Data encryption strategy making and data full-life-cycle safety guarantee system and method based on artificial intelligence

By adopting artificial intelligence-based data encryption strategy formulation and data full life cycle security guarantee system in a cross-public cloud environment, the problem of insufficient data encryption strategy formulation and insufficient data full life cycle security guarantee is solved, and intelligent encryption management of data and full life cycle security protection is realized.

CN120200862AActive Publication Date: 2025-06-24BEIJING SANSEC TECH DEV

Patent Information

Application Number
CN202510686624.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

In a cross-public cloud environment, data encryption strategy formulation is not intelligent enough, encryption rules at rest are difficult to cope with dynamically changing business scenarios, data life cycle security is insufficient, and a unified encryption engine and key management system lacks, resulting in data facing risks such as leakage, tampering, and illegal access during transmission and processing.

Method used

Using artificial intelligence-based data encryption strategy formulation and data full life cycle security guarantee system, through intelligent encryption and decryption engine, cataloging system, encryption judgment service, key management module and artificial intelligence algorithm, intelligent identification, dynamic update and automated execution of data encryption policies are realized, and a security guarantee system covering the entire life cycle of data is built.

Benefits of technology

It realizes intelligent management of data encryption policies, adapts to the rapid changes of massive and multi-type data, ensures the security of data throughout the entire life cycle, provides a unified data security policy application across cloud platforms, and reduces the risks of data leakage, tampering and illegal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200862A_ABST
    Figure CN120200862A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, and discloses a data encryption strategy making and data full-life-cycle security guarantee system and method based on artificial intelligence, the system comprises a plurality of public clouds and an intelligent encryption and decryption engine, and a business system, a database, an encryption judgment service system and an encryption and decryption service system are respectively deployed on a plurality of public cloud platforms. The intelligent encryption and decryption engine comprises a cataloguing system, a key management service system and an authorization management service system; by introducing an intelligent encryption engine, a cataloguing system, an encryption judgment service, a key management module and an artificial intelligence algorithm, intelligent identification, dynamic updating and automatic execution of a data encryption strategy are realized, and a set of security guarantee system covering the full life cycle of data is constructed in combination with a plurality of links such as authorization management and encryption and decryption services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and more specifically, to an artificial intelligence-based data encryption strategy formulation and data full-life cycle security guarantee system and method. Background Art

[0002] With the rapid development of information technology, cloud computing, as a new information technology service model, has been widely applied to enterprise informatization construction and data management. As one of the important service models of cloud computing, public cloud provides infrastructure support such as computing resources, storage resources, and network services to the public or enterprises through the Internet, greatly reducing the construction and operation and maintenance costs of enterprise IT systems and improving resource utilization and business deployment efficiency.

[0003] However, with the increasing popularity of the multi-cloud architecture adopted by enterprises, data interaction and management in a cross-public cloud environment have become an important challenge in the current development of cloud computing. Especially in terms of data security, there are heterogeneity, lack of unified security policy management and key control mechanisms between different public cloud platforms, resulting in risks such as leakage, tampering, and illegal access of sensitive data during cross-platform transmission and processing. Therefore, how to achieve data security protection in a cross-public cloud environment has become the core issue to be solved urgently in the field of cloud computing security.

[0004] In terms of data encryption, traditional methods usually rely on manual setting of encryption rules or configuration based on fixed templates. However, with the explosive growth of data volume and the increasing complexity of data types, this static and manual method has been difficult to meet the dual requirements of data security and processing efficiency in modern information systems. In addition, in terms of data full-life cycle management, existing technologies often only focus on the security protection in the data storage stage, while ignoring the security risks in other links such as data generation, transmission, use, and even destruction.

[0005] In summary, the current data security system in a cross-public cloud environment still has the following main problems:

[0006] 1) The formulation of data encryption strategies is not intelligent enough: Traditional methods rely on manual judgment, unable to adapt to the rapid changes of massive and multi-type data, lacking the ability of automatic recognition and hierarchical encryption based on AI algorithms;

[0007] 2) The management of encryption rules is not flexible: Static encryption rules are difficult to cope with dynamic business scenarios and lack an effective automatic update mechanism;

[0008] 3) The security guarantee of the data full-life cycle is insufficient: There is a lack of security control means covering the entire process of data generation, storage, transmission, use, etc.;

[0009] 4) Difficulties in cross-cloud platform security management: The lack of a unified encryption engine and key management system makes it difficult to implement consistent data security policy applications across multiple public clouds.

