Data secure transmission method and system, computer and storage medium
By dynamically generating key seed sequences and building spatiotemporal correlation verification hashs, security threats in industrial Internet data transmission are solved, efficient data transmission reliability and security are achieved, and replay attacks and traffic analysis are resisted.
Patent Information
- Application Number
- CN202510821478.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-19
AI Technical Summary
In the prior art, the data transmission scheme of the industrial Internet is difficult to resist replay attacks and traffic analysis. The traditional single hash verification mechanism cannot identify space-time and temporal dimensional attacks such as data tampering and out of order injection in multi-path transmission, resulting in the security threats such as confidentiality damage, instruction fraud, and timing tampering, and data transmission is poor.
By collecting real-time performance parameters of the transmission device and network environment parameters, a dynamic key seed sequence is generated, a data sharding strategy and transformation matrix is established based on the dynamic key seed sequence, the data is encrypted, and a verification hash of spatiotemporal association is constructed to realize the integrity and spatiotemporal continuity verification of multi-path transmission.
It realizes blocking replay attacks, enhancing ciphertext randomness, reducing retransmission rates, improving high jitter network throughput, and improving transmission reliability in high dynamic environments of the industrial Internet.
Smart Images

Figure CN120342616A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly relates to a data secure transmission method, system, computer, and storage medium. Background Art
[0002] Currently, the data transmission solutions in industrial Internet generally adopt static keys or periodically updated keys, which are difficult to resist replay attacks and traffic analysis. At the same time, the traditional single hash verification mechanism cannot identify spatio-temporal dimension attacks such as data tampering and out-of-order injection in multi-path transmission, resulting in security threats such as confidentiality damage, instruction deception, and timing tampering to key industrial control instructions and sensing data, and the data transmission security is relatively poor. Summary of the Invention
[0003] Aiming at the deficiencies of the prior art, the purpose of the present invention is to provide a data secure transmission method, system, computer, and storage medium, aiming to solve the technical problem of relatively poor data transmission security in the prior art.
[0004] To achieve the above purpose, in the first aspect, the present invention provides: A data secure transmission method, including the following steps: Collect real-time performance parameters and network environment parameters of the transmission device; Based on the network environment parameters of the transmission device, generate a dynamic key seed sequence based on the round-trip delay jitter parameter and packet loss rate characteristic of the transmission path; Dynamically generate a data fragmentation strategy according to the performance parameters of the transmission device, so as to divide the data to be transmitted into several fragmentation units based on the data fragmentation strategy, and establish a transformation matrix for data encryption based on the dynamic key seed sequence to perform transformation encryption on the fragmentation unit data; Encapsulate the fragmentation unit data through an encryption window, and generate a transmission path quality evaluation parameter according to the mapping algorithm, so as to dynamically adjust the offset of the encryption window according to the quality evaluation parameter; Construct a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmit the encrypted fragmentation unit data through multi-path transmission, and the receiving end performs integrity and spatio-temporal continuity verification based on the verification hash.
[0005] According to one aspect of the above technical solution, the step of dynamically generating a data fragmentation strategy according to the performance parameters of the transmission device specifically includes: Establish a joint perception model of device performance and network state, and dynamically sample the performance load factor corresponding to the performance parameters of the transmission device through a sliding window mechanism; Determine the fragmentation threshold according to the non-linear mapping relationship between the characteristics of the data to be transmitted and the performance load factor: ; ; In the formula, is the sharding threshold, is the total size of the data to be transmitted, is the reference bandwidth value, is the currently available bandwidth, is the server quality coefficient, is the performance load factor, is the device performance coefficient, and n is the number of samplings of the sliding window. is the processor utilization rate at the k-th sampling, is the memory usage at the k-th sampling, is the time difference between the current time and the k-th sampling, is the average delay, is the total memory.
[0006] According to one aspect of the above technical solution, the calculation expression of the dynamic key seed sequence is: ; ; In the formula, is the dynamic key seed sequence, ( ) is the HKDF derivation function, is the path stability factor, H( ) is the hash function, t is the byte sequence corresponding to the timestamp, is the shard length, S is the byte sequence corresponding to the path feature entropy value of the dynamic key seed sequence, represents the byte concatenation operation, m is the number of transmission paths, is the average transmission delay, is the delay jitter of the i-th path, is the packet loss rate of the i-th path, is the modulo operation.
