Government information security management method based on hierarchical encryption
Through hierarchical encryption and dynamic permission management, combined with multi-round encryption and DNA encoding and decoding rules, the problems of resource waste and permission abuse in traditional government document encryption methods are solved, and efficient and secure management of government documents is achieved.
Patent Information
- Application Number
- CN202510898324.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-01
AI Technical Summary
Traditional government document encryption methods lack the ability to manage document content in a refined manner, resulting in waste of resources and insufficient security. In addition, the authority management model is static, which easily leads to authority abuse.
A hierarchical encryption-based method is adopted to provide differentiated protection for each component according to the confidentiality level of government documents. Combined with multi-round encryption and DNA encoding and decoding rules, user permissions are dynamically managed to ensure a high level of protection for sensitive information, and unauthorized access is prevented through credibility assessment.
It achieves differentiated protection for each component of the file, improves overall security, reduces the possibility of cracking, prevents abuse of authority, and is suitable for highly secure government document scenarios.
Smart Images

Figure CN120415725B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information encryption technology, and more specifically, to a government information security management method based on hierarchical encryption. Background Art
[0002] Since government documents involve sensitive information such as national security, social stability and citizens' privacy, their security and confidentiality management is particularly important and is an important issue in modern information-based governments.
[0003] With the deepening of digital transformation, the storage, transmission and access of government documents are increasingly dependent on computer network systems, which exposes documents to more security threats such as unauthorized access, data leakage and tampering.
[0004] Traditional encryption methods usually treat the entire file as a whole for encryption, without distinguishing the sensitivity of different components in the file; this "one-size-fits-all" encryption method will lead to a waste of resources, because low-sensitivity parts are also subjected to high-intensity encryption, increasing computing overhead and storage costs; at the same time, for highly sensitive parts, single encryption may not be sufficient to resist increasingly sophisticated attack methods, thereby reducing the overall security of the system.
[0005] In addition, traditional permission allocation mechanisms are usually static and are set based on the user's fixed role or identity, while ignoring the user's real-time credibility and dynamic behavior characteristics. This fixed permission management model is prone to permission abuse and lacks a security assessment mechanism for user requests, which may lead to malicious users obtaining sensitive information by forging identities or other means.
[0006] In summary, traditional security management methods mainly rely on single encryption technology or fixed permission control strategies, lack the ability to manage file content in a refined manner, and also have deficiencies in user permission management, making it difficult to meet the needs of modern government documents for multi-level and differentiated protection. Summary of the Invention
[0007] In order to solve the technical problems that the above-mentioned traditional security management methods lack the ability to manage the content of files in a refined manner and are also insufficient in user authority management, the present invention provides a government information security management method based on hierarchical encryption, including: , determine the confidentiality level of each component in the government document, the confidentiality level of each component is not greater than the confidentiality level of the government document; perform text encoding on each component, and encrypt the text encoding result of each component: according to the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The encryption result of the round is Round encryption, obtain each component in the first The encryption result of the round; From 1 to ; Each component is in The encryption results of the rounds constitute the encryption results of the government documents; the decryption level is determined according to the user's identity level and credibility and the confidentiality level of the government documents. , decrypt the encrypted results of government documents according to the decryption level and the level keys of each confidentiality level: based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The decryption result of the round is Round of decryption, get each component in the first The decryption result of the round, from Get 1; combine the decryption results of each component in the first round to form the decryption result of the government document.
[0008] The present invention realizes differentiated protection of various components of the file, ensuring that sensitive information receives a higher level of protection, while non-sensitive information adopts a lower-intensity encryption strategy. This refined management method can effectively respond to the security needs of information with different levels of sensitivity and improve overall security; secondly, the present invention increases the randomness and complexity of the encryption algorithm through the application of multiple rounds of encryption and DNA encoding and decoding rules, significantly reducing the possibility of being cracked; in addition, the step-by-step encryption process makes it impossible for the attacker to restore the entire file content even if a certain round of encryption is broken. This multi-level protection mechanism greatly improves the security of the system and is particularly suitable for government document scenarios that require high security; at the same time, the present invention can dynamically manage and limit the user's access scope by calculating the user's authority level and decryptability level, preventing the occurrence of authority abuse or illegal access, and providing comprehensive technical support for the security management of government documents.
