Data security and communication method based on password technology
Through risk monitoring and analysis of databases and IP, model construction combined with random forest algorithms, and dynamically adjusting encryption levels, the balance between communication security and system performance is solved, and risk adaptability adjustment in each communication process is achieved.
Patent Information
- Application Number
- CN202510764496.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, it is difficult to dynamically adjust the encryption level in a single communication process to balance communication security with system performance, resulting in too low encryption level in some scenarios affecting security, while too high overall encryption level reduces communication efficiency.
By monitoring the risk of the database and access IP, the first and second risk statuses are obtained respectively, and the database risk events are identified in combination with the random forest algorithm, security and performance models are built, and communication strategies are determined after comprehensive analysis and appropriate password encryption levels are selected.
The encryption level is dynamically adjusted according to the risk level of each communication process, ensuring the balance between communication security and system performance, and avoiding the security or efficiency problems caused by individual adjustments.
Smart Images

Figure CN120342775A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication security, and specifically provides a data security and communication method based on cryptographic technology. Background Art
[0002] Communication security is the core cornerstone of a digital society. Its importance lies not only in the technical aspect but also in personal privacy, corporate survival, economic order, etc. With the complexity of cyberattacks and the normalization of APT (Advanced Persistent Threat), communication security has been upgraded from "optional" to "essential". Among them, data security communication methods using cryptographic technology need to comprehensively apply various encryption technologies and security protocols to ensure data confidentiality, integrity, identity authentication, and non-repudiation.
[0003] In the prior art, different cryptographic encryption technologies are adopted to ensure the security of data transmission and communication, that is, different encryption levels are used for different scenarios to meet the security and performance requirements of communication processes in different scenarios. Although this method can generally ensure the balance between communication security and system performance, for the communication process between different points, if the encryption level is too low, it will affect the security of a single communication process. If the overall encryption level is set too high, although the security of a single communication process can be ensured, it will also have an adverse impact on the system load and reduce the efficiency of the communication process. Therefore, how to dynamically adjust the encryption level for a single communication process to ensure the balance between communication security and system performance is the fundamental problem to be solved by the present invention. Summary of the Invention
[0004] The purpose of the present invention is to provide a data security and communication method based on cryptographic technology, and solve the following technical problems: How to dynamically adjust the encryption level for a single communication process to ensure the balance between communication security and system performance.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A data security and communication method based on cryptographic technology, the method includes: Perform a first risk monitoring on the database to obtain a first risk status; Perform a second risk monitoring on the access IP to obtain a second risk status; Determine a communication strategy according to the first risk status and the second risk status, and different communication strategies adopt different cryptographic encryption levels.
[0006] Through the above technical solution, the database environment and IP risks are comprehensively monitored and analyzed to obtain the first risk status and the second risk status respectively. The first risk status reflects the security risk status of the database, and the second risk status reflects the security risk status of the reverse IP. Therefore, by combining the first risk status and the second risk status, the overall risk level of each IP during the communication process with the database is determined, and the corresponding communication strategy is determined, that is, the corresponding encryption level can be determined according to the risk degree of each communication process, ensuring the balance between communication security and system performance.
[0007] Further, the process of the first risk monitoring includes: Obtain the log file of the database, identify and classify the risk events of the database based on the random forest algorithm, and obtain the security model and the performance model; among them, the security model is expressed as follows:
[0008] Where n is the number of security problems, i is a positive integer and i ∈ [1, n], is the weight value of the i-th security problem, is the judgment value of the i-th indicator. When a security problem occurs , otherwise, ; is the security risk value; The performance model is expressed as follows:
[0009]
[0010]
[0011]
[0012]
[0013] Among them, is the initial performance risk coefficient, d is the average delay, is the delay threshold, is a defined function. When any one of A and B is zero, , otherwise, , is the first step function, is the delay coefficient, L is the packet loss ratio, is the average packet loss ratio threshold, is the second step function, is the packet loss coefficient, B is the bandwidth ratio, is the bandwidth ratio threshold, is the third step function, is the bandwidth coefficient, is the delay packet loss coefficient, is the delay bandwidth coefficient, is the packet loss bandwidth coefficient, is the performance risk coefficient; According to the security risk value and the performance risk coefficient obtain the first risk state.
