Information leakage prevention method and device
By combining zero-trust architecture, dynamic key stream and blockchain technology, the problem that data leakage prevention technology is difficult to adapt to access control in a dynamic network environment is solved, and the security of data transmission and the prevention of leakage capabilities are improved.
Patent Information
- Application Number
- CN202510518921.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-04-24
AI Technical Summary
Existing data leakage prevention technologies are difficult to adapt to complex access control requirements in dynamic network environments, traditional encryption methods are vulnerable to attacks, and there is room for improvement in zero-trust architecture in terms of dynamic key management and blockchain integration.
Combining zero-trust architecture, dynamic key stream and blockchain technology, network data packets are verified through computing units, edge computing devices extract traffic characteristics, generate data payload content, and use encryption modules to generate dynamic key streams to encrypt data, store it in the blockchain, or call smart contracts for distributed decryption.
It improves the security and anti-leakage capabilities of data transmission, adapts to access control requirements in complex network environments, and enhances data confidentiality and privacy protection.
Smart Images

Figure CN120074952B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method and device for preventing information leakage. Background Art
[0002] With the rapid development of information technology, data leakage is becoming increasingly serious. Traditional information security technologies are unable to cope with the risk of data leakage in complex network environments. Existing data leakage prevention technologies mainly focus on the following aspects:
[0003] Data encryption and access control: Encryption technology is used to protect data confidentiality, but traditional encryption methods are vulnerable to attacks in dynamic network environments and are difficult to adapt to complex access control requirements.
[0004] Privacy-enhancing technologies: Although technologies such as homomorphic encryption and differential privacy have certain effects in protecting privacy, their usability and implementation costs in actual business still need to be optimized.
[0005] The rise of zero-trust architecture: Zero-trust architecture improves security through multi-dimensional verification (such as device identity, user permissions, and contextual association), but there is still room for improvement in dynamic key management and blockchain integration. Summary of the Invention
[0006] To address the above issues, this application proposes an information leakage prevention method and device that combines zero-trust architecture, dynamic key stream and blockchain technology, aiming to improve the security and leakage prevention capabilities of data transmission.
[0007] In a first aspect, an embodiment of the present application provides an information leakage prevention method, which is applied to an information leakage prevention device, wherein the information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes:
[0008] The computing unit obtains the network data packet and verifies it through the zero trust architecture module;
[0009] The edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit;
[0010] The computing unit performs deep packet inspection on the verified network data packets to generate data payload content;
[0011] The calculation unit determines whether the data payload content is a negotiation message;
[0012] If the data payload content is a negotiation message, generating an enhanced key QK+ by the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content;
[0013] The encryption module sends the target data payload content to the blockchain for storage and recording;
[0014] If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device.
[0015] In a second aspect, an embodiment of the present application provides an information leakage prevention device, the information leakage prevention device comprising: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method comprising:
[0016] The computing unit is configured to obtain network data packets and verify them through the zero-trust architecture module;
[0017] The edge computing device is configured to extract features from the network data packets to obtain traffic features, and send the traffic features to the computing unit;
[0018] The computing unit is configured to perform deep packet inspection on the authenticated network data packet to generate data payload content; determine whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content;
[0019] The encryption module is used to send the target data payload content to the blockchain for storage and recording;
[0020] If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device.
[0021] In a third aspect, an embodiment of the present application provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the information leakage prevention method described in any one of the first aspects above is implemented.
[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the information leakage prevention method described in any one of the first aspects above is implemented.
[0023] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a computer device, enables the computer device to execute the information leakage prevention method described in any one of the first aspects above.
[0024] Compared with the prior art, the embodiments of the present application have the following advantages: the embodiments of the present application provide an information leakage prevention method, which is applied to an information leakage prevention device, and the information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module and a blockchain; the information leakage prevention method includes: the computing unit obtains a network data packet and verifies it through the zero-trust architecture module; the edge computing device extracts features from the network data packet to obtain traffic features, and sends the traffic features to the computing unit; the computing unit performs deep message detection on the verified network data packet to generate a data packet. The computing unit determines whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generates an enhanced key QK+ through the encryption module, generates a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypts the data payload content based on the dynamic key stream to generate target data payload content; the encryption module sends the target data payload content to the blockchain for storage and recording; if the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device.
