A Secure Encryption Transmission Method and System for 5G Messages

By obtaining the security requirements parameters of 5G message data sources, analyzing and extracting dynamic encryption rules, performing multi-dimensional threat detection and adaptive security hierarchy, building a key distribution link, and using the quantum cache module to monitor the interactive status of data flow, solving the risks of data leakage and tampering in 5G message transmission, and achieving efficient and flexible secure encrypted transmission.

CN120111477BActive Publication Date: 2025-07-08深圳市壹通道科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510578380.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-08
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

There is a risk of data leakage and tampering in 5G message transmission. Traditional encryption methods are difficult to resist complex network attacks and lack flexibility, which cannot meet the high real-time requirements of different application environments.

Method used

By obtaining the security requirements parameters of 5G message data sources, analyzing and extracting dynamic encryption rules, performing multi-dimensional threat detection and adaptive security hierarchy, building a key distribution link, using the quantum cache module to monitor the interactive status of the data flow, and generating an encrypted transmission report.

Benefits of technology

It enhances the flexibility and adaptability of encryption policies, effectively resists network attacks, ensures data security and integrity, meets the dual needs of high real-time and high security, and improves encryption efficiency and data processing reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111477B_ABST
    Figure CN120111477B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication technologies, and discloses a secure encrypted transmission method and system for 5G messages, including: first, obtaining a 5G information data source and parsing security requirement parameters, querying a corresponding dynamic encryption rule set, extracting core encryption elements and detecting associated topology nodes on their transmission paths, performing multi-dimensional threat detection on the nodes, identifying abnormal behavior patterns and calculating real-time risk entropy values, accordingly performing adaptive security grading on the data source, constructing a key distribution link through operations such as dynamic masking processing, then injecting multi-layer encrypted data blocks into a quantum cache module, determining the link optimization direction according to the interaction state, calculating an encryption balance value, etc., and finally generating an encrypted transmission report. The present invention can ensure the security and integrity of 5G messages during the transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secure encryption transmission method and system for 5G messages, belonging to the field of communication technologies. Background Art

[0002] As one of the important applications in the 5G era, 5G messages integrate various rich media forms such as text, pictures, audio, and video, greatly expanding the dimension and efficiency of information transmission, and are widely used in many fields such as social, financial, government affairs, and medical.

[0003] However, with the continuous expansion of the application scenarios of 5G messages, on the one hand, the data transmitted by 5G messages contains a large amount of sensitive information, such as personal privacy, business secrets, financial transaction data, etc. Traditional transmission encryption methods are difficult to resist increasingly complex network attack means, such as malware intrusion, man-in-the-middle attack, etc., which are extremely likely to cause data leakage and tampering, seriously threatening user information security; on the other hand, under different application environments and business requirements, the transmission encryption of 5G messages lacks flexible adaptability. For example, in some scenarios of transmitting medical emergency information with extremely high real-time requirements, the existing encryption algorithms may take too long for the encryption and decryption processes, affecting the timely transmission of information and unable to meet the urgent needs of actual business. Therefore, there is an urgent need for a secure encryption transmission method for 5G messages to ensure the security and integrity of 5G messages during the transmission process. Summary of the Invention

[0004] The present invention provides a secure encryption transmission method and system for 5G messages, and its main purpose is to ensure the security and integrity of 5G messages during the transmission process.

[0005] To achieve the above object, a secure encryption transmission method for 5G messages provided by the present invention includes:

[0006] Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topology nodes of the core encryption elements on the transmission path;

[0007] Perform multi-dimensional threat detection on the associated topology nodes to obtain a multi-dimensional threat vector, identify the abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate the real-time risk entropy value corresponding to the abnormal behavior pattern;

[0008] Based on the real-time risk entropy value, adaptively perform security grading on the 5G message data source to obtain multi-layer encrypted data blocks, perform dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associate the mask identification sequence with the authentication credentials of a preset target terminal, and construct a key distribution link corresponding to the authentication credentials;

[0009] Based on the key distribution link, inject the multi-layer encrypted data blocks into a preset quantum cache module, monitor the interaction state of the data flow in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption points in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption points;

[0010] Based on the encryption balance value, generate a security transmission index corresponding to the key distribution link, analyze the security fluctuation trend corresponding to the security transmission index, identify the fluctuation transmission factors in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuation transmission factors.

[0011] Optionally, the detecting the associated topology nodes of the core encryption elements on the transmission path includes:

[0012] Analyze the key feature identifiers in the core encryption elements;

[0013] Draw a preliminary topology sketch corresponding to the key feature identifiers on the transmission path;

[0014] Extract the potential topology points in the preliminary topology sketch;

[0015] Perform a deep scan on the potential topology points to obtain topology association parameters;

[0016] Based on the topology association parameters, determine the associated topology nodes on the transmission path.

[0017] Optionally, the performing multi-dimensional threat detection on the associated topology nodes to obtain a multi-dimensional threat vector includes:

[0018] Collect the basic operation data corresponding to the associated topology nodes;

[0019] Based on the basic operation data, construct an initial state portrait corresponding to the associated topology nodes;

[0020] Analyze the portrait traffic distribution in the initial state portrait;

[0021] Mark the abnormal detection segments in the portrait traffic distribution;

[0022] Perform multi-dimensional threat detection on the abnormal detection segments to obtain a multi-dimensional threat vector.

[0023] Optionally, calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes:

[0024] Calculating the real-time risk entropy value corresponding to the abnormal behavior pattern by using the following formula: Wherein, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the quantity corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, represents the th occurrence probability corresponding to the abnormal behavior pattern, represents the th duration corresponding to the abnormal behavior pattern, represents the time range from the start of the abnormal behavior to the current moment, represents the th severity score of the abnormal behavior pattern at time , represents the th weight coefficient of the abnormal behavior pattern at time .

[0025] Optionally, adaptively security grading the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, including:

[0026] Analyzing the distribution law corresponding to the real-time risk entropy value;

[0027] Based on the distribution law, determining the fluctuation interval corresponding to the real-time risk entropy value;

[0028] Based on the fluctuation interval, initially grouping the 5G message data source to obtain grouped data sources;

[0029] Evaluating the importance coefficient corresponding to the grouped data sources;

[0030] Based on the importance coefficient, sorting the grouped data sources to obtain a sorting result;

[0031] Performing adaptive security grading on the sorting result to obtain multi-layer encrypted data blocks.

[0032] Optionally, performing dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, including:

[0033] Analyzing the encryption strength corresponding to the data in the multi-layer encrypted data blocks;

[0034] Generate a mask rule set corresponding to the multi-layer encrypted data block based on the encryption strength;

[0035] Perform mask processing on the multi-layer encrypted data block based on the mask rule set to obtain a set of masked data blocks;

[0036] Extract the mask identification points from the set of masked data blocks;

[0037] Generate a mask identification sequence corresponding to the multi-layer encrypted data block based on the mask identification points.

[0038] Optionally, the determining the link optimization direction corresponding to the key distribution link based on the interaction state includes:

[0039] Extract the core state metrics from the interaction state;

[0040] Identify the state impact points in the key distribution link based on the core state metrics;

[0041] Query the link structure corresponding to the key distribution link based on the state impact points;

[0042] Analyze the topology optimization suggestions corresponding to the link structure;

[0043] Generate an optimization strategy set corresponding to the key distribution link based on the topology optimization suggestions;

[0044] Determine the link optimization direction corresponding to the key distribution link based on the optimization strategy set.

[0045] Optionally, the calculating the encryption balance value corresponding to the key distribution link based on the optimized encryption points includes:

[0046] Calculate the encryption balance value corresponding to the key distribution link using the following formula: Where, represents the encryption balance value corresponding to the key distribution link, represents the total number of the optimized encryption, represents the quantity index of the optimized encryption, represents the th security score corresponding to the optimized encryption point, represents the th transmission efficiency corresponding to the optimized encryption point, represents the th transmission delay corresponding to the optimized encryption point, represents the th computational overhead value corresponding to the optimized encryption point, represents the maximum computational overhead value among all optimized encryption points.

