Multi-path network communication security guarantee method based on adaptive encryption algorithm
By using adaptive encryption algorithms and trust evaluation models in network security monitoring, dynamically adjusting the communication security level and encryption strength, the static problem of network security monitoring and encryption policies in traditional methods is solved, and more efficient and secure network communication is achieved.
Patent Information
- Application Number
- CN202510305986.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-13
AI Technical Summary
Traditional network security monitoring methods cannot adapt to changes in network state in real time, node trust levels rely on hard coding strategies, lack dynamic monitoring and behavioral analysis, and the encryption strength is fixed, resulting in waste of performance or insufficient encryption strength.
The multi-path network communication security guarantee method based on adaptive encryption algorithm is adopted. By obtaining the network undirected graph, the behavioral characteristics of the second node are extracted, the trust level is evaluated using a pre-trained trust classification model, and the communication security level and encryption level are determined based on the security status and trust level of the first node, so as to dynamically select the encryption algorithm and adjust the encryption strength.
It realizes dynamic adjustment of communication security level according to actual conditions, improve network security, identify potential security threats, reduce data leakage and attack risks, avoids the problems of performance waste and insufficient encryption strength in traditional methods, and improves data transmission efficiency while ensuring security.
Smart Images

Figure CN120151035A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security monitoring, and particularly relates to a multi-path network communication security guarantee method based on an adaptive encryption algorithm. Background Art
[0002] In traditional methods, trust evaluation is often static and based on preset rules, unable to adapt to changes in network status in real time. The trust level of nodes usually depends on hard-coded policies or manual settings, lacking dynamic monitoring and behavior analysis. The encryption intensity is also fixed in advance and will not be adjusted according to actual security requirements and network status. Moreover, in traditional methods, the encryption intensity is usually uniform, and all data transmissions will use the same encryption algorithm and intensity. This fixed encryption method often leads to problems such as performance waste or insufficient encryption intensity, wasting computing resources. In some high-risk transmission scenarios, the encryption intensity adopted may be insufficient to cope with potential threats. And traditional methods usually use fixed encryption algorithms, and these algorithms will not be dynamically adjusted according to specific network requirements or transmission content, which may lead to excessive computing overhead or low data transmission efficiency. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to overcome the above-mentioned disadvantages of the prior art and provide a multi-path network communication security guarantee method based on an adaptive encryption algorithm.
[0004] The technical solution adopted to solve the above technical problem is: A multi-path network communication security guarantee method based on an adaptive encryption algorithm, including:
[0005] Obtain the network undirected graph corresponding to the target network, where the network undirected graph includes a first node set, a second node set, and an undirected edge set. Among them, the first node is used to collect and manage data, the second node is used to monitor the security status of the first node, and the undirected edge is used to connect the first node and the second node;
[0006] Extract features from the second node set according to the behaviors among the second nodes to obtain the behavior features of each second node in the second node set;
[0007] Classify the behavior features of each second node in the second node set according to a pre-trained trust classification model to obtain the trust level of the second node;
[0008] Determine the communication security level of the first node according to the security status of the first node and the trust level of the second node, and determine the data encryption level required by the first node according to the communication security level of the first node;
[0009] Determine the encryption algorithm required by the first node according to the data encryption level required by the first node, and encrypt and transmit the data according to the encryption algorithm.
[0010] Preferably, the second node is used to monitor the security status of the first node, including:
[0011] Monitor the ratio of the number of type data successfully processed by the first node to the total number of all type data processed by the first node, and use the ratio of the number of type data successfully processed by the first node to the total number of all type data processed by the first node as the first performance characteristic;
[0012] The second node sends a probe packet to the first node, and uses the delay of the probe packet as the second performance characteristic;
[0013] Monitor the ratio of the number of routing interruption reports initiated by the first node to the limit number of routing interruption reports, and use the ratio of the number of routing interruption reports initiated by the first node to the limit number of routing interruption reports as the first security characteristic;
[0014] Monitor the ratio of the number of routes of the first node to the number of known routes, and use the ratio of the number of routes of the first node to the number of known routes as the second security characteristic.