[0010] In view of the above problems, the present invention proposes an intelligent data encryption policy formulation and data full-life cycle security guarantee system and method based on artificial intelligence. Summary of the Invention

[0011] In view of this, the present invention provides an artificial intelligence-based data encryption policy formulation and data full-life cycle security guarantee system and method, aiming to solve the data security problems in the cross-public cloud environment. By introducing an intelligent encryption engine, a cataloging system, an encryption determination service, a key management module, and artificial intelligence algorithms, the intelligent identification, dynamic update, and automated execution of data encryption policies are realized, and combined with multiple links such as authorization management and encryption and decryption services, a security guarantee system covering the entire data life cycle is constructed.

[0012] To achieve the above object, the present invention adopts the following technical solutions:

[0013] An artificial intelligence-based data encryption policy formulation and data full-life cycle security guarantee system includes multiple public clouds and an intelligent encryption and decryption engine. Each public cloud is respectively deployed with a business system, a database, an encryption judgment service system, and an encryption and decryption service system; the intelligent encryption and decryption engine includes a cataloging system, a key management service system, and an authorization management service system;

[0014] The application system is used to receive the data operation request input by the user, execute the corresponding business logic, and generate an operation instruction for the database;

[0015] The database is used to store data and provide a data access interface for the application system;

[0016] The cataloging system is responsible for analyzing the data structure information in the database, automatically identifying the data under the fields that need to be encrypted by evaluating the sensitivity and importance of the data, formulating encryption and decryption rules, periodically updating the encryption and decryption rules, and sending the latest encryption and decryption rules to the encryption judgment service system to achieve dynamic management;

[0017] The key management service system is used to complete the life cycle management of keys;

[0018] The authorization management service system is used to verify the access permissions of the encryption judgment service systems in each public cloud and complete authorization management;

[0019] The encryption judgment service system is used to complete the authorization operation, regularly obtain the latest encryption and decryption rules from the catalog system, intercept the operation instructions when the application system initiates a data operation request, and determine in real time whether encryption or decryption processing is required according to the current operation type and field information. If it is determined that encryption or decryption processing is required, the catalog system is called to obtain the encryption and decryption rules;

[0020] The encryption and decryption service system is used to respond to the request of the encryption judgment service system, obtain the corresponding key from the key management service system, perform specific encryption or decryption operations according to the preset encryption level, and return the processed data to the application system or write it into the database.

[0021] Preferably, the operation instructions include operations for adding, querying, updating, or deleting data.

[0022] Preferably, the life cycle management of the key includes key generation, storage, distribution, update, and synchronization.

[0023] Preferably, the encryption and decryption rules include the encryption level, encryption algorithm, and parameter configuration of the field.

[0024] Preferably, the encryption and decryption rules are regularly trained, specifically including:

[0025] Convert the field name in the field into a word vector, extract the data type, field length, and data volume of the field, and perform a full connection operation with the word vector to obtain a word vector with a length of Form a feature matrix ;

[0026] Input the feature matrix into the feedforward neural network model, which includes four hidden layers and one output layer;

[0027] Each hidden layer is represented by the variable The processing process through the hidden layer is:

[0028]

[0029]

[0030] Among them, and respectively represent the weight matrix and offset of the th layer, is the RELU activation function, and represent input and output; among them,

[0031] ​

[0032] The weight matrix representing the first hidden layer, The bias vector representing the first hidden layer, and represent the input and output of the first hidden layer;

[0033] After passing through the hidden layer, the input matrix , the input matrix passes through the output layer and the Softmax function to obtain the probability distribution of the output layer :

[0034]

[0035] Among them, represents the th encryption level, is the number of encryption levels, serves as a temporary variable in the accumulated value, represents the total number of samples in the th sample, represents the input matrix of the output layer the th value of the th encryption level in the th sample, represents the value to be accumulated for the th sample at the

[0036] Use the cross-entropy loss function to calculate the loss and train the model to the optimal state:

[0037]

[0038] Among them, represents the true value of the th encryption level in the th sample, represents the function value of the cross-entropy function, N represents the total number of samples.

