A digital space full-flow encrypted transmission system and method

Through modular processing of entry authentication, structural enclosure, identity binding and permission verification, the dynamic permission control problem of network data transmission in digital space is solved, precise access management and behavior tracking is realized, and the security and reliability of data transmission are improved.

CN120342792BActive Publication Date: 2025-08-19SICHUAN YOUJIA TRACEABILITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510822134.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-08-19
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

In the process of network data transmission in digital space, the existing technology lacks dynamic linkage and fine-grained constraints on the source identity, path status and operation behavior of the access operator, resulting in generalization of permission judgment, fuzzy path ownership and difficulty in tracing access behavior, and it is difficult to achieve comprehensive supervision of permission boundaries, identity associations and behavioral legitimacy in complex operation chains.

Method used

The access list is generated through the entrance authentication module, the structure enclosed module builds a boundary enclosed map, the identity binding module establishes a file access index table, the permission verification module performs two-way matching, and the path trace module generates access action sequences to form a verifiable and traceable data flow structure, improving the accuracy and boundary clarity of permission verification.

Benefits of technology

It realizes multi-dimensional trustworthy judgment of operators, combines the structured identification and positioning of path levels and file storage status, and establishes a clear data access index system, improves the accuracy and boundary clarity of permission control, and ensures the verifiability and traceability of data flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342792B_ABST
    Figure CN120342792B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network information security technology, specifically a digital space full-flow encrypted transmission system and method, the system includes an entry authentication module, a structure closure module, an identity binding module, an authority verification module and a path trace module. In the present invention, an access list is generated by jointly identifying the operator's identity information, access environment identifier and terminal network affiliation, a multi-dimensional trustworthy judgment basis for the access source is constructed, and the path hierarchy extraction and file storage status classification are combined to achieve structured identification and positioning of the access target. The identity field and the path mapping relationship are cross-matched to form a unique binding identifier, and a clear data access index system is established. The authority control is based on the two-way matching of the access level and the affiliation group, which improves the accuracy and boundary clarity of the authority verification. The access behavior is sequenced by path, time and file operation and bound to the identity, forming a data flow structure that is verifiable, traceable and has closed-loop control capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security technology, and in particular to a digital space full-flow encrypted transmission system and method. Background Art

[0002] The field of network information security technology encompasses mechanisms to safeguard confidentiality, integrity, availability, and non-repudiation during data transmission, storage, and processing within a network environment. Its core elements include cryptographic mechanisms, access control mechanisms, identity authentication mechanisms, secure communication protocols, and intrusion detection and prevention mechanisms. This technology is widely used in information technology applications such as internet communications, e-commerce, government services, and financial transactions, aiming to build a secure and trustworthy network environment and prevent information leakage, tampering, forgery, and unauthorized access. Network information security technology continues to evolve, gradually forming a multi-layered protection system based on cryptographic algorithms, supported by protocol specifications, and framed by a security architecture, achieving systematic protection for data throughout its lifecycle.

[0003] Among them, the digital space full-flow encrypted transmission system and method refers to the system structure and operation method designed for the network data transmission process in the digital space environment to achieve overall encryption of network traffic. This patent subject addresses the problem that multi-source heterogeneous network communication data in the digital space is easily intercepted, eavesdropped and analyzed during transmission, and proposes an encrypted transmission method with full-flow encryption as the core. It mainly processes the format of the original data in the data generation link, and then organizes and classifies the network flow data according to the communication session, and then uses the symmetric key encryption method to encrypt and encapsulate each type of data. At the same time, it cooperates with the asymmetric key mechanism to realize the key negotiation and distribution process, and adds an encryption channel strategy to the transmission path to ensure the data consistency and encryption integrity of the relay node and the target receiving end. The entire system uses the key management mechanism, data classification strategy and transmission channel configuration as a means to form a full-flow encryption architecture suitable for high-frequency data exchange environments.

[0004] While existing technologies can encrypt communication flows and negotiate keys during data transmission, they lack dynamic linkage and fine-grained constraints on the source identity, path status, and operational behavior of access operators. This often leads to generalized permission determination, ambiguous path attribution, and difficulty tracing access behavior. Because access control largely relies on static permission configuration and initial session identity authentication, operations lack the support of dynamic identification and path matching throughout the entire process. This makes it difficult for the system to distinguish between the legitimacy of operations and the boundaries of access scope, leading to unauthorized access and potential data leakage risks. Path structure information and file status are not incorporated into permission calculation logic, allowing sensitive data to be erroneously accessed even after path changes or permission adjustments. Access recording mechanisms generally store operation information in log form, lacking a systematic link between behavior sequences and identity traceability, making it difficult to establish a reliable basis for accountability. In high-frequency operation scenarios, such as multi-departmental collaborative business platforms, operation frequency and identity overlap significantly. Without a path and identity binding mechanism, access rights confusion and uncontrolled data flow are easily caused. These deficiencies restrict the system's comprehensive supervision of permission boundaries, identity associations, and the legitimacy of operations within complex operation chains, impacting the security of data operations in network information environments. Summary of the Invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a digital space full-flow encrypted transmission system and method.

[0006] In order to achieve the above-mentioned object, the present invention adopts the following technical solution: A digital space full-flow encrypted transmission system comprises:

[0007] The entry authentication module obtains the operator identity record, access environment identifier and entry source, matches the account structure with the source field, determines the access environment and terminal network attribution, and generates an entry access list;

[0008] The structural closure module extracts the path entry according to the entry access list, generates a structural hierarchical description, performs integrity judgment and classification on the storage type, summarizes the closed area, and generates a boundary closure map;

[0009] The identity binding module extracts the file path mark item and the file available status field based on the boundary closed graph, performs field cross-comparison on the access identity record and the path mapping field, sets the cross-item identifier, establishes a number list, and generates a file access index table;

[0010] The permission verification module extracts the identity and path field contents according to the file access index table, matches the access level label with the belonging group, opens the permission label if the permission is met, and puts it into the restriction pool if it is not met, and generates an access execution list;

[0011] The path trace module extracts the release path segment from the access execution list, collects the execution time and operation file name, combines the time and path into an access action sequence, enters the record pool and indicates the source identity, and generates a spatial traffic encrypted transmission result.

