Business data encryption method and system applying quantum encryption

By building a fixed time window in the direct connection system of the bank-enterprise, generating topological structures and persistent graphs, dynamically compute decision factors and key lengths, and using quantum random number generators for encryption, the problem of lack of accuracy and low data transmission efficiency in the existing technology is solved, and efficient and secure data transmission is achieved.

CN120090883AActive Publication Date: 2025-06-03BANK OF SHANGHAI

Patent Information

Application Number
CN202510573472.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-03
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to dynamically adjust the encryption strategy according to real-time network status, resulting in a decrease in data transmission efficiency when the network environment fluctuates, and the security strategy lacks accuracy, making it difficult to meet financial-level security requirements.

Method used

By building a fixed time window, the key metadata and network pulse information of banking and enterprise data are obtained, point cloud collections are generated, and topological structures of different scales are generated based on the point cloud collections, topological feature information is recorded, and durable graphs are generated. Then, the statistics of the persistent graph are extracted, the decision factor is calculated, the key length is dynamically determined based on the sensitivity coefficient and decision factor of the business data, and a unique key is generated by a quantum random number generator for encryption.

Benefits of technology

It realizes dynamic adjustment of encryption strategies based on real-time network status and service data, improves data transmission efficiency, enhances the adaptability and robustness of the encryption system, and can greatly improve transmission efficiency while ensuring basic security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090883A_ABST
    Figure CN120090883A_ABST
Patent Text Reader

Abstract

The invention provides a business data encryption method and system applying quantum encryption, and relates to the field of bank business data encryption, the method comprises the following steps: constructing a fixed time window, obtaining key metadata and network pulse information of business data of each bank enterprise in the fixed time window, and generating a point cloud set; topological structures of different scales are generated according to the point cloud set, topological feature information is recorded under each scale, and a persistent graph is generated; performing statistic extraction on the persistent graph, and calculating a decision factor corresponding to the current fixed time window; and based on the sensitivity coefficient of each bank-enterprise service data, determining the key length of each bank-enterprise service data according to the decision factor, and calling a quantum random number generator to generate a unique key for each bank-enterprise service data under the current fixed time window. According to the invention, the encryption strategy can be dynamically and flexibly adjusted, the dynamic decoupling of the security strategy and the network resources is realized, and the service interruption caused by the excessive occupation of the bandwidth by the encryption calculation is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of banking business data encryption, and particularly to a business data encryption method and system applying quantum encryption. Background Art

[0002] At present, for large customers of bank cash management, communication is mainly achieved through the enterprise-bank direct connection server and the enterprise-bank direct connection client. Since financial transfer data, account data, etc. are relatively sensitive, their security must be considered to ensure the confidentiality and integrity of data during network transmission; however, affected by environmental factors, the network environment of each enterprise is different and the network status fluctuates frequently, so the stability of data transmission also needs to be considered.

[0003] At present, business data encryption methods are mainly divided into static encryption and dynamic encryption: Static encryption technology generally uses a fixed key length and predefined security policies, and its encryption strength has no dynamic association with the network status and business sensitivity. When the network environment fluctuates (such as a sudden drop in bandwidth or a sharp increase in latency), high-intensity encryption will cause a serious deterioration in data transmission efficiency. Experiments show that when the network latency exceeds 150 ms, the throughput of AES-256 encryption drops by more than 45%. Shortening the key length can improve efficiency, but it will introduce security risks. Dynamic encryption technology (such as the key rotation mechanism based on network traffic monitoring) attempts to adjust encryption parameters, but its decision model mostly relies on single-dimensional threshold judgment (such as reducing the key length when the packet loss rate > 5%); such methods cannot quantitatively analyze the deep association between the topological characteristics of business data and the network status, resulting in a lack of accuracy in security policies. At the same time, the pseudo-random number generators used in existing dynamic solutions have periodic repetition defects and are difficult to meet financial-level security requirements.

[0004] Therefore, how to dynamically adjust the key strategy and optimize data transmission efficiency while ensuring encryption requirements according to the real-time network status is an urgent problem to be solved and optimized in enterprise-bank business data encryption. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a business data encryption method and system applying quantum encryption to solve the problem of optimizing data transmission efficiency while ensuring encryption requirements according to the real-time network status.

