authorized subjects may generate the same key, causing key conflicts. In this parallel authorization environment, when multiple authorized subjects request access rights to the same object in a short period of time, the system needs to generate keys for each authorized subject in a certain order according to the characteristics of the chaos algorithm. This process may introduce additional time overhead, especially when the number of authorized subjects is large, the order of key generation may become complicated. In addition, during the key generation process, the number of iterations and the selection of initial values ​​of the chaos algorithm will also affect the efficiency of key generation. Improper parameter settings may cause the key generation time to be too long, which in turn affects the response speed of the entire authorization process. Therefore, how to optimize the parameter settings of the chaos algorithm while ensuring the key generation order and ensuring consistency in the parallel environment is a problem that needs to be studied in depth. The solution to this problem is of great significance to improving the authorization efficiency in the parallel authorization environment. Summary of the invention

[0003] The present invention provides a company information encryption method combined with a chaotic public key encryption algorithm, which mainly includes:

[0004] When several devices request to access the same server, the priority information of the device to be accessed is compared with the preset authorization subject priority list. If the priority of the device to be accessed matches the first priority level in the list, the device to be accessed is determined to be an authorization subject of the first priority level. If it matches the second priority level, the device to be accessed is determined to be an authorization subject of the second priority level, and a corresponding key is generated according to the priority level of the authorization subject.

[0005] Compare the time difference between the key generation of the first priority authorization subject and the second priority authorization subject. If the time difference is less than the preset time difference threshold, generate a set of pseudo-random number sequences as sorting weights according to the priority level of the authorization subject and the historical key generation timestamp;

[0006] According to the sorting weights, the authorized subjects are sorted to determine the key generation order of the authorized subjects in this key conflict coordination process;

[0007] In the key generation process, the identity information and timestamp of the authorized subject are obtained, and the identity information and timestamp of the authorized subject are used as the initial parameters of the chaotic public key encryption algorithm, a chaotic feature sequence is generated through the chaotic algorithm, and the chaotic feature sequence is used to generate the initial value or iteration parameter of the key;

[0008] After the key generation is completed, the new key is distributed to the corresponding authorized object, and the key status table is updated to record the timestamp and authorized subject information of this key update, and the key update process is triggered regularly;

[0009] Monitor the system security status in real time, dynamically calculate the key update frequency adjustment range, generate the key update frequency parameter, calculate the key conflict judgment threshold adjustment range, generate the update threshold parameter, write the key update frequency parameter and the update threshold parameter into the system configuration file, trigger the dynamic adjustment of the key update frequency and the conflict judgment threshold, and after the adjustment is completed, monitor and record the system security status change data;

[0010] Audit and record all actions in the key coordination process, including trigger conditions, chaos mapping and encryption parameters, sorting results, key distribution and updates, and continuously improve the process.

[0011] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:

[0012] The present invention discloses a company information encryption method combined with a chaotic public key encryption algorithm. When multiple devices request to access a server at the same time, the present invention first obtains the device priority and compares it with a preset authorization list to determine the priority level of the authorized subject. The corresponding key is generated according to the priority, and the time difference of the key generation of different levels is compared. If the time difference is less than the threshold, the conflict coordination mechanism is triggered. The mechanism adopts a chaotic mapping algorithm to generate a pseudo-random sequence as a sorting weight according to the authorization subject priority and the historical timestamp to determine the key generation order. During the key generation process, the authorization subject identity information and timestamp are used as the initial parameters of the chaotic public key encryption algorithm. After the key is distributed, the state table is updated to record the update time and authorization information. The present invention also dynamically adjusts the key update frequency and the conflict judgment threshold by real-time monitoring of the security status and performance indicators. The whole process is fully audited and recorded, and the process is continuously improved. The method effectively solves the key conflict problem when multiple devices access at the same time, and improves the system security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 The present invention is a flow chart of a company information encryption method combined with a chaotic public key encryption algorithm.

[0014] Figure 2 The diagram is a schematic diagram of a company information encryption method combined with a chaotic public key encryption algorithm according to the present invention. DETAILED DESCRIPTION

[0015] In order to further understand the content of the present invention, the present invention is described in detail in conjunction with the accompanying drawings and embodiments. The present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It is understood that the specific embodiments described herein are only used to explain the relevant inventions, rather than to limit the invention. It is also necessary to explain that, for ease of description, only the parts related to the invention are shown in the accompanying drawings.

[0016] like Figure 1-2 In this embodiment, a company information encryption method combined with a chaotic public key encryption algorithm may specifically include:

[0017] Step S101, when several devices request to access the same server, the priority information of the device to be accessed is compared with the preset authorization subject priority list. If the priority of the device to be accessed matches the first priority level in the list, the device to be accessed is determined to be an authorization subject of the first priority level; if it matches the second priority level, the device to be accessed is determined to be an authorization subject of the second priority level, and a corresponding key is generated according to the priority level of the authorization subject.

[0018] For the access device, a device identification code and an access timestamp are obtained, and a similarity calculation is performed between the device identification code and a pre-stored device feature library to obtain a device authentication pass mark; according to the device authentication pass mark, historical access records within a preset time window are read, and a device access frequency value and a device priority score are obtained by counting the number of accesses; the device priority score is matched with an authorization subject priority rule library, and if the priority score is within a first priority interval, it is determined to be a first priority authorization subject; a key generation reference value is obtained from a preset key generation rule library using the authorization subject priority level, a device access key is generated according to the key generation reference value, and the authorized access server area is determined by the device access key.

