A quantum key-based hierarchical data storage and encryption transmission method and system

Through a quantum key-based hierarchical data storage and encrypted transmission method, data is divided into ordinary, sensitive, and core levels in real time, and the transmission path is dynamically selected and combined with the storage node type. This solves the problems of data security adaptability and inefficiency in existing technologies and achieves efficient and secure data transmission and storage.

CN120034331BActive Publication Date: 2025-09-16BEIJING GUODU INTERNET TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510503578.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-09-16
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

In existing technologies, data encryption and transmission lack a mechanism to divide data into levels according to its importance, resulting in the inability to dynamically adapt the security protection strength of core data and ordinary data. The selection of network transmission paths does not comprehensively evaluate the real-time availability of quantum keys and the level of network threats. The storage link does not design differentiated strategies for different security levels, resulting in low security and efficiency.

Method used

Through a quantum key-based hierarchical data storage and encrypted transmission method, data is divided into three encryption levels: ordinary, sensitive, and core in real time. The security strength value is dynamically calculated based on data sensitivity, network threat level, and quantum key entropy value. A comprehensive scoring mechanism is used to select the transmission path. Combined with the encryption level and storage node type, a full-link dynamic security mechanism is constructed.

Benefits of technology

It achieves a precise match between encryption strength and data importance, avoids the risk of over-reliance on traditional encryption for core data, prevents the waste of resources due to redundant encryption of ordinary data, ensures that data with high security requirements is transmitted through anti-eavesdropping channels, and improves data integrity verification efficiency and resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034331B_ABST
    Figure CN120034331B_ABST
Patent Text Reader

Abstract

The present invention discloses a quantum key-based hierarchical data storage and encryption transmission method and system, which relates to the field of data security technology. The method includes: receiving an original data set in real time and dividing it into at least three encryption levels; encrypting the original data of different encryption levels using corresponding encryption keys; dynamically selecting different encryption transmission paths based on the security level of the encryption level of the original data and network status parameters; and storing the corresponding encrypted data in the corresponding storage node according to the encryption level. By dividing the data into three encryption levels of ordinary, sensitive, and core in real time, a precise match between encryption strength and data importance is achieved; in the transmission path selection, transmission reliability is improved through a redundant path switching mechanism; and in the storage link, the system's anti-attack capability, resource utilization, and data integrity verification efficiency in complex network environments are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a quantum key-based hierarchical data storage and encryption transmission method and system. Background Art

[0002] With the increasing demand for data security, the limitations of traditional encryption technologies in combating quantum computing attacks and dynamic network environments are becoming increasingly apparent. Existing technologies often use single-security encryption algorithms for data encryption and transmission, lacking a mechanism for stratifying data based on its importance. This results in an inability to dynamically adapt the security strength of core and general data, resulting in both resource waste and security risks. Furthermore, network transmission path selection is often based on single metrics such as bandwidth or latency, failing to incorporate the real-time availability of quantum keys, network threat levels, and data sensitivity into a comprehensive assessment. This makes it difficult to ensure the reliability and eavesdropping resistance of quantum encryption channels in high-threat environments. Furthermore, storage generally utilizes unified storage nodes, lacking differentiated storage strategies for data of different security levels. For example, core confidential data lacks physical isolation for quantum state offline storage, sensitive data lacks a hybrid hash-based redundant verification mechanism, and the distributed storage of general data is not integrated into the encryption hierarchy, resulting in inefficient data integrity verification and susceptibility to man-in-the-middle attacks. Summary of the Invention

[0003] In view of this, the present invention proposes a hierarchical data storage and encrypted transmission method and system based on quantum keys, which can design differentiated storage strategies for data of different security levels and dynamically select the most appropriate encrypted transmission path to ensure data security and transmission efficiency. The present invention provides the following technical solutions:

[0004] A quantum key-based hierarchical data storage and encryption transmission method, the method comprising:

[0005] Receive the original data set in real time and divide it into at least three encryption levels according to the importance and security requirements of the original data in the original data set;

[0006] The original data of different encryption levels are encrypted using corresponding encryption keys;

[0007] Dynamically select different encryption transmission paths based on the security level of the original data's encryption layer and network status parameters to complete the encrypted transmission of encrypted data;

[0008] The corresponding encrypted data is stored in the corresponding storage node according to the encryption level.

