Communication network data leakage prevention method
By using dynamic key systems and quantum mechanics principles to generate random keys in the communication network, and combining zero-knowledge proof and distributed ledger technology for data segmentation and reorganization, the problems of insufficient security of data transmission and inflexible key management in the communication network are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510379105.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-24
AI Technical Summary
Data transmission security in existing communication networks is insufficient, random key life cycle management is inflexible, and data segmentation and reorganization are inefficient.
The dynamic key system is used to combine quantum mechanics principles to generate random keys, and the key life cycle is managed by the time-destruction mechanism unit. Use zero-knowledge proof to segment and encrypt data, and record the transmission path and reorganization order of data segments through distributed ledger technology.
It significantly improves the security of data transmission in communication networks, effectively prevents data leakage, ensures data privacy protection, and realizes transparency and traceability of data transmission. It is suitable for complex and changeable network environments.
Smart Images

Figure CN120200744A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication network data security. Specifically, it relates to a method and system for preventing data leakage in a communication network. Background Art
[0002] Today, with the wide application of technologies such as cloud computing, the Internet of Things, and edge computing, massive amounts of data are exchanged through complex network environments. Traditional security measures are increasingly difficult to fully address the growing security threats. Therefore, how to effectively prevent data leakage in communication networks has become a key issue that urgently needs to be solved in the current information technology field.
[0003] In the specific practice of preventing data leakage in communication networks, existing technologies mainly rely on encryption algorithms and access control policies to ensure data security. However, in certain specific scenarios, such as high-concurrency real-time communication or cross-domain data transmission, these methods have obvious limitations. On the one hand, traditional encryption methods may reduce system performance due to the high complexity of key management; on the other hand, access control mechanisms often struggle to adapt to dynamic network environments, especially in data sharing scenarios involving multi-party collaboration, where permission management is prone to vulnerabilities. Summary of the Invention
[0004] Embodiments of the present invention provide a method and system for preventing data leakage in a communication network, a computer-readable medium, and an electronic device, thereby at least to some extent solving the problems of insufficient data transmission security, inflexible random key lifecycle management, and low data segmentation and recombination efficiency in existing communication networks.
[0005] Other features and advantages of the present invention will become apparent through the following detailed description, or will be partially learned through the practice of the present invention.
[0006] According to one aspect of the present invention, there is provided a method for preventing data leakage in a communication network, including:
[0007] In a dynamic key system for generating communication network data, a random key is generated using the principles of quantum mechanics, and in combination with a time destruction mechanism unit in the dynamic key system, the random key is processed during data transmission;
[0008] The generation of the random key includes data segmentation and data recombination based on zero-knowledge proof. The data segmentation includes, before transmitting the random key, dividing the transmitted data into N data segments and encrypting each data segment through a zero-knowledge proof algorithm;
[0009] The data reorganization includes using distributed ledger technology to record the transmission path and reorganization order of data segments. The reorganization order includes writing the data segments into the distributed ledger before the random key transmission and reorganizing them in the order of writing into the distributed ledger to complete the transmission of communication network data.
[0010] In the present invention, based on the foregoing solution, the time destruction mechanism unit includes assigning a timestamp to the generated random key. The timestamp includes defining the period of the random key. When the period N is exceeded, the random key becomes invalid.
[0011] The defined period of the random key includes a period definition mechanism that combines the design intelligence of the communication network. The design intelligence period definition mechanism includes introducing a network environment perception module for design. The network environment perception module includes the network environment and network communication frequency, and defines the period of the random key according to the network environment perception module.
[0012] The network environment includes collecting network metrics through network performance monitoring sensors. When the monitored network latency is greater than / ms, the period N is shortened.
[0013] The network communication frequency includes high-frequency communication and low-frequency communication. The shortening of the period N includes performing it in the scenario where the number of transmissions per second of high-frequency communication is greater than ∈ times.
[0014] When the monitored network latency is less than or equal to / ms, the network environment is at a normal level. At this time, it is performed in the scenario where the number of transmissions per second of low-frequency communication is less than or equal to ∈ times.
[0015] In the present invention, based on the foregoing solution, the splitting of the transmitted data into N data segments includes introducing a multi-level splitting mechanism to classify the original data D. The classification of the original data D includes defining the splitting points of the original data D.
[0016] The multi-level splitting mechanism includes coarse-grained splitting and fine-grained splitting, and introducing dynamic context variables C coares and C fine ;
[0017] Coarse-grained splitting is used to divide data segments, and fine-grained splitting is used to perform secondary division on the divided data segments.
[0018] The introduction of dynamic context variables C coares and C fine includes expanding the dynamic context variables. The expansion includes analyzing the traffic patterns of the dynamic context variables. The analysis of the traffic patterns of the dynamic context variables includes capturing the data packets of the data segments using the IP address, extracting the packet features, and establishing a traffic pattern model.
