Data encryption method based on enterprise data security management

By combining attribute-based encryption, zero-trust encryption and AI-driven management, dynamically evaluate enterprise data security, solving the static and rigidity problems of traditional encryption methods, achieving an efficient and adaptive data encryption strategy, and improving the initiative and sustainability of enterprise data security.

CN120389915AActive Publication Date: 2025-07-29JIANGSU ZHONGQI YIRONG DATA TECHNOLOGY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510884585.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-07-29
Estimated Expiration
2045-06-30

AI Technical Summary

Technical Problem

Traditional encryption methods have problems such as access static lag, data fragmentation and rigid key management. The combination of attribute-based encryption (ABE) and zero-trust encryption (ZTA) leads to high computing resource consumption, high deployment complexity and security risks.

Method used

Data subject information is extracted through the system behavior log, attribute-based encryption (ABE) and zero-trust encryption (ZTA), combined with the AI encryption management model, dynamic risk assessment and adaptive key management are realized, deep learning is used to optimize key rotation strategy, integrate device status, user behavior and system environment data, and use hash functions and bilinear group technology to ensure the efficient and reliable encryption process.

Benefits of technology

It realizes fine-grained, dynamic and adaptive data encryption strategies, improves the initiative, adaptability and sustainability of enterprise data security, reduces internal threats and external attack risks, reduces resource waste, and is suitable for large-scale enterprise environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389915A_ABST
    Figure CN120389915A_ABST
Patent Text Reader

Abstract

The invention discloses a data encryption method based on enterprise data security management, which comprises the following five steps of: extracting attribute information and operation information of a data main body by a system behavior log, establishing attribute-based encryption (ABE) of the data main body, creating zero-trust encryption (ZTA) of an access request, establishing a unique matched key pair (SP) and establishing an AI encryption management model. Through triple innovation of attribute-based encryption, zero-trust encryption and AI-driven management, a fine-grained, dynamic and self-adaptive data encryption strategy is realized, the accuracy of the encryption strategy is improved, the problems of static property, rigidity and fragmentation of a traditional encryption method are solved, the initiative, adaptability and sustainability of enterprise data security are remarkably improved, and the security of enterprise data is improved. According to the method, the security is guaranteed, the resource waste is reduced, the self-adaptive key management is realized, the expandability of data security management is improved due to the technical fusion and automation characteristics, and the use compatibility and flexibility are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular to a data encryption method based on enterprise data security management. Background Art

[0002] With the acceleration of enterprise digital transformation, data has become one of the core assets of enterprises, and the importance of data security has become increasingly prominent. Existing data encryption methods have limitations such as static access lag, data fragmentation, and rigid key management.

[0003] Since traditional encryption methods are usually based on fixed permission allocation, they cannot dynamically adapt to changes in the internal and external environment of the enterprise. For example, multi-dimensional data such as device health status, abnormal user behavior, and system environment risks are fragmented, resulting in static and lagging access security policies; and the generation and rotation of keys often rely on manual intervention or fixed-cycle policies, lacking a dynamic trade-off between security gains and performance losses, which can easily lead to resource waste or security vulnerabilities, resulting in rigid key management.

[0004] Existing attribute-based encryption (ABE) can achieve fine-grained attribute-based access control, but lacks dynamic risk assessment capabilities. Zero-trust encryption (ZTA) emphasizes dynamic trust assessment, but the encryption process is disconnected from attribute management. Combining the two leads to high computing resource consumption, high deployment complexity, and security risks. To address these technical shortcomings, a solution is proposed. Summary of the Invention

[0005] The purpose of this invention is to solve the problems of static access lag, data fragmentation and key management rigidity in traditional encryption methods, as well as the problems of large computing resource consumption, high deployment complexity and security risks caused by combining attribute-based encryption (ABE) with zero-trust encryption (ZTA).

