Computer data security encryption protection system based on computer network
By dynamically adjusting the AES encryption key in the computer data security encryption protection system, combining factors such as plaintext data size and key generation time, the problems of encryption strength adjustment and resource allocation in the existing technology are solved, and efficient data encryption protection is achieved.
Patent Information
- Application Number
- CN202510456301.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-04-11
AI Technical Summary
Existing computer data encryption protection systems are difficult to adjust encryption strength based on factors such as encrypted data size and encryption time, and it is difficult to optimize the allocation of encrypted resources when resources are limited.
The AES encryption key KAES is generated through the AES encryption key algorithm unit, and combined with the plaintext data size Pds, key generation time Tgen and other factors, the AES encryption key is dynamically adjusted, and multiple sets of algorithm units are used to form a core architecture to generate dynamically changing session key Knew to adapt to the encryption needs of different data volumes and times.
It improves the complexity and randomness of encryption keys, effectively resists replay attacks and brute-force cracking, optimizes resource allocation, adapts to diverse application scenarios, and ensures the reliability and efficiency of data encryption.
Smart Images

Figure CN120281539A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and specifically to a computer data security encryption protection system based on a computer network. Background Art
[0002] A computer network is also called a computer communication network. The simplest definition of a computer network is: a collection of interconnected, autonomous computers for the purpose of sharing resources. In existing computer networks, the data encryption security is relatively low, and encryption protection of computer data is required.
[0003] Chinese Patent CN202210599195.0 discloses a computer security protection system. When data anomalies are detected in this security protection system, it will automatically determine the anomaly situation and perform intelligent processing according to the anomaly situation. It can automatically turn off the data transmission function and the computer locking function. When data anomalies occur, it will intelligently determine the data anomaly situation and perform intelligent processing according to the actual situation. And a computer network big data security protection method and system disclosed in Chinese Patent CN202311533630.0 obtains the node encryption key through complex and unique connection parameters of device nodes. At the same time, the node encryption key will be updated over time, and its complexity and dynamic characteristics further increase the cracking difficulty and the security of distributed storage.
[0004] The existing encryption protection of computer data is relatively simple, and it is difficult to adjust the encryption strength of data according to factors such as the size of encrypted data and the encryption time. And when there is a large amount of data to be encrypted, it is difficult to evaluate subsequent encryption strategies and optimize the allocation of encryption resources according to the current encryption state of the data under limited encryption resources.
[0005] Therefore, there is an urgent need for a computer data security encryption protection system based on a computer network to solve the above problems. Summary of the Invention
[0006] The purpose of the present invention is to provide a computer data security encryption protection system based on a computer network to solve the problems raised in the above background art.
[0007] To achieve the above purpose, the present invention provides the following technical solution: A computer data security encryption protection system based on a computer network, comprising:
[0008] A data collection module, used to monitor and obtain encrypted data information through the operating system built in the computer;
[0009] A calculation processing module, and the specific calculation processing steps are as follows:
[0010] S1, calculate and generate an AES encryption key K through the AES encryption key algorithm unitAES ;
[0011] S2. Input the AES encryption key K AES into the AES-GCM encryption algorithm, combine it with the initialization vector IV to encrypt the plaintext, and output the ciphertext;
[0012] S3. Obtain the plaintext data size Pds and the ciphertext data size Cds through the file management interface of the operating system, input them together into the encryption performance compensation value algorithm unit, combine with the encryption time Tenc to calculate the encryption performance compensation value Se, and upload it to the database of the computer data security encryption protection system;
[0013] S4. Set the adjustment threshold Y of the encryption performance compensation value Se in the database of the computer data security encryption protection system, compare the encryption performance compensation value Se with the adjustment threshold Y, and perform dynamic adjustment of the parameter values in the AES encryption key algorithm unit.
[0014] Optionally, the obtaining of the encrypted data information specifically includes:
[0015] Record the timestamp during the key generation process through the operating system built in the computer and obtain the key generation time Tgen;
[0016] Record the timestamp during the encryption process of the AES-GCM encryption algorithm through the operating system built in the computer and obtain the encryption time Tenc.