[0025] It can be understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0027] Figure 1 This is a flowchart of an information leakage prevention method provided by an embodiment of the present application;
[0028] Figure 2is a schematic structural diagram of an information leakage prevention device provided in an embodiment of the present application;
[0029] Figure 3 It is a structural diagram of the computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0030] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0031] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0032] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0033] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0034] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0035] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0036] Figure 1 A schematic flow chart of an information leakage prevention method provided by the present application is shown. The information leakage prevention method is applied to an information leakage prevention device, which includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes:
[0037] In step S101, the computing unit obtains a network data packet and verifies it through the zero-trust architecture module.
[0038] Among them, the computing unit captures the network data packets flowing through the network interface in real time, and supports the acquisition of network data packets in multiple protocol formats such as TCP / IP, UDP, and ICMP.
[0039] Among them, for the obtained network data packets, the zero-trust architecture module performs the following multi-dimensional verification process: device identity authenticity verification, user authority level verification, context association verification, etc.
[0040] In step S102, the edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit.
[0041] Step S103: the computing unit performs deep packet inspection on the verified network data packets to generate data payload content.
[0042] Step S104: The calculation unit determines whether the data payload content is a negotiation message.
[0043] In step S105, if the data payload content is a negotiation message, an enhanced key QK+ is generated through the encryption module, and a dynamic key stream is generated based on the traffic characteristics and the enhanced key QK+, and the data payload content is encrypted based on the dynamic key stream to generate the target data payload content.
[0044] In step S106, the encryption module sends the target data payload content to the blockchain for storage and recording.
[0045] Step S107: If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device.
[0046] In an optional embodiment, the computing unit in step S103 performs deep packet inspection on the verified network data packet to generate data payload content, including:
[0047] In step a1, the computing unit performs deep packet inspection on the verified network data packet to obtain a data packet.
[0048] In step a2, the calculation unit determines the type and priority of the data message.
[0049] In step a3, the computing unit distributes the data message to different edge computing nodes based on the type and priority of the data message, and generates the data payload content.
[0050] In an optional embodiment, the information leakage prevention device further includes a cloud, and the cloud pre-stores a feature library; the calculation unit in step S104 determines whether the data payload content is a negotiation message, including:
[0051] Step b1: pulse-encode the data payload content using a pulse neural network, convert the data payload content into a time series pulse signal, extract spatiotemporal features from the time series pulse signal, and generate a pulse feature matrix.
[0052] Step b2: reconstruct the phase space of the pulse characteristic matrix to generate the chaotic trajectory characteristic vector.
[0053] Step b3: generating a composite feature vector based on the pulse feature matrix and the chaotic trajectory feature vector, and performing cosine similarity matching with the feature library on the cloud to determine whether the data payload content is the negotiation message.
[0054] In an optional embodiment, step S105 of generating an enhanced key QK+ by the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content includes:
[0055] Step c1: Generate an initial quantum key QK through the encryption module, and generate the enhanced key QK+ by combining the obtained device hardware fingerprint entropy value.
[0056] Step c2: Generate an attribute key SK according to the acquired attribute base, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append it to the IP header extension field in the data payload content.
[0057] Step c3: performing an XOR operation on the traffic characteristics and the enhanced key QK+ to generate the dynamic key stream.
[0058] Step c4: encrypt the appended data payload content based on the dynamic key stream to generate the target data payload content.
[0059] In an optional embodiment, the method further includes:
[0060] Step d1: judging whether the negotiation phase is completed based on the target data payload content.
[0061] Step d2: If not completed, return to the step where the computing unit performs deep packet inspection on the verified network data packet to generate data payload content.
[0062] Step d3, if completed, determines the processing status and data performance based on the target data payload content, and feeds back the processing status and data performance to the cloud.
[0063] In step d4, the cloud adjusts processing strategies and resource allocation according to processing status and data performance.
[0064] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0065] Corresponding to the information leakage prevention method described in the above embodiment, Figure 2 A structural block diagram of the information leakage prevention device provided in an embodiment of the present application is shown. For the sake of convenience, only the parts related to the embodiment of the present application are shown.
[0066] Reference Figure 2 The information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes:
[0067] The computing unit is configured to obtain network data packets and verify them through the zero-trust architecture module;
[0068] The edge computing device is configured to extract features from the network data packets to obtain traffic features, and send the traffic features to the computing unit;
[0069] The computing unit is configured to perform deep packet inspection on the authenticated network data packet to generate data payload content; determine whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content;
[0070] The encryption module is used to send the target data payload content to the blockchain for storage and recording;
[0071] If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device.
[0072] In a possible implementation, the computing unit is configured to:
[0073] Performing deep packet inspection on the verified network data packet to obtain a data packet;
[0074] Determining the type and priority of the data message;
[0075] Based on the type and priority of the data message, the data message is distributed to different edge computing nodes to generate the data payload content.
