Multi-level encryption-based trusted data transmission method and system, and medium
Through the multi-level combination of symmetric encryption and asymmetric encryption, and the use of quantum key distribution protocol to generate keys, the vulnerabilities in key distribution and management of traditional encryption methods are solved, and the security of data transmission is significantly improved.
Patent Information
- Application Number
- CN202510337101.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
AI Technical Summary
Traditional encryption methods have vulnerabilities in key distribution and management, which has led to the threat of the security of data transmission.
The confidentiality of key distribution and transmission is ensured through a multi-level combination of symmetric encryption and asymmetric encryption, and the generation of keys in combination with the quantum key distribution protocol.
It improves the security of data transmission, ensures effective protection of keys when network is unsafe, enhances the security of key distribution, and ensures the security and efficiency of data transmission in different network environments.
Smart Images

Figure CN120185884A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key management, and particularly to a trusted data transmission method, system and medium based on multi-level encryption. Background Art
[0002] In traditional data transmission, the protection of information relies on encryption technologies, including symmetric encryption, asymmetric encryption, etc. However, with the continuous evolution of network attack means, traditional encryption methods have obvious security risks in some scenarios. Specifically, existing traditional encryption methods usually adopt a combination of symmetric encryption and asymmetric encryption to protect data. The symmetric encryption algorithm has high encryption and decryption speeds, but there are difficulties in key management. Key distribution and storage are the main problems faced by symmetric encryption systems. Especially in a large-scale distributed environment, how to securely transmit keys becomes crucial. In traditional encryption systems, the transmission of keys often relies on pre-shared keys or public key infrastructures. In these ways, the key transmission process is vulnerable to network attacks, such as man-in-the-middle attacks, eavesdropping and forgery attacks, etc. Even when using asymmetric encryption methods, there are also security risks in the key exchange process. Summary of the Invention
[0003] The present application provides a trusted data transmission method, system and medium based on multi-level encryption, aiming to solve the technical problem that the traditional trusted data transmission method has loopholes in key distribution and management, threatening the security of data transmission. Through the multi-level combination of symmetric encryption and asymmetric encryption, and combining with the quantum key distribution protocol to generate keys, the confidentiality of key distribution and transmission is ensured, achieving the technical effect of improving the security of data transmission.
[0004] In the first aspect disclosed by the present application, a trusted data transmission method based on multi-level encryption is provided. The method includes: performing symmetric encryption on the original trusted data to be transmitted to generate an encrypted data packet; extracting a first key based on the encrypted data packet for asymmetric encryption to generate key protection data; generating a second key based on the quantum key distribution protocol; and transmitting the encrypted data packet, the key protection data, and the second key to a data receiving end through a public channel according to parameters adjusted by encryption strength, and the data receiving end decrypts them in sequence to obtain the original trusted data.
[0005] The second aspect disclosed in this application provides a trusted data transmission system based on multi-level encryption. The system is used for the above-mentioned trusted data transmission method based on multi-level encryption. The system includes: a symmetric encryption module for symmetrically encrypting the original trusted data to be transmitted to generate an encrypted data packet; an asymmetric encryption module for asymmetrically encrypting based on extracting a first key from the encrypted data packet to generate key protection data; a second key generation module for generating a second key based on the quantum key distribution protocol; and an original trusted data acquisition module for transmitting the encrypted data packet, the key protection data, and the second key to a data receiving end through a public channel according to parameters adjusted by encryption strength, and the original trusted data is obtained after being decrypted in sequence by the data receiving end.
[0006] The third aspect disclosed in this application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the trusted data transmission method based on multi-level encryption in the first aspect are implemented.
[0007] One or more technical solutions provided in this application have at least the following beneficial effects:
[0008] Through the multi-level combination of symmetric encryption and asymmetric encryption, the security of data in different transmission stages is ensured. First, the data is encrypted through symmetric encryption to enhance the confidentiality of the data. Then, the key data is further protected through asymmetric encryption to avoid key leakage. Combining the quantum key distribution protocol to generate a second key further enhances the security of the key, ensuring that the key can still be effectively protected even in an insecure network environment; by generating a second key based on the quantum key distribution protocol, the secure generation and transmission of the key can be ensured. The quantum key distribution protocol utilizes the measurement principle of quantum states to ensure the confidentiality of the key during transmission. Any eavesdropping or interference behavior will cause the destruction of the quantum state, thus detecting potential attackers in a timely manner and enhancing the security of key distribution; combining parameters adjusted by encryption strength to adjust the encryption strategy according to the real-time network state, this dynamic adjustment method ensures the security and efficiency of data transmission in different network environments; the data receiving end gradually restores the original trusted data through the key decryption process. The decryption processes of the encrypted data packet, the key protection data, and the second key all undergo strict multi-level encryption protection, ensuring that even if the data is intercepted during transmission, the attacker cannot easily decrypt the data. Through these steps, the receiving end can efficiently and securely restore the original data, ensuring the trustworthiness of data transmission.
[0009] The above description is only an overview of the technical solutions of this application. In order to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of this application more obvious and understandable, the following specifically illustrates the specific embodiments of this application. Brief Description of the Drawings
[0010] Figure 1 It is a schematic flowchart of a trusted data transmission method based on multi - level encryption provided by an embodiment of the present application.
[0011] Figure 2 It is a schematic structural diagram of a trusted data transmission system based on multi - level encryption provided by an embodiment of the present application.
