Intelligent data security transmission method driven by dynamic coding table
Through the intelligent data security transmission method driven by dynamic encoding table, the problem of insufficient adaptability and security of the network environment in the prior art is solved, and efficient and secure data transmission in complex network environments is achieved, and compatibility and fast response capabilities are adapted to different network domains.
Patent Information
- Application Number
- CN202510628754.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-22
AI Technical Summary
Existing data transmission encryption technology cannot dynamically adapt to changes in the network environment, cannot respond quickly to sudden attacks, and there is a single point of failure risk and data leakage risks in complex and changing network environments.
The intelligent data security transmission method driven by dynamic encoding table is adopted. By generating a key combination containing a variable public key and a dynamic private key, combining multi-layer dynamic encoding table and dual dynamic encoding factor verification, the dynamic switching of fast encoding mode, deep encoding mode and emergency encoding mode is achieved, and real-time monitoring and abnormal fuse protection mechanism are combined to ensure the security of data transmission.
It realizes dynamic adjustment of encryption strategies in complex network environments, improves the security and integrity of data transmission, reduces the risk of data leakage, adapts to compatibility of different network domains, and improves transmission efficiency and stability.
Smart Images

Figure CN120358024A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transmission and encryption technologies, and particularly to an intelligent data security transmission method driven by a dynamic coding table. Background Art
[0002] In the digital age, secure data transmission has become a crucial link in ensuring the stable operation of information systems and user privacy. Currently, data transmission encryption technologies mainly adopt static encryption algorithms and fixed key mechanisms, such as the SSL / TLS protocol, the AES symmetric encryption algorithm, etc. Such traditional technologies have many limitations in practical applications: firstly, once the static key is stolen or cracked, the security of the entire data transmission link will be completely lost, and attackers can easily obtain the transmitted data; secondly, in the face of dynamic changes in the network environment, such as network topology adjustment, transmission traffic fluctuations, new network attacks, etc., traditional encryption technologies cannot dynamically adjust the encryption intensity and strategy according to the real-time environment, and it is difficult to meet the complex and changeable security requirements; thirdly, the single encryption algorithm and fixed key management mode make there is a risk of single point of failure in the data transmission process. Once a problem occurs in a certain link of the encryption mechanism, it will lead to global data leakage.
[0003] To overcome the defects of traditional static encryption technologies, researchers have carried out research on dynamic encryption technologies. Some existing solutions adopt a key update mechanism based on timestamps or an adaptive encryption algorithm, which improves the security of data transmission to a certain extent. However, these solutions still have obvious deficiencies: firstly, their dynamic adjustment mechanism depends on preset rules and lacks the ability to deeply perceive key information such as network topology and node load status, and it is difficult to accurately adapt to different network environments; secondly, in the face of emergency events such as sudden network attacks and abnormal transmission paths, existing dynamic encryption technologies cannot quickly respond and switch to an effective encryption strategy, resulting in the security of data transmission not being guaranteed in a timely manner; in addition, the update process of traditional dynamic coding tables is usually relatively complex and is prone to large time delays, and it cannot meet the requirements of real-time data transmission scenarios such as video conferencing and online games.
[0004] With the rapid development of emerging fields such as 5G communication technology and the Internet of Things, the network environment has become increasingly complex. In the scenario of multi-device interconnection, the data transmission path involves multiple intermediate nodes, and the risk of data being intercepted and tampered with during transmission increases significantly; for resource-constrained low-power devices, frequent updates of complex encryption algorithms will consume excessive device computing resources and power, affecting the normal operation of the devices; the differences in encryption standards and security protocols between different network domains also bring compatibility problems to cross-domain data transmission, further exacerbating the challenges of secure data transmission. Therefore, there is an urgent need for a data security transmission method that can dynamically adapt to changes in the network environment and has an efficient abnormal response ability. Summary of the Invention
[0005] In view of the above problems, the present invention provides a dynamic coding table-driven intelligent data security transmission method and system.
