Dynamic encryption and authentication data transmission optimization method

Through monitoring nodes and machine learning to identify network threats and dynamically adjust encryption and authentication strategies, the low encryption problem caused by abnormal fluctuations in the network environment in the existing technology is solved, and high security and stability in malicious environments are achieved.

CN120455038AActive Publication Date: 2025-08-08CHINA YANGTZE POWER

Patent Information

Application Number
CN202510434545.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-08-08
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

The existing dynamic encryption mechanism is difficult to identify potential security threats when the network environment fluctuates abnormally, resulting in the system being maintained in a low encryption state for a long time and being easily stolen by attackers.

Method used

Through monitoring nodes, they collect multi-dimensional network environment data in real time, combine feature engineering and machine learning to evaluate network security situations, identify potential malicious attacks, and actively improve encryption strength and authentication level when attacks are detected, shorten the key update cycle, and combine multi-channel path switching and coordinated response to block risk propagation paths.

Benefits of technology

Effectively prevent sensitive data leakage, improve the security and stability of communication systems in malicious environments, reduce the risks of intermediary monitoring and brute-force cracking, and ensure the adaptive security of the system in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455038A_ABST
    Figure CN120455038A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic encryption and authentication data transmission optimization method, which relates to the technical field of information security and comprises the following steps of: planning and deploying monitoring nodes according to a topological structure and security protection requirements of a communication system; after deployment of monitoring nodes is completed, multi-dimensional network environment data information of a network layer and an application layer is collected in real time, the collected data is preprocessed, and a standardized data set is established. Multi-dimensional network environment data are collected in real time through the monitoring nodes, the network security situation is evaluated in combination with feature engineering and machine learning, and potential hostile attacks can be accurately recognized; when an attack behavior is detected, weak encryption degradation is actively prevented, the encryption strength and the authentication level are improved, the key updating period is shortened, and sensitive data leakage is effectively prevented; meanwhile, in combination with multi-channel path switching and collaborative response, a risk propagation path is isolated, an attack surface is reduced, and the security and stability of a communication system in a malicious environment are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data transmission optimization method with dynamic encryption and authentication. Background Art

[0002] "Data transmission optimization with dynamic encryption and authentication" refers to the real-time and flexible adjustment of encryption and authentication strategies and optimization of the data transmission process during the data transmission process, taking into account the network environment, transmission task characteristics, and security risk changes, so as to achieve improved transmission efficiency and communication performance while ensuring data security. Unlike traditional static encryption and fixed authentication mechanisms, dynamic encryption can intelligently select or adjust encryption algorithms, key lengths, encryption strengths, and even switch between different encryption protocols based on network conditions (such as bandwidth, latency, packet loss rate, etc.), attack risks (such as sniffing, hijacking, forgery, etc.), or data sensitivity; dynamic authentication can flexibly adjust authentication frequency and authentication methods (symmetric, asymmetric, multi-factor, etc.) based on node trust and environmental changes. At the same time, this method will also perform collaborative optimization in terms of transmission paths, data fragmentation, retransmission strategies, caching mechanisms, etc., to reduce the performance overhead brought by dynamic encryption and authentication, and achieve a balance between high security and high transmission efficiency.

[0003] Existing technologies have the following shortcomings: To adapt to complex and changing network environments, existing dynamic encryption mechanisms typically allow for dynamic adjustment of encryption strength during data transmission based on indicators such as network bandwidth, latency, and packet loss rate, in order to achieve a balance between security and transmission efficiency. For example, in a favorable network environment with high bandwidth and low latency, a high-strength encryption algorithm (such as 256-bit encryption) is used to ensure data security; whereas in a restricted network environment such as low bandwidth or high latency, a low-strength encryption algorithm (such as 128-bit or lower encryption) is automatically switched to reduce computational and transmission overhead. However, during the dynamic adjustment of encryption strength, existing technologies lack effective adaptive capabilities to environmental changes and attack risks. This is especially true when the network environment fluctuates abnormally (such as when attackers engage in malicious activities such as artificially creating congestion or faking high packet loss rates). Existing technologies typically adjust encryption strength based solely on network indicators, making it difficult to effectively identify abnormal network changes and potential security threats, resulting in the system being prone to maintaining a low-strength encryption state for long periods of time.

[0004] If the system runs in weak encryption mode for a long time, it is very easy for sensitive data to be obtained by attackers through man-in-the-middle monitoring, offline brute force cracking or other cryptanalysis methods, which seriously threatens the confidentiality of user data and the overall security of the system and brings unacceptable security risks.

[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the Invention

[0006] The purpose of the present invention is to provide a data transmission optimization method with dynamic encryption and authentication. By monitoring nodes to collect multi-dimensional network environment data in real time, and combining feature engineering and machine learning to evaluate network security situation, it can accurately identify potential malicious attacks; when attack behavior is detected, it actively prevents weak encryption degradation, improves encryption strength and authentication level, shortens the key update cycle, and effectively prevents sensitive data leakage; at the same time, combined with multi-channel path switching and coordinated response, it isolates risk propagation paths, reduces attack surfaces, and significantly improves the security and stability of communication systems in malicious environments to solve the problems in the above-mentioned background technology.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a data transmission optimization method with dynamic encryption and authentication, comprising the following steps:

[0008] Plan and deploy monitoring nodes based on the topology of the communication system and security protection requirements;

[0009] After the monitoring nodes are deployed, they collect multi-dimensional network environment data information at the network layer and application layer in real time, pre-process the collected data, and establish a standardized data set;

[0010] After obtaining high-quality pre-processed data, we extract key features that characterize potential malicious attacks on the current network from the data set through feature engineering, and perform quantitative analysis on the extracted key features;

[0011] The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to evaluate the security situation of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0012] When the assessment results show that there are malicious attacks in the current network environment, the dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. At the same time, the encryption strength of data transmission is proactively improved, authentication measures are added, and the key update cycle is shortened to improve the level of communication security protection from the source. In addition, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked, the attack surface is reduced, and it is ensured that the communication system maintains stable and reliable security protection capabilities under interference from malicious environments.

