Safety measurement system for data transmission encryption
Through environmental entropy and dual random seed-driven AST mutation, dynamic randomized backup and recovery scripts, the problem of data disaster recovery solutions being vulnerable to supply chain attacks is solved, and the security measurement of data transmission and early abnormal identification is realized to ensure the integrity and security of data disaster recovery.
Patent Information
- Application Number
- CN202510436796.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-04
AI Technical Summary
Existing data disaster recovery solutions are vulnerable to attacks in the supply chain, resulting in key leakage or data being maliciously decrypted, destroying the recovery capabilities of the data disaster recovery system.
Through AST mutation driven by environmental entropy and dual random seeds, dynamic randomization backup and recovery scripts are prevented from supply chain attacks, multi-level mutation methods are used to improve script unpredictability, and a security measurement indicator monitoring system is built through digital signature generation and real-time signature comparison mechanisms.
Effectively prevent supply chain attacks, ensure the integrity of data disaster recovery, improve the script's anti-reverse engineering capabilities, early identification of abnormal status of equipment or software, and prevent unauthorized equipment from interfering with data disaster recovery processes.
Smart Images

Figure CN120263489A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data disaster recovery, and more specifically, to a security measurement system for data transmission encryption. Background Art
[0002] The security measurement of data transmission encryption refers to measures for evaluating and ensuring the confidentiality, integrity, and availability of data during the transmission process by adopting technical means such as encryption algorithms, key management, identity authentication, and integrity verification. Only by ensuring the security of data during the transmission process can the backup data remain intact in the event of a disaster, thereby providing a security foundation and effective disaster recovery support for data disaster recovery;
[0003] Currently, most data disaster recovery solutions rely on highly automated backup and recovery scripts. These scripts and their configuration files usually contain encryption keys and key parameters for data disaster recovery and are released through the software supply chain. During the data disaster recovery process, if an attacker implants malicious code or tampers with the configuration files in the supply chain, even if the main system remains secure, the automated process may execute the tampered code during the disaster recovery phase of data disaster recovery, which may lead to key leakage or malicious decryption of data in data disaster recovery, and ultimately damage the recovery ability of the entire data disaster recovery system. Summary of the Invention
[0004] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a security measurement system for data transmission encryption, which realizes the dynamic randomization of backup and recovery scripts through AST mutation driven by environmental entropy and double random seeds, thereby preventing supply chain attacks to solve the problems raised in the above background art.
[0005] To achieve the above object, the present invention provides the following technical solution: A security measurement system for data transmission encryption, comprising an authentication module, a collection module, a seed generation module, an AST construction module, a mutation module, a verification module, and a packaging module;
[0006] The authentication module verifies whether the device or software is in an unauthorized state by constructing a prefrontal feature vector;
[0007] The collection module is used to obtain the internal environmental characteristics and external environmental characteristics of the device or software when the determination result of the authentication module is in an unauthorized state, splice them into a string, calculate the hash value of the splicing result of the string through a hash function, and output an environmental entropy string;
[0008] The seed generation module generates and outputs two random seeds by using the environmental entropy string output by the collection module, and the seeds are used for subsequent randomization input;
[0009] The AST construction module is used to parse predefined backup and recovery scripts into an abstract syntax tree through a syntax parser and output a standardized AST;
[0010] The mutation module takes the standardized AST and a random seed as input variables, randomly swaps the positions of code blocks whose order does not affect semantics, and inserts empty loops or constant assignments; after reconstructing the control flow structure of the code blocks, it outputs the mutated AST;
[0011] The verification module is used to generate a unique digital signature and verification code for each mutated AST, embed them in the corresponding script, and perform security measurement index monitoring. The security measurement index monitoring is used to self-check whether the script has been tampered with;
[0012] The encapsulation module is used to convert the AST back into an executable script text for disaster recovery in data disaster tolerance.