[0009] Preferably, the components of the government document include document issuance information, titles at all levels, main text and attachments; the document issuance information includes document title, document number, issuer, signature and date of the issuing authority, copy unit, printing and issuing authority and printing and issuing date; any government document contains at least document issuance information and main text.
[0010] Preferably, the method of determining the confidentiality level of each component of a government document according to the confidentiality level of the government document includes: for any government document, recording the confidentiality level of the government document as the confidentiality level , record the level of the title in the government document as ;in, , and confidentiality level 1 is the lowest confidentiality level, confidentiality level The highest level of confidentiality. Equal to the preset value; set the confidentiality level of the published information to the confidentiality level ,and , Indicates rounding down. Indicates taking the maximum value; sets the confidentiality level of the text and attachments to the confidentiality level ; then The confidentiality level of the title is set to confidentiality level ,and , Indicates rounding up.
[0011] The present invention follows the principles of integrity and differentiation, and sets the confidentiality level of each component according to the confidentiality level of government documents, which not only ensures that the security of each component in the document is consistent with the confidentiality level of the overall document, but also realizes refined security management.
[0012] Preferably, the hierarchical key is constructed based on the initial conditions of a two-dimensional chaotic mapping function, the initial conditions of the two-dimensional chaotic mapping function include two initial values and four parameters, and the hierarchical keys of different confidentiality levels are different.
[0013] Preferably, the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence include: according to the confidentiality level The initial values and parameters in the level key of the two-dimensional chaotic mapping function are iterated multiple times, and the number of iterations is not less than , Equal to the sum of the lengths of the text encoding results of all components, each iteration obtains a chaotic value pair; multiply the two chaotic values in each chaotic value pair by And round up, and record the rounded results as the first rule number and the second rule number respectively; Equal to the number of all DNA encoding and decoding rules; all first rule numbers are combined into a confidentiality level The coding rule sequence of all second rule numbers is composed of confidentiality levels The decoding rule sequence.
[0014] Preferably, the obtaining of each component is carried out in the The encryption results of the round include: When the text encoding results of the components with a confidentiality level of not less than 1 are concatenated into the first round of encryption objects, When the confidentiality level is not less than The components of The encryption results of the first round are concatenated into Encrypted objects of rounds; according to confidentiality level The rule number in the encoding rule sequence is determined to determine the corresponding DNA encoding and decoding rule, and the The encrypted object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the decoding rule sequence is used to determine the corresponding DNA encoding and decoding rule, and The encoding results of the round are decoded by DNA to obtain the components in the first The encryption result of the round.
[0015] The present invention combines DNA encoding and decoding rules to perform multiple rounds of encryption, which can achieve secure management and efficient protection of government documents. It not only improves the security of the encryption algorithm, but also realizes refined management of information of different sensitivity levels.
[0016] Preferably, the method also includes: when a user requests access, obtaining the user's credibility based on the content requested by the user and setting a threshold; when the user's credibility is greater than the preset threshold, the user is allowed to access the requested content; when the user's credibility is less than or equal to the preset threshold, the user is not allowed to access the requested content; when the user is allowed to access the requested content, determining the decryptability level based on the user's identity level and credibility and the confidentiality level of the government document; and decrypting the encryption result of the government document based on the decryptability level and the level keys of each confidentiality level.
[0017] The present invention ensures that only trusted users can enter the subsequent permission determination process through credibility assessment, thereby effectively preventing malicious attacks or illegal access.
[0018] Preferably, the method of determining the decryptability level based on the user's identity level and credibility and the confidentiality level of government documents includes: determining the user's authority level based on the user's identity level and credibility, and determining the decryptability level based on the user's authority level and the confidentiality level of government documents, wherein the decryptability level is a lower level of the user's authority level and the confidentiality level of government documents.
[0019] The present invention uses a permission management mechanism based on user level and credibility, and dynamically determines the decryption level in combination with the confidentiality level of government documents, so as to achieve secure management and efficient access control of government documents and ensure that information is strictly protected during the access process.
[0020] Preferably, determining the user's authority level based on the user's identity level and credibility includes: Where, is the user's permission level, For user credibility, is the preset threshold, is the user's identity level, Indicates taking the minimum value, Indicates rounding up.
