Digital space full-flow encryption transmission system and method

By building access lists, boundary enclosed maps, file access index tables and access action sequences, the problem of insufficient dynamic linkage of access control in the existing technology is solved, multi-dimensional trusted judgment of operator identity and paths and fine-grained permission control is realized, and the security and traceability of data transmission are improved.

CN120342792AActive Publication Date: 2025-07-18SICHUAN YOUJIA TRACEABILITY TECH CO LTD

Patent Information

Application Number
CN202510822134.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-18
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

The prior art lacks dynamic linkage and fine-grained constraints on the source identity, path status and operation behavior of the access operator during data transmission, resulting in generalization of permission judgment, fuzzy path ownership and difficulty in tracing access behavior, making it difficult to distinguish between operational legitimacy and access scope boundaries, and there is a risk of data overpriced access and potential leakage.

Method used

The access list is generated through the entrance authentication module, the structure enclosed module builds a boundary enclosed map, the identity binding module establishes a file access index table, the permission verification module performs two-way matching, and the path trace module generates access action sequences, realizing multi-dimensional trusted judgment and dynamic permission control of the operator's identity, access environment and path.

Benefits of technology

It improves the accuracy and boundary clarity of permission verification, builds a verifiable and traceable data flow structure, has closed-loop control capabilities, and reduces the risk of data overpriced access and leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342792A_ABST
    Figure CN120342792A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network information security, in particular to a digital space full-flow encryption transmission system and method, and the system comprises an entrance authentication module, a structure closing module, an identity binding module, an authority verification module and a path trace module. According to the method, the access list is generated through joint identification of operator identity information, access environment identification and terminal network attribution, a multi-dimensional credible judgment basis of an access source is constructed, and structured identification and positioning of an access target are realized by combining path hierarchy extraction and file storage state classification; identity fields and path mapping relations are subjected to cross matching to form unique binding identifiers, a clear data access index system is established, authority control is based on bidirectional matching of access levels and attribution groups, authority verification precision and boundary definition are improved, access behaviors generate sequences through path, time and file operations, and identities are bound. And a verifiable and traceable data flow structure with closed-loop control capability is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security technology, and in particular to a digital space full-traffic encryption transmission system and method. Background Art

[0002] The field of network information security technology includes security mechanisms for aspects such as the confidentiality, integrity, availability, and non-repudiation of data during transmission, storage, and processing in a network environment. Its core contents include cryptographic mechanisms, access control mechanisms, identity authentication mechanisms, secure communication protocols, intrusion detection and prevention mechanisms, etc. This technical field is widely applied in information-based application scenarios such as Internet communication, e-commerce, government services, and financial transactions, aiming to build a secure and trustworthy network environment to prevent information leakage, tampering, forgery, and illegal access. Network information security technology has been evolving continuously, and gradually formed a multi-level protection system based on encryption algorithms, supported by protocol specifications, and framed by a security architecture to achieve systematic protection of the entire life cycle of data.

[0003] Among them, the digital space full-traffic encryption transmission system and method refer to the system structure and operation mode designed for the network data transmission process in the digital space environment to achieve overall encryption of network traffic. This patent theme aims at the problem that multi-source heterogeneous network communication data in the digital space is easily intercepted, eavesdropped, and analyzed during the transmission process, and proposes an encryption transmission method with full-traffic encryption as the core. It mainly uniformly processes the format of the original data in the data generation link, then sorts and classifies the network flow data according to communication sessions, and then uses the symmetric key encryption method to encrypt and encapsulate each type of data. At the same time, it cooperates with the asymmetric key mechanism to realize the key negotiation and distribution process, and adds an encrypted channel strategy in the transmission path to ensure the data consistency and encryption integrity of the relay node and the target receiving end. The entire system uses the key management mechanism, data classification strategy, and transmission channel configuration as means to form a full-traffic encryption architecture applicable to high-frequency data exchange environments.

[0004] In the process of ensuring data transmission in the prior art, although the encryption of communication flow and key negotiation operations can be achieved, there is a lack of dynamic linkage and fine-grained constraints on the source identity, path status, and operation behavior of access operators. Problems such as generalization of permission judgment, ambiguity of path attribution, and difficulty in tracing access behavior often occur. Since access control mostly relies on static permission configuration and identity authentication at the initial stage of the session, the operation behavior lacks full-process dynamic identification and path matching support, resulting in the system's difficulty in distinguishing the legality of operations and the boundary of access scope, forming risks of data over-access and potential leakage. The path structure information and file status are not incorporated into the permission calculation logic, making it possible for sensitive data to still be accessed incorrectly after path changes or permission adjustments. The access record mechanism generally stores operation information in the form of logs, lacking systematic association of behavior sequences and identity traceability, and it is difficult to form a reliable basis for accountability. In high-frequency operation scenarios, such as business platforms with multi-department collaboration, there are many overlaps in operation frequencies and identities. Without the support of a path and identity binding mechanism, it is extremely easy to cause confusion in access ownership and out-of-control data flow. The above deficiencies restrict the system's comprehensive supervision of permission boundaries, identity associations, and behavior legality in complex operation chains, and affect the security guarantee ability of data operations in the network information environment. Summary of the Invention

[0005] The purpose of the present invention is to solve the deficiencies existing in the prior art, and a digital space full-traffic encrypted transmission system and method are proposed.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A digital space full-traffic encrypted transmission system includes: The entrance authentication module obtains the operator identity record, access environment identifier, and entrance source, matches the account structure and source fields, judges the attribution of the access environment and the terminal network, and generates an entrance access list; The structure closure module extracts the path entrance according to the entrance access list, extracts and generates a structural hierarchy description, judges and classifies the integrity of the storage type, summarizes the closed area, and generates a boundary closure map; The identity binding module extracts the file path tag item and file available status field based on the boundary closure map, performs field cross-comparison on the access identity record and path mapping field, sets the cross-item identifier, establishes a number list, and generates a file access index table; The permission verification module extracts the identity and path field contents according to the file access index table, matches the access level label and the attribution group, and if the permission conforms, it opens and releases the label, and if it does not conform, it classifies it into the restriction pool, and generates an access execution list; The path trace module extracts the released path segment from the access execution list, collects the execution time and operation file name, combines the time and the path into an access action sequence, enters it into the record pool and marks the source identity, and generates the result of spatial traffic encrypted transmission.

