Self-adaptive encryption management method and system in edge computing environment
By building a resource encryption evaluation matrix and a fuzzy decision network in an edge computing environment, and generating a differentiated encryption strategy in combination with the data sensitivity hierarchical model, the problems of low encryption efficiency and resource redundancy in edge computing are solved, adaptive encryption management is realized, and system stability and resource utilization are improved.
Patent Information
- Application Number
- CN202510562125.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-05
AI Technical Summary
The encryption technology in traditional edge computing faces insufficient adaptability, resulting in a decrease in encryption efficiency in high-load scenarios, obstacles in synchronization of centralized key management, lack of data grading, resulting in resource redundancy consumption, long cross-domain authentication process of mobile devices and potential identity counterfeiting, making it difficult to meet real-time interaction needs, and the accumulation of encryption tasks in burst traffic scenarios triggers a double response delay.
The resource encryption evaluation matrix is constructed by real-time monitoring of edge node data, the fuzzy decision network is used to dynamically adjust the encryption strength weight, and differentiated encryption strategies are generated based on the data sensitivity hierarchical model, and adaptive encryption is realized through distributed key management to optimize load allocation and resource utilization.
It realizes accurate matching of security levels and resource consumption in an edge computing environment, improves system stability and scalability, optimizes energy efficiency ratio, and solves the adaptability and efficiency problems of traditional encryption strategies.
Smart Images

Figure CN120433987A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of encryption management technology, and in particular relates to an adaptive encryption management method and system in an edge computing environment. Background Art
[0002] In edge computing scenarios, traditional encryption technology faces multiple adaptability challenges due to the use of static encryption strategies: traditional rigid encryption mechanisms are difficult to adapt to the dynamic resource changes of edge nodes, resulting in a sharp drop in encryption efficiency in high-load scenarios; centralized key management systems produce synchronization barriers when the network topology changes frequently, seriously affecting system reliability; the lack of a data classification mechanism leads to excessive encryption of low-sensitivity services, resulting in redundant consumption of computing resources; the cross-domain authentication process for mobile devices is lengthy and there is a risk of identity forgery, making it difficult to meet real-time interaction needs; the accumulation of encryption tasks in bursty traffic scenarios causes the response delay to double.
[0003] Existing technologies use high-intensity encryption, which results in excessively high service latency, while simplified protection increases the risk of data tampering. This fundamental conflict between security and efficiency seriously restricts the large-scale application and deployment of edge computing in key areas. Summary of the Invention
[0004] In order to solve the above problems existing in the prior art, the present invention proposes an adaptive encryption management method and system in an edge computing environment.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] An adaptive encryption management method in an edge computing environment, comprising:
[0007] S1: monitor edge node data in real time and build a resource encryption evaluation matrix based on the edge node data;
[0008] S2: Dynamically adjust the resource encryption evaluation matrix through a fuzzy decision network to obtain encryption strength weight information;
[0009] S3: Processing the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy;
[0010] S4: Processing the edge node data using the differentiated encryption strategy to obtain distributed adaptive encryption information.
[0011] Preferably, the structure of the resource encryption evaluation matrix in step S1 is:
[0012] The rows and columns of the resource encryption evaluation matrix are edge node numbers and resource encryption evaluation indicators respectively; the resource encryption evaluation indicators include node resource indicators, network status indicators, and security situation indicators.
[0013] Preferably, the process of generating the encryption strength weight information in step S2 is:
[0014] S201: Obtaining fuzzy encryption input variables according to the resource encryption evaluation matrix;
[0015] S202: Obtaining an encryption strength weight value by dynamically reasoning the fuzzy encryption input variable through fuzzy reinforcement learning;
[0016] S203: Obtain encryption strength weight information by dynamically correcting and feeding back the encryption strength weight value.
[0017] Preferably, the process of generating the encryption strength weight value in step S202 is:
[0018] S202-1: Preset initial fuzzy rule base;
[0019] S202-2: fuzzy mapping the initial fuzzy rule base to process the fuzzy encrypted input variable to obtain an encryption trigger rule condition;
[0020] S202-3: Optimizing the encryption trigger rule conditions through reinforcement learning to obtain dynamic encryption rule weights;
[0021] S202-4: Processing the dynamic encryption rule weight according to the rule trigger strength to obtain a dynamic encryption strength;
[0022] S202-5: Obtain an encryption strength weight value by defuzzifying the dynamic encryption strength.
