Hierarchical data storage and encrypted transmission method and system based on quantum key
Patent Information
- Application Number
- CN202510503578.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-22
AI Technical Summary
When responding to quantum computing attacks and dynamic network environments, the existing technology lacks a mechanism to divide hierarchical levels according to the importance of data, resulting in the inability to dynamically adapt the security protection strength of core data and ordinary data, and there are resource waste and security risks.
A hierarchical data storage and encryption transmission method based on quantum key is proposed. By dividing the data into three encryption levels in real time, it is possible to dynamically calculate the security intensity value based on data sensitivity, network threat level and quantum key entropy value, and dynamically select the encrypted transmission path and storage strategy.
It realizes the accurate matching of encryption strength and data importance, avoids the risk of quantum computing attacks due to excessive dependence on traditional encryption, and prevents the waste of resources caused by redundant encryption of ordinary data, improving the system's anti-attack capability and data integrity verification efficiency in complex network environments.
Smart Images

Figure CN120034331A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a quantum key-based hierarchical data storage and encryption transmission method and system. Background Art
[0002] At present, with the increasing demand for data security, the limitations of traditional encryption technology in dealing with quantum computing attacks and dynamic network environments are gradually emerging. In the existing technology, data encryption and transmission mostly use encryption algorithms with a single security level, and lack a mechanism to divide the levels according to the importance of data, resulting in the inability to dynamically adapt the security protection strength of core data and ordinary data, which not only wastes resources but also poses security risks. At the same time, the selection of network transmission paths is usually based on single indicators such as bandwidth or latency, and the real-time availability of quantum keys, network threat levels, and data sensitivity are not included in the comprehensive evaluation system, making it difficult to ensure the reliability and anti-eavesdropping of quantum encryption channels in high-threat environments. In addition, the storage link generally adopts a unified storage node, and does not design differentiated storage strategies for data of different security levels. For example, core confidential data lacks physical isolation protection for quantum state offline storage, sensitive data lacks a redundant verification mechanism based on hybrid hashing, and the distributed storage of ordinary data does not form a closed-loop linkage with the encryption level, resulting in low efficiency of data integrity verification and vulnerability to man-in-the-middle attacks. Summary of the invention
[0003] In view of this, the present invention proposes a hierarchical data storage and encrypted transmission method and system based on quantum keys, which can design differentiated storage strategies for data of different security levels and dynamically select the most appropriate encrypted transmission path to ensure data security and transmission efficiency. The present invention provides the following technical solutions: A hierarchical data storage and encryption transmission method based on quantum keys, the method comprising: receiving the original data set in real time, and dividing it into at least three encryption levels according to the importance and security requirements of the original data in the original data set; The original data of different encryption levels are encrypted using corresponding encryption keys; According to the security level of the encryption layer of the original data and the network status parameters, different encryption transmission paths are dynamically selected to complete the encrypted transmission of the encrypted data; The corresponding encrypted data is stored in the corresponding storage node according to the encryption level.
[0004] Optionally, the receiving of the original data set in real time and dividing the original data in the data set into at least three encryption levels according to the importance and security requirements of the original data in the data set includes: Receive raw data in real time and obtain the sensitivity parameters of the data in real time based on the content and label information of the raw data ; Dynamically detect the network threat level parameter based on the attack event frequency and abnormal traffic data of the current network ; Call the quantum key and calculate the randomness strength of the quantum key, i.e., the quantum key entropy value, through Shannon entropy , and the calculation formula is: , where is the probability of the th bit in the quantum key; Based on the sensitivity parameter , network threat level parameter and quantum key entropy value calculate the security strength value , and the calculation formula is: , where is a preset security threshold coefficient; Compare the security strength value with the preset hierarchical threshold and . Specifically: If , then divide the current original data into the ordinary level; If , then divide the current original data into the sensitive level; If , then divide the current original data into the core level.
[0005] Optionally, encrypt the original data at different encryption levels using the corresponding encryption keys, including: Generate the first traditional symmetric key through a quantum random number generator , and encrypt the ordinary level data; Generate a quantum key through the quantum key distribution protocol , and at the same time generate the second traditional key , and generate a mixed key through a hash function: , and use the mixed key to encrypt the sensitive level data: , where is a symmetric encryption algorithm, is a quantum-resistant hash function; Generate a quantum key through the quantum key distribution protocol , and encrypt the core layer data using the quantum direct communication protocol: , where is a quantum direct communication encryption function.