[0012] Description of the reference numerals: Symmetric encryption module 10, Asymmetric encryption module 20, Second key generation module 30, Original trusted data acquisition module 40. Detailed Embodiments
[0013] By providing a trusted data transmission method, system and medium based on multi - level encryption, the embodiments of the present application solve the technical problem that the traditional trusted data transmission method has loopholes in key distribution and management, threatening the security of data transmission. Through the multi - level combination of symmetric encryption and asymmetric encryption, and combined with the quantum key distribution protocol to generate keys, the confidentiality of key distribution and transmission is ensured, achieving the technical effect of improving the security of data transmission.
[0014] After introducing the basic principle of the present application, the following will specifically introduce various non - restrictive embodiments of the present application in conjunction with the drawings of the specification. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0015] Embodiment 1, as Figure 1 shown, the embodiments of the present application provide a trusted data transmission method based on multi - level encryption, and the method includes:
[0016] Perform symmetric encryption on the original trusted data to be transmitted to generate an encrypted data packet.
[0017] Original trusted data refers to the data that needs to be securely transmitted through encryption, including sensitive information such as personal identity information, financial data, company secrets, etc. Select an appropriate symmetric encryption algorithm. Common symmetric encryption algorithms include AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc. Symmetric encryption requires the use of a single key for both encryption and decryption. Therefore, first, an encryption key needs to be generated. This key usually has a certain length, such as 128 bits, 256 bits, etc. The generated key must ensure its security to avoid leakage. Use the selected symmetric encryption algorithm and the generated key to encrypt the original trusted data. The encryption process converts the original data into ciphertext that cannot be directly read, thereby ensuring that the data is not stolen or tampered with during transmission. The encrypted result is called an encrypted data packet. This data packet includes the ciphertext and relevant information used during the encryption process, such as the encryption algorithm identifier, the encryption method of the key, etc. The encrypted data packet will serve as the carrier for transmitting the data.
[0018] Extract the first key from the encrypted data packet and perform asymmetric encryption to generate key-protected data.
[0019] Extract the first key of the symmetric encryption algorithm from the generated encrypted data packet. This key is the symmetric key used to encrypt the original data. The extraction process needs to ensure the security of the key to avoid leakage. Select an asymmetric encryption algorithm. Asymmetric encryption algorithms are usually based on the mechanism of public keys and private keys, such as RSA or ECC (Elliptic Curve Cryptography). Different from symmetric encryption, asymmetric encryption algorithms use two keys, namely the public key and the private key. The public key is used to encrypt data, and the private key is used to decrypt data.
[0020] For the extracted first key, use the asymmetric encryption algorithm to encrypt it. Specifically, perform asymmetric encryption based on the encrypted data packet to generate the first public key. Cross-verify the first public key with the second public key in the data receiving end to generate a combined public key certificate. Use the combined public key certificate to encrypt the first key. In this way, only the receiving end with the corresponding private key can decrypt this key. This is achieved through the public key encryption process of the asymmetric encryption algorithm. The encrypted first key is the key-protected data. This part of the data will be sent together with the encrypted data packet through the transmission channel to ensure the security of the key during data transmission.
[0021] Encrypting the first key through asymmetric encryption protects the key from being obtained by malicious attackers. Even if the encrypted data packet is intercepted, the attacker cannot decrypt the key-protected data because they do not have access to the private key of the receiving end.
[0022] Generate a second key based on the quantum key distribution protocol.
[0023] Quantum key distribution is a technology that uses the principles of quantum mechanics to achieve secure communication, which can effectively prevent eavesdropping attacks. A second key is generated based on the quantum key distribution protocol, and this key will be used in the subsequent encryption and decryption processes. Specifically, the data sender and receiver communicate through a quantum channel. First, a connection between the sender and receiver is established and the transmission channel for the quantum key is determined. The sender generates a set of quantum random number sequences, namely quantum bits, which will be used to generate a shared key in the subsequent steps. The sender encodes the generated quantum random number sequences into photon polarization states and sends these photons through the quantum channel to the receiver. The encoding of the quantum polarization state can ensure that it cannot be stolen during transmission. After the data receiver receives it, it measures the photon polarization state according to a predetermined random basis vector. Through quantum measurement, the receiver generates a set of raw quantum keys. The data sender and receiver generate a common quantum key by comparing their respective measurement results, and verify whether the used basis vectors are the same through public discussion to ensure that they share the same key. After comparison, the generated quantum key fragments are processed into a complete second key for the subsequent encryption and decryption processes.
[0024] The encrypted data packet, the key protection data, and the second key are transmitted to the data receiver through a public channel according to the parameters for adjusting the encryption strength, and the original trusted data is obtained after being decrypted in sequence by the data receiver.
[0025] The network transmission environment of the public channel is monitored in real time to obtain network state parameters, such as network bandwidth, latency, packet loss rate, signal strength, etc. These network state parameters are dynamic and may be affected by factors such as network attacks and traffic fluctuations. According to the real-time monitored network state, the encryption strength is dynamically adjusted. Specifically, the key length of the symmetric encryption algorithm is increased or decreased according to the security and quality of the network. For example, in a high-risk network environment, the key length will be increased to improve the encryption strength; the padding mode of the asymmetric encryption algorithm is adjusted, such as adding an additional encryption layer to further enhance the encryption strength.
