Data encryption transmission method based on transaction security

By analyzing the behavioral characteristics and transaction attraction representation coefficients of the client, setting the importance tag, and adjusting the key length according to the privacy tendency characteristics, and using different encryption methods for data transmission, the problem of lack of flexibility in data encryption transmission in the prior art is solved, and the security and adaptability of data transmission are improved.

CN120218929AInactive Publication Date: 2025-06-27HENGSHUI UNIVERSITY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510346009.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, data encryption transmission is in a single form during online transactions, and cannot be flexibly adjusted according to different characteristics of the data. The encryption lacks flexibility, and there are transmission security vulnerabilities, which reduces the security of data transmission.

Method used

By obtaining the product update data of the server and the behavioral characteristics of the client, analyzing the transaction attraction characterization coefficient, setting the importance tag of the client, adjusting the key length according to the privacy tendency characteristics, using different encryption methods for data transmission, and monitoring traffic fluctuations in real time, identifying abnormal fluctuations stages, and limiting access to the source port.

Benefits of technology

It improves the security and adaptability of data transmission, and can flexibly adjust the encryption method according to the different importance and data characteristics of the client, enhancing the protection of private data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120218929A_ABST
    Figure CN120218929A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data encryption transmission, in particular to a data encryption transmission method based on transaction security, and the method comprises the steps: obtaining the product updating data of a server and the behavior evaluation historical data of a client, so as to recognize the behavior characteristics of the client; analyzing a transaction attraction characterization coefficient aiming at the client in combination with the total transaction amount of the product updating cycle so as to set an importance degree label of the client; based on the importance degree label, adaptively performing encryption transmission on data generated during transaction with the client; the method comprises the following steps: monitoring traffic fluctuation data of a server in real time, identifying a traffic abnormal fluctuation stage, obtaining a plurality of data received in the traffic abnormal fluctuation stage, and judging whether to limit access of a source port and send a data re-transmission request to the client according to the same number of timestamps corresponding to the data and the number of the same ports of the data. According to the invention, on the premise of flexibly selecting an encryption mode of transmission data, the security and adaptability of data transmission are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encrypted transmission, and particularly to a data encrypted transmission method based on transaction security. Background Art

[0002] With the rapid development of Internet technology, people are increasingly inclined to conduct transaction activities through the network, including purchasing goods, transferring money, investing in finance, etc. However, the convenience of online transactions also brings many security risks. The data generated during the transaction process faces risks such as being stolen, tampered with, and forged during transmission, threatening the user's capital security and personal information security; Meanwhile, the computer processing power is continuously improving, which can support the operation of more complex and advanced data encryption algorithms. The processor can complete a large number of data encryption and decryption operations in a short time, providing a powerful computing foundation for data encrypted transmission. Therefore, it promotes the development of the data transmission form of using encrypted transmission in online transactions to ensure the security and stability of data during transmission.

[0003] Chinese Patent Application Publication No.: CN108848089A, discloses a data encryption method and a data transmission system. The data encryption method includes: generating a first dynamic password from transaction data; calculating a first key from the first dynamic password and the counting data of the current transaction; using the first key to encrypt sensitive data to form first encrypted data; calculating a Mac for the sensitive data using a device key to form first Mac data; calculating a second digest for the original data composed of the unencrypted data, the first encrypted data, and the first Mac data in the transaction data using the device key, and attaching the second digest to the original data and transmitting it to the server together. The invention achieves the technical effects of protecting data with different keys, preventing the transmitted data from being tampered with, effectively ensuring the security of data transmission, and being efficient.

[0004] However, there are still the following problems in the prior art. During the online transaction process, there is no effective classification of customer categories. For customers who have a close transaction interaction behavior with the service provider, the privacy and importance of the data transmitted during the transaction process are relatively high. For example, customers who have a long-term cooperation with the service provider or have frequent transactions may require more detailed data for completing the transaction, and even involve customer privacy. Therefore, more attention needs to be paid to the encrypted protection of data. However, in the prior art, a single encrypted transmission form is adopted for the data generated during the online transaction process. For data with a relatively high privacy and importance, the risk of transmission security vulnerabilities is relatively high, reducing the security of data transmission. At the same time, overall, the data transmission encryption method cannot be flexibly adjusted according to different characteristics of the data, making the data encryption lack flexibility. Summary of the Invention

[0005] To this end, the present invention provides a data encryption transmission method based on transaction security, which is used to overcome the problem in the prior art that in the process of network transactions, a single encryption transmission form is adopted for the data generated, and for data with a relatively high degree of privacy and importance, there is a relatively high risk of transmission security vulnerabilities, reducing the security of data transmission. At the same time, overall, the data transmission encryption method cannot be flexibly adjusted according to different characteristics of the data, resulting in the lack of flexibility in data encryption.