[0006] To solve the above technical problem, the technical solution of the present invention is as follows: In the first aspect, a business data encryption method applying quantum encryption, the method includes: Construct a fixed time window, obtain the key metadata and network pulse information of each enterprise-bank business data within the fixed time window, and generate a point cloud set; Generate topological structures of different scales according to the point cloud set, and record topological feature information at each scale to generate a persistence diagram; Extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window; Based on the sensitivity coefficients of each bank-enterprise business data, determine the key length of each bank-enterprise business data according to the decision factor, and call the quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window; Encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet.

[0007] Furthermore, obtain the key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set, including: Obtain the key metadata of each transaction through the bank-enterprise direct connection system and detect the network pulse parameters in real time; wherein, the key metadata includes the transaction timestamp, transaction amount, transaction serial number, and user identifier, and the network pulse parameters include bandwidth, latency, packet loss rate, and jitter; Combine the key metadata of each transaction and the corresponding network pulse parameters into a multi-dimensional vector, and collect all multi-dimensional vectors under the current fixed time window to obtain the point cloud set corresponding to the current fixed time window.

[0008] Furthermore, generate topological structures of different scales according to the point cloud set, and record topological feature information at each scale to generate a persistence diagram, including: Construct a topological structure according to the point cloud set through the Vietoris-Rips complex and extract topological features of different scales; Record the lifespan of each topological feature and generate a persistence diagram according to the lifespans of all topological features.

[0009] Furthermore, extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window, including: Classify the feature points in the persistence diagram by dimension and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension; Calculate the statistical quantities of topological features according to the persistence list; Calculate the decision factor corresponding to the current fixed time window according to the statistical quantities of topological features.

[0010] Furthermore, classify the feature points in the persistence diagram by dimension and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension, including: Classify 0-dimensional features, 1-dimensional features, and 2-dimensional features as connected components, loops, and holes in sequence; Calculate the persistence of each feature point and classify and count the persistence of each feature point to obtain a persistence list corresponding to the feature points of each dimension.

[0011] Further, based on the sensitivity coefficients of each bank-enterprise business data, determine the key lengths of each bank-enterprise business data according to the decision factors, and call the quantum random number generator to generate unique keys for each bank-enterprise business data under the current fixed time window, including: Classify different business types and match corresponding sensitivity coefficients to different business types to obtain the sensitivity coefficients corresponding to each bank-enterprise business data under the fixed time window; Dynamically calculate the key lengths of each bank-enterprise business data according to the decision factors and sensitivity coefficients; Use the unique identifier of the bank-enterprise business data as a seed, and call the quantum random number generator. With the seed as the input, generate a random key according to the key length; Associate the random key with the bank-enterprise business data and store it.

[0012] Further, encrypt each bank-enterprise business data with the unique key and generate an encrypted data packet, including: Serialize each bank-enterprise business data into a byte stream, and encrypt the byte stream to generate ciphertext and an authentication tag; Encapsulate the encrypted data and related metadata into an encrypted data packet, and transmit the encrypted data packet.

[0013] In a second aspect, a business data encryption system applying quantum encryption includes: An acquisition module, configured to construct a fixed time window, acquire the key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set; A generation module, configured to generate topological structures of different scales according to the point cloud set, and record topological feature information at each scale to generate a persistence diagram; A calculation module, configured to extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window; An encryption module, configured to determine the key lengths of each bank-enterprise business data according to the decision factors based on the sensitivity coefficients of each bank-enterprise business data, and call the quantum random number generator to generate unique keys for each bank-enterprise business data under the current fixed time window; A transmission module, which encrypts each bank-enterprise business data with the unique key and generates an encrypted data packet.

[0014] In a third aspect, a computing device includes: One or more processors; A storage system, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the above method.

[0015] Fourth aspect, a computer-readable storage medium stores a program, which when executed by a processor implements the above method.

[0016] The above solution of the present invention at least includes the following beneficial effects: With the above solution of the present invention, through the extracted topological features and dynamic decision factors, the encryption policy can be dynamically and flexibly adjusted according to the real-time network status and service data conditions, realizing the dynamic decoupling of security policies and network resources, and avoiding service interruptions caused by excessive occupation of bandwidth by encryption calculations; moreover, through the deep linkage of topological features and encryption parameters, this method realizes the transformation of the defense mode from passive protection to active interference, can greatly improve the transmission efficiency on the premise of ensuring basic security, and is particularly suitable for current service scenarios with high requirements for real-time performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a schematic flowchart of a service data encryption method applying quantum encryption provided by an embodiment of the present invention.