[0047] Optionally, generating a security transmission metric corresponding to the key distribution link based on the encrypted equilibrium value includes:

[0048] Analyzing equilibrium distribution points corresponding to the encrypted equilibrium value;

[0049] Based on the equilibrium distribution points, querying uniform weak areas in the key distribution link;

[0050] Performing high-risk detection on the uniform weak areas to obtain a high-risk detection result;

[0051] Extracting key risk items from the high-risk detection result;

[0052] Generating a security transmission metric corresponding to the key distribution link based on the key risk items.

[0053] To solve the above problems, the present invention further provides a secure encryption transmission system for 5G messages, and the system includes:

[0054] A node detection module, configured to obtain a 5G message data source, parse security requirement parameters in the 5G message data source, query a dynamic encryption rule set corresponding to the security requirement parameters, extract core encryption elements in the dynamic encryption rule set, and detect associated topological nodes of the core encryption elements on a transmission path;

[0055] A risk entropy value calculation module, configured to perform multi-dimensional threat detection on the associated topological nodes to obtain multi-dimensional threat vectors, identify abnormal behavior patterns corresponding to the multi-dimensional threat vectors, and calculate real-time risk entropy values corresponding to the abnormal behavior patterns;

[0056] A link construction module, configured to perform adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, perform dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associate the mask identification sequence with an authentication credential of a preset target terminal, and construct a key distribution link corresponding to the authentication credential;

[0057] An equilibrium value calculation module, configured to inject the multi-layer encrypted data blocks into a preset quantum cache module based on the key distribution link, monitor an interaction state of data streams in the quantum cache module, determine a link optimization direction corresponding to the key distribution link based on the interaction state, extract optimized encryption points in the link optimization direction, and calculate an encrypted equilibrium value corresponding to the key distribution link based on the optimized encryption points;

[0058] A report generation module, which is used to generate a security transmission metric corresponding to the key distribution link based on the encrypted equilibrium value, analyze the security fluctuation trend corresponding to the security transmission metric, identify the fluctuation transmission factors in the security fluctuation trend, and generate an encrypted transmission report corresponding to the 5G message data source based on the fluctuation transmission factors.

[0059] Compared with the problems described in the background art, the present invention enhances the flexibility and adaptability of the encryption policy by obtaining the 5G message data source and parsing the security requirement parameters in the 5G message data source, ensuring targeted protection of data during transmission. At the same time, it helps to optimize resource allocation, improve encryption efficiency, and meet the dual requirements of high real-time and high security. The present invention obtains multi-dimensional threat vectors by performing multi-dimensional threat detection on the associated topology nodes, and can comprehensively understand the security risks faced by nodes from multiple dimensions. Potential threats such as malware intrusion and abnormal traffic attacks can be accurately located by analyzing factors such as network traffic, node status, and surrounding environment, effectively improving the security and stability of key nodes in the 5G message transmission path. Further, the present invention adaptively classifies the security level of the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, which can accurately adapt to the protection requirements of data sources with different risk levels, effectively resist serious threats, and protect key data; a relatively lightweight encryption is used for low risk entropy values to improve processing efficiency. Further, the present invention injects the multi-layer encrypted data blocks into a preset quantum cache module based on the key distribution link and monitors the interaction status of the data stream in the preset quantum cache module, enabling real-time monitoring of data storage and invocation. It can not only timely detect potential security threats and ensure data integrity, but also optimize the data processing process, improving the reliability and efficiency of 5G message data processing. Finally, the present invention generates a security transmission metric corresponding to the key distribution link based on the encrypted equilibrium value, which can convert the link encryption state into an intuitive quantitative value, facilitating the evaluation of the overall security transmission level of the link, accurately positioning advantages and disadvantages, and providing a strong reference for optimizing the link security policy, helping to improve data transmission security and stability, and ensuring the reliable operation of 5G message communication. Therefore, a security encryption transmission method and system for 5G messages provided by an embodiment of the present invention can ensure the security and integrity of 5G messages during transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 It is a schematic flowchart of a security encryption transmission method for 5G messages provided by an embodiment of the present invention;

[0061] Figure 2 It is a schematic module diagram of a security encryption transmission system for 5G messages provided by an embodiment of the present invention.

[0062] The implementation, functional features, and advantages of the present invention will be further described in conjunction with embodiments with reference to the accompanying drawings. Specific Embodiments

[0063] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0064] The embodiments of the present application provide a secure encrypted transmission method for 5G messages. The execution subject of the secure encrypted transmission method for 5G messages includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided in the embodiments of the present application. In other words, the secure encrypted transmission method for 5G messages can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc.

[0065] Embodiment 1:

[0066] Refer to Figure 1 As shown, it is a flowchart of a secure encrypted transmission method for 5G messages provided by an embodiment of the present invention. In this embodiment, the secure encrypted transmission method for 5G messages includes:

[0067] S1. Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topology nodes of the core encryption elements on the transmission path.

[0068] By obtaining the 5G message data source and parsing the security requirement parameters in the 5G message data source, the present invention enhances the flexibility and adaptability of the encryption policy, ensures that the data is protected specifically during the transmission process. At the same time, it helps to optimize resource allocation, improve the encryption efficiency, and meet the dual requirements of high real-time and high security.

[0069] Among them, the 5G message data source refers to the source that generates the original data of 5G messages, which covers the information collection containing various media forms such as text, pictures, audio, and video sent from various application programs, devices, or systems. For example, messages containing text and pictures sent by users in social applications, account transaction information (which may contain text and charts) pushed by financial institutions to customers, notices issued by government departments (which may have text, audio explanations, etc.), and patient medical records transmitted by medical institutions (which may contain text, images, etc.). These all belong to the category of 5G message data sources; the security requirement parameters refer to a series of indicators used to describe the specific requirements for the secure transmission of 5G messages, which may include the sensitivity level of the data. For example, personal privacy information belongs to a high-sensitivity level, and ordinary notification information belongs to a low-sensitivity level; the real-time requirement for transmission, such as the transmission of medical emergency information requires extremely high real-time performance, while the real-time requirement for some non-urgent commercial promotion messages is relatively low; and specific requirements for data integrity and confidentiality. For example, financial transaction data must ensure integrity to prevent being tampered with, and at the same time, it has extremely high confidentiality requirements and cannot be illegally obtained. Optionally, parsing the security requirement parameters in the 5G message data source can be implemented through a decision tree algorithm. For example, various features of the 5G message are used as input nodes, such as the message source, message type, transmission frequency, etc. By training the decision tree, it can output the corresponding security requirement parameters according to these features.

[0070] Furthermore, by querying the dynamic encryption rule set corresponding to the security requirement parameters and extracting the core encryption elements in the dynamic encryption rule set, the present invention can effectively cope with complex network attacks, ensure the confidentiality and integrity of data during transmission, prevent the leakage and tampering of sensitive information. At the same time, it can greatly improve the encryption efficiency, meet business scenarios with different requirements for real-time performance and security such as medical and financial fields, and enhance the security and adaptability of 5G message transmission.

[0071] Among them, the dynamic encryption rule set refers to a set of encryption rules dynamically generated according to different security requirement parameters. It is not fixed, but can adapt to the diverse application scenarios of 5G messages and the real-time changing security situation. For example, when 5G messages involve financial transactions, the rule set focuses on high-strength data encryption and integrity verification, stipulating the use of specific encryption algorithms to encrypt key information such as transaction amounts and account numbers, and setting up strict integrity verification mechanisms; while in the general social message scenario, the rule set pays more attention to encryption efficiency and adopts relatively lightweight encryption methods on the premise of ensuring a certain level of security. The core encryption elements refer to the most crucial components in the dynamic encryption rule set, which determine the core characteristics and effects of encryption. It includes the selection of encryption algorithms. Different encryption algorithms have their own characteristics in terms of security, computational complexity, and encryption speed. For example, the AES algorithm is often used in scenarios with high requirements for data confidentiality, while the RSA algorithm performs well in key exchange and digital signature. Key management methods, such as the rules for key generation, distribution, update, and storage. Secure and efficient key management is crucial for ensuring the security of the encryption system. And data integrity verification methods, such as generating message digests through hash functions to verify whether the data has been tampered with during transmission. Optionally, querying the dynamic encryption rule set corresponding to the security requirement parameters can be achieved through rule engine matching methods, such as the Drools rule engine, etc. Taking the security requirement parameters as input facts, a series of rules for matching the dynamic encryption rule set according to different security requirement parameters are predefined in the rule engine. Extracting the core encryption elements in the dynamic encryption rule set can be achieved through element extraction tools, such as tools like ANTLR, etc. The generated analyzer can accurately extract elements such as encryption algorithms and key lengths.

