Secure encryption transmission method and system for 5G message

Through technical means such as dynamic encryption rule set and multi-dimensional threat detection, flexible and efficient encryption of 5G message transmission is achieved, solving the problem that traditional encryption methods are difficult to cope with complex network attacks and lack of flexibility, improving security and adaptability, and ensuring data transmission security.

CN120111477AActive Publication Date: 2025-06-06深圳市壹通道科技有限公司

Patent Information

Application Number
CN202510578380.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-06-06
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

In 5G message transmission, traditional encryption methods are difficult to resist complex network attacks, and lack flexibility, and cannot meet the real-time and security requirements of different application environments and business needs.

Method used

By obtaining 5G message data sources, analyzing security requirements parameters, querying dynamic encryption rulesets, extracting core encryption elements, detecting associated topology nodes, performing multi-dimensional threat detection, calculating real-time risk entropy values, performing adaptive security hierarchy, performing dynamic mask processing, building a key distribution link, and injecting a quantum cache module to monitor the interaction state to optimize encrypted transmission.

Benefits of technology

It realizes flexible encryption protection for data sources of different risk levels, improves the security and adaptability of 5G message transmission, meets the needs of high real-time and high security, and ensures the confidentiality and integrity of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111477A_ABST
    Figure CN120111477A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and discloses a 5G message-oriented security encryption transmission method and system, and the method comprises the steps: firstly obtaining a 5G information data source, analyzing security demand parameters, querying a corresponding dynamic encryption rule set, extracting a core encryption element, detecting an associated topology node on a transmission path, carrying out the multi-dimensional threat detection of the node, and obtaining a 5G information data source; an abnormal behavior mode is recognized, a real-time risk entropy value is calculated, according to the real-time risk entropy value, data sources are subjected to adaptive security grading, a key distribution link is constructed through operations such as dynamic mask processing and the like, then multilayer encrypted data blocks are injected into a quantum cache module, a link optimization direction is determined according to an interaction state, an encryption equilibrium value is calculated and the like, and finally an encryption transmission report is generated. According to the invention, the security integrity of the 5G message in the transmission process can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secure encryption transmission method and system for 5G messages, and belongs to the field of communication technology. Background Art

[0002] As one of the important applications in the 5G era, 5G messages integrate a variety of rich media forms such as text, pictures, audio, video, etc., greatly expanding the dimension and efficiency of information transmission, and are widely used in many fields such as social, finance, government affairs, and medical care.

[0003] However, with the continuous expansion of 5G message application scenarios, on the one hand, the data transmitted by 5G messages contains a large amount of sensitive information, such as personal privacy, commercial secrets, financial transaction data, etc. The traditional transmission encryption method is difficult to resist the increasingly complex network attack methods, such as malware intrusion, man-in-the-middle attacks, etc., which can easily lead to data leakage and tampering, seriously threatening user information security; on the other hand, under different application environments and business needs, the transmission encryption of 5G messages lacks flexible adaptability. For example, in some medical emergency information transmission scenarios with extremely high real-time requirements, the existing encryption algorithms may take too long to encrypt and decrypt, affecting the timely delivery of information and failing to meet the urgent needs of actual business. Therefore, there is an urgent need for a secure encryption transmission method for 5G messages to ensure the security and integrity of 5G messages during transmission. Summary of the invention

[0004] The present invention provides a secure encryption transmission method and system for 5G messages, the main purpose of which is to ensure the security integrity of 5G messages during transmission.

[0005] To achieve the above object, the present invention provides a secure encryption transmission method for 5G messages, comprising: Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; Performing multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identifying an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculating a real-time risk entropy value corresponding to the abnormal behavior pattern; Based on the real-time risk entropy value, the 5G message data source is adaptively security graded to obtain a multi-layer encrypted data block, dynamic mask processing is performed on the multi-layer encrypted data block to obtain a mask identification sequence, the mask identification sequence is associated with the authentication credential of the preset target terminal, and a key distribution link corresponding to the authentication credential is constructed; Based on the key distribution link, injecting the multi-layer encrypted data block into a preset quantum cache module, monitoring the interaction state of the data flow in the quantum cache module, determining the link optimization direction corresponding to the key distribution link based on the interaction state, extracting the optimized encryption point in the link optimization direction, and calculating the encryption equilibrium value corresponding to the key distribution link based on the optimized encryption point; Based on the encryption balance value, a security transmission indicator corresponding to the key distribution link is generated, the security fluctuation trend corresponding to the security transmission indicator is analyzed, and the fluctuating transmission factor in the security fluctuation trend is identified; based on the fluctuating transmission factor, an encryption transmission report corresponding to the 5G message data source is generated.

[0006] Optionally, detecting the associated topological nodes of the core encryption element on the transmission path includes: Parsing key feature identifiers in the core encryption elements; Draw a preliminary topological sketch corresponding to the key feature identifier on the transmission path; Extracting potential topological points in the preliminary topological sketch; Performing a deep scan on the potential topological points to obtain topological correlation parameters; Based on the topology association parameters, an associated topology node on the transmission path is determined.

[0007] Optionally, performing multi-dimensional threat detection on the associated topological node to obtain a multi-dimensional threat vector includes: Collect basic operation data corresponding to the associated topological nodes; Based on the basic operation data, construct an initial state portrait corresponding to the associated topological node; Analyzing the image traffic distribution in the initial state image; Marking anomaly detection segments in the profile traffic distribution; Multi-dimensional threat detection is performed on the anomaly detection segment to obtain a multi-dimensional threat vector.

[0008] Optionally, calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes: The real-time risk entropy value corresponding to the abnormal behavior pattern is calculated using the following formula: in, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the number corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, Indicates The probability of occurrence of abnormal behavior patterns, Indicates The duration of abnormal behavior patterns, Indicates the time range from the start of abnormal behavior to the current moment, Indicates abnormal behavior patterns over time The severity score, Indicates abnormal behavior patterns over time The weight coefficient of .

[0009] Optionally, based on the real-time risk entropy value, adaptively grading the 5G message data source to obtain a multi-layer encrypted data block includes: Analyze the distribution law corresponding to the real-time risk entropy value; Based on the distribution law, determining the fluctuation range corresponding to the real-time risk entropy value; Based on the fluctuation range, preliminarily grouping the 5G message data source to obtain a grouped data source; Evaluating the importance coefficient corresponding to the grouped data source; Based on the importance coefficient, the grouped data sources are sorted to obtain a sorting result; Adaptively perform security grading on the sorting results to obtain multi-layer encrypted data blocks.

[0010] Optionally, performing dynamic mask processing on the multi-layer encrypted data block to obtain a mask identification sequence includes: Analyzing the encryption strength corresponding to the data in the multi-layer encrypted data block; Based on the encryption strength, generating a mask rule set corresponding to the multi-layer encrypted data block; Based on the mask rule set, masking is performed on the multi-layer encrypted data blocks to obtain a masked data block set; Extracting mask identification points from the mask data block set; Based on the mask identification points, a mask identification sequence corresponding to the multi-layer encrypted data block is generated.

[0011] Optionally, determining a link optimization direction corresponding to the key distribution link based on the interaction state includes: Extracting core status indicators in the interaction status; Based on the core status indicator, identifying a status influencing point in the key distribution link; Based on the state influencing point, querying the link structure corresponding to the key distribution link; Analyze the topology optimization suggestions corresponding to the link structure; Based on the topology optimization suggestion, generating an optimization strategy set corresponding to the key distribution link; Based on the optimization strategy set, a link optimization direction corresponding to the key distribution link is determined.

[0012] Optionally, the calculating, based on the optimized encryption point, an encryption balance value corresponding to the key distribution link includes: The encryption balance value corresponding to the key distribution link is calculated using the following formula: in, represents the encryption balance value corresponding to the key distribution link, Indicates the total number of optimized encryptions. represents the quantity index corresponding to the optimized encryption, Indicates The security score corresponding to the optimized encryption point, Indicates The transmission efficiency corresponding to the optimized encryption point is Indicates The transmission delay corresponding to the optimized encryption point is Indicates The computational cost of the optimized encryption point is Indicates the maximum computational cost value among all optimized encryption points.