[0014] Through the above technical solution, based on the obtained security risk value, the security state of the database can be judged; in addition, for the system performance risk, the influence degree of the three factors of network delay, packet loss rate and bandwidth occupancy on the database operation risk is determined to judge, and according to the security risk value and the performance risk coefficient obtain the first risk state, and then the security risk of the overall database can be judged.
[0015] Further, the process of obtaining the first risk state according to the security risk value and the performance risk coefficient includes: Based on the security risk value and the performance risk coefficient construct a first risk model to obtain a first risk value R1. The first risk model is expressed as follows: .
[0016] Through the above technical solution, by integrating the security risk and operation performance risk factors in the database, the risk state of the database can be evaluated by the magnitude of the first risk value R1.
[0017] Further, the process of the second risk monitoring includes: Conduct attribute analysis and blacklist query on the IP. Interrupt communication when it is judged that the IP is abnormal, and obtain IP access data when it is judged that the IP is not abnormal. Build an IP risk model based on the IP access data, and obtain a second risk state according to the IP risk model.
[0018] Through the above technical solution, the IP risk is judged in real time through the data during the IP access process, and then an appropriate encryption level can be selected in the subsequent communication process, thus ensuring the balance between communication security and system performance.
[0019] Further, the IP risk model is expressed as follows:
[0020]
[0021] Among them, is the cumulative request number change curve of the IP within the preset historical period, represents within the preset historical period the maximum value of is the cumulative request number of the IP within the preset historical period, is a judgment function. When x ≤ 0, otherwise, ; is the cumulative request number warning value, is the comparison table coefficient, is the IP request sequence consistency coefficient. m is the number of differences between adjacent IP request time points, j is a positive integer and j ∈ [1, m], is the jth adjacent IP request time difference, is the average value of all adjacent IP request time differences.
[0022] Through the above technical solution, when the IP access volume reaches the warning value within a period of time, it can be judged according to the speed of the IP surge and the regularity of the IP access. When the speed of the IP surge is faster and the regularity is higher (the IP is entrusted), it indicates that the risk of the IP is higher. Therefore, the risk status of the IP is judged by the size of R2.
[0023] Furthermore, the process of determining the communication strategy includes: Calculate the risk value R through the formula and obtain the communication strategy corresponding to the interval where the risk value R is located; Among them, u1, u2, and u3 are weight coefficients.
[0024] Through the above technical solution, Furthermore, the communication strategy includes four levels of password encryption levels. Among them, the first-level password encryption level uses the AES-128 encryption algorithm; the second-level password encryption level uses the AES-256 encryption algorithm; the third-level password encryption level uses the SM4 encryption algorithm; the fourth-level password encryption level uses the Kyber-1024 encryption algorithm.
[0025] Through the above technical solution, it is possible to determine a suitable encryption method according to the database and the IP risk status during each communication, thereby ensuring the balance between communication security and system performance.
[0026] Furthermore, the process of the attribute analysis includes IP geographical attribute judgment, IP proxy status judgment, and IP affiliated ISP judgment.
[0027] The beneficial effects of the present invention: (1) By comprehensively monitoring and analyzing the database environment and IP risks, the present invention obtains the first risk status and the second risk status respectively. The first risk status reflects the security risk status of the database, and the second risk status reflects the security risk status of the access IP. Therefore, by combining the first risk status and the second risk status, the overall risk level of each communication process between the IP and the database is determined, and the corresponding communication strategy is determined, that is, the corresponding encryption level can be determined according to the risk degree of each communication process, ensuring the balance between communication security and system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The present invention will be further described below with reference to the accompanying drawings.
[0029] Figure 1 It is a flowchart of the steps of the data security and communication method based on cryptographic technology of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0031] In one embodiment, a data security and communication method based on cryptographic technology is provided. Please refer to Figure 1 As shown, the method includes: performing a first risk monitoring on the database to obtain the first risk status; performing a second risk monitoring on the access IP to obtain the second risk status; determining a communication strategy according to the first risk status and the second risk status. Different communication strategies adopt different password encryption levels. In this embodiment, by comprehensively monitoring and analyzing the database environment and IP risks, the first risk status and the second risk status are obtained respectively. The first risk status reflects the security risk status of the database, and the second risk status reflects the security risk status of the access IP. Therefore, by combining the first risk status and the second risk status, the overall risk level of each communication process between the IP and the database is determined, and the corresponding communication strategy is determined, that is, the corresponding encryption level can be determined according to the risk degree of each communication process, ensuring the balance between communication security and system performance.
