Electronic official document encryption exchange method and system oriented to multiple exchange nodes
By adopting a verifiable hybrid secret sharing mechanism, node reputation evaluation model, dynamic path optimization algorithm and multi-level access control strategy in the electronic document exchange system, the security risks and inefficiency of existing systems in key management, path selection and access control are solved, and high security, high efficiency and traceability of official documents transmission is achieved.
Patent Information
- Application Number
- CN202510175853.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-18
AI Technical Summary
The existing electronic document exchange system has security risks and inefficiency problems in key management, path selection and access control, especially in multi-node and large-scale network environments, which are difficult to ensure the security and efficiency of data transmission.
Using a verifiable hybrid secret sharing mechanism, node reputation evaluation model, dynamic path optimization algorithm and multi-level access control strategy, an electronic official document encryption exchange system for multi-switch nodes is built to ensure the secure exchange of keys, dynamic path optimization and real-time adjustment of access permissions.
It improves the security and efficiency of official document transmission, enhances the system's attack resistance and traceability, and ensures the confidentiality and integrity of data during the exchange process.
Smart Images

Figure CN120034376A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a method and system for encrypting and exchanging electronic documents for multiple exchange nodes. Background Art
[0002] With the development of information technology, the transmission and exchange of electronic documents has become an indispensable part of modern office and government management. Electronic documents not only save paper and labor costs, but also improve work efficiency and information processing speed. In the process of electronic document exchange, it is crucial to ensure the security, integrity and traceability of documents. This demand has spawned many related technologies, especially document encryption, access control and node trust evaluation, which aim to ensure the data security of electronic documents during transmission. However, there are still some significant problems with existing document exchange technologies.
[0003] At present, many traditional electronic official document exchange systems use symmetric encryption algorithms or encryption algorithms based on public key cryptography in encryption and key management. These methods can ensure the confidentiality of data to a certain extent. However, these traditional encryption methods usually face some security risks in the key management and key exchange process. For example, in symmetric encryption systems, the distribution and storage of keys are particularly prominent. If the keys are leaked or maliciously tampered with, the security of the entire system will be invalid. In the encryption method based on the public key cryptography system, although the public key exchange protocol can theoretically guarantee the secure exchange of keys, in practical applications, how to efficiently and securely exchange official document keys between multiple exchange nodes is still a complex problem. Most of the existing technologies fail to fully consider the balance between security and efficiency in the key exchange process, especially in scenarios with many nodes and complex network topology. How to ensure the trust of each node and the correctness of the key is still a problem worth studying.
[0004] In addition to the challenges of key exchange and management, path optimization in the process of electronic document exchange is also a key issue. Most existing technologies rely on static paths or simple path selection algorithms based on network bandwidth, but fail to take into account the dynamic changes in the network environment and the fluctuations in trust between nodes. In actual document exchange, factors such as the communication quality between nodes, the reputation of nodes, and network latency will affect the efficiency and security of data transmission. Existing path selection algorithms often do not evaluate the trust of nodes and network latency in real time, resulting in low transmission efficiency of documents in multi-node, large-scale network environments, and are vulnerable to attacks by malicious nodes or man-in-the-middle attacks. Therefore, how to dynamically select the optimal transmission path based on the real-time trust of nodes and changes in the network environment has become a technical problem that needs to be solved urgently.
[0005] In addition, the current electronic document exchange system also has some defects in access control. Traditional access control strategies are often based on static permission settings, ignoring the dynamic changes in node behavior. In practical applications, the reputation of a node may change over time, and attackers may bypass access control by forging identities or other malicious means. Therefore, how to adjust access rights in real time based on the dynamic reputation of the node and the optimization results of the document transmission path is an urgent problem to be solved in the current electronic document exchange technology. Existing access control methods usually fail to fully consider the dynamic changes in node reputation and changes in network topology, resulting in weak access control capabilities of the system and vulnerability to internal and external security threats.
[0006] Therefore, how to provide an encrypted exchange method and system for electronic documents for multiple exchange nodes is an urgent problem that needs to be solved by those skilled in the art. Summary of the invention
[0007] One purpose of the present invention is to propose a method and system for electronic document encryption exchange for multiple exchange nodes. The present invention makes full use of a verifiable hybrid secret sharing mechanism, a node reputation evaluation model, a dynamic path optimization algorithm, and a multi-level access control strategy, and describes in detail a technical solution for realizing secure and rapid document exchange between multiple exchange nodes. The solution can effectively solve the defects of the prior art in key management, path selection, access control, etc., and has the advantages of high security, high efficiency, traceability and flexibility.