[0018] Figure 2 is a schematic diagram of a service data encryption system applying quantum encryption provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0020] As Figure 1 shown, an embodiment of the present invention proposes a service data encryption method applying quantum encryption, and the method includes: Step 1, construct a fixed time window, obtain key metadata and network pulse information of each bank-enterprise service data within the fixed time window, and generate a point cloud set; Step 2, generate topological structures of different scales according to the point cloud set, record topological feature information at each scale, and generate a persistence diagram; Step 3, extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window; Step 4, based on the sensitivity coefficients of each bank-enterprise service data, determine the key length of each bank-enterprise service data according to the decision factor, and call a quantum random number generator to generate a unique key for each bank-enterprise service data under the current fixed time window; Step 5, encrypt each bank-enterprise service data according to the unique key and generate an encrypted data packet.

[0021] In this embodiment, in step 1, the fixed time window can define a time window at a fixed time interval (such as 5 minutes). At the beginning of each fixed time window, the data collection process can be carried out through the direct bank-enterprise connection system and the network monitoring system to ensure that all bank-enterprise transaction data and network pulse information occurring during this period are completely recorded; among them, the size of the fixed time window can be dynamically adjusted according to specific business requirements. For example, it can be shortened to 2 minutes during the peak period and extended to 10 minutes during the off-peak period.

[0022] In the business data encryption method applying quantum encryption described in the embodiment of the present invention, by constructing a fixed time window and obtaining the key metadata and network pulse information (such as bandwidth, delay, etc.) of each bank-enterprise business data within the window, this method can perceive the changes in the network state in real time and generate a point cloud set for subsequent analysis, enabling the system to adjust the encryption strategy according to network conditions. For example, when the network state is poor, the data transmission efficiency can be optimized by adjusting parameters such as the key length, thus avoiding the performance bottleneck of the traditional fixed encryption strategy during network fluctuations; based on the point cloud set, topological structures of different scales are generated, and topological feature information is recorded at each scale to generate a persistence diagram. This method uses topological data analysis to extract the deep features of business data and network states, can capture the complex relationships and patterns between data, and provides comprehensive and accurate basic data for the calculation of subsequent decision factors, enhancing the adaptability and robustness of the encryption system; by extracting statistical quantities from the persistence diagram and calculating the decision factors corresponding to the current fixed time window, the encryption parameters can be dynamically adjusted according to the sensitivity of business data and network states, ensuring the flexibility of the encryption strategy and being able to automatically balance security and efficiency in different scenarios; based on the sensitivity coefficients and decision factors of each bank-enterprise business data, the key length is determined, and the quantum random number generator is called to generate a unique key for each bank-enterprise business data under the current fixed time window, ensuring the true randomness and high security of the key. Compared with the traditional pseudo-random number generator, the key generated by the QRNG is more difficult to predict and crack, significantly enhancing the security strength of the encryption system; by dynamically determining the key length of each bank-enterprise business data according to the decision factor and sensitivity coefficient, this method realizes the adaptive adjustment of the key length. In high-sensitivity or high-risk scenarios, longer keys are used to enhance security; while in low-sensitivity or poor network state, shorter keys are used to optimize the transmission efficiency, which can maximize the utilization efficiency of system resources on the premise of ensuring basic security and achieve a good balance between security and efficiency; each bank-enterprise business data is encrypted according to the unique key to generate an encrypted data packet, and this method ensures the confidentiality and integrity of the data. At the same time, the efficiency of the encryption process benefits from the dynamic key length and adaptive encryption strategy, and can maintain stable performance and security in different network environments.

