Network information security processing method and device based on block chain

By calculating the execution security level of the private key and the maze encryption model, combined with dynamic path decryption and data wall technology, the problems of brute force cracking and quantum computing threats in blockchain network information security processing are solved, and multiple protections for private keys and data are realized, ensuring the high security of the data access process.

CN120337256AInactive Publication Date: 2025-07-18HEFEI HUIMENG CLOUD CHAIN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510421380.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing blockchain-based network information security processing methods have shortcomings in responding to brute-force cracking, quantum computing threats, and data storage and transmission security. Traditional encryption methods lack effective protection measures in the data access process, especially when facing complex attacks.

Method used

By calculating the execution security level of private keys, using maze encryption model and data wall technology, combining dynamic path decryption and abnormal access frequency monitoring, enhance the security of data storage, and provide multiple protection through flexible adjustment of intelligent key management and encryption solutions.

Benefits of technology

It realizes high security of private keys and multiple protections during data access, can monitor and adjust encryption solutions in real time according to security needs, effectively resisting advanced attack technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337256A_ABST
    Figure CN120337256A_ABST
Patent Text Reader

Abstract

The invention discloses a network information security processing method and device based on a block chain, and relates to the technical field of network information security processing, and the device comprises a private key security analysis module, a private key management analysis module and a key management and encryption enhancement module. The problems that in the prior art, the defects in the aspects of coping with brute force cracking, quantum computing threats and data storage and transmission safety are overcome, an encryption method does not have enough protective measures in the data access process, and vulnerabilities may exist in the face of complex attacks are solved. According to the invention, through intelligent key management and flexible adjustment of an encryption scheme, the security of the private key is improved; by adopting a labyrinth encryption model, dynamic path decryption and a data wall technology, the security of data storage is enhanced, violent decryption is prevented, and potential security threats can be found and dealt with in time through abnormal access frequency monitoring, so that multiple protections are provided, and high security of data in an access process is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network information security processing, and specifically to a network information security processing method and device based on blockchain. Background Art

[0002] Existing network information security processing methods based on blockchain utilize the characteristics of decentralization, immutability, and transparency of blockchain technology to provide effective solutions for network information security; in traditional network security architectures, data storage and management are usually concentrated on a single node or server, making them vulnerable to attacks or tampering; while blockchain, through distributed ledger technology, makes the data storage and transmission processes more secure and reliable, greatly enhancing the integrity and traceability of information;

[0003] However, there are still some deficiencies. There are shortcomings in dealing with brute-force attacks, quantum computing threats, and data storage and transmission security in the existing technology; traditional encryption methods do not have sufficient protection measures during data access, especially there may be vulnerabilities in the face of complex attacks; Summary of the Invention

[0004] The purpose of the present invention is to solve the above problems and propose a network information security processing method and device based on blockchain.

[0005] The purpose of the present invention can be achieved through the following technical solutions: A network information security processing method based on blockchain, including:

[0006] Step 1: Calculate the execution security level of the private key, specifically:

[0007] S111: Calculate the time required for brute-force cracking, through the formula Calculate the time T required for brute-force cracking 暴力 , where L is the key length and P is the attacker's computing power;

[0008] S112: Calculate the quantum computing impact, the quantum computing impact factor = α × log2(N) + β; where N is the key length, and α and β are preset empirical coefficients;

[0009] S113: Calculate the execution security level, through the formula: Obtain the security level ESL; S is the security target; compare the security level ESL with the preset requirement level threshold ESL0; if ESL ≥ ESL0, then perform key management analysis; otherwise replace the encryption scheme; adopt the data brick encryption method, construct a data wall and generate a laying order as the data encryption public key and private key;

[0010] Step 2: Conduct key management analysis on the private key, specifically:

[0011] S221: Storage security, detect storage methods, including HSM, TPM, encrypted databases, software-encrypted storage, and public network storage, and generate corresponding storage security signals;

[0012] S222: Access permission management, detect permission management methods, and generate access permission instructions;

[0013] S223: Private key usage, analyze the usage environment and frequency of the private key, detect whether it is stored in HSM / TPM, encrypted databases, software storage, not rotated for a long time, or exposed to an insecure environment, and generate private key usage commands;

[0014] S224: Determine the security management level through the combination of signals, instructions, and commands, and select encryption operations according to preset requirements;

[0015] S225: Use the maze encryption model to store data, ensure security through dynamic path decryption and data walls, and trigger position replacement and device offline processing for brute-force decryption detection.