[0039] An artificial intelligence-based data encryption strategy formulation and data full-life cycle security guarantee method, including:

[0040] Deploy the business system, database, encryption judgment service system, and encryption and decryption service system on multiple public cloud platforms respectively. The catalog system is responsible for analyzing the data structure information in the database, automatically identifying the data under the fields that need to be encrypted by evaluating the sensitivity and importance of the data, formulating encryption and decryption rules, determining the corresponding encryption levels, and periodically updating the encryption and decryption rules, and sending the latest encryption and decryption rules to the encryption judgment service system to achieve dynamic management; the authorization management service system periodically verifies the access permissions of the encryption judgment service systems in each public cloud to complete authorization management.

[0041] Receive the data operation request input by the user through the application system, execute the corresponding business logic, and generate an operation instruction for the database.

[0042] The encryption judgment service system intercepts the operation instruction and, based on the current operation type and field information, determines in real time whether encryption or decryption processing is required.

[0043] If it is determined that encryption or decryption processing is required, the encryption judgment service system calls the catalog system to obtain the encryption and decryption rules.

[0044] The encryption judgment service system triggers the encryption and decryption service system. The encryption and decryption service system obtains the corresponding key from the key management service system, performs specific encryption or decryption operations according to the preset encryption level, and returns the processed data to the application system or writes it into the database to complete the full life cycle security management of the data.

[0045] Preferably, the operation instructions include operations for adding, querying, updating, or deleting data.

[0046] Preferably, the life cycle management of the key includes key generation, storage, distribution, update, and synchronization.

[0047] Preferably, the encryption and decryption rules include the encryption level, encryption algorithm, and parameter configuration of the field.

[0048] Preferably, the encryption and decryption rules are trained regularly, specifically including:

[0049] Convert the field name in the field into a word vector, extract the data type, field length, and data volume of the field, and perform a full connection operation with the word vector to obtain a word vector with a length of of to form a feature matrix ;

[0050] Input the feature matrix into the feedforward neural network model. The feedforward neural network model includes four hidden layers and one output layer.

[0051] Each hidden layer uses a variable It is shown that the processing process through the hidden layer is as follows:

[0052]

[0053]

[0054] Among them, and respectively represent the weight matrix and bias of the th layer, is the RELU activation function, and represent the input and output of ; among them,

[0055]

[0056] represent the weight matrix of the first hidden layer, represents the bias vector of the first hidden layer, and represent the input and output of the first hidden layer;

[0057] After passing through the hidden layer, the input matrix is obtained. The input matrix passes through the output layer and the Softmax function to obtain the output layer probability distribution :

[0058]

[0059] Among them, represents the th encryption level, is the number of encryption levels, serves as a temporary variable in the cumulative value, represents the total number of samples in the th sample, represents the value of the th sample in the th sample of the output layer input matrix at the th encryption level, represents the value to be accumulated for the th sample at the

[0060] The cross-entropy loss function is used to calculate the loss and train the model to the optimal state:

[0061]

[0062] Among them, represents the The true value of the th encryption level in a sample, representing the function value of the cross-entropy function, N indicating the total number of samples.

[0063] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a data encryption strategy formulation and data full-life cycle security guarantee system and method based on artificial intelligence, having the following advantages:

[0064] 1) For a data system with a large number of data tables and a large amount of data, the determination of the encryption level of fields is automatically completed by means of artificial intelligence.

[0065] 2) Through multiple links (such as authorization management, encryption and decryption, rule application, etc.), the security processing of data throughout the life cycle is realized, achieving all-round protection of data.

[0066] 3) It is sent to the encryption judgment service through the catalog system, realizing the automated management and application of encryption rules. The dynamic acquisition, update and application of encryption rules are realized to ensure that the data encryption strategy always meets the latest security requirements and business needs.

[0067] 4) The intelligent encryption and decryption engine has a flexible deployment method, which can support both private deployment and public cloud deployment, and can be reasonably deployed according to user needs. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0069] Figure 1 It is a schematic structural diagram of a data encryption strategy formulation and data full-life cycle security guarantee system based on artificial intelligence provided by the present invention.