[0013] Optionally, generating a security transmission indicator corresponding to the key distribution link based on the encryption balance value includes: Analyzing the balanced distribution points corresponding to the encrypted balanced values; Based on the balanced distribution points, querying uniformly weak areas in the key distribution link; Performing high-risk detection on the uniform weak area to obtain a high-risk detection result; Extracting key risk items from the high-risk detection results; Based on the key risk items, a security transmission indicator corresponding to the key distribution link is generated.

[0014] In order to solve the above problems, the present invention also provides a secure encryption transmission system for 5G messages, the system comprising: A node detection module is used to obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; A risk entropy value calculation module is used to perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate a real-time risk entropy value corresponding to the abnormal behavior pattern; A link construction module, configured to perform adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain a multi-layer encrypted data block, perform dynamic mask processing on the multi-layer encrypted data block to obtain a mask identification sequence, associate the mask identification sequence with the authentication credential of the preset target terminal, and construct a key distribution link corresponding to the authentication credential; A balance value calculation module, used to inject the multi-layer encrypted data block into a preset quantum cache module based on the key distribution link, monitor the interaction state of the data flow in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption point in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption point; A report generation module is used to generate a security transmission indicator corresponding to the key distribution link based on the encryption balance value, analyze the security fluctuation trend corresponding to the security transmission indicator, identify the fluctuating transmission factor in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuating transmission factor.

[0015] Compared with the problems described in the background technology, the present invention obtains the 5G message data source and parses the security requirement parameters in the 5G message data source to enhance the flexibility and adaptability of the encryption strategy, ensuring that the data is protected in a targeted manner during transmission. At the same time, it helps to optimize resource allocation, improve encryption efficiency, and meet the dual requirements of high real-time and high security. The present invention performs multi-dimensional threat detection on the associated topological nodes to obtain multi-dimensional threat vectors, which can comprehensively understand the security risks faced by the nodes from multiple dimensions. It can accurately locate potential threats such as malware intrusion and abnormal traffic attacks by analyzing multiple factors such as network traffic, node status, and surrounding environment, and effectively improve the security and stability of key nodes in the 5G message transmission path. Furthermore, the present invention performs adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, which can accurately adapt to different risks. The protection requirements of the data source of the degree can effectively resist serious threats and protect key data; low-risk entropy values ​​use relatively lightweight encryption to improve processing efficiency. Further, based on the key distribution link, the present invention injects the multi-layer encrypted data block into the preset quantum cache module, and monitors the interactive state of the data flow in the preset quantum cache module, which can grasp the storage and call of the data in real time. It can not only timely discover potential security threats and ensure data integrity, but also optimize the data processing flow and improve the reliability and efficiency of 5G message data processing. Finally, based on the encryption balance value, the present invention generates the security transmission index corresponding to the key distribution link, which can convert the link encryption state into an intuitive quantitative value, which is convenient for evaluating the overall security transmission level of the link, accurately locating advantages and disadvantages, and can provide a strong reference for optimizing the link security strategy, helping to improve the security and stability of data transmission, and ensuring the reliable operation of 5G message communication. Therefore, a secure encryption transmission method and system for 5G messages provided in an embodiment of the present invention can ensure the security integrity of 5G messages during transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A flowchart of a secure encryption transmission method for 5G messages provided by an embodiment of the present invention; Figure 2 A schematic diagram of modules for implementing a secure encrypted transmission system for 5G messages provided in accordance with an embodiment of the present invention.

[0017] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION

[0018] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0019] The embodiment of the present application provides a secure encrypted transmission method for 5G messages. The execution subject of the secure encrypted transmission method for 5G messages includes but is not limited to at least one of the electronic devices such as a server and a terminal that can be configured to execute the method provided by the embodiment of the present application. In other words, the secure encrypted transmission method for 5G messages can be executed by software or hardware installed on a terminal device or a server device. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc.

[0020] Embodiment 1: Reference Figure 1 As shown, it is a flow chart of a secure encryption transmission method for 5G messages provided by an embodiment of the present invention. In this embodiment, the secure encryption transmission method for 5G messages includes: S1. Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path.

[0021] The present invention obtains the 5G message data source and parses the security requirement parameters in the 5G message data source, thereby enhancing the flexibility and adaptability of the encryption strategy and ensuring that the data is targetedly protected during the transmission process. At the same time, it helps to optimize resource allocation, improve encryption efficiency, and meet the dual requirements of high real-time performance and high security.

[0022] Among them, the 5G message data source refers to the source of the original data of 5G messages, which covers a collection of information in various media forms such as text, pictures, audio, video, etc., sent from various applications, devices or systems. For example, messages containing text and pictures sent by users in social applications, account transaction information pushed by financial institutions to customers (may contain text and charts), notices issued by government departments (may contain text, audio descriptions, etc.), and patient medical records transmitted by medical institutions (may contain text, images, etc.), all of which belong to the category of 5G message data sources; the security requirement parameters refer to a series of indicators used to describe the specific requirements of 5G messages in terms of secure transmission, which may include the sensitivity level of data, For example, personal privacy information is highly sensitive, while general notification information is of low sensitivity; real-time transmission requirements, such as medical emergency information transmission requires extremely high real-time requirements, while some non-urgent commercial promotion messages have relatively low real-time requirements; and specific requirements for data integrity and confidentiality, such as financial transaction data must ensure integrity to prevent tampering, and at the same time, the confidentiality requirements are also extremely high and cannot be illegally obtained. Optionally, the analysis of the security requirement parameters in the 5G message data source can be achieved through a decision tree algorithm, such as: taking various features of 5G messages as input nodes, such as message source, message type, transmission frequency, etc., and training the decision tree so that it can output corresponding security requirement parameters based on these features.

[0023] Furthermore, the present invention can effectively respond to complex network attacks, ensure the confidentiality and integrity of data during transmission, and prevent the leakage and tampering of sensitive information by querying the dynamic encryption rule set corresponding to the security requirement parameters and extracting the core encryption elements in the dynamic encryption rule set. At the same time, it can greatly improve the encryption efficiency, meet the business scenarios with different requirements for real-time and security such as medical and financial, and enhance the security and adaptability of 5G message transmission.

[0024] Among them, the dynamic encryption rule set refers to a set of encryption rules dynamically generated according to different security requirement parameters. It is not fixed, but can adapt to the diverse application scenarios and real-time changing security situation of 5G messages. For example, when 5G messages involve financial transactions, the rule set focuses on high-intensity data encryption and integrity verification, and stipulates the use of specific encryption algorithms to encrypt key information such as transaction amounts and account numbers, and sets up strict integrity verification mechanisms; in general social message scenarios, the rule set pays more attention to encryption efficiency, and adopts a relatively lightweight encryption method while ensuring a certain level of security; the core encryption element refers to the most critical component of the dynamic encryption rule set, which determines The core characteristics and effects of encryption are determined, including the selection of encryption algorithms. Different encryption algorithms have their own characteristics in terms of security, computational complexity and encryption speed. For example, the AES algorithm is often used in scenarios with high requirements for data confidentiality, while the RSA algorithm performs well in key exchange and digital signatures; key management methods, such as key generation, distribution, update and storage rules. Secure and efficient key management is essential to ensure the security of the encryption system; and data integrity verification methods, such as generating message digests through hash functions to verify whether data has been tampered with during transmission. Optionally, the query of the dynamic encryption rule set corresponding to the security requirement parameters can be implemented through a rule engine matching method, such as: Drools rule engine, etc., taking the security requirement parameters as input facts, and pre-defining a series of rules in the rule engine that match the dynamic encryption rule set according to different security requirement parameters; the extraction of the core encryption elements in the dynamic encryption rule set can be implemented through element extraction tools, such as: ANTLR and other tools, and the generation analyzer can accurately extract elements such as encryption algorithms and key lengths.

