Internet data encryption method and system

By acquiring and processing Internet mail system data in Internet data encryption technology, performing hardware channel lock encryption analysis and encryption key generation, it solves the problem that the existing technology is difficult to cope with the encryption needs of large-scale, cross-device, and cross-network, and realizes high intensity and security of data transmission.

CN120128405AInactive Publication Date: 2025-06-10PUTIAN SHUNLIAN E-COMMERCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510350889.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing Internet data encryption technology is difficult to cope with the encryption needs of large-scale, cross-device and cross-networks. Especially in the case of multi-device interconnection, how to ensure the security of key exchange between various devices and the encryption strength and security of data transmission is still a difficult problem.

Method used

By obtaining Internet mail system data, extracting email sending features and performing character set conversion encoding, identifying and processing the formats and contents of different emails. Then, hardware channel lock encryption analysis is performed based on the characteristics of the email sender and receiver, an encryption key is generated, and the email content is encrypted. At the same time, an encryption error recovery mechanism is implemented to ensure the stability and security of encryption tasks.

Benefits of technology

A unified security protection solution for Internet data is realized, ensuring the security of key exchange between various devices and the encryption strength and security of data transmission, improving the security and stability of the encryption process, and preventing potential man-in-the-middle attacks and other forms of intrusions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128405A_ABST
    Figure CN120128405A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to an Internet data encryption method and system. The method comprises the following steps of: acquiring internet mail system data, and extracting E-mail sending characteristics according to the internet mail system data so as to obtain E-mail sending data; carrying out character set conversion coding according to the E-mail sending data so as to obtain E-mail character set conversion coding data; extracting features of an E-mail sender and features of an E-mail receiver according to the Internet E-mail data so as to obtain data of the E-mail sender and data of the E-mail receiver; and performing hardware channel lock encryption analysis according to the e-mail sender data and the e-mail receiver data so as to obtain hardware channel lock encryption data. According to the invention, the success rate and security of mail data encryption are improved based on the information security technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to an Internet data encryption method and system. Background Art

[0002] Most of the existing Internet data encryption technologies are designed for a single encryption process and are difficult to meet the encryption requirements of large-scale, cross-device, and cross-network. In practical applications, in the face of different types of devices (such as PC terminals, mobile terminals, Internet of Things devices, etc.) and different network environments (such as local area networks, wide area networks, cloud computing environments, etc.), the existing encryption technologies cannot provide a unified security protection solution. Especially in the case of multi-device interconnection, how to ensure the security of key exchange between devices and how to ensure the encryption intensity and security of data transmission between different devices are still unsolved problems. Although the existing hardware-accelerated encryption methods improve the encryption efficiency, due to the limitations of the hardware itself and potential physical security problems, the security of hardware-accelerated encryption technologies often cannot be fully guaranteed. The hardware accelerator is threatened by security threats such as physical attacks and side-channel attacks, resulting in the leakage of encrypted data. Summary of the Invention

[0003] Based on this, it is necessary for the present invention to provide an Internet data encryption method and system to solve at least one of the above technical problems.

[0004] To achieve the above object, an Internet data encryption method includes the following steps:

[0005] Step S1: Obtain Internet mail system data, extract email sending characteristics according to the Internet mail system data to obtain email sending data; perform character set conversion encoding according to the email sending data to obtain email character set conversion encoding data;

[0006] Step S2: Extract email sender characteristics and email recipient characteristics according to the Internet email data to obtain email sender data and email recipient data; perform hardware channel lock encryption analysis according to the email sender data and the email recipient data to obtain hardware channel lock encryption data;

[0007] Step S3: Generate an encryption key according to the hardware channel lock encryption data to obtain encryption key data; encrypt the email character set conversion encoding data according to the encryption key data to obtain email encryption processing data;

[0008] Step S4: Extract the characteristics of email encryption failure based on the data processed by email encryption, so as to obtain the email encryption failure data; perform hardware acceleration error analysis based on the email encryption failure data, so as to obtain the hardware acceleration error data;

[0009] Step S5: Start the encryption error recovery mechanism based on the hardware acceleration error data, so as to obtain the encryption error recovery mechanism data, and upload the encryption error recovery mechanism data to the Internet mail system to execute the mail data encryption task.

[0010] The present invention ensures the ability to identify and process the formats and contents of different emails by obtaining Internet mail system data and extracting sending characteristics, which is crucial for subsequent character set conversion encoding. Character set conversion ensures the compatibility and information consistency of emails between different devices and platforms, providing a standardized data format for the encryption process. By extracting the characteristics of the email sender and receiver, the method can identify different hardware devices and encryption protocols, thereby performing hardware channel lock encryption analysis. The importance of this link lies in ensuring the effective protection of the transmission path of mail data by deeply analyzing the encryption channels of the sender and receiver devices, preventing the mail data from being stolen or tampered with due to device vulnerabilities or network attacks. The introduction of hardware channel lock encryption effectively enhances the security of the encryption process, preventing potential man-in-the-middle attacks or other forms of intrusion. After the hardware channel lock encryption analysis, the system generates an encryption key and uses this key to encrypt the email content to ensure the confidentiality of the email content. In this link, the generation and management of the key are crucial to ensure the security of the key during transmission and storage, preventing the key from being leaked or illegally obtained. By extracting the characteristics of encryption failure, problems occurring during the encryption process can be discovered in a timely manner, and it can be analyzed whether the hardware accelerator fails during the encryption process. The hardware accelerator error affects the stability and speed of the encryption process. Therefore, the analysis of the hardware acceleration error can timely locate and solve the hardware failures occurring during the encryption process, ensuring that the encryption task will not be interrupted due to hardware problems. After detecting the encryption error, the system can automatically start the encryption error recovery mechanism to timely resume the normal operation of the encryption process. The activation of the recovery mechanism avoids the risk of data leakage caused by encryption failure and ensures that the mail data can finally complete the encryption task. After the data of the recovery mechanism is uploaded to the Internet mail system, it can provide reference data and improvement solutions for subsequent encryption tasks, further optimizing the system performance and enhancing the reliability and stability of the encryption process.

[0011] Optionally, step S1 is specifically:

[0012] Step S11: Obtain Internet mail system data, and extract email sending characteristics based on the Internet mail system data, so as to obtain email sending data;

[0013] Step S12: Identify the character set of the email body based on the email sending data, so as to obtain the original sending character set data of the email body;

[0014] Step S13: Perform unified conversion based on the original sending character set of the email body, so as to obtain the unified sending character set data of the email body;

[0015] Step S14: Convert the character set of the email attachment based on the email sending data, so as to obtain the unified sending character set data of the email attachment;

[0016] Step S15: Perform standardized encoding based on the unified sending character set data of the email body and the unified sending character set data of the email attachment, so as to obtain the character set conversion encoding data of the email.

[0017] The present invention ensures the compatibility, security, and transmission stability of email content through the processing and encryption of email system data. In the first step, internet email system data is obtained and email sending characteristics are extracted, which can comprehensively understand information such as the structure of the email, sending time, sender, and recipient, thereby providing data support for the subsequent encryption process. By extracting these characteristics, the system can identify and analyze the types of email data, laying a foundation for unified character set conversion and encryption tasks. Next, the character set identification of the email body ensures that the email content can correctly identify its encoding method. Regardless of the character set format used for sending the email, it can ensure that there are no garbled characters or information loss during the encryption process. By identifying and extracting the original sending character set data of the email body, the system can ensure that the email content remains consistent and readable during the encryption process, reducing the risk of character set encoding errors. Unified conversion can convert different character set formats of the email body into a standard unified character set format, providing compatibility support for subsequent encryption and decryption processes, and avoiding encryption failures caused by inconsistent character sets. The process of unified character set conversion ensures that the email content will not deviate during the encryption process regardless of which device or platform it is sent from, thereby improving the adaptability of the encryption system. At the same time, the character set conversion of attachments is equally important. The content in attachments includes documents, images, or other file formats. Therefore, before encrypting the attachments together with the body, the character set conversion of the attachment content must be performed to ensure its accuracy and consistency during encryption. After the email attachments are converted to a unified character set, they are uniformly standardized encoded like the body, which lays a foundation for the encryption of the entire email content and subsequent decryption operations. By standardizing the encoding of the character sets of the email body and attachments, not only is the compatibility of the email content between different platforms ensured, but also the encryption process can proceed smoothly. Standardized encoding enables the email content to maintain integrity and readability regardless of the encryption algorithm used, preventing any format errors or information loss problems during the encryption and decryption processes. Through these steps, the character set conversion and encryption process of the entire email are optimized, not only improving the compatibility of the email system, but also enhancing the security of email data during transmission, ensuring that the email content is not tampered with, leaked, or lost. Therefore, the present invention provides a stable, efficient, and highly compatible email encryption solution through the standardized processing of the email character set, further ensuring the secure transmission of email data across different platforms, devices, and environments.

[0018] Optionally, step S2 is specifically as follows:

[0019] Step S21: Extract email sender characteristics and email recipient characteristics based on internet email data, thereby obtaining email sender data and email recipient data;

[0020] Step S22: Perform side-channel attack prevention analysis based on the email sender data to obtain the side-channel attack prevention data of the sending device;

[0021] Step S23: Perform encrypted channel analysis of the receiving device based on the email recipient data to obtain the encrypted data of the channel lock of the receiving device;

[0022] Step S24: Perform hardware channel lock encryption integration based on the side-channel attack prevention data of the sending device and the encrypted data of the channel lock of the receiving device to obtain the encrypted data of the hardware channel lock.