[0009] Optionally, the receiving of the original data set in real time and dividing the original data in the data set into at least three encryption levels according to the importance and security requirements of the original data include:

[0010] Receive raw data in real time and obtain the sensitivity parameters of the data based on the content and label information of the raw data ;

[0011] Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ;

[0012] Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits;

[0013] Based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating security strength values , the calculation formula is: ,in, is the preset safety threshold coefficient;

[0014] The security strength value With the preset stratification threshold and For comparison, specifically:

[0015] like , then the current original data is divided into common levels;

[0016] like , the current original data is divided into sensitive levels;

[0017] like , the current raw data is divided into core levels.

[0018] Optionally, encrypting original data of different encryption levels using corresponding encryption keys includes:

[0019] Generating the first conventional symmetric key via a quantum random number generator , and encrypting the common-level data;

[0020] Generate quantum keys through quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: , using a mixed key to encrypt the sensitive level data: ,in, is a symmetric encryption algorithm, is a quantum-resistant hash function, Encrypt data for sensitive levels; The data that needs to be encrypted is in an unencrypted state;

[0021] Generate quantum keys through the quantum key distribution protocol , and uses quantum direct communication protocol to encrypt the core layer data: ,in, is the quantum direct communication encryption function, Encrypt data at the core level.

[0022] Optionally, dynamically selecting different encryption transmission paths according to the security level of the encryption layer of the original data and network status parameters to complete the encrypted transmission of the encrypted data includes:

[0023] For each available transmission path Calculate its comprehensive score , the formula is: ,in, 、 、 and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path Node transmission delay;

[0024] The only allowed path constraint type at the core level is the quantum encryption channel, denoted as , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold;

[0025] The constraint types of the allowed paths of the sensitive level include quantum encryption channels and hybrid encryption channels ,when When selecting quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, 、 、 are all different, and Greater than , Greater than , is the minimum bandwidth;

[0026] The only allowed path constraint type for the common layer is the traditional encrypted channel ;

[0027] In the Constraint Type field for the path, select Comprehensive Score. The largest path and through the path Complete the encrypted transmission of encrypted data.

[0028] Optionally, the method further includes:

[0029] Building redundant paths for path switching ,in For path The quantum key availability parameter, For path Node transmission delay;

[0030] Calculate the selected path Real-time rating ,like , dynamic path switching is triggered to select redundant paths Complete the encrypted transmission of encrypted data, where is the initial score, is the preset adjustment factor.

[0031] Optionally, storing the corresponding encrypted data in the corresponding storage node according to the encryption level includes:

[0032] The core level data is stored in quantum offline storage nodes in the form of quantum states ;

[0033] The sensitive level data is stored in the edge node through local encryption ;

[0034] The common level data is stored in a distributed manner on cloud nodes ;

[0035] By random number Determine the shard storage nodes for the core-level data: ;

[0036] Through hash function Determine the shard storage nodes for sensitive data: .

[0037] Optionally, the method further includes:

[0038] Build redundant storage nodes for the core layer data , the redundant storage node The selection rules are: ,in For nodes The quantum key availability parameter, is the node transmission delay;

[0039] Build redundant storage nodes for sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's accompanying label is ,in, is a hybrid hash function;

[0040] Constructing redundant storage nodes for the common level data , the common level data is distributed and stored in at least five redundant storage nodes , the node's accompanying label is ,in, It is a traditional hash function.

[0041] The present invention further discloses a quantum key-based hierarchical data storage and encryption transmission system, comprising:

[0042] An encryption level division module is used to receive the original data set in real time and divide it into at least three encryption levels according to the importance and security requirements of the original data in the original data set;

[0043] The encryption module is used to encrypt the original data of different encryption levels using the corresponding encryption keys;

[0044] The encryption transmission module is used to dynamically select different encryption transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encrypted transmission of the encrypted data;

[0045] The encryption storage module is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level.

[0046] The present invention further discloses a computer-readable storage medium, wherein the storage medium stores a computer program, and the computer program implements the above method when executed by a processor.

[0047] The present invention further discloses an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above method when executing the program.