[0007] According to one aspect of the above technical solution, the steps of splitting the data to be transmitted into several shard units based on the data sharding strategy specifically include: Calculate the dynamic correction factor through the bandwidth volatility, and correct the sharding threshold based on the dynamic correction factor to obtain the corrected threshold. Among them, the calculation expression of the dynamic correction factor is: ; In the formula, is the absolute value of the bandwidth fluctuation, is the average bandwidth, is the standard shard size; The calculation expression of the transformation matrix is: ; In the formula, is the transformation matrix, is the path feature check value, is the byte sequence corresponding to the dynamic key seed sequence, is the byte sequence corresponding to the available bandwidth, is the exclusive OR operation, U( ) represents the cyclic left shift operation, represents the number of shift bits, is the row entropy value of the transformation matrix, is the column entropy value of the transformation matrix.
[0008] According to one aspect of the above technical solution, the calculation expression of the transmission path quality evaluation parameter is: ; In the formula, is the transmission path quality evaluation parameter, is the bandwidth of the i-th path, is the maximum bandwidth, is the delay normalization factor.
[0009] According to one aspect of the above technical solution, the steps of dynamically adjusting the offset of the encryption window according to the quality evaluation parameter specifically include: Calculate the offset parameter difference degree of adjacent shard units, and then generate a phase offset correction factor according to the difference degree and the quality evaluation parameter to update the offset in real time according to the phase offset correction factor. Among them, the calculation expression of the offset is: ; ; ; In the formula, is the current phase offset, is the phase offset of the previous period, G is the number of shard units included in the current encryption window, is the partial derivative of the quality evaluation parameter Q with respect to the bandwidth of the g-th shard transmission path, is the absolute value of the fluctuation of the bandwidth of the g-th shard transmission path, is the delay jitter parameter of the bandwidth of the g-th shard transmission path, is the weighted average of the quality evaluation parameters of all shard units corresponding to the transmission paths in the current encryption window.
[0010] According to one aspect of the above technical solution, the steps of constructing a spatio-temporal associated verification hash based on a dynamic key seed sequence, transmitting the encrypted shard unit data through multiple paths, and the receiving end performing integrity and spatio-temporal continuity verification based on the verification hash specifically include: Construct a coordinate marker based on the row and column entropy values of the transformation matrix and the timestamp of the data shard unit according to the following calculation formula: ; In the formula, is the transmission time offset of the f-th shard relative to the first shard, is the dynamic key corresponding to the dynamic key seed sequence; Calculate the hash value for each shard unit according to the following calculation formula, generate a verification hash in the spatio-temporal dimension based on the hash value and the coordinate marker, and use the verification hash as a label to mark the shard unit: ; In the formula, is the verification hash of the f-th shard, is the ciphertext data of the f-th shard, is the verification hash of the previous shard; The receiving end performs integrity and spatio-temporal continuity verification based on the verification hash according to the following calculation formula: ; ; In the formula, is the conjunction symbol, F is the number of shards, is the verification hash of the f-th shard, is the received ciphertext data, is the verified valid hash of the (f - 1)-th shard, is the coordinate marker calculated by the receiving end, is the receiving timestamp of the f-th shard, is the receiving timestamp of the (f - 1)-th shard, is the time threshold.
[0011] In a second aspect, the present invention provides a data security transmission system, including: An acquisition module that acquires real-time performance parameters and network environment parameters of a transmission device; A key module that generates a dynamic key seed sequence based on the network environment parameters of the transmission device, based on the round-trip delay jitter parameter and packet loss rate characteristics of the transmission path; The sharding module dynamically generates a data sharding strategy according to the performance parameters of the transmission device, divides the data to be transmitted into several shard units based on the data sharding strategy, and performs transformation encryption on the shard unit data by establishing a transformation matrix for data encryption based on a dynamic key seed sequence; The encryption module encapsulates the shard unit data through an encryption window and generates a transmission path quality evaluation parameter according to a mapping algorithm to dynamically adjust the offset of the encryption window according to the quality evaluation parameter; The verification module is used to construct a space-time associated verification hash based on a dynamic key seed sequence, transmit the encrypted shard unit data through multiple paths, and the receiving end performs integrity and space-time continuity verification based on the verification hash.
