Data encryption method and system, computer and storage medium
By using a one-way hash chain to generate dynamic temporary keys and three-dimensional key pools for encryption in the hydrological monitoring system, combining energy consumption-aware cluster head election and load balancing path allocation, and embedding authentication codes, the problem of poor data security in the existing technology is solved, and data transmission with high security and low energy consumption is achieved.
Patent Information
- Application Number
- CN202510447781.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, fixed keys are easily breached or reproduced, especially in scenarios where edge device resources are limited, it is difficult to achieve frequent key updates, resulting in poor data security.
By dividing the data network into an edge acquisition area, an intermediate transmission area and a data monitoring area, a dynamic temporary key is generated by a one-way hash chain to encrypt the data segments of the edge acquisition area in one go, and a secondary encryption is performed in combination with a three-dimensional key pool. At the same time, energy-consuming-aware cluster head election and load balancing path allocation are performed in the intermediate transmission area, and authentication codes containing spatiotemporal marks and cluster head IDs are embedded.
It improves data security, reduces network energy consumption, and ensures the security, efficiency and reliability of hydrological data transmission.
Smart Images

Figure CN120151087A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly relates to a data encryption method, system, computer, and storage medium. Background Art
[0002] Hydrological monitoring systems are often deployed in complex field environments, and need to collect data such as water levels and flow velocities in real time through a distributed network.
[0003] In the prior art, fixed keys are easily cracked by brute force or subject to replay attacks, especially in scenarios where edge device resources are limited, it is difficult to update keys frequently, and the data security is poor. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the purpose of the present invention is to provide a data encryption method, system, computer, and storage medium, aiming to solve the technical problem of poor data security in the prior art.
[0005] To achieve the above object, in the first aspect, the present invention provides: A data encryption method, including the following steps: Divide the data network into an edge collection area, an intermediate transmission area, and a data monitoring area according to hydrological monitoring objectives; Slice the hydrological data collected in the edge collection area according to timestamps to obtain multiple data segments, and perform area marking on the data segments based on regional distribution; Generate a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, and transmit them to the intermediate transmission area; Encrypt and aggregate the encrypted data segments in the intermediate transmission area to generate an aggregated data packet, and add an authentication code including regional location and timestamp to the aggregated data packet, and transmit it to the data monitoring area; Select polynomial parameters from a preset three-dimensional key pool to generate an asymmetric encryption key pair, and perform secondary encryption on the aggregated data packet based on the asymmetric encryption key pair to obtain an encrypted data packet.
[0006] According to one aspect of the above technical solution, after the step of generating a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, the method further includes: Perform energy consumption-aware cluster head election in the intermediate transmission area to dynamically select the target cluster head for transmission, where the weight formula for cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the security weight, is the number of keys that a node can store, is the encryption calculation speed, is the maximum key capacity of a node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, is the transmission delay.
[0007] According to one aspect of the above technical solution, the steps of encrypting the data segments in the edge collection area once with a dynamic temporary key generated based on a one-way hash chain and transmitting them to the intermediate transmission area specifically include: Mark the data segments based on the cluster head ID in the cluster head election result, so that the data segments are associated with the target cluster head; Generate a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, and allocate the corresponding data segments to be transmitted to the intermediate transmission area based on the load conditions of each path.
[0008] According to one aspect of the above technical solution, before the step of encrypting and aggregating the encrypted data segments in the intermediate transmission area, the method further includes: Verify whether the cluster head ID in each data segment is consistent with the target cluster head.
[0009] According to one aspect of the above technical solution, the steps of adding an authentication code including the regional location and timestamp to the aggregated data packet specifically include: Add authentication information including the regional location and timestamp to the aggregated data packet, and generate an authentication code based on the cluster head ID in the data segment to mark the aggregated data packet.
[0010] According to one aspect of the above technical solution, the method further includes: After decrypting the encrypted data packet, verify the authentication code. If the verification fails, trigger key update and cluster head re-election. In a second aspect, the present invention provides a data encryption system, including: A network module, configured to divide the data network into an edge collection area, an intermediate transmission area, and a data monitoring area according to the hydrological monitoring target; A sharding module, configured to shard the hydrological data collected in the edge collection area according to timestamps to obtain multiple data segments, and perform regional marking on the data segments based on the regional distribution; A primary encryption module, configured to generate a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, and transmit them to the intermediate transmission area; An aggregation module, configured to perform encrypted aggregation on encrypted data fragments in the intermediate transmission area, generate an aggregated data packet, add an authentication code including a regional location and a timestamp to the aggregated data packet, and transmit it to the data monitoring area; A secondary encryption module, configured to select polynomial parameters from a preset three-dimensional key pool through the three-dimensional key pool to generate an asymmetric encryption key pair, and perform secondary encryption on the aggregated data packet based on the asymmetric encryption key pair to obtain an encrypted data packet.
