A business data encryption method and system applying quantum encryption

By building a time window and topological structure in banking data encryption, and dynamically generating quantum random number keys, the transmission efficiency and security problems caused by network state fluctuations in the prior art are solved, and efficient and secure encryption in banking data transmission is achieved.

CN120090883BActive Publication Date: 2025-07-04BANK OF SHANGHAI

Patent Information

Application Number
CN202510573472.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-04
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

Existing banking data encryption methods are difficult to dynamically adjust the key strategy when the network state fluctuates, resulting in low transmission efficiency or insufficient security. Especially traditional encryption at rest decreases in efficiency when network delays, dynamic encryption fails to effectively combine network state and business topology characteristics, and there are lack of accuracy in security policies and pseudo-random number generator defects.

Method used

By building a fixed time window, key metadata and network pulse information are obtained to generate point cloud collections, topological structures of different scales are generated, topological feature information is recorded, decision factors are calculated, and quantum random number keys are dynamically generated based on sensitivity coefficients and decision factors to realize encrypted data packet transmission.

Benefits of technology

It realizes dynamic adjustment of encryption strategies based on real-time network status and service sensitivity, improves data transmission efficiency and security, avoids excessive bandwidth utilization by encrypted computing, and provides an efficient and secure data transmission solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090883B_ABST
    Figure CN120090883B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for encrypting business data using quantum encryption, which relates to the field of banking business data encryption. The method includes: constructing a fixed-time window, obtaining the key metadata and network pulse information of each bank-enterprise business data within the fixed-time window, and generating a point cloud set; generating topological structures of different scales based on the point cloud set, and recording topological feature information at each scale to generate a persistence diagram; extracting statistical quantities from the persistence diagram and calculating the decision factor corresponding to the current fixed-time window; based on the sensitivity coefficients of each bank-enterprise business data, determining the key length of each bank-enterprise business data according to the decision factor, and invoking a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed-time window. The present invention can dynamically and flexibly adjust the encryption strategy, realizes the dynamic decoupling of the security strategy and network resources, and avoids service interruption caused by excessive occupation of bandwidth by encryption calculations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of banking business data encryption, and particularly to a business data encryption method and system applying quantum encryption. Background Art

[0002] At present, major customers of bank cash management mainly communicate through the enterprise-bank direct connection server and the enterprise-bank direct connection client. Since financial transfer data, account data, etc. are relatively sensitive, their security must be considered to ensure the confidentiality and integrity of data during network transmission; however, affected by environmental factors, each enterprise has a different network environment and frequent network state fluctuations, so the stability of data transmission also needs to be considered.

[0003] Currently, business data encryption methods are mainly divided into static encryption and dynamic encryption: Static encryption technology generally uses a fixed key length and predefined security policies, and its encryption strength has no dynamic association with the network state and business sensitivity. When the network environment fluctuates (such as a sudden drop in bandwidth or a sharp increase in latency), high-strength encryption will cause a serious deterioration in data transmission efficiency. Experiments show that when the network latency exceeds 150 ms, the throughput of AES-256 encryption drops by more than 45%. Although shortening the key length can improve efficiency, it will introduce security risks. Dynamic encryption technology (such as the key rotation mechanism based on network traffic monitoring) attempts to adjust encryption parameters, but its decision-making model mostly relies on single-dimensional threshold judgment (such as reducing the key length when the packet loss rate > 5%); such methods fail to quantitatively analyze the deep association between the topological characteristics of business data and the network state, resulting in a lack of accuracy in security policies. At the same time, the pseudo-random number generators used in existing dynamic solutions have periodic repetition defects and are difficult to meet financial-level security requirements.

[0004] Therefore, how to dynamically adjust the key strategy and optimize data transmission efficiency while ensuring encryption requirements according to the real-time network state is an urgent problem to be solved and optimized in enterprise-bank business data encryption. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a business data encryption method and system applying quantum encryption, and solve the problem of optimizing data transmission efficiency while ensuring encryption requirements according to the real-time network state.

[0006] To solve the above technical problem, the technical solution of the present invention is as follows:

[0007] In a first aspect, a business data encryption method applying quantum encryption, the method includes:

[0008] Construct a fixed time window, obtain the key metadata and network pulse information of each enterprise-bank business data within the fixed time window, and generate a point cloud set;

[0009] Generate topological structures of different scales based on the point cloud set, record topological feature information at each scale, and generate a persistence diagram;

[0010] Extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window;

[0011] Based on the sensitivity coefficients of the business data of each bank and enterprise, determine the key length of the business data of each bank and enterprise according to the decision factor, and call the quantum random number generator to generate a unique key for the business data of each bank and enterprise under the current fixed time window;

[0012] Encrypt the business data of each bank and enterprise according to the unique key and generate an encrypted data packet.