[0016] As a preferred embodiment of the present invention, the calculation process of the attacker's computing power P is as follows:

[0017] The attacker's computing power P depends on multiple factors, including hardware performance, parallel computing power, optimization algorithms, and also includes single-threaded computing power, multi-threading and multi-core computing, GPU or FPGA parallel computing, distributed computing, and the influence of optimization algorithms; Assume: The CPU clock frequency is 3 GHz, and 1000 clock cycles are required for each attempt; An 8-core CPU, with 2 threads per core; A GPU has 4000 cores, and each core supports 32 threads; Then: If the attacker controls 1000 such GPU devices: P 总 = P GPU × 1000.

[0018] As a preferred embodiment of the present invention, the specific process of using the data brick encryption method to construct a data wall and generate the stacking order as the data encryption public key and private key is as follows:

[0019] Substitute the digital sequence data into the encryption model for encryption; Split and combine the digital sequence data according to the corresponding fixed splitting rules, and each new digital sequence after splitting and combination is used as a data brick; Each data brick corresponds to a number in the encryption model; Stack several data bricks to obtain a data wall; Obtain the stacking order of the numbers corresponding to each data brick according to the stacking process of the data wall; And use the stacking order as the data encryption public key; Obtain the overall brick position of the data wall according to the positional relationship of each data brick in the data wall; Then set the stacking order according to the overall brick position relationship of the data wall; If there are several stacking orders, select one of them as the private key.

[0020] As a preferred embodiment of the present invention, the specific process of generating the corresponding storage security signal is as follows:

[0021] Detect through the PKCS#11 API and the HSM device management interface to identify whether the HSM is enabled and whether there is an effective key storage. If so, generate storage security signal one; detect whether the TPM is enabled through the TPM 2.0 API or the system BIOS / UEFI settings, and read the TPM configuration information; if the TPM is enabled, generate storage security signal two; identify the configuration of the database software; whether the encryption software for transparent data encryption or application layer encryption is enabled; if the software for transparent data encryption or application layer encryption is enabled, generate storage security signal three; identify software-level encryption through the file system or process monitoring; detect whether the encryption software is enabled; if enabled, generate storage security signal four; identify whether the storage is located on a publicly accessible server or bucket; detect whether there is an anonymous access right by scanning the storage permissions; perform a storage access right test using the cloud API, and then, based on the detection results, if there is an anonymous access right, generate storage security signal five.

[0022] As a preferred embodiment of the present invention, the body process of generating the access permission instruction is as follows:

[0023] Detect the current permission management methods, including multi-factor authentication + hardware token, MFA, password only, password only and no authentication; collect information related to the authentication method through system logs, authentication configuration files, API calls, and network traffic monitoring; classify through specific detection methods according to the characteristics of the authentication method: for the detection of multi-factor authentication + hardware token, identify whether MFA is enabled and check whether the use of a hardware token is mandatory; analyze the system security policy to confirm whether a hardware token is required.

[0024] If MFA is enabled and it is confirmed that a hardware token is required, generate access permission instruction 1; for MFA detection: identify whether MFA based on SMS, email, TOTP, or PUSH is enabled; check the authentication log for SMS / email OTP verification records; read the MFA-related configuration, such as the TOTP key storage file or SMS gateway / API configuration; then check the MFA binding situation through the identity management API. If MFA based on SMS, email, TOTP, or PUSH is enabled, there are SMS / email OTP verification records, and the MFA binding is checked through the identity management API, generate access permission instruction 2; for password-only detection: identify whether the system only requires a password for authentication; check the password policy; parse the identity authentication configuration file to see if a strong password policy is enabled; identify whether password change is forced regularly to prevent the long-term use of weak passwords; if a strong password policy is enabled and password change is forced regularly, generate access permission instruction 3; for password-only detection: identify whether the system allows users to authenticate with passwords of any strength without setting a password complexity policy; check whether plaintext password storage is enabled; parse the system authentication log to determine whether other security measures are enabled; if users are allowed to authenticate with passwords of any strength, plaintext password storage is used, and there are no other security measures, generate access permission instruction 4; for no-authentication detection: identify whether access to system resources is allowed without authentication; detect open API endpoints, databases, and file shares; identify anonymously accessible services through port scanning and access permission checks. If authentication is not required, generate access permission instruction 5.

[0025] As a preferred embodiment of the present invention, the specific process of determining the security management level through a combination of signals, instructions, and commands and selecting the encryption operation according to preset requirements is as follows:

[0026] Obtain the signals, instructions, and commands generated in steps S221, S222, and S223 for security level determination; if storage security signal 1, access permission instruction 1, and key usage command 1 are generated simultaneously, it is determined as high security management; if storage security signal 2, access permission instruction 2, and key usage command 2 are generated simultaneously, it is determined as medium security management; if storage security signal 3, access permission instruction 3, and key usage command 3 are generated simultaneously, it is determined as low security management; if storage security signal 1, access permission instruction 1, and key usage command 2 are generated simultaneously, it is determined as medium security management; and other combinations are determined as no security management; compare the security management level corresponding to the security management with the preset required management level. If the preset required management level is greater than high security management, perform security management encryption to generate an encryption signal.