[0023] By extracting the characteristic data of the email sender and recipient, the present invention can understand in detail the types of sending and receiving devices of the email, the protocols used, and the encryption requirements. This provides a clear data basis for subsequent encryption operations, ensuring that the encryption process can be optimized according to the different characteristics of the sending and receiving ends. According to the device characteristics of the sender and recipient, existing security vulnerabilities, device capability differences, and encryption requirements can be identified, thereby ensuring the effectiveness and compatibility of the encryption operations. Next, by performing side-channel attack prevention analysis on the email sender data, side-channel attack means that pose risks to the encryption device can be identified, thereby generating the side-channel attack prevention data of the sending device. This analysis step can not only prevent attacks that leak encrypted information through physical signals but also enhance the security of the sending device, avoiding encryption failures or key leaks caused by hardware vulnerabilities. For the receiving device, the analysis of the encrypted channel is equally crucial. By performing encrypted channel lock encryption analysis on the recipient data, it can be ensured that the encrypted protection of the email on the receiving end can effectively prevent external interference or tampering, thereby providing further protection for the email data. Through the integration of the side-channel attack prevention data of the sending device and the encrypted data of the channel lock of the receiving device, a complete hardware channel lock encryption scheme can be formed. This integration not only ensures that every link in the data transmission process from the sending end to the receiving end has sufficient encryption protection but also can be optimized according to the different characteristics of the hardware devices, improving the adaptability and security of the encryption system in different devices and environments. The generation of the encrypted data of the hardware channel lock not only enhances the encryption strength of the email data but also enhances the anti-attack ability of the overall system, ensuring the confidentiality and integrity of the email content during transmission and further reducing the risk of being cracked or leaked. In summary, the entire process provides a systematic encryption scheme by comprehensively analyzing the device characteristics, encrypted channels, and anti-attack capabilities of the sender and recipient, ensuring all-round protection of the email data during encryption, transmission, and reception, solving the security vulnerabilities existing in traditional email encryption, and further enhancing the security and reliability of the email data.

[0024] Optionally, step S22 is specifically as follows:

[0025] Step S221: Extract the sender device characteristics based on the email sender data, so as to obtain the sender device data;

[0026] Step S222: Detect the electromagnetic field of the sender device data, so as to obtain the sender device electromagnetic field data;

[0027] Step S223: Generate an electromagnetic radiation curve based on the sender device electromagnetic field data, so as to obtain the electromagnetic radiation curve data;

[0028] Step S224: Detect the abnormal pattern according to the electromagnetic radiation curve data, so as to obtain the radiation abnormal pattern data;

[0029] Step S225: Evaluate the leakage risk of the radiation abnormal pattern data, so as to obtain the leakage risk data;

[0030] Step S226: Optimize the radiation protection of the sending device according to the leakage risk data, so as to obtain the data for the sending device to prevent side-channel attacks.

[0031] By extracting the features of the data of the sending device, the present invention can accurately understand the hardware composition and its encryption capabilities of the sending device. These device features provide key information for subsequent encryption analysis, helping to identify security vulnerabilities and encryption performance of the device, and ensuring that the encryption operation is optimized within the device's capabilities. Next, by detecting the electromagnetic field of the sending device, the electromagnetic radiation data generated by the hardware during the encryption process can be obtained. This operation helps to reveal whether there is a risk of leaking key information during the encryption task of the device, because electromagnetic radiation is a common way of side-channel attacks and can infer sensitive information during the encryption process by monitoring radiation characteristics. The generated electromagnetic radiation curve data can provide a basis for subsequent abnormal pattern detection, thereby effectively identifying whether there are vulnerabilities in the device during the encryption process due to side-channel attacks. Through abnormal pattern detection, abnormal radiation patterns that appear during the encryption process can be screened out. These patterns are related to the leakage of sensitive information in the encryption operation, further enhancing the protection ability of the encryption system. Evaluating the leakage risk of the detected abnormal radiation patterns helps to quantify the severity of the radiation signal leakage, thereby guiding the protection design of the device and reducing potential security threats. Finally, by analyzing the leakage risk data, radiation protection optimization measures for the sending device are implemented, thereby enhancing the anti-side-channel attack ability of the sending device and ensuring the information security during the encryption process. These optimization measures can effectively improve the security of the device, prevent information leakage during the encryption process, and ensure the confidentiality and integrity of data transmission. The entire process, through refined hardware analysis, radiation detection, and risk assessment, not only improves the security of the email encryption system but also enhances the anti-attack ability of the device in a complex environment, providing a comprehensive and reliable encryption protection solution to ensure that sensitive information in the email is not leaked or tampered with during transmission.

[0032] Optionally, step S224 is specifically as follows:

[0033] Perform low-pass filtering denoising on the electromagnetic radiation curve data to obtain denoised electromagnetic radiation curve data;

[0034] Construct a normal electromagnetic radiation baseline for the denoised electromagnetic radiation curve data to obtain normal electromagnetic radiation baseline data;

[0035] Compare the denoised electromagnetic radiation curve data with the normal electromagnetic radiation baseline data for abnormal deviation from the baseline to obtain abnormal electromagnetic radiation deviation from the baseline data;

[0036] Locate the abnormal points for the abnormal electromagnetic radiation deviation from the baseline data, and obtain the electromagnetic radiation deviation data of the abnormal points;

[0037] Divide the abnormal pattern according to the electromagnetic radiation deviation data of the abnormal points to obtain radiation abnormal pattern data.

[0038] Through low-pass filtering and denoising of the electromagnetic radiation curve data, the present invention can effectively remove the noise and interference in the signal, ensuring that the obtained electromagnetic radiation data is purer. This operation guarantees the accuracy of subsequent analysis, avoiding the influence of environmental noise, hardware failures, or other external factors on the radiation data, thereby enhancing the reliability of radiation monitoring. Next, by constructing a normal electromagnetic radiation baseline for the denoised electromagnetic radiation curve data, a reference line can be provided for the normal operation during the email encryption process. This baseline reflects the normal radiation characteristics of the device during the encryption process and is a key reference for evaluating whether there are abnormal leaks in the device. Through comparative analysis based on this normal electromagnetic radiation baseline, abnormal deviations occurring during the encryption operation can be effectively identified. When the electromagnetic radiation curve deviates from the normal baseline, it indicates that the device has leaked sensitive information or suffered a side-channel attack during the encryption task. Further abnormal point location operations can accurately determine the specific location of the abnormal radiation, helping to locate the source of the leak and identify which links or encryption steps have potential security hazards. The electromagnetic radiation deviation data of the abnormal points identified in this process is the basis for further analysis and can provide specific improvement directions for encryption protection. Finally, by classifying the abnormal point data into abnormal patterns, not only can the specific patterns of radiation leaks be identified, but also different types of radiation anomalies can be classified and analyzed, thereby more precisely identifying and preventing different types of side-channel attacks. This comprehensive abnormal pattern recognition method, combining denoising, baseline comparison, abnormal point location, and pattern classification, comprehensively improves the security during the email encryption process, ensures the protection of sensitive information under different devices and different encryption processes, and enhances the anti-attack ability and reliability of the encryption system.

[0039] Optionally, step S23 is specifically as follows:

[0040] Step S231: Extract the recipient device characteristics based on the email recipient data to obtain the recipient device data;

[0041] Step S232: Analyze the encryption channels of the recipient device data to obtain the recipient device encryption channel data;

[0042] Step S233: Statistically analyze the recipient device encryption algorithms based on the recipient device encryption channel data to obtain the recipient device encryption algorithm data;

[0043] Step S234: Classify the device types based on the recipient device data to obtain the PC device data and the mobile device data;

[0044] Step S235: Allocate the PC encryption algorithms to the PC device data based on the recipient device encryption algorithm data to obtain the PC encryption algorithm data;

[0045] Step S236: Perform mobile - end encryption algorithm allocation on the mobile - end device data according to the recipient device encryption algorithm data, so as to obtain mobile - end encryption algorithm data;

[0046] Step S237: Perform recipient device channel lock encryption integration according to the PC - end encryption algorithm data and the mobile - end encryption algorithm data, so as to obtain recipient device channel lock encryption data.

[0047] Through feature extraction of the recipient device based on the email recipient data, the present invention can obtain detailed data related to the recipient device, laying a foundation for subsequent encryption processing. By further analyzing the encryption channels of the recipient device data, the characteristics of the encryption channels used by the recipient device can be identified, ensuring the security of its encrypted communication. This step provides the necessary data support for the security assessment of the encryption channels and helps to identify potential security vulnerabilities. On this basis, by statistically analyzing the encryption algorithms of the recipient device encryption channel data, the types of encryption algorithms adopted by the recipient device can be analyzed, thereby evaluating its encryption strength and adaptability. This analysis helps to ensure the effectiveness of email encryption and determine whether it is necessary to adjust the encryption algorithm or perform stronger encryption processing. Classifying the devices according to the recipient device data into PC - end devices and mobile - end devices helps to carry out customized design for the encryption requirements of different types of devices. This step can be optimized according to the device performance and characteristics to ensure that in different device environments, email encryption can achieve the best security and performance. Then, by performing encryption algorithm allocation on the PC - end device data according to the recipient device encryption algorithm data, a suitable encryption algorithm can be selected for the PC - end device and optimized according to its computing power and performance. Similarly, for mobile - end devices, performing mobile - end encryption algorithm allocation based on its encryption algorithm data can ensure that mobile devices can also use encryption algorithms suitable for their hardware capabilities. This customized encryption algorithm allocation ensures that the encryption processing on different devices can be carried out in the best way, improving the overall efficiency and security of the email encryption system. By integrating the PC - end encryption algorithm data and the mobile - end encryption algorithm data to form recipient device channel lock encryption data, it is ensured that a unified standard encryption process can be executed on different devices, effectively preventing threats such as man - in - the - middle attacks and side - channel attacks. This step ensures that during the entire email encryption process, whether on the PC - end or the mobile - end, the data transmission and encryption processes can be fully protected, enhancing the overall security of the email system and ensuring that the confidentiality and integrity of the email content are not threatened.

[0048] Optionally, step S232 is specifically:

[0049] Identify the communication protocol of the recipient device data to obtain the recipient device communication protocol data;

[0050] Evaluate the encryption of the mail transmission path based on the communication protocol data of the receiving device, so as to obtain the encrypted data of the mail transmission path;

[0051] Perform vulnerability scanning on the encrypted data of the mail transmission path, so as to obtain the encrypted vulnerability data of the mail transmission path;

[0052] Update the encryption protocol according to the encrypted vulnerability data of the mail transmission path, so as to obtain the updated data of the encryption protocol;

[0053] Update the transmission channel protocol for the encrypted data of the mail transmission path according to the updated data of the encryption protocol, so as to obtain the encrypted channel data of the receiving device.