[0023] In another alternative embodiment of the present invention, in step 1 above, key metadata and network pulse information of each bank-enterprise business data within a fixed time window are obtained, and a point cloud set is generated, including: Step 11, obtaining key metadata of each transaction through the bank-enterprise direct connection system and real-time detecting network pulse parameters; wherein, the key metadata includes a transaction timestamp, a transaction amount, a transaction serial number, and a user identifier, and the network pulse parameters include bandwidth, latency, packet loss rate, and jitter; Step 12, combining the key metadata of each transaction and the corresponding network pulse parameters into a multi-dimensional vector, and collecting all multi-dimensional vectors under the current fixed time window to obtain a point cloud set corresponding to the current fixed time window.

[0024] In this embodiment, the key metadata of each transaction and the corresponding network pulse parameters can be integrated into an 8-dimensional vector. Among them, the transaction serial number and the user identifier are in string form, and they can be converted into numerical values through hash mapping. Furthermore, the 8-dimensional vectors corresponding to all transactions under the fixed time window can be formed into a point cloud set. For example, if 100 transactions occur under the fixed time window, the point cloud set contains 100 8-dimensional vectors, and the point cloud set is stored in the form of a list or an array.

[0025] In another alternative embodiment of the present invention, in step 2 above, topological structures of different scales are generated based on the point cloud set, and topological feature information is recorded at each scale to generate a persistence diagram, including: Step 21, constructing a topological structure through the Vietoris-Rips complex based on the point cloud set and extracting topological features of different scales; Step 22, recording the lifespan of each topological feature, and generating a persistence diagram based on the lifespans of all topological features.

[0026] In this embodiment, the lifespan is the scale corresponding to the birth of each feature point and the scale corresponding to the death, so as to form a lifespan; furthermore, on the two-dimensional plane, each feature is represented by a point, the horizontal axis is the birth scale, the vertical axis is the death scale, and the persistence of the feature is represented by the distance from the point to the diagonal line. For example, if a loop is born at scale 1.0 and dies at scale 3.0, then the point (1.0, 3.0) is marked on the persistence diagram.

[0027] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, complex geometric and topological relationships between data are captured through topological data analysis, revealing patterns and rules that are difficult to discover by traditional analysis methods; by constructing a multi-scale topological structure, changes in the business environment can be comprehensively perceived, ensuring the robustness and adaptability of the analysis results; the recording of the life cycle and the generation of the persistence diagram further transform high-dimensional data into intuitive statistical features, facilitating the efficient extraction of key information by the system, thereby optimizing the decision-making process; in addition, this method demonstrates strong computational efficiency and scalability when processing high-dimensional data, and is applicable to diverse business scenarios in the direct bank-enterprise connection system.

[0028] In another alternative embodiment of the present invention, in step 3 above, statistical quantities are extracted from the persistence diagram, and a decision factor corresponding to the current fixed time window is calculated, including: Step 31, classifying the feature points in the persistence diagram by dimension, and calculating the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension; Step 32, calculating statistical quantities of topological features according to the persistence list; Step 33, calculating a decision factor corresponding to the current fixed time window according to the statistical quantities of topological features.

[0029] In another alternative embodiment of the present invention, in step 31 above, classifying the feature points in the persistence diagram by dimension, and calculating the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension, includes: Step 311, classifying 0-dimensional features, 1-dimensional features, and 2-dimensional features as connected components, loops, and holes in sequence; Step 312, calculating the persistence of each feature point, and classifying and statistically analyzing the persistence of each feature point to obtain a persistence list corresponding to the feature points of each dimension.

[0030] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, through clear dimension classification, the clustering, cyclic, and high-dimensional void characteristics of data are clearly distinguished, providing structured feature data for subsequent analysis; the calculation and classification statistics of persistence quantify the life cycle of each feature, revealing the deep correlation and stability information between data, enhancing the decision-making accuracy and self-adaptability of the system, while improving the data processing efficiency and security analysis ability.

[0031] In another alternative embodiment of the present invention, in step 32 above, calculating statistical quantities of topological features according to the persistence list includes: Calculating the average value of the persistence of all 0-dimensional features to obtain the mean persistence of connected components Calculate the variance of the persistence of all 1D features to obtain the persistence variance of the loop Screen the value with the maximum persistence among all 2D features to obtain the maximum persistence of the hole

[0032] In the business data encryption method applying quantum encryption described in the embodiments of the present invention, the accurate quantification of topological features in the straight-through banking system is realized. Through the customized statistical analysis of features in different dimensions, the stability of data clustering, the volatility of cyclic structures, and the significance of high-dimensional voids are accurately captured, providing high-quality feature inputs for subsequent decision factor calculations, thereby enhancing the dynamic adaptability and accuracy of encryption strategies, and at the same time optimizing the performance and data security guarantee capabilities of the system in complex network environments.