[0008] The electronic document encryption exchange method for multiple exchange nodes according to an embodiment of the present invention comprises the following steps:
[0009] S1. Build a document exchange environment, configure multiple exchange nodes, deploy core modules, and initialize key management strategies and trust assessment models;
[0010] S2, split the key using a verifiable hybrid secret sharing mechanism, and store it in a distributed manner after being protected by homomorphic encryption;
[0011] S3. Before the exchange of official documents, the node reputation is evaluated based on the trust evaluation model, the trust value is calculated in combination with Bayesian optimization, and the exchange path is generated;
[0012] S4, based on the exchange path, performing key exchange using a multi-party secure key exchange protocol based on verifiable secret negotiation;
[0013] S5. Based on the exchange path and key exchange results, the document transmission path is dynamically adjusted using adaptive topology-aware routing optimization;
[0014] S6. Based on the initialized key management policy and trust value, a dynamic verifiable storage mapping mechanism is used to manage access rights;
[0015] S7. During the exchange of official documents, detect abnormal traffic and optimize security protection strategies based on the official document transmission records.
[0016] Optionally, the S2 specifically includes:
[0017] S21. Let the official document data be D. Use the encryption algorithm based on polymorphic pseudo-random permutation to generate the key K. Encrypt the official document data to obtain the encrypted official document data D. ′ :
[0018]
[0019] Among them, H(D) is the hash value of the official document data, PRG(s) is the pseudo-random stream, mod is the modulus operation, λ is the key bit length, and ⊕ is the exclusive OR operation;
[0020] S22, using a verifiable hybrid secret sharing mechanism to split the key K, setting a threshold secret sharing scheme, splitting the key K into n key shares {K 1 ,K 2 ,...,K n}:
[0021]
[0022] Among them, K i is the key share, K is the original key, H(i) is the hash value of index i, r i is the key randomization factor, g is the generator, x i is the shared index, L is a large prime number, t is the total number of keys, L i is the interpolation coefficient, i is the key index;
[0023] S23. Perform homomorphic encryption on the key share. The homomorphic encryption function is E h (·), using the exponential homomorphic encryption method, the key share is encrypted as follows:
[0024]
[0025] Among them, H(K i ) is the hash value of the key share, E h (K i ) is the key share K i The result after homomorphic encryption;
[0026] S24, generate key share verification information, and use zero-knowledge proof to construct verification parameter V i :
[0027]
[0028] Among them, H is a secure hash function, h is a secure base, ξ i is the random challenge value;
[0029] S25. Distribute and store the encrypted key shares and corresponding key share verification information to multiple switching nodes.
[0030] Optionally, the S3 specifically includes:
[0031] S31, let the set of switching nodes be N = {N 1 ,N 2 ,…,N m}, for each node N i Collect its original behavior data to form a feature vector X i =[x i1 ,x i2 ,…,x id ] T , using adaptive normalization to generate enhanced feature vectors:
[0032]
[0033] Among them, μ X is the mean vector, σ X is the standard deviation vector, Y i For node N i Enhanced feature vectors;
[0034] S32. Use graph convolutional network combined with self-attention mechanism to calculate the initial trust score T of each node i :
[0035]
[0036] Among them, T i is the initial trust score of the node, α is the activation function, W is the weight matrix, b is the bias term, ln is the logarithmic function, exp is the exponential function, W a is the self-attention weight matrix, Y j For node N j The enhanced feature vector of , m is the total number of exchange nodes, j is the exchange node index;
[0037] S33, based on Bayesian optimization, the initial trust score is updated to obtain the trust value
[0038]
[0039] Among them, μ 0,i is the prior mean of the node, ω i is the Bayesian optimization coefficient, is the prior variance of the node, is the observed variance of the node;
[0040] S34, construct a candidate switching path set ρ, and based on the trust value Select a switching path P, where the candidate path satisfy:
[0041]
[0042] Where k is the number of nodes in the path, δ is the weight factor, For Node The trust value, For Node and The network delay between P'∈ρ To select the path P' that minimizes the following objective function from the candidate path set ρ;
[0043] S35. Output trust score vector And the selected switching path P.
[0044] Optionally, the S4 specifically includes:
[0045] S41, based on the generated switching path The key exchange is performed using a multi-party secure key exchange protocol based on verifiable secret negotiation;
[0046] S42, set the secure communication between nodes to C = {C i,j}, where each pair of adjacent nodes The key exchange process between i,j , using the following key exchange process:
[0047]
[0048] Among them, C i,j is the key exchange communication result, VSA-MPKE is a multi-party secure key exchange protocol based on verifiable secret negotiation, For Node Encryption key share The ciphertext obtained by homomorphic encryption method is For Node Encryption key share The ciphertext obtained by homomorphic encryption method, γ i,j is the communication key agreement protocol, δ i,j is the dynamic key enhancement factor;
[0049] S43. After the key exchange is completed, the node With Node The validity of the key exchange is verified by:
[0050]
[0051] Among them, V i,j For Node and The key exchange verification parameter between them, H is the hash function;
[0052] S44, using the key fusion method based on node reputation weighting, after the key exchange on all paths is completed, the key exchange result K is calculated by the following formula final :
[0053]
[0054] Where k is the number of nodes in the path, For Node The reputation weighting coefficient, mod is the modular operation, and L is a large prime number;
[0055] S45. Distribute the generated key exchange result to each exchange node through a distributed key distribution protocol.