[0017] Optionally, the dynamic adjustment of the parameter values in the AES encryption key algorithm unit specifically includes:
[0018] When the encryption performance compensation value Se ≥ the adjustment threshold Y, trigger the key adjustment mechanism, input the AES encryption key KAES and the encryption performance compensation value Se into the session key adjustment value algorithm unit, and calculate the new session key Knew;
[0019] Input the new session key Knew back into the AES encryption key algorithm unit for secondary calculation and re-encrypt the data.
[0020] Optionally, the calculation processing module includes an AES encryption key algorithm unit, an encryption performance compensation value algorithm unit, a session key adjustment value algorithm unit, and an AES-GCM encryption algorithm.
[0021] Optionally, the calculation logic of the AES encryption key algorithm unit is as follows:
[0022] S11. Map the plaintext data size Pds to the logarithmic space, compress the numerical influence of the plaintext data size Pds, and make the change of the data size have a smoother influence on the key generation;
[0023] S12. Divide the key generation time Tgen by 1000 and then take the natural exponent. By the characteristics of the exponential function, small time differences can be amplified, causing large fluctuations in amplitude due to small time changes, ensuring that the AES encryption key K is generated within a short time. AES Differently, it prevents replay attacks and makes it difficult for attackers to predict the key by measuring time differences.
[0024] S13. Combine the logarithmic influence term of the plaintext data size Pds and the exponential influence term of the key generation time Tgen with the random number -R1 to generate a dynamically changing intermediate value, ensuring that the key is strongly correlated with the size and time of the plaintext encrypted each time, enhancing uniqueness.
[0025] S14. Through the XOR operation, mix the TLS session key K TLS with the intermediate value, ensuring that the key is both session - based secure and related to the current encryption operation, enhancing the randomness of the key.
[0026] S15. Through the hash operation, map the mixed value to an AES key of a fixed length to obtain the AES encryption key K AES .
[0027] Optionally, the calculation logic of the encryption performance compensation value algorithm unit is as follows:
[0028] S31. Reflect the efficiency of the encryption algorithm in processing data through the ratio of the encryption time Tenc to the plaintext data size Pds.
[0029] S32. Reflect the degree of data expansion of the encryption algorithm through the ratio of the ciphertext data size Cds to the plaintext data size Pds, and perform logarithmic transformation after adding 1 to this ratio, making the influence of this part of the ratio on the encryption performance compensation value Se smoother.
[0030] S33. Map the influence term of the encryption time Tenc on the encryption performance compensation value Se to the numerical range of 0 - 1 through a variant form of the Sigmoid function.
[0031] Optionally, the calculation logic of the session key adjustment value algorithm unit is as follows:
[0032] S41. Normalize the influence of the encryption performance compensation value Se on the new session key Knew according to the maximum and minimum values of the encryption performance compensation values calculated during previous encryptions recorded in the database.
[0033] S42. Calculate the new session key Knew based on the AES encryption key K AES combined with the normalized influence value.
[0034] Optionally, set the adjustment threshold Y of the encryption performance compensation value Se in the database of the computer data security encryption protection system to 0.1.
[0035] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0036] First, through the mutual cooperation of multiple algorithm units, the present invention constitutes the core architecture of the computer data security encryption protection system based on the computer network. By comprehensively considering influencing factors such as the size of the plaintext data Pds and the key generation time Tgen, the AES encryption key K is calculated and generated in the AES encryption key algorithm unit AES , which greatly improves the complexity and randomness of the data encryption key. By integrating the time factor into the key generation and calculation, the key for each encryption operation is different, effectively resisting replay attacks. Even if the attacker intercepts the ciphertext, they cannot reuse the same key to decrypt, thus avoiding the brute force cracking or dictionary attack of the static key. This mechanism of dynamically generating encryption keys enables the computer data security encryption protection system to effectively resist brute force cracking and replay attacks and adapt to diverse application scenarios.