[0033] In another optional embodiment of the present invention, step 33, calculating the decision factor corresponding to the current fixed time window according to the statistic of the topological feature, includes: Step 331, preset a time window security value according to the business information in the current fixed time window; Step 332, through the formula: calculate the decision factor D; where is the global scaling coefficient, is the current bandwidth, is the maximum bandwidth, L is the current delay, is the maximum delay, is the packet loss rate, is the scaling coefficient for controlling the influence of sensitivity, is the preset time window security value, is the weighting coefficient for balancing the topological influence, is the persistence mean of the connected component, is the persistence variance of the loop, the maximum persistence of the hole.

[0034] In the business data encryption method applying quantum encryption described in the embodiments of the present invention, by integrating network parameters such as bandwidth, delay, and packet loss rate with topological features such as connected components, loops, and holes, accurate decision factors are generated, which can dynamically adapt to complex network environments and business requirements, thereby optimizing the key length and encryption strategy; at the same time, its high sensitivity and balance significantly improve the coordination ability of data transmission efficiency and security, providing an intelligent and efficient solution for banking business data protection.

[0035] In another alternative embodiment of the present invention, in step 4 above, based on the sensitivity coefficients of each bank-enterprise business data, determine the key length of each bank-enterprise business data according to the decision factor, and call the quantum random number generator to generate a unique key for each bank-enterprise business data in the current fixed time window, including: Step 41, classify different business types and match corresponding sensitivity coefficients to different business types to obtain the sensitivity coefficients corresponding to each bank-enterprise business data in the fixed time window; Step 42, dynamically calculate the key length of each bank-enterprise business data according to the decision factor and the sensitivity coefficient; Step 43, use the unique identifier of the bank-enterprise business data as the seed, and call the quantum random number generator (QRNG), use the seed as the input, and generate a random key according to the key length; Step 44, associate the random key with the bank-enterprise business data and store it.

[0036] In this embodiment, in step 41, the sensitivity of each business data can be quantified according to factors such as each bank-enterprise business type, amount, and user permissions to obtain the sensitivity coefficient; preferably, the sensitivity coefficient of each business data can be accurately quantified according to various weights. For example, the sensitivity of financial transfer is higher than that of querying balance, which can be assigned 0.8 (transfer) and 0.2 (query); the larger the transaction amount, the higher the sensitivity. For example, when the amount exceeds 1 million, it is assigned 1.0, and when it is less than 10,000, it is 0.3; transactions involving high-level users (such as administrators) have higher sensitivity, assigned 0.9, and ordinary users are 0.5. Thus, through the weighted summation of each item, a sensitivity coefficient S between 0 and 1 can be obtained, and finally data annotation is performed, and the calculated sensitivity coefficient is assigned to this business data and recorded in the sensitivity field of the dataset.

[0037] In this embodiment, in step 43, use the unique identifier of the business data (such as the transaction serial number) as the seed. For example, the serial number "TXN20231001001" generates a seed through SHA-256 hashing, and the output 256-bit hash value is used as the input of the random number generator; and call the quantum random number generator (QRNG), use the seed as the initial input, and generate a truly random key with a length of X bits (calculated through step 42). Since QRNG utilizes the principles of quantum physics, it can ensure the unpredictability of the key. Finally, the generated X-bit key is associated with the business data and stored in a secure database or a hardware security module (HSM) for subsequent encryption use.

[0038] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, through precise business type classification and dynamic key length calculation, the encryption policy is ensured to be highly matched with business sensitivity and network status, thereby enhancing security in high-risk scenarios and optimizing transmission efficiency in low-risk scenarios; the quantum random number generator significantly improves the randomness and anti-attack ability of the key.

[0039] In another alternative embodiment of the present invention, step 42 above, dynamically calculating the key length of each bank-enterprise business data according to the decision factor and the sensitivity coefficient, includes: By the formula: , calculate the key length of each bank-enterprise business data , where is the minimum key length, is the maximum key length, is the decision factor, is a control parameter (preferably 5.0), is the sensitivity coefficient corresponding to the bank-enterprise business data.