[0011] According to one aspect of the above technical solution, the system further includes: A cluster head module, configured to perform energy consumption-aware cluster head election in the intermediate transmission area to dynamically select a target cluster head for transmission, where the weight formula for cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the security weight, is the number of keys that the node can store, is the encryption calculation speed, is the maximum key capacity of the node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, is the transmission delay.
[0012] According to one aspect of the above technical solution, the primary encryption module is specifically configured to: Mark the data fragment based on the cluster head ID of the cluster head election result, so that the data fragment is associated with the target cluster head; Perform primary encryption on the data fragment in the edge collection area based on a one-way hash chain to generate a dynamic temporary key pair, and allocate the corresponding data fragment to the intermediate transmission area based on the load conditions of each path.
[0013] According to one aspect of the above technical solution, the system further includes: A primary verification module, configured to verify whether the cluster head ID in each data fragment is consistent with the target cluster head.
[0014] According to one aspect of the above technical solution, the aggregation module is specifically configured to: Add authentication information including a regional location and a timestamp to the aggregated data packet, and generate an authentication code based on the cluster head ID in the data fragment to mark the aggregated data packet.
[0015] According to one aspect of the above technical solution, the system further includes: A secondary verification module, configured to verify the authentication code after decrypting the encrypted data packet. If the verification fails, it triggers key update and cluster head reselection.
[0016] In a third aspect, the present invention also provides a computer, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the data encryption method described in the above technical solution.
[0017] In a fourth aspect, the present invention also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the data encryption method described in the above technical solution.
[0018] Compared with the prior art, the beneficial effects of the present invention are as follows: One-time encryption is achieved by generating a temporary key through a dynamic one-way hash chain, and secondary encryption is performed in combination with a three-dimensional parameter key pool of time-space-random numbers, improving security. At the same time, data is fragmented and energy consumption-aware cluster head election and load balancing path allocation are used to reduce network energy consumption. At the same time, an authentication code containing time-space markers and cluster head IDs is embedded to further ensure the accuracy and security of data, making the transmission of hydrological data take into account security, efficiency, and reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic flowchart of the data encryption method in the first embodiment of the present invention; Figure 2 It is a structural block diagram of the data encryption system in the fourth embodiment of the present invention; Figure 3 It is a schematic hardware structure diagram of the computer in the third embodiment of the present invention; The following specific embodiments will further illustrate the present invention in conjunction with the above drawings. DETAILED DESCRIPTION
[0020] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.
[0021] It should be noted that when an element is referred to as being "fixed to" another element, it can be directly on the other element or there can also be an intermediate element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.
[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.
[0023] Embodiment 1 Please refer to Figure 1 , which shows the flowchart of the data encryption method in the first embodiment of the present invention. As Figure 1 shown, the method includes the following steps: Step S100, divide the data network into an edge collection area, an intermediate transmission area and a data monitoring area according to the hydrological monitoring target. Specifically, in this embodiment, the above-mentioned edge collection area covers the dense area of hydrological monitoring terminal devices and needs to process the raw data with high real-time requirements nearby. The above-mentioned intermediate transmission area is used to connect the edge devices and the monitoring center and needs to ensure the security and stability of cross-regional data transmission; the above-mentioned data monitoring area is used for data encryption, storage, analysis, etc.
[0024] Step S200, slice the hydrological data collected in the edge collection area according to the time stamp to obtain a plurality of data segments, and perform area marking on the data segments based on the area distribution. Specifically, in this embodiment, the slicing operation adopts a dynamic window division mechanism; the area marking operation is used to convert the longitude and latitude coordinates corresponding to the monitoring area into character identification codes for marking.
[0025] Step S300, generate a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, and transmit them to the intermediate transmission area.