[0015] Preferably, the second node is used to monitor the security status of the first node, and further includes:
[0016] The second node monitors the average retransmission times of the first node according to the Carrier Sense Multiple Access protocol;
[0017] Determine the congestion level of the first node according to the average retransmission times of the first node, and determine the decrease values of the first performance characteristic and the second performance characteristic according to the congestion level of the first node;
[0018] Determine the characteristic deviation degree under the current weight configuration and the characteristic deviation degree under the static weight configuration according to the decrease values of the first performance characteristic and the second performance characteristic;
[0019] If the characteristic deviation degree under the current weight configuration is less than the characteristic deviation degree under the static weight configuration, update the static weight configuration to the current weight configuration, and update the characteristic deviation degree under the current weight configuration to the characteristic deviation degree under the static weight configuration, and repeat the previous operation until the characteristic deviation degree under the current weight configuration is not less than the characteristic deviation degree under the static weight configuration to obtain the optimal current weight configuration;
[0020] Determine the security status value of the first node according to the optimal current weight configuration, and determine the security status of the first node according to the security status value of the first node.
[0021] Preferably, the calculation formula of the average retransmission times is as follows:
[0022]
[0023] wherein, R i represents the average retransmission times of the first node i, M L represents the maximum retransmission times, represents the probability of the (l - 1)-th retransmission failure, and p f represents the probability of this retransmission failure;
[0024] The calculation formula of the feature deviation degree is as follows:
[0025]
[0026] wherein, δ(ω q ) represents the feature deviation degree under the current weight configuration ω q , T N (k) represents the performance feature, wherein the performance feature includes the first performance feature and the second performance feature, and T R (k) represents the security feature, wherein the security feature includes the first security feature and the second security feature, and ΔD(C i ) represents the decrease value of the performance feature under the congestion level, represents the weight configuration, and represents the static weight configuration.
[0027] Preferably, feature extraction is performed on the second node set according to the behaviors between the second nodes to obtain the behavior features of each second node in the second node set, including:
[0028] Monitoring the total number of first nodes covered by the second node, and determining the first behavior feature of the second node according to the total number of first nodes covered by the second node, wherein the calculation formula of the first behavior feature is as follows:
[0029]
[0030] wherein, represents the first behavior feature of the second node, represents the total number of one-hop neighbor first nodes covered by the second node, represents all the first nodes existing in the target network except the second node;
[0031] Monitor the number of successful and failed interactions between the second node and the first node, and determine the second behavior feature of the second node according to the number of successful and failed interactions between the second node and the first node. The calculation formula of the second behavior feature is as follows:
[0032]
[0033] Wherein, represents the second behavior feature of the second node, represents the number of successful interactions between the second node and the first node, represents the number of failed interactions between the second node and the first node;
[0034] Monitor the interaction time between the second nodes, and determine the third behavior feature of the second node according to the interaction time between the second nodes. The calculation formula of the third behavior feature is as follows:
[0035]
[0036] Wherein, represents the third behavior feature of the second node, t ij represents the interaction time between the i-th second node and the j-th second node, t ik represents the interaction time between the i-th second node and the k-th second node.
[0037] Preferably, feature extraction is performed on the second node set according to the behaviors between the second nodes to obtain the behavior features of each second node in the second node set. It further includes:
[0038] Monitor the number of interactions between the second nodes, and determine the fourth behavior feature of the second node according to the number of interactions between the second nodes. The calculation formula of the fourth behavior feature is as follows:
[0039]
[0040] Wherein, represents the fourth behavior feature of the second node, n ij represents the number of interactions between the i-th second node and the j-th second node, n ik represents the number of interactions between the i-th second node and the k-th second node;
[0041] Monitor the feedback information between the second nodes, where the feedback information includes positive feedback and negative feedback. Determine the fifth behavior feature of the second node according to the feedback information between the second nodes. The calculation formula of the fifth behavior feature is as follows:
[0042]
[0043] Among them, represents the fifth row of the second node as a feature, represents all second nodes that provided negative feedback to the i-th second node in the past, represents the number of all second nodes that provided feedback to the i-th second node, represents the number of negative feedback given among all second nodes that provided negative feedback to the i-th second node in the past, represents whether the feedback information provided by the j-th second node to the i-th first node is negative feedback. When negative feedback is provided, then otherwise time l represents the start time of monitoring the feedback information between the second nodes, time 0 represents the end time of monitoring the feedback information between the second nodes.
[0044] Preferably, the trust classification model adopts an improved support vector machine model, wherein the support vector machine model is improved according to an optimization algorithm.