[0072] Furthermore, by detecting the associated topological nodes of the core encryption elements on the transmission path, the present invention helps to discover potential security weak points in advance, focus on protecting the nodes vulnerable to attacks, and avoid the failure of the encrypted transmission process due to the damage of key nodes, thus effectively ensuring the reliability and security of 5G message encrypted transmission.

[0073] Among them, the transmission path refers to the physical and logical path of 5G messages starting from the data source, passing through network devices such as base stations, optical fibers, routers, and switches, following specific network routing rules, dynamically adjusting the links passed through, and finally reaching the target terminal. The associated topological nodes refer to the network nodes that are finally determined based on topological association parameters and have an actual and close association with the core encryption elements on the transmission path. By analyzing the topological association parameters, the nodes that are truly relevant to the core encryption elements are screened out, and these nodes constitute the actual network architecture of the core encryption elements on the transmission path. For example, after analyzing the topological association parameters of multiple potential topological points, certain specific base stations, servers, etc. are determined as associated topological nodes.

[0074] As an embodiment of the present invention, detecting the associated topological nodes of the core encryption element on the transmission path includes: parsing the key feature identifiers in the core encryption element; drawing a preliminary topological sketch corresponding to the key feature identifiers on the transmission path; extracting the potential topological points in the preliminary topological sketch; performing a deep scan on the potential topological points to obtain topological association parameters; and determining the associated topological nodes on the transmission path based on the topological association parameters.

[0075] Among them, the key feature identifier refers to the specific information in the core encryption element that can characterize its unique attributes and association relationships on the transmission path. These identifiers can include the encryption algorithm type, key length, encrypted data block size, etc. For example, for a specific encryption algorithm such as AES-256, its algorithm name and key length of 256 bits constitute a key feature identifier; the preliminary topological sketch refers to a schematic network topological structure drawn by mapping the key feature identifiers on the transmission path. The sketch is not an exact network topology diagram, but a potential relevant area quickly located and outlined based on the key feature identifiers; the potential topological point refers to the position of the network node identified in the preliminary topological sketch that has a close association with the core encryption element. It can be the location of network devices such as routers, switches, base stations, etc., and is the key object for subsequent deep scanning and analysis. For example, if it is found in the sketch that multiple nodes in a certain area show characteristics related to a specific encryption algorithm, the positions of these nodes are potential topological points; the topological association parameter refers to a series of parameters obtained by performing a deep scan on the potential topological points and used to describe the specific association relationship between the potential topological points and the core encryption element. These parameters include the network address of the node, device type, transmission rate, encryption support ability, connection status with adjacent nodes, etc.

[0076] Further, the key feature identification in the core encryption elements can be achieved through a rule-based matching method. For example, by matching the data of the core encryption elements with the rules, when the data conforms to a certain rule, the corresponding key feature identification can be recognized. The preliminary topological sketch of the key feature identification corresponding to the transmission path can be achieved through a heuristic search method. For example, starting from the node where the known key feature identification is located, adjacent nodes are gradually searched through heuristic rules to construct a preliminary topological sketch. The potential topological points in the preliminary topological sketch can be extracted through a clustering analysis method. For example, the nodes in the preliminary topological sketch are clustered according to their features, and the central node or representative node in each cluster can be used as a potential topological point. The in-depth scanning of the potential topological points can be achieved through in-depth scanning tools. For example, tools such as Nessus and Masscan. The associated topological nodes on the transmission path can be determined through a multi-factor comprehensive evaluation method. For example, by comprehensively considering multiple factors in the topological association parameters, such as the encryption ability, bandwidth, and security status of the nodes, the potential topological points are evaluated to determine the associated topological nodes.

[0077] S2. Perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify the abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate the real-time risk entropy value corresponding to the abnormal behavior pattern.

[0078] Through the multi-dimensional threat detection of the associated topological nodes of the present invention, a multi-dimensional threat vector is obtained, which can comprehensively insight into the security risks faced by the nodes from multiple dimensions. By analyzing multiple factors such as network traffic, node status, and surrounding environment, potential threats such as malware intrusion and abnormal traffic attacks can be accurately located, effectively improving the security and stability of the key nodes in the 5G message transmission path.

[0079] Among them, the multi-dimensional threat vector refers to a quantitative representation that comprehensively reflects the threat situation faced by the associated topological nodes in multiple dimensions. It usually consists of threat feature values in multiple dimensions, and these dimensions can include threat types (such as malware attacks, DDoS attacks, port scans, etc.), threat severity levels (from low to high), the likelihood of threat occurrence (probability assessment based on historical data and current abnormal situations), the types of affected resources (such as CPU, memory, network bandwidth, etc.), and the propagation range of the threat (within the node, local network, or a larger range).

[0080] As an embodiment of the present invention, the multi-dimensional threat detection of the associated topology node to obtain a multi-dimensional threat vector includes: collecting the basic operation data corresponding to the associated topology node; constructing an initial state portrait corresponding to the associated topology node based on the basic operation data; analyzing the portrait traffic distribution in the initial state portrait; marking the abnormal detection segments in the portrait traffic distribution; and performing multi-dimensional threat detection on the abnormal detection segments to obtain a multi-dimensional threat vector.

[0081] Among them, the basic operation data refers to a series of key information generated by the associated topology node in the normal operation state. These data cover the hardware performance indicators of the node, such as CPU usage rate, memory occupancy, disk I / O rate, etc., reflecting the usage of the computing and storage resources of the node; network-related data, including the transmission rate of the network interface, the number of received and sent data packets, packet loss rate, etc., reflecting the performance of the node in network communication; and system operation state information, such as the number of processes, service operation state, etc.; the initial state portrait refers to an intuitive and comprehensive node state description model constructed based on the basic operation data of the associated topology node. For example, a curve showing the change of CPU usage rate over time, the real-time value of memory occupancy, and the fluctuation trend of network traffic are presented through charts; the portrait traffic distribution refers to the detailed presentation of the network traffic part in the initial state portrait, which describes the traffic distribution of the associated topology node in different time periods, different network protocols, and different communication directions. For example, the size of TCP and UDP traffic received and sent by the node in different hourly periods within a day is presented through a bar chart or a line chart; or the traffic proportion occupied by different application layer protocols (such as HTTP, FTP, SMTP, etc.) is presented in the form of a pie chart; the abnormal detection segment refers to the time period or traffic interval in the portrait traffic distribution that is identified as having a significant difference from the normal traffic pattern. For example, the network traffic was relatively stable at a certain time period, and suddenly a peak several times the normal traffic appeared, or a large amount of traffic was generated by a protocol that is rarely used at ordinary times within a certain time period. The traffic time period or interval corresponding to these abnormal situations is the abnormal detection segment.

[0082] Furthermore, the collection of basic operation data corresponding to the associated topological nodes can be achieved through data collection tools, such as Zabbix, Syslog-ng and other tools; the construction of the initial state portrait corresponding to the associated topological nodes can be achieved through data fusion and visualization methods, such as fusing the collected basic operation data of different types, and then displaying it as an intuitive portrait through visualization technology; the analysis of the portrait traffic distribution in the initial state portrait can be achieved through a protocol analysis method, such as classifying and counting the traffic data according to different network protocols, analyzing the proportion of each protocol in the total traffic and its changes over time; the marking of the abnormal detection segment in the portrait traffic distribution can be achieved through a threshold-based detection method, such as setting a reasonable traffic threshold based on historical traffic data and business needs. When the traffic data exceeds or falls below these thresholds, the corresponding time period is marked as an abnormal detection segment; the multi-dimensional threat detection of the abnormal detection segment can be achieved through threat detection tools, such as SIEM, VirusTotal and other tools.

[0083] By identifying the abnormal behavior patterns corresponding to the multi-dimensional threat vectors, the present invention can quickly locate abnormal behaviors such as malware intrusion and DDoS attacks, and then provide early warnings, thereby buying valuable time for the timely deployment of targeted protection strategies, and effectively ensuring the security and stability of 5G message transmission.