[0012] As a further solution of the present invention, the entry access list includes account structure information, source identification, access environment characteristics, terminal network mark, and identity comparison label; the boundary closed map includes path entry identification, structural hierarchy information, file storage type, integrity classification result, and closed area mark; the file access index table includes path mark number, file availability status, identity mapping number, and access identity list; the access execution list includes access identity label, path belonging group, permission matching identifier, and access control result; the spatial traffic encrypted transmission result includes access path segment, operation time point, file name entry, action sequence item, and source identity information.

[0013] As a further solution of the present invention, the entry authentication module includes:

[0014] The identity matching submodule obtains the account structure field and source field in the operator identity record, compares the corresponding values of the account code field and the access platform field, calculates the number of field matches and the matching rate, and generates a field matching ratio result;

[0015] The environment identification submodule calls the access environment identifier and the terminal network source field according to the field matching ratio result, counts the access environment occurrence frequency, calculates the weighted frequency value, obtains the access source group corresponding to the frequency, and generates the main access frequency ratio value;

[0016] The list generation submodule screens the account set that meets both conditions based on the field matching ratio result and the main access frequency ratio value, calculates the ratio of the set to all records, marks the corresponding identity into the record set, and generates an entry access list.

[0017] As a further solution of the present invention, the weighted frequency value calculation formula is specifically:

[0018] ;

[0019] in, Representative environmental logo The weighted frequency value of Representative environmental logo The normalization coefficient of the field matching ratio result, Representative environmental logo The original number of occurrences of Represents the terminal network source The adjustment factor, Represents the terminal network source Independent correction term, Represents the total number of terminal network sources.

[0020] As a further solution of the present invention, the structural enclosed module includes:

[0021] The path extraction submodule obtains the path entry pointed to by the record in the entry access list, performs a level-by-level traversal on each path, extracts all file locations in the path, calculates the number of path structure layers and the distribution within the layer based on the node depth and the number of the same level of the file location, and generates the structure level density;

[0022] The structure judgment submodule calls the file storage type in the traversal result based on the structure level density value, performs integrity judgment based on the file suffix field, creation method field and access method field, and classifies the records according to whether the key fields are missing in the file, calculates the number of complete files in the classification group, and generates a complete file ratio result;

[0023] The closed generation submodule determines the path closure degree of the area corresponding to the structural hierarchy distribution and the integrity classification group based on the complete file ratio result and the structural hierarchy density value, selects the path segments that simultaneously meet the closed path depth and the complete file ratio exceeding the set threshold, counts the number of classifications of the path segments and archives them, and generates a boundary closed map.

[0024] As a further solution of the present invention, the formula for calculating the number of complete files in the classification group is specifically:

[0025] ;

[0026] in, Represents the number of complete files in the classification group, Represents the validity ratio of the suffix field, Represents the normalized value of the creation method field, Represents the normalized value of the access method field, Represents the creation method weight factor, Represents the completeness score of the current file field. represents the baseline integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor.

[0027] As a further solution of the present invention, the identity binding module includes:

[0028] The path indexing submodule obtains the file path tag items and the file available status fields extracted from the boundary closed graph, performs a cross-combination extraction operation based on the values of the file path field and the available status field, establishes a mapping record group of paths and statuses, calculates the differentiation index in the record group, and generates a path status combination quantity;

[0029] The identity number submodule calls the access identity record and path mapping fields according to the path state combination quantity, performs a field cross-comparison between the identity identification field and the path field, selects matching items and sets unique numbers, builds a number list and calculates the number of identities corresponding to the number items to generate the identity number density;

[0030] Based on the identity number density and the path status combination quantity, the access mapping submodule writes the identity number and the corresponding file status combination into an exclusive record list, filters the combination items in which the identity number and the path status appear at the same time, counts the proportion in the total records, establishes a mapping structure and outputs a record table to generate a file access index table.

[0031] As a further solution of the present invention, the authority verification module includes:

[0032] The permission extraction submodule obtains the contents of the identity field and the path field in the file access index table, calls the access level label in the identity field and the access attribution group in the path field, performs number mapping on the identity field value, groups and classifies the path field value, calculates the number of identity levels corresponding to each group of paths, and generates a level attribution distribution;

[0033] The matching judgment submodule performs a bidirectional matching operation on the identity access level label and the path access attribution group according to the level attribution distribution, marks the matching field pair identity number set, puts the numbers that do not meet the matching conditions into the restriction record pool, counts the number of numbers in the matching set and the restriction set, and generates a permission matching ratio value;

[0034] The list generation submodule extracts the marked matching identity number set based on the permission matching ratio value and the level attribution distribution, and recombines it with the file path field to establish an identity path comparison list, summarizes the releaseable path records corresponding to each identity number, and generates an access execution list.

[0035] As a further solution of the present invention, the path trace module includes:

[0036] The path collection submodule obtains the access path segment marked as released in the access execution list, collects the execution time field and the operation file name field in the path segment, combines and pairs the time field with the path field, counts the number of combined entries and the time coverage, and generates the number of path actions;

[0037] The sequence generation submodule calls the combination result of the path field and the time field according to the number of path actions, constructs a sequential arrangement structure for each combination entry, marks the time sequence relationship and forms a continuous action chain, counts the number of action chains and the length of the time span, and generates the access action sequence quantity;

[0038] Based on the access action sequence quantity, the identity marking submodule writes the source identity field corresponding to each access action sequence into the access record circulation pool, performs binding operation on the sequence entry and identity value and marks the unique code, counts the number and distribution ratio of encrypted marking entries in the circulation pool, and generates the spatial traffic encrypted transmission result.

[0039] A digital space full-flow encrypted transmission method comprises the following steps:

[0040] S1: Obtain the account structure and source fields, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and source fields, determine the attribution of the access environment identifier and terminal network source, set a mark status for the identity records that are successfully matched and attributable, and generate an entry access list after aggregating the marked identity records;

[0041] S2: Extracting the path entry pointed to by the record item based on the entry access list, performing traversal extraction on the path entry, obtaining the path structure hierarchy and file location information, performing integrity judgment and classification record operations on the storage type field, screening the closable area paths, marking and summarizing them, and generating a boundary closure map;

[0042] S3: Extracting file path mark items and file availability status fields based on the boundary closure graph, performing field cross-comparison on access identity records and path mapping fields, extracting cross-items, setting unique identifiers, and creating a numbered list, writing the file status records into the identity mapping list, and generating a file access index table;

[0043] S4: calling the identity field and the path field in the file access index table, performing a two-way matching operation on the access level label and the access belonging group, setting the matching items to be marked with a release label, and placing the non-matching items into the restriction pool, and generating an access execution list after summarizing the release records;

[0044] S5: Based on the access execution list, extract the access path segment with the label of release, collect the execution time and operation file name fields in the path segment, combine the time and path fields to form an access action sequence entry, write the entry into the access record flow pool and indicate the source identity, and generate the spatial traffic encrypted transmission result.