[0025] Furthermore, the present invention helps to discover potential security weaknesses in advance by detecting the associated topological nodes of the core encryption elements on the transmission path, focus on protecting nodes that are vulnerable to attacks, avoid the failure of the encrypted transmission process due to damage to key nodes, and effectively ensure the reliability and security of 5G message encrypted transmission.

[0026] Among them, the transmission path refers to the physical and logical path of the 5G message starting from the data source, passing through base stations, optical fibers, routers, switches and other network equipment, following specific network routing rules, dynamically adjusting the links passed, and finally reaching the target terminal; the associated topology node refers to the network node that is finally determined based on the topology association parameters and has an actual and close association with the core encryption elements on the transmission path. By analyzing the topology association parameters, the nodes that are truly related to the core encryption elements are screened out. These nodes constitute the actual network architecture of the core encryption elements on the transmission path. For example, after analyzing the topology association parameters of multiple potential topology points, certain specific base stations, servers and other nodes are determined to be associated topology nodes.

[0027] As an embodiment of the present invention, the detection of associated topological nodes of the core encryption elements on the transmission path includes: parsing key feature identifiers in the core encryption elements; drawing a preliminary topological sketch corresponding to the key feature identifiers in the transmission path; extracting potential topological points in the preliminary topological sketch; performing a deep scan on the potential topological points to obtain topological association parameters; and determining associated topological nodes on the transmission path based on the topological association parameters.

[0028] Among them, the key feature identifier refers to the specific information in the core encryption element that can characterize its unique attributes and associations on the transmission path. These identifiers may include the encryption algorithm type, key length, encrypted data block size, etc. For example, a specific encryption algorithm such as AES-256, its algorithm name and key length of 256 bits constitute a key feature identifier; the preliminary topology sketch refers to a rough network topology structure mapped and drawn on the transmission path based on the key feature identifier. The sketch is not an accurate network topology map, but a potential related area quickly located and outlined based on the key feature identifier; the potential topology point refers to the preliminary topology sketch. The network node locations that are identified and closely associated with the core encryption elements may be the locations of network devices such as routers, switches, and base stations, and are the focus of subsequent deep scanning and analysis. For example, in the sketch, it is found that multiple nodes in a certain area show characteristics related to a specific encryption algorithm. These node locations are potential topological points; the topological association parameters refer to a series of parameters obtained by deep scanning of potential topological points, which are used to describe the specific association relationship between potential topological points and core encryption elements. These parameters include the node's network address, device type, transmission rate, encryption support capability, and connection status with adjacent nodes.

[0029] Furthermore, the parsing of the key feature identifiers in the core encryption elements can be achieved through a rule-based matching method, such as matching the data of the core encryption elements with the rules, and when the data conforms to a certain rule, the corresponding key feature identifier can be identified; the drawing of the preliminary topology sketch corresponding to the key feature identifier in the transmission path can be achieved through a heuristic search method, such as starting from the node where the known key feature identifier is located, gradually searching adjacent nodes through heuristic rules to construct a preliminary topology sketch; the extraction of potential topology points in the preliminary topology sketch can be achieved through a clustering analysis method, such as clustering the nodes in the preliminary topology sketch according to their characteristics, and the central node or representative node in each cluster can be used as a potential topology point; the deep scanning of the potential topology points can be achieved through a deep scanning tool, such as Nessus, Masscan and other tools; the determination of the associated topology nodes on the transmission path can be achieved through a multi-factor comprehensive evaluation method, such as: comprehensively considering multiple factors in the topology association parameters, such as the encryption capability, bandwidth, security status, etc. of the node, evaluating the potential topology points, and determining the associated topology nodes.

[0030] S2. Perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate a real-time risk entropy value corresponding to the abnormal behavior pattern.

[0031] The present invention performs multi-dimensional threat detection on the associated topological nodes to obtain multi-dimensional threat vectors, which can provide comprehensive insights into the security risks faced by the nodes from multiple dimensions. It can accurately locate potential threats such as malware intrusion and abnormal traffic attacks by analyzing multiple factors such as network traffic, node status, and surrounding environment, and effectively improve the security and stability of key nodes in the 5G message transmission path.

[0032] Among them, the multidimensional threat vector refers to a quantitative representation that comprehensively reflects the threat situation faced by the associated topological nodes in multiple dimensions. It is usually composed of threat feature values ​​of multiple dimensions. These dimensions may include threat type (such as malware attack, DDoS attack, port scan, etc.), threat severity (different levels from low to high), the possibility of threat occurrence (based on the probability assessment of historical data and current abnormal situations), the type of resources affected (such as CPU, memory, network bandwidth, etc.) and the scope of threat propagation (inside the node, local network or larger range), etc.

[0033] As an embodiment of the present invention, the multi-dimensional threat detection is performed on the associated topological nodes to obtain a multi-dimensional threat vector, including: collecting basic operation data corresponding to the associated topological nodes; based on the basic operation data, constructing an initial state portrait corresponding to the associated topological node; analyzing the portrait traffic distribution in the initial state portrait; marking the abnormal detection segment in the portrait traffic distribution; performing multi-dimensional threat detection on the abnormal detection segment to obtain a multi-dimensional threat vector.

[0034] Among them, the basic operation data refers to a series of key information generated by the associated topological nodes under normal operating conditions. These data cover the hardware performance indicators of the nodes, such as CPU utilization, memory usage, disk I / O rate, etc., reflecting the computing and storage resource usage of the nodes; network-related data, including the transmission rate of the network interface, the number of data packets sent and received, the packet loss rate, etc., reflecting the performance of the nodes in network communications; and system operation status information, such as the number of processes, service operation status, etc.; the initial state portrait refers to an intuitive and comprehensive node state description model constructed based on the basic operation data of the associated topological nodes, for example, through a chart showing the change curve of CPU utilization over time, the real-time value of memory usage, and the fluctuation trend of network traffic; the portrait traffic distribution refers to the detailed presentation of the network traffic part in the initial state portrait, which describes It describes the traffic distribution of associated topological nodes in different time periods, different network protocols and different communication directions. For example, a bar chart or a line chart is used to show the TCP and UDP traffic sizes received and sent by nodes in different hourly periods within a day; or a pie chart is used to present the traffic proportions occupied by different application layer protocols (such as HTTP, FTP, SMTP, etc.); the anomaly detection segment refers to a time period or traffic interval that is significantly different from the normal traffic pattern and is identified in the profile traffic distribution. For example, the network traffic was relatively stable in a certain period of time, but suddenly a peak several times the normal traffic appeared, or a protocol that is rarely used in normal times generated a large amount of traffic in a certain period of time. The traffic time period or interval corresponding to these abnormal situations is the anomaly detection segment.

[0035] Furthermore, the collection of basic operation data corresponding to the associated topological nodes can be achieved through data collection tools, such as Zabbix, Syslog-ng and other tools; the construction of the initial state portrait corresponding to the associated topological nodes can be achieved through data fusion and visualization methods, such as fusing the collected basic operation data of different types, and then displaying it as an intuitive portrait through visualization technology; the analysis of the portrait traffic distribution in the initial state portrait can be achieved through a protocol analysis method, such as classifying and counting the traffic data according to different network protocols, analyzing the proportion of each protocol in the total traffic and its changes over time; the marking of the abnormal detection segment in the portrait traffic distribution can be achieved through a threshold-based detection method, such as setting a reasonable traffic threshold based on historical traffic data and business needs. When the traffic data exceeds or falls below these thresholds, the corresponding time period is marked as an abnormal detection segment; the multi-dimensional threat detection of the abnormal detection segment can be achieved through threat detection tools, such as SIEM, VirusTotal and other tools.

[0036] By identifying the abnormal behavior patterns corresponding to the multi-dimensional threat vectors, the present invention can quickly locate abnormal behaviors such as malware intrusion and DDoS attacks, and then provide early warnings, thereby buying valuable time for the timely deployment of targeted protection strategies, and effectively ensuring the security and stability of 5G message transmission.