[0037] Second, when the encryption performance compensation value Se ≥ the adjustment threshold Y, the present invention dynamically adjusts the key through the session key adjustment value algorithm unit, which can ensure the reliability of data encryption. Moreover, this way of dynamically adjusting the key can reasonably allocate system resources according to the changes in the encryption performance of multiple data. When the encryption performance of the data is good, a smaller key adjustment range can reduce the waste of system resources, while when the encryption performance decreases, a larger key adjustment range will prompt the system to re-evaluate the encryption strategy, enabling the computer data security encryption protection system to evaluate subsequent encryption strategies according to the current encryption performance of different data under limited encryption resources, so as to save computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a schematic diagram of the overall structure of the computer data security encryption protection system based on the computer network. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0040] Embodiment 1. Please refer to Figure 1 , the present invention provides a computer data security encryption protection system based on the computer network, including:
[0041] A data collection module, used to monitor and obtain encrypted data information through the operating system built into the computer, specifically including:
[0042] Record the timestamp during the key generation process through the operating system built into the computer and obtain the key generation time Tgen;
[0043] Record the timestamp during the encryption process using the AES-GCM encryption algorithm through the operating system built into the computer and obtain the encryption time Tenc;
[0044] A calculation processing module, and the specific calculation processing steps are as follows:
[0045] S1, calculate and generate the AES encryption key K through the AES encryption key algorithm unit AES ;
[0046] S2, input the AES encryption key K AES into the AES-GCM encryption algorithm to encrypt the plaintext in combination with the initialization vector IV, and output the ciphertext;
[0047] S3, obtain the plaintext data size Pds and the ciphertext data size Cds through the file management interface of the operating system, input them together into the encryption performance compensation value algorithm unit, calculate the encryption performance compensation value Se in combination with the encryption time Tenc, and upload it to the database of the computer data security encryption protection system;
[0048] S4, set the adjustment threshold Y of the encryption performance compensation value Se in the database of the computer data security encryption protection system, compare the encryption performance compensation value Se with the adjustment threshold Y, and perform dynamic adjustment of the parameter values in the AES encryption key algorithm unit, specifically including:
[0049] When the encryption performance compensation value Se ≥ the adjustment threshold Y, trigger the key adjustment mechanism, input the AES encryption key KAES and the encryption performance compensation value Se into the session key adjustment value algorithm unit, and calculate the new session key Knew;
[0050] Input the new session key Knew back into the AES encryption key algorithm unit for secondary calculation and re-encrypt the data.
[0051] In this embodiment:
[0052] Through the mutual cooperation of multiple algorithm units in the calculation processing module, the present invention jointly constitutes the core architecture of the computer data security encryption protection system based on the computer network. By comprehensively considering influencing factors such as the plaintext data size Pds and the key generation time Tgen, calculate and generate the AES encryption key K in the AES encryption key algorithm unit AES , so that the encryption key KAES The complexity and randomness are significantly improved. By incorporating the time factor into key generation and calculation, the key for each encryption operation is different, which can effectively resist replay attacks. Even if the attacker intercepts the ciphertext, they cannot reuse the same key to decrypt it, thus avoiding brute-force cracking or dictionary attacks on static keys. This mechanism for dynamically generating encryption keys can effectively resist brute-force cracking and replay attacks, optimize the key generation efficiency, and adapt to diverse application scenarios.
[0053] When the encryption performance compensation value Se ≥ the adjustment threshold Y, the key is dynamically adjusted by the session key adjustment value algorithm unit, which can ensure the reliability of data encryption. For example, after the system runs for a long time, there may be slight fluctuations in encryption performance. If the key is not adjusted in a timely manner, some potential security risks may gradually accumulate. However, the dynamic adjustment method of the session key adjustment value algorithm unit can avoid this situation and make the system more reliable in the face of various complex security environments.