[0006] In order to achieve the above object, the present invention adopts the following technical solutions: A data encryption method based on enterprise data security management includes the following steps: Step 1: Extract the attribute information and operation information of the data subject through the system behavior log; Step 2: Build Attribute-Based Encryption (ABE) for the data subject: integrate the attribute information into the attribute set A, build the access policy tree V based on the attribute set A, perform bilinear encryption on the plaintext M and combine it with hash function analysis to preliminarily obtain the master key MK and public key PK; Step 3: Create Zero Trust Encryption (ZTA) for access requests: By preprocessing the operational information, the device health score, user behavior anomaly score, and system environment risk score are obtained. The access decision function is then generated and dynamically updated to obtain the user's private key SK. Step 4: Establish a unique matching key pair SP: Use the user's private key SK to encrypt the public key PK twice to obtain the new public key PKnew. The user's private key SK and the new public key PKnew are combined and marked as the key pair SP; Step 5: Establish an AI encryption management model: Use deep learning to evaluate the security gains and performance losses of data encryption, obtain data key rotation strategies, and thus adaptively drive key pair SP management.

[0007] Furthermore, the specific process of initially obtaining the master key MK and public key PK is as follows: The attribute information is integrated and marked as the attribute set A. The access policy tree V is constructed based on the attribute set A. The leaf nodes of the access policy tree V are attributes, and the non-leaf nodes are thresholds. Only users who meet the access policy tree V can decrypt the data. Obtain the corresponding random number through the quantum random number generator to obtain the master key MK: ,in, is a random number; Set up and label the bilinear group G, which satisfies the bilinear map e: , where G and It is a multiplication cyclic group, and the generator g of the group G is obtained through the GMP library; Encrypt the plaintext M through the bilinear mapping e and the generator g to obtain the plaintext bilinear ciphertext ; Mark the attribute information as the attribute set A, and mark any attribute element of the attribute set A as a; Shared secret via polynomial And combined with the Lagrange interpolation formula to obtain , and then through Combined with the generator g to obtain the first ciphertext Ca of attribute element a 1 ; Obtain the hash value H(a) of attribute element a through the hash function, and combine Comprehensively obtain the second ciphertext Ca of attribute element a 2 ; Bilinear ciphertext , the first ciphertext Ca of attribute element a 1 and the second ciphertext Ca 2 Combined to obtain the public key PK.

[0008] Furthermore, the specific process of preprocessing the operation information is as follows: Operational information includes device status data, user behavior data, and system environment data; Set the information collection cycle Tc to collect the operation information regularly; Mark the number of metrics of the device status data as n1, mark any one of the metrics of the device status data as Di, obtain the normalized standard value norm(Di) of the metric Di, and then comprehensively obtain the device health status score Sd through the normalized standard values of the n1 metrics Di; Mark the number of metrics of the user behavior data as n2, mark any one of the metrics of the user behavior data as Et, obtain the normalized standard value norm(Et) of the metric Et, mark the historical data evaluation value of the metric Et in the long short-term memory network (LSTM) as LSTM(Et), and comprehensively obtain the user behavior anomaly score Se through the difference between the normalized standard values and the historical data evaluation values of the n2 metrics Et; Mark the number of metrics of the system environment data as n3, mark any one of the metrics of the system environment data as Gj, obtain the normalized standard value norm(Gj) of the metric Gj, and then comprehensively obtain the system environment risk score Sg through the normalized standard values of the n3 metrics Gj.

[0009] Furthermore, the specific process of obtaining the user private key SK is as follows: Combine the device health status score Sd, the user behavior anomaly score Se, and the system environment risk score Sg to obtain the comprehensive risk probability Access(t); Set a risk threshold θ for the comprehensive risk probability Access(t) for comparison, and generate an access decision function: if the output comprehensive risk probability Access(t) is lower than the risk threshold θ, then access is allowed; mark the timestamp Tn and the dynamic decay factor of the attribute information collection , and obtain the ciphertext aging factor ; Set the aging threshold r of the ciphertext aging factor for comparison, obtain the updated complete set of attributes and mark it as A(t + 1); Mark any element in the updated complete set of attributes A(t + 1) as , and then obtain the user private key SK through the hash function.