[0013] Furthermore, obtain the key metadata and network pulse information of the business data of each bank and enterprise within the fixed time window, and generate a point cloud set, including:

[0014] Obtain the key metadata of each transaction through the direct bank-enterprise connection system and detect the network pulse parameters in real time; wherein, the key metadata includes the transaction timestamp, transaction amount, transaction serial number, and user identifier, and the network pulse parameters include bandwidth, latency, packet loss rate, and jitter;

[0015] Combine the key metadata of each transaction and the corresponding network pulse parameters into a multi-dimensional vector, and collect all multi-dimensional vectors under the current fixed time window to obtain the point cloud set corresponding to the current fixed time window.

[0016] Furthermore, generate topological structures of different scales based on the point cloud set, record topological feature information at each scale, and generate a persistence diagram, including:

[0017] Construct a topological structure through the Vietoris-Rips complex according to the point cloud set and extract topological features of different scales;

[0018] Record the lifespan of each topological feature and generate a persistence diagram based on the lifespans of all topological features.

[0019] Furthermore, extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window, including:

[0020] Classify the feature points in the persistence diagram by dimension and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension;

[0021] Calculate the statistical quantities of topological features according to the persistence list;

[0022] Calculate the decision factor corresponding to the current fixed time window according to the statistical quantities of topological features.

[0023] Further, classify the feature points in the persistence diagram by dimension, and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension, including:

[0024] Classify 0-dimensional features, 1-dimensional features, and 2-dimensional features as connected components, loops, and holes in sequence;

[0025] Calculate the persistence of each feature point, and classify and count the persistence of each feature point to obtain a persistence list corresponding to the feature points of each dimension.

[0026] Further, based on the sensitivity coefficients of each bank-enterprise business data, determine the key length of each bank-enterprise business data according to the decision factor, and call a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window, including:

[0027] Classify different business types, and match corresponding sensitivity coefficients to different business types to obtain the sensitivity coefficients corresponding to each bank-enterprise business data under the fixed time window;

[0028] Dynamically calculate the key length of each bank-enterprise business data according to the decision factor and the sensitivity coefficient;

[0029] Use the unique identifier of the bank-enterprise business data as a seed, and call a quantum random number generator. Using the seed as input, generate a random key according to the key length;

[0030] Associate the random key with the bank-enterprise business data and store it.

[0031] Further, encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet, including:

[0032] Serialize each bank-enterprise business data into a byte stream, and encrypt the byte stream to generate a ciphertext and an authentication tag;

[0033] Package the encrypted data and related metadata into an encrypted data packet, and transmit the encrypted data packet.

[0034] In a second aspect, a business data encryption system applying quantum encryption includes:

[0035] An acquisition module, configured to construct a fixed time window, acquire the key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set;

[0036] A generation module, configured to generate topological structures of different scales according to the point cloud set, and record topological feature information at each scale to generate a persistence diagram;

[0037] A calculation module, configured to extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window;

[0038] An encryption module, configured to determine the key length of each banking business data according to a decision factor based on the sensitivity coefficient of each banking business data, and call a quantum random number generator to generate a unique key for each banking business data under the current fixed time window;

[0039] A transmission module, configured to encrypt each banking business data according to the unique key and generate an encrypted data packet.

[0040] In a third aspect, a computing device includes:

[0041] One or more processors;

[0042] A storage system, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the above method.

[0043] In a fourth aspect, a computer-readable storage medium stores a program, and when the program is executed by a processor, the above method is implemented.

[0044] The above solution of the present invention has at least the following beneficial effects:

[0045] With the above solution of the present invention, through the extracted topological features and dynamic decision factors, the encryption policy can be dynamically and flexibly adjusted according to the real-time network state and business data situation, realizing the dynamic decoupling of the security policy and network resources, and avoiding service interruption caused by excessive occupation of bandwidth by encryption calculation; moreover, through the deep linkage between the topological features and encryption parameters, this method realizes the transformation of the defense mode from passive protection to active interference, can greatly improve the transmission efficiency on the premise of ensuring basic security, and is particularly suitable for business scenarios with high real-time requirements at present. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 is a schematic flowchart of a method for encrypting business data using quantum encryption provided by an embodiment of the present invention.