[0013] In a preferred embodiment, the pre - feature vectors include a physical layer feature vector, an authentication layer feature vector, and a behavior pattern layer feature vector; a first vector principle is constructed based on the physical layer feature vector. The first vector principle includes: if the device temperature is greater than the system - preset temperature threshold and the device voltage is less than the system - preset voltage threshold, then it is determined that the device or software is physically abnormal;
[0014] A second vector principle is constructed based on the authentication layer feature vector. The second vector principle includes: if the number of consecutive authentication failures is greater than the system - preset failure - count threshold and the authentication response time is greater than the system - preset authentication response time threshold, then it is determined that the device or software is authentication - layer abnormal;
[0015] A third vector principle is constructed based on the behavior pattern layer feature vector. The third vector principle includes: when the user access frequency is greater than the system - preset access frequency threshold and the single - time data transmission traffic is greater than the system - preset transmission traffic threshold, then it is determined that the device or software is behavior - pattern - layer abnormal;
[0016] When any one of the physical layer, authentication layer, and behavior pattern layer of the device or software is determined to be abnormal, the corresponding device or software is defined as an unauthorized state.
[0017] In a preferred embodiment, the two random seeds in the seed generation module include seed one and seed two; seed one is the core mutation seed, which is used to drive the mutation of the syntax tree structure; seed two is the conditional - branch seed, which is used for the generation and adjustment of dynamic conditional branches; before the seed generation module outputs two random seeds, randomness verification and uniqueness verification are performed on the generated seeds. If they meet the expectations, they are output; otherwise, the acquisition module is returned to execute again.
[0018] In a preferred embodiment, the AST construction module receives a predefined backup and recovery script text as input and inputs the text to a syntax parser. The syntax parser parses the script into an abstract syntax tree (AST) according to syntax rules. Each AST node included in the AST is defined as a data structure containing variable, operator, control structure, and function call attributes;
[0019] During the parsing process of the syntax parser of the AST construction module, a random seed provided by the input seed generation module is used. The random seed is used to indicate the identifier replacement and node order rearrangement of AST nodes to obtain a preliminary mutation direction. The AST construction module outputs a standardized AST based on this. The standardized AST is expressed in a unified data structure format and includes node types, attribute fields, and a list of child nodes;
[0020] The reconstructed control flow structure in the mutation module includes rewriting the execution logic of if or else conditional statements equivalently.
[0021] In a preferred embodiment, a conditional branch embedding module is further included; the conditional branch embedding module takes the mutated AST output by the mutation module as input, integrates it in combination with the state parameters collected in real time, and calculates a threshold based on the comparison between the current load and a preset reference value; the state parameters include the current CPU utilization rate and network latency;
[0022] The conditional branch embedding module randomly selects a non-critical execution node in the mutated AST and inserts a new conditional branch node at this position. The conditional branch node includes two preset recovery paths inside, namely a standard recovery path and a backup recovery path; the branch node determines which path to execute according to the calculated threshold; an AST with conditional logic is output based on the output of the conditional branch embedding module.
[0023] In a preferred embodiment, a dual module is further included. The dual module takes the AST with conditional logic output by the conditional branch embedding module as input, checks the operation nodes of the input AST. The operation nodes include calling an encryption interface, writing to disk, and accessing backup data; and embeds a runtime decryption unit in the AST. The decryption unit derives a one-time key based on two random seeds of the seed generation module and the environmental entropy string output by the acquisition module;
[0024] The dual module sets an execution time limit for the decryption unit within the authorized recovery window and outputs an AST containing the one-time key and a temporary decryption unit.
[0025] In a preferred embodiment, it further includes an obfuscation unit. The obfuscation unit takes the AST output by the dual module as input, parses the code block input structure of the AST, extracts the code nodes containing arithmetic operations and constants, and constructs an operation unit index table. After the operation unit index table is generated, it traverses each operation unit according to the index order of the operation unit index table, and applies a non-linear transformation to convert the original numerical parameters into multi-layer nested expressions to generate a transformation mapping.
[0026] After the transformation mapping is generated, the obfuscation unit reconstructs the calculation expression according to the algebraic isomorphism rule, inserts equivalent calculation paths into the original structure to obtain a reconstructed calculation expression. After the calculation expression is reconstructed, the obfuscation unit regenerates the operation dependency graph, determines the topological sorting of the calculation units based on the operation dependency graph, and performs a topological sorting mutation operation based on the topological sorting, randomly groups the calculation units and rearranges the calculation paths.