[0037] Among them, the abnormal behavior pattern refers to a series of behavior characteristics or behavior sequences that are significantly different from the behavior performance under normal operating conditions in a system or network environment, which may include traffic anomalies, such as sudden large-scale data transmission, abnormal traffic peaks, or continuous low-traffic but high-frequency connection attempts; resource usage anomalies, such as excessive occupation of resources such as CPU and memory, or abnormal resource allocation patterns; user behavior anomalies, such as frequent logins during non-working hours, abnormal operation sequences, or abuse of permissions; and data access anomalies, such as abnormal reading and writing operations on sensitive data, or unauthorized data access attempts, etc. Optionally, the identification of the abnormal behavior pattern corresponding to the multidimensional threat vector can be achieved through a clustering analysis method, such as: treating the multidimensional threat vector as a data point, using a clustering algorithm to cluster similar vectors together, and each cluster represents a potential behavior pattern, where a cluster that is significantly different from a normal behavior pattern cluster can be identified as an abnormal behavior pattern.

[0038] Furthermore, by calculating the real-time risk entropy value corresponding to the abnormal behavior pattern, the present invention can intuitively compare the risk levels of different abnormal behavior patterns and clearly determine the severity of the threat, which provides an accurate basis for security decision-making, helps to prioritize high-risk anomalies, and reasonably allocate security protection resources.

[0039] Among them, the real-time risk entropy value refers to a quantitative indicator of the risk level of an abnormal behavior pattern within a specific time range, which comprehensively considers multiple factors, such as the probability of occurrence, duration, severity score and weight coefficient of the abnormal behavior pattern. For example, in a network security scenario, the higher the real-time risk entropy value, the greater the threat posed by the current abnormal behavior pattern to network security.

[0040] As an embodiment of the present invention, the calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes: The real-time risk entropy value corresponding to the abnormal behavior pattern is calculated using the following formula: in, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the number corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, Indicates The probability of occurrence of abnormal behavior patterns, Indicates The duration of abnormal behavior patterns, Indicates the time range from the start of abnormal behavior to the current moment, Indicates abnormal behavior patterns over time The severity score, Indicates abnormal behavior patterns over time The weight coefficient of .

[0041] In detail, the occurrence probability refers to The probability of occurrence of an abnormal behavior pattern is a value between 0 and 1 obtained based on historical data, monitoring data or related model predictions, where 0 means that the abnormal behavior pattern is unlikely to occur and 1 means that it will definitely occur. The duration refers to the The duration of the abnormal behavior pattern from the beginning to the current moment, which reflects the time span of the abnormal behavior pattern affecting the system or network; the severity score refers to the severity of the abnormal behavior pattern. A quantitative assessment of the degree of harm caused by a type of abnormal behavior pattern to a system or network at a certain time. It is usually scored by security experts based on experience, relevant standards or pre-set rules. The higher the score, the higher the severity of the abnormal behavior pattern. The weight coefficient refers to the coefficient of the importance or influence of the type of abnormal behavior pattern at a certain time relative to other abnormal behavior patterns. For example, in some systems with extremely high requirements for data confidentiality, the weight coefficient of abnormal behavior patterns involving data leakage will be set higher, while in scenarios focusing on system availability, the weight coefficient of abnormal behavior patterns that affect the normal operation of the system will be greater.

[0042] S3. Based on the real-time risk entropy value, the 5G message data source is adaptively security graded to obtain multi-layer encrypted data blocks, dynamic mask processing is performed on the multi-layer encrypted data blocks to obtain a mask identification sequence, the mask identification sequence is associated with the authentication credential of the preset target terminal, and a key distribution link corresponding to the authentication credential is constructed.

[0043] Based on the real-time risk entropy value, the present invention performs adaptive security grading on the 5G message data source to obtain multi-layer encrypted data blocks, which can accurately adapt to the protection requirements of data sources with different risk levels, effectively resist serious threats, and protect key data; low-risk entropy values ​​use relatively lightweight encryption to improve processing efficiency.

[0044] Among them, the multi-layer encrypted data block refers to an encrypted data unit formed by using encryption methods of different strengths and algorithms for data sources of different security levels after adaptive security grading of the 5G message data source according to the sorting results.

[0045] As an embodiment of the present invention, the 5G message data source is adaptively security graded based on the real-time risk entropy value to obtain a multi-layer encrypted data block, including: analyzing the distribution law corresponding to the real-time risk entropy value; determining the fluctuation range corresponding to the real-time risk entropy value based on the distribution law; preliminarily grouping the 5G message data source based on the fluctuation range to obtain a grouped data source; evaluating the importance coefficient corresponding to the grouped data source; sorting the grouped data source based on the importance coefficient to obtain a sorting result; and adaptively security grading the sorting result to obtain a multi-layer encrypted data block.

[0046] Among them, the distribution law refers to the changing characteristics and trends of the real-time risk entropy value within a certain time or space range, such as whether it is concentrated in certain numerical ranges, or is relatively evenly distributed in a larger numerical interval, or presents periodic changes, etc.; the fluctuation range refers to the changing range of the real-time risk entropy value determined based on the distribution law, that is, the interval formed by the maximum and minimum values ​​of the real-time risk entropy value; the grouped data source refers to the set of data sources of different groups formed after the 5G message data source is preliminarily divided according to the real-time risk entropy value fluctuation range; the importance coefficient refers to the quantitative indicator obtained after evaluating the grouped data source from the dimensions of business, data value, etc., which is used to measure the importance of each data source in the entire 5G message system; the sorting result refers to the sequential list obtained after arranging the grouped data sources from high to low or from low to high according to the importance coefficient. Through sorting, the importance differences of different data sources can be clearly distinguished, providing a direct basis for subsequent security classification.

[0047] Furthermore, the analysis of the distribution law corresponding to the real-time risk entropy value can be achieved through a statistical analysis method, such as: collecting the real-time risk entropy value every hour within a week, dividing the entropy value range into several small intervals, and counting the number of occurrences of the entropy value in each interval to analyze its distribution law; the determination of the fluctuation range corresponding to the real-time risk entropy value can be achieved through a moving average algorithm, such as: by calculating the moving average and moving standard deviation of the real-time risk entropy value, and determining the fluctuation range according to a certain multiple relationship (such as 3 times the standard deviation); the preliminary grouping of the 5G message data source can be achieved through an interval division method, such as: dividing it into several sub-intervals according to the determined real-time risk entropy value fluctuation interval, and then matching the real-time risk entropy value of each data source with these sub-intervals, and classifying the data source into the corresponding interval group; the evaluation of the importance coefficient corresponding to the grouped data source can be achieved through a coefficient evaluation tool, such as: in Yaahp A hierarchical model is constructed, a judgment matrix formed by expert scoring is input, and the importance coefficient of each grouped data source is automatically calculated; the sorting of the grouped data sources can be achieved through a comparison-based sorting method, such as: using a bubble sorting algorithm to compare and exchange the importance coefficients of a group of grouped data sources until all data sources are arranged in order of importance coefficients; the adaptive security grading of the sorting results can be achieved through a threshold division method, such as: setting different security level thresholds according to business needs and security policies, and comparing the sorted data sources with the thresholds according to their importance coefficients, and dividing them into different security levels.

[0048] The present invention performs dynamic mask processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, which can change over time or under specific conditions, effectively resisting continuous targeted attacks. The mask identification sequence is convenient for tracking and managing mask applications, ensuring the confidentiality and integrity of data in different scenarios, and improving the overall security of 5G message data.

[0049] Among them, the mask identification sequence refers to an ordered sequence generated based on the mask identification point, which comprehensively records the detailed information of the mask processing of the multi-layer encrypted data blocks. For example, the mask identification sequence can include information such as the mask starting position, mask length, mask character or value encoding of each data block.