[0006] Optionally, dynamically selecting different encrypted transmission paths according to the security level of the encryption level of the original data and the network status parameters to complete the encrypted transmission of the encrypted data includes: For each available transmission path Calculate its comprehensive score , the formula is: ,in, , , and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path Node transmission delay; The only allowed path constraint type at the core level is the quantum encryption channel, denoted by , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; The constraint types of the allowed paths of the sensitive level include quantum encryption channels and hybrid encryption channels ,when When selecting the quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, , , are not the same, and Greater than , Greater than ; The only allowed path constraint type for the normal layer is the traditional encrypted channel ; In the Constraint type field for the path, select Comprehensive scoring. The largest path , and through the path Complete the encrypted transmission of encrypted data.
[0007] Optionally, the method further comprises: Building redundant paths for path switching ; Calculate the selected path Real-time ratings ,like , dynamic path switching is triggered to select a redundant path Complete the encrypted transmission of encrypted data, where: is the initial score, is the preset adjustment factor.
[0008] Optionally, storing the corresponding encrypted data in the corresponding storage node according to the encryption level includes: The core level data is stored in quantum offline storage nodes in the form of quantum states. ; The sensitive level data is stored in the edge node through local encryption ; The common level data is stored in a distributed manner on cloud nodes ; By random number Determine the shard storage nodes for the core-level data: ; Through hash function Determine the shard storage nodes for sensitive level data: .
[0009] Optionally, the method further comprises: Constructing redundant storage nodes for the core-level data , the redundant storage node The selection rules are: ,in For Node The quantum key availability parameter, is the node transmission delay; Construct redundant storage nodes for the sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's attached label is ,in, is a hybrid hash function; Constructing redundant storage nodes for the common level data , the common level data is distributed and stored in at least five redundant storage nodes The node's accompanying label is ,in, It is a traditional hash function.
[0010] The present invention further discloses a quantum key-based hierarchical data storage and encryption transmission system, comprising: An encryption level division module, used for receiving the original data set in real time, and dividing the original data in the original data set into at least three encryption levels according to the importance and security requirements of the original data; An encryption module is used to encrypt the original data of different encryption levels using corresponding encryption keys; The encryption transmission module is used to dynamically select different encryption transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encryption transmission of the encrypted data; The encryption storage module is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level.
[0011] The present invention further discloses a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program implements the above method when executed by a processor.
[0012] The present invention further discloses an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above method when executing the program.
[0013] According to the technical solution of the present invention, by constructing a hierarchical data storage and encryption transmission method based on quantum keys, by dividing data into three encryption levels of ordinary, sensitive, and core in real time, and dynamically calculating the security strength value based on data sensitivity, network threat level and quantum key entropy value, a precise match between encryption strength and data importance is achieved, which not only avoids the risk of quantum computing attacks on core data due to over-reliance on traditional encryption, but also prevents the waste of resources caused by redundant encryption of ordinary data; in the selection of transmission paths, a comprehensive scoring mechanism is used to conduct multi-dimensional evaluation of the path's security risk, bandwidth, quantum key availability and latency, and combined with the mandatory constraint rules of the encryption level to ensure high security The demand data is transmitted through an eavesdropping-resistant quantum communication channel, and the transmission reliability is improved through a redundant path switching mechanism. In the storage link, by forcibly binding the encryption level and storage node type, and combining the sharding storage strategy, not only the dual protection of data integrity and availability is achieved, but also the quantum direct communication protocol is used to encrypt core data, and the layered adaptation of hybrid keys and traditional encryption is used to build a dynamic balance system between anti-quantum attack capabilities, transmission efficiency and storage security, and finally form a full-link dynamic security mechanism covering data encryption, transmission path selection, and storage protection, which significantly improves the system's anti-attack capabilities, resource utilization and data integrity verification efficiency in complex network environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] For the purpose of illustration and not limitation, the present invention is now described in conjunction with the embodiments of the present invention and the accompanying drawings, in which: Figure 1 It is a schematic flow chart of a method for storing and encrypting hierarchical data based on quantum keys in an embodiment of the present invention; Figure 2 It is a schematic diagram of the structure of a hierarchical data storage and encryption transmission system based on quantum keys in an embodiment of the present invention; Figure 3 It is a schematic diagram of the structure of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION
[0015] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the implementation mode of the present application will be clearly and completely described below in conjunction with the drawings in the implementation mode of the present application. Obviously, the described implementation mode is only a part of the implementation mode of the present application, not all the implementation modes. Based on the implementation mode in the present application, all other implementation modes obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present application.