[0019] Specifically, the device identity code and access timestamp are collected from the access device, and the similarity calculation is performed for the device identity code and the pre-stored device feature library to obtain the device authentication score. If the authentication score is greater than the preset authentication threshold, the device authentication pass mark is output. According to the device authentication pass mark, the historical access record of the device in the preset time window is read, the number of accesses is counted to obtain the device access frequency value, and the device priority score is calculated based on the access frequency value. The device priority score is matched with the authorization subject priority rule library. If the priority score is within the first priority interval, it is determined to be the first priority authorization subject. If the priority score is within the second priority interval, it is determined to be the second priority authorization subject. According to the determined authorization subject priority level, the corresponding key generation reference value and random factor are obtained from the preset key generation rule library, and the device access key is generated using a symmetric encryption algorithm based on an elliptic curve. A key feature record is established for the generated device access key, and the key validity period value and security level value are set based on the authorization subject priority level, and a key authorization verification record is generated. The server access area range corresponding to different security levels is obtained from the preset server access permission configuration table, and the key security level value is compared with the access permission configuration table to determine the device's authorized access server area within the current time window. In the process of collecting device identification codes, the hardware feature value and software feature value of the device are combined. The hardware feature value includes the serial number of the central processor, the serial number of the hard disk and the physical address of the network card of the device. The software feature value includes the version number of the operating system and the application installation list. A 128-bit device identification code is obtained through the feature extraction algorithm. The device authentication score is calculated using the cosine similarity method to calculate the similarity between the device identification code and the identification code stored in the feature library. If the cosine value of the angle between the two vectors is greater than 0.95, the authentication pass mark is output. The statistics of the access frequency value are based on the cumulative number of accesses to the device within a 24-hour time window. The original access number is smoothed by the exponential smoothing method to reduce the impact of sudden access on priority determination. The device priority score is calculated using a nonlinear mapping function based on the access frequency. When the smoothed access frequency value is less than 5 times / hour, it is mapped to the 0-60 point interval, 5-10 times / hour is mapped to the 60-80 point interval, and more than 10 times / hour is mapped to the 80-100 point interval. Three priority intervals are preset in the authorization subject priority rule base: 90-100 points correspond to the first priority authorization subject, 70-89 points correspond to the second priority authorization subject, and below 70 points correspond to the third priority authorization subject. In the key generation process, the elliptic curve cryptographic algorithm is used to select different key lengths for authorization subjects of different priorities. The first priority uses a 256-bit key, the second priority uses a 192-bit key, and the third priority uses a 128-bit key. The key feature record contains attribute fields such as the key generation timestamp, key length value, and authorization subject priority level.The key validity period value is positively correlated with the priority level of the authorized subject. The key validity period of the first priority authorized subject is 24 hours, the second priority is 12 hours, and the third priority is 6 hours. The server access area is divided into three levels: core area, application area, and data area. Keys of different security levels have different access rights. Keys with a security level of 1 can access all areas, keys with a security level of 2 can access the application area and data area, and keys with a security level of 3 can only access the data area. When a device requests access to core area resources, the server access permission control module first verifies the validity period of the key. If the key is within the validity period and the security level is 1, access to core area resources is allowed. Based on this multi-level access control mechanism, differentiated protection of server resources of different importance is achieved. By dynamically adjusting the priority score of the device, the access control policy can adapt to the dynamic changes in device behavior.

[0020] Step S102, compare the time difference between the key generation of the first priority level authorization subject and the second priority level authorization subject. If the time difference is less than the preset time difference threshold, generate a set of pseudo-random number sequences as sorting weights based on the priority level of the authorization subject and the historical key generation timestamp.

[0021] The key generation timestamps of the first authorized subject and the second authorized subject are read from the key generation record library, the time difference value is calculated by the timestamp, and the key conflict mark is obtained according to the time difference value and the preset time difference threshold; the historical key generation time records of the first authorized subject and the second authorized subject are obtained from the timestamp record table according to the key conflict mark, and the average key generation time interval is calculated for the historical key generation time records; the average key generation time interval is iteratively calculated using the Logistic chaotic mapping equation, and a normalized pseudo-random number sequence is generated for the first authorized subject and the second authorized subject respectively; the comprehensive weight score is calculated according to the normalized pseudo-random number sequence and the priority level value of the first authorized subject and the priority level value of the second authorized subject.

[0022] Specifically, the key generation timestamps of the first priority authorization subject and the second priority authorization subject are read from the key generation record library, the millisecond difference between the two timestamps is calculated to obtain the time difference value, and the time difference value is compared with the preset time difference threshold. If the time difference value is less than the preset time difference threshold, a key conflict mark is generated. According to the key conflict mark, the historical key generation time records of the two authorization subjects in the past 24 hours are obtained from the timestamp record table, and the average key generation time interval of each authorization subject is calculated. The initial value and control parameter are read from the chaotic mapping parameter library, and the average time interval is iteratively calculated using the Logistic chaotic mapping equation to generate two groups of normalized pseudo-random number sequences. For the generated pseudo-random number sequence, the comprehensive weight score is calculated in combination with the first priority value and the second priority value, and the weighted sum of the pseudo-random number sequence mean and the priority value is used as the final sorting basis. The two authorization subjects are prioritized based on the comprehensive weight score, and a key generation sequence number is generated, and the sequence number is written into the key generation queue. According to the key generation queue order, the key generation task is executed in sequence, a unique identifier is assigned to each generated key, and a new key generation timestamp is recorded. Update the historical key generation timestamp record of the authorized subject, write the current key generation time into the timestamp record table, and set the conflict coordination completion mark. In the key generation time conflict processing, the accuracy of the timestamp directly affects the accuracy of the conflict judgment. The timestamp adopts the millisecond recording format. For example, when the key generation time of the first priority authorized subject is 1640995200123 and the second priority is 1640995200234, the calculated time difference value is 111 milliseconds. When the preset time difference threshold is set to 200 milliseconds, the key conflict coordination mechanism is triggered. The historical key generation time record reflects the access behavior characteristics of the authorized subject. By counting the historical records within the 24-hour window, the average key generation time interval of the first priority authorized subject is 300 seconds, and the second priority is 500 seconds. These time interval data are used as the initial input value of the chaotic map. Logistic chaotic mapping uses the iterative equation Xn+1=μXn(1-Xn), where Xn is the iteration value of the nth step, μ is the control parameter, and the value is 3.99. The initial value X0 is obtained by normalizing the time interval. For example, the initial value of the first priority level authorization subject is 0.3, and the second priority level is 0.5. After 10 iterative calculations, two sets of pseudo-random number sequences are generated: the first priority level sequence is