[0054] By identifying the communication protocol of the receiving device data, the present invention can accurately obtain the type of communication protocol adopted by the receiving device. This provides a necessary basis for subsequent encryption evaluation and security analysis. Further analyzing the communication protocol data of the receiving device can evaluate the encryption of the mail transmission path, so as to ensure that the mail can effectively prevent mid-way leakage or tampering during the transmission process. This evaluation can determine whether there are potential transmission path vulnerabilities and whether the existing encryption scheme is strong enough to resist modern network attacks. Based on the evaluation of the encryption of the mail transmission path, vulnerability scanning is performed to identify security vulnerabilities existing in the encrypted path. This operation ensures the security of the entire mail transmission process, and weaknesses that appear in the encrypted channel are discovered and processed in a timely manner to prevent attackers from using these vulnerabilities for illegal access or data tampering. By updating the encryption protocol for the discovered vulnerability data, a more secure encryption protocol can be adopted for the existing vulnerabilities, further strengthening the data protection during the mail transmission process so that it can still maintain high-strength protection when facing more complex attack means. By updating the transmission channel protocol for the updated data of the encryption protocol, the updated encryption protocol can be effectively combined with the existing mail transmission path to ensure the consistency and compatibility of the mail transmission channel and the encryption protocol. This step can effectively improve the encryption ability of the mail system in different transmission channels, ensure that the entire process of the mail content from sending to receiving can be encrypted and protected, not only prevent data leakage during the transmission process, but also avoid network attack means such as man-in-the-middle attacks. By integrating the encrypted channel data of the receiving device, a comprehensive encryption protection scheme is formed, so that the encryption and secure transmission of e-mails are guaranteed, ensuring that all communication and encryption processes meet the highest security standards, providing users with efficient and reliable mail encryption services, improving the overall security of the mail system, and ensuring that the confidentiality and integrity of e-mails are protected to the greatest extent.

[0055] Optionally, step S4 is specifically as follows:

[0056] Step S41: Extract the features of email encryption failure based on the data processed by email encryption, so as to obtain the email encryption failure data;

[0057] Step S42: Extract the features of email encryption failure log from the email encryption failure data, so as to obtain the email encryption failure log data;

[0058] Step S43: Locate the hardware communication error according to the email encryption failure log data, so as to obtain the hardware communication error data;

[0059] Step S44: Conduct encryption simulation according to the hardware communication error data, so as to obtain the encryption simulation data;

[0060] Step S45: Extract the features of the hardware accelerator status from the encryption simulation data, so as to obtain the hardware accelerator status data;

[0061] Step S46: Identify the hardware performance bottleneck according to the hardware accelerator status data, so as to obtain the hardware acceleration error data.

[0062] The present invention can timely identify the failure situations occurring during the encryption process by extracting the characteristics of email encryption failures based on the data encrypted by emails. This step helps the system automatically discover the problems in the encryption operation, ensuring that the root causes of encryption failures can be quickly located and processed. Further, by extracting the characteristics of email encryption failure logs from the email encryption failure data, detailed error information can be extracted from the failure logs, providing more accurate data to help analyze the specific reasons for encryption failures. This process ensures the transparency of the email encryption operation, enabling the failure information of each encryption operation to be accurately recorded and analyzed. After identifying the encryption failure, localizing the hardware communication errors for the email encryption failure log data helps discover the problems at the hardware communication level. This step provides key data for the early detection of hardware failures, helping the operation and maintenance personnel quickly understand whether there are failures or unstable communication problems in the hardware devices. Then, using the hardware communication error data for encryption simulation, the response of the hardware device and the execution of the encryption algorithm can be tested by simulating the running process of the encryption task, thereby confirming whether the cooperation between the hardware and software is smooth. This simulation helps identify potential problems existing in the encryption process, providing a basis for subsequent fault repair and performance optimization. Extracting the characteristics of the hardware accelerator status from the encryption simulation data can comprehensively analyze the running status of the hardware accelerator. Especially when the encryption task is executed by the hardware accelerator, the running status of the hardware accelerator is crucial for encryption performance. This step ensures the monitoring of the accelerator status, timely discovering existing performance bottlenecks or hardware failures. After obtaining the hardware accelerator status data, further identifying the hardware performance bottlenecks can locate the specific reasons for the performance degradation or failure of the accelerator, such as insufficient processing capacity, resource bottlenecks, etc. By identifying the hardware acceleration errors, the performance of the hardware accelerator can be optimized or replaced to ensure that the encryption task can be completed efficiently and securely.

[0063] Optionally, step S43 is specifically as follows:

[0064] Step S431: Extract the characteristics of the encryption hardware module logs based on the email encryption failure log data, thereby obtaining the encryption hardware module log data;

[0065] Step S432: Identify the data transmission errors for the encryption hardware module log data, thereby obtaining the data transmission error data;

[0066] Step S433: Conduct load statistics on the encryption hardware module log data, thereby obtaining the high-load encryption hardware data;

[0067] Step S434: Conduct temperature statistics on the encryption hardware module log data, thereby obtaining the high-temperature encryption hardware data;

[0068] Step S435: Perform an intersection operation based on the high-load encrypted hardware data and the high-temperature encrypted hardware data to obtain encrypted hardware failure risk data;

[0069] Step S436: Conduct a correlation analysis based on the encrypted hardware failure risk data and the data transmission error data to obtain hardware communication error data.

[0070] Through feature extraction of the encrypted hardware module logs based on the email encryption failure log data, the present invention can accurately extract relevant features from the logs of the encrypted hardware module, helping to identify problems occurring in the encryption operation. This step provides detailed monitoring of the operating status of the hardware module, providing the necessary data support for subsequent problem diagnosis. Immediately following, identifying data transmission errors in the encrypted hardware module log data helps to discover data transmission problems during the encryption process. Data transmission errors can cause interruptions or incorrect decryption of the encryption task. Therefore, by identifying and fixing these problems early, the integrity and security of the data can be ensured. Performing a load statistics on the encrypted hardware module log data further helps to detect whether there is an overload situation in the hardware accelerator. High load can lead to a slowdown in the encryption speed and even cause the failure of the encryption process. The beneficial effect of this step is that it can identify the resource consumption situation of the hardware accelerator, providing a basis for performance optimization and resource scheduling. By performing a temperature statistics on the encrypted hardware module log data, the operating temperature of the encrypted hardware can be monitored to ensure that the hardware device operates within a reasonable temperature range. Excessive temperature can cause hardware failures or performance degradation. Therefore, through temperature statistics, the overheating situation of the encrypted hardware can be discovered in a timely manner, and corresponding cooling or protection measures can be taken to ensure the stability of the device. Performing an intersection operation on the high-load encrypted hardware data and the high-temperature encrypted hardware data helps to evaluate the encrypted hardware failure risk. High load and high temperature are usually precursors to hardware failures. By combining these two data points, potential failure risks can be identified more accurately. The beneficial effect of this process is that it can predict and prevent hardware failures in advance, avoiding the failure or delay of the encryption task due to hardware problems, thereby improving the reliability of the encryption system. Conducting a correlation analysis based on the encrypted hardware failure risk data and the data transmission error data can deeply explore the relationship between hardware failures and data transmission errors, providing a more systematic solution to the problems in the encryption process. Through correlation analysis, it can be identified whether a hardware failure is the root cause of a data transmission error, and then effective preventive measures can be taken. Generally speaking, this series of steps work together to be able to monitor the operating status of the hardware in real time, ensure the smooth progress of the encryption process, and reduce the risk of encryption failure caused by hardware problems, thereby improving the reliability and security of email encryption.

[0071] Optionally, this specification also provides an Internet data encryption system for performing the Internet data encryption method described above. The Internet data encryption system includes:

[0072] A mail character set conversion and encoding module, configured to obtain Internet mail system data, extract email sending characteristics based on the Internet mail system data to obtain email sending data; perform character set conversion and encoding on the email sending data to obtain email character set conversion and encoding data;

[0073] A hardware channel lock encryption analysis module, configured to extract email sender characteristics and email recipient characteristics based on Internet email data to obtain email sender data and email recipient data; perform hardware channel lock encryption analysis based on the email sender data and the email recipient data to obtain hardware channel lock encryption data;

[0074] An email encryption processing module, configured to generate an encryption key based on the hardware channel lock encryption data to obtain encryption key data; perform encryption processing on the email character set conversion and encoding data based on the encryption key data to obtain email encryption processing data;

[0075] A hardware acceleration error analysis module, configured to extract email encryption failure characteristics based on the email encryption processing data to obtain email encryption failure data; perform hardware acceleration error analysis based on the email encryption failure data to obtain hardware acceleration error data;

[0076] An encryption error recovery mechanism startup module, configured to start the encryption error recovery mechanism based on the hardware acceleration error data to obtain encryption error recovery mechanism data, and upload the encryption error recovery mechanism data to the Internet mail system to perform the mail data encryption task.

[0077] The Internet data encryption system of the present invention can implement any Internet data encryption method of the present invention. It is a medium for coordinating the operations and signal transmissions between various modules to complete the Internet data encryption method. The internal modules of the system cooperate with each other, thereby improving the success rate and security of mail data encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objectives, and advantages of the present invention will become more apparent:

[0079] Figure 1 It is a schematic flowchart of the steps of the Internet data encryption method of the present invention;

[0080] Figure 2It is a detailed step - by - step process schematic diagram of step S1 in the present invention;

[0081] Figure 3 It is a detailed step - by - step process schematic diagram of step S2 in the present invention;

[0082] The realization of the purpose, functional characteristics and advantages of the present invention will be further described in conjunction with embodiments with reference to the accompanying drawings. Detailed implementation manners

[0083] The technical method of the present invention patent will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work fall within the scope of protection of the present invention.

[0084] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the figures are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.

[0085] It should be understood that although terms such as "first", "second", etc. may be used here to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit can be called the second unit, and similarly the second unit can be called the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed related items.

[0086] To achieve the above - mentioned purpose, please refer to Figures 1 to 3 , the present invention provides an Internet data encryption method, and the method includes the following steps:

[0087] Step S1: Obtain Internet mail system data, extract email sending characteristics according to the Internet mail system data to obtain email sending data; perform character set conversion encoding according to the email sending data to obtain email character set conversion encoding data;

[0088] In this embodiment, obtaining the email data in the Internet email system mainly includes the email content, attachments, email header information, etc. of the sender. The email content can be accessed through the API from the email server or the email client, and relevant fields such as the sender, recipient, and email subject are extracted. Then, by identifying the character set of the email body content and attachments, the original email character set is identified and converted (for example, from ISO-8859-1 to UTF-8) to ensure that the email content does not get garbled during transmission between different devices and regions. The data in the email body and attachments is unified into a standard format through the process of standardizing the character set conversion encoding, so as to facilitate subsequent encryption processing. The data after character set conversion encoding is stored as a text file in a standard format or a data structure in JSON format, which is convenient for subsequent encryption operations.