[0032] In one embodiment, a process for first risk monitoring is provided, including: First, obtain the log file of the database, identify and classify the risk events of the database based on the random forest algorithm, and obtain the security model and the performance model; wherein, based on the random forest algorithm, the risk events in the database can be classified, such as abnormal access and sensitive operations, etc. By integrating multiple decision trees, the generalization ability is improved, so it has better recognition ability and classification accuracy. The random forest algorithm is obtained based on the prior art training and will not be elaborated here; the content identified and classified by the random forest algorithm is divided into two categories, one is the security problem, and the other is the performance parameter. Among them, a security model is established for the identified security problem, which is expressed as follows:
[0033] where n is the number of security problems, i is a positive integer and i ∈ [1, n], is the weight value of the i-th security problem, which is set according to the severity of different security problems in the empirical data, is the judgment value of the i-th indicator, when a security problem occurs , otherwise, ; is the security risk value; therefore, based on the obtained security risk value, the security status of the database can be judged. Additionally, regarding system performance risks, they are mainly affected by three factors: network latency, packet loss rate, and bandwidth occupancy. High network latency may cause some security protocols to time out. For example, the TLS handshake may take longer. If the latency is too high, the handshake may fail, thus affecting the establishment of an encrypted connection. Moreover, high latency may also give attackers the opportunity to perform man-in-the-middle attacks, especially when the timeout mechanism is not properly implemented. At the same time, when the packet loss rate is too high, the retransmission of data packets will increase, which not only affects the transmission efficiency but may also be exploited by attackers. For example, during the retransmission process, attackers may infer sensitive information by analyzing the retransmitted packets or launch a denial-of-service attack to prevent legitimate users from communicating normally. In addition, if the encryption protocol does not handle packet loss properly, the overall security may be reduced. Regarding bandwidth occupancy, a large amount of bandwidth occupancy may lead to network congestion, and the data packets of legitimate users may be delayed or lost. At this time, attackers may launch a DDoS attack using the situation of bandwidth exhaustion, further exacerbating network instability. Therefore, network latency, packet loss rate, and bandwidth occupancy are the main factors threatening the performance security of the database. At the same time, there will be an interaction problem among the above three factors. When high latency and packet loss exist simultaneously, it will cause protocol degradation due to encrypted retransmission, which may lead to being hijacked by a man-in-the-middle, and there are risks such as session key leakage and data tampering. When high bandwidth and packet loss exist simultaneously, there are risks of DDoS masking covert channels and data exfiltration, which may lead to problems such as sensitive information theft and lateral movement. When high latency and high bandwidth exist simultaneously, there is a risk of real-time defense failure, which may lead to problems such as system compromise and ransomware implantation. Therefore, in this embodiment, a performance model is established based on the three factors of network latency, packet loss rate, and bandwidth occupancy, which is expressed as follows:
[0034]
[0035]
[0036]
[0037]
[0038] Among them, is the initial performance risk coefficient, d is the average latency,[[]] is the latency threshold,[[]] is a defined function. When either A or B is zero,[[]] otherwise,[[]] [[]] is the first-step function,[[]] is the latency coefficient, L is the packet loss ratio,[[]] is the average packet loss ratio threshold value, is the second step function, is the packet loss coefficient, B is the bandwidth occupancy ratio, is the bandwidth occupancy ratio threshold value, is the third step function, is the bandwidth coefficient, is the delay packet loss coefficient, is the delay bandwidth coefficient, is the packet loss bandwidth coefficient, is the performance risk coefficient; among the above parameters, the step functions , , respectively set the corresponding values according to the influence degrees corresponding to different ranges where the differences between the parameters and the threshold values in the empirical data are located. The delay threshold , the average packet loss ratio threshold value and the bandwidth occupancy ratio threshold value are set according to the relevant standard data in the empirical data. Therefore, through the obtaining processes of the delay coefficient , the packet loss coefficient , the bandwidth coefficient and the initial performance risk coefficient , it is possible to determine the influence degree of the ranges of the three factors of network delay, packet loss rate, and bandwidth occupancy on the database operation risk, and at the same time consider the mutual influence process among the three factors. Therefore, in this embodiment, the corresponding coefficients are set according to the overall influence degree of any two factors in the empirical data, and then the delay packet loss coefficient , the delay bandwidth coefficient , and the packet loss bandwidth coefficient is . Therefore, through the obtaining process of the performance risk coefficient , it is further possible to judge the influence degree of the three factors of network delay, packet loss rate, and bandwidth occupancy on the database performance operation risk. Therefore, according to the security risk value and the performance risk coefficient , the first risk state is obtained, and then the overall security risk of the database can be judged.