[0006] The object of the present invention is achieved by the following technical solutions:
[0007] In a first aspect, a dynamic coding table-driven intelligent data security transmission method is provided, including the following steps:
[0008] S1. When establishing an initial session between communication nodes, generate a key combination including a variable public key and a dynamic private key, where the number of dynamic private keys forms a mapping relationship with the number of participating nodes in the current session path, and synchronously generate a first dynamic coding factor when generating each key combination, and generate a second dynamic coding factor when generating the dynamic private key corresponding to each variable public key;
[0009] S2. Generate coding reference parameters according to the dynamic verification relationship between the variable public key and the dynamic private key, and construct a multi-layer dynamic coding table in combination with the first dynamic coding factor and the second dynamic coding factor. The dynamic coding table includes a rolling update mechanism based on a time stamp and a mutation update mechanism triggered by an event;
[0010] S3. Receive the dynamic coding table and perform unit encapsulation on the transmitted data. Write a dynamic path identification code at the head of the data unit to generate a unit check value. The dynamic path identification code is generated by chaotic calculation of the network topology sequence of the communication node, the hash feature value of the first dynamic coding factor, and the entropy feature value of the second dynamic coding factor, and embed the unit check value into the check section of the dynamic coding table;
[0011] S4. During the transmission process of the data unit, dynamically select the coding table application mode according to the network environment state, including:
[0012] Enable the fast coding mode in the low-latency requirement scenario, and perform streaming encryption using a simplified version of the dynamic coding table;
[0013] Enable the deep coding mode in the high-security requirement scenario, and perform block recombination encryption using the complete version of the dynamic coding table;
[0014] Enable the emergency coding mode in the abnormal transmission scenario, and trigger the mutation update mechanism of the dynamic coding table to generate a temporary encryption policy;
[0015] S5. Real-time monitor the application status of the coding table in the transmission path, and ensure the transmission security through the following mechanisms:
[0016] Verify the initial state of the coding table according to the network feature parameters at the moment when the first dynamic coding factor is generated;
[0017] Compare the matching degree between the second dynamic coding factor and the topological entropy value of the current transmission path;
[0018] Request the receiving node to return the reverse coding verification result based on the unit check value;
[0019] S6. Continuously execute the following abnormal fuse protection measures during data transmission:
[0020] During homologous path transmission, if no version update trace of the dynamic coding table is detected in three consecutive data units, trigger a path reset instruction;
[0021] During cross-domain transmission, if the unit check value feedback from the receiving end cannot pass the reverse parsing of the dynamic coding table, start the transmission channel switching;
[0022] When the number of coding table verification failure events exceeding the threshold is detected within a unit time, automatically destroy the current dynamic coding table and rebuild the security session.
[0023] As a preferred method, constructing the dynamic coding table further includes the following steps:
[0024] Store the basic coding rule set, and use a cyclic coverage strategy to store a preset number of coding rules with the highest usage frequency within a preset time window;
[0025] Store the dynamic confusion parameters, including multiple groups of confusion coefficient matrices matching the current network topology, and update the weight values according to the node connection status at preset time intervals;
[0026] Store the emergency mutation templates, pre-store multiple encryption templates and automatically load them when the detected transmission error rate exceeds the threshold;
[0027] Among them, a two-way data channel is established between the three-level caches, allowing cross-level data calls according to the transmission quality indicators.
[0028] As a preferred method, when performing unitized encapsulation, it specifically includes the following steps:
[0029] Intercept the network identifiers of the first 3-hop nodes in the current transmission path, and generate a 16-bit initial entropy value through non-linear transformation;
[0030] Decompose the first dynamic coding factor into 4 8-bit segments, and perform exclusive OR recombination with the second dynamic coding factor;
[0031] Use an improved Logistic mapping to perform 7 rounds of iteration on the fused data, and introduce the lower 8 bits of the current timestamp as a perturbation parameter in each round of iteration;
[0032] Finally, generate a 32-bit dynamic path identification code, where the first 16 bits are used for header verification and the last 16 bits are used as the load encryption key.
[0033] As a preferred method, when performing deep encoding, the following steps are specifically included:
[0034] Recombine the base block with a data unit of 64 bytes to be transmitted across blocks according to the specified arrangement rule in the dynamic encoding table. First, use AES-128 to perform block encryption on the recombined base block, then use the elliptic curve encryption algorithm to encapsulate the block key, and append a 4-byte cyclic redundancy check code to the tail of each base block. This check code also includes the hash feature value of the previous base block.
