Intelligent data security encryption method in edge computing environment
Through discrete wavelet transformation, dynamic encryption strategies and blockchain technology in edge computing environments, data security and integrity issues in edge computing are solved, and flexible access control and efficient data protection are achieved.
Patent Information
- Application Number
- CN202510458967.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the edge computing environment, data security faces limited resources, distributed networks and strong openness. Existing encryption algorithms are difficult to operate efficiently, and access control is not flexible enough, and data integrity verification is insufficient, resulting in an increase in the risk of data leakage.
Data flow is decomposed through discrete wavelet transformation, random perturbation sequences are added, dynamic encryption policy network is built, encryption algorithms are adaptively selected, data integrity is verified using decentralized consensus mechanism and zero-knowledge proof, and key updates and storage are combined with blockchain technology.
Improves the security and integrity of data, realizes flexible access control, and ensures the security and reliability of data during multi-node storage and transmission.
Smart Images

Figure CN120342679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and particularly to an intelligent data security encryption method in an edge computing environment. Background Technique
[0002] With the rapid development of technologies such as the Internet of Things and 5G, edge computing has been widely applied in many fields. Edge computing brings computing and storage closer to the data source or user, greatly reducing data transmission latency, improving system response speed, and meeting the requirements of real-time services. For example, in an intelligent transportation system, roadside edge nodes can process vehicle sensor data in real time to achieve intelligent control of traffic lights; in the industrial Internet of Things scenario, edge devices in the factory can quickly analyze device operation data and timely detect potential faults.
[0003] However, data security in the edge computing environment faces severe challenges. On the one hand, edge node resources are limited, and traditional complex encryption algorithms are difficult to operate efficiently. Edge devices usually have weak computing power and small memory. For example, in some small intelligent sensor nodes, running complex encryption algorithms will cause a sharp increase in device power consumption, a decline in performance, and even inability to work properly. On the other hand, the distributed and open characteristics of the edge computing network make data vulnerable to attacks during transmission and storage. Data may be transmitted between multiple edge nodes, and the network boundary is blurred. Attackers can use vulnerabilities to steal or tamper with data. For example, malicious nodes may intercept and modify industrial control data, causing serious production accidents.
[0004] Existing data encryption methods are difficult to meet the special requirements of the edge computing environment. Traditional encryption algorithms are mostly general-purpose and do not fully consider the resource constraints of edge nodes and the dynamically changing network environment. For example, although symmetric encryption algorithms have fast encryption speeds, key management is complex, and it is difficult to achieve secure key distribution in a dynamic edge computing network; asymmetric encryption algorithms have high security, but large computational overheads and are not suitable for resource-constrained edge devices. At the same time, existing encryption methods are not flexible enough in access control and are difficult to perform precise permission management according to the sensitivity of data and user roles. In practical applications, it may occur that ordinary users obtain access rights to highly sensitive data, increasing the risk of data leakage. Moreover, in terms of data integrity verification, existing technologies lack an efficient cross-node verification mechanism and are difficult to ensure that data has not been tampered with during multi-node storage and transmission. In summary, there is an urgent need for an intelligent data security encryption method suitable for the edge computing environment to ensure data security, integrity, and controllability of access. Summary of the Invention
[0005] The purpose of the present invention is to provide an intelligent data security encryption method in an edge computing environment to solve the problems raised in the above background technique.
[0006] To achieve the above object, the present invention provides the following technical solutions: An intelligent data security encryption method in an edge computing environment, the method comprising:
[0007] Obtain the original data stream transmitted by the edge node, perform discrete wavelet transform decomposition on the original data stream to generate multiple data sub-blocks, and add a random perturbation sequence to each data sub-block based on the dynamic noise injection algorithm;
[0008] Construct a dynamic encryption policy network, generate a dynamic key matrix associated with the characteristics of the data sub-blocks through a chaotic mapping model, and assign an independent access control policy to each data sub-block based on the attribute-based encryption algorithm;
[0009] According to the security level of the data sub-blocks and the real-time load status of the edge nodes, adaptively select a symmetric encryption or an asymmetric encryption algorithm to perform block encryption on the data sub-blocks, and generate an encrypted metadata tag;
[0010] Construct a collaborative verification network among edge nodes based on a decentralized consensus mechanism, and use the zero-knowledge proof algorithm to perform cross-node consistency verification on the encrypted metadata tag to ensure the integrity of the encrypted data;
[0011] Dynamically adjust the period of the dynamic key matrix through a key update model based on a time decay function, and combine blockchain technology to distribute and store the updated key to multiple edge nodes.
[0012] Preferably, the method of adding a random perturbation sequence to each data sub-block based on the dynamic noise injection algorithm includes:
[0013] Generate a Gaussian white noise base according to the frequency domain energy distribution of the data sub-blocks, perform multi-scale transformation on the base using the random phase modulation algorithm, and generate a perturbation mask matching the size of the data sub-blocks;
[0014] Perform pixel-by-pixel exclusive OR operation on the perturbation mask and the data sub-blocks through a sliding window mechanism, and dynamically adjust the perturbation intensity parameter according to the computing resource limitations of the edge nodes.
