Office process automation data analysis method based on symmetric encryption algorithm
Through an intelligent encryption strategy generator and adaptive optimization model, combining multi-path transmission and lightweight key negotiation, the shortcomings of symmetric encryption algorithms in the automated data analysis of office processes are solved, flexible data encryption and efficient resource management are achieved, and the security and response capabilities of the system are improved.
Patent Information
- Application Number
- CN202510476139.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing symmetric encryption algorithms have problems such as lack of flexibility in office process automation data analysis, limited resource consumption control, lack of real-time and dynamic adjustment capabilities, complex key management and insufficient security, resulting in system performance degradation and increased security risks.
An intelligent encryption strategy generator is introduced, which dynamically adjusts encryption parameters through real-time analysis of data sensitivity, frequency and quantity, adopts multi-path transmission and lightweight key negotiation, introduces key lifecycle management and security event self-healing mechanism, and builds an adaptive optimization model and encryption strategy iteration mechanism.
Dynamic adjustment of symmetric encryption algorithms is realized, the security and efficiency of data transmission are improved, resource consumption is reduced, the adaptability and response capabilities of the system are enhanced, and the security of the key and data integrity are ensured.
Smart Images

Figure CN120342591A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an office process automation data analysis method based on a symmetric encryption algorithm. Background Art
[0002] At present, the office process automation data analysis method has become an important means for many enterprises to ensure data security and optimize data processing in daily office work. However, although this method has significant advantages in enhancing data protection and office efficiency, there are still many deficiencies and drawbacks, which affect the performance, security, and adaptability of the overall system in the specific application process. First of all, the traditional office process automation data analysis method based on the symmetric encryption algorithm usually adopts a static encryption strategy, that is, the parameters of the encryption algorithm (such as the key length and the number of encryption rounds) are rarely adjusted after being set at the time of system deployment. Although this method can provide basic security protection, it lacks flexibility when dealing with the constantly changing data sensitivity, network environment, and computing resources. The static encryption configuration is likely to result in insufficient encryption intensity for highly sensitive data, or over-encryption of low-sensitive data, thus causing waste of system resources, prolonging the data processing time, and reducing the efficiency of the overall office process. In addition, the static key is used unchanged for a long time, which also gradually reduces the security of the key, increases the risk of the key being cracked, and cannot meet the dynamically changing security requirements.
[0003] Secondly, the existing methods have relatively limited control over the resource consumption in the encryption and decryption processes. Although the symmetric encryption algorithm is superior to the public-key encryption algorithm in terms of computational complexity, it still exerts great pressure on the system's computing resources, bandwidth, and storage resources when faced with scenarios of a large amount of data or high-frequency data exchange. Especially in the case of a mixture of highly sensitive data and ordinary data, it is very difficult for the system to flexibly allocate resources. Existing solutions often adopt a unified encryption strategy, where different data is transmitted in the same transmission channel, resulting in a low transmission efficiency for highly sensitive data, while the transmission of ordinary data incurs unnecessary overhead due to excessive encryption. In addition, the existence of the decryption process exposes the data to the decryption module at the terminal node of the transmission link. Once the decryption module at the terminal is compromised, the integrity and confidentiality of the data will face great risks, increasing the likelihood of data leakage and security vulnerabilities. Especially in the enterprise office automation process, where customer sensitive information, financial statements, and internal decision-making documents often need to be processed, the risk of data exposure during the decryption process is even more significant, becoming a potential security hazard. Thirdly, the traditional symmetric encryption data processing methods lack support for real-time performance and flexibility. The office processes of many enterprises involve highly dynamic data transmission, including a large number of real-time interactions and rapid processing requirements, such as instant messaging, online collaborative work, file sharing, etc. However, the existing symmetric encryption schemes often lack the ability of instantaneity and dynamic adjustment, and are unable to quickly respond to different types of data encryption requirements. When faced with scenarios of sudden transmission and large fluctuations in data traffic, the static encryption strategy is difficult to adjust in a timely manner, resulting in a decline in system performance and an increase in transmission latency. At the same time, most of the current symmetric encryption schemes lack an intelligent feedback mechanism, lacking real-time monitoring and adjustment means for the execution of the encryption strategy, and being unable to dynamically optimize the encryption strategy according to the transmission status, resource consumption, and occurrence of security events, affecting the system's adaptability and responsiveness to complex office scenarios. The lack of a feedback mechanism makes it difficult for the system to quickly respond to abnormal situations during the encryption process, such as low encryption efficiency, excessive resource occupation, and too long transmission latency, which are not processed in a timely manner, ultimately affecting the office efficiency and user experience.
[0004] In addition, existing symmetric encryption data processing methods lack automated support for key management and update, resulting in complex and error-prone key management work. Existing methods usually require manual intervention for key generation, distribution, and update. The key update cycle is long and not flexible enough, which not only increases the complexity of system management but also poses the security risk of key exposure during long-term use when the update is not timely. Without the support of a key lifecycle management mechanism, once the key is cracked, all encrypted data based on this key can be decrypted by malicious attackers, causing immeasurable losses to enterprises. Moreover, the keys of symmetric encryption need to be shared between the two communication parties. Once the key is intercepted during transmission, the attacker can directly use the key to decrypt the data. Therefore, the secure distribution and management of keys have become a significant weak link in symmetric encryption schemes. Summary of the Invention
[0005] The object of the present invention is to provide an office process automation data analysis method based on a symmetric encryption algorithm, so as to solve some of the drawbacks pointed out in the background technology.
[0006] The technical solutions adopted by the present invention to solve its above technical problems include the following steps:
[0007] S1. Intelligent symmetric encryption policy generation and optimization:
[0008] S1.1. Introduce an encryption policy generator, and dynamically adjust the parameters of the symmetric encryption algorithm, including the key length and the number of encryption rounds, by real-time analysis of the data communication content, including data sensitivity, frequency, and data volume.