[0047] Figure 2 is a schematic diagram of a business data encryption system using quantum encryption provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0048] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that this disclosure can be more thoroughly understood and the scope of this disclosure can be fully conveyed to those skilled in the art.

[0049] As Figure 1 shown, an embodiment of the present invention proposes a business data encryption method applying quantum encryption. The method includes:

[0050] Step 1, construct a fixed time window, obtain key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set;

[0051] Step 2, generate topological structures of different scales according to the point cloud set, record topological feature information at each scale, and generate a persistence diagram;

[0052] Step 3, extract statistical quantities from the persistence diagram, and calculate the decision factor corresponding to the current fixed time window;

[0053] Step 4, based on the sensitivity coefficients of each bank-enterprise business data, determine the key length of each bank-enterprise business data according to the decision factor, and call a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window;

[0054] Step 5, encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet.

[0055] In this embodiment, the fixed time window in Step 1 can define a time window at a fixed time interval (such as 5 minutes). At the beginning of each fixed time window, the data collection process can be carried out through the bank-enterprise direct connection system and the network monitoring system to ensure that all bank-enterprise transaction data and network pulse information occurring during this period are completely recorded; among them, the size of the fixed time window can be dynamically adjusted according to specific business requirements. For example, it can be shortened to 2 minutes during peak periods and extended to 10 minutes during off-peak periods.

[0056] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, by constructing a fixed time window and obtaining the key metadata and network pulse information (such as bandwidth, latency, etc.) of each bank-enterprise business data within the window, this method can perceive the changes in the network state in real time and generate a point cloud set for subsequent analysis, enabling the system to adjust the encryption strategy according to the network conditions. For example, when the network state is poor, the data transmission efficiency is optimized by adjusting parameters such as the key length, thereby avoiding the performance bottleneck of the traditional fixed encryption strategy during network fluctuations; based on the point cloud set, topological structures of different scales are generated, and topological feature information is recorded at each scale to generate a persistence diagram. This method uses topological data analysis to extract the deep features of business data and network state, can capture the complex relationships and patterns between data, provides comprehensive and accurate basic data for the calculation of subsequent decision factors, and enhances the adaptability and robustness of the encryption system; by extracting statistical quantities from the persistence diagram and calculating the decision factors corresponding to the current fixed time window, the encryption parameters can be dynamically adjusted according to the sensitivity of business data and network state, ensuring the flexibility of the encryption strategy and being able to automatically balance security and efficiency in different scenarios; based on the sensitivity coefficients and decision factors of each bank-enterprise business data, the key length is determined, and a quantum random number generator is called to generate a unique key for each bank-enterprise business data under the current fixed time window, ensuring the true randomness and high security of the key. Compared with the traditional pseudo-random number generator, the key generated by the QRNG is more difficult to predict and crack, significantly improving the security strength of the encryption system; by dynamically determining the key length of each bank-enterprise business data according to the decision factors and sensitivity coefficients, this method realizes the adaptive adjustment of the key length. In high-sensitivity or high-risk scenarios, longer keys are used to enhance security; while in low-sensitivity or poor network state, shorter keys are used to optimize the transmission efficiency, which can maximize the utilization efficiency of system resources while ensuring basic security and achieve a good balance between security and efficiency; encrypting each bank-enterprise business data according to the unique key and generating encrypted data packets, this method ensures the confidentiality and integrity of the data. At the same time, the efficiency of the encryption process benefits from the dynamic key length and adaptive encryption strategy, and can maintain stable performance and security in different network environments.

[0057] In another alternative embodiment of the present invention, step 1 above, obtaining the key metadata and network pulse information of each bank-enterprise business data within the fixed time window and generating a point cloud set, includes:

[0058] Step 11, obtaining the key metadata of each transaction through the bank-enterprise direct connection system and detecting the network pulse parameters in real time; wherein, the key metadata includes transaction timestamp, transaction amount, transaction serial number, and user identifier, and the network pulse parameters include bandwidth, latency, packet loss rate, and jitter;

[0059] Step 12: Combine the key metadata of each transaction and the corresponding network pulse parameters into a multi-dimensional vector, and collect all the multi-dimensional vectors within the current fixed time window to obtain the point cloud set corresponding to the current fixed time window.