[0056] Optionally, the S5 specifically includes:
[0057] S51, according to the switching path and key exchange result K final , initialize the routing optimization model and assign initial transmission parameters to each node in the document transmission path in For Node The routing parameter vector of
[0058] S52, using adaptive topology-aware routing optimization algorithm, according to the trust value of the node and network latency Dynamically adjust the document transmission path and calculate the nodes With Node The route parameters between:
[0059]
[0060] in, For Node Updated routing parameters, ε is the weight factor, d max is the maximum value of network delay, For Node Trust value;
[0061] S53, routing parameters for each document transmission path node Update and calculate the globally optimized document transmission path P opt , the weighted sum of the total transmission delay and the trust difference between nodes is minimized by the following optimization objective function:
[0062]
[0063] in, For Node The trust value, argmin P'∈P To find the path P' that minimizes the objective function in the path set ρ, k is the number of nodes in the path;
[0064] S54. Based on the optimized document transmission path, dynamically adjust the data flow between nodes and calculate the total bandwidth requirement of each path. Data traffic is scheduled according to network bandwidth constraints, using an adaptive traffic allocation algorithm based on trust and delay weighting:
[0065]
[0066] in, For Node The trust value of , ε is the weight factor;
[0067] S55, output the optimal document transmission path P opt and route parameters
[0068] Optionally, the S6 specifically includes:
[0069] S61, according to the initialized key management strategy and the generated trust value Adopt dynamic adaptive multi-level access control mechanism for each switching node Generate access rights data And perform hierarchical management on node access;
[0070] S62. Define the access permission vector of each node as in Representation Node The mth access permission level in path P;
[0071] S63, based on the trust value and path optimization result P opt , using a dynamic permission adjustment method based on node reputation weighting to dynamically adjust access rights between nodes:
[0072]
[0073] in, For Node The final access permission vector, θ is the reputation weighting coefficient, For Node The reputation change, k is the number of nodes in the path, and j is the node index;
[0074] S64. Generate an encrypted access control list based on the final access rights through a multi-factor authentication mechanism:
[0075]
[0076] in, is the access control list of the node, The final access rights of the node are obtained through homomorphic encryption function E h (·) The encrypted result, The final access right of the node is generated by the hash message authentication code. The result of the encrypted processing of the private information retrieval for the access rights of the node;
[0077] S65, distribute and store the encrypted access control list to each exchange node, and use the access record storage mechanism based on blockchain technology and the multi-level trusted computing platform to verify whether the document transmission process meets the authority requirements. If the node Access rights If the conditions are met, the node is allowed to participate in the document exchange, otherwise it is refused to participate and a security alarm is triggered.
[0078] The electronic document encryption exchange system for multiple exchange nodes according to an embodiment of the present invention includes the following modules:
[0079] Key management module, used to generate, manage and distribute keys required for document encryption;
[0080] Trust evaluation module, which is used to evaluate the reputation of each exchange node, calculate the trust value of the node based on historical behavior data, and dynamically adjust the path selection;
[0081] Key exchange module, used to implement secure key exchange protocol;
[0082] The path optimization module is used to dynamically select the optimal document transmission path based on the trust value and network delay to optimize the transmission efficiency;
[0083] Access control module, used to assign appropriate access rights to each switching node based on node reputation and path optimization results;
[0084] Data encryption module, used to encrypt official documents;
[0085] The anomaly detection module is used to monitor abnormal behavior during document transmission and optimize protection strategies.
[0086] The beneficial effects of the present invention are:
[0087] The present invention effectively solves the problems existing in the prior art in key management, path selection and access control by introducing an electronic document encryption exchange method based on dynamic trust evaluation and path optimization. First, by adopting a verifiable hybrid secret sharing mechanism and homomorphic encryption technology, the secure exchange of document encryption keys is ensured, avoiding the potential security risks that may arise in the traditional key management and exchange process. Compared with the existing single encryption scheme, the present invention can safely and efficiently transmit keys between multiple nodes, thereby improving the security and efficiency of document transmission.
