Import and export trade data exchange system
By dynamically generating encryption policy matrix in the import and export trade data exchange system, generating cross-system dynamic keys and performing quantum state superposition model mapping, the problem of encryption standards difference between multiple systems is solved, the security and compatibility of data exchange is achieved, and the reliability of data exchange is improved.
Patent Information
- Application Number
- CN202510418627.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
During the exchange of import and export trade data, security vulnerabilities and compatibility issues caused by differences in encryption standards between multiple systems, especially the risk of encryption degradation when high-strength encryption systems are transmitted to low-strength systems.
The encryption policy matrix is dynamically generated through the policy negotiation module, the key management module is used to generate cross-system dynamic keys, the protocol conversion module performs quantum state superposition model mapping, and safe transmission is carried out through the anti-degradation transmission module to ensure the security and compatibility of data during the exchange process.
It realizes the reliability of data exchange in multi-system collaborative scenarios, ensures data confidentiality and integrity, solves compatibility vulnerabilities caused by differences in encryption standards, and prevents attackers from destroying data integrity through path analysis or protocol downgrade.
Smart Images

Figure CN120263479A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of import and export trade data exchange, and particularly relates to an import and export trade data exchange system. Background Art
[0002] In the process of import and export trade data exchange, the problem of the transmission security of fund data is particularly prominent. Since fund data usually needs to be exchanged among multiple systems, including multiple links such as banks, customs, and logistics, the encryption standards and transmission protocols of each link may be different, resulting in security vulnerabilities easily occurring when data is transmitted across systems. For example, the bank system may adopt a high-strength asymmetric encryption algorithm, while the logistics system may use a relatively simple symmetric encryption. This inconsistency provides an opportunity for attackers.
[0003] In the prior art, when data flows from a high-strength encryption system to a low-strength system, a weak algorithm is forced to be adopted, resulting in the risk of encryption downgrade, causing security weaknesses and affecting the data security of the import and export trade data exchange system. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide an import and export trade data exchange system that can achieve secure data exchange among multiple systems, which can ensure the security, compatibility, and reliability of data during the exchange and transmission process.
[0005] In a first aspect, the present application provides an import and export trade data exchange system, including a policy negotiation module, a key management module, a protocol conversion module, and an anti-downgrade transmission module:
[0006] The policy negotiation module is used to dynamically generate an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems;
[0007] The key management module is used to generate a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through cryptographic operations that fuse the private key of the source system and the public key of the target system;
[0008] The protocol conversion module is used to parse the original protocol message into a field set, and map the field type to the target protocol specification through a quantum state superposition model to generate an encrypted message compatible with the target system;
[0009] The anti-downgrade transmission module is used to perform anti-downgrade secure transmission processing on the encrypted message to obtain an anti-downgrade encrypted data stream.
[0010] Further, the policy negotiation module includes:
[0011] A normalization unit for normalizing the encryption capability vectors of participating systems to obtain a standardized vector, which includes algorithm type, key length, protocol version, and computing power load;
[0012] A compatibility calculation unit for calculating the encryption compatibility between each participating system according to the following formula:
[0013]
[0014] where E ij is the encryption compatibility, K′ is the key length, max(K' i ,K' j ) is the maximum key length, T′ is the protocol version, and T max is the highest protocol version number;
[0015] A policy generation unit for solving the maximization of the total compatibility objective function through a combinatorial optimization algorithm to generate an encryption policy matrix, where the matrix elements in the encryption policy matrix are used to indicate that each participating system adopts a matching policy.
[0016] Furthermore, the key management module includes:
[0017] A key extraction unit for extracting the private key of the source system and the public key of the target system corresponding to the matching pair from the encryption policy matrix;
[0018] A cross-algorithm derivation unit for constructing a cross-algorithm key derivation tree based on the private key and the public key through the following formula to generate a session key:
[0019]
[0020] where K session is the session key, H is a cryptographic hash function, g is a generator, N i is the modulus of the source system, N j is the modulus of the target system, ski is the private key, pk j is the public key, e j is the exponential parameter of the public key, mod is the modulo operation, is the exclusive OR operator;
[0021] A fragment distribution unit for splitting the session key into multiple key fragments through a secret sharing algorithm and distributing them to the participating systems. The secret sharing algorithm is a mathematical method that requires a preset number of fragments to reconstruct the key.
[0022] Furthermore, the protocol conversion module includes:
[0023] A syntax parsing unit for parsing the original protocol message and extracting a field set, which includes protocol type, data length, and content identifier;
[0024] A quantum mapping unit, configured to map the field types in a field set into a quantum state superposition model according to the following formula through a target protocol specification, so as to obtain a mapped data set:
[0025]
[0026] Wherein, is the k-th field in the target protocol compatible format, Compat is the field compatibility function, is the quantum state representation of the j-th field in the source protocol, α j is the weight coefficient;
[0027] A message reconstruction unit, configured to generate a target protocol message based on the mapped data set and inject a session key to form an encrypted message.