[0060] In this embodiment, the key metadata of each transaction and the corresponding network pulse parameters can be integrated into an 8-dimensional vector. Among them, the transaction serial number and user identifier are in string form, which can be converted into numerical values through hash mapping. Furthermore, the 8-dimensional vectors corresponding to all transactions within the fixed time window can be combined into a point cloud set. For example, if 100 transactions occur within the fixed time window, the point cloud set contains 100 8-dimensional vectors, and the point cloud set is stored in the form of a list or an array.

[0061] In another alternative embodiment of the present invention, in step 2 above, generating topological structures of different scales based on the point cloud set and recording topological feature information at each scale to generate a persistence diagram includes:

[0062] Step 21: Construct a topological structure based on the point cloud set through the Vietoris-Rips complex and extract topological features of different scales;

[0063] Step 22: Record the lifespan of each topological feature and generate a persistence diagram based on the lifespans of all topological features.

[0064] In this embodiment, the lifespan is the scale corresponding to the birth of each feature point and the scale corresponding to its death to form a lifespan. Furthermore, in the two-dimensional plane, each feature is represented by a point, the horizontal axis is the birth scale, the vertical axis is the death scale, and the persistence of the feature is represented by the distance from the point to the diagonal line. For example, if a loop is born at scale 1.0 and dies at scale 3.0, then the point (1.0, 3.0) is marked on the persistence diagram.

[0065] In the business data encryption method applying quantum encryption described in the embodiments of the present invention, complex geometric and topological relationships between data are captured through topological data analysis, revealing patterns and rules that are difficult to discover by traditional analysis methods; by constructing multi-scale topological structures, the changes in the business environment can be comprehensively perceived, ensuring the robustness and adaptability of the analysis results; the recording of lifespans and the generation of persistence diagrams further transform high-dimensional data into intuitive statistical features, facilitating the system to efficiently extract key information, thereby optimizing the decision-making process; in addition, this method demonstrates strong computational efficiency and scalability when processing high-dimensional data and is applicable to diverse business scenarios in the direct connection system between banks and enterprises.

[0066] In another alternative embodiment of the present invention, in step 3 above, extracting statistical quantities from the persistence diagram and calculating the decision factor corresponding to the current fixed time window includes:

[0067] Step 31: Classify the feature points in the persistence diagram by dimension, and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension;

[0068] Step 32: Calculate the statistics of topological features according to the persistence list;

[0069] Step 33: Calculate the decision factor corresponding to the current fixed time window according to the statistics of topological features.

[0070] In another optional embodiment of the present invention, the above step 31: Classify the feature points in the persistence diagram by dimension, and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension, includes:

[0071] Step 311: Classify 0-dimensional features, 1-dimensional features, and 2-dimensional features as connected components, loops, and holes in sequence;

[0072] Step 312: Calculate the persistence of each feature point, and classify and count the persistence of each feature point to obtain a persistence list corresponding to the feature points of each dimension.

[0073] In the business data encryption method applying quantum encryption described in the embodiments of the present invention, through explicit dimension classification, the clustering, cyclic, and high-dimensional void characteristics of the data are clearly distinguished, providing structured feature data for subsequent analysis; the calculation and classification statistics of persistence quantify the life cycle of each feature, revealing the deep correlation and stability information between data, enhancing the decision-making accuracy and self-adaptability of the system, and at the same time improving the data processing efficiency and security analysis ability.

[0074] In another optional embodiment of the present invention, in the above step 32, calculating the statistics of topological features according to the persistence list includes:

[0075] Calculate the average value of the persistence of all 0-dimensional features to obtain the mean persistence of connected components Calculate the variance of the persistence of all 1-dimensional features to obtain the persistence variance of loops Screen the maximum value of the persistence among all 2-dimensional features to obtain the maximum persistence of holes

[0076] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, the accurate quantification of topological features in the straight-through banking system is realized. Through customized statistical analysis of different dimensional features, the stability of data clustering, the volatility of cyclic structures, and the significance of high-dimensional voids are accurately captured, providing high-quality feature inputs for subsequent decision factor calculation, thereby enhancing the dynamic adaptability and accuracy of encryption strategies, and optimizing the performance and data security protection capabilities of the system in complex network environments.