[0013] Preferably, the monitoring nodes are deployed according to the topology and security protection requirements of the communication system, and the specific steps include:

[0014] First, comprehensively analyze the topology of the communication system to clarify the boundaries of each network area, node distribution, communication links, key business flows, and key security areas;

[0015] Secondly, based on the types of security threats faced by the system, the sensitivity level of data, and business continuity requirements, determine the areas and communication links that require key monitoring and clarify the monitoring objectives;

[0016] Then, monitoring nodes are selected for different locations and deployed at key communication nodes to ensure full coverage of the target network environment;

[0017] Finally, plan the deployment strategy of the monitoring nodes, including the collaborative communication mechanism between nodes, data aggregation and reporting channel design, and performance and availability assurance solutions, to ensure that the operation of the monitoring nodes minimizes the impact on bandwidth and performance while ensuring real-time and reliability.

[0018] Preferably, after obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the data set through feature engineering. The extracted features include the changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate of the IPSec encryption negotiation phase. The changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate of the IPSec encryption negotiation phase are quantitatively analyzed to generate authentication retry reference values and encryption negotiation failure reference values respectively. The authentication retry reference values and encryption negotiation failure reference values are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behaviors in the current network environment.

[0019] Preferably, the specific steps of quantitatively analyzing the changing trend of the number of IP authentication retries per unit time to generate an authentication retry reference value are as follows:

[0020] During the communication process, the total energy consumption of any monitoring node on the communication path in a unit observation period is set to E i ,In order to quantify the abnormal changes in energy consumption, the node energy consumption increment factor is introduced, and the definition formula is as follows:

[0021]

[0022] Where, E i is the total energy consumption of the i-th node in the current observation period, is the energy consumption benchmark value of node i in the historical safe and stable state, ΔE i is the node energy consumption increment factor, which represents the rate of change of node i’s energy consumption relative to the baseline energy consumption in the current cycle;

[0023] Based on the node energy consumption increment factor ΔE i , combined with the authentication failure trigger situation, generate the authentication retry reference value, the generation formula is as follows:

[0024]

[0025] Where AARI is the authentication retry reference value, R i is the number of authentication retry triggers of the i-th node in the observation period, C i is the number of authentication retry source types observed by the i-th node, and n is the number of all nodes participating in the monitoring on the communication path.

[0026] Preferably, the specific steps of quantitatively analyzing the change curve of the failure rate in the IPSec encryption negotiation phase to generate the encryption negotiation failure reference value are as follows:

[0027] First, the collected original negotiation records of the IPSec protocol encryption negotiation phase are processed. Suppose that N negotiation events are observed in one analysis cycle, and the result of each negotiation is expressed as S. j Indicates that when the i-th negotiation fails, S j =1, when successful S j =0; To characterize the cumulative and abnormal nature of recent negotiation failures, a negotiation failure increment factor is constructed, and the calculation expression is as follows:

[0028]

[0029] Where F-IF is the negotiation failure increment factor, S j is the jth negotiation result, where failure is recorded as 1 and success is recorded as 0. N is the total number of negotiations in the current analysis period;

[0030] After obtaining the negotiation failure increment factor F-IF, we further improve the sensitivity to continuous abnormal failures by introducing the maximum continuous failure segment length and the number of successful negotiations as additional features to construct the encryption negotiation failure reference value. The calculation expression is as follows:

[0031]

[0032] Where CENFI is the encryption negotiation failure reference value, M is the maximum length of consecutive negotiation failures within the analysis period, and K is the total number of successful negotiations within the analysis period.

[0033] Preferably, the authentication retry reference value and encryption negotiation failure reference value after quantitative analysis are input into a pre-trained machine learning model, and the network environment security risk coefficient is generated by the machine learning model. The security situation of the current network environment is evaluated by the network security risk coefficient to determine whether there is potential malicious attack in the current network environment.

[0034] Preferably, the network security risk coefficient generated when the security situation of the current network environment is evaluated by a pre-trained machine learning model is compared with a pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows;

[0035] If the network security risk factor is greater than the pre-set network security risk factor reference threshold, it is determined that there is a malicious attack in the current network environment;

[0036] If the network security risk factor is less than or equal to a preset network security risk factor reference threshold, it is determined that there is no malicious attack in the current network environment.