[0012] According to one aspect of the above technical solution, the sharding module is specifically used for: Establish a joint perception model of device performance and network status, and dynamically sample the performance load factor corresponding to the performance parameters of the transmission device through a sliding window mechanism; Determine the sharding threshold according to the non-linear mapping relationship between the characteristics of the data to be transmitted and the performance load factor: ; ; In the formula, is the sharding threshold, is the total size of the data to be transmitted, is the reference bandwidth value, is the currently available bandwidth, is the server quality coefficient, is the performance load factor, is the device performance coefficient, n is the number of sampling times of the sliding window, is the processor utilization rate at the k-th sampling, is the memory usage at the k-th sampling, is the time difference between the current time and the k-th sampling time, is the average delay, is the total memory.
[0013] According to one aspect of the above technical solution, the sharding module is specifically further used for: Calculate a dynamic correction factor through the bandwidth volatility, and correct the sharding threshold based on the dynamic correction factor to obtain a corrected threshold, where the calculation expression of the dynamic correction factor is: ; In the formula, is the absolute value of bandwidth fluctuation, is the average bandwidth, is the standard shard size; The calculation expression of the transformation matrix is as follows: ; In the formula, is the transformation matrix, is the path feature check value, is the byte sequence corresponding to the dynamic key seed sequence, is the byte sequence corresponding to the available bandwidth, is the exclusive OR operation, and U( ) represents the cyclic left shift operation, represents the shift bit number, is the row entropy value of the transformation matrix, is the column entropy value of the transformation matrix.
[0014] According to one aspect of the above technical solution, the encryption module is specifically used for: Calculating the offset parameter difference degree of adjacent shard units, and then generating a phase offset correction factor according to the difference degree and the quality evaluation parameter to update the offset in real time according to the phase offset correction factor. Among them, the calculation expression of the offset is: ; ; ; In the formula, is the current phase offset, is the phase offset of the previous period, G is the number of shard units included in the current encryption window, is the partial derivative of the quality evaluation parameter Q with respect to the bandwidth of the g-th shard transmission path, is the absolute value of the bandwidth fluctuation of the g-th shard transmission path, is the delay jitter parameter of the bandwidth of the g-th shard transmission path, is the weighted average value of the quality evaluation parameters of all shard unit corresponding transmission paths in the current encryption window.
[0015] According to one aspect of the above technical solution, the verification module is specifically used for: Based on the row and column entropy values of the transformation matrix and the time stamps of the data shard units, constructing a coordinate marker according to the following calculation formula: ; In the formula, is the transmission time offset of the f-th shard relative to the first shard, is the dynamic key corresponding to the dynamic key seed sequence; Calculate the hash value for each shard unit according to the following calculation formula, generate a verification hash in the spatio-temporal dimension based on the hash value and coordinate markers, and use the verification hash as a label to mark the shard unit: ; In the formula, is the verification hash of the f-th shard, is the ciphertext data of the f-th shard, is the verification hash of the previous shard; The receiving end performs integrity and spatio-temporal continuity verification based on the verification hash according to the following calculation formula: ; ; In the formula, is the conjunction symbol, F is the number of shards, is the verification hash of the f-th shard, is the received ciphertext data, is the verified valid hash of the (f - 1)-th shard, is the coordinate marker calculated by the receiving end, is the receiving timestamp of the f-th shard, is the receiving timestamp of the (f - 1)-th shard, is the time threshold.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: realizing one-time pad encryption by dynamically generating a key seed sequence through real-time collection of network environment parameters, blocking replay attacks; dynamically adjusting the data sharding strategy based on device performance parameters to reduce the retransmission rate; using a transformation matrix to perform exclusive-or transformation on the sharded data to enhance the randomness of the ciphertext to resist traffic analysis; adjusting the offset of the encryption window in real time through the transmission path quality evaluation parameter, improving the throughput rate of high-jitter networks while ensuring security; finally, constructing a spatio-temporal associated verification hash to achieve double verification of the integrity and temporal continuity of multi-path transmitted data, and improving the transmission reliability in the high-dynamic environment of the industrial Internet. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a schematic flow chart of the data secure transmission method in the first embodiment of the present invention; Figure 2 is a structural block diagram of the data secure transmission system in the second embodiment of the present invention; Figure 3 is a schematic hardware structure diagram of a computer in the third embodiment of the present invention; The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION OF THE INVENTION
[0018] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are shown in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.
[0019] It should be noted that when an element is referred to as being "fixedly provided on" another element, it can be directly on the other element or there may also be an intermediate element. When an element is considered to be "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.