[0040] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, by using the sigmoid function , the key length increases smoothly when D + S approaches 1, ensuring that the key length rapidly increases in high-risk scenarios. The sigmoid function can provide a smooth transition, avoiding sudden changes in the key length, ensuring smooth adjustment at different network risk levels, so as to achieve that in high-risk scenarios (where D and S are large), the key length approaches the maximum key length, providing stronger security; in low-risk scenarios (where D and S are small), the key length approaches the minimum key length, optimizing calculation and transmission efficiency, and there are great differences in the length of each bank-enterprise business data, which can dynamically match the current network status and environment.

[0041] In another alternative embodiment of the present invention, step 5 above, encrypting each bank-enterprise business data with the unique key and generating an encrypted data packet, includes: Step 51, serializing each bank-enterprise business data into a byte stream and encrypting the byte stream to generate a ciphertext and an authentication tag; Step 52, encapsulating the encrypted data and related metadata into an encrypted data packet and transmitting the encrypted data packet.

[0042] In this embodiment, in step 51, the AES-256-GCM mode can be used to encrypt the byte stream to generate ciphertext and an authentication tag. The authentication tag generated by the GCM mode is used to verify the integrity of the data. In step 52, the encrypted data packet includes the ciphertext, the authentication tag, the initialization vector, the timestamp, the sequence number, and the sensitive metadata (such as the user ID) is additionally encrypted, and the digital signature technology is used to sign the data packet to ensure the authenticity of the source. When transmitting, a secure protocol such as TLS 1.3 can be used to transmit the encrypted data packet, and the receiving end decrypts the ciphertext using the shared key.

[0043] As Figure 2 shown, the present application also provides a business data encryption system applying quantum encryption, and the system includes: An acquisition module 10, configured to construct a fixed time window, acquire key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set; A generation module 20, configured to generate topological structures of different scales according to the point cloud set, record topological feature information at each scale, and generate a persistence diagram; A calculation module 30, configured to extract statistical quantities from the persistence diagram and calculate a decision factor corresponding to the current fixed time window; An encryption module 40, configured to determine the key length of each bank-enterprise business data according to the decision factor based on the sensitivity coefficient of each bank-enterprise business data, and call a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window; A transmission module 50, configured to encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet.

[0044] It should be noted that this system corresponds to the above method. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0045] An embodiment of the present invention also provides a computing device, including: a processor and a memory storing a computer program. When the computer program is run by the processor, the above-mentioned method is executed. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0046] An embodiment of the present invention also provides a computer-readable storage medium storing instructions. When the instructions are run on a computer, the computer is enabled to execute the above-mentioned method. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0047] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0048] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, systems, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0049] In the embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of systems or units can be electrical, mechanical, or other forms.

[0050] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0051] In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0052] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0053] In addition, it should be noted that in the systems and methods of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations shall be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to execute them in chronological order. Some steps can be executed in parallel or independently of each other. For those of ordinary skill in the art, it is understandable that all or any steps or components of the method and system of the present invention can be implemented in any computing system (including processors, storage media, etc.) or a network of computing systems in the form of hardware, firmware, software, or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0054] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing system. The computing system can be a well-known general-purpose system. Therefore, the object of the present invention can also be achieved only by providing a program product containing program code for implementing the method or system. That is to say, such a program product also constitutes the present invention, and a storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be noted that in the systems and methods of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations shall be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to execute them in chronological order. Some steps can be executed in parallel or independently of each other.

[0055] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for encrypting business data using quantum encryption, characterized in that: The method comprises: Construct a fixed time window, obtain key metadata and network pulse information of each bank's business data within the fixed time window, and generate a point cloud collection; Generate topological structures of different scales based on point cloud collections, record topological feature information at each scale, and generate a persistence graph; Extract statistics from the persistence graph and calculate the decision factor corresponding to the current fixed time window; Based on the sensitivity coefficient of each bank's business data, the key length of each bank's business data is determined according to the decision factor, and the quantum random number generator is called to generate a unique key for each bank's business data in the current fixed time window; Encrypt each bank's business data based on a unique key and generate an encrypted data packet.

