Big data auxiliary key generation method and system in communication data encryption transmission
Through multi-source heterogeneous data acquisition and dynamic entropy source processing, quantum-resistant entropy pools are generated. Combined with blockchain proof storage technology, the problem of insufficient key randomness and entropy source reliability is solved, efficient key negotiation and cross-domain communication are achieved, and the security and business continuity of communication data are ensured.
Patent Information
- Application Number
- CN202510611918.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, key randomness and entropy source reliability are insufficient, traditional PRNGs are susceptible to algorithm vulnerabilities, big data entropy sources may include predictable modes, key negotiation efficiency in dynamic environments, Diffie-Hellman protocol is too expensive in IoT device scenarios, and key synchronization is difficult in cross-domain communication.
A multi-source heterogeneous data acquisition module is used to collect network traffic characteristics, device behavior logs and environmental sensor data in real time, and a high random entropy pool is generated through a dynamic entropy source processing module. Combined with an anti-quantum key generation module and a hierarchical key negotiation module, blockchain evidence storage technology is used to realize traceability and periodic update of the key distribution path.
A quantum dynamic entropy pool is generated, which improves the randomness of keys and the reliability of entropy sources, realizes millisecond-level key negotiation efficiency, ensures communication security and business continuity, and adapts to key negotiation and cross-domain communication in dynamic environments.
Smart Images

Figure CN120342603A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data analysis and processing, and particularly to a big data-assisted key generation method and system for encrypted transmission of communication data. Background Art
[0002] With the rapid development of information technology, the security of communication data has become crucial. Whether it is personal privacy, business secrets, or national security, it depends on the confidentiality and integrity of communication data during transmission. Although traditional encryption methods can ensure data security to a certain extent, in the face of an increasingly complex network environment and continuously evolving attack methods, it is necessary to continuously improve and innovate key generation technologies to enhance the strength and reliability of encryption.
[0003] The rise of big data technology has provided new ideas and methods for key generation. Big data has characteristics such as massive volume, diversity, and rapid change, and contains rich information. By analyzing and mining big data, some features with randomness and unpredictability can be obtained, and these features can be used to generate keys, thereby increasing the complexity and security of keys.
[0004] However, there are still problems to be solved in the existing technologies: the randomness of keys and the reliability of entropy sources are insufficient, traditional PRNGs are vulnerable to algorithm vulnerabilities, big data entropy sources may contain predictable patterns, and complex cleaning and enhancement algorithms are required; the key negotiation efficiency in a dynamic environment is low, the Diffie-Hellman protocol has excessive computational overhead in the scenario of tens of thousands of Internet of Things devices, and key synchronization is difficult in cross-domain communication, such as the time delay difference in a satellite-ground hybrid network. Summary of the Invention
[0005] To solve the above technical problems, a big data-assisted key generation method and system for encrypted transmission of communication data are provided, and the technical solution solves the problems of insufficient randomness of keys and reliability of entropy sources and low key negotiation efficiency in a dynamic environment.
[0006] To achieve the above object, the technical solution adopted by the present invention is as follows: A big data-assisted key generation system for encrypted transmission of communication data, comprising: A multi-source heterogeneous data acquisition module: used to collect network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data in real time, and perform data aggregation through distributed nodes; A dynamic entropy source processing module: perform cleaning, decorrelation, and pattern elimination operations on the collected data, and combine an information entropy quantization model to generate a high-randomness entropy pool by using a Shannon entropy and minimum entropy fusion algorithm; A quantum-resistant key generation module: generate a dynamically variable-length key seed based on a post-quantum cryptographic algorithm driven by the entropy pool; Hierarchical Key Negotiation Module: Adopts a clustered Diffie-Hellman protocol, dynamically divides the negotiation domain according to the network topology, and reduces the core network load through edge node pre-computation; Lightweight Verification and Update Module: Achieves the traceability of the key distribution path through blockchain evidence storage technology, and triggers the periodic update of the key based on the network state.
[0007] Preferably, the dynamic entropy source processing module specifically includes: Data Preprocessing and Quality Enhancement Unit: Performs multi-modal data cleaning, identifies and filters abnormal data based on the Isolation Forest algorithm; normalizes heterogeneous data; adopts dynamic adaptive binning to smooth high-frequency jitter data; uses pattern elimination technology to identify hidden periodic patterns in the data through Fourier transform and LSTM prediction model; shuffles the time series correlation using the Fisher-Yates shuffle algorithm; Decorrelation and Entropy Enhancement Core Engine: Adopts decorrelation algorithms, including principal component analysis and independent component analysis; establishes an entropy fusion model, fuses Shannon entropy - minimum entropy with weights, compensates through Kolmogorov complexity, and injects a random bit stream based on chaotic mapping into low-entropy data segments to ensure that the overall entropy pool is greater than or equal to a predefined threshold.
[0008] Preferably, the dynamic entropy source processing module specifically includes: Anti-Interference and Real-Time Monitoring Unit: Real-time corrects the steady-state error in sensor data through Kalman filtering; performs frequency-domain filtering on high-frequency electromagnetic interference using wavelet threshold denoising; monitors the entropy quality, evaluates the quality of the entropy pool based on the NIST SP 800-90B standard; detects abnormal fluctuations in the entropy pool through a Markov chain model; Dynamic Adaptive Control Interface: Dynamically sets the outlier rejection boundary based on sliding window statistics; controls the chaos confusion depth according to the real-time quality of the entropy pool; balances resources and efficiency, enables PCA dimensionality reduction and lightweight chaos on edge devices; enables ICA + hyperchaos confusion in the cloud to support quantum security scenarios.
[0009] Preferably, the multi-source heterogeneous data acquisition module specifically includes: Data Source Classification and Dynamic Adaptation Unit: Constructs a classifier based on random forest and LSTM network, divides the data into high-entropy value sources, medium-entropy value sources, and low-entropy value sources; adaptively adjusts the acquisition frequency according to the network load and attack risk; Real-Time Streaming Data Acquisition Engine: Based on DPDK bypassing the kernel, achieves line-speed packet capture; embeds a lightweight Agent into the terminal device and uses zero-copy technology for transmission; based on LoRaWAN and MQTT protocols, achieves low-power wide-area acquisition; uses a sliding window to split the data stream and matches the key generation period; extracts the traffic frequency-domain characteristics in real-time through a hardware-level FFT chip; Privacy Protection and Compliance Control Unit: Hierarchical desensitization strategy. The strong desensitization layer performs homomorphic encryption on user identity information, and the weak desensitization layer adds Laplace noise to device behavior data; Cross-domain privacy isolation, using a federated learning pipeline to complete feature extraction before data aggregation and only transmit non-sensitive feature vectors; Using secure enclave technology to build a trusted execution environment based on Intel SGX to isolate the access rights of raw data.
[0010] Preferably, the multi-source heterogeneous data acquisition module specifically includes: Distributed node collaborative aggregation mechanism: Topology-aware routing, allocating node loads based on the Consistent Hashing algorithm and using the QUIC protocol to replace TCP; Using heartbeat detection to automatically switch backup nodes; Data sharding redundancy, storing data shards on multiple nodes through Reed-Solomon coding.