[0026] The encrypted data packet, the key protection data, and the second key after adjusting the encryption strength are transmitted through the public channel. These data are packaged and sent through the network to the data receiver. During the transmission process, although there may be a risk of being stolen for the public channel, through the protection of multi-layer encryption, the security of the data is greatly enhanced.
[0027] After the data receiver receives the data, it first decrypts the key-protected data using the second key to recover the first key, which is the data key for symmetric encryption. Then, according to the actual conditions of the network and the adjusted encryption strength parameters, it loads an appropriate symmetric decryption algorithm module and uses the recovered first key to decrypt the encrypted data packet through the symmetric decryption algorithm, finally recovering the original trusted data. Through the above steps, the data receiver can successfully decrypt and restore the encrypted data packet, obtain the original trusted data, and complete the secure data transmission.
[0028] Furthermore, generating the second key based on the quantum key distribution protocol includes:
[0029] Traverse the data transmission channel to determine the data sender and the data receiver; generate a quantum random number sequence through the data sender, encode the quantum random number sequence into photon polarization states and send them to the data receiver; measure the photon polarization states by the data receiver according to random basis vectors to generate the original quantum key; compare the basis vectors between the data sender and the data receiver to generate a comparison result, the comparison result includes quantum key segments; process the original quantum key according to the quantum key segments to generate the second key.
[0030] In the process of quantum key distribution, it is first necessary to ensure the transmission channel of quantum communication, which can be a physical optical fiber network, free space optical communication, etc. Quantum key distribution requires the use of a dedicated quantum channel to ensure that information is not eavesdropped during transmission. The data sender and the data receiver need to establish a stable connection through this quantum channel. Among them, the data sender is the initiator in the process of quantum key distribution, usually using a quantum device to generate quantum random numbers; the data receiver is the receiving end, receiving photons and performing quantum measurements. The receiving end usually needs to be equipped with a quantum detection device that can detect and measure the photons transmitted through the quantum channel.
[0031] The data sender generates a quantum random number sequence through a quantum device, such as a quantum random number generator, based on the principles of quantum mechanics. These quantum random numbers are represented by quantum bits and have the uncertainty of quantum mechanics, which can ensure that the generated random numbers are unpredictable and have a high degree of security.
[0032] Encode the generated quantum random number sequence into photon polarization states. Photon polarization state is a physical state that describes the polarization direction of photons and can be used to transmit quantum information. The data sender selects different polarization bases, such as horizontal, vertical, diagonal, anti-diagonal, etc., according to the quantum random number sequence, and then encodes each quantum bit into the corresponding photon polarization state. These photon polarization states are the carriers of the quantum key and will be sent to the receiving end.
[0033] Send the encoded photon polarization state to the data receiving end through a quantum channel. During the transmission process, the integrity of the photon information and the polarization state are protected by quantum physics. Any potential eavesdropping attempt will change the quantum state, thus revealing the existence of the eavesdropper.
[0034] The data receiving end receives the photons transmitted through the quantum channel through a quantum detection device. Specifically, the data receiving end measures the qubits according to a pre-agreed measurement basis. Each photon polarization state corresponds to a random basis vector, that is, the measurement direction. The receiving end selects a basis vector that matches the sending end to measure the photons. Due to the unpredictability of quantum measurement, the receiving end can only determine the measurement result of the photons according to the rules of quantum mechanics. According to the measured results, the receiving end can extract a sequence of bits from the polarization state, usually 0 or 1, and these bits form the original quantum key. Due to the special nature of the quantum state, the measurement results of the sending end and the receiving end will form an identical key segment, and this key segment is used as the basis for subsequent encryption algorithms.
[0035] In the process of quantum key distribution, the sending end and the receiving end generate quantum key segments by measuring the photon polarization state. However, due to the uncertainty of quantum measurement, the sending end and the receiving end may choose different bases for measurement, resulting in a mismatch of some key segments. Therefore, basis vector comparison must be carried out to screen out those matching key segments, and these segments will become the keys used in the subsequent encryption process. The basis vector comparison is carried out through a classical channel. The classical channel is a conventional communication channel used to exchange public information but cannot be used to transmit keys. The sending end and the receiving end use the classical channel to exchange the basis information they used in the quantum key distribution process. What the two parties exchange is only the measurement basis, not the actual quantum key itself. The sending end and the receiving end compare whether the bases they selected are the same. If the basis vectors selected by both ends are the same, for example, both choose the horizontal basis or the diagonal basis, then their measurement results can be used as the shared quantum key segment, and the measurement results with the same basis vectors will be retained as valid quantum key segments.
[0036] The original quantum key is processed according to the quantum key segments, including privacy amplification and error correction. Among them, according to the properties of the quantum channel, such as channel noise, loss, etc., some key segments may not be reliable enough, or may have been obtained by eavesdroppers. Privacy amplification enhances the security of the remaining key by selecting reliable quantum key segments. Privacy amplification usually processes through a hash function, compresses the original quantum key segments, and generates a shorter but more secure final key. In this way, although some information of the original key segments sent may be leaked, after privacy amplification processing, the final key will be more secure; in the process of quantum key distribution, due to factors such as channel noise and transmission loss, some errors may occur. To ensure the accuracy of the generated key, the error correction step corrects these errors through the classical channel. The error correction process adjusts the relative error between the key segments at the sending end and the receiving end to ensure the integrity and consistency of the final key.
[0037] After privacy amplification and error correction are completed, the processed quantum key segments generate the final second key, which is used for subsequent data encryption and decryption processes. These steps make the generated key more secure and can effectively avoid man-in-the-middle attacks, ensuring the confidentiality of data transmission.