[0016] It should be noted that, in the absence of conflict, the embodiments of the present application and the features in the embodiments can be combined with each other. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0017] refer to Figure 1 This embodiment discloses a hierarchical data storage and encryption transmission method based on quantum key, the method comprising: S100: receiving an original data set in real time, and dividing the original data set into at least three encryption levels according to the importance and security requirements of the original data in the original data set.
[0018] Specifically, the original data is received in real time through the data interface and the original data set is formed. The above data interface supports the input of multi-source heterogeneous data, such as IoT devices. Database or user terminal, and metadata tags are added to each piece of original data, including: data type, field, business priority, and the sensitivity parameters of the data are obtained in real time based on the content and tag information of the original data. The tag information includes the sensitivity of the current data and the corresponding basic weight. For example, the basic weight of high sensitivity is 0.8. The superposition weight is further dynamically set by detecting sensitive fields in the original data. For example, when financial fields such as credit cards are detected, the superposition weight is set to 0.2.
[0019] Secondly, the network threat detection module is used to collect the attack event frequency, abnormal traffic proportion and the alarm level of the intrusion detection system in real time. Based on the attack event frequency and abnormal traffic data of the current network, the network threat level parameters are dynamically detected. , the calculation formula is: ,in, is the number of attack events on the current network, is the abnormal traffic ratio, It is the alarm weight of the intrusion detection system. , , is a preset weight coefficient. Exemplary setting in this embodiment: high-risk alarm , medium-risk warning , low risk warning .
[0020] Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; Based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating the security strength value , the calculation formula is: ,in, is the preset safety threshold factor; The security strength value With the preset stratification threshold and For comparison, specifically: , the current raw data is divided into common levels; if , the current raw data is divided into sensitive levels; if , the current raw data is divided into core levels.
[0021] S200: Encrypting original data of different encryption levels using corresponding encryption keys.
[0022] For the generation of encryption keys, including: Generating the first conventional symmetric key via a quantum random number generator To ensure the randomness of the key, the common layer data is encrypted by the key. The encryption process is to encrypt the common layer data using the AES-256 algorithm.
[0023] Generating quantum keys through quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: ,in, The sensitive level data is encrypted using a quantum-resistant hash function such as SHA-3 using a hybrid key: ,in, is a symmetric encryption algorithm. It is a quantum-resistant hash function; Generate quantum keys through the quantum key distribution protocol , and use the quantum direct communication protocol to encrypt the core layer data: ,in, Encryption function for quantum direct communication.
[0024] This embodiment further discloses a dynamic key update mechanism, specifically, real-time calculation of the entropy value of the current quantum key ,like , then trigger the key update: , and update the affected data blocks based on the new key, where It is a quantum random number generator. At the same time, when the data level is affected by the threat level or quantum key availability When the key type is upgraded due to a change, such as upgrading from normal to sensitive, an update of the key type is triggered.
[0025] S300: Dynamically select different encrypted transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encrypted transmission of the encrypted data. Specifically, the system collects all available transmission paths in real time. Status parameters include: Obtain the security risk factor of the path through historical attack frequency, number of vulnerabilities, or IDS alarm records ; Obtain the current available bandwidth of the path through the network monitoring module ; The quantum key availability is constructed by the quantum key management module return path corresponding to the quantum key pool remaining amount and distribution success rate ; Use a path detection tool (such as ICMP or OWAMP) to measure the one-way delay of the path, that is, the node transmission delay .
[0026] After obtaining the above parameters, for each available transmission path Calculate its comprehensive score , the formula is: ,in, , , and is the dynamic weight coefficient.
[0027] Further enforce the path type based on the data encryption level, as follows: The only allowed path at the core level is of the quantum encryption channel type, denoted by , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; Constraint types for allowed paths at sensitive levels include quantum encrypted channels and hybrid encryption channels ,when When selecting the quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, , , are not the same, and Greater than , Greater than ; The only allowed path at the normal level has a constraint type of traditional encrypted channel ; In the Constraint type for the path, select Comprehensive scoring The largest path , and through the path Complete the encrypted transmission of encrypted data. That is, for the core layer, only and Select the highest quantum encryption channel Corresponding path; for sensitive levels, in the allowed quantum encryption channel and hybrid encryption channels Select the highest path Corresponding path; for the ordinary layer, directly select the traditional encryption channel , no additional constraints are required.