[0070] Figure 2 It is a flowchart of a data encryption strategy formulation and data full-life cycle security guarantee method based on artificial intelligence provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0071] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0072] An embodiment of the present invention discloses an artificial intelligence-based data encryption strategy formulation and data full-life cycle security guarantee system, as Figure 1 shown, including:

[0073] Multiple public clouds, at least 2, Figure 1 2 public clouds are shown in

[0074] Business systems, databases, encryption judgment service systems, and encryption and decryption service systems deployed on each of the public clouds;

[0075] An intelligent encryption and decryption engine, deployed locally or in the cloud, for uniformly managing cross-platform data security policies. The intelligent encryption and decryption engine includes a catalog system, a key management service system, and an authorization management service system;

[0076] Among them,

[0077] The application system is used to receive data requests input by users, execute business logics, and generate operation instructions for the database, including operations such as adding, querying, updating, or deleting data;

[0078] The database is used to store structured data and provide a data access interface for the application system, supporting the reading of meta-information such as table structures and field definitions;

[0079] The catalog system is connected to the databases in each public cloud, obtains their data structure information, analyzes the sensitivity and importance of the data, automatically judges the data under the fields that need to be encrypted, and formulates corresponding encryption and decryption rules. The encryption and decryption rules include the encryption level, encryption algorithm, and parameter configuration of the fields. For example, the encryption level is divided into L0 (no encryption required), L1, L2, L3, L4. The larger the number, the more the data of the field needs to be encrypted, and the higher the encryption degree of the data. For example, L2 uses the SM4 algorithm for encryption, and L3 uses AES with a 192-bit key for encryption. The corresponding relationship between the encryption level and the encryption method is prefabricated in the encryption judgment service system, and different levels correspond to different encryption algorithms and parameter configurations;

[0080] The key management service system is used to complete the life cycle management of keys, including key generation, storage, distribution, update, and synchronization, to ensure that the encryption and decryption services can safely obtain and use the corresponding encryption keys;

[0081] The authorization management service system is used to authenticate the identity and control the permissions of the encryption judgment service system to ensure that it has the legal permission to access the encryption and decryption resources;

[0082] The encryption judgment service system is used to complete access authorization by calling the authorization management service system and regularly obtain the latest encryption and decryption rules from the catalog system; intercept the operation instructions when the application system initiates data operations, and determine in real time whether encryption or decryption processing is required according to the current operation type and field information. If it is determined that encryption or decryption processing is required, call the catalog system to obtain the encryption and decryption rules;

[0083] The encryption and decryption service system responds to the request of the encryption judgment service system, obtains the corresponding key from the key management service system, performs specific encryption or decryption operations according to the preset encryption level, and returns the processed data to the encryption judgment service system, and then the encryption judgment service system returns it to the application system or writes it into the database.

[0084] Among them, the intelligent encryption and decryption engine can be privately deployed or publicly cloud-deployed according to user needs, and the key management service system is deployed in the key management device.

[0085] In this embodiment, the encryption levels of the field data in the connected database system are dynamically and intelligently determined. The main process is as follows:

[0086] 1. Feature extraction

[0087] The catalog system configures information such as the database address, port, username, and password to establish a connection to the database and complete the access.

[0088] Obtain the field names in all data table fields in the database, perform word segmentation according to the symbol "_", and then use the word-to-word vector tool Word2Vec to convert the fields into word vectors, and extract features such as the data type, field length, and data volume of the fields and perform a full connection operation with the word vectors to obtain a length of word vector to form a feature matrix .

[0089] Perform one-hot encoding (One-Hot-Encoding) on the encryption levels (L0, L1, L2, L3, L4), and represent each encryption level as a binary vector. For example:

[0090]

[0091] 2. Model training

[0092] Input the feature matrix into the DNN (feedforward neural network) model and calculate the input of the first hidden layer and the output after being processed by the ReLU activation function : :

[0093]

[0094] wherein, represents the weight matrix of the first layer, represents the bias vector of the first layer.

[0095] In the present invention, a total of four hidden layers and one output layer are provided, and each hidden layer is represented by the variable . Calculate the input and output of which requires using the output of the previous layer

[0096]

[0097]

[0098] wherein, and respectively represent the weight matrix and the offset of the th layer.

[0099] Finally, the input matrix of the output layer is calculated through the above formula, and the probability distribution of the output layer is obtained through the Softmax function:

[0100]

[0101] wherein, represents the th encryption level, is the number of encryption levels, is used as a temporary variable in the cumulative value, represents the total number of samples the th sample in represents the value of the th sample in the input matrix of the output layer at the th encryption level, represents the value to be accumulated for the th sample at the th encryption level.

[0102] Finally, the cross-entropy loss function is used for loss calculation, and the model is trained to the optimal state:

[0103]

[0104] Among them, represents the true value of the th encryption level in the th sample, represents the function value of the cross-entropy function, N indicates the total number of samples.

[0105] So far, the cataloging system generates the intelligent encryption level for the fields in the public data system through the regular training method of artificial intelligence.