[0021] Embodiment 1 Please refer to Figure 1 , which shows the flowchart of the data security transmission method in the first embodiment of the present invention. As shown in the figure, the method includes the following steps: Step S100, collect the real-time performance parameters and network environment parameters of the transmission device. Specifically, in this embodiment, the above real-time performance parameters include memory usage and processor utilization rate, etc., and the above network environment parameters include path delay jitter, path packet loss rate, and available bandwidth, etc.
[0022] Step S200, based on the network environment parameters of the transmission device, generate a dynamic key seed sequence based on the round-trip delay jitter parameter and packet loss rate characteristic of the transmission path.
[0023] Preferably, in this embodiment, the calculation expression of the dynamic key seed sequence is: ; ; In the formula, is the dynamic key seed sequence, ( ) is the HKDF derivation function, is the path stability factor, H( ) is the hash function, t is the byte sequence corresponding to the timestamp, is the shard length, and S is the byte sequence corresponding to the path feature entropy value of the dynamic key seed sequence. represents the byte concatenation operation, and m is the number of transmission paths. is the average transmission delay. is the delay jitter of the i-th path. is the packet loss rate of the i-th path. is the modulo operation.
[0024] Specifically, is used to quantify the relative intensity of path jitter. is used to non-linearly amplify the packet loss rate. is used to generate a 32-bit entropy value S, which is compatible with the AES-256 key length. In some application scenarios of this embodiment, when a certain AGV cart performs dual transmission through 5G (path 1) and Wi-Fi (path 2), there are differences in delay and packet loss rate.
[0025] Step S300, dynamically generate a data sharding strategy according to the performance parameters of the transmission device, divide the data to be transmitted into several shard units based on the data sharding strategy, and perform transformation encryption on the shard unit data based on the transformation matrix established by the dynamic key seed sequence.
[0026] Specifically, in this embodiment, the steps of dynamically generating a data sharding strategy according to the performance parameters of the transmission device specifically include: Establish a joint perception model of device performance and network status, and dynamically sample the performance load factor corresponding to the performance parameters of the transmission device through a sliding window mechanism. Determine the sharding threshold according to the non-linear mapping relationship between the characteristics of the data to be transmitted and the performance load factor: ; ; In the formula, is the sharding threshold. is the total size of the data to be transmitted. is the reference bandwidth value. is the currently available bandwidth. is the server quality coefficient. is the performance load factor. is the device performance coefficient, n is the number of sampling times of the sliding window. is the processor utilization rate at the k-th sampling. is the memory usage at the k-th sampling. is the time difference between the current time and the time of the k-th sampling. is the average delay. is the total memory size. Specifically, when the load is high, the shards are automatically shrunk to reduce the device pressure.
[0027] Further, the step of splitting the data to be transmitted into several shard units based on the data sharding strategy specifically includes: Calculating a dynamic correction factor through the bandwidth volatility, and correcting the shard threshold based on the dynamic correction factor to obtain a corrected threshold. The calculation expression of the dynamic correction factor is: ; In the formula, is the absolute value of bandwidth fluctuation, is the average bandwidth, is the standard shard size. Specifically, when the bandwidth fluctuates, the shard is further reduced to reduce the retransmission probability.
[0028] The calculation expression of the transformation matrix is: ; In the formula, is the transformation matrix, is the path feature check value, is the byte sequence corresponding to the dynamic key seed sequence, is the byte sequence corresponding to the available bandwidth, is the exclusive OR operation, U( ) represents the cyclic left shift operation, represents the shift bit number, is the row entropy value of the transformation matrix, is the column entropy value of the transformation matrix. In this step, H( ) adopts the SHA3-256 hash security function.
[0029] Further, in this embodiment, the transformation encryption of the shard unit data adopts the AES algorithm, which specifically includes: first, taking the bytes represented in hexadecimal corresponding to the shard unit data as the plaintext matrix, then sequentially extracting the elements in the transformation matrix to generate the key represented in hexadecimal, and then performing multiple rounds of exclusive OR transformations of byte substitution, row shift, and column confusion in sequence to obtain the ciphertext matrix.
[0030] Step S400, encapsulating the shard unit data through an encryption window, and generating a transmission path quality evaluation parameter according to the mapping algorithm, so as to dynamically adjust the offset of the encryption window according to the quality evaluation parameter.
[0031] Specifically, in this embodiment, the calculation expression of the transmission path quality evaluation parameter is: ; In the formula, is the transmission path quality evaluation parameter, is the bandwidth of the i-th path, is the maximum bandwidth, is the delay normalization factor.