[0015] Preferably, the method for the chaotic mapping model to generate a dynamic key matrix includes:
[0016] Generate an initial chaotic sequence based on Logistic mapping iteration, inject the hash digest of the data sub-blocks as a perturbation factor into the chaotic system to generate a non-linear spread spectrum sequence;
[0017] Divide the spread spectrum sequence into multiple sub-key segments according to a preset segmentation rule, and perform redundant coding on the sub-key segments based on the Hamming code error correction algorithm to form the row vectors of the dynamic key matrix.
[0018] Preferably, the implementation method of the adaptive selection encryption algorithm includes:
[0019] Statistically analyze the CPU utilization rate, memory occupancy rate, and network latency parameters of the edge nodes, and construct a resource evaluation vector;
[0020] Calculate the membership degree of the resource evaluation vector and the preset threshold through the fuzzy logic decision model. If the membership degree is higher than the first threshold, enable AES symmetric encryption; otherwise, enable RSA asymmetric encryption.
[0021] Preferably, the method for generating the encrypted metadata tag includes:
[0022] Extract the entropy value feature and position index of the encrypted data sub-block, and perform multi-level hash aggregation on the features using the Merkle tree structure;
[0023] Combine the aggregated root hash value with the digital signature of the data sub-block to generate a metadata tag containing the timestamp and node identity information.
[0024] Preferably, the method for cross-node consistency verification using the zero-knowledge proof algorithm includes:
[0025] Convert the encrypted metadata tag into a polynomial commitment form, and generate a challenge-response interactive proof based on the Fiat-Shamir heuristic protocol;
[0026] Cross-verify the response results of multiple edge nodes through the random oracle model. If more than half of the nodes pass the verification, it is determined that the data integrity is established.
[0027] Preferably, the construction method of the key update model of the time decay function includes:
[0028] Set the key life cycle as an exponential decay curve, and dynamically adjust the decay rate according to the historical access frequency of the edge nodes;
[0029] When the remaining valid value of the key is lower than the second threshold, trigger the key regeneration protocol, and use the ring signature algorithm to generate a distributed authorization certificate for the new key.
[0030] Preferably, the execution method of the key regeneration protocol includes:
[0031] Select multiple edge nodes as key escrow agents, and split the new key into multiple sub-shares based on the Shamir secret sharing scheme;
[0032] Require at least K escrow agents to jointly sign through the threshold signature algorithm to reconstruct the complete key, where K is the preset security threshold value.
[0033] Preferably, the method for storing keys using blockchain technology includes:
[0034] Organize the updated keys in the Merkle - Patricia tree structure to generate a key block containing the version number and the forward hash;
[0035] Elect a master node based on the proof - of - stake consensus mechanism to verify the key block and broadcast the verified block to the local ledgers of all edge nodes.
[0036] Preferably, the method for allocating the access control policy includes:
[0037] Analyze the sensitivity level and user role attributes of the data sub - block, and use the lattice - based encryption algorithm to generate a multi - dimensional policy vector;
[0038] Compress and encode the policy vector through a Bloom filter and embed the encoding result into the policy description field of the encrypted data header.
[0039] Compared with the prior art, the beneficial effects of the present invention are:
[0040] The intelligent data security encryption method in the edge computing environment proposed by the present invention has significant beneficial effects in many aspects. At the data encryption level, the original data stream is decomposed into data sub - blocks through discrete wavelet transform and a random perturbation sequence is added, effectively confusing the original data features and increasing the difficulty of data cracking. For example, for the original data stream containing multimedia data such as images and audio, after the decomposed sub - blocks are perturbed, even if an attacker obtains part of the data, it is difficult to restore the original content, greatly enhancing the security of the data before encryption.
[0041] The encryption policy and key generation links have prominent advantages. The dynamic key matrix generated by the chaotic mapping model is closely related to the characteristics of the data sub - blocks, enhancing the security and pertinence of the keys. Compared with the traditional fixed - key generation method, this dynamic key generation method makes the key different each time when encrypting the same data sub - block, further increasing the security of encryption. At the same time, the attribute - based encryption algorithm realizes the independent allocation of access control policies for each data sub - block, and can accurately manage permissions according to the sensitivity level and user role attributes of the data sub - blocks. In the enterprise data management scenario, employees in different departments have different access rights to data, and this algorithm can ensure that only employees meeting specific attribute conditions can access the corresponding data sub - blocks, effectively preventing data leakage.
[0042] The adaptive selection of encryption algorithms fully considers the security levels of data sub - blocks and the real - time load status of edge nodes. When the resources of edge nodes are sufficient, the AES symmetric encryption algorithm is enabled. Taking advantage of its fast encryption and decryption speed, the encryption efficiency is improved. When resources are scarce, the RSA asymmetric encryption algorithm is selected to ensure data security. This mechanism avoids problems such as low encryption efficiency or insufficient security caused by improper algorithm selection, ensuring a balance between encryption efficiency and security under different resource conditions.