[0106] In this embodiment, each public cloud includes three modules: an application system, a database, and a plugin. The plugin includes an encryption judgment service and an encryption / decryption service. The main process of data encryption / decryption for each public cloud is as follows:

[0107] 1) Obtain the fields in the data table that need to be encrypted in the rule according to the encryption / decryption rule, and obtain the data of the fields that need to be encrypted in the data to be inserted according to the fields. That is, what needs to be encrypted is not the field, but the data corresponding to the field.

[0108] 2) Based on the data to be encrypted, call the encryption / decryption service system to encrypt the data;

[0109] 3) The encryption / decryption service system calls the key management service system in the key management device to obtain the key;

[0110] 4) Based on the obtained key, encrypt the data and return it to the encryption judgment service system;

[0111] 5) The encryption judgment service system returns the encrypted data to the database.

[0112] Since the business data of the business system is stored in the database, if the business system needs to query data, but it has been encrypted by the encryption judgment service at this time. Then after the business system obtains the data, it needs to decrypt the data. The main process is as follows:

[0113] 1) The business system calls the encryption judgment service system to judge which fields of data are encrypted and obtain the encryption rule;

[0114] 2) Based on the obtained encryption / decryption rule, obtain the decryption method according to the corresponding relationship between the pre-set encryption level and the encryption method;

[0115] 3) Based on the obtained decryption method, call the encryption / decryption service system to decrypt the data;

[0116] 4) The encryption / decryption service system obtains the key in the key management service system;

[0117] 5) Based on the obtained key, decrypt the encrypted data, and after returning it to the encryption determination service system, it is returned by the encryption judgment service system to the business system;

[0118] 6) The business system obtains the decrypted data for subsequent business processing.

[0119] In addition, when the encryption judgment service synchronizes the encryption rules, it needs to apply for authorization from the authorization management service system, and can synchronize the encryption rules only after obtaining the authorization permission.

[0120] In this embodiment, a method for formulating an artificial intelligence-based data encryption strategy and ensuring data full-life cycle security is provided. As Figure 2 shown, a business system, a database, an encryption judgment service system, and an encryption / decryption service system are respectively deployed on multiple public cloud platforms;

[0121] The user submits a data operation request to the application system, executes the corresponding business logic, and generates an operation instruction for the database, including operations such as addition, query, update, or deletion;

[0122] The encryption judgment service system intercepts the operation instruction and, based on the current operation type and the data field information involved, determines in real time whether encryption or decryption processing is required;

[0123] If it is determined that encryption or decryption processing is required, the encryption judgment service system calls the catalog system to obtain the encryption / decryption rules. The catalog system provides the encryption / decryption rules for determining whether the data under the field needs to be encrypted and determining the corresponding encryption level;

[0124] The encryption judgment service system triggers the encryption / decryption service system, and the encryption / decryption service system obtains the corresponding encryption key from the key management service system;

[0125] The encryption / decryption service system selects the corresponding encryption or decryption algorithm according to the preset encryption level and executes the specific encryption or decryption operation;

[0126] The encryption / decryption service system returns the processed data to the application system or writes it into the database through the encryption determination service system, completing the full-life cycle security management of the data.

[0127] Among them, during the process of respectively deploying the business system, the database, the encryption judgment service system, and the encryption / decryption service system on multiple public cloud platforms, the catalog system configures information such as the database address, port, username, and password to establish a connection to the database and complete the access. The catalog system is responsible for analyzing the data structure information in the database and automatically identifying the data under the data fields that need to be encrypted by evaluating the sensitivity and importance of the data;

[0128] According to the above analysis results, the cataloging system formulates and maintains encryption and decryption rules. The encryption and decryption rules include the encryption level, encryption algorithm, and parameter configuration of the fields. For example, the encryption levels are divided into L0 (no encryption required), L1, L2, L3, and L4. The larger the number, the more the data of the field needs to be encrypted, and the higher the degree of data encryption. For example, L2 uses the SM4 algorithm for encryption, and L3 uses AES with a 192-bit key for encryption. The corresponding relationship between the encryption level and the encryption method is pre-set in the encryption judgment service system, and different levels correspond to different encryption algorithms and parameter configurations;

[0129] The cataloging system periodically updates these encryption and decryption rules and distributes the latest encryption and decryption rules to the encryption judgment service system to ensure that it can perform encryption or decryption judgments based on the latest security policies.