[0045] Preferably, determining the communication security level of the first node according to the security state of the first node and the trust level of the second node includes:
[0046] Encoding the security state of the first node and the trust level of the second node to obtain a security state encoding sequence and a trust level encoding sequence;
[0047] Combining the security state encoding sequence and the trust level encoding sequence to obtain a security-trust encoding sequence;
[0048] Matching the security-trust encoding sequence with a preset communication security level encoding sequence table to obtain the communication security level corresponding to the security-trust encoding sequence, that is, obtaining the communication security level of the first node.
[0049] Preferably, determining the encryption algorithm required by the first node according to the data encryption level required by the first node includes:
[0050] Matching the data encryption level required by the first node with a preset encryption level-algorithm mapping table to obtain the encryption algorithm required by the first node, wherein the encryption level-algorithm mapping table includes communication security level, encryption level, algorithm selection, and key length.
[0051] The beneficial effects of the present invention are as follows: (1) By extracting the characteristics of the behavior of the second nodes in the network and combining with a pre-trained trust classification model, the present invention can dynamically evaluate and adjust the trust levels of each node. This adaptive feature can effectively adjust the communication security level according to the actual situation, thereby improving the security of the network. Moreover, by monitoring and analyzing the behavior of the second nodes, potential security threats or malicious nodes can be identified, and the trust levels of the nodes can be adjusted in a timely manner, so that the first node selects a path with a higher trust level for data transmission during communication. This trust evaluation mechanism helps improve the communication security in the network and can effectively reduce the risks of data leakage, tampering, or other attacks; (2) By determining the communication security level of the first node according to the security state of the first node and the trust level of the second node, the present invention accurately calculates the required data encryption level. This on-demand encryption strategy avoids the problems of performance waste or insufficient encryption intensity that may be brought about by traditional fixed encryption methods, ensures that the encryption intensity matches the security requirements, and improves the security of data transmission; (3) By selecting an adaptive encryption algorithm, the present invention can improve the efficiency of data transmission on the premise of ensuring security. Different data encryption levels can optimize the transmission performance according to the actual situation, reducing unnecessary calculations and network loads. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 It is a schematic flowchart of the steps of the overall method in an embodiment proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] Embodiment 1, as Figure 1 shown, the multi-path network communication security guarantee method based on an adaptive encryption algorithm proposed by the present invention includes:
[0054] S1. Obtain the network undirected graph corresponding to the target network, where the network undirected graph includes a first node set, a second node set, and an undirected edge set. Among them, the first node is used to collect and manage data, the second node is used to monitor the security state of the first node, and the undirected edge is used to connect the first node and the second node;
[0055] S2. Extract the characteristics of the second node set according to the behavior between the second nodes to obtain the behavior characteristics of each second node in the second node set;
[0056] S3. Classify the behavior characteristics of each second node in the second node set according to the pre-trained trust classification model to obtain the trust level of the second node;
[0057] S4. Determine the communication security level of the first node according to the security state of the first node and the trust level of the second node, and determine the required data encryption level of the first node according to the communication security level of the first node;
[0058] S5. Determine the encryption algorithm required by the first node according to the data encryption level required by the first node, and encrypt and transmit the data according to the encryption algorithm.
[0059] In the present invention, the network undirected graph is a graph structure in graph theory, where the edges between nodes have no direction, meaning that the connections of the edges are bidirectional. The target network is represented as an undirected graph, where nodes represent devices or nodes in the network, and edges represent communication paths between nodes; the encryption algorithm is an algorithm that converts data into an unreadable form, and only users with the encryption key can decrypt it. According to different encryption levels, encryption algorithms with different strengths may be used, such as symmetric encryption (such as AES), asymmetric encryption (such as RSA), etc.; encrypted transmission means encrypting data during the transmission process to prevent the data from being eavesdropped, tampered with or leaked during the transmission process, and only the receiving party with the correct encryption key can decrypt the data; the trust classification model is a method based on machine learning or data analysis for judging the credibility of nodes according to their behavioral characteristics. These models are usually trained to classify nodes according to historical data or behavioral patterns and judge their trust levels. For example, if the behavior of certain nodes is abnormal, they may be rated as untrustworthy.