[0009] S1.2. Build an adaptive optimization model to adjust the encryption policy according to external conditions such as network status, device computing power, and user behavior.
[0010] S2. Encrypted data dispersion based on multi-path transmission:
[0011] S2.1. Fragment the data packet before transmission and allocate different transmission paths according to the current network conditions and security assessment.
[0012] S2.2. At the data receiving end, build a dynamic data recombination module to verify and recombine the data when encrypted data packets from different paths arrive.
[0013] S3. Real-time key negotiation and update:
[0014] S3.1. Adopt a lightweight key negotiation protocol based on symmetric encryption to instantaneously generate and negotiate keys when the two communication parties initiate data exchange.
[0015] S3.2. Introduce a key lifecycle management mechanism, set the usage period and number limit for each key; when the key reaches the predetermined conditions, trigger the key refresh mechanism to generate a new key and perform secure distribution;
[0016] S4. Security event self-healing and encryption policy iteration:
[0017] S4.1. When security events such as key leakage and abnormal path are detected in data communication, trigger the response mechanism, including immediately switching to the backup key, renegotiating the transmission path or temporarily encrypting and strengthening;
[0018] S4.2. Input the analysis results of security events into the policy optimization engine, and update and optimize the encryption policy using historical data and the experience of security events.
[0019] Furthermore, the encryption policy generator consists of: real-time monitoring and feature analysis of data including documents, emails, and task data in the office process; identifying the sensitivity of the data through the content classification model, determining the transmission frequency of the data, and calculating the impact of the data volume on encryption and analysis; using the comprehensive analysis formula:
[0020]
[0021] where f(x) represents the comprehensive analysis result, which is used to guide the dynamic adjustment of the subsequent encryption policy; T is the upper limit of the analysis time interval, representing the observation period of the data in the office process; α, β, γ are weight parameters, which respectively control the influence degree of sensitivity, frequency change, and data volume on the overall analysis result; S(x,t) is the sensitivity function, which quantifies its sensitivity by classifying and identifying the data content, including whether the document contains confidential information; is the derivative of the communication frequency change, reflecting the change rate of the data transmission frequency in the office process, and is used to capture sudden or frequent transmission behaviors; V(x,t) is the data volume function, representing the data packet size at time t, and improves the computational perception when analyzing big data by combining the square term of the data volume and the logarithmic function log(1 + V(x,t)).
[0022] Furthermore, the encryption policy generator consists of: inputting the analysis results into the parameter optimization module to dynamically adjust the key parameters of the symmetric encryption algorithm; adopting an optimization model to timely adjust the key length and the number of encryption rounds by evaluating the sensitivity level and analysis complexity of the data; the optimization process is described by the formula:
[0023]
[0024] Where: φ(x) is the optimized output value of the encryption policy, which determines the adjustment directions of the key length k and the number of encryption rounds e; M(x,t) represents the data sensitivity level function, which quantifies the comprehensive sensitivity of the data at time t; is the second derivative of the sensitivity function, which is used to detect drastic changes in data sensitivity and help quickly respond to possible sensitive data peaks; k is the key length, which affects the encryption strength and is dynamically adjusted between 128 bits, 192 bits, and 256 bits; r is the number of encryption rounds, which represents the number of cycles of the encryption algorithm execution; enhances the adaptability to encryption complexity when the data volume increases; δ is the adjustment factor, which adjusts the encryption strength.
[0025] Furthermore, the encryption policy generator consists of: through the encryption execution and feedback mechanism, it monitors the performance during the encryption process in real time, including encryption time and resource consumption, and adjusts the encryption policy according to the actual situation; the continuous optimization of the encryption policy is achieved through the feedback formula:
[0026]
[0027] Where: ψ(x) is the feedback function, which is used to evaluate the effect of the current encryption policy in real time; P(x,t) is the encryption performance index function, which measures the resource consumption of the current encryption policy for office process analysis; Q(x,t) is the security index function, which describes the actual effect of the encryption policy in protecting sensitive data; λ, μ are the feedback control parameters, which dynamically adjust the balance between analysis efficiency and security; log(1 + r) represents the adjustment impact of the number of encryption rounds.
[0028] Furthermore, the process of instantaneously generating and negotiating keys includes: classifying the data stream through the classification model and the real-time monitoring system, classifying the data into high-sensitivity, ordinary, and low-sensitivity levels, and matching the corresponding encryption strength according to different levels; the mechanism is quantitatively evaluated through the formula:
[0029]
[0030] Where: A(t) represents the evaluation function of the dynamic encryption strength, which is used to quantify and guide the adjustment of encryption parameters; T is the upper limit of the evaluation time period, which represents the time range for observation and adjustment; α, β, γ are the feature weight parameters, which are used to adjust the influence of sensitivity, frequency change, and data volume on the encryption strength; S(t) is the data sensitivity function, which is used to evaluate the sensitive level of the data at time t; F ′ (t) is the time derivative of the transmission frequency, which reflects the change rate of the data transmission frequency at different time points; V(t) is the data volume function, which describes the size of the data at time t, through Nonlinear adjustment to amplify the impact of big data traffic on encryption intensity; λ is the nonlinear adjustment parameter, used to control the degree of influence of the data volume on the overall encryption intensity.