[0010] Furthermore, the specific process of obtaining the new public key PKn is as follows: Perform secondary encryption on the public key PK using the user private key SK, then splice it with the enterprise data plaintext M, and obtain the new public key PKnew through the hash function and in combination with the access decision function; Integrate and mark the user private key SK and the new public key PKnew as the key pair SP: .

[0011] Furthermore, the specific process of evaluating the security gain and performance loss of data encryption is as follows: Monitor and obtain the security parameters and performance parameters of data encryption; Mark the security parameters as the set Qaq, and mark any element of the set Qaq as ; Mark the performance parameters as the set Qxn, and mark any element of the set Qxn as ; Thus, evaluate the security gain and performance loss, and comprehensively obtain the reward function R: ; where is the conversion exponent of the element , is the conversion exponent of the element ; refers to the security gain, refers to the performance loss; and are the proportionality coefficients of the security gain and performance loss respectively.

[0012] Furthermore, the specific process of obtaining the data key rotation strategy is as follows: The data key rotation strategy includes a state space and an action space; Mark the state space as ZTt, and mark any element of the state space ZTt as zt; Mark the action space as DZt: Mark any element of the action space DZt as dz; Obtain the policy value function St(zt, dz) through the state space ZTt and the action space DZt; Iteratively update the policy value function St(zt, dz) through deep learning, so as to perform adaptive drive management for the key; Select the DQN (Deep Q-Network) algorithm, then the data key rotation strategy is: ; where is the learning rate, is the immediate reward, refers to the next state and its action .

[0013] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are: Through the triple innovations of attribute - based encryption (ABE), zero - trust encryption (ZTA), and AI - driven management, the present invention realizes fine - grained, dynamic, and adaptive data encryption strategies, solves the problems of staticity, rigidity, and fragmentation of traditional encryption methods, significantly improves the initiative, adaptability, and sustainability of enterprise data security. Its technology integration and automation features are particularly suitable for high - security - requirement scenarios and enhance the scalability of data security management; The present invention integrates attribute - based encryption (ABE) and zero - trust encryption (ZTA), and based on real - time scoring of three aspects: device status, user behavior, and system environment, dynamically adjusts access permissions through an access decision function to achieve continuous verification, reducing the risks of internal threats and external attacks; The present invention integrates multi - dimensional data such as device status, user behavior, and system environment, generates a comprehensive risk score through normalization processing, and through hash function and bilinear group technology, ensures that attribute information cannot be tampered with and the encryption process is efficient and reliable, enhancing the accuracy of the encryption strategy; The present invention sets a reward function through an AI - driven management model to quantify security gains and performance losses, introduces a ciphertext aging factor and a dynamic attenuation factor, automatically eliminates obsolete attributes or keys, avoids security risks caused by long - term unupdated keys, and dynamically optimizes the key rotation strategy through the DQN algorithm, reducing resource waste while ensuring security, achieving adaptive key management; The present invention automates key generation, rotation, and policy update through AI, reduces manual intervention, is suitable for large - scale enterprise environments, and presets parameters through actual application scenarios to adapt to the security requirements of different enterprises, improving compatibility and flexibility in use. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 Shows a schematic flow diagram of the overall solution of the present invention; Figure 2 Shows a schematic flow diagram of attribute - based encryption (ABE) of the present invention; Figure 3 Shows a schematic flow diagram of zero - trust encryption (ZTA) of the present invention; Figure 4 Shows a schematic flow diagram of the AI encryption management model of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0014] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention. Embodiment

[0015] AsFigures 1-4 As shown in Figures 1-4 , a data encryption method based on enterprise data security management includes the following steps: S1. Extract the attribute information and operation information of the data subject through the system behavior log; the attribute information includes user name, department, role, and level; The operation information includes device status data, user behavior data, and system environment data; set the information collection period Tc to collect the operation information regularly; The device status data includes the number of system patches, the proportion of abnormal access processes, and the proportion of GPS geographical anomalies, etc.; The user behavior data includes the number of decryption failure attempts, the frequency of accessing sensitive files, and the keyboard typing delay time; The system environment data includes the network threat alarm frequency, the proportion of non-enterprise network connection ports, and the proportion of third-party component vulnerabilities.