[0006] To achieve the above object, the present invention provides a data encryption transmission method based on transaction security, which includes: Obtain the product update data of the server to identify the behavior characteristics of the client; Based on the behavior characteristics and combined with the total transaction amount in the product update cycle, analyze the transaction attraction characterization coefficient for the client to set the importance level label of the client; Based on the importance level label, encrypt and transmit the data generated when trading with the client, including parsing the generated data, identifying sensitive data, obtaining the private tendency characteristics of the sensitive data, calculating the privacy degree characterization value based on the private tendency characteristics to adjust the length of the key, and encrypting and transmitting the generated data using the first encryption method; Or, encrypt and transmit the generated data using the second encryption method; Real-time monitor the traffic fluctuation data of the server, identify the traffic abnormal fluctuation stage, obtain a number of data received during the traffic abnormal fluctuation stage, and determine whether to restrict the access of the source port and send a request to the client to re-transmit the data according to the same number of timestamps corresponding to each data and the number of data from the same port; Wherein, the private tendency characteristics include the coverage rate of the client main body associated data and the remaining duration of the storage time limit.

[0007] Further, the process of identifying the behavior characteristics of the client includes, Call the product update data of the server to determine the product update cycle and the corresponding new products within the product update cycle; call the behavior characteristics of the client within the product update cycle, including the conversion rate of the client to the new products and the number of repeat purchases.

[0008] Further, the process of analyzing the transaction attraction characterization coefficient for the client based on the behavior characteristics and combined with the total transaction amount in the product update cycle includes using the ratio of the conversion rate to the conversion rate threshold and the ratio of the number of repeat purchases to the repeat purchase threshold as the first transaction attraction feature; using the ratio of the total transaction amount in the product update cycle to the total transaction amount threshold as the second transaction attraction feature; Sum the weighted first transaction attraction feature and the second transaction attraction feature as the transaction attraction representation coefficient.

[0009] Further, set the importance level label of the client, including If the transaction attraction representation coefficient for the client is greater than or equal to the transaction attraction representation coefficient threshold, mark the client with a high importance level label; If the transaction attraction representation coefficient for the client is less than the transaction attraction representation coefficient threshold, mark the client with a low importance level label.

[0010] Further, based on the importance level label, encrypt and transmit the data generated during the transaction with the client, including If the client is marked with a high importance level label, parse the generated data to identify sensitive data, obtain the private tendency feature of the sensitive data, calculate the privacy degree representation value based on the private tendency feature, adjust the length of the encryption key, and encrypt and transmit the generated data using the first encryption method; If the client is marked with a low importance level label, encrypt and transmit the generated data using the second encryption method.

[0011] Further, the process of identifying sensitive data includes Pre - establish a sensitive corpus; Match the generated data with the sensitive words in the sensitive corpus to determine the sensitive semantic similarity; If the average value of the sensitive semantic similarity corresponding to any data is greater than or equal to the sensitive semantic similarity average threshold, identify the data as the sensitive data.

[0012] Further, calculating the privacy degree representation value based on the private tendency feature includes Take the ratio of the client - entity associated data coverage rate to the associated data coverage rate threshold as the first privacy degree feature; Take the ratio of the remaining duration of the storage time limit to the remaining duration threshold as the second privacy degree representation value; Take the sum of the first privacy degree feature and the second privacy degree feature as the privacy degree representation value.

[0013] Further, adjusting the length of the encryption key includes If the privacy degree representation value is greater than or equal to the privacy degree representation threshold, adjust the length of the encryption key; Increase the length of the encryption key, and the increase amount of the length is positively correlated with the privacy degree representation value.