[0007] As a further solution of the present invention, the entrance access list includes account structure information, source identifier, access environment characteristics, terminal network mark, and identity comparison label; the boundary closed graph includes path entrance identifier, structure level information, file storage type, integrity classification result, and closed area mark; the file access index table includes path mark number, file availability status, identity mapping number, and access identity list; the access execution list includes access identity label, path ownership group, permission matching identifier, and access control result; the space traffic encryption transmission result includes access path segment, operation time point, file name entry, action sequence item, and source identity information.

[0008] As a further solution of the present invention, the entrance authentication module includes: The identity comparison sub-module obtains the account structure field and source field in the operator's identity record, compares them based on the corresponding values of the account coding field and the access platform field, calculates the field matching quantity and matching rate, and generates a field matching ratio result; The environment recognition sub-module calls the access environment identifier and the terminal network source field according to the field matching ratio result, counts the occurrence frequency of the access environment, calculates the weighted frequency value, obtains the access source group corresponding to the frequency, and generates the main access frequency occupancy ratio; The list generation sub-module filters the account set that simultaneously meets the two conditions based on the field matching ratio result and the main access frequency occupancy ratio, calculates the ratio value of the set to all records, marks the corresponding identity and enters the record set, and generates an entrance access list.

[0009] As a further solution of the present invention, the formula for calculating the weighted frequency value is specifically: ; Wherein, represents the weighted frequency value of the environment identifier , represents the normalization coefficient of the field matching ratio result of the environment identifier , represents the original occurrence times of the environment identifier , represents the adjustment factor of the terminal network source , represents the independent correction term of the terminal network source , represents the total number of terminal network sources.

[0010] As a further solution of the present invention, the structure closing module includes: The path extraction sub-module obtains the path entrances pointed to by the record items in the entry access list, traverses each path level by level, extracts all file locations in the path, calculates the path structure levels and the intra-level distribution based on the node depth and the number of siblings of the file locations, and generates the structural level density. The structure judgment sub-module, based on the structural level density value, calls the file storage types in the traversal results, makes integrity judgments according to the file suffix field, the creation method field, and the access method field, classifies the records according to whether there are missing key fields in the files, calculates the number of complete files in the classification group, and generates the complete file ratio result. The closed generation sub-module, according to the complete file ratio result and the structural level density value, judges the path closure degree of the corresponding area of the structural level distribution and the integrity classification group, filters out the path segments that simultaneously meet the closed path depth and the complete file ratio exceeding the set threshold, counts the classification number of the path segments and archives them, and generates the boundary closed graph.

[0011] As a further solution of the present invention, the calculation formula for the number of complete files in the classification group is specifically: ; Wherein, represents the number of complete files in the classification group, represents the validity ratio of the suffix field, represents the standardized value of the creation method field, represents the standardized value of the access method field, represents the creation method weight factor, represents the current file field integrity score, represents the reference integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor.

[0012] As a further solution of the present invention, the identity binding module includes: The path indexing sub-module obtains the file path marker items and the file available status fields extracted from the boundary closed graph, performs cross-combination extraction operations based on the values of the file path field and the available status field, establishes a mapping record group of paths and statuses, calculates the differential index in the record group, and generates the path status combination quantity. The identity numbering sub-module, according to the path status combination quantity, calls the access identity records and the path mapping fields, cross-compares the identity identification field and the path field, filters out the matching items and sets unique numbers, constructs a numbering list and calculates the number of identities corresponding to the numbering items, and generates the identity number density. The access mapping sub-module writes the combination of the identity number and the corresponding file status into the exclusive record list based on the identity number density and the combined amount of path statuses, screens the combined items where the identity number and the path status appear simultaneously, calculates the proportion in the total records, establishes a mapping structure and outputs a record table, and generates a file access index table.

[0013] As a further solution of the present invention, the permission verification module includes: The permission extraction sub-module obtains the content of the identity field and the path field in the file access index table, calls the access level label in the identity field and the access attribution group in the path field, performs number mapping on the identity field value, performs grouping classification on the path field value, calculates the number of identity levels corresponding to each group of paths, and generates a level attribution distribution amount; The matching judgment sub-module performs a two-way matching operation on the identity access level label and the path access attribution group according to the level attribution distribution amount, marks the matching field pairs in the identity number set, classifies the numbers that do not meet the matching conditions into the restricted record pool, calculates the number of numbers in the matching set and the restricted set, and generates a permission matching ratio value; The list generation sub-module extracts the marked matching identity number set based on the permission matching ratio value and the level attribution distribution amount, recombines it with the file path field, establishes an identity-path comparison list, summarizes the passable path records corresponding to each identity number, and generates an access execution list.

[0014] As a further solution of the present invention, the path trace module includes: The path collection sub-module obtains the access path segments marked as passed in the access execution list, collects the execution time field and the operation file name field in the path segment, combines and pairs the time field and the path field, calculates the number of combined entries and the time coverage range, and generates a path action number; The sequence generation sub-module calls the combined result of the path field and the time field according to the path action number, constructs an ordered arrangement structure for each combined entry, marks the time sequence relationship and forms a continuous action chain, calculates the number of action chains and the time span length, and generates an access action sequence amount; The identity marking sub-module writes the source identity field corresponding to each access action sequence into the access record transfer pool based on the access action sequence amount, performs a binding operation on the sequence entry and the identity value and marks a unique code, calculates the number of encrypted marked entries and the distribution ratio in the transfer pool, and generates a spatial traffic encrypted transmission result.

[0015] A method for encrypting and transmitting all traffic in a digital space includes the following steps: S1: Obtain the account structure, source field, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and source field, conduct attribution judgment on the access environment identifier and terminal network source, set a marked status for the successfully matched and attributed identity record, and generate an entry access list after summarizing the marked identity records; S2: Based on the entry access list, extract the path entry pointed to by the record item, perform traversal extraction on the path entry, obtain the path structure level and file location information, perform integrity judgment and classification record operations on the storage type field, filter the path of the closable area, mark and summarize it, and generate a boundary closure map; S3: According to the boundary closure map, extract the file path marked item and file availability status field, perform field cross-comparison on the access identity record and path mapping field, extract the cross-item, set a unique identifier, and establish a number list, write the record in the file status into the identity mapping list, and generate a file access index table; S4: Call the identity field and path field in the file access index table, perform two-way matching operations on the access level label and access attribution group, set a release label for the matched item, classify the unmatched item into the restriction pool, and generate an access execution list after summarizing the release records; S5: Based on the access execution list, extract the access path segment with a release label, collect the execution time and operation file name field in the path segment, form an access action sequence entry from the combination of time and path fields, write the entry into the access record transfer pool and mark the source identity, and generate a spatial traffic encryption transmission result.