[0023] Preferably, the process of dynamic correction feedback in step S203 is:
[0024] S203-1: Obtain encryption execution performance information and encryption execution security information through encryption monitoring;
[0025] S203-2: Generate weight adjustment trigger state information by dynamically evaluating the encryption execution performance information and the encryption execution security information;
[0026] S203-3: Execute the weight adjustment trigger state information through the policy engine to obtain encrypted weight correction data;
[0027] S203-4: Verify the encryption weight correction data through encryption feedback to generate encryption strength weight information.
[0028] Preferably, the generation process of the differentiated encryption strategy in step S3 is:
[0029] S301: Processing the resource encryption evaluation matrix through dynamic sensitivity analysis to obtain a sensitivity classification label;
[0030] S302: Mapping the sensitivity classification label through the encryption strength weight information to obtain a differentiated encryption strategy.
[0031] Preferably, the process of generating the sensitivity classification label in step S301 is as follows:
[0032] S301-1: Processing the resource encryption evaluation matrix through sensitive entity extraction to obtain a preliminary sensitive entity set;
[0033] S301-2: Processing the preliminary sensitive entity set through sensitivity grading to obtain sensitivity grading labels.
[0034] Preferably, the process of generating the distributed adaptive encryption information in step S4 is:
[0035] S401: dynamically loading an algorithm engine using the differentiated encryption strategy to obtain a node matching encryption engine instance;
[0036] S402: Processing the node matching encryption engine instance through distributed key management distribution to obtain edge node encryption key parameters;
[0037] S403: Processing the edge node encryption key parameters by parallel encryption of data fragments to obtain fragmented encrypted data blocks;
[0038] S404: Synchronizing the sharded encrypted data blocks through a consensus protocol to obtain distributed adaptive encryption information.
[0039] Preferably, the process of generating the fragmented encrypted data block in step S403 is:
[0040] S403-1: The shard controller processes the original data block of the edge node to obtain a plaintext shard set;
[0041] S403-2: Processing the plaintext fragment set and the edge node encryption key parameter by a parallel encryption engine to generate a ciphertext fragment set;
[0042] S403-3: Process the ciphertext fragment set through metadata reassembly and encapsulation to output fragmented encrypted data blocks.
[0043] An adaptive encryption management system in an edge computing environment, the system being applied to the adaptive encryption management method according to any one of claims 1 to 9, characterized in that it comprises a resource encryption evaluation matrix construction module, a fuzzy decision network module, a data sensitivity grading module, and a differentiated encryption module:
[0044] The resource encryption evaluation matrix construction module is used to monitor edge node data in real time and construct a resource encryption evaluation matrix;
[0045] The fuzzy decision network module is used to dynamically adjust the resource encryption evaluation matrix through the fuzzy decision network to obtain encryption strength weight information;
[0046] The data sensitivity grading module is used to process the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy;
[0047] The differential encryption module is used to process the edge node data through the differential encryption strategy to obtain distributed adaptive encryption information.
[0048] The beneficial effects of the present invention are:
[0049] (1) By constructing a resource encryption evaluation matrix based on edge node data, the status of edge nodes can be accurately quantified, providing a basis for subsequent encryption decisions;
[0050] (2) Dynamically adjust the resource evaluation matrix through the fuzzy decision network to achieve intelligent processing of nonlinear relationships and break through the limitations of traditional rule engines;
[0051] (3) Differentiated encryption strategies are generated through data sensitivity classification models, which can accurately match security levels and resource consumption. Distributed adaptive encryption information is generated through differentiated encryption strategies, which can maximize resource utilization, realize intelligent load distribution, optimize energy efficiency, and improve system stability and scalability. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] To facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0053] Figure 1 This is a flow chart of an adaptive encryption management method in an edge computing environment of the present invention. DETAILED DESCRIPTION
[0054] In order to further illustrate the technical means and effects adopted by the present invention to achieve the predetermined purpose of the invention, the specific implementation methods, structures, features and effects of the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments.
[0055] See also Figure 1 , an adaptive encryption management method in an edge computing environment, comprising:
[0056] S1: monitor edge node data in real time and build a resource encryption evaluation matrix based on the edge node data;
[0057] S2: Dynamically adjust the resource encryption evaluation matrix through a fuzzy decision network to obtain encryption strength weight information;
[0058] S3: Processing the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy;
[0059] S4: Processing the edge node data using the differentiated encryption strategy to obtain distributed adaptive encryption information.