[0130] At the same time, the authorization management service system regularly verifies the access permissions of the encryption judgment service systems in each public cloud to complete authorization management, which runs through the entire system as a security mechanism.

[0131] The database is used to store structured data and provides a data access interface for the application system, supporting the reading of meta-information such as table structures and field definitions.

[0132] Among them, the intelligent encryption and decryption engine can be privately deployed or publicly cloud-deployed according to user needs.

[0133] In this embodiment, the encryption levels of the field data in the accessed database system are dynamically and intelligently determined. The main process is as follows:

[0134] 1. Feature extraction

[0135] The cataloging system configures information such as the database address, port, username, and password to establish a connection to the database and complete the access.

[0136] Obtain the field names in all data table fields in the database, perform word segmentation according to the symbol "_", and then use the word-to-word vector tool Word2Vec to convert the fields into word vectors. Extract features such as the data type, field length, and data volume of the fields and perform a full connection operation with the word vectors, that is, the length of the word vector to form a feature matrix .

[0137] Perform one-hot encoding (One-Hot-Encoding) on the encryption levels (L0, L1, L2, L3, L4), and represent each encryption level as a binary vector. For example:

[0138]

[0139] 2. Model Training

[0140] Input the feature matrix into the DNN (feedforward neural network) model to calculate the input of the first hidden layer and the output after being processed by the ReLU activation function : :

[0141]

[0142] Among them, represents the weight matrix of the first layer, represents the bias vector of the first layer.

[0143] In the present invention, a total of four hidden layers and an output layer are set, and each hidden layer is represented by the variable . Calculate the input and output of which need to use the output of the previous layer

[0144]

[0145]

[0146] Among them, and respectively represent the weight matrix and offset of the th layer.

[0147] Finally, calculate the input matrix of the output layer through the above formula, and obtain the probability distribution of the output layer through the Softmax function:

[0148]

[0149] Among them, represents the th encryption level, is the number of encryption levels, is used as a temporary variable in the accumulative value, represents the total number of samples in the th sample, represents the value of the th encryption level in the th sample of the input matrix of the output layer, and represents the value to be accumulated for the th sample at the th encryption level.

[0150] Finally, the cross - entropy loss function is used to calculate the loss, and the model is trained to the optimal state:

[0151]

[0152] Among them, represents the true value of the th encryption level in the th sample, represents the function value of the cross - entropy function, N represents the total number of samples.

[0153] So far, the cataloging system generates the intelligent encryption level for the fields in the public data system through the regular training method of artificial intelligence.

[0154] In this embodiment, each public cloud includes three modules: an application system, a database, and a plugin. The plugin includes an encryption judgment service and an encryption - decryption service. The main process of data encryption - decryption for each public cloud is as follows:

[0155] 1) According to the encryption - decryption rules, obtain the fields in the data table that need to be encrypted in the rules, and obtain the data under the data table fields, that is, the data to be encrypted is not the field, but the data corresponding to the field.

[0156] 2) Based on the data to be encrypted, call the encryption - decryption service system to encrypt the data;

[0157] 3) The encryption - decryption service system calls the key management service system in the key management device to obtain the key;

[0158] 4) Based on the obtained key, encrypt the data and return it to the encryption judgment service system;

[0159] 5) The encryption judgment service system returns the encrypted data to the database.

[0160] Since the business data of the business system is stored in the database, if the business system needs to query data, but at this time it has been encrypted by the encryption judgment service. Then after the business system obtains the data, it needs to decrypt the data. The main process is as follows:

[0161] 1) The business system calls the encryption judgment service system to judge which fields of data are encrypted and obtain the encryption - decryption rules;

[0162] 2) Based on the obtained encryption - decryption rules, obtain the decryption method according to the corresponding relationship between the pre - set encryption level and encryption method;

[0163] 3) Based on the obtained decryption method, call the encryption - decryption service system to decrypt the data;

[0164] 4) The encryption / decryption service system obtains the key from the key management service system;

[0165] 5) Based on the obtained key, decrypt the encrypted data, and after returning to the encryption determination service system, it is returned to the business system by the encryption judgment service system;

[0166] 6) The business system obtains the decrypted data for subsequent business processing.

[0167] In addition, when the encryption judgment service synchronizes the encryption rules, it needs to apply for authorization to the authorization management service system, and the encryption rule synchronization can be carried out only after obtaining the authorization permission.