[0016] S2. Build the attribute-based encryption (ABE) of the data subject: Integrate and mark the attribute information as the attribute universe A, build the access policy tree V through the attribute universe A, perform bilinear encryption processing on the plaintext M and combine it with the hash function analysis to initially obtain the master key MK and the public key PK; S2-1. Integrate and mark the attribute information as the attribute universe A, build the access policy tree V through the attribute universe A. The leaf nodes of the access policy tree V are attributes, and the non-leaf nodes are threshold gates. Only users who meet the access policy tree V can decrypt the data; S2-2. Obtain the corresponding random numbers through the quantum random number generator; obtain the master key MK: , where is a random number; S2-3. Set and mark the bilinear group G, satisfying the bilinear mapping e: , where G and are multiplicative cyclic groups; Obtain the generator g of the group G through the GMP library (GNU Multiple - Precision Arithmetic Library). For example: Select the large prime number p of the group G, select the integer g in the interval [2, p - 1], and verify that for all positive integers i less than p - 1, there is , then g is the generator of G; Encrypt the plaintext M to obtain the plaintext bilinear ciphertext : , where is the bilinear mapping, is a random number; S2-4. Perform hash processing on the attribute information. The specific process is as follows: Mark the attribute universe A: , for any attribute element a, perform transformation to obtain the first ciphertext Ca of the attribute element a 1 and the second ciphertext Ca 2 ; , , where g is the generator of the group G is a polynomial shared secret, obtained through the Lagrange interpolation formula , H is a hash function, and H(a) is the hash value of the attribute element a; S2-5, through the plaintext bilinear ciphertext , the first ciphertext Ca of the attribute element a 1 and the second ciphertext Ca 2 are combined to obtain the public key PK: . S3, create zero-trust encryption (ZTA) for the access request: By preprocessing the running information, obtain the device health status score, user behavior anomaly score, and system environment risk score, and then generate and dynamically update the access decision function to obtain the user private key SK; S3-1, the specific process of preprocessing the running information is: S3-101, mark the number of metrics of the device status data as n1, mark any metric of the device status data as Di, and obtain the normalized standard value norm(Di) of the metric Di: ; where and are respectively the minimum and maximum values of the metric Di in the historical data; By assigning the corresponding anomaly weight factor to the metric Di, the device health status score Sd is comprehensively obtained: ; S3-102, mark the number of metrics of the user behavior data as n2, mark any metric of the user behavior data as Et, and obtain the normalized standard value norm(Et) of the metric Et: ; where and are respectively the mean and standard deviation of the metric Et; mark the historical data evaluation value of the metric Et in the long short-term memory network (LSTM) as LSTM(Et): ; where is a preset conversion constant, aiming to combine the mean and standard deviation of the metric Et to convert it into the historical data evaluation value of the metric Et; By assigning the corresponding anomaly weight factor to the metric Et, the user behavior anomaly score Se is comprehensively obtained: ; S3-103, mark the number of indicators of the system environment data as n3, mark any indicator of the system environment data as Gj, and obtain the normalized standard value norm(Gj) of the indicator Gj: ; By assigning the corresponding abnormal weight factor to the indicator Gj , thereby comprehensively obtaining the system environment risk score Sg: ;in, It is the maximum value of indicator Gj in historical data.

[0017] S3-2, the specific process of obtaining the user's private key SK is as follows: S3-201, obtains the access decision function by combining the device health status score Sd, the user behavior anomaly score Se, and the system environment risk score Sg: ; in, 、 、 are the weight coefficients of the device health status score Sd, the user behavior abnormality score Se, and the system environment risk score Sg, respectively, and 、 、 The preset values of are all greater than 0. The weight coefficient is obtained by calculating a large amount of experimental data and needs to be set in combination with the actual application situation. Access (t) is the comprehensive risk probability, θ is the risk threshold, and the Sigmoid function is: ; If the output comprehensive risk probability Access(t) is lower than the risk threshold θ, access is allowed; otherwise, access is denied; S3-202, mark the timestamp Tn and dynamic attenuation factor of attribute information collection , get the ciphertext aging factor : , where e is a natural constant, λ is the decay rate, λ is a constant parameter obtained by preset, and t is the encryption duration, which refers to the time interval from the start of the encryption operation to the current timestamp Tn; S3-203, and then obtain the dynamic attribute update strategy: The complete set of attributes marked as updated is A(t+1): ; Among them, r is the aging threshold, when the attenuation factor of attribute element a When it is lower than the aging threshold r, the attribute element is removed; For the new attribute element; Mark any element in the updated attribute set A(t+1) as , and then obtain the user's private key SK through the hash function: .