[0038] Furthermore, the basis vectors of the data sender and the data receiver are compared to generate a comparison result, including:
[0039] Extract the data of the data sender and the data receiver for basis vector comparison to obtain the basis vector comparison error rate; determine whether the basis vector comparison error rate exceeds a preset error threshold. When the basis vector comparison error rate exceeds the preset error threshold, terminate the quantum key distribution process and record the obtained network attack risk level; according to the network attack risk level, adjust the photon polarization state to generate photon polarization state adjustment data; update the quantum key segments based on the photon polarization state adjustment data and add them to the comparison result.
[0040] In the basis vector comparison stage, the sender and the receiver exchange the basis information they have selected through the classical channel, such as horizontal, vertical, diagonal, etc. Then, both sides compare their measurement results according to the selected basis. The error rate refers to the proportion of inconsistent measurement bases. For example, if 30% of the measurement results of the sender and the receiver are inconsistent, then the basis vector comparison error rate is 30%. The basis vector comparison error rate affects whether the generated quantum key segments can match. Since the measurement of quantum bits is essentially based on probability, the sender and the receiver may choose different bases for measurement in some cases, resulting in some inconsistent comparison results. Therefore, the basis vector comparison error rate is a key indicator to measure the consistency and reliability of the sender and the receiver in the process of quantum key distribution.
[0041] The preset error threshold is a standard used to determine whether anomalies occur during the quantum key distribution process. This threshold is usually set according to the actual application scenario, the characteristics of the quantum channel, and the communication security requirements. For example, the error threshold can be set to 5%, 10%, etc., to ensure that valid quantum keys can still be generated under a certain degree of error.
[0042] If the error rate of basis comparison is lower than the preset error threshold, it indicates that the quantum key distribution process is stable, and the generated key segments can continue to be used for subsequent key processing; conversely, if the error rate exceeds the preset error threshold, it indicates that there may be problems during the quantum key distribution process, such as excessive noise in the quantum channel, a large number of photon losses during transmission, or potential eavesdropping behavior. At this time, the key distribution process must be stopped to ensure communication security. When the error rate exceeds the threshold, record the network attack risk level. This level can be evaluated based on the magnitude of the error rate, the quality of the channel, and other factors that may affect quantum communication. Recording the risk level helps to track and analyze potential eavesdropping behavior or other attacks.
[0043] Adjust the quantum key distribution process according to the level of the network attack risk to ensure the security of the key. Specifically, if the attack risk level is low, it means that the quality of the quantum channel is good, and only minor adjustments are needed; if the attack risk level is high, it indicates that the quantum channel is likely to be severely interfered with or eavesdropped on. In this case, more stringent measures need to be taken to enhance the security of the key.
[0044] The purpose of adjusting the photon polarization state is to take additional measures during the communication process to improve the security of the key. Especially when network attacks are suspected, adjust the photon polarization state of the transmitted photons appropriately according to the attack risk level to prevent eavesdroppers from inferring the key content through incorrect measurements. The adjustment of the photon polarization state can be achieved by changing the direction of photon polarization. For example, adjust the photon polarization to different polarization states such as horizontal, vertical, diagonal, etc. After adjusting the photon polarization state, generate the corresponding photon polarization state adjustment data for subsequent key segment updates to ensure the security of the final key.
[0045] Update the original quantum key segments based on the new photon polarization state adjustment data. The updated key segments reflect the new quantum signals or the securely processed key information, making it more difficult for eavesdroppers to obtain or decrypt. During the basis comparison process, valid quantum key segments are generated only when the measurement bases are consistent. With the adjustment of the photon polarization state, the new polarization state can better align with the measurement bases at the receiving end, further improving the matching of the key segments. Add the updated quantum key segments to the basis comparison result to become part of the finally generated quantum key for encryption and decryption operations.
[0046] Furthermore, processing the original quantum key according to the quantum key segment to generate the second key includes:
[0047] Correct the original quantum key according to the basis comparison error rate based on the quantum key segment to generate a first quantum key; select a random hash function to compress the first quantum key to determine the compression ratio; perform privacy amplification on the first quantum key according to the compression ratio to generate an intermediate key; combine the intermediate key with the pre-shared identity information and generate the second key through a key derivation function.
[0048] According to the basis comparison error rate, correct the original quantum key based on the quantum key segment. The purpose of error correction is to ensure that the generated quantum key has no errors or damages, so that it can be safely used in encrypted communication. Generally, classical error correction codes, such as Hamming codes, low-density parity-check codes, etc., are used to correct the incorrect quantum bits. Through the error correction process, the original quantum key content can be effectively restored, eliminating potential security problems caused by errors. After error correction, the corrected quantum key segments are combined into a new quantum key, called the first quantum key, for subsequent processing.
[0049] During the generation of quantum keys, the hash function can compress the input quantum key data into a smaller output, and improve the security of the key through this compression process. Here, a linear hash function constructed by a Toeplitz matrix is used. This type of hash function has high collision resistance and anti-derivation ability, and is suitable for use in the quantum key generation process. The main purpose of compression is to reduce the size of the key, making the key easier to store and transmit, while removing redundant information. Through compression, the accuracy and information content of the quantum key can be controlled to ensure the security and effectiveness of the key. The compression ratio is usually determined based on the length of the original quantum key and the properties of the hash function. The compressed key should maintain sufficient security while reducing its length to reduce storage and transmission overhead.