[0031] Furthermore, the process of instantaneously generating and negotiating keys includes: adopting a multi-level encrypted data transmission optimization strategy to divide data communication into different transmission channels; each channel selects an encryption strategy according to the sensitivity and transmission requirements of the data. Highly sensitive data passes through a strong encryption channel, and low-sensitive data passes through a light encryption channel. The optimization of the transmission strategy is described by a transmission benefit function:
[0032]
[0033] Where: T(x) is the optimization benefit function of the transmission channel, evaluating the overall transmission effect of different levels of encryption strategies; N is the total number of transmission channels, representing the number of multi-level channels used for data with different sensitivities; δ i is the weighting factor of the i-th layer transmission channel, balancing the contribution of each channel to the overall transmission benefit; P i (x) represents the performance index function of the i-th layer channel, quantifying the transmission efficiency and stability of a specific channel; R i (x) is the resource occupancy rate function, describing the occupancy of system resources by the channel when executing the current encryption strategy; ω is the resource adjustment parameter, used to adjust the impact of the resource occupancy rate on the transmission channel selection; Q i (u) is the transmission path priority function, indicating the priority of data packets in different channels during transmission.
[0034] Furthermore, the process of instantaneously generating and negotiating keys includes: introducing an automated parsing and collaborative analysis engine for encrypted data to perform parsing and analysis on encrypted data; the engine directly analyzes the encrypted data through specific data identifier and content feature extraction technologies; the parsing and analysis process is controlled by a formula:
[0035]
[0036] Where: R(y) is the parsing and collaborative analysis output function of encrypted data, evaluating the parsing efficiency of the engine at different time points; Y represents the length of the data parsing time interval, used to control the timeliness of the analysis process; κ is the adjustment coefficient; E(y) is the parsing efficiency function of encrypted data, reflecting the ability of the engine to parse and analyze data at time y; θ is the parsing precision control parameter, affecting the response speed of the engine to the parsing of high-frequency data; φ controls the periodic characteristics in the parsing process, and optimizes the parsing precision of data with different frequencies through the periodic regulation term of.
[0037] The data analysis method for office process automation based on the symmetric encryption algorithm of the present invention has the following beneficial effects:
[0038] By monitoring and analyzing the sensitivity, transmission frequency, and data volume of data in real time, the present invention can dynamically adjust the key parameters of the symmetric encryption algorithm, such as the key length and the number of encryption rounds, according to the data characteristics, so as to provide customized encryption protection for different types of data. Highly sensitive data is protected by a stronger encryption strategy to ensure that it cannot be obtained or tampered with by unauthorized visitors during transmission and storage, effectively resisting the risks of information leakage and man-in-the-middle attacks.
[0039] Using a multi-level encryption data transmission optimization strategy, different transmission channels are selected according to the sensitivity level of the data, and the corresponding encryption intensity is matched. Highly sensitive data uses a strong encryption channel to ensure security, while low-sensitive data uses a light encryption channel to reduce the system burden, thereby realizing the reasonable allocation of computing resources, bandwidth, and storage resources. This resource optimization mechanism not only improves the overall performance of the system but also effectively reduces the latency during the data processing process.
[0040] By introducing an instant key negotiation and dynamic adjustment mechanism, the present invention can instantaneously generate and negotiate keys according to the current network conditions and device computing capabilities, avoiding the complex calculations and delays in the traditional key negotiation process. This mechanism makes the encryption and decryption processes more efficient, especially significantly reducing the time overhead of data transmission in high-frequency data exchange scenarios, providing a means of rapid-response data protection for the automated office process. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a flowchart of the data analysis method for office process automation based on the symmetric encryption algorithm of the present invention.
[0042] Figure 2 It is a flowchart of the method for constructing the encryption strategy generator of the present invention.
[0043] Figure 3 It is a flowchart of the method for instantaneously generating and negotiating keys. DETAILED DESCRIPTION OF THE INVENTION
[0044] The following will give a detailed description of the specific implementation manners of the present invention in conjunction with the accompanying drawings.
[0045] Combined with the atta Figure 1The shown flowchart generates and optimizes through intelligent encryption strategies to improve the security and processing efficiency of data in the office automation process. Its core steps include S1: intelligent symmetric encryption strategy generation and optimization. In this process, first, an encryption strategy generator is introduced. This generator can monitor and analyze the content characteristics of data communication in real time, including key factors such as data sensitivity, communication frequency, and data volume. Data sensitivity evaluates the importance and confidentiality of data through a classification model. Communication frequency reflects the activity level of data during transmission, while data volume represents the size of data packets and the transmission load. Through comprehensive analysis of these factors, the system can dynamically adjust the parameters of the symmetric encryption algorithm, such as key length and number of encryption rounds, to meet the security requirements and processing requirements of different data scenarios. For example, when detecting highly sensitive data, the system will automatically increase the key length and number of encryption rounds to enhance encryption strength and ensure data security. For low-sensitivity or ordinary data, the system will appropriately reduce the encryption strength to optimize transmission and processing efficiency and avoid unnecessary resource waste.
[0046] To ensure the adaptability of the encryption strategy to the actual office environment, the system further constructs an adaptive optimization model. This model can dynamically adjust the encryption strategy according to external conditions such as real-time network status, device computing power, and user behavior. Network status includes indicators such as current network bandwidth, latency, and stability, which affect the speed and security requirements of data transmission. Device computing power refers to the hardware resources for executing the encryption algorithm, such as the availability of CPU and memory, which determines the complexity and execution speed of the encryption algorithm. User behavior includes the access frequency, operation habits, and permission levels of users for data, which directly affect the data security policy. Through comprehensive evaluation of these external conditions, the adaptive optimization model can adjust the encryption strategy in real time. For example, when network congestion occurs, it reduces the number of encryption rounds to speed up data transmission, or when the device computing power is insufficient, it optimizes the algorithm complexity of key generation to maintain the efficient operation of the system.
[0047] Step S2 is the dispersion of encrypted data based on multi-path transmission. This technology improves the security and anti-attack ability of data transmission through packet fragmentation and multi-path transmission strategies. In the specific implementation process, first, the data packet is fragmented before transmission, that is, the complete data is split into multiple small segments. After these segments are symmetrically encrypted, they will be distributed to different transmission paths for transmission according to the current network conditions and security evaluation results. Network conditions include factors such as network bandwidth, latency, and stability, which determine the transmission performance of each path. Security evaluation is based on information such as data sensitivity and transmission frequency, which determines the security requirements of each path. By dispersing the encrypted data segments to multiple paths for transmission, even if a certain path is attacked or the data is intercepted, the attacker cannot obtain the complete data content, thus greatly improving the security of data transmission.