[0011] Preferably, the post-quantum key generation module specifically includes: Post-quantum algorithm engine: Lattice-based encryption, using the CRYSTALS-Kyber algorithm to generate public and private keys using the Module-LWE problem; Hash signature fusion, integrating the SPHINCS+ scheme to achieve post-quantum signature through a hash tree structure and form an encryption-signature double chain with Kyber; Entropy pool-driven mechanism, using the high-entropy bit stream output by the entropy pool as the random number seed for the Kyber algorithm; Generating a unique salt value based on the timestamp and device fingerprint; Dynamic key length adjustment unit: Threat awareness model, detecting abnormal quantum bit streams and evaluating the attack probability of the Shor / Grover algorithm through a traffic analysis model; Classical attack detection, monitoring the frequency of brute-force cracking attempts; Using an adaptive strategy, with low-risk mode, high-risk mode, and seamless switching; Key seed destruction and regeneration mechanism: Physically unclonable function, using SRAM PUF to generate a unique key for the device and erasing the physical state after each call; Optical quantum randomization, irradiating the storage unit with a quantum dot laser to achieve physical randomization coverage of key bits; Regeneration protocol, starting the regeneration process when the key usage times are greater than or equal to the established times or a memory sniffing attack is detected; Linking with the entropy pool module to re-inject entropy flow and generate a new seed; Anti-side-channel attack reinforcement layer: Clock randomization, inserting random clock delays during key generation; Asynchronous circuit design, based on a GALS hardware architecture; Using a masking technique to split the key seed into multiple shards and encrypt and store the shards independently; Through a Boolean permutation network, real-time disturbing the logic gate states of the key generation path.
[0012] Preferably, the hierarchical key negotiation module specifically includes: Dynamic Clustering and Topology Awareness Engine: Multi-dimensional clustering, dynamically dividing cluster groups based on device geographical location, communication latency, and security level; using the PBFT consensus algorithm to select highly reliable edge nodes as cluster heads; topology update mechanism, incremental update, only reclustering the topological change area; lightweight heartbeat protocol; Edge Pre-computation and Lightweight Negotiation Protocol: Parameter pre-generation, pre-computing the elliptic curve base point; establishing a temporary public key pool, pre-generating temporary public key-private key pairs; lightweight ECDH optimization, compressed point transmission, compressing the elliptic curve public key; simplifying zero-knowledge proof, using Schnorr signature to replace traditional RSA; Cross-cluster Key Synchronization and Anti-destruction Mechanism: Hierarchical key derivation, master key derivation, cluster heads negotiate the global master key through threshold signature; sub-key derivation, based on the HKDF-HMAC-SHA3 algorithm, deriving sub-cluster session keys from the master key; anti-destruction strategy, multi-path redundancy, each cluster head maintains multiple cross-cluster communication paths, automatically switching when a single path fails; fragmented key storage, sharding the master key and storing it on multiple edge nodes; Security and Efficiency Monitoring Unit: Threat detection, identifying man-in-the-middle attacks, detecting MITM attacks based on traffic characteristics and timestamp deviation; replay attack defense, binding a unique Nonce value to each session key, rejecting repeated requests; edge load balancing, dynamically allocating pre-computation tasks according to CPU / memory utilization.
[0013] Preferably, the lightweight verification and update module specifically includes: Blockchain Evidence Storage and Traceability Engine: Hybrid chain architecture, storing core metadata on a private chain, anchoring summaries on a public chain, uploading the data fingerprint of the private chain to Ethereum and Polkadot through Merkle Root; lightweight evidence storage optimization, IPFS sharding storage, zero-knowledge proof compression, using zk-SNARKs to generate evidence integrity proofs; homomorphic encryption logs, encrypting sensitive fields using the Paillier algorithm, supporting ciphertext retrieval; dynamic desensitization strategy: filtering sensitive information in real-time according to the visitor's identity; Network Status Awareness and Key Update Trigger: Multi-dimensional monitoring metrics, basic metrics including latency, packet loss rate, node online rate, security metrics including DDoS attack traffic characteristics, quantum channel interference intensity; intelligent trigger strategy, threshold-driven including preset dynamic thresholds, combining the LSTM prediction model to predict risks, event-driven including forced update when a key leakage event is detected; seamless switching protocol, using a double-buffered key pool, ensuring uninterrupted communication during the switch; edge collaborative distribution, distributing new keys by edge nodes nearby; Lightweight Verification and Synchronization Protocol: lattice-based lightweight signature, using the Falcon-512 algorithm, pruning Merkle trees to verify only branches related to the key path; incremental synchronization mechanism, differential synchronization protocol, transmitting differential data of key changes through the COAP protocol, automatically merging multi-version key states based on CRDT; anti-attack reinforcement, embedding hash time locks in key update requests, physically unclonable binding, binding keys to device PUF fingerprints. Compliance Audit and Self-Healing Interface: automated audit engine, setting up a compliance rule library, built-in GDPR and CCPA regulations, automatically detecting the compliance of key storage locations and access logs; intelligent report generation, outputting audit reports through NLG technology, supporting one-click submission to regulatory agencies; self-healing mechanism, key fragment regeneration, when a key is detected to be damaged, recovering fragments from distributed storage nodes; blockchain rollback protection, anti-tampering logs based on PBFT consensus; API open platform, providing RESTful APIs for third-party audit tools to access, cross-chain interoperability, synchronizing compliance evidence of other chains through the Polkadot cross-chain protocol.
[0014] Furthermore, a big data-assisted key generation method for encrypted transmission of communication data, used to implement the big data-assisted key generation system for encrypted transmission of communication data as described above, includes: Real-time collecting network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data through distributed nodes, and dynamically adjusting the collection frequency based on the entropy quality weight factor; Performing decorrelation, pattern elimination, and Shannon entropy-minimum entropy fusion calculation on the collected data to generate a dynamically updated anti-quantum entropy pool; Driving a post-quantum cryptographic algorithm based on the entropy pool to generate a key seed of variable length; Dynamically dividing negotiation domains according to the network topology, pre-computing elliptic curve multiple point parameters through edge nodes to achieve clustered Diffie-Hellman negotiation; Using blockchain evidence storage technology to record the key distribution path, and triggering periodic key updates based on the quantum channel state perception result.
[0015] Optionally, the performing decorrelation, pattern elimination, and Shannon entropy-minimum entropy fusion calculation on the collected data to generate a dynamically updated anti-quantum entropy pool specifically includes: Selecting high-entropy candidate sources for data sources including environmental noise, user interaction behavior, and device hardware fingerprints, and low-entropy auxiliary sources including network protocol packets and sensor periodic data; dynamic collection strategy, adjusting the sampling frequency according to the entropy quality weight factor; Nonlinear decorrelation pipeline, using principal component analysis, independent component analysis, and mutual information pruning; Pattern detection and elimination, identifying periodic signals through Fourier transform, and superimposing the Chen hyperchaotic sequence to disrupt the pattern; adding Laplace noise to geographical location data to satisfy differential privacy; predicting user behavior patterns using LSTM and injecting Poisson distribution random events for interference; Autocorrelation function monitoring, triggering secondary confusion if the ACF peak is greater than a predefined threshold; dynamic noise intensity, reducing the ϵ value to a predefined threshold when a side-channel attack is detected; Dual-entropy dynamic fusion model, calculating Shannon entropy and minimum entropy, and then performing dynamic weighted fusion; achieving low-entropy compensation through sliding window detection and entropy pool reorganization.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention proposes to generate an anti-quantum dynamic entropy pool by fusing high-entropy sources such as environmental noise, user behavior, and device hardware fingerprints with low-entropy sources such as network packets and sensor data, and combining intelligent acquisition strategies and non-linear decorrelation techniques (PCA, chaotic interference). This process completely eliminates data periodicity, redundancy, and correlation, significantly improves the quality of randomness, and ensures the unpredictability and anti-quantum attack ability of the key seed.