[0054] Moreover, this way of dynamically adjusting the key can reasonably allocate system resources according to changes in encryption performance. When the encryption performance is good, a smaller key adjustment range can reduce waste of system resources; when the encryption performance decreases, a larger key adjustment range will prompt the system to re-evaluate the encryption strategy, optimize subsequent encryption resource allocation, improve overall security and efficiency, and be able to evaluate subsequent encryption strategies according to the current encryption performance of different data under limited resources, saving computing resources.
[0055] Please refer to Figure 1 , the AES encryption key algorithm unit is as follows:
[0056]
[0057] Where:
[0058] K AES represents the AES encryption key;
[0059] K TLS represents the TLS session key, which is a 16-byte random string randomly generated by the operating system-level random number generator built into the computer;
[0060] R1 represents a random number randomly generated by the random number generator built into the computer;
[0061] Pds represents the plaintext data size, obtained through the file management interface of the operating system, with the unit of bytes;
[0062] Tgen represents the key generation time, which is recorded and obtained by the operating system built into the computer during the key generation process;
[0063] This part of log2(Pds + 1) maps the size of the plaintext data Pds to the logarithmic space, compresses the numerical impact of the size of the plaintext data Pds, and makes the impact of the change in data size on key generation smoother. Specifically:
[0064] When the data size increases from 100 bytes to 1000 bytes, directly using the data size as a parameter will cause a relatively large change in the key. After logarithmic transformation, this change will be relatively small, avoiding drastic fluctuations in the key due to small changes in data size.
[0065] This part takes the natural exponent after dividing the key generation time Tgen by 1000. The exponential function has a growth property. As the key generation time Tgen increases, this part of the value increases. Through the characteristics of the exponential function, small time differences can be amplified, resulting in relatively large fluctuations in amplitude caused by small time changes, so as to ensure that the AES encryption key K generated in a short time AES is different, preventing replay attacks and making it difficult for attackers to predict the key by measuring time differences.
[0066] This part combines the logarithmic influence term of the plaintext data size Pds and the exponential influence term of the key generation time Tgen with the random number R1 to generate a dynamically changing intermediate value, so as to ensure that the key is strongly correlated with the context (plaintext size, time) of each encryption, enhancing uniqueness.
[0067] This part mixes the TLS session key K TLS with the intermediate value through exclusive - OR operation, ensuring that the key is both session - based secure and related to the current encryption operation. Through the simple and efficient exclusive - OR operation, the randomness of the key is enhanced.
[0068] Finally, through the hash operation, the mixed value is mapped to an AES key of a fixed length to obtain the AES encryption key K AES ;
[0069] In this embodiment, the AES encryption key algorithm unit calculates and generates the AES encryption key K by comprehensively considering factors such as the plaintext data size Pds and the key generation time Tgen AES , AES making the complexity and randomness of the encryption key K significantly improved. Specifically, the time factor is incorporated into key generation, and the keys for each encryption operation are different, which can effectively resist replay attacks. Even if the attacker intercepts the ciphertext, the same key cannot be reused for decryption, thus avoiding brute - force cracking or dictionary attacks on static keys.
[0070] Moreover, by generating the encryption key considering the plaintext size and generation time, the computational complexity of the key generation algorithm can be optimized. For example, a lightweight KDF is used for small amounts of data, and parallel key expansion is used for large amounts of data to balance the security and system performance of the computer data security encryption protection system. Generally speaking, this mechanism for dynamically generating encryption keys can effectively resist threats such as brute-force cracking and replay attacks, while being able to optimize the key generation efficiency and adapt to diverse application scenarios.