[0050] As an embodiment of the present invention, the dynamic mask processing is performed on the multi-layer encrypted data blocks to obtain a mask identification sequence, including: analyzing the encryption strength corresponding to the data in the multi-layer encrypted data blocks; based on the encryption strength, generating a mask rule set corresponding to the multi-layer encrypted data blocks; based on the mask rule set, performing mask processing on the multi-layer encrypted data blocks to obtain a mask data block set; extracting mask identification points in the mask data block set; based on the mask identification points, generating a mask identification sequence corresponding to the multi-layer encrypted data blocks.

[0051] The encryption strength refers to an indicator that measures the degree of data encryption in a multi-layer encrypted data block, which comprehensively considers factors such as the complexity of the encryption algorithm, the key length, and the number of encryption rounds. For example, the encryption strength of a data block encrypted using the AES-256 algorithm is relatively high, because the 256-bit key length and the complex encryption mechanism of the AES algorithm itself can effectively resist a variety of cracking methods; the mask rule set refers to a set of rules for mask processing generated according to the encryption strength of the multi-layer encrypted data block. These rules specify in detail how to perform mask operations on data blocks, including the selection of mask position, the type of mask character or value, the length of the mask, and other aspects; The masked data block set refers to a group of masked data blocks obtained after masking a multi-layer encrypted data block according to a mask rule set. For example, a multi-layer encrypted data block originally contains sensitive information of the user. After masking, some characters of the sensitive information are replaced by mask characters, thereby forming a masked data block; the mask identification point refers to a key information point in the masked data block set used to identify the position and characteristics of the mask operation. These points record the specific position of the mask and the relevant attributes of the mask during the masking process. For example, in a masked data block, the mask identification point may record information such as the position of the mask starting byte, the type or value of the mask character, etc.

[0052] Furthermore, the analysis of the encryption strength corresponding to the data in the multi-layer encrypted data block can be achieved through a prediction algorithm based on machine learning, such as: by training a random forest model, inputting a large number of data blocks with different encryption algorithms and key lengths and their corresponding known encryption strength levels, and after the training is completed, inputting the characteristics of the data block to be analyzed to predict the encryption strength; the generation of the mask rule set corresponding to the multi-layer encrypted data block can be achieved through a hierarchical strategy method, such as: according to the encryption strength obtained by analysis, it is divided into different levels, such as high, medium and low levels, and different mask rules are formulated for each level; the mask processing of the multi-layer encrypted data block can be achieved through a loop traversal algorithm , such as: for a rule of inserting mask characters at fixed intervals, use a loop to traverse the data block, insert mask characters every fixed number of bytes, and finally obtain a set of data blocks after mask processing; the extraction of mask identification points in the masked data block set can be achieved by a position marking method, such as: when a "#" character is inserted as a mask at the 5th byte position of the data block, the position "5" and the mask character "#" are recorded as the information of the mask identification point; the generation of the mask identification sequence corresponding to the multi-layer encrypted data block can be achieved by a sorting and merging method, such as: after sorting the data block numbers from small to large, the mask identification point information of each data block is connected in sequence to form a mask identification sequence.

[0053] The present invention associates the mask identification sequence with the authentication credentials of the preset target terminal and constructs a key distribution link corresponding to the authentication credentials. By constructing the key distribution link, it ensures that the authentication credentials are transmitted in a safe and orderly manner. While improving data confidentiality, it strengthens the security of terminal access authentication, effectively prevents illegal terminal access, and ensures the security and stability of 5G message communication at the terminal level.

[0054] Among them, the preset target terminal refers to the device that is pre-designated as the data receiving or interaction object in the 5G message communication scenario. These terminals can be various devices that support 5G communication, such as smart phones, tablets, IoT devices, etc. For example, in the 5G message communication system within the enterprise, the employee's work mobile phone is the preset target terminal. The system will perform specific security settings and data distribution for these terminals to ensure the safe transmission and interaction of enterprise information; the authentication credential refers to a set of information used to verify the legitimacy of the identity of the preset target terminal, which contains a variety of elements that can prove the identity of the terminal, such as digital certificates, passwords, tokens, etc. The authentication credential plays a key role in identity authentication when the terminal accesses the 5G communication network or receives specific data. Taking a digital certificate as an example, it is issued by an authoritative certificate authority (CA) and contains the terminal's public key, identity information, and CA's signature, etc.; the key distribution link refers to a set of logical paths and mechanism combinations specially constructed for the secure transmission of authentication credential-related keys. The key distribution link is responsible for securely transmitting these keys from the key generation center or authorized agency to the preset target terminal. It involves a series of communication protocols, encryption algorithms and security strategies. For example, a key distribution method based on public key infrastructure (PKI) can be adopted to exchange and verify key information through digital certificates; or a secure channel, such as a dedicated encrypted tunnel, can be used to ensure that the key is not stolen or tampered with during transmission. Optionally, the association of the mask identification sequence with the authentication credential of the preset target terminal can be achieved through an association method based on a mapping table, such as: creating a mapping table, whose key is the unique identifier of the preset target terminal (such as the international mobile equipment identity code IMEI, the media access control address MAC, etc.), and the value is the corresponding authentication credential information; the construction of the key distribution link corresponding to the authentication credential can be achieved through a link construction method, such as: in an enterprise 5G communication network, the enterprise's internal CA issues certificates to each terminal and the key generation center, and the key generation center distributes keys to the terminal according to the above process.

[0055] S4. Based on the key distribution link, inject the multi-layer encrypted data block into a preset quantum cache module, monitor the interaction state of the data flow in the preset quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption point in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption point.

[0056] Based on the key distribution link, the present invention injects the multi-layer encrypted data blocks into a preset quantum cache module and monitors the interactive state of the data flow in the preset quantum cache module, so as to grasp the storage and call status of the data in real time. It can not only timely discover potential security threats and ensure data integrity, but also optimize the data processing flow and improve the reliability and efficiency of 5G message data processing.

[0057] Among them, the preset quantum cache module refers to a storage device designed using the principles of quantum mechanics, which is specially planned to store key data in the 5G message communication system, such as multi-layer encrypted data blocks. It has ultra-high storage density and can store massive amounts of data in a very small physical space. In the data storage process, the stability of the quantum state is used to ensure the security of the data, which can effectively resist some attacks based on traditional computing technology; the interactive state refers to the dynamic behavior of the data flow in the preset quantum cache module, which covers data writing, reading, transmission and other operations. In terms of writing, it includes the data writing rate, whether it is successfully written, and whether errors or conflict; when reading, it involves the response time of the read request, the accuracy of the read data, and the impact of the read operation on the state of the cache module; at the transmission level, it focuses on the speed at which data is output from the cache module to other components, the stability of the transmission, and the data integrity during the transmission process. For example, through monitoring, it is found that the data write rate suddenly decreases, which may mean that the cache module is faulty or facing external interference; if the read response time is too long, it may imply that the quantum state inside the cache module is abnormal, affecting the rapid reading of data. Optionally, the interactive state of the data flow in the preset quantum cache module can be monitored by a state monitoring device, such as a quantum oscilloscope, a quantum spectrum analyzer, and other equipment.

[0058] Furthermore, based on the interaction state, the present invention determines the link optimization direction corresponding to the key distribution link, and can optimize from aspects such as encryption algorithm and transmission protocol to improve link efficiency, which not only ensures stable data transmission, but also enhances overall security, ensuring that multi-layer encrypted data blocks are efficiently and securely injected into the quantum cache module through the key distribution link, thereby improving the reliability of 5G message data processing.

[0059] Among them, the link optimization direction refers to the specific action direction that needs to be taken to improve the performance of the key distribution link determined according to the optimization strategy set. For example, if the optimization strategy set includes multiple strategies such as upgrading hardware, optimizing software algorithms, and adjusting topology structures, then the link optimization direction can be to first upgrade the hardware of the nodes with the heaviest load to quickly alleviate the current performance bottleneck; then, gradually optimize the software algorithms of the entire network to improve the overall processing efficiency; finally, according to the long-term change trend of network traffic, adjust the topology of the link to achieve more efficient traffic distribution and resource utilization.

