A computer network data storage encryption method and system

By generating multidimensional feature vectors through dynamic encryption parameters and chaos models, and combining them with geo-fencing strategies, the problems of data forgery attacks and key rotation faults in traditional encryption schemes in cold chain logistics are solved, and efficient and secure data storage and decryption are achieved.

CN120415808BActive Publication Date: 2025-10-17BEIJING SIHUA NET TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510535491.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-10-17
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

Traditional encryption schemes cannot effectively resist data source forgery attacks in cold chain logistics. There is a gap between the key rotation mechanism and the real-time data flow, which cannot meet the emergency temperature adjustment needs of drugs. The tamper-proof nature of blockchain can easily solidify contaminated data.

Method used

A dynamic encryption parameter generation method is adopted, combined with a chaos model and geo-fence strategy, to generate a multi-dimensional feature vector through environmental parameters, embed it into the plaintext header and encrypt it using the national secret algorithm, store it in shards on the edge computing node, and verify decryption permissions in real time.

Benefits of technology

It blocks forgery attacks from the source of data, ensures the uniqueness and unpredictability of dynamic keys, improves decryption efficiency and security, avoids the problem of solidification of contaminated data, and reduces the cost of cracking replay attacks and cross-regional data migration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415808B_ABST
    Figure CN120415808B_ABST
Patent Text Reader

Abstract

The application discloses a computer network data storage encryption method and system, relates to the technical field of storage encryption, and is based on an environment parameter collection mechanism of space-time constraints to block possible forgeries from a data source, converts physical environment characteristics into encryption elements, and makes an attacker need to synchronously imitate multi-dimensional environment parameters to implement tampering; based on a dynamic characteristic vector generation technology of a chaotic model driver, initial value sensitivity of a Lorenz system is utilized to exponentially amplify environment disturbance, so that each encryption key has uniqueness and unpredictability, and a time window vulnerability of a fixed key rotation mechanism is cracked; a combination of a geographic fence strategy and a distributed storage architecture, through sharding-level geographic constraints and BFT consensus verification, while retaining the tamper-proof advantage of a blockchain, a dynamic decryption permission control system is established, and a permanent solidification problem of contaminated data is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of storage encryption technology, in particular to a computer network data storage encryption method and system. BACKGROUND

[0002] For the cold chain logistics field of medicine and fresh food, the temperature control data storage system is the core of quality supervision and responsibility tracing. The traditional scheme generally uses transmission layer encryption such as TLS combined with AES CBC static storage encryption to form a double-layer protection architecture of transmission encryption and static storage.

[0003] But this encryption can be reverse-engineered by the vehicle terminal firmware, and a compliant temperature curve can be forged at the data generation source. The main defect of the traditional encryption is that the encryption algorithm only verifies the integrity of the data packet and cannot identify the content logic anomaly, and the fixed key rotation mechanism has a matching fault with the real-time data stream, and attackers can implant malicious data in the key switching gap.

[0004] The existing improved scheme introduces multi-party computation MPC and trusted execution environment TEE to cope with the above problems. The MPC technology stores the key fragments in the transportation party, the supervision party and the receiving party, and the decryption needs the cooperation of the three parties for calculation, but the cold chain logistics often involves cross-country multi-party cooperation. The network delay causes the real-time decryption response time to exceed about 15 seconds, which cannot meet the urgent temperature adjustment demand of medicines, and the TEE chip has a high failure rate at low temperature. Therefore, there is an urgent need for a computer network data storage encryption method and system to solve such problems. SUMMARY

[0005] In view of the above existing problems, the present application is proposed.

[0006] The present application provides a computer network data storage encryption method and system to solve the problem that the traditional encryption scheme relies on static keys and transmission layer protection, is difficult to resist data source forgery attacks, and the block chain cannot be tampered with. The characteristics of data are easily contaminated, and the key rotation mechanism has a fault with real-time business.