[0088] Secondly, the technology based on node reputation evaluation and dynamic path optimization makes up for the limitations of existing path selection methods in multi-node and complex network environments. Traditional technologies often rely on static path selection or simple algorithms based on bandwidth, while the present invention optimizes the transmission path of official documents in real time by introducing dynamic evaluation of modified trust values and network delays, ensuring that official documents can still be efficiently transmitted under changing network conditions. At the same time, access rights are adjusted based on the trust of nodes, so that the system can respond to the threat of malicious nodes in real time, improving the system's anti-attack capabilities.
[0089] In addition, the access record storage mechanism based on blockchain technology makes all access and operation records traceable, increasing the transparency and auditability of the system. Compared with the prior art, the present invention not only ensures the confidentiality and integrity of data during the exchange process, but also improves the transparency and traceability of official document exchange, effectively preventing data tampering and illegal access.
[0090] In general, the present invention overcomes the security, efficiency and scalability issues of traditional electronic document exchange systems by introducing advanced technologies such as dynamic trust evaluation, path optimization, encrypted storage, and blockchain evidence storage, and has high innovation and practical application value. BRIEF DESCRIPTION OF THE DRAWINGS
[0091] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0092] Figure 1 This is a flow chart of the electronic document encryption exchange method for multiple exchange nodes proposed by the present invention;
[0093] Figure 2 This is a schematic diagram of the structure of the electronic document encryption exchange system for multiple exchange nodes proposed by the present invention. DETAILED DESCRIPTION
[0094] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.
[0095] refer to Figure 1 , an electronic document encryption exchange method for multiple exchange nodes, comprising the following steps:
[0096] S1. Build a document exchange environment, configure multiple exchange nodes, deploy core modules, and initialize key management strategies and trust assessment models;
[0097] S2, split the key using a verifiable hybrid secret sharing mechanism, and store it in a distributed manner after being protected by homomorphic encryption;
[0098] S3. Before the exchange of official documents, the node reputation is evaluated based on the trust evaluation model, the trust value is calculated in combination with Bayesian optimization, and the exchange path is generated;
[0099] S4, based on the exchange path, performing key exchange using a multi-party secure key exchange protocol based on verifiable secret negotiation;
[0100] S5. Based on the exchange path and key exchange results, the document transmission path is dynamically adjusted using adaptive topology-aware routing optimization;
[0101] S6. Based on the initialized key management policy and trust value, a dynamic verifiable storage mapping mechanism is used to manage access rights;
[0102] S7. During the exchange of official documents, detect abnormal traffic and optimize security protection strategies based on the official document transmission records.
[0103] In this implementation, S2 specifically includes:
[0104] S21. Let the official document data be D. Use the encryption algorithm based on polymorphic pseudo-random permutation to generate the key K. Encrypt the official document data to obtain the encrypted official document data D. ′ :
[0105]
[0106] Among them, H(D) is the hash value of the official document data, PRG(s) is the pseudo-random stream, mod is the modulus operation, λ is the key bit length, and ⊕ is the exclusive OR operation;
[0107] S22, using a verifiable hybrid secret sharing mechanism to split the key K, setting a threshold secret sharing scheme, splitting the key K into n key shares {K 1 ,K 2 ,...,K n}:
[0108]
[0109] Among them, K i is the key share, K is the original key, H(i) is the hash value of index i, r i is the key randomization factor, g is the generator, x i is the shared index, L is a large prime number, t is the total number of keys, L i is the interpolation coefficient, i is the key index;
[0110] S23. Perform homomorphic encryption on the key share. The homomorphic encryption function is E h (·), using the exponential homomorphic encryption method, the key share is encrypted as follows:
[0111]
[0112] Among them, H(K i ) is the hash value of the key share, E h (K i ) is the key share K i The result after homomorphic encryption;
[0113] S24, generate key share verification information, and use zero-knowledge proof to construct verification parameter V i :
[0114]
[0115] Among them, H is a secure hash function, h is a secure base, ξ i is the random challenge value;
[0116] S25. Distribute and store the encrypted key shares and corresponding key share verification information to multiple switching nodes.
[0117] In this implementation, S3 specifically includes:
[0118] S31, let the set of switching nodes be N = {N 1 ,N 2 ,…,N m}, for each node N i Collect its original behavior data to form a feature vector X i =[x i1 ,x i2 ,…,x id ] T , using adaptive normalization to generate enhanced feature vectors:
[0119]
[0120] Among them, μ Xis the mean vector, σ X is the standard deviation vector, Y i For node N i Enhanced feature vectors;
[0121] S32. Use graph convolutional network combined with self-attention mechanism to calculate the initial trust score T of each node i :
[0122]
[0123] Among them, T i is the initial trust score of the node, α is the activation function, W is the weight matrix, b is the bias term, ln is the logarithmic function, exp is the exponential function, W a is the self-attention weight matrix, Y j For node N j The enhanced feature vector of , m is the total number of exchange nodes, j is the exchange node index;
[0124] S33, based on Bayesian optimization, the initial trust score is updated to obtain the trust value
[0125]
[0126] Among them, μ 0,i is the prior mean of the node, ω i is the Bayesian optimization coefficient, is the prior variance of the node, is the observed variance of the node;
[0127] S34, construct a candidate switching path set ρ, and based on the trust value Select a switching path P, where the candidate path satisfy:
[0128]
[0129] Where k is the number of nodes in the path, δ is the weight factor, For Node The trust value, For Node and The network delay between P'∈ρ To select the path P' that minimizes the following objective function from the candidate path set ρ;
[0130] S35. Output trust score vector And the selected switching path P.