[0037] Preferably, when the assessment results indicate the presence of malicious attacks in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. The mechanism also proactively improves the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle. Furthermore, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked and the attack surface is reduced. The specific steps are as follows:

[0038] When a malicious attack is detected in the current network environment, the security policy is automatically adjusted according to the risk level to improve the encryption and authentication strength during the communication process. The encryption and authentication level calculation expression is as follows:

[0039]

[0040] Where S is the security level, which indicates the encryption and authentication strength level adopted by the current system, S0 is the initial security level, NSRI is the network security risk factor, and S max is the maximum safety level, α is the safety gain factor, T s (θ, λ) is the dynamic security reference threshold, indicating the upper limit of risk tolerance, θ is the service level factor, λ is the load factor, and γ is the security index magnification factor;

[0041] After completing the security level control, we further isolate the risk propagation path, dynamically select the optimal communication path through the multi-channel mechanism, and suppress the probability of using the risk channel. The communication weight calculation expression of each channel is as follows:

[0042]

[0043] Where w q is the routing weight of the qth communication channel in multi-channel scheduling, r q is the real-time risk assessment value of the qth communication channel, β is the entropy adjustment factor, M is the total number of communication channels, r p is the real-time risk assessment value of the p-th communication channel.

[0044] In the above technical solution, the technical effects and advantages provided by the present invention are:

[0045] The present invention fundamentally eliminates the problem that existing dynamic encryption technology relies solely on network performance indicators and is easily induced by attackers to be in a weak encryption state for a long time through accurate identification and real-time response to abnormal changes in the network environment and attack behaviors, thereby ensuring the adaptive improvement of system security in complex malicious network environments. At the same time, the method can also actively perform security protection regulation, improve the encryption strength and authentication measures in the data transmission process, shorten the key update cycle, and timely block the risk diffusion path through multi-channel path switching and coordinated response means, effectively reducing the security risks of sensitive data being monitored by middlemen, brute force cracking or data tampering, and significantly improving the overall security and stability of the communication system in malicious interference environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction to the drawings required for use in the embodiments will be given below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0047] Figure 1 This is a flow chart of a method for optimizing data transmission using dynamic encryption and authentication according to the present invention.

[0048] Figure 2 This is a method mind map of a dynamic encryption and authentication data transmission optimization method of the present invention. DETAILED DESCRIPTION

[0049] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these example embodiments are provided so that the description of this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art.

[0050] The present invention provides Figure 1 A data transmission optimization method with dynamic encryption and authentication is shown, comprising the following steps:

[0051] Plan and deploy monitoring nodes based on the topology of the communication system (such as the distribution of LAN, WAN, cloud and edge nodes, VPN or private network configuration) and security protection requirements;

[0052] These monitoring nodes can be independent hardware probes or software agents, deployed at key network traffic nodes or critical links to achieve comprehensive monitoring of the communication system. Through reasonable layout in each core link, it is possible to achieve extensive coverage of the network environment, collect multi-dimensional and full-path network data, and ensure comprehensive perception of abnormal behavior. At the same time, the monitoring nodes have the ability to collect and report data in real time or periodically, and can promptly transmit monitoring data back to the central system for analysis, ensuring the timeliness and effectiveness of the data. In addition, by scientifically planning the deployment density and location of monitoring nodes, the existence of monitoring blind spots can be effectively reduced, reducing the risk of undetected attacks due to missed detection. During the deployment process, full consideration must also be given to network bandwidth, load balancing, system disaster recovery capabilities, and deployment costs to prevent the monitoring nodes themselves from becoming a network burden or a new single point of failure, ensuring the stability and high availability of the monitoring system.

[0053] Monitoring nodes are deployed according to the topology of the communication system and the security protection requirements. The specific steps include: first, comprehensively analyze the topology of the communication system to clarify the boundaries, node distribution, communication links, key business flows and security key areas of each network area, such as core switching areas, Internet exits, edge access nodes, cloud service interfaces, etc.; second, based on the types of security threats faced by the system, data sensitivity levels and business continuity requirements, determine the areas and communication links that need to be monitored, and clarify the monitoring targets (such as traffic anomaly detection, attack behavior identification, encryption policy tracking, etc.); then, select monitoring nodes for different locations, such as hardware traffic probes, software agents, distributed sensors, etc., and deploy them at key communication nodes to ensure comprehensive coverage of the target network environment; finally, plan the deployment strategy of the monitoring nodes, including the collaborative communication mechanism between nodes, data aggregation and reporting channel design, performance and availability assurance plan, to ensure that the operation of the monitoring nodes minimizes the impact on the system bandwidth and performance, while ensuring real-time and reliability.

[0054] After the monitoring nodes are deployed, they collect multi-dimensional network environment data information at the network layer and application layer in real time, pre-process the collected data, and establish a standardized data set;

[0055] The collected data includes network-layer metrics (such as bandwidth utilization, packet loss rate, round-trip time (RTT), and congestion window changes) and application-layer metrics (such as response time, request / response error rates, exception log information, and user behavior characteristics). This enables multi-layered, comprehensive monitoring of the communication system, from the network to the application, providing comprehensive awareness of network operational status and a complete understanding of the environment. By monitoring these multi-dimensional metrics in real time, the system can promptly detect subtle changes such as traffic surges, network congestion, and abnormal retransmissions in high-concurrency or attack-threat environments, providing a reliable basis for subsequent feature extraction and attack identification. Rich and granular network environment data provides more accurate and comprehensive context for feature engineering and machine learning model training and judgment, significantly improving attack identification accuracy and the system's adaptability. In the actual collection process, a hierarchical collection strategy should be designed based on the sensitivity and importance of the data. High-frequency sampling should be applied to key nodes and key metrics, while low-frequency sampling can be used for less important nodes. This approach balances system performance overhead with security requirements while ensuring real-time performance and accuracy.