[0027] As a preferred embodiment of the present invention, the specific process of using the maze encryption model to store data, ensuring security through dynamic path decryption and data walls, and triggering position replacement and device offline processing for brute-force decryption detection is as follows:

[0028] Encrypted storage is performed through the maze encryption model; specifically: the encrypted storage data is stored at a specific location within the maze encryption model, and this storage location is changed regularly to enhance security; when querying, the storage location information of the encrypted data needs to be obtained first through the entrance of the maze encryption model; subsequently, multiple possible query paths are generated based on this location data, and one of them is dynamically selected as the decryption path; during the decryption process, a data wall is set at each path node, and it can only continue to move forward after being decrypted with the corresponding private key, gradually passing through each intersection, and finally reaching the encrypted data storage point; after successfully obtaining the encrypted data, the exit position is determined in the same way, and the decryption path is gradually parsed until the encrypted storage data is completely restored, thus ensuring the secure access of the data; brute-force decryption is detected through abnormal access frequency. If there is brute-force decryption, the position is immediately replaced, and the device corresponding to the stored data is subjected to offline processing.

[0029] On the other hand, the present invention provides a network information security processing device based on blockchain, which includes: a private key security analysis module, a private key management analysis module, and a key management and encryption enhancement module;

[0030] The private key security analysis module is used to analyze the security of the private key to obtain the execution security level ESL of the private key, ensuring that ESL≥ESL0, otherwise replacing the encryption scheme;

[0031] The private key management analysis module is used to check whether the private key is stored in a secure environment such as HSM, TPM, encrypted database, etc., and whether there is a risk of plaintext storage; detect the access control measures of the private key, including whether multi-factor authentication MFA, hardware tokens, and strong password policies are enabled; check whether the private key has not been replaced for a long time, and whether it is stored or used in an insecure environment;

[0032] The key management and encryption enhancement module optimizes the key management strategy and performs encryption enhancement based on the results of private key security assessment and management analysis.

[0033] Compared with the prior art, the beneficial effects of the present invention are:

[0034] 1. By comprehensively considering various security factors such as brute-force cracking and the impact of quantum computing, the present invention can accurately evaluate the execution security level of the private key, and through intelligent key management and encryption scheme adjustment, ensure the high security of the private key. This method can monitor in real time and flexibly adjust the encryption scheme according to security requirements, providing strong data protection capabilities, especially having superior security when facing advanced attack technologies.

[0035] 2. By adopting the maze encryption model, the present invention not only enhances the security of data storage, but also guarantees multiple protections for data during the access process through dynamic path decryption and data wall technology. The maze encryption model makes the positions and paths of data change regularly, increasing the ability to prevent brute-force decryption. Combined with abnormal access frequency monitoring, it can be detected and applied in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.

[0037] Figure 1 It is a method step diagram of the present invention;

[0038] Figure 2 It is a principle block diagram of the present invention;

[0039] Figure 3 It is a schematic diagram of the encryption model of the present invention;

[0040] Figure 4 It is a schematic diagram of the maze encryption model of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0041] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0042] It should be understood that the terms "including" and "comprising" used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations.

[0043] It should also be understood that the terms used in this disclosure specification are only for the purpose of describing specific embodiments and are not intended to limit this disclosure. As used in this disclosure specification and claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms. It should be further understood that the term "and / or" used in this disclosure specification and claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0044] Please refer to Figure 1 As shown, on the one hand, the present invention provides a network information security processing method based on blockchain, including:

[0045] Step 1: Calculate the execution security level of the private key by determining the basic parameters of the private key, including the key length L, such as RSA-2048, ECC-256, etc., the encryption algorithm type A, such as RSA, ECC, AES, the hash algorithm H, such as SHA-256, SHA-3, and the security goal S: the time goal against brute-force cracking (such as 10 years, 30 years, etc.).

[0046] S111: Calculate the time required for brute-force cracking: Through the known formula: Obtain \(T_{brute}\), where L \(N\) is the number of key possibilities, and \(P\) is the computing power of the attacker (number of key attempts per second); Note: The computing power \(P\) (number of key attempts per second) of the attacker depends on multiple factors, including hardware performance, parallel computing power, optimization algorithms; it also includes single-threaded computing power, multi-threading and multi-core computing, GPU or FPGA parallel computing, distributed computing, and the impact of optimization algorithms; Example: Assume: The CPU clock frequency is 3 GHz, and each attempt requires 1000 clock cycles; an 8-core CPU, with 2 threads per core; a GPU has 4000 cores, and each core supports 32 threads; then: If the attacker controls 1000 such GPU devices: \(P\) 总 \(=\) \(P\) GPU \(\times 1000\).

