Information leakage prevention method and device
By combining zero-trust architecture, dynamic key flow and blockchain technology, the problem of data leakage risks in complex network environments is solved, high security and leakage prevention capabilities of data transmission are achieved, implementation costs are reduced, and the efficiency of dynamic key management and blockchain integration is improved.
Patent Information
- Application Number
- CN202510518921.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-24
AI Technical Summary
The existing technology seems to be incompetent in dealing with the risk of data leakage in complex network environments. Traditional encryption methods are vulnerable to attacks, and the implementation cost of privacy enhancement technology is high. Zero-trust architecture still has room for improvement in dynamic key management and blockchain integration.
Combining the zero-trust architecture, dynamic key stream and blockchain technology, network data packets are obtained and verified through the computing unit, edge computing equipment performs feature extraction, and the computing unit performs in-depth message detection and determines whether the data payload content is a negotiated message. If so, a dynamic key stream is generated for encryption and storage in the blockchain. If not, a smart contract for blockchain is called for distributed decryption.
It improves the security and leakage prevention capabilities of data transmission, enhances the ability to respond to data leakage risks in complex network environments, reduces implementation costs, and improves the efficiency of dynamic key management and blockchain integration.
Smart Images

Figure CN120074952A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of information security technology, and particularly relates to an information leakage prevention method and device. Background Art
[0002] With the rapid development of information technology, the problem of data leakage has become increasingly serious. Traditional information security technologies are unable to cope with the data leakage risks in complex network environments. Existing data leakage prevention technologies mainly focus on the following aspects: Data Encryption and Access Control: Protect the confidentiality of data through encryption technology. However, traditional encryption methods are vulnerable to attacks in dynamic network environments and are difficult to adapt to complex access control requirements.
[0003] Privacy Enhancement Technologies: Such as homomorphic encryption and differential privacy technologies. Although they have certain effects in protecting privacy, their usability and implementation costs in actual business still need to be optimized.
[0004] The Rise of the Zero-Trust Architecture: The zero-trust architecture improves security through multi-dimensional verification (such as device identity, user permissions, and context association). However, there is still room for improvement in its dynamic key management and blockchain integration. Summary of the Invention
[0005] In view of the above problems, this application proposes an information leakage prevention method and device that combines the zero-trust architecture, dynamic key stream, and blockchain technology, aiming to improve the security and leakage prevention ability of data transmission.
[0006] In a first aspect, an embodiment of this application provides an information leakage prevention method. The information leakage prevention method is applied to an information leakage prevention device, and the information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes: The computing unit obtains network data packets and verifies them through the zero-trust architecture module; The edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit; The computing unit performs deep packet inspection on the network data packets that pass the verification to generate data payload content; The computing unit determines whether the data payload content is a negotiation message; If the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic features and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content; The encryption module sends the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit invokes the smart contract of the blockchain and jointly decrypts the data payload content with the edge computing device.
[0007] In a second aspect, an information leakage prevention device is provided in an embodiment of the present application. The information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes: The computing unit is configured to obtain a network data packet and perform verification through the zero-trust architecture module; The edge computing device is configured to extract features of the network data packet to obtain traffic features and send the traffic features to the computing unit; The computing unit is configured to perform deep packet inspection on the network data packet that passes the verification to generate data payload content; determine whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic features and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content; The encryption module is configured to send the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit invokes the smart contract of the blockchain and jointly decrypts the data payload content with the edge computing device.
[0008] In a third aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the information leakage prevention method described in any one of the first aspects above is implemented.
[0009] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the information leakage prevention method described in any one of the first aspects above is implemented.
[0010] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a computer device, the computer device is caused to execute the information leakage prevention method described in any one of the first aspects above.
[0011] The beneficial effects of the embodiments of the present application compared with the prior art are as follows: The embodiments of the present application provide an information anti-leakage method, which is applied to an information anti-leakage device. The information anti-leakage device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain. The information anti-leakage method includes: the computing unit obtains network data packets and verifies them through the zero-trust architecture module; the edge computing device extracts features from the network data packets to obtain traffic features and sends the traffic features to the computing unit; the computing unit performs deep packet inspection on the network data packets that pass the verification to generate data payload content; the computing unit determines whether the data payload content is a negotiation message; if the data payload content is a negotiation message, the encryption module generates an enhanced key QK+, generates a dynamic key stream based on the traffic features and the enhanced key QK+, and encrypts the data payload content based on the dynamic key stream to generate a target data payload content; the encryption module sends the target data payload content to the blockchain for storage and recording; if the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly decrypts the data payload content with the edge computing device.