[0019] The establishment of the traffic pattern model includes dynamically adjusting the judgment threshold according to the current network state. The dynamic adjustment of the judgment threshold for the current network state includes preprocessing the state data collected from the current network. The preprocessing includes constructing a network state vector S using the state data collected from the current network, and mapping the original data D and the state data collected from the current network through a non-linear transformation;
[0020] The mapping includes delay feature mapping, bandwidth utilization feature mapping, traffic load feature mapping, device location feature mapping, and abnormal signal feature mapping.
[0021] In the present invention, based on the foregoing solution, the division of data segments includes adjusting the corresponding adjustment amount according to the overall state score value of the current network:
[0022] When Score(S) < threshold1, the corresponding threshold adjustment amount is ΔT1, where Score(S) represents the overall state score value of the current network;
[0023] When threshold1 ≤ Score(S) < threshold2, the corresponding threshold adjustment amount is ΔT2;
[0024] When Score(S) ≥ threshold2, the corresponding threshold adjustment amount is ΔT3;
[0025] Dynamically adjust the judgment threshold according to the interval to which the overall state score value of the current network belongs;
[0026] The coarse-grained segmentation further includes determining the size of the coarse-grained segmentation according to the dynamically adjusted threshold T dynamic , and determining the size of the coarse-grained segmentation;
[0027] The secondary segmentation on the divided data segments includes further dividing the size of the coarse-grained segmentation into the size of the fine-grained segmentation.
[0028] In the present invention, based on the foregoing solution, the use of the distributed ledger technology to record the transmission path of the data segment includes assigning identifiers to the size of the coarse-grained segmentation Segment Size coarse and the size of the fine-grained segmentation , introducing a dynamic path optimization mechanism to obtain the transmission path, defining the network topology structure of the data segment, selecting the transmission process when the network delay is less than or equal to / ms, and assigning an initial transmission path to the data segment when it is less than or equal to / ms,
[0029] The described initial transmission path allocation includes deploying a smart contract on a distributed ledger and defining recording rules. The defining of the recording rules includes the sender submitting the meta-information of the data segment by calling the deployed smart contract interface, verifying the received meta-information, and the verification includes the sender proving the meta-information of the data segment and recording the transmission path of the data segment;
[0030] Combined with the overall status score value of the current network, collect the bandwidth utilization rate and latency packet loss rate of the transmission path, organize structured objects, use the smart contract to score the received meta-information, and divide it into three levels: I, II, and III according to the overall status score value. The higher the level, the higher the overall status score value corresponding to this level is given priority to allocate the transmission path.
[0031] In the present invention, based on the foregoing solution, the writing of the data segment into the distributed ledger includes using the smart contract to automatically verify and record the information of the data segment into the distributed ledger. The smart contract writes the meta-information of the data segment into the distributed ledger to generate a distributed consensus mechanism, and each data segment verifies the recording request according to the consensus mechanism;
[0032] If an agreement is reached, the record is written into the distributed ledger.
[0033] In the present invention, based on the foregoing solution, the reorganization according to the writing order into the distributed ledger includes using the timestamp information recorded in the distributed ledger to sort the data segments according to the writing order, using the time window mechanism to dynamically process the sorting anomalies caused by network latency or data segment loss, by setting the time window range, reinserting the delayed data segments into the sorting queue, and checking for invalid or duplicate data segments for the data segment records read by the receiver from the distributed ledger.
[0034] In the present invention, based on the foregoing solution, the sorting anomalies include extracting historical records from the distributed ledger, statistically analyzing the network latency distribution, defining the time window expansion factor and contraction factor according to the historical records extracted from the distributed ledger, triggering the delayed data segments, and reinserting them into the sorting queue twice to complete the transmission of the communication network data.
[0035] According to one aspect of the present invention, there is provided a communication network data anti-leakage system, including:
[0036] A random key processing module, which generates a random key using the principle of quantum mechanics in the dynamic key system generated by the communication network data, and combines with the time destruction mechanism unit in the dynamic key system to process the random key during the data transmission process;
[0037] Data segmentation module. The generation of random keys includes data segmentation and recombination based on zero-knowledge proof. The data segmentation includes, before the transmission of the random key, splitting the transmission data into N data segments and encrypting each data segment through a zero-knowledge proof algorithm.
[0038] Data recombination module. The data recombination includes using distributed ledger technology to record the transmission path and recombination order of the data segments. The recombination order includes, before the transmission of the random key, writing the data segments into the distributed ledger and recombining them in the order of writing into the distributed ledger to complete the transmission of communication network data.