[0050] Privacy amplification is used to enhance the security and attack resistance of the key. Through privacy amplification, some potentially leaked information can be concealed, making the key more difficult to be deduced or cracked by eavesdroppers. The core idea of privacy amplification is to expand the key fragment so that even if the attacker obtains partial information, they cannot infer the complete content of the key. In this step, privacy amplification processes the first quantum key according to the compression ratio. After the compressed key undergoes privacy amplification, a new intermediate key will be generated, thereby increasing the security of the key.
[0051] In the process of quantum key distribution, identity information is usually used to verify the validity of the key. By combining pre-shared identity information, it can be ensured that the keys used by both parties match their identities, thereby enhancing the security of the keys. The pre-shared identity information includes the authentication information of both parties, such as passwords, key phrases, or other security authentication information.
[0052] The key derivation function is an algorithm used to generate new keys. In this process, the key derivation function combines the intermediate key and the pre-shared identity information as inputs to generate the final second key, which contains the key after privacy amplification and identity information verification and is used for security operations such as encryption, decryption, and identity authentication in communication.
[0053] Furthermore, the process of obtaining the encryption strength adjustment parameter includes:
[0054] Performing real-time monitoring of the network transmission environment of the public channel to generate a set of network state parameters; according to the set of network state parameters, traversing the encryption strength rule library for matching to determine the encryption algorithm combination, where the encryption algorithm combination includes the key length of the symmetric encryption algorithm and the padding mode of the asymmetric encryption algorithm; when there is a network attack event in the set of network state parameters, increasing the key length of the symmetric encryption algorithm to a preset security threshold and activating the padding mode of the asymmetric encryption algorithm for double asymmetric encryption to determine the encryption strength adjustment parameter.
[0055] Performing real-time monitoring of the network transmission environment of the public channel includes monitoring latency, bandwidth, and packet loss rate. Among them, the latency of the network affects the time efficiency of data transmission. In the case of high latency, data may take longer to reach the receiving end from the sending end, which will affect the real-time performance of encrypted communication; bandwidth is a measure of the available data transmission rate in the network. When the bandwidth is insufficient, it may lead to a bottleneck in data transmission and affect the execution efficiency of the encryption algorithm; the packet loss rate refers to the proportion of lost data packets during network transmission. A higher packet loss rate usually leads to unstable data transmission and increases the risk of encrypted transmission.
[0056] By monitoring these network transmission environment parameters in real time, a set of network status parameters including latency, bandwidth, and data packet loss rate is generated. These parameters are used to adjust the encryption algorithm to ensure the security and efficiency of communication.
[0057] The encryption strength rule library is a predefined rule set used to select appropriate encryption algorithms and encryption parameters according to the network environment. This rule library contains encryption algorithm selection strategies under different network conditions to ensure the security and efficiency of communication in different environments. According to the set of network status parameters obtained from real-time monitoring, traverse the encryption strength rule library to find the encryption algorithm combination that best matches the current network environment. The encryption algorithm combination includes the key length of the symmetric encryption algorithm and the padding mode of the asymmetric encryption algorithm. Among them, different network statuses require different key lengths to balance encryption strength and encryption efficiency; different padding modes are used in the encryption process of the asymmetric encryption algorithm, such as PKCS#1, OAEP, etc., and these modes will affect the security and efficiency of encryption.
[0058] When anomalies are detected in the set of network status parameters during real-time monitoring, or potential network attack events are discovered, such as a sharp increase in latency, abnormal packet loss rate, or abnormal bandwidth, it is necessary to promptly adjust the encryption strategy. Specifically, if a network attack is detected, it may reduce the security of network transmission. At this time, it is necessary to increase the key length of the symmetric encryption algorithm to improve the strength of the key and enhance the difficulty of key cracking. A longer key will increase the encryption strength, thereby improving the security of communication; at the same time, activate the padding mode of the asymmetric encryption algorithm. This padding mode enhances the security of encryption by adding additional redundant data. Common padding modes include PKCS#1 and OAEP, which can resist certain types of attacks, such as chosen-plaintext attacks. Double asymmetric encryption, that is, first use one asymmetric encryption algorithm to encrypt the data, and then use another asymmetric encryption algorithm to encrypt the result. This double encryption increases the difficulty for attackers to crack the encryption.
[0059] Finally, based on the adjusted key length and padding mode, new encryption strength adjustment parameters are generated. These parameters will be used to update the encryption algorithm configuration and ensure sufficient security in the event of a network attack.
[0060] Furthermore, extracting the first key from the encrypted data packet for asymmetric encryption to generate key protection data includes:
[0061] Based on the encrypted data packet, perform asymmetric encryption according to the elliptic curve cryptosystem to generate a first public key; cross-verify the first public key with the second public key in the data receiving end to generate a combined public key certificate; use the combined public key certificate to encrypt the first key to obtain the key protection data.
[0062] The elliptic curve cryptosystem is an asymmetric encryption algorithm widely used to improve encryption efficiency and security. It utilizes the mathematical structure of elliptic curves to provide strong encryption protection while maintaining a low computational cost. Encrypted data packets are asymmetrically encrypted according to the elliptic curve cryptosystem to generate the first public key required for encryption. Although the first private key is generated synchronously in this step, since it is not directly used in the subsequent process, the ultimate focus is on the first public key.