[0056] Collected raw network environment data often suffers from noise, high redundancy, and inconsistent formats. Therefore, comprehensive data preprocessing is required. The cleaned and standardized data is then stored in a unified dataset to provide high-quality foundational data for subsequent analysis. During preprocessing, data cleaning and denoising are first performed to filter out obvious errors, missing data, or anomalies, and to smooth out extreme values to ensure the accuracy and stability of analytical results. Secondly, standardization and normalization are used to convert data of varying formats and magnitudes into unified feature values or indicators, addressing discrepancies in dimensionality and ranges between indicators. Furthermore, during the training phase, if supervised learning is required, data can be annotated and stratified based on time, network scenario, and user group dimensions to facilitate subsequent feature engineering and model building. In practical systems, data preprocessing must balance efficiency and scalability. Especially in large-scale distributed environments, distributed computing frameworks such as Spark and Flink are recommended to ensure real-time, consistent, and reliable processing of massive data volumes, providing solid data support for intelligent system assessment and dynamic security control.

[0057] After obtaining high-quality pre-processed data, we extract key features that characterize potential malicious attacks on the current network from the data set through feature engineering, and perform quantitative analysis on the extracted key features;

[0058] After obtaining high-quality preprocessed data, key features that characterize potential malicious attacks on the current network are extracted from the data set through feature engineering. The extracted features include the changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate in the IPSec encryption negotiation phase. The changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate in the IPSec encryption negotiation phase are quantitatively analyzed to generate authentication retry reference values and encryption negotiation failure reference values respectively. The authentication retry reference values and encryption negotiation failure reference values are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behaviors in the current network environment.

[0059] Abnormally high authentication retries for a specific IP address within a specific timeframe can often be a key indicator of potential malicious attacks on the network. This is because the number of authentication failures experienced by normal users is generally limited and distributed over a relatively long period of time. However, abnormally high authentication retries are often closely associated with brute force attacks, illegal authentication attempts after session hijacking, or identity forgery. Attackers often use automated tools to conduct large-scale, short-term, repeated authentication attempts against target systems in an attempt to obtain valid authentication credentials or session tokens, thereby achieving unauthorized access or illegal operations. This behavior not only causes a significant increase in authentication retries within a short period of time, but may also be accompanied by significant abnormalities in retry rates and failure rates, far exceeding the operational habits and behavioral patterns of normal users. Therefore, abnormally high IP authentication retries within a specific timeframe are a typical behavioral indicator of an active attacker, directly indicating the presence of a potential security threat in the network environment and providing important insights for subsequent intrusion detection, risk assessment, and dynamic security policy adjustments.

[0060] The specific steps for quantitatively analyzing the trend of IP authentication retry times per unit time and generating a reference value for authentication retry times are as follows:

[0061] During the communication process, the total energy consumption of any monitoring node on the communication path in a unit observation period is set to E i Energy consumption can be derived from comprehensive indicators of resource consumption such as the node's CPU load, memory consumption, interface traffic, and authentication module activity (which can be obtained through a variety of measurement tools). To quantify abnormal changes in energy consumption, a node energy consumption increment factor is introduced, and the definition formula is as follows:

[0062]

[0063] Where, E i is the total energy consumption of the i-th node in the current observation period, is the energy consumption benchmark value of node i in the historical safe and stable state, ΔEi is the node energy consumption increment factor, which represents the rate of change of node i’s energy consumption relative to the baseline energy consumption in the current cycle;

[0064] The above steps directly quantify the relative increase in the current energy consumption of each node on the communication path compared to the baseline level. i >0 and is large, indicating that the node energy consumption is abnormally increased, which may be related to frequent authentication retries, attack traffic, abnormal control requests, etc., without the need to model the average or standard deviation of the energy consumption value, and has stronger instantaneous sensitivity and interpretability.

[0065] Based on the node energy consumption increment factor ΔE i , combined with the authentication failure trigger situation, generate the authentication retry reference value, the generation formula is as follows:

[0066]

[0067] Where AARI is the authentication retry reference value, R i is the number of authentication retry triggers of the i-th node in the observation period, C i is the number of authentication retry source types observed by the i-th node (such as IP address, user ID, terminal ID, etc.), and n is the number of all nodes participating in the monitoring on the communication path.

[0068] By combining the degree of abnormal node energy consumption, the frequency of authentication retries, and the diversity of retry sources, we generate a comprehensive authentication retry reference value, which comprehensively reflects the security risks caused by abnormal authentication behavior in the current network. This reference value can effectively distinguish normal occasional authentication failures from malicious attacks caused by attackers forging multiple sources of identity and frequent attempts, providing a reliable basis for subsequent dynamic security regulation.

[0069] The larger the authentication retry reference value generated by quantitatively analyzing the changing trend of the number of IP authentication retries per unit time, the more abnormal the authentication retry behavior in the network. This is often caused by malicious attackers using automated tools to perform brute force attacks, forge identities, or hijack sessions. This abnormal authentication retry behavior not only leads to frequent identity failures, but also causes nodes to consume a large amount of energy in a short period of time, exceeding the range that can be explained by normal communication traffic, thus reflecting a potential security threat. Conversely, when the authentication retry reference value remains at a low level, it indicates that the energy consumption rate of each node on the communication path is in a normal fluctuation state, and there are no obvious authentication anomalies or energy consumption surges. It can be considered that the current network is not at risk of malicious attacks.