[0039] In the technical solution of the present invention, by combining the principle of quantum mechanics to generate random keys and the time destruction mechanism of the dynamic key system, the security of communication network data transmission is significantly improved, effectively preventing data leakage. Zero-knowledge proof is introduced for data segmentation and encryption to ensure privacy protection of data during transmission. At the same time, distributed ledger technology is used to record the transmission path and recombination order of data segments, realizing the transparency and traceability of data transmission. In addition, through dynamic context variables and multi-level segmentation mechanisms, the data segmentation granularity is optimized to adapt to different network environment requirements. The time destruction mechanism combined with the network environment perception module intelligently adjusts the life cycle of random keys, reducing the risk of key cracking. The time window mechanism and sorting exception handling strategy effectively cope with network delays or data loss problems, ensuring the accuracy of data recombination, improving the data security, transmission efficiency and system flexibility of the communication network, and being applicable to complex and changeable network environments.
[0040] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. Brief Description of the Drawings
[0041] The drawings here are incorporated into the specification and form a part of this specification, showing the embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0042] Figure 1 Schematically shows the flowchart of the method for preventing data leakage in a communication network in an embodiment of the present invention.
[0043] Figure 2 Schematically shows the segmentation flowchart of the method for preventing data leakage in a communication network in an embodiment of the present invention.
[0044] Figure 3Schematically shows the reorganization flowchart of the communication network data anti-leakage method in an embodiment of the present invention. Detailed implementation manners
[0045] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this invention will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0046] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present invention. However, those skilled in the art will realize that the technical solutions of the present invention may be practiced without one or more of the specific details, or may be implemented using other methods, components, devices, steps, etc. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present invention.
[0047] The implementation details of the technical solutions of the present invention are elaborated in detail below:
[0048] Figures 1 to 3 Shows the flowchart of a communication network data anti-leakage method according to an embodiment of the present invention. Refer to Figure 1 As shown.
[0049] S1: In the dynamic key system for generating communication network data, use the principles of quantum mechanics to generate random keys, and combine with the time destruction mechanism unit in the dynamic key system to process the random keys during data transmission.
[0050] Among them, the time destruction mechanism unit includes assigning a timestamp to the generated random key, and the timestamp includes defining the period of the random key. When the period N is exceeded, the random key becomes invalid;
[0051] Defining the period of the random key includes combining the period definition mechanism of communication network design intelligence. The period definition mechanism of design intelligence includes introducing a network environment perception module for design. The network environment perception module includes the network environment and the network communication frequency, and defines the period of the random key according to the network environment perception module;
[0052] The network environment includes collecting network metrics through network performance monitoring sensors. When it is monitored that the network delay is greater than / ms, the period N is shortened;
[0053] The network communication frequency includes high-frequency communication and low-frequency communication. Shortening the period N includes performing it in the scenario where the number of transmissions per second of high-frequency communication is greater than ∈ times;
[0054] When the monitored network latency is less than or equal to / ms, the network environment is at a normal level. In this case, the scenario where the number of transmissions per second in low-frequency communication is less than or equal to ∈ times is adopted.
[0055] Furthermore, the destruction mechanism unit assigns a timestamp to the generated random key. The timestamp is used to define the period of the random key. When the period exceeds 10 seconds, the random key becomes invalid. This 10-second period is obtained based on the statistical analysis of the security validity period of keys in typical communication scenarios, which can balance performance while ensuring security. Defining the period of the random key includes combining an intelligent period definition mechanism for communication network design. The intelligent period definition mechanism includes introducing a network environment perception module for design. The network environment perception module includes the network environment and network communication frequency. The period of the random key is defined according to the network environment perception module; these period definitions are summarized through a large number of actual network environment tests and historical data accumulations, and can dynamically adapt to different network conditions. Network metrics are collected through network performance monitoring sensors. When the monitored network latency is greater than 50 ms, the random key period is shortened to 5 seconds; this 50-ms threshold is set based on the actual test results of the impact of latency on data transmission in various network environments, which can effectively address the security risks brought by high latency. For high-frequency communication and low-frequency communication, shortening the period N includes the scenario where the number of transmissions per second in high-frequency communication is greater than 200 times; this 200-times high-frequency communication threshold is statistically obtained based on the average transmission rate in actual high-frequency communication scenarios, which can accurately identify the high-frequency communication state. When the monitored network latency is less than or equal to 50 ms, the network environment is at a normal level. In this case, the scenario where the number of transmissions per second in low-frequency communication is less than or equal to 100 times is adopted, and the random key period is restored to 10 seconds; this 100-times low-frequency communication threshold is set through long-term monitoring and analysis of conventional network communication frequencies, which can reasonably distinguish low-frequency communication scenarios. The random key period and network environment parameters in the communication network are shown in Table 1 below:
[0056] Table 1 Random key period and network environment parameter table in the communication network
[0057]
[0058] Table 1 shows the set values and sources of the random key period and related network parameters in the communication network, including the key invalidation period, network latency threshold, high-frequency and low-frequency communication thresholds. These data are obtained based on actual tests and statistical analyses, and are used to dynamically adapt to the network environment and ensure communication security and performance.