2. The method for encrypting business data using quantum encryption according to claim 1, characterized in that: Obtain key metadata and network pulse information of each bank's business data within a fixed time window and generate a point cloud collection, including: Obtain key metadata of each transaction through the bank-enterprise direct connection system and detect network pulse parameters in real time; wherein the key metadata includes transaction timestamp, transaction amount, transaction serial number and user identifier, and the network pulse parameters include bandwidth, delay, packet loss rate and jitter; The key metadata of each transaction and the corresponding network pulse parameters are combined into a multidimensional vector, and all multidimensional vectors in the current fixed time window are collected to obtain the point cloud set corresponding to the current fixed time window.

3. The method for encrypting business data using quantum encryption according to claim 2, characterized in that: Generate topological structures of different scales based on point cloud collections, record topological feature information at each scale, and generate a persistent graph, including: Constructing a topological structure through a Vietoris-Rips complex according to the point cloud set, and extracting topological features of different scales; The life cycle is recorded for each topological feature, and a persistence graph is generated based on the life cycles of all topological features.

4. The method for encrypting business data using quantum encryption according to claim 3, characterized in that: Extract statistics from the persistence graph and calculate the decision factors corresponding to the current fixed time window, including: Classifying the feature points in the persistence graph according to the dimensions, and calculating the persistence of each feature point to generate a persistence list corresponding to the feature points in each dimension; Calculating statistics of topological features based on the persistent list; The decision factor corresponding to the current fixed time window is calculated based on the statistics of the topological features.

5. The method for encrypting business data using quantum encryption according to claim 4, characterized in that: The feature points in the persistence graph are classified by dimension, and the persistence of each feature point is calculated to generate a persistence list corresponding to the feature points of each dimension, including: Classify 0-dimensional features, 1-dimensional features, and 2-dimensional features into connected components, rings, and holes in turn; The persistence of each feature point is calculated, and the persistence of each feature point is classified and counted to obtain a persistence list corresponding to the feature points of each dimension.

6. The method for encrypting business data using quantum encryption according to claim 5, characterized in that: Based on the sensitivity coefficient of each bank's business data, the key length of each bank's business data is determined according to the decision factor, and the quantum random number generator is called to generate a unique key for each bank's business data in the current fixed time window, including: Different business types are classified and the corresponding sensitivity coefficients are matched to different business types to obtain the sensitivity coefficients corresponding to the business data of each bank in a fixed time window; Dynamically calculate the key length of each bank's business data based on the decision factor and sensitivity coefficient; Use the unique identifier of the bank's business data as a seed, call the quantum random number generator, take the seed as input, and generate a random key based on the key length; The random key is associated with the banking business data and stored.

7. The method for encrypting business data using quantum encryption according to claim 6, characterized in that: Encrypt each banking business data according to the unique key and generate an encrypted data package, including: Serialize each bank's business data into a byte stream, encrypt the byte stream, and generate ciphertext and authentication tags; The encrypted data and related metadata are encapsulated into an encrypted data packet, and the encrypted data packet is transmitted.

8. A business data encryption system using quantum encryption, characterized in that: include: The acquisition module is used to construct a fixed time window, obtain key metadata and network pulse information of each bank's business data within the fixed time window, and generate a point cloud set; The generation module is used to generate topological structures of different scales based on the point cloud set, and record the topological feature information at each scale to generate a persistent graph; The calculation module is used to extract statistics from the persistence graph and calculate the decision factor corresponding to the current fixed time window; An encryption module is used to determine the key length of each banking business data based on the sensitivity coefficient of each banking business data and the decision factor, and call the quantum random number generator to generate a unique key for each banking business data in the current fixed time window; The transmission module encrypts each bank's business data according to a unique key and generates an encrypted data packet.

9. A computing device, characterized in that include: one or more processors; A storage system for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program, which, when executed by a processor, implements the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Three-dimensional point cloud classification method fusing persistent coherence

    CN114581718A

  • Data transmission method and system based on encrypted communication in service operating system

    CN118784361A

  • Alzheimer disease classification method and system based on multi-view spatio-temporal topology fusion

    CN118899076A

  • Security encryption communication method and system based on quantum key management

    CN119316138A

  • Cyberattack detection with topological data

    US20230412623A1

Cited By

  • Quantum key scheduling method based on service awareness

    CN121283625A