[0089] Step S2: Extract the features of the email sender and the features of the email recipient based on the Internet email data, so as to obtain the email sender data and the email recipient data; perform hardware channel lock encryption analysis based on the email sender data and the email recipient data, so as to obtain the hardware channel lock encryption data;

[0090] In this embodiment, the features of the email sender and recipient are extracted. This includes, but is not limited to, information such as the sender's IP address, email client type, transmission protocols used (such as SMTP, IMAP, etc.), and email sending time. The recipient features include the type of email server it uses, receiving protocol, device information, etc. Through these features, potential security threats during the email sending and receiving processes can be identified. Next, hardware channel lock encryption analysis is performed based on these features. Hardware channel lock encryption analysis needs to combine the security design of the hardware devices of the sender and recipient (such as the encryption cards, encryption chips, etc. of the server), analyze whether there is support for hardware acceleration during the encryption process, and whether there are encryption channel lock protection measures such as physical isolation. During this process, hardware encryption analysis tools are used to check the security authentication information of the device, such as whether it complies with international security standards such as FIPS140-2, and evaluate whether the encryption channel lock is effective in combination with the working principle of the hardware device.

[0091] Step S3: Generate an encryption key based on the hardware channel lock encryption data, so as to obtain the encryption key data; perform an encryption process on the email character set conversion encoding data based on the encryption key data, so as to obtain the email encryption process data;

[0092] In this embodiment, data is encrypted according to the hardware channel lock, and a highly secure encryption algorithm (such as RSA or AES) is used to generate an encryption key. RSA, as an asymmetric encryption algorithm, is used for key exchange and key protection during the encryption process, while AES is used as a symmetric encryption algorithm for actual data encryption processing. When generating the key, the hardware key management system (such as HSM or TPM) plays a key role in ensuring the security of the key during generation, storage, and use, preventing the key from being illegally extracted or tampered with. HSM (Hardware Security Module) or TPM (Trusted Platform Module) provides hardware-level security for encryption operations, preventing the key from being stolen in memory or leaked through software vulnerabilities. The generated key is stored through the hardware security module and is subject to strict access control measures to ensure that only authorized entities can use or access these keys. The generated key will be used to encrypt email data. Before entering the encryption process, the email data will undergo character set conversion encoding (such as Base64 encoding or other standardized formats), converting the email body, attachments, and metadata from the original character set to a unified encoding format. This conversion process ensures that all email content will not cause garbled characters or parsing errors due to inconsistent character sets during subsequent processing. The converted email data will enter the encryption phase, and a symmetric encryption algorithm (such as AES) will be used to encrypt the email content. After the AES algorithm selects the key length (such as 128 bits, 192 bits, or 256 bits), a series of sub-keys are generated through the key scheduling algorithm, and these sub-keys are used for the encryption processing of data blocks to ensure that each data block can be encrypted independently and securely. During the encryption process, the email body content, attachment files, and email metadata (such as the sender, recipient, subject, etc.) will all be converted into ciphertext format, and these encrypted data are accelerated through the hardware acceleration module (such as GPU acceleration or a dedicated encryption card) to improve the encryption speed and efficiency. The encrypted email data will generate an encrypted file format, such as PGP, S / MIME, etc., to ensure that the email will not be intercepted or tampered with during network transmission. The encrypted email content, attachments, and all metadata will be encapsulated as ciphertext and stored as encrypted email data. This encryption process enhances the security of data encryption by encrypting each email data block and using different encryption modes (such as AES CBC mode, AES GCM mode, etc.), ensuring that the email cannot be decrypted or modified by unauthorized third parties during transmission. The key and encryption parameters (such as the initialization vector IV, authentication tag, etc.) will be encapsulated together with the email data to ensure the integrity, confidentiality, and authenticity of the email. The generated encrypted email data will be transmitted over a verified and encrypted network path to ensure that the email is not eavesdropped on, tampered with, or forged during transmission. Each link in the encryption process depends on high-security hardware support and the strict implementation of encryption algorithms to ensure that the confidentiality and integrity of the email are fully protected.

[0093] Step S4: Extract the characteristics of email encryption failure based on the data processed by email encryption to obtain email encryption failure data; perform hardware acceleration error analysis based on the email encryption failure data to obtain hardware acceleration error data;

[0094] In this embodiment, the data of encryption failure can be obtained through encryption logs, error messages or status monitoring tools. Usually, these data include error codes encountered during the encryption process, hardware resource utilization (such as CPU, memory usage, etc.). For failed encryption operations, detailed fault analysis is carried out to find the reasons for failure. Common error reasons include hardware acceleration errors, memory overflow, key errors, etc. By analyzing the encryption failure logs, use dedicated hardware fault diagnosis tools (such as monitoring tools, intelligent diagnosis software, etc.) to check whether the hardware accelerator fails to respond to the encryption request normally, whether there are interruptions or communication errors in the encryption calculation, etc. Finally, the hardware acceleration error data is obtained and used as a basis for subsequent repair.

[0095] Step S5: Start the encryption error recovery mechanism based on the hardware acceleration error data to obtain the encryption error recovery mechanism data, and upload the encryption error recovery mechanism data to the Internet email system to execute the email data encryption task.

[0096] In this embodiment, it includes regenerating the encryption key, restarting the encryption hardware device, adjusting the encryption algorithm parameters or switching to a different encryption hardware device, etc. Through the automated recovery mechanism, it can ensure that in the case of hardware acceleration failure, the system can quickly recover and complete the encryption task. The startup process of the recovery mechanism includes system self-diagnosis, adjusting the hardware configuration, updating the driver or adjusting the load, etc., to ensure the continuity and stability of the encryption process. The data obtained through the recovery mechanism will be uploaded to the Internet email system to execute the email data encryption task. The recovered encrypted data will be verified again to ensure that the encryption process is not interrupted and the email data can be encrypted and transmitted securely.

[0097] Optionally, step S1 is specifically:

[0098] Step S11: Obtain the Internet email system data, and extract the email sending characteristics based on the Internet email system data to obtain the email sending data;

[0099] In this embodiment, the data of email transmission is obtained by calling the API interface of the Internet email system, especially the metadata such as the sending time, sender, recipient, and email size of the email, as well as the email body and attachments. The email system will obtain the relevant data through the SMTP or IMAP protocol. After parsing this data, the characteristic data in the email sending process is extracted, including the sender's IP address, the length of the email content, the file type and size of the attachments, etc., and then the standardized email sending data is formed. These data will provide a basis for subsequent character set conversion and encryption processing.

[0100] Step S12: Identify the character set of the email body according to the email sending data, so as to obtain the original sending character set data of the email body;

[0101] In this embodiment, a character set detection algorithm is used to automatically analyze the content of the email body. First, the email body data is parsed through text, and pre-identified using common character sets such as UTF-8 and ISO-8859-1, and the actual character set of the email body is identified through algorithms (such as the chardet library or the python-charset-detector tool). By checking the character encoding identifier (such as the charset field in the Content-Type header information), or by analyzing the encoding method of common characters in the email body (such as English text, Chinese characters, etc.), the original character set data of the email body is determined, further providing a data basis for character set conversion.

[0102] Step S13: Perform unified conversion according to the original sending character set of the email body, so as to obtain the unified character set data for sending the email body;

[0103] In this embodiment, the original character set data of the email body is converted into a unified character set format through a character set conversion algorithm (such as using the iconv tool or the encode() method of Python), and UTF-8 is usually selected as the standard encoding format. According to the original character set of the email body, using the corresponding conversion rules, all email content is unified into the UTF-8 format to ensure that all characters can be correctly parsed. This conversion process needs to ensure that there is no loss or garbled characters between the source character set and the target character set, and perform exception handling for character mapping errors to ensure the integrity of the output character set data.

[0104] Step S14: Perform character set conversion on the email attachments according to the email sending data, so as to obtain the unified character set data for sending the email attachments;

[0105] In this embodiment, all attachment files in the email are extracted, and the file types of the attachments are identified. According to the types of the attachment files (such as PDF, Word, Excel, etc.), appropriate character sets are selected for parsing. The character sets of the attachment contents are identified by using file parsing tools (such as the PyPDF2 library for PDF and the python-docx library for Word). If the attachment contains text information, the same character set conversion technology as that of the email body is adopted to convert it into the UTF-8 format. If the attachment is a binary file (such as a picture, audio, etc.), this step will skip the character set conversion and directly process the binary data to ensure that the attachment data will not be affected during the email encryption process.

[0106] Step S15: Standardize and encode the unified character set data sent according to the email body and the unified character set data sent for the email attachment, so as to obtain the email character set conversion encoding data.

[0107] In this embodiment, after the email body and the attachments are respectively subjected to character set conversion, a unified standard encoding process will be carried out. In this process, Base64 encoding is used to process the email body and attachment data. Base64 encoding is a common method for processing binary data into ASCII characters, which can effectively prevent encoding problems from occurring during the transmission of the email content. When performing Base64 encoding on the email body and attachment data, the encoding lengths of the body and the attachments are calculated respectively, and they are combined into encrypted email data in a standardized format. This step ensures that all email data can have a unified encoding format before encryption and can be decoded and restored without misunderstanding at the email receiving end.

[0108] Optionally, step S2 is specifically as follows:

[0109] Step S21: Extract the characteristics of the email sender and the characteristics of the email recipient according to the Internet email data, so as to obtain the email sender data and the email recipient data;

[0110] In this embodiment, metadata during the email transmission process is extracted through an Internet email system (such as SMTP, IMAP), including information such as the sender's IP address, recipient address, email size, and transmission time. The email system parses the sender and recipient information and extracts their device characteristics (such as operating system, device model, network environment, etc.). For the email sender, the device IP and related SMTP client information are extracted through the SMTP protocol, and combined with the email sending time, attachment type, body content, etc., to form the device characteristic data of the email sender. For the recipient, the IMAP protocol is used to obtain the device characteristic data for email reception, such as the client version, network bandwidth at the time of email reception, etc. This process automatically extracts data using the email transmission protocol and formats it for storage as characteristic data, ensuring that the data structure is clear and standardized for subsequent analysis and processing.