[0047] S112: Calculate the impact of quantum computing; Shor's algorithm is an efficient quantum algorithm that can be used for factorization (cracking RSA) and calculating discrete logarithms (cracking ECC); it makes the computational complexity much lower than traditional algorithms, posing a serious threat to RSA and ECC;

[0048] Among them: Shor's algorithm can efficiently factor large integers, so it has the greatest impact on RSA. According to research: For RSA-1024 (\(N = 1024\)): \(Q\) RSA-1024 \(\approx 40\); For RSA-2048 (\(N = 2048\)): \(Q\) RSA-2048 \( = 44\); For RSA-4096 (\(N = 4096N\)): \(Q\) RSA-4096 \( = 48\);

[0049] Shor's algorithm is also used to crack ECC (elliptic curve cryptography). The key of ECC is much shorter than that of RSA, and its equivalent security is relatively high; for example, the security of ECC-256 is roughly equivalent to that of RSA-3072;

[0050] Then the quantum computing influence factor Q can be expressed as: Q = α × log2(N) + β; where N is the key length, and α and β are preset empirical coefficients, and different algorithms have different values, depending on the quantum resource requirements of the Shor algorithm and the search complexity of the Grover algorithm.

[0051] S113: Calculate the execution security level ESL of the execution, define the execution security level ESL of the private key, through the formula: Compare the security level ESL with the preset required level threshold ESL0; if ESL ≥ ESL0, then perform key management analysis; conversely, if ESL < ESL0, then replace the encryption scheme for re-encryption; for example: map the encrypted data to obtain digital sequence data, and substitute the digital sequence data into the encryption model (such as Figure 3 shown) for encryption; split and combine the digital sequence data according to the corresponding fixed splitting rules, and each new digital sequence after splitting and combination is used as a data brick; each data brick corresponds to a number in the encryption model; stack several data bricks to obtain a data wall; obtain the stacking order of the numbers corresponding to each data brick according to the stacking process of the data wall; and use the stacking order as the data encryption public key; obtain the overall brick position of the data wall according to the positional relationship of each data brick in the data wall; then set the stacking order according to the overall brick position relationship of the data wall; if there are several stacking orders, select one of them as the private key.

[0052] Step 2: Conduct management analysis on the private key; in reality, the formulas and models related to the risk assessment of private key management are usually based on cryptographic security assessment frameworks, risk management standards (such as NIST SP 800-57, ISO 27001), and general information security risk assessment models (such as CVSS, FAIR, OCTAVE);

[0053] Calculate through the key management life cycle model. In the SP 800-57 document, the secure life cycle of the key is defined, and key security calculation is proposed; the main considerations are: storage security, access privilege management, and private key usage.

[0054] S221: Among them, the storage security is detected by detecting the security of the storage method, by detecting the current storage support methods, including hardware security modules (HSM), trusted platform modules (TPM), encrypted databases, software encrypted storage, public storage, etc.;

[0055] Detect through the PKCS#11 API and the HSM device management interface to identify whether the HSM is enabled and whether there is a valid key store. If so, generate storage security signal one; detect whether TPM is enabled through the TPM 2.0 API or the system BIOS / UEFI settings, and read the TPM configuration information, such as key management, platform integrity protection status, etc.; if TPM is enabled, generate storage security signal two; identify the configuration of database software (such as MySQL, PostgreSQL, SQL Server); whether encryption software such as transparent data encryption (TDE) or application-layer encryption is enabled; if software such as transparent data encryption (TDE) or application-layer encryption is enabled, generate storage security signal three; identify software-level encryption (such as AES, DES, ChaCha20) through file system or process monitoring; detect whether encryption software (such as BitLocker, VeraCrypt) is enabled; if enabled, generate storage security signal four; identify whether the storage is located on a publicly accessible server or bucket (S3, OSS, Azure Blob); detect whether there is anonymous access permission by scanning the storage permissions (ACL, IAM policy); use cloud APIs (such as AWS CLI, Google Cloud Storage API) to test the storage access permissions, and then based on the detection results, if there is anonymous access permission, generate storage security signal five; collectively refer to storage security signal one, storage security signal two, storage security signal three, storage security signal four, and storage security signal five as storage security signals.