[0023] [0.837,0.546,0.990,0.040,0.153...], the second priority sequence is

[0024] [0.999, 0.004, 0.016, 0.063, 0.236...]. In the comprehensive weight calculation, the weight coefficient of the priority value is 0.7, the weight coefficient of the pseudo-random number sequence mean is 0.3, the first priority value is 90 points, and the second priority is 80 points. The first priority pseudo-random number sequence mean 0.513 is multiplied by the priority score 90 and the weighted comprehensive score is 73.91. The second priority pseudo-random number sequence mean 0.264 is multiplied by the priority score 80 and the weighted comprehensive score is 56.79. Based on the calculated comprehensive weight score, the keys are sorted and assigned key generation sequence numbers. The first priority authorization subject obtains sequence number 1, and the second priority obtains sequence number 2. During the key generation process, the sequence number is used as a queue index to ensure that the key is generated in priority order. The newly generated key is assigned a 32-bit unique identifier, such as "7B9A2F4D", and the exact generation timestamp is recorded. In the update phase of the timestamp record table, the historical records outside the 24-hour window are removed, and only the latest key generation time record is retained. The updated timestamp record is used for subsequent time difference calculation and chaos map initial value generation, thereby forming a dynamically adjusted key generation priority mechanism. Through this randomized sorting method based on historical behavior, while ensuring the dominant position of high-priority authorized subjects, moderate uncertainty is introduced to avoid the key generation concentration problem that may be caused by fixed priorities.

[0025] Step S103: sorting the authorized subjects according to the sorting weights to determine the key generation order of the authorized subjects in this key conflict coordination process.

[0026] A set of authorization subject identifiers to be sorted is obtained from the authorization subject queue, and the authorization subject identifier set is arranged in descending order according to the sorting weight values ​​to obtain an authorization subject sequence table; the reference time interval value in the time window configuration table is read according to the sorting sequence number in the authorization subject sequence table, and the key generation time is obtained by multiplying the sorting sequence number and the reference time interval value; according to the key generation time and the sorting sequence number, a binary heap structure is used to allocate resource blocks to the authorization subject to obtain a resource occupancy sequence; if the resource occupancy sequence includes an authorization subject, the priority attribute value of the authorization subject is read, the resource occupancy mark is set according to the priority attribute value, and a key conflict coordination sorting result record is generated.

[0027] Specifically, a set of authorization subject identifiers to be sorted is read from the authorization subject queue, and the sorting weight value of each authorization subject identifier is extracted. The authorization subject sequence table is generated by arranging the identifiers in descending order according to the weight value, and the authorization subject identifiers are numbered through the sequence table to obtain the sorting sequence number. According to the authorization subject sorting sequence number, the reference time interval value is read from the time window configuration table, and the key generation time of each authorization subject is calculated according to the product of the sorting sequence number and the reference time interval value. The resource occupancy time of each authorization subject is calculated by the sorting sequence number and the key generation time, and the resource block is allocated to the authorization subject using a binary heap structure to generate a resource occupancy sequence. For the authorization subject in the resource occupancy sequence, its priority attribute value is read, and the resource occupancy mark is set based on the priority attribute value to generate a resource allocation record table. The authorization subject identifier and the sorting sequence number are extracted from the resource allocation record table, an identifier mapping relationship is established, a key generation status mark is set, and a record of the result of the coordination sorting of the key conflict in this round is generated. According to the order of the authorization subject identifiers in the sorting result record, the key generation task is arranged according to the resource occupancy time, and the key generation status value of the authorization subject is updated. There are 5 authorization subjects to be processed in the authorization subject queue, and their sorting weight values ​​are 85.6, 92.3, 78.4, 88.9 and 82.1 respectively. The sequence is obtained by arranging in descending order.

[0028] [92.3,88.9,85.6,82.1,78.4], the corresponding authorization subject identifier is [B,D,A,E,C], and the sorting sequence number assigned accordingly is [1,2,3,4,5]. The base time interval value is set to 200 milliseconds, and the key generation time of each authorization subject is calculated according to the sorting sequence number. The generation time of authorization subject B is the base time point plus 200 milliseconds, D is the base time point plus 400 milliseconds, A is the base time point plus 600 milliseconds, and so on. This incremental time allocation ensures that high-priority authorization subjects get earlier processing time. In the resource allocation link, the resource occupation time of each authorization subject is determined according to its priority. The authorization subject with priority 1 is allocated 150 milliseconds, the authorization subject with priority 2 is allocated 120 milliseconds, and the authorization subject with priority 3 is allocated 100 milliseconds. A binary heap structure is used for resource block allocation. The nodes of the heap record the authorization subject identifier, start time and end time. The heap operation ensures that there is no time overlap in resource block allocation. The resource allocation record table shows the detailed allocation: the authorized subject B occupies 0-150 milliseconds, with a priority attribute value of 90; D occupies 200-320 milliseconds, with a priority attribute value of 85; A occupies 400-500 milliseconds, with a priority attribute value of 82. The resource occupancy mark is represented by binary bits, with the occupied state being 1 and the idle state being 0. Each time slice corresponds to a mark bit. In the identifier mapping relationship, the corresponding relationship between the authorized subject identifier and the sorting sequence number is established: {B:1, D:2, A:3, E:4, C:5}, and the key generation status is recorded at the same time, with the pending generation status recorded as 0, the generating status recorded as 1, and the generation completion status recorded as 2. Through this mapping relationship, the key generation task executor can schedule the key generation operation in a strict order. The final key generation process is executed according to the schedule of the resource allocation record table. When the key generation of authorized subject B is completed, its status value is updated to 2, and the key generation task of authorized subject D is triggered at the same time. Through strict time control and status management, the key generation operations of multiple authorized subjects are ensured to be carried out in an orderly manner, avoiding resource competition and time conflicts. This weight-based dynamic sorting mechanism not only ensures the processing advantage of high-priority authorized subjects, but also improves the overall processing efficiency through reasonable time allocation.