[0048] According to the technical solution of the present invention, by constructing a hierarchical data storage and encryption transmission method based on quantum keys, by dividing data into three encryption levels of ordinary, sensitive, and core in real time, and dynamically calculating the security strength value based on data sensitivity, network threat level and quantum key entropy value, a precise match between encryption strength and data importance is achieved, which not only avoids the risk of quantum computing attacks on core data due to over-reliance on traditional encryption, but also prevents the waste of resources caused by redundant encryption of ordinary data; in the selection of transmission paths, a comprehensive scoring mechanism is used to conduct a multi-dimensional evaluation of the path's security risk, bandwidth, quantum key availability and latency, and combined with the mandatory constraint rules of the encryption level to ensure high security The required data is transmitted through an eavesdropping-resistant quantum communication channel, and the transmission reliability is improved through a redundant path switching mechanism. In the storage link, by forcibly binding the encryption level and storage node type, and combining it with a sharded storage strategy, not only is the dual protection of data integrity and availability achieved, but also the quantum direct communication protocol is used to encrypt core data, and the layered adaptation of hybrid keys and traditional encryption is used to build a dynamic balance system between anti-quantum attack capabilities, transmission efficiency and storage security, and ultimately form a full-link dynamic security mechanism covering data encryption, transmission path selection, and storage protection, which significantly improves the system's anti-attack capabilities, resource utilization and data integrity verification efficiency in complex network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] For purposes of illustration and not limitation, the present invention will now be described with reference to embodiments thereof and the accompanying drawings, in which:

[0050] Figure 1 1 is a flow chart of a method for hierarchical data storage and encrypted transmission based on quantum keys in an embodiment of the present invention;

[0051] Figure 2 1 is a schematic structural diagram of a quantum key-based hierarchical data storage and encryption transmission system in an embodiment of the present invention;

[0052] Figure 3 Schematic diagram of the structure of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION

[0053] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of this application.

[0054] It should be noted that, in the absence of conflict, the embodiments of the present application and the features thereof can be combined with each other. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0055] refer to Figure 1 This embodiment discloses a hierarchical data storage and encrypted transmission method based on quantum keys, the method comprising:

[0056] S100: Receive an original data set in real time, and divide the original data in the original data set into at least three encryption levels according to the importance and security requirements of the original data.

[0057] Specifically, the raw data is received in real time through the data interface and the raw data set is formed. The above data interface supports the input of multi-source heterogeneous data, such as IoT devices, databases or user terminals, and metadata tags are added to each piece of raw data, including: data type, field, business priority, and the sensitivity parameters of the data are obtained in real time based on the content and tag information of the raw data. The tag information includes the sensitivity of the current data and the corresponding basic weight. For example, the basic weight of high sensitivity is 0.8. The superposition weight is further dynamically set by detecting sensitive fields in the original data. For example, when financial fields such as credit cards are detected, the superposition weight is set to 0.2.

[0058] Secondly, the network threat detection module is used to collect the attack event frequency, abnormal traffic ratio and the alarm level of the intrusion detection system in real time. Based on the current network attack event frequency and abnormal traffic data, the network threat level parameters are dynamically detected. , the calculation formula is: ,in, is the number of attack events on the current network, is the abnormal traffic ratio, It is the alarm weight of the intrusion detection system. 、 、 is a preset weight coefficient. In this embodiment, the exemplary setting is: high-risk alarm , medium-risk warning , low-risk warning .

[0059] Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits;

[0060] Based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating security strength values , the calculation formula is: ,in, is the preset safety threshold coefficient;

[0061] The security strength value With the preset stratification threshold and To compare, specifically: , then the current original data is divided into common levels; if , the current original data is divided into sensitive levels; if , the current raw data is divided into core levels.

[0062] S200: Encrypting original data of different encryption levels using corresponding encryption keys.

[0063] For the generation of encryption keys, including:

[0064] Generating the first conventional symmetric key via a quantum random number generator To ensure the randomness of the key, the common layer data is encrypted using the key. The encryption process uses the AES-256 algorithm to encrypt the common layer data.

[0065] Generate quantum keys through quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: ,in, The sensitive level data is encrypted using a quantum-resistant hash function such as SHA-3 using a mixed key: ,in, is a symmetric encryption algorithm, is a quantum-resistant hash function, Encrypt data for sensitive levels; The data that needs to be encrypted is in an unencrypted state;

[0066] Generate quantum keys through the quantum key distribution protocol , and uses quantum direct communication protocol to encrypt the core layer data: ,in, is the quantum direct communication encryption function, Encrypt data at the core level.