[0012] It can be understood that the beneficial effects of the second to fifth aspects above can refer to the relevant descriptions in the first aspect above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0014] Figure 1 It is a flowchart of the information anti-leakage method provided by an embodiment of the present application; Figure 2 It is a structural diagram of the information anti-leakage device provided by an embodiment of the present application; Figure 3 It is a structural diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0015] In the following description, specific details such as specific system architectures and technologies are presented for purposes of illustration and not limitation in order to provide a thorough understanding of the embodiments of the present application. However, those skilled in the art should understand that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present application with unnecessary details.
[0016] It should be understood that when used in the specification of the present application and the appended claims, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their combinations.
[0017] It should also be understood that the term "and / or" as used in the specification of the present application and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0018] As used in the specification of the present application and the appended claims, the term "if" may be interpreted, depending on the context, as "when" or "once" or "in response to determining" or "in response to detecting". Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined" or "in response to determining" or "once detected [the described condition or event]" or "in response to detecting [the described condition or event]".
[0019] In addition, in the description of the specification of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for descriptive distinction and should not be construed as indicating or implying relative importance.
[0020] The reference to "one embodiment" or "some embodiments" or the like described in the specification of the present application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the present application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.
[0021] Figure 1The figure shows a schematic flowchart of an information anti-leakage method provided by this application. Among them, the information anti-leakage method is applied to an information anti-leakage device, and the information anti-leakage device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information anti-leakage method includes: Step S101, the computing unit obtains network data packets and verifies them through the zero-trust architecture module.
[0022] Among them, the computing unit captures the flowing network data packets in real time through the network interface, and supports the acquisition of network data packets in various protocol formats such as TCP / IP, UDP, and ICMP.
[0023] Among them, for the obtained network data packets, the zero-trust architecture module executes the following multi-dimensional verification processes: device identity authenticity verification, user permission grading verification, context association verification, and so on.
[0024] Step S102, the edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit.
[0025] Step S103, the computing unit performs deep packet inspection on the network data packets that have passed the verification to generate data payload content.
[0026] Step S104, the computing unit determines whether the data payload content is a negotiation message.
[0027] Step S105, if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic feature and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content.
[0028] Step S106, the encryption module sends the target data payload content to the blockchain for storage and recording.
[0029] Step S107, if the data payload content is not the negotiation message, the computing unit invokes the smart contract of the blockchain and jointly decrypts the data payload content with the edge computing device.
[0030] In an optional embodiment, step S103 that the computing unit performs deep packet inspection on the network data packets that have passed the verification to generate data payload content includes: Step a1, the computing unit performs deep packet inspection on the network data packets that have passed the verification to obtain data packets.
[0031] Step a2, the computing unit determines the type and priority of the data packet.
[0032] Step a3, the computing unit allocates the data packet to different edge computing nodes based on the type and priority of the data packet, and generates the data payload content.
[0033] In an optional embodiment, the information leakage prevention device further includes a cloud, and a feature library is pre-stored in the cloud; the computing unit in step S104 determines whether the data payload content is a negotiation packet, including: Step b1, pulse-encode the data payload content using a spiking neural network, convert the data payload content into a time-series pulse signal, and extract spatio-temporal features from the time-series pulse signal to generate a pulse feature matrix.
[0034] Step b2, perform phase space reconstruction on the pulse feature matrix to generate a chaotic trajectory feature vector.
[0035] Step b3, generate a composite feature vector based on the pulse feature matrix and the chaotic trajectory feature vector, and perform cosine similarity matching with the feature library in the cloud to determine whether the data payload content is the negotiation packet.
[0036] In an optional embodiment, step S105 includes generating an enhanced key QK+ through the encryption module, generating a dynamic key stream based on the traffic feature and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate a target data payload content, including: Step c1, generate an initial quantum key QK through the encryption module, and generate the enhanced key QK+ by combining the obtained device hardware fingerprint entropy value.
[0037] Step c2, generate an attribute key SK according to the obtained attribute basis, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append it to the IP header extension field in the data payload content.
[0038] Step c3, perform an exclusive OR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream.
[0039] Step c4, encrypt the appended data payload content based on the dynamic key stream to generate the target data payload content.
[0040] In an optional embodiment, the method further includes: Step d1, determine whether the negotiation phase processing is completed based on the target data payload content.
[0041] Step d2, if not completed, return to the calculation unit to perform deep packet inspection on the verified network packets to generate the data payload content.
[0042] Step d3, if completed, determine the processing status and data performance based on the target data payload content, and feedback the processing status and data performance to the cloud.
[0043] Step d4, the cloud adjusts the processing policy and resource allocation according to the processing status and data performance.
[0044] It should be understood that the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0045] Corresponding to the information leakage prevention method described in the above embodiments, Figure 2 The block diagram of the information leakage prevention device provided by the embodiments of the present application is shown. For the convenience of description, only the parts related to the embodiments of the present application are shown.