[0168] The present invention can be applied in multiple fields, such as:

[0169] Financial service field: Financial institutions such as banks, securities companies, and insurance companies will process a large amount of customer sensitive information, such as account information, transaction records, financial data, etc. Using this patented technology, data can be securely exchanged between public clouds where different financial business systems are located. For example, when conducting customer credit assessments, multi-party data can be securely integrated and analyzed, and it is ensured that the data is not leaked or tampered with during transmission and storage, meeting the strict regulatory compliance requirements of the financial industry.

[0170] Healthcare field: Hospitals, pharmaceutical companies, medical research institutions, etc. will generate and manage a large amount of medical data, including patient medical records, genetic data, clinical trial data, etc. With the help of this patent to achieve cross-cloud data security processing, it can support the secure sharing of medical data between public cloud systems of different medical institutions, facilitate remote medical diagnosis, medical research cooperation, etc., while protecting the security of patients' private data.

[0171] Government public service field: There are many government affairs systems in government departments distributed in different public clouds, such as tax systems, social security systems, household registration systems, etc. Through this patented technology, secure encryption and decryption of government affairs data can be achieved in a cross-cloud environment, ensuring the security of citizens' personal information and government sensitive data.

[0172] Internet technology enterprises: Large Internet enterprises often have multiple business lines, and data storage and processing are scattered in different public clouds. This patent can help enterprises achieve secure integration and analysis of internal data, mine data value. For example, in scenarios such as advertising placement and user behavior analysis, user data can be securely processed and utilized.

[0173] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts between each embodiment, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and reference can be made to the description in the method part for related parts.

[0174] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1. An artificial intelligence-based data encryption strategy formulation and data full-life cycle security guarantee system, characterized in that, It includes multiple public clouds and intelligent encryption and decryption engines. Each public cloud is deployed with business systems, databases, encryption judgment service systems and encryption and decryption service systems. The intelligent encryption and decryption engine includes cataloging systems, key management service systems and authorization management service systems. The application system is used to receive data operation requests input by users, execute corresponding business logic, and generate operation instructions for the database; The database is used to store data and provide data access interfaces for application systems; The cataloging system is responsible for analyzing the data structure information in the database, automatically identifying the data in the fields that need to be encrypted by evaluating the sensitivity and importance of the data, formulating encryption and decryption rules, and periodically updating the encryption and decryption rules. The latest encryption and decryption rules are sent to the encryption judgment service system to achieve dynamic management; The key management service system is used to complete the life cycle management of keys; The authorization management service system is used to verify access rights of encryption judgment service systems in each public cloud and complete authorization management; The encryption judgment service system is used to complete the authorization operation and obtain the latest encryption and decryption rules from the cataloging system at regular intervals. It also intercepts the operation instructions when the application system initiates a data operation request, and determines in real time whether encryption or decryption is required based on the current operation type and field information. If encryption or decryption is required, the cataloging system is called to obtain the encryption and decryption rules. The encryption and decryption service system is used to respond to the request of the encryption judgment service system, obtain the corresponding key from the key management service system, perform specific encryption or decryption operations according to the preset encryption level, and return the processed data to the application system or write it to the database.

2. The data encryption policy formulation and data full - life - cycle security guarantee system based on artificial intelligence according to claim 1, characterized in that, Operation instructions include adding, querying, updating or deleting data.

3. The system for formulating data encryption policies based on artificial intelligence and ensuring the security of the entire data life cycle according to claim 1, characterized in that, Key lifecycle management includes key generation, storage, distribution, update, and synchronization.

4. The data encryption strategy formulation and data full - life - cycle security guarantee system based on artificial intelligence according to claim 1, characterized in that, Encryption and decryption rules include the encryption level of the field, encryption algorithm and parameter configuration.

5. The data encryption strategy formulation and data full - life - cycle security guarantee system based on artificial intelligence according to claim 1, characterized in that, Regular training of encryption and decryption rules includes: Convert the field name in the field to a word vector, extract the data type, field length, and data volume of the field, and perform a fully connected operation with the word vector to obtain a word vector with a length of to form a feature matrix ; ; Input the feature matrix into the feedforward neural network model, which includes four hidden layers and one output layer; Each hidden layer is represented by the variable and the processing procedure through the hidden layer is as follows: ; ; Among them, and respectively represent the layer weight matrix and offset, is the RELU activation function, and represent input and output; among them, ; The weight matrix representing the first hidden layer, The bias vector representing the first hidden layer, and represent the input and output of the first hidden layer; The input matrix is obtained after passing through the hidden layer , the input matrix The output layer probability distribution is obtained after passing through the output layer and the Softmax function : ; Among them, represents the th encryption level, is the number of encryption levels, serves as a temporary variable in the accumulated value, represents the total number of samples in the th sample, represents the input matrix of the output layer in the th sample, the value of the th encryption level, represents the value to be accumulated for the th sample at the th encryption level; Use the cross entropy loss function to calculate the loss and train the model to the optimal state: ; Among them, represents the true value of the th encryption level in the th sample, represents the function value of the cross-entropy function, N represents the total number of samples.