[0071] Please refer to Figure 1 , the encryption performance compensation value algorithm unit is as follows:
[0072]
[0073] Where:
[0074] Se represents the encryption performance compensation value;
[0075] Cds represents the ciphertext data size, which is obtained through the file management interface of the operating system, and the unit is bytes;
[0076] Pds represents the plaintext data size, and the unit is bytes;
[0077] Tenc represents the encryption time, and the computer's built-in operating system records the timestamp and obtains it during the encryption process using the AES-GCM encryption algorithm;
[0078] Tavg represents the average encryption time;
[0079] Tstd represents the standard deviation, which is the standard deviation of the historical encryption time of the data in the computer;
[0080] Regarding the calculation formulas for the average encryption time Tavg and the standard deviation Tstd:
[0081]
[0082] n represents the number of encryptions;
[0083] Tenci represents the encryption time of the i-th time;
[0084] This part divides the encryption time Tenc by the plaintext data size Pds, representing the encryption time corresponding to processing a unit of plaintext data size, reflecting the efficiency of the encryption algorithm in processing data, and is the basic calculation item of the encryption performance compensation value Se. When the plaintext data size Pds remains unchanged, as this ratio decreases, it indicates that the encryption algorithm spends less time processing the same size of plaintext data, has a higher encryption efficiency, and the calculated encryption performance compensation value Se decreases;
[0085] This part divides the size of the ciphertext data by the size of the plaintext data, representing the ratio of the size of the ciphertext data to the size of the plaintext data, which reflects the degree of data expansion of the encryption algorithm. This part This part performs a logarithmic transformation after adding 1 to the ratio, making the influence of this part of the ratio on the encryption performance compensation value Se smoother. Specifically:
[0086] When the size of the ciphertext data Cds increases relative to the size of the plaintext data Pds, this part The value will increase, indicating that there is an efficiency problem in the data storage aspect of the encryption algorithm, and the calculated encryption performance compensation value Se increases;
[0087] The denominator in this part of the fraction is a deformation of the Sigmoid function, which is an adjustment term based on the difference between the encryption time Tenc and the average encryption time Tavg, It is the standardized difference between the encryption time and the average encryption time, It is an exponential transformation of this standardized difference, and then through It is mapped to the interval (0, 1), and finally adding a constant 1 makes the result in the interval (1, 2). Specifically:
[0088] When the encryption time Tenc is close to the average encryption time Tavg, this value is close to 1 and has little influence on the encryption performance compensation value Se. When the encryption time Tenc is much greater than the average encryption time Tavg, this value is close to 2, and the calculated value of the encryption performance compensation value Se increases, indicating that the current encryption operation takes a long time and the encryption efficiency is low;
[0089] In this embodiment:
[0090] The encryption performance compensation value algorithm unit can intuitively evaluate the degree of data expansion of the encryption algorithm through the ratio of the size of the ciphertext data Cds to the size of the plaintext data Pds. Different encryption algorithms will result in different sizes of ciphertext data. By calculating the encryption performance compensation value Se, it can help the computer data security encryption protection system select a more efficient encryption algorithm in terms of storage and transmission. For example, for a system with limited storage resources, choosing an algorithm with less ciphertext expansion can save storage space. Moreover, the ratio of the size of the ciphertext data Cds to the size of the plaintext data Pds also reflects the encryption time required for unit plaintext data and can directly measure the processing speed of the encryption algorithm, which is crucial for application scenarios with high real-time requirements (such as online transactions, real-time communication, etc.), ensuring that the data can be encrypted within a reasonable time without affecting the overall performance of the system.
[0091] The stability of the encryption time is an important guarantee for the reliability of the computer data security encryption protection system. If the encryption time fluctuates greatly, it will lead to performance bottlenecks or failures in the system. The encryption performance compensation value algorithm unit incorporates the fluctuation of the encryption time into the formula calculation, enabling the system to promptly detect and handle unstable encryption performance situations and make corresponding processing measures within the computer data security encryption protection system in a timely manner, improving the reliability of the system to ensure the normal operation of the system.