[0043] The cross - node consistency verification mechanism relies on the decentralized consensus mechanism and zero - knowledge proof algorithm to ensure the integrity of encrypted data. The decentralized consensus mechanism avoids verification failures caused by single - node failures or malicious attacks, improving the reliability of verification. The zero - knowledge proof algorithm verifies data integrity without revealing the specific content of the data. Even if there are malicious nodes attempting to tamper with the data, it can be detected in a timely manner. In a distributed storage system, multiple edge nodes store different copies of the same data. Through this verification mechanism, the consistency and integrity of each copy can be ensured.
[0044] In terms of key update and storage, the key update model based on the time - decay function and blockchain technology play important roles. The time - decay function dynamically adjusts the key update period according to the historical access frequency of edge nodes. As time goes by, when the key security decreases, the key is updated in a timely manner, effectively preventing the key from being cracked. Blockchain technology distributes and stores the updated key to multiple edge nodes. Utilizing its decentralized, immutable, and traceable characteristics, it improves the security and reliability of key storage. Even if some nodes fail or are attacked, the key will not be lost or tampered with, ensuring long - term secure access to data.
[0045] The method for allocating access control policies parses the sensitivity levels of data sub - blocks and user role attributes, generates a multi - dimensional policy vector using lattice - based encryption algorithms, and embeds it into the encrypted data header through compression encoding by a Bloom filter. This approach achieves efficient and precise access control. Without occupying too much storage space, it can quickly determine whether a user has the right to access a data sub - block, enhancing the security and performance of the system. For example, in a medical data management system, different medical staff have different access rights to patient data, and this method can ensure the secure storage and reasonable access of patient data. Brief Description of the Drawings
[0046] Figure 1 It is the working principle diagram of the intelligent data security encryption method described in the present invention;
[0047] Figure 2 It is the step diagram of the adaptive selection of encryption algorithms;
[0048] Figure 3Step diagram for verifying cross - node consistency of zero - knowledge proof algorithms;
[0049] Figure 4 Flowchart for storing keys in blockchain technology. Detailed implementation manners
[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0051] Please refer to Figures 1-4 , the present invention provides an intelligent data security encryption method in an edge computing environment, aiming to ensure the security, integrity and controllability of access to data in the edge computing environment. The specific implementation steps are as follows:
[0052] Obtain the original data stream transmitted by edge nodes. In the edge computing scenario, the original data stream is generated and transmitted from each edge node, and may contain various types of data, such as data collected by sensors, device operation status data, etc. Perform discrete wavelet transform decomposition on the original data stream. Discrete wavelet transform is a mature signal processing technology that can decompose the original data stream into multiple data sub - blocks with different frequencies and resolutions for subsequent targeted processing of data with different characteristics. After generating multiple data sub - blocks, add a random perturbation sequence to each data sub - block based on the dynamic noise injection algorithm. This operation increases the complexity of the data by introducing random perturbations into the data sub - blocks, making it difficult for attackers to directly obtain the original data information, thereby improving the security of the data.
[0053] Construct a dynamic encryption policy network. This network comprehensively considers various factors of the data and provides flexible policy support for the encryption process. Generate a dynamic key matrix associated with the characteristics of the data sub - blocks through the chaotic mapping model. The chaotic mapping model has characteristics such as sensitivity to initial conditions and pseudo - randomness. The key matrix generated using these characteristics is closely related to the characteristics of the data sub - blocks, enhancing the security and pertinence of the keys. At the same time, assign an independent access control policy to each data sub - block based on the attribute - based encryption algorithm. The attribute - based encryption algorithm can precisely control the access rights of different users to the data sub - blocks according to factors such as the attributes of the data sub - blocks and the role attributes of users. Only users who meet specific attribute conditions can access the corresponding data sub - blocks, greatly improving the security and controllability of data access.
[0054] According to the security level of data sub - blocks and the real - time load status of edge nodes, adaptively select symmetric encryption or asymmetric encryption algorithms to perform block encryption on data sub - blocks. Data with different security levels require different levels of encryption to ensure security, and the real - time load status of edge nodes will affect the execution efficiency of encryption algorithms. By adaptively selecting the appropriate encryption algorithm, both the security of the data and the efficiency of the encryption process can be ensured. After completing the block encryption, generate encrypted metadata tags. These tags contain important information about the encrypted data sub - blocks and are used for subsequent data verification and management.
[0055] Build a collaborative verification network among edge nodes based on a decentralized consensus mechanism. The decentralized consensus mechanism avoids the problem of verification failure caused by a single node failure or malicious attack, improving the reliability of verification. Use the zero - knowledge proof algorithm to perform cross - node consistency verification on the encrypted metadata tags. The zero - knowledge proof algorithm can verify the integrity of the data without revealing the specific content of the data, ensuring that the encrypted data has not been tampered with during transmission and storage.