[0048] When the data reaches the receiving end, the system constructs a dynamic data recombination module, which is responsible for verifying and recombining the encrypted data segments transmitted dispersedly. The dynamic data recombination module can identify and recombine the encrypted data packets from different paths, and ensure the integrity and correctness of the data through technologies such as hash verification and sequence number matching. During the data recombination process, the system first performs an integrity check on the received data segments to detect whether there is data loss or tampering; then, according to the order of the segments before transmission, it reassembles each data segment into the original data. This module has an adaptive repair function. If it detects that some segments are lost or damaged, the system will automatically initiate a retransmission request to ensure the integrity of the data and the continuity of the transmission.
[0049] Step S3 is real-time key negotiation and update, whose purpose is to ensure that the data is always protected by high-strength encryption during the transmission process and avoid security risks caused by using the same key for a long time. This step first adopts a lightweight key negotiation protocol based on symmetric encryption to generate and negotiate keys immediately when the communication parties initiate data exchange. This lightweight protocol does not rely on a complex public key infrastructure, but quickly generates a session key through symmetric encryption technology, reducing the computational overhead and latency during the negotiation process. In the specific implementation, when the communication parties establish a connection, the protocol uses a preset symmetric key seed or a simple random number generation algorithm to immediately generate a temporary session key. The two parties confirm the validity and security of the key through encrypted handshake messages. This immediate and lightweight key negotiation method can significantly reduce the time cost of data exchange while ensuring the security of the data transmission process.
[0050] To further strengthen key management, the system introduces a key lifecycle management mechanism to set the usage period and number limit for each generated key, avoiding the risk of the key being exposed to the risk of being cracked due to long-term use. The key lifecycle mechanism performs dynamic management according to the actual usage situation of the key (such as usage duration, number of uses, etc.). When the key reaches the predetermined usage conditions, such as exceeding the specified number of uses or reaching the set time limit, the system will automatically trigger the key refresh mechanism. The key refresh mechanism is responsible for generating a new key and synchronizing the new key to both communication parties through a secure distribution channel to ensure that the key is safely replaced before the end of its lifecycle and avoid potential security hazards. During the new key distribution process, the system uses symmetric encryption to protect the transmission process of the key to prevent man-in-the-middle attacks and key leakage.
[0051] Step S4 is for the self-healing of security incidents and the iteration of encryption policies. The core of this step lies in enhancing the system's response ability to security incidents and the self-optimization ability of encryption policies. In practical applications, when the system detects security incidents such as key leakage or abnormal transmission paths during data communication, it will immediately trigger corresponding response mechanisms to quickly contain security risks. This response mechanism includes various countermeasures, such as immediately switching to a backup key, renegotiating the transmission path, or temporarily strengthening the current encryption policy. When key leakage is detected, the system will quickly switch to the prepared backup key and distribute this key to both communication parties to replace the compromised key, preventing the data from being further exposed in an insecure state; when an abnormal transmission path (such as the path being attacked or the transmission being interrupted) is detected, the system will immediately renegotiate a new transmission path, avoiding the abnormal path by adjusting the transmission route to improve the security and stability of data transmission;
[0052] If insufficient encryption strength or other potential threats are found during transmission, the system will also automatically trigger a temporary encryption strengthening mechanism, that is, increasing the encryption strength in the current session, such as increasing the number of encryption rounds or replacing with a more complex encryption algorithm, to ensure that the data is still highly protected under abnormal conditions. In addition, the system is not limited to immediate response. It will also input the analysis results of each security incident into the policy optimization engine. The policy optimization engine continuously updates and optimizes the encryption policy by collecting and analyzing historical data and the experience of security incidents. Through machine learning and big data analysis, the policy optimization engine can extract key patterns and vulnerability information from historical security incidents, identify weaknesses in the encryption policy, and make self-adjustment and optimization of the policy according to the actual situation. For example, if it is found that a certain encryption configuration is more vulnerable to attacks under specific network conditions, the system will adjust the encryption parameters or configuration according to the suggestions of the optimization engine to avoid the recurrence of the same security problem.
[0053] Example 1:
[0054] Combined with the Figure 2 flowchart shown, in the daily office process of a large multinational company, a large number of sensitive documents are transmitted, emails are exchanged, and task data is processed. To ensure the security and transmission efficiency of this data, the company introduced an automated data analysis method for office processes based on the symmetric encryption algorithm. Specifically, the system uses an intelligent encryption policy generator. By monitoring and analyzing the characteristics of documents, emails, and task data in the office process in real time, combined with the content classification model to identify the sensitivity of the data, determine the data transmission frequency, and calculate the impact of the data volume on encryption and analysis. To illustrate the working principle of the system in detail, taking the daily operation of a project team in the company as an example, the working process of this encryption policy generator is analyzed in detail.
[0055] In the example, the key data that the project team needs to process every day includes customer contract documents, internal email exchanges, and data records in the task management system. For this data, the system monitors it in real time and extracts features. Among them, the documents contain sensitive information of customers (such as contract amounts and terms), the internal emails contain sensitive information such as project progress and personnel changes, and the data records in the task management system include task assignments and completion status, etc. Through the content classification model, the system scores the sensitivity of this data. Among them, the sensitivity score of the documents is 8 (on a 0-10 scale), the emails are 5, and the task data is 3. In terms of transmission frequency, the transmission frequency of emails is relatively high, about 30 transmissions per hour; while the contract documents are less, with an average of 2 transmissions per day; the transmission frequency of task data is about 5 times per hour. In terms of data volume, the average file size of contract documents is 5MB, the average size of emails is 100KB, and the size of task data records is 50KB.