[0016] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, an access list is generated through the joint recognition of the operator's identity information, access environment identifier, and terminal network attribution, constructing a multi-dimensional trusted determination basis for the access source. Combining path level extraction and file storage status classification, the structured recognition and positioning of the access target are realized. The cross-matching of the identity field and path mapping relationship forms a unique binding identifier, establishing a clear data access index system. The permission control is based on the two-way matching of the access level and attribution group, improving the accuracy and boundary clarity of permission verification. The access behavior generates a sequence based on the path, time, and file operation and binds the identity, constituting a data flow structure with verifiability, traceability, and closed-loop control capabilities. Brief Description of the Drawings

[0017] Figure 1 is the system flow chart of the present invention; Figure 2 is the system block diagram of the present invention; Figure 3 is the flow chart of the entry authentication module of the present invention; Figure 4Flowchart of the structure closing module of the present invention; Figure 5 Flowchart of the identity binding module of the present invention; Figure 6 Flowchart of the permission verification module of the present invention; Figure 7 Flowchart of the path tracing module of the present invention; Figure 8 Flowchart of the method steps of the present invention. Detailed implementation manners

[0018] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0019] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, in the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.

[0020] Please refer to Figure 1 and Figure 2 , a full-flow encrypted transmission system for a digital space includes: The entry authentication module obtains the operator's identity record, access environment identifier and entry source, performs field matching and comparison on the account structure and source fields in the identity record, performs attribution judgment on the access environment identifier and the terminal network source, compares the marked identity and enters the record set, and generates an entry access list; The structure closing module extracts the path entry pointed to by the record item according to the entry access list, performs a traversal extraction operation on each path, generates a structural hierarchy description of the file location, performs an integrity judgment and classification record operation on the file storage type, marks the closable area and summarizes and archives it, and generates a boundary closing map; The identity binding module extracts the file path marker item and the file available status field based on the boundary closing map, performs field cross-comparison on the access identity record and the path mapping field, sets a unique identifier for the cross-item and establishes a number list, and writes the identity mapping record of the file status into a dedicated list, and generates a file access index table; The permission verification module extracts the content of the identity field and the path field according to the file access index table, performs a two-way matching operation on the access level label in the identity field and the access belonging group in the path field, opens the release label for the records with matching permissions during the comparison, classifies the non-matching records into the restriction pool, and generates an access execution list; The path trace module extracts the access path segments with the release label according to the access execution list, collects the execution time and the operation file name field in the path segment, combines the time and the path into an access action sequence entry, enters the entry into the access record transfer pool and marks the source identity, and generates a spatial traffic encrypted transmission result.

[0021] The entry access list includes account structure information, source identifier, access environment characteristics, terminal network mark, identity comparison label, the boundary closed graph includes path entry identifier, structure level information, file storage type, integrity classification result, closed area mark, the file access index table includes path mark number, file availability status, identity mapping number, access identity list, the access execution list includes access identity label, path belonging group, permission matching identifier, access control result, and the spatial traffic encrypted transmission result includes access path segment, operation time point, file name entry, action sequence item, source identity information.

[0022] Please refer to Figure 3 and Figure 2 , the entry authentication module includes: The identity comparison sub-module obtains the account structure field and the source field in the operator's identity record, performs a comparison based on the corresponding values of the account coding field and the access platform field, calculates the field matching quantity and matching rate, and generates a field matching ratio result; The identity comparison sub-module obtains the account structure field and source field in the operator's identity record. During the extraction process, first, according to the structure information of each piece of data in the identity record, the account structure field is read item by item. Commonly, such as account_id, user_code, login_id, etc. The source field can be source_type, platform_tag, etc. The account coding field, such as account_code, is extracted in segments. For example, in "AC_102938", the prefix "AC" is regarded as the account type identifier, and the suffix "102938" is the specific coding value. The access platform field, such as access_platform, is mapped to a unified standard format after being identified according to platform identifiers such as "WEB", "APP", "API". During the comparison process, the system traverses the operator's identity record item by item, conducts a character-level one-to-one comparison between the account coding field in each record and the account structure field, and at the same time compares whether the platform identifiers of the access platform field and the source field are consistent. Each matching item is accumulated once. When the total number of fields is set to 10 items, the comparison result is marked for each comparison. If the field account_id is "USR2025" and matches the suffix of account_code, and source_type is "WEB_LOGIN" and access_platform is "WEB", both are counted as valid comparison items. If the total number of comparisons is 7 items, then the field matching ratio result is 0.7. In the set operation, the matching ratio value does not require a separate formula and is only obtained by counting the total number of comparison results and the total number of field items, which is recorded as the final result.

[0023] The environment recognition sub-module, based on the field matching ratio result, calls the access environment identifier and the terminal network source field, counts the occurrence frequency of the access environment, calculates the weighted frequency value, obtains the access source group corresponding to the frequency, and generates the main access frequency occupancy ratio; The specific formula for the weighted frequency value is: ; Among them, represents the weighted frequency value of the environment identifier ; represents the normalization coefficient of the field matching ratio result of the environment identifier ; represents the original occurrence times of the environment identifier ; represents the adjustment factor of the terminal network source ; represents the independent correction term of the terminal network source ; represents the total number of the terminal network source; "Weighted frequency value" is a statistical indicator used to measure the dominance and credibility of a certain access environment identifier in identity authentication, mainly used in the "entry authentication module" to judge and screen the access source environment. This value is not used to calculate the probability of an event occurring, but is a weighted indicator that integrates multi-factor evaluation.

[0024] Basis for parameter assignment and data source (Normalization coefficient): Based on the field matching ratio result of the environment identifier The field matching ratio result is the percentage of the number of successful matches of the environment identifier in the monitoring period to the total number of matches. For example, the total number of matches in the monitoring period is 1000 times, and the number of successful matches of the environment identifier is 200 times, and its fluctuation range is from 0 to 1.

[0025] (Original occurrence times): Count the actual occurrence times of the environment identifier in the monitoring period through log data. For example, log statistics times.

[0026] (Adjustment factor): Set according to the historical traffic quality score of the terminal network source , and the scoring range is from 0.5 to 1.5. For example, Wi-Fi source (high stability), mobile data (low stability), based on the linear mapping result after quantifying the network delay and packet loss rate monitoring data.