[0028] Further, the anti-degradation transmission module includes:
[0029] A noise generation unit, configured to generate noise data having the same length as the encrypted message, satisfying a sparsity constraint and an entropy constraint, wherein the sparsity constraint requires that the non-zero proportion after the noise is XORed with the original data is not less than a preset threshold, and the entropy constraint requires that the information entropy of the noise data is not less than a preset security threshold;
[0030] A fragmentation transmission unit, configured to fragment the encrypted message after noise processing and perform multi-path transmission, and the multi-path transmission is to send the data fragments in parallel through different network links;
[0031] An integrity verification unit, configured to obtain verification information, and the verification information is used to characterize that the receiving end verifies the integrity of the fragments based on a hash chain, and if the continuous failure times exceed a preset threshold, a key reset is triggered.
[0032] Further, the cross-algorithm derivation unit includes:
[0033] A generator selection subunit, configured to select a generator according to the source system algorithm type, and the generator is a predefined integer in a modular exponentiation algorithm or a curve base point in an elliptic curve algorithm;
[0034] A confusion value calculation subunit, configured to calculate a cross-algorithm confusion value based on the generator and a public key, and the confusion value is an intermediate value obtained by mixing the operation results of the public and private keys through a hash function;
[0035] An iterative compression subunit, configured to perform multiple hash iterative compressions on the confusion value to generate a final session key, and the number of hash iterations is a preset anti-brute-force cracking strength parameter.
[0036] Further, the quantum mapping unit includes:
[0037] A compatibility definition subunit, which is used to define a field compatibility function. The field compatibility function is used to output a compatibility coefficient ranging from 0 to 1 according to the matching degree of field semantics and data types;
[0038] A superposition state projection subunit, which is used to perform projection measurement on a quantum state superposition model. The projection measurement is to select the field mapping result corresponding to the maximum probability amplitude;
[0039] An extended header generation subunit, which is used to generate encrypted extended header data for fields that cannot be mapped. The extended header data is encrypted by a session key and appended to the tail of the target protocol message.
[0040] In a second aspect, the present application further provides a method for exchanging import and export trade data, which is characterized in that the method includes:
[0041] Dynamically generate an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems;
[0042] Generate a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through a cryptographic operation that fuses the private key of the source system and the public key of the target system;
[0043] Parse the original protocol message into a field set, and map the field types to the target protocol specification through a quantum state superposition model to generate an encrypted message compatible with the target system;
[0044] Perform anti-degradation secure transmission processing on the encrypted message to obtain an anti-degradation encrypted data stream.
[0045] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned method for exchanging import and export trade data is implemented.
[0046] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned method for exchanging import and export trade data is implemented.
[0047] The above import and export trade data exchange system dynamically generates an encryption policy matrix for multiple systems through a policy negotiation module, solving the compatibility vulnerabilities caused by differences in encryption standards among participants such as banks, customs, and logistics; the key management module generates cross-system dynamic keys based on the encryption policy matrix to ensure the consistency of key mapping between different encryption systems; the protocol conversion module converts the original protocol message into an encrypted message compatible with the target system, achieving seamless adaptation between heterogeneous protocols; the anti-degradation transmission module performs anti-degradation secure transmission processing on the encrypted message to prevent attackers from destroying data integrity through path analysis or protocol degradation means. The above method can significantly improve the reliability of data exchange in the multi-system collaboration scenario while ensuring data confidentiality and integrity. Brief Description of the Drawings
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0049] Figure 1 It is a schematic structural diagram of an import and export trade data exchange system provided by an embodiment of the present invention;
[0050] Figure 2 It is a flowchart of an import and export trade data exchange method provided by an embodiment of the present invention. Detailed Embodiments
[0051] In order to make the purpose, technical solutions and advantages of the present application more clear, the following will further elaborate on the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0052] First, a brief introduction to the nouns involved in the embodiments of the present application will be given.
[0053] Cryptography is a technical science that studies the preparation and breaking of codes, aiming to protect the confidentiality, integrity, and authenticity of information. In modern cryptography, public-private keys are an important encryption technology. It uses a pair of keys, namely the public key and the private key. Among them, the public key can be publicly distributed and used to encrypt information, while only the corresponding private key can decrypt the information. This asymmetric encryption method ensures the security of information during transmission. Even if the public key is made public, it is difficult to derive the private key from the public key to decrypt the information. For example, in digital signatures, the sender uses their own private key to sign a message, and the receiver can use the sender's public key to verify the authenticity of the signature, thereby ensuring that the source of the message is reliable and has not been tampered with. Cryptography plays a key role in many fields such as finance, communication, and e-commerce, and is an important cornerstone for ensuring information security.
[0054] The cross-algorithm key derivation tree is a structure used for key management and derivation between different encryption algorithms. Starting from the root key, through specific algorithms and rules, it derives multiple sub-keys from the root key, and these sub-keys can be applied to different encryption algorithms or different application scenarios. Its advantage lies in being able to flexibly provide keys for multiple encryption algorithms and realizing hierarchical management of keys through a tree structure, enhancing the security and manageability of keys.