[0084] Among them, the abnormal behavior pattern refers to a series of behavior characteristics or behavior sequences that are significantly different from the behavior performance under normal operating conditions in a system or network environment, which may include traffic anomalies, such as sudden large-scale data transmission, abnormal traffic peaks, or continuous low-traffic but high-frequency connection attempts; resource usage anomalies, such as excessive occupation of resources such as CPU and memory, or abnormal resource allocation patterns; user behavior anomalies, such as frequent logins during non-working hours, abnormal operation sequences, or abuse of permissions; and data access anomalies, such as abnormal reading and writing operations on sensitive data, or unauthorized data access attempts, etc. Optionally, the identification of the abnormal behavior pattern corresponding to the multidimensional threat vector can be achieved through a clustering analysis method, such as: treating the multidimensional threat vector as a data point, using a clustering algorithm to cluster similar vectors together, and each cluster represents a potential behavior pattern, where a cluster that is significantly different from a normal behavior pattern cluster can be identified as an abnormal behavior pattern.

[0085] Furthermore, by calculating the real-time risk entropy value corresponding to the abnormal behavior pattern, the present invention can intuitively compare the risk levels of different abnormal behavior patterns and clearly determine the severity of the threat, which provides an accurate basis for security decision-making, helps to prioritize high-risk anomalies, and reasonably allocate security protection resources.

[0086] Among them, the real-time risk entropy value refers to a quantitative index of the risk level of an abnormal behavior pattern within a specific time range, which comprehensively considers various factors, such as the occurrence probability, duration, severity score, and weight coefficient of the abnormal behavior pattern. For example, in the network security scenario, the higher the real-time risk entropy value, the greater the threat posed by the current abnormal behavior pattern to network security.

[0087] As an embodiment of the present invention, calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes:

[0088] Calculating the real-time risk entropy value corresponding to the abnormal behavior pattern by using the following formula: Wherein, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the quantity corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, represents the th occurrence probability corresponding to the abnormal behavior pattern, represents the th duration corresponding to the abnormal behavior pattern, represents the time range from the start of the abnormal behavior to the current moment, represents the th severity score of the abnormal behavior pattern at time , represents the th weight coefficient of the abnormal behavior pattern at time .

[0089] Specifically, the occurrence probability refers to the likelihood of the th abnormal behavior pattern occurring, which is a value between 0 and 1 obtained based on historical data, monitoring data, or relevant model predictions. 0 indicates that the abnormal behavior pattern hardly occurs, and 1 indicates that it will definitely occur; the duration refers to the length of time that the th abnormal behavior pattern has lasted from the start to the current moment, which reflects the time span during which the abnormal behavior pattern affects the system or network; the severity score refers to the Quantitative assessment of the degree of harm caused by a certain abnormal behavior pattern to the system or network at a certain time, which is usually scored by security experts according to experience, relevant standards or preset rules. The higher the score, the higher the severity of the abnormal behavior pattern; the weight coefficient refers to the coefficient of the importance or influence degree of the \(i\)th abnormal behavior pattern relative to other abnormal behavior patterns at a certain time. For example, in some systems with extremely high requirements for data confidentiality, the weight coefficient of the abnormal behavior pattern involving data leakage will be set relatively high, while in scenarios focusing on system availability, the weight coefficient of the abnormal behavior pattern affecting the normal operation of the system will be larger.

[0090] S3. Based on the real-time risk entropy value, perform adaptive security grading on the 5G message data source to obtain multi-layer encrypted data blocks, perform dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associate the mask identification sequence with the authentication credentials of a preset target terminal, and construct a key distribution link corresponding to the authentication credentials.

[0091] Based on the real-time risk entropy value, the present invention performs adaptive security grading on the 5G message data source to obtain multi-layer encrypted data blocks, which can accurately adapt to the protection requirements of data sources with different risk levels, effectively resist serious threats, and protect key data; for low-risk entropy values, relatively lightweight encryption is used to improve processing efficiency.

[0092] Among them, the multi-layer encrypted data block refers to the encrypted data unit formed by using different encryption methods with different intensities and algorithms for data sources with different security levels after performing adaptive security grading on the 5G message data source according to the sorting result.

[0093] As an embodiment of the present invention, the performing adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks includes: analyzing the distribution law corresponding to the real-time risk entropy value; determining the fluctuation interval corresponding to the real-time risk entropy value based on the distribution law; performing preliminary grouping on the 5G message data source based on the fluctuation interval to obtain grouped data sources; evaluating the importance coefficient corresponding to the grouped data sources; performing sorting processing on the grouped data sources based on the importance coefficient to obtain a sorting result; and performing adaptive security grading on the sorting result to obtain multi-layer encrypted data blocks.

[0094] Among them, the distribution law refers to the variation characteristics and trends of real-time risk entropy values within a certain time or space range. For example, whether they are concentrated in certain numerical ranges, evenly distributed in a larger numerical interval, or show periodic variations, etc.; the fluctuation range refers to the variation range of real-time risk entropy values determined based on the distribution law, that is, the interval formed by the maximum and minimum values of real-time risk entropy values; the grouped data sources refer to the set of data sources in different groups formed after initially dividing the 5G message data sources according to the fluctuation range of real-time risk entropy values; the importance coefficient refers to the quantitative index obtained by evaluating the grouped data sources from dimensions such as business and data value, and is used to measure the importance degree of each data source in the entire 5G message system; the sorting result refers to the order list obtained by arranging the grouped data sources from high to low or from low to high according to the importance coefficient. Through sorting, the importance degree differences of different data sources can be clearly distinguished, providing a direct basis for subsequent security grading.

[0095] Furthermore, analyzing the distribution law corresponding to the real-time risk entropy value can be achieved through statistical analysis methods. For example: collect the real-time risk entropy values per hour within a week, divide the entropy value range into several small intervals, and count the occurrence times of entropy values in each interval to analyze its distribution law; determining the fluctuation range corresponding to the real-time risk entropy value can be achieved through a moving average algorithm. For example: calculate the moving average value and moving standard deviation of the real-time risk entropy value, and determine the fluctuation range according to a certain multiple relationship (such as 3 times the standard deviation); initially grouping the 5G message data sources can be achieved through the interval division method. For example: according to the determined fluctuation range of the real-time risk entropy value, divide it into several sub-intervals, then match the real-time risk entropy value of each data source with these sub-intervals, and classify the data source into the corresponding interval group; evaluating the importance coefficient corresponding to the grouped data sources can be achieved through a coefficient evaluation tool. For example: construct a hierarchical structure model in Yaahp, input the judgment matrix formed by expert scoring, and automatically calculate the importance coefficients of each grouped data source; sorting the grouped data sources can be achieved through a comparison-based sorting method. For example: use the bubble sort algorithm to compare and exchange the importance coefficients of a group of grouped data sources until all data sources are arranged in the order of importance coefficients; adaptively grading the security of the sorting result can be achieved through the threshold division method. For example: according to business requirements and security policies, set different security level thresholds, compare the sorted data sources with the thresholds according to their importance coefficients, and classify them into different security levels.

[0096] The present invention performs dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, which can change over time or under specific conditions, effectively resisting continuous targeted attacks. Moreover, the mask identification sequence facilitates the tracking and management of mask application, ensuring the confidentiality and integrity of data in different scenarios and enhancing the overall security of 5G message data.

[0097] Among them, the mask identification sequence refers to an ordered sequence generated based on mask identification points, which comprehensively records the detailed information of the masking process for multi-layer encrypted data blocks. For example, the mask identification sequence may include information such as the mask start position, mask length, and encoding of mask characters or values for each data block.

[0098] As an embodiment of the present invention, performing dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence includes: analyzing the encryption strength corresponding to the data in the multi-layer encrypted data blocks; generating a mask rule set corresponding to the multi-layer encrypted data blocks based on the encryption strength; performing masking processing on the multi-layer encrypted data blocks based on the mask rule set to obtain a set of masked data blocks; extracting mask identification points from the set of masked data blocks; and generating a mask identification sequence corresponding to the multi-layer encrypted data blocks based on the mask identification points.