[0046] Refer to Figure 2 , the information leakage prevention device includes: a calculation unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes: The calculation unit is used to obtain network packets and verify them through the zero-trust architecture module; The edge computing device is used to extract features from the network packets to obtain traffic features, and send the traffic features to the calculation unit; The calculation unit is used to perform deep packet inspection on the verified network packets to generate data payload content; determine whether the data payload content is a negotiation packet; if the data payload content is a negotiation packet, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic features and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate a target data payload content; The encryption module is used to send the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation packet, the calculation unit calls the smart contract of the blockchain to jointly decrypt the data payload content with the edge computing device.
[0047] In a possible implementation, the calculation unit is used for: Perform deep packet inspection on the verified network packets to obtain data packets; Determine the type and priority of the data packet; Based on the type and priority of the data packet, allocate the data packet to different edge computing nodes to generate the data payload content.
[0048] In a possible implementation, the information leakage prevention device further includes a cloud, and a feature library is pre-stored in the cloud; The computing unit is used to perform pulse coding on the data payload content by using a spiking neural network, convert the data payload content into a time series pulse signal, extract spatio-temporal features from the time series pulse signal to generate a pulse feature matrix; perform phase space reconstruction on the pulse feature matrix to generate a chaotic trajectory feature vector; generate a composite feature vector according to the pulse feature matrix and the chaotic trajectory feature vector, and perform cosine similarity matching with the feature library in the cloud to determine whether the data payload content is the negotiation packet.
[0049] In a possible implementation, the encryption module is used for: Generate an initial quantum key QK, and generate the enhanced key QK+ by combining the obtained device hardware fingerprint entropy value; Generate an attribute key SK according to the obtained attribute basis, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append it to the IP header extension field in the data payload content; Perform an exclusive OR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream; Encrypt the data payload content after appending based on the dynamic key stream to generate the target data payload content.
[0050] In a possible implementation, the information leakage prevention device further includes: A judgment module, used to judge whether the negotiation stage processing is completed based on the target data payload content; A return module, used to return to the step of the computing unit to perform in-depth packet detection on the network data packet that has passed the verification to generate the data payload content if not completed; A feedback module, used to determine the processing status and data performance based on the target data payload content and feedback the processing status and data performance to the cloud if completed; The cloud is used to adjust the processing strategy and resource allocation according to the processing status and data performance.
[0051] It should be noted that the information interaction, execution process, etc. between the above modules, due to the same concept as the method embodiment of the present application, for the specific functions and the technical effects brought, please refer to the method embodiment part specifically, and will not be elaborated here.
[0052] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In practical applications, the above functions can be assigned to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of this application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.
[0053] This application embodiment also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, the steps in any of the foregoing method embodiments are implemented.
[0054] This application embodiment also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in each of the foregoing method embodiments can be implemented.
[0055] This application embodiment provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal is caused to execute the steps in each of the foregoing method embodiments.
[0056] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above method embodiments of this application, a computer program can be used to instruct relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device that can carry the computer program code to the photographing device / terminal device, recording medium, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0057] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0058] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0059] In the embodiments provided in this application, it should be understood that the disclosed device / network device and method can be implemented in other ways. For example, the device / network device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0060] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0061] The above embodiments are only used to illustrate the technical solutions of the present application, not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included within the protection scope of the present application.
[0062] Figure 3 The structural schematic diagram of a computer device provided by an embodiment of the present application. As Figure 3 shown, the computer device of this embodiment includes: at least one processor 20 ( Figure 3 only one is shown in the figure), a memory 21, and a computer program 22 stored in the memory 21 and executable on the at least one processor 20. When the processor 20 executes the computer program 22, the steps in any of the above-mentioned information leakage prevention method embodiments are implemented.
[0063] The computer device may include, but is not limited to, a processor 20 and a memory 21. Those skilled in the art can understand that Figure 3 this is only an example of a computer device and does not constitute a limitation on the computer device. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.
[0064] The so-called processor 20 may be a central processing unit (CPU), and this processor 20 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.
[0065] In some embodiments, the memory 21 may be an internal storage unit of the computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 21 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device. Further, the memory 21 may also include both the internal storage unit and the external storage device of the computer device. The memory 21 is used to store an operating system, application programs, a BootLoader, data, and other programs, such as program codes of the computer program. The memory 21 may also be used to temporarily store data that has been output or will be output.
[0066] In each embodiment of the present application, the relevant user personal information that may be involved is all processed in strict accordance with the requirements of laws and regulations, following the principles of legality, legitimacy, and necessity, and for reasonable purposes based on business scenarios, for the personal information actively provided by the user during the use of the product / service or generated due to the use of the product / service, as well as the personal information obtained with the user's authorization.