[0014] Further, the process of identifying the traffic abnormal fluctuation stage includes: Construct a traffic fluctuation time-domain curve based on the traffic; If there exists a slope of the corresponding curve segment within any time domain segment that is greater than or equal to the slope threshold, then identify the time domain segment as the traffic abnormal fluctuation stage.

[0015] Further, determining whether to restrict access to the source port and sending a request to the client to re-transmit data includes: if a number of data corresponding to the abnormal fluctuation stage do not meet the secure transmission benchmark conditions, then determine to restrict access to the source port and send a request to the client to re-transmit data; Wherein, the secure transmission benchmark conditions include that the number of the same timestamps corresponding to each of the data is greater than the timestamp same number threshold and the number of data from the same port is greater than the same port number threshold, and determine the corresponding same port as the source port.

[0016] Compared with the prior art, the present invention identifies the behavior characteristics of the client by obtaining the product update data of the server and the historical data of the behavior evaluation for the client; analyzes the transaction attraction characterization coefficient for the client based on the behavior characteristics in combination with the total transaction amount in the product update cycle to set the importance level label for the client; adaptively encrypts the data generated when transacting with the client based on the importance level label; monitors the traffic fluctuation data of the server in real time, identifies the traffic abnormal fluctuation stage, obtains a number of data received within the traffic abnormal fluctuation stage, and determines whether to restrict access to the source port and send a request to the client to re-transmit data based on the number of the same timestamps corresponding to each data and the number of data from the same port. The present invention improves the security and adaptability of data transmission on the premise of flexibly selecting the encryption method of the transmitted data.

[0017] In particular, the present invention analyzes the transaction attraction characterization coefficient for the client based on the behavior characteristics in combination with the total transaction amount in a predetermined time period. In actual situations, according to various behavior characteristics of the client such as the response to product updates and the purchase intention, the importance level of the client is determined, which is convenient for the server to conduct accurate market positioning, and further reflects the value of the data generated between the server and the client. Therefore, the present invention uses the transaction attraction characterization coefficient to characterize the loyalty of the client to the server and the degree of satisfaction of the server with the client's needs, providing data support for setting the importance level label of the client later. The present invention improves the security and adaptability of data transmission on the premise of flexibly selecting the encryption method of the transmitted data.

[0018] In particular, the present invention sets corresponding importance labels for different clients. For clients set to high importance labels, such clients may have long-term and frequent transaction cooperation with the server. At the same time, the server may collect more detailed information data about the client in order to better provide services to such clients. Therefore, the present invention identifies the sensitive data generated by both parties to the transaction, among which the coverage rate of the client subject-related data can reflect the closeness and privacy of the data's association with the client's personal information; the remaining duration of the storage period can reflect the timeliness and sensitivity of the data within a certain period of time. For example, in the case where there is a long-term cooperation plan between the client and the server, the data will have important value and confidentiality for a long time in the future. Therefore, the present invention calculates the privacy characterization value through the privacy tendency feature to characterize the privacy of the data generated between the two parties, and provides data support for adjusting the length of the key. The present invention improves the security and adaptability of data transmission under the premise of flexibly selecting the encryption method for transmitting data.

[0019] In particular, the present invention takes into account the traffic fluctuations presented by the data generated between the client and the server during the encrypted transmission process, so as to analyze the possibility of network attacks or other security incidents in the data transmission process, and then analyzes the same repetition of timestamps and data from ports in several data received by the server during the abnormal traffic fluctuation stage, and then accurately locates the possible attack source port. If more data with the same timestamp and coming from the same port, it may mean that the port has abnormal behavior, which may be the source of malicious attacks. The specific port is processed in a targeted manner to improve the efficiency of security protection. The present invention improves the security and adaptability of data transmission under the premise of flexibly selecting the encryption method for transmitting data. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 A schematic diagram of the steps of a data encryption transmission method based on transaction security according to an embodiment of the invention; Figure 2 A logical decision diagram for setting importance labels of clients for embodiments of the invention; Figure 3 A logical decision diagram for encrypting and transmitting data generated when conducting transactions with a client in an embodiment of the invention; Figure 4 A logical decision diagram for determining whether to restrict access to a source port and send a request to the client to transmit data again according to an embodiment of the present invention. DETAILED DESCRIPTION