[0099] Among them, the encryption strength is an index that measures the degree of data encryption in multi-layer encrypted data blocks, which comprehensively considers factors such as the complexity of the encryption algorithm, key length, and number of encryption rounds. For example, a data block encrypted using the AES-256 algorithm has a relatively high encryption strength because the 256-bit key length and the complex encryption mechanism of the AES algorithm can effectively resist various cracking methods. The mask rule set refers to a set of rules for masking processing generated according to the encryption strength of multi-layer encrypted data blocks, and these rules specify in detail how to perform masking operations on data blocks, including aspects such as mask position selection, mask character or value type, and mask length. The set of masked data blocks refers to a group of masked data blocks obtained after performing masking processing on multi-layer encrypted data blocks according to the mask rule set. For example, a multi-layer encrypted data block originally contains sensitive information of a user, and after masking processing, some characters of the sensitive information are replaced with mask characters, thus forming a masked data block. The mask identification point refers to a key information point in the set of masked data blocks used to identify the position and characteristics of the masking operation, and these points record the position where the mask specifically acts and the relevant attributes of the mask during the masking process. For example, in a certain masked data block, the mask identification point may record information such as the position of the start byte of the mask, the type or value of the mask character.

[0100] Further, the encryption strength corresponding to the data in the multi-layer encrypted data block can be analyzed through a prediction algorithm based on machine learning. For example, by training a random forest model, inputting a large number of data blocks with different encryption algorithms and key lengths and their corresponding known encryption strength levels, after training, inputting the features of the data block to be analyzed to predict the encryption strength; the generation of the mask rule set corresponding to the multi-layer encrypted data block can be achieved through a hierarchical strategy method. For example, according to the analyzed encryption strength, it is divided into different levels, such as high, medium, and low levels, and different mask rules are formulated for each level; the masking process of the multi-layer encrypted data block can be achieved through a loop traversal algorithm. For example, for a rule of inserting mask characters at fixed intervals, use loop traversal to the data block and insert mask characters every fixed number of bytes, and finally obtain a set of data blocks after masking; the extraction of the mask identification points in the set of masked data blocks can be achieved through a position marking method. For example, when inserting a "#" character as a mask at the 5th byte position of the data block, record the position "5" and the mask character "#" as the information of the mask identification point; the generation of the mask identification sequence corresponding to the multi-layer encrypted data block can be achieved through a sorting and merging method. For example, after sorting in ascending order according to the data block number, connect the mask identification point information of each data block in sequence to form a mask identification sequence.

[0101] The present invention associates the mask identification sequence with the authentication credential of a preset target terminal, and constructs a key distribution link corresponding to the authentication credential. By constructing the key distribution link, it ensures the secure and orderly transmission of the authentication credential, while enhancing the data confidentiality and strengthening the security of terminal access authentication, effectively preventing illegal terminals from accessing, and ensuring the security and stability of 5G message communication at the terminal level.

[0102] Among them, the preset target terminal refers to a device that is pre-specified as the data receiving or interaction object in the 5G messaging communication scenario. These terminals can be various types of devices supporting 5G communication, such as smartphones, tablets, Internet of Things devices, etc. For example, in the 5G messaging communication system within an enterprise, the work mobile phones of employees are the preset target terminals. The system will perform specific security settings and data distribution for these terminals to ensure the secure transmission and interaction of enterprise information; the authentication credential refers to a set of information used to verify the legitimacy of the identity of the preset target terminal, which contains various elements that can prove the identity of the terminal, such as digital certificates, passwords, tokens, etc. The authentication credential plays a key role in identity verification when the terminal accesses the 5G communication network or receives specific data. Taking the digital certificate as an example, it is issued by an authoritative certificate authority (CA) and contains the public key of the terminal, identity information, and the signature of the CA, etc.; the key distribution link refers to a combination of a logical path and mechanism specifically constructed for securely transmitting the keys related to the authentication credential. The key distribution link is responsible for securely transmitting these keys from the key generation center or the authorized institution to the preset target terminal, which involves a series of communication protocols, encryption algorithms, and security policies. For example, the key distribution method based on the public key infrastructure (PKI) can be adopted to exchange and verify the key information through digital certificates; or a secure channel, such as a dedicated encrypted tunnel, can be used to ensure that the keys are not stolen or tampered with during the transmission process. Optionally, the authentication credential associating the mask identification sequence with the preset target terminal can be achieved through an association method based on a mapping table. For example: create a mapping table, whose key is the unique identifier of the preset target terminal (such as the International Mobile Equipment Identity IMEI, Media Access Control address MAC, etc.), and the value is the corresponding authentication credential information; the construction of the key distribution link corresponding to the authentication credential can be achieved through a link construction method. For example: in an enterprise 5G communication network, the internal CA of the enterprise issues certificates for each terminal and the key generation center, and the key generation center distributes keys to the terminals according to the above process.

[0103] S4. Based on the key distribution link, inject the multi-layer encrypted data block into a preset quantum cache module, and monitor the interaction state of the data stream in the preset quantum cache module. Based on the interaction state, determine the link optimization direction corresponding to the key distribution link, extract the optimized encryption points in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link.

[0104] Based on the key distribution link of the present invention, injecting the multi-layer encrypted data block into a preset quantum cache module and monitoring the interaction state of the data stream in the preset quantum cache module can enable real-time understanding of the data storage and call situation. It can not only promptly discover potential security threats, ensure data integrity, but also optimize the data processing process, and improve the reliability and efficiency of 5G messaging data processing.

[0105] Among them, the preset quantum cache module refers to a storage device designed based on the principles of quantum mechanics, which is specifically planned to store key data in the 5G message communication system, such as multi-layer encrypted data blocks. It has an ultra-high storage density, can store a large amount of data in a very small physical space, and during the data storage process, it uses the stability of quantum states to ensure data security and can effectively resist some attack means based on traditional computing technologies; the interaction state refers to the dynamic behavior of the data stream in the preset quantum cache module, which covers operations such as data writing, reading, and transmission. In terms of writing, it includes the writing rate of data, whether the writing is successful, and whether there are errors or conflicts during the writing process; when reading, it involves the response time of the read request, the accuracy of the read data, and the impact of the read operation on the state of the cache module; at the transmission level, it focuses on the speed of data output from the cache module to other components, the stability of the transmission, and the data integrity during the transmission. For example, if it is found through monitoring that the data writing rate suddenly decreases, it may mean that the cache module has a fault or is facing external interference; if the read response time is too long, it may imply that the quantum state inside the cache module is abnormal, affecting the rapid reading of data. Optionally, the monitoring of the interaction state of the data stream in the preset quantum cache module can be achieved through state monitoring devices, such as quantum oscilloscopes, quantum spectrum analyzers, etc.

[0106] Furthermore, based on the interaction state, the present invention determines the link optimization direction corresponding to the key distribution link, which can be optimized from aspects such as encryption algorithms and transmission protocols to improve the link efficiency. This not only ensures the stability of data transmission but also enhances the overall security, ensuring that multi-layer encrypted data blocks are efficiently and securely injected into the quantum cache module through the key distribution link, and improving the reliability of 5G message data processing.

[0107] Among them, the link optimization direction refers to the specific action direction determined according to the optimization strategy set to achieve the performance improvement of the key distribution link. For example, if the optimization strategy set includes various strategies such as upgrading hardware, optimizing software algorithms, and adjusting the topology structure, then the link optimization direction can be to first upgrade the hardware of the node with the most severe load to quickly relieve the current performance bottleneck; then, gradually optimize the software algorithms of the entire network to improve the overall processing efficiency; finally, adjust the topology structure of the link according to the long-term change trend of network traffic to achieve more efficient traffic distribution and resource utilization.

[0108] As an embodiment of the present invention, determining the link optimization direction corresponding to the key distribution link based on the interaction state includes: extracting the core state indicators from the interaction state; identifying the state impact points in the key distribution link based on the core state indicators; querying the link structure corresponding to the key distribution link based on the state impact points; analyzing the topology optimization suggestions corresponding to the link structure; generating an optimization strategy set corresponding to the key distribution link based on the topology optimization suggestions; and determining the link optimization direction corresponding to the key distribution link based on the optimization strategy set.