[0067] The user personal information processed by the applicant may vary depending on the specific product / service scenario, and it is subject to the specific scenario of the user's use of the product / service. It may involve the user's account information, device information, driving information, vehicle information, or other relevant information. The applicant will treat the user's personal information and its processing with a high degree of diligence.
[0068] The applicant attaches great importance to the security of user personal information and has taken security protection measures that meet industry standards and are reasonable and feasible to protect the user's information and prevent the personal information from being accessed, publicly disclosed, used, modified, damaged, or lost without authorization.
Claims
1. A method for preventing information leakage, characterized in that: The information leakage prevention method is applied to an information leakage prevention device, which includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes: The computing unit obtains a network data packet and verifies it through the zero trust architecture module; The edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit; The computing unit performs deep packet inspection on the verified network data packets to generate data payload content; The calculation unit determines whether the data payload content is a negotiation message; If the data payload content is a negotiation message, generating an enhanced key QK+ through the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate a target data payload content; The encryption module sends the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and cooperates with the edge computing device to perform distributed decryption on the data payload content.
2. The information leakage prevention method according to claim 1, characterized in that: The computing unit performs deep packet inspection on the verified network data packets to generate data payload content, including: The computing unit performs deep packet inspection on the verified network data packet to obtain a data packet; The computing unit determines the type and priority of the data message; The computing unit distributes the data message to different edge computing nodes based on the type and priority of the data message, and generates the data payload content.
3. The information leakage prevention method according to claim 2, characterized in that: The information leakage prevention device further includes a cloud, wherein the cloud pre-stores a feature library; The calculating unit determines whether the data payload content is a negotiation message, including: Using a pulse neural network to pulse encode the data payload content, convert the data payload content into a time series pulse signal, and extract spatiotemporal features from the time series pulse signal to generate a pulse feature matrix; Reconstruct the pulse characteristic matrix in phase space to generate chaotic trajectory characteristic vector; A composite feature vector is generated according to the pulse feature matrix and the chaotic trajectory feature vector, and cosine similarity matching is performed with the feature library on the cloud to determine whether the data payload content is the negotiation message.
4. The information leakage prevention method according to claim 3, characterized in that: The step of generating an enhanced key QK+ through the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content includes: Generate an initial quantum key QK through the encryption module, and generate the enhanced key QK+ in combination with the acquired device hardware fingerprint entropy value; Generate an attribute key SK according to the acquired attribute base, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append it to the IP header extension field in the data payload content; Performing an XOR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream; The attached data payload content is encrypted based on the dynamic key stream to generate the target data payload content.
5. The information leakage prevention method according to claim 4, characterized in that: The method further comprises: Determining whether the negotiation phase processing is completed based on the target data payload content; If not completed, return to the step of performing deep packet inspection on the verified network data packet by the computing unit to generate data payload content; If completed, a processing state and data performance will be determined based on the target data payload content, and the processing state and data performance will be fed back to the cloud; The cloud adjusts processing strategies and resource allocation according to processing status and data performance.
6. An information leakage prevention device, characterized in that: The information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module and a blockchain; The computing unit is used to obtain network data packets and verify them through the zero trust architecture module; The edge computing device is used to extract features from the network data packets to obtain traffic features, and send the traffic features to the computing unit; The computing unit is configured to perform deep message inspection on the verified network data packet to generate data payload content; determine whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate a target data payload content; The encryption module is used to send the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and cooperates with the edge computing device to perform distributed decryption on the data payload content.
7. The information leakage prevention device according to claim 6, characterized in that: The information leakage prevention device further includes a cloud, wherein the cloud pre-stores a feature library; The computing unit is used to pulse encode the data payload content using a pulse neural network, convert the data payload content into a time series pulse signal, extract spatiotemporal features from the time series pulse signal, and generate a pulse feature matrix; The pulse feature matrix is reconstructed in phase space to generate a chaotic trajectory feature vector; a composite feature vector is generated according to the pulse feature matrix and the chaotic trajectory feature vector, and a cosine similarity match is performed with the feature library on the cloud to determine whether the data payload content is the negotiation message.
8. A computer device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 5 when executing the computer program.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
10. A computer program product, characterized in that When the computer program product is executed on a computer device, the computer device is caused to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Lightweight zero-trust system based on channel information and suitable for edge internet-of-things environment and construction method
CN116915817A
Data transmission method and device based on quantum encryption, terminal equipment and storage medium
CN118764297A
Communication method, system and device, electronic equipment, storage medium and program product
CN118802141A
Self-adaptive zero-trust network evaluation method and system based on edge calculation
CN118869267A
Encrypted communication method, related equipment and encrypted communication system
CN119070974A