[0032] Furthermore, the step of dynamically adjusting the offset of the encryption window according to the quality evaluation parameter specifically includes: Calculating the offset parameter difference degree of adjacent shard units, and then generating a phase offset correction factor according to the difference degree and the quality evaluation parameter to update the offset in real time according to the phase offset correction factor. Among them, the calculation expression of the offset is: ; ; ; In the formula, is the current phase offset, is the phase offset of the previous cycle, G is the number of shard units included in the current encryption window, is the partial derivative of the quality evaluation parameter Q with respect to the bandwidth of the transmission path of the g-th shard, is the absolute value of the bandwidth fluctuation of the transmission path of the g-th shard, is the delay jitter parameter of the bandwidth of the transmission path of the g-th shard, is the weighted average of the quality evaluation parameters of all shard unit corresponding transmission paths within the current encryption window.
[0033] Specifically, the encryption window is used to load data shard units on demand and then adjusted by the current phase offset, represents the mixing degree difference, is the phase offset correction factor. By using the phase offset correction factor, the same data is differentially encapsulated on different paths to resist traffic analysis and replay attacks.
[0034] Step S500, constructing a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmitting the encrypted shard unit data through multiple paths, and the receiving end performing integrity and spatio-temporal continuity verification based on the verification hash.
[0035] Preferably, in this embodiment, the step of constructing a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmitting the encrypted shard unit data through multiple paths, and the receiving end performing integrity and spatio-temporal continuity verification based on the verification hash specifically includes: According to the following calculation formula, constructing a coordinate marker based on the row and column entropy values of the transformation matrix and the timestamp of the data shard unit: ; In the formula, is the transmission time offset of the f-th shard relative to the first shard, is the dynamic key corresponding to the dynamic key seed sequence, and H( ) uses a hash security function; According to the following calculation formula, calculate the hash value for each shard unit, and generate a verification hash in the spatio-temporal dimension based on the hash value and the coordinate marker, so as to mark the shard unit with the verification hash as a label: ; In the formula, is the verification hash of the f-th shard, is the ciphertext data of the f-th shard, is the verification hash of the previous shard, and H( ) uses a hash security function; The receiving end performs integrity and spatio-temporal continuity verification based on the verification hash according to the following calculation formula: ; ; In the formula, is the conjunction symbol, F is the number of shards, is the verification hash of the f-th shard, is the received ciphertext data, is the verified valid hash of the (f - 1)-th shard, is the coordinate marker calculated by the receiving end, is the receiving timestamp of the f-th shard, is the receiving timestamp of the (f - 1)-th shard, is the time threshold, and H( ) uses a hash security function. Specifically, means that for all shards where f = 1 to F, the equation condition is satisfied, means that the received hash value is the same as the locally calculated hash value. If they are the same, the data integrity verification passes. Among them, the coordinate marker calculated by the receiving end can be calculated with reference to the coordinate marker of the sending end. Among them, the row-column entropy value of the transformation matrix and the sending time offset are sent in the data packet, and the dynamic key is synchronized by the key distribution center.
[0036] means that the maximum absolute value of the difference in time offsets between all adjacent shards is less than the time threshold. Even if the shards arrive out of order, after sorting by sequence number, the arrival time difference between adjacent sequence numbers of shards should be within the time threshold to ensure temporal continuity.
[0037] In summary, the data security transmission method in the above embodiments of the present invention realizes one-time pad encryption by dynamically generating a key seed sequence through real-time collection of network environment parameters, blocking replay attacks; dynamically adjusts the data sharding strategy based on device performance parameters to reduce the retransmission rate; performs exclusive OR transformation on the sharded data using a transformation matrix to enhance the randomness of the ciphertext to resist traffic analysis; adjusts the offset of the encryption window in real time through the transmission path quality evaluation parameter, improving the throughput rate of high-jitter networks while ensuring security; and finally constructs a spatio-temporal associated verification hash to implement double verification of the integrity and temporal sequence continuity of multi-path transmitted data, improving the transmission reliability in the highly dynamic environment of the industrial Internet.
[0038] Embodiment 2 The second embodiment of the present application also provides a data security transmission system, which is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the systems described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0039] As Figure 2 shown, the system includes: a collection module 100, a key module 200, a sharding module 300, an encryption module 400, and a verification module 500.