[0109] Among them, the core state indicators refer to the quantitative parameters extracted from the interaction state data that can most directly and crucially reflect the operating conditions of the key distribution link. These indicators cover data transmission rate, data packet loss rate, link delay time, encryption and decryption time consumption, and node load rate, etc. For example, the data transmission rate determines the efficiency of key distribution, the packet loss rate reflects the stability of the transmission process, the link delay time affects real-time performance, the encryption and decryption time consumption reflects the impact of the security mechanism on the link performance, and the node load rate shows the working pressure of each node; the state impact points refer to the specific locations or links in the key distribution link that have a significant impact on the core state indicators. These points can be key nodes in the network, such as routers and switches, or specific transmission lines in the link. For example, when the data transmission rate suddenly decreases, after investigation, it is found that the load rate of a certain specific router is extremely high, and this router is a state impact point; the link structure refers to the physical connection relationship and logical layout that describe the various components (such as node devices, transmission lines, etc.) in the key distribution link. For example, a key distribution link can be composed of multiple server nodes distributed in different regions, and these nodes are connected by high-speed optical fibers to form a star or mesh topology structure; the topology optimization suggestions refer to the professional opinions on adjusting the network topology proposed to improve the performance of the key distribution link based on the analysis of the link structure and state impact points. For example, if it is found that the node load in a certain area is too high, the topology optimization suggestion can be to add an intermediate node in this area to divert the load, or adjust the connection method of the link, changing the original series structure to a parallel structure to improve the parallelism of data transmission; the optimization strategy set refers to a set of specific optimization measures for the key distribution link, and these measures are further refined and expanded based on the topology optimization suggestions. For example, for a node with too high a load, the optimization strategy set can include upgrading the server hardware of this node, increasing memory and CPU performance; at the same time, optimizing the algorithm of the key distribution software running on this node to improve its processing efficiency; in addition, the network protocol parameters used for communication between this node and other nodes can also be adjusted, such as increasing the window size, to improve the data transmission efficiency.

[0110] Furthermore, the extraction of the core state indicators in the interaction state can be achieved through statistical analysis methods. For example, the data transmission rates of each node in the key distribution link within one hour are statistically analyzed, and their average value is calculated as the core transmission rate indicator during this time period. The identification of the state impact points in the key distribution link can be achieved through association analysis methods. For example, by calculating the correlation between the data transmission rate and the load of each node, it is found that the load of a certain node is highly correlated with the data transmission rate, and the data transmission rate decreases significantly when the load increases. Then this node is a state impact point. The query of the link structure corresponding to the key distribution link can be achieved through the breadth-first search algorithm. For example, starting from a node in the link, the BFS algorithm is used to traverse the entire network, record the connection relationships between nodes, and finally construct the link structure. The analysis of the topology optimization suggestions corresponding to the link structure can be achieved through the traffic analysis and optimization method. For example, the traffic distribution in the link is analyzed, traffic bottlenecks and hot spots are found, and topology optimization suggestions are put forward based on the analysis results. The generation of the optimization strategy set corresponding to the key distribution link can be achieved through the expert system method. For example, the expert system infers suitable optimization strategies, such as replacing node devices and adjusting routing protocols, according to information such as the topology structure, traffic conditions, and reliability requirements of the link. The determination of the link optimization direction corresponding to the key distribution link can be achieved through the analytic hierarchy process. For example, performance improvement, cost control, and reliability enhancement are used as the target layer, and optimization strategies such as upgrading devices and adjusting the topology structure are used as the solution layer. The scores of each solution are calculated through AHP, and the solution with the highest score is the link optimization direction.

[0111] By extracting the optimized encryption points in the link optimization direction and making targeted improvements to these points, the present invention can significantly enhance the encryption strength and effectively resist potential security threats. This not only ensures the confidentiality of data during transmission but also enhances the security and stability of the entire 5G messaging communication system.

[0112] Among them, the optimized encryption points refer to specific links or positions in the key distribution link that are determined through link optimization direction analysis and play a crucial role in enhancing encryption performance. For example, at a node where data transmission is frequent and the confidentiality requirement is extremely high, if the current encryption algorithm cannot meet the security requirements, this node is an optimized encryption point, and the encryption effect can be enhanced by replacing it with a higher-level encryption algorithm. Optionally, the extraction of the optimized encryption points in the link optimization direction can be achieved through cryptographic analysis tools. For example, the cryptography test suite of OpenSSL can perform strength tests on the encryption algorithms used in the link, detect the weaknesses of the algorithms, and thus determine the optimized encryption points.

[0113] Furthermore, based on the optimized encryption points, the present invention calculates the encryption balance value corresponding to the key distribution link, which can clearly identify the weak and redundant areas of the encryption strength, providing a basis for targeted adjustment. This can not only improve the overall encryption efficiency but also avoid resource waste, ensuring that data can be appropriately and evenly encrypted and protected at each link of the link, enhancing the security of 5G message communication.

[0114] Among them, the encryption balance value refers to a numerical value that comprehensively measures the encryption status of the key distribution link. It comprehensively considers factors such as the security score, transmission efficiency, transmission delay, and calculation overhead value of the optimized encryption points, reflecting the balance degree of the link in terms of encryption strength, transmission performance, and calculation resource consumption.

[0115] As an embodiment of the present invention, calculating the encryption balance value corresponding to the key distribution link based on the optimized encryption points includes:

[0116] Calculating the encryption balance value corresponding to the key distribution link using the following formula: Among them, represents the encryption balance value corresponding to the key distribution link, represents the total number of the optimized encryption, represents the quantity index corresponding to the optimized encryption, represents the security score corresponding to the th optimized encryption point, represents the transmission efficiency corresponding to the th optimized encryption point, represents the transmission delay corresponding to the th optimized encryption point, represents the calculation overhead value corresponding to the th optimized encryption point,

[0117] Specifically, the security score refers to the quantitative evaluation of the j-th optimized encryption point in terms of encryption security. It is determined based on multiple factors, such as the strength of the encryption algorithm used, the security of key management, the ability to resist common attacks, etc. The higher the score, the better the performance of the optimized encryption point in terms of security, and it can more effectively protect data from being illegally obtained or tampered with. The transmission efficiency refers to the performance index of the j-th optimized encryption point in data transmission, which measures the amount of data successfully transmitted per unit time at this point. The transmission delay refers to the time delay generated during the data transmission process of the j-th optimized encryption point, which reflects the time taken for data to enter and leave this optimized encryption point. The lower the transmission delay, the better the real-time performance of data transmission and the faster the response speed of the service. The calculation overhead value refers to the amount of resources consumed by the j-th optimized encryption point during encryption-related calculations, such as CPU computing resources, memory resources, etc. The lower the calculation overhead value, the less the optimized encryption point occupies system resources when implementing the encryption function, which is beneficial to the overall performance and resource utilization efficiency of the system.

[0118] S5. Based on the encryption balance value, generate the security transmission index corresponding to the key distribution link, analyze the security fluctuation trend corresponding to the security transmission index, identify the fluctuation transmission factors in the security fluctuation trend, and based on the fluctuation transmission factors, generate the encryption transmission report corresponding to the 5G message data source.

[0119] Based on the encryption balance value, the present invention generates the security transmission index corresponding to the key distribution link, which can convert the link encryption state into an intuitive quantitative value, facilitating the evaluation of the overall security transmission level of the link, accurately positioning the advantages and disadvantages, and providing a strong reference for optimizing the link security strategy, helping to improve the security and stability of data transmission and ensuring the reliable operation of 5G message communication.

[0120] Among them, the security transmission index refers to a quantitative index generated based on key risk items, used to evaluate the security and reliability of the key distribution link, such as security score (0 - 100), risk level (low, medium, high), or threat coverage rate (percentage).

[0121] As an embodiment of the present invention, generating the security transmission index corresponding to the key distribution link based on the encryption balance value includes: analyzing the equilibrium distribution points corresponding to the encryption balance value; querying the uniform weak areas in the key distribution link based on the equilibrium distribution points; performing high-risk detection on the uniform weak areas to obtain the high-risk detection results; extracting the key risk items from the high-risk detection results; and generating the security transmission index corresponding to the key distribution link based on the key risk items.

[0122] Among them, the equilibrium distribution point refers to a specific position or node determined when analyzing the encryption equilibrium value, which can reflect the equilibrium state of each optimized encryption point in the key distribution link in terms of security, transmission efficiency, computational overhead, etc., and reflects the distribution of encryption-related factors in the link; the uniform weak area refers to an area found in the key distribution link based on the equilibrium distribution point, where the encryption performance is relatively weak and the distribution is relatively average. This area performs poorly in terms of security, transmission efficiency and other indicators, and may affect the overall secure transmission level of the link; the high-risk detection result refers to the result obtained after carrying out high-risk detection on the uniform weak area, which includes various potential risk information that may cause serious security problems in this area, such as vulnerable links, encryption algorithm vulnerabilities, etc.; the key risk item refers to the risk item selected from the high-risk detection result that has a significant impact on the secure transmission of the key distribution link, and is the key security hidden danger that needs to be focused on and processed.