[0028] Furthermore, redundant paths are constructed for path switching. ; Calculate the selected path Real-time ratings ,like , dynamic path switching is triggered to select a redundant path Complete the encrypted transmission of encrypted data, where: is the initial score, is the preset adjustment coefficient. When switching, the quantum encryption channel achieves seamless switching through quantum entanglement backup, and the hybrid / traditional channel is completed through traditional redundant protocols (such as IP routing switching).
[0029] This embodiment further discloses the comprehensive score The calculation is based on the real-time threat level and global quantum key availability Recalculate , the calculation formula is: , is the preset adjustment coefficient, for weight , and , allocated through the remaining proportion and set by the user according to needs.
[0030] In this embodiment, if the availability of the quantum key is detected A significant decline, e.g. , then temporarily reduce the quantum channel activation threshold of the sensitive level , for example, from 0.5 to 0.4 to release core-level resources.
[0031] This embodiment exemplifies a core data transmission process: Execution path parameter collection: Quantum encryption channel : , , , ; Traditional Channel : , .
[0032] Path constraints and score calculation: Core Data Force Selection , only when satisfy and ; calculate Rating .
[0033] Constructing redundant paths: like The delay suddenly increases to , triggering the redundant path , through the formula Select another quantum channel .
[0034] S400: Storing corresponding encrypted data in corresponding storage nodes according to the encryption level.
[0035] The core level data is stored in quantum offline storage nodes in the form of quantum states. , offline isolation is achieved through quantum memory or photon storage media; random numbers are used Determine the shard storage nodes for the core-level data: ; The sensitive level data is stored in the edge node through local encryption ; Through the hash function Determine the shard storage nodes for sensitive level data: .
[0036] The common level data is stored in a distributed manner on cloud nodes ; Through traditional hash functions Determine where the shards are stored: .
[0037] Furthermore, redundant storage nodes for the core data are constructed. , the redundant storage node The selection rules are: ,in For Node The quantum key availability parameter, is the node transmission delay; Construct redundant storage nodes for the sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's attached label is ,in, is a hybrid hash function; Constructing redundant storage nodes for the common level data The common level data is distributed and stored in at least five redundant storage nodes. The node's accompanying label is ,in, It is a traditional hash function.
[0038] After the encrypted data is stored in the corresponding storage node, the integrity of the encrypted data is periodically verified. The verification trigger is implemented through a preset period (such as every minute) or event trigger (such as data update). The specific verification steps include: Read data shards from storage nodes and its labels (core layer has no labels, sensitive / ordinary layers require labels), recalculate the hash chain verification value: for the core layer, directly verify the data integrity through quantum state measurement (no hash calculation is required), for the sensitive layer, calculate the mixed hash label ,like , the current data is considered damaged; for the normal level, calculate the traditional hash tag ,like , then the current data is determined to be damaged.
[0039] For sensitive and common data, the integrity of the current data block is verified through recursive hashing. For the verification of sensitive data: ; For verification of common level data: As for the verification of core-level data, since the core data is stored in quantum state, the integrity is directly verified through quantum state measurement, without .
[0040] Furthermore, when data recovery is required, the present embodiment discloses a data recovery mechanism. For core-level recovery, the redundant nodes Read the quantum state backup data from the quantum entanglement measurement and restore the original data; for sensitive level recovery, use at least two redundant nodes Reading Shards , and verify the tag , reconstructing the complete data through majority voting or erasure coding. For normal level recovery, at least four redundant nodes are used to Reading Shards , and verify the tag , recover data through erasure coding or replicas.
[0041] In summary, the technical solution of this implementation method achieves a precise match between encryption strength and data importance by constructing a hierarchical data storage and encrypted transmission method based on quantum keys, dividing data into three encryption levels of ordinary, sensitive, and core in real time, and dynamically calculating the security strength value based on data sensitivity, network threat level, and quantum key entropy value. This not only avoids the risk of quantum computing attacks on core data due to over-reliance on traditional encryption, but also prevents the waste of resources caused by redundant encryption of ordinary data. In the selection of transmission paths, a comprehensive scoring mechanism is used to conduct a multi-dimensional evaluation of the path's security risk, bandwidth, quantum key availability, and latency, and combined with the mandatory constraint rules of the encryption level to ensure high Security requirement data is transmitted through an eavesdropping-resistant quantum communication channel, and the transmission reliability is improved through a redundant path switching mechanism. In the storage link, by forcibly binding the encryption level and storage node type, and combining the sharding storage strategy, not only is the dual protection of data integrity and availability achieved, but also the quantum direct communication protocol is used to encrypt core data, and the layered adaptation of hybrid keys and traditional encryption is used to build a dynamic balance system between anti-quantum attack capabilities, transmission efficiency and storage security, and finally form a full-link dynamic security mechanism covering data encryption, transmission path selection, and storage protection, which significantly improves the system's anti-attack capabilities, resource utilization and data integrity verification efficiency in complex network environments.