[0017] Based on the post-quantum cryptographic algorithm driven by the dynamic entropy pool, variable-length key seeds are generated, and the negotiation domain is dynamically divided according to the network topology. The edge nodes pre-compute the elliptic curve parameters to achieve millisecond-level clustered key negotiation, breaking through the efficiency bottleneck of traditional centralized solutions.
[0018] Construct a hybrid chain architecture, where the private chain stores metadata, the public chain anchors the tamper-proof digest, and combined with zero-knowledge proof compression technology, it realizes the trustworthy traceability of the entire key life cycle. Trigger the dynamic update mechanism through quantum channel state perception (bit error rate, photon fluctuation), support seamless switching of the dual-buffer key pool, and ensure business continuity. Description of the Drawings
[0019] Figure 1 It is the internal framework diagram of the big data-assisted key generation system for encrypted communication data transmission; Figure 2 It is the internal framework diagram of the dynamic entropy source processing module; Figure 3 It is the flowchart of the big data-assisted key generation method for encrypted communication data transmission. Detailed Embodiments
[0020] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art can think of other obvious variations.
[0021] Refer to Figure 1As shown in the figure, a big data-assisted key generation system for encrypted transmission of communication data includes: Multi-source heterogeneous data acquisition module: It is used to collect network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data in real time, and converge the data through distributed nodes; Dynamic entropy source processing module: It performs cleaning, decorrelation, and pattern elimination operations on the collected data. Combining with the information entropy quantization model, it uses the Shannon entropy and minimum entropy fusion algorithm to generate a high-randomness entropy pool; Post-quantum key generation module: Based on the entropy pool-driven post-quantum cryptography algorithm, it generates a key seed with a dynamically variable length; Hierarchical key negotiation module: It adopts the clustered Diffie-Hellman protocol, dynamically divides the negotiation domain according to the network topology, and reduces the core network load through edge node pre-computation; Lightweight verification and update module: It realizes the traceability of the key distribution path through blockchain deposit technology, and triggers the periodic update of the key based on the network state.
[0022] It should be noted that there is a data-entropy pool linkage. The multi-source data acquisition module provides real-time input for the dynamic entropy source processing module. At the same time, the entropy pool quality is fed back to the acquisition module to dynamically adjust the data source weight; Key-negotiation optimization. The length of the key seed output by the post-quantum key generation module is dynamically adjusted by the hierarchical key negotiation module according to the network topology complexity; Blockchain-network awareness. The blockchain deposit data of the lightweight verification module is synchronized to the dynamic entropy source processing module in real time for detecting abnormal distribution behavior.
[0023] The threat response strategies include: Quantum attack detection. When the photonic crystal sensor detects an abnormal quantum channel, it triggers the post-quantum key generation module to switch to the NTRU Prime algorithm and starts a full key update; Network attack disaster tolerance. The hierarchical key negotiation module supports the "cluster head-backup cluster head" dual-active mechanism.
[0024] Refer to Figure 2 As shown in the figure, the dynamic entropy source processing module includes: Data preprocessing and quality enhancement unit: Multi-modal data cleaning, identifying and filtering abnormal data based on the isolation forest algorithm; normalizing heterogeneous data; using dynamic adaptive binning to smooth high-frequency jitter data; using pattern elimination technology to identify hidden periodic patterns in the data through Fourier transform and LSTM prediction model; using the Fisher-Yates shuffle algorithm to disrupt the temporal correlation; Decorrelation and Entropy Enhancement Core Engine: Adopt decorrelation algorithms, including principal component analysis and independent component analysis; establish an entropy fusion model, fuse Shannon entropy and minimum entropy with weights, compensate through Kolmogorov complexity, and inject a random bit stream based on chaotic mapping into low-entropy data segments to ensure that the overall entropy pool is greater than or equal to a predefined threshold; Anti-interference and Real-time Monitoring Unit: Through Kalman filtering, real-time correct the steady-state error in sensor data; adopt wavelet threshold denoising for frequency-domain filtering of high-frequency electromagnetic interference; entropy quality monitoring, evaluate the quality of the entropy pool based on the NIST SP 800-90B standard; detect abnormal fluctuations in the entropy pool through a Markov chain model; Dynamic Adaptive Control Interface: Dynamically set the outlier rejection boundary based on sliding window statistics; control the depth of chaotic confusion according to the real-time quality of the entropy pool; resource-efficiency balance, enable PCA dimensionality reduction and lightweight chaos on edge devices; enable ICA + hyperchaotic confusion in the cloud to support quantum security scenarios.
[0025] It should be noted that the data preprocessing and quality enhancement unit includes: Isolation Forest Algorithm Optimization, adopt dynamic subtree depth control (depth = 15), and jointly detect network traffic characteristics such as burst traffic spikes and device behavior logs such as abnormal login frequencies; Multi-modal Fusion Cleaning, perform spatio-temporal alignment on the temperature and humidity of sensor data and the touch screen trajectory of user interaction data, and eliminate cross-modal conflict data, such as a sudden increase in environmental temperature but no user operation record; Dynamic Adaptive Binning Smoothing: Binning granularity control, dynamically adjust the bin width according to the data jitter frequency, such as high-frequency noise of sensors caused by electromagnetic interference, and the variance of the smoothed data is reduced by 80%; Edge optimization implementation, deploy a lightweight binning algorithm on the RISC-V chip; Frequency-domain - Time-domain Dual Elimination: Fourier Transform, identify periodic signals, such as the device heartbeat packet period T = 1s ± 0.2s, and the cut-off frequency component > 10Hz; LSTM Prediction Adversary, generate adversarial noise through time series prediction (window size = 64) to disrupt the attacker's speculation on the data trend; Temporal Correlation Elimination, Fisher-Yates Shuffle Enhancement, perform random permutation within a 256-bit block, and the permutation seed is provided by a quantum random number generator.
[0026] The decorrelation and entropy enhancement core engine includes: PCA-ICA Hybrid Pipeline, PCA Dimensionality Reduction: Eliminate linear correlations, such as the linear correlation of temperature and humidity sensors, and retain the principal components with 95% variance; ICA Blind Source Separation: Separate independent signal sources in concurrent device operations, such as multi-user concurrent instruction aliasing; Quantum Security Extension: Use lattice-based random projection to prevent quantum algorithms from reverse-deriving original data; Dual-Entropy Dynamic Weighting Formula: In the formula, is the fused entropy value; is the weight factor, and its value range is between [0.3, 0.7]; is the Shannon entropy, a measure of information entropy used to measure the uncertainty of information; is the minimum entropy, another measure of information entropy, usually used to measure the orderliness of information; Weight Dynamic Adjustment, based on the PPO algorithm of the reinforcement learning model, optimize the α value in real time, response time < 2ms; Kolmogorov Compensation, when the complexity K of the data segment Kolmogorov < 0.6, inject the random bit stream generated by the Chebyshev chaotic map (cycle length > 10^10); Chaotic Enhancement Mechanism, generation of hyperchaotic sequences, using an improved Chen system (parameters a = 35, b = 3, c = 28, d = -7), Lyapunov exponent > 0.5 to ensure unpredictability; Edge-Cloud Collaborative Confusion, perform lightweight Logistic chaos at the edge (iteration times = 100), and perform hyperchaotic confusion at the cloud (iteration times = 1000).