[0077] In another optional embodiment of the present invention, step 33, calculating the decision factor corresponding to the current fixed time window according to the statistic of the topological feature, includes:

[0078] Step 331, presetting a time window security value according to the business information in the current fixed time window;

[0079] Step 332, through the formula:

[0080] calculate the decision factor D; where, is the global scaling coefficient, is the current bandwidth, is the maximum bandwidth, L is the current delay, is the maximum delay, is the packet loss rate, is the scaling coefficient for controlling the influence of sensitivity, is the preset time window security value, is the weighting coefficient for balancing the topological influence, is the persistence mean of the connected component, is the persistence variance of the loop, the maximum persistence of the void.

[0081] In the business data encryption method applying quantum encryption according to the embodiments of the present invention, by integrating network parameters such as bandwidth, delay, and packet loss rate with topological features such as connected components, loops, and voids, accurate decision factors are generated, which can dynamically adapt to complex network environments and business requirements, thereby optimizing the key length and encryption strategy; at the same time, its high sensitivity and balance significantly improve the coordination ability of data transmission efficiency and security, providing an intelligent and efficient solution for banking business data protection.

[0082] In another optional embodiment of the present invention, step 4, based on the sensitivity coefficients of each banking business data, determining the key length of each banking business data according to the decision factor, and calling a quantum random number generator to generate a unique key for each banking business data in the current fixed time window, includes:

[0083] Step 41: Classify different business types and match corresponding sensitivity coefficients to different business types to obtain the sensitivity coefficients corresponding to each bank-enterprise business data under a fixed time window;

[0084] Step 42: Dynamically calculate the key length of each bank-enterprise business data according to the decision factor and the sensitivity coefficient;

[0085] Step 43: Use the unique identifier of the bank-enterprise business data as a seed, and call a quantum random number generator (QRNG). With the seed as the input, generate a random key according to the key length;

[0086] Step 44: Associate the random key with the bank-enterprise business data and store it.

[0087] In this embodiment, in step 41, the sensitivity of each business data can be quantified according to factors such as each bank-enterprise business type, amount size, and user permissions to obtain the sensitivity coefficient; preferably, the sensitivity coefficient of each business data can be accurately quantified according to various weights. For example, the sensitivity of financial transfer is higher than that of querying balance, which can be assigned 0.8 (transfer) and 0.2 (query); the larger the transaction amount, the higher the sensitivity. For example, when the amount exceeds 1 million, it is assigned 1.0, and when it is less than 10,000, it is 0.3; transactions involving high-level users (such as administrators) have higher sensitivity, assigned 0.9, and ordinary users are 0.5. Thus, through the weighted summation of each item, a sensitivity coefficient S between 0 and 1 can be obtained, and finally, data annotation is performed. The calculated sensitivity coefficient is assigned to this business data and recorded in the sensitivity field of the dataset.

[0088] In this embodiment, in step 43, the unique identifier of the business data (such as the transaction serial number) is used as the seed. For example, the serial number "TXN20231001001" generates a seed through SHA-256 hashing, and the output fixed 256-bit hash value is used as the input of the random number generator; and call a quantum random number generator (QRNG), with the seed as the initial input, to generate a truly random key with a length of X bits (calculated through step 42). Since the QRNG utilizes quantum physical principles, it can ensure the unpredictability of the key. Finally, the generated X-bit key is associated with the business data and stored in a secure database or a hardware security module (HSM) for subsequent encryption use.

[0089] In the business data encryption method applying quantum encryption described in the embodiments of the present invention, through accurate business type classification and dynamic key length calculation, it ensures a high degree of matching between the encryption strategy and business sensitivity and network status, thereby enhancing security in high-risk scenarios and optimizing transmission efficiency in low-risk scenarios; the quantum random number generator significantly improves the randomness and anti-attack ability of the key.

[0090] In another alternative embodiment of the present invention, in step 42 above, dynamically calculating the key lengths of each banking business data according to the decision factor and the sensitivity coefficient includes:

[0091] Through the formula:

[0092] , calculate the key lengths of each banking business data , where is the minimum key length, is the maximum key length, is the decision factor, is the control parameter (preferably 5.0), is the sensitivity coefficient corresponding to the banking business data.