[0021] Preferably, the obtaining of each component is carried out in the The decryption results of the round include: When the encryption result of the government documents is encrypted, the confidentiality level shall be no less than The encrypted results of the components are concatenated into The decryption object of the round; when When the confidentiality level is not less than The components of The decryption results of the first round are concatenated into Decryption object of the round; according to the confidentiality level The rule number in the decoding rule sequence is used to determine the corresponding DNA encoding and decoding rule, and The decryption object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the encoding rule sequence is determined to determine the corresponding DNA encoding and decoding rule, and the The encoding results of the round are decoded by DNA to obtain the components in the first The decryption result of the round.
[0022] The beneficial effects of the present invention are:
[0023] The present invention realizes differentiated protection of various components of the file, ensuring that sensitive information receives a higher level of protection, while non-sensitive information adopts a lower-intensity encryption strategy. This refined management method can effectively respond to the security needs of information with different levels of sensitivity and improve overall security; secondly, the present invention increases the randomness and complexity of the encryption algorithm through the application of multiple rounds of encryption and DNA encoding and decoding rules, significantly reducing the possibility of being cracked; in addition, the step-by-step encryption process makes it impossible for the attacker to restore the entire file content even if a certain round of encryption is broken. This multi-level protection mechanism greatly improves the security of the system and is particularly suitable for government document scenarios that require high security; at the same time, the present invention can dynamically manage and limit the user's access scope by calculating the user's authority level and decryptability level, preventing the occurrence of authority abuse or illegal access, and providing comprehensive technical support for the security management of government documents. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 is a flow chart schematically illustrating a method for managing government information security based on hierarchical encryption in the present invention;
[0025] Figure 2 It is a schematic diagram showing the Flowchart of round encryption;
[0026] Figure 3 is a schematic diagram schematically illustrating all DNA encoding and decoding rules that conform to the Watson-Crick complementarity rule in traditional DNA coding;
[0027] Figure 4 This is a schematic diagram schematically illustrating the eight DNA encoding and decoding rules in Hachimoji DNA encoding that conform to the Watson-Crick complementarity rule. DETAILED DESCRIPTION
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.
[0029] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0030] The embodiment of the present invention discloses a government information security management method based on hierarchical encryption, referring to Figure 1 , including steps S1 to S5:
[0031] S1. Determine the confidentiality level of each component in government documents based on the confidentiality level of government documents.
[0032] It should be noted that, based on the confidentiality level of government documents, the overall principle and the differentiation principle are followed when setting the confidentiality level of each component. The overall principle means that the confidentiality level of each component of a government document is not greater than the confidentiality level of the government document. This principle ensures that the security of each component in the document is consistent with the confidentiality level of the overall document; the differentiation principle means that since there are significant differences in the depth, breadth and sensitivity of the information displayed by the issuing information, titles at all levels, text and attachments, different confidentiality levels need to be set for each component to achieve refined security management.
[0033] Specifically, the text format of government documents usually needs to follow certain specifications and standards to ensure the formality, authority and readability of the documents. Therefore, government documents can be divided into several components, namely, document issuance information, titles at all levels, main text and attachments; and any government document contains at least document issuance information and main text.
[0034] Among them, the document issuance information includes the document title, document number, issuer, signature and date of the issuing authority, copy units, printing and issuing authority and printing and issuing date; the document title is the core theme of the government document, which is used to summarize the content of the entire document; the document number is the unique identifier of the document, which is used for archiving and retrieval; the issuer refers to the person in charge who approves the issuance of the document; the signature and date of the issuing authority indicate the source and issuance time of the document; the copy units refer to units that need to know the content of the document but do not need to directly execute it; the printing and issuing authority and printing and issuing date originally indicate the printing and issuing unit and printing time of the document.
[0035] Among them, the titles at each level are subdivisions of the contents of each part under the document title, which are used to organize and divide paragraphs. The first-level title uses numbers such as "one," "two," and the font is No. 3 bold or Song bold. The second-level title uses numbers such as "(one)" and "(two)". The third-level title uses numbers such as "1." and "2.". The fourth-level title uses numbers such as "(1)" and "(2)".
[0036] The main text is the core part of the government document, which elaborates on the specific content of the document; the appendix is supplementary material or specific implementation plan related to the main text.