[0029] Step S104, during the key generation process, obtain the identity information and timestamp of the authorized subject, and use the identity information and timestamp of the authorized subject as the initial parameters of the chaotic public key encryption algorithm, generate a chaotic feature sequence through the chaotic algorithm, and use the chaotic feature sequence to generate the initial value or iteration parameter of the key.

[0030] The hardware serial number of the authorized subject is read from the identity authentication center, and an identity feature identification code is generated according to the hardware serial number and identity feature data, and the identity feature identification code is verified by the identity authentication center; the identity feature identification code is segmented and extracted, and the identity feature identification code and the timestamp sequence are feature mapped by a hyperbolic tangent function to obtain a time feature sequence; control parameters are extracted according to the time feature sequence, and the control parameters are iteratively calculated by a Logistic chaotic mapping equation, and combined with the identity feature identification code to obtain a chaotic feature sequence; nonlinear function mapping is performed on the chaotic feature sequence to obtain the initial parameters of the key.

[0031] Specifically, the hardware serial number of the authorized subject is read from the identity authentication center, and the identity feature identification code is generated in combination with the identity feature data submitted by the authorized subject. The identity feature identification code is compared with the preset identity authentication threshold to determine the identity authentication result. According to the identity authentication pass mark, the identity feature identification code of the authorized subject is segmented and extracted, and a time feature sequence is generated in combination with the current timestamp. The time feature sequence is mapped and transformed using the hyperbolic tangent function. The control parameters are extracted from the time feature sequence, and iterative calculations are performed based on the Logistic chaotic mapping equation. The iterative results are combined with the identity feature identification code to generate a chaotic feature sequence. According to the chaotic feature sequence, the corresponding mapping function is read from the preset parameter mapping rule library, and the chaotic feature sequence is mapped by a nonlinear function to obtain the initial key parameters. The iterative function is constructed through the initial key parameters, and a fixed-length key sequence is generated using the Henon chaotic mapping. The key generation seed value is calculated based on the key sequence. The key generation seed value is processed in blocks, and the key block parameters are set in combination with the priority information of the authorized subject to generate the final key iteration parameter sequence. The identity authentication center obtains the 32-bit hardware serial number from the authorized subject, such as "A7B9C4D2E8F1G3H5", splits it into 4 8-bit subsequences, and performs an XOR operation on each subsequence with the identity feature data. The identity feature data contains a combination of the device MAC address, CPU serial number, and hard disk serial number, and generates a 256-bit identity feature identification code through the SHA-256 hash algorithm. The identity authentication threshold is set at a similarity of more than 0.85, and the verification result is judged by calculating the Hamming distance. The time feature sequence is generated using the timestamp segmentation method, taking the last 8 digits of the current timestamp "1640995200123", and taking each 2 digits as a group to obtain 4 groups of values.

[0032] [00,12,31,23]. The hyperbolic tangent function tanh(x) normalizes and maps these values ​​and converts them to the interval [-1,1] to obtain the mapping sequence [-0.761,0.423,0.892,-0.156]. The Logistic chaotic mapping uses the equation Xn+1=μXn(1-Xn), the control parameter μ is 3.99, and the first value of the time feature sequence -0.761 is used as the initial value X0, and 20 iterations are performed. The output of each iteration is modulo-added with the corresponding bit of the identity feature identification code to generate a chaotic feature sequence with a length of 256 bits. The nonlinear function mapping uses a piecewise function. When the value of the chaotic feature sequence element is less than 0.5, the square function f(x)=x is used. 2 , when it is greater than 0.5, the exponential function f(x)=ex-1 is used. The mapped sequence is used as the initial key parameter, and each 32 bits constitute a parameter block. Henon chaotic mapping uses a two-dimensional iterative equation, Xn+1=1-aXn2+Yn, Yn+1=bXn, parameters a=1.4, b=0.3, and Xn+1 is the iteration value of the n+1th step. The first two values ​​of the initial key parameters are used as the initial points (X0, Y0), and 128 groups of two-dimensional point pairs are iteratively generated. The x coordinates of these point pairs are extracted, and a 256-byte key sequence is obtained through linear transformation. The key generation seed value is obtained by performing group XOR operations on the key sequence, one group for each 32 bytes, and finally an 8-byte seed value is generated. Different block parameters are set according to the priority information of the authorized subject. Authorization subjects with a priority of 1 use 8-byte key blocks, those with a priority of 2 use 16-byte key blocks, and those with a priority of 3 use 32-byte key blocks. This block strategy is closely related to the generation of the key iteration parameter sequence. Authorization subjects with a higher priority obtain more fine-grained key control.