[0067] This embodiment further discloses a dynamic key update mechanism, specifically, the entropy value of the current quantum key is calculated in real time. ,like ,in, is the preset threshold for evaluating the quality of the quantum key, triggering a key update: , and update the affected data blocks based on the new key, where For quantum random number generation. At the same time, when the data level is affected by the threat level or quantum key availability When the key type is upgraded due to a change, for example, from normal to sensitive, an update of the key type is triggered.

[0068] S300: According to the security level of the encryption layer of the original data and the network status parameters, different encryption transmission paths are dynamically selected to complete the encrypted transmission of the encrypted data. Specifically, the system collects all available transmission paths in real time. Status parameters include:

[0069] Obtain the security risk factor of the path through historical attack frequency, number of vulnerabilities, or IDS alarm records ;

[0070] Obtain the current available bandwidth of the path through the network monitoring module ;

[0071] The quantum key availability is constructed by the quantum key pool remaining amount and distribution success rate corresponding to the quantum key management module return path ;

[0072] Use a path detection tool (such as ICMP or OWAMP) to measure the one-way delay of the path, that is, the node transmission delay .

[0073] After obtaining the above parameters, for each available transmission path Calculate its comprehensive score , the formula is: ,in, 、 、 and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path The node transmission delay.

[0074] The path type is further constrained based on the data encryption level, as follows:

[0075] The only allowed path constraint type at the core level is the quantum encryption channel, denoted as , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold;

[0076] Constraint types for allowed paths at sensitive levels include quantum encryption channels and hybrid encryption channels ,when When selecting quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, 、 、 are all different, and Greater than , Greater than , is the minimum bandwidth;

[0077] The only allowed path constraint type at the normal level is the traditional encrypted channel ;

[0078] In the Constraint type field for the path, select Comprehensive scoring. The largest path and through the path Complete the encrypted transmission of encrypted data. That is, for the core layer, only and Select the highest quantum encryption channel Corresponding path; for sensitive levels, in the allowed quantum encryption channel and hybrid encryption channels Select the highest path Corresponding path; for the ordinary layer, directly select the traditional encryption channel , no additional constraints are required.

[0079] Furthermore, redundant paths are constructed for path switching. ,in For path The quantum key availability parameter, For path Node transmission delay;

[0080] Calculate the selected path Real-time rating ,like , dynamic path switching is triggered to select redundant paths Complete the encrypted transmission of encrypted data, where is the initial score, The default adjustment coefficient is . During switching, the quantum encryption channel achieves seamless switching through quantum entanglement backup, while the hybrid / traditional channel is completed through traditional redundancy protocols (such as IP routing switching).

[0081] This embodiment further discloses the comprehensive scoring The calculation is based on the real-time threat level and global quantum key availability Recalculate , the calculation formula is: , is the preset adjustment coefficient, for weight 、 and , allocated through the remaining proportion and set by the user according to needs.

[0082] In this embodiment, if the availability of the quantum key is detected A significant drop, e.g. , then temporarily reduce the quantum channel activation threshold of the sensitive level , for example, from 0.5 to 0.4 to release core-level resources.

[0083] This embodiment exemplifies a core data transmission process:

[0084] Execution path parameter collection:

[0085] Quantum encryption channel : , , , ;

[0086] Traditional channels : , .

[0087] Path constraints and score calculation:

[0088] Core Data Forced Selection , only when satisfy and ;

[0089] calculate Rating .

[0090] Build redundant paths:

[0091] like The delay suddenly increased to , triggering redundant paths , through the formula Select another quantum channel .

[0092] S400: Storing corresponding encrypted data in corresponding storage nodes according to the encryption level.

[0093] The core level data is stored in quantum offline storage nodes in the form of quantum states , offline isolation is achieved through quantum memory or photon storage media; through random numbers Determine the shard storage nodes for the core-level data: ;

[0094] The sensitive level data is stored in the edge node through local encryption ; Through hash function Determine the shard storage nodes for sensitive data: .

[0095] The common level data is stored in a distributed manner on cloud nodes ; Through traditional hash function Determine where the shards are stored: .