[0026] Preferably, in this embodiment, after the step of generating a dynamic temporary key based on a one-way hash chain to encrypt the data segments in the edge collection area once, the method further includes: Perform energy consumption-aware cluster head election in the intermediate transmission area to dynamically select the target cluster head for transmission, where the weight formula for cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the security weight, is the number of keys that the node can store, is the encryption calculation speed, is the maximum key capacity of the node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, is the transmission delay.
[0027] Among them, the energy weight part considers the remaining energy of the node, which is preferably 0.6 in this embodiment, and is used to screen out nodes with low battery life to avoid frequent reselection due to energy exhaustion. The parameter value of is between 0 and 1. The security weight part is related to the encryption performance of the node, which is preferably 0.2 in this embodiment. The larger the number of keys that can be stored, the higher the security redundancy of the node. A high encryption speed can reduce the delay caused by encryption. and The parameter values of and are between 0 and 1. The link weight part is related to the comprehensive quality of the link, which is preferably 0.2 in this embodiment. The lower the packet loss rate, the higher the link reliability, and the greater the delay, the more the weight is penalized. The parameter value of is between 0 and 1.
[0028] In other embodiments, the energy weight can be appropriately increased in scenarios with high battery life requirements, the security weight can be appropriately increased in scenarios with high security requirements, and the link weight can be appropriately increased in scenarios with high real-time requirements.
[0029] Furthermore, the steps of generating a dynamic temporary key based on a one-way hash chain to encrypt the data fragment in the edge collection area once and transmitting it to the intermediate transmission area specifically include: Mark the data fragment based on the cluster head ID of the cluster head election result, so that the data fragment is associated with the target cluster head; Generate a dynamic temporary key based on a one-way hash chain to encrypt the data fragment in the edge collection area once, and allocate the corresponding data fragment to the intermediate transmission area based on the load conditions of each path.
[0030] Step S400, encrypt and aggregate the encrypted data fragments in the intermediate transmission area to generate an aggregated data packet, add an authentication code including the regional location and timestamp to the aggregated data packet, and transmit it to the data monitoring area.
[0031] Preferably, in this embodiment, before the step of encrypting and aggregating the encrypted data fragments in the intermediate transmission area, the method further includes: Verify whether the cluster head IDs in each data fragment are the same as the target cluster head. Specifically, the intermediate transmission area pre-stores a whitelist of valid cluster heads, which contains the 16-bit hash identification codes and corresponding public keys of all legal cluster heads in the current election cycle. By comparing the identification fields in the data shards with the whitelist entries, filter out the data shards marked with abnormal or invalid cluster heads.
[0032] Specifically, in this embodiment, the step of adding an authentication code including the regional location and timestamp to the aggregated data packet specifically includes: Add authentication information including the regional location and timestamp to the aggregated data packet, and generate an authentication code based on the cluster head ID in the data fragment to mark the aggregated data packet.
[0033] Step S500, select polynomial parameters from a preset three-dimensional key pool to generate an asymmetric encryption key pair, and based on the asymmetric encryption key pair, perform secondary encryption on the aggregated data packet to obtain an encrypted data packet.
[0034] Specifically, in this embodiment, the above three-dimensional key pool is a three-dimensional parameter key pool of time-space-random number, and the selection rule of the polynomial parameters is: according to the space-time tags of the data shards, select the three nearest parameters from the key pool to construct an elliptic curve polynomial: ; In the formula, is the spatial dimension parameter, is the time dimension parameter, is the device dimension parameter (based on the hardware fingerprint of the monitoring sensor corresponding to the hydrological data), x is the polynomial variable, p is the prime modulus, indicates that the operation is performed in the finite field of modulus p; The generation rule of the asymmetric encryption key pair: take the value of the polynomial at x = 1 as the private key, and generate the public key Q = d*G based on the elliptic curve point multiplication operation, where G is the curve base point.
[0035] In summary, the data encryption method in the above embodiment of the present invention realizes primary encryption through a dynamic one-way hash chain, combines a three-dimensional parameter key pool of time-space-random number for secondary encryption to improve security, and at the same time uses energy consumption-aware cluster head election and load balancing path allocation for data shards to reduce network energy consumption; at the same time, embed an authentication code containing space-time tags and cluster head IDs to further ensure the accuracy and security of the data, making the transmission of hydrological data take into account security, efficiency and reliability.
[0036] Embodiment Two The second embodiment of the present application further provides a data encryption system, which is used to implement the above-mentioned embodiment and preferred implementation manners. Those that have been described will not be repeated here. As used below, terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0037] As Figure 2 shown, the system includes: a network module 100, a sharding module 200, a primary encryption module 300, an aggregation module 400, and a secondary encryption module 500.