[0056] S222: Access permission management detects the permission management method; similarly, detect the current permission management method, including multi-factor authentication (MFA) + hardware token, MFA (such as SMS / email / APP authentication), password only (strong password policy), password only, and no authentication (anonymous access); collect authentication method-related information through system logs, authentication configuration files, API calls, and network traffic monitoring; classify through specific detection methods according to the characteristics of the authentication method: for multi-factor authentication (MFA) + hardware token detection, identify whether MFA is enabled and check whether the use of a hardware token (such as YubiKey, RSA SecureID) is mandatory; parse the system security policy to confirm whether a hardware token is required; for example:

[0057] cat / etc / security / mfa_config

[0058] grep "require_hardware_token" / var / log / auth.log

[0059] Call identity management APIs (such as AWS IAM, Azure AD) to query MFA settings:

[0060] aws iam list-mfa-devices --user-name example-user;

[0061] If MFA is enabled and it is confirmed that a hardware token is required, generate access permission instruction one; Detect MFA (SMS / email / APP authentication): Identify whether MFA based on SMS, email, TOTP (such as Google Authenticator), PUSH (such as Duo Security) is enabled; Check the authentication log for SMS / email OTP verification records; Read MFA-related configurations, such as the TOTP key storage file or SMS gateway / API configuration; Then check the MFA binding situation through the identity management API, for example:

[0062] gcloud auth list

[0063] az ad user list --query "[].{MFA:strongAuthenticationMethods}"

[0064] If MFA based on SMS, email, TOTP (such as Google Authenticator), PUSH (such as Duo Security) is enabled, there are SMS / email OTP verification records, and the MFA binding is checked through the identity management API, generate access permission instruction two; Detect only password (strong password policy): Identify whether the system only requires passwords for authentication; Check the password policy (such as minimum length, complexity requirements, expiration time); Parse the authentication configuration file (such as PAM, Active Directory) to see if the strong password policy is enabled:

[0065] cat / etc / security / pwquality.conf

[0066] net accounts / domain

[0067] Identify whether password replacement is forced at regular intervals to prevent the long-term use of weak passwords; if the strong password policy is enabled and password replacement is forced at regular intervals, then generate access permission instruction three; for password detection only: identify whether the system allows users to authenticate with passwords of any strength, and no password complexity policy is set; check whether plaintext password storage is enabled (an insecure practice); parse the system authentication log to determine whether other security measures are enabled (such as account lockout policy); if users are allowed to authenticate with passwords of any strength, plaintext password storage is used, and no other security measures are in place, then generate access permission instruction four; for no-authentication (anonymous access) detection: identify whether access to system resources is allowed without authentication; detect open API endpoints, databases, file shares (such as S3 Bucket, NFS share, anonymous FTP); identify services that can be anonymously accessed through port scanning and access permission checks:

[0068] url-I http: / / example.com / open-resource

[0069] nmap-p 445--script=smb-enum-shares target-ip

[0070] If access without authentication is allowed, then generate access permission instruction five; collectively refer to access permission instruction one, access permission instruction two, access permission instruction three, access permission instruction four, and access permission instruction five as access permission instructions.

[0071] S223: The usage of private keys is analyzed by obtaining the usage frequency and exposure risk of private keys, including factors: used in a secure environment (such as HSM) each time the private key is used, the private key is used in software and replaced regularly, the private key is used for a long time without regular replacement, and the private key is used multiple times in an insecure environment; among them, detect whether the private key is only used in HSM or TPM devices and not exported to the external environment; verify through the HSM API or TPM configuration: pkcs11-tool--module / usr / lib / softhsm / libsofthsm2.so--list-objects to read the HSM key management policy and confirm whether the access control of the private key is strict; if it is confirmed that the access control of the private key is strict, then generate private key usage command one; identify whether the private key is stored in an encrypted database, software storage (such as OpenSSL, SSH), and a regular rotation policy is used; detect the creation and replacement time of the private key to ensure compliance with the security policy:

[0072] openssl x509-in cert.pem-noout-dates

[0073] Query the key rotation policy through the Key Management System (KMS):

[0074] aws kms get-key-rotation-status --key-id example-key

[0075] If both meet the security policy and the key rotation policy, generate the private key usage command two; identify whether the private key has been in use for a long time (such as the creation time exceeds 1 year and has not been rotated); parse the certificate validity period and the key creation time to confirm whether it meets the rotation requirements; detect whether the private key is still using an outdated or weak encryption algorithm (such as RSA 1024):

[0076] openssl rsa -in private.pem -text -noout | grep "Private-Key" If it meets the rotation requirements, generate the private key usage command three; identify whether the private key is stored in a plaintext file, code repository, cloud storage (such as S3, GitHub); check whether the private key is leaked through a scanning tool: grep -r --include "*.pem" "-----BEGIN PRIVATE KEY-----" / path / to / code If the private key is leaked, generate a leakage command, directly execute the leakage alarm, and generate the corresponding leakage record; if it is detected that the private key is used in an insecure environment (such as a public server, unencrypted storage device); then the private key usage command four; collectively refer to the private key usage command one, the private key usage command two, the private key usage command three, and the private key usage command four as the private key usage command.