[0060] Embodiment 2. The multi-path network communication security guarantee method based on the adaptive encryption algorithm proposed by the present invention further includes, compared with Embodiment 1: The second node is used to monitor the security status of the first node, including:
[0061] A1. Monitor the ratio of the number of type data successfully processed by the first node to the total number of all type data processed by the first node, and use the ratio of the number of type data successfully processed by the first node to the total number of all type data processed by the first node as the first performance characteristic;
[0062] A2. The second node sends a probe packet to the first node, and uses the delay of the probe packet as the second performance characteristic;
[0063] A3. Monitor the ratio of the number of routing interruption reports initiated by the first node to the number of routing interruption report limits, and use the ratio of the number of routing interruption reports initiated by the first node to the number of routing interruption report limits as the first security characteristic;
[0064] A4. Monitor the ratio of the number of routes of the first node to the number of known routes, and use the ratio of the number of routes of the first node to the number of known routes as the second security characteristic.
[0065] In this embodiment, the number of successfully processed type data refers to the number of data types that the first node can successfully complete processing. These data types may involve operations such as transmission, parsing, and processing; Probe packets are usually the data packets sent during the network performance detection process, aiming to test network latency, bandwidth, packet loss rate, etc. Probe packets do not carry user data but are used to collect network performance information; Latency refers to the time required for a probe packet to be sent from the second node to the first node and then return. Latency is an important indicator of network performance, usually measured in milliseconds (ms). The lower the latency, the faster the network response; Routing interruption report means that when a routing failure or interruption occurs in the network, a node will send a report to other nodes in the network to notify them of the routing interruption. This report helps other nodes recalculate the routing to ensure that data can bypass the faulty area; The number of routes refers to the number of routing paths that the first node currently knows and can be used for data transmission. A route is the path of a data packet from the source node to the target node, and network nodes maintain this path information through the routing table; The number of known routes refers to the number of available routing paths that have been identified or preset in the network. These routing paths are usually defined in the network configuration or protocol.
[0066] In an alternative embodiment, the second node is used to monitor the security status of the first node, and further includes:
[0067] A5. The second node monitors the average retransmission times of the first node according to the Carrier Sense Multiple Access protocol;
[0068] A6. Determine the congestion level of the first node according to the average retransmission times of the first node, and determine the degradation values of the first performance characteristic and the second performance characteristic according to the congestion level of the first node;
[0069] A7. Determine the feature deviation degree under the current weight configuration and the feature deviation degree under the static weight configuration according to the degradation values of the first performance characteristic and the second performance characteristic;
[0070] A8. If the feature deviation degree under the current weight configuration is less than the feature deviation degree under the static weight configuration, update the static weight configuration to the current weight configuration, and update the feature deviation degree under the current weight configuration to the feature deviation degree under the static weight configuration, and repeat the previous operation until the feature deviation degree under the current weight configuration is not less than the feature deviation degree under the static weight configuration to obtain the optimal current weight configuration;
[0071] A9. Determine the security status value of the first node according to the optimal current weight configuration, and determine the security status of the first node according to the security status value of the first node.
[0072] It should be noted that the Carrier Sense Multiple Access (CSMA) protocol is a network access control protocol used to avoid data collisions caused by multiple nodes sending data packets simultaneously. Through carrier sensing, a node can sense whether the channel is idle. If the channel is idle, the node can send data; if the channel is busy, it will wait until the channel becomes idle. The feature deviation degree is a metric used to measure the difference between the current network state and the expected network state. The current weight configuration is a weight configuration that is adjusted in real-time according to changes in the network state, aiming to optimize network performance in real-time.
[0073] In an alternative embodiment, the formula for calculating the average number of retransmissions is as follows:
[0074]
[0075] Where, R i represents the average number of retransmissions of the first node i, M L represents the maximum number of retransmissions, represents the probability of the (l - 1)-th retransmission failure, p f represents the probability of this retransmission failure;
[0076] The formula for calculating the feature deviation degree is as follows:
[0077]
[0078] Where, δ(ω q ) represents the feature deviation degree under the current weight configuration ω q , T N (k) represents the performance feature, where the performance feature includes the first performance feature and the second performance feature, T R (k) represents the security feature, where the security feature includes the first security feature and the second security feature, ΔD(C i ) represents the decrease value of the performance feature under the congestion level, represents the weight configuration, and represents the static weight configuration.