[0038] The network module 100 is used to divide the data network into an edge collection area, an intermediate transmission area, and a data monitoring area according to the hydrological monitoring target; The sharding module 200 is used to shard the hydrological data collected in the edge collection area according to timestamps to obtain multiple data segments, and perform area marking on the data segments based on the area distribution; The primary encryption module 300 is used to generate a dynamic temporary key based on a one-way hash chain to perform primary encryption on the data segments in the edge collection area, and transmit them to the intermediate transmission area; The aggregation module 400 is used to perform encrypted aggregation on the encrypted data segments in the intermediate transmission area to generate an aggregated data packet, and add an authentication code including the area location and timestamp to the aggregated data packet, and transmit it to the data monitoring area; The secondary encryption module 500 is used to select polynomial parameters from a preset three-dimensional key pool through the three-dimensional key pool to generate an asymmetric encryption key pair, and perform secondary encryption on the aggregated data packet based on the asymmetric encryption key pair to obtain an encrypted data packet.
[0039] Preferably, in this embodiment, the system further includes: A cluster head module, which is used to perform energy consumption-aware cluster head election in the intermediate transmission area to dynamically select the target cluster head for transmission. The weight formula for cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the security weight, is the number of keys that the node can store, is the encryption calculation speed, is the maximum key capacity of the node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, is the transmission delay.
[0040] Preferably, in this embodiment, the primary encryption module is specifically configured to: Based on the cluster head ID in the cluster head election result, mark the data fragments so that the data fragments are associated with the target cluster head; Generate a dynamic temporary key based on a one-way hash chain to perform primary encryption on the data fragments in the edge collection area, and allocate the corresponding data fragments to be transmitted to the intermediate transmission area based on the load conditions of each path.
[0041] Preferably, in this embodiment, the system further includes: A primary verification module, which is used to verify whether the cluster head ID in each data fragment is consistent with the target cluster head.
[0042] Preferably, in this embodiment, the aggregation module is specifically configured to: Add authentication information including the regional location and timestamp to the aggregated data packet, and generate an authentication code based on the cluster head ID in the data fragment to mark the aggregated data packet.
[0043] Preferably, in this embodiment, the system further includes: A secondary verification module, which is used to verify the authentication code after decrypting the encrypted data packet. If the verification fails, it triggers key update and cluster head re-election.
[0044] It should be noted that each of the above modules can be a functional module or a program module, and can be implemented either by software or by hardware. For the modules implemented by hardware, each of the modules can be located in the same processor; or each of the modules can also be located in different processors in any combined form.
[0045] Embodiment Three The third embodiment of the present application provides a computer, which may include a processor 81 and a memory 82 storing computer program instructions.
[0046] Specifically, the above processor 81 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0047] Among them, the memory 82 may include a mass storage for data or commands. By way of example and not limitation, the memory 82 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In a suitable case, the memory 82 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 82 may be inside or outside the data processing device. In a particular embodiment, the memory 82 is a non-volatile memory. In a particular embodiment, the memory 82 includes a read-only memory (ROM) and a random access memory (RAM). In a suitable case, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory (FLASH), or a combination of two or more of these. In a suitable case, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0048] The memory 82 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program commands executed by the processor 81.
[0049] The processor 81 reads and executes the computer program commands stored in the memory 82 to implement any one of the data encryption methods in the above embodiments.
[0050] In some of the embodiments, the computer may further include a communication interface 83 and a bus 80. Among them, as Figure 3 shown, the processor 81, the memory 82, and the communication interface 83 are connected through the bus 80 and complete communication with each other.
[0051] The communication interface 83 is used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application. The communication interface 83 can also implement data communication with other components such as external devices, image / data acquisition devices, databases, external storage, and image / data processing workstations, etc.
[0052] Bus 80 includes hardware, software, or both, and couples the components of a computer to each other. Bus 80 includes, but is not limited to, at least one of the following: Data Bus, Address Bus, Control Bus, Expansion Bus, Local Bus. By way of example and not limitation, Bus 80 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable bus or a combination of two or more of these. In a suitable case, Bus 80 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.
[0053] Embodiment Four The fourth embodiment of the present application provides a readable storage medium. A computer program command is stored on the readable storage medium; when the computer program command is executed by a processor, any of the data encryption methods in the above embodiments is implemented.