[0055] The quantum state superposition model is one of the basic principles of quantum mechanics. It shows that a quantum system can simultaneously be in a superposition state of multiple different states. This superposition property enables the quantum system to process multiple pieces of information simultaneously, bringing powerful parallel computing capabilities to quantum computing, improving the computing efficiency. At the same time, it also has important applications in fields such as quantum communication and quantum encryption, and is one of the key characteristics that distinguish quantum technology from traditional technology.
[0056] According to the above noun explanations, the implementation environment of an import and export trade data exchange system provided by an embodiment of this application is described. Exemplarily, this implementation environment includes: a data exchange terminal, a security processor, and a storage device. Among them, the data exchange terminal and the security processor are connected to the storage device through a redundant fiber optic network to form an end-to-end encrypted processing link to ensure that the data transmission is encrypted throughout the process; the data exchange terminal is integrated with a secure encryption acceleration card and / or a multi-protocol gateway device; the security processor includes, but is not limited to, a distributed processor cluster or an edge computing node equipped with an AI chip; the storage device can be a highly reliable storage device, such as a Ceph cluster or a distributed database, which is not limited here.
[0057] Combined with the above noun explanations and the implementation environment, the application scenarios of an embodiment of this application are described. An import and export trade data exchange system provided by an embodiment of this application can be applied to the following scenarios, including but not limited to:
[0058] In the transaction scenario of cross-border e-commerce platforms, the encryption capabilities and data transmission protocols of e-commerce systems in different countries or regions vary. This system can generate an encryption policy matrix according to the encryption capabilities of each participating party, generate a security key by integrating public and private keys, accurately convert protocol messages, and ensure the secure and efficient transmission of cross-border commodity transaction data between different platform systems, avoiding data leakage and transmission errors.
[0059] In the scenario of data interaction between customs and enterprises, the customs system and the import and export enterprise systems need to frequently exchange key data such as customs declaration and clearance. The system can flexibly formulate encryption policies according to the encryption parameters of both parties, achieve reliable key management, convert the complex original messages of enterprises into a format compatible with the customs system, and at the same time, the anti-degradation transmission module ensures that data can be transmitted completely and accurately even when the network is unstable, facilitating efficient customs supervision and the smooth customs clearance of enterprises.
[0060] Exemplarily, an import and export trade data exchange system provided by an embodiment of the present application can also be applied to other application scenarios. Only examples are given here, and the specific application scenarios are not limited.
[0061] In an exemplary embodiment, as Figure 1 shown, an import and export trade data exchange system 10 is provided. Taking the application of this system to the aforementioned data exchange terminal as an example, it can be understood that this system can also be realized through the interaction between the processor carried by the data exchange terminal and other processors / controllers / servers. In this embodiment, the system includes a policy negotiation module 11, a key management module 12, a protocol conversion module 13, and an anti-degradation transmission module 14:
[0062] The policy negotiation module 11 is used to dynamically generate an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems.
[0063] Specifically, an encryption policy matrix can be dynamically generated according to the encryption capability parameters of the participating systems to adapt to different combinations of systems with different encryption capabilities, and make full use of the encryption advantages of each system while ensuring security. For example, when a new participating system joins, if it has a more advanced encryption algorithm, the system can automatically adjust the encryption policy matrix to improve the overall encryption performance.
[0064] The key management module 12 is used to generate a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through a cryptographic operation that integrates the private key of the source system and the public key of the target system.
[0065] Specifically, the private key of the source system and the public key of the target system can be fused and calculated according to specific cryptographic operation rules. For example, a fusion algorithm based on the elliptic curve cryptosystem may be adopted, and through specific operations on the relevant parameters of the private key and the public key, a cross-system dynamic key is generated.
[0066] The protocol conversion module 13 is used to parse the original protocol message into a set of fields, and map the field types to the target protocol specification through the quantum state superposition model to generate an encrypted message compatible with the target system.
[0067] Specifically, using the quantum state superposition model for field type mapping can, compared with traditional mapping methods, more comprehensively consider various possible representation forms of fields under different protocol specifications, improving the accuracy of protocol conversion. At the same time, the mapping method based on quantum principles can utilize its parallel processing characteristics when dealing with complex protocol conversions, enhancing the conversion efficiency and reducing the time required for protocol conversion.
[0068] The anti-degradation transmission module 14 is used to perform anti-degradation secure transmission processing on the encrypted message to obtain an anti-degradation encrypted data stream.
[0069] Exemplarily, for possible transmission degradation risks, such as sudden reduction of network bandwidth, increased transmission delay, etc., the anti-degradation transmission module can adopt various technologies for processing. For example, when detecting a reduction in network bandwidth, it uses data compression technology to compress the encrypted message, and at the same time adjusts the parameters of the transmission protocol, such as reducing the transmission rate to ensure reliable data transmission, and finally generates an anti-degradation encrypted data stream for transmission.
[0070] The above import and export trade data exchange system dynamically generates an encryption policy matrix for multiple systems through the policy negotiation module, solving the compatibility vulnerabilities caused by differences in encryption standards among participating parties such as banks, customs, and logistics; the key management module generates cross-system dynamic keys based on the encryption policy matrix to ensure the consistency of key mapping between different encryption systems; the protocol conversion module converts the original protocol message into an encrypted message compatible with the target system, achieving seamless adaptation between heterogeneous protocols; the anti-degradation transmission module prevents attackers from destroying data integrity through path analysis or protocol degradation means by performing anti-degradation secure transmission processing on the encrypted message. The above method can significantly improve the reliability of data exchange in a multi-system collaboration scenario while ensuring data confidentiality and integrity.