[0027] After the calculation path rearrangement is completed, the obfuscation unit inserts redundant operation branches and constructs dynamic path selection logic to make the execution process present different calculation flows in different environments. After the redundant calculation paths are inserted, the obfuscation unit performs an overall consistency check. After the consistency check is completed, it outputs the representation of the final mutated AST.
[0028] The technical effects and advantages of the present invention:
[0029] 1. Through the AST mutation driven by environmental entropy and dual random seeds, the present system realizes the dynamic randomization of backup and recovery scripts, prevents supply chain attacks. Even if an attacker tampers with the configuration file, the dynamically generated and key protection mechanisms relied on during the recovery process relatively ensure the security of the script, thereby guaranteeing the integrity of data disaster recovery.
[0030] 2. By adopting a multi-level mutation method, including randomly swapping the order of code blocks, inserting empty loops and constant assignments, and reconstructing the control flow structure, these measures achieve diverse expressions through non-linear transformations and algebraic isomorphism rules, relatively improving the unpredictability of the script, thereby resisting static analysis and reverse engineering attacks.
[0031] 3. In the verification module, by using the digital signature generation and real-time signature comparison mechanism, a continuous self-check and security measurement index monitoring system is constructed, which is conducive to the security measurement and early warning of data transmission encryption.
[0032] 4. By fusing the preposed feature vectors of the physical, authentication, and behavior pattern layers, a multi-dimensional determination architecture is constructed to identify the abnormal state of devices or software at an early stage, thereby fundamentally preventing unauthorized devices from interfering with the data disaster recovery process. Description of the Drawings
[0033] Figure 1System execution process of the present invention Figure 1 。
[0034] Figure 2 System execution process of the present invention Figure 2 。
[0035] Figure 3 System execution process of the present invention Figure 3 。
[0036] Figure 4 Schematic diagram of the system module of the present invention. Detailed implementation manners
[0037] Next, with reference to the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0038] Referring to the attached Figures 1-4 description, a secure measurement system for data transmission encryption in an embodiment of the present invention includes an authentication module, a collection module, a seed generation module, an AST construction module, a mutation module, a verification module, and a packaging module;
[0039] The authentication module verifies whether the device or software is in an unauthorized state by constructing a pre - defined feature vector;
[0040] The collection module is used to obtain the internal environment characteristics and external environment characteristics of the device or software when the determination result of the authentication module is in an unauthorized state, splice them into a string, calculate the hash value of the splicing result of the string through a hash function, and output an environmental entropy string;
[0041] The seed generation module generates and outputs two random seeds using the environmental entropy string output by the collection module. The seeds are used for subsequent random input to make each execution unpredictable;
[0042] The AST construction module is used to parse a predefined backup and recovery script into an abstract syntax tree through a syntax parser and output a standardized AST;
[0043] The mutation module takes the standardized AST and random seeds as input variables, randomly swaps the positions of code blocks that do not affect the semantics, and inserts empty loops or constant assignments; after reconstructing the control flow structure of the code blocks, it outputs the mutated AST;
[0044] The verification module is used to generate a unique digital signature and verification code for each mutated AST, embed them into the corresponding script, and perform security measurement index monitoring. The security measurement index monitoring is used to self-check whether the script has been tampered with;
[0045] The encapsulation module is used to convert the AST back into an executable script text for disaster recovery in data disaster tolerance;
[0046] In addition, it should be noted that the internal environmental characteristics of the acquisition module include but are not limited to CPU load, memory occupancy, disk I / O rate, system running time, process list, registry status, kernel log, device temperature, voltage, current, fan speed, firmware version, BIOS information, security chip status, and system startup integrity;