[0027] (Independent correction term): Calculate based on the number of abnormal requests of the terminal network source . For example, if the number of abnormal requests of the source is 10 times, then , and the number of abnormal times is counted by the firewall log.

[0028] (Total number of terminal sources): The number of actual access terminal network sources in the monitoring period. For example, Wi-Fi and mobile data are detected as two sources, .

[0029] Formula calculation derivation (numerical example) Substitute parameters: , , , (mobile data), (number of Wi-Fi abnormalities), (Number of abnormal mobile data), .

[0030] Calculation steps: Calculate ; Calculate ; Sum: ; Calculate ; Take the absolute value: ; Result interpretation and relevance This result indicates that the environmental identifier has a weighted frequency value of 29.248, which is calculated by comprehensively considering the original occurrence times, the terminal network quality score, and the abnormal correction term. The weighted frequency value is used to generate the main access frequency ratio in the following. The specific association method is: take the ratio of to the sum of all weighted frequency values in the environmental identifier set as the main access frequency ratio. For example, if the sum of all environmental identifiers is 200, then the current environmental identifier accounts for , which is consistent with the result of generating the main access frequency ratio for the short sentence at the end of the original paragraph.

[0031] The list generation sub-module filters the account set that meets both conditions based on the field matching ratio result and the main access frequency ratio, calculates the ratio value of the set to all records, marks the corresponding identity and enters the record set, and generates the entry access list; First, set the minimum threshold M_thresh for the field matching ratio result and the minimum threshold F_thresh for the main access frequency occupancy ratio. The threshold setting is determined according to the sample distribution law. For example, M_thresh is set to a value near the sample mean of the field matching ratio result, which is 0.65. That is, 0.65 is taken as the set threshold. F_thresh is set to a value that is 5% higher after weighting the sample mean of the access frequency occupancy ratio. If the mean is 0.5, then F_thresh is set to 0.55. Traverse all account records. For each record, first judge whether the field matching ratio result is higher than 0.65. If so, continue to judge whether the access environment it belongs to is within the main access source group and whether the occurrence frequency of this access environment is greater than 0.55. For example, if the field matching ratio result of an account is 0.68 and the access environment is "office+wifi", which is within the main access source group and the frequency is 0.6, then this account meets the double screening conditions and enters the valid set. Continue to accumulate the number of such accounts. When all traversals are completed, calculate the ratio between the number of valid accounts S and the total number of records T to obtain the set occupancy ratio. For example, after screening, 90 accounts meet the conditions and the total number of records is 300, then the set occupancy ratio is 30%. Take this ratio as the final judgment value and attach the status flag "valid_entry=1" to all accounts in the set to construct the entry access list for the next process operation.

[0032] Please refer to Figure 4 and Figure 2 , the structure closed module includes: The path extraction sub-module obtains the path entry pointed to by the record item in the entry access list, performs a hierarchical traversal on each path, extracts all file positions in the path, calculates the path structure layer number and the in-layer distribution quantity based on the node depth and the number of siblings of the file position, and generates the structure layer density; First, read the path field value in each record, extract the path content such as " / business system / module A / task table / plan.xlsx", split the path string into several hierarchical nodes according to the delimiter " / ", which are "business system", "module A", "task table", "plan.xlsx" in sequence. Read and build a path tree structure step by step from top to bottom for each level, and rely on the file system or data directory structure to obtain the total number of peer files or folders at each level. For example, there are 3 nodes in total, namely "module A", "module B", and "module C" under the first level "business system", 3 items in total, namely "task table", "requirement document", and "archiving plan" under the second level "module A", and 2 files, namely "plan.xlsx" and "budget.xlsx" under the third level "task table". Calculate that the number of path structure layers is 4 layers (excluding the root directory), and at the same time count the number of peer nodes at each level as 3, 3, and 2 respectively. After the system traverses each path, calculate the average structure layer number of all paths in the path set and the average distribution quantity under the level. Suppose the average number of layers of all paths is 4.2 layers, then the structure density division threshold is set as: low density is less than 3 layers, medium density is between 3 and 5 layers, and high density is greater than 5 layers. For example, a certain path " / platform / business module / task set / year / report / detail / 2025.doc" has a total of 7 layers, and the number of peer files at each layer is not less than 3 items, then the structure layer density of this path is high density. Finally, the system generates the structure layer density value of each path according to the number of layers and distribution value extracted from each path and outputs it.

[0033] Based on the structure layer density value, the structure judgment sub-module calls the file storage type in the traversal result, and makes an integrity judgment according to the file suffix field, creation method field, and access method field, classifies and records according to whether there are missing key fields in the file, calculates the number of complete files in the classification group, and generates the complete file ratio result; The specific calculation formula for the number of complete files in the classification group is: ; Among them, represents the number of complete files in the classification group, represents the validity ratio of the suffix field, represents the standardized value of the creation method field, represents the standardized value of the access method field, represents the creation method weight factor, represents the current file field integrity score, represents the benchmark integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor; Parameter assignment and acquisition method: (Suffix field validity ratio): By monitoring the validity of the suffix field in the file storage type, the ratio of the number of valid suffixes to the total number of suffixes is calculated. For example, if the total number of suffixes monitored is 200 items and the number of valid suffixes is 180 items, then . The validity determination criterion is that the suffix exists in the system predefined list and is not marked as obsolete.

[0034] (Normalized value of the creation method field): The creation method field is divided into three categories: automatically generated, user uploaded, and system migrated. The quantization rule is: automatically generated is assigned 0.8, user uploaded is assigned 0.5, and system migrated is assigned 0.3. If the current file creation method is monitored as automatically generated, then .

[0035] (Normalized value of the access method field): The access method field is divided into three categories: read-only, read-write, and encrypted access. The quantization rule is: read-only is assigned 0.9, read-write is assigned 0.6, and encrypted access is assigned 0.4. If the current file access method is monitored as read-write, then .

[0036] (Creation method weight factor): The weight factor is preset to 0.4 according to the impact degree of the creation method on integrity, based on the fact that the proportion of integrity errors caused by the missing creation method field in historical data accounts for 40% of the total field missing events.

[0037] (Integrity score of the current file fields): Calculated by weighted summation through detecting whether the suffix, creation method, and access method fields of the file are missing. For example, if the suffix field exists and gets 1 point, the creation method field exists and gets 0.8 points, and the access method field exists and gets 0.6 points, then .