[0063] To ensure the security of data and the authenticity of both parties' identities, it is necessary to cross-verify the generated first public key with the second public key at the receiving end. Cross-verification validates the effectiveness of both parties' public keys, ensuring there is no potential malicious tampering or forgery. The verification process includes checking whether the first public key and the second public key conform to the expected format and standards, specifically through multiple dimensions such as checking whether the public key conforms to the expected format, whether it is signed by a trusted certificate authority, and whether it is within the valid period.
[0064] If the verification is successful, the two parties' public keys will be integrated after verification to generate a combined public key certificate, which indicates that the public key pair has been verified and can be safely used for data encryption and identity confirmation. Conversely, if the verification fails, the key escrow mechanism will be triggered to ensure that untrusted public keys are not used for encryption or signature operations, safeguarding the security of communication.
[0065] After passing the cross-verification and generating the combined public key certificate, the first key is then encrypted using this certificate. In this way, the key will be protected and its security ensured. Only the receiving party with the correct private key can decrypt and use the key. The encryption process ultimately results in key-protected data, which is an encrypted key data, guaranteeing the effective protection of the key during transmission and storage.
[0066] Furthermore, after cross-verifying the first public key with the second public key in the data receiving end, it includes:
[0067] Cross-verify the first public key with the second public key in the data receiving end. If the second public key fails the verification, trigger the key escrow mechanism, split the first key into multiple sub-key fragments; encrypt each of the multiple sub-key fragments and store them in multiple trusted third-party nodes; when the data receiving end passes the identity authentication, obtain the sub-key fragments from the trusted third-party nodes for recombination to obtain the first key.
[0068] If the cross-verification fails, it indicates that there may be identity issues or the public key is untrusted. At this time, the key escrow mechanism is triggered. The purpose of the key escrow mechanism is to ensure that the key can still be securely processed and managed in the case of public key verification failure. Through the escrow mechanism, the first key will be further split and encrypted, so as to ensure that even if there are problems with the public key, the integrity and security of the key can still be protected. Under the key escrow mechanism, the first key is split into multiple sub-key fragments. This splitting process increases the security of the key, so that even if some sub-key fragments are stolen, the attacker cannot reconstruct the entire key. The number and splitting method of the sub-key fragments are designed according to the system security policy and key management standards to ensure the security of the storage and processing of each sub-key fragment.
[0069] Each sub-key fragment is encrypted to ensure that even if the sub-key fragment is illegally accessed, the attacker cannot use them to reconstruct the original key. The encryption method can use symmetric encryption or asymmetric encryption to ensure the security of the key fragment during storage. The encrypted sub-key fragments are distributed and stored in multiple trusted third-party nodes. These third-party nodes can be a distributed storage system or node services provided by multiple independent institutions. The trusted third-party nodes usually need to go through strict authentication and will use encryption technology to protect the confidentiality of data during the entire storage process. In this way, even if some third-party nodes are attacked, the sub-key fragments in other nodes are still secure and the complete key cannot be recovered by breaking a single node.
[0070] Before the data receiving end prepares to reconstruct the key, identity authentication needs to be carried out. After passing the identity authentication, the receiving end will send requests to multiple trusted third-party nodes to gradually obtain all the sub-key fragments. Each node only returns a part of the key. The receiving end needs to obtain the complete key fragments from multiple nodes. After receiving all the sub-key fragments, the receiving end reconstructs these fragments and combines them into the original first key. The reconstruction process is completed through a predetermined algorithm or protocol, usually through the inverse process of the encryption algorithm, to ensure the accuracy of key reconstruction.
[0071] Furthermore, the original trusted data is obtained by decrypting in sequence by the data receiving end, including:
[0072] Using the second key to decrypt the key-protected data to obtain the first key; adjusting the parameters according to the encryption strength and loading the symmetric decryption algorithm module; using the first key through the symmetric decryption algorithm module to decrypt and restore the encrypted data packet to obtain the original trusted data.
[0073] The key protection data is decrypted using the second key. The decryption process ensures that only the legitimate recipient can recover the first key with the correct second key. After successful decryption, the first key is obtained, which is the core key for encrypting data packets and protecting data.
[0074] The encryption strength adjustment parameters are obtained based on the monitoring and dynamic adjustment of network status, encryption strength, etc. in the foregoing steps. These parameters include settings such as the key length, encryption mode, and padding mode required for the symmetric encryption algorithm. According to these adjustment parameters, the symmetric decryption algorithm module is automatically loaded. This module performs data decryption according to the actual encryption strength requirements. The symmetric decryption algorithm module is the core part of the decryption process. It uses the first key to perform the decryption operation on the encrypted data packet. The symmetric decryption algorithm generally uses the same key for encryption and decryption, so it is necessary to ensure the correctness of the first key.
[0075] When the symmetric decryption algorithm module is loaded, the encrypted data packet is decrypted and restored using the first key. The content of the data packet is protected by symmetric encryption, and the first key is the key to decrypting this data. The decryption process gradually restores the original trusted data. These data were initially encrypted at the sender to protect privacy and security. Through symmetric decryption, the originally encrypted data packet is restored to the original trusted data, which are the core content in encrypted communication and may include user information, transaction records, or other important encrypted data.