[0035] As a preferred method, the step S3 further includes the following steps:
[0036] Record the set of environmental parameters when each first dynamic encoding factor is generated. The set of environmental parameters includes the system clock value accurate to milliseconds at the generation moment, the CRC32 check value of the current network interface, and the normalized value of the system memory occupancy rate;
[0037] Compare the deviation degree between the set of environmental parameters and the current environmental parameters, and calculate the environmental similarity index;
[0038] When the environmental similarity index is lower than the preset threshold, trigger the forced update of the dynamic encoding table.
[0039] As a preferred method, when implementing the abnormal fuse protection mechanism,
[0040] When any abnormal response occurs, check its occurrence times;
[0041] When a single encoding verification fails, discard the current data unit and request retransmission
[0042] After N consecutive verification failures within a unit time, close the current transmission channel and enable the standby route. After K consecutive verification failures within a unit time, destroy all dynamic encoding factors in the current session, where K > N.
[0043] As a preferred method, before performing the step S3, the following steps are further included:
[0044] Monitor the computing load status of each node in the transmission path. When the CPU utilization rate of the node exceeds 60%, automatically degrade to the fast encoding mode;
[0045] Statistical historical transmission delay data. When the path delay fluctuation coefficient exceeds 0.3, enable the preloading mechanism of the emergency encoding mode;
[0046] Establish a coding table version compatibility buffer to allow adjacent two generations of dynamic coding tables to run in parallel during a 15-second transition period.
[0047] A second aspect of the present invention provides an intelligent data security transmission system driven by a dynamic coding table, comprising:
[0048] A dynamic factor generator, used to generate dynamic coding factors with spatiotemporal correlation, which includes a seed generation unit based on hardware fingerprint, a network topology perception unit, and an event-triggered factor mutation module;
[0049] An intelligent coding table distributor, connected to the dynamic factor generator, having a built-in expandable memory and a dynamic load balancing module, and configured to distribute the coding table in real time according to the transmission path quality indicator;
[0050] The transmission path controller integrates a multi-mode encoding selector and a dynamic address encapsulator, forms a closed-loop control with the intelligent encoding table distributor through a path entropy value monitor, and realizes intelligent encapsulation of data units and optimization of transmission paths;
[0051] The real-time verification gateway includes a programmable verification pipeline and a fuse mechanism executor, which is connected to the dynamic factor generator through a dual-factor verification channel and cooperates with the transmission path controller to perform dynamic verification feedback and abnormal fuse operations.
[0052] The beneficial effects of the present invention are:
[0053] Multi-mode dynamic encryption: Through the three modes of fast encoding, deep encoding and emergency encoding, the encryption strategy can be dynamically adjusted according to the network environment. In low-latency scenarios, the fast encoding mode is enabled, and a simplified version of the dynamic encoding table is used for streaming encryption, which can not only ensure the security of data transmission, but also meet real-time requirements; in high-security scenarios, the deep encoding mode is enabled, and the full version of the dynamic encoding table is used to reorganize and encrypt the data in blocks, and combined with AES-128 and elliptic curve encryption algorithms, the data encryption strength is significantly improved; in abnormal transmission scenarios, the emergency encoding mode is enabled, triggering the mutation update mechanism of the dynamic encoding table, quickly generating a temporary encryption strategy, and effectively responding to sudden security threats.
[0054] Dynamic update of coding table: The dynamic coding table adopts a timestamp-based rolling update mechanism and an event-triggered mutation update mechanism. It can perceive changes in the network environment in real time, such as network topology adjustment, abnormal traffic, etc., and update the coding rules and encryption strategies in time to ensure that the encryption scheme is always adapted to the network environment and effectively resist new network attacks.
[0055] Dual Dynamic Coding Factor Verification: Through the dual verification mechanism of the first dynamic coding factor and the second dynamic coding factor, combined with the network feature parameters at the generation moment and the topological entropy value of the transmission path, the coding table is verified comprehensively. At the same time, it is required that the receiving node returns the reverse coding verification result based on the unit check value, greatly improving the integrity and reliability of data transmission and effectively preventing data from being tampered with or stolen.
