Secret-related carrier full life cycle monitoring and safety management system
By expanding and encrypting the data at the carrier information extraction module and expansion unit on the receiving end of the confidential carrier, encrypted transmission data with high randomness and variations are dynamically generated, which solves the risk of data leakage caused by poor key management at the receiving end, and improves the security and cracking resistance of data transmission.
Patent Information
- Application Number
- CN202510301095.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
At the receiving end of confidential carriers, there is a lack of a professional information security management team and a complete key management system, which leads to the risk of leakage of keys, which may in turn cause confidential data leakage.
By setting up a carrier information extraction module to extract data from the target confidential carrier, and using the carrier information expansion unit to perform binary conversion and replacement of the data to create an extended square matrix. Then, the carrier information encryption unit determines the square matrix mapping digital code based on the number of rows and element ratios of the extended square matrix, and dynamically generates encrypted transmission data with high randomness and variability.
By dynamically generating encrypted transmission data with high randomness and variability, the security and cracking resistance of data during transmission are significantly increased, and the risks of key leakage and data leakage are reduced.
Smart Images

Figure CN120217455A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and specifically to a full-life-cycle monitoring and security management system for confidential carriers. Background Art
[0002] In today's digital information era, as an important storage and transmission medium for sensitive information, confidential carriers range from paper documents to various electronic storage devices such as USB flash drives and external hard drives, and then to confidential data transmitted over the network. These carriers carry key information, and their security is of utmost importance;
[0003] Currently, in the process of full-life-cycle monitoring of carriers, in order to ensure the security of confidential carriers during transmission, the AES (Advanced Encryption Standard) encryption algorithm is widely used. With its efficient encryption performance and strong security, the AES encryption algorithm occupies an important position in the field of encryption. It converts plaintext into ciphertext through complex mathematical operations, effectively preventing information from being stolen or tampered with during data transmission;
[0004] However, the effective operation of the AES encryption algorithm highly depends on the security management of keys. In practical applications, it is necessary to ensure that the keys at the sending end and the receiving end are exactly the same and in a secure state. However, at the receiving end, facing an extremely complex environment and uneven management capabilities, there may be a lack of professional information security management teams and perfect key management systems. When receiving confidential carriers, it is impossible to strictly encrypt and store the keys and control access, resulting in a risk of key leakage, which may in turn cause the leakage of confidential data;
[0005] To solve the above problems, the present invention proposes a solution. Summary of the Invention
[0006] The purpose of the present invention is to provide a full-life-cycle monitoring and security management system for confidential carriers to solve the problems raised in the above background art.
[0007] The present invention provides a full-life-cycle monitoring and security management system for confidential carriers, including:
[0008] A carrier information expansion unit, configured to traverse the content of the target confidential carrier data after receiving it, and perform binary conversion on each character in the target confidential carrier data bit by bit during the traversal to obtain the binary data of each character;
[0009] The carrier information expansion unit is further configured to determine the character length of the binary data after obtaining the binary data of each character, and perform padding on the binary number of the corresponding character with several characters '0' based on the determination result to obtain the binary extended data of each character;
[0010] The carrier information expansion unit is also used to determine the number of rows of the expansion square matrix of each character in the target classified carrier data according to the number of digits and the multiple characteristic of 4 in the binary expansion data of each character, and create the expansion square matrix of the character by combining the number of rows and the preset standard number of columns and the binary expansion data of the character;
[0011] The carrier information encryption unit is used to determine the square matrix mapping code of each character according to the ratio of the number of rows of the expansion square matrix and the ratio of the number of 0 and 1 elements in each row after receiving the expansion square matrices of all characters in the target classified carrier data, and splice the expansion square matrices of all characters in the target classified carrier data to obtain the encrypted transmission data of the target classified carrier data;
[0012] The carrier information encryption unit is also used to transmit the encrypted transmission data of the target classified carrier data to the corresponding target electronic device.