[0037] Further, set Confidentiality level 1 is the lowest level, The highest level of confidentiality. It is equal to the preset number. The specific value of the preset number can be set according to the actual application scenario and requirements and is an integer. The present invention sets the preset number to 6.
[0038] It should be noted that since there are differences in the depth, breadth and sensitivity of information displayed by document information, titles at all levels, main text and attachments, different confidentiality levels need to be set for each component to ensure the overall security and confidentiality of the document; among the various components of government documents: document information displays the lowest depth, breadth and sensitivity of information, therefore, the confidentiality level of document information is the lowest; the main text and attachments display the highest depth, breadth and sensitivity of information, therefore, the confidentiality level of the main text and attachments is the highest; the depth, breadth and sensitivity of information displayed by titles at all levels are between the document information and the main text and attachments, therefore, the confidentiality level of titles at all levels is not less than the confidentiality level of document information and not greater than the confidentiality level of the main text and attachments, and increases with the number of titles.
[0039] Furthermore, for any government document, set the confidentiality level of the government document and record it as the confidentiality level , ;Record the number of levels of titles in government documents as According to the confidentiality level of government documents, the confidentiality level of each component in the government document is determined, and the confidentiality level of each component shall not be greater than the confidentiality level of the government document. In other words, the highest confidentiality level of each component in the government document is equal to the confidentiality level of the government document. The specific setting methods include:
[0040] (1) Set the confidentiality level of the published information to the confidentiality level ,and , Indicates rounding down. Indicates taking the maximum value.
[0041] (2) Set the confidentiality level of the text and attachments to the confidentiality level .
[0042] (3) The confidentiality level of the title is set to confidentiality level ,and , Indicates rounding up.
[0043] It should be noted that the confidentiality level to confidentiality level Confidentiality Level , confidentiality level ,…, confidentiality level , confidentiality level ,common The number of confidentiality levels in government documents is , in addition to the post information and text, so it contains component.
[0044] It should be further explained that the present invention divides government documents into differentiated confidentiality levels based on the depth, breadth and sensitivity of the information displayed by each component of the document, which is a scientific and effective security management strategy; by clarifying the confidentiality levels of the issued information, titles at all levels, text and attachments, and combining multi-level encryption technology, the security, flexibility and resource utilization efficiency of government documents can be greatly improved, and at the same time, a reasonable access control mechanism can be provided for users with different permissions.
[0045] S2. Constructing the level keys of each confidentiality level according to the initial conditions of the two-dimensional chaotic mapping function.
[0046] It should be noted that chaotic mapping functions have been widely used in the field of cryptography due to their unique mathematical properties and behaviors, especially in the design of key generators.
[0047] The two-dimensional chaotic mapping function includes but is not limited to the two-dimensional Logistic chaotic mapping function, the two-dimensional Henon mapping chaotic algorithm, the Lotka-Volterra model, etc. The two-dimensional Logistic chaotic mapping function, the two-dimensional Henon mapping chaotic algorithm, and the Lotka-Volterra model are all well-known technologies and will not be described in detail here.
[0048] In this embodiment, the two-dimensional Logistic chaotic mapping function is taken as an example to construct the level key of each confidentiality level; in other embodiments, the level key of each confidentiality level can be constructed according to other two-dimensional chaotic mapping functions.
[0049] For the two-dimensional Logistic chaotic mapping function, whether it can enter the chaotic state and obtain the chaotic value depends on the initial value and parameters; when both initial values are Within the range, and the four parameters are 、 、 and When the two-dimensional Logistic chaotic mapping function is within the range, it enters a chaotic state and generates chaotic values between [0,1].
[0050] Specifically, according to the two-dimensional chaotic mapping function, the process of constructing the key is: in the range of two initial values And the value ranges of the four parameters 、 、 and Randomly generate two initial values and And four parameters 、 、 、 , the two initial values and And four parameters 、 、 、 Make up a key .
[0051] Furthermore, for each confidentiality level, a level key of each confidentiality level is constructed according to a two-dimensional chaotic mapping function, and different level keys of different confidentiality levels are required to be different.
[0052] S3. Perform text encoding on each component to obtain a text encoding result of each component.
[0053] Specifically, text encoding is performed on each component to obtain a text encoding result of each component, and the text encoding result is in a binary form consisting of 0 and 1.