[0096] Furthermore, redundant storage nodes for the core data are constructed. , the redundant storage node The selection rules are: ,in For nodes The quantum key availability parameter, is the node transmission delay;

[0097] Build redundant storage nodes for sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's accompanying label is ,in, is a hybrid hash function, is a mixed key, Sharding of data;

[0098] Constructing redundant storage nodes for the common level data , the common level data is distributed and stored in at least five redundant storage nodes The node's accompanying label is ,in, It is a traditional hash function.

[0099] After the encrypted data is stored in the corresponding storage node, the integrity of the encrypted data is periodically verified. The verification is triggered by a preset period (such as every minute) or an event (such as data update). The specific verification steps include:

[0100] Read data shards from storage nodes and its label (core layer has no label, sensitive / normal layer requires label), recalculate the hash chain verification value: for the core layer, directly verify the data integrity through quantum state measurement (no hash calculation required), for the sensitive layer, calculate the mixed hash label ,in, is a hybrid hash function, if , then the current data is determined to be damaged; for the normal level, calculate the traditional hash tag ,like , it is determined that the current data is damaged.

[0101] For sensitive and common data, the integrity of the current data block is verified through recursive hashing. For the verification of sensitive data: ; For verification of common level data: As for the verification of core-level data, since the core data is stored in quantum state, the integrity is directly verified through quantum state measurement, without the need for ,in The currently calculated hash value.

[0102] Furthermore, when data recovery is required, this embodiment discloses a data recovery mechanism. For core level recovery, the redundant nodes Read the quantum state backup data from the quantum state backup node and restore the original data through quantum entanglement measurement; for sensitive level recovery, the data is restored from at least two redundant nodes. Read shards , and verify the label , reconstructing the complete data through majority voting or erasure coding. For normal level recovery, from at least four redundant nodes Read shards , and verify the label , recover data through erasure coding or replication.

[0103] In summary, the technical solution of this embodiment achieves a precise match between encryption strength and data importance by constructing a hierarchical data storage and encrypted transmission method based on quantum keys, dividing data into three encryption levels: ordinary, sensitive, and core in real time, and dynamically calculating the security strength value based on data sensitivity, network threat level, and quantum key entropy value. This not only avoids the risk of quantum computing attacks on core data due to over-reliance on traditional encryption, but also prevents the waste of resources caused by redundant encryption of ordinary data. In the selection of transmission paths, a comprehensive scoring mechanism is used to conduct a multi-dimensional assessment of the path's security risk, bandwidth, quantum key availability, and latency, and combined with the mandatory constraint rules of the encryption level to ensure high Security requirement data is transmitted through an eavesdropping-resistant quantum communication channel, and the transmission reliability is improved through a redundant path switching mechanism. In the storage link, by forcibly binding the encryption level and storage node type, and combining it with a sharded storage strategy, not only is the dual protection of data integrity and availability achieved, but also the quantum direct communication protocol is used to encrypt core data, and the layered adaptation of hybrid keys and traditional encryption is used to build a dynamic balance system between anti-quantum attack capabilities, transmission efficiency and storage security, ultimately forming a full-link dynamic security mechanism covering data encryption, transmission path selection, and storage protection, which significantly improves the system's anti-attack capabilities, resource utilization and data integrity verification efficiency in complex network environments.

[0104] refer to Figure 2 This embodiment further discloses a quantum key-based hierarchical data storage and encryption transmission system, including:

[0105] The encryption level division module 21 is used to receive the original data set in real time and divide it into at least three encryption levels according to the importance and security requirements of the original data in the original data set, including: receiving the original data in real time and obtaining the sensitivity parameters of the data in real time based on the content and label information of the original data Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ; Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating security strength values , the calculation formula is: ,in, is the preset safety threshold coefficient; the safety strength value With the preset stratification threshold and To compare, specifically: , then the current original data is divided into common levels; if , the current original data is divided into sensitive levels; if , then divide the current raw data into core levels;