[0038] (Benchmark integrity score threshold): Set to 2.0 according to the median of the integrity scores of normal files in historical data.

[0039] (Dynamic adjustment coefficient): Calculated based on the historical missing rate, and the formula is , where is the file missing rate in the recent week. For example, if the monitored missing rate is 5%, then .

[0040] (Normalization factor): Calculated by the ratio of the total amount of the current file group to the total amount of files in the system. For example, if the current file group is monitored to contain 50 files and the total amount of files in the system is 1000, then .

[0041] Formula calculation and derivation: Calculate : Substitute , to get .

[0042] Calculate : Substitute , to get .

[0043] Calculate : Substitute , , , to get .

[0044] Summation of the numerator part: .

[0045] Calculate : Substitute , , to get .

[0046] Final result: .

[0047] Meaning of the numerical result: It indicates that the integrity score of the current file is significantly higher than the benchmark threshold of 1.0 and is classified as a complete file. This score quantifies the integrity status of the file by comprehensively considering field validity, differences in creation and access methods, dynamic adjustment, and normalization factors, and is used to subsequently count the number and proportion of complete files.

[0048] The closed generation sub-module determines the path closure degree between the structural hierarchy distribution and the corresponding area of the integrity classification group based on the complete file ratio result and the structural hierarchy density value, filters the path segments that simultaneously meet the closed path depth and the complete file ratio exceeding the set threshold, counts the classification quantity of the path segments and archives them, and generates a boundary closed graph; First, read the structure density values and the complete file ratio results of each path in sequence. Set the judgment threshold as follows: a path is determined to have the ability to close if the depth of the path structure hierarchy reaches more than 5 levels, and the threshold of the complete file ratio is set to 70%, which is obtained based on the mean of the overall data sample plus a tolerance of 5%. In specific judgment, for the path " / system / module / branch / sub-module / data / result / report.docx", its structure has 7 layers, belonging to a high-structure density path. There are a total of 20 files in this path directory, and 17 of them are complete files, with a complete ratio of 85%. Since it meets the integrity threshold condition and the closed path hierarchy condition, the system marks this path segment as a valid closed path segment. After judging all paths, collect and count the path segments that meet the conditions and conduct classification statistics. For example, if 92 path segments that meet the conditions are selected from 500 paths, the classification quantity is 92. At the same time, organize information such as the structure hierarchy and file integrity ratio of these 92 paths into the graph structure dataset to output the boundary closed graph. The path number, depth, distribution, and integrity level are marked in the graph.

[0049] Please refer to Figure 5 and Figure 2 , the identity binding module includes: The path indexing sub-module obtains the file path marking items and file availability status fields extracted from the boundary closed graph, performs cross-combination extraction operations based on the values of the file path field and the availability status field, establishes a mapping record group of paths and statuses, calculates the differential indicators in the record group, and generates the path status combination quantity; First, read the path fields recorded in the atlas one by one, such as " / Project A / Module X / Data Table.xlsx", and at the same time read the file availability status field values corresponding to the paths, such as "valid", "invalid", "inaccessible". The system takes the path field and the availability status field as two dimensions and performs a cross-combination extraction operation. It splices each path value with the corresponding status value into a combined key-value pair, such as " / Project A / Module X / Data Table.xlsx - valid", to establish a mapping record group between the path and the status. Sort and deduplicate the mapping group, establish a combined index table according to the combined items, and record the occurrence frequency of each combination at the same time. Then, calculate the differentiation index for each combination. This index is calculated based on the balance degree of the status distribution. For example, for the path " / Project B / Module Y / Drawing.dwg", there are 3 record statuses which are "valid", "invalid", and "valid" respectively. Then there are two statuses in this path status combination, and the status difference rate is 66.7%. For the path " / Project C / Module Z / Configuration.xml", all 5 records are "valid", and the difference rate is 0%. Set the differentiation index range as 0% - 30% for low difference, 30% - 70% for medium difference, and greater than 70% for high difference. The system traverses all combinations and tags them, and finally outputs the quantity of each path status combination, including the number of combined paths, the number of corresponding status items, the difference label value, and the distribution density.

[0050] The identity number sub-module calls the access identity record and the path mapping field according to the quantity of the path status combination, performs a field cross-comparison on the identity identification field and the path field, filters the matching items and sets a unique number, constructs a number list and calculates the number of identities corresponding to the number items to generate the identity number density; First, read each group of path and status combination records, and call the access identity record fields such as user_id and the path mapping fields such as access_path to perform a field comparison operation on the two fields. During the comparison process, read the access_path field in the identity record and the combined path field for character-level matching to determine whether the path is consistent with the path in the identity record. If the match is successful, establish an identity correspondence relationship. Further, read the identity identifier fields, such as "U10452", "U30567", under the same match item, and establish an independent number for each unique identity and path status combination, such as "IDX001", "IDX002". The number generation can use the sequential accumulation method combined with the hash result of the combined fields to generate the code, and then form a list of numbers. For each number, count the number of identity records matched under it. For example, the number IDX001 corresponds to 3 identity records, and IDX002 corresponds to 5 identity records, then generate the identity quantity corresponding to the number item. Finally, calculate the identity quantity density value corresponding to the number. The density interval is set as: less than 3 people is low density, 3 to 6 people is medium density, and more than 6 people is high density. For example, among 200 combined numbers, 50 numbers correspond to less than 3 identities, then the low-density ratio is 25%. Output all numbers and identity quantity and density value labels.

[0051] The access mapping sub-module writes the identity number and the corresponding file status combination into the exclusive record list based on the identity number density and the path status combination quantity, filters the combination items where the identity number and the path status appear simultaneously, counts the proportion in the total records, establishes a mapping structure and outputs the record table, and generates a file access index table; First, read each number and its density value in the number list, and at the same time read the path status combination item bound to it, construct an exclusive record list of the identity number and the corresponding path status combination, bind the number as the primary key and the status combination item as the secondary key for recording. Filter the combination items where the identity number and the path status appear simultaneously in all records. For example, the number IDX015 binds the path " / business / form A / annual statistics.xlsx" and the status "valid". If there are multiple identity records that all appear this combination item, then mark this combination item as a valid mapping item. After the filtering is completed, count the proportion of all mapping items in the total records. For example, the total number of all identity path combination records is 800, and the number of filtered valid mapping items is 210, then the proportion is 26.25%. The proportion interval is set as: less than 20% is the low correlation area, greater than or equal to 20% and less than 50% is the medium correlation area, and greater than or equal to 50% is the high correlation area. In this example, it belongs to the medium correlation area. The system establishes a mapping structure accordingly, lists each identity number, the path status combination it points to and the corresponding occurrence frequency in the structure table, and outputs it as the final file access index table for subsequent index tracking use.