[0056] Dynamically adjust the period of the dynamic key matrix through a key update model based on a time - decay function. As time goes by, the security of the key will gradually decrease, so the key needs to be updated regularly. This model dynamically adjusts the key update period according to the time - decay function and relevant data of edge nodes to ensure the security of the key. Combine blockchain technology to distribute the updated key to multiple edge nodes. Blockchain technology has the characteristics of decentralization, immutability, and traceability. Storing the key distributedly on multiple edge nodes improves the security and reliability of key storage and prevents the key from being lost or tampered with.
[0057] The following further illustrates the implementation of the present invention in combination with Embodiments 1 to 6.
[0058] Embodiment 1:
[0059] In this embodiment, the specific implementation process of adding a random perturbation sequence to data sub - blocks based on the dynamic noise injection algorithm is described in detail.
[0060] After obtaining the original data stream transmitted by the edge node and decomposing it into multiple data sub - blocks through discrete wavelet transform, it enters the link of adding a random perturbation sequence.
[0061] Generating a Gaussian white noise basis according to the frequency-domain energy distribution of data sub-blocks is the first step. The frequency-domain energy distribution of data sub-blocks reflects the energy concentration of data in different frequency components. Taking a time-series data sub-block collected by a sensor as an example, it may contain more trend information in the low-frequency part, while the high-frequency part contains some noise and detail information. By performing a Fourier transform on the data sub-block, its frequency-domain representation can be obtained, and then the energy values of each frequency component can be acquired. Suppose the data sub-block is D, and after performing frequency-domain analysis on it, the energy value corresponding to frequency f is E(f). According to the distribution characteristics of these energy values, a Gaussian white noise basis N is generated using the properties of the Gaussian distribution. Gaussian white noise has a uniform power spectral density in the frequency domain, and its probability density function is where μ is the mean, usually set to 0; σ 2 is the variance, and the size of the variance is adjusted according to the frequency-domain energy distribution of the data sub-block. If the data sub-block has higher energy in certain specific frequency bands, in order to more effectively mask the data characteristics in these frequency bands, the variance of the Gaussian white noise in the corresponding frequency bands can be appropriately increased.
[0062] Using the random phase modulation algorithm to perform multi-scale transformation on the basis to generate a perturbation mask that matches the size of the data sub-block. The random phase modulation algorithm breaks the regularity of the noise and further enhances the randomness of the noise by introducing random phase changes. Specifically, a series of random phase values θ are generated, and their value range is between [0, 2π]. For each frequency component in the Gaussian white noise basis N, multiply it by e jθ (j is the imaginary unit) to achieve phase modulation. The multi-scale transformation is to process the noise of different frequency components to different extents to better adapt to the characteristics of the data sub-block. For example, for the noise in the low-frequency part, a larger scale transformation coefficient is used to make its change relatively gentle; for the noise in the high-frequency part, a smaller scale transformation coefficient is used to retain its detailed changes. After such multi-scale transformation, a perturbation mask M that exactly matches the size of the data sub-block is obtained.
[0063] Using the sliding window mechanism to perform an exclusive OR operation on the perturbation mask and the data sub-block pixel by pixel. The size of the sliding window is selected according to the type of data sub-block and the processing requirements. Suppose the selected sliding window size is m×n. Taking an image data sub-block as an example, starting from the upper left corner of the data sub-block, slide the window one pixel to the right and down with a step size of 1 pixel. At each pixel point (i, j) covered by the window, perform an exclusive OR operation on the pixel value at the corresponding position in the perturbation mask M and the value of this pixel point in the data sub-block D, that is, D(i, j) = D(i, j) ⊕ M(i, j). The characteristic of the exclusive OR operation is that the result is 0 when the two operands are the same, and 1 when they are different. In this way, the perturbation information is incorporated into the data sub-block, changing the pixel values of the original data to achieve the purpose of confusing the data.
[0064] Dynamically adjust the perturbation intensity parameter according to the computing resource limitations of edge nodes. Edge nodes usually have limited computing resources. If the perturbation intensity is too large, it may cause an excessive computing burden on edge nodes and affect their normal operation; if the perturbation intensity is too small, data security cannot be effectively guaranteed. Therefore, it is necessary to monitor the computing resource status of edge nodes in real time, such as indicators like CPU utilization rate and memory occupancy rate. Let the comprehensive evaluation value of the computing resources of the edge node be R. When R is lower than a preset threshold T, it indicates that the computing resources are tense. At this time, appropriately reduce the variance σ of the perturbation mask 2 , reduce the perturbation intensity to relieve the computing pressure on the edge node; when R is higher than the preset threshold T, it means that the computing resources are relatively sufficient, and the variance σ can be appropriately increased 2 , increase the perturbation intensity to further enhance the security of the data. Through this dynamic adjustment mechanism, while ensuring data security, it is ensured that edge nodes can operate stably and efficiently.