[0033] Step S105, after the key generation is completed, the new key is distributed to the corresponding authorized object, and the key status table is updated to record the timestamp and authorized subject information of this key update, and the key update process is triggered regularly.

[0034] A key distribution data packet is generated according to the key content and the authorized subject identification code, and the key distribution data packet is sent to the authorized subject through an encrypted channel; a key status item is created in the key status record library for the digital signature information returned by the authorized subject, and the key status item includes the key identification code, the authorized subject identification code, the distribution timestamp and the key validity period; according to the monitoring mark in the key status item, the key update cycle value of the authorized subject is read from the preset key validity parameter table to obtain the next key update time point; if the timing scanner reads the due task record in the key update planning table, a key update trigger instruction is generated, and the key update trigger instruction is used to start a new round of key generation process.

[0035] Specifically, the newly generated key content is read from the key generator, and a key distribution data packet is generated in combination with the authorized subject identification code. The key distribution data packet is sent to the authorized subject through an encrypted channel, and the distribution completion status is judged based on the digital signature information returned by the authorized subject. For the key that has been distributed, a key status item is created in the key status record library, and the key identification code, the authorized subject identification code, the distribution timestamp and the key validity period are recorded to generate a key status monitoring mark. According to the key status monitoring mark, the preset key validity parameter table is read, the key update cycle value of the corresponding authorized subject is extracted, and the next key update time point is calculated. Using the time window sliding method, an update task record is created in the key update planning table, and the task execution timestamp and the authorized subject identification code are set. The expired task record in the key update planning table is read by a timed scanner, and the authorized subject update parameter set is extracted. A key update trigger instruction is generated based on the update parameter set, and the original key status item is marked as updated. An update trigger instruction is sent to the key generator to start a new round of key generation process, and the original key status information is saved in the key history record table. The key distribution data packet is constructed in a standard format, including 256-bit key content, 32-bit authorized subject identification code and 64-bit timestamp. RSA asymmetric encryption is used to encrypt the data packet for transmission. After receiving the key, the authorized subject uses the private key to generate a digital signature for the receipt confirmation information. The signature uses the SHA-256 algorithm to generate a message digest, and then encrypts the digest with the private key to obtain the digital signature value. The key status item records the complete life cycle information of the key. The identification code uses the UU ID format to generate a 32-bit unique identifier, and the distribution timestamp is recorded to the millisecond level, such as "1640995200123". The key validity period is set according to the security level of the authorized subject. The highest level is 24 hours, the intermediate level is 12 hours, and the basic level is 6 hours. The status monitoring mark uses binary bits to represent different states. 0x01 means distributed, 0x02 means in use, and 0x04 means expired. In the key validity parameter table, different update cycles are set for authorized subjects of different security levels, such as the highest level is updated every 12 hours, the intermediate level is updated every 6 hours, and the basic level is updated every 3 hours. The update time point is calculated by adding the base time to the offset. The base time is selected as 0 o'clock on the day, and the offset is an integer multiple of the update cycle. The time window sliding method uses a fixed-size time window, and the window size is set to 1 hour. When an update task is detected in the window, the update preparation is triggered 5 minutes in advance. The update task record contains fields such as task number, execution time, and authorized subject information. It is stored in a priority queue, and high-priority tasks are executed first. The scheduled scanner scans the update planning table every 1 minute to extract the update tasks that need to be executed in the last 10 minutes. The update parameter set contains information such as the security level of the authorized subject, historical update records, and current key status.The update trigger instruction is delivered through the message queue, and the message body contains the detailed parameters of the update task. Before the original key status record is transferred to the history table, the update timestamp and update reason code are added. The history table retains the update records of the last 7 days for analyzing the key update mode and optimizing the update strategy. Through this time window-based update mechanism, combined with the differentiated configuration of the authorized subject, the automatic update and status tracking of the key are realized.

[0036] Step S106, real-time monitoring of the system security status, dynamic calculation of the key update frequency adjustment range, generation of key update frequency parameters, calculation of the key conflict judgment threshold adjustment range, generation of update threshold parameters, writing the key update frequency parameters and update threshold parameters into the system configuration file, triggering dynamic adjustment of the key update frequency and conflict judgment threshold, and after the adjustment is completed, monitoring and recording the system security status change data.

[0037] A cyclic monitor is used to obtain the operating status data of the processor load rate, memory occupancy rate and network throughput, and the security situation characteristics are extracted through a convolutional neural network to obtain a performance indicator matrix; according to the performance indicator matrix, the ratio of the number of key conflicts to the total number of key generation times in a fixed-size time window is counted to obtain a key conflict rate value; an adjustment coefficient is calculated based on the comparison result of the key conflict rate value with a preset benchmark value, and a frequency parameter is linearly transformed by the adjustment coefficient to obtain a new frequency parameter; if the new frequency parameter passes the parameter consistency verification rule, the new frequency parameter is written into a configuration parameter table, and the adjustment timestamp of the new frequency parameter is recorded in an adjustment record table.