[0013] Further, it also includes a carrier information extraction module for extracting target classified carrier data from the target classified carrier, and the target classified carrier data is stored in the target classified carrier in a digital information form.
[0014] Further, the character types included in the target classified carrier data are one or more of Chinese characters, English characters, and digital characters.
[0015] Further, the steps to obtain the encrypted transmission data of the target classified carrier data are as follows:
[0016] Step 1: Mark each character constituting the target classified carrier data as A1, A2,..., Aa in sequence from left to right, where a≥1;
[0017] Step 2: Obtain the expansion square matrix of the character A1, and determine the square matrix mapping digit code of the character A1 according to the number of rows of the expansion square matrix of the character A1;
[0018] Step 3: Traverse all elements in the first row of the expansion square matrix of the character A1 from left to right, determine the ratio of the number of elements that are 0 and 1, and determine an element mapping digit code of the character A1 according to the ratio. The ratio result of the number of elements that are 0 or 1 is one of 0:4, 1:3, 2:2, 3:1, 4:0;
[0019] Step 4: Similarly, traverse all elements corresponding to the second, third,..., P1 rows of the expansion square matrix of the character A1 from left to right in sequence to determine P1 - 1 element mapping digit codes, where P1 is the number of rows of the expansion square matrix of the character A1;
[0020] In this application, each digit filled into the extended square matrix is collectively referred to as an element;
[0021] Step Five: Concatenate the P1 elements' mapped digital codes of the character A1 in the order of concatenation to obtain the square matrix mapped code of the character A1;
[0022] Step Six: Sequentially obtain the square matrix mapped codes of characters A2, A3,..., Aa according to Steps One to Five, and concatenate the square matrix mapped codes of characters A1, A2,..., Aa in the order of acquisition to obtain the encrypted transmission data of the target confidential carrier data.
[0023] Compared with the prior art, the following beneficial effects are achieved:
[0024] In the present invention, a carrier information extraction module is set to extract target confidential carrier data from the target confidential carrier, a carrier information expansion unit is set to expand the binary numbers of each character in the target confidential carrier data, the number of rows of the extended square matrix corresponding to the character is determined based on the number of digits in the binary extended data obtained after expansion and the characteristic of being a multiple of 4, a carrier information encryption unit is set to determine the square matrix mapped digital codes for the extended square matrix of each character according to the number of rows of the extended square matrix, and the element mapped digital codes of each row are determined according to the proportion of elements with value 0 and value 1 in each row of the extended square matrix. Among them, during the process of determining the element mapped digital codes, a character is randomly selected from 0 and 1 dynamically based on the proportion of element 0 and element 1. In this way, the element mapped digital codes of several rows of each element have a high degree of randomness, greatly increasing the difficulty of cracking and restoring the element mapped digital codes of each row of elements;
[0025] Moreover, the number of element mapped digital codes corresponding to different numbers of rows is different, making the character length of the square matrix mapped code of each character change dynamically, further increasing the difficulty of cracking the final encrypted transmission data;
[0026] At the same time, the square matrix mapped digital codes also represent the total number of characters of the square matrix mapped code corresponding to the character in the concatenation. In this way, the finally obtained encrypted transmission data has higher security and anti-cracking ability;
[0027] In the present invention, the target confidential carrier data to be pre-transmitted is encrypted and transmitted by using an encryption logic instead of an encryption algorithm, avoiding the occurrence of the situation that the target confidential carrier data transmitted is insecure due to the complex environment at the receiving end. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 It is the system block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0030] Please refer to Figure 1 , this application provides a full-life-cycle monitoring and security management system for classified carriers, including a carrier information extraction module and a carrier information processing platform;
[0031] The carrier information extraction module is used to extract target classified carrier data from a target classified carrier, where the target classified carrier data is stored in the target classified carrier in a digital information form. In this application, the character types included in the target classified carrier data are one or more of Chinese characters, English characters, and digital characters;
[0032] The carrier information extraction module transmits the extracted target classified carrier data of the target classified carrier to the carrier information processing platform;