[0065] Example 2:
[0066] When generating a dynamic key matrix using the chaotic mapping model, the following specific steps are adopted:
[0067] First, generate an initial chaotic sequence based on the Logistic mapping iteration. The Logistic mapping is a simple and effective chaotic mapping model, and its mathematical expression is:
[0068] x n+1 = μx n (1 - x n )
[0069] where x n represents the result of the nth iteration, x n+1 represents the result of the (n + 1)th iteration, μ is the control parameter, and its value range is usually between (3.5699456, 4]. Different μ values will generate different chaotic sequences. In this embodiment, select an appropriate μ value, such as μ = 3.9, and set the initial value x0, for example, x0 = 0.5. Through multiple iterations, generate the initial chaotic sequence X = {x1, x2,..., x m}, where m is the number of iterations, which is determined according to the key length and security requirements. Generally, m takes a relatively large value, such as m = 1000.
[0070] Next, the hash digest of the data sub - block is injected into the chaotic system as a perturbation factor to generate a non - linear spread - spectrum sequence. The data sub - block is hashed to obtain its hash digest H. Hashing is an algorithm that maps data of any length to a fixed - length hash value. For example, the SHA - 256 algorithm is used. The hash digest H is converted into a numerical form and used as a perturbation factor to operate on the initial chaotic sequence. Assuming the perturbation operation function is F(X,H), the chaotic system is perturbed by performing a certain operation (such as addition, multiplication, etc.) on the elements of H and the initial chaotic sequence X to generate a non - linear spread - spectrum sequence Y. This perturbation makes the generated key closely related to the data sub - block, improving the security of the key.
[0071] Then, the spread - spectrum sequence is divided into multiple sub - key segments according to a preset segmentation rule. The preset segmentation rule is determined according to the length and usage requirements of the key. For example, assuming the length of the generated spread - spectrum sequence Y is L, and it is divided into n sub - key segments, with the length of each sub - key segment being l, then L = n×l. If the key length requirement is 128 bits and the spread - spectrum sequence length is 1024 bits, it can be divided into 8 sub - key segments, each with a length of 128 bits.
[0072] Finally, based on the Hamming code error - correction algorithm, redundant coding is performed on the sub - key segments to form the row vectors of the dynamic key matrix. The Hamming code error - correction algorithm is a coding technique that can detect and correct errors. For each sub - key segment Y i (i = 1,2,…,n), redundant bits are added according to the coding rules of the Hamming code. Let the length of the sub - key segment Y i be l, and the length of the coded sub - key segment after adding redundant bits is l + r, where r is the number of redundant bits, and r is determined according to the parity relationship of the Hamming code. After redundant coding, these coded sub - key segments are used as the row vectors of the dynamic key matrix, thus constructing the dynamic key matrix. In this way, even if a small number of errors occur during key transmission or storage, the correct key can be restored through the error - correction function of the Hamming code, improving the reliability of the key.
[0073] Example 3:
[0074] The specific implementation method of adaptively selecting the encryption algorithm is as follows:
[0075] First, the CPU utilization rate, memory occupancy rate, and network latency parameters of the edge nodes are statistically analyzed to construct a resource evaluation vector. The CPU utilization rate represents the busy degree of the CPU over a period of time. Assuming that within the time interval t, the time when the CPU is in a busy state is t busy , then the CPU utilization rate The memory occupancy rate reflects the proportion of the currently used memory to the total memory. Let the total memory size be M total , and the size of the used memory be Mused , the memory occupancy rate The network latency parameter refers to the time it takes for data to be transmitted in the network. By sending test data packets to a specific server and recording the round-trip time, the network latency D is obtained by taking the average value after multiple measurements. net . Combine these three parameters into a resource evaluation vector
[0076] Next, calculate the membership degree of the resource evaluation vector and the preset threshold through the fuzzy logic decision model. The fuzzy logic decision model is a decision-making method that can handle fuzzy and uncertain information. Preset two thresholds, the first threshold is α, and the second threshold is β (α > β). Define fuzzy sets. For example, for CPU utilization, define fuzzy sets such as "high", "medium", and "low"; similar fuzzy set definitions are also made for memory occupancy rate and network latency. According to the fuzzy logic rules, map each element in the resource evaluation vector to the corresponding fuzzy set and calculate its membership degree. For example, for CPU utilization U CPU , if U CPU > α, then its membership degree to the "high" fuzzy set is 1, and the membership degrees to the "medium" and "low" fuzzy sets are 0; if β < U CPU ≤ α, then calculate its membership degrees to the "high" and "medium" fuzzy sets through a specific membership function (such as a triangular membership function, a trapezoidal membership function, etc.).
[0077] Finally, select the encryption algorithm according to the calculation results of the membership degrees. If the membership degree is higher than the first threshold α, it means that the resources of the edge node are relatively sufficient. At this time, the AES symmetric encryption algorithm is enabled. The AES symmetric encryption algorithm has the advantages of fast encryption and decryption speeds and is suitable for use when resources are sufficient. If the membership degree is lower than the first threshold α, then the RSA asymmetric encryption algorithm is enabled. The RSA asymmetric encryption algorithm has high security but a large computational complexity. When resources are relatively scarce, although the encryption and decryption speeds are slower, it can ensure the security of data. By this way of adaptively selecting the encryption algorithm, the most suitable encryption algorithm can be selected under different resource conditions of the edge node, balancing encryption efficiency and security.