[0038] Specifically, a cyclic monitor is used to read the operation status data, and the processor load rate, memory occupancy rate, and network throughput within a specified time period are sampled. The security situation features are extracted through a convolutional neural network to generate a performance indicator matrix. According to the performance indicator matrix, the current key conflict rate is calculated, and the number of key conflicts per unit time is divided by the total number of key generation using a fixed-size time window to obtain the conflict rate value. The conflict rate value is compared with the preset benchmark value, and the key update frequency adjustment coefficient is calculated based on the comparison result. The current frequency parameter is linearly transformed by the adjustment coefficient. For the transformed frequency parameter, the maximum and minimum limit intervals are set, and the parameter values ​​exceeding the interval are truncated to generate a new frequency parameter value. The exponential smoothing method is used to calculate the adjustment amount of the conflict judgment threshold, and a new threshold parameter value is generated in combination with the historical adjustment record. The newly generated frequency parameter value and the threshold parameter value are checked for parameter consistency, and the validity of the parameter is judged by the verification rule. The parameters that pass the verification are written into the configuration parameter table, and the parameter change information is recorded in the adjustment record table, including the adjustment timestamp, the parameter value before adjustment, and the parameter value after adjustment. The parameter monitoring program is started, the updated performance data is collected, and the performance comparison data before and after the parameter adjustment is recorded in the monitoring log table. During the performance data sampling process, system status data is collected every 10 seconds, including a processor load rate of 75%, a memory occupancy rate of 60%, and a network throughput of 150MB / s. The sampled data constitutes a 32x32 feature map, and feature extraction is performed through a 3-layer convolutional neural network with a convolution kernel size of 3x3 and a step size of 1, resulting in a performance indicator matrix containing 8 dimensions. The key conflict rate is calculated using a fixed time window of 60 minutes, and the total number of key generation and the number of conflicts are counted within the window. For example, if the total number of key generation in the current time window is 1200 times and there are 48 conflicts, the calculated conflict rate is 4%. The preset baseline conflict rate is 3%. When the actual conflict rate exceeds the baseline value, the parameter adjustment mechanism is triggered. The frequency adjustment coefficient is calculated using a linear mapping method to map the difference between the conflict rate and the baseline value to the interval [0.8,1.2]. When the conflict rate is 4%, the difference is 1%, and the mapping results in an adjustment coefficient of 1.1. The current update frequency is 6 times per hour, which increases to 6.6 times per hour after adjustment. The limit interval of the frequency parameter is set to [4,12], and values ​​outside this range will be truncated. The adjustment of the conflict judgment threshold adopts the exponential smoothing formula, Yt=αXt+(1-α)Yt-1, where α is the smoothing coefficient 0.3, Xt is the current calculated adjustment amount, and Yt-1 is the last adjustment result. If the current calculated adjustment amount is 5ms, and the last adjustment result is 8ms, then the adjustment result after smoothing is 7.1ms. The parameter consistency verification rules include three aspects: the ratio of the frequency parameter to the threshold parameter should be within the range of [1.5,3]; the parameter adjustment range should not exceed 30% of the current value; the fluctuation trend of the new parameter should be consistent with that of the historical parameter.The parameters that have passed the verification are written into the configuration table, and the record format is "parameter type: frequency parameter, value before adjustment: 6.0, value after adjustment: 6.6, timestamp: 1640995200". The performance comparison data collection lasts for 30 minutes, and the comparison data includes indicators such as system throughput, response time, and resource utilization before and after adjustment. After the parameter adjustment, the system throughput increased from 150MB / s to 165MB / s, the average response time decreased from 85ms to 78ms, and the resource utilization remained at around 65%. Through this dynamic parameter adjustment mechanism based on real-time monitoring, system performance is continuously optimized. The monitoring log table retains the adjustment records of the last 7 days for analyzing the long-term effects of parameter adjustments.

[0039] Step S107, audit and record all actions in the key coordination process, including trigger conditions, chaotic mapping and encryption parameters, sorting results, key distribution and update, and continuously improve the process.

[0040] Acquire coordination process data from a key coordinator, the coordination process data including an authorized subject identification code, a resource request time, and a conflict mark value, and generate a coordination process record based on the coordination process data; extract chaotic mapping algorithm operating parameters for the coordination process record, the chaotic mapping algorithm operating parameters including an initial seed value and a control variable value, and obtain a chaotic mapping process record using the chaotic mapping algorithm operating parameters; perform priority calculation on the authorized subject based on the chaotic mapping process record, use a weighted sum method to process historical behavior values ​​and current state values ​​in the chaotic mapping process record, and obtain a priority sorting table; after receiving a key distribution request, allocate key resources based on the priority sorting table, record the distribution timestamp and the authorized subject number, and obtain a key state tracking record.

[0041] Specifically, the coordination process data including the authorized subject identification code, resource request time, conflict mark value, and coordination trigger condition are collected from the key coordinator, and a coordination process record file is generated and written into the key coordination database. Based on the coordination process record file, the operating parameters of the chaotic mapping algorithm are extracted, including the initial seed value, the control variable value, and the number of iteration rounds, and a chaotic mapping process record is generated. According to the chaotic mapping process record, the priority score of the authorized subject is calculated, and the historical behavior value and the current state value are combined by the weighted summation method to generate a priority sorting table. Through the priority sorting table, the key distribution task is executed, the distribution timestamp, the authorized subject number, and the key identification code are recorded, and the key distribution record is generated. For the key distribution record, the key validity period value is calculated in combination with the security level of the authorized subject, and the key status tracking record is generated. The key status tracking record is counted by a data analyzer, and the key update frequency value, conflict occurrence rate, and distribution success rate are calculated to generate a performance statistical report. Based on the performance statistical report, key performance indicators are extracted, performance benchmark values ​​are set, and warning signals are generated for indicators that exceed the benchmark range. According to the warning signal, the coordination process record of the corresponding period is read, the abnormal cause is analyzed, and the key coordination parameter configuration table is updated. The key coordination process record contains multiple key fields. The authorization subject identification code is represented by a 16-bit hexadecimal number, such as "A5B2C3D4E6F78901", the resource request time is accurate to milliseconds, such as "1640995200123", and the conflict mark value uses binary bits to represent different types of conflicts, such as "1010"

[0042] Indicates time conflict and priority conflict. The trigger condition field records the specific reason for triggering coordination, such as resource competition exceeding 80%. The chaotic mapping parameters use the Logistic equation. The initial seed value is obtained by normalizing the timestamp, such as 0.6234. The control variable value is set to 3.99, and the number of iterations is 20. The output value of each iteration is recorded to form a chaotic sequence.