[0045] Compared with the prior art, the advantages and positive effects of the present invention are:

[0046] In the present invention, an access list is generated by jointly identifying the operator's identity information, access environment identifier and terminal network affiliation, and a multi-dimensional trust judgment basis for the access source is constructed. Combined with path hierarchy extraction and file storage status classification, structured identification and positioning of the access target are achieved, and the identity field and path mapping relationship are cross-matched to form a unique binding identifier, establishing a clear data access index system. Permission control is based on the two-way matching of access level and affiliation group, which improves the accuracy and boundary clarity of permission approval. Access behavior is sequenced by path, time and file operation and bound to identity, forming a verifiable, traceable data flow structure with closed-loop control capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 is a system flow chart of the present invention;

[0048] Figure 2 is a system block diagram of the present invention;

[0049] Figure 3 This is a flow chart of the entry authentication module of the present invention;

[0050] Figure 4 It is a flow chart of the structural closed module of the present invention;

[0051] Figure 5 This is a flow chart of the identity binding module of the present invention;

[0052] Figure 6 This is a flowchart of the authority verification module of the present invention;

[0053] Figure 7 This is a flow chart of the path trace module of the present invention;

[0054] Figure 8 The figure is a flow chart of the steps of the method of the present invention. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0056] In the description of the present invention, it should be understood that the terms "length," "width," "up," "down," "front," "back," "left," "right," "vertical," "horizontal," "top," "bottom," "inside," "outside," and the like, indicating positions or relationships, are based on the positions or relationships shown in the accompanying drawings and are intended only to facilitate the description of the present invention and simplify the description. They do not indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limiting the present invention. Furthermore, in the description of the present invention, "plurality" means two or more, unless otherwise expressly and specifically defined.

[0057] See also Figure 1 and Figure 2 , a digital space full-flow encrypted transmission system includes:

[0058] The entry authentication module obtains the operator identity record, access environment identifier, and entry source, performs field matching and comparison between the account structure and source field in the identity record, makes attribution judgment on the access environment identifier and the terminal network source, compares the marked identity entry record set, and generates an entry access list;

[0059] The structural closure module extracts the path entry pointed to by the record item according to the entry access list, performs traversal extraction operations on each path, generates a structural hierarchical description of the file location, performs integrity judgment and classification record operations on the file storage type, marks the closable area and summarizes and archives it, and generates a boundary closure map;

[0060] The identity binding module extracts file path marker items and file availability status fields based on the boundary closed graph, cross-checks the access identity records with the path mapping fields, sets unique identifiers for the cross-items and creates a numbered list, writes the identity mapping records of the file status into a dedicated list, and generates a file access index table;

[0061] The permission verification module extracts the contents of the identity field and path field from the file access index table, performs a two-way matching operation on the access level label in the identity field and the access group in the path field. Records that meet the permission requirements are marked with a release tag, and mismatched records are placed in the restriction pool to generate an access execution list.

[0062] The path trace module extracts the access path segment labeled as released based on the access execution list, collects the execution time and operation file name fields in the path segment, combines the time and path into an access action sequence entry, enters the entry into the access record flow pool and indicates the source identity, and generates the spatial traffic encrypted transmission result.

[0063] The entry access list includes account structure information, source identification, access environment characteristics, terminal network tags, and identity comparison tags. The boundary closure map includes path entry identification, structural hierarchy information, file storage type, integrity classification results, and closed area tags. The file access index table includes path tag number, file availability status, identity mapping number, and access identity list. The access execution list includes access identity tags, path belonging groups, permission matching identification, and access control results. The spatial traffic encrypted transmission results include access path segments, operation time points, file name entries, action sequence items, and source identity information.

[0064] See also Figure 3 and Figure 2 , the entry authentication module includes:

[0065] The identity matching submodule obtains the account structure field and source field in the operator identity record, compares the corresponding values of the account code field and the access platform field, calculates the number of field matches and the matching rate, and generates a field matching ratio result;

[0066] The identity matching submodule obtains the account structure field and source field in the operator's identity record. During the extraction process, the account structure fields are read one by one according to the structural information of each data in the identity record. Common fields include account_id, user_code, login_id, etc. The source field can be source_type, platform_tag, etc. The account code field such as account_code is segmented and extracted. For example, the prefix "AC" in "AC_102938" is regarded as the account type identifier, and the suffix "102938" is the specific code value. The access platform field such as access_platform is identified by the platform identifier such as "WEB", "APP", and "API" and mapped to a unified standard format. During the matching process, the system Traverse the operator identity records one by one, compare the account code field with the account structure field at the character level in each record, and compare the access platform field with the source field to see if the platform identification is consistent. The matching items are accumulated once. When the total number of field pairs is set to 10, the comparison result is marked for each comparison. If the field account_id is "USR2025" and matches the suffix of account_code, and source_type is "WEB_LOGIN" and matches access_platform is "WEB", they are all counted as valid matching items. The total number of comparisons is 7, and the field matching ratio result is 0.7. In the setting operation, the matching ratio value does not require a separate formula. It is only obtained by counting the total number of comparison results and the total number of field items, and recorded as the final result.

[0067] The environment identification submodule uses the access environment identifier and the terminal network source field based on the field matching ratio result to count the access environment occurrence frequency, calculate the weighted frequency value, obtain the access source group corresponding to the frequency, and generate the main access frequency ratio value;

[0068] The specific formula for calculating the weighted frequency value is:

[0069] ;

[0070] in, Representative environmental logo The weighted frequency value of Representative environmental logo The normalization coefficient of the field matching ratio result, Representative environmental logo The original number of occurrences of Represents the terminal network source The adjustment factor, Represents the terminal network source Independent correction term, Represents the total number of terminal network sources;

[0071] The "weighted frequency value" is a statistical indicator used to measure the dominance and credibility of a particular access environment identifier in identity authentication. It is primarily used in the "entry authentication module" to determine and screen access source environments. This value is not used to calculate the probability of an event, but rather a weighted indicator that integrates multiple factors.