[0078] Example 4:
[0079] The specific method for generating the encrypted metadata tag is as follows:
[0080] Extract the entropy value feature and position index of the encrypted data sub-block. The entropy value is an index to measure the uncertainty or randomness of data. For the encrypted data sub-block E, the calculation of its entropy value H(E) can be through the information entropy formula:
[0081]
[0082] where n is the number of different data values in the data sub - block, and p i is the probability of the i - th data value occurring. By calculating the entropy value, the degree of chaos of the encrypted data can be reflected. The higher the entropy value, the stronger the randomness of the data and the better the encryption effect. The position index is used to record the position information of the data sub - block in the original data. Assuming that the starting position of the data sub - block in the original data is (x, y), the length is l, and the width is w, then the position index can be expressed as [(x, y), l, w].
[0083] Use the Merkle tree structure to perform multi - level hash aggregation on the features. A Merkle tree is a tree - shaped data structure. Each leaf node is the hash value of a data sub - block, and each non - leaf node is the hash value of the hash values of its two child nodes. First, perform a hash operation on the entropy value feature and the position index of each data sub - block to obtain the hash values h1, h2, …, h m (m is the number of data sub - blocks). Then, combine the hash values of two adjacent leaf nodes and perform a hash operation again to obtain the hash values of the nodes in the upper layer, and so on, until the root hash value h root is generated. This multi - level hash aggregation method can efficiently verify the integrity of the data, and when the data volume is large, it can reduce the computational amount and storage space required for verification.
[0084] Combine the aggregated root hash value with the digital signature of the data sub - block to generate a metadata tag containing a timestamp and node identity information. The digital signature is the result of encrypting the data using a private key and is used to verify the source and integrity of the data. Let the digital signature be S, the timestamp be T, and the node identity information be I, then the format of the metadata tag L is:
[0085] L = [h root , S, T, I]
[0086] Combining these information together forms an encrypted metadata tag. In the subsequent data verification process, the integrity and source reliability of the encrypted data can be ensured by verifying the information in the metadata tag.
[0087] Example 5:
[0088] When performing cross - node consistency verification and constructing a key update model for a time - decay function, the following specific method is adopted:
[0089] Convert the encrypted metadata tag into the form of polynomial commitment, and generate a challenge-response interactive proof based on the Fiat-Shamir heuristic protocol. The encrypted metadata tag contains important information about the encrypted data sub-blocks. To verify its integrity without revealing the data content, it is converted into the form of polynomial commitment. Let the encrypted metadata tag be L, and it is converted into a polynomial P(x) through a specific conversion function f(L). The Fiat-Shamir heuristic protocol is a method to convert an interactive proof into a non-interactive proof. The verifier randomly generates a challenge value c and sends it to the prover. The prover calculates the response value r based on the polynomial P(x) and the challenge value c, and returns the response value to the verifier. The verifier determines whether the prover has the correct encrypted metadata tag by verifying whether P(c) is equal to the expected value calculated according to the response value r.
[0090] Next, cross-verify the response results of multiple edge nodes through the random oracle model. The random oracle model is an idealized hash function model, which is used to simulate hash operations in this embodiment. Suppose there are N edge nodes participating in the verification. For the response result r i (i = 1, 2, …, N) of each edge node, use the random oracle model to calculate the hash value H(r i ). The verifier compares these hash values. If the hash values of more than half of the nodes are the same, it is determined that the data integrity is established. For example, when N = 7, if the hash values of at least 4 nodes are the same, it is considered that the encrypted data has not been tampered with during transmission and storage, and the data integrity is guaranteed.
[0091] In terms of constructing a key update model for the time decay function, set the key life cycle as an exponential decay curve, and dynamically adjust the decay rate according to the historical access frequency of the edge nodes. Let the initial strength of the key be K0, the time be t, and the decay rate be λ. Then the change of the key strength over time can be expressed by the exponential decay function as:
[0092] K(t) = K0e -λt
[0093] where λ is adjusted according to the historical access frequency of the edge nodes. The historical access frequency of the edge nodes can be obtained by counting the number of accesses to the data within a certain period of time. Let the historical access frequency be f. When the access frequency is high, it means that the key is used frequently. To ensure security, appropriately increase the decay rate λ; when the access frequency is low, decrease the decay rate λ. For example, a functional relationship λ = αf + β can be set, where α and β are constants determined according to the actual situation.
[0094] When the remaining valid value of the key is lower than the second threshold, the key regeneration protocol is triggered. Let the second threshold be γ. When K(t) < γ, the key regeneration protocol is started. The distributed authorization credentials for the new key are generated using the ring signature algorithm. The ring signature algorithm is an anonymous signature technology. In this embodiment, multiple edge nodes form a ring, and the distributed authorization credentials for the new key are generated through the ring signature algorithm, so that in the process of generating the new key, the identities of each node have a certain degree of anonymity, improving the security of the key generation process.