[0079] In an alternative embodiment, feature extraction is performed on the second node set according to the behaviors between the second nodes to obtain the behavior features of each second node in the second node set, including:
[0080] B1. Monitor the total number of first nodes covered by the second node, and determine the first behavior feature of the second node according to the total number of first nodes covered by the second node. The formula for the first behavior feature is as follows:
[0081]
[0082] Where, The first line represents the second node as a feature, represents the total number of first nodes covered by the second node as one-hop neighbors, represents all the first nodes existing in the target network except the second node;
[0083] B2. Monitor the number of successful and failed interactions between the second node and the first node, and determine the second behavior feature of the second node according to the number of successful and failed interactions between the second node and the first node. The calculation formula of the second behavior feature is as follows:
[0084]
[0085] where, represents the second behavior feature of the second node, represents the number of successful interactions between the second node and the first node, represents the number of failed interactions between the second node and the first node;
[0086] B3. Monitor the interaction time between the second nodes, and determine the third behavior feature of the second node according to the interaction time between the second nodes. The calculation formula of the third behavior feature is as follows:
[0087]
[0088] where, represents the third behavior feature of the second node, t ij represents the interaction time between the i-th second node and the j-th second node, t ik represents the interaction time between the i-th second node and the k-th second node.
[0089] It should be noted that the first node covered refers to the first node with which the second node can communicate, interact, or detect. In the network topology, a node may cover multiple other nodes, which means it can establish connections with these nodes within a certain range; a neighbor node refers to a node directly connected to a certain node. In the network, neighbor nodes are nodes that can communicate directly through a single hop. For example, the neighbors of the second node are the first nodes with which it can communicate directly; a one-hop neighbor refers to a node that can be directly connected to the target node through one transmission step (or hop) in the network topology. For example, if A and B are directly connected, then B is a one-hop neighbor of A, and vice versa; the number of successful interactions refers to the number of normal and successful communications between the second node and the first node; the number of failed interactions refers to the number of times when the second node and the first node cannot successfully establish a connection or cannot communicate normally; the interaction time refers to the time experienced when communication occurs between the second node and other nodes, which may represent metrics of network performance such as data transmission delay and response time; the interaction time difference refers to the gap in interaction time between two second nodes, indicating the difference in their communication efficiency or response speed.
[0090] In an optional embodiment, feature extraction is performed on the second node set according to the behaviors between the second nodes to obtain the behavior features of each second node in the second node set, and it further includes:
[0091] B4. Monitor the number of interactions between the second nodes, and determine the fourth behavior feature of the second node according to the number of interactions between the second nodes. The calculation formula of the fourth behavior feature is as follows:
[0092]
[0093] Wherein, represents the fourth behavior feature of the second node, n ij represents the number of interactions between the i-th second node and the j-th second node, n ik represents the number of interactions between the i-th second node and the k-th second node;
[0094] B5. Monitor the feedback information between the second nodes. The feedback information includes positive feedback and negative feedback. Determine the fifth behavior feature of the second node according to the feedback information between the second nodes. The calculation formula of the fifth behavior feature is as follows:
[0095]
[0096] Wherein, represents the fifth behavior feature of the second node, represents all the second nodes that provided negative feedback to the i-th second node in the past, represents the number of all second nodes that provide feedback to the i-th second node, represents the number of negative feedback given among all second nodes that provided negative feedback to the i-th second node in the past, represents whether the feedback information provided by the j-th second node to the i-th first node is negative feedback. When negative feedback is provided, then otherwise time l represents the start time, time, of monitoring the feedback information between second nodes, 0 represents the end time of monitoring the feedback information between second nodes.
[0097] It should be noted that the feedback information refers to the feedback generated between second nodes after interaction. These feedbacks can be positive feedback (indicating that a certain behavior is recognized or supported) or negative feedback (indicating that a certain behavior is negated or criticized); the second nodes that provide negative feedback refer to other second nodes that have provided negative feedback to a certain second node, and the behaviors of these nodes may affect the behavior characteristics of the target node; the number of negative feedback given refers to the number of nodes that provide negative feedback to a specific second node, and this indicator is used to measure the degree to which the behavior of a specific second node in the network is criticized or opposed by other nodes; the start time and end time refer to the time range of monitoring the feedback information between second nodes.
[0098] In an optional embodiment, the trust classification model adopts an improved support vector machine model, wherein the support vector machine model is improved according to an optimization algorithm.
[0099] It should be noted that the support vector machine (SVM) is a supervised learning algorithm used for classification and regression analysis. Its core idea is to find an optimal hyperplane to distinguish data of different categories; the optimization algorithm refers to an algorithm that finds the optimal solution through a series of steps. In machine learning and trust classification tasks, the optimization algorithm is usually used to adjust model parameters (such as the regularization parameter and kernel function parameter in SVM) to improve the performance of the model.