[0052] Please refer toFigure 6 and Figure 2 , the authority verification module includes: The authority extraction sub-module obtains the identity field and path field content in the file access index table, calls the access level label in the identity field and the access belonging group in the path field, performs number mapping on the identity field value, groups and classifies the path field value, calculates the number of identities corresponding to each group of paths, and generates a level belonging distribution quantity; First, the system reads the identity field value (such as "U1023", "U2451") and path field value (such as " / Data Center / 2025 / Q1 Report.xlsx") of each record from the index table, extracts the access level label in the identity field, such as "Level 1", "Level 2", "Level 3", and the access level label field is read from the original identity registration or system authorization label. The access belonging group field in the path field is extracted from the business module, system classification or project belonging to which the path belongs. For example, the path belongs to "Finance Department", "Technical Department", "Sales Department". In the number mapping operation, each identity value is encoded in sequence to generate a standard number, such as "ID001", "ID002", etc. The path field is grouped and classified to establish a mapping structure according to the belonging access belonging group. For example, all paths belonging to the "Finance Department" are grouped into the same classification group, and then the identity number and the belonging path group are cross-mapped and counted. For each belonging path group, the number of identity numbers corresponding to access levels such as "Level 1", "Level 2", "Level 3" is counted respectively. For example, there are 50 users in the path group "Finance Department", including 20 users with Level 1 authority, 18 users with Level 2 authority, and 12 users with Level 3 authority. This distribution structure is recorded as "Finance Department - 20 / 18 / 12". After the system completes the statistics of the level numbers of all path belonging groups, it outputs them as the level belonging distribution quantity.

[0053] The matching judgment sub-module performs a two-way matching operation on the identity access level label and the path access belonging group according to the level belonging distribution quantity, marks the matching field pairs of the identity number set, classifies the numbers that do not meet the matching conditions into the restricted record pool, counts the number of numbers in the matching set and the restricted set, and generates an authority matching ratio value; First, set the range of allowed access identity levels for each path attribution group. For example, the "Finance Department" path group allows access levels 1 and 2, the "Technical Department" allows all levels, and the "Sales Department" only allows level 1 access. After reading the levels corresponding to each identity number in the level attribution distribution table, compare and judge item by item. If the identity level meets the accessible level set for the current path group, mark the number as a matching item; otherwise, mark the number as non-matching and put it into the restricted record pool. For example, if the identity number "ID025" has a level of 3 and belongs to the "Finance Department" path, since it is not within the allowed level range, its number is put into the restricted record pool. After the system traverses all identity numbers, count the number of matching number sets and restricted number sets. For example, there are 340 matching numbers and 160 restricted numbers, and the calculated ratio is 340 / (340 + 160) = 68%. Set the range of permission matching ratio values as follows: less than 50% is weak matching, 50% to 80% is medium matching, and more than 80% is strong matching. Here, the result falls into the medium matching range, and finally output the permission matching ratio value and the corresponding marked set result.

[0054] The list generation sub-module extracts the marked set of matching identity numbers based on the permission matching ratio value and the level attribution distribution, recombines them with the file path field, establishes an identity-path comparison list, summarizes the record of accessible paths corresponding to each identity number, and generates an access execution list; The list generation sub-module reads the set of identity numbers marked as matching in the previous sub-module based on the permission matching ratio value and the level attribution distribution, and recombines them with the path field to construct an identity-path comparison relationship. For example, the identity number "ID041" can access the path group "Finance Department", and in the "Finance Department" path classification, it contains paths " / Finance / Budget.xlsx" and " / Finance / Expenditure Summary.xlsx". Then record "ID041 - Budget.xlsx" and "ID041 - Expenditure Summary.xlsx" as its accessible path records. The system sequentially combines each identity number with all file paths in its attributed path group to form complete record entries. After summarizing all identity number and path comparison entries, construct an identity-path comparison list, and then perform a structured output on this list, recording the number of paths corresponding to each number. For example, there are 5 paths under "ID041" and 8 paths under "ID053". Finally, the system integrates all number entries to generate a unified access execution list, the content of which includes: identity number, access level, attributed path group, list of accessible paths, number of paths. This list is output as index data for implementing access permission control.

[0055] Please refer to Figure 7 and Figure 2 , the path trace module includes: The path collection sub-module obtains the access path segments marked as released in the access execution list, collects the execution time field and the operation file name field within the path segment, combines and pairs the time field and the path field, counts the number of combined entries and the time coverage range, and generates the path action quantity. First, read the path segment field values with the release flag in the execution list one by one, such as " / Platform Module A / Project Data / Report Summary Table.xlsx", and at the same time extract the execution time field value from the corresponding record, such as "2025-06-15 08:42:13", and the operation file name field, such as "Report Summary Table.xlsx". The system establishes a combined key based on the path field and the time field, combines and pairs the path value and the time value to form a combined entry such as " / Platform Module A / Project Data / Report Summary Table.xlsx_2025-06-15 08:42:13". Traverse all records to establish a list of such entries, and then perform statistical operations on the combined entry list to calculate the total number of combined entries. For example, a total of 350 path segments and corresponding time combination items are extracted in a certain operation, then the number of path action combined entries is 350. Next, read the time field values in all combination items, extract the earliest time and the latest time point, which are, for example, "2025-06-10 09:00:00" and "2025-06-18 18:30:00" respectively, and calculate the time coverage range to be 8 days and 9.5 hours. Set the time range judgment criteria as: less than 1 day is short-term, between 1 and 3 days is medium-term, and more than 3 days is long-term. Then in this example, it falls into the long-term time period range. Finally, the system outputs the path action quantity as 350 and its corresponding time coverage range is marked as "long-term".