[0021] To make the objectives and advantages of the present invention more clear and understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0022] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0023] Please refer to Figure 1 As shown, which is a schematic diagram of the steps of the civil aviation data analysis method according to an embodiment of the present invention. The data encryption and transmission method based on transaction security according to an embodiment of the present invention includes: Step S1, obtaining product update data of the server to identify the behavior characteristics of the client; Step S2, analyzing the transaction attraction characterization coefficient for the client based on the behavior characteristics in combination with the total transaction amount in the product update cycle to set the importance level label of the client; Step S3, based on the importance level label, encrypting and transmitting the data generated when transacting with the client, including, Parsing the generated data, identifying sensitive data, obtaining the private tendency characteristics of the sensitive data, calculating the privacy degree characterization value based on the private tendency characteristics to adjust the length of the key, encrypting the generated data using the first encryption method and transmitting it; Or, encrypting and transmitting the generated data using the second encryption method; Step S4, real-time monitoring the traffic fluctuation data of the server, identifying the traffic abnormal fluctuation stage, obtaining a number of data received during the traffic abnormal fluctuation stage, and determining whether to restrict the access of the source port and sending a request to the client to re-transmit the data based on the same number of timestamps corresponding to each data and the number of data from the same port; Wherein, the private tendency characteristics include the coverage rate of the client main body associated data and the remaining duration of the storage time limit.

[0024] Specifically, the generated data refers to the data received by the server from the client, which can be the data for submitting a transaction order or the relevant materials required for concluding a transaction. These data are transmitted to the server in the form of data packets. Among them, the header of the data packet contains a timestamp, which will not be elaborated here.

[0025] In this embodiment, the first encryption method is an encryption method that combines symmetric encryption and asymmetric encryption. For example, in the SSL / TLS protocol, an asymmetric encryption algorithm, such as RSA or ECC, is used for key exchange to negotiate a symmetric encryption key, and then a symmetric encryption algorithm, such as AES, is used to encrypt and transmit subsequent communication data, which can not only ensure the security of key exchange, but also improve the efficiency of data encryption; The second encryption method is asymmetric encryption, which uses a pair of different but related keys for encryption and decryption operations. For example, RSA can encrypt data using the public key of the server, and the server uses its own private key for decryption, which will not be elaborated here.

[0026] Specifically, the process of identifying the behavioral characteristics of the client includes, Invoking the product update data of the server to determine the product update cycle and the corresponding new products within the product update cycle; Invoking the behavioral characteristics of the client within the product update cycle, including the conversion rate of the client to the new product and the number of repeat purchases.

[0027] It can be understood that the product update data contains the listing records of several products of the server and the purchase records of each product by the client.

[0028] Specifically, the product update cycle refers to the time interval from one product launch of the server to the next product launch, and the new product refers to the product first launched and listed by the server, which will not be elaborated here.

[0029] Specifically, the conversion rate of the client to the new product refers to the proportion of potential clients converted into actual purchasing clients within the product update cycle, that is, the ratio of the number of clients with actual purchase behavior of the product to the total number of clients browsing the product, and the attractiveness of the product to the client and the satisfaction of the client's needs are reflected through the conversion rate of the client to the new product, which will not be elaborated here.

[0030] Specifically, the number of repeat purchases refers to the number of times the client repeats the purchase of the new product within the product update cycle.

[0031] Specifically, the process of analyzing the transaction attraction characterization coefficient for the client based on the behavioral characteristics combined with the total transaction amount in the product update cycle includes using the ratio of the conversion rate to the conversion rate threshold and the ratio of the number of repeat purchases to the repeat purchase threshold as the first transaction attraction feature; Using the ratio of the total transaction amount in the product update cycle to the total transaction amount threshold as the second transaction attraction feature; Weighted summing the first transaction attraction feature and the second transaction attraction feature as the transaction attraction characterization coefficient.