[0071] Furthermore, the policy negotiation module 11 may include:
[0072] The normalization unit 111 is used to normalize the encryption capability vectors of the participating systems to obtain a normalized vector, and the normalized vector includes algorithm type, key length, protocol version, and computing power load.
[0073] Specifically, an encoding method can be adopted to convert different algorithm names into digital forms for subsequent calculations. For the key length, divide the actual key length by the maximum key length supported in the system to obtain a normalized value between 0 and 1; perform normalization on the protocol version and convert it into a proportional value relative to the predefined highest protocol version number; convert the computing power load into the proportion of the remaining available computing power, and output a normalized vector to eliminate the dimensional differences of different system parameters, enabling unified quantification and comparison of heterogeneous encryption capability parameters.
[0074] The compatibility calculation unit 112 is used to calculate the encryption compatibility between each participating system according to the following formula:
[0075]
[0076] Where, E ij is the encryption compatibility, K′ is the key length, max(K' i , K' j ) is the maximum key length, T′ is the protocol version, and T max is the highest protocol version number.
[0077] Specifically, the above method can accurately reflect the potential risks of encryption collaboration between systems by quantifying the differences in key length and protocol version, and reduce the compatibility error rate.
[0078] The policy generation unit 113 is used to solve the maximization total compatibility objective function through a combinatorial optimization algorithm to generate an encryption policy matrix, and the matrix elements in the encryption policy matrix are used to indicate that each participating system adopts a matching policy.
[0079] Specifically, using a combinatorial optimization algorithm to solve the maximization total compatibility objective function can find the optimal solution from numerous possible encryption policy combinations, and the generated encryption policy matrix maximizes the encryption compatibility of the entire system set. When the system conducts data exchange, each participating system can cooperate with the best encryption policy combination, giving full play to the encryption advantages of each system and improving the security and efficiency of data exchange.
[0080] Furthermore, the key management module 12 may include:
[0081] The key extraction unit 121 is used to extract the private key of the source system and the public key of the target system corresponding to the matching pair from the encryption policy matrix.
[0082] Specifically, by parsing the elements marked as matching pairs in the encryption policy matrix, the private key is extracted from the corresponding source system, and the public key is extracted from the target system simultaneously. The storage locations of the private key and the public key can be a local key library or an authenticated remote key management service. The keys are obtained through a secure channel (such as TLS1.3), and the key formats are standardized and converted (such as converting the hexadecimal encoding of the SM2 public key to the ASN.1 structure) to ensure the syntactic compatibility of cross-system keys.
[0083] The cross-algorithm derivation unit 122 is used to construct a cross-algorithm key derivation tree based on the private key and the public key through the following formula to generate a session key:
[0084]
[0085] where K session is the session key, H is a cryptographic hash function, g is a generator, N i is the modulus of the source system, N j is the modulus of the target system, ski is the private key, pk j is the public key, e j is the exponent parameter of the public key, mod is the modulo operation, and ⊕ is the exclusive-or operator.
[0086] Specifically, the generator selection subunit accurately selects a generator according to the source system algorithm type, making the subsequent public-private key operations and key derivation processes more in line with the security logic of the algorithm, giving full play to the advantages of different algorithms, and improving the security and effectiveness of key derivation. For example, in the scenario of import and export trade data exchange where different encryption algorithms are used in combination, the most suitable generator can be selected for each algorithm to ensure the accuracy of key derivation.
[0087] The fragment distribution unit 123 is used to split the session key into multiple key fragments through a secret sharing algorithm and distribute them to the participating systems. The secret sharing algorithm is a mathematical method that requires a preset number of fragments to reconstruct the key.
[0088] Specifically, through a distributed key fragment management and fault tolerance mechanism, the risk of single-point key leakage or loss is prevented, and the security of key storage and transmission and the system reliability are improved.
[0089] Furthermore, the protocol conversion module 13 includes:
[0090] The syntax parsing unit 131 is used to parse the original protocol message and extract a field set, and the field set includes the protocol type, data length, and content identifier.
[0091] Specifically, by receiving the original protocol messages (such as SWIFT MT7XX, EDIFACT, or custom XML format), parsing the message structure using the recursive descent algorithm, identifying and extracting the protocol type identifier, data length field, and content identifier, dynamically loading the corresponding syntax rule library according to the protocol type, and performing a deep traversal of the nested fields, a field set containing the protocol header, data payload, and checksum is generated. For unstructured data (such as free text remarks), regular expression matching and context analysis can be used to extract semantic tags as content identifiers to achieve automated parsing and standardized extraction of heterogeneous protocol messages, avoid manual parsing errors, and improve data processing efficiency and accuracy.
[0092] A quantum mapping unit 132, configured to map the field types in the field set to a quantum state superposition model according to the following formula through a target protocol specification, obtaining a mapping data set:
[0093]
[0094] Wherein, is the k-th field in the target protocol compatible format, Compat is the field compatibility function, is the quantum state representation of the j-th field in the source protocol, α j is the weight coefficient.