[0040] The collection module 100 is used to collect the real-time performance parameters and network environment parameters of the transmission device; The key module 200 is used to generate a dynamic key seed sequence based on the network environment parameters of the transmission device, based on the round-trip delay jitter parameter and packet loss rate characteristics of the transmission path; The sharding module 300 is used to dynamically generate a data sharding strategy according to the performance parameters of the transmission device, to divide the data to be transmitted into several sharding units based on the data sharding strategy, and to perform transformation on the sharding unit data by establishing a transformation matrix for data encryption based on the dynamic key seed sequence; The encryption module 400 is used to encapsulate the sharding unit data through an encryption window, and generate a transmission path quality evaluation parameter according to a mapping algorithm, so as to dynamically adjust the offset of the encryption window according to the quality evaluation parameter; The verification module 500 is used to construct a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmit the encrypted sharding unit data through multiple paths, and the receiving end performs integrity and spatio-temporal continuity verification based on the verification hash.
[0041] Preferably, in this embodiment, the sharding module 300 is specifically used for: Establish a joint perception model of device performance and network status, and dynamically sample the performance load factor corresponding to the performance parameters of the transmission device through a sliding window mechanism; Determine the fragmentation threshold according to the non-linear mapping relationship between the characteristics of the data to be transmitted and the performance load factor: ; ; In the formula, is the fragmentation threshold, is the total size of the data to be transmitted, is the reference bandwidth value, is the current available bandwidth, is the server quality coefficient, is the performance load factor, is the device performance coefficient, n is the number of samplings of the sliding window, is the processor utilization rate at the k-th sampling, is the memory usage at the k-th sampling, is the time difference between the current time and the k-th sampling time, is the average delay, is the total memory.
[0042] Preferably, in this embodiment, the fragmentation module 300 is specifically further configured to: Calculate a dynamic correction factor through the bandwidth volatility, and correct the fragmentation threshold based on the dynamic correction factor to obtain a corrected threshold, where the calculation expression of the dynamic correction factor is: ; In the formula, is the absolute value of bandwidth fluctuation, is the average bandwidth, is the standard fragmentation size; The calculation expression of the transformation matrix is: ; In the formula, is the transformation matrix, is the path feature check value, is the byte sequence corresponding to the dynamic key seed sequence, is the byte sequence corresponding to the available bandwidth, is the exclusive OR operation, U( ) represents a cyclic left shift operation, represents the shift bit number, is the row entropy value of the transformation matrix, is the column entropy value of the transformation matrix.
[0043] Preferably, in this embodiment, the encryption module 400 is specifically configured to: Calculate the difference degree of the offset parameters of adjacent shard units, and then generate a phase offset correction factor based on the difference degree and the quality evaluation parameter to update the offset in real time according to the phase offset correction factor. Among them, the calculation expression of the offset is: ; ; ; In the formula, is the current phase offset, is the phase offset of the previous period, G is the number of shard units included in the current encryption window, is the partial derivative of the quality evaluation parameter Q with respect to the bandwidth of the g-th shard transmission path, is the absolute value of the fluctuation of the bandwidth of the g-th shard transmission path, is the delay jitter parameter of the bandwidth of the g-th shard transmission path, is the weighted average of the quality evaluation parameters of all shard unit corresponding transmission paths in the current encryption window.
[0044] Preferably, in this embodiment, the verification module 500 is specifically configured to: Construct a coordinate tag based on the row-column entropy value of the transformation matrix and the timestamp of the data shard unit according to the following calculation formula: ; In the formula, is the transmission time offset of the f-th shard relative to the first shard, is the dynamic key corresponding to the dynamic key seed sequence; Calculate the hash value for each shard unit according to the following calculation formula, and generate a verification hash in the space-time dimension based on the hash value and the coordinate tag, so as to use the verification hash as a tag to mark the shard unit: ; In the formula, is the verification hash of the f-th shard, is the ciphertext data of the f-th shard, is the verification hash of the previous shard; The receiving end performs integrity and space-time continuity verification based on the verification hash according to the following calculation formula: ; ; In the formula, is the conjunction symbol, F is the number of shards, is the verification hash of the f-th shard, is the received ciphertext data, is the verified valid hash of the (f - 1)-th shard, is the coordinate marker calculated by the receiving end, is the receiving timestamp of the f-th shard, is the receiving timestamp of the (f - 1)-th shard, is the time threshold.
[0045] It should be noted that each of the above modules can be a functional module or a program module, and can be implemented either by software or by hardware. For the modules implemented by hardware, each of the modules can be located in the same processor; or each of the modules can also be located in different processors in any combined form.
[0046] Embodiment III The third embodiment of the present application provides a computer, which may include a processor 81 and a memory 82 storing computer program instructions.