[0076] In a possible implementation, the information leakage prevention device further includes a cloud, and the cloud pre-stores a feature library;
[0077] The computing unit is configured to perform pulse encoding on the data payload content using a pulse neural network, convert the data payload content into a time series pulse signal, extract spatiotemporal features from the time series pulse signal, and generate a pulse feature matrix; perform phase space reconstruction on the pulse feature matrix to generate a chaotic trajectory feature vector; generate a composite feature vector based on the pulse feature matrix and the chaotic trajectory feature vector, and perform cosine similarity matching with the feature library on the cloud to determine whether the data payload content is the negotiation message.
[0078] In one possible implementation, the encryption module is used to:
[0079] Generate an initial quantum key QK, and combine it with the obtained device hardware fingerprint entropy value to generate the enhanced key QK+;
[0080] Generate an attribute key SK according to the acquired attribute base, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append the encrypted value to the IP header extension field in the data payload content;
[0081] Performing an XOR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream;
[0082] The appended data payload content is encrypted based on the dynamic key stream to generate the target data payload content.
[0083] In a possible implementation, the information leakage prevention device further includes:
[0084] A judgment module, configured to judge whether the negotiation phase is completed based on the target data payload content;
[0085] A return module, configured to return to the step of performing deep packet inspection on the verified network data packet and generating data payload content in the computing unit if the step is not completed;
[0086] a feedback module, configured to, if completed, determine a processing status and data performance based on the target data payload content, and feed back the processing status and data performance to the cloud;
[0087] The cloud is used to adjust processing strategies and resource allocation according to processing status and data performance.
[0088] It should be noted that the information interaction, execution process and other contents between the above modules are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0089] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0090] An embodiment of the present application also provides a computer device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps of any of the above-mentioned method embodiments when executing the computer program.
[0091] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.
[0092] An embodiment of the present application provides a computer program product. When the computer program product is run on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned various method embodiments when executing the computer program product.
[0093] If the integrated unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application can implement all or part of the process steps in the above-mentioned method embodiments by using a computer program to instruct the relevant hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0094] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0095] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0096] In the embodiments provided in this application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0097] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0098] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
[0099] Figure 3 This is a schematic diagram of the structure of a computer device provided in one embodiment of the present application. Figure 3 As shown, the computer device of this embodiment includes: at least one processor 20 ( Figure 3 Only one is shown), a memory 21 and a computer program 22 stored in the memory 21 and executable on the at least one processor 20, wherein the processor 20 implements the steps of any of the above-mentioned information leakage prevention method embodiments when executing the computer program 22.
[0100] The computer device may include, but is not limited to, a processor 20 and a memory 21. Those skilled in the art will understand that Figure 3 The computer device is merely an example and does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device may also include input and output devices, network access devices, etc.
[0101] The processor 20 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.
[0102] In some embodiments, the memory 21 may be an internal storage unit of the computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 21 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped with the computer device. Furthermore, the memory 21 may include both an internal storage unit of the computer device and an external storage device. The memory 21 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 21 may also be used to temporarily store data that has been output or is about to be output.
[0103] The relevant user personal information that may be involved in the various embodiments of this application is strictly in accordance with the requirements of laws and regulations, following the principles of legality, legitimacy and necessity, and based on the reasonable purposes of business scenarios, to process the personal information that users actively provide during the use of products / services or generated due to the use of products / services, as well as the personal information obtained with the user's authorization.
[0104] The personal information processed by the Applicant will vary depending on the specific product / service scenario and will be based on the specific scenario in which the user uses the product / service. This may involve the user's account information, device information, driving information, vehicle information, or other related information. The Applicant will treat the user's personal information and its processing with a high degree of diligence.
[0105] The Applicant attaches great importance to the security of user personal information and has taken reasonable and feasible security measures that comply with industry standards to protect user information and prevent personal information from being accessed, disclosed, used, modified, damaged or lost without authorization.