[0047] The external environmental characteristics of the acquisition module include but are not limited to network latency, IP address range, Wi-Fi SSID, mobile device base station location, DNS resolution time, list of connected devices, open ports, network traffic pattern, external storage device connection status, number of external authentication requests, device GPS location, and sensor data;
[0048] In addition, the mutation module is used to improve the uniqueness and anti-reverse engineering ability of backup and recovery scripts by performing multi-level random transformation on the abstract syntax tree in the data disaster tolerance scenario;
[0049] The mutation module uses a random seed generated by environmental entropy to drive the mutation process, randomly swaps statement blocks in the code that do not affect semantics, ensuring that the order and position of each node can be different each time it is generated, thus disrupting the recognition path of traditional static analysis; in addition, empty loops and constant assignment instructions are inserted at specific nodes. The introduction of this redundant code changes the overall structure of the script but does not change its function, which can relatively confuse potential malicious attackers;
[0050] In addition, the mutation module also includes restructuring the control flow structure, achieving formal diversity by using multiple logically equivalent expressions for conditional judgments and loop logic. While ensuring the correctness of the final recovery operation of the script, it increases the difficulty for attackers to perform reverse analysis on the script; for example, swapping the positions of two independent assignment statements or randomly adding arithmetic operations that have no impact during the calculation process can all enhance the unpredictability of the script. The purpose of the solution is to reduce the success rate of supply chain attacks;
[0051] The verification module uses a digital-signature-based mechanism to generate a unique verification code for each node of the mutated abstract syntax tree to ensure integrity and anti-tampering. When the verification module executes, it will first traverse the AST and perform deterministic serialization on the node content, concatenating the variables, operators, control structures, and function calls in the node in a fixed order, and then use a secure hash algorithm combined with the input random seed to calculate the digital signature. The purpose of doing this is to ensure that even a tiny change will cause the signature to change, so that unauthorized modifications can be quickly detected;
[0052] After generating the signature, the verification module embeds it into the attribute field of the corresponding node and performs self-check before the script execution, verifying the security of the data transmission and mutation process by comparing the expected signature and the actual signature in real time; for example, when processing a function call node, if the calculated signature does not match the original signature, it is immediately determined that the node has been tampered with, thus triggering security alarms and recovery measures. This verification design provides a security proof for subsequent data disaster recovery operations and realizes continuous self-check in a dynamic environment;
[0053] The encapsulation module in the above solution is used to accurately convert the mutated and verified abstract syntax tree into an executable code text, enabling all dynamic mutations, embedded security checks, and reconstructed control flows to be correctly restored. During the execution of the encapsulation module, by traversing each node in the AST and concatenating the generated variable declarations, function calls, conditional statements, etc. in sequence according to predefined syntax rules, the output script not only retains the original data disaster recovery logic but also embeds a security self-check mechanism, which is conducive to isolating the script generation and execution processes and improving the stability of the code during disaster recovery;
[0054] In addition, in the verification module, there is a further specific description scheme: in the bit difference calculation of the verification module, for any node n in the AST, a binary bit difference indicator is defined. Let the original signature of node n be S o (n), and the signature recalculated during execution be S r (n). The signatures are both set as binary strings of a fixed length L. For each position i, i = 1, 2, …, L, define b i (n) as the bit difference indicator for the i-th bit, and S o (n) i and S r (n) i respectively represent the corresponding values of the i-th bit
[0055]
[0056] In the construction of the weighted bit difference sum in the verification module, in order to make each bit difference have different weights for the contribution to the overall security measurement index, a multi-logarithmic function is used to define the weights. Let the parameter α > 0 be the multi-logarithmic order and β > 0 be the offset constant,
[0057] Among them is a polylogarithmic function, which converges when 0 ≤ x < 1 and then calculates the weighted bit difference sum; d(n) is a quantity used to reflect the comprehensive degree of signature differences of node n.