[0047] Specifically, the above processor 81 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0048] Among them, the memory 82 may include a mass memory for data or commands. By way of example and not limitation, the memory 82 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In appropriate cases, the memory 82 may include removable or non-removable (or fixed) media. In appropriate cases, the memory 82 may be internal or external to the data processing device. In a particular embodiment, the memory 82 is non-volatile memory. In a particular embodiment, the memory 82 includes a read-only memory (ROM) and a random access memory (RAM). In appropriate cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In appropriate cases, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0049] The memory 82 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program commands executed by the processor 81.
[0050] The processor 81 reads and executes the computer program commands stored in the memory 82 to implement any one of the data security transmission methods in the above embodiments.
[0051] In some of the embodiments, the computer may further include a communication interface 83 and a bus 80. Among them, as Figure 3 shown, the processor 81, the memory 82, and the communication interface 83 are connected through the bus 80 and complete communication with each other.
[0052] The communication interface 83 is used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application. The communication interface 83 can also implement data communication with other components such as external devices, image / data acquisition devices, databases, external storage, and image / data processing workstations, etc.
[0053] Bus 80 includes hardware, software, or both, and couples components of a computer to each other. Bus 80 includes, but is not limited to, at least one of the following: Data Bus, Address Bus, Control Bus, Expansion Bus, Local Bus. By way of example and not limitation, Bus 80 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable bus or a combination of two or more of these. In a suitable case, Bus 80 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.
[0054] Embodiment 4 The fourth embodiment of the present application provides a readable storage medium. Computer program commands are stored on the readable storage medium; when the computer program commands are executed by a processor, any one of the data security transmission methods in the above embodiments is implemented.
[0055] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0056] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A data security transmission method, characterized in that, It includes the following steps: Collect the real-time performance parameters and network environment parameters of the transmission device; Based on the network environment parameters of the transmission device, generate a dynamic key seed sequence based on the round-trip delay jitter parameter and packet loss rate characteristic of the transmission path; Dynamically generate a data fragmentation strategy according to the performance parameters of the transmission device, divide the data to be transmitted into several fragmentation units based on the data fragmentation strategy, and establish a transformation matrix for data encryption based on the dynamic key seed sequence to perform transformation encryption on the fragmentation unit data; Encapsulate the fragmentation unit data through an encryption window, and generate a transmission path quality evaluation parameter according to a mapping algorithm, so as to dynamically adjust the offset of the encryption window according to the quality evaluation parameter; Construct a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmit the encrypted fragmentation unit data through multiple paths, and the receiving end performs integrity and spatio-temporal continuity verification based on the verification hash.
2. The data security transmission method according to claim 1, wherein The step of dynamically generating a data fragmentation strategy according to the performance parameters of the transmission device specifically includes: Establish a joint perception model of device performance and network status, and dynamically sample the performance load factor corresponding to the performance parameters of the transmission device through a sliding window mechanism; Determine the fragmentation threshold according to the non-linear mapping relationship between the characteristics of the data to be transmitted and the performance load factor; ; ; In the formula, is the sharding threshold, is the total size of the data to be transmitted, is the reference bandwidth value, is the currently available bandwidth, is the server quality coefficient, is the performance load factor, is the device performance coefficient, and n is the number of samplings of the sliding window. is the processor utilization rate at the k-th sampling, is the memory usage at the k-th sampling, is the time difference between the current time and the time of the k-th sampling, is the average delay, is the total memory size.
3. The data security transmission method according to claim 2, wherein The calculation expression of the dynamic key seed sequence is: ; ; In the formula, is the dynamic key seed sequence, ( ) is the HKDF derivation function, is the path stability factor, H( ) is the hash function, t is the byte sequence corresponding to the timestamp, is the shard length, S is the byte sequence corresponding to the path feature entropy value of the dynamic key seed sequence, represents the byte concatenation operation, m is the number of transmission paths, is the average transmission delay, is the delay jitter of the i-th path, is the packet loss rate of the i-th path, is the modulo operation.