[0060] Example 1
[0061] In this embodiment, the real-time monitoring of edge node data and the construction of a resource encryption evaluation matrix based on the edge node data are specifically implemented by the following steps:
[0062] The edge node data includes node resource data, network status data, and security situation data;
[0063] The node resource data includes CPU utilization data, GPU utilization data, memory usage data, mobile edge node remaining power data, and storage space data;
[0064] The network status data includes bandwidth data, delay data, jitter data, and packet loss rate data;
[0065] The security situation data includes intrusion detection alarm frequency data, historical attack record data, and current threat level data.
[0066] The edge node data is collected in the following way:
[0067] Deploy lightweight probes to capture edge node data in real time to avoid polling overhead; transmit the edge node data to the central analysis node through an encrypted channel (such as DTLS).
[0068] The structure of the resource encryption evaluation matrix is as follows: the rows and columns of the resource encryption evaluation matrix are edge node numbers and resource encryption evaluation indicators respectively;
[0069] The resource encryption evaluation indicators include node resource indicators, network status indicators, and security situation indicators;
[0070] It should be noted that each resource encryption evaluation indicator is Min-Max normalized to ensure that the value range is [0,1].
[0071] In this embodiment, dynamically adjusting the resource encryption evaluation matrix through the fuzzy decision network to obtain encryption strength weight information is specifically implemented by the following steps:
[0072] S201: Obtaining fuzzy encryption input variables according to the resource encryption evaluation matrix;
[0073] Specifically, the resource encryption evaluation index of the resource encryption evaluation matrix is selected as the key input variable; by designing the triangular / trapezoidal membership function, the levels are divided into "low security, medium security, and high security"; the numerical values in the resource encryption evaluation matrix are mapped to the membership of each key encryption input variable, and the fuzzified encryption input variable membership set is obtained.
[0074] S202: Obtaining an encryption strength weight value by dynamically reasoning the fuzzy encryption input variable through fuzzy reinforcement learning;
[0075] S202-1: Preset initial fuzzy rule base;
[0076] S202-2: fuzzy mapping the initial fuzzy rule base to process the fuzzy encrypted input variable to obtain an encryption trigger rule condition;
[0077] S202-3: Optimizing the encryption trigger rule conditions through reinforcement learning to obtain dynamic encryption rule weights;
[0078] S202-4: Processing the dynamic encryption rule weight according to the rule trigger strength to obtain a dynamic encryption strength;
[0079] S202-5: Obtain an encryption strength weight value by defuzzifying the dynamic encryption strength.
[0080] The reinforcement learning defines a resource matrix feature state space, a weight adjustment amplitude action space, a safety and performance balance reward function, and uses Q-learning to update rule weights.
[0081] S203: Obtain encryption strength weight information by dynamically correcting and feeding back the encryption strength weight value. S203-1: Obtain encryption execution performance information and encryption execution security information through encryption monitoring;
[0082] S203-2: Generate weight adjustment trigger state information by dynamically evaluating the encryption execution performance information and the encryption execution security information;
[0083] S203-3: Execute the weight adjustment trigger state information through the policy engine to obtain encrypted weight correction data;
[0084] S203-4: Verify the encryption weight correction data through encryption feedback to generate encryption strength weight information.
[0085] In this embodiment, the process of processing the encryption strength weight information using the data sensitivity grading model to generate a differentiated encryption strategy is specifically implemented by the following steps:
[0086] S301: Processing the resource encryption evaluation matrix through dynamic sensitivity analysis to obtain a sensitivity classification label;
[0087] S301-1: Processing the resource encryption evaluation matrix through sensitive entity extraction to obtain a preliminary sensitive entity set;
[0088] S301-2: Processing the preliminary sensitive entity set through sensitivity grading to obtain sensitivity grading labels.
[0089] Specifically, sensitive entities in the data content are extracted through a lightweight natural language processing pre-training model to obtain sensitivity grading labels. The sensitivity grading labels are the security sensitivity of edge device nodes, including low security level, medium security level, and high security level.
[0090] S302: Mapping the sensitivity classification label through the encryption strength weight information to obtain a differentiated encryption strategy.