[0076] In summary, the trusted data transmission method based on multi-level encryption provided by the embodiments of the present application has the following technical effects:
[0077] Through the multi-level combination of symmetric encryption and asymmetric encryption, the security of data in different transmission stages is ensured. First, the data is encrypted by symmetric encryption to enhance the confidentiality of the data. Then, the key data is further protected by asymmetric encryption to avoid key leakage. A second key is generated by combining with the quantum key distribution protocol, which further enhances the security of the key and ensures that the key can still be effectively protected even in an insecure network environment. By generating a second key based on the quantum key distribution protocol, the secure generation and transmission of the key can be ensured. The quantum key distribution protocol utilizes the measurement principle of quantum states to ensure the confidentiality of the key during transmission. Any eavesdropping or interference behavior will cause the destruction of the quantum state, thereby detecting potential attackers in a timely manner and enhancing the security of key distribution. The encryption strategy is adjusted according to the real-time network status by combining encryption strength adjustment parameters. This dynamic adjustment method ensures the security and efficiency of data transmission in different network environments. The data receiving end gradually restores the original trusted data through the key decryption process. The decryption processes of the encrypted data packet, key-protected data, and the second key are all protected by strict multiple encryptions, ensuring that even if the data is intercepted during transmission, the attacker cannot easily decrypt the data. Through these steps, the receiving end can efficiently and securely restore the original data, ensuring the credibility of data transmission.
[0078] Embodiment 2, based on the same inventive concept as the trusted data transmission method based on multi-level encryption in the foregoing embodiment, as Figure 2 shown, the embodiment of the present application provides a trusted data transmission system based on multi-level encryption, and the system includes:
[0079] A symmetric encryption module 10, configured to perform symmetric encryption on the original trusted data to be transmitted to generate an encrypted data packet.
[0080] An asymmetric encryption module 20, configured to perform asymmetric encryption based on the first key extracted from the encrypted data packet to generate key-protected data.
[0081] A second key generation module 30, configured to generate a second key based on the quantum key distribution protocol.
[0082] An original trusted data acquisition module 40, configured to transmit the encrypted data packet, the key-protected data, and the second key to the data receiving end through a common channel according to the encryption strength adjustment parameters, and the data receiving end decrypts them in sequence to obtain the original trusted data.
[0083] Furthermore, the second key generation module 30 includes the following operation steps:
[0084] Traverse the data transmission channel to determine the data sender and the data receiver; generate a quantum random number sequence through the data sender, encode the quantum random number sequence into a photon polarization state and send it to the data receiver; measure the photon polarization state by the data receiver according to a random basis vector to generate an original quantum key; compare the basis vectors of the data sender and the data receiver to generate a comparison result, where the comparison result includes a quantum key segment; process the original quantum key according to the quantum key segment to generate the second key.
[0085] Furthermore, the second key generation module 30 further includes the following operating steps:
[0086] Extract the data of the data sender and the data of the data receiver for basis vector comparison to obtain a basis vector comparison error rate; determine whether the basis vector comparison error rate exceeds a preset error threshold. When the basis vector comparison error rate exceeds the preset error threshold, terminate the quantum key distribution process and record the obtained network attack risk level; adjust the photon polarization state according to the network attack risk level to generate photon polarization state adjustment data; update the quantum key segment based on the photon polarization state adjustment data and add it to the comparison result.
[0087] Furthermore, the second key generation module 30 further includes the following operating steps:
[0088] Correct the original quantum key according to the basis vector comparison error rate based on the quantum key segment to generate a first quantum key; select a random hash function to compress the first quantum key to determine a compression ratio; perform privacy amplification on the first quantum key according to the compression ratio to generate an intermediate key; combine the intermediate key with pre-shared identity information and generate the second key through a key derivation function.
[0089] Furthermore, the original trusted data acquisition module 40 includes the following operating steps:
[0090] Perform real-time monitoring of the network transmission environment of the public channel to generate a set of network state parameters; according to the set of network state parameters, traverse the encryption strength rule library for matching to determine an encryption algorithm combination, where the encryption algorithm combination includes the key length of the symmetric encryption algorithm and the padding mode of the asymmetric encryption algorithm; when there is a network attack event in the set of network state parameters, increase the key length of the symmetric encryption algorithm to a preset security threshold and activate the padding mode of the asymmetric encryption algorithm for double asymmetric encryption to determine the encryption strength adjustment parameters.
[0091] Furthermore, the asymmetric encryption module 20 includes the following operating steps:
[0092] Based on the encrypted data packet, perform asymmetric encryption according to the elliptic curve cryptosystem to generate a first public key; cross-verify the first public key with a second public key in the data receiving end to generate a joint public key certificate; use the joint public key certificate to encrypt the first key to obtain the key-protected data.
[0093] Furthermore, the asymmetric encryption module 20 further includes the following operation steps:
[0094] Cross-verify the first public key with a second public key in the data receiving end. If the second public key fails the verification, trigger the key escrow mechanism, split the first key into multiple sub-key fragments; encrypt the multiple sub-key fragments respectively and store them in multiple trusted third-party nodes; when the data receiving end passes the identity authentication, obtain the sub-key fragments from the trusted third-party nodes for recombination to obtain the first key.
[0095] Furthermore, the original trusted data acquisition module 40 further includes the following operation steps:
[0096] Use the second key to decrypt the key-protected data to obtain the first key; adjust the parameters according to the encryption strength and load the symmetric decryption algorithm module; use the first key through the symmetric decryption algorithm module to decrypt and restore the encrypted data packet to obtain the original trusted data.