[0093] In the business data encryption method applying quantum encryption according to the embodiment of the present invention, by using the sigmoid function , the key length increases smoothly when D + S approaches 1, ensuring that the key length increases rapidly in high-risk scenarios. The sigmoid function can provide a smooth transition, avoiding sudden changes in the key length, ensuring smooth adjustment under different network risk levels, so as to achieve that in high-risk scenarios (where D and S are large), the key length approaches the maximum key length, providing stronger security; in low-risk scenarios (where D and S are small), the key length approaches the minimum key length, optimizing the calculation and transmission efficiency, and there are great differences in the lengths of each banking business data, which can dynamically match the current network state and environment.

[0094] In another alternative embodiment of the present invention, in step 5 above, encrypting each banking business data with the unique key and generating an encrypted data packet includes:

[0095] Step 51, serialize each banking business data into a byte stream, and encrypt the byte stream to generate a ciphertext and an authentication tag;

[0096] Step 52, encapsulate the encrypted data and related metadata into an encrypted data packet, and transmit the encrypted data packet.

[0097] In this embodiment, in step 51, the AES-256-GCM mode can be used to encrypt the byte stream to generate a ciphertext and an authentication tag. The authentication tag generated by the GCM mode is used to verify the integrity of the data. In step 52, the encrypted data packet includes the ciphertext, the authentication tag, the initialization vector, the timestamp, the serial number, and the sensitive metadata (such as the user ID) is additionally encrypted, and the digital signature technology is used to sign the data packet to ensure the authenticity of the source; when transmitting, a secure protocol such as TLS 1.3 can be used to transmit the encrypted data packet, and the receiving end decrypts the ciphertext with the shared key.

[0098] As shown in Figure 2 the figure, the present application further provides a service data encryption system applying quantum encryption. The system includes:

[0099] An acquisition module 10, configured to construct a fixed time window, acquire key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set;

[0100] A generation module 20, configured to generate topological structures of different scales according to the point cloud set, record topological feature information at each scale, and generate a persistence diagram;

[0101] A calculation module 30, configured to extract statistical quantities from the persistence diagram and calculate a decision factor corresponding to the current fixed time window;

[0102] An encryption module 40, configured to determine the key length of each bank-enterprise business data according to the decision factor based on the sensitivity coefficient of each bank-enterprise business data, and call a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window;

[0103] A transmission module 50, configured to encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet.

[0104] It should be noted that this system corresponds to the above method. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0105] An embodiment of the present invention further provides a computing device, including: a processor and a memory storing a computer program. When the computer program is run by the processor, the above-mentioned method is executed. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0106] An embodiment of the present invention further provides a computer-readable storage medium storing instructions. When the instructions are run on a computer, the computer is made to execute the above-mentioned method. All implementation manners in the above method embodiments are applicable to this embodiment and can achieve the same technical effects.

[0107] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0108] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, systems, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0109] In the embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the systems or units can be in electrical, mechanical, or other forms.

[0110] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0111] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0112] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0113] In addition, it should be noted that in the system and method of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to be executed in chronological order. Some steps can be executed in parallel or independently of each other. For those of ordinary skill in the art, it is understandable that all or any steps or components of the method and system of the present invention can be implemented in any computing system (including processors, storage media, etc.) or a network of computing systems in the form of hardware, firmware, software, or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0114] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing system. The computing system can be a well-known general system. Therefore, the object of the present invention can also be achieved only by providing a program product containing program code for implementing the method or system. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be noted that in the system and method of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to be executed in chronological order. Some steps can be executed in parallel or independently of each other.