[0056] To dynamically adjust the encryption policy, the system uses the comprehensive analysis formula:
[0057]
[0058] Among them, T is the observation period, set as an 8-hour working day; α, β, γ are weight parameters, and the specific values are α = 0.5, β = 0.3, γ = 0.2. These weights are used to balance the impacts of data sensitivity, frequency changes, and data volume on the overall encryption policy. S(x,t) is the sensitivity function, used to evaluate the sensitive degree of data; represents the derivative of the communication frequency change, capturing the fluctuation characteristics in data transmission; V(x,t) is the data volume function, combining a square term and a logarithmic function, used to quantify the impact of the data packet size on encryption and analysis.
[0059] Substitute the data for calculation. At a certain time point t, the sensitivity score of the contract document S(x,t) = 8, the transmission frequency change times per hour (lower volatility), and the data volume is V(x,t) = 5MB. Then the calculation result of the formula is:
[0060]
[0061] For emails, set the sensitivity score S(x,t) = 5, the transmission frequency change times per hour (frequent fluctuations), and the data volume V(x,t) = 0.1MB. Then the formula calculation is:
[0062]
[0063] For task data, set the sensitivity score S(x,t) = 3, the transmission frequency change times per hour, with the data volume V(x,t) = 0.05MB, the formula calculation is as follows:
[0064]
[0065] Based on these calculation results, the system performs higher-strength encryption on contract documents (such as a key length of 256 bits and 20 encryption rounds), medium-strength encryption on emails (a key length of 192 bits and 15 encryption rounds), and lower-strength encryption on task data (a key length of 128 bits and 10 encryption rounds) to ensure the security of sensitive data and the transmission efficiency of ordinary data.
[0066] In the previous stage, through the encryption policy generator, real-time monitoring and feature analysis were carried out on documents, emails, and task data in the office process. The system conducted a comprehensive evaluation based on the sensitivity, transmission frequency, and data volume of the data, calculated the adaptive analysis result f(x), and initially determined the encryption strength requirements for different data. Next, the system inputs these analysis results into the parameter optimization module to further dynamically adjust the key parameters of the symmetric encryption algorithm, including the key length k and the number of encryption rounds r, to optimize the overall encryption policy.
[0067] Specifically, the system adopts an optimization model to adjust the encryption parameters in a timely manner by evaluating the sensitivity level and analysis complexity of the data. Assume that the current system is processing a customer contract document (the analysis result f in the previous calculation 合同文档 ≈52.8). Due to the high sensitivity of this data, the system needs to perform higher-strength encryption on it. To achieve optimal encryption, the system uses the following optimization formula:
[0068]
[0069] Among them, φ(x) is the optimization output value, guiding the adjustment direction of the key length k and the number of encryption rounds r; M(x,t) represents the comprehensive sensitivity of the data at time t. Assume that the sensitivity change function of this document is M(x,t) = 8 - 0.5t, indicating that the sensitivity gradually decreases from the highest 8 to the lowest 4; is the second derivative of the sensitivity function, used to detect drastic changes in data sensitivity. If it is positive, it means that the sensitivity fluctuates greatly and the encryption strength needs to be increased; assume that the average value of the second derivative within the analysis period is 0.8, indicating that the sensitivity has a certain fluctuation; k is the key length, assumed to be adjusted between 128 bits, 192 bits, and 256 bits; r is the number of encryption rounds, initially set to 10 times and adjusted to 20 times according to the analysis; is the adjustment function, adapting to changes in data volume. Assume that the current data volume V(x) = 5MB; δ is the adjustment factor, with a value range of 0.8 - 1.2, used to flexibly control the encryption strength, and the current value is set to 1.1.
[0070] Substitute the above specific data into the formula and calculate to obtain:
[0071]
[0072] Calculate each part. First is the sensitivity integral:
[0073]
[0074] Then is the second derivative integral:
[0075]
[0076] Substitute these results into:
[0077]
[0078] Further calculate,
[0079] φ 合同文档 ≈1.1×6.49×(256×28)≈1.1×6.49×7168≈51115.52
[0080] From the calculation results, the high sensitivity and large data volume of the contract document require the highest strength of the encryption strategy. Therefore, the system finally adjusts the key length to 256 bits and increases the number of encryption rounds to 20 times to ensure the high security of data transmission. In contrast, if processing email data (f 邮件 ≈32.16, and the sensitivity function is set as M(x,t) = 5 - 0.2t, the result will be significantly reduced, and the encryption strategy is correspondingly adjusted to a key length of 192 bits and 15 encryption rounds. This dynamic adjustment process shows that the present invention can flexibly and efficiently adjust the encryption strategy in the actual office process to ensure the balance between security and efficiency for different data types.
[0081] Previously, the system has set a high encryption strength for the contract document (key length 256 bits, number of encryption rounds 20 times). Next, the system evaluates the actual operation effect of this strategy through the encryption execution and feedback mechanism, and continuously optimizes the encryption strategy through the feedback formula.
[0082] In this process, the system real-time collects performance indicators including encryption time, resource consumption (CPU, memory usage, etc.) and data security. It is set that the system currently monitors that the encryption time of the contract document is 120 milliseconds, the CPU occupancy rate during the encryption process is 30%, and the memory usage rate is 15%. These data indicate that the current encryption strategy consumes a relatively high amount of system resources, but ensures the high security of the document. To continuously optimize the strategy, the system uses the feedback formula:
[0083]
[0084] Among them, ψ(x) is the feedback function, which is used to evaluate the effect of the current encryption policy in real time. T is the monitoring period, which is set to 8 hours of working time; P(x,t) is the encryption performance index function, which is used to measure the resource consumption of the encryption policy; q(x,t) is the security index function, which evaluates the actual effect of the encryption policy in protecting sensitive data; λ and μ are feedback control parameters, which adjust the weights of analysis efficiency and security. The specific value range is λ = 0.6 to 0.8, μ = 1.0 to 1.2. The selection of these coefficients is dynamically adjusted according to the balance of the system's resource consumption and security requirements; log(1 + r) reflects the impact of the number of encryption rounds on system resources and security. The current number of encryption rounds r = 20.