[0092] Please refer to Figure 1 , the session key adjustment value algorithm unit is as follows:
[0093]
[0094] Where:
[0095] Knew represents the new session key;
[0096] K AES represents the AES encryption key;
[0097] α represents the adjustment coefficient, with a default value of 0.2;
[0098] Se represents the encryption performance compensation value;
[0099] Se max represents the maximum value of the encryption performance compensation value, which is the maximum value of the encryption performance compensation values calculated during previous encryptions recorded in the database;
[0100] Se min represents the minimum value of the encryption performance compensation value, which is the minimum value of the encryption performance compensation values calculated during previous encryptions recorded in the database;
[0101] represents the relative position of the current encryption performance compensation value Se within the range of the encryption performance compensation value, that is, from the minimum value to the maximum value. When the encryption performance compensation value Se approaches the minimum value Se of the encryption performance compensation value min at this time, this part of the ratio is smaller, this part of the value is close to 1, meaning that the new session key Knew is not much different from the original AES encryption key K AES indicating that the current encryption performance is good and there is no need to significantly adjust the key;
[0102] When the encryption performance compensation value Se approaches the maximum value Se of the encryption performance compensation value max at this time, this part of the ratio increases, and the newly calculated session key Knew relative to the original AES encryption key K AESThere are significant changes, indicating that when the encryption performance is poor, the new session key Knew is dynamically adjusted for secondary calculation and data encryption is performed again to address the existing security risks;
[0103] In this embodiment:
[0104] In practical applications, the encryption environment of the computer data security encryption protection system is complex and changeable. Various emergencies may occur, leading to a decline in encryption performance. The dynamic adjustment of parameters in the session key adjustment value algorithm unit enables the system to adapt to these changes. For example, in the case of network attacks causing encryption resources to be occupied or encryption algorithms being interfered with, timely adjustment of the key can maintain the security of the system. Specifically, by setting the adjustment threshold Y of the encryption performance compensation value Se in the database of the computer data security encryption protection system to 0.1, when the encryption performance compensation value Se ≥ the adjustment threshold Y, the key adjustment mechanism is automatically triggered. This dynamic adjustment method of parameters can monitor the encryption performance in real time. Once it is found that the encryption efficiency is low and there may be security risks, the key can be adjusted in a timely manner to avoid the continuous existence of potential security threats.
[0105] By dynamically adjusting the key, the reliability of data encryption can be ensured. Because different encryption performance conditions mean different security risks, timely adjustment of the key can reduce the impact of these risks on data security. For example, after the system runs for a long time, there may be slight fluctuations in encryption performance. If the key is not adjusted in a timely manner, some potential security hazards may gradually accumulate. The dynamic adjustment method of the session key adjustment value algorithm unit can avoid this situation, making the system more reliable in the face of various complex security environments. And by dynamically adjusting the key, system resources can be reasonably allocated according to changes in encryption performance. When the encryption performance is good (the encryption performance compensation value Se is low), a smaller key adjustment range can reduce waste of system resources; when the encryption performance declines (the encryption performance compensation value Se is high), a larger key adjustment range can prompt the system to re-evaluate the encryption strategy, optimize resource allocation, and improve overall security and efficiency. In the case of limited resources, dynamically adjusting the key according to encryption performance can avoid unnecessary key update operations and save computing resources.
[0106] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A computer data security encryption and protection system based on a computer network, characterized in that, Including: A data collection module, configured to monitor and obtain encrypted data information through an operating system built in the computer; A calculation and processing module, and the specific calculation and processing steps are as follows: S1, Calculate and generate the AES encryption key K through the AES encryption key algorithm unit AES ; S2, input the AES encryption key K AES into the AES-GCM encryption algorithm to encrypt the plaintext in combination with the initialization vector IV, and output the ciphertext; S3. Obtain the plaintext data size Pds and the ciphertext data size Cds through the file management interface of the operating system, input them together into the encryption performance compensation value algorithm unit, calculate the encryption performance compensation value Se in combination with the encryption time Tenc, and upload it to the database of the computer data security encryption protection system; S4. Set an adjustment threshold Y for the encryption performance compensation value Se in the database of the computer data security encryption protection system, compare the encryption performance compensation value Se with the adjustment threshold Y, and perform dynamic adjustment of the parameter values in the AES encryption key algorithm unit.