[0072] Parameter assignment basis and data source

[0073] (Normalization coefficient): Based on environmental identification The field matching ratio result is calculated, and the field matching ratio result is the environment identifier The percentage of successful matches to the total number of matches during the monitoring period. For example, if the total number of matches during the monitoring period is 1000, the environment identifier The number of successful matches is 200. , which fluctuates between 0 and 1.

[0074] (Original number of occurrences): Statistical environment identifier through log data The actual number of occurrences during the monitoring period. For example, log statistics Second-rate.

[0075] (Adjustment Factor): Based on the terminal network source The historical traffic quality score is set on a scale of 0.5 to 1.5. For example, Wi-Fi sources (High stability), mobile data (Low stability), based on the linear mapping results of quantified network delay and packet loss rate monitoring data.

[0076] (Independent correction item): Based on terminal network source Calculation of abnormal request counts, such as the source The number of abnormal requests is 10, then ,The number of exceptions is counted by the firewall log.

[0077] (Total number of terminal sources): The number of terminal network sources that are actually connected during the monitoring period. For example, if Wi-Fi and mobile data are monitored, .

[0078] Formula calculation derivation (calculation example)

[0079] Substitute the parameters:

[0080] , , , (Mobile Data), (Wi-Fi abnormality times), (Number of abnormal mobile data), .

[0081] Calculation steps:

[0082] calculate ;

[0083] calculate ;

[0084] Sum: ;

[0085] calculate ;

[0086] Take the absolute value: ;

[0087] Interpretation and relevance of results

[0088] The results show that environmental labeling The weighted frequency value of is 29.248, which is calculated by the original number of occurrences, the terminal network quality score and the abnormal correction item. The weighted frequency value is used to generate the main access frequency ratio value in the subsequent generation. The specific association method is: The ratio of the sum of all weighted frequency values in the environment identifier set is used as the primary access frequency ratio. For example, if all environment identifiers The total is 200, so the current environmental identification ratio is , which is consistent with the result of generating the main access frequency ratio value of the short sentence at the end of the original paragraph.

[0089] The list generation submodule selects the account set that meets both conditions based on the field matching ratio and the primary access frequency ratio. It calculates the ratio of the set to all records, marks the corresponding identity into the record set, and generates the entry access list.

[0090] First, set the minimum threshold M_thresh of the field matching ratio result and the minimum threshold F_thresh of the main access frequency ratio. The threshold setting is determined according to the sample distribution law. For example, M_thresh is set to a value near the mean of the field matching ratio result sample of 0.65, that is, 0.65 is taken as the set threshold, and F_thresh is set to the weighted mean of the access frequency ratio sample plus 5% increase. If the mean is 0.5, set F_thresh to 0.55. Traverse all account records, and for each record, first determine whether the field matching ratio result is higher than 0.65. If so, continue to determine whether the access environment to which it belongs is in the main access source group, and whether the access environment has a frequency Is the rate greater than 0.55? For example, if the result of the field matching ratio of an account is 0.68, the access environment is "office+wifi", it is in the main access source group and the frequency is 0.6, then the account meets the double screening conditions and enters the valid set. The number of such accounts continues to accumulate. After all traversals are completed, the ratio between the number of valid accounts S and the total number of records T is counted to obtain the set proportion. For example, after screening, 90 accounts meet the conditions and the total number of records is 300, then the set proportion is 30%. This ratio is used as the final judgment value, and the status mark "valid_entry=1" is added to all accounts in the set to build the entry access list for the next process operation.

[0091] See also Figure 4 and Figure 2 , the structural closure module includes:

[0092] The path extraction submodule obtains the path entry pointed to by the record in the entry access list, performs a level-by-level traversal on each path, extracts all file locations in the path, calculates the number of path structure layers and the distribution within the layer based on the node depth and the number of peers of the file location, and generates the structure level density;

[0093] First, read the path field value in each record, extract the path content such as " / Business System / Module A / Task Table / Plan.xlsx", and split the path string into several hierarchical nodes based on the separator " / ", namely "Business System", "Module A", "Task Table", and "Plan.xlsx". Read each level from top to bottom and establish a path tree structure. Rely on the file system or data directory structure to obtain the total number of files or folders at the same level at each level. For example, under the first level "Business System", there are 3 nodes: "Module A", "Module B", and "Module C". Under the second level "Module A", there are 3 items: "Task Table", "Requirement Document", and "Archive Plan". Under the third level "Task Table", there are "Plan.xlsx", "Budget.xlsx". lsx" files, the calculated path structure layer number is 4 layers (excluding the root directory), and the number of nodes at the same level at each level is counted as 3, 3, and 2 respectively. After the system traverses each path, it counts the average number of structure layers of all paths in the path set and the average distribution under the layer. Assuming the average number of layers of all paths is 4.2 layers, the structural density division threshold is set as follows: low density is less than 3 layers, medium density is between 3 and 5 layers, and high density is greater than 5 layers. For example, a path " / platform / business module / task set / annual / report / details / 2025.doc" has a total of 7 layers, and the number of files at the same level in each layer is not less than 3. In this case, the path structure layer density is high. The system finally generates and outputs the structure layer density value of the path based on the number of layers and distribution values extracted from each path.

[0094] The structure judgment submodule uses the structure level density value to call the file storage type in the traversal result, and makes integrity judgments based on the file suffix field, creation method field, and access method field. It also classifies the records according to whether the key fields are missing in the file, calculates the number of complete files in the classification group, and generates a complete file ratio result.

[0095] The formula for calculating the number of complete files in a classification group is:

[0096] ;

[0097] in, Represents the number of complete files in the classification group, Represents the validity ratio of the suffix field, Represents the normalized value of the creation method field, Represents the normalized value of the access method field, Represents the creation method weight factor, Represents the completeness score of the current file field. represents the baseline integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor;

[0098] Parameter assignment and acquisition methods:

[0099] (Suffix field validity ratio): By monitoring the validity of the suffix field in the file storage type, the ratio of the number of valid suffixes to the total number of suffixes is calculated. For example, if the total number of suffixes monitored is 200 and there are 180 valid suffixes, then The validity criterion is that the suffix exists in the system predefined list and is not marked as obsolete.

[0100] (Normalized value of the creation method field): The creation method field is divided into three categories: automatic generation, user upload, and system migration. The quantitative rules are: automatic generation is assigned a value of 0.8, user upload is assigned a value of 0.5, and system migration is assigned a value of 0.3. If the current file creation method is monitored as automatic generation, then .