[0033] The carrier information processing platform is used to process the pre-transmitted carrier information. The carrier information processing platform includes a carrier information expansion unit and a carrier information encryption unit. After receiving the transmitted target classified carrier data of the target classified carrier, the carrier information processing platform transmits it to the carrier information expansion unit;
[0034] After receiving the transmitted target classified carrier data, the carrier information expansion unit traverses its content. During the traversal process, each character in the target classified carrier data is converted into binary bit by bit to obtain the binary data of each character;
[0035] Then, determine the character length of the binary number of each character, and based on the determination result, pad the binary number of the corresponding character to obtain the binary extended data of each character. Specifically, for the binary number of any character, if the character length of the binary number is less than 4, fill several characters '0' at the leftmost end of the binary number to make the character length of the binary number equal to 4; if the character length of the binary number is greater than 4 and less than 8, fill several characters '0' at the leftmost end of the binary number to make the character length of the binary number equal to 8; if the character length of the binary number is greater than 8 and less than 12, fill several characters '0' at the leftmost end of the binary number to make the character length of the binary number equal to 12; if the character length of the binary number is greater than 12 and less than 16, fill several characters '0' at the leftmost end of the binary number to make the character length of the binary number equal to 16. It should be noted here that if the character length of the binary number is any one of 4, 8, 12, or 16, the number of characters '0' filled at the leftmost end of the binary number is 0;
[0036] For the binary extended data of each character in the target classified carrier data, determine the number of rows of the extended square matrix of the character according to the number of digits forming the binary extended data and the multiple feature of 4. It should be noted here that a binary number is a number represented by two digits, 0 and 1;
[0037] In this application, the quotient obtained by dividing the number of digits by 4 is the multiple feature of the number of digits and 4;
[0038] Create the extended square matrix of the character according to the number of columns of the extended square matrix of the character and the preset standard number of columns in combination with the binary extended data of the character. In this application, the standard number of columns is 4;
[0039] In this application, when creating the extended square matrix of the character, fill all the digits in the binary extended data of the character into the extended square matrix in the order from left to right. The filling order is: first fill the first row of the extended square matrix from left to right, and after the first row is filled, fill the second row in the same way, and so on, until all the digits forming the binary extended data of the character are filled into the corresponding positions of the extended square matrix;
[0040] After the extended square matrices of each character in the target classified carrier data are all constructed, transmit all the constructed extended square matrices to the carrier information encryption unit;
[0041] After receiving the extended square matrices of all the characters constituting the target classified carrier data transmitted, the carrier information encryption unit maps the extended square matrices of all the characters according to the preset mapping rule. The mapping rule is as follows:
[0042] Step 1: Mark each character in the target classified carrier data as A1, A2, ..., Aa in sequence from left to right, where a≥1;
[0043] Step 2: Obtain the extended square matrix of the character A1, and determine the square matrix mapping digit code of the character A1 according to the number of rows of the extended square matrix of the character A1;
[0044] Step 3: Traverse all elements in the first row of the extended square matrix of the character A1 from left to right, determine the ratio of the number of elements with value 0 to the number of elements with value 1, and determine an element mapping digit code of the character A1 according to the ratio. In this application, the ratio result of the number of elements with value 0 or 1 is one of 0:4, 1:3, 2:2, 3:1, 4:0;
[0045] Specifically, if the ratio result is 0:4 or 4:0, first determine that 00 is the element quantity mapping group code of the character A1 based on the first row, and then compare the numerical value of the number of elements with value 0 with the numerical value of the number of elements with value 1. If the numerical value of the number of elements with value 0 is larger than the numerical value of the number of elements with value 1, then use 0 as the element type mapping group code of the character A1 based on the first row;
[0046] If the ratio result is 1:3, first determine that 01 is the element quantity mapping group code of the character A1 based on the first row, and then compare the numerical value of the number of elements with value 0 with the numerical value of the number of elements with value 1. If the numerical value of the number of elements with value 0 is larger than the numerical value of the number of elements with value 1, then use 0 as the element type mapping group code of the character A1 based on the first row;