[0032] When performing weighted summation in this implementation, the weight of the first transaction attraction feature is set to 0.6, and the weight of the second transaction attraction feature is set to 0.4; The conversion rate threshold, the repeat purchase times threshold, and the total transaction amount threshold are preset. By calling the product update historical data of the server and several behavioral characteristics of the client, the average conversion rate, the average repeat purchase times, and the average total transaction amount are solved respectively. Since the purpose of setting the above three thresholds in this embodiment is to characterize the situation where the server has a high degree of attraction to the client and thus a high degree of transaction conversion, the conversion rate threshold is determined between 1.15 times and 1.2 times the average conversion rate, the repeat purchase times threshold is determined between 1.5 integer times and 2 integer times the average repeat purchase times, and the total transaction amount threshold is determined between 1.2 times and 1.5 times the average total transaction amount.

[0033] Specifically, the present invention analyzes the transaction attraction characterization coefficient for the client based on behavioral characteristics in combination with the total transaction amount in a predetermined time period. In actual situations, according to various behavioral characteristics such as the client's response to product updates and purchase willingness, the importance level of the client is determined, which facilitates the server to perform accurate market positioning and further reflects the value of the data generated between the server and the client. Therefore, the present invention uses the transaction attraction characterization coefficient to characterize the loyalty of the client to the server and the degree of the server's satisfaction with the client's needs, providing data support for setting the importance level label of the client in the future. On the premise of flexibly selecting the encryption method for transmitting data, the present invention improves the security and adaptability of data transmission.

[0034] Specifically, please refer to Figure 2 As shown, it is the logical decision diagram for setting the importance level label of the client in the embodiment of the present invention. Setting the importance level label of the client includes, If the transaction attraction characterization coefficient for the client is greater than or equal to the transaction attraction characterization coefficient threshold, then the client is marked with a high importance level label; If the transaction attraction characterization coefficient for the client is less than the transaction attraction characterization coefficient threshold, then the client is marked with a low importance level label.

[0035] The transaction attraction characterization coefficient threshold is selected within the interval [1.78, 1.84].

[0036] Specifically, please refer to Figure 3As shown, it is a logical decision diagram for encrypting and transmitting data generated during a transaction with a client in an embodiment of the present invention. Based on the importance level tag, data generated during a transaction with the client is encrypted and transmitted, including: if the client is marked with a high importance level tag, the generated data is parsed to identify sensitive data, the private tendency characteristics of the sensitive data are obtained, a private degree representation value is calculated based on the private tendency characteristics to adjust the length of the key, and the generated data is encrypted using a first encryption method and transmitted; If the client is marked with a low importance level tag, the generated data is encrypted using a second encryption method and transmitted.

[0037] Specifically, the process of identifying sensitive data includes pre - establishing a sensitive corpus; Matching the generated data with sensitive words in the sensitive corpus to determine the sensitive semantic similarity; If the average value of the sensitive semantic similarity corresponding to any data is greater than or equal to the sensitive semantic similarity average value threshold, the data is identified as the sensitive data.

[0038] Specifically, the generated data refers to the data for interaction between the client and the server, which will not be elaborated here.

[0039] Specifically, in this embodiment, by pre - establishing a sensitive corpus containing sensitive words related to the client, such as ID numbers, bank card numbers, etc., and matching the generated data with numerous sensitive words included in the sensitive corpus, the sensitive words and the words in the data can be converted into vector representations through a word vector model, such as Word2Vec, GloVe, etc., and then the cosine similarity between the vectors is calculated, and the cosine similarity is used as the sensitive semantic similarity; The purpose of setting the sensitive semantic similarity average value threshold is to represent the situation where the generated data is highly sensitive. By obtaining the historical records of the data generated between the client and the server several times, calling the historical records of the average value of the sensitive semantic similarity, and solving the average value of the average value of the sensitive semantic similarity, based on the purpose of setting the sensitive semantic similarity average value threshold, the sensitive semantic similarity average value threshold is determined between 0.85 times and 0.9 times the average value of the sensitive semantic similarity.

[0040] Specifically, calculating the private degree representation value based on the private tendency characteristics includes: Taking the ratio of the client - entity associated data coverage rate to the associated data coverage rate threshold as the first private degree characteristic; Taking the ratio of the remaining duration of the preservation time limit to the remaining duration threshold as the second private degree representation value; Take the sum of the first privacy level feature and the second privacy level feature as the privacy level representation value.