[0027] The anti-interference and real-time monitoring unit includes: Entropy Quality Monitoring System, NIST SP 800-90B test, deploy lightweight test suites at the edge; Markov Chain Anomaly Detection, construct a three-state (normal / warning / anomaly) Markov model to detect entropy pool fluctuations, such as a single-step transition probability mutation > 50%; Real-time Feedback Control, multi-threshold linkage, when the entropy value H Fused < 0.9 and the Markov state is "anomaly", trigger full-pool reconstruction; Quantum Random Number Emergency Injection, call satellite QRNG through the space-ground quantum communication network, and inject ≥1024 bits each time.
[0028] The dynamic adaptive control interface includes: Sliding Window Statistics, the window size is dynamically adjusted (64~1024 samples), and the outlier rejection boundary is set to μ ± 3σ (μ is the mean, σ is the standard deviation); Chaotic Confusion Depth Control, dynamically adjust the chaotic iteration times according to the entropy pool quality (50~200 times at the edge, 500~1000 times at the cloud); Edge lightweighting, enabling PCA dimensionality reduction (retaining 85% variance) and Logistic chaos (iteration = 100 times) on IoT devices, with memory occupancy < 10MB; High performance in the cloud, deploying ICA + hyperchaotic confusion (iteration = 1000 times), supporting quantum-resistant security scenarios such as e-government encrypted communication.
[0029] Post-quantum algorithm interface, supporting seamless switching between CRYSTALS-Kyber and SIKE algorithms; anti-storage attack design, with entropy pool sharding encryption storage, keys generated by device PUF, and physical theft being ineffective.
[0030] The multi-source heterogeneous data acquisition module includes: Data source classification and dynamic adaptation unit: Construct a classifier based on random forest and LSTM network, dividing data into high-entropy value sources, medium-entropy value sources, and low-entropy value sources; adaptively adjust the acquisition frequency according to network load and attack risk; Real-time streaming data acquisition engine: Based on DPDK bypassing the kernel to achieve line-speed packet capture; embedded in terminal devices through lightweight Agent, using zero-copy technology for transmission; based on LoRaWAN and MQTT protocols to achieve low-power wide-area acquisition; using a sliding window to segment the data stream and match the key generation period; through a hardware-level FFT chip, real-time extraction of traffic frequency-domain features; Privacy protection and compliance control unit: Hierarchical desensitization strategy, with the strong desensitization layer performing homomorphic encryption on user identity information, and the weak desensitization layer adding Laplace noise to device behavior data; cross-domain privacy isolation, using a federated learning pipeline to complete feature extraction before data aggregation and only transmit non-sensitive feature vectors; using secure enclave technology to build a trusted execution environment based on Intel SGX to isolate the access rights of raw data; Distributed node collaborative aggregation mechanism: Topology-aware routing, distributing node loads based on the Consistent Hashing algorithm, using the QUIC protocol to replace TCP; using heartbeat detection to automatically switch backup nodes; data sharding redundancy, storing data shards in multiple nodes through Reed-Solomon coding.
[0031] It should be noted that the intelligent classification model includes: Random forest-LSTM fusion architecture: Random forest processes structured data, including network protocol fields and sensor values, and filters key features through the Gini coefficient, including traffic burstiness and device CPU occupancy rate; the LSTM network analyzes time-series data, including user interaction behavior sequences and traffic periodic fluctuations, to capture long-term dependencies (window length = 64 time steps); Dynamic entropy value determination, jointly calculated based on Shannon entropy and Kolmogorov complexity, with the formula E = 0.6HShannon + 0.4KKolmogorov; Adaptive acquisition strategy, risk-load linkage control: Network load awareness, dynamically adjusting the acquisition frequency according to the size of the TCP congestion window, high-frequency acquisition under light load, and reducing the frequency to 50% under heavy load; Attack risk response, when a DDoS attack is detected, the acquisition of low-entropy sources is suspended, and the continuity of high-entropy sources is prioritized.
[0032] The real-time streaming data acquisition engine includes: Ultra-high-speed packet capture technology, DPDK bypassing the kernel, bypassing the operating system protocol stack, with a single-machine throughput of 100 Gbps (measured by Intel Sapphire Rapids); zero-copy transmission, directly writing to the GPU video memory through RDMA, reducing the latency to 0.1 μs; Wide-area low-power acquisition, LoRaWAN-MQTT collaboration: Remote nodes: The LoRaWAN (868 MHz band) has a coverage radius of 10 km and a power consumption of < 100 μW; Proximal nodes: MQTT over 5G NR-U (unlicensed band), with an air interface latency of < 5 ms.
[0033] Hardware acceleration processing, real-time analysis by the FFT chip, integrating the Analog Devices ADI-FFT-2025 chip, with a 1024-point FFT calculation time of < 50 ns; frequency domain feature extraction to identify traffic burst patterns, such as the spectral differences between video streams and IoT heartbeat packets.
[0034] The privacy protection and compliance control unit includes: Hierarchical desensitization strategy: Strong desensitization layer: User identity information is encrypted homomorphically using Paillier (key length 3072 bits), supporting ciphertext calculation; weak desensitization layer: Laplace noise (ϵ = 0.1, δ = 10−5) is added to device behavior data to meet GDPR requirements.
[0035] Federated learning pipeline: Feature extraction is pre-positioned, PCA dimensionality reduction is performed at the edge node (retaining 90% of the variance), and only non-sensitive feature vectors (dimension ≤ 32) are transmitted; secure aggregation protocol, based on multi-party secure computing, to prevent the central node from snooping on the original data.
[0036] The distributed node collaborative aggregation mechanism includes: Topology-aware routing, optimized by consistent hashing, with the number of virtual nodes = 1024 and a load balancing deviation of < 5%; Advantages of the QUIC protocol, multiplexing + 0-RTT handshake, with a 70% reduction in latency compared to TCP.
[0037] Disaster tolerance and recovery mechanism, heartbeat detection, sending heartbeat packets every 200 ms, triggering node switching after 3 timeouts; Backup node hot standby: Adopting a "one master and two backups" architecture, with a switching time < 50 ms.
[0038] Data sharding redundancy, Reed-Solomon coding, number of shards = 12, fault tolerance = 4 shards, 60% reduction in storage overhead; Quantum-resistant storage, with shard encryption keys generated by post-quantum algorithms.
[0039] The anti-quantum key generation module specifically includes: Post-quantum algorithm engine: lattice-based encryption, using the CRYSTALS-Kyber algorithm, generating public and private keys using the Module-LWE problem; Hash signature fusion, integrating the SPHINCS+ scheme, achieving anti-quantum signatures through a hash tree structure, forming an encryption-signature double chain with Kyber; Entropy pool drive mechanism, using the high-entropy bit stream output by the entropy pool as the random number seed for the Kyber algorithm; Generating a unique salt value based on the timestamp and device fingerprint; Dynamic key length adjustment unit: Threat perception model, detecting abnormal quantum bit streams and evaluating the attack probability of the Shor / Grover algorithm through a traffic analysis model; Classic attack detection, monitoring the frequency of brute-force cracking attempts; Adopting an adaptive strategy, with low-risk mode, high-risk mode, and seamless switching; Key seed destruction and regeneration mechanism: Physically unclonable function, generating a device-unique key using SRAM PUF and erasing the physical state after each call; Optical quantum randomization, irradiating the storage unit with a quantum dot laser to achieve physical randomization coverage of key bits; Regeneration protocol, starting the regeneration process when the key usage times are greater than or equal to the established number of times or a memory sniffing attack is detected; Linking with the entropy pool module to re-inject entropy flow and generate a new seed; Anti-side-channel attack reinforcement layer: Clock randomization, inserting random clock delays during key generation; Asynchronous circuit design, based on a GALS hardware architecture; Adopting a masking technique, splitting the key seed into multiple shards and encrypting and storing the shards independently; Through a Boolean permutation network, real-time disturbing the logic gate states of the key generation path.