[0111] Step S22: Perform side-channel attack prevention analysis based on the email sender data to obtain side-channel attack prevention data for the sending device;

[0112] In this embodiment, the hardware characteristic data of the email sender device is obtained, including the hardware specifications, encryption algorithm support, power consumption mode, etc. of the encryption modules (such as HSM, TPM, smart card, etc.) used by the device. A power consumption analysis instrument (such as an oscilloscope, current detector, etc.) is used to monitor the power consumption of the sender device, and observe whether there are power consumption fluctuations and leakage patterns during the encryption process. By analyzing the correlation between the power consumption data and the encryption operation, identify whether the device has the risk of being attacked by side channels. At the same time, check whether the device adopts hardware protection measures against side-channel attacks (such as hardware modules with side-channel protection design, tamper-proof packaging, etc.) to ensure that it complies with relevant security standards such as FIPS140-2 and prevent the leakage of key information. Compare all the extracted device data to generate side-channel attack prevention data for the sending device and provide data support for subsequent protection optimization.

[0113] Step S23: Perform encrypted channel analysis on the receiving device based on the email recipient data to obtain encrypted channel lock data for the receiving device;

[0114] In this embodiment, the device information of the email recipient is obtained, including data such as the hardware encryption module used by the device, the encryption protocol version, and the recipient's network environment. By analyzing the encryption algorithm used by the recipient and its encryption strength, it is checked whether it supports the hardware channel lock encryption protocol (such as encryption modules like TPM and HSM), and the strength of the encryption channel is evaluated. A protocol analysis tool (such as Wireshark or SSL Labs) is used to evaluate the encryption channel used during the email transmission process, analyze the encryption strength during the email data transmission process, whether there are potential vulnerabilities, and whether there is an unencrypted communication path. By comparing the support of the encryption transmission protocol with the actual capabilities of the receiving device, the weaknesses of the encryption channel are identified, and channel lock encryption data for the receiving device is generated based on these weaknesses, providing a basis for subsequent encryption enhancement.

[0115] Step S24: Integrate the hardware channel lock encryption based on the side-channel attack prevention data of the sending device and the channel lock encryption data of the receiving device, so as to obtain the hardware channel lock encryption data.

[0116] In this embodiment, by combining the side-channel protection measures of the sending device and the encryption channel capabilities of the receiving device, a comprehensive analysis of the encrypted transmission path of the entire email data is carried out. By correlating the side-channel attack prevention protection data of the sender with the encryption channel analysis data of the recipient, security vulnerabilities existing in the email transmission process are identified, and the encryption process is optimized. During the encryption integration process, a unified encryption evaluation standard (such as AES-256 or RSA, etc.) is used to evaluate the matching degree of the encryption algorithm and the encryption channel, ensuring that the security of the key is not threatened during the process of sending data to the recipient. Finally, optimized hardware channel lock encryption data is generated, which will serve as the basis for secure email transmission, ensuring the security and confidentiality of the email data transmission process.

[0117] Optionally, step S22 is specifically:

[0118] Step S221: Extract the sender device characteristics based on the email sender data, so as to obtain the sender device data;

[0119] In this embodiment, relevant data of the email sender is extracted from the Internet email system. The sender device data includes device type, operating system, hardware configuration, encryption support capabilities (such as whether there is a hardware encryption module (HSM) or whether TPM is supported, etc.). The device characteristics can be extracted by analyzing the email header information, device log files, and hardware identification codes (such as MAC address, CPU identifier, etc.). If some key information is missing in the device configuration file, it is supplemented with the device configuration file, system hardware information, operating system logs, etc. of the sending device to obtain complete device information. Step S222: Conduct electromagnetic field detection on the sender device data to obtain the electromagnetic field data of the sender device;

[0120] In this embodiment, a high-precision electromagnetic field detection instrument (such as an electromagnetic field detector, vector network analyzer) is used to detect the electromagnetic radiation of the sender device in real time. This process records the electromagnetic radiation information when the sending device is working normally. It is necessary to select an appropriate frequency range for monitoring according to the device usage frequency band and electromagnetic wave radiation characteristics. The specific operation includes placing the electromagnetic field detector around the device, selecting the frequency band where the monitored device is located (for example, the 2.4 GHz to 5 GHz frequency band), and recording the change in electromagnetic field intensity during the encryption operation. The detection instrument needs to be able to capture the electromagnetic radiation generated by the device in different working modes, including different radiation modes generated during the encryption and decryption processes.

[0121] Step S223: Generate an electromagnetic radiation curve based on the electromagnetic field data of the sender device to obtain electromagnetic radiation curve data;

[0122] In this embodiment, based on the electromagnetic radiation signal data obtained through electromagnetic field detection, a spectrum analyzer or signal processing software (such as MATLAB, LabVIEW) is used to generate an electromagnetic radiation curve. These curves represent the relationship between the electromagnetic field intensity and frequency of the sending device during a specific time period. First, the time-domain signal is converted into a frequency-domain signal through Fourier transform to obtain the spectral characteristics of the device during operation. The different frequency bands are analyzed in detail to extract the characteristic frequencies during the encryption operation, especially the radiation characteristics of the device during the encryption key generation and processing. The generated electromagnetic radiation curve data will help analyze the electromagnetic radiation pattern of the device when performing the encryption task.

[0123] Step S224: Conduct abnormal mode detection based on the electromagnetic radiation curve data to obtain radiation abnormal mode data;

[0124] In this embodiment, the detection of the radiation anomaly mode is carried out by setting a reference threshold for electromagnetic radiation. This threshold can be set according to historical data, laboratory measurements or standardized operations, and is usually the maximum value of the radiation signal intensity in the normal operating state of the device plus a certain margin. For example, the reference threshold can be set as the 95th percentile value of the electromagnetic radiation intensity when the device is operating normally. Anomaly detection algorithms (such as the clustering-based K-means algorithm, isolation forest, etc.) are used to process the radiation data to identify abnormal radiation patterns. According to the fluctuation characteristics of electromagnetic radiation, especially the changes in radiation during the encryption process, abnormal points inconsistent with the normal radiation pattern are marked. By further analyzing these abnormal data, leakage risk information related to the encryption operation is extracted.

[0125] Step S225: Perform a leakage risk assessment on the radiation anomaly mode data to obtain leakage risk data;

[0126] In this embodiment, it is determined whether the abnormal points are related to the generation and processing process of the encryption key. The leakage risk assessment is usually analyzed based on the correlation between the electromagnetic radiation pattern and known encryption algorithms. Machine learning algorithms (such as support vector machine SVM, decision tree, etc.) are used to classify the abnormal mode data to identify whether it is a potential key leakage mode. During the assessment process, a risk threshold is set. For example, when the signal intensity exceeds 5 times the set standard deviation value, it is marked as a high-risk area. The leakage risk data will provide a basis for further protection measures.

[0127] Step S226: Optimize the radiation protection of the sending device according to the leakage risk data to obtain data for the sending device to prevent side-channel attacks.

[0128] In this embodiment, according to the evaluated risk level, it is determined which parts of the device need enhanced protection. By adjusting the hardware configuration of the sending device, such as adding shielding materials, replacing the encryption module or optimizing the power supply design, the electromagnetic radiation leakage is reduced. For high-risk areas, electromagnetic shielding technology is applied or the electrical characteristics during the encryption process are changed to reduce the leakage signal. Further, by improving the heat dissipation design, strengthening the hardware components or using a more advanced encryption module (such as HSM) to reduce the radiation leakage. The radiation protection optimization measures of the sending device will enhance its resistance to side-channel attacks and ensure the secure transmission of encrypted information.

[0129] Optionally, step S224 is specifically:

[0130] Perform low-pass filtering and denoising on the electromagnetic radiation curve data to obtain denoised electromagnetic radiation curve data;

[0131] In this embodiment, the electromagnetic radiation curve data obtained from the electromagnetic radiation detection device will be filtered. A low-pass filter (such as Butterworth filter, Chebyshev filter) is used to process the signal. It is very important to select an appropriate cut-off frequency, which is usually set based on the operating frequency of the device and the known noise frequency characteristics. Assuming the cut-off frequency is 2 GHz, when the signal contains noise above this frequency, the low-pass filter will automatically filter out these high-frequency signals and retain the low-frequency part. In actual operation, tools such as MATLAB or Python are used to implement the filtering through the scipy.signal.butter function, and appropriate sampling frequency and cut-off frequency parameters are input to obtain the denoised electromagnetic radiation curve data.

[0132] The denoised data of the electromagnetic radiation curve is used to construct a normal electromagnetic radiation baseline, thereby obtaining normal electromagnetic radiation baseline data;

[0133] In this embodiment, the normal electromagnetic radiation baseline represents the electromagnetic radiation characteristics of the device in the normal operating state. Usually, the electromagnetic radiation data of the device is collected over multiple operating cycles, and then its average value or median value is calculated to obtain the normal radiation characteristics of the device. In actual operation, the electromagnetic radiation intensity values within each time period can be calculated, and these values are time-averaged, and a sliding window method (such as a 5-second window or a 10-second window) is used for smoothing processing to finally obtain the normal electromagnetic radiation baseline data. These data will be used as the benchmark for subsequent comparative analysis. This process requires long-term monitoring of the device without generating abnormal signals to ensure the accuracy of the baseline.

[0134] The denoised data of the electromagnetic radiation curve is compared with the normal electromagnetic radiation baseline according to the normal electromagnetic radiation baseline data, thereby obtaining abnormal electromagnetic radiation deviation baseline data;

[0135] In this embodiment, the difference between each data point and the baseline is calculated. If some data points on the electromagnetic radiation curve deviate from the baseline by more than the set threshold, they are marked as abnormal. These deviation data will form abnormal electromagnetic radiation deviation baseline data. The threshold is set according to the operating characteristics of the device. For example, if the electromagnetic radiation intensity of the baseline fluctuates within the range of ±5%, the deviation threshold is set to 10%. The selection of this threshold can be adjusted based on experimental data or standardized signal characteristics. In actual operation, the difference is calculated through the numpy library in Python and conditional statements are used to identify outliers to generate a dataset of deviations from the baseline.