[0059] S2: Generating a random key includes data segmentation and data recombination based on zero - knowledge proof. Data segmentation includes, before transmitting the random key, splitting the transmitted data into N data segments and encrypting each data segment through a zero - knowledge proof algorithm.
[0060] Among them, splitting the transmitted data into N data segments includes introducing a multi - level segmentation mechanism to classify the original data D. Classifying the original data D includes defining the segmentation points of the original data D. The calculation formula for defining the segmentation points of the original data D is:
[0061] start i = H(D, i, R, C)
[0062] end i = H(D, i + 1, R, C)
[0063] Among them, C represents a dynamic context variable, R represents a dynamic random value based on a timestamp, start i represents the start segmentation point, end i represents the end segmentation point, D represents the original data, i represents the index of the data segment, and H represents a hash function;
[0064] The multi - level segmentation mechanism includes coarse - grained segmentation and fine - grained segmentation, and introducing dynamic context variables C coares and C fine ;
[0065] Coarse - grained segmentation is used to divide data segments, and fine - grained segmentation is used to perform secondary division on the divided data segments;
[0066] Introducing dynamic context variables C coares and C fine includes expanding the dynamic context variables. The expansion includes analyzing the traffic pattern of the dynamic context variables. Analyzing the traffic pattern of the dynamic context variables includes capturing the data packets of the data segments using IP addresses, extracting the packet features, and establishing a traffic pattern model;
[0067] Establishing a traffic pattern model includes dynamically adjusting the judgment threshold through the current network state. Dynamically adjusting the judgment threshold of the current network state includes pre - processing the state data collected by the current network. The pre - processing includes constructing a network state vector S using the state data collected by the current network and mapping the original data D and the state data collected by the current network through a non - linear transformation;
[0068] The mapping includes delay feature mapping, bandwidth utilization feature mapping, traffic load feature mapping, device location feature mapping, and abnormal signal feature mapping;
[0069] Integrating the mapping results to construct a network state vector. The integration process is:
[0070]
[0071] Among them, S represents the network state vector, and different threshold adjustment amounts ΔT corresponding to different state scoring intervals are obtained according to the network state vector.
[0072] Furthermore, the formula for delay feature mapping is:
[0073]
[0074] Among them, represents the delay feature mapping value, Δt D represents the packet time interval sequence extracted from the original data D, σ(Δt D ) represents the standard deviation of the packet time interval sequence, μ(Δt D ) represents the mean of the packet time interval sequence, and log() represents the logarithmic function;
[0075] The formula for bandwidth utilization feature mapping is:
[0076]
[0077] Among them, represents the bandwidth utilization feature mapping value, mean(S D ) represents the mean of the packet size, and std(S D ) represents the standard deviation of the packet size;
[0078] The formula for traffic load feature mapping is:
[0079]
[0080] Among them, represents the traffic load feature mapping value, entropy(P D ) represents the entropy value of the protocol type, and |P D | represents the total number of protocol types;
[0081] The formula for device location feature mapping is:
[0082]
[0083] Among them, represents the device location feature mapping value, variance(L D ) represents the variance of the location sequence, α represents the adjustment parameter, and distance 2 represents the square of the distance between the current device location and the reference location;
[0084] The formula for abnormal signal feature mapping is:
[0085]
[0086] Among them, represents the abnormal signal feature mapping value, anomaly represents the abnormal signal intensity or abnormal score under the current network state, and threshold i represents the threshold of the i-th anomaly detection, β represents the adjustment parameter, and score D represents the abnormal score extracted from the original data D;
[0087] Calculate the overall state score of the current network according to the network state vector S, and the scoring formula is:
[0088]
[0089] Among them, 5 represents the mapping process of the original data and the state data collected by the current network through non-linear transformation, Score(S) represents the overall state score value of the current network, and w i represents the i-th feature S i of the weight, represents the i-th network state feature S i of the non-linear mapping value.
[0090] S2.1: Divide the data segment, including adjusting the corresponding adjustment amount according to the overall state score value of the current network:
[0091] When Score(S) < threshold1, the corresponding threshold adjustment amount is ΔT1, where Score(S) represents the overall state score value of the current network;
[0092] When threshold1 ≤ Score(S) < threshold2, the corresponding threshold adjustment amount is ΔT2;
[0093] When Score(S) ≥ threshold2, the corresponding threshold adjustment amount is ΔT3;
[0094] Dynamically adjust the judgment threshold according to the interval to which the overall state score value of the current network belongs:
[0095] T dynamic = T base + ΔT
[0096] Among them, T base represents the initial threshold, ΔT represents the threshold adjustment amount, and T dynamic represents the interval to which the overall state score value of the current network belongs;
[0097] Coarse-grained segmentation also includes according to the dynamically adjusted threshold Tdynamic , determine the size of the coarse-grained segmentation;
[0098] Segment Size coarse = max(MinSize, α·T dynamic )
[0099] where MinSize represents the segmentation size, α represents the adjustment parameter, and Segment Size coarse represents the coarse-grained segmentation size;
[0100] Performing secondary partitioning on the segmented data segments includes further partitioning the coarse-grained segmentation size into fine-grained segmentation sizes:
[0101] Encrypting each data segment through a zero-knowledge proof algorithm includes encrypting each data segment using a symmetric encryption algorithm:
[0102]
[0103] where, and respectively represent the encryption results of the coarse-grained and fine-grained data segments, K represents the encryption key, Encrypt represents the encryption function, represents the original data of the i-th data segment after coarse-grained segmentation, represents the original data of the j-th data segment after the i-th coarse-grained segmentation is further divided into fine-grained segments.