[0007] To solve the above technical problems, the present application provides the following technical solutions:

[0008] In a first aspect, the present application embodiment provides a computer network data storage encryption method, which comprises,

[0009] Step S1, generating a dynamic encryption parameter based on a current environment parameter set by a data acquisition node, the environment parameter set at least containing a timestamp, a geographic position and a device running state;

[0010] Step S2, inputting the dynamic encryption parameter into a chaotic model to generate a multi-dimensional feature vector, the chaotic model constructing a dynamic parameter evolution path based on Lorenz equation;

[0011] Step S3, before the data plaintext is encrypted, the multi-dimensional feature vector is embedded in the header of the data to be encrypted according to a preset rule to form an enhanced plaintext with an environment fingerprint;

[0012] Step S4, the enhanced plaintext is encrypted using a national secret algorithm to generate a ciphertext data block and store it in association with the dynamic encryption parameter.

[0013] As a preferred scheme of the computer network data storage encryption method, the environment parameter set is obtained in the following manner:

[0014] The sensor raw data is collected by a trusted execution environment (TEE);

[0015] The raw data is subjected to a space-time constraint, which includes GPS signal continuity verification and sensor sampling frequency compliance detection;

[0016] The verified data is cross-synchronized with a blockchain node clock to generate an environment parameter set resistant to replay attacks;

[0017] The GPS signal continuity verification requires that the geographical position offset of two adjacent data points does not exceed 3 times the satellite positioning error threshold; the sensor sampling frequency compliance detection is determined by comparing the variance of the preset sampling period and the actual collection timestamp, and when the variance exceeds the set threshold, a data discard mechanism is triggered.

[0018] As a preferred scheme of the computer network data storage encryption method, the parameter evolution path of the chaotic model is constructed in the following manner:

[0019] The initial value of the three-dimensional chaotic system is initialized, which is generated by environment parameter hash value mapping;

[0020] A 128-dimensional feature vector space is generated by iterative calculation, where each dimension corresponds to the evolution trajectory of a specific environment parameter;

[0021] The disturbance factor of the chaotic system is reset at the end of each data collection period, which is dynamically adjusted by the data flow characteristics of the previous period.

[0022] As a preferred scheme of the computer network data storage encryption method, the disturbance factor is adjusted according to the logarithmic function value of the ratio of the data flow peak value to the average value in the previous period, and when the flow fluctuation exceeds the preset critical value, the disturbance factor update amplitude is positively correlated with the fluctuation intensity.

[0023] As a preferred scheme of the computer network data storage encryption method, in step S2, the multi-dimensional feature vector is generated by mapping the dynamic encryption parameter vector into the initial state of the Lorenz system, then obtaining the chaotic trajectory through numerical integration, and finally mapping the trajectory into an e-dimensional feature vector.

[0024] In step S2, the dynamic encryption parameter vector p is mapped to obtain three normalized pseudo-random numbers and generate the initial state under the action of the secure hash function:

[0025]

[0026] (x0,y0,z0)=(M(2s1-1),M(2s2-1),M(2s3-1)),

[0027] where p represents the dynamic encryption parameter vector, || represents the concatenation operation, Hash(·) represents the secure hash function, represents the decimal part operation, k∈{1,2,3} represents the hash output index, M represents the trajectory amplitude factor, (x0,y0,z0) represents the initial state of the Lorenz system, 2 32 represents the bit width scale of the hash function output, used for normalization;

[0028] The chaotic system is represented by the continuous-time Lorenz equation:

[0029]

[0030] where x, y, and z represent the three state variables of the system, t represents the time variable, a, b, and c represent the Lorenz system parameters σ, ρ, and β, respectively.

[0031] The Lorenz equation is numerically integrated with a step size d using the fourth-order Runge-Kutta method to generate the n-th step state increment and update:

[0032]

[0033] where n=0,1,…,e-1 represents the iteration step number, d represents the numerical integration step size, (x n ,y n ,z n ) represents the n-th step system state, represents the i-th order increment in the x, y, and z directions, respectively.

[0034] The discrete trajectory is mapped to generate an e-dimensional feature vector according to a predetermined mapping:

[0035] v ι =frac(x ιsiny ι +z ι ),ι=1,…,e,

[0036] where v ι represents the ith eigenvalue, sin(·) represents the sine function, and e represents the eigenvector dimension.