[0085] According to the real-time monitored data, the encryption performance index function P(x,t) = 5 - 0.02t is set, which represents the change of system resource consumption at different time points during encryption execution. It is efficient at the beginning but gradually increases over time; the security index function Q(x,t) = 8 - 0.1t reflects the security performance of the encryption policy at different time periods. As the number of transmissions increases, the security decreases slightly. Substitute these specific values into the formula for calculation:
[0086]
[0087] First, calculate the integral term:
[0088]
[0089] Substitute these results into:
[0090] ψ(x) = 0.7×39.36 - 1.1×60.8×log 21
[0091] log21 ≈ 3.04
[0092] Calculate the final result:
[0093] ψ(x) = 0.7×39.36 - 1.1×60.8×3.04 = 27.552 - 203.968 = -176.416
[0094] This negative value indicates that the current encryption policy consumes much more resources than it gains in terms of security. The system feedback believes that this policy is too resource-consuming, so it needs to be optimized. According to the feedback result, the system will appropriately reduce the number of encryption rounds r to 15 times and adjust the key length to 192 bits without affecting security to reduce the pressure on the CPU and memory.
[0095] Similarly, the system monitors and feedback-optimizes the mail and task data, and sets the initial feedback value ψ of the mail邮件 ≈ -60, indicating that the resource utilization of its current encryption policy is relatively reasonable and only minor adjustments are needed, while the feedback value ψ of the task data 任务 ≈ 10, showing that the encryption policy is relatively balanced and no major adjustments are required.
[0096] Example 2:
[0097] Combined with the attached Figure 3 As shown in the flowchart, during the daily office work of a project team, through the generation and optimization of intelligent encryption policies, the transmission security of contract documents, emails, and task data is ensured. However, the sensitivity, transmission frequency, and data volume of the data vary, so a process of instantaneously generating and negotiating keys is required to dynamically match the appropriate encryption intensity according to different data types. This process is driven by a classification model and a real-time monitoring system. Through the real-time monitoring and hierarchical processing of data streams, the data is classified into high-sensitivity, normal, and low-sensitivity levels, and the corresponding encryption intensity is matched according to different levels, thereby ensuring data security and reasonable resource utilization. To specifically illustrate the working principle of this mechanism, continue to follow up a series of office data processed by the project team, including contract documents, emails, and task data, and elaborate on the process of instantaneously generating and negotiating keys.
[0098] It is set that within a working day, the main data types processed by the team include highly sensitive customer contracts (documents), moderately sensitive internal emails, and low-sensitivity task management data. The system first analyzes the sensitivity, transmission frequency, and data volume of these data. Taking the evaluation time period T = 8 hours as an example, the system quantifies the characteristics of each type of data, and sets the currently set weight parameters as α = 0.6, β = 0.3, γ = 0.1. These weights are used to balance the impacts of sensitivity, frequency change, and data volume on the overall encryption intensity. To evaluate the sensitive level of the data, the system gives the sensitivity function S(t) of each data through the classification model. Among them, the sensitivity function of the customer contract is set as S(t) = 8, reflecting its high requirements for security; the sensitivity of the internal email is S(t) = 5, and the task management data is S(t) = 2, representing the differences in security requirements for different data. In terms of the change in transmission frequency, the derivative of the transmission frequency of the contract document is set as F ′ (t) = 0.2 times per hour. The transmission frequency of emails fluctuates greatly and is set as F ′ (t) = 3 times per hour, while the frequency change of task data is relatively stable, being F ′ (t) = 0.5 times per hour. For the data volume, the average size of the contract document is 5MB, that is, the data volume function V(t) = 5, the email size is 0.1MB, and the task data is 0.05MB, reflecting the loads of different data during transmission and processing.
[0099] Substitute these parameters into the evaluation formula for dynamic encryption strength:
[0100]
[0101] where λ is the non - linear adjustment parameter, used to control the influence degree of the data volume on the overall encryption strength. Set λ = 0.5, which reflects the amplification effect of the data volume on the encryption strength. Taking the contract document as an example, substitute each parameter specifically for calculation:
[0102]
[0103] Calculate each part:
[0104]
[0105] Calculate the last part, which varies non - linearly with time, and the approximate integral result is 16:
[0106] A 合同文档 = 38.4 + 0.48 + 16 ≈ 54.88
[0107] For internal email data:
[0108]
[0109] This has a minimal impact on the whole:
[0110] A 邮件 ≈ 24 + 7.2 = 31.2
[0111] For task data:
[0112]
[0113] The impact is minimal:
[0114] A 任务数据 ≈ 9.6 + 1.2 = 10.8
[0115] According to these calculation results, the system determines that the contract document requires the highest encryption strength. Therefore, a key with a length of 256 bits and 20 encryption rounds is generated and negotiated; the email data is set with a 192 - bit key and 15 encryption rounds; while the task data only requires a 128 - bit key and 10 encryption rounds.
[0116] To further optimize the data transmission efficiency and security, the system introduces a multi - level encrypted data transmission optimization strategy, divides the data communication into different transmission channels, and selects appropriate encryption strategies according to the sensitivity level of the data to achieve efficient and secure data transmission.
[0117] In this example, the office data of the project team is divided into three categories: highly sensitive contract documents, moderately sensitive internal emails, and low-sensitive task data. The system adopts a three-layer transmission channel, and each channel corresponds to a different encryption strategy. Highly sensitive data is transmitted through a strong encryption channel, which uses the highest key length and the maximum number of encryption rounds to ensure data security; moderately sensitive data passes through a channel with medium encryption intensity to optimize the transmission efficiency; while low-sensitive data passes through a light encryption channel to ensure the lowest resource consumption.