[0039] In one embodiment, a process for obtaining the first risk state according to the security risk value and the performance risk coefficient is given, including: constructing a first risk model based on the security risk value and the performance risk coefficient to obtain the first risk value R1, and the first risk model is expressed as , since when the security risk and operation performance risk of the system occur simultaneously, the corresponding risk of the system increases exponentially. Therefore, by integrating the factors of security risk and operation performance risk in the database through the first risk model, the risk status of the database can be evaluated by the magnitude of the first risk value R1.
[0040] In one embodiment, a process of second risk monitoring is given, including: performing attribute analysis and blacklist query on the IP. The process of attribute analysis includes judging the geographical attribute of the IP, judging the proxy status of the IP, and judging the ISP (Internet Service Provider) to which the IP belongs. Through the above process of attribute analysis and blacklist query, the risk of the IP can be directly judged. When it is judged that the IP is abnormal, the communication is interrupted. When it is judged that the IP is normal, the IP access data is obtained. An IP risk model is obtained by modeling according to the IP access data. The second risk status is obtained according to the IP risk model. The risk of the IP is judged in real time through the data during the IP access process, and then an appropriate encryption level can be selected in the subsequent communication process, thus ensuring the balance between communication security and system performance.
[0041] In one embodiment, the IP risk model is expressed as follows:
[0042]
[0043] Wherein, is the cumulative request number change curve of the IP within a preset historical period, represents within the preset historical period the maximum value of, is the cumulative request number of the IP within a preset historical period. The preset historical period is set according to the data volume of the database and actual requirements and is not limited here. is a judgment function. When x ≤ 0, otherwise, ; is the cumulative request number warning value, which is set according to the historical average data of the database. is the IP request sequence consistency coefficient. is the comparison table coefficient, which sets the corresponding coefficient according to the range where is located in the test data, and satisfies The larger the value, the larger the corresponding coefficient. m is the number of differences between adjacent IP request time points, j is a positive integer and j ∈ [1, m], is the j-th adjacent IP request time difference. is the average value of the time differences between adjacent IP requests. Through the above IP risk model, when the IP access volume reaches the warning value within a certain period of time, it can be judged according to the speed of IP surge and the regularity of IP access. When the speed of IP surge is faster and the regularity is higher (the IP is entrusted), it indicates that the risk of this IP is higher. Therefore, the risk status of the IP is judged by the size of R2.
[0044] In one embodiment, the process of determining the communication strategy is given, including: through the formula Calculate to obtain the risk value R, and obtain the communication strategy corresponding to the interval where the risk value R is located; where u1, u2, and u3 are weight coefficients, and the weight coefficients are set according to the test data according to the influence degrees of the database and the IP and the comprehensive factors of both. Therefore, by comprehensively considering the database risk, IP risk and the comprehensive influence of both, the risk status of each communication security can be judged, that is, the corresponding communication strategy is determined according to the range where the obtained risk value R is located, and then the corresponding password encryption level is determined. Among them, different ranges where different risk values R are located in the test data are divided into different intervals, and the corresponding encryption levels are set according to the risk status corresponding to different intervals. Therefore, the appropriate encryption method can be determined according to the database and IP risk status during each communication, thus ensuring the balance between communication security and system performance.