[0136] Locate the abnormal points in the abnormal electromagnetic radiation deviation baseline data, and the electromagnetic radiation deviation data of the abnormal points;

[0137] In this embodiment, an algorithm (such as a detection method based on standard deviation or a clustering analysis method) is used to identify which data points are outliers. If the deviation degree of certain data points is greater than 3 standard deviations of the benchmark threshold, they are regarded as outliers. The electromagnetic radiation deviation data of the outliers are these data points with relatively large deviation degrees. The zscore function in the scipy library can be used to calculate the standard deviation, and the outlier data points are screened based on the set threshold. By graphically displaying the relationship between the data and the outliers, the positions and fluctuations of these points are further confirmed.

[0138] Based on the electromagnetic radiation deviation data of the outliers, the abnormal pattern is divided to obtain the radiation abnormal pattern data.

[0139] In this embodiment, a clustering algorithm (such as K-means or DBSCAN) is used to cluster the outlier data to identify different existing abnormal patterns. By analyzing these abnormal patterns, it is judged whether they are related to the encryption process or other operations of the device. Each abnormal pattern can be characterized by features such as electromagnetic radiation intensity, frequency characteristics, and fluctuation patterns. In actual operation, sklearn.cluster.KMeans can be used to cluster the data, specify an appropriate number of clusters and adjust the hyperparameters of the algorithm, so as to obtain different radiation abnormal pattern data. These pattern data provide an important basis for subsequent risk assessment and protection optimization.

[0140] Optionally, step S23 is specifically as follows:

[0141] Step S231: Extract the receiver device features according to the email receiver data to obtain the receiver device data;

[0142] In this embodiment, the hardware features of the device are extracted, such as the operating system, processor architecture, memory capacity, storage space, network interface, etc. These device features help to understand the system performance of the receiver and the existing security problems. Device identification technology is adopted to extract features by checking the operating system information of the device (such as Windows, Linux, Android, iOS, etc.), hardware ID, device model and other unique identifiers. The device information can be extracted through device management tools or operating system APIs (such as Windows Management Instrumentation WMIC, the lsusb command in Linux, etc.). These information will be converted into structured data, stored as the receiver device data, and provide support for subsequent steps.

[0143] Step S232: Analyze the encrypted channels of the receiver device data to obtain the receiver device encrypted channel data;

[0144] In this embodiment, the communication protocols used in the email transmission process (such as SMTP, IMAP, POP3, etc.) and the corresponding encryption standards (such as TLS, SSL, etc.) are analyzed. The TLS handshake process in network communication can be monitored through network packet capture tools (such as Wireshark or tcpdump) to obtain the encryption algorithm and protocol version (such as TLS1.2, TLS1.3, etc.). Then, based on the information extracted from the device data and combined with the characteristics of the communication protocol, the security of the encrypted channel is evaluated. If weak encryption is used in the communication process (such as TLS1.0), this can be recorded as a potential security risk, and finally, the encrypted channel data of the receiving device is generated.

[0145] Step S233: Perform statistics on the encryption algorithms of the receiving device according to the encrypted channel data of the receiving device, so as to obtain the encryption algorithm data of the receiving device;

[0146] In this embodiment, the types of encryption algorithms used by the receiving device (such as AES, RSA, ECC, etc.) and their parameters (such as key length, encryption mode, etc.) are identified and confirmed. By analyzing the data packets in the encryption negotiation process, the types and configurations of the encryption algorithms are identified. Tools such as OpenSSL can be used for encryption protocol parsing, or custom scripts (such as the cryptography library in Python) can be written to analyze the encryption protocols and algorithms involved in the email transmission process. Finally, the collected encryption algorithm data will be provided for the selection and optimization of subsequent encryption policies.

[0147] Step S234: Divide the receiving device data according to the device type to obtain the PC device data and the mobile device data;

[0148] In this embodiment, the receiving device data is classified according to its hardware characteristics into PC devices and mobile devices. The device type is identified according to the hardware specifications of the device, such as screen size, operating system, processing power, etc. For example, the device type (such as Windows, macOS, Android, iOS, etc.) and processor information of the device are used to determine whether the device is a PC device or a mobile device. Device management tools or APIs within the operating system can be used (for example, through the sysctl command in iOS or the wmic cpu get command in Windows) to identify the hardware characteristics and perform type classification. The device type classification data will be used as the basis for encrypting algorithm allocation in subsequent steps.

[0149] Step S235: Allocate the PC encryption algorithm to the PC device data according to the encryption algorithm data of the receiving device, so as to obtain the PC encryption algorithm data;

[0150] In this embodiment, the encryption algorithm to be used is determined by analyzing the characteristics of the PC device (such as performance requirements, encryption standards supported by the system, etc.). For example, when processing a PC device with higher performance, a stronger encryption algorithm (such as AES-256, RSA-2048, etc.) can be selected. For devices with weaker computing power, a lighter encryption algorithm will be chosen. In this process, factors such as device performance, encryption strength, and encryption and decryption speed must be considered to select the optimal encryption solution. Through this allocation method, encryption algorithm data for the PC device is generated to meet the encryption requirements of the device.

[0151] Step S236: Allocate the mobile encryption algorithm to the mobile device data according to the recipient device encryption algorithm data, so as to obtain the mobile encryption algorithm data;

[0152] In this embodiment, since mobile devices usually have limited performance, especially with certain constraints in processing power and memory usage, the selection of the encryption algorithm will consider these limitations. Common mobile encryption algorithms include AES-128, ECC (Elliptic Curve Cryptography), etc. Usually, the algorithm is optimized to reduce the computational load and improve the encryption efficiency. The most suitable encryption algorithm can be selected by analyzing the hardware information of the mobile device (such as CPU performance, memory size, etc.) and the support of the mobile operating system for the encryption algorithm. The generated mobile encryption algorithm data will be used for the configuration of subsequent encryption operations.

[0153] Step S237: Integrate the recipient device channel lock encryption according to the PC encryption algorithm data and the mobile encryption algorithm data, so as to obtain the recipient device channel lock encryption data.

[0154] In this embodiment, according to the collected encryption algorithm data, it is determined which encryption standards need to be used for data transmission between the PC and the mobile device. By establishing an adapter layer, the PC and mobile devices can use a unified encryption strategy when communicating via the Internet mail system. The encryption process involves encrypting the mail content and attachments, encrypting the transmission channel, and encrypting the key exchange. In this step, the finally generated recipient device channel lock encryption data ensures the security of encrypted communication of emails.

[0155] Optionally, step S232 is specifically:

[0156] Identify the communication protocol of the recipient device data, so as to obtain the recipient device communication protocol data;

[0157] In this embodiment, the network protocol stack information of the extraction device includes the protocols of the transport layer and the application layer. By capturing the data packets used during email transmission by the receiving device (such as SMTP, IMAP, or POP3 protocols), the encryption protocols used during the communication process (such as SSL, TLS, etc.) are identified. In specific operations, data packets during the email transmission process are analyzed using network packet capture tools (such as Wireshark, tcpdump) to extract the protocol version, handshake process, and encryption method. By analyzing data such as TLS handshake information, certificate information, and encryption suites, the encryption protocol used in the email transmission path is confirmed and further classified into types using encryption protocols such as SSL and TLS. After identification, communication protocol data of the receiving device is generated for subsequent email transmission path encryption evaluation.

[0158] Based on the communication protocol data of the receiving device, an encryption evaluation of the email transmission path is performed to obtain email transmission path encryption data;

[0159] In this embodiment, based on the protocols and their versions used during the email transmission process, the encryption strength and security are evaluated. For example, it is checked whether the TLS protocol uses strong encryption suites such as AES-256, RSA2048, etc. This process can determine the encryption strength by analyzing the encryption suite selection in the communication protocol (such as AES-GCM, ECDHE, etc.). At the same time, it is verified whether the receiving device supports the latest TLS version (such as TLS1.3) and whether a complete encryption mechanism such as Forward Secrecy is enabled. The goal of the encryption evaluation is to ensure that the data on the email transmission path can be protected during the mid-transmission process and is not affected by potential man-in-the-middle attacks (MITM). The encryption evaluation data of the email transmission path will provide a basis for subsequent vulnerability scanning and encryption protocol updates.

[0160] A vulnerability scan is performed on the email transmission path encryption data to obtain email transmission path encryption vulnerability data;

[0161] In this embodiment, a vulnerability scanning tool (such as Nessus, OpenVAS, Qualys) is used to comprehensively scan the email transmission path of the receiving device. During the scanning process, it is checked whether there are known vulnerabilities in the communication protocol, such as known vulnerabilities in the SSL / TLS protocol (such as Heartbleed, POODLE attacks, etc.). In addition, it is evaluated whether the encryption protocol of the email transmission path complies with the latest security standards, and it is detected whether outdated encryption algorithms or algorithms with insufficiently secure key lengths are used. The scan will also check for protocol downgrade attacks (such as SSL 3.0 being downgraded to the insecure TLS1.0). The vulnerability scan results generate email transmission path encryption vulnerability data, which will be used for subsequent decisions on encryption protocol updates.

[0162] Update the encryption protocol based on the encrypted vulnerability data of the mail transfer path to obtain encrypted protocol update data;

[0163] In this embodiment, analyze the vulnerability scan results and adjust the existing encryption protocol according to the discovered vulnerabilities. Check whether known insecure protocols (such as SSL 2.0, SSL 3.0) are used. If so, it is recommended to upgrade to TLS1.2 or TLS 1.3 to ensure higher encryption strength. Secondly, check whether there are weak encryption algorithms such as RC4 and 3DES. If so, they need to be replaced with stronger algorithms (such as AES-GCM, ChaCha20, etc.). This process needs to follow the latest encryption standards and industry best practices (such as NIST SP 800-57). By updating the encryption protocol and key exchange algorithm, ensure the security of the mail transfer path. The generated encrypted protocol update data will be used to better protect the encryption path of the receiving device and provide information for the update of the transmission channel protocol.