[0056] Multi-layer Security Protection: From key generation, data encapsulation to dynamic verification during the transmission process, and then to abnormal fusing protection measures, a multi-level security protection system is constructed. For example, the generation of dynamic path identification codes integrates various elements such as network topology information and dynamic coding factor eigenvalue, making it difficult for attackers to crack; when the security threat is detected, the abnormal fusing protection mechanism can quickly take measures such as path reset, channel switching, and destruction of the coding table to block the attack and ensure data security.
[0057] Adaptive Resource Scheduling: By monitoring the node computing load status and transmission delay data, the system can automatically adjust the coding mode. For example, when the node CPU utilization rate exceeds 60%, it automatically degrades to the fast coding mode to avoid node overload; when the path delay fluctuation coefficient exceeds 0.3, the preloading mechanism of the emergency coding mode is enabled to optimize resource allocation in advance, improving the transmission efficiency while ensuring data security.
[0058] Cross-domain Compatibility and Version Transition: A coding table version compatibility buffer is established, allowing adjacent generations of dynamic coding tables to run in parallel within a 15-second transition period to ensure the stability of data transmission during the coding table update process; at the same time, the system design fully considers the characteristics of different network domains and can effectively adapt to cross-domain transmission scenarios, improving the versatility and compatibility of the system.
[0059] By real-time monitoring of the application status of the coding table and the integrity of the transmitted data, the system can accurately identify various abnormal situations. For different types of abnormalities such as single coding verification failure, multiple verification failures within a unit time, and no coding table update for the same-source path, hierarchical processing measures such as data retransmission, channel switching, and session destruction are taken respectively, realizing a quick response and effective disposal of abnormal events and reducing the risks of data leakage and transmission interruption. Brief Description of the Drawings
[0060] The present invention is further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to the following drawings without creative efforts.
[0061] Figure 1 It is the structural block diagram of the system of the embodiment of the present invention. Detailed Embodiment
[0062] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0063] In the first aspect of the embodiments of the present disclosure, there is provided an intelligent data security transmission system driven by a dynamic coding table, as Figure 1 shown, which includes a dynamic factor generator, an intelligent coding table distributor, a transmission path controller, and a real-time verification gateway. The specific implementation manners of each component are as follows:
[0064] The dynamic factor generator is used to generate dynamic coding factors with spatio-temporal correlation, and it includes a seed generation unit based on hardware fingerprint, a network topology awareness unit, and an event-triggered factor mutation module.
[0065] The seed generation unit based on hardware fingerprint generates an initial seed value by reading the unique identifier of the device's trusted platform module (TPM chip). This unique identifier has device uniqueness and provides a stable and unique basis for the subsequent generation of dynamic coding factors. The network topology awareness unit uses an active probing protocol, such as an improved Traceroute protocol, to actively send probing data packets to the network and obtain the media access control (MAC) addresses, Internet protocol (IP) addresses, and port information of at least the first three-hop network nodes according to the returned response information, so as to perceive the network topology structure. The event-triggered factor mutation module monitors the network state in real time. When events such as a change in the network topology, the appearance of abnormal traffic, or the arrival of a preset time window are detected, it triggers the mutation operation of the dynamic coding factors to adapt to the dynamic changes of the network environment.
[0066] The intelligent coding table distributor is connected to the dynamic factor generator and is built with an extensible memory and a dynamic load balancing module. The extensible memory adopts a three-level cache structure to store the basic coding rule set, the dynamic obfuscation parameter set, and the emergency mutation template set respectively. Among them, the basic coding rule set adopts the Least Recently Used (LRU) cache policy to store a preset number of coding rules with the highest usage frequency within a preset time window, ensuring that commonly used rules can be quickly called; the dynamic obfuscation parameter set contains multiple groups of obfuscation coefficient matrices that match the current network topology. Within a preset time interval, the weight values of each element in the matrix are updated according to the node connection status to enhance the data obfuscation effect; the emergency mutation template set pre-stores multiple encryption templates. When it is detected that the transmission error rate exceeds the threshold, the corresponding template is automatically loaded to implement emergency encryption processing. The dynamic load balancing module dynamically adjusts the coding table distribution strategy according to indicators such as the Central Processing Unit (CPU) utilization rate and bandwidth occupancy rate of each communication node, and efficiently distributes the coding table to the appropriate nodes to ensure the overall performance of the system.