[0054] Among them, the text encoding methods include UTF-8 encoding, GB2312 encoding, GBK encoding, UTF-16 encoding, etc. UTF-8 encoding, GB2312 encoding, GBK encoding, and UTF-16 encoding are all well-known technologies and will not be repeated here.
[0055] S4. Encrypt the text encoding results of each component in the government document according to the confidentiality level of each component and the level key of each confidentiality level to obtain the encryption result of the government document.
[0056] It should be noted that by converting the text content of each component into binary form, the corresponding encoding rule sequence and decoding rule sequence are generated according to the level key of the confidentiality level, and the confidentiality level is not less than Components of Based on the round encryption results, apply the confidentiality level The coding rule sequence and decoding rule sequence are first Round encryption; repeat this process until it is complete Round encryption.
[0057] Specifically, when encrypting the text encoding results of each component, a total of Round encryption, and according to the first round encryption to the The encryption is performed in the order of rounds; finally, each component is encrypted in the first The encryption results of the rounds constitute the encryption results of the government documents.
[0058] therefore, From 1 to , is the confidentiality level of government documents, then The process of round encryption is: according to the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The encryption result of the round is Round encryption, obtain each component in the first The encryption result of the round.
[0059] It should be noted that through multiple rounds of encryption and DNA encoding and decoding rules, the complexity of the encryption algorithm is significantly improved and the possibility of cracking is reduced; the corresponding encryption strength is selected according to the confidentiality level of different components to meet diverse needs.
[0060] No. Refer to the flowchart of round encryption Figure 2 , including steps S401 to S402, specifically:
[0061] S401, according to the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence.
[0062] Specifically, according to the confidentiality level The initial values and parameters in the level key of the two-dimensional chaotic mapping function are iterated multiple times, and the number of iterations is not less than , It is equal to the sum of the lengths of the text encoding results of all components. Each iteration obtains a chaotic value pair, and each chaotic value pair consists of two chaotic values, which are recorded as the first chaotic value and the second chaotic value respectively.
[0063] Furthermore, the two chaotic values in each chaotic value pair are multiplied by And round up, and record the rounded results as the first rule number and the second rule number respectively; Equal to the number of all DNA encoding and decoding rules; all first rule numbers are combined into a confidentiality level The coding rule sequence of all second rule numbers is composed of confidentiality levels The decoding rule sequence.
[0064] DNA encoding is the process of encoding binary numbers into corresponding bases, and DNA decoding is the process of decoding bases into corresponding binary numbers.
[0065] In one embodiment, DNA encoding refers to traditional DNA encoding. Traditional DNA encoding is based on four bases: A, T, G, and C. There are only eight DNA encoding and decoding rules that conform to the Watson-Crick complementarity rule. The schematic diagrams of these eight DNA encoding and decoding rules are as follows: Figure 3 As shown; In one embodiment, the DNA encoding refers to the Hachimoji DNA encoding. The Hachimoji DNA encoding is based on eight bases: A, T, G, C, B, S, P, and Z. There are as many as 384 DNA encoding and decoding rules that conform to the Watson-Crick complementarity rule, of which 8 DNA encoding and decoding rules are shown in the schematic diagram. Figure 4 shown.
[0066] S402, based on confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The encryption result of the round is Round encryption, obtain each component in the first The encryption result of the round.
[0067] Specifically, when When the component The encryption result of the first round refers to the text encoding result of the components. Therefore, the text encoding results of the components with a confidentiality level of not less than 1 are concatenated as the encryption object of the first round. When the confidentiality level is not less than The components of The encryption results of the first round are concatenated into The encryption object of the round.
[0068] Furthermore, according to the confidentiality level The rule number in the encoding rule sequence is determined by the corresponding DNA encoding and decoding rule, and the first The encrypted object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the decoding rule sequence is determined by the corresponding DNA encoding and decoding rule, and the first The encoding results of the round are decoded by DNA to obtain the components in the first The encryption result of the round; among them, DNA encoding is to encode binary numbers into corresponding bases, and DNA decoding is to decode the bases into corresponding binary numbers.
[0069] It should be noted that for confidentiality levels less than Components of The encryption result of the first round is used as The encryption result of the round.