[0070] When the failure rate curve during the IPSec encryption negotiation phase shows a significant upward trend, it can generally be considered that the current network environment is vulnerable to potential malicious attacks. This is because, under normal circumstances, encryption negotiations between the two parties should proceed stably, with a low failure rate. However, an abnormally high failure rate may indicate man-in-the-middle interference, forged negotiation packets, or downgrade attacks. Attackers often actively inject, tamper with, or replay packets during the negotiation process, preventing the two parties from successfully establishing a secure connection and significantly increasing the failure rate. Such attacks aim to disrupt the normal security negotiation process, forcing the communicating parties to downgrade to a weaker encryption mode or completely terminate the encryption negotiation, creating opportunities for subsequent data eavesdropping, tampering, or offline cracking. Therefore, monitoring an upward trend in the encryption negotiation failure rate can serve as an important indicator for detecting and warning of potential malicious attacks, providing a basis for implementing subsequent protective measures such as dynamic security regulation, enhanced identity authentication, and security policy switching, thereby mitigating the risk of attackers exploiting negotiation failures to compromise communication security at the source.

[0071] The specific steps for quantitatively analyzing the IPSec encryption negotiation failure rate curve to generate an encryption negotiation failure reference value are as follows:

[0072] First, the collected original negotiation records of the IPSec protocol encryption negotiation phase are processed. Suppose that N negotiation events are observed in one analysis cycle, and the result of each negotiation is expressed as S. j Indicates that when the i-th negotiation fails, S j =1, when successful S j =0; To characterize the cumulative and abnormal nature of recent negotiation failures, a negotiation failure increment factor is constructed, and the calculation expression is as follows:

[0073]

[0074] Where F-IF is the negotiation failure increment factor, S j is the jth negotiation result, where failure is recorded as 1 and success is recorded as 0. N is the total number of negotiations in the current analysis period;

[0075] By introducing a quadratic weight for the negotiation sequence number, each negotiation result during the IPSec encryption negotiation phase is weighted, highlighting the impact of recent negotiation failures on the system's security posture. By calculating the negotiation failure increment factor, this effectively quantifies potential, time-concentrated, anomalies in encryption negotiation behavior within the network, providing key features for identifying subsequent malicious attacks.

[0076] After obtaining the negotiation failure increment factor F-IF, we further improve the sensitivity to continuous abnormal failures by introducing the maximum continuous failure segment length and the number of successful negotiations as additional features to construct the encryption negotiation failure reference value. The calculation expression is as follows:

[0077]

[0078] Where CENFI is the encryption negotiation failure reference value, M is the maximum length of the segment with consecutive negotiation failures during the analysis period, that is, the maximum number of consecutive failures observed, and K is the total number of successful negotiations during the analysis period.

[0079] By introducing the maximum length of consecutive negotiation failures and the number of successful negotiations, combined with a negotiation failure increment factor, we construct a cryptographic negotiation failure reference value that comprehensively reflects the abnormality and continuity characteristics of the negotiation process. This step can effectively identify continuous negotiation failures caused by man-in-the-middle attacks, downgrade attacks, and other behaviors, providing a precise basis for anomaly determination for subsequent dynamic security regulation.

[0080] A larger encryption negotiation failure reference value, generated by quantitatively analyzing the IPSec encryption negotiation failure rate curve, indicates a higher frequency of negotiation failures within the specified time window. This abnormal increase is often associated with malicious attacks, such as man-in-the-middle attacks, forged negotiation packets, or forced downgrade attacks. These attacks intentionally disrupt the normal encryption negotiation process, preventing both parties from successfully establishing a secure connection. Conversely, a lower encryption negotiation failure reference value indicates a stable negotiation process with a low failure rate, typically indicating a lack of significant malicious interference or attacks in the current network environment.

[0081] The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to evaluate the security situation of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0082] The authentication retry reference value and encryption negotiation failure reference value after quantitative analysis are input into the pre-trained machine learning model. The network environment security risk coefficient is generated by the machine learning model. The security situation of the current network environment is evaluated by the network security risk coefficient to determine whether there is potential malicious attack in the current network environment.

[0083] A pre-trained machine learning model is trained offline before implementation using historical network data, simulated attack samples, and various data from normal and abnormal communication environments. This model is trained using machine learning algorithms (such as random forests, support vector machines, deep neural networks, or other statistical learning models) to build a predictive model capable of automatically identifying security risk characteristics in a network environment. During the training process, researchers divide the pre-processed dataset into training, validation, and test sets according to a specific ratio. Key metrics extracted through feature engineering (such as authentication retry thresholds and encryption negotiation failure thresholds) serve as input features, and output labels representing known attack events, abnormal conditions, or normal conditions. The model continuously learns and optimizes its internal parameters through iterations, ultimately outputting a prediction reflecting the security risk profile of the current network environment when presented with new input data. This process is similar to "infusing" the model with security expertise, allowing it to extract patterns and patterns from complex data that reveal potential malicious attacks. This allows the model to quickly and efficiently determine whether a network environment is vulnerable to potential threats in real-world operations. After the trained model is deployed online, there is no need to rely on experts to set tedious rules. Instead, it analyzes real-time data through an automated prediction mechanism, thereby achieving real-time monitoring and assessment of the network security situation.