[0095] Specifically, by considering factors such as the quantum state representation of the field, the weight coefficient, and the field compatibility function, the source protocol field type can be more accurately mapped to the target protocol specification, enabling the system to adapt to the complex type conversion requirements between different protocols.
[0096] A message reconstruction unit 133, configured to generate a target protocol message based on the mapping data set and inject a session key to form an encrypted message.
[0097] Specifically, by accurately injecting the session key while generating the target protocol message to form an encrypted message, the integrity and security of the data are ensured. On the one hand, reconstructing the message according to the target protocol specification ensures the readability and availability of the data in the target system; on the other hand, injecting the session key realizes the encryption protection of the data, preventing the data from being stolen or tampered with during transmission, and enhancing the reliability of the system in practical applications.
[0098] Furthermore, the anti-degradation transmission module 14 may include:
[0099] A noise generation unit 141, configured to generate noise data of the same length as the encrypted message, satisfying the sparsity constraint and the entropy constraint. Among them, the sparsity constraint requires that the non-zero ratio after the noise is XORed with the original data is not lower than a preset threshold, and the entropy constraint requires that the information entropy of the noise data is not lower than a preset security threshold.
[0100] Specifically, noise data of the same length as the encrypted message is generated. During the process of generating the noise data, the sparsity constraint and entropy constraint conditions need to be satisfied: for the sparsity constraint, the noise generation unit controls the proportion of non-zero elements in the result after the generated noise data is XORed with the original encrypted data through a specific random number generation algorithm; for the entropy constraint, the noise generation unit uses an entropy calculation algorithm to ensure that the generated noise data has sufficient information entropy. In this way, noise data that satisfies both the sparsity and entropy constraints is generated, effectively resisting eavesdropping and tampering attack means.
[0101] The fragmentation transmission unit 142 is used to fragment the encrypted message after noise processing and transmit it through multiple paths. Multiple-path transmission means that the data fragments are sent in parallel through different network links.
[0102] Specifically, the multi-path parallel transmission method makes full use of the advantages of different network links and improves the transmission efficiency. Even if a certain link fails or its performance degrades, other links can still continue to transmit data, ensuring the reliability of data transmission. For example, in the data exchange of import and export trade, which involves cross-border network transmission and complex and changeable network conditions, multi-path fragmentation transmission can avoid problems such as network congestion and link interruption to a certain extent, ensuring that data can reach the receiving end in a timely and complete manner.
[0103] The integrity verification unit 143 is used to obtain verification information. The verification information is used to represent that the receiving end verifies the integrity of the fragments based on the hash chain. If the number of consecutive failure times exceeds a preset threshold, the key reset is triggered.
[0104] Specifically, based on the hash chain technology for fragment integrity verification, it can accurately determine whether the data has been tampered with during transmission. Once it is found that the number of consecutive verification failures exceeds the preset threshold, the key reset is triggered in a timely manner, avoiding the expansion of security risks caused by data tampering or transmission errors, ensuring the integrity and security of data transmission, improving the anti-degradation ability of the system in a complex network environment, and ensuring the smooth progress of import and export trade data exchange.
[0105] Furthermore, the cross-algorithm derivation unit 122 includes:
[0106] The generator selection subunit 1221 is used to select a generator according to the source system algorithm type. The generator is a predefined integer in the modular exponentiation algorithm or the curve base point in the elliptic curve algorithm.
[0107] Specifically, the generator can be selected according to the source system algorithm type: if it is a modular exponentiation algorithm, the generator is a predefined integer; if it is an elliptic curve algorithm, the generator is the elliptic curve base point coordinates. Perform modular exponentiation operation and public key operation, and perform exclusive OR confusion on the hash results of the two. Iteratively generate a cross-system session key through a hash function. The above method generates a unified session key by integrating the mathematical characteristics of different algorithms, effectively solves the key consistency problem of heterogeneous encryption standards such as RSA and SM2, can resist man-in-the-middle attacks and replay attacks, and improves the security of cross-border data exchange processes.
[0108] The confusion value calculation subunit 1222 is used to calculate the cross-algorithm confusion value based on the generator and the public key. The confusion value is an intermediate value obtained by mixing the public and private key operation results through a hash function.
[0109] Specifically, based on the output of the generator selection subunit, perform cross-algorithm confusion value calculation. For modular exponentiation algorithms, the subunit calculates the modular exponentiation result of the source system private key and performs a hash operation on the modular exponentiation result of the target system public key; for elliptic curve algorithms, the subunit calculates the scalar multiplication of the source system private key and the generator and hashes the target system public key coordinates. Mix the intermediate values of the two algorithms through exclusive OR operations to generate a cross-algorithm confusion value, which breaks the mathematical isolation between algorithms and makes it impossible for attackers to reverse-derive the key through a single algorithm feature, significantly enhancing the anti-quantum computing attack ability.
[0110] The iterative compression subunit 1223 is used to perform multiple hash iterative compressions on the confusion value to generate the final session key. The number of hash iterations is a preset anti-brute-force cracking strength parameter.