[0164] Update the transmission channel protocol for the encrypted data of the mail transfer path according to the encrypted protocol update data to obtain the encrypted channel data of the receiving device.

[0165] In this embodiment, the purpose of updating the transmission channel protocol is to ensure that the mail communication protocol of the receiving device can effectively respond to current security threats. The specific operations include configuring a new version of the TLS protocol for the receiving device, replacing outdated encryption suites, and forcibly enabling Perfect Forward Secrecy. At the same time, ensure that each node (such as mail servers, clients, etc.) in the mail transfer path adopts the updated encryption protocol. In this way, the encryption strength of the data during the mail transmission process can be effectively improved, and data leakage or tampering caused by the use of weak encryption algorithms or outdated protocols can be avoided. The updated encrypted channel data of the receiving device will ensure the confidentiality, integrity, and authentication of the communication, ultimately enhancing the overall data transmission security.

[0166] Optionally, step S4 is specifically as follows:

[0167] Step S41: Extract the characteristics of email encryption failure based on the email encryption processing data to obtain email encryption failure data;

[0168] In this embodiment, an email encryption log is read by a log parsing tool (such as Logstash, ElasticSearch, or a custom Python script). The information contained in the log includes error codes, timestamps, encryption algorithm types, key lengths, encryption status, etc. By comparing these log records with known encryption algorithm implementations, failure characteristics are located. For example, by parsing the "error_code" field in the error log, it is identified whether the encryption failure is caused by issues such as mismatched key lengths, hardware accelerator failures, timeouts, etc. According to the hardware resources involved in the log information, the error type is extracted. For each failed encryption task, the corresponding failure characteristics (such as encryption time, hardware resources used, etc.) are recorded, and encryption failure data is generated for subsequent analysis.

[0169] Step S42: Extract email encryption failure log characteristics from the email encryption failure data to obtain email encryption failure log data;

[0170] In this embodiment, these log records will include error types, hardware usage, protocol versions, key management status, etc. By using a log parsing tool or a custom script, each error code is processed, and the corresponding hardware status information (such as whether the hardware accelerator responds, whether the key storage is normal, etc.) is extracted. For example, when parsing the log file, the "error_type" and "timestamp" fields are extracted to check whether problems such as hardware module downtime, overload, or communication interruption have occurred, and further these failure log characteristics are extracted and classified as encryption failure log data.

[0171] Step S43: Locate hardware communication errors based on the email encryption failure log data to obtain hardware communication error data;

[0172] In this embodiment, by comparing the log data of the encryption failure with the hardware interface monitoring data (such as I2C, USB, PCIe communication logs), errors in the hardware communication are located. If a communication failure occurs during the encryption process, it is because the hardware acceleration module fails to correctly respond to the request or the interface is interrupted. Hardware monitoring tools (such as hardware monitoring cards, JTAG debugging tools, USB monitoring tools) are used to detect the hardware communication status in real time. Further analyze the time, frequency, and error codes of the hardware communication interruption to confirm whether the communication error is caused by hardware devices, transmission protocols, or power supply problems, and record these hardware communication errors as hardware communication error data.

[0173] Step S44: Perform encryption simulation based on the hardware communication error data to obtain encryption simulation data;

[0174] In this embodiment, encryption operations are simulated through simulation tools (such as OpenSSL, PyCrypto, hardware simulation software, etc.), especially for testing under incorrect communication conditions. First, communication problems between the hardware accelerator and the host during encryption are simulated according to hardware communication error data. Different hardware resource loads, communication bandwidths, or encryption algorithms (such as RSA, AES, etc.) can be simulated to observe whether encryption failures are related to insufficient hardware resources or hardware communication problems. Based on the simulation results, the results of each test case are recorded, including the latency, failure rate, hardware response time, etc. during the encryption process, and encryption simulation data is generated, which provides a basis for subsequent extraction of the state characteristics of the hardware accelerator.

[0175] Step S45: Extract the state characteristics of the hardware accelerator from the encryption simulation data to obtain the hardware accelerator state data;

[0176] In this embodiment, a hardware monitoring tool (such as NVIDIA Nsight, Intel VTune, hardware diagnostic tool) is used to collect the operating state of the hardware accelerator during the encryption process. These tools can provide metrics such as the load, temperature, memory usage, processing speed, etc. of the hardware accelerator. Specifically, the working state of the hardware accelerator during each encryption operation is extracted, including information such as the core temperature, power consumption, number of executed instructions, memory bandwidth, etc. For each hardware resource, these state data are obtained through multiple encryption tests and classified. Finally, all these state data of the hardware accelerator will be used to evaluate the performance of the hardware during the encryption process to determine whether there are bottlenecks or faults.

[0177] Step S46: Identify the hardware performance bottleneck based on the hardware accelerator state data to obtain the hardware acceleration error data.

[0178] In this embodiment, a hardware performance analysis tool (such as Intel VTune, NVIDIA Nsight) is used for in-depth analysis to identify the bottlenecks of hardware resources during the encryption operation. For example, check the load conditions of the GPU or TPM module to determine whether there is a shortage of computing resources, or whether the memory bandwidth limit affects the encryption speed. By analyzing the operation data of each hardware acceleration module, the performance bottleneck is identified. For example, if the CPU core temperature of the hardware accelerator is too high or the memory usage rate is close to the upper limit, it will affect the execution efficiency or stability of the encryption task. Through these analyses, hardware acceleration error data is obtained, indicating the specific hardware problems that cause encryption failures, such as overload, overheating, or memory bottleneck.

[0179] Optionally, step S43 is specifically:

[0180] Step S431: Extract the log features of the encryption hardware module based on the email encryption failure log data, so as to obtain the encryption hardware module log data;

[0181] In this embodiment, a log parsing tool (such as ElasticSearch, Logstash, the log processing library of Python) is used to read the encryption failure log. The fields in the log include the reason for encryption failure, the usage of hardware resources, the type of encryption algorithm, the key length, the encryption time, etc. By parsing the "error_code" field and the "hardware_resource_status" field, the relevant hardware module information is extracted. The encryption hardware module usually includes a hardware security module (HSM), a TPM, an encryption chip, etc., and their operating status and error codes can be reflected in the log. Further screen out the log records of each encryption failure, and extract the detailed features related to the encryption hardware in each record, such as the type, working status, processing capacity, etc. of the encryption module.

[0182] Step S432: Identify data transmission errors in the encryption hardware module log data, so as to obtain data transmission error data;

[0183] In this embodiment, the relevant data extracted from the encryption hardware module log is analyzed to identify data transmission errors. By checking the transmission error flag in the log (such as the "communication_error" flag in the "error_type" field), the transmission-related information in each encryption failure log is screened and analyzed. A log analysis tool (such as Splunk, Logstash) is used for filtering to find the log data related to the communication error of the hardware accelerator. For example, by matching the "error_message" field, check whether it contains keywords such as "timeout", "connection_refused", "data_corruption", etc., to identify the specific reasons for data transmission failure. Through these transmission error feature extractions, data transmission error data is obtained, providing data support for subsequent hardware fault analysis.

[0184] Step S433: Perform load statistics on the encryption hardware module log data, so as to obtain high-load encryption hardware data;

[0185] In this embodiment, by using a log analysis tool (such as Elasticsearch or a custom Python script), the usage fields of hardware resources are extracted, such as "cpu_usage", "memory_usage", "gpu_usage", etc. By setting thresholds (for example, when the CPU load exceeds 90%, it is considered a high load), these fields are statistically analyzed to identify the load conditions during each encryption process. Specifically, a threshold is set (for example, when the CPU usage exceeds 80%, it is considered "high load"), and then the load data of each task in the encryption log is compared, and the high load conditions exceeding the threshold are recorded. Further analyze the status of these high-load encryption hardware to generate "high-load encryption hardware data" and provide necessary performance bottleneck identification information for subsequent analysis.

[0186] Step S434: Perform temperature statistics on the log data of the encryption hardware module to obtain high-temperature encryption hardware data;

[0187] In this embodiment, the encryption hardware module usually records its operating temperature and records relevant information in the log (such as the "temperature" and "temperature_status" fields). Use a log analysis tool (such as Kibana, Logstash) to extract the temperature data of each encryption task and compare it with the set temperature threshold (for example, when the temperature exceeds 85°C, it is considered high temperature). If the temperature data in the log exceeds the set threshold, mark the task as a "high-temperature task" and record the relevant high-temperature encryption hardware data. In this way, it can be identified whether the hardware performance drops due to the high temperature during the encryption task, further analyze whether the high temperature is related to the encryption failure, and finally generate high-temperature encryption hardware data for subsequent analysis.

[0188] Step S435: Perform an intersection operation based on the high-load encryption hardware data and the high-temperature encryption hardware data to obtain encryption hardware failure risk data;

[0189] In this embodiment, use a data analysis tool (such as the Pandas library of Python or SQL query) to merge the high-load and high-temperature data to find the encryption tasks that occur simultaneously under high-load and high-temperature conditions. Set a threshold condition for an encryption task, such as when the load and temperature of the hardware both exceed a predetermined value, it is marked as a high-risk state. Through intersection analysis, identify those encryption tasks that are both in a high-load state and a high-temperature state. These tasks are considered high-risk and may cause hardware failures or encryption failures. Generate "encryption hardware failure risk data", which can provide a basis for the maintenance, optimization, and upgrade of the hardware.

[0190] Step S436: Perform correlation analysis based on the encrypted hardware failure risk data and the data transmission error data to obtain hardware communication error data.

[0191] In this embodiment, the encrypted hardware failure risk data and the data transmission error data are combined for correlation analysis to identify potential causes of hardware communication errors. Through a data correlation analysis tool (such as R, Scikit-learn in Python, or SQL JOIN operation), the encrypted hardware failure risk data and the data transmission error data are matched to find the correlation between hardware load, temperature, failure risk, and transmission errors. By analyzing these data, it can be determined whether data transmission errors frequently occur under certain hardware failures or high loads. For example, by combining the relationship between overheating, excessive hardware load, and communication interruption, it is analyzed whether there is a direct causal link. Finally, "hardware communication error data" is generated, providing data support for subsequent hardware performance optimization and system adjustment.