[0101] (Normalized value of access mode field): The access mode field is divided into three categories: read-only, read-write, and encrypted access. The quantitative rule is: read-only is assigned a value of 0.9, read-write is assigned a value of 0.6, and encrypted access is assigned a value of 0.4. If the current file access mode is read-write, then .

[0102] (Creation method weight factor): The weight factor is preset to 0.4 based on the impact of the creation method on integrity. The basis is that the proportion of integrity errors caused by missing creation method fields in historical data accounts for 40% of the total field missing events.

[0103] (Current file field integrity score): Calculates by checking whether the file's suffix, creation method, and access method fields are missing, and performing a weighted sum calculation. For example, if the suffix field exists, it will score 1 point; if the creation method field exists, it will score 0.8 points; and if the access method field exists, it will score 0.6 points. .

[0104] (Baseline integrity score threshold): The median integrity score of normal files in historical data is set to 2.0.

[0105] (Dynamic adjustment coefficient): Calculated based on the historical missing rate, the formula is ,in is the file loss rate in the past week. For example, if the loss rate is 5%, .

[0106] (Normalization factor): Calculated by the ratio of the total number of files in the current file group to the total number of files in the system. For example, if the current file group monitoring contains 50 files and the total number of files in the system is 1000, then .

[0107] Formula calculation derivation:

[0108] calculate : Substitution , have to .

[0109] calculate : Substitution ,have to .

[0110] calculate : Substitution , , ,have to .

[0111] Sum the numerator: .

[0112] calculate : Substitution , ,have to .

[0113] Final result: .

[0114] Meaning of numerical results:

[0115] This indicates that the current file's integrity score is significantly higher than the baseline threshold of 1.0, classifying it as intact. This score quantifies the file's integrity by integrating field validity, differences in creation and access methods, dynamic adjustments, and normalization factors. This score is used to subsequently calculate the number and proportion of intact files.

[0116] The closed-loop generation submodule determines the path closure degree of the corresponding area of the structural hierarchy distribution and integrity classification group based on the complete file ratio result and the structural hierarchy density value. It selects path segments that simultaneously meet the closed path depth and complete file ratio exceeding the set threshold, counts the number of path segments classified and archives them, and generates a boundary closed map.

[0117] First, the structural density value and complete file ratio results of each path are read in sequence. The judgment threshold is set as follows: a path structure level depth of at least 5 layers is considered to have closure capability. The complete file ratio threshold is set to 70%, which is based on the mean of the entire data sample plus a tolerance of 5%. In the specific judgment, for the path " / system / module / branch / submodule / data / result / report.docx", it has 7 structural levels, which is a high structural density path. There are 20 files in this path directory, 17 of which are complete files, with a completeness ratio of 85%. This meets the completeness threshold and closed path level conditions, so the system marks this path segment as a valid closed path segment. After judging all paths, the path segments that meet the conditions are collected, counted, and classified. For example, if 92 path segments meet the conditions out of 500 paths, the number of classified paths is 92. At the same time, the structural hierarchy and file integrity ratio of these 92 paths are compiled into the graph structure dataset, which is used to output a boundary closed graph, annotated with path number, depth, distribution, and integrity level.

[0118] See also Figure 5 and Figure 2 , the identity binding module includes:

[0119] The path indexing submodule obtains the file path tag items and file available status fields extracted from the boundary closed graph, performs cross-combination extraction operations based on the values of the file path field and the available status field, establishes a mapping record group of paths and statuses, calculates the differentiation index in the record group, and generates a path status combination quantity;

[0120] First, read the path fields recorded in the atlas one by one, such as " / Project A / Module X / Data Table.xlsx", and read the file availability status field value corresponding to the path, such as "valid", "invalid", and "inaccessible". The system uses the path field and the availability status field as two dimensions to perform a cross-combination extraction operation, and splices each path value and the corresponding status value into a combination key-value pair, such as " / Project A / Module X / Data Table.xlsx-Valid". A mapping record group between the path and the status is established, and the mapping group is sorted and deduplicated. A combination index table is established according to the combination item, and the frequency of occurrence of each combination is recorded. Then, a differentiation index calculation is performed on each combination. The index is calculated based on The calculation is based on the degree of balance of state distribution. For example, for the path " / ProjectB / ModuleY / Drawing.dwg", there are three records with the states of "valid", "invalid", and "valid" respectively. Then, this path state combination has two states, and the state difference rate is 66.7%. For the path " / ProjectC / ModuleZ / Configuration.xml", all five records are "valid", and the difference rate is 0%. The differentiation index range is set as 0%-30% for low difference, 30%-70% for medium difference, and greater than 70% for high difference. The system traverses all combinations and labels them, and finally outputs the number of path state combinations for each group, including the number of combined paths, the number of corresponding state items, the difference label value, and the distribution density.

[0121] The identity number submodule calls the access identity record and path mapping fields according to the path state combination quantity, performs a field cross-comparison between the identity identification field and the path field, selects matching items and sets unique numbers, builds a number list and calculates the number of identities corresponding to the number items to generate the identity number density;

[0122] First, read each set of path and status combination records, and call the access identity record field such as user_id and the path mapping field such as access_path, and perform a field comparison operation on the two fields. During the comparison process, read the access_path field in the identity record and the combined path field for character-level matching to determine whether the path is consistent with the path in the identity record. If the match is successful, an identity correspondence is established. Further, read the identity identification field under the same matching item, such as "U10452" and "U30567", and establish an independent number for each unique identity and path status combination, such as "IDX001", "IDX002 ", the number generation can be generated by sequential accumulation combined with the hash result of the combination field, and then all the numbers are formed into a number list. For each number, the number of identity records matching it is counted. For example, the number IDX001 corresponds to 3 identity records, and IDX002 corresponds to 5 identity records. Then the number of identities corresponding to the number item is generated, and finally the density value of the number of identities corresponding to the number is calculated. The density range is set as: less than 3 people are low density, 3 to 6 people are medium density, and more than 6 people are high density. For example, among 200 combination numbers, 50 numbers correspond to identities with a number less than 3, then the low density ratio is 25%, and all numbers and identity numbers and density value labels are output.