[0067] The transmission path controller integrates a multi-mode coding selector and a dynamic address encapsulator, and forms a closed-loop control with the intelligent coding table distributor through a path entropy value monitor. The multi-mode coding selector obtains network status indicators such as latency, jitter, and error rate in real time, and dynamically selects a fast coding mode, a deep coding mode, or an emergency coding mode according to different network environment states. The dynamic address encapsulator is responsible for unitizing and encapsulating data units and generating dynamic path identification codes. The path entropy value monitor calculates the topological entropy value of the transmission path in real time. This entropy value reflects the complexity and security of the path and is used to verify the coding table to ensure the adaptability of the coding table to the transmission path and realize the intelligent encapsulation of data units and the optimization of the transmission path.
[0068] The real-time verification gateway includes a programmable verification pipeline and a fuse mechanism executor, and is connected to the dynamic factor generator through a dual-factor verification channel to jointly execute dynamic verification feedback and abnormal fuse operations with the transmission path controller. The programmable verification pipeline is implemented using a Xilinx UltraScale+ Field Programmable Gate Array (FPGA) and has powerful parallel processing capabilities, capable of supporting more than 10,000 coding table verification operations per second to quickly and accurately verify the validity of the coding table. The fuse mechanism executor performs fuse operations such as data discarding, retransmission requests, and channel switching according to the verification results to ensure data transmission security. The dual-factor verification channel simultaneously verifies the validity of the first dynamic coding factor and the second dynamic coding factor to ensure the reliability of the dynamic coding factor during data transmission.
[0069] The second aspect of the embodiments of the present disclosure provides an intelligent data security transmission method driven by a dynamic coding table, including the following steps:
[0070] Step S1: Key combination and dynamic coding factor generation
[0071] When establishing an initial session between communication nodes, the dynamic factor generator performs key combination and dynamic coding factor generation operations. Based on the Elliptic Curve Cryptography (ECC) algorithm, a key combination including a variable public key and a dynamic private key is generated. Specifically, according to the number of participating nodes in the current session path, a corresponding number of dynamic private keys are generated. Each dynamic private key is a byte sequence of a specific length, such as 32 bytes, generated by a secure random number generation algorithm. At the same time, according to the public-private key generation rule of the elliptic curve algorithm, a corresponding variable public key is generated for each dynamic private key. When generating each key combination, a first dynamic coding factor is generated synchronously. This factor is generated by hashing the initial seed value generated by the seed generation unit based on the hardware fingerprint, combined with the current network timestamp and partial network node information obtained by the network topology awareness unit. When generating the dynamic private key corresponding to each variable public key, a second dynamic coding factor is generated, which is generated by processing the dynamic private key, the variable public key, and a randomly generated salt value through a symmetric encryption algorithm.
[0072] Step S2: Construct a multi-layer dynamic coding table
[0073] According to the dynamic verification relationship based on elliptic curve cryptography between the variable public key and the dynamic private key, coding reference parameters are calculated and generated. The coding reference parameters are combined with the first dynamic coding factor and the second dynamic coding factor to construct a multi-layer dynamic coding table. The dynamic coding table includes a rolling update mechanism based on the time stamp and a mutation update mechanism triggered by events. The rolling update mechanism performs partial updates on the coding table every preset time interval, such as every 10 minutes, according to the newly generated dynamic coding factor and the current network state. The mutation update mechanism is immediately triggered when abnormal events such as network attacks and major topology changes are detected, and a full update of the coding table is performed. At the same time, the expandable memory of the intelligent coding table distributor stores and manages the basic coding rule set, the dynamic confusion parameter set, and the emergency mutation template set required for constructing the dynamic coding table according to the aforementioned three-level cache structure and storage strategy. A two-way data channel is established between the three-level caches, and cross-level data calls are made according to transmission quality indicators such as bandwidth and latency to ensure the construction and update of the dynamic coding table.