[0040] It should be noted that the post-quantum algorithm engine includes: Double-chain encryption-signature architecture, CRYSTALS-Kyber encryption chain, based on the Module-LWE problem, with parameter selection of Kyber1024 (security level ≥ 256 bits), public key size 1.6 KB, and ciphertext expansion rate 3.2 times; Entropy pool driven, the 2560-bit high-entropy stream output by the entropy pool is extracted by SHAKE-256 to generate the Kyber random number seed, and the residual predictability < 10⁻¹²; Salt value generation: The timestamp and the device PUF fingerprint are hashed by BLAKE3 to generate a unique salt value to prevent rainbow table attacks.
[0041] SPHINCS+ signature chain, using FORS and XMMS hash tree structures, the signature length is 15KB, and the quantum collision resistance ability reaches 2¹² 8 ; Forms an "encryption-signature double chain" with Kyber, and cracking requires simultaneously breaking the LWE problem and the hash preimage problem.
[0042] Dynamic parameter switching, when a quantum channel anomaly is detected, such as a photon number statistical deviation, it automatically switches to Kyber1536 (security level 384 bits), and the delay increase ≤ 8ms.
[0043] The dynamic key length adjustment unit includes: Quantum bit stream monitoring, counting the number of photons in the quantum channel through a single-photon detector. If the fluctuation > 3σ (standard deviation) and conforms to the characteristics of the Shor algorithm, it triggers the high-risk mode; Grover algorithm identification, monitoring the compression rate of the key search space, and when the decrease > 50%, it is determined as an omen of Grover attack.
[0044] Classical attack detection, brute-force cracking defense, counting the frequency of authentication failures (threshold = 5 times / second). After exceeding the limit, enable the "challenge-response" mechanism to generate dynamic tokens based on PUF.
[0045] Adaptive mode switching: Low-risk mode (default): The key length is 256 bits, Kyber1024 algorithm, and the delay ≤ 10ms; High-risk mode: The key length is 512 bits, Kyber1536+SPHINCS+ dual verification, and the delay ≤ 30ms; Seamless switching protocol: Adopting a dual-buffer design, the old and new keys take effect in parallel for 5 seconds to ensure business continuity.
[0046] The key seed destruction and regeneration mechanism includes: Physical unclonability guarantee, the SRAM PUF uses the SRAM startup state entropy to generate a 256-bit device-unique key; optical quantum coverage, the quantum dot laser (wavelength = 850nm) irradiates the storage unit to realize the quantum tunneling randomization of bit positions, and the residual data recovery probability < 10⁻¹ 5 。
[0047] Regeneration trigger conditions: Usage times threshold: single key usage ≥ 10,000 times (based on NIST SP 800-57 standard); Attack events: Detect traces of Rowhammer attack or cold boot attack (abnormal memory voltage fluctuation > 5%).
[0048] Regeneration process, entropy pool linkage, extract 4096-bit new seeds from the high-entropy pool, and inject them after passing the NIST SP 800-90B test; salt value reconstruction, generate a new salt value after chaotic confusion of the timestamp and PUF fingerprint, confusion depth = 1000 iterations.
[0049] The side-channel attack resistant reinforcement layer includes: Timing randomization: Insert clock jitter, insert random delays (range = 10 - 100 ns) in the key generation critical path (such as modular exponentiation) to disrupt the power consumption / electromagnetic side-channel synchronization; GALS asynchronous architecture, global asynchronous local synchronous circuit, eliminate clock edge information leakage.
[0050] Spatial confusion technology, Boolean permutation network, dynamically change the connection relationship of logic gates (permutation frequency = 1 MHz), making it impossible for attackers to locate the critical signal path; masked shard storage, split the key into 3 shards, and encrypt and store them in SRAM, MRAM, and ReRAM respectively. A single shard leakage cannot restore the complete key.
[0051] Electromagnetic shielding design, multi-layer metal shielding cover, attenuate electromagnetic radiation > 60 dB (frequency band 1 MHz - 10 GHz); frequency scrambling transmitter, actively emit pseudo-random electromagnetic noise to cover the characteristics of real signals.
[0052] The hierarchical key negotiation module specifically includes: Dynamic clustering and topology awareness engine: multi-dimensional clustering, dynamically divide cluster groups based on device geographical location, communication delay, and security level; use the PBFT consensus algorithm to select highly reliable edge nodes as cluster heads; topology update mechanism, incremental update, only re-cluster the topology change area; lightweight heartbeat protocol; Edge pre-computation and lightweight negotiation protocol: parameter pre-generation, pre-compute the elliptic curve base point; establish a temporary public key pool, pre-generate temporary public key-private key pairs; lightweight ECDH optimization, compressed point transmission, compress the elliptic curve public key; zero-knowledge proof simplification, use Schnorr signature to replace traditional RSA; Cross-cluster Key Synchronization and Anti-destruction Mechanism: Hierarchical key derivation, master key derivation, cluster heads negotiate the global master key through threshold signature; sub-key derivation, based on the HKDF-HMAC-SHA3 algorithm, derive the sub-cluster session key from the master key; anti-destruction strategy, multi-path redundancy, each cluster head maintains multiple cross-cluster communication paths and automatically switches when a single path fails; fragmented key storage, fragment the master key and store it in multiple edge nodes; Security and Performance Monitoring Unit: Threat detection, identify man-in-the-middle attacks, detect MITM attacks based on traffic characteristics and timestamp deviation; replay attack defense, each session key is bound to a unique Nonce value to reject repeated requests; edge load balancing, dynamically allocate pre-computation tasks according to CPU / memory utilization.
[0053] It should be noted that the dynamic clustering and topology awareness engine includes: Multi-dimensional clustering criteria include geographical distance. Based on Beidou-4 sub-meter positioning, ensure that the physical distance between nodes in the same cluster ≤ 1km; communication delay, require end-to-end delay ≤ 1ms under 6G network (URLLC ultra-reliable low-latency communication); security level, weighted clustering based on device authentication level, and high-risk nodes are isolated independently.
[0054] PBFT Consensus Optimization: Introduce a reputation scoring mechanism (historical response rate, encryption strength), with the reputation weight accounting for 70% and computing power accounting for 30% when electing cluster heads; support PBFT consensus delay < 5ms under ten-thousand-level nodes.
[0055] Incremental Topology Update: Local reconstruction strategy, only re-cluster the area where nodes are added or deleted / link quality fluctuation > 20%, reducing network overhead by 80%; lightweight heartbeat protocol, send an 8-byte heartbeat packet every 50ms, and trigger re-election of cluster heads when the timeout occurs 3 times, with a fault tolerance rate > 99.9%.
[0056] Edge Pre-computation and Lightweight Negotiation Protocol include: Forward Computation Resources: Elliptic curve pre-computation, cache the secp521r1 curve base point multiple point parameters ({2 i G}) in edge nodes, reducing the scalar multiplication time from 15ms to 0.5ms; temporary public key pool, pre-generate 100 groups of public-private key pairs (ECDSA / secp256k1), with the key pool refresh period = 10 minutes and the single-call delay < 0.1ms.