[0037] As a preferred scheme of the computer network data storage encryption method, the generation process of the enhanced plaintext includes:

[0038] The multi-dimensional eigenvector is divided into a head identification segment and a tail check segment.

[0039] The environmental parameter hash tree root value is embedded in the head identification segment, and the hash tree root value is constructed by the same batch of collected data.

[0040] The time-constrained redundant check code is inserted in the tail check segment, and the generation interval of the check code is negatively correlated with the data collection frequency.

[0041] As a preferred scheme of the computer network data storage encryption method, the storage process of the ciphertext data block includes:

[0042] The ciphertext data block is divided into N data fragments, N≥5.

[0043] An independent geofencing strategy is attached to each data fragment, and the strategy includes a set of longitude and latitude ranges that allow decryption operations.

[0044] The data fragments with geofencing strategies are distributed and stored in edge computing nodes, and a synchronization verification channel based on BFT consensus is established between nodes.

[0045] As a preferred scheme of the computer network data storage encryption method, in step S4, the way of attaching an independent geofencing strategy to each data fragment is:

[0046] A circular fence is generated based on the current environmental geographic location for the fragment index i, and is attached to the fragment metadata.

[0047] Let the total number of data fragments be N, and the current environmental longitude and latitude be

[0048] To make the fence center evenly distributed around the environmental location, the fence center of the ith fragment is generated according to the index i:

[0049]

[0050] where, represents the latitude value in the environmental parameter set, and λenv represents a longitude value in the set of environmental parameters, represents a maximum offset angle amplitude, represents a constant of circular ratio, represents a data shard index, and N represents a total number of data shards;

[0051] The fence radius of the i-th shard is obtained by linearly increasing the base radius:

[0052]

[0053] wherein r base represents a base radius, and represents a radius growth factor;

[0054] The fence of the i-th shard is defined as a circular region:

[0055]

[0056] wherein G i represents a geographic fence policy of the i-th shard, represents a latitude and longitude of a decryption request end, and d(·,·) represents a great circle distance between two points;

[0057] The Haversine formula is used to calculate the distance between any point and the center of the fence, and the calculation formula is:

[0058]

[0059] wherein R represents the radius of the earth, represents an arbitrary decryption request point, represents the corresponding fence center coordinates;

[0060] The metadata structure of each shard is extended to (ID i , D i , G i ), wherein ID i is a shard identifier, D i is an encrypted shard content, and G i is a geographic fence policy, each shard is stored in an edge node, and the decryption needs to verify that the request end coordinates meet the corresponding G i condition.

[0061] In a second aspect, the present application provides a computer network data storage encryption system, comprising,

[0062] An environment perception module is integrated in a data collection terminal and includes an anti-physical tampering sensor group and a TEE security chip;

[0063] A chaotic computing engine is deployed in an edge gateway device and is configured to generate an environment-bound feature vector in real time;

[0064] A dynamic encryption unit is located in front of a cloud storage service and includes a national encryption algorithm hardware accelerator and a geofencing policy executor.

[0065] A distributed verification network is composed of blockchain nodes deployed in multiple geographic regions, and each node is configured with a differentiated consensus verification rule set.

[0066] As a preferred scheme of the computer network data storage encryption system, the operation logic of the geofencing policy executor includes:

[0067] When the decryption request is triggered, the real-time environmental parameter set of the request terminal is obtained.

[0068] The spatial similarity matrix of the request parameters and the storage parameters is calculated, and the matrix includes a time dimension attenuation factor.

[0069] Only when the weighted value of the similarity matrix exceeds the dynamic threshold value, the decryption coprocessor of the corresponding data shard is activated, and the dynamic threshold value is exponentially increased with the data storage time.