[0123] Furthermore, analyzing the equilibrium distribution point corresponding to the encryption equilibrium value can be achieved through the Matplotlib tool of Python. For example: use the Matplotlib library of Python to draw a scatter plot of the encryption equilibrium value, observe the data distribution, and thus determine the equilibrium distribution point; querying the uniform weak area in the key distribution link can be achieved through the sliding window algorithm. For example: use the sliding window algorithm to slide the window on the key distribution link data, calculate the average encryption performance index within each window. If the indicators of multiple consecutive windows are lower than the average level, then this area can be regarded as a uniform weak area; performing high-risk detection on the uniform weak area can be achieved through the CVSS algorithm. For example: use the CVSS algorithm to calculate the risk score of each vulnerability according to factors such as the exploitability and impact scope of the vulnerability, and obtain the high-risk detection result; extracting the key risk items from the high-risk detection result can be achieved through the Splunk log analysis tool. For example: use the Splunk log analysis tool, and by setting rules, such as according to the risk score threshold, vulnerability type, etc., extract the key risk items that meet the conditions; generating the secure transmission index corresponding to the key distribution link can be achieved through the entropy weight method. For example: use the entropy weight method to determine the weights of various factors in the key risk items, and then calculate a comprehensive secure transmission index value through the weighted average method.

[0124] By analyzing the security fluctuation trend corresponding to the secure transmission index and identifying the fluctuation transmission factors in the security fluctuation trend, the present invention can intuitively insight into the dynamic changes of the security performance of the key distribution link, and by mastering the trend, potential risks can be predicted in advance. And identifying the fluctuation factors helps to accurately locate the root cause of the problem, provides strong support for timely adjusting the security strategy and optimizing the link performance, and effectively ensures the secure and stable progress of 5G message communication.

[0125] Among them, the security fluctuation trend refers to a dynamic description of the changes in the security transmission indicators of the key distribution link over time or business volume and other variables. For example, if the security transmission indicator frequently rises and falls within a period of time, it indicates that the link security performance is unstable and there are large fluctuations; if the indicator shows a trend of gradual increase or decrease, it reflects that the link security is gradually increasing or decreasing; the fluctuating transmission factor refers to various internal and external reasons that cause the fluctuation of the security transmission indicators of the key distribution link. Internal factors may include hardware aging of some nodes in the link, resulting in a decrease in data processing capacity, affecting transmission efficiency and security; or unreasonable parameter settings of the encryption algorithm, resulting in insufficient encryption strength in certain specific business scenarios; external factors such as network attacks and malware intrusions can lead to security The overall transmission index deteriorates sharply; the sudden and substantial increase in network traffic exceeds the carrying capacity of the link, which will also cause problems such as transmission delay and packet loss, thereby affecting the security transmission index. Optionally, the analysis of the security fluctuation trend corresponding to the security transmission index can be implemented through Pandas in Python, such as: using Python's Pandas library to read the time series data of the security transmission index, using the moving average algorithm to smooth the data, eliminating short-term fluctuations, and highlighting the overall trend; the identification of the fluctuation transmission factors in the security fluctuation trend can be implemented through a decision tree algorithm, such as: using a decision tree algorithm, taking the fluctuation of the security transmission index as the target variable, and various potential factors as feature variables, to construct a decision tree model, and the important feature in the model is the fluctuation transmission factor.

[0126] Based on the fluctuating transmission factors, the present invention generates an encrypted transmission report corresponding to the 5G message data source, which can systematically sort out the key factors affecting secure transmission, and the report can intuitively present the problem, providing technical personnel with a clear optimization direction, and helping to strengthen encryption measures in a targeted manner. It not only improves the security of 5G message data transmission, but also enhances the reliability and stability of the entire communication system, and ensures the security of user information.

[0127] Among them, the encrypted transmission report refers to a comprehensive and detailed comprehensive document on the encrypted transmission of 5G message data sources. Starting from the fluctuating transmission factors, it deeply analyzes various situations in the encrypted transmission process of 5G messages. The report covers the overall performance of current encrypted transmission, such as key indicators like data transmission rate, encryption intensity, and error rate during transmission; clearly points out the specific factors leading to security fluctuations, including hardware device aging, network attacks, encryption algorithm defects, etc.; at the same time, based on these analyses, it provides targeted and operable improvement strategies and suggestions, providing solid data support and decision-making reference for optimizing the 5G message encrypted transmission process and enhancing data transmission security. Optionally, generating the encrypted transmission report corresponding to the 5G message data source can be achieved through report generation tools, such as tools like Tableau, Power BI, etc.

[0128] Compared with the problems described in the background technology, the present invention enhances the flexibility and adaptability of the encryption strategy by obtaining the 5G message data source and parsing the security requirement parameters in the 5G message data source, ensuring targeted protection of data during transmission. At the same time, it helps optimize resource allocation, improve encryption efficiency, and meet the dual requirements of high real-time and high security. The present invention performs multi-dimensional threat detection on the associated topology nodes to obtain multi-dimensional threat vectors, enabling a comprehensive insight into the security risks faced by nodes from multiple dimensions. Potential threats such as malware intrusion and abnormal traffic attacks can be accurately located by analyzing various factors such as network traffic, node status, and surrounding environment, effectively enhancing the security and stability of key nodes in the 5G message transmission path. Further, based on the real-time risk entropy value, the present invention performs adaptive security grading on the 5G message data source to obtain multi-layer encrypted data blocks, which can accurately adapt to the protection requirements of data sources with different risk levels, effectively resist serious threats, and protect key data; low risk entropy values use relatively lightweight encryption to improve processing efficiency. Further, based on the key distribution link, the present invention injects the multi-layer encrypted data blocks into a preset quantum cache module and monitors the interaction status of the data stream in the preset quantum cache module, enabling real-time understanding of the storage and invocation of data. It can not only promptly discover potential security threats and ensure data integrity, but also optimize the data processing process, improving the reliability and efficiency of 5G message data processing. Finally, based on the encryption balance value, the present invention generates a security transmission index corresponding to the key distribution link, which can convert the link encryption status into an intuitive quantitative value, facilitating the evaluation of the overall security transmission level of the link, accurately positioning advantages and disadvantages, and providing strong reference for optimizing the link security strategy, helping to enhance data transmission security and stability, and ensuring the reliable operation of 5G message communication. Therefore, a security encryption transmission method and system for 5G messages provided by an embodiment of the present invention can ensure the security integrity of 5G messages during transmission.

[0129] Example 2:

[0130] As Figure 2 shown, it is a functional module diagram of a secure encrypted transmission system for 5G messages according to the present invention.

[0131] The secure encrypted transmission system 200 for 5G messages according to the present invention can be installed in an electronic device. According to the functions implemented, the secure encrypted transmission system for 5G messages can include a node detection module 201, a risk entropy value calculation module 202, a link construction module 203, an equilibrium value calculation module 204, and a report generation module 205. The modules in the present invention can also be referred to as units, which refer to a series of computer program segments that can be executed by a processor of an electronic device and can complete fixed functions, and are stored in the memory of the electronic device.

[0132] In the embodiments of the present invention, the functions of each module / unit are as follows:

[0133] The node detection module 201 is used to obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the dynamic encryption rule set corresponding to the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path;

[0134] The risk entropy value calculation module 202 is used to perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify the abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate the real-time risk entropy value corresponding to the abnormal behavior pattern;

[0135] The link construction module 203 is used to perform adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, perform dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associate the mask identification sequence with the authentication credentials of a preset target terminal, and construct a key distribution link corresponding to the authentication credentials;

[0136] The equilibrium value calculation module 204 is used to inject the multi-layer encrypted data blocks into a preset quantum cache module based on the key distribution link, monitor the interaction state of the data flow in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption points in the link optimization direction, and calculate the encryption equilibrium value corresponding to the key distribution link based on the optimized encryption points;

[0137] The report generation module 205 is configured to generate a security transmission metric corresponding to the key distribution link based on the encrypted equilibrium value, analyze a security fluctuation trend corresponding to the security transmission metric, identify a fluctuation transmission factor in the security fluctuation trend, and generate an encrypted transmission report corresponding to the 5G message data source based on the fluctuation transmission factor.