2. The computer data security encryption and protection system based on a computer network according to claim 1, wherein: The obtaining of the encrypted data information specifically includes: Recording a timestamp and obtaining the key generation time Tgen during the key generation process through the operating system built in the computer; Recording a timestamp and obtaining the encryption time Tenc during the encryption process using the AES-GCM encryption algorithm through the operating system built in the computer.
3. The computer data security encryption and protection system based on a computer network according to claim 2, wherein: The dynamic adjustment of the parameter values in the AES encryption key algorithm unit specifically includes: When the encryption performance compensation value Se ≥ the adjustment threshold Y, the key adjustment mechanism is triggered, and the AES encryption key K AES and the encryption performance compensation value Se are input into the session key adjustment value algorithm unit to calculate the new session key Knew; Re-inputting the new session key Knew into the AES encryption key algorithm unit, performing secondary calculation and re-encrypting the data.
4. The computer data security encryption and protection system based on a computer network according to claim 3, characterized in that: The calculation and processing module includes an AES encryption key algorithm unit, an encryption performance compensation value algorithm unit, a session key adjustment value algorithm unit, and an AES-GCM encryption algorithm.
5. The computer data security encryption and protection system based on a computer network according to claim 4, characterized in that: The calculation logic of the AES encryption key algorithm unit is as follows: S11. Map the plaintext data size Pds to the logarithmic space, compress the numerical influence of the plaintext data size Pds, and make the influence of the data size change on key generation smoother; S12, divide the key generation time Tgen by 1000 and then take the natural exponent. The characteristics of the exponential function can amplify tiny time differences, causing large fluctuations due to small time changes, ensuring the generation of the AES encryption key K within a short time AES which is different, preventing replay attacks and making it difficult for attackers to predict the key by measuring time differences; S13. Combine the logarithmic influence term of the plaintext data size Pds and the exponential influence term of the key generation time Tgen with a random number R1 to generate a dynamically changing intermediate value, ensuring that the key is strongly correlated with the size and time of the plaintext encrypted each time, and enhancing uniqueness; S14, mix the TLS session key K with the intermediate value through exclusive OR operation to ensure that the key is both session-security-based and relevant to the current encryption operation, enhancing the randomness of the key; TLS S15, through hash operation, map the mixed value to an AES key of a fixed length to obtain the AES encryption key K AES .
6. The computer data security encryption and protection system based on a computer network according to claim 5, characterized in that: The calculation logic of the encryption performance compensation value algorithm unit is as follows: S31. Reflect the efficiency of the encryption algorithm in processing data through the ratio of the encryption time Tenc to the plaintext data size Pds; S32. Reflect the degree of data expansion of the encryption algorithm through the ratio of the ciphertext data size Cds to the plaintext data size Pds, perform logarithmic transformation processing after adding 1 to this ratio, and make the influence of this part of the ratio on the encryption performance compensation value Se smoother; S33. Map the influence term of the encryption time Tenc on the encryption performance compensation value Se to the numerical interval of 0 to 1 through a variant form of the Sigmoid function.
7. The computer data security encryption and protection system based on a computer network according to any one of claims 3-6, characterized in that: The calculation logic of the session key adjustment value algorithm unit is as follows: S41. Normalize the influence of the encryption performance compensation value Se on the new session key Knew according to the maximum and minimum values of the encryption performance compensation values calculated during previous encryptions recorded in the database; S42, according to the AES encryption key K AES Combine the normalized influence value to calculate a new session key Knew.
8. The computer data security encryption and protection system based on a computer network according to claim 1, characterized in that, Set the adjustment threshold Y of the encryption performance compensation value Se in the database of the computer data security encryption protection system to 0.1.
Citation Information
Patent Citations
Satellite network information encryption system and method
CN116896445A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Hybrid encryption method and device and storage medium
CN117353899A
Solid state disk data encryption method and solid state disk
CN117892369A
Wireless communication network data secure transmission method and system
CN119521212A