[0041] Specifically, the client main body associated data is data that conforms to the association standard with the sensitive words in the sensitive corpus. Match the generated data with the numerous sensitive words included in the sensitive corpus. The sensitive words and the words in the data can be converted into vector representations through a word vector model, such as Word2Vec, GloVe, etc. Then calculate the average value of the cosine similarity between the vectors, and determine the data that conforms to the association standard as the client main body associated data. Conforming to the association standard means that the average value of the cosine similarity is greater than 0.8. The storage time limit represents the validity of the generated data in the time dimension, that is, the validity period for the server to store the generated data confidentially. In this embodiment, the remaining duration of the storage time limit reflects the period during which the generated data needs to be kept confidential in the time dimension, and indirectly reflects the sensitive importance of this data, which will not be elaborated here.

[0042] In this embodiment, by obtaining the historical records of the data generated between the client and the server several times, calling the historical records of the coverage rate of the client main body associated data and the remaining duration of the storage time limit, and solving the average value of the coverage rate of the client main body associated data and the average value of the remaining duration of the storage time limit. Since the purpose of setting the threshold of the coverage rate of the client main body associated data and the average value of the remaining duration of the storage time limit is to represent the situation where the generated data has a high privacy importance, therefore, determine the threshold of the coverage rate of the client main body associated data between 1.15 times and 1.2 times the average value of the coverage rate of the client main body associated data, and determine the threshold of the remaining duration of the storage time limit between 1.2 times and 1.25 times the average value of the remaining duration of the storage time limit.

[0043] Specifically, adjusting the length of the key includes, If the privacy level representation value is greater than or equal to the privacy level representation threshold, then adjust the length of the key; If the privacy level representation value is less than the privacy level representation threshold, then there is no need to adjust the length of the key; Increase the length of the key, and the increase amount of the length is positively correlated with the privacy level representation value.

[0044] The privacy level representation threshold is selected within the interval [2.15, 2.21]; In this embodiment, optionally, Compare the privacy level representation value with a preset first privacy level representation comparison threshold and a second privacy level representation comparison threshold. When the privacy degree characterization value is greater than the second privacy degree characterization comparison threshold, the increase in length is determined to be the first increase, and it is set that the first increase is 3 times the initial length; When the privacy degree characterization value is greater than or equal to the first privacy degree characterization comparison threshold and less than or equal to the second privacy degree characterization comparison threshold, the increase in length is determined to be the second increase, and it is set that the second increase is 1 time the initial length; When the privacy degree characterization value is less than the first privacy degree characterization comparison threshold, the increase in length is determined to be the third increase, and it is set that the third increase is 0.5 times the initial length; Among them, the first privacy degree characterization comparison threshold is 1.1 times the privacy degree characterization threshold, and the second privacy degree characterization comparison threshold is 1.3 times the privacy degree characterization threshold.

[0045] In this embodiment, the initial length of the key is set to 256 bits.

[0046] Specifically, the present invention sets corresponding importance level tags for different clients. For clients set with high importance level tags, such clients may conduct long-term and frequent transaction cooperation with the server. At the same time, for the purpose of better serving such clients, the server may collect more detailed information data about the clients. Therefore, the present invention identifies sensitive data generated by both trading parties. Among them, the coverage rate of client entity associated data can reflect the closeness and privacy degree of the association between the data and the personal information of the client; the remaining duration of the preservation time limit can reflect the timeliness and sensitivity of the data within a certain period of time. For example, in the case of a long-term cooperation plan between the client and the server, the data has important value and confidentiality in the future for a long time. Therefore, the present invention calculates the privacy degree characterization value through privacy tendency features to characterize the privacy degree of the data generated between the two parties, providing data support for adjusting the length of the key. On the premise of flexibly selecting the encryption method for transmitting data, the present invention improves the security and adaptability of data transmission.

[0047] Specifically, the process of identifying the traffic abnormal fluctuation stage includes, Constructing a traffic fluctuation time-domain curve based on the traffic; If there exists a slope of the corresponding curve segment in any time domain segment that is greater than or equal to the slope threshold, then the time domain segment is identified as the traffic abnormal fluctuation stage.