[0118] To evaluate the overall benefits of these multi-level encrypted transmissions, the system uses a transmission benefit function for quantification:
[0119]
[0120] where T(x) represents the transmission benefit of the multi-level encryption strategy, N = 3 is the total number of transmission channels, corresponding to the three layers of highly sensitive, moderately sensitive, and low-sensitive channels respectively; δ i is the weighting factor for each layer of the channel, set as δ1 = 1.5 (highly sensitive), δ2 = 1.0 (moderately sensitive), δ3 = 0.5 (low-sensitive). These coefficients are used to balance the contributions of different channels to the overall transmission benefit; P i (x) represents the performance metric function of the channel, reflecting the transmission efficiency and stability of the channel. For example, the performance of the highly sensitive channel is P1(x) = 4 - 0.1x, the moderately sensitive channel is P2(x) = 6 - 0.2x, and the low-sensitive channel is P3(x) = 8 - 0.05x; R i (x) is the resource occupancy rate function, used to describe the consumption of system resources by each channel when executing the current encryption strategy. The values are R1(x) = 3 + 0.1x, R2(x) = 2 + 0.15x, R3(x) = 1 + 0.05x; ω is the resource adjustment parameter, with a value range of 0.8 to 1.2, used to adjust the influence of the resource occupancy rate on the selection of the transmission channel, set as ω = 1.0; Q i (u) is the transmission path priority function, set as the priority of data packets in different channels during transmission, which are Q1(u) = 2u, Q2(u) = 1.5u, Q3(u) = u respectively.
[0121] Substitute into the formula to calculate the transmission benefit. First, calculate for the highly sensitive channel:
[0122]
[0123] Integral part:
[0124]
[0125] Then calculate:
[0126]
[0127] Taking x = 5 as an example, the calculation gives:
[0128]
[0129] For moderately sensitive channels:
[0130]
[0131] The integral part:
[0132]
[0133] Then calculate:
[0134]
[0135] Taking x = 5 as an example, the calculation gives:
[0136]
[0137] For low - sensitive channels:
[0138]
[0139] The integral part:
[0140]
[0141] Then calculate:
[0142]
[0143] Adding the results of each layer of channels gives the overall benefit:
[0144] T(x) = 101.14 + 26.28 + 23.22 = 150.64
[0145] This result shows that through a multi - level encrypted data transmission strategy, the system effectively balances the security of highly sensitive data and the resource utilization rate of low - sensitive data.
[0146] To further improve the processing efficiency of encrypted data, the company introduced an automated parsing and collaborative analysis engine for encrypted data. This engine directly parses and analyzes encrypted data through specific data identifier and content feature extraction technologies, without the need to decrypt the data first, thus reducing the risk of data exposure. The working principle and performance of this engine are controlled by the parsing and collaborative analysis formula.
[0147] In specific examples, when the project team processed contract documents, internal emails, and task data, they used an automated parsing and collaborative analysis engine for encrypted data, achieving real-time parsing and analysis of various types of encrypted data. To evaluate the parsing efficiency of the engine, the following formula was adopted:
[0148]
[0149] Among them, R(y) is the output function of parsing and collaborative analysis, reflecting the parsing efficiency of the engine at different time points; Y represents the length of the time interval for data parsing, controlling the timeliness of the analysis process, and is set to 8 hours; κ is an adjustment coefficient used to balance the parsing speed and accuracy, with a value range of 0.9 to 1.2, and currently set to κ = 1.1; E(y) is the parsing efficiency function of encrypted data, with the parsing efficiency of contract documents set as E(y) = 5 - 0.1y, the parsing efficiency of email data as E(y) = 4 - 0.05y, and the parsing efficiency of task data as E(y) = 3 - 0.02y; θ is the parsing accuracy control parameter, affecting the response speed of the engine to the parsing of high-frequency data, with a setting range of 0.5 to 1.5, and the current value is θ = 1.0; φ controls the periodic characteristics in the parsing process and is set to 6, used to regulate the adaptability of the parsing to data of different frequencies.
[0150] First, evaluate the parsing efficiency of the contract documents:
[0151]
[0152] The integral part is calculated in two parts, considering the influence of the periodic regulation term:
[0153] For the first part:
[0154]
[0155] For the regulation term Estimate that the influence of the integral is 0.8 times:
[0156] R 合同文档 = 1.1×36.8×0.8 = 32.38
[0157] Then, evaluate the parsing efficiency of the email data:
[0158]
[0159] Similarly calculate:
[0160]
[0161] The estimate of the regulation term is also 0.8 times:
[0162] R 邮件= 1.1 × 30.4 × 0.8 = 26.75
[0163] Finally, evaluate the task data:
[0164]
[0165] The integration result is:
[0166]
[0167] Similarly, multiply by the 0.8 - fold regulation term:
[0168] R 任务数据 = 1.1 × 23.36 × 0.8 = 20.57
[0169] It can be seen from the calculation that the parsing efficiency of the contract document is the highest, followed by the email data, and the parsing efficiency of the task data is relatively low. Through these parsing efficiency evaluation results, the system can adjust the parameters of the parsing engine in real - time, improve the processing priority of highly sensitive data, and at the same time smoothly parse low - sensitive data when resources permit.
Claims
1. An office process automation data analysis method based on a symmetric encryption algorithm, characterized in that The following steps are involved: S1. Intelligent symmetric encryption strategy generation and optimization: S1.1, introduce encryption strategy generator, through real-time analysis of data communication content including data sensitivity, frequency, and data volume, dynamically adjust the parameters of symmetric encryption algorithm including key length and number of encryption rounds; S1.