[0070] The present application has the following advantages: the spatiotemporal constraint-based environmental parameter acquisition mechanism blocks the possibility of forgery from the data source, converts physical environmental characteristics into encryption elements, and makes it necessary for attackers to simultaneously fake multi-dimensional environmental parameters to implement tampering; the dynamic feature vector generation technology based on a chaotic model drives the initial value sensitivity of the Lorenz system to exponentially amplify environmental disturbances, making each encryption key unique and unpredictable, and breaking the time window vulnerability of the fixed key rotation mechanism; the combination of geofencing strategy and distributed storage architecture establishes a dynamic decryption permission control system through shard-level geographic constraints and BFT consensus verification, while retaining the tamper-proof advantage of blockchain, avoiding the problem of permanent solidification of contaminated data.

[0071] The introduction of the spatiotemporal similarity matrix further enhances the dynamic defense capability, and through the dual constraints of geographic proximity and time attenuation factor, the cracking cost of replay attacks and cross-region data migration is significantly improved under the premise of ensuring emergency retrieval efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0072] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0073] Figure 1 The flowchart of the computer network data storage encryption method in embodiment 1 is shown.

[0074] Figure 2 A schematic diagram of a framework of a computer network data storage encryption system of Example 1. DETAILED DESCRIPTION

[0075] In order to make the above objectives, characteristics and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0076] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application, but the present application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the concept of the present application, therefore the present application is not limited to the specific embodiments disclosed below.

[0077] Secondly, the "one embodiment" or "embodiment" referred to herein means that the specific features, structures or characteristics can be included in at least one implementation of the present application. "In one embodiment" appearing in different places in the specification does not mean the same embodiment, nor is it an embodiment that is independent of or selected from other embodiments.

[0078] Example 1, Reference Figure 1 The example provides a computer network data storage encryption method, comprising: step S1, generating dynamic encryption parameters based on a current set of environment parameters by a data acquisition node, the set of environment parameters at least including a timestamp, a geographic position and a device running state;

[0079] The acquisition method of the set of environment parameters includes:

[0080] The sensor raw data is acquired by a trusted execution environment (TEE);

[0081] The raw data is subjected to a space-time constraint, and the space-time constraint includes GPS signal continuity verification and sensor sampling frequency compliance detection;

[0082] The verified data is cross-synchronized with a blockchain node clock to generate a set of environment parameters resistant to replay attacks;

[0083] The GPS signal continuity verification requires that the geographic position offset of two adjacent data points does not exceed 3 times the satellite positioning error threshold; the sensor sampling frequency compliance detection is determined by comparing the variance value of the preset sampling period and the actual acquisition timestamp, and when the variance exceeds the set threshold, a data discard mechanism is triggered;

[0084] Step S2, inputting the dynamic encryption parameters into a chaotic model to generate a multi-dimensional feature vector, and the chaotic model constructs a dynamic parameter evolution path based on the Lorenz equation;

[0085] The parameter evolution path construction of the chaotic model includes:

[0086] Initialize the initial value of the three-dimensional chaotic system, which is generated by the environmental parameter hash value mapping;

[0087] Generate a 128-dimensional feature vector space by iterative calculation, where each dimension corresponds to the evolution trajectory of a specific environmental parameter;

[0088] Reset the disturbance factor of the chaotic system at the end of each data collection period, which is dynamically adjusted by the data flow characteristics of the previous period;

[0089] The disturbance factor is adjusted according to the logarithmic function value of the ratio of the peak value to the average value of the data flow in the previous period. When the flow fluctuation exceeds the preset critical value, the disturbance factor update amplitude is positively correlated with the fluctuation intensity;

[0090] Step S2, the generation of multi-dimensional feature vectors is as follows: the dynamic encryption parameter vector is mapped to the initial state of the Lorenz system, then the chaotic trajectory is obtained by numerical integration, and finally the trajectory is mapped to the e-dimensional feature vector;

[0091] Step S2, under the action of the secure hash function, the dynamic encryption parameter vector p is mapped to obtain three normalized pseudo-random numbers and generate the initial state:

[0092]

[0093] (x0,y0,z0)=(M(2s1-1),M(2s2-1),M(2s3-1)),

[0094] Where p represents the dynamic encryption parameter vector, || represents the concatenation operation, Hash(·) represents the secure hash function, represents the decimal part operation, k∈{1,2,3} represents the hash output index, M represents the trajectory amplitude factor, (x0,y0,z0) represents the initial state of the Lorenz system, 2 32 represents the bit width scale of the hash function output, used for normalization;