[0084] Pre-trained machine learning models are highly valuable in practical applications. Based on quantitatively analyzed key features, such as authentication retry reference values and encryption negotiation failure reference values, they intelligently process input network environment data to generate a network security risk factor. This risk factor intuitively reflects the severity of potential malicious attacks or abnormal behavior in the current network environment. When the model detects that input features match patterns previously observed in abnormal or attack environments, the risk factor increases significantly, triggering subsequent security response measures such as preventing weak encryption downgrades, increasing encryption strength, adding authentication methods, and initiating multi-channel switching. In other words, this pre-trained model not only enables rapid analysis of real-time data but also leverages historical experience and pattern recognition to provide early warning of potential security risks, providing robust data support and decision-making for the entire network security protection system. Leveraging this model, the system can dynamically and intelligently assess network security trends, enabling timely implementation of appropriate security strategies in complex and changing network environments, effectively mitigating potential attack risks and ensuring a consistently high level of security for the communication system.

[0085] The machine learning model is not limited here. Any machine learning model that can comprehensively analyze the authentication retry reference value AARI and the encryption negotiation failure reference value CENFI to generate the network security risk coefficient NSRI can be used. To implement the technical solution of the present invention, the present invention provides a specific implementation method.

[0086] The formula for generating the network security risk factor NSRI is as follows:

[0087]

[0088] Where s a and s b are the preset proportional coefficients of the authentication retry reference value AARI and the encryption negotiation failure reference value CENFI, and s a and s b Both are greater than 0.

[0089] The preset scale factor s here a and s b Refers to the weighting parameters used to set the degree of impact of the authentication retry reference value AARI and the encryption negotiation failure reference value CENFI on the overall network security risk when generating the network security risk coefficient NSRI. Specifically, these two coefficients represent the proportional values set in advance by the system designer based on empirical knowledge, historical data, or the security requirements of actual scenarios when conducting a comprehensive assessment of the current network environment security status. This setting method allows the system to flexibly adjust and clearly express the relative importance of different characteristic indicators to the overall risk assessment, thereby more effectively capturing and highlighting key security threats or attack behaviors in the network environment during the assessment process, helping the system to more accurately adopt dynamic security control measures.

[0090] It can be seen from the network security risk coefficient that the larger the authentication retry reference value generated by quantitative analysis of the changing trend of the number of IP authentication retries per unit time, and the larger the encryption negotiation failure reference value generated after quantitative analysis of the changing curve of the failure rate in the IPSec encryption negotiation phase, the larger the network security risk coefficient generated when evaluating the security situation of the current network environment using a pre-trained machine learning model, indicating that the risk of malicious attacks in the current network environment is higher, and vice versa, indicating that the risk of malicious attacks in the current network environment is lower.

[0091] The network security risk coefficient generated by the pre-trained machine learning model when evaluating the security situation of the current network environment is compared with the pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows:

[0092] If the network security risk factor is greater than the pre-set network security risk factor reference threshold, it is determined that there is a malicious attack in the current network environment;

[0093] If the network security risk factor is less than or equal to a preset network security risk factor reference threshold, it is determined that there is no malicious attack in the current network environment.

[0094] When the assessment results indicate the presence of malicious attacks in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. The mechanism also proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle, thereby enhancing communication security protection from the source. Furthermore, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked, the attack surface is reduced, and the communication system maintains stable and reliable security protection capabilities even under interference from malicious environments.

[0095] After detecting malicious attacks in the network environment, the system proactively adjusts security policies through intelligent response mechanisms, comprehensively improving the system's defense capabilities from multiple dimensions, blocking the attack chain, strengthening communication security, and maintaining stable system operation. Specifically, first, the system will prevent automatic encryption strength degradation caused by network fluctuations or performance degradation, preventing attackers from creating illusions of high latency, congestion, or packet loss to induce the system into a weak encryption state, thereby creating an attack breakthrough. Second, the system will proactively increase the encryption strength of data transmission, such as switching from 128-bit symmetric encryption to 256-bit or enabling more secure asymmetric encryption suites, and increase authentication methods, including multi-factor authentication, dynamic challenge-response mechanisms, and session behavior verification, to ensure the credibility of communication participants at the identity level. At the same time, the system will shorten the key update cycle, accelerate key rotation speed, reduce the window of exploitation after key leakage, and enhance resistance to attacks such as man-in-the-middle eavesdropping and offline cracking. Furthermore, to prevent attacks from spreading laterally across the network, this mechanism also leverages multi-channel path switching and coordinated defense mechanisms, such as dynamic routing reconstruction, isolation of high-risk links, and traffic redistribution. This severs attack propagation paths, reduces the attack surface, and effectively safeguards the availability and data integrity of core communication links. Overall, this process, upon detecting an attack, rapidly establishes a multi-layered, three-dimensional dynamic security protection system, ensuring that the communication system maintains stable, reliable, and adaptive security protection capabilities even in a hostile environment, providing a solid foundation for business continuity.