[0077] S224: Obtain the signals, instructions, and commands generated in steps S221, S222, and S223 for security level determination; if the storage security signal one, access permission instruction one, and key usage command one are generated simultaneously, it is determined as high security management; if the storage security signal two, access permission instruction two, and key usage command two are generated simultaneously, it is determined as medium security management; if the storage security signal three, access permission instruction three, and key usage command three are generated simultaneously, it is determined as low security management; if the storage security signal one, access permission instruction one, and key usage command two are generated simultaneously, it is determined as medium security management (similarly, signal one, instruction two, and command one are generated simultaneously, or signal two, instruction one, and command one are generated simultaneously, and signal two, instruction two, and command one are generated; signal two, instruction one, and command two, and signal one, instruction two, and command two); if the storage security signal two, access permission instruction two, and key usage command three are generated simultaneously, it is determined as low security management (similarly, signal three, instruction two, and command two are generated simultaneously, or signal two, instruction three, and command two are generated simultaneously, and signal three, instruction three, and command two are generated; signal two, instruction three, and command three, and signal three, instruction two, and command three); and determine other combinations as no security management.

[0078] Then compare the level corresponding to the security management with the preset demand management level. If the preset demand management level is greater than the high security management level, perform security management encryption to generate an encrypted signal; if the preset demand management level is less than or equal to the high security management level and greater than the medium security management level, perform the encryption operations corresponding to generating the storage security signal 1, the access permission instruction 1, and the key usage instruction 1; if the preset demand management level is less than or equal to the medium security management level and greater than the low security management level, perform the encryption operations corresponding to generating the storage security signal 2, the access permission instruction 2, and the key usage instruction 2; if the preset demand management level is less than the low security management level, perform the encryption operations corresponding to generating the storage security signal 3, the access permission instruction 3, and the key usage instruction 3.

[0079] S225: Please refer to Figure 4 As shown, the data is encrypted and stored through the maze encryption model; specifically: the encrypted storage data is stored at a specific location within the maze encryption model (the location is changed regularly), and this storage location will be changed regularly to enhance security; when querying, it is necessary to first obtain the storage location information of the encrypted data through the entrance of the maze encryption model; subsequently, based on the location data, multiple possible query paths are generated, and one of them is dynamically selected as the decryption path (the path will be changed regularly); during the decryption process, a data wall (S113) is provided at each path node, and it can only continue to move forward after being decrypted using the corresponding private key, gradually passing through each intersection, and finally reaching the encrypted data storage point; after successfully obtaining the encrypted data, the exit location is determined in the same way, and it is gradually parsed according to the decryption path until the encrypted storage data is completely restored, thereby ensuring the secure access of the data; detect brute-force decryption through abnormal access frequency (set the maximum number of decryption attempts within a certain time window (such as a maximum of 3 failures within 5 minutes); if it is detected that there are frequent decryption failure attempts within a short period of time (such as continuously inputting a large number of incorrect private keys or attempting brute-force traversal at multiple path nodes), it is determined as a brute-force decryption behavior), if there is brute-force decryption, immediately change the location and perform offline processing on the device corresponding to the stored data.

[0080] Please refer to Figure 2 As shown, on the other hand, the present invention provides a network information security processing device based on a blockchain, including a private key security analysis module, a private key management analysis module, and a key management and encryption enhancement module;

[0081] The key security analysis module is used to analyze the security of the private key, determine whether the preset security requirements are met; calculate the execution security level (ESL) of the private key, and analyze whether the private key can resist traditional brute-force cracking and quantum computing attacks; use the brute-force cracking time calculation formula, combined with the attacker's computing power P for security; the impact of Shor's algorithm on encryption algorithms such as RSA and ECC, and calculate the impact factor Q of quantum computing; ensure that ESL≥ESL0, otherwise replace the encryption scheme, such as building a data wall, data bricks, etc. to improve security;

[0082] The private key management analysis module is used to check whether the private key is stored in a secure environment such as HSM, TPM, encrypted database, etc., and whether there is a risk of plaintext storage; detect the access control measures of the private key, including whether multi-factor authentication (MFA), hardware tokens, strong password policies, etc. are enabled; check whether the private key has not been replaced for a long time, and whether it is stored or used in an insecure environment (such as code repositories, cloud storage);

[0083] The key management and encryption enhancement module optimizes the key management strategy and performs encryption enhancement based on the results of private key security assessment and management analysis;

[0084] If it is detected that the private key does not meet the security requirements, replace the encryption scheme and adopt a new key management strategy; adopt a data wall encryption model, split the data into bricks and stack them in an orderly manner to make the key more difficult to crack; optimize the key management life cycle in combination with SP 800-57 and ISO 27001 standards, including key generation, storage, use, and destruction.