[0131] In this implementation manner, the S4 specifically includes:
[0132] S41, based on the generated switching path The key exchange is performed using a multi-party secure key exchange protocol based on verifiable secret negotiation;
[0133] S42, set the secure communication between nodes to C = {C i,j}, where each pair of adjacent nodes The key exchange process between i,j , using the following key exchange process:
[0134]
[0135] Among them, C i,j is the key exchange communication result. VSA-MPKE is a multi-party secure key exchange protocol based on verifiable secret negotiation. For Node Encryption key share The ciphertext obtained by homomorphic encryption method is For Node Encryption key share The ciphertext obtained by homomorphic encryption method, γ i,j is the communication key agreement protocol, δ i,j is the dynamic key enhancement factor;
[0136] S43. After the key exchange is completed, the node With Node The validity of the key exchange is verified by:
[0137]
[0138] Among them, V i,j For Node and The key exchange verification parameter between them, H is the hash function;
[0139] S44, using the key fusion method based on node reputation weighting, after the key exchange on all paths is completed, the key exchange result K is calculated by the following formula final :
[0140]
[0141] Where k is the number of nodes in the path, For Node The reputation weighting coefficient, mod is the modular operation, and L is a large prime number;
[0142] S45. Distribute the generated key exchange result to each exchange node through a distributed key distribution protocol.
[0143] In this implementation manner, S5 specifically includes:
[0144] S51, according to the switching path and key exchange result K final , initialize the routing optimization model and assign initial transmission parameters to each node in the document transmission path in For Node The routing parameter vector of
[0145] S52, using adaptive topology-aware routing optimization algorithm, based on the trust value of the node and network latency Dynamically adjust the document transmission path and calculate the nodes With Node The route parameters between:
[0146]
[0147] in, For Node Updated routing parameters, ε is the weight factor, d max is the maximum value of network delay, For Node Trust value;
[0148] S53, routing parameters for each document transmission path node Update and calculate the globally optimized document transmission path P opt , the weighted sum of the total transmission delay and the trust difference between nodes is minimized by the following optimization objective function:
[0149]
[0150] in, For Node The trust value, argmin P'∈P To find the path P' that minimizes the objective function in the path set ρ, k is the number of nodes in the path;
[0151] S54. Based on the optimized document transmission path, dynamically adjust the data flow between nodes and calculate the total bandwidth requirement of each path. Data traffic is scheduled according to network bandwidth constraints, using an adaptive traffic allocation algorithm based on trust and delay weighting:
[0152]
[0153] in, For Node The trust value of , ε is the weight factor;
[0154] S55, output the optimal document transmission path P opt and route parameters
[0155] In this implementation manner, S6 specifically includes:
[0156] S61, according to the initialized key management strategy and the generated trust value Adopt dynamic adaptive multi-level access control mechanism for each switching node Generate access rights data And perform hierarchical management on node access;
[0157] S62. Define the access permission vector of each node as in Representation Node The mth access permission level in path P;
[0158] S63, based on the trust value and path optimization result P opt , using a dynamic permission adjustment method based on node reputation weighting to dynamically adjust access rights between nodes:
[0159]
[0160] in, For Node The final access permission vector, θ is the reputation weighting coefficient, For Node The reputation change, k is the number of nodes in the path, and j is the node index;
[0161] S64. Generate an encrypted access control list based on the final access rights through a multi-factor authentication mechanism:
[0162]
[0163] in, is the access control list of the node, The final access rights of the node are obtained through homomorphic encryption function E h (·) The encrypted result, The final access right of the node is generated by the hash message authentication code. The result of the encrypted processing of the private information retrieval for the access rights of the node;
[0164] S65, distribute and store the encrypted access control list to each exchange node, and use the access record storage mechanism based on blockchain technology and the multi-level trusted computing platform to verify whether the document transmission process meets the authority requirements. If the node Access rights If the conditions are met, the node is allowed to participate in the document exchange, otherwise it is refused to participate and a security alarm is triggered.