[0070] For example, That is, during the first round of encryption, based on the encoding rule sequence {3,1,7,4,5,2,8,4} and the decoding rule sequence {5,2,5,3,1,6,7,7} of confidentiality level 1, Figure 3 The eight DNA encoding and decoding rules shown in the figure, the process of performing the first round of encryption on the text encoding result "1101001010111011" is:
[0071] (1) According to confidentiality level The rule numbers in the encoding rule sequence {3,1,7,4,5,2,8,4} determine the corresponding DNA encoding and decoding rules, which are Figure 3 Rule 3, Rule 1, Rule 7, Rule 4, Rule 5, Rule 2, Rule 8, and Rule 4 in the schematic diagram shown.
[0072] (2) Take the text encoding result "1101001010111011" as the encryption object of the first round, and perform DNA encoding on the encryption object of the first round according to the corresponding DNA encoding and decoding rules, that is, according to Figure 3 Rules 3, Rule 1, Rule 7, Rule 4, Rule 5, Rule 2, Rule 8, and Rule 4 in the schematic diagram are used to DNA encode 11, 01, 00, 10, 10, 11, 10, and 11 in the encryption object of the first round. The encoding results are C, G, T, T, A, T, G, and G respectively. The encoding result of the first round is "CGTTATGG".
[0073] (3) According to confidentiality level The rule numbers in the decoding rule sequence {5,2,5,3,1,6,7,7} determine the corresponding DNA encoding and decoding rules, which are Figure 3 Rule 5, Rule 2, Rule 5, Rule 3, Rule 1, Rule 6, Rule 7, Rule 7 in the diagram shown.
[0074] (4) DNA decoding is performed on the encoding results of the first round according to the corresponding DNA encoding and decoding rules, that is, according to Figure 3 Rule 5, Rule 2, Rule 5, Rule 3, Rule 1, Rule 6, Rule 7, and Rule 7 in the schematic diagram shown perform DNA decoding on C, G, T, T, A, T, G, and G in the encoding result of the first round, and the decoding results obtained are 11, 10, 01, 10, 00, 01, 01, and 01, respectively. The encryption result of the first round is "1110011000010101".
[0075] It should be noted that through multiple rounds of encryption, each round introduces new complexity, making it difficult for an attacker to restore the entire file content even if they crack a certain round of encryption, thereby improving encryption security.
[0076] S5. Determine the decryption level based on the user's identity level and credibility and the confidentiality level of the government document, and decrypt the encrypted result of the government document based on the decryption level and the level keys of each confidentiality level.
[0077] Specifically, when a user requests access, the user's credibility is obtained based on the content requested by the user, and a threshold is set. When the user's credibility is greater than the preset threshold, it means that the user's request is safe. At this time, the user is allowed to access the requested content. When the user's credibility is less than or equal to the preset threshold, it means that the user's request is unsafe. At this time, the user is not allowed to access the requested content.
[0078] The method for obtaining the user's credibility is to classify the historical records of access to content and determine the user's credibility based on the access conditions of similar users to the accessed content.
[0079] The preset threshold is set by the implementer according to the actual implementation situation. For example, the preset threshold can be set to 0.7.
[0080] It should be noted that this process ensures that only trusted users can enter the subsequent permission determination process through credibility assessment, thereby effectively preventing malicious attacks or illegal access.
[0081] Furthermore, when the user is allowed to access the requested content, the decryption level is determined based on the user's identity level and credibility and the confidentiality level of the government document; the encrypted result of the government document is decrypted based on the decryption level and the level keys of each confidentiality level.
[0082] Among them, the decryption level is determined according to the user's identity level and credibility and the confidentiality level of government documents, including: determining the user's authority level according to the user's identity level and credibility, and determining the decryption level according to the user's authority level and the confidentiality level of government documents. The decryption level is the lower level of the user's authority level and the confidentiality level of government documents.
[0083] 1. Determine the user's authority level based on the user's identity level and credibility. The calculation formula for the user's authority level is:
[0084] ;
[0085] Where, is the user's permission level, For user credibility, is the preset threshold, is the user's identity level, Indicates taking the minimum value, Indicates rounding up.
[0086] It should be noted that the Indicates the degree of influence of credibility on the permission level: when the user's credibility Significantly higher than the preset threshold hour, The larger the value, the higher the user's authority level; when the user's credibility Approaching the preset threshold hour, A smaller value limits the user's permission level; Ensure that the user's permission level does not exceed the user's identity level ; Finally, round up to ensure that the permission level is an integer.