[0047] If the ratio result is 3:1, first determine that 10 is the element quantity mapping group code of the character A1 based on the first row, and then compare the numerical value of the number of elements with value 0 with the numerical value of the number of elements with value 1. If the numerical value of the number of elements with value 0 is larger than the numerical value of the number of elements with value 1, then use 0 as the element type mapping group code of the character A1 based on the first row;
[0048] If the ratio result is 2:2, first determine that 11 is the element quantity mapping group code of the character A1 based on the first row, and then randomly select one from 0 or 1 as the element type mapping group code of the character A1 based on the first row;
[0049] Concatenate the element type mapping group code and the element quantity mapping group code of the character A1 to obtain an element mapping digit code of the character A1, and the concatenation order is in the order of the element type mapping group code and the element quantity mapping group code;
[0050] Step 4: Similarly, traverse all the elements in the second, third, …, P1-th rows of the extended square matrix of the character A1 from left to right in sequence to determine P1-1 element mapping digital codes correspondingly, where P1 is the number of rows of the extended square matrix of the character A1;
[0051] In this application, each digital code filled into the extended square matrix is collectively referred to as an element;
[0052] Step 5: Concatenate the P1 element mapping digital codes of the character A1 in the order of concatenation to obtain the square matrix mapping code of the character A1;
[0053] Step 6: Obtain the square matrix mapping codes of the characters A2, A3, …, Aa in sequence according to Steps 1 to 5, and concatenate the square matrix mapping codes of the characters A1, A2, …, Aa in the order of acquisition to obtain the encrypted transmission data of the target classified carrier data;
[0054] The carrier information encryption unit transmits the encrypted transmission data of the target classified carrier data to the corresponding target electronic device. In this application, the target electronic device is a desktop computer or a server that has passed identity authentication and is authorized to receive;
[0055] For some data in the above formula, numerical calculations are performed after removing their dimensions, and the content not described in detail in this specification belongs to the prior art well known to those skilled in the art.
[0056] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A full life cycle monitoring and security management system for confidential carriers, characterized by: include: The carrier information expansion unit is used to traverse the content of the target confidential carrier data after receiving it, and during the traversal process, perform binary conversion on each character in the target confidential carrier data bit by bit to obtain the binary data of each character; The carrier information extension unit is further used to determine the character length of the binary data after obtaining the binary data of each character, and to fill the binary number of the corresponding character with a number of characters 0 based on the determination result to obtain the binary extension data of each character; The carrier information extension unit is also used to determine the number of rows of the extended square matrix of the character according to the number of digits constituting the binary extended data and the multiple of 4 for the binary extended data of each character in the target confidential carrier data, and to create the extended square matrix of the character according to the number of rows and a preset standard number of columns in combination with the binary extended data of the character; A carrier information encryption unit, configured to determine the matrix mapping code of each character according to the number of rows of the extended matrix and the ratio of the number of 0 elements to the number of 1 elements in each row after receiving the transmitted extended matrix constituting all characters in the target confidential carrier data, and to concatenate the extended matrices of all characters in the target confidential carrier data to obtain the encrypted transmission data of the target confidential carrier data; The carrier information encryption unit is also used to transmit the encrypted transfer data of the target confidential carrier data to the corresponding target electronic device.
2. The full life cycle monitoring and security management system for confidential carriers according to claim 1 is characterized in that: It also includes a carrier information extraction module for extracting target confidential carrier data from the target confidential carrier. The target confidential carrier data is stored in the target confidential carrier in the form of digital information.
3. The full life cycle monitoring and security management system for confidential carriers according to claim 3 is characterized in that: The character types contained in the target confidential carrier data are one or more of Chinese characters, English characters and numeric characters.
4. The full life cycle monitoring and security management system for confidential carriers according to claim 1 is characterized in that: The quotient obtained by dividing the number of digits by 4 is the characteristic of the number of digits and multiples of 4.