[0095] The chaotic system adopts the continuous-time Lorenz equation:

[0096]

[0097] Where x, y, z represent the three state variables of the system, t represents the time variable, a, b, c represent the Lorenz system parameters σ, ρ, β, respectively;

[0098] The fourth-order Runge-Kutta method is used to perform numerical integration on the Lorenz equation with a step size d, and the n-step state increment and update are generated by iteration:

[0099]

[0100] where n = 0, 1, …, e-1 represents the number of iteration steps, d represents the numerical integration step size, (x n ,y n ,z n ) represents the system state at the n-th step, represents the increment in the x, y, z direction respectively;

[0101] The discrete trajectory is generated into an e-dimensional feature vector according to a preset mapping:

[0102] v ι = frac(x ι sin y ι +z ι ), i = 1, …, e,

[0103] where v ι represents the i-th feature value, sin(·) represents the sine function, and e represents the feature vector dimension;

[0104] Specifically, the sensitivity of the Lorenz system to the initial state is utilized to realize exponential amplification of the small disturbance of the environmental parameter to the feature vector, the hash mapping maps the dynamic encryption parameter to the chaotic initial condition without conflict, ensuring that the trajectory generated each time is unique, the fourth-order Runge-Kutta integration takes into account the calculation accuracy and efficiency, so that the real-time system can also maintain the chaotic characteristics, the splitting function with nonlinear sine transformation is selected for the trajectory mapping function, which not only improves the feature entropy, but also preserves the reversible association to the input, and the e-dimensional feature vector is uniformly distributed in the high-dimensional space and can be directly used as a symmetric encryption key or a pseudo-random seed. This process does not need to store the historical state, only needs the environmental parameter input and a small amount of computing resources, is suitable for edge device deployment, and can continuously resist replay and statistical analysis attacks.

[0105] Step S3, before encrypting the data plaintext, embedding the multi-dimensional feature vector into the header of the data to be encrypted according to a preset rule to form an enhanced plaintext with environmental fingerprints;

[0106] The generation process of the enhanced plaintext includes:

[0107] The multi-dimensional feature vector is divided into a head identification segment and a tail check segment;

[0108] The environmental parameter hash tree root value is embedded in the head identification segment, and the hash tree root value is constructed by the same batch of collected data;

[0109] The time-constrained redundancy check code is inserted in the tail check segment, and the generation interval of the check code is negatively correlated with the data collection frequency;

[0110] Step S4, using the national secret algorithm to encrypt the enhanced plaintext, generating a ciphertext data block and storing it with dynamic encryption parameters;

[0111] The storage process of the ciphertext data block includes:

[0112] The ciphertext data block is divided into N data fragments, N≥5;

[0113] An independent geo-fencing policy is attached to each data fragment, and the policy includes a set of latitude and longitude ranges that allow decryption operations;

[0114] The data fragments with geo-fencing policies are distributed and stored in edge computing nodes, and a synchronization verification channel based on BFT consensus is established between nodes;

[0115] In step S4, the way to attach an independent geo-fencing policy to each data fragment is:

[0116] A circular fence is generated based on the current environmental geographic location for fragment index i, and it is attached to the fragment metadata;

[0117] Let the total number of data fragments be N, and the current environmental latitude and longitude be

[0118] To make the fence center evenly distributed near the environmental location, the fence center of the i-th fragment is generated according to index i:

[0119]

[0120] wherein, represents the latitude value in the environmental parameter set, λ env represents the longitude value in the environmental parameter set, α represents the maximum offset angle, π represents the constant of circular ratio, i∈{1,…,N} represents the data fragment index, and N represents the total number of data fragments;

[0121] The fence radius of the i-th fragment is obtained by linearly increasing the base radius:

[0122]

[0123] wherein, r base represents the base radius, and δ represents the radius growth factor;

[0124] The fence of the i-th fragment is defined as a circular area:

[0125]