[0060] As an embodiment of the present invention, determining the link optimization direction corresponding to the key distribution link based on the interaction state includes: extracting core state indicators in the interaction state; identifying state impact points in the key distribution link based on the core state indicators; querying the link structure corresponding to the key distribution link based on the state impact points; analyzing the topology optimization suggestions corresponding to the link structure; generating an optimization strategy set corresponding to the key distribution link based on the topology optimization suggestions; and determining the link optimization direction corresponding to the key distribution link based on the optimization strategy set.

[0061] Among them, the core status indicators refer to the quantitative parameters extracted from the interactive status data that can most directly and critically reflect the operating status of the key distribution link. These indicators cover data transmission rate, data packet loss rate, link delay time, encryption and decryption time, and node load rate. For example, the data transmission rate determines the efficiency of key distribution, the packet loss rate reflects the stability of the transmission process, the link delay time affects the real-time performance, the encryption and decryption time reflects the impact of the security mechanism on the link performance, and the node load rate shows the working pressure of each node; the state influencing point refers to the specific positions or links in the key distribution link that have a significant impact on the core status indicators. These points can be key nodes in the network, such as routers, switches, or specific transmission lines in the link. For example, when the data transmission rate suddenly decreases, after investigation, it is found that the load rate of a specific router is extremely high. This router is a state influencing point; the link structure refers to the physical connection relationship and logical layout of each component (such as node equipment, transmission line, etc.) in the key distribution link. For example, a key distribution link can consist of multiple The network is composed of server nodes distributed in different regions, which are connected by high-speed optical fibers to form a star or mesh topology. The topology optimization suggestion refers to professional advice on adjusting the network topology to improve the performance of the key distribution link based on the analysis of the link structure and state influencing points. For example, if it is found that the node load in a certain area is too high, the topology optimization suggestion may be to add an intermediate node in the area to divert the load, or adjust the connection mode of the link to change the original series structure to a parallel structure to improve the parallelism of data transmission. The optimization strategy set refers to a collection of specific optimization measures for the key distribution link, which are further refined and expanded on the basis of the topology optimization suggestion. For example, for a node with too high load, the optimization strategy set may include upgrading the server hardware of the node, increasing memory and CPU performance; at the same time, performing algorithm optimization on the key distribution software running on the node to improve its processing efficiency; in addition, the network protocol parameters used for communication between the node and other nodes may be adjusted, such as increasing the window size, to improve data transmission efficiency.

[0062] Furthermore, the extraction of the core state indicator in the interaction state can be achieved through a statistical analysis method, such as: counting the data transmission rate of each node in the key distribution link within one hour, and calculating its average value as the core transmission rate indicator within the time period; the identification of the state influencing point in the key distribution link can be achieved through an association analysis method, such as: by calculating the correlation between the data transmission rate and the load of each node, it is found that the load of a certain node is highly correlated with the data transmission rate, and the data transmission rate decreases significantly when the load increases, then the node is a state influencing point; the query of the link structure corresponding to the key distribution link can be achieved through a breadth-first search algorithm, such as: starting from a node in the link, using BFS The algorithm traverses the entire network, records the connection relationship between nodes, and finally constructs a link structure; the topology optimization suggestion corresponding to the analysis of the link structure can be implemented through the traffic analysis optimization method, such as: analyzing the traffic distribution in the link, finding out the traffic bottleneck and hot spot area, and proposing topology optimization suggestions based on the analysis results; the generation of the optimization strategy set corresponding to the key distribution link can be implemented through the expert system method, such as: the expert system infers suitable optimization strategies based on the topological structure, traffic conditions and reliability requirements of the link, such as replacing node equipment, adjusting routing protocols, etc.; the determination of the link optimization direction corresponding to the key distribution link can be implemented through the hierarchical analysis method, such as: taking performance improvement, cost control and reliability enhancement as the target layer, and taking optimization strategies such as upgrading equipment and adjusting topological structure as the solution layer, and calculating the score of each solution through AHP, and the solution with the highest score is the link optimization direction.

[0063] The present invention extracts the optimized encryption points in the link optimization direction and makes targeted improvements to these points, which can significantly improve the encryption strength and effectively resist potential security threats. This not only ensures the confidentiality of data during transmission, but also enhances the security and stability of the entire 5G message communication system.

[0064] Among them, the optimized encryption point refers to a specific link or position in the key distribution link that is determined after the link optimization direction analysis and plays a key role in improving encryption performance. For example, at a node where data transmission is frequent and confidentiality requirements are extremely high, if the current encryption algorithm cannot meet security requirements, this node is the optimized encryption point, and the encryption effect can be enhanced by replacing a higher-level encryption algorithm. Optionally, the extraction of the optimized encryption point in the link optimization direction can be achieved through a cryptographic analysis tool, such as: OpenSSL's cryptography test suite, which can perform strength tests on the encryption algorithm used in the link, detect weaknesses in the algorithm, and thus determine the optimized encryption point.

[0065] Furthermore, the present invention calculates the encryption balance value corresponding to the key distribution link based on the optimized encryption point, which can clearly understand the weak and redundant areas of encryption strength and provide a basis for targeted adjustments. This can not only improve the overall encryption efficiency, but also avoid waste of resources, ensure that data can be properly and balancedly encrypted and protected in each link of the link, and enhance the security of 5G message communication.

[0066] Among them, the encryption balance value refers to a numerical value that comprehensively measures the encryption status of the key distribution link. It comprehensively considers factors such as the security score of the optimized encryption point, transmission efficiency, transmission delay, and computing overhead value, and reflects the balance of the link in terms of encryption strength, transmission performance, and computing resource consumption.

[0067] As an embodiment of the present invention, the step of calculating the encryption balance value corresponding to the key distribution link based on the optimized encryption point includes: The encryption balance value corresponding to the key distribution link is calculated using the following formula: in, represents the encryption balance value corresponding to the key distribution link, Indicates the total number of optimized encryptions. represents the quantity index corresponding to the optimized encryption, Indicates The security score corresponding to the optimized encryption point, Indicates The transmission efficiency corresponding to the optimized encryption point is Indicates The transmission delay corresponding to the optimized encryption point is Indicates The computational cost of the optimized encryption point is Indicates the maximum computational cost value among all optimized encryption points.

[0068] In detail, the security score refers to a quantitative evaluation of the encryption security of the jth optimized encryption point, which is determined based on multiple factors, such as the strength of the encryption algorithm used, the security of key management, the ability to resist common attacks, etc., and the higher the score, the better the security performance of the optimized encryption point, and the more effectively it can protect data from being illegally obtained or tampered with; the transmission efficiency refers to the performance index of the jth optimized encryption point in data transmission, which measures the amount of data successfully transmitted by the point per unit time; the transmission delay refers to the time delay generated by the jth optimized encryption point during data transmission, which reflects the time it takes for data to enter the optimized encryption point and leave the point. The lower the transmission delay, the better the real-time performance of data transmission and the faster the response speed of the business; the computational overhead value refers to the amount of resources consumed by the jth optimized encryption point when performing encryption-related calculations, such as CPU computing resources, memory resources, etc., and the lower the computational overhead value, the less system resources the optimized encryption point occupies when implementing encryption functions, which is beneficial to the overall performance and resource utilization efficiency of the system.

[0069] S5. Based on the encryption balance value, generate a security transmission indicator corresponding to the key distribution link, analyze the security fluctuation trend corresponding to the security transmission indicator, and identify the fluctuating transmission factor in the security fluctuation trend; based on the fluctuating transmission factor, generate an encryption transmission report corresponding to the 5G message data source.

[0070] Based on the encryption balance value, the present invention generates a secure transmission indicator corresponding to the key distribution link, and can convert the link encryption status into an intuitive quantitative value, which is convenient for evaluating the overall secure transmission level of the link, accurately locating advantages and disadvantages, and can provide a powerful reference for optimizing the link security strategy, help improve the security and stability of data transmission, and ensure the reliable operation of 5G message communication.

[0071] The secure transmission index refers to a quantitative index generated based on key risk items, which is used to evaluate the security and reliability of the key distribution link, such as a security score (0-100), a risk level (low, medium, high), or a threat coverage rate (percentage).