5. The full life cycle monitoring and security management system for confidential carriers according to claim 1 is characterized in that: For any binary number of a character, if the character length of the binary number is less than 4, several characters 0 are filled into the leftmost end of the binary number so that the character length of the binary number is equal to 4; if the character length of the binary number is greater than 4 and less than 8, several characters 0 are filled into the leftmost end of the binary number so that the character length of the binary number is equal to 8; if the character length of the binary number is greater than 8 and less than 12, several characters 0 are filled into the leftmost end of the binary number so that the character length of the binary number is equal to 12; if the character length of the binary number is greater than 12 and less than 16, several characters 0 are filled into the leftmost end of the binary number so that the character length of the binary number is equal to 16.
6. The full life cycle monitoring and security management system for confidential carriers according to claim 5 is characterized in that: If the character length of the binary number is any one of 4, 8, 12 or 16, the number of characters 0 filled into the leftmost end of the binary number is 0.
7. The full life cycle monitoring and security management system for confidential carriers according to claim 1 is characterized in that: The steps of obtaining the encrypted transmission data of the target confidential carrier data are as follows: Step 1: Mark each character constituting the target confidential carrier data as A1, A2, ..., Aa, a≥1 in order from left to right; Step 2: Obtain the extended square matrix of the character A1, and determine the square matrix mapping digital code of the character A1 according to the number of rows of the extended square matrix of the character A1; Step 3: Traverse all elements in the first row of the extended matrix of the character A1 from left to right, determine the ratio of the number of elements that are 0 to the number of elements that are 1, and determine a digital code mapping of an element of the character A1 according to the ratio, and the ratio of the number of elements that are 0 or 1 is one of 0:4, 1:3, 2:2, 3:1, and 4:0; Step 4: Similarly, all elements in the second, third, ..., P1 rows in the extended matrix of the character A1 are traversed from left to right to determine the corresponding digital codes of P1-1 elements, where P1 is the number of rows in the extended matrix of the character A1; In this application, each number filled into the extended matrix is collectively referred to as an element; Step 5: splicing the P1 element mapping digital codes of the character A1 in the splicing order to obtain the square matrix mapping code of the character A1; Step six: Obtain the square matrix mapping codes of characters A2, A3, ..., Aa in sequence according to steps one to five, and concatenate the square matrix mapping codes of characters A1, A2, ..., Aa in the order obtained to obtain the encrypted transmission data of the target confidential carrier data.
8. The full life cycle monitoring and security management system for confidential carriers according to claim 7 is characterized in that: In step 3, if the ratio result is 0:4 or 4:0, first determine 00 as the mapping group code of the character A1 based on the number of elements in the first row, and then compare the numerical values of the number of elements that are 0 and the number of elements that are 1. If the numerical value of the number of elements that are 0 is greater than the numerical value of the number of elements that are 1, use 0 as the mapping group code of the character A1 based on the element type of the first row; If the ratio result is 1:3, first determine 01 as the mapping group code of the character A1 based on the number of elements in the first row, and then compare the numerical values of the number of elements that are 0 and the number of elements that are 1. If the numerical value of the number of elements that are 0 is greater than the numerical value of the number of elements that are 1, use 0 as the mapping group code of the character A1 based on the element type of the first row; If the ratio result is 3:1, first determine that 10 is the mapping group code of the character A1 based on the number of elements in the first row, and then compare the numerical values of the number of elements that are 0 and the number of elements that are 1. If the numerical value of the number of elements that are 0 is greater than the numerical value of the number of elements that are 1, then use 0 as the mapping group code of the character A1 based on the element type of the first row; If the ratio result is 2:2, first determine 11 as the mapping group code of the number of elements of the character A1 based on the first row, and then randomly select one from 0 or 1 as the mapping group code of the element type of the character A1 based on the first row; The character A1 is concatenated based on the element type mapping group code and the element quantity mapping group code in the first row to obtain an element mapping digital code of the character A1.