[0018] S4. Establish a uniquely matched key pair SP: Double-encrypt the public key PK with the user's private key SK to obtain a new public key PKnew, and integrate and label the user's private key SK and the new public key PKnew as the key pair SP; Double-encrypt the public key PK with the user's private key SK, then splice it with the enterprise data plaintext M, and obtain the new public key PKnew by taking the modulus of q through a hash function in combination with an access decision function: ; Integrate and label the user's private key SK and the new public key PKnew as the key pair SP: .

[0019] S5. Establish an AI encryption management model: Evaluate the security gain and performance loss of data encryption through deep learning to obtain a data key rotation strategy, so as to perform adaptive drive management on the key pair SP; S5-1. The specific process of evaluating the security gain and performance loss of data encryption is as follows: During the enterprise data security management process, monitor the security parameters and performance parameters of data encryption; The security parameters include the reduction in threat events, the number of key attacks cracked, and the number of security vulnerabilities fixed; Among them, count the number of occurrences of security threat events such as key leakage and illegal access before and after the implementation of the key management strategy. If the number of events decreases significantly, it indicates a high security gain; adopt penetration testing to compare the time and resources required for an attacker to successfully crack the key under a dynamic strategy. The longer the time and the greater the resource consumption, the greater the security gain; check the change in the number and severity of relevant security vulnerabilities fixed during the key management process. When high-risk vulnerabilities are fixed and the total number of vulnerabilities decreases, it means that the system security is enhanced and the security gain is obvious; Label the security parameters as the set Qaq: , label any element of the set Qaq as ; The performance parameters include system response time, resource occupancy rate, and business throughput; among them, by measuring the change in the system response time when performing key-related operations (such as key generation, rotation, etc.), the more the response time extends, the greater the performance loss; by monitoring the occupancy of system resources such as CPU and memory during the execution of key management tasks, if the resource occupancy rate rises significantly, it indicates performance loss; by comparing the processing volume or throughput of the business before and after the adjustment of the key management strategy, if the business processing ability decreases, it indicates performance loss; Label the performance parameters as the set Qxn: , label any element of the set Qxn as ; Thus, obtain the reward function R: ; Among them, is the element The conversion index is for the element The conversion index; refers to the security gain refers to the performance loss; and are the proportionality coefficients of the security gain and the performance loss respectively; the conversion index and the proportionality coefficient are preset according to the actual application situation.

[0020] S5-2. The specific process of obtaining the data key rotation policy is as follows: The data key rotation policy includes a state space and an action space; the state space is marked as ZTt: ; The action space is marked as DZt: ; Among them, the state space includes access frequency, sensitivity level, and risk score; the action space includes immediately rotating the key, delaying the key expiration, and keeping the key unchanged; Obtain the policy value function St(zt, dz) through the state space ZTt and the action space DZt; Iteratively update the policy value function St(zt, dz) through deep learning, so as to perform adaptive drive management for the key; For example, if the DQN (Deep Q-Network) algorithm is selected, the data key rotation policy is: ; among them, is the learning rate, is the immediate reward, refers to the next state and its action , the purpose is to make constantly approach , so as to obtain the optimal action, realize the self-growth optimization of key drive, and finally realize the data encryption method for enterprise data security management that integrates dynamic keys and access control.