[0085] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific implementation manners. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A method for processing network information security based on blockchain, characterized in that Including: Step 1: Calculate the execution security level of the private key, specifically: S111: Calculate the time required for brute-force cracking using the formula Calculate the time T required for brute-force cracking 暴力 , where L is the key length and P is the attacker's computing power; S112: Calculate the quantum computing impact. The quantum computing impact factor = α × log2(N) + β; where N is the key length, and α and β are preset empirical coefficients; S113: Calculate the execution security level through the formula: Obtain the security level ESL; S is the security objective; Compare the security level ESL with the preset required level threshold ESL0; If ESL ≥ ESL0, perform key management analysis; Otherwise, replace the encryption scheme; Adopt the data brick encryption method, construct a data wall and generate a laying order as the data encryption public key and private key; Step 2: Conduct a management analysis on the private key, specifically: S221: Storage security. Detect the storage method, including HSM, TPM, encrypted database, software encryption storage, and public network storage, and generate corresponding storage security signals; S222: Access permission management. Detect the permission management method and generate access permission instructions; S223: Private key usage. Analyze the usage environment and frequency of the private key, detect whether it is stored in HSM / TPM, encrypted database, software storage, not rotated for a long time, or exposed to an insecure environment, and generate private key usage commands; S224: Determine the security management level through the combination of signals, instructions, and commands, and select encryption operations according to preset requirements; S225: Use the maze encryption model to store data, ensure security through dynamic path decryption and data walls, and detect the trigger position for brute-force decryption to replace and handle device offline.

2. The method for processing network information security based on blockchain according to claim 1, wherein, The calculation process of the attacker's computing power P is as follows: The attacker's computing power P depends on multiple factors, including hardware performance, parallel computing ability, optimization algorithms, and also includes single-threaded computing ability, multi-threading and multi-core computing, GPU or FPGA parallel computing, distributed computing, and the impact of optimization algorithms; Suppose: The CPU clock frequency is 3 GHz, and each attempt requires 1000 clock cycles; an 8-core CPU, with 2 threads per core; a GPU has 4000 cores, and each core supports 32 threads; Then: If an attacker controls 1000 such GPU devices: P 总 = P GPU × 1000.

3. The method for processing network information security based on blockchain according to claim 2, wherein The specific process of using the data brick encryption method to construct a data wall and generate the stacking order as the data encryption public key and private key is as follows: Substitute the digital sequence data into the encryption model for encryption; split and combine the digital sequence data according to the corresponding fixed splitting rules, and each new digital sequence after splitting and combination is used as a data brick; each data brick corresponds to a number in the encryption model; stack several data bricks to obtain a data wall; obtain the stacking order of the numbers corresponding to each data brick according to the stacking process of the data wall; and use the stacking order as the data encryption public key; obtain the overall brick position of the data wall according to the positional relationship of each data brick in the data wall; Then set the stacking order according to the overall brick position relationship of the data wall; if there are several stacking orders, select one of them as the private key.

4. The method for processing network information security based on blockchain according to claim 1, wherein, The specific process of generating the corresponding storage security signal is as follows: Detect through the PKCS#11 API and the HSM device management interface to identify whether the HSM is enabled and whether there is a valid key store. If so, generate storage security signal one; Detect whether the TPM is enabled through the TPM 2.0 API or the system BIOS / UEFI settings, and read the TPM configuration information; If the TPM is enabled, generate storage security signal two; Identify the configuration of the database software; Whether the encryption software for transparent data encryption or application layer encryption is enabled; If the software for transparent data encryption or application layer encryption is enabled, generate storage security signal three; Identify software-level encryption through file system or process monitoring; Detect whether the encryption software is enabled; If enabled, generate storage security signal four; Identify whether the storage is located on a publicly accessible server or bucket; Detect whether there is anonymous access permission by scanning the storage permissions; Use the cloud API to test the storage access permissions. Then, based on the test results, if there is anonymous access permission, generate storage security signal five.