[0097] Through the foregoing detailed description of the trusted data transmission method based on multi-level encryption in this specification, those skilled in the art can clearly know the trusted data transmission system based on multi-level encryption in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For related parts, refer to the description in the method part.
[0098] Embodiment 3 provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, any step of Embodiment 1 is implemented.
[0099] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0100] The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A trusted data transmission method based on multi-level encryption, characterized in that: The method comprises: Symmetrically encrypt the original trusted data to be transmitted to generate an encrypted data packet; Extracting a first key based on the encrypted data packet to perform asymmetric encryption and generate key protection data; Generate a second key based on a quantum key distribution protocol; The encrypted data packet, the key protection data, and the second key are transmitted to the data receiving end through a public channel according to the encryption strength adjustment parameter, and the data receiving end decrypts them in sequence to obtain the original trusted data.
2. The trusted data transmission method based on multi-level encryption as claimed in claim 1, characterized in that: Generating a second key based on a quantum key distribution protocol, including: Traverse the data transmission channel to determine the data sending end and the data receiving end; Generate a quantum random number sequence through a data sending end, encode the quantum random number sequence into a photon polarization state and send it to a data receiving end; The data receiving end measures the polarization state of the photon according to a random basis vector to generate an original quantum key; Performing basis vector comparison between a data transmitting end and a data receiving end to generate a comparison result, wherein the comparison result includes a quantum key fragment; The original quantum key is processed according to the quantum key fragment to generate the second key.
3. The trusted data transmission method based on multi-level encryption as claimed in claim 2, characterized in that: The data transmitter and the data receiver are compared by base vectors to generate comparison results, including: Extract the data from the data sending end and the data from the data receiving end to perform basis vector comparison, and obtain the basis vector comparison error rate; Determine whether the basis vector comparison error rate exceeds a preset error threshold, and when the basis vector comparison error rate exceeds the preset error threshold, terminate the quantum key distribution process and record and obtain the network attack risk level; According to the network attack risk level, the photon polarization state is adjusted to generate photon polarization state adjustment data; The quantum key fragment is updated based on the photon polarization state adjustment data and added to the comparison result.
4. The trusted data transmission method based on multi-level encryption as claimed in claim 2, characterized in that: Processing the original quantum key according to the quantum key fragment to generate the second key includes: Based on the quantum key fragment, the original quantum key is corrected according to the basis vector comparison error rate to generate a first quantum key; Selecting a random hash function to compress the first quantum key and determining a compression ratio; Amplify the first quantum key according to the compression ratio to generate an intermediate key; The intermediate key is combined with the pre-shared identity information to generate the second key through a key derivation function.
5. The trusted data transmission method based on multi-level encryption as claimed in claim 1, characterized in that: The process of obtaining the encryption strength adjustment parameter includes: Conduct real-time monitoring of the network transmission environment of the public channel and generate a set of network status parameters; According to the network status parameter set, traverse the encryption strength rule library for matching and determine the encryption algorithm combination, wherein the encryption algorithm combination includes the key length of the symmetric encryption algorithm and the padding mode of the asymmetric encryption algorithm; When a network attack event occurs in the network status parameter set, the key length of the symmetric encryption algorithm is increased to a preset security threshold, and the filling mode of the asymmetric encryption algorithm is activated to perform double asymmetric encryption, and the encryption strength adjustment parameter is determined.
6. The trusted data transmission method based on multi-level encryption as claimed in claim 1, characterized in that: Extracting a first key based on the encrypted data packet to perform asymmetric encryption and generate key protection data, including: Perform asymmetric encryption based on the encrypted data packet according to the elliptic curve cryptography system to generate a first public key; Cross-verify the first public key with the second public key in the data receiving end to generate a joint public key certificate; The first key is encrypted using the joint public key certificate to obtain the key protection data.
7. The trusted data transmission method based on multi-level encryption as claimed in claim 6, characterized in that: After cross-verifying the first public key with the second public key in the data receiving end, the method includes: Cross-verify the first public key with the second public key in the data receiving end. If the second public key fails the verification, trigger the key escrow mechanism to split the first key into multiple sub-key fragments; Encrypting the multiple sub-key fragments respectively and storing them in multiple trusted third-party nodes; When the data receiving end passes the identity authentication, the sub-key fragments are obtained from the trusted third-party node for reorganization to obtain the first key.
8. The trusted data transmission method based on multi-level encryption as claimed in claim 1, characterized in that: The data receiving end decrypts the original trusted data in sequence, including: Decrypting the key-protected data using the second key to obtain the first key; Adjust parameters according to the encryption strength and load a symmetric decryption algorithm module; The encrypted data packet is decrypted and restored using the first key through the symmetric decryption algorithm module to obtain the original trusted data.
9. A trusted data transmission system based on multi-level encryption, characterized in that: For implementing the trusted data transmission method based on multi-level encryption according to any one of claims 1 to 8, the system comprises: A symmetric encryption module is used to symmetrically encrypt the original trusted data to be transmitted and generate an encrypted data packet; an asymmetric encryption module, used to extract a first key based on the encrypted data packet to perform asymmetric encryption and generate key protection data; A second key generation module, used to generate a second key based on a quantum key distribution protocol; The original trusted data acquisition module is used to transmit the encrypted data packet, the key protection data, and the second key to the data receiving end through a public channel according to the encryption strength adjustment parameter, and the data receiving end decrypts them in sequence to obtain the original trusted data.
10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the trusted data transmission method based on multi-level encryption according to any one of claims 1 to 8 are implemented.