[0057] Lightweight Protocol Design: Compressed point transmission, compress the public key coordinates (x, y) into the x coordinate + sign bit (saving 50% bandwidth), compatible with the IEEE 1363a standard; Schnorr signature optimization, with a signature length of 64 bytes and a 40% increase in verification speed (measured on RISC-V).
[0058] Quantum-resistant expansion, dual-algorithm support, default use of ECDH-521, seamlessly switches to SIKEp751 when a quantum attack is detected.
[0059] The cross-cluster key synchronization and anti-destruction mechanism includes: Hierarchical key derivation system: Master key negotiation: 5 cluster heads generate a global key through (t,n)=(3,5) threshold signature (EdDSA algorithm), and it requires breaking ≥3 physically isolated nodes simultaneously to crack; Sub-key derivation: Generates a session key (256 bits) based on HKDF-HMAC-SHA3-512, with quantum collision resistance > 2¹² 8 。
[0060] Path selection algorithm, primary path: shortest delay (6G millimeter-wave direct connection); backup path: satellite relay (Starlink V3 satellite delay 25ms); failover: path fault detection time < 10ms, switching time < 5ms (QUIC protocol multiplexing).
[0061] Fragmentation algorithm, using Shamir secret sharing (number of fragments = 5, threshold = 3), fragments are encrypted and stored in the edge node TEE environment; quantum erasure, quantum dot laser coverage is immediately triggered after fragment access, and the residual data recovery probability < 10⁻¹ 8 。
[0062] The lightweight verification and update module specifically includes: Blockchain evidence storage and traceability engine: Hybrid chain architecture, private chain stores core metadata, public chain anchors the digest, and the data fingerprint of the private chain is uploaded to Ethereum and Polkadot through Merkle Root; lightweight evidence storage optimization, IPFS sharding storage, zero-knowledge proof compression, using zk-SNARKs to generate evidence integrity proofs; homomorphic encryption logs, encrypting sensitive fields using the Paillier algorithm, supporting ciphertext retrieval; dynamic desensitization strategy: real-time filtering of sensitive information according to the identity of the visitor; Network status awareness and key update trigger: Multi-dimensional monitoring metrics, basic metrics include latency, packet loss rate, node online rate, and security metrics include DDoS attack traffic characteristics, quantum channel interference intensity; intelligent trigger strategy, threshold-driven includes preset dynamic thresholds, combined with the LSTM prediction model to predict risks, event-driven includes forced update when a key leakage event is detected; seamless switching protocol, using a dual-buffer key pool, communication does not interrupt during switching; edge collaborative distribution, new keys are distributed by edge nodes nearby; Lightweight Verification and Synchronization Protocol: lattice-based lightweight signature, using the Falcon-512 algorithm, pruning the Merkle tree, and only verifying the branches related to the key path; incremental synchronization mechanism, differential synchronization protocol, transmitting key change differential data through the COAP protocol, and automatically merging multi-version key states based on CRDT; anti-attack reinforcement, embedding a hash time lock in the key update request, physically unclonable binding, and binding the key to the device PUF fingerprint. Compliance Audit and Self-Healing Interface: automated audit engine, setting up a compliance rule library, embedding GDPR and CCPA regulations, automatically detecting the compliance of key storage locations and access logs; intelligent report generation, outputting audit reports through NLG technology, supporting one-click submission to regulatory agencies; self-healing mechanism, key fragment regeneration, when a key is detected to be damaged, restoring fragments from distributed storage nodes; blockchain rollback protection, tamper-proof logs based on PBFT consensus; API open platform, providing RESTful APIs for third-party audit tools to access, cross-chain interoperability, and synchronizing compliance evidence from other chains through the Polkadot cross-chain protocol.
[0063] It should be noted that the blockchain evidence storage and traceability engine includes: Hybrid Chain Architecture Design: private chain, storing key metadata such as generation time and device fingerprint, achieving high throughput (100,000 TPS) using Hyperledger Fabric; Public Chain Anchoring, regularly uploading the private chain data fingerprint to Ethereum (every 5 minutes) and Polkadot (cross-chain verification).
[0064] IPFS Sharded Storage, sharding key logs into 128KB blocks, redundantly storing them on global edge nodes, with retrieval latency < 50ms; zk-SNARKs Compression, compressing the size of the evidence integrity proof to 1 / 100 of the traditional scheme (only 288 bytes).
[0065] Paillier Homomorphic Encryption, supporting ciphertext retrieval such as "the number of times a device key is generated", with ciphertext operation error < 10⁻¹ 5 ; Dynamic Data Masking, according to the visitor's role such as auditor / operator, real-time masking of sensitive fields such as PUF fingerprint, meeting the GDPR minimization principle.
[0066] Network Status Awareness and Key Update Trigger Include: Multi-Dimensional Monitoring System: Basic Metrics, latency (6G URLLC requirement ≤ 1ms), packet loss rate (threshold < 0.001%), node online rate (99.99% SLA); Security indicators, DDoS attack traffic identification (based on CNN model, accuracy > 99%), quantum channel interference detection (photon number fluctuation > 3σ).
[0067] Intelligent trigger strategy, threshold - event dual - drive: The LSTM prediction model predicts risks. For example, if the attack probability within the next 10 seconds > 30%, the key update is triggered in advance; for key leakage events such as memory sniffing traces, a forced update is triggered.
[0068] Seamless switching and distribution, dual - buffer key pool, the old and new keys take effect in parallel for 5 seconds, supporting seamless switching for millions of terminals; edge - collaborative distribution, edge nodes cache high - frequency keys, and the distribution delay < 2ms (5G millimeter - wave coverage).
[0069] Refer to Figure 3 As shown, in the big - data - assisted key generation method for encrypted transmission of communication data, it includes: Real - time collection of network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data through distributed nodes, and dynamically adjusting the collection frequency based on the entropy quality weight factor; Perform decorrelation, pattern elimination, and Shannon entropy - minimum entropy fusion calculation on the collected data to generate a dynamically updated anti - quantum entropy pool; Based on the entropy pool, drive the post - quantum cryptography algorithm to generate variable - length key seeds; Dynamically divide the negotiation domain according to the network topology, and pre - calculate the elliptic curve multiple point parameters through edge nodes to achieve clustered Diffie - Hellman negotiation; Adopt blockchain evidence - storing technology to record the key distribution path, and trigger the periodic key update based on the quantum channel state perception result.
[0070] It should be noted that for the distributed intelligent acquisition system, data source classification: Network traffic characteristics: Extract packet - length distribution, protocol type, burst traffic pattern, such as the pulse characteristics under DDoS attacks; Device behavior logs: Analyze CPU / memory fluctuations, abnormal login frequency, threshold > 5 times / minute; Environmental sensor data: Temperature / humidity, electromagnetic interference intensity (> 3σ fluctuation triggers an alarm); User interaction behavior: Touch - screen trajectory entropy value, biometric features, such as dynamically modeling fingerprint pressing force.
[0071] Entropy quality weight factor: In the formula, is the entropy quality weight factor of the i - th data segment; is the i - th data segment The Shannon entropy, which is used to measure the uncertainty of the data segment; is the i-th data segment The Kolmogorov complexity, which is used to measure the minimum amount of information required to describe the data segment; is the sum of the products of the Shannon entropy and the Kolmogorov complexity of all data segments, where n is the total number of data segments, and are the Shannon entropy and the Kolmogorov complexity of the j-th data segment respectively; Dynamically adjust the acquisition frequency (100Hz - 1kHz), and high-entropy sources (such as quantum noise) are preferentially acquired.