[0123] The access mapping submodule writes the identity number and the corresponding file status combination into a dedicated record list based on the identity number density and the path status combination quantity, filters the combination items where the identity number and path status appear at the same time, calculates the proportion in the total records, establishes a mapping structure and outputs the record table, and generates a file access index table;

[0124] First, read each item number and its density value in the number list, and read the path status combination item bound to it at the same time, build an exclusive record list of the identity number and the corresponding path status combination, use the number as the primary key and the status combination item as the subsidiary key to bind the record, and filter out the combination items that appear at the same time in all records. For example, the number IDX015 is bound to the path " / business / form A / annual statistics.xlsx" and the status "valid". If there are multiple identity records with this combination item, mark the combination item as a valid mapping item. After the screening is completed, The occurrence ratio of all mapping items in the total records is counted. For example, the total number of identity-path combination records is 800, and 210 valid mapping items are screened, then the ratio is 26.25%. The ratio interval is set as follows: less than 20% is a low-association area, greater than or equal to 20% and less than 50% is a medium-association area, and greater than or equal to 50% is a high-association area. This example belongs to the medium-association area. The system establishes a mapping structure based on this, lists each identity number, the path state combination it refers to, and the corresponding occurrence frequency in the structure table, and outputs it as the final file access index table for subsequent index tracking.

[0125] See also Figure 6 and Figure 2 , the authority verification module includes:

[0126] The permission extraction submodule obtains the contents of the identity field and path field in the file access index table, calls the access level label in the identity field and the access attribution group in the path field, maps the identity field values to numbers, groups and classifies the path field values, calculates the number of identity levels corresponding to each group of paths, and generates the level attribution distribution;

[0127] First, the system reads the identity field value (such as "U1023", "U2451") and path field value (such as " / Data Center / 2025 / Q1 Report.xlsx") of each record from the index table, extracts the access level label in the identity field, such as "Level 1", "Level 2", and "Level 3". The access level label field is read from the original identity registration or system authorization label. The access group field in the path field is extracted from the business module, system classification, or project to which the path belongs. For example, the path belongs to "Finance Department", "Technology Department", and "Sales Department". When performing the number mapping operation, each identity value is encoded in sequence to generate a standard number, such as "ID001 ”, “ID002”, etc. The path fields are grouped and classified to establish a mapping structure according to the access group to which they belong. For example, all paths belonging to the “Finance Department” are classified into the same classification group. Then the identity number and the belonging path group are cross-mapped and counted. For each belonging path group, the number of identity numbers corresponding to the access levels such as “first level”, “second level”, and “third level” are counted respectively. For example, there are 50 users under the path group “Finance Department”, including 20 first-level users, 18 second-level users, and 12 third-level users. The distribution structure is recorded as “Finance Department-20 / 18 / 12”. After the system completes the level count of all path belonging groups, it outputs it as the level attribution distribution quantity.

[0128] The matching judgment submodule performs a bidirectional matching operation on the identity access level label and the path access attribution group based on the level attribution distribution, marks the matching field pair identity number set, and puts the numbers that do not meet the matching conditions into the restricted record pool. It counts the number of numbers in the matching set and the restricted set, and generates the permission matching ratio value;

[0129] First, set the range of identity levels allowed for access for each path group. For example, the "Finance Department" path group allows access levels 1 and 2, the "Technology Department" allows all levels, and the "Sales Department" is limited to 1st level access. The level corresponding to each identity number in the level distribution table is read and compared individually. If the identity level meets the access level set for the current path group, the number is marked as a match. Otherwise, the number is marked as a mismatch and placed in the restricted record pool. For example, identity number "ID025" is level 3 and belongs to the "Finance Department" path. Since it does not fall within the allowed level range, it is placed in the restricted record pool. The system iterates through all identity numbers and counts the number of matching number sets and the number of restricted number sets. For example, if there are 340 matching numbers and 160 restricted numbers, the calculated ratio is 340 / (340+160)=68%. The permission match ratio value range is set as follows: below 50% is a weak match, 50% to 80% is a medium match, and above 80% is a strong match. The result is placed in the medium match range. Finally, the permission match ratio value and the corresponding marked set result are output.

[0130] The list generation submodule extracts the set of marked matching identity numbers based on the permission matching ratio value and the level attribution distribution, and recombines them with the file path field to establish an identity path comparison list, summarizes the release path records corresponding to each identity number, and generates an access execution list;

[0131] Based on the permission matching ratio and the level attribution distribution, the list generation submodule reads the set of identity numbers marked as matching in the previous submodule and recombines them with the path field to construct an identity-path comparison relationship. For example, ID "ID041" has access to the path group "Finance Department." If the "Finance Department" path category includes the paths " / Finance / Budget Table.xlsx" and " / Finance / Expenditure Summary.xlsx," then "ID041-Budget Table.xlsx" and "ID041-Expenditure Summary.xlsx" are recorded as its releasable path records. The system sequentially combines each identity number with all file paths in its path group to form a complete record entry. After summarizing all identity number and path comparison entries, it constructs an identity-path comparison list and outputs this list in a structured manner, recording the number of paths corresponding to each number. For example, "ID041" has five paths, and "ID053" has eight paths. Finally, the system integrates all number entries to generate a unified access execution list, which contains the identity number, access level, path group, releasable path list, and path number. This list is output as index data for executing access control.

[0132] See also Figure 7 and Figure 2 , the path trace module includes:

[0133] The path collection submodule obtains the access path segments marked as released in the access execution list, collects the execution time field and operation file name field in the path segment, combines and pairs the time field with the path field, counts the number of combined entries and the time coverage, and generates the number of path actions;

[0134] First, read the path segment field values with release marks in the execution list one by one, such as " / Platform Module A / Project Data / Report Summary Table.xlsx", and extract the execution time field value such as "2025-06-1508:42:13" and the operation file name field such as "Report Summary Table.xlsx" from the corresponding record. The system creates a composite key based on the path field and the time field, and combines and pairs the path value with the time value to form a combination entry such as " / Platform Module A / Project Data / Report Summary Table.xlsx_2025-06-1508:42:13". Traverse all records to create a list of such entries, and then perform statistical operations on the combined entry list to calculate Calculate the total number of combination entries. For example, if a total of 350 path segments and corresponding time combination items are extracted in a certain operation, the number of path action combination entries is 350. Then read the time field values in all combination items and extract the earliest time and the latest time points, such as "2025-06-10 09:00:00" and "2025-06-18 18:30:00", respectively. The calculated time coverage is 8 days and 9.5 hours. The time range judgment criteria are set as follows: less than 1 day is short-term, between 1 and 3 days is medium-term, and more than 3 days is long-term. In this example, the time period is classified as long-term. Finally, the system outputs 350 path actions and its corresponding time coverage is marked as "long-term".