[0021] The application effect of the present invention is as follows: The present invention integrates attribute-based encryption (ABE) and zero-trust encryption (ZTA), and based on the real-time scoring of the three aspects of device status, user behavior, and system environment, dynamically adjusts access permissions through the access decision function to achieve continuous verification and reduce the risks of internal threats and external attacks; The present invention integrates multi-dimensional data such as device status, user behavior, and system environment, generates a comprehensive risk score through normalization processing, and through the hash function and bilinear group technology, ensures that the attribute information cannot be tampered with and the encryption process is efficient and reliable, improving the accuracy of the encryption policy; The present invention quantifies security gains and performance losses by AI-driven management to set the number of reward letters, introduces a ciphertext aging factor and a dynamic decay factor, automatically eliminates obsolete attributes or keys, and avoids security risks caused by long-term unupdated keys. The key rotation strategy is dynamically optimized through the DQN algorithm to reduce resource waste while ensuring security, achieving adaptive key management; The present invention automates the processing of key generation, rotation, and policy update through an AI model, reduces manual intervention, is suitable for large-scale enterprise environments, and presets parameters through actual application scenarios to adapt to the security requirements of different enterprises, improving compatibility and flexibility in use; In summary, through the triple innovation of dynamic attribute-based encryption, zero-trust real-time decision-making, and AI-driven management, this solution realizes a fine-grained, dynamic, and adaptive data encryption strategy, solves the problems of staticity, rigidity, and fragmentation of traditional encryption methods, significantly improves the initiative, adaptability, and sustainability of enterprise data security, and its technology integration and automation characteristics are particularly suitable for high-security requirement scenarios, enhancing the scalability of data security management.

[0022] The setting of the size of the interval and the threshold is for the convenience of comparison. Regarding the size of the threshold, it depends on the amount of sample data and the number of base numbers set by those skilled in the art for each group of sample data; as long as the proportional relationship between the parameters and the quantified values is not affected.

[0023] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation; The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A data encryption method based on enterprise data security management, characterized in that: It includes the following steps: Step 1, extract the attribute information and running information of the data subject through the system behavior log; Step 2, construct the attribute-based encryption (ABE) of the data subject: integrate and label the attribute information as the complete attribute set A, construct the access policy tree V through the complete attribute set A, perform bilinear encryption processing on the plaintext M and combine with the hash function analysis to initially obtain the master key MK and the public key PK; Step 3, create the zero-trust encryption (ZTA) of the access request: preprocess the running information to obtain the device health status score, user behavior anomaly score, and system environment risk score, then generate the access decision function and update it dynamically to obtain the user private key SK; Step 4, establish a uniquely matched key pair SP: perform secondary encryption on the public key PK with the user private key SK to obtain the new public key PKnew, and integrate and label the user private key SK and the new public key PKnew as the key pair SP; Step 5, establish an AI encryption management model: evaluate the security gain and performance loss of data encryption through deep learning to obtain the data key rotation strategy, so as to perform adaptive drive management on the key pair SP.

2. The data encryption method based on enterprise data security management according to claim 1, wherein: The specific process of initially obtaining the master key MK and the public key PK is as follows: Integrate and label the attribute information as the complete attribute set A, construct the access policy tree V through the complete attribute set A. The leaf nodes of the access policy tree V are attributes, and the non-leaf nodes are threshold gates. Only users who meet the access policy tree V can decrypt the data; Obtain the corresponding random number through a quantum random number generator and obtain the master key MK: , where is a random number; Set and label a bilinear group \(G\) that satisfies the bilinear mapping \(e\): , where \(G\) and are multiplicative cyclic groups, and obtain the generator \(g\) of the group \(G\) through the GMP library; Encrypt the plaintext M using the bilinear mapping e and the generator g to obtain the plaintext bilinear ciphertext ; Label the attribute information as the complete attribute set A, and label any attribute element of the complete attribute set A as a; Share secrets through polynomials and obtain them by combining with the Lagrange interpolation formula , and then through synthesize with the generator g to obtain the first ciphertext Ca of the attribute element a 1 ; Obtain the hash value H(a) of the attribute element a through a hash function, and combine it with Comprehensively obtain the second ciphertext Ca of the attribute element a 2 ; Through plaintext and bilinear ciphertext , the first ciphertext Ca of attribute element a 1 and the second ciphertext Ca 2 are combined to obtain the public key PK.