[0165] refer to Figure 2 , an electronic document encryption exchange system for multiple exchange nodes, including the following modules:
[0166] Key management module, used to generate, manage and distribute keys required for document encryption;
[0167] Trust evaluation module, which is used to evaluate the reputation of each exchange node, calculate the trust value of the node based on historical behavior data, and dynamically adjust the path selection;
[0168] Key exchange module, used to implement secure key exchange protocol;
[0169] The path optimization module is used to dynamically select the optimal document transmission path based on the trust value and network delay to optimize the transmission efficiency;
[0170] Access control module, used to assign appropriate access rights to each switching node based on node reputation and path optimization results;
[0171] Data encryption module, used to encrypt official documents;
[0172] The anomaly detection module is used to monitor abnormal behavior during document transmission and optimize protection strategies.
[0173] Embodiment 1:
[0174] In order to verify the feasibility of the present invention in implementation, the present invention is applied to the electronic document exchange system of a certain government department. The system in the scenario adopts an electronic document encryption exchange method based on dynamic trust evaluation and path optimization, and makes full use of modules such as key management, trust evaluation, path optimization, and access control.
[0175] Within a government department, the exchange of electronic documents involves a large amount of sensitive data, which usually needs to be transmitted between multiple departments and units. Due to the particularity of government documents, the confidentiality, integrity and timeliness of data transmission need to be considered during the exchange of documents. Traditional electronic document exchange systems usually rely on fixed paths and static access control mechanisms, and face the following problems: 1) The selection of document transmission paths does not take into account the dynamic changes of the network in real time, resulting in low efficiency; 2) The trust of nodes is not evaluated and adjusted dynamically in a timely manner, and malicious nodes may affect the security of the system; 3) There is a potential risk of leakage during the exchange and storage of keys, making it difficult to ensure the secure transmission of encrypted data between multiple nodes.
[0176] In order to solve these problems, the technology of the present invention is applied to introduce a document exchange solution based on dynamic trust evaluation and path optimization, and the following improvements are made:
[0177] First, in the encryption module, a verifiable hybrid secret sharing mechanism and homomorphic encryption technology are used to encrypt official document data. During the key exchange process, the system selects the optimal path for official document exchange based on the reputation value of each exchange node and the real-time network delay. Specifically, when exchanging keys between nodes, the system will dynamically select the key exchange path between nodes based on the node's reputation prediction and network delay to ensure the secure transmission of keys. After adopting this scheme, the efficiency of key exchange has increased by about 20%, and due to the evaluation of node reputation, the system can avoid the participation of malicious nodes, thereby improving the security of official document exchange.
[0178] In terms of trust evaluation, the system dynamically calculates the reputation of each node through graph convolutional networks and Bayesian optimization algorithms. The reputation of a node is not only based on historical behavior data, but also adjusted in real time based on factors such as network latency and node response time. In this way, the system can automatically adjust access rights and path selection based on the behavior of the node, thereby ensuring the security and efficiency of data transmission. In an actual test, by using the trust evaluation mechanism of the present invention, the accuracy of the node's trust evaluation was improved by about 30%, effectively reducing the threat of malicious nodes to system security.
[0179] In addition, the path optimization module uses a dynamic path adjustment algorithm, taking into account changes in network latency and node trust, and dynamically selects the optimal path. Through this optimization, the transmission time of official documents has been greatly shortened. In the test, compared with the traditional static path selection, the transmission time of official documents was shortened by about 25%. For example, the time for a document to be transmitted from one department to another was reduced from 12 minutes to 9 minutes, which greatly improved the transmission efficiency of official documents.
[0180] In terms of access control, the system adopts a multi-level access control strategy to dynamically allocate access rights to each exchange node based on the node's reputation. When controlling node access, the system not only relies on static permission settings, but also adjusts its permissions in real time according to changes in node reputation. In the test, the system's access control accuracy was improved by about 40%, effectively preventing unauthorized nodes from accessing official document data and ensuring the security of the system.
[0181] In terms of data storage and management, all access control information and transmission records are stored through blockchain technology. This technology ensures the traceability of access rights to official documents, and all operations and records are encrypted and stored in the blockchain to prevent data tampering and illegal access. This not only improves the transparency of the system, but also increases the credibility of the system.
[0182] Table 1 Electronic document exchange system performance improvement data table
[0183]
[0184] According to the data analysis in the table, after adopting the technology of the present invention, the official document exchange system has shown significant improvements in many aspects.
[0185] First, the document transmission time was reduced from 12 minutes in the traditional solution to 9 minutes, with an improvement of -25%, showing that the present invention has significantly improved the efficiency of path optimization and key exchange. Second, the accuracy of node reputation evaluation was improved by 30%, from 70% in the traditional solution to 95%, indicating that the present invention has made significant progress in the accuracy of reputation evaluation. Furthermore, the malicious node identification rate was increased from 60% in the traditional solution to 98%, with an improvement of +38%, effectively improving the security of the system.