[0048] In this embodiment, the traffic fluctuation time-domain curve is constructed in the following manner: Construct a rectangular coordinate system with time as the horizontal axis and traffic as the vertical axis; Mark the coordinate points of the traffic at each moment in the rectangular coordinate system; Connect each of the coordinate points with a smooth curve to obtain the time-domain curve of the flow rate fluctuation.

[0049] There is no limitation on the method of constructing the time-domain curve of the flow rate fluctuation. For example, the time-domain curve can be fitted by relevant fitting software such as matlab, which will not be elaborated here.

[0050] Specifically, in this embodiment, the purpose of setting the slope threshold is to characterize the abnormal situation of the flow rate fluctuation at the server side. By calling the historical flow rate data of the server side, the average flow rate is solved, and the flow rate threshold is set as the product of the average flow rate and the deviation coefficient, where the deviation coefficient is selected within the range of [1.12, 1.25].

[0051] Specifically, please refer to Figure 4 As shown, it is the logic decision diagram for determining whether to restrict the access of the source port and send a request for the client to re-transmit data in the embodiment of the present invention. Determining whether to restrict the access of the source port and send a request for the client to re-transmit data includes: if several data corresponding to the abnormal fluctuation stage do not meet the secure transmission benchmark conditions, it is determined to restrict the access of the source port and send a request for the client to re-transmit data; if several data corresponding to the abnormal fluctuation stage meet the secure transmission benchmark conditions, it is determined that there is no need to restrict the access of the source port; where the secure transmission benchmark conditions include that the number of the same time stamps corresponding to each of the data is greater than the time stamp same number threshold and the number of the data from the same port is greater than the same port number threshold, and the corresponding same port is determined as the source port.

[0052] In this embodiment, the purpose of setting the time stamp same number threshold and the number of data from the same port threshold is to characterize the situation where the degree of abnormality of the data source received by the server side is high. Based on the average value of the number of the same time stamps and the average value of the number of data from the same port, the time stamp same number threshold and the same port number threshold are determined correspondingly; By calling the historical data of the data received by the server side, the average value of the number of the same time stamps and the average value of the number of data from the same port are determined. Based on the purpose of setting the time stamp same number threshold and the same port number threshold, the time stamp same number threshold is set as the product of the average value of the number of the same time stamps and the first offset coefficient, and the number of data from the same port threshold is set as the product of the average value of the number of data from the same port and the second offset coefficient, where the first offset coefficient is selected within the range of [1.8, 2.4], and the second offset coefficient is selected within the range of [1.4, 1.8]; There is no specific limitation on the method of limiting access to the source port. Any existing technology that can prevent the source port from sending data can be used, for example, packet filtering technology, which usually works at the network layer and transport layer, and checks and filters the source IP address, source port and other information of the data packet according to pre-set rules. When it is detected that the source port of the data packet matches the set blocking rule, the data packet will be discarded, thereby preventing it from sending data, thereby achieving the purpose of limiting access to the source port. This will not be repeated.

[0053] Specifically, the present invention considers the traffic fluctuations presented by the data generated between the client and the server during the encrypted transmission process, so as to analyze the possibility of network attacks or other security incidents in the data transmission process, and then analyzes the same repetition of timestamps and data from ports in several data received by the server during the abnormal traffic fluctuation stage, and then accurately locates the possible attack source port. If more data with the same timestamp and coming from the same port, it may mean that the port has abnormal behavior, which may be the source of malicious attacks. The specific port is processed in a targeted manner to improve the efficiency of security protection. The present invention improves the security and adaptability of data transmission under the premise of flexibly selecting the encryption method for transmitting data.

[0054] If the data encryption transmission method based on transaction security of the present invention is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention, and the aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0055] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A data encryption transmission method based on transaction security, characterized in that: include: Obtain product update data from the server to identify the behavioral characteristics of the client; Analyzing the transaction attraction representation coefficient for the client based on the behavioral characteristics combined with the total transaction amount in the product update cycle to set an importance label for the client; Based on the importance tag, data generated when conducting transactions with the client is encrypted and transmitted, including: Parsing the generated data, identifying sensitive data, obtaining privacy tendency characteristics of the sensitive data, calculating a privacy degree representation value based on the privacy tendency characteristics to adjust the length of the key, encrypting the generated data using the first encryption method, and transmitting the data; or, encrypting the generated data using a second encryption method and transmitting the data; Monitor the traffic fluctuation data of the server in real time, identify the abnormal traffic fluctuation stage, obtain a number of data received during the abnormal traffic fluctuation stage, and determine whether to restrict the access of the source port and send a request to the client to transmit the data again based on the same number of timestamps corresponding to the data and the number of data from the same port; The privacy tendency features include the client subject associated data coverage rate and the remaining time of the storage period.

2. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: The process of identifying the behavioral characteristics of the client includes: Call the product update data of the server to determine the product update cycle and the new products corresponding to the product update cycle; call the behavioral characteristics of the client during the product update cycle, Including the client's conversion rate for the new product and the number of repeat purchases.

3. The data encryption transmission method based on transaction security according to claim 2 is characterized in that: The process of analyzing the transaction attraction representation coefficient for the client based on the behavioral characteristics combined with the total transaction amount of the product update cycle includes: The ratio of the conversion rate to the conversion rate threshold and the ratio of the number of repurchases to the repurchase number threshold are used as the first transaction attraction feature; The ratio of the total transaction amount in the product update cycle to the total transaction amount threshold is used as the second transaction attraction feature; The first transaction attraction feature and the second transaction attraction feature are weightedly summed to obtain the transaction attraction characterization coefficient.

4. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: Set the importance label of the client, include, If the transaction attraction characterization coefficient for the client is greater than or equal to the transaction attraction characterization coefficient threshold, the client is marked as a high importance label; If the transaction attraction characterization coefficient for the client is less than the transaction attraction characterization coefficient threshold, the client is marked as a low importance label.

5. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: Based on the importance tag, data generated when conducting transactions with the client is encrypted and transmitted, including: If the client is marked as a high-importance label, the generated data is parsed to identify sensitive data, obtain the privacy tendency characteristics of the sensitive data, calculate the privacy level representation value based on the privacy tendency characteristics to adjust the length of the key, and use the first encryption method to encrypt the generated data and transmit it; If the client is marked as a low importance tag, the generated data is encrypted using the second encryption method and transmitted.

6. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: The process of identifying sensitive data includes, Pre-establish sensitive corpus; Matching the generated data with sensitive words in the sensitive corpus to determine sensitive semantic similarity; If there is any data whose corresponding sensitive semantic similarity mean is greater than or equal to the sensitive semantic similarity mean threshold, the data is identified as the sensitive data.

7. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: Calculating the privacy level representation value based on the privacy tendency feature includes: The ratio of the client subject associated data coverage rate to the associated data coverage rate threshold is used as a first privacy level feature; The ratio of the remaining duration of the storage time limit to the remaining duration threshold is used as a second privacy level representation value; The sum of the first privacy level feature and the second privacy level feature is used as the privacy level representation value.

8. The data encryption transmission method based on transaction security according to claim 1 is characterized in that: Adjust the key length, including, If the privacy level representation value is greater than or equal to the privacy level representation threshold, the length of the key is adjusted; The length of the key is increased, and the increase in the length is positively correlated with the value representing the degree of privacy.

9. The data encryption transmission method based on transaction security according to claim 1, characterized in that: The process of identifying the abnormal traffic fluctuation stage includes, Construct the flow fluctuation time domain curve based on the flow; If there is any time domain segment in which the slope of the corresponding curve segment is greater than or equal to the slope threshold, the time domain segment is identified as the abnormal flow fluctuation stage.

10. The data encryption transmission method based on transaction security according to claim 1, characterized in that: Determine whether to restrict access to the source port and send a request to the client to retransmit data, including: If some data corresponding to the abnormal fluctuation stage does not meet the security transmission benchmark conditions, it is determined to restrict the access to the source port and send a request to the client to transmit the data again; Among them, the safety transmission benchmark conditions include that the number of identical timestamps corresponding to each data is greater than a threshold of identical timestamps and the number of data coming from the same port is greater than a threshold of the same port number, and the same port is determined to be the source port.

Citation Information

Patent Citations

  • Data encryption method and data transmission system

    CN108848089A