[0074] Step S3: Data unit encapsulation and dynamic path identification code generation
[0075] After receiving the dynamic coding table, the dynamic address encapsulator of the transmission path controller performs unitized encapsulation on the transmitted data. The specific operations are as follows: First, intercept the network identifiers of the first 3-hop nodes in the current transmission path, including MAC addresses, IP addresses, etc., and generate a 16-bit initial entropy value through the MurmurHash3 non-linear transformation algorithm; then, decompose the first dynamic coding factor into 4 8-bit segments and perform exclusive OR recombination with the second dynamic coding factor; then, use an improved Logistic mapping to perform 7 rounds of iteration on the fused data, and introduce the lower 8 bits of the current timestamp as a perturbation parameter in each round of iteration; finally, generate a 32-bit dynamic path identification code, where the first 16 bits are used for data unit header verification and the last 16 bits are used as payload encryption keys. At the same time, record the set of environmental parameters when each first dynamic coding factor is generated, and this set includes the system clock value accurate to milliseconds, the CRC32 check value of the current network interface, and the normalized value of the system memory occupancy rate. Compare the deviation degree between the set of environmental parameters and the current environmental parameters, calculate the environmental similarity index, and when the environmental similarity index is lower than the preset threshold, trigger the forced update of the dynamic coding table. After writing the dynamic path identification code into the data unit header, generate a unit check value and embed the unit check value into the check section of the dynamic coding table.
[0076] Step S4: Dynamically select the coding table application mode
[0077] During the data unit transmission process, the multi-mode coding selector of the transmission path controller dynamically selects the coding table application mode according to the network environment status. In scenarios with low latency requirements, such as real-time video stream transmission, enable the fast coding mode, adopt a simplified version of the dynamic coding table, perform Advanced Encryption Standard-128 (AES-128) streaming encryption on the data, reduce the encryption processing time while ensuring a certain level of security, and reduce the transmission latency; in scenarios with high security requirements, such as financial transaction data transmission, enable the deep coding mode, adopt the complete version of the dynamic coding table, divide the transmitted data into 64-byte base blocks, perform cross-block recombination according to the specified arrangement rules in the dynamic coding table, first use AES-128 to perform block encryption on the recombined base blocks, and then use the Elliptic Curve Integrated Encryption Scheme (ECIES) to encapsulate the block keys, and append a 4-byte CRC-32 cyclic redundancy check code at the end of each base block, and this check code also includes the SHA-256 hash feature value of the previous base block to ensure the high security of the data; in abnormal transmission scenarios, such as detecting network attacks or high bit error rates, enable the emergency coding mode, trigger the mutation update mechanism of the dynamic coding table to generate a temporary encryption policy to ensure the security of data transmission.
[0078] Step S5: Monitor the application status of the coding table and ensure security
[0079] The real-time verification gateway monitors the application status of the coding table in the transmission path in real time through multiple mechanisms to ensure transmission security. According to the network characteristic parameters at the moment when the first dynamic coding factor is generated, such as the network topology structure, node load, etc., verify whether the initial state of the coding table is normal; compare the matching degree between the second dynamic coding factor and the topological entropy value of the current transmission path to judge the adaptability of the coding table to the transmission path; require the receiving node to return the reverse coding verification result based on the unit check value to further verify the effectiveness and integrity of the coding table during data transmission.
[0080] Step S6: Execute abnormal fusing protection measures
[0081] During data transmission, the real-time verification gateway continuously executes abnormal fusing protection measures. During homologous path transmission, if no version update trace of the dynamic coding table is detected for three consecutive data units, it indicates that there may be an abnormality in the transmission path, triggering a path reset instruction to re-plan the transmission path; during cross-domain transmission, if the unit check value feedback by the receiving end cannot pass the reverse parsing of the dynamic coding table, it means that there may be an error or an attack in data transmission, and the transmission channel is switched to ensure the continuity and security of data transmission; when more than the threshold number of coding table verification failure events are detected within a unit time, the current dynamic coding table is automatically destroyed and a secure session is re-established to prevent data leakage and the spread of attacks. Specifically, when any abnormal response occurs, check the number of occurrences. When a single coding verification failure is detected, discard the current data unit and request retransmission; after N consecutive verification failures within a unit time, close the current transmission channel and enable the backup route; when K consecutive verification failures occur within a unit time, where K > N, destroy all dynamic coding factors in the current session. Through a hierarchical processing mechanism, different degrees of abnormal situations can be effectively dealt with.