[0056] The sequence generation sub-module calls the combined result of the path field and the time field according to the path action quantity, constructs an ordered arrangement structure for each combined entry, marks the time sequence relationship and forms a continuous action chain, counts the number of action chains and the length of the time span, and generates the access action sequence quantity. First, read all combinations of path and time fields. Before constructing the ordered arrangement structure, the system groups the combination entries by path field, and sorts the combination entries in ascending order by time field within each path field group, forming an ordered structure chain in sequence. For example, under the path " / Department A / Task in 2025", there are combination entries with times "2025-06-11 10:15:00", "2025-06-11 11:00:00", and "2025-06-11 12:45:00". After sorting, an action chain sequence "Step 1 - Step 2 - Step 3" is formed, and sequential tags such as "SEQ001-1", "SEQ001-2", "SEQ001-3" are assigned to each combination entry. Each action chain represents the trajectory of operations at different time points under this path. After the system completes the above operations on all path groups, it counts the total number of action chains. For example, 95 action chains are generated from all 350 combination entries. Then, it counts the time span length of each action chain. The time span is calculated as the difference between the latest time and the earliest time in the same chain. If the start time of an action chain is "2025-06-11 09:00:00" and the end time is "2025-06-11 14:30:00", the time span is 5.5 hours. Record the time spans of all chains and classify them by interval: chains with a time span less than 1 hour are short chains, those between 1 and 4 hours are medium chains, and those exceeding 4 hours are long chains. Combine the quantity values and output them. Finally, the system outputs 95 access action sequences, and marks the time length types of the chains as long, medium, and short respectively.

[0057] Based on the quantity of access action sequences, the identity marking sub-module writes the source identity field corresponding to each access action sequence into the access record transfer pool, performs a binding operation on the sequence entry and the identity value, marks a unique code, counts the number and distribution ratio of encrypted marked entries in the transfer pool, and generates the spatial traffic encryption transmission result; First, read the path-time combination items bound in each of the previously generated access action sequence structures, and then extract the source identity field values corresponding to each combination item, such as "U1053", "U1172", etc. Write the identity field value into the access record transfer pool, and establish a binding relationship between the identity-sequence items. During the binding process, generate a unique coding identifier for each sequence combination and the corresponding identity field. For example, bind "U1053" to "SEQ010" to generate the identifier "SEQ010-U1053", which is generated by splicing the sequence number and the user identity field to ensure that each sequence action and its source identity are uniquely identifiable. The system records all binding relationships in the transfer pool, and then performs an encryption marking operation on all records in the transfer pool, that is, write the status flag "encrypted=1" into the record as the encryption identifier. In the statistical link, the system reads all encrypted marked entries and counts the total number, such as 570 entries. The distribution ratio of encrypted entries in all records is 570 / 800 = 71.25%. The system sets the encryption distribution range as: less than 50% is sparse distribution, 50% to 80% is medium density, and more than 80% is high-density encrypted transfer scenario. Then this record is of medium density, and the encrypted transmission result record is "medium density - 71.25% - 570 entries", and finally outputs the spatial traffic encrypted transmission result.

[0058] Please refer to Figure 8 , a method for encrypting and transmitting all digital space traffic, comprising the following steps: S1: Obtain the account structure, source field, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and source field, judge the attribution of the access environment identifier and the terminal network source, set the mark status for the successfully matched and attributed identity records, and generate an entry access list after summarizing the marked identity records; S2: Based on the entry access list, extract the path entry pointed to by the record item, perform traversal extraction on the path entry, obtain the path structure level and file location information, perform integrity judgment and classification record operations on the storage type field, filter the paths in the closable area, mark and summarize them to generate a boundary closure map; S3: According to the boundary closure map, extract the file path mark item and the file availability status field, perform field cross-comparison on the access identity record and the path mapping field, extract the cross-items, set unique identifiers, and establish a number list, write the records in the file status into the identity mapping list, and generate a file access index table; S4: Call the identity field and the path field in the file access index table, perform two-way matching operations on the access level label and the access attribution group, set the release label for the matching items, and classify the non-matching items into the restriction pool. Generate an access execution list after summarizing the release records; S5: Extract the access path segments with the label of "release" based on the access execution list, collect the execution time and the operation file name field in the path segment, combine the time and the path field to form an access action sequence entry, write the entry into the access record transfer pool and mark the source identity, and generate the spatial traffic encrypted transmission result.

[0059] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as the technical solution content of the present invention is not departed from, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present invention still belong to the protection scope of the technical solution of the present invention.

Claims

1. A full-flow encrypted transmission system for the digital space, characterized in that: The system includes: The entry authentication module obtains the operator identity record, access environment identifier and entry source, matches the account structure and source fields, judges the attribution of the access environment and the terminal network, and generates an entry access list; The structure enclosure module extracts the path entry according to the entry access list, extracts and generates the structure level description, judges and classifies the integrity of the storage type, summarizes the enclosed area, and generates a boundary enclosure map; The identity binding module extracts the file path tag item and file availability status field based on the boundary enclosure map, performs a field cross-comparison on the access identity record and the path mapping field, sets the cross-item identifier, establishes a number list, and generates a file access index table; The permission verification module extracts the identity and path field contents according to the file access index table, matches the access level label and the attribution group, the permission conforms to the open and release label, and the non-conforming ones are classified into the restriction pool, and generates an access execution list; The path trace module extracts the released path segment from the access execution list, collects the execution time and the operation file name, combines the time and the path into an access action sequence, enters it into the record pool and marks the source identity, and generates a spatial traffic encrypted transmission result.

2. The digital space full-traffic encryption transmission system according to claim 1, wherein: The entry access list includes account structure information, source identifier, access environment characteristics, terminal network mark, identity comparison label, the boundary enclosure map includes path entry identifier, structure level information, file storage type, integrity classification result, enclosed area mark, the file access index table includes path mark number, file availability status, identity mapping number, access identity list, the access execution list includes access identity label, path attribution group, permission matching identifier, access control result, and the spatial traffic encrypted transmission result includes access path segment, operation time point, file name entry, action sequence item, source identity information.

3. The digital space full-flow encryption transmission system according to claim 1, wherein The entry authentication module includes: The identity comparison sub-module obtains the account structure field and the source field in the operator identity record, performs a comparison based on the corresponding values of the account coding field and the access platform field, calculates the field matching quantity and matching rate, and generates a field matching ratio result; The environment recognition sub-module calls the access environment identifier and the terminal network source field according to the field matching ratio result, counts the occurrence frequency of the access environment, calculates the weighted frequency value, obtains the access source group corresponding to the frequency, and generates the main access frequency occupancy ratio; The list generation sub-module filters the account set that meets both conditions based on the field matching ratio result and the main access frequency occupancy ratio, calculates the ratio value of the set to all records, marks the corresponding identity and enters it into the record set, and generates an entry access list.