6. A method for formulating data encryption strategies based on artificial intelligence and ensuring data security throughout the entire life cycle, characterized in that, include: Business systems, databases, encryption judgment service systems, and encryption and decryption service systems are deployed on multiple public cloud platforms. The cataloging system is responsible for analyzing the data structure information in the database, automatically identifying the data under the fields that need to be encrypted by evaluating the sensitivity and importance of the data, formulating encryption and decryption rules, determining the corresponding encryption level, and periodically updating the encryption and decryption rules. The latest encryption and decryption rules are sent to the encryption judgment service system to achieve dynamic management; the authorization management service system regularly verifies the access rights of the encryption judgment service systems in each public cloud to complete authorization management; Receive data operation requests input by users through the application system, execute corresponding business logic, and generate operation instructions for the database; The encryption judgment service system intercepts the operation instructions and determines in real time whether encryption or decryption is required based on the current operation type and field information; If it is determined that encryption or decryption processing is required, the encryption judgment service system calls the cataloging system to obtain encryption and decryption rules; The encryption and decryption judgment service system triggers the encryption and decryption service system. The encryption and decryption service system obtains the corresponding key from the key management service system, performs specific encryption or decryption operations according to the preset encryption level, and returns the processed data to the application system or writes it into the database to complete the full life cycle security management of the data.

7. The method for formulating an artificial intelligence-based data encryption policy and ensuring data security throughout the entire life cycle according to claim 6, wherein The operation instructions include operations for adding, querying, updating, or deleting data.

8. The method for formulating an artificial intelligence-based data encryption strategy and ensuring data security throughout the entire life cycle according to claim 6, characterized in that, The life cycle management of keys includes key generation, storage, distribution, update, and synchronization.

9. The method for formulating an artificial intelligence-based data encryption strategy and ensuring data security throughout the entire life cycle according to claim 6, characterized in that, The encryption and decryption rules include the encryption level of fields, encryption algorithms, and parameter configurations.

10. The method for formulating an artificial intelligence-based data encryption policy and ensuring the security of the entire data life cycle according to claim 6, wherein Regular training of the encryption and decryption rules specifically includes: Convert the field name in the field into a word vector, extract the data type, field length, and the amount of data in the field, and perform a fully connected operation with the word vector to obtain a word vector with a length of of the word vector to form a feature matrix ; Input the feature matrix into the feedforward neural network model, which includes four hidden layers and an output layer; Each hidden layer is represented by the variable and the processing procedure through the hidden layer is as follows: ; ; Among them, and respectively represent the layer weight matrix and offset, is the RELU activation function, and represent input and output; among them, ; The weight matrix representing the first hidden layer, The bias vector representing the first hidden layer, and represent the input and output of the first hidden layer; The input matrix is obtained after passing through the hidden layer , the input matrix The output layer probability distribution is obtained after passing through the output layer and the Softmax function : ; Among them, represents the th encryption level, is the number of encryption levels, serves as a temporary variable in the cumulative value, represents the total number of samples in the th sample, represents the input matrix of the output layer in the th sample, the value of the th encryption level, represents the value to be accumulated for the th sample at the th encryption level; Calculating the loss using the cross-entropy loss function and training the model to the optimal state: ; Among them, represents the true value of the th encryption level in the th sample, represents the function value of the cross-entropy function, N indicates the total number of samples.

Citation Information

Patent Citations

  • Data transparent encryption and decryption system suitable for big data platform

    CN111625843A

  • Deep reinforcement learning optimization algorithm based on adaptive encryption framework

    CN119513891A

  • Server cluster security control method combined with multi-level encryption strategy joint scheduling

    CN119939637A

  • Object storage data encryption method based on large model

    CN120017355A

  • Encryption key lifecycle management

    US20170257214A1

Cited By

  • Intelligent security method and system based on international general cryptographic algorithm

    CN122316702A