[0111] Specifically, generate the final session key through multiple hash iterative compressions, and the number of hash iterations can be adjusted according to the anti-brute-force cracking strength parameter, so that the generated session key has a high anti-brute-force cracking ability. Further, in the face of increasingly powerful computing power and brute-force cracking attack means, by increasing the number of hash iterations, it is possible to significantly increase the computing amount and time cost required for attackers to crack the key, effectively protecting the key security of import and export trade data during transmission, and ensuring the confidentiality and integrity of data exchange.
[0112] Furthermore, the quantum mapping unit 132 includes:
[0113] The compatibility definition subunit 1321 is used to define a field compatibility function. The field compatibility function is used to output a compatibility coefficient from 0 to 1 according to the field semantics and data type matching degree.
[0114] Specifically, by invoking the semantic analysis engine and the data type mapping rule library, the compatibility between the source protocol fields and the target protocol fields can be dynamically evaluated, the field semantics and data types can be deeply analyzed, and the field compatibility function can be accurately determined, providing an accurate quantitative basis for quantum mapping.
[0115] The superposition state projection subunit 1322 is used to perform projection measurement on the quantum state superposition model, and the projection measurement is to select the field mapping result corresponding to the maximum probability amplitude.
[0116] Specifically, the method of selecting the field mapping result corresponding to the maximum probability amplitude can quickly make a decision among the multiple possibilities provided by the quantum state superposition model, saving the time required for mapping. When dealing with the protocol conversion of a large number of trade data messages, the field mapping can be quickly completed, improving the data processing efficiency of the entire system and ensuring that the import and export trade data can be exchanged in a timely and efficient manner.
[0117] The extended header generation subunit 1323 is used to generate encrypted extended header data for the unmapped fields, and the extended header data is encrypted with the session key and appended to the end of the target protocol message.
[0118] Specifically, during the quantum mapping process, there may be some fields that cannot be directly mapped to the target protocol specification. Analyze these unmapped fields, extract their key information, such as field names, original data types, etc., encrypt this key information with the session key, generate encrypted extended header data and append it to the end of the target protocol message. After the target system receives the message, the same session key can be used to decrypt the extended header data to obtain the relevant information of the original field for further processing.
[0119] In summary, an import and export trade data exchange system provided by an embodiment of the present application normalizes the encryption capability parameters participating in the system, including algorithm type, key length, protocol version, and computing power load, quantifies the encryption compatibility between systems, and generates a globally optimal encryption policy matrix based on a combinatorial optimization algorithm to dynamically adapt to the encryption standard differences of different countries or institutions, ensuring the consistency of encryption policies for multi-system collaboration; extracts cross-system key pairs based on the policy matrix, generates session keys through a cross-algorithm key derivation tree that combines modular exponentiation and elliptic curve scalar multiplication, and uses a secret sharing algorithm to store the key fragments distributively, realizing seamless key collaboration between heterogeneous algorithms and anti-single-point leakage capabilities; performs syntax parsing and field extraction on the original protocol message, uses a quantum state superposition model to achieve semantic-driven dynamic field mapping, and selects the optimal conversion path through probability amplitude projection to support lossless conversion of heterogeneous protocols. For fields that cannot be mapped, encrypted extension header data is generated to ensure integrity; the statistical characteristics of the ciphertext are destroyed through noise confusion technology, combined with a multi-path fragmentation transmission and hash chain verification mechanism to resist traffic analysis, man-in-the-middle attacks, and network congestion threats, ensuring the integrity and availability of data in a complex network environment. The above technical solutions provide a full-link security foundation for cross-border trade data exchange, which can ensure the security, compatibility, and reliability of data during the exchange and transmission process.
[0120] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed sequentially according to the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.
[0121] Based on the same inventive concept, an embodiment of the present application also provides an import and export trade data exchange method for implementing the import and export trade data exchange system described above. The implementation solutions for solving problems provided by this method are similar to the implementation solutions described in the above system. Therefore, the specific limitations in one or more embodiments of the import and export trade data exchange method provided below can refer to the limitations on the import and export trade data exchange system in the above text, and will not be repeated here.
[0122] In an exemplary embodiment, as Figure 2 shown, an import and export trade data exchange method is provided, including:
[0123] Step 101: Dynamically generate an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems.
[0124] Step 102: Generate a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through a cryptographic operation that fuses the private key of the source system and the public key of the target system.
[0125] Step 103: Parse the original protocol message into a field set, and map the field types to the target protocol specification through a quantum state superposition model to generate an encrypted message compatible with the target system.
[0126] Step 104: Perform anti-degradation secure transmission processing on the encrypted message to obtain an anti-degradation encrypted data stream.
[0127] Furthermore, dynamically generating an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems includes:
[0128] Step 201: Normalize the encryption capability vectors of the participating systems to obtain a normalized vector, and the normalized vector includes algorithm type, key length, protocol version, and computing power load.
[0129] Step 202: Calculate the encryption compatibility degree between each pair of participating systems according to the following formula:
[0130]
[0131] where E ij is the encryption compatibility degree, K′ is the key length, max(K' i , K' j ) is the maximum key length, T′ is the protocol version, and T max is the highest protocol version number.