Claims
1. A method for preventing information leakage, characterized in that: The information leakage prevention method is applied to an information leakage prevention device, which includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module, and a blockchain; the information leakage prevention method includes: The computing unit obtains the network data packet and verifies it through the zero trust architecture module; The edge computing device extracts features from the network data packets to obtain traffic features, and sends the traffic features to the computing unit; The computing unit performs deep packet inspection on the verified network data packets to generate data payload content; The calculation unit determines whether the data payload content is a negotiation message; If the data payload content is a negotiation message, generating an enhanced key QK+ by the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content; The encryption module sends the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device; The step of generating an enhanced key QK+ by the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content includes: Generate an initial quantum key QK through the encryption module, and generate the enhanced key QK+ by combining the obtained device hardware fingerprint entropy value; Generate an attribute key SK according to the acquired attribute base, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append the encrypted value to the IP header extension field in the data payload content; Performing an XOR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream; The appended data payload content is encrypted based on the dynamic key stream to generate the target data payload content.
2. The information leakage prevention method according to claim 1, wherein: The computing unit performs deep packet inspection on the verified network data packets to generate data payload content, including: The computing unit performs deep packet inspection on the verified network data packet to obtain a data packet; The computing unit determines the type and priority of the data message; The computing unit distributes the data message to different edge computing nodes based on the type and priority of the data message, and generates the data payload content.
3. The information leakage prevention method according to claim 2, wherein: The information leakage prevention device further includes a cloud, wherein the cloud pre-stores a feature library; The calculating unit determines whether the data payload content is a negotiation message, including: Performing pulse encoding on the data payload content using a pulse neural network to convert the data payload content into a time series pulse signal, and extracting spatiotemporal features from the time series pulse signal to generate a pulse feature matrix; Reconstruct the phase space of the pulse characteristic matrix to generate the chaotic trajectory characteristic vector; A composite feature vector is generated according to the pulse feature matrix and the chaotic trajectory feature vector, and cosine similarity matching is performed with the feature library on the cloud to determine whether the data payload content is the negotiation message.
4. The information leakage prevention method according to claim 3, wherein: The method further comprises: Determining whether the negotiation phase is complete based on the target data payload content; If not completed, returning to the step of performing deep packet inspection on the verified network data packet by the computing unit to generate data payload content; If completed, a processing status and data performance will be determined based on the target data payload content, and the processing status and data performance will be fed back to the cloud; The cloud adjusts processing strategies and resource allocation according to processing status and data performance.
5. An information leakage prevention device, characterized in that: The information leakage prevention device includes: a computing unit, an edge computing device, an encryption module, a zero-trust architecture module and a blockchain; The computing unit is configured to obtain network data packets and verify them through the zero-trust architecture module; The edge computing device is configured to extract features from the network data packets to obtain traffic features, and send the traffic features to the computing unit; The computing unit is configured to perform deep packet inspection on the authenticated network data packet to generate data payload content; determine whether the data payload content is a negotiation message; if the data payload content is a negotiation message, generate an enhanced key QK+ through the encryption module, generate a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypt the data payload content based on the dynamic key stream to generate target data payload content; The encryption module is used to send the target data payload content to the blockchain for storage and recording; If the data payload content is not the negotiation message, the computing unit calls the smart contract of the blockchain and jointly performs distributed decryption on the data payload content with the edge computing device; The step of generating an enhanced key QK+ by the encryption module, generating a dynamic key stream based on the traffic characteristics and the enhanced key QK+, and encrypting the data payload content based on the dynamic key stream to generate target data payload content includes: Generate an initial quantum key QK through the encryption module, and generate the enhanced key QK+ by combining the obtained device hardware fingerprint entropy value; Generate an attribute key SK according to the acquired attribute base, encrypt the hash value of the enhanced key QK+ based on the attribute key SK, and append the encrypted value to the IP header extension field in the data payload content; Performing an XOR operation on the traffic feature and the enhanced key QK+ to generate the dynamic key stream; The appended data payload content is encrypted based on the dynamic key stream to generate the target data payload content.
6. The information leakage prevention device according to claim 5, wherein: The information leakage prevention device further includes a cloud, wherein the cloud pre-stores a feature library; The computing unit is configured to pulse encode the data payload content using a pulse neural network, convert the data payload content into a time series pulse signal, extract spatiotemporal features from the time series pulse signal, and generate a pulse feature matrix; The pulse feature matrix is reconstructed in phase space to generate a chaotic trajectory feature vector; a composite feature vector is generated based on the pulse feature matrix and the chaotic trajectory feature vector, and a cosine similarity match is performed with the feature library on the cloud to determine whether the data payload content is the negotiation message.
7. A computer device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 4 when executing the computer program.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.
9. A computer program product, characterized in that When the computer program product is run on a computer device, the computer device is caused to execute the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Lightweight zero-trust system based on channel information and suitable for edge internet-of-things environment and construction method
CN116915817A
Data transmission method and device based on quantum encryption, terminal equipment and storage medium
CN118764297A