[0087] For example, suppose the overall confidentiality level of a government document is =5, user A and user B request to access the file:
[0088] (1) For user A, user A's level =4, user A's credibility =0.9, due to the preset threshold =0.7, therefore, user A's credibility is greater than the preset threshold, indicating that user A's request is safe. At this time, user A is allowed to access the requested content. Further, based on user A's level and credibility, the permission level of user A is determined. The permission level =4, further increase the permission level of user A =4 and the confidentiality level of government documents =The lower level among 5, namely confidentiality level 4 as the decryption level, that is, the decryption level =4, that is, user A can decrypt the confidentiality level of government documents not exceeding 4.
[0089] (2) For user B, user B's level =3, user B's credibility =0.6, due to the preset threshold =0.7, therefore, the credibility of user B is less than the preset threshold, indicating that the user's request is unsafe. At this time, the user's request is rejected and is not allowed to access government documents.
[0090] 2. The above-mentioned method of determining the decryption level according to the user's authority level and the confidentiality level of the government document includes: when the user's authority level is greater than or equal to the confidentiality level of the government document, the decryption level is equal to the confidentiality level of the government document; when the user's authority level is less than the confidentiality level of the government document, the decryption level is equal to the user's authority level; that is, the decryption level It is the lower level between the user's permission level and the file confidentiality level, ensuring that the user can only decrypt the part that matches his or her permission. At the same time, it realizes refined access control and avoids the abuse of permission.
[0091] Furthermore, according to the decryption level and the level key of each confidentiality level, the encrypted result of the government document is decrypted. Round decryption, and according to the The decryption is carried out in the order of round 1 to round 1 decryption. is the decryption level; finally, the decryption results of each component in the first round are combined into the decryption result of the government document; by strictly decrypting according to the decryption level K, it is ensured that users can only access the content within the authorized scope.
[0092] therefore, from If 1 is obtained, then The decryption process is as follows: Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The decryption result of the round is Round of decryption, get each component in the first The decryption result of the round.
[0093] Among them, "according to the confidentiality level Level keys to build confidentiality levels The implementation of the encoding rule sequence and decoding rule sequence" and the "according to the confidentiality level" in step S401 Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence are implemented in the same way.
[0094] Among them, based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The decryption result of the round is Round of decryption, get each component in the first The decryption results of the round include:
[0095] 1. When When the component The decryption result of the round refers to the encryption result of the component in the encryption result of the government document. Therefore, the confidentiality level of the encryption result of the government document is not less than The encrypted results of the components are concatenated into The decryption object of the round; when When the confidentiality level is not less than The components of The decryption results of the first round are concatenated into The decryption object of the round.
[0096] 2. According to confidentiality level The rule number in the decoding rule sequence is determined by the corresponding DNA encoding and decoding rule, and the first The decryption object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the encoding rule sequence is determined by the corresponding DNA encoding and decoding rule, and the first The encoding results of the round are decoded by DNA to obtain the components in the first The decryption result of the round; among them, DNA encoding is to encode binary numbers into corresponding bases, and DNA decoding is to decode the bases into corresponding binary numbers.
[0097] It should be noted that for confidentiality levels less than Components of The decryption result of the first round is used as the The decryption result of the round.
Claims
1. A government information security management method based on hierarchical encryption, characterized in that: include: According to the confidentiality level of government documents , determine the confidentiality level of each component in the government document, and the confidentiality level of each component shall not be greater than the confidentiality level of the government document; When encoding each component and encrypting the encoded text of each component: according to the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The encryption result of the round is Round encryption, obtain each component in the first The encryption result of the round; From 1 to ; Get each component in the The encryption result of the round includes: when When the text encoding results of the components with a confidentiality level of not less than 1 are concatenated into the first round of encryption objects, When the confidentiality level is not less than The components of The encryption results of the first round are concatenated into The encryption object of the round; According to confidentiality level The rule number in the encoding rule sequence is determined to determine the corresponding DNA encoding and decoding rule, and the The encrypted object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the decoding rule sequence is used to determine the corresponding DNA encoding and decoding rule, and The encoding results of the round are decoded by DNA to obtain the components in the first The encryption result of the round; Put each component in The encryption results of the rounds constitute the encryption results of the government documents; Determine the decryption level based on the user's identity level and credibility as well as the confidentiality level of government documents , decrypt the encrypted results of government documents according to the decryption level and the level keys of each confidentiality level: based on the confidentiality level The encoding rule sequence and decoding rule sequence of DNA encoding and decoding rules are not less than The components of The decryption result of the round is Round of decryption, get each component in the first The decryption result of the round, from Get 1; combine the decryption results of each component in the first round to form the decryption result of the government document.
2. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: The various components of the government documents include document issuance information, titles at various levels, main text and attachments; the document issuance information includes document title, document number, issuer, signature and date of the issuing authority, copy recipient, issuing authority and issuing date; any government document contains at least document issuance information and main text.
3. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: The confidentiality level of each component of a government document is determined based on the confidentiality level of the government document, including: For any government document, the confidentiality level of the government document is recorded as the confidentiality level , record the level of the title in the government document as ;in, , and confidentiality level 1 is the lowest confidentiality level, confidentiality level The highest level of confidentiality. Equal to the preset value; Set the confidentiality level of the published information to the confidentiality level ,and , Indicates rounding down. Indicates taking the maximum value; sets the confidentiality level of the text and attachments to the confidentiality level ; then The confidentiality level of the title is set to confidentiality level ,and , Indicates rounding up.
4. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: The hierarchical key is constructed according to the initial conditions of a two-dimensional chaotic mapping function. The initial conditions of the two-dimensional chaotic mapping function include two initial values and four parameters, and the hierarchical keys of different confidentiality levels are different.
5. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: According to the confidentiality level Level keys to build confidentiality levels The encoding rule sequence and decoding rule sequence include: According to confidentiality level The initial values and parameters in the level key of the two-dimensional chaotic mapping function are iterated multiple times, and the number of iterations is not less than , It is equal to the sum of the lengths of the text encoding results of all components, and a chaotic value pair is obtained in each iteration; Multiply the two chaotic values in each chaotic value pair by And round up, and record the rounded results as the first rule number and the second rule number respectively; Equal to the number of all DNA encoding and decoding rules; Group all first rule numbers into confidentiality levels The coding rule sequence of all second rule numbers is composed of confidentiality levels The decoding rule sequence.
6. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: The method further comprises: When a user requests access, the user's credibility is obtained based on the content requested by the user and a threshold is set. When the user's credibility is greater than the preset threshold, the user is allowed to access the requested content. When the user's credibility is less than or equal to the preset threshold, the user is not allowed to access the requested content. When the user is allowed to access the requested content, the decryption level is determined based on the user's identity level and credibility and the confidentiality level of the government document; the encrypted result of the government document is decrypted based on the decryption level and the level keys of each confidentiality level.
7. The government information security management method based on hierarchical encryption according to claim 6 is characterized in that: Determining the decryption level based on the user's identity level and credibility and the confidentiality level of the government document includes: The user's authority level is determined based on the user's identity level and credibility, and the decryption level is determined based on the user's authority level and the confidentiality level of government documents. The decryption level is the lower level of the user's authority level and the confidentiality level of government documents.
8. The government information security management method based on hierarchical encryption according to claim 7 is characterized in that: Determining the user's authority level based on the user's identity level and credibility includes: ; Where, is the user's permission level, For user credibility, is the preset threshold, is the user's identity level, Indicates taking the minimum value, Indicates rounding up.
9. The government information security management method based on hierarchical encryption according to claim 1 is characterized in that: The components are obtained in The decryption results of the round include: when When the encryption result of the government documents is encrypted, the confidentiality level shall be no less than The encrypted results of the components are concatenated into The decryption object of the round; when When the confidentiality level is not less than The components of The decryption results of the first round are concatenated into The decryption object of the wheel; According to confidentiality level The rule number in the decoding rule sequence is used to determine the corresponding DNA encoding and decoding rule, and The decryption object of the round is encoded with DNA to obtain the The coding result of the round; according to the confidentiality level The rule number in the encoding rule sequence is determined to determine the corresponding DNA encoding and decoding rule, and the The encoding results of the round are decoded by DNA to obtain the components in the first The decryption result of the round.
Citation Information
Patent Citations
File encryption method and device and file decryption method
CN113836558A
Emergency training platform database dynamic management method and device and storage medium
CN119272337A