[0043] [0.837, 0.546, 0.990, 0.040, 0.153...], which is used for subsequent randomization. The priority score is calculated using a weighted summation method, with the historical behavior value weighted at 0.6 and the current state value weighted at 0.4. The historical behavior value includes indicators such as the frequency of key usage, number of conflicts, and response time in the past 24 hours, and the current state value includes indicators such as resource occupancy, request priority, and waiting time. The historical behavior value of an authorized subject is 85 points, and the current state value is 92 points. The final priority score is calculated to be 87.8 points. The key distribution record records each link of the distribution process in detail, including the sending time "2023-12-

[0044] 1610:30:45.123", the receiving confirmation time is "2023-12-1610:30:45.456", and the transmission time is 333 milliseconds. The key identification code is UU ID format, such as "550e8400-e29b-41d4-a716-446655440000". Combined with the security level of the authorized subject, it is divided into 1 / 2 / 3 levels, and the key validity period is set. Level 1 is 24 hours, level 2 is 12 hours, and level 3 is 6 hours. Performance statistics show that in the past hour, the average key update frequency was 6 times / hour, the conflict rate was 3.5%, and the distribution success rate reached 99.8%. The performance benchmark value is set to an update frequency of 4-8 times / hour, a conflict rate of less than 5%, and a distribution success rate of more than 99%. When the conflict rate is detected to continue to rise within 10 minutes, from 2.8% to 4.2%, an early warning signal is generated. By analyzing the coordination process records during the early warning period, it is found that the main reason is that multiple high-priority authorized subjects request resources at the same time in a certain period of time. The time window parameter in the coordination parameter configuration table is adjusted from the original 200 milliseconds to 300 milliseconds, and the weight of the historical behavior value in the weight calculation formula is adjusted from 0.6 to 0.7. The optimized conflict rate is reduced to 2.8%.

[0045] Based on the above embodiments of the present invention, relevant personnel can make various changes and modifications without departing from the technical concept of the present invention through the above description. The technical scope of the present invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.

Claims

1. A company information encryption method combined with a chaotic public key encryption algorithm, characterized in that: The method comprises: When several devices request to access the same server, the priority information of the device to be accessed is compared with the preset authorization subject priority list. If the priority of the device to be accessed matches the first priority level in the list, the device to be accessed is determined to be an authorization subject of the first priority level. If it matches the second priority level, the device to be accessed is determined to be an authorization subject of the second priority level, and a corresponding key is generated according to the priority level of the authorization subject. Compare the time difference between the key generation of the first priority authorization subject and the second priority authorization subject. If the time difference is less than the preset time difference threshold, generate a set of pseudo-random number sequences as sorting weights according to the priority level of the authorization subject and the historical key generation timestamp; According to the sorting weights, the authorized subjects are sorted to determine the key generation order of the authorized subjects in this key conflict coordination process; In the key generation process, the identity information and timestamp of the authorized subject are obtained, and the identity information and timestamp of the authorized subject are used as the initial parameters of the chaotic public key encryption algorithm, a chaotic feature sequence is generated through the chaotic algorithm, and the chaotic feature sequence is used to generate the initial value or iteration parameter of the key; After the key generation is completed, the new key is distributed to the corresponding authorized object, and the key status table is updated to record the timestamp and authorized subject information of this key update, and the key update process is triggered regularly; Monitor the system security status in real time, dynamically calculate the key update frequency adjustment range, generate the key update frequency parameter, calculate the key conflict judgment threshold adjustment range, generate the update threshold parameter, write the key update frequency parameter and the update threshold parameter into the system configuration file, trigger the dynamic adjustment of the key update frequency and the conflict judgment threshold, and after the adjustment is completed, monitor and record the system security status change data; Audit and record all actions in the key coordination process, including trigger conditions, chaos mapping and encryption parameters, sorting results, key distribution and updates, and continuously improve the process.

2. The method according to claim 1, characterized in that When several devices request to access the same server, the priority information of the device to be accessed is compared with the preset authorization subject priority list. If the priority of the device to be accessed matches the first priority level in the list, the device to be accessed is determined to be an authorization subject of the first priority level. If it matches the second priority level, the device to be accessed is determined to be an authorization subject of the second priority level, and a corresponding key is generated according to the priority level of the authorization subject, including: Obtaining a device identification code and an access timestamp for the access device, and performing similarity calculation between the device identification code and a pre-stored device feature library to obtain a device authentication pass mark; Read the historical access records within a preset time window according to the device authentication pass mark, and obtain the device access frequency value and device priority score by counting the number of accesses; Matching the device priority score with the authorization subject priority rule base, and determining the device as a first priority authorization subject if the priority score is within the first priority interval; The key generation reference value is obtained from a preset key generation rule library using the authorization subject priority level, a device access key is generated according to the key generation reference value, and the authorized access server area is determined by the device access key.

3. The method according to claim 1, characterized in that The method compares the time difference between the key generation of the first priority authorization subject and the second priority authorization subject. If the time difference is less than a preset time difference threshold, a set of pseudo-random number sequences are generated according to the priority level of the authorization subject and the historical key generation timestamp as the sorting weight, including: Read the key generation timestamps of the first authorized subject and the second authorized subject from the key generation record library, calculate the time difference value through the timestamps, and obtain the key conflict mark according to the comparison between the time difference value and the preset time difference threshold; According to the key conflict mark, obtain the historical key generation time records of the first authorized subject and the second authorized subject from the timestamp record table, and calculate the average key generation time interval based on the historical key generation time records; The average key generation time interval is iteratively calculated using a Logistic chaotic mapping equation, and a normalized pseudo-random number sequence is generated for the first authorized subject and the second authorized subject respectively; A comprehensive weight score is calculated based on the normalized pseudo-random number sequence, the first authorization subject priority level value, and the second authorization subject priority level value.