[0072] Quantum-resistant entropy pool generation, decorrelation and pattern elimination: Principal component analysis to eliminate the linear correlation of temperature and humidity sensors (correlation coefficient < 0.01); LSTM adversarial network to predict and eliminate periodic patterns, such as the device heartbeat packet period T = 1s ± 0.1sT.
[0073] Entropy-driven key generation, enhanced by CRYSTALS-Kyber, with dynamic adjustment of the key seed length (256 - 512 bits), and switch to 512 bits according to the quantum channel bit error rate (BER > 10⁻ 6 when switching to 512 bits); The output of the entropy pool is injected into the Kyber random number generator after being extracted by SHA-3, and the residual predictability < 10⁻¹ 5 .
[0074] Design against storage attacks, the key seed is sharded and stored in SRAM PUF and quantum random overwrite memory, and physical theft is ineffective.
[0075] In summary, the advantages of the present invention are as follows: By integrating high-entropy sources such as quantum noise, user behavior, and device hardware, combining hyperchaotic interference and dual-entropy fusion technology, a dynamic quantum-resistant entropy pool is generated, eliminating the periodic correlation of data, improving the quality of randomness, and providing an unpredictable entropy source basis for keys; Based on the entropy pool-driven post-quantum cryptography algorithm, it supports the dynamic generation of variable-length keys, combines 6G edge pre-computation and topology-aware clustering to achieve millisecond-level key negotiation, greatly improving efficiency and adapting to high-speed mobile and ultra-low latency scenarios; uses a hybrid chain architecture to achieve trusted storage and proof of the entire life cycle of keys, and zero-knowledge proof compression technology significantly reduces the verification overhead. Through quantum channel state awareness and dual-buffer key pool, trigger dynamic seamless update to ensure zero business interruption and real-time response to quantum-resistant attacks; integrate differential privacy noise injection, hardware PUF binding and anti-side-channel noise coverage to form a physical-algorithm double-layer protection. The automated compliance engine dynamically adapts to multi-country regulations, generates audit reports, and meets privacy protection and regulatory requirements.
[0076] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and these changes and improvements fall within the scope of the present invention claimed. The scope of protection required by the present invention is defined by the appended claims and their equivalents.
Claims
1. A big data-assisted key generation system for encrypted transmission of communication data, characterized in that Including: Multi-source heterogeneous data acquisition module: used to collect network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data in real time, and aggregate data through distributed nodes; Dynamic entropy source processing module: performs cleaning, decorrelation, and pattern elimination operations on the collected data, combines the information entropy quantization model, and uses the Shannon entropy and minimum entropy fusion algorithm to generate a high-randomness entropy pool; Post-quantum key generation module: generates key seeds with dynamic variable lengths based on the entropy pool-driven post-quantum cryptography algorithm; Hierarchical key negotiation module: adopts the clustered Diffie-Hellman protocol, dynamically divides the negotiation domain according to the network topology, and reduces the core network load through edge node pre-computation; Lightweight verification and update module: realizes the traceability of the key distribution path through blockchain evidence storage technology, and triggers the periodic update of the key based on the network state.
2. The big data-assisted key generation system for encrypted transmission of communication data according to claim 1, characterized in that, The dynamic entropy source processing module specifically includes: Data preprocessing and quality enhancement unit: multi-modal data cleaning, identifying and filtering abnormal data based on the isolation forest algorithm; normalizing heterogeneous data; using dynamic adaptive binning to smooth high-frequency jitter data; adopting pattern elimination technology to identify hidden periodic patterns in the data through Fourier transform and LSTM prediction model; using the Fisher-Yates shuffle algorithm to disrupt the temporal correlation; Decorrelation and entropy enhancement core engine: adopts decorrelation algorithms, including principal component analysis and independent component analysis; establishes an entropy fusion model, fuses Shannon entropy and minimum entropy with weights, compensates through Kolmogorov complexity, and injects a random bit stream based on chaotic mapping into low-entropy data segments to ensure that the overall entropy pool is greater than or equal to the established threshold.
3. The big data-assisted key generation system in the encrypted transmission of communication data according to claim 2, wherein The dynamic entropy source processing module specifically includes: Anti-interference and real-time monitoring unit: uses Kalman filtering to correct the steady-state error in sensor data in real time; adopts wavelet threshold denoising for frequency-domain filtering of high-frequency electromagnetic interference; entropy quality monitoring, evaluating the quality of the entropy pool based on the NIST SP 800-90B standard; detecting abnormal fluctuations in the entropy pool through the Markov chain model; Dynamic adaptive control interface: dynamically sets the outlier rejection boundary based on sliding window statistics; controls the depth of chaotic confusion in real time according to the quality of the entropy pool; resource-efficiency balance, enabling PCA dimensionality reduction and lightweight chaos on edge devices; enabling ICA + hyperchaotic confusion in the cloud to support quantum security scenarios.
4. The big data-assisted key generation system for encrypted transmission of communication data according to claim 3, characterized in that The multi-source heterogeneous data acquisition module specifically includes: Data source classification and dynamic adaptation unit: constructs a classifier based on the random forest and LSTM network, divides the data into high-entropy value sources, medium-entropy value sources, and low-entropy value sources; adaptively adjusts the acquisition frequency according to the network load and attack risk; Real-time streaming data acquisition engine: based on DPDK bypass kernel, realizes line-speed packet capture; embeds a lightweight Agent into the terminal device and uses zero-copy technology for transmission; based on the LoRaWAN and MQTT protocols, realizes low-power wide-area acquisition; uses a sliding window to split the data stream and matches the key generation period; extracts traffic frequency-domain characteristics in real time through a hardware-level FFT chip; Privacy Protection and Compliance Control Unit: Hierarchical desensitization strategy. The strong desensitization layer performs homomorphic encryption on user identity information, and the weak desensitization layer adds Laplace noise to device behavior data; Cross-domain privacy isolation, using a federated learning pipeline to complete feature extraction before data aggregation and only transmit non-sensitive feature vectors; Utilize secure enclave technology to build a trusted execution environment based on Intel SGX to isolate the access rights of raw data.
5. The big data-assisted key generation system in the encrypted transmission of communication data according to claim 4, wherein The multi-source heterogeneous data collection module specifically includes: Distributed node collaborative aggregation mechanism: Topology-aware routing, distributing node loads based on the Consistent Hashing algorithm and replacing TCP with the QUIC protocol; Using heartbeat detection to automatically switch backup nodes; Data sharding redundancy, storing data shards on multiple nodes through Reed-Solomon coding.