[0132] Step 203: Solve the maximum total compatibility degree objective function through a combinatorial optimization algorithm to generate an encryption policy matrix, and the matrix elements in the encryption policy matrix are used to indicate that each participating system adopts a matching strategy.
[0133] Furthermore, generating a cross-system dynamic key based on the encryption policy matrix includes:
[0134] Step 301: Extract the private key of the source system and the public key of the target system corresponding to the matching pair from the encryption policy matrix.
[0135] Step 302: Construct a cross-algorithm key derivation tree based on the private key and the public key through the following formula to generate a session key:
[0136]
[0137] where K sessionLet \(K\) be the session key, \(H\) be the cryptographic hash function, \(g\) be the generator, \(N\) i be the modulus of the source system, \(N\) j be the modulus of the target system, \(ski\) be the private key, \(pk\) j be the public key, \(e\) j be the exponent parameter of the public key, \(mod\) be the modular operation, and \(\oplus\) be the exclusive - or operator.
[0138] In step 303, the session key is split into multiple key fragments through a secret - sharing algorithm and distributed to the participating systems. The secret - sharing algorithm is a mathematical method that requires a preset number of fragments to reconstruct the key.
[0139] Furthermore, parsing the original protocol message into a set of fields and mapping the field types to the target protocol specification through a quantum - state superposition model to generate an encrypted message compatible with the target system may include:
[0140] In step 401, parse the original protocol message and extract the set of fields. The set of fields includes the protocol type, data length, and content identifier.
[0141] In step 402, according to the following formula, map the field types in the set of fields to the quantum - state superposition model through the target protocol specification to obtain the mapping data set:
[0142]
[0143] where \(F_{k}\) is the \(k\) - th field in the target - protocol - compatible format, \(Compat\) is the field - compatibility function, \(\vert\psi_{j}\rangle\) is the quantum - state representation of the \(j\) - th field in the source protocol, \(\alpha\) j is the weight coefficient.
[0144] In step 403, generate the target - protocol message based on the mapping data set and inject the session key to form the encrypted message.
[0145] Furthermore, perform anti - downgrade secure - transmission processing on the encrypted message to obtain the anti - downgrade encrypted data stream, including:
[0146] In step 501, generate noise data of the same length as the encrypted message, satisfying the sparsity constraint and the entropy constraint. Among them, the sparsity constraint requires that the non - zero proportion after the exclusive - or of the noise and the original data is not lower than the preset threshold, and the entropy constraint requires that the information entropy of the noise data is not lower than the preset security threshold.
[0147] In step 502, fragment the encrypted message after noise processing and transmit it through multi - path transmission. Multi - path transmission is to send the fragmented data in parallel through different network links.
[0148] Step 503: Obtain the verification information. The verification information is used to characterize the integrity verification of the shards by the receiving end based on the hash chain. If the number of consecutive failure times exceeds the preset threshold, the key reset is triggered.
[0149] Further, construct a cross-algorithm key derivation tree based on the private key and the public key to generate a session key, which may include:
[0150] Step 601: Select a generator according to the source system algorithm type. The generator is a predefined integer in the modular exponentiation algorithm or the curve base point in the elliptic curve algorithm.
[0151] Step 602: Calculate the cross-algorithm confusion value based on the generator and the public key. The confusion value is an intermediate value obtained by mixing the operation results of the public and private keys through a hash function.
[0152] Step 603: Perform multiple hash iteration compressions on the confusion value to generate the final session key. The number of hash iterations is a preset anti-brute-force strength parameter.
[0153] Further, map the field types in the field set to the quantum state superposition model through the target protocol specification, and the obtained mapped data set includes:
[0154] Step 701: Define a field compatibility function. The field compatibility function is used to output a compatibility coefficient from 0 to 1 according to the matching degree of the field semantics and the data type.
[0155] Step 702: Perform projection measurement on the quantum state superposition model. The projection measurement is to select the field mapping result corresponding to the maximum probability amplitude.
[0156] Step 703: Generate encrypted extension header data for the fields that cannot be mapped. The extension header data is encrypted with the session key and appended to the tail of the target protocol message.
[0157] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of an import and export trade data exchange method as described above are implemented.
[0158] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0159] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions of the method embodiments. The device embodiments described above are merely illustrative. The components described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure solution. A person of ordinary skill in the art can understand and implement it without creative efforts.
[0160] The above embodiments only represent several implementation manners of the embodiments of the present application. The descriptions are relatively specific and detailed, but should not be construed as a limitation on the patent scope of the embodiments of the application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the embodiments of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the embodiments of the present application.
Claims
1. An import and export trade data exchange system, characterized in that, The system includes a policy negotiation module, a key management module, a protocol conversion module, and an anti-degradation transmission module: The policy negotiation module is used to dynamically generate an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems; The key management module is used to generate a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through a cryptographic operation that fuses the private key of the source system and the public key of the target system; The protocol conversion module is used to parse the original protocol message into a set of fields, and map the field types to the target protocol specification through a quantum state superposition model to generate an encrypted message compatible with the target system; The anti-degradation transmission module is used to perform anti-degradation secure transmission processing on the encrypted message to obtain an anti-degradation encrypted data stream.