[0042] refer to Figure 2This embodiment further discloses a quantum key-based hierarchical data storage and encryption transmission system, including: The encryption level division module 21 is used to receive the original data set in real time and divide it into at least three encryption levels according to the importance and security requirements of the original data in the original data set, including: receiving the original data in real time and obtaining the sensitivity parameters of the data in real time based on the content and label information of the original data ; Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ; Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating the security strength value , the calculation formula is: ,in, is a preset safety threshold coefficient; the safety strength value With the preset stratification threshold and For comparison, specifically: , the current raw data is divided into common levels; if , the current raw data is divided into sensitive levels; if , then the current raw data is divided into core levels; The encryption module 22 is used to encrypt the original data of different encryption levels using the corresponding encryption keys, including: generating a first traditional symmetric key through a quantum random number generator , and encrypt the ordinary level data; generate a quantum key through a quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: , using a mixed key to encrypt the sensitive level data: ,in, is a symmetric encryption algorithm. is a quantum-resistant hash function; a quantum key is generated by the quantum key distribution protocol , and use the quantum direct communication protocol to encrypt the core layer data: ,in, Encryption function for quantum direct communication; The encryption transmission module 23 is used to dynamically select different encryption transmission paths according to the security level of the encryption level of the original data and the network status parameters to complete the encryption transmission of the encrypted data, including: for each available transmission path Calculate its comprehensive score , the formula is: ,in, , , and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path The node transmission delay of the core layer is the only allowed path constraint type of the quantum encryption channel, denoted as , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; the constraint type of the allowed path of the sensitive level includes quantum encryption channel and hybrid encryption channels ,when When selecting the quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, , , are not the same, and Greater than , Greater than ; The only allowed path constraint type for the common level is the traditional encrypted channel ; Select the comprehensive score within the constraint type range of the path The largest path , and through the path Complete the encrypted transmission of encrypted data; build redundant paths for path switching ; Calculate the selected path Real-time ratings ,like , dynamic path switching is triggered to select a redundant path Complete the encrypted transmission of encrypted data, where: is the initial score, is the preset adjustment factor; The encryption storage module 24 is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level, including: storing the core level data in the quantum state form in the quantum offline storage node ; Store the sensitive level data in the edge node through local encryption ; The common level data is stored in a distributed manner on cloud nodes ; Through random numbers Determine the shard storage nodes for the core-level data: ; Through the hash function Determine the shard storage nodes for sensitive level data: ; Also used to construct redundant storage nodes for the core-level data , the redundant storage node The selection rules are: ,in For Node The quantum key availability parameter, Delay node transmission; build redundant storage nodes for sensitive level data , the sensitive level data is distributed and stored in at least three nodes , the node's attached label is ,in, is a hybrid hash function; constructs redundant storage nodes for the common level data , the common level data is distributed and stored in at least five nodes The node's accompanying label is ,in, It is a traditional hash function.
[0043] Figure 3 A schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as Figure 3 As shown, the electronic device 50 includes: a processor 501 (processor), a memory 502 (memory) and a bus 503; The processor 501 and the memory 502 communicate with each other via the bus 503 ; the processor 501 is used to call program instructions in the memory 502 to execute the methods provided by the above-mentioned method implementation methods.
[0044] This embodiment provides a non-transitory computer-readable storage medium, which stores computer instructions. The computer instructions enable a computer to execute the methods provided by the above-mentioned method embodiments.
[0045] A person skilled in the art can understand that all or part of the steps for implementing the above-mentioned method implementation method can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium, which, when executed, executes the steps of the above-mentioned method implementation method; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, etc., various storage media that can store program codes.
[0046] The device implementation described above is merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, i.e., they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present implementation scheme. Those of ordinary skill in the art may understand and implement it without creative effort.
[0047] Through the description of the above implementation modes, those skilled in the art can clearly understand that each implementation mode can be implemented by means of software plus a necessary general hardware platform, or of course by hardware. Based on such an understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each implementation mode or some parts of the implementation mode.