[0126] wherein, G i represents the geo-fencing policy of the i-th fragment, represents the latitude and longitude of the decryption request end, and d(·,·) represents the great circle distance between two points;

[0127] The Haversine formula is used to calculate the distance between any point and the center of the fence, and the calculation formula is:

[0128]

[0129] where R represents the radius of the earth, λ1 represents an arbitrary decryption request point, λ2 represents the corresponding fence center coordinates;

[0130] The metadata structure of each shard is extended to (ID i ,D i ,G i ), wherein ID i is the shard identifier, D i is the encrypted shard content, and G i is the geographic fence policy. Each shard is stored in an edge node, and the request end coordinates need to be verified to meet the corresponding G i condition during decryption.

[0131] Specifically, a circular fence at the shard level is dynamically generated based on the environmental geographic location, which not only ensures the geographic decryption constraints of each shard, but also uses the index i and the sine-cosine distribution to achieve uniform distribution of the fence center. The linearly increasing radius strategy makes the accessible areas of different shards significantly different, improving the difficulty of replay or transfer of attackers based on only part of the shards. The Haversine formula ensures the accuracy of distance calculation worldwide and is compatible with geographic constraint requirements at different latitudes. By attaching parameters such as λ c,i ,r i to the metadata, the legality of the request can be verified on the edge device without state, avoiding the single-point bottleneck of the center. The overall scheme only relies on environmental parameters and a small amount of calculation, meets the real-time requirements of edge computing, and has strong robustness against replay and migration attacks.

[0132] Embodiment 2, refer to Figure 2 This embodiment provides a computer network data storage encryption system, comprising: an environment perception module integrated in a data collection terminal, including an anti-physical tampering sensor group and a TEE security chip;

[0133] A chaotic computing engine is deployed on an edge gateway device and is configured to generate an environment-bound feature vector in real time.

[0134] A dynamic encryption unit is located in front of a cloud storage service and includes a national cryptographic algorithm hardware accelerator and a geographic fence policy executor.

[0135] A distributed verification network is composed of blockchain nodes deployed in multiple geographic regions, each node is configured with a differentiated consensus verification rule set;

[0136] The operation logic of the geofencing policy executor includes:

[0137] When the decryption request is triggered, the real-time environmental parameter set of the request terminal is obtained;

[0138] Calculate the spatial similarity matrix of the request parameters and the storage parameters, and the matrix contains a time dimension decay factor;

[0139] Only when the weighted value of the similarity matrix exceeds the dynamic threshold, activate the decryption coprocessor of the corresponding data shard, and the dynamic threshold increases exponentially with the data storage time length;

[0140] The step of calculating the spatial similarity matrix of the request parameters and the storage parameters is:

[0141] Let the real-time environmental parameters of the decryption request terminal be latitude and longitude And the request timestamp t req ;

[0142] For the i-th data shard, the fence center radius r i and the storage timestamp t store,i are attached in the metadata;

[0143] Use the Haversine formula to calculate the great circle distance between the request point and the i-th shard fence center:

[0144]

[0145] Where d i represents the distance between the i-th shard and the request terminal, R represents the earth radius, λ req respectively represent the latitude and longitude of the request terminal, λ c,i respectively represent the latitude and longitude of the i-th shard fence center;

[0146] Normalize the distance to the spatial similarity:

[0147]

[0148] Where, represents the spatial similarity factor of the i-th shard, r i represents its fence radius, when d i >r i , the similarity is automatically 0;

[0149] Calculate the exponential decay according to the difference between the request time and the storage time:

[0150] α i =exp(-τ(t req -t store,i )), where α i represents the time decay factor of the i-th slice, τ represents the time decay constant, t req With t store,i Represents the Unix timestamp of the request and storage respectively, in seconds;

[0151] Multiply the spatial similarity by the time decay to get the final similarity: Among them, S i Indicates the comprehensive similarity of the i-th shard;

[0152] Arrange all the shard similarities by index to form a 1×N matrix: S=[S1,S2,…,S N ]Where S represents the spatial-temporal similarity matrix between the request parameters and the parameters of each storage shard;