[0058] Finally, a security measurement index η(n) is constructed based on the verification module. In η(n), let the parameter Δ > 0 be the offset constant of the Gamma function, E > 0 and K > 0 be the two parameters of the Beta function, Λ > 0 be the scaling coefficient of the complementary error function, and μ > 0 be the power adjustment parameter, then it is defined as
[0059] Regarding the above formula, it should be noted that Γ(z) represents the Gamma function, which converges when the real part z > 0; B(x,y) is the Beta function, erfc(z) is the complementary error function,
[0060] Regarding the above formula, it should be explained that n is the identifier of the node in the AST; b i (n) is the bit difference indicator of the i-th bit. If the i-th bit is different, then b i (n) = 1, otherwise it is 0; w i is the weight of the i-th bit, and the polylogarithmic function Li α is used for calculation; is the normalization factor;
[0061] Among them, Δ is the translation constant added to the Gamma function; Γ(d(n)+Δ) represents the non-linear amplification of d(n) after weighting through the Gamma function; E is the offset constant of the first parameter in the Beta function, and E is used to ensure that d(n)+E is within the domain of the Beta function; K is the second parameter of the Beta function, and K is used to balance the growth rate of the Gamma function; B(d(n)+E,K) as a whole represents the calculation of the Beta function, which is used to provide normalization correction; Λ is the constant used to scale the input of the complementary error function, which is used to control the exponential decay rate; μ is the parameter used to adjust the power change of d(n) in the complementary error function;
[0062] In the above formula, first, by comparing the bits of the original signature S o (n) and the real-time signature S r (n) of each node n, a binary bit difference sequence b i (n) is constructed to quantify the differences in each bit of the node signature;
[0063] Using the polylogarithmic function Li αAssign a dynamic weight w to each bit i , which is used to highlight the sensitivity of the latter bits or specific positions during weighted summation. The weighted sum d(n) is the sum of all bit differences multiplied by their corresponding weights; the d(n) is non-linearly amplified by the Gamma function Γ, and at the same time, the result is normalized by the Beta function to obtain the first term, that is which increases with the increase of d(n), and the index change accelerates;
[0064] Finally, the complementary error function erfc is used to perform exponential decay regulation on the power transformation result of d(n) to form the second term erfc(Λ[d(n)] μ ), so as to suppress the noise interference during extreme changes;
[0065] The final security measurement index η(n) is the product of these two terms, which can respond when a small change is detected, and at the same time ensure that the index is low when there is no change, so as to realize the self-check of the integrity and anti-tampering of the AST node.
[0066] The preposed feature vectors include the physical layer feature vector, the authentication layer feature vector, and the behavior pattern layer feature vector; based on the physical layer feature vector, the first vector principle is constructed. The first vector principle includes: if the device temperature is greater than the system preset temperature threshold and the device voltage is less than the system preset voltage threshold, then it is determined that the device or the software applied to the corresponding device is an anomaly in the physical layer;
[0067] Based on the authentication layer feature vector, the second vector principle is constructed. The second vector principle includes: if the number of consecutive authentication failures is greater than the system preset failure times threshold and the authentication response time is greater than the system preset authentication response time threshold, then it is determined that the device or the software applied to the corresponding device is an anomaly in the authentication layer;
[0068] Based on the behavior pattern layer feature vector, the third vector principle is constructed. The third vector principle includes: when the user access frequency is greater than the system preset access frequency threshold and the single data transmission traffic is greater than the system preset transmission traffic threshold, then it is determined that the device or the software applied to the corresponding device is an anomaly in the behavior pattern layer;
[0069] When any one of the physical layer, authentication layer, and behavior pattern layer of the device or software is determined to be abnormal, the corresponding device or software is defined as an unauthorized state.
[0070] The two random seeds in the seed generation module include Seed One and Seed Two; Seed One is the core mutation seed, and Seed One is used to drive the mutation of the syntax tree structure; Seed Two is the conditional branch seed, and Seed Two is used for the generation and adjustment of dynamic conditional branches; before the seed generation module outputs two random seeds, perform randomness verification and uniqueness verification on the generated seeds. If they meet the expectations, output them, otherwise return to the acquisition module to execute again;
[0071] During the execution of the seed generation module, it also includes performing multiple hashing operations and entropy enhancement operations on the environmental entropy string to make the initial calculations of Seed One and Seed Two have sufficient randomness and unpredictability. During the generation process, metadata at the time of generation can be recorded through the seed generation module. The metadata can include timestamps, hash algorithm parameters, and entropy collection sources for subsequent auditing and debugging. Immediately afterwards, a built-in perturbation mechanism in the seed generation module can be used to fine-tune the seeds, thereby further enhancing their uniqueness and randomness, such that an independent and secure random input can be generated for each execution process.