5. The method for processing network information security based on blockchain according to claim 1, characterized in that, The specific process of generating the access permission instruction is as follows: Detect the current permission management methods, including multi-factor authentication + hardware token, MFA, password only, password only, and no authentication; Collect information related to the authentication method through system logs, authentication configuration files, API calls, and network traffic monitoring; Classify according to the characteristics of the authentication method through specific detection methods: For multi-factor authentication + hardware token detection, identify whether MFA is enabled and check whether the use of a hardware token is mandatory; Parse the system security policy to confirm whether a hardware token is required; If MFA is enabled and it is confirmed that a hardware token is required, generate access permission instruction one; For MFA detection: Identify whether MFA based on SMS, email, TOTP, or PUSH is enabled; Check the authentication log to see if there is an SMS / email OTP verification record; Read the MFA-related configuration, such as the TOTP key storage file or the SMS gateway / API configuration; Then check the MFA binding through the identity management API. If MFA based on SMS, email, TOTP, or PUSH is enabled, there is an SMS / email OTP verification record, and the MFA binding is checked through the identity management API, generate access permission instruction two; For password only detection: Identify whether the system only requires passwords for authentication; Check the password policy; Parse the authentication configuration file to see if a strong password policy is enabled; Identify whether password change is forced regularly to prevent the long-term use of weak passwords; If a strong password policy is enabled and password change is forced regularly, generate access permission instruction three; For password only detection: Identify whether the system allows users to use passwords of any strength for authentication and no password complexity policy is set; Check whether plaintext password storage is enabled; Parse the system authentication log to determine whether other security measures are enabled; If the user is allowed to authenticate with passwords of any strength, the passwords are stored in plain text, and there are no other security measures, then access permission instruction four is generated; for no authentication detection: identify whether access to system resources is allowed without authentication; detect open API endpoints, databases, file shares; through port scanning and access permission checks, identify services that can be anonymously accessed. If access without authentication is allowed, then access permission instruction five is generated.

6. The method for processing network information security based on blockchain according to claim 5, wherein The specific process of determining the security management level through a combination of signals, instructions, and commands and selecting encryption operations according to preset requirements is as follows: Obtain the signals, instructions, and commands generated in steps S221, S222, and S223 for security level determination; if storage security signal one, access permission instruction one, and key usage command one are generated simultaneously, it is determined as high security management; if storage security signal two, access permission instruction two, and key usage command two are generated simultaneously, it is determined as medium security management; if storage security signal three, access permission instruction three, and key usage command three are generated simultaneously, it is determined as low security management; if storage security signal one, access permission instruction one, and key usage command two are generated simultaneously, it is determined as medium security management; and other combinations are determined as no security management; compare the level corresponding to the security management with the preset required management level. If the preset required management level is greater than high security management, then security management encryption is performed to generate an encryption signal.

7. The method for processing network information security based on blockchain according to claim 6, wherein The specific process of storing data using the maze encryption model, ensuring security through dynamic path decryption and data walls, and triggering location replacement and device offline processing for brute-force decryption detection is as follows: Perform encrypted storage through the maze encryption model; specifically: the encrypted storage data is stored at a specific location within the maze encryption model, and this storage location is changed regularly to enhance security; when querying, first obtain the storage location information of the encrypted data through the entrance of the maze encryption model. Subsequently, generate multiple possible query paths based on the location data and dynamically select one of them as the decryption path. During the decryption process, a data wall is set at each path node, and it is necessary to decrypt with the corresponding private key to continue moving forward, gradually passing through each intersection, and finally reaching the encrypted data storage point; after successfully obtaining the encrypted data, similarly determine the exit location and gradually parse according to the decryption path until the encrypted storage data is completely restored, thereby ensuring the secure access and storage of the data; detect brute-force decryption through abnormal access frequency. If there is brute-force decryption, immediately perform location replacement and execute offline processing on the device corresponding to the stored data.

8. A network information security processing device based on blockchain, characterized in that, Applied to implement the blockchain-based network information security processing method according to any one of claims 1-7, the device includes: a private key security analysis module, a private key management analysis module, and a key management and encryption enhancement module; The key security analysis module is used to analyze the security of the private key to obtain the execution security level ESL of the private key, ensure that ESL ≥ ESL0, otherwise replace the encryption scheme; The private key management analysis module is used to check whether the private key is stored in a secure environment such as HSM, TPM, encrypted database, etc., and whether there is a risk of plaintext storage; detect access control measures for the private key, including whether multi-factor authentication MFA, hardware tokens, and strong password policies are enabled; check whether the private key has not been replaced for a long time, and whether it is stored or used in an insecure environment; Based on the results of private key security assessment and management analysis, the key management and encryption enhancement module optimizes the key management strategy and performs encryption enhancement.