[0091] The differentiated encryption strategy includes:
[0092] When the sensitivity classification label is a high security level, a high-intensity encryption algorithm is mandatory for data encryption;
[0093] When the sensitivity classification label is a medium security level, a balanced algorithm is selected for data encryption.
[0094] When the sensitivity classification label is a low security level, a lightweight encryption algorithm is used to encrypt data.
[0095] In this embodiment, the step of processing the edge node data using the differentiated encryption strategy to obtain the distributed adaptive encryption information is specifically implemented by the following steps:
[0096] S401: dynamically loading an algorithm engine using the differentiated encryption strategy to obtain a node matching encryption engine instance;
[0097] Specifically, according to the algorithm identifier in the differentiated encryption strategy and the hardware capability of the edge node, an encryption engine instance matching the capability of the edge node is selected through the algorithm library.
[0098] S402: Processing the node matching encryption engine instance through distributed key management distribution to obtain edge node encryption key parameters;
[0099] Specifically, through key sharding storage, Shamir secret sharing is used to split the master key into N parts and store them in a distributed manner on multiple nodes; dynamic key distribution is performed based on the MQTT protocol, and key rotation is used to trigger key updates every 24 hours or when the amount of encrypted data exceeds 1GB.
[0100] S403: Processing the edge node encryption key parameters by parallel encryption of data fragments to obtain fragmented encrypted data blocks;
[0101] S403-1: The shard controller processes the original data block of the edge node to obtain a plaintext shard set;
[0102] The plaintext fragment set is a plaintext fragment set carrying a fragment index;
[0103] S403-2: Processing the plaintext fragment set and the edge node encryption key parameter by a parallel encryption engine to generate a ciphertext fragment set;
[0104] S403-3: Process the ciphertext fragment set through metadata reassembly and encapsulation to output fragmented encrypted data blocks.
[0105] It should be noted that the metadata reassembly and encapsulation processing is to encapsulate the metadata according to the target transmission format through the protocol adapter based on the ciphertext shard set and the shard index, and output self-verifiable shard encrypted data blocks, wherein the metadata and the ciphertext shard are strongly bound through the index, and the protocol encapsulation ensures end-to-end compatibility.
[0106] S404: Synchronizing the sharded encrypted data blocks through a consensus protocol to obtain distributed adaptive encryption information.
[0107] Specifically, data hashes, encrypted node IDs, and timestamps are stored through a lightweight blockchain. The data integrity of the encrypted node is verified through MerkleProof, and cluster status synchronization is quickly completed through the Raft edge-optimized consensus protocol. If the encryption fails and the node is marked as unavailable, data re-encryption is triggered.
[0108] It should be noted that the distributed adaptive encryption information includes a globally consistent data encryption state record.
[0109] Example 2
[0110] An adaptive encryption management system in an edge computing environment includes a resource encryption evaluation matrix building module, a fuzzy decision network module, a data sensitivity classification module, and a differentiated encryption module;
[0111] The resource encryption evaluation matrix construction module is used to monitor edge node data in real time and construct a resource encryption evaluation matrix;
[0112] The fuzzy decision network module is used to dynamically adjust the resource encryption evaluation matrix through the fuzzy decision network to obtain encryption strength weight information;
[0113] The data sensitivity grading module is used to process the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy;
[0114] The differential encryption module is used to process the edge node data through the differential encryption strategy to obtain distributed adaptive encryption information.
[0115] The above description is merely a preferred embodiment of the present invention and does not constitute any form of limitation to the present invention. Although the present invention has been disclosed as a preferred embodiment as above, it is not intended to limit the present invention. Any person skilled in the art can make some changes or modifications to equivalent embodiments using the technical contents disclosed above without departing from the scope of the technical solution of the present invention. However, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention are still within the scope of the technical solution of the present invention.
Claims
1. An adaptive encryption management method in an edge computing environment, characterized in that: include: S1: monitor edge node data in real time and build a resource encryption assessment matrix based on the edge node data; S2: Dynamically adjust the resource encryption evaluation matrix through a fuzzy decision network to obtain encryption strength weight information; S3: Processing the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy; S4: Processing the edge node data using the differentiated encryption strategy to obtain distributed adaptive encryption information.