[0106] The encryption module 22 is used to encrypt the original data of different encryption levels using the corresponding encryption keys, including: generating a first traditional symmetric key through a quantum random number generator , and encrypt the ordinary level data; generate a quantum key through a quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: , using a mixed key to encrypt the sensitive level data: ,in, is a symmetric encryption algorithm, is a quantum-resistant hash function, Encrypt data for sensitive levels; The data to be encrypted is in an unencrypted state; a quantum key is generated by the quantum key distribution protocol , and uses quantum direct communication protocol to encrypt the core-level data: ,in, is the quantum direct communication encryption function, Encrypt data at the core level;

[0107] The encryption transmission module 23 is used to dynamically select different encryption transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encryption transmission of the encrypted data, including: for each available transmission path Calculate its comprehensive score , the formula is: ,in, 、 、 and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path The node transmission delay of the core layer is the only allowed path constraint type for the quantum encryption channel, which is denoted as , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; the constraint type of the allowed path of the sensitive level includes quantum encryption channel and hybrid encryption channels ,when When selecting quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, 、 、 are all different, and Greater than , Greater than , is the minimum bandwidth; the only allowed path constraint type for the common layer is the traditional encrypted channel ; Select the comprehensive score within the constraint type range of the path The largest path and through the path Complete encrypted transmission of encrypted data; build redundant paths for path switching ,in For path The quantum key availability parameter, For path Node transmission delay; calculate the selected path Real-time rating ,like , dynamic path switching is triggered to select redundant paths Complete the encrypted transmission of encrypted data, where is the initial score, is the preset adjustment coefficient;

[0108] The encryption storage module 24 is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level, including: storing the core level data in the form of quantum state in the quantum offline storage node ; Store the sensitive level data in the edge node through local encryption ; The common level data is stored in a distributed manner on cloud nodes ; By random number Determine the shard storage nodes for the core-level data: ; Through hash function Determine the shard storage nodes for sensitive data: ;

[0109] Also used to construct redundant storage nodes for the core-level data , the selection rule of the redundant node is: ,in For nodes The quantum key availability parameter, Delay node transmission; build redundant storage nodes for sensitive level data , the sensitive level data is distributed and stored in at least three nodes , the node's accompanying label is ,in, is a hybrid hash function, is a mixed key, Sharding data; building redundant storage nodes for the common level data , the common level data is distributed and stored in at least five nodes The node's accompanying label is ,in, It is a traditional hash function.

[0110] Figure 3 A schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as Figure 3 As shown, the electronic device 50 includes: a processor 501 (processor), a memory 502 (memory) and a bus 503;

[0111] The processor 501 and the memory 502 communicate with each other via the bus 503 ; the processor 501 is used to call program instructions in the memory 502 to execute the methods provided by the above-mentioned method implementation methods.

[0112] This embodiment provides a non-transitory computer-readable storage medium, which stores computer instructions. The computer instructions enable a computer to execute the methods provided by the above-mentioned method embodiments.

[0113] Those skilled in the art will understand that all or part of the steps for implementing the above-mentioned method implementation method can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method implementation method; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk, etc. Various storage media that can store program codes.

[0114] The device embodiments described above are merely illustrative. Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of these modules may be selected based on actual needs to achieve the objectives of this embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0115] Through the description of the above embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods of each embodiment or certain portions of the embodiments.

[0116] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A hierarchical data storage and encryption transmission method based on quantum key, characterized in that: The method comprises: Receive the original data set in real time and divide it into at least three encryption levels based on the importance and security requirements of the original data in the original data set, including: receive the original data in real time and obtain the sensitivity parameters of the data in real time based on the content and label information of the original data Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ; Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating security strength values , the calculation formula is: ,in, is the preset safety threshold coefficient; the safety strength value With the preset stratification threshold and To compare, specifically: , then the current original data is divided into common levels; if , the current original data is divided into sensitive levels; if , then divide the current raw data into core levels; The original data of different encryption levels are encrypted using corresponding encryption keys; Dynamically select different encryption transmission paths based on the security level of the original data's encryption layer and network status parameters to complete the encrypted transmission of encrypted data; The corresponding encrypted data is stored in the corresponding storage node according to the encryption level.

2. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 1 is characterized in that: Encrypting original data at different encryption levels using corresponding encryption keys includes: Generating the first conventional symmetric key via a quantum random number generator , and encrypting the common-level data; Generate quantum keys through quantum key distribution protocol , and generate the second traditional key , generate a mixed key through a hash function: , using a mixed key to encrypt the sensitive level data: ,in, is a symmetric encryption algorithm, is a quantum-resistant hash function, Encrypt data for sensitive levels; The data that needs to be encrypted is in an unencrypted state; Generate quantum keys through the quantum key distribution protocol , and uses quantum direct communication protocol to encrypt the core-level data: ,in, is the quantum direct communication encryption function, Encrypt data at the core level.

3. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 1 is characterized in that: The method of dynamically selecting different encryption transmission paths based on the security level of the encryption layer of the original data and network status parameters to complete the encrypted transmission of the encrypted data includes: For each available transmission path Calculate its comprehensive score , the formula is: ,in, 、 、 and is the dynamic weight coefficient, For path The safety risk factor, For path Real-time bandwidth, The bandwidth requirement for data transmission is For path Quantum key availability, For path Node transmission delay; The only allowed path constraint type at the core level is the quantum encryption channel, denoted as , set the channel enabling conditions: and ,in, is the quantum key availability threshold, is the maximum delay threshold; The constraint types of the allowed paths of the sensitive level include quantum encryption channels and hybrid encryption channels ,when When selecting quantum encryption channel ,when and When selecting a hybrid encryption channel ,in, 、 、 are all different, and Greater than , Greater than , is the minimum bandwidth; The only allowed path constraint type for the common layer is the traditional encrypted channel ; In the Constraint Type field for the path, select Comprehensive Score. The largest path and through the path Complete the encrypted transmission of encrypted data.

4. The hierarchical data storage and encrypted transmission method based on quantum keys according to claim 3 is characterized in that: The method further comprises: Building redundant paths for path switching ,in For path The quantum key availability parameter, For path Node transmission delay; Calculate the selected path Real-time rating ,like , dynamic path switching is triggered to select redundant paths Complete the encrypted transmission of encrypted data, where is the initial score, is the preset adjustment factor.

5. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 1 is characterized in that: Storing the corresponding encrypted data in the corresponding storage node according to the encryption level includes: The core level data is stored in quantum offline storage nodes in the form of quantum states ; The sensitive level data is stored in the edge node through local encryption ; The common level data is stored in a distributed manner on cloud nodes ; By random number Determine the shard storage nodes for the core-level data: ; Through hash function Determine the shard storage nodes for sensitive data: .

6. The hierarchical data storage and encrypted transmission method based on quantum key according to claim 1 is characterized in that: The method further comprises: Build redundant storage nodes for the core layer data , the redundant storage node The selection rules are: ,in For nodes The quantum key availability parameter, is the node transmission delay; Build redundant storage nodes for sensitive level data , the sensitive level data is distributed and stored in at least three redundant storage nodes , the node's accompanying label is ,in, is a hybrid hash function, is a mixed key, Sharding of data; Constructing redundant storage nodes for the common level data , the common level data is distributed and stored in at least five redundant storage nodes , the node's accompanying label is ,in, It is a traditional hash function.

7. A quantum key-based hierarchical data storage and encryption transmission system, characterized in that: include: The encryption level division module is used to receive the original data set in real time and divide it into at least three encryption levels according to the importance and security requirements of the original data in the original data set, including: receiving the original data in real time and obtaining the sensitivity parameters of the data in real time based on the content and label information of the original data Dynamically detect network threat level parameters based on the current network attack event frequency and abnormal traffic data ; Call the quantum key and calculate the randomness strength of the quantum key through Shannon entropy, that is, the quantum key entropy value , the calculation formula is: ,in, It is the first The probability of bits; based on the sensitivity parameter , Network Threat Level Parameters and quantum key entropy Calculating security strength values , the calculation formula is: ,in, is the preset safety threshold coefficient; the safety strength value With the preset stratification threshold and To compare, specifically: , then the current original data is divided into common levels; if , the current original data is divided into sensitive levels; if , then divide the current raw data into core levels; The encryption module is used to encrypt the original data of different encryption levels using the corresponding encryption keys; The encryption transmission module is used to dynamically select different encryption transmission paths according to the security level of the encryption layer of the original data and the network status parameters to complete the encrypted transmission of the encrypted data; The encryption storage module is used to store the corresponding encrypted data in the corresponding storage node according to the encryption level.

8. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Office data encryption storage system and method based on Internet

    CN118194330A