[0096] When the assessment results indicate the presence of malicious attacks in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. The mechanism also proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle. Furthermore, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked and the attack surface is reduced. The specific steps are as follows:

[0097] When a malicious attack is detected in the current network environment, the security policy is automatically adjusted according to the risk level to improve the encryption and authentication strength during the communication process. The encryption and authentication level calculation expression is as follows:

[0098]

[0099] Where S is the security level, which indicates the encryption and authentication strength level adopted by the current system, S0 is the initial security level, NSRI is the network security risk factor, and S max is the maximum security level, which indicates the maximum security policy level allowed by the system design. α is the security gain coefficient, which is used to control the impact of the risk factor on the security level improvement. T s (θ, λ) is the dynamic security reference threshold, representing the upper limit of risk tolerance. θ is the service level factor, indicating the importance of the current communication service, such as core service, ordinary service, and low-priority service. λ is the load factor, reflecting the level of system resource utilization (such as CPU, memory, and link utilization). γ is the security exponential amplification factor, an exponential amplification parameter used to increase response sensitivity in high-risk situations.

[0100] The above steps nonlinearly increase the security protection level based on the risk level, preventing low-strength encryption from being exploited by attackers in high-risk scenarios, while preventing performance loss caused by excessive encryption, and achieving a dynamic balance between performance and security.

[0101] After completing the security level control, we further isolate the risk propagation path, dynamically select the optimal communication path through the multi-channel mechanism, and suppress the probability of using the risk channel. The communication weight calculation expression of each channel is as follows:

[0102]

[0103] Where w q is the routing weight of the qth communication channel in multi-channel scheduling, r q is the real-time risk assessment value of the qth communication channel, reflecting the current security threat level of the channel, β is the entropy adjustment factor, and is the adjustment risk value r q For channel weight w q The coefficient of influence strength, M is the total number of communication channels, r p is the real-time risk assessment value of the p-th communication channel.

[0104] The above steps dynamically adjust channel usage weights to effectively avoid high-risk channels, limit the spread of attack paths, and ensure that data traffic preferentially passes through low-risk channels, thereby achieving security optimization of communication paths and compression of attack surfaces.

[0105] The present invention fundamentally eliminates the problem that existing dynamic encryption technology relies solely on network performance indicators and is easily induced by attackers to be in a weak encryption state for a long time through accurate identification and real-time response to abnormal changes in the network environment and attack behaviors, thereby ensuring the adaptive improvement of system security in complex malicious network environments. At the same time, the method can also actively perform security protection regulation, improve the encryption strength and authentication measures in the data transmission process, shorten the key update cycle, and timely block the risk diffusion path through multi-channel path switching and coordinated response means, effectively reducing the security risks of sensitive data being monitored by middlemen, brute force cracking or data tampering, and significantly improving the overall security and stability of the communication system in malicious interference environments.

[0106] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.

[0107] The above description is merely illustrative of certain exemplary embodiments of the present invention. It goes without saying that those skilled in the art will be able to modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims.

[0108] It should be noted that, in this document, if there are relational terms such as first and second, etc., they are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device that includes the element.

[0109] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0110] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0111] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0112] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0113] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0114] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0115] The above description is merely illustrative of certain exemplary embodiments of the present invention. It goes without saying that those skilled in the art will be able to modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims.

Claims

1. A data transmission optimization method with dynamic encryption and authentication, characterized in that: The following steps are involved: Plan and deploy monitoring nodes based on the topology of the communication system and security protection requirements; After the monitoring nodes are deployed, they collect multi-dimensional network environment data information at the network layer and application layer in real time, pre-process the collected data, and establish a standardized data set; After obtaining high-quality pre-processed data, we extract key features that characterize potential malicious attacks on the current network from the data set through feature engineering, and perform quantitative analysis on the extracted key features; The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to evaluate the security situation of the current network environment and determine whether there are potential malicious attacks in the current network environment. When the assessment results show that there are malicious attacks in the current network environment, the dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. At the same time, the encryption strength of data transmission is proactively improved, authentication measures are added, and the key update cycle is shortened to improve the level of communication security protection from the source. In addition, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked, the attack surface is reduced, and it is ensured that the communication system maintains stable and reliable security protection capabilities under interference from malicious environments.

2. The data transmission optimization method of dynamic encryption and authentication according to claim 1, characterized in that: Deploy monitoring nodes based on the topology and security protection requirements of the communication system. The specific steps include: First, comprehensively analyze the topology of the communication system to clarify the boundaries of each network area, node distribution, communication links, key business flows, and key security areas; Secondly, based on the types of security threats faced by the system, the sensitivity level of data, and business continuity requirements, determine the areas and communication links that require key monitoring and clarify the monitoring objectives; Then, monitoring nodes are selected for different locations and deployed at key communication nodes to ensure full coverage of the target network environment; Finally, plan the deployment strategy of the monitoring nodes, including the collaborative communication mechanism between nodes, data aggregation and reporting channel design, and performance and availability assurance solutions, to ensure that the operation of the monitoring nodes minimizes the impact on bandwidth and performance while ensuring real-time and reliability.

3. The data transmission optimization method of dynamic encryption and authentication according to claim 1, characterized in that: After obtaining high-quality preprocessed data, key features that characterize potential malicious attacks on the current network are extracted from the data set through feature engineering. The extracted features include the changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate in the IPSec encryption negotiation phase. The changing trend of the number of IP authentication retries per unit time and the changing curve of the failure rate in the IPSec encryption negotiation phase are quantitatively analyzed to generate authentication retry reference values and encryption negotiation failure reference values respectively. The authentication retry reference values and encryption negotiation failure reference values are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behaviors in the current network environment.