[0186] In terms of encryption key exchange efficiency, the present invention shortens the key exchange time from the traditional 15 seconds to 12 seconds, an improvement of -20%, optimizing the speed of data exchange. In addition, the access control accuracy is increased from the traditional 65% to 90%, an improvement of +40%, further strengthening the access control during the exchange of official documents.
[0187] Finally, the tampering detection rate in data transmission has increased by 44%, from the traditional 55% to 99%, effectively ensuring the integrity and security of data transmission.
[0188] In summary, the present invention improves the efficiency and security of official document exchange and significantly optimizes system performance by introducing multiple innovative technologies.
[0189] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. An electronic document encryption exchange method for multiple exchange nodes, characterized in that: The steps include: S1. Build a document exchange environment, configure multiple exchange nodes, deploy core modules, and initialize key management strategies and trust assessment models; S2, split the key using a verifiable hybrid secret sharing mechanism, and store it in a distributed manner after being protected by homomorphic encryption; S3. Before the exchange of official documents, the node reputation is evaluated based on the trust evaluation model, the trust value is calculated in combination with Bayesian optimization, and the exchange path is generated; S4, based on the exchange path, performing key exchange using a multi-party secure key exchange protocol based on verifiable secret negotiation; S5. Based on the exchange path and key exchange results, the document transmission path is dynamically adjusted using adaptive topology-aware routing optimization; S6. Based on the initialized key management policy and trust value, a dynamic verifiable storage mapping mechanism is used to manage access rights; S7. During the exchange of official documents, detect abnormal traffic and optimize security protection strategies based on the official document transmission records.
2. The electronic document encryption exchange method for multiple exchange nodes according to claim 1 is characterized in that: The S2 specifically includes: S21. Let the official document data be D. Use the encryption algorithm based on polymorphic pseudo-random permutation to generate the key K. Encrypt the official document data to obtain the encrypted official document data D. ′ : Among them, H(D) is the hash value of the document data, PRG(s) is the pseudo-random stream, mod is the modular operation, λ is the key bit length, is an XOR operation; S22, using a verifiable hybrid secret sharing mechanism to split the key K, setting a threshold secret sharing scheme, splitting the key K into n key shares {K1, K2, ..., K n }: Among them, K i is the key share, K is the original key, H(i) is the hash value of index i, r i is the key randomization factor, g is the generator, x i is the shared index, L is a large prime number, t is the total number of keys, L i is the interpolation coefficient, i is the key index; S23. Perform homomorphic encryption on the key share. The homomorphic encryption function is E h (·), using the exponential homomorphic encryption method, the key share is encrypted as follows: Among them, H(K i ) is the hash value of the key share, E h (K i ) is the key share K i The result after homomorphic encryption; S24, generate key share verification information, and use zero-knowledge proof to construct verification parameter V i : Among them, H is a secure hash function, h is a secure base, ξ i is the random challenge value; S25. Distribute and store the encrypted key shares and corresponding key share verification information to multiple switching nodes.
3. The method for electronic document encryption exchange for multiple exchange nodes according to claim 1 is characterized in that: The S3 specifically includes: S31, let the set of switching nodes be N = {N1, N2, ..., N m }, for each node N i Collect its original behavior data to form a feature vector X i =[x i1 ,x i2 ,…,x id ] T , using adaptive normalization to generate enhanced feature vectors: Among them, μ X is the mean vector, σ X is the standard deviation vector, Y i For node N i Enhanced feature vectors; S32. Use graph convolutional network combined with self-attention mechanism to calculate the initial trust score T of each node i : Among them, T i is the initial trust score of the node, α is the activation function, W is the weight matrix, b is the bias term, ln is the logarithmic function, exp is the exponential function, W a is the self-attention weight matrix, Y j For node N j The enhanced feature vector of , m is the total number of exchange nodes, j is the exchange node index; S33, based on Bayesian optimization, the initial trust score is updated to obtain the trust value Among them, μ 0,i is the prior mean of the node, ω i is the Bayesian optimization coefficient, is the prior variance of the node, is the observed variance of the node; S34, construct a candidate switching path set ρ, and based on the trust value Select a switching path P, where the candidate path satisfy: Where k is the number of nodes in the path, δ is the weight factor, For Node The trust value, For Node and The network delay between P'∈ρ To select the path P' that minimizes the following objective function from the candidate path set ρ; S35. Output trust score vector and the selected switching path P.