[0095] Embodiment 6:
[0096] When executing the key regeneration protocol, first, multiple edge nodes are selected as key trustees. These multiple edge nodes usually have a certain degree of security and stability to ensure the secure storage and management of the key. For example, edge nodes with relatively strong computing power, stable network connections, and good reputations are selected from the entire edge computing network as key trustees. Suppose n edge nodes are selected as key trustees.
[0097] Based on the Shamir secret sharing scheme, the new key is split into multiple sub-shares. The Shamir secret sharing scheme is a method of splitting and storing secrets, and its core principle is based on Lagrange interpolation polynomials. Let the new key be K, and regard it as the value of a polynomial f(x) at x = 0, that is, f(0) = K. Construct a polynomial f(x) = a k-1 x k-1 +...+a1x+a0, where a0 = K, and a1, a2,…,a k-1 are randomly selected coefficients. Then, in a finite field (p is a prime number greater than K and greater than all x values), a different x value is selected for each key trustee, such as x1, x2,…,x n , and the corresponding y i =f(x i ) is calculated. These y i are the sub-shares of the new key K. Each key trustee holds a pair of (x i ,y i ).
[0098] Through the threshold signature algorithm, at least K trustees are required to jointly sign to reconstruct the complete key, where K is a preset security threshold value. The threshold signature algorithm ensures that the key can only be reconstructed when a certain number of trustees participate together, improving the security of the key. When the key needs to be reconstructed, any at least K pairs of (x i ,y i ) of the trustees are selected, and using the Lagrange interpolation formula:
[0099]
[0100] Calculate the polynomial f(x), and then obtain f(0), that is, reconstruct the complete new key K. For example, if K = 3 is preset, any 3 of the n trustees can be selected, and the key can be reconstructed using the above formula.
[0101] In terms of storing keys using blockchain technology, the updated keys are organized in the Merkle-Patricia tree structure. The Merkle-Patricia tree is a data structure that combines the advantages of the Merkle tree and the prefix tree, and can efficiently store and verify data. The updated keys are split into multiple data blocks, and each data block serves as a leaf node of the tree. Hash operations are performed on the leaf nodes, and intermediate nodes are constructed based on the hash values, and finally a root node is formed. Each node contains not only the hash value but also records the version number and the forward hash. The version number is used to identify different versions of the key, and the forward hash is used to connect the front and back key blocks to form the chain structure of the blockchain.
[0102] Based on the proof-of-stake consensus mechanism, the master node is elected to verify the key blocks. The proof-of-stake mechanism allocates the accounting right according to the rights and interests held by the nodes (such as resource contributions and reputations in the edge computing network). Nodes with higher rights and interests have a greater probability of being elected as the master node. The master node is responsible for collecting and verifying the legality of the key blocks, checking whether the key data in the blocks is complete and whether the hash values are correct, etc. After passing the verification, the verified blocks are broadcast to the local ledgers of all edge nodes. In this way, all edge nodes have the same key storage records, ensuring the consistency and immutability of key storage.
[0103] When allocating access control policies, parse the sensitivity level and user role attributes of the data sub-blocks. The sensitivity level of the data sub-blocks can be determined according to factors such as the content and source of the data. For example, data sub-blocks containing personal privacy information have a higher sensitivity level, while some public and general data sub-blocks have a lower sensitivity level. The user role attributes are divided according to the user's permissions and responsibilities in the system, such as administrators, ordinary users, etc.
[0104] Use the lattice-based encryption algorithm to generate a multi-dimensional policy vector. The lattice-based encryption algorithm has the characteristics of high security and relatively good computational efficiency. According to the sensitivity level and user role attributes of the data sub-blocks, a multi-dimensional vector is generated in the lattice space as the policy vector. For example, if the sensitivity level is divided into 3 levels: high, medium, and low, and there are 2 types of user roles: administrator and ordinary user, then the policy vector may be a 5-dimensional vector, and different dimensions correspond to the permission information of different combinations of sensitivity levels and user roles.
[0105] The policy vector is compressed and encoded through a Bloom filter, and the encoding result is embedded into the policy description field of the encrypted data header. A Bloom filter is a probabilistic data structure with high space efficiency that can quickly determine whether an element belongs to a set. The elements in the multi-dimensional policy vector are mapped to multiple hash functions of the Bloom filter to generate a series of bit vectors, realizing the compression and encoding of the policy vector. Then, the result of the compressed encoding is embedded into the policy description field of the encrypted data header. When a user requests access to data, the system can quickly obtain the corresponding policy information from the policy description field according to the user's role attributes, and determine whether the user has the permission to access the data sub-block, thereby realizing efficient access control.