[0072] As an embodiment of the present invention, the generation of a secure transmission indicator corresponding to the key distribution link based on the encryption balance value includes: analyzing the balanced distribution point corresponding to the encryption balance value; based on the balanced distribution point, querying the uniform weak area in the key distribution link; performing high-risk detection on the uniform weak area to obtain a high-risk detection result; extracting key risk items in the high-risk detection result; and generating a secure transmission indicator corresponding to the key distribution link based on the key risk items.

[0073] Among them, the balanced distribution point refers to a specific position or node determined when analyzing the encryption balance value, which can reflect the balanced state of each optimized encryption point in the key distribution link in terms of security, transmission efficiency, computing overhead, etc., and reflects the distribution of encryption-related factors in the link; the uniformly weak area refers to an area with relatively weak encryption performance and relatively even distribution found in the key distribution link based on the balanced distribution point. This area performs poorly in terms of indicators such as security and transmission efficiency, and may affect the overall security transmission level of the link; the high-risk detection result refers to the result obtained after conducting a high-risk detection on the uniformly weak area, which contains various potential risk information in the area that may cause serious security problems, such as vulnerable links, encryption algorithm vulnerabilities, etc.; the key risk item refers to the risk item that has a significant impact on the secure transmission of the key distribution link, which is screened out from the high-risk detection results, and is a key security risk that needs to be focused on and handled.

[0074] Furthermore, the analysis of the balanced distribution points corresponding to the encrypted balance value can be implemented through Python's Matplotlib tool, such as: using Python's Matplotlib library to draw a scatter plot of the encrypted balance value, observing the data distribution, and thus determining the balanced distribution point; the query of the uniformly weak area in the key distribution link can be implemented through a sliding window algorithm, such as: using a sliding window algorithm, sliding a window on the key distribution link data, and calculating the average encryption performance index in each window. If the indicators of multiple consecutive windows are lower than the average level, then the area can be regarded as a uniformly weak area; the high-risk detection of the uniformly weak area can be It is implemented through the CVSS algorithm, such as: using the CVSS algorithm, according to factors such as the exploitability of the vulnerability and the scope of impact, the risk score of each vulnerability is calculated to obtain a high-risk detection result; the extraction of key risk items in the high-risk detection result can be implemented by the Splunk log analysis tool, such as: using the Splunk log analysis tool, by setting rules, such as according to the risk score threshold, vulnerability type, etc., to extract qualified key risk items; the generation of the security transmission index corresponding to the key distribution link can be implemented by the entropy weight method, such as: using the entropy weight method to determine the weight of each factor in the key risk item, and then calculating a comprehensive security transmission index value by the weighted average method.

[0075] By analyzing the security fluctuation trend corresponding to the security transmission indicator and identifying the fluctuating transmission factors in the security fluctuation trend, the present invention can intuitively understand the dynamic changes in the security performance of the key distribution link. By grasping the trend, potential risks can be predicted in advance. Identifying fluctuation factors helps to accurately locate the root cause of the problem, provide strong support for timely adjustment of security strategies and optimization of link performance, and effectively ensure the safe and stable 5G message communication.

[0076] Among them, the security fluctuation trend refers to a dynamic description of the changes in the security transmission indicators of the key distribution link over time or business volume and other variables. For example, if the security transmission indicator frequently rises and falls within a period of time, it indicates that the link security performance is unstable and there are large fluctuations; if the indicator shows a trend of gradual increase or decrease, it reflects that the link security is gradually increasing or decreasing; the fluctuating transmission factor refers to various internal and external reasons that cause the fluctuation of the security transmission indicators of the key distribution link. Internal factors may include hardware aging of some nodes in the link, resulting in a decrease in data processing capacity, affecting transmission efficiency and security; or unreasonable parameter settings of the encryption algorithm, resulting in insufficient encryption strength in certain specific business scenarios; external factors such as network attacks and malware intrusions can lead to security The overall transmission index deteriorates sharply; the sudden and substantial increase in network traffic exceeds the carrying capacity of the link, which will also cause problems such as transmission delay and packet loss, thereby affecting the security transmission index. Optionally, the analysis of the security fluctuation trend corresponding to the security transmission index can be implemented through Pandas in Python, such as: using Python's Pandas library to read the time series data of the security transmission index, using the moving average algorithm to smooth the data, eliminating short-term fluctuations, and highlighting the overall trend; the identification of the fluctuation transmission factors in the security fluctuation trend can be implemented through a decision tree algorithm, such as: using a decision tree algorithm, taking the fluctuation of the security transmission index as the target variable, and various potential factors as feature variables, to construct a decision tree model, and the important feature in the model is the fluctuation transmission factor.

[0077] Based on the fluctuating transmission factors, the present invention generates an encrypted transmission report corresponding to the 5G message data source, which can systematically sort out the key factors affecting secure transmission, and the report can intuitively present the problem, providing technical personnel with a clear optimization direction, and helping to strengthen encryption measures in a targeted manner. It not only improves the security of 5G message data transmission, but also enhances the reliability and stability of the entire communication system, and ensures the security of user information.

[0078] Among them, the encrypted transmission report refers to a comprehensive and detailed comprehensive document on the encrypted transmission status of the 5G message data source. It takes the fluctuating transmission factor as the starting point and deeply analyzes the various conditions of 5G messages in the encrypted transmission process. The report covers the overall performance of the current encrypted transmission, such as data transmission rate, encryption strength, and key indicators such as error rate during transmission; it clearly points out the specific factors that cause security fluctuations, including hardware equipment aging, network attacks, encryption algorithm defects, etc.; at the same time, based on these analyses, it provides targeted and operational improvement strategies and suggestions to provide solid data support and decision-making reference for optimizing the 5G message encrypted transmission process and improving data transmission security. Optionally, the generation of the encrypted transmission report corresponding to the 5G message data source can be achieved through a report generation tool, such as: Tableau, Power BI and other tools.

[0079] Compared with the problems described in the background technology, the present invention obtains the 5G message data source and parses the security requirement parameters in the 5G message data source to enhance the flexibility and adaptability of the encryption strategy, ensuring that the data is protected in a targeted manner during transmission. At the same time, it helps to optimize resource allocation, improve encryption efficiency, and meet the dual requirements of high real-time and high security. The present invention performs multi-dimensional threat detection on the associated topological nodes to obtain multi-dimensional threat vectors, which can comprehensively understand the security risks faced by the nodes from multiple dimensions. It can accurately locate potential threats such as malware intrusion and abnormal traffic attacks by analyzing multiple factors such as network traffic, node status, and surrounding environment, and effectively improve the security and stability of key nodes in the 5G message transmission path. Furthermore, the present invention performs adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, which can accurately adapt to different risks. The protection requirements of the data source of the degree can effectively resist serious threats and protect key data; low-risk entropy values ​​use relatively lightweight encryption to improve processing efficiency. Further, based on the key distribution link, the present invention injects the multi-layer encrypted data block into the preset quantum cache module, and monitors the interactive state of the data flow in the preset quantum cache module, which can grasp the storage and call of the data in real time. It can not only timely discover potential security threats and ensure data integrity, but also optimize the data processing flow and improve the reliability and efficiency of 5G message data processing. Finally, based on the encryption balance value, the present invention generates the security transmission index corresponding to the key distribution link, which can convert the link encryption state into an intuitive quantitative value, which is convenient for evaluating the overall security transmission level of the link, accurately locating advantages and disadvantages, and can provide a strong reference for optimizing the link security strategy, helping to improve the security and stability of data transmission, and ensuring the reliable operation of 5G message communication. Therefore, a secure encryption transmission method and system for 5G messages provided in an embodiment of the present invention can ensure the security integrity of 5G messages during transmission.

[0080] Embodiment 2: like Figure 2 Shown is a functional module diagram of a secure encrypted transmission system for 5G messages according to the present invention.