[0135] The sequence generation submodule calls the combination of the path field and the time field based on the number of path actions, constructs a sequential structure for each combination entry, marks the time sequence relationship and forms a continuous action chain, counts the number of action chains and the length of the time span, and generates the access action sequence quantity;

[0136] First, all path and time field combination items are read. Before constructing the sequential arrangement structure, the system groups the combination items by the path field. In each path field group, the combination items are sorted in ascending order by the time field to form an ordered structure chain. For example, under the path " / Department A / 2025 Task", there are combination items with the times "2025-06-1110:15:00", "2025-06-1111:00:00", and "2025-06-1112:45:00". After sorting, an action chain sequence "Step 1 - Step 2 - Step 3" is formed, and each combination item is given a sequential label such as "SEQ001-1", "SEQ001-2", and "SEQ001-3". Each action chain represents the actions performed at different points in time under the path. For the trajectory of the action, the system completes the above operations on all path groups and counts the total number of action chains. For example, 95 action chains are generated in all 350 combination items. The time span of each action chain is then counted. The time span is calculated as the difference between the latest time and the earliest time in the same chain. If the start time of an action chain is "2025-06-11 09:00:00" and the end time is "2025-06-11 14:30:00", the time span is 5.5 hours. All chain time spans are recorded and classified by interval: less than 1 hour is a short chain, 1 to 4 hours is a medium chain, and more than 4 hours is a long chain. The time spans are then combined with the quantity value and output together. Finally, the system outputs 95 access action sequences and marks the chain time length type as long, medium, and short.

[0137] Based on the number of access action sequences, the identity tag submodule writes the source identity field corresponding to each access action sequence into the access record circulation pool, binds the sequence entries with the identity value and marks them with a unique code, counts the number and distribution ratio of encrypted tag entries in the circulation pool, and generates the spatial traffic encrypted transmission results;

[0138] First, read the path and time combination items bound to each access action sequence structure generated above, and then extract the source identity field value corresponding to each combination item, such as "U1053", "U1172", etc., write the identity field value into the access record flow pool, and establish a binding relationship between the identity and sequence items. During the binding process, a unique coding identifier is generated for each sequence combination and the corresponding identity field. For example, "U1053" is bound to "SEQ010" to generate the identifier "SEQ010-U1053". This identifier is generated by splicing the serial number and the user identity field to ensure that each sequence action and its source identity are uniquely identifiable. The system will bind all the bindings. The fixed relationship records are put into the circulation pool, and then all records in the circulation pool are encrypted and marked, that is, the status flag "encrypted=1" is written in the record as an encryption identifier. In the statistical link, the system reads all encrypted marked entries and counts the total number, such as 570. The distribution ratio of encrypted entries in all records is 570 / 800=71.25%. The system sets the encryption distribution range as follows: less than 50% is sparse distribution, 50% to 80% is medium density, and more than 80% is a high-density encrypted circulation scenario. In this case, the record is medium density, and the encrypted transmission result is recorded as "medium density-71.25%-570", and the final output is the spatial traffic encrypted transmission result.

[0139] See also Figure 8 , a digital space full-flow encrypted transmission method, comprising the following steps:

[0140] S1: Obtain the account structure and source fields, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and source fields, determine the attribution of the access environment identifier and terminal network source, set a mark status for the identity records that are successfully matched and attributable, and generate an entry access list after aggregating the marked identity records;

[0141] S2: Extract the path entry pointed to by the record item based on the entry access list, perform traversal extraction on the path entry, obtain the path structure hierarchy and file location information, perform integrity judgment and classification operations on the storage type field, filter the path of the enclosable area, mark and summarize it, and generate a boundary closure map;

[0142] S3: Extract file path mark items and file availability status fields based on the boundary closed graph, perform field cross-comparison on access identity records and path mapping fields, extract cross-items, set unique identifiers, and create a numbered list, write the file status records into the identity mapping list, and generate a file access index table;

[0143] S4: Call the identity field and path field in the file access index table to perform a two-way matching operation on the access level label and the access belonging group. Set the matching items to be released and the unmatched items to be placed in the restriction pool. After summarizing the release records, generate an access execution list.

[0144] S5: Extract access path segments labeled as release based on the access execution list, collect the execution time and operation file name fields in the path segments, combine the time and path fields to form access action sequence entries, write the entries into the access record flow pool and indicate the source identity, and generate spatial traffic encrypted transmission results.

[0145] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention still falls within the scope of protection of the technical solution of the present invention.

Claims

1. A digital space full-flow encrypted transmission system, characterized by: The system comprises: The entry authentication module obtains the operator identity record, access environment identifier and entry source, matches the account structure with the source field, determines the access environment and terminal network attribution, and generates an entry access list; The structural closure module extracts the path entry according to the entry access list, generates a structural hierarchical description, performs integrity judgment and classification on the storage type, summarizes the closed area, and generates a boundary closure map; The identity binding module extracts the file path mark item and the file available status field based on the boundary closed graph, performs field cross-comparison on the access identity record and the path mapping field, sets the cross-item identifier, establishes a number list, and generates a file access index table; The permission verification module extracts the identity and path field contents according to the file access index table, matches the access level label with the belonging group, opens the permission label if the permission is met, and puts it into the restriction pool if it is not met, and generates an access execution list; The path trace module extracts the release path segment from the access execution list, collects the execution time and operation file name, combines the time and path into an access action sequence, enters the record pool and marks the source identity, and generates a spatial traffic encrypted transmission result; The entry authentication module includes: The identity matching submodule obtains the account structure field and source field in the operator identity record, compares the corresponding values of the account code field and the access platform field, calculates the number of field matches and the matching rate, and generates a field matching ratio result; The environment identification submodule calls the access environment identifier and the terminal network source field according to the field matching ratio result, counts the access environment occurrence frequency, calculates the weighted frequency value, obtains the access source group corresponding to the frequency, and generates the main access frequency ratio value; The list generation submodule selects a set of accounts that meet both conditions based on the field matching ratio result and the primary access frequency ratio, calculates the ratio of the set to all records, marks the corresponding identities into the record set, and generates an entry access list; The weighted frequency value calculation formula is specifically: ; in, Representative environmental logo The weighted frequency value of Representative environmental logo The normalization coefficient of the field matching ratio result, Representative environmental logo The original number of occurrences of Represents the terminal network source The adjustment factor, Represents the terminal network source Independent correction term, Represents the total number of terminal network sources.