2. Build an adaptive optimization model to adjust the encryption strategy based on network status, device computing power, and external conditions of user behavior; S2. Encrypted data dispersion based on multi-path transmission: S2.1, fragment the data packet before transmission and assign different transmission paths according to the current network conditions and security assessment; S2.2, at the data receiving end, a dynamic data reassembly module is constructed to verify and reassemble the data when the encrypted data packets from different paths arrive; S3, real-time key negotiation and update: S3.
1. A lightweight key negotiation protocol based on symmetric encryption is used to instantly generate and negotiate keys when the communicating parties initiate data exchange; S3.
2. Introduce a key lifecycle management mechanism to set a usage period and number of times for each key; when a key reaches a predetermined condition, a key refresh mechanism is triggered to generate a new key and distribute it securely; S4. Security incident self-healing and encryption strategy iteration: S4.
1. When security events such as key leakage and path abnormality are detected in data communication, a response mechanism is triggered, including immediate switching to backup keys, re-negotiating transmission paths, or temporary encryption reinforcement; S4.
2. Input the analysis results of security events into the policy optimization engine, and use historical data and experience from security events to update and optimize encryption policies.
2. The method for analyzing data of office process automation based on symmetric encryption algorithm according to claim 1, wherein The encryption strategy generator comprises: real-time monitoring and feature analysis of data in office processes including documents, emails, and task data; identifying the sensitivity of data through content classification models, determining the frequency of data transmission, and calculating the impact of data volume on encryption and analysis; using a comprehensive analysis formula: Among them, f(x) represents the comprehensive analysis result, which is used to guide the dynamic adjustment of subsequent encryption strategies; T is the upper limit of the analysis time interval, representing the observation period of data in the office process; α, β, γ are weight parameters, which respectively control the influence degrees of sensitivity, frequency change, and data volume on the overall analysis result; S(x,t) is the sensitivity function, which quantifies the sensitivity by classifying and identifying the data content, including whether the document contains confidential information; is the derivative of the communication frequency change, reflecting the change rate of the data transmission frequency in the office process, and is used to capture sudden or frequent transmission behaviors; V(x,t) is the data volume function, representing the data packet size at time t, and improves the computational perception during big data analysis through the combination of the square term of the data volume and the logarithmic function log(1 + V(x,t)).
3. The method for analyzing office process automation data based on the symmetric encryption algorithm according to claim 2, wherein The encryption strategy generator comprises: inputting the analysis results into a parameter optimization module to dynamically adjust the parameters of the symmetric encryption algorithm; using an optimization model to timely adjust the key length and the number of encryption rounds by evaluating the sensitivity level of the data and the complexity of the analysis.
4. The method for analyzing office process automation data based on the symmetric encryption algorithm according to claim 3, wherein The encryption strategy generator comprises: monitoring the performance of the encryption process in real time, including encryption time and resource consumption, through an encryption execution and feedback mechanism, and adjusting the encryption strategy according to actual conditions.
5. The office process automation data analysis method based on the symmetric encryption algorithm according to claim 1, wherein The instant generation and negotiation of keys process includes: grading the data stream through the classification model and real-time monitoring system, dividing the data into high sensitivity, ordinary and low sensitivity levels, and matching the corresponding encryption strength according to the different levels; the mechanism is quantitatively evaluated through the formula: Where: A(t) represents the evaluation function of the dynamic encryption strength, which is used to quantify and guide the adjustment of encryption parameters; T is the upper limit of the evaluation time period, representing the time range for observation and adjustment; α, β, γ are feature weight parameters, which are used to adjust the influence of sensitivity, frequency change, and data volume on the encryption strength; S(t) is the data sensitivity function, which is used to evaluate the sensitive level of data at time t; F′(t) is the time derivative of the transmission frequency, reflecting the change rate of the data transmission frequency at different time points; V(t) is the data volume function, which describes the size of the data at time t. Through the nonlinear adjustment, the influence of big data traffic on the encryption strength is amplified; λ is the nonlinear adjustment parameter, which is used to control the influence degree of the data volume on the overall encryption strength.
6. The method for analyzing office process automation data based on the symmetric encryption algorithm according to claim 5, wherein The instant generation and negotiation of keys process includes: adopting a multi-level encrypted data transmission optimization strategy to divide data communication into different transmission channels; each channel selects an encryption strategy based on the sensitivity and transmission requirements of the data, with highly sensitive data passing through a strong encryption channel and less sensitive data passing through a light encryption channel.
7. The method for analyzing office process automation data based on the symmetric encryption algorithm according to claim 6, characterized in that The process of instant key generation and negotiation includes: introducing an automated parsing and collaborative analysis engine for encrypted data to perform parsing and analysis processing on the encrypted data; the engine directly analyzes the encrypted data through specific data identifier and content feature extraction technologies; the parsing and analysis process is controlled by a formula: Where: R(y) is the parsing and collaborative analysis output function of the encrypted data, evaluating the parsing efficiency of the evaluation engine at different time points; Y represents the time interval length of data parsing, used to control the timeliness of the analysis process; κ is the adjustment coefficient; E(y) is the parsing efficiency function of the encrypted data, reflecting the ability of the engine to parse and analyze data at time y; θ is the parsing precision control parameter, affecting the response speed of the engine to the parsing of high-frequency data; φ controls the periodic characteristics in the parsing process, and optimizes the parsing precision of data with different frequencies through the periodic regulation term of
Citation Information
Cited By
Implementation method of anti-quantum hybrid cryptographic optimization algorithm
CN121396434A
An anti-quantum mixing password optimization algorithm implementation method
CN121396434B
Data block encryption management system and method, electronic equipment and storage medium
CN121881388A
Data block encryption management system, method, electronic device and storage medium
CN121881388B
Electric power data classification encryption transmission method and system for intelligent terminal
CN121967087A