[0072] In a further description of the above embodiment, based on the seed generation module, the environmental entropy string is set as E. The environmental entropy string E is obtained by concatenating internal environmental features and external environmental features by the acquisition module and then performing a hashing process. Define an encryption hash function H(·) with an output of a predetermined length of L bits, and calculate the entropy hash E′ = H(E). E′ refers to the preliminary expansion result of the environmental entropy.
[0073] Immediately afterwards, let I(E ′ ) represent interpreting the first 8 bits of E ′ as an unsigned integer, and define the rotation parameter r; r = (I(E′) mod 17) + 1. The modulo operation ensures that the value range of r is from 1 to 17, thereby avoiding zero rotation.
[0074] Immediately afterwards, define the right circular rotation operation R(X, r) to perform a right circular rotation of r bits on any binary string X, expressed as: X = R(E′, r);
[0075] Then, through the seed generation module, set a predefined perturbation constant P, whose length is the same as that of E ′ to introduce additional entropy perturbation and finally generate two random seeds S1 and S2;
[0076] S1 = H(E ′ ∥X∥P)
[0077] S2 = H(X∥E ′ ∥P)
[0078] where ∥ represents the concatenation operation; S1 is the core mutation seed used to drive the mutation of the syntax tree structure; S2 is the conditional branch seed used for dynamic conditional branch generation. S1 and S2 are obtained by hashing the concatenation of E ′ , X, and P; in this way, the seed generation module forms a non-linear transformation through hashing, bit rotation, and concatenation operations, making S1 and S2 generated during each execution independent and relatively unpredictable.
[0079] The AST construction module receives a predefined backup and recovery script text as input and inputs this text to a syntax parser. The syntax parser parses the script into an Abstract Syntax Tree (AST) according to syntax rules. Each AST node included in the AST is defined as a data structure containing variable, operator, control structure, and function call attributes;
[0080] During the parsing process of the syntax parser of the AST construction module, a random seed provided by the input seed generation module is used. The random seed is used to indicate the identifier replacement and node order rearrangement of AST nodes to obtain a preliminary mutation direction. The AST construction module outputs a standardized AST based on this. The standardized AST is expressed in a unified data structure format and includes node types, attribute fields, and a list of child nodes, which is used to ensure that subsequent mutation processing procedures can identify and execute mutation operations for each syntax unit;
[0081] The refactored control flow structure in the mutation module includes rewriting the execution logic of if or else conditional statements to be logically equivalent.
[0082] It also includes a conditional branch embedding module; the conditional branch embedding module takes the mutated AST output by the mutation module as input and integrates it in combination with real-time collected status parameters. Based on this, a threshold is calculated after comparing the current load with a preset reference value; the status parameters include the current CPU utilization rate and network latency;
[0083] The conditional branch embedding module randomly selects a non-critical execution node in the mutated AST and inserts a new conditional branch node at this position. The conditional branch node internally includes two preset recovery paths, namely a standard recovery path and an alternate recovery path; the branch node determines which path to execute according to the calculated threshold; in addition, the standard recovery path and the alternate recovery path can be understood as a standard recovery function and an alternate recovery function. The alternate recovery function and the standard recovery function are both included in the AST, but only one path will be triggered; based on the output of the conditional branch embedding module, an AST with conditional logic is generated, so that even if the same logic is executed in different environments, the actual path is random.
[0084] It also includes a dual module. The dual module takes the AST with conditional logic output by the conditional branch embedding module as input, checks the operation nodes of the input AST. The operation nodes include calling an encryption interface, writing to disk, and accessing backup data; and embeds a runtime decryption unit in the AST. The decryption unit derives a one-time key based on two random seeds of the seed generation module and the environmental entropy string output by the collection module. The purpose of this is to ensure that the critical logic can be successfully decrypted and executed only in an authorized recovery environment;
[0085] Set the execution time limit of the decryption unit within the authorization recovery window through a dual module, and output an AST containing a one-time key and a temporary decryption unit, aiming to increase the difficulty of reverse cracking.