3. A data encryption method based on enterprise data security management according to claim 2, characterized in that: The specific process of preprocessing the running information is as follows: The running information includes device status data, user behavior data, and system environment data; Set the information collection period Tc to collect the running information regularly; Label the number of indicators of the device status data as n1, label any one indicator of the device status data as Di, obtain the normalized standard value norm(Di) of the indicator Di, and then comprehensively obtain the device health status score Sd through the normalized standard values of the n1 indicators Di; Label the number of indicators of the user behavior data as n2, label any one indicator of the user behavior data as Et, obtain the normalized standard value norm(Et) of the indicator Et, label the historical data evaluation value of the indicator Et in the long short-term memory network (LSTM) as LSTM(Et), and comprehensively obtain the user behavior anomaly score Se through the difference between the normalized standard values of the n2 indicators Et and the historical data evaluation values; Label the number of indicators of the system environment data as n3, label any one indicator of the system environment data as Gj, obtain the normalized standard value norm(Gj) of the indicator Gj, and then comprehensively obtain the system environment risk score Sg through the normalized standard values of the n3 indicators Gj.

4. A data encryption method based on enterprise data security management according to claim 3, characterized in that: The specific process of obtaining the user private key SK is as follows: Combine the device health status score Sd, the user behavior anomaly score Se, and the system environment risk score Sg to obtain the comprehensive risk probability Access(t); Set the risk threshold θ of the comprehensive risk probability Access(t) for comparison to generate an access decision function: If the output comprehensive risk probability Access(t) is lower than the risk threshold θ, access is permitted; Timestamp Tn for collecting tag attribute information and dynamic attenuation factor , obtain ciphertext aging factor ; Set the ciphertext aging factor Compare with the aging threshold r, obtain the updated complete set of attributes and mark it as A(t + 1); Mark any element in the updated complete set of attributes A(t + 1) as , and then obtain the user's private key SK through the hash function.

5. A data encryption method based on enterprise data security management according to claim 4, characterized in that: The specific process for obtaining the new public key PKn is as follows: The public key PK is encrypted twice using the user's private key SK, then concatenated with the enterprise data plaintext M, and the new public key PKnew is obtained through a hash function in combination with the access decision function; Integrate the user's private key SK and the new public key PKnew and mark them as the key pair SP: .

6. A data encryption method based on enterprise data security management according to claim 5, characterized in that: The specific process for evaluating the security gain and performance loss of data encryption is as follows: Monitor and obtain the security parameters and performance parameters of data encryption; Mark the security parameters as set Qaq, and mark any element of set Qaq as ; Mark the performance parameters as the set Qxn, and mark any element of the set Qxn as ; Thus, the safety gain and performance loss are evaluated, and the reward function R is comprehensively obtained: ; Among them, is the conversion index of element , is the conversion index of element ; refers to the safety gain, refers to the performance loss; and are the proportionality coefficients of the safety gain and the performance loss respectively.

7. A data encryption method based on enterprise data security management according to claim 6, characterized in that: The specific process for obtaining the data key rotation strategy is as follows: The data key rotation strategy includes a state space and an action space; Mark the state space as ZTt, and mark any element of the state space ZTt as zt; Mark the action space as DZt: Mark any element of the action space DZt as dz; Obtain the policy value function St(zt, dz) through the state space ZTt and the action space DZt; Iteratively update the policy value function St(zt, dz) through deep learning to perform adaptive drive management for the key; If the DQN (Deep Q-Network) algorithm is selected, the data key rotation strategy is: ; Among them, is the learning rate, is the immediate reward, refers to the next state and its action .

Citation Information

Patent Citations

  • Client secure deduplication method of ciphertext data in cloud storage

    CN105939191A

  • anti-quantum rapid authentication and data transmission method for mass NB-IoT equipment

    CN109756877A

  • Time-controlled fine-grained traceability method for large-scale supply chain data

    CN119272313A

  • Power data privacy security protection system, method and application based on ciphertext policy attribute-based encryption

    CN119892452A

  • Data encryption transmission method based on zero-trust architecture

    CN119966746A