6. The big data-assisted key generation system in the encrypted transmission of communication data according to claim 5, wherein The quantum-resistant key generation module specifically includes: Post-quantum algorithm engine: Lattice-based encryption, using the CRYSTALS-Kyber algorithm to generate public and private keys using the Module-LWE problem; Hash signature fusion, integrating the SPHINCS+ scheme to achieve quantum-resistant signatures through a hash tree structure and form an encryption-signature double chain with Kyber; Entropy pool-driven mechanism, using the high-entropy bitstream output by the entropy pool as the random number seed for the Kyber algorithm; Generating a unique salt value based on the timestamp and device fingerprint; Dynamic key length adjustment unit: Threat perception model, evaluating the attack probability of Shor / Grover algorithms through a traffic analysis model based on the detection of abnormal qubit streams; Classical attack detection, monitoring the frequency of brute-force cracking attempts; Using an adaptive strategy, with low-risk mode, high-risk mode, and seamless switching; Key seed destruction and regeneration mechanism: Physically unclonable function, using SRAM PUF to generate a unique key for the device and erasing the physical state after each call; Optical quantum randomization, irradiating the storage unit with a quantum dot laser to achieve physical randomization coverage of key bits; Regeneration protocol, starting the regeneration process when the number of key usage times is greater than or equal to a predefined number or a memory sniffing attack is detected; Linking with the entropy pool module to re-inject entropy flow and generate a new seed; Side-channel attack-resistant reinforcement layer: Clock randomization, inserting random clock delays during key generation; Asynchronous circuit design, based on a GALS hardware architecture; Using a masking technique to split the key seed into multiple shards and encrypt and store the shards independently; Through a Boolean permutation network, real-time disturbing the logic gate states of the key generation path.
7. The big data-assisted key generation system in the encrypted transmission of communication data according to claim 6, wherein The hierarchical key negotiation module specifically includes: Dynamic clustering and topology-aware engine: Multi-dimensional clustering, dynamically dividing cluster groups based on device geographical location, communication latency, and security level; Using the PBFT consensus algorithm to select highly reliable edge nodes as cluster heads; Topology update mechanism, incremental update, only reclustering the areas with topological changes; Lightweight heartbeat protocol; Edge Precomputation and Lightweight Negotiation Protocol: Parameter pre-generation, precomputation of elliptic curve base points; Establish a temporary public key pool, pre-generate temporary public key-private key pairs; Lightweight ECDH optimization, compressed point transmission, compress the elliptic curve public key; Simplify zero-knowledge proof, use Schnorr signature to replace traditional RSA; Cross-Cluster Key Synchronization and Anti-Destruction Mechanism: Hierarchical key derivation, master key derivation, cluster heads negotiate the global master key through threshold signature; Sub-key derivation, based on the HKDF-HMAC-SHA3 algorithm, derive sub-cluster session keys from the master key; Anti-destruction strategy, multi-path redundancy, each cluster head maintains multiple cross-cluster communication paths and automatically switches when a single path fails; Fragmented key storage, shard the master key and store it on multiple edge nodes; Security and Performance Monitoring Unit: Threat detection, identify man-in-the-middle attacks, detect MITM attacks based on traffic characteristics and timestamp deviation; Replay attack defense, bind a unique Nonce value to each session key and reject repeated requests; Edge load balancing, dynamically allocate precomputation tasks according to CPU / memory utilization.
8. The big data-assisted key generation system for encrypted transmission of communication data according to claim 7, characterized in that, The lightweight verification and update module specifically includes: Blockchain Evidence Storage and Traceability Engine: Hybrid chain architecture, private chain stores core metadata, public chain anchors summaries, and upload the fingerprint of the private chain data to Ethereum and Polkadot through Merkle Root; Lightweight evidence storage optimization, IPFS sharding storage, zero-knowledge proof compression, use zk-SNARKs to generate evidence integrity proofs; Homomorphic encryption log, use the Paillier algorithm to encrypt sensitive fields and support ciphertext retrieval; Dynamic desensitization strategy: Filter sensitive information in real time according to the identity of the visitor; Network Status Awareness and Key Update Trigger: Multi-dimensional monitoring metrics, basic metrics include latency, packet loss rate, node online rate, and security metrics include DDoS attack traffic characteristics, quantum channel interference intensity; Intelligent trigger strategy, threshold-driven includes preset dynamic thresholds, combined with the LSTM prediction model to predict risks, event-driven includes forced update when a key leakage event is detected; Seamless switching protocol, use a double-buffered key pool to ensure uninterrupted communication during switching; Edge collaborative distribution, new keys are distributed by edge nodes nearby; Lightweight Verification and Synchronization Protocol: Lattice-based lightweight signature, use the Falcon-512 algorithm, utilize Merkle tree pruning, and only verify the branches related to the key path; Incremental synchronization mechanism, differential synchronization protocol, transmit key change differential data through the COAP protocol, and automatically merge multi-version key states based on CRDT; Anti-attack reinforcement, embed a hash time lock in the key update request, physically unclonable binding, bind the key to the device PUF fingerprint; Compliance Audit and Self-Healing Interface: An automated audit engine sets up a compliance rule library with built-in GDPR and CCPA regulations. It automatically detects the compliance of key storage locations and access logs; intelligent report generation outputs audit reports through NLG technology and supports one-click submission to regulatory agencies; self-healing mechanism for key fragment regeneration, when a key is detected as damaged, fragments are restored from distributed storage nodes; blockchain rollback protection with tamper-proof logs based on PBFT consensus; API open platform provides RESTful APIs for third-party audit tools to access, and cross-chain interoperability synchronizes compliance evidence from other chains through the Polkadot cross-chain protocol.
9. A method for generating a key assisted by big data in the encrypted transmission of communication data. According to the system for generating a key assisted by big data in the encrypted transmission of communication data described in claims 1-8, it is characterized in that, It includes: Real-time collection of network traffic characteristics, device behavior logs, environmental sensor data, and user interaction behavior data through distributed nodes, and dynamically adjusts the collection frequency based on the entropy quality weight factor; Performs decorrelation, pattern elimination, and Shannon entropy - minimum entropy fusion calculation on the collected data to generate a dynamically updated post-quantum entropy pool; Drives post-quantum cryptographic algorithms based on the entropy pool to generate variable-length key seeds; Dynamically divides negotiation domains according to the network topology, pre-computes elliptic curve multiple point parameters through edge nodes, and realizes clustered Diffie-Hellman negotiation; Adopts blockchain evidence storage technology to record the key distribution path and triggers periodic key updates based on the quantum channel state perception results.
10. The method for generating a large data-assisted key in the encrypted transmission of communication data according to claim 9, wherein The performing of decorrelation, pattern elimination, and Shannon entropy - minimum entropy fusion calculation on the collected data to generate a dynamically updated post-quantum entropy pool specifically includes: The data source selects high-entropy candidate sources including environmental noise, user interaction behavior, and device hardware fingerprints, and low-entropy auxiliary sources including network protocol packets and sensor periodic data; dynamic collection strategy adjusts the sampling frequency according to the entropy quality weight factor; Nonlinear decorrelation pipeline using principal component analysis, independent component analysis, and mutual information pruning; Pattern detection and elimination, identifies periodic signals through Fourier transform and superimposes Chen hyperchaotic sequences to disrupt the pattern; adds Laplace noise to geographical location data to satisfy differential privacy; LSTM predicts user behavior patterns and injects Poisson distribution random events for interference; Autocorrelation function monitoring, if the ACF peak is greater than a predefined threshold, triggers secondary scrambling; dynamic noise intensity, when a side-channel attack is detected, reduces the ϵ value to a predefined threshold; Dual-entropy dynamic fusion model, performs Shannon entropy calculation and minimum entropy calculation, and then conducts dynamic weighted fusion; realizes low-entropy compensation through sliding window detection and entropy pool reorganization.
Citation Information
Cited By
Dynamic encryption and security level adaptive adjustment method for flight data
CN120528601A
Electric vehicle interconnection, intercommunication and sharing charging operation method and device and storage medium
CN120746215A
Power system cloud side data secure transmission method and system
CN120750648A
Transformation-free identity authentication method and system based on intelligent password key
CN120808479A
Encryption system and method of trusted chip and storage medium
CN120934747A