[0153] Specifically, the Haversine formula is first used to measure the geographic distance between the requesting end and the center of each shard fence. Then, the spatial similarity factor is obtained through linear normalization, so that the shards closer to the central area have a higher matching degree. The exponential time decay factor is introduced to dynamically reduce the decryption priority of shards stored for a long time to resist delayed replay attacks. The multiplication of the two not only retains the hard boundary of the spatial constraint, but also incorporates the soft attenuation of the time dimension into the similarity measurement, balancing real-time and security. The final output similarity matrix can not only be used for fast shard-by-shard verification, but can also be combined with subsequent dynamic threshold judgment logic to flexibly decide which shards' decryption coprocessors to activate, thereby achieving efficient and secure multi-level geo-fence access control.

[0154] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A computer network data storage encryption method, characterized in that: include, Step S1: The data collection node generates dynamic encryption parameters based on a current set of environmental parameters, wherein the set of environmental parameters at least includes a timestamp, a geographic location, and a device operating status; Step S2: inputting the dynamic encryption parameters into a chaotic model to generate a multi-dimensional feature vector, wherein the chaotic model constructs a dynamic parameter evolution path based on the Lorenz equation; Step S3, before encrypting the data plaintext, embedding the multidimensional feature vector into the header of the data to be encrypted according to a preset rule to form an enhanced plaintext with an environmental fingerprint; Step S4: Encrypt the enhanced plaintext using the national encryption algorithm to generate a ciphertext data block and store it in association with the dynamic encryption parameter; The parameter evolution path construction of the chaos model includes: Initializing an initial value of the three-dimensional chaotic system, where the initial value is generated by a hash value mapping of an environmental parameter; A 128-dimensional feature vector space is generated through iterative calculation, where each dimension corresponds to the evolution trajectory of a specific environmental parameter; Resetting the disturbance factor of the chaotic system at the end of each data collection period, wherein the disturbance factor is dynamically adjusted according to the data flow characteristics of the previous period; Step S2, the method of generating the multidimensional feature vector is: mapping the dynamic encryption parameter vector to the initial state of the Lorenz system, then obtaining the chaotic trajectory by numerical integration, and finally mapping the trajectory to an e-dimensional feature vector; Step S2: Under the action of the secure hash function, the dynamic encryption parameter vector p is mapped to obtain three normalized pseudo-random numbers and generate an initial state: (x0,y0,z0)=(M(2s1-1),M(2s2-1),M(2s3-1)), Where p represents the dynamic encryption parameter vector, ‖ represents the concatenation operation, Hash(·) represents the secure hash function, represents the fractional part operation, k∈{1,2,3} represents the hash output index, M represents the trajectory amplitude factor, (x0,y0,z0) represents the initial state of the Lorenz system, 2 32 Indicates the bit width scale of the hash function output, used for normalization; The chaotic system is represented by the continuous-time Lorenz equation: Among them, x, y, z represent the three state variables of the system, t represents the time variable, a, b, c represent the Lorenz system parameters σ, ρ, β respectively; The fourth-order Runge-Kutta method is used to numerically integrate the Lorenz equation with a step size d, iteratively generating the n-th step state increment and update: Among them, n=0,1,…,e-1 represents the number of iteration steps, d represents the numerical integration step size, (x n ,y n ,z n ) represents the system status at step n, Respectively represent the increment of the ι-th order in the x, y, and z directions; Discrete trajectories Generate an e-dimensional feature vector according to the preset mapping: in, represents the ι-th dimension eigenvalue, sin(·) represents the sine function, and e represents the eigenvector dimension; The process of generating the enhanced plaintext includes: Split the multidimensional feature vector into a head identification segment and a tail check segment; Embed the environment parameter hash tree root value in the header identification segment, where the hash tree root value is constructed from the same batch of collected data; A time-constrained redundant check code is inserted into the tail check segment, and the generation interval of the check code is negatively correlated with the data collection frequency.