[0104] Preferably, the calculation and application of the threshold adjustment amount are the core links for dynamically adapting to the network environment and optimizing the data segmentation strategy. Specifically, according to the overall state score value of the current network, denoted as S, the network state is divided into three intervals: when S ≤ 50, the corresponding threshold adjustment amount is -0.2×S, indicating that the segmentation standard is further tightened when the network state is poor; when 50 < S ≤ 80, the threshold adjustment amount is 0.1×(S - 50), which is used to moderately relax the segmentation conditions when the network state is medium; when S > 80, the threshold adjustment amount is 0.3×(S - 80) + 3.
[0105] S3: Data recombination includes using distributed ledger technology to record the transmission path and recombination order of the data segments. The recombination order includes writing the data segments into the distributed ledger before the random key transmission and recombining them in the order of writing into the distributed ledger to complete the transmission of the communication network data.
[0106] where, using distributed ledger technology to record the transmission path of the data segments includes for the coarse-grained segmentation size Segment Size coarse and the fine-grained segmentation size Allocate identifiers, introduce a dynamic path optimization mechanism to obtain the transmission path, define the network topology of the data segment, and select the transmission process when the network latency is less than or equal to / ms, and for data segments less than or equal to / ms, allocate the initial transmission path.
[0107] Allocating the initial transmission path includes deploying a smart contract on the distributed ledger, defining the recording rules. The defined recording rules include that the sender submits the meta-information of the data segment by calling the deployed smart contract interface, verifies the received meta-information, and the verification includes the sender proving the meta-information of the data segment and recording the transmission path of the data segment.
[0108] Combined with the overall state score value of the current network, collect the bandwidth utilization rate and latency packet loss rate of the transmission path, organize structured objects, use the smart contract to score the received meta-information, divide it into three levels: I, II, and III according to the overall state score value. The higher the level, the higher the overall state score value corresponding to this level is given priority to allocate the transmission path.
[0109] Preferably, in the data recombination stage, when using the distributed ledger technology to record the transmission path and recombination order of the data segment;
[0110] Specifically, it is refined as follows: allocate unique identifiers to the coarse-grained segmentation size (such as 1MB) and the fine-grained segmentation size (such as 256KB), introduce a dynamic path optimization mechanism to obtain the optimal transmission path, define the network topology of the data segment, and the system preferentially selects the transmission path with a network latency less than or equal to 30ms.
[0111] When the latency exceeds 30ms but does not exceed 50ms, switch to the alternate path.
[0112] When the latency exceeds 50ms, trigger the path re-selection algorithm to recalculate the optimal path. At the same time, deploy a smart contract on the distributed ledger, define the recording rules, and the sender submits the data segment meta-information through the smart contract interface, including fields such as ID, Timestamp, Content_Hash, and Random_Seed. The smart contract verifies the received meta-information and combines it with the overall state score value of the current network.
[0113] When the bandwidth utilization rate of the path is greater than 80% and the packet loss rate is less than 0.1%, it is rated as level I. When the bandwidth utilization rate is between 60%-80% and the packet loss rate is between 0.1%-0.5%, it is rated as level II, and the rest are rated as level III. Give priority to allocating the transmission path to the high-scoring level to ensure that the data segment is recombined in the order of writing to the distributed ledger, and finally realize the secure and efficient transmission of communication network data.
[0114] Furthermore, it is worth noting that the efficiency and security of data transmission are ensured through a multi-level mechanism. First, unique identifiers are assigned to the coarse-grained and fine-grained segmentation sizes, and combined with a dynamic path optimization mechanism, the transmission path with a network latency less than or equal to 30 ms is preferentially selected, effectively reducing the impact of transmission latency on data integrity.
[0115] When the latency exceeds the set threshold, the system can intelligently switch to an alternative path or recalculate the optimal path, demonstrating strong adaptability. Second, smart contracts are deployed on the distributed ledger to ensure the authenticity and immutability of data by verifying the metadata of data segments. At the same time, combined with network status scoring, the transmission paths are hierarchically managed, and high-scoring paths are preferentially selected, further improving the reliability and efficiency of data transmission. This design that deeply integrates dynamic path optimization with distributed ledger technology not only ensures the accurate recombination of data segments in the write order but also provides a solid guarantee for the secure and efficient transmission of communication network data.