[0081] The secure encryption transmission system 200 for 5G messages described in the present invention can be installed in an electronic device. According to the functions implemented, the secure encryption transmission system for 5G messages can include a node detection module 201, a risk entropy value calculation module 202, a link construction module 203, an equilibrium value calculation module 204 and a report generation module 205. The module described in the present invention can also be referred to as a unit, which refers to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, which are stored in the memory of the electronic device.

[0082] In the embodiment of the present invention, the functions of each module / unit are as follows: The node detection module 201 is used to obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; The risk entropy value calculation module 202 is used to perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate a real-time risk entropy value corresponding to the abnormal behavior pattern; The link construction module 203 is used to perform adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain a multi-layer encrypted data block, perform dynamic mask processing on the multi-layer encrypted data block to obtain a mask identification sequence, associate the mask identification sequence with the authentication credential of the preset target terminal, and construct a key distribution link corresponding to the authentication credential; The balance value calculation module 204 is used to inject the multi-layer encrypted data block into a preset quantum cache module based on the key distribution link, monitor the interaction state of the data flow in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption point in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption point; The report generation module 205 is used to generate a security transmission indicator corresponding to the key distribution link based on the encryption balance value, analyze the security fluctuation trend corresponding to the security transmission indicator, and identify the fluctuating transmission factor in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuating transmission factor.

[0083] In detail, each module in the secure encrypted transmission system 200 for 5G messages in the embodiment of the present invention adopts the same method as above when used. Figure 1 The technical means are the same as the secure encryption transmission method for 5G messages described in, and can produce the same technical effects, so they will not be repeated here.

[0084] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.

Claims

1. A secure encryption transmission method for 5G messages, characterized in that: The method comprises: Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; Performing multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identifying an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculating a real-time risk entropy value corresponding to the abnormal behavior pattern; Based on the real-time risk entropy value, the 5G message data source is adaptively security graded to obtain a multi-layer encrypted data block, dynamic mask processing is performed on the multi-layer encrypted data block to obtain a mask identification sequence, the mask identification sequence is associated with the authentication credential of the preset target terminal, and a key distribution link corresponding to the authentication credential is constructed; Based on the key distribution link, injecting the multi-layer encrypted data block into a preset quantum cache module, monitoring the interaction state of the data flow in the quantum cache module, determining the link optimization direction corresponding to the key distribution link based on the interaction state, extracting the optimized encryption point in the link optimization direction, and calculating the encryption equilibrium value corresponding to the key distribution link based on the optimized encryption point; Based on the encryption balance value, a security transmission indicator corresponding to the key distribution link is generated, the security fluctuation trend corresponding to the security transmission indicator is analyzed, and the fluctuating transmission factor in the security fluctuation trend is identified; based on the fluctuating transmission factor, an encryption transmission report corresponding to the 5G message data source is generated.

2. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The detecting of the associated topological nodes of the core encryption element on the transmission path includes: Parsing key feature identifiers in the core encryption elements; Draw a preliminary topological sketch corresponding to the key feature identifier on the transmission path; Extracting potential topological points in the preliminary topological sketch; Performing a deep scan on the potential topological points to obtain topological correlation parameters; Based on the topology association parameters, an associated topology node on the transmission path is determined.

3. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The performing multi-dimensional threat detection on the associated topological node to obtain a multi-dimensional threat vector includes: Collect basic operation data corresponding to the associated topological nodes; Based on the basic operation data, construct an initial state portrait corresponding to the associated topological node; Analyzing the image traffic distribution in the initial state image; Marking anomaly detection segments in the profile traffic distribution; Multi-dimensional threat detection is performed on the anomaly detection segment to obtain a multi-dimensional threat vector.

4. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes: The real-time risk entropy value corresponding to the abnormal behavior pattern is calculated using the following formula: in, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the number corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, Indicates The probability of occurrence of abnormal behavior patterns, Indicates The duration of abnormal behavior patterns, Indicates the time range from the start of abnormal behavior to the current moment, Indicates abnormal behavior patterns over time The severity score, Indicates abnormal behavior patterns over time The weight coefficient of .

5. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: Based on the real-time risk entropy value, adaptively grading the 5G message data source to obtain a multi-layer encrypted data block includes: Analyze the distribution law corresponding to the real-time risk entropy value; Based on the distribution law, determining the fluctuation range corresponding to the real-time risk entropy value; Based on the fluctuation range, preliminarily grouping the 5G message data source to obtain a grouped data source; Evaluating the importance coefficient corresponding to the grouped data source; Based on the importance coefficient, the grouped data sources are sorted to obtain a sorting result; Adaptively perform security grading on the sorting results to obtain multi-layer encrypted data blocks.

6. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The performing dynamic mask processing on the multi-layer encrypted data block to obtain a mask identification sequence includes: Analyzing the encryption strength corresponding to the data in the multi-layer encrypted data block; Based on the encryption strength, generating a mask rule set corresponding to the multi-layer encrypted data block; Based on the mask rule set, masking is performed on the multi-layer encrypted data blocks to obtain a masked data block set; Extracting mask identification points from the mask data block set; Based on the mask identification points, a mask identification sequence corresponding to the multi-layer encrypted data block is generated.

7. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The determining, based on the interaction state, a link optimization direction corresponding to the key distribution link includes: Extracting core status indicators in the interaction status; Based on the core status indicator, identifying a status influencing point in the key distribution link; Based on the state influencing point, querying the link structure corresponding to the key distribution link; Analyze the topology optimization suggestions corresponding to the link structure; Based on the topology optimization suggestion, generating an optimization strategy set corresponding to the key distribution link; Based on the optimization strategy set, a link optimization direction corresponding to the key distribution link is determined.

8. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The calculating, based on the optimized encryption point, an encryption balance value corresponding to the key distribution link comprises: The encryption balance value corresponding to the key distribution link is calculated using the following formula: in, represents the encryption balance value corresponding to the key distribution link, Indicates the total number of optimized encryptions, represents the quantity index corresponding to the optimized encryption, Indicates The security score corresponding to the optimized encryption point, Indicates The transmission efficiency corresponding to the optimized encryption point is Indicates The transmission delay corresponding to the optimized encryption point is Indicates The computational cost of the optimized encryption point is Indicates the maximum computational cost value among all optimized encryption points.

9. A secure encrypted transmission method for 5G messages as claimed in claim 1, characterized in that: The step of generating a security transmission indicator corresponding to the key distribution link based on the encryption balance value includes: Analyzing the balanced distribution points corresponding to the encrypted balanced values; Based on the balanced distribution points, querying uniformly weak areas in the key distribution link; Performing high-risk detection on the uniform weak area to obtain a high-risk detection result; Extracting key risk items from the high-risk detection results; Based on the key risk items, a security transmission indicator corresponding to the key distribution link is generated.

10. A secure encryption transmission system for 5G messages, characterized in that: The system comprises: A node detection module is used to obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; A risk entropy value calculation module is used to perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify an abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate a real-time risk entropy value corresponding to the abnormal behavior pattern; A link construction module, configured to perform adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain a multi-layer encrypted data block, perform dynamic mask processing on the multi-layer encrypted data block to obtain a mask identification sequence, associate the mask identification sequence with the authentication credential of the preset target terminal, and construct a key distribution link corresponding to the authentication credential; A balance value calculation module, used to inject the multi-layer encrypted data block into a preset quantum cache module based on the key distribution link, monitor the interaction state of the data flow in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption point in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption point; A report generation module is used to generate a security transmission indicator corresponding to the key distribution link based on the encryption balance value, analyze the security fluctuation trend corresponding to the security transmission indicator, identify the fluctuating transmission factor in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuating transmission factor.

Citation Information

Patent Citations

  • Online data secure transmission method and system based on 5G message, and electronic equipment

    CN116261139A

  • Fire-fighting equipment detection and evaluation system and method based on video processing and deep learning

    CN118095867A

  • Distributed storage method and system for data security

    CN119720256A

  • Risk identification

    WO2025077903A1

Cited By

  • Industrial end node data tamper-proofing method and system based on Internet of Things

    CN121125353A