2. A computer network data storage encryption method according to claim 1, characterized in that: The method of obtaining the environmental parameter set includes: Collect raw sensor data through the trusted execution environment (TEE); Applying spatiotemporal constraints to the raw data, the spatiotemporal constraints including GPS signal continuity verification and sensor sampling frequency compliance detection; Cross-synchronize the verified data with the blockchain node clock to generate a set of environmental parameters that are resistant to replay attacks; The GPS signal continuity verification requires that the geographic location offset of two adjacent data points does not exceed 3 times the satellite positioning error threshold; the sensor sampling frequency compliance detection is determined by comparing the variance value of the preset sampling period with the actual collection timestamp. When the variance exceeds the set threshold, the data discard mechanism is triggered.

3. A computer network data storage encryption method according to claim 1, characterized in that: The disturbance factor is adjusted according to the logarithmic function value of the ratio of the data flow peak value to the mean value in the previous period. When the flow fluctuation exceeds the preset critical value, the update amplitude of the disturbance factor is positively correlated with the fluctuation intensity.

4. A computer network data storage encryption method according to claim 1, characterized in that: The storage process of the ciphertext data block includes: Divide the ciphertext data block into N data fragments, N ≥ 5; Attaching an independent geo-fence policy to each data shard, wherein the policy includes a set of latitude and longitude ranges where decryption operations are allowed; Data with geo-fencing strategies are sharded and distributed and stored in edge computing nodes, and a synchronous verification channel based on BFT consensus is established between nodes.

5. A computer network data storage encryption method as claimed in claim 4, characterized in that: In step S4, the method of adding an independent geo-fencing strategy to each data shard is: Generate a circular fence for shard index i based on the current environment's geographic location and append it to the shard metadata; Assume the total number of data shards is N, and the current environment latitude and longitude is To make the fence centers evenly distributed around the environment, generate the fence center of the i-th slice according to index i: in, Represents the latitude value in the environmental parameter set, λ env Represents the longitude value in the environmental parameter set, α represents the maximum offset angle amplitude, π represents the pi constant, i∈{1,…,N} represents the data shard index, and N represents the total number of data shards; The fence radius of the i-th shard is obtained by linearly increasing the base radius: Among them, r base represents the base radius, and δ represents the radius growth factor; The fence of the i-th shard is defined as a circular area: Among them, G i represents the geo-fencing strategy of the i-th shard, represents the latitude and longitude of the decryption requesting end, and d(·,·) represents the great circle distance between the two points; The Haversine formula is used to calculate the distance between any point and the center of the fence. The calculation formula is: Where R represents the radius of the Earth, represents any decryption request point, Indicates the center coordinates of the corresponding fence; Expand the metadata structure of each shard to (ID i ,D i ,G i ), where ID i is the fragment identifier, D i To encrypt the fragment content, G i For geo-fencing strategy, each shard is stored in the edge node. When decrypting, it is necessary to verify that the requesting end coordinates meet the corresponding G i condition.

6. A computer network data storage encryption system, based on a computer network data storage encryption method according to any one of claims 1 to 5, characterized in that: include: The environmental perception module is integrated into the data acquisition terminal and includes a sensor group and a TEE security chip that are resistant to physical tampering; Chaos computing engine, deployed on edge gateway devices, and configured to generate environment-bound feature vectors in real time; The dynamic encryption unit, located at the front end of the cloud storage service, includes a hardware accelerator for national encryption algorithms and a geo-fencing policy executor; The distributed verification network consists of blockchain nodes deployed in multiple geographical regions, and each node is configured with a differentiated set of consensus verification rules.

7. A computer network data storage encryption system as claimed in claim 6, characterized in that: The operation logic of the geo-fence policy executor includes: When a decryption request is triggered, a set of real-time environment parameters of the requesting terminal is obtained; Calculating a spatial similarity matrix between the request parameters and the stored parameters, wherein the matrix includes a time dimension attenuation factor; The decryption coprocessor of the corresponding data slice is activated only when the weighted value of the similarity matrix exceeds a dynamic threshold, and the dynamic threshold increases exponentially with the data storage duration.

Citation Information

Patent Citations

  • Electronic signature generation and anti-counterfeiting system based on multi-source information fusion

    CN119885294A