[0106] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0107] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An intelligent data security encryption method in an edge computing environment, characterized in that, The method includes the following steps: Obtain the original data stream transmitted by the edge node, perform discrete wavelet transform decomposition on the original data stream to generate multiple data sub-blocks, and add a random perturbation sequence to each data sub-block based on the dynamic noise injection algorithm; Construct a dynamic encryption policy network, generate a dynamic key matrix associated with the characteristics of the data sub-block through a chaotic mapping model, and assign an independent access control policy to each data sub-block based on the attribute-based encryption algorithm; According to the security level of the data sub-block and the real-time load status of the edge node, adaptively select a symmetric encryption or asymmetric encryption algorithm to perform block encryption on the data sub-block and generate an encrypted metadata tag; Construct a collaborative verification network among edge nodes based on a decentralized consensus mechanism, and use the zero-knowledge proof algorithm to perform cross-node consistency verification on the encrypted metadata tag to ensure the integrity of the encrypted data; Dynamically adjust the period of the dynamic key matrix through a key update model based on a time decay function, and combine blockchain technology to distribute and store the updated key to multiple edge nodes.
2. The intelligent data security encryption method in an edge computing environment according to claim 1, wherein The method of adding a random perturbation sequence to each data sub-block based on the dynamic noise injection algorithm includes: Generate a Gaussian white noise base according to the frequency domain energy distribution of the data sub-block, and perform multi-scale transformation on the base using the random phase modulation algorithm to generate a perturbation mask matching the size of the data sub-block; Perform pixel-by-pixel exclusive OR operation on the perturbation mask and the data sub-block through a sliding window mechanism, and dynamically adjust the perturbation intensity parameter according to the computing resource limitation of the edge node.
3. An intelligent data security encryption method in an edge computing environment according to claim 1, characterized in that, The method for the chaotic mapping model to generate a dynamic key matrix includes: Generate an initial chaotic sequence based on Logistic mapping iteration, inject the hash digest of the data sub-block as a perturbation factor into the chaotic system to generate a non-linear spread spectrum sequence; Divide the spread spectrum sequence into multiple sub-key segments according to a preset segmentation rule, and perform redundant coding on the sub-key segments based on the Hamming code error correction algorithm to form the row vectors of the dynamic key matrix.
4. The intelligent data security encryption method in an edge computing environment according to claim 1, characterized in that, The implementation method of adaptively selecting an encryption algorithm includes: Statistically analyze the CPU utilization rate, memory occupancy rate, and network delay parameters of the edge node to construct a resource evaluation vector; Calculate the membership degree of the resource evaluation vector and a preset threshold through a fuzzy logic decision model. If the membership degree is higher than the first threshold, enable AES symmetric encryption; otherwise, enable RSA asymmetric encryption.
5. An intelligent data security encryption method in an edge computing environment according to claim 1, characterized in that, The method for generating an encrypted metadata tag includes: Extract the entropy value feature and position index of the encrypted data sub-block, and perform multi-level hash aggregation on the features using the Merkle tree structure; Combine the aggregated root hash value with the digital signature of the data sub-block to generate a metadata tag containing a timestamp and node identity information.
6. The intelligent data security encryption method in an edge computing environment according to claim 1, wherein, The method for the zero-knowledge proof algorithm to perform cross-node consistency verification includes: Convert the encrypted metadata tag into a polynomial commitment form, and generate a challenge-response interactive proof based on the Fiat-Shamir heuristic protocol; Perform cross-verification on the response results of multiple edge nodes through a random oracle model. If more than half of the nodes pass the verification, it is determined that the data integrity is established.
7. An intelligent data security encryption method in an edge computing environment according to claim 1, characterized in that The construction method of the key update model based on the time decay function includes: Set the key life cycle as an exponential decay curve and dynamically adjust the decay rate according to the historical access frequency of edge nodes; When the remaining valid value of the key is lower than the second threshold, trigger the key regeneration protocol and use the ring signature algorithm to generate distributed authorization credentials for the new key.
8. The intelligent data security encryption method in an edge computing environment according to claim 7, wherein The execution method of the key regeneration protocol includes: Select multiple edge nodes as key trustees and split the new key into multiple sub-shares based on the Shamir secret sharing scheme; Require at least K trustees to jointly sign to reconstruct the complete key through the threshold signature algorithm, where K is a preset security threshold value.
9. The intelligent data security encryption method in an edge computing environment according to claim 1, wherein The method for storing keys by the blockchain technology includes: Organize the updated keys in the Merkle-Patricia tree structure to generate key blocks containing version numbers and forward hashes; Elect a master node based on the proof-of-stake consensus mechanism to verify the key blocks and broadcast the verified blocks to the local ledgers of all edge nodes.
10. An intelligent data security encryption method in an edge computing environment according to claim 1, characterized in that, The distribution method of the access control policy includes: Analyze the sensitivity level and user role attributes of data sub-blocks and generate a multi-dimensional policy vector using the lattice-based encryption algorithm; Compress and encode the policy vector through a Bloom filter and embed the encoding result into the policy description field of the encrypted data header.
Citation Information
Cited By
Transmission data encryption method for network data
CN120512307A
Block chain-based mesenchymal stem cell safety inspection method and system
CN120750600A
Energy data dynamic encryption method and system based on edge computing
CN120896748A
An energy data dynamic encryption method and system based on edge computing
CN120896748B