[0192] Optionally, this specification also provides an Internet data encryption system for executing the Internet data encryption method described above. The Internet data encryption system includes:

[0193] A mail character set conversion and encoding module for obtaining Internet mail system data, extracting email sending characteristics based on the Internet mail system data to obtain email sending data; performing character set conversion and encoding on the email sending data to obtain email character set conversion and encoding data;

[0194] A hardware channel lock encryption analysis module for extracting email sender characteristics and email recipient characteristics based on Internet email data to obtain email sender data and email recipient data; performing hardware channel lock encryption analysis based on the email sender data and the email recipient data to obtain hardware channel lock encryption data;

[0195] An email encryption processing module for generating an encryption key based on the hardware channel lock encryption data to obtain encryption key data; encrypting the email character set conversion and encoding data based on the encryption key data to obtain email encryption processing data;

[0196] A hardware acceleration error analysis module for extracting email encryption failure characteristics based on the email encryption processing data to obtain email encryption failure data; performing hardware acceleration error analysis based on the email encryption failure data to obtain hardware acceleration error data;

[0197] An encryption error recovery mechanism startup module is used to start the encryption error recovery mechanism based on hardware acceleration error data, thereby obtaining encryption error recovery mechanism data and uploading the encryption error recovery mechanism data to the Internet mail system to perform mail data encryption tasks.

[0198] The Internet data encryption system of the present invention can implement any Internet data encryption method of the present invention and is used as a medium for coordinating operations and signal transmissions between various modules to complete the Internet data encryption method. The internal modules of the system cooperate with each other, thereby improving the success rate and security of mail data encryption.

[0199] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the application documents are intended to be encompassed within the present invention.

[0200] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. A method for encrypting Internet data, characterized in that: The following steps are involved: Step S1: obtaining Internet mail system data, and extracting email sending features based on the Internet mail system data, thereby obtaining email sending data; Performing character set conversion encoding according to the email sending data, thereby obtaining email character set conversion encoding data; Step S2: extracting email sender features and email receiver features based on Internet email data, thereby obtaining email sender data and email receiver data; Performing hardware channel lock encryption analysis based on email sender data and email receiver data, thereby obtaining hardware channel lock encrypted data; Step S3: Generate an encryption key according to the hardware channel lock encryption data, thereby obtaining encryption key data; Encrypting the email character set conversion encoded data according to the encryption key data, thereby obtaining the email encrypted data; Step S4: extracting email encryption failure features based on the email encryption processing data, thereby obtaining email encryption failure data; performing hardware acceleration error analysis based on the email encryption failure data, thereby obtaining hardware acceleration error data; Step S5: The encryption error recovery mechanism is started according to the hardware acceleration error data, thereby obtaining encryption error recovery mechanism data, and uploading the encryption error recovery mechanism data to the Internet mail system to execute the mail data encryption task.

2. The Internet data encryption method according to claim 1, characterized in that: Step S1 is specifically as follows: Step S11: acquiring Internet mail system data, and extracting email sending features based on the Internet mail system data, thereby obtaining email sending data; Step S12: performing email body character set recognition according to the email sending data, thereby obtaining the original sending character set data of the email body; Step S13: performing a unified conversion according to the original sending character set of the email body, thereby obtaining the email body sending unified character set data; Step S14: performing email attachment character set conversion according to the email sending data, thereby obtaining email attachment sending unified character set data; Step S15: performing standardized encoding according to the unified character set data sent in the email body and the unified character set data sent in the email attachment, thereby obtaining email character set conversion encoding data.

3. The Internet data encryption method according to claim 1, characterized in that: Step S2 is specifically as follows: Step S21: extracting email sender features and email receiver features based on Internet email data, thereby obtaining email sender data and email receiver data; Step S22: performing side channel attack prevention analysis based on the email sender data, thereby obtaining sending device side channel attack prevention data; Step S23: performing receiving device encryption channel analysis according to the email recipient data, thereby obtaining receiving device channel lock encryption data; Step S24: Perform hardware channel lock encryption integration according to the side channel attack protection data of the sending device and the channel lock encryption data of the receiving device, so as to obtain the hardware channel lock encryption data.

4. The Internet data encryption method according to claim 3, characterized in that: Step S22 is specifically as follows: Step S221: extracting sender device features according to the email sender data, thereby obtaining the sender device data; Step S222: Perform electromagnetic field detection on the sender device data to obtain the electromagnetic field data of the sender device; Step S223: generating an electromagnetic radiation curve according to the electromagnetic field data of the sending device, thereby obtaining electromagnetic radiation curve data; Step S224: performing abnormal pattern detection according to the electromagnetic radiation curve data, thereby obtaining radiation abnormal pattern data; Step S225: performing leakage risk assessment on the radiation abnormality pattern data to obtain leakage risk data; Step S226: Optimize the radiation protection of the sending device according to the leakage risk data, so as to obtain the side channel attack protection data of the sending device.

5. The Internet data encryption method according to claim 4, characterized in that: Step S224 is specifically as follows: Perform low-pass filtering and denoising on the electromagnetic radiation curve data, thereby obtaining electromagnetic radiation curve denoised data; The electromagnetic radiation curve denoising data is used to construct a normal electromagnetic radiation baseline, thereby obtaining normal electromagnetic radiation baseline data; According to the normal electromagnetic radiation baseline data, the electromagnetic radiation curve denoised data is compared with the abnormal deviation baseline, so as to obtain the abnormal electromagnetic radiation deviation baseline data; The abnormal point location of abnormal electromagnetic radiation deviation from the baseline data is carried out, and the abnormal point electromagnetic radiation deviation data is carried out; Abnormal patterns are divided according to the electromagnetic radiation deviation data of abnormal points, so as to obtain radiation abnormal pattern data.

6. The Internet data encryption method according to claim 3, characterized in that: Step S23 is specifically as follows: Step S231: extracting the recipient's device features according to the email recipient's data, thereby obtaining the recipient's device data; Step S232: performing encryption channel analysis on the receiving device data, thereby obtaining the receiving device encryption channel data; Step S233: performing encryption algorithm statistics of the receiving device according to the encryption channel data of the receiving device, thereby obtaining encryption algorithm data of the receiving device; Step S234: classifying the device types according to the receiving device data, thereby obtaining PC-end device data and mobile-end device data; Step S235: assigning a PC-side encryption algorithm to the PC-side device data according to the receiving-side device encryption algorithm data, thereby obtaining the PC-side encryption algorithm data; Step S236: assigning a mobile end encryption algorithm to the mobile end device data according to the receiving end device encryption algorithm data, thereby obtaining the mobile end encryption algorithm data; Step S237: Perform receiving device channel lock encryption integration according to the PC-side encryption algorithm data and the mobile-side encryption algorithm data, thereby obtaining receiving device channel lock encryption data.

7. The Internet data encryption method according to claim 6, characterized in that: Step S232 is specifically as follows: Perform communication protocol identification on the receiving device data, thereby obtaining the receiving device communication protocol data; Performing an encryption evaluation of the mail transmission path according to the communication protocol data of the receiving device, thereby obtaining the encrypted data of the mail transmission path; Perform vulnerability scanning on the encrypted data of the mail transmission path, thereby obtaining the encryption vulnerability data of the mail transmission path; The encryption protocol is updated according to the encryption vulnerability data of the mail transmission path, thereby obtaining the encryption protocol update data; The transmission channel protocol is updated for the encrypted data of the mail transmission path according to the encryption protocol update data, thereby obtaining the encrypted channel data of the receiving device.

8. The Internet data encryption method according to claim 1, characterized in that: Step S4 is specifically as follows: Step S41: extracting email encryption failure features based on the email encryption processing data, thereby obtaining email encryption failure data; Step S42: extracting email encryption failure log features from the email encryption failure data, thereby obtaining email encryption failure log data; Step S43: locating the hardware communication error according to the email encryption failure log data, thereby obtaining the hardware communication error data; Step S44: performing encryption simulation according to the hardware communication error data, thereby obtaining encrypted simulation data; Step S45: extracting hardware accelerator state features from the encrypted simulation data, thereby obtaining hardware accelerator state data; Step S46: Identify the hardware performance bottleneck according to the hardware accelerator status data, thereby obtaining hardware acceleration error data.

9. The Internet data encryption method according to claim 8, characterized in that: Step S43 is specifically as follows: Step S431: extracting encryption hardware module log features according to the email encryption failure log data, thereby obtaining encryption hardware module log data; Step S432: performing data transmission error identification on the encryption hardware module log data, thereby obtaining data transmission error data; Step S433: performing load statistics on the encryption hardware module log data, thereby obtaining high-load encryption hardware data; Step S434: performing temperature statistics on the encryption hardware module log data, thereby obtaining high-temperature encryption hardware data; Step S435: performing an intersection operation according to the high-load encryption hardware data and the high-temperature encryption hardware data, thereby obtaining encryption hardware failure risk data; Step S436: performing correlation analysis based on the encrypted hardware failure risk data and the data transmission error data to obtain hardware communication error data.

10. An Internet data encryption system, characterized in that: Used to execute the Internet data encryption method as claimed in claim 1, the Internet data encryption system comprises: The mail character set conversion and encoding module is used to obtain Internet mail system data, and perform email sending feature extraction based on the Internet mail system data, thereby obtaining email sending data; perform character set conversion and encoding based on the email sending data, thereby obtaining email character set conversion and encoding data; The hardware channel lock encryption analysis module is used to extract the email sender's features and the email receiver's features based on the Internet email data, so as to obtain the email sender's data and the email receiver's data; perform hardware channel lock encryption analysis based on the email sender's data and the email receiver's data, so as to obtain the hardware channel lock encrypted data; The e-mail encryption processing module is used to generate an encryption key according to the hardware channel lock encryption data, thereby obtaining encryption key data; encrypt the e-mail character set conversion encoding data according to the encryption key data, thereby obtaining e-mail encryption processing data; The hardware accelerated error analysis module is used to extract the features of email encryption failure according to the email encryption processing data, thereby obtaining the email encryption failure data; perform hardware accelerated error analysis according to the email encryption failure data, thereby obtaining the hardware accelerated error data; The encryption error recovery mechanism startup module is used to start the encryption error recovery mechanism according to the hardware acceleration error data, thereby obtaining the encryption error recovery mechanism data, and uploading the encryption error recovery mechanism data to the Internet mail system to perform the mail data encryption task.