[0082] In addition, before executing step S3, the system also performs an adaptive coding mode pre-adjustment operation. Monitor the computing load status of each node in the transmission path. When the CPU utilization rate of the node exceeds 60%, in order to avoid affecting the transmission efficiency due to node overload, automatically downgrade to the fast coding mode; count the historical transmission delay data. When the path delay fluctuation coefficient exceeds 0.3, enable the preloading mechanism of the emergency coding mode and prepare the emergency encryption strategy in advance; establish a coding table version compatibility buffer zone to allow two adjacent generations of dynamic coding tables to run in parallel within a 15-second transition period to ensure the stability of data transmission during the coding table update process.
[0083] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure, enabling those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, process, and other changes. Embodiments only represent possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the terms used in this application are only for describing embodiments and do not limit the claims. As used in the description of embodiments and claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to also include the plural forms. Similarly, as used in this application, the term "and / or" refers to any and all possible combinations of one or more of the associated listed items. Additionally, when used in this application, the term "comprise" and its variants "comprises" and / or "comprising" etc. mean the presence of the stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups of these. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, or apparatus comprising the element. Herein, each embodiment may focus on the differences from other embodiments, and the same or similar parts among the embodiments may be referred to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method parts disclosed in the embodiments, the relevant parts may refer to the description of the method parts.
[0084] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner may depend on the specific application and design constraints of the technical solution. The skilled person may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present disclosure. The skilled person can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0085] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functions, and operations of possible implementations of apparatuses, methods, and computer program products according to embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in an order different from that disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. Each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based device that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A dynamic coding table-driven intelligent data security transmission method, characterized in that It includes the following steps: S1. When establishing an initial session between communication nodes, generate a key combination including a variable public key and a dynamic private key, where the number of dynamic private keys forms a mapping relationship with the number of participating nodes in the current session path. When generating each key combination, synchronously generate a first dynamic coding factor, and generate a second dynamic coding factor when generating the dynamic private key corresponding to each variable public key; S2. Generate coding reference parameters according to the dynamic verification relationship between the variable public key and the dynamic private key, and construct a multi-layer dynamic coding table in combination with the first dynamic coding factor and the second dynamic coding factor. The dynamic coding table includes a rolling update mechanism based on timestamps and a mutation update mechanism triggered by events; S3. Receive the dynamic coding table and perform unit encapsulation on the transmitted data. Write a dynamic path identification code at the head of the data unit to generate a unit check value. The dynamic path identification code is generated by chaotic calculation of the network topology sequence of the communication node, the hash feature value of the first dynamic coding factor, and the entropy feature value of the second dynamic coding factor, and embed the unit check value into the check section of the dynamic coding table; S4. During the transmission process of the data unit, dynamically select the coding table application mode according to the network environment status, including: Enable the fast coding mode in the scenario with low latency requirements, and perform stream encryption using a simplified version of the dynamic coding table; Enable the deep coding mode in the scenario with high security requirements, and perform block recombination encryption using the complete version of the dynamic coding table; Enable the emergency coding mode in the abnormal transmission scenario, and trigger the mutation update mechanism of the dynamic coding table to generate a temporary encryption policy; S5. Real-time monitor the application status of the coding table in the transmission path, and ensure transmission security through the following mechanisms: Verify the initial state of the coding table according to the network feature parameters at the moment when the first dynamic coding factor is generated; Compare the matching degree between the second dynamic coding factor and the topological entropy value of the current transmission path; Require the receiving node to return the reverse coding verification result based on the unit check value; S6. Continuously execute the following abnormal fuse protection measures during the data transmission process: During the transmission of the same-source path, if no version update trace of the dynamic coding table is detected in three consecutive data units, trigger a path reset instruction; During cross-domain transmission, if the unit check value fed back by the receiving end cannot pass the reverse parsing of the dynamic coding table, initiate a transmission channel switch; When more than the threshold number of coding table verification failure events are detected within a unit time, automatically destroy the current dynamic coding table and reconstruct a secure session.