[0086] It further includes an obfuscation unit. The obfuscation unit takes the AST output by the dual module as input, parses the code block input structure of the AST, extracts the code nodes containing arithmetic operations and constants, and constructs an operation unit index table; after the operation unit index table is generated, traverse each operation unit according to the index order of the operation unit index table, and apply a non-linear transformation to convert the original numerical parameters into multi-layer nested expressions to generate a transformation mapping.
[0087] After the transformation mapping is generated, the obfuscation unit reconstructs the calculation expression according to the algebraic isomorphism rule, inserts equivalent calculation paths into the original structure to obtain a reconstructed calculation expression; after the calculation expression is reconstructed, the obfuscation unit regenerates the operation dependency graph, determines the topological sorting of the calculation units based on the operation dependency graph, and performs a topological sorting mutation operation based on the topological sorting, randomly groups the calculation units and rearranges the calculation paths.
[0088] After the calculation path rearrangement is completed, the obfuscation unit inserts redundant operation branches and constructs dynamic path selection logic to make the execution process present different calculation flows in different environments; after the redundant calculation paths are inserted, the obfuscation unit performs an overall consistency check, aiming to ensure that all mutated calculation units maintain mathematical equivalence in different execution environments; after the consistency check is completed, output the representation of the final mutated AST.
[0089] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A security measurement system for data transmission encryption, comprising an authentication module, a collection module, a seed generation module, an AST construction module, a mutation module, a verification module, and a packaging module; The authentication module verifies whether the device or software is in an unauthorized state by constructing a pre - feature vector; The collection module is used to obtain the internal environment characteristics and external environment characteristics of the device or software when the determination result of the authentication module is in an unauthorized state, splice them into a string, calculate the hash value of the splicing result of the string through a hash function, and output an environmental entropy string; It is characterized in that: The seed generation module generates and outputs two random seeds by using the environmental entropy string output by the collection module, and the seeds are used for subsequent random input; The AST construction module is used to parse the predefined backup and recovery script into an abstract syntax tree through a syntax parser and output a standardized AST; The mutation module takes the standardized AST and random seeds as input variables, randomly swaps the positions of code blocks whose order does not affect the semantics, and inserts empty loops or constant assignments; after reconstructing the control flow structure of the code block, it outputs the mutated AST; The verification module is used to generate a unique digital signature and verification code for each mutated AST, embed them into the corresponding script, and perform security measurement index monitoring. The security measurement index monitoring is used to self - check whether the script has been tampered with; The packaging module is used to convert the AST back into an executable script text for disaster recovery in data disaster tolerance.
2. A security measurement system for data transmission encryption according to claim 1, characterized in that: The pre - feature vector includes a physical layer feature vector, an authentication layer feature vector, and a behavior pattern layer feature vector; Based on the physical layer feature vector, a first vector principle is constructed. The first vector principle includes: if the device temperature is greater than the system - preset temperature threshold and the device voltage is less than the system - preset voltage threshold, then it is determined that the device or software is physically abnormal; Based on the authentication layer feature vector, a second vector principle is constructed. The second vector principle includes: if the number of consecutive authentication failures is greater than the system - preset failure - times threshold and the authentication response time is greater than the system - preset authentication response - time threshold, then it is determined that the device or software is authentication - layer abnormal; Based on the behavior pattern layer feature vector, a third vector principle is constructed. The third vector principle includes: when the user access frequency is greater than the system - preset access - frequency threshold and the single - time data transmission flow is greater than the system - preset transmission - flow threshold, then it is determined that the device or software is behavior - pattern - layer abnormal; When any one of the physical layer, authentication layer, and behavior pattern layer of the device or software is determined to be abnormal, the corresponding device or software is defined as being in an unauthorized state.