[0116] S3: Writing the data segment into the distributed ledger includes using a smart contract to automatically verify and record the information of the data segment into the distributed ledger. The smart contract writes the metadata of the data segment into the distributed ledger, generates a distributed consensus mechanism, and each data segment verifies the record request according to the consensus mechanism.
[0117] If an agreement is reached, the record is written into the distributed ledger.
[0118] In the process of writing the data segment into the distributed ledger, first, the smart contract ensures the legality and integrity of the data segment metadata through a multi-stage verification mechanism. The verification process includes zero-knowledge proof verification to confirm that the data segment is consistent with the encryption parameters generated by the random key.
[0119] Timestamp consistency check to ensure that the timestamp of the data segment is within a reasonable time window (e.g., ±30 seconds), path legality verification, combined with the network topology structure to verify whether the data segment transmission path conforms to the predefined rules; the smart contract organizes the verified metadata into a structured object, records its hash value into the distributed ledger, and at the same time generates an immutable record. To enhance the robustness of the system, a dynamic consensus weight adjustment mechanism is introduced: each node dynamically adjusts the consensus voting weight according to the current network state, and preferentially adopts the verification results of high-scoring nodes.
[0120] When more than 75% of the preset proportion of nodes reach an agreement, the smart contract triggers the write operation, writes the record into the distributed ledger formally, and updates the global state to reflect the recombination order of the latest data segment. By combining creative designs such as zero-knowledge proof, dynamic consensus weight adjustment, and time window verification, the security and reliability of data writing are significantly improved.
[0121] The timestamp consistency check includes statistical analysis based on the actual delay distribution in the network environment. By monitoring the historical transmission data, it is found that the timestamp deviation of most normal data segments is within ±30 seconds.
[0122] The preset ratio of 75% of nodes is obtained through experiments simulating the trade-off between consensus efficiency and security under different network scales and numbers of nodes. In a distributed system, when more than 75% of the nodes reach a consensus, the system's performance and fault tolerance can be taken into account while ensuring high security.
[0123] S3.1: Reorganization in the order in which data are written to the distributed ledger includes using the timestamp information recorded in the distributed ledger to sort the data segments in the order in which they are written, using the time window mechanism to dynamically handle sorting anomalies caused by network delays or data segment loss, delaying the data segments and reinserting them into the sorting queue by setting the time window range, and checking whether there are invalid or duplicate data segments for the data segment records read by the receiver from the distributed ledger.
[0124] Furthermore, when reorganizing the data segments in the order in which they were written to the distributed ledger, the data segments are sorted using the timestamp information recorded in the distributed ledger, and anomalies caused by network delays or data segment loss are dynamically handled through an adaptive time window mechanism, with the initial time window set to twice the average system delay;
[0125] When it is detected that the network delay exceeds the preset threshold of 50ms, the time window automatically expands to 1.5 times the initial value, and gradually shrinks after returning to normal;
[0126] For delayed data segments, a buffer queue is used for temporary storage, and the priority is calculated by combining the timestamp and path score. After arrival, the insertion position is located according to the timestamp, and the legality of the transmission path is verified. Through a multi-dimensional conflict detection algorithm, invalid or duplicate data segments are identified, triggering retransmission or skipping operations. The smart contract dynamically adjusts the sorting logic according to the meta-information score to ensure that the reorganization result strictly follows the write order, thereby improving the accuracy and reliability of data reorganization.
[0127] Preferably, by long-term monitoring and recording the actual delays of a large number of data segment transmissions in a distributed network, the system average delay is calculated. The statistical results reflect the typical delay level of the network under normal operating conditions. The initial time window is set to twice the system average delay, covering the delay range in the vast majority of normal cases. Through experimental analysis of the delay distribution in different network environments, it is found that when the delay exceeds 50 ms, it usually indicates an abnormal network condition. Taking 50 ms as the critical value for triggering the expansion of the time window can promptly respond to network state changes and avoid incorrect sorting of data segments due to excessive delay. When dynamically adjusting the time window, expanding it to 1.5 times the initial value can effectively accommodate the delayed data segments caused by network anomalies.
[0128] On the other hand, in the field of communication network data security technology, the technical solution of the present invention has verified its effectiveness in solving data transmission security, random key lifecycle management, and efficient data recombination through a series of innovative experimental designs. The experimental process is as follows: First, in the dynamic key generation link, a quantum random number generator is used in combination with a zero-knowledge proof algorithm to generate random keys that meet the high-entropy requirements, and they are applied to data segmentation and encryption. In the experiment, the length of the random key is set to 256 bits to ensure that its anti-cracking ability reaches the current highest standard. At the same time, a timely destruction mechanism unit is introduced to dynamically adjust the effective period of the random key to 10 seconds (shortened to 5 seconds when the network delay exceeds 50 ms), and indicators such as bandwidth utilization rate and delay packet loss rate are collected in real time through network performance monitoring sensors to verify the adaptability of this mechanism to different network environments.