2. The adaptive encryption management method according to claim 1, characterized in that: The structure of the resource encryption evaluation matrix in step S1 is: The rows and columns of the resource encryption evaluation matrix are edge node numbers and resource encryption evaluation indicators respectively; the resource encryption evaluation indicators include node resource indicators, network status indicators, and security situation indicators.
3. The adaptive encryption management method according to claim 1, wherein: The generation process of the encryption strength weight information in step S2 is as follows: S201: Obtaining fuzzy encryption input variables according to the resource encryption evaluation matrix; S202: Obtaining an encryption strength weight value by dynamically reasoning the fuzzy encryption input variable through fuzzy reinforcement learning; S203: Obtain encryption strength weight information by dynamically correcting and feeding back the encryption strength weight value.
4. The adaptive encryption management method according to claim 3, wherein: The process of generating the encryption strength weight value in step S202 is as follows: S202-1: Preset initial fuzzy rule base; S202-2: fuzzy mapping the initial fuzzy rule base to process the fuzzy encrypted input variable to obtain an encryption trigger rule condition; S202-3: Optimizing the encryption trigger rule conditions through reinforcement learning to obtain dynamic encryption rule weights; S202-4: Processing the dynamic encryption rule weight according to the rule trigger strength to obtain a dynamic encryption strength; S202-5: Obtain an encryption strength weight value by defuzzifying the dynamic encryption strength.
5. The adaptive encryption management method according to claim 3, wherein: The process of dynamic correction feedback in step S203 is as follows: S203-1: Obtain encryption execution performance information and encryption execution security information through encryption monitoring; S203-2: Generate weight adjustment trigger state information by dynamically evaluating the encryption execution performance information and the encryption execution security information; S203-3: Execute the weight adjustment trigger state information through the policy engine to obtain encrypted weight correction data; S203-4: Verify the encryption weight correction data through encryption feedback to generate encryption strength weight information.
6. The adaptive encryption management method according to claim 1, wherein: The generation process of the differential encryption strategy in step S3 is as follows: S301: Processing the resource encryption evaluation matrix through dynamic sensitivity analysis to obtain a sensitivity classification label; S302: Mapping the sensitivity classification label through the encryption strength weight information to obtain a differentiated encryption strategy.
7. The adaptive encryption management method according to claim 6, characterized in that: The process of generating the sensitivity classification label in step S301 is as follows: S301-1: Processing the resource encryption evaluation matrix through sensitive entity extraction to obtain a preliminary sensitive entity set; S301-2: Processing the preliminary sensitive entity set through sensitivity grading to obtain sensitivity grading labels.
8. The adaptive encryption management method according to claim 1, wherein: The generation process of the distributed adaptive encryption information in step S4 is as follows: S401: dynamically loading an algorithm engine using the differentiated encryption strategy to obtain a node matching encryption engine instance; S402: Processing the node matching encryption engine instance through distributed key management distribution to obtain edge node encryption key parameters; S403: Processing the edge node encryption key parameters by parallel encryption of data fragments to obtain fragmented encrypted data blocks; S404: Synchronizing the sharded encrypted data blocks through a consensus protocol to obtain distributed adaptive encryption information.
9. The adaptive encryption management method according to claim 8, characterized in that: The process of generating the fragmented encrypted data block in step S403 is as follows: S403-1: The shard controller processes the original data block of the edge node to obtain a plaintext shard set; S403-2: Processing the plaintext fragment set and the edge node encryption key parameter by a parallel encryption engine to generate a ciphertext fragment set; S403-3: Process the ciphertext fragment set through metadata reassembly and encapsulation to output fragmented encrypted data blocks.
10. An adaptive encryption management system in an edge computing environment, the system being applied to the adaptive encryption management method according to any one of claims 1 to 9, characterized in that: It includes resource encryption assessment matrix building module, fuzzy decision network module, data sensitivity classification module, and differentiated encryption module: The resource encryption evaluation matrix construction module is used to monitor edge node data in real time and construct a resource encryption evaluation matrix; The fuzzy decision network module is used to dynamically adjust the resource encryption evaluation matrix through the fuzzy decision network to obtain encryption strength weight information; The data sensitivity grading module is used to process the encryption strength weight information through a data sensitivity grading model to generate a differentiated encryption strategy; The differential encryption module is used to process the edge node data through the differential encryption strategy to obtain distributed adaptive encryption information.