4. The method for electronic document encryption exchange for multiple exchange nodes according to claim 1 is characterized in that: The S4 specifically includes: S41, based on the generated switching path The key exchange is performed using a multi-party secure key exchange protocol based on verifiable secret negotiation; S42, set the secure communication between nodes to C = {C i,j }, where each pair of adjacent nodes The key exchange process between i,j , using the following key exchange process: Among them, C i,j is the key exchange communication result. VSA-MPKE is a multi-party secure key exchange protocol based on verifiable secret negotiation. For Node Encryption key share The ciphertext obtained by homomorphic encryption method is For Node Encryption key share The ciphertext obtained by homomorphic encryption method, γ i,j is the communication key agreement protocol, δ i,j is the dynamic key enhancement factor; S43. After the key exchange is completed, the node With Node The validity of the key exchange is verified by: Among them, V i,j For Node and The key exchange verification parameter between them, H is the hash function; S44, using the key fusion method based on node reputation weighting, after the key exchange on all paths is completed, the key exchange result K is calculated by the following formula final : Where k is the number of nodes in the path, For Node The reputation weighting coefficient, mod is the modular operation, and L is a large prime number; S45. Distribute the generated key exchange result to each exchange node through a distributed key distribution protocol.
5. The method for electronic document encryption exchange for multiple exchange nodes according to claim 1 is characterized in that: The S5 specifically includes: S51, according to the switching path and key exchange result K final , initialize the routing optimization model and assign initial transmission parameters to each node in the document transmission path in For Node The routing parameter vector of S52, using adaptive topology-aware routing optimization algorithm, based on the trust value of the node and network latency Dynamically adjust the document transmission path and calculate the nodes With Node The route parameters between: in, For Node Updated routing parameters, ε is the weight factor, d max is the maximum value of network delay, For Node Trust value; S53, routing parameters for each document transmission path node Update and calculate the globally optimized document transmission path P opt , the weighted sum of the total transmission delay and the trust difference between nodes is minimized by the following optimization objective function: in, For Node The trust value, argmin P'∈P To find the path P' that minimizes the objective function in the path set ρ, k is the number of nodes in the path; S54. Based on the optimized document transmission path, dynamically adjust the data flow between nodes and calculate the total bandwidth requirement of each path. Data traffic is scheduled according to network bandwidth constraints, using an adaptive traffic allocation algorithm based on trust and delay weighting: in, For Node The trust value of , ε is the weight factor; S55, output the optimal document transmission path P opt and route parameters 6. The electronic document encryption exchange method for multiple exchange nodes according to claim 1 is characterized in that: The S6 specifically includes: S61, according to the initialized key management strategy and the generated trust value Adopt dynamic adaptive multi-level access control mechanism for each switching node Generate access rights data And perform hierarchical management on node access; S62. Define the access permission vector of each node as in Representation Node The mth access permission level in path P; S63, based on the trust value and path optimization result P opt , using a dynamic permission adjustment method based on node reputation weighting to dynamically adjust access rights between nodes: in, For Node The final access permission vector, θ is the reputation weighting coefficient, For Node The change in reputation, k is the number of nodes in the path, and j is the node index; S64. Generate an encrypted access control list based on the final access rights through a multi-factor authentication mechanism: in, is the access control list of the node, The final access rights of the node are obtained through homomorphic encryption function E h (·) The encrypted result, The final access right of the node is generated by the hash message authentication code. The result of the encrypted processing of the private information retrieval for the access rights of the node; S65, distribute and store the encrypted access control list to each exchange node, and use the access record storage mechanism based on blockchain technology and the multi-level trusted computing platform to verify whether the document transmission process meets the authority requirements. If the node Access rights If the conditions are met, the node is allowed to participate in the document exchange, otherwise it is refused to participate and a security alarm is triggered.
7. An electronic document encryption exchange system for multiple exchange nodes, an electronic document encryption exchange method for multiple exchange nodes as claimed in any one of claims 1 to 6, characterized in that: Includes the following modules: Key management module, used to generate, manage and distribute keys required for document encryption; Trust evaluation module, which is used to evaluate the reputation of each exchange node, calculate the trust value of the node based on historical behavior data, and dynamically adjust the path selection; Key exchange module, used to implement secure key exchange protocol; The path optimization module is used to dynamically select the optimal document transmission path based on the trust value and network delay to optimize the transmission efficiency; Access control module, used to assign appropriate access rights to each switching node based on node reputation and path optimization results; Data encryption module, used to encrypt official documents; The anomaly detection module is used to monitor abnormal behavior during document transmission and optimize protection strategies.
Citation Information
Patent Citations
Safety verification system for electronic document office system and method thereof
CN102333077A
Electronic official document exchange system
CN115664687A
Office document processing method and system
CN116127427A
Internet of Things access control system and method based on smart contract and trust evaluation
CN119420522A
Official document circulating system based on goverment affairs trust and authorized service
CN1350255A