[0115] The above are the preferred embodiments of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for encrypting service data using quantum encryption, characterized in that, The method includes: Construct a fixed time window, obtain the key metadata of each transaction through the direct bank-enterprise connection system, and detect the network pulse parameters in real time; the key metadata includes the transaction timestamp, transaction amount, transaction serial number, and user identifier, and the network pulse parameters include bandwidth, latency, packet loss rate, and jitter; combine the key metadata of each transaction and the corresponding network pulse parameters into a multi-dimensional vector, and collect all multi-dimensional vectors under the current fixed time window to obtain the point cloud set corresponding to the current fixed time window; Generate topological structures of different scales based on the point cloud set, record the topological feature information at each scale, and generate a persistence diagram; Extract statistical quantities from the persistence diagram and calculate the decision factor corresponding to the current fixed time window; Based on the sensitivity coefficients of each bank-enterprise business data, determine the key length of each bank-enterprise business data according to the decision factor, and call the quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window; Encrypt each bank-enterprise business data according to the unique key and generate an encrypted data packet; Among them, the extracting statistical quantities from the persistence diagram and calculating the decision factor corresponding to the current fixed time window includes: presetting the time window security value according to the business information under the current fixed time window; Through the formula: Calculate the decision factor D; where α is the global scaling factor, B is the current bandwidth, B max is the maximum bandwidth, L is the current delay, L max is the maximum delay, P is the packet loss rate, β is the scaling factor for controlling the sensitivity impact, T is the preset time window safety value, γ is the weighting factor for balancing the topology impact, C0 is the mean persistence of the connected component, C1 is the variance of the persistence of the ring, and C2 is the maximum persistence of the hole; The determining the key length of each bank-enterprise business data according to the decision factor based on the sensitivity coefficients of each bank-enterprise business data includes: Classify different business types, and match the corresponding sensitivity coefficients for different business types to obtain the sensitivity coefficients corresponding to each bank-enterprise business data under the fixed time window; Through the formula: Calculate the key length CL of each bank-enterprise business data, where CL min is the minimum key length, and CL max is the maximum key length, D is the decision factor, τ is the control parameter, and S is the sensitivity coefficient corresponding to the bank-enterprise business data.

2. The method for encrypting service data using quantum encryption according to claim 1, characterized in that, Generating topological structures of different scales based on the point cloud set, recording the topological feature information at each scale, and generating a persistence diagram includes: Construct a topological structure according to the point cloud set through the Vietoris-Rips complex and extract topological features of different scales; Record the lifespan of each topological feature, and generate a persistence diagram according to the lifespans of all topological features.

3. The business data encryption method applying quantum encryption according to claim 2, wherein The extracting statistical quantities from the persistence diagram and calculating the decision factor corresponding to the current fixed time window further includes: Classify the feature points in the persistence diagram by dimension, and calculate the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension; Calculate the statistical quantities of the topological features according to the persistence list.

4. The business data encryption method using quantum encryption according to claim 3, wherein Classifying the feature points in the persistence diagram by dimension, and calculating the persistence of each feature point to generate a persistence list corresponding to the feature points of each dimension includes: Classify 0-dimensional features, 1-dimensional features, and 2-dimensional features as connected components, loops, and holes in sequence; Calculate the persistence of each feature point, and classify and count the persistence of each feature point to obtain a persistence list corresponding to the feature points of each dimension.

5. The method for encrypting service data using quantum encryption according to claim 4, characterized in that, Calling the quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window includes: Use the unique identifier of the bank-enterprise business data as the seed, and call the quantum random number generator. With the seed as the input, generate a random key according to the key length; Associate the random key with the bank-enterprise business data and store it.

6. The service data encryption method applying quantum encryption according to claim 5, characterized in that, Encrypt each bank-enterprise business data according to a unique key and generate an encrypted data packet, including: Serialize each bank-enterprise business data into a byte stream, and encrypt the byte stream to generate a ciphertext and an authentication tag; Encapsulate the encrypted data and related metadata into an encrypted data packet, and transmit the encrypted data packet.

7. A business data encryption system applying quantum encryption, characterized in that, For implementing the business data encryption method using quantum encryption as described in any one of claims 1-6, the system includes: An acquisition module, configured to construct a fixed time window, acquire the key metadata and network pulse information of each bank-enterprise business data within the fixed time window, and generate a point cloud set; A generation module, configured to generate topological structures of different scales according to the point cloud set, and record topological feature information at each scale to generate a persistent graph; A calculation module, configured to extract statistical quantities from the persistent graph and calculate the decision factor corresponding to the current fixed time window; An encryption module, configured to determine the key length of each bank-enterprise business data according to the decision factor based on the sensitivity coefficient of each bank-enterprise business data, and call a quantum random number generator to generate a unique key for each bank-enterprise business data under the current fixed time window; A transmission module, which encrypts each bank-enterprise business data according to the unique key and generates an encrypted data packet.

8. A computing device, characterized in that, Including: One or more processors; A storage system, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, A program is stored in the computer-readable storage medium, and when the program is executed by a processor, the method as described in any one of claims 1-6 is implemented.

Citation Information

Patent Citations

  • Three-dimensional point cloud classification method fusing persistent coherence

    CN114581718A

  • Cyberattack detection with topological data

    US20230412623A1

Cited By

  • Quantum encryption method based on EOS M-OTN equipment

    CN122226503A

  • Warehouse business data encryption system and method based on hybrid encryption architecture

    CN122802148A