[0129] Secondly, in the data segmentation and recombination stage, a multi-level segmentation mechanism is adopted to divide the original data into a coarse-grained 1 MB and a fine-grained 256 KB, and the traffic pattern is optimized by analyzing dynamic context variables to select the segmentation point. In the experiment, for high-frequency communication scenarios with more than 200 transmissions per second and low-frequency communication scenarios with less than or equal to 100 transmissions per second, the efficiency and accuracy of the data segmentation strategy are respectively tested. The results show that the average segmentation error of the data segments is less than 0.5%.
[0130] Finally, in the data reorganization process supported by distributed ledger technology, the experiment simulated the data transmission process under different network latency conditions. Through the adaptive time window mechanism, with the initial value set to twice the system average latency, such as 40 ms, the sorting anomaly problem caused by network latency was successfully addressed. The experimental data showed that when the network latency exceeded 50 ms, after the time window was extended to 1.5 times the initial value, the data segment loss rate decreased by 85%, and the reorganization success rate increased to 99.7%. In addition, through the consensus mechanism implemented by smart contracts, in a distributed network with 100 nodes, the time to verify and write data segments was only 300 ms on average, significantly improving the overall efficiency of the system.
[0131] In the technical solution of the present invention, by combining the principle of quantum mechanics to generate random keys and the time destruction mechanism of the dynamic key system, the security of data transmission in the communication network is significantly improved, effectively preventing data leakage. Zero-knowledge proof is introduced for data segmentation and encryption to ensure privacy protection during data transmission. At the same time, the distributed ledger technology is used to record the transmission path and reorganization order of data segments, realizing the transparency and traceability of data transmission. In addition, through the dynamic context variable and multi-level segmentation mechanism, the data segmentation granularity is optimized to meet the requirements of different network environments. The time destruction mechanism combined with the network environment perception module intelligently adjusts the life cycle of random keys, reducing the risk of key cracking. The time window mechanism and sorting anomaly handling strategy effectively address network latency or data loss problems, ensuring the accuracy of data reorganization, improving the data security, transmission efficiency, and system flexibility of the communication network, and being applicable to complex and changeable network environments.
[0132] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0133] The units involved in the embodiments of the present invention can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not constitute a limitation on the unit itself in some cases.
[0134] According to one aspect of the present invention, there is provided a computer program product or a computer program, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the above various alternative implementation manners.
[0135] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of the present invention.
[0136] After considering the specification and practicing the disclosed embodiments herein, those skilled in the art will readily conceive of other embodiments of the present invention. The present invention is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed by the present invention.
[0137] It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A communication network data leakage prevention method, characterized in that: Including: In a dynamic key system for generating communication network data, a random key is generated using the principles of quantum mechanics and combined with a time-destruction mechanism unit in the dynamic key system to process the random key during data transmission. The generation of the random key includes data segmentation and data recombination based on zero-knowledge proof. The data segmentation includes, before the transmission of the random key, dividing the transmission data into N data segments and encrypting each data segment through a zero-knowledge proof algorithm. The data recombination includes using distributed ledger technology to record the transmission path and recombination order of the data segments. The recombination order includes, before the transmission of the random key, writing the data segments into the distributed ledger and recombining them in the order of writing into the distributed ledger to complete the transmission of communication network data.
2. The communication network data leakage prevention method according to claim 1, characterized in that: The time-destruction mechanism unit includes assigning a timestamp to the generated random key. The timestamp includes defining the period of the random key. When the period N is exceeded, the random key becomes invalid. The definition of the period of the random key includes combining an intelligent period definition mechanism for communication network design. The intelligent period definition mechanism for design includes introducing a network environment perception module for design. The network environment perception module includes the network environment and network communication frequency, and defines the period of the random key according to the network environment perception module. The network environment includes collecting network indicators through network performance monitoring sensors. When the network delay is greater than When , the period N is shortened; The network communication frequency includes high-frequency communication and low-frequency communication. The shortening of the period N includes using the scenario where the number of transmissions per second in high-frequency communication is greater than ∈ times. When the network delay is less than or equal to When , the network environment is at a normal level, and low-frequency communication is used in a scenario where the number of transmissions per second is less than or equal to ∈ times.