3. A security measurement system for data transmission encryption according to claim 2, characterized in that: The two random seeds in the seed generation module include seed one and seed two; seed one is the core mutation seed, and seed one is used to drive the mutation of the syntax tree structure; seed two is the conditional - branch seed, and seed two is used for the generation and adjustment of dynamic conditional branches; before the seed generation module outputs two random seeds, randomness verification and uniqueness verification are performed on the generated seeds. If they meet the expectations, they are output; otherwise, it returns to the collection module to execute again.
4. A secure measurement system for data transmission encryption according to claim 3, wherein: The AST construction module receives a predefined backup and recovery script text as input and inputs the text into a syntax parser. The syntax parser parses the script into an abstract syntax tree (AST) according to syntax rules. Each AST node included in the abstract syntax tree (AST) is defined as a data structure containing variable, operator, control structure, and function call attributes. During the parsing process of the syntax parser of the AST construction module, a random seed provided by the input seed generation module is used. The random seed is used to indicate the identifier replacement and node order rearrangement of AST nodes to obtain a preliminary mutation direction. The AST construction module outputs a standardized AST based on this. The standardized AST is expressed in a unified data structure format and includes node type, attribute fields, and a list of child nodes. The reconstructed control flow structure in the mutation module includes rewriting the execution logic of if or else conditional statements to be logically equivalent.
5. A secure measurement system for data transmission encryption according to claim 4, wherein: It further includes a conditional branch embedding module. The conditional branch embedding module takes the mutated AST output by the mutation module as input, integrates it with the state parameters collected in real time, and calculates a threshold based on the comparison between the current load and a preset reference value. The state parameters include the current CPU utilization rate and network latency. The conditional branch embedding module randomly selects a non-critical execution node in the mutated AST and inserts a new conditional branch node at this position. The conditional branch node internally includes two preset recovery paths, namely a standard recovery path and a backup recovery path. The branch node determines which path to execute according to the calculated threshold. An AST with conditional logic is output based on the conditional branch embedding module.
6. A secure measurement system for data transmission encryption according to claim 5, wherein: It further includes a dual module. The dual module takes the AST with conditional logic output by the conditional branch embedding module as input, and checks the operation nodes of the input AST. The operation nodes include calling an encryption interface, writing to disk, and accessing backup data. And a runtime decryption unit is embedded in the AST. The decryption unit derives a one-time key based on two random seeds of the seed generation module and the environmental entropy string output by the acquisition module. The dual module sets an execution time limit for the decryption unit within the authorized recovery window and outputs an AST containing the one-time key and the temporary decryption unit.
7. A secure measurement system for data transmission encryption according to claim 6, wherein: It further includes an obfuscation unit. The obfuscation unit takes the AST output by the dual module as input, parses the code block input structure of the AST, extracts the code nodes containing arithmetic operations and constants, and constructs an operation unit index table. After the operation unit index table is generated, each operation unit is traversed according to the index order of the operation unit index table, and a non-linear transformation is applied to convert the original numerical parameters into multi-layer nested expressions to generate a transformation mapping. After the transformation mapping is generated, the obfuscation unit reconstructs the calculation expression according to the algebraic isomorphism rule, inserts equivalent calculation paths into the original structure, and obtains the reconstructed calculation expression; after the calculation expression is reconstructed, the obfuscation unit regenerates the operation dependency graph, determines the topological sorting of the calculation units based on the operation dependency graph, and performs a topological sorting mutation operation based on the topological sorting, randomly groups the calculation units, and rearranges the calculation paths; After the calculation path rearrangement is completed, the obfuscation unit inserts redundant operation branches and constructs dynamic path selection logic, so that the execution process presents different calculation flows in different environments; after the redundant calculation paths are inserted, the obfuscation unit performs an overall consistency check; After the consistency check is completed, the representation of the final mutated AST is output.
Citation Information
Patent Citations
Method for resisting quantum computing block chain
CN114969799A
Smart card with enhanced security and implementation method thereof
CN118607019A
Payment environment information security management method for aggregate payment
CN118917848A
Privacy protection method and system based on big data security and privacy calculation
CN119128960A
KR20240083838A
Cited By
Coverage rate database merging method, electronic equipment and storage medium
CN121070889A