4. The data transmission optimization method of dynamic encryption and authentication according to claim 3, characterized in that: The specific steps for quantitatively analyzing the trend of IP authentication retry times per unit time and generating a reference value for authentication retry times are as follows: During the communication process, the total energy consumption of any monitoring node on the communication path in a unit observation period is set to E i ,In order to quantify the abnormal changes in energy consumption, the node energy consumption increment factor is introduced, and the definition formula is as follows: Where, E i is the total energy consumption of the i-th node in the current observation period, is the energy consumption benchmark value of node i in the historical safe and stable state, ΔE i is the node energy consumption increment factor, which represents the rate of change of node i’s energy consumption relative to the baseline energy consumption in the current cycle; Based on the node energy consumption increment factor ΔE i , combined with the authentication failure trigger situation, generate the authentication retry reference value, the generation formula is as follows: Where AARI is the authentication retry reference value, R i is the number of authentication retry triggers of the i-th node in the observation period, C i is the number of authentication retry source types observed by the i-th node, and n is the number of all nodes participating in the monitoring on the communication path.

5. The data transmission optimization method of dynamic encryption and authentication according to claim 3, characterized in that: The specific steps for quantitatively analyzing the IPSec encryption negotiation failure rate curve to generate an encryption negotiation failure reference value are as follows: First, the collected original negotiation records of the IPSec protocol encryption negotiation phase are processed. Suppose that N negotiation events are observed in one analysis cycle, and the result of each negotiation is expressed as S. j Indicates that when the i-th negotiation fails, S j =1, when successful S j =0; To characterize the cumulative and abnormal nature of recent negotiation failures, a negotiation failure increment factor is constructed, and the calculation expression is as follows: Where F-IF is the negotiation failure increment factor, S j is the jth negotiation result, where failure is recorded as 1 and success is recorded as 0. N is the total number of negotiations in the current analysis period; After obtaining the negotiation failure increment factor F-IF, we further improve the sensitivity to continuous abnormal failures by introducing the maximum continuous failure segment length and the number of successful negotiations as additional features to construct the encryption negotiation failure reference value. The calculation expression is as follows: Where CENFI is the encryption negotiation failure reference value, M is the maximum length of consecutive negotiation failures within the analysis period, and K is the total number of successful negotiations within the analysis period.

6. The data transmission optimization method with dynamic encryption and authentication according to claim 3, characterized in that: The authentication retry reference value and encryption negotiation failure reference value after quantitative analysis are input into the pre-trained machine learning model. The network environment security risk coefficient is generated by the machine learning model. The security situation of the current network environment is evaluated by the network security risk coefficient to determine whether there is potential malicious attack in the current network environment.

7. The data transmission optimization method of dynamic encryption and authentication according to claim 6, characterized in that: The network security risk coefficient generated by the pre-trained machine learning model when evaluating the security situation of the current network environment is compared with the pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows: If the network security risk factor is greater than the pre-set network security risk factor reference threshold, it is determined that there is a malicious attack in the current network environment; If the network security risk factor is less than or equal to a preset network security risk factor reference threshold, it is determined that there is no malicious attack in the current network environment.

8. The data transmission optimization method with dynamic encryption and authentication according to claim 7, characterized in that: When the assessment results indicate the presence of malicious attacks in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption degradation caused by network fluctuations. The mechanism also proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle. Furthermore, through multi-channel path switching and coordinated response measures, the risk diffusion path is blocked and the attack surface is reduced. The specific steps are as follows: When it is determined that there is a malicious attack in the current network environment, the security policy is automatically adjusted according to the risk level to improve the encryption and authentication strength during the communication process. The encryption and authentication level calculation expression is as follows: Where S is the security level, which indicates the encryption and authentication strength level adopted by the current system, S0 is the initial security level, NSRI is the network security risk factor, and S max is the maximum safety level, α is the safety gain factor, T s (θ, λ) is the dynamic security reference threshold, indicating the upper limit of risk tolerance, θ is the service level factor, λ is the load factor, and γ is the security index magnification factor; After completing the security level control, we further isolate the risk propagation path, dynamically select the optimal communication path through the multi-channel mechanism, and suppress the probability of using the risk channel. The communication weight calculation expression of each channel is as follows: Where w q is the routing weight of the qth communication channel in multi-channel scheduling, r q is the real-time risk assessment value of the qth communication channel, β is the entropy adjustment factor, M is the total number of communication channels, r p is the real-time risk assessment value of the p-th communication channel.

Citation Information

Patent Citations

  • Process for secure transmission

    CA2469426A1

  • Encryption method of train controller

    CN113225179A

  • Underwater wireless sensor network trust evaluation method based on variable membership function

    CN116546498A

  • Data security protection method based on link layer transparent encryption

    CN119254454A

  • Security encryption transmission system for game data

    CN119561787A

Cited By

  • Network data transmission encryption system and method in industrial computer communication

    CN120614660A

  • Adaptive security monitoring method, system and program product

    CN120856461A

  • Wearable vitamin D intelligent synthesis physiotherapy instrument based on phototherapy

    CN121041602A

  • 5G network dynamic security capability scheduling method based on deep learning

    CN121078436A