3. The communication network data leakage prevention method according to claim 1, characterized in that: The division of the transmission data into N data segments includes introducing a multi-level segmentation mechanism to classify the original data D. The classification of the original data D includes defining the segmentation points of the original data D. The multi-level segmentation mechanism includes coarse-grained segmentation and fine-grained segmentation, and introduces a dynamic context variable C coares and C fine ; Coarse-grained segmentation is used to divide data segments, and fine-grained segmentation is used to perform secondary division on the divided data segments. The introduction of dynamic context variable C coares and C fine The method includes extending the dynamic context variable, wherein the extending includes analyzing the traffic pattern of the dynamic context variable, wherein the analyzing the traffic pattern of the dynamic context variable includes capturing data packets of the data segment using the IP address, extracting data packet features, and establishing a traffic pattern model; The establishment of the traffic pattern model includes dynamically adjusting the judgment threshold according to the current network state. The dynamic adjustment of the judgment threshold according to the current network state includes preprocessing the state data collected from the current network. The preprocessing includes constructing a network state vector S using the state data collected from the current network and mapping the original data D and the state data collected from the current network through a non-linear transformation. The mapping includes delay feature mapping, bandwidth utilization feature mapping, traffic load feature mapping, device location feature mapping, and abnormal signal feature mapping.
4. The communication network data leakage prevention method according to claim 1, characterized in that: The one used for dividing data segments includes adjusting the corresponding adjustment amount according to the overall state score value of the current network: When Score(S) < threshold1, the corresponding threshold adjustment amount is ΔT1, where Score(S) represents the overall state score value of the current network. When threshold1 ≤ Score(S) < threshold2, the corresponding threshold adjustment amount is ΔT2. When Score(S) ≥ threshold2, the corresponding threshold adjustment amount is ΔT3. Dynamically adjust the judgment threshold according to the interval to which the overall state score value of the current network belongs. Coarse-grained segmentation also includes the dynamically adjusted threshold T dynamic , determine the size of the coarse-grained segmentation; Performing secondary division on the divided data segments includes dividing the size of the coarse-grained segmentation into the size of the fine-grained segmentation for secondary division.
5. The communication network data leakage prevention method according to claim 1, characterized in that: The transmission path of the data segment recorded by the distributed ledger technology includes the coarse-grained segmentation size Segment Size coarse and fine-grained segmentation size Assign identifiers, introduce dynamic path optimization mechanism to obtain transmission paths, define network topology of data segments, and select network delays less than or equal to During the transmission process, for less than or equal to The data segment is assigned the initial transmission path when The allocating the initial transmission path includes deploying a smart contract on a distributed ledger and defining a recording rule, wherein the defining the recording rule includes the sender submitting the meta information of the data segment by calling the deployed smart contract interface and verifying the received meta information, wherein the verification includes the sender recording the transmission path of the data segment by proving the meta information of the data segment; Combined with the overall status score of the current network, the bandwidth utilization and delay packet loss rate of the transmission path are collected, structured objects are organized, and the received meta-information is scored using smart contracts. The three levels of I, II, and III are divided according to the overall status score. The higher the level, the higher the overall status score corresponding to the level is assigned priority to the transmission path.
6. The communication network data leakage prevention method according to claim 1, characterized in that: Writing the data segment into the distributed ledger includes using a smart contract to automatically verify and record the information of the data segment into the distributed ledger, the smart contract writes the meta information of the data segment into the distributed ledger, generates a distributed consensus mechanism, and each data segment verifies the record request according to the consensus mechanism; If consensus is reached, the record is written to the distributed ledger.
7. The communication network data leakage prevention method according to claim 1, characterized in that: include: The reorganization according to the order of writing into the distributed ledger includes using the timestamp information recorded in the distributed ledger to sort the data segments according to the order of writing, using the time window mechanism to dynamically handle sorting anomalies caused by network delays or data segment loss, by setting the time window range, delaying the data segment and reinserting it into the sorting queue, and checking whether there are invalid or duplicate data segments for the data segment records read by the receiver from the distributed ledger.
8. The communication network data leakage prevention method according to claim 1, characterized in that: include: The dynamic processing of sorting anomalies caused by network delay or data segment loss includes extracting historical records from the distributed ledger, counting the distribution of network delays, defining a time window expansion factor and a contraction factor based on the historical records extracted from the distributed ledger, triggering the delayed data segment, and inserting it into the sorting queue for the second time to complete the transmission of communication network data.
9. A communication network data leakage prevention system, characterized in that: include: A random key processing module, which generates random keys using the principles of quantum mechanics in a dynamic key system for communication network data generation, and processes the random keys during data transmission in combination with a time-destruction mechanism unit in the dynamic key system; A data segmentation module, wherein the generating of the random key includes data segmentation and reorganization based on zero-knowledge proof, wherein the data segmentation includes segmenting the transmitted data into N data segments before the random key is transmitted, and encrypting each data segment by a zero-knowledge proof algorithm; A data reorganization module, wherein the data reorganization includes using distributed ledger technology to record the transmission path and reorganization order of the data segments, wherein the reorganization order includes writing the data segments into the distributed ledger before the random key is transmitted, and reorganizing them in the order of writing into the distributed ledger to complete the transmission of the communication network data.
10. An electronic device, characterized in that: include: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the one or more processors to implement the communication network data leakage prevention method as described in any one of claims 1 to 8.