[0138] Specifically, each module in the security encryption transmission system 200 for 5G messages in the embodiments of the present invention adopts the same technical means as those described in the above Figure 1 a security encryption transmission method for 5G messages, and can produce the same technical effects, which will not be elaborated here.

[0139] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.

[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A secure encryption transmission method for 5G messages, characterized in that, The method includes: Obtain a 5G message data source, parse the security requirement parameters in the 5G message data source, query the corresponding dynamic encryption rule set for the security requirement parameters, extract the core encryption elements in the dynamic encryption rule set, and detect the associated topological nodes of the core encryption elements on the transmission path; Perform multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector, identify the abnormal behavior pattern corresponding to the multi-dimensional threat vector, and calculate the real-time risk entropy value corresponding to the abnormal behavior pattern; Based on the real-time risk entropy value, perform adaptive security grading on the 5G message data source to obtain multi-layer encrypted data blocks, perform dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associate the mask identification sequence with the authentication credentials of a preset target terminal, and construct a key distribution link corresponding to the authentication credentials; Based on the key distribution link, inject the multi-layer encrypted data blocks into a preset quantum cache module, monitor the interaction status of the data stream in the quantum cache module, based on the interaction status, determine the link optimization direction corresponding to the key distribution link, extract the optimized encryption points in the link optimization direction, and calculate the encryption balance value corresponding to the key distribution link based on the optimized encryption points; Based on the encryption balance value, generate a security transmission index corresponding to the key distribution link, analyze the security fluctuation trend corresponding to the security transmission index, identify the fluctuation transmission factors in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuation transmission factors.

2. The secure encryption transmission method for 5G messages according to claim 1, characterized in that, The detecting the associated topological nodes of the core encryption elements on the transmission path includes: Parse the key feature identifiers in the core encryption elements; Draw a preliminary topological sketch of the key feature identifiers corresponding to the transmission path; Extract the potential topological points in the preliminary topological sketch; Perform a deep scan on the potential topological points to obtain topological association parameters; Based on the topological association parameters, determine the associated topological nodes on the transmission path.

3. A secure encryption transmission method for 5G messages as described in claim 1, characterized in that, The performing multi-dimensional threat detection on the associated topological nodes to obtain a multi-dimensional threat vector includes: Collect the basic operation data corresponding to the associated topological nodes; Based on the basic operation data, construct an initial state portrait corresponding to the associated topological nodes; Analyze the portrait traffic distribution in the initial state portrait; Mark the abnormal detection segments in the portrait traffic distribution; Perform multi-dimensional threat detection on the abnormal detection segments to obtain a multi-dimensional threat vector.

4. A secure encryption transmission method for 5G messages according to claim 1, characterized in that The calculating the real-time risk entropy value corresponding to the abnormal behavior pattern includes: Calculate the real-time risk entropy value corresponding to the abnormal behavior pattern using the following formula: Wherein, represents the real-time risk entropy value corresponding to the abnormal behavior pattern, represents the quantity corresponding to the abnormal behavior pattern, represents the quantity index corresponding to the abnormal behavior pattern, represents the th occurrence probability corresponding to the abnormal behavior pattern, represents the th duration corresponding to the abnormal behavior pattern, represents the time range from the start of the abnormal behavior to the current moment, represents the th severity score of the abnormal behavior pattern at time , represents the th weight coefficient of the abnormal behavior pattern at time .

5. A secure encryption transmission method for 5G messages according to claim 1, characterized in that, The performing adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks includes: Analyze the distribution law corresponding to the real-time risk entropy value; Based on the distribution law, determine the fluctuation interval corresponding to the real-time risk entropy value; Based on the fluctuation interval, perform a preliminary grouping on the 5G message data source to obtain grouped data sources; Evaluate the importance coefficient corresponding to the grouped data sources; Based on the importance coefficient, perform a sorting process on the grouped data sources to obtain a sorting result; Perform adaptive security grading on the sorting result to obtain multi-layer encrypted data blocks.

6. The secure encrypted transmission method for 5G messages according to claim 1, characterized in that Performing dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, including: Analyze the encryption strength corresponding to the data in the multi-layer encrypted data blocks; Based on the encryption strength, generate a mask rule set corresponding to the multi-layer encrypted data blocks; Based on the mask rule set, perform masking processing on the multi-layer encrypted data blocks to obtain a set of masked data blocks; Extract the mask identification points in the set of masked data blocks; Based on the mask identification points, generate a mask identification sequence corresponding to the multi-layer encrypted data blocks.

7. A secure encryption transmission method for 5G messages according to claim 1, characterized in that Determining the link optimization direction corresponding to the key distribution link based on the interaction state, including: Extract the core state indicators in the interaction state; Based on the core state indicators, identify the state impact points in the key distribution link; Based on the state impact points, query the link structure corresponding to the key distribution link; Analyze the topology optimization suggestions corresponding to the link structure; Based on the topology optimization suggestions, generate an optimization strategy set corresponding to the key distribution link; Based on the optimization strategy set, determine the link optimization direction corresponding to the key distribution link.

8. A secure encryption transmission method for 5G messages according to claim 1, characterized in that, Calculating the encryption balance value corresponding to the key distribution link based on the optimized encryption points, including: Calculate the encryption balance value corresponding to the key distribution link using the following formula: where represents the encryption balance value corresponding to the key distribution link, represents the total quantity corresponding to the optimized encryption, represents the quantity index corresponding to the optimized encryption, represents the security score corresponding to the th optimized encryption point, represents the transmission efficiency corresponding to the th optimized encryption point, represents the transmission delay corresponding to the th optimized encryption point, represents the calculation overhead value corresponding to the th optimized encryption point, represents the maximum calculation overhead value among all optimized encryption points.

9. A secure encryption transmission method for 5G messages according to claim 1, characterized in that Generating the secure transmission metrics corresponding to the key distribution link based on the encryption balance value, including: Analyze the equilibrium distribution points corresponding to the encryption balance value; Based on the equilibrium distribution points, query the uniform weak areas in the key distribution link; Perform high-risk detection on the uniform weak areas to obtain high-risk detection results; Extract the key risk items in the high-risk detection results; Based on the key risk items, generate the secure transmission metrics corresponding to the key distribution link.

10. A secure encrypted transmission system for 5G messages, characterized in that, The system includes: A node detection module for obtaining a 5G message data source, parsing the security requirement parameters in the 5G message data source, querying the dynamic encryption rule set corresponding to the security requirement parameters, extracting the core encryption elements in the dynamic encryption rule set, and detecting the associated topology nodes of the core encryption elements on the transmission path; A risk entropy value calculation module for performing multi-dimensional threat detection on the associated topology nodes to obtain a multi-dimensional threat vector, identifying the abnormal behavior patterns corresponding to the multi-dimensional threat vector, and calculating the real-time risk entropy value corresponding to the abnormal behavior patterns; A link construction module for performing adaptive security grading on the 5G message data source based on the real-time risk entropy value to obtain multi-layer encrypted data blocks, performing dynamic masking processing on the multi-layer encrypted data blocks to obtain a mask identification sequence, associating the mask identification sequence with the authentication credentials of a preset target terminal, and constructing a key distribution link corresponding to the authentication credentials; An equilibrium value calculation module, configured to inject the multi-layer encrypted data block into a preset quantum cache module based on the key distribution link, monitor the interaction state of the data stream in the quantum cache module, determine the link optimization direction corresponding to the key distribution link based on the interaction state, extract the optimized encryption points in the link optimization direction, and calculate the encryption equilibrium value corresponding to the key distribution link based on the optimized encryption points; A report generation module, configured to generate a secure transmission index corresponding to the key distribution link based on the encryption equilibrium value, analyze the security fluctuation trend corresponding to the secure transmission index, identify the fluctuation transmission factors in the security fluctuation trend, and generate an encryption transmission report corresponding to the 5G message data source based on the fluctuation transmission factors.

Citation Information

Patent Citations

  • Online data secure transmission method and system based on 5G message, and electronic equipment

    CN116261139A

  • Fire-fighting equipment detection and evaluation system and method based on video processing and deep learning

    CN118095867A