[0045] It is judged that in one embodiment, the communication strategy includes four levels of password encryption levels. Among them, the first-level password encryption level uses the AES-128 encryption algorithm; the second-level password encryption level uses the AES-256 encryption algorithm; the third-level password encryption level uses the SM4 encryption algorithm; the fourth-level password encryption level uses the Kyber-1024 encryption algorithm. The encryption intensity of the encryption algorithm corresponding to each of the above levels increases with the increase of the level, and the key life cycle decreases with the increase of the encryption level. Through the above division of the password encryption levels, the corresponding encryption method can be determined according to the security status of each communication process, ensuring the balance between communication security and system performance.
[0046] The above has described an embodiment of the present invention in detail, but the content described is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the present invention application should still fall within the scope covered by the patent of the present invention.
Claims
1. A data security and communication method based on cryptographic technology, characterized in that The method includes: Performing a first risk monitoring on the database to obtain a first risk status; Performing a second risk monitoring on the access IP to obtain a second risk status; Determining a communication strategy according to the first risk status and the second risk status, and different communication strategies adopt different password encryption levels.
2. A data security and communication method based on cryptographic technology according to claim 1, characterized in that, The process of the first risk monitoring includes: Obtaining the log file of the database, identifying and classifying the risk events of the database based on the random forest algorithm to obtain a security model and a performance model; wherein, the security model is expressed as follows: ; where n is the number of security issues, i is a positive integer and i ∈ [1, n], is the weight value of the i-th security issue, is the judgment value of the i-th indicator. When a security issue occurs , otherwise, ; is the security risk value; The performance model is expressed as follows: ; ; ; ; ; Among them, is the initial performance risk coefficient, d is the average delay volume, is the delay volume threshold, is a defined function. When any one of A and B is zero, , otherwise, , is the first step function, is the delay coefficient, L is the packet loss ratio, is the average packet loss ratio threshold, is the second step function, is the packet loss coefficient, B is the bandwidth ratio, is the bandwidth ratio threshold, is the third step function, is the bandwidth coefficient, is the delay packet loss coefficient, is the delay bandwidth coefficient, is the packet loss bandwidth coefficient, is the performance risk coefficient; According to the security risk value and the performance risk coefficient Obtain the first risk status.
3. A data security and communication method based on cryptographic technology according to claim 2, characterized in that, According to the security risk value and the performance risk coefficient The process of obtaining the first risk state includes: Based on the security risk value and the performance risk coefficient Construct a first risk model to obtain a first risk value R1. The first risk model is expressed as follows: 。 4. A data security and communication method based on cryptographic technology according to claim 3, characterized in that, The process of the second risk monitoring includes: Performing attribute analysis and blacklist query on the IP, interrupting communication when it is determined that the IP is abnormal, obtaining IP access data when it is determined that the IP is not abnormal, modeling according to the IP access data to obtain an IP risk model, and obtaining a second risk status according to the IP risk model.
5. A data security and communication method based on cryptographic technology according to claim 4, characterized in that, The IP risk model is expressed as follows: ; ; Among them, is the cumulative request number change curve of the IP within the preset historical period, represents within the preset historical period the maximum value of is the cumulative request number of the IP within the preset historical period, is a judgment function. When x ≤ 0, otherwise, ; is the cumulative request number warning value, is the comparison table coefficient, is the IP request sequence consistency coefficient. m is the number of differences between adjacent IP request time points, j is a positive integer and j ∈ [1, m], is the j-th adjacent IP request time difference, is the average value of all adjacent IP request time differences.
6. A data security and communication method based on cryptographic technology according to claim 5, characterized in that, The process of determining the communication strategy includes: The risk value R is obtained by the formula and the communication strategy is obtained corresponding to the interval where the risk value R is located; Wherein, u1, u2, and u3 are weight coefficients.
7. A data security and communication method based on cryptographic technology according to claim 6, characterized in that, The communication strategy includes four levels of password encryption levels. Among them, the first-level password encryption level adopts the AES-128 encryption algorithm; the second-level password encryption level adopts the AES-256 encryption algorithm; the third-level password encryption level adopts the SM4 encryption algorithm; the fourth-level password encryption level adopts the Kyber-1024 encryption algorithm.
8. A data security and communication method based on cryptographic technology according to claim 4, characterized in that, The process of the attribute analysis includes judging the geographical attribute of the IP, judging the proxy status of the IP, and judging the ISP to which the IP belongs..