4. The data security transmission method according to claim 3, wherein The step of dividing the data to be transmitted into several fragmentation units based on the data fragmentation strategy specifically includes: Calculate a dynamic correction factor through the bandwidth volatility, and correct the fragmentation threshold based on the dynamic correction factor to obtain a corrected threshold, where the calculation expression of the dynamic correction factor is: ; Wherein, is the absolute value of bandwidth fluctuation, is the average bandwidth, is the standard shard size; The calculation expression of the transformation matrix is: ; In the formula, is the transformation matrix, is the path feature check value, is the byte sequence corresponding to the dynamic key seed sequence, is the byte sequence corresponding to the available bandwidth, is the exclusive OR operation, U( ) represents the circular left shift operation, represents the shift bit number, is the row entropy value of the transformation matrix, is the column entropy value of the transformation matrix.
5. The data security transmission method according to claim 3, wherein The calculation expression of the transmission path quality evaluation parameter is: ; Wherein, is the transmission path quality evaluation parameter, is the bandwidth of the i-th path, is the maximum bandwidth, is the delay normalization factor.
6. The data security transmission method according to claim 4, wherein The step of dynamically adjusting the offset of the encryption window according to the quality evaluation parameter specifically includes: Calculate the offset parameter difference degree of adjacent fragmentation units, then generate a phase offset correction factor according to the difference degree and the quality evaluation parameter, and update the offset in real time according to the phase offset correction factor, where the calculation expression of the offset is: ; ; ; Wherein, is the current phase offset, is the phase offset of the previous cycle, G is the number of shard units included in the current encryption window, is the partial derivative of the quality evaluation parameter Q with respect to the bandwidth of the g-th shard transmission path, is the absolute value of the fluctuation of the bandwidth of the g-th shard transmission path, is the delay jitter parameter of the bandwidth of the g-th shard transmission path, is the weighted average of the quality evaluation parameters of the transmission paths corresponding to all shard units within the current encryption window.
7. The data security transmission method according to claim 6, characterized in that, The step of constructing a spatio-temporal associated verification hash based on the dynamic key seed sequence, transmitting the encrypted fragmentation unit data through multiple paths, and the receiving end performing integrity and spatio-temporal continuity verification based on the verification hash specifically includes: According to the following calculation formula, construct a coordinate marker based on the row and column entropy values of the transformation matrix and the timestamp of the data fragmentation unit; ; wherein, is the transmission time offset of the f-th shard relative to the first shard, is the dynamic key corresponding to the dynamic key seed sequence; According to the following calculation formula, calculate the hash value for each fragmentation unit, generate a verification hash in the spatio-temporal dimension based on the hash value and the coordinate marker, and use the verification hash as a label to mark the fragmentation unit; ; Wherein, is the verification hash of the f-th shard, is the ciphertext data of the f-th shard, is the verification hash of the previous shard; The receiving end performs integrity and spatio-temporal continuity verification based on the verification hash according to the following calculation formula: ; ; In the formula, is the conjunction symbol, F is the number of shards, is the verification hash of the f-th shard, is the received ciphertext data, is the verified valid hash of the (f - 1)-th shard, is the coordinate marker calculated by the receiving end, is the receiving timestamp of the f-th shard, is the receiving timestamp of the (f - 1)-th shard, is the time threshold.
8. A data security transmission system, characterized in that, It includes: An acquisition module that acquires the real-time performance parameters and network environment parameters of the transmission device; A key module that generates a dynamic key seed sequence based on the network environment parameters of the transmission device, based on the round-trip delay jitter parameter and packet loss rate characteristic of the transmission path; The sharding module dynamically generates a data sharding strategy according to the performance parameters of the transmission device, divides the data to be transmitted into several sharding units based on the data sharding strategy, and performs transformation encryption on the sharding unit data by establishing a transformation matrix for data encryption based on a dynamic key seed sequence; The encryption module encapsulates the sharding unit data through an encryption window and generates a transmission path quality evaluation parameter according to a mapping algorithm to dynamically adjust the offset of the encryption window according to the quality evaluation parameter; The verification module is used to construct a space-time associated verification hash based on the dynamic key seed sequence, transmit the encrypted sharding unit data through multiple paths, and the receiving end performs integrity and space-time continuity verification based on the verification hash.
9. A computer, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data security transmission method according to any one of claims 1-7.
10. A storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the data security transmission method according to any one of the above claims 1-7.
Citation Information
Patent Citations
Secure dynamic communication network and protocol
CN107750441A
Method for safely transmitting digital information of internet of things
CN119544210A
Low earth orbit satellite Internet of Things communication method and system based on dynamic block chain
CN119561605A
Industrial control system safety protection algorithm design method
CN119576288A
Computer network security data transmission method and device
CN119922011A
Cited By
Terminal security access and data protection method based on virtual power plant
CN122204401A