4. The digital space full-flow encryption transmission system according to claim 3, characterized in that The specific formula for the weighted frequency value is: ; Among them, represents the weighted frequency value of the environmental identifier , represents the normalization coefficient of the field matching ratio result of the environmental identifier , represents the original occurrence times of the environmental identifier , represents the adjustment factor of the terminal network source , represents the independent correction term of the terminal network source , represents the total number of terminal network sources.

5. The digital space full-traffic encryption transmission system according to claim 1, characterized in that, The structure enclosure module includes: The path extraction sub-module obtains the path entry pointed to by the record item in the entry access list, performs a hierarchical traversal on each path, extracts all file positions in the path, calculates the path structure layer number and the intra-layer distribution quantity based on the node depth and the same-level quantity of the file position, and generates a structure level density; Based on the structure level density value, the structure judgment sub-module calls the file storage type in the traversal result, performs integrity judgment according to the file suffix field, creation method field, and access method field, classifies and records according to whether there are missing key fields in the file, calculates the number of complete files in the classification group, and generates the complete file ratio result; According to the complete file ratio result and the structure level density value, the closed generation sub-module judges the path closure degree of the corresponding area between the structure level distribution and the integrity classification group, filters the path segments that simultaneously meet the closed path depth and the complete file ratio exceeding the set threshold, counts the classification quantity of the path segments and archives them, and generates a boundary closed graph.

6. The digital space full-flow encryption transmission system according to claim 5, wherein The specific calculation formula for the number of complete files in the classification group is as follows: ; Among them, represents the number of complete documents in the classification group, represents the validity ratio of the suffix field, represents the standardized value of the creation method field, represents the standardized value of the access method field, represents the creation method weight factor, represents the integrity score of the current document field, represents the baseline integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor.

7. The digital space full-flow encryption transmission system according to claim 1, characterized in that The identity binding module includes: The path indexing sub-module obtains the file path marking item and the file available status field extracted from the boundary closed graph, performs a cross-combination extraction operation based on the values of the file path field and the available status field, establishes a mapping record group of paths and statuses, calculates the differentiation index in the record group, and generates the path status combination quantity; According to the path status combination quantity, the identity numbering sub-module calls the access identity record and the path mapping field, performs a field cross-comparison on the identity identification field and the path field, filters the matching items and sets a unique number, constructs a number list and calculates the number of identities corresponding to the number items, and generates the identity number density; Based on the identity number density and the path status combination quantity, the access mapping sub-module writes the identity number and the corresponding file status combination into the exclusive record list, filters the combination items where the identity number and the path status appear simultaneously, counts the proportion in the total records, establishes a mapping structure and outputs the record table, and generates the file access index table.

8. The digital space full-flow encryption transmission system according to claim 1, characterized in that, The permission verification module includes: The permission extraction sub-module obtains the content of the identity field and the path field in the file access index table, calls the access level label in the identity field and the access attribution group in the path field, performs number mapping on the identity field value, performs grouping classification on the path field value, calculates the number of identity levels corresponding to each group of paths, and generates the level attribution distribution quantity; According to the level attribution distribution quantity, the matching judgment sub-module performs a two-way matching operation on the identity access level label and the path access attribution group, marks the matching field pairs of the identity number set, classifies the numbers that do not meet the matching conditions into the restricted record pool, counts the number of identity numbers in the matching set and the restricted set, and generates the permission matching ratio value; Based on the permission matching ratio value and the level attribution distribution quantity, the list generation sub-module extracts the marked matching identity number set, recombines it with the file path field, establishes an identity-path comparison list, summarizes the allowable path records corresponding to each identity number, and generates the access execution list.

9. The digital space full-flow encryption transmission system according to claim 1, characterized in that The path tracing module includes: The path collection sub-module obtains the access path segments marked as allowed in the access execution list, collects the execution time field and the operation file name field in the path segment, combines and pairs the time field and the path field, counts the number of combined entries and the time coverage range, and generates the path action quantity; The sequence generation sub-module calls the combined result of the path field and the time field according to the number of path actions, constructs an ordered arrangement structure for each combined entry, marks the chronological relationship to form a continuous action chain, counts the number of action chains and the length of the time span, and generates the access action sequence quantity. The identity marking sub-module writes the source identity field corresponding to each access action sequence into the access record transfer pool based on the access action sequence quantity, performs a binding operation on the sequence entry and the identity value and marks a unique code, counts the number of encrypted marking entries and the distribution ratio in the transfer pool, and generates the spatial traffic encrypted transmission result.

10. A full-traffic encryption transmission method for the digital space, characterized in that, Execute according to a digital space full-traffic encrypted transmission system according to any one of claims 1-9, including the following steps: S1: Obtain the account structure, source field, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and the source field, make an attribution judgment on the access environment identifier and the terminal network source, set a marking status for the successfully matched and attributed identity record, and generate an entry access list after summarizing the marked identity records. S2: Extract the path entry pointed to by the record item based on the entry access list, perform traversal extraction on the path entry, obtain the path structure level and file location information, perform an integrity judgment and classification record operation on the storage type field, screen the path of the closable area, mark and summarize it, and generate a boundary closure map. S3: Extract the file path marking item and the file availability status field according to the boundary closure map, perform a field cross-comparison on the access identity record and the path mapping field, extract the cross item, set a unique identifier, and establish a number list, and write the record in the file status into the identity mapping list to generate a file access index table. S4: Call the identity field and the path field in the file access index table, perform a two-way matching operation on the access level label and the access attribution group, set a release label for the matching item, and classify the non-matching item into the restriction pool. Generate an access execution list after summarizing the release records. S5: Extract the access path segment with the release label based on the access execution list, collect the execution time and the operation file name field in the path segment, form an access action sequence entry by combining the time and the path field, write the entry into the access record transfer pool and indicate the source identity, and generate the spatial traffic encrypted transmission result.

Citation Information

Patent Citations

  • Data access control analysis method based on data security law category

    CN114205118A

  • Transaction data analysis system and method based on block chain

    CN118797531A

  • Government affair file multi-dimensional factor safety management system

    CN119004426A

  • Private domain live broadcast data storage and visitor authentication method and system based on block chain

    CN119363316A

  • Intelligent evaluation method and system for network security level protection

    CN119363487A

Cited By

  • Access control method for legal consultation data

    CN120974537A

  • Method for access control of legal consultation data

    CN120974537B

  • Digital identity recognition and safety management system based on biological characteristics

    CN121051730A