[0048] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions may occur depending on design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A hierarchical data storage and encryption transmission method based on quantum key, characterized in that: The method comprises: receiving the original data set in real time, and dividing it into at least three encryption levels according to the importance and security requirements of the original data in the original data set; The original data of different encryption levels are encrypted using corresponding encryption keys; According to the security level of the encryption layer of the original data and the network status parameters, different encryption transmission paths are dynamically selected to complete the encrypted transmission of the encrypted data; The corresponding encrypted data is stored in the corresponding storage node according to the encryption level.
2. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 1 is characterized in that: The real-time receiving of the original data set and dividing the original data in the data set into at least three encryption levels according to the importance and security requirements of the original data in the data set include: Receive raw data in real time and obtain the sensitivity parameters of the data in real time based on the content and label information of the raw data ; Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ; Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; Based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating the security strength value , the calculation formula is: ,in, is the preset safety threshold factor; The security strength value With the preset stratification threshold and For comparison, specifically: like , then the current raw data is divided into common levels; like , the current raw data is divided into sensitive levels; like , the current raw data is divided into core levels.
3. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 2 is characterized in that: Encrypting the original data of different encryption levels using corresponding encryption keys includes: Generating the first conventional symmetric key via a quantum random number generator , and encrypting the common level data; Generating quantum keys through quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: , using a mixed key to encrypt the sensitive level data: ,in, is a symmetric encryption algorithm. It is a quantum-resistant hash function; Generate quantum keys through the quantum key distribution protocol , and use the quantum direct communication protocol to encrypt the core layer data: ,in, Encryption function for quantum direct communication.
4. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 2 is characterized in that: The dynamically selecting different encryption transmission paths according to the security level of the encryption level of the original data and the network status parameters to complete the encrypted transmission of the encrypted data includes: For each available transmission path Calculate its comprehensive score , the formula is: ,in, , , and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path Node transmission delay; The only allowed path constraint type at the core level is the quantum encryption channel, denoted by , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; The constraint types of the allowed paths of the sensitive level include quantum encryption channels and hybrid encryption channels ,when When selecting the quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, , , are not the same, and Greater than , Greater than ; The only allowed path constraint type for the normal level is the traditional encrypted channel ; In the Constraint type field for the path, select Comprehensive scoring. The largest path , and through the path Complete the encrypted transmission of encrypted data.
5. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 4 is characterized in that: The method further comprises: Building redundant paths for path switching ; Calculate the selected path Real-time ratings ,like , dynamic path switching is triggered to select a redundant path Complete the encrypted transmission of encrypted data, where: is the initial score, is the preset adjustment factor.
6. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 2 is characterized in that: The storing of the corresponding encrypted data in the corresponding storage node according to the encryption level includes: The core level data is stored in quantum offline storage nodes in the form of quantum states. ; The sensitive level data is stored in the edge node through local encryption ; The common level data is stored in a distributed manner on cloud nodes ; By random number Determine the shard storage nodes for the core-level data: ; Through hash function Determine the shard storage nodes for sensitive level data: .
7. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 2 is characterized in that: The method further comprises: Constructing redundant storage nodes for the core-level data , the redundant storage node The selection rules are: ,in For Node The quantum key availability parameter, is the node transmission delay; Construct redundant storage nodes for the sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's attached label is ,in, is a hybrid hash function; Constructing redundant storage nodes for the common level data The common level data is distributed and stored in at least five redundant storage nodes. , the node's attached label is ,in, It is a traditional hash function.
8. A hierarchical data storage and encryption transmission system based on quantum keys, characterized in that: include: An encryption level division module, used for receiving the original data set in real time, and dividing the original data in the original data set into at least three encryption levels according to the importance and security requirements of the original data; An encryption module is used to encrypt the original data of different encryption levels using corresponding encryption keys; The encryption transmission module is used to dynamically select different encryption transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encryption transmission of the encrypted data; The encryption storage module is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level.
9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Office data encryption storage system and method based on Internet
CN118194330A
Encryption optimization method for data communication
CN118944952A
Bidirectional trusted identity verification method and system based on offline file
CN119363461A
Auditing data distributed storage method based on multi-layer encryption strategy and related product
CN119441229A
Use of quantum secure key in a network
EP4213440A1
Cited By
Quantum computing assisted cloud storage encryption system and anti-quantum attack algorithm
CN120896738A
Quantum computing assisted cloud storage encryption system and anti-quantum attack algorithm
CN120896738B
Cloud storage method and system of Internet of Things equipment data
CN120935204A
Cloud storage method and system for internet of things device data
CN120935204B
Power communication resource data encryption method, system and equipment based on multi-algorithm fusion
CN121012627A