2. The method for intelligent data secure transmission driven by a dynamic coding table according to claim 1, wherein Constructing the dynamic coding table further includes the following steps: Store the basic coding rule set, and store the preset number of coding rules with the highest usage frequency within the preset time window using a cyclic overwrite strategy; Store the dynamic confusion parameters, including multiple groups of confusion coefficient matrices matching the current network topology, and update the weight values according to the node connection status at preset time intervals; Store the emergency mutation templates, pre-store multiple encryption templates and automatically load them when the detected transmission error rate exceeds the threshold; Among them, a two-way data channel is established between the three-level caches, allowing cross-level data calls according to the transmission quality indicators.
3. The dynamic coding table-driven intelligent data security transmission method according to claim 1, wherein When performing unit encapsulation, it specifically includes the following steps: Intercept the network identifiers of the first 3-hop nodes in the current transmission path and generate a 16-bit initial entropy value through non-linear transformation; Decompose the first dynamic coding factor into 4 8-bit segments and perform XOR recombination with the second dynamic coding factor; Use an improved Logistic mapping to perform 7 rounds of iteration on the fused data, and introduce the lower 8 bits of the current timestamp as a perturbation parameter in each round of iteration; Finally, generate a 32-bit dynamic path identification code, where the first 16 bits are used for header verification and the last 16 bits are used as the payload encryption key.
4. The method for dynamically encoding table-driven intelligent data secure transmission according to claim 1, characterized in that, When performing deep coding, it specifically includes the following steps: Take a 64-byte base block of the transmitted data unit and perform cross-block recombination according to the arrangement rules specified in the dynamic coding table. First, use AES-128 to perform block encryption on the recombined base block, then use the elliptic curve encryption algorithm to encapsulate the block key, and append a 4-byte cyclic redundancy check code to the end of each base block. This check code also includes the hash feature value of the previous base block.
5. The method for dynamically encoding table-driven intelligent data secure transmission according to claim 1, wherein The step S3 further includes the following steps: Record the set of environmental parameters when each first dynamic coding factor is generated. The set of environmental parameters includes the system clock value accurate to milliseconds at the generation time, the CRC32 check value of the current network interface, and the normalized value of the system memory occupancy rate; Compare the deviation degree between the set of environmental parameters and the current environmental parameters, and calculate the environmental similarity index; When the environmental similarity index is lower than the preset threshold, trigger the forced update of the dynamic coding table.
6. The method for dynamically encoding table-driven intelligent data secure transmission according to claim 1, wherein When executing the abnormal fuse protection mechanism, When any abnormal response occurs, check the number of its occurrences; When a single coding verification fails, discard the current data unit and request retransmission After N consecutive verification failures per unit time, close the current transmission channel and enable the standby route. After K consecutive verification failures per unit time, destroy all dynamic coding factors in the current session, where K > N.
7. The method for dynamically encoding table-driven intelligent data secure transmission according to claim 1, characterized in that Before executing the step S3, it further includes the following steps: Monitor the computing load status of each node in the transmission path, and automatically degrade to the fast coding mode when the node CPU utilization rate exceeds 60%; Statistical historical transmission delay data, and enable the preloading mechanism of the emergency coding mode when the path delay fluctuation coefficient exceeds 0.3; Establish a coding table version compatibility buffer to allow adjacent generations of dynamic coding tables to run in parallel within a 15-second transition period.
8. A dynamic coding table-driven intelligent data security transmission method system, for the method according to any one of claims 1-7, characterized in that, It includes: A dynamic factor generator for generating dynamic coding factors with spatio-temporal correlation, which includes a seed generation unit based on hardware fingerprints, a network topology awareness unit, and an event-triggered factor mutation module; An intelligent coding table distributor, connected to the dynamic factor generator, with an expandable memory and a dynamic load balancing module built-in, and is configured to distribute the coding table in real time according to the transmission path quality index; A transmission path controller, integrating a multi-mode coding selector and a dynamic address encapsulator, forming a closed-loop control with the intelligent coding table distributor through a path entropy value monitor, and realizing intelligent encapsulation of data units and optimization of the transmission path; The real-time verification gateway includes a programmable verification pipeline and a fuse mechanism executor, which is connected to the dynamic factor generator through a dual-factor verification channel and cooperates with the transmission path controller to perform dynamic verification feedback and abnormal fuse operations.
Citation Information
Cited By
Multi-algorithm dynamic encryption paperless conference file protection method
CN120602088A
Multi-algorithm dynamic encryption paperless conference file protection method
CN121547169A