[0100] In an optional embodiment, determining the communication security level of the first node according to the security status of the first node and the trust level of the second node includes:
[0101] C1. Encode the security status of the first node and the trust level of the second node to obtain a security status encoding sequence and a trust level encoding sequence;
[0102] C2. Combine the security status encoding sequence and the trust level encoding sequence to obtain a security-trust encoding sequence;
[0103] C3. Match the security-trust coding sequence with a preset communication security level coding sequence table to obtain the communication security level corresponding to the security-trust coding sequence, that is, obtain the communication security level of the first node.
[0104] It should be noted that the communication security level coding sequence is a preset set of codes used to represent different communication security levels.
[0105] In an optional embodiment, determining the encryption algorithm required by the first node according to the data encryption level required by the first node includes:
[0106] D1. Match the data encryption level required by the first node with a preset encryption level-algorithm mapping table to obtain the encryption algorithm required by the first node, where the encryption level-algorithm mapping table includes communication security level, encryption level, algorithm selection, and key length.
[0107] It should be noted that the encryption level-algorithm mapping table is a table or data structure that maps different encryption levels to corresponding encryption algorithms and key lengths. This table selects appropriate encryption algorithms and key lengths according to different communication security levels to ensure data security.
[0108] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited thereto. Various changes can be made without departing from the spirit of the present invention within the scope of knowledge possessed by those skilled in the art.
Claims
1. A multi-path network communication security assurance method based on an adaptive encryption algorithm, characterized in that: include: Acquire a network undirected graph corresponding to the target network, wherein the network undirected graph includes a first node set, a second node set, and an undirected edge set, wherein the first node is used to collect and manage data, the second node is used to monitor the security status of the first node, and the undirected edge is used to connect the first node and the second node; Extracting features from the second node set according to behaviors between the second nodes to obtain behavioral features of each second node in the second node set; classifying the behavior characteristics of each second node in the second node set according to a pre-trained trust classification model to obtain a trust level of the second node; Determining a communication security level of the first node according to the security state of the first node and the trust level of the second node, and determining a data encryption level required by the first node according to the communication security level of the first node; The encryption algorithm required by the first node is determined according to the data encryption level required by the first node, and the data is encrypted and transmitted according to the encryption algorithm.
2. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 1 is characterized in that: The second node is used to monitor the security status of the first node, including: monitoring a ratio of the number of data of a type successfully processed by the first node to the total number of data of all types processed by the first node, and taking the ratio of the number of data of a type successfully processed by the first node to the total number of data of all types processed by the first node as a first performance characteristic; The second node sends a detection packet to the first node, and uses a delay of the detection packet as a second performance characteristic; monitoring a ratio of the number of times the first node initiates a route interruption report to a limited number of times the route interruption report is initiated, and taking the ratio of the number of times the first node initiates a route interruption report to the limited number of times the route interruption report is initiated as a first security feature; The ratio of the number of routes of the first node to the number of known routes is monitored, and the ratio of the number of routes of the first node to the number of known routes is used as a second security feature.
3. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 2 is characterized in that: The second node is used to monitor the security status of the first node, and further includes: The second node monitors an average number of retransmissions of the first node according to a carrier sense multiple access protocol; determining a congestion level of the first node according to an average number of retransmissions of the first node, and determining reduction values of the first performance characteristic and the second performance characteristic according to the congestion level of the first node; Determining a characteristic deviation degree under a current weight configuration and a characteristic deviation degree under a static weight configuration according to the decrease values of the first performance characteristic and the second performance characteristic; If the characteristic deviation degree under the current weight configuration is less than the characteristic deviation degree under the static weight configuration, the static weight configuration is updated to the current weight configuration, and the characteristic deviation degree under the current weight configuration is updated to the characteristic deviation degree under the static weight configuration, and the previous operation is repeated until the characteristic deviation degree under the current weight configuration is not less than the characteristic deviation degree under the static weight configuration, so as to obtain the optimal current weight configuration; The security status value of the first node is determined according to the optimal current weight configuration, and the security status of the first node is determined according to the security status value of the first node.
4. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 3 is characterized in that: The calculation formula of the average number of retransmissions is as follows: Among them, R i represents the average number of retransmissions of the first node i, M L Indicates the maximum number of retransmissions. represents the probability of failure of the l-1th retransmission, p f Indicates the probability of retransmission failure; The calculation formula of the characteristic deviation is as follows: Among them, δ(ω q ) represents the current weight configuration ω q The characteristic deviation under T N (k) represents a performance characteristic, wherein the performance characteristic includes a first performance characteristic and a second performance characteristic, T R (k) represents a security feature, wherein the security feature includes a first security feature and a second security feature, ΔD(C i ) represents the degradation value of the performance characteristics under the congestion level, represents the weight configuration, and Indicates static weight configuration.
5. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 1 is characterized in that: Extracting features from the second node set according to the behaviors between the second nodes to obtain behavior features of each second node in the second node set includes: The total number of first nodes covered by the second node pair is monitored, and a first behavior feature of the second node is determined according to the total number of first nodes covered by the second node pair, wherein a calculation formula for the first behavior feature is as follows: in, represents the first behavior feature of the second node, Indicates the total one-hop neighbor first node covered by the second node, represents all first nodes existing in the target network except the second node; The number of successful and failed interactions between the second node and the first node is monitored, and a second behavior feature of the second node is determined according to the number of successful and failed interactions between the second node and the first node, wherein a calculation formula for the second behavior feature is as follows: in, represents the second behavior feature of the second node, represents the number of successful interactions between the second node and the first node, represents the number of failed interactions between the second node and the first node; Monitor the interaction time between the second nodes, and determine the third behavior feature of the second node according to the interaction time between the second nodes, wherein the calculation formula of the third behavior feature is as follows: in, represents the third behavior feature of the second node, t ij represents the interaction time between the i-th second node and the j-th second node, t ik represents the interaction time between the i-th second node and the k-th second node.
6. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 5 is characterized in that: Extracting features from the second node set according to the behaviors between the second nodes to obtain behavior features of each second node in the second node set also includes: The number of interactions between the second nodes is monitored, and a fourth behavior feature of the second node is determined according to the number of interactions between the second nodes, wherein a calculation formula for the fourth behavior feature is as follows: in, Indicates the fourth behavior of the second node, n ij represents the number of interactions between the i-th second node and the j-th second node, n ik represents the number of interactions between the i-th second node and the k-th second node; Monitoring feedback information between the second nodes, wherein the feedback information includes positive feedback and negative feedback, and determining a fifth behavior characteristic of the second node according to the feedback information between the second nodes, wherein a calculation formula for the fifth behavior characteristic is as follows: in, The fifth line of the second node represents the characteristics, represents all the second nodes that provided negative feedback to the i-th second node in the past, represents the number of all second nodes that provide feedback to the i-th second node, represents the number of negative feedbacks given by all second nodes that provided negative feedback to the i-th second node in the past, Indicates whether the feedback information provided by the j-th second node to the i-th first node is negative feedback. If negative feedback is provided, otherwise time l time0 represents the start time of monitoring the feedback information between the second nodes, and time1 represents the end time of monitoring the feedback information between the second nodes.
7. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 6 is characterized in that: The trust classification model adopts an improved support vector machine model, wherein the support vector machine model is improved according to an optimization algorithm.
8. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 1 is characterized in that: Determining a communication security level of the first node according to the security state of the first node and the trust level of the second node includes: Encoding the security status of the first node and the trust level of the second node to obtain a security status coding sequence and a trust level coding sequence; combining the security state coding sequence and the trust level coding sequence to obtain a security-trust coding sequence; The security-trust coding sequence is matched with a preset communication security level coding sequence table to obtain the communication security level corresponding to the security-trust coding sequence, that is, to obtain the communication security level of the first node.
9. The multi-path network communication security guarantee method based on the adaptive encryption algorithm according to claim 1 is characterized in that: Determining the encryption algorithm required by the first node according to the data encryption level required by the first node includes: The data encryption level required by the first node is matched with a preset encryption level-algorithm mapping table to obtain the encryption algorithm required by the first node, wherein the encryption level-algorithm mapping table includes communication security level, encryption level, algorithm selection and key length.
Citation Information
Cited By
Power grid data hybrid security encryption method based on artificial intelligence driving
CN120750649A
Optimizing networks microsegmentation policy for cyber resilience
US12732526B2
Optimizing networks microsegmentation policy for cyber resilience
US20240356961A1