2. The system according to claim 1, wherein The policy negotiation module includes: A normalization unit, which is used to normalize the encryption capability vector of the participating systems to obtain a normalized vector, and the normalized vector includes algorithm type, key length, protocol version, and computing power load; A compatibility calculation unit, which is used to calculate the encryption compatibility between each of the participating systems according to the following formula: Among them, E ij is the encryption compatibility degree, K' is the key length, max(K' i , K' j ) is the maximum key length, T' is the protocol version, and T max is the highest protocol version number; A policy generation unit, which is used to solve the maximum total compatibility objective function through a combinatorial optimization algorithm to generate the encryption policy matrix, and the matrix elements in the encryption policy matrix are used to indicate that each of the participating systems adopts a matching policy.
3. The system according to claim 2, wherein The key management module includes: A key extraction unit, which is used to extract the private key of the source system and the public key of the target system corresponding to the matching pair from the encryption policy matrix; A cross-algorithm derivation unit, which is used to construct a cross-algorithm key derivation tree based on the private key and the public key through the following formula to generate a session key: where K session is the session key, H is a cryptographic hash function, g is a generator, N i is the modulus of the source system, N j is the modulus of the target system, ski is the private key, pk j is the public key, e j is the exponential parameter of the public key, mod is the modulo operation, is the exclusive OR operator; A fragment distribution unit, which is used to split the session key into multiple key fragments through a secret sharing algorithm and distribute them to the participating systems, and the secret sharing algorithm is a mathematical method that requires a preset number of fragments to reconstruct the key.
4. The system according to claim 1, wherein The protocol conversion module includes: A syntax parsing unit, which is used to parse the original protocol message and extract a set of fields, and the set of fields includes protocol type, data length, and content identifier; A quantum mapping unit, which is used to map the field types in the set of fields to a quantum state superposition model through the target protocol specification according to the following formula to obtain a mapped data set: Among them, is the k-th field of the target protocol compatible format, and Compat is the field compatibility function, is the quantum state representation of the j-th field of the source protocol, and α j is the weight coefficient; A message reconstruction unit, which is used to generate a target protocol message based on the mapped data set and inject the session key to form an encrypted message.
5. The system according to claim 1, characterized in that The anti-degradation transmission module includes: A noise generation unit, which is used to generate noise data of the same length as the encrypted message, satisfying the sparsity constraint and the entropy constraint. Among them, the sparsity constraint requires that the non-zero ratio after the noise is XORed with the original data is not less than a preset threshold, and the entropy constraint requires that the information entropy of the noise data is not less than a preset security threshold; A sharding transmission unit, which is used to shard the encrypted message after noise processing and transmit it through multi-path transmission, and the multi-path transmission is to parallelly send the data shards through different network links; An integrity verification unit, configured to obtain verification information, where the verification information is used to characterize the integrity verification of shards by the receiving end based on a hash chain, and trigger key reset if the continuous failure count exceeds a preset threshold.
6. The system according to claim 3, characterized in that, The cross-algorithm derivation unit includes: A generator selection sub-unit, configured to select the generator according to the source system algorithm type, where the generator is a predefined integer in a modular exponentiation algorithm or a curve base point in an elliptic curve algorithm; A confusion value calculation sub-unit, configured to calculate a cross-algorithm confusion value based on the generator and the public key, where the confusion value is an intermediate value obtained by mixing the public and private key operation results through a hash function; An iterative compression sub-unit, configured to perform multiple hash iterative compressions on the confusion value to generate a final session key, where the number of hash iterations is a preset anti-brute-force strength parameter.
7. The system according to claim 4, wherein The quantum mapping unit includes: A compatibility definition sub-unit, configured to define the field compatibility function, where the field compatibility function outputs a compatibility coefficient from 0 to 1 according to the field semantics and data type matching degree; A superposition state projection sub-unit, configured to perform projection measurement on the quantum state superposition model, where the projection measurement is to select the field mapping result corresponding to the maximum probability amplitude; An extended header generation sub-unit, configured to generate encrypted extended header data for fields that cannot be mapped, and the extended header data is encrypted with the session key and appended to the tail of the target protocol message.
8. A method for exchanging import and export trade data, characterized in that, The method includes: Dynamically generating an encryption policy matrix for multiple systems according to the encryption capability parameters of the participating systems; Generating a cross-system dynamic key based on the encryption policy matrix; the cross-system dynamic key is generated through a cryptographic operation that fuses the source system private key and the target system public key; Parsing the original protocol message into a field set, and mapping the field types to the target protocol specification through a quantum state superposition model to generate an encrypted message compatible with the target system; Performing anti-degradation secure transmission processing on the encrypted message to obtain an anti-degradation encrypted data stream.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the method described in claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method described in claim 8.
Citation Information
Cited By
Message validity detection method, client, server and storage medium
CN121056183A
Communication method based on anti-quantum key encapsulation algorithm
CN121727721A
A communication method based on an anti-quantum key encapsulation algorithm
CN121727721B