4. The method according to claim 1, characterized in that: The step of sorting the authorized subjects according to the sorting weights and determining the key generation order of the authorized subjects in the key conflict coordination process includes: Acquire a set of authorization subject identifiers to be sorted from the authorization subject queue, and arrange the set of authorization subject identifiers in descending order according to sorting weight values ​​to obtain an authorization subject sequence list; Read the reference time interval value in the time window configuration table according to the sorting sequence number in the authorization subject sequence table, and obtain the key generation time by multiplying the sorting sequence number by the reference time interval value; According to the key generation time and the sorting sequence number, a binary heap structure is used to allocate resource blocks to the authorized subject to obtain a resource occupation sequence; If the resource occupation sequence includes an authorized subject, the priority attribute value of the authorized subject is read, a resource occupation mark is set according to the priority attribute value, and a key conflict coordination sorting result record is generated.

5. The method according to claim 1, characterized in that In the key generation process, the identity information and timestamp of the authorized subject are obtained, and the identity information and timestamp of the authorized subject are used as the initial parameters of the chaotic public key encryption algorithm, a chaotic feature sequence is generated by the chaotic algorithm, and the chaotic feature sequence is used to generate the initial value or iteration parameter of the key, including: Read the hardware serial number of the authorized subject from the identity authentication center, generate an identity feature identification code based on the hardware serial number and identity feature data, and the identity feature identification code is verified by the identity authentication center; Segmented extraction is performed on the identity feature identification code, and feature mapping is performed on the identity feature identification code and the timestamp sequence using a hyperbolic tangent function to obtain a time feature sequence; Extracting control parameters according to the time characteristic sequence, performing iterative operation on the control parameters using a Logistic chaotic mapping equation, and combining the control parameters with the identity characteristic identification code to obtain a chaotic characteristic sequence; Nonlinear function mapping is performed on the chaotic characteristic sequence to obtain initial key parameters.

6. The method according to claim 1, characterized in that After the key generation is completed, the new key is distributed to the corresponding authorized object, and the key status table in the update is updated to record the timestamp and authorized subject information of this key update. At the same time, the key update process is triggered regularly, including: Generate a key distribution data packet according to the key content and the authorized subject identification code, and send the key distribution data packet to the authorized subject through an encrypted channel; A key status item is created in the key status record library for the digital signature information returned by the authorization subject, wherein the key status item includes a key identification code, an authorization subject identification code, a distribution timestamp, and a key validity period; According to the monitoring mark in the key status item, the key update period value of the authorized subject is read from the preset key validity parameter table to obtain the next key update time point; If the timing scanner reads the expired task record in the key update planning table, a key update trigger instruction is generated, and the key update trigger instruction is used to start a new round of key generation process.

7. The method according to claim 1, characterized in that The system security status is monitored in real time, the key update frequency adjustment range is dynamically calculated, the key update frequency parameter is generated, the key conflict judgment threshold adjustment range is calculated, the update threshold parameter is generated, the key update frequency parameter and the update threshold parameter are written into the system configuration file, and the dynamic adjustment of the key update frequency and the conflict judgment threshold is triggered. After the adjustment is completed, the system security status change data is monitored and recorded, including: A cyclic monitor is used to obtain the operating status data of processor load rate, memory occupancy rate and network throughput, and a convolutional neural network is used to extract security situation features to obtain a performance indicator matrix; According to the performance indicator matrix, a ratio of the number of key conflicts to the total number of key generation times within a fixed-size time window is counted to obtain a key conflict rate value; An adjustment coefficient is calculated based on the comparison result of the key conflict rate value and a preset reference value, and a new frequency parameter is obtained by linearly transforming the frequency parameter using the adjustment coefficient; If the new frequency parameter passes the parameter consistency check rule, the new frequency parameter is written into the configuration parameter table, and the adjustment timestamp of the new frequency parameter is recorded in the adjustment record table.

8. The method according to claim 1, characterized in that: The audit and record of all actions in the key coordination process, including trigger conditions, chaos mapping and encryption parameters, sorting results, key distribution and updates, and continuous process improvement, including: Acquire coordination process data from the key coordinator, the coordination process data including the authorized subject identification code, resource request time, and conflict mark value, and generate a coordination process record according to the coordination process data; Extracting chaotic mapping algorithm operation parameters from the coordination process record, wherein the chaotic mapping algorithm operation parameters include an initial seed value and a control variable value, and obtaining a chaotic mapping process record by using the chaotic mapping algorithm operation parameters; Calculating the priority of the authorized subject according to the chaotic mapping process record, processing the historical behavior value and the current state value in the chaotic mapping process record by a weighted summation method, and obtaining a priority ranking table; After receiving the key distribution request, key resources are allocated according to the priority sorting table, the distribution timestamp and the authorization subject number are recorded, and the key status tracking record is obtained.

Citation Information

Patent Citations

  • Controller encryption method based on chaotic sequence

    CN114598445A

  • Compression transmission method and device of power data, terminal equipment and storage medium

    CN117395719A

  • Multi-user QKD system and method with priority ranking function

    CN117879805A

  • QR code encryption and decryption method and system based on chaos theory and AES algorithm

    CN119094102A

Cited By

  • Intelligent conference control method and system based on multi-mode perception and quantum encryption

    CN120602241A

  • Cloud mobile phone equipment fingerprint disguising method and related equipment

    CN120768541A

  • Safe and credible interaction method for photovoltaic data

    CN120811799A