[0054] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0055] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A data encryption method, characterized in that: The following steps are involved: The data network is divided into edge collection area, intermediate transmission area and data monitoring area according to the hydrological monitoring objectives; The hydrological data collected in the edge collection area are fragmented according to the timestamp to obtain multiple data fragments, and the data fragments are regionally marked based on regional distribution; Generate a dynamic temporary key based on a one-way hash chain to encrypt the data fragments in the edge collection area once and transmit them to the intermediate transmission area; Encrypting and aggregating the encrypted data fragments in the intermediate transmission area to generate an aggregated data packet, adding an authentication code including a regional location and a timestamp to the aggregated data packet, and transmitting the aggregated data packet to the data monitoring area; A polynomial parameter is selected from a preset three-dimensional key pool to generate an asymmetric encryption key pair, so as to perform secondary encryption on the aggregated data packet based on the asymmetric encryption key pair to obtain an encrypted data packet.
2. The data encryption method according to claim 1, characterized in that: After the step of generating a dynamic temporary key based on a one-way hash chain to encrypt the data fragments in the edge collection area once, the method further includes: Energy-aware cluster head election is performed in the middle transmission area to dynamically select the target cluster head for transmission, where the weight formula for cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the safety weight, is the number of keys that a node can store, For encryption calculation speed, is the maximum key capacity of the node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, For transmission delay.
3. The data encryption method according to claim 2, characterized in that: The steps of generating a dynamic temporary key based on a one-way hash chain to encrypt the data fragments in the edge collection area once and transmitting them to the intermediate transmission area specifically include: Based on the cluster head ID of the cluster head election result, marking the data segment so that the data segment is associated with the target cluster head; A dynamic temporary key is generated based on a one-way hash chain to encrypt the data fragments in the edge collection area once, and the corresponding data fragments are allocated and transmitted to the intermediate transmission area based on the load conditions of each path.
4. The data encryption method according to claim 3, characterized in that: Before the step of encrypting and aggregating the encrypted data segments in the intermediate transmission area, the method further includes: Verify whether the cluster head ID in each data segment is consistent with the target cluster head.
5. The data encryption method according to claim 2, characterized in that: The step of adding an authentication code including a regional location and a timestamp to the aggregate data packet specifically comprises: Authentication information including the area location and a timestamp is added to the aggregate data packet, and an authentication code is generated based on the cluster head ID in the data segment to mark the aggregate data packet.
6. The data encryption method according to claim 5, characterized in that: The method further comprises: After the decryption of the encrypted data packet is completed, the authentication code is verified, and if the verification fails, key update and cluster head reselection are triggered.
7. A data encryption system, characterized in that: include: The network module is used to divide the data network into edge collection area, intermediate transmission area and data monitoring area according to the hydrological monitoring target; A sharding module is used to shard the hydrological data collected in the edge collection area according to the timestamp to obtain multiple data fragments, and to mark the data fragments based on regional distribution; A one-time encryption module is used to generate a dynamic temporary key based on a one-way hash chain to encrypt the data fragments in the edge collection area once and transmit them to the intermediate transmission area; An aggregation module, used to encrypt and aggregate the encrypted data fragments in the intermediate transmission area to generate an aggregated data packet, add an authentication code including a regional location and a timestamp to the aggregated data packet, and transmit it to the data monitoring area; The secondary encryption module is used to select polynomial parameters from a three-dimensional key pool through a preset three-dimensional key pool to generate an asymmetric encryption key pair, so as to perform secondary encryption on the aggregated data packet based on the asymmetric encryption key pair to obtain an encrypted data packet.
8. The data encryption system according to claim 7, characterized in that: The system further comprises: The cluster head module is used to perform energy-aware cluster head election in the middle transmission area to dynamically select the target cluster head for transmission. The weight formula of cluster head election is: ; is the node weight, is the energy weight, is the remaining energy of the node, is the maximum energy of the node, is the safety weight, is the number of keys that a node can store, For encryption calculation speed, is the maximum key capacity of the node, is the maximum encryption speed, is the link weight, is the packet loss rate, is the delay penalty coefficient, For transmission delay.
9. A computer comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the data encryption method according to any one of claims 1 to 6 is implemented.
10. A storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the data encryption method as described in any one of claims 1 to 6 is implemented.