2. The digital space full-flow encrypted transmission system according to claim 1, characterized in that: The entry access list includes account structure information, source identification, access environment characteristics, terminal network tag, and identity comparison tag; the boundary closed map includes path entry identification, structure hierarchy information, file storage type, integrity classification result, and closed area tag; the file access index table includes path tag number, file availability status, identity mapping number, and access identity list; the access execution list includes access identity tag, path belonging group, permission matching identification, and access control result; the spatial traffic encrypted transmission result includes access path segment, operation time point, file name entry, action sequence item, and source identity information.

3. The digital space full-flow encrypted transmission system according to claim 1, characterized in that: The structural enclosed module comprises: The path extraction submodule obtains the path entry pointed to by the record in the entry access list, performs a level-by-level traversal on each path, extracts all file locations in the path, calculates the number of path structure layers and the distribution within the layer based on the node depth and the number of the same level of the file location, and generates the structure level density; The structure judgment submodule calls the file storage type in the traversal result based on the structure level density value, performs integrity judgment based on the file suffix field, creation method field and access method field, and classifies the records according to whether the key fields are missing in the file, calculates the number of complete files in the classification group, and generates a complete file ratio result; The closed generation submodule determines the path closure degree of the area corresponding to the structural hierarchy distribution and the integrity classification group based on the complete file ratio result and the structural hierarchy density value, selects the path segments that simultaneously meet the closed path depth and the complete file ratio exceeding the set threshold, counts the number of classifications of the path segments and archives them, and generates a boundary closed map.

4. The digital space full-flow encrypted transmission system according to claim 3, characterized in that: The specific calculation formula for the number of complete files in the classification group is: ; in, Represents the number of complete files in the classification group, Represents the validity ratio of the suffix field, Represents the normalized value of the creation method field, Represents the normalized value of the access method field, Represents the creation method weight factor, Represents the completeness score of the current file field. represents the baseline integrity score threshold, represents the dynamic adjustment coefficient, represents the normalization factor.

5. The digital space full-flow encrypted transmission system according to claim 1, characterized in that: The identity binding module includes: The path indexing submodule obtains the file path tag items and the file available status fields extracted from the boundary closed graph, performs a cross-combination extraction operation based on the values of the file path field and the available status field, establishes a mapping record group of paths and statuses, calculates the differentiation index in the record group, and generates a path status combination quantity; The identity number submodule calls the access identity record and path mapping fields according to the path state combination quantity, performs a field cross-comparison between the identity identification field and the path field, selects matching items and sets unique numbers, builds a number list and calculates the number of identities corresponding to the number items to generate the identity number density; Based on the identity number density and the path status combination quantity, the access mapping submodule writes the identity number and the corresponding file status combination into an exclusive record list, filters the combination items in which the identity number and the path status appear at the same time, counts the proportion in the total records, establishes a mapping structure and outputs a record table to generate a file access index table.

6. The digital space full-flow encrypted transmission system according to claim 1, characterized in that: The authority verification module includes: The permission extraction submodule obtains the contents of the identity field and the path field in the file access index table, calls the access level label in the identity field and the access attribution group in the path field, performs number mapping on the identity field value, groups and classifies the path field value, calculates the number of identity levels corresponding to each group of paths, and generates a level attribution distribution; The matching judgment submodule performs a bidirectional matching operation on the identity access level label and the path access attribution group according to the level attribution distribution, marks the matching field pair identity number set, puts the numbers that do not meet the matching conditions into the restriction record pool, counts the number of numbers in the matching set and the restriction set, and generates a permission matching ratio value; The list generation submodule extracts the marked matching identity number set based on the permission matching ratio value and the level attribution distribution, and recombines it with the file path field to establish an identity path comparison list, summarizes the releaseable path records corresponding to each identity number, and generates an access execution list.

7. The digital space full-flow encrypted transmission system according to claim 1, characterized in that: The path trace module includes: The path collection submodule obtains the access path segment marked as released in the access execution list, collects the execution time field and the operation file name field in the path segment, combines and pairs the time field with the path field, counts the number of combined entries and the time coverage, and generates the number of path actions; The sequence generation submodule calls the combination result of the path field and the time field according to the number of path actions, constructs a sequential arrangement structure for each combination entry, marks the time sequence relationship and forms a continuous action chain, counts the number of action chains and the length of the time span, and generates the access action sequence quantity; Based on the access action sequence quantity, the identity marking submodule writes the source identity field corresponding to each access action sequence into the access record circulation pool, performs binding operation on the sequence entry and identity value and marks the unique code, counts the number and distribution ratio of encrypted marking entries in the circulation pool, and generates the spatial traffic encrypted transmission result.

8. A digital space full-flow encrypted transmission method, characterized in that: According to any one of claims 1 to 7, a digital space full-flow encrypted transmission system is implemented, comprising the following steps: S1: Obtain the account structure and source fields, access environment identifier, and terminal network source in the operator identity record, perform field matching on the account structure and source fields, determine the attribution of the access environment identifier and terminal network source, set a mark status for the identity records that are successfully matched and attributable, and generate an entry access list after aggregating the marked identity records; S2: Extracting the path entry pointed to by the record item based on the entry access list, performing traversal extraction on the path entry, obtaining the path structure hierarchy and file location information, performing integrity judgment and classification record operations on the storage type field, screening the closable area paths, marking and summarizing them, and generating a boundary closure map; S3: Extracting file path mark items and file availability status fields based on the boundary closure graph, performing field cross-comparison on access identity records and path mapping fields, extracting cross-items, setting unique identifiers, and creating a numbered list, writing the file status records into the identity mapping list, and generating a file access index table; S4: calling the identity field and the path field in the file access index table, performing a two-way matching operation on the access level label and the access belonging group, setting the matching items to be marked with a release label, and placing the non-matching items into the restriction pool, and generating an access execution list after summarizing the release records; S5: Based on the access execution list, extract the access path segment with the label of release, collect the execution time and operation file name fields in the path segment, combine the time and path fields to form an access action sequence entry, write the entry into the access record flow pool and indicate the source identity, and generate the spatial traffic encrypted transmission result.

Citation Information

Patent Citations

  • Data access control analysis method based on data security law category

    CN114205118A

  • Transaction data analysis system and method based on block chain

    CN118797531A