A dynamic encryption and authentication data transmission optimization method

By monitoring nodes and using machine learning to identify network threats and dynamically adjusting encryption and authentication strategies, the low encryption problem caused by abnormal fluctuations in the network environment in existing technologies is solved, achieving high security and stability in malicious environments.

CN120455038BActive Publication Date: 2025-11-25CHINA YANGTZE POWER
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510434545.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-11-25
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

Existing dynamic encryption mechanisms struggle to identify potential security threats when the network environment fluctuates abnormally, causing the system to remain in a low-strength encryption state for extended periods, making it vulnerable to attackers stealing sensitive data.

Method used

By collecting multi-dimensional network environment data in real time through monitoring nodes, combining feature engineering and machine learning to assess network security status, identify potential malicious attacks, and trigger dynamic security control mechanisms, the encryption strength and authentication level are improved, the key update cycle is shortened, and multi-channel path switching and collaborative response measures are used to block the spread of risks.

Benefits of technology

Effectively prevents the leakage of sensitive data, enhances the security and stability of communication systems in malicious environments, and ensures that the system adaptively improves its security protection level in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455038B_ABST
    Figure CN120455038B_ABST
Patent Text Reader

Abstract

The application discloses a kind of dynamic encryption and authentication data transmission optimization method, it is related to information security technical field, including the following steps: according to the topology of communication system and security protection demand, monitoring node is planned and deployed;After the deployment of monitoring node, real-time acquisition network layer and application layer multidimensional network environment data information, and the data collected are preprocessed, and the standardized data set is established.The application can accurately identify potential malicious attacks by real-time acquisition of multidimensional network environment data by monitoring node, combined with feature engineering and machine learning to evaluate network security posture;When detecting attack behavior, actively prevent weak encryption degradation, improve encryption strength and authentication level, shorten key update cycle, effectively prevent sensitive data leakage;At the same time, combined with multi-channel path switching and collaborative response, isolate risk propagation path, reduce attack surface, significantly improve the security and stability of communication system in malicious environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and specifically to a data transmission optimization method with dynamic encryption and authentication. Background Technology

[0002] "Dynamic encryption and authentication data transmission optimization" refers to the real-time and flexible adjustment of encryption and authentication strategies during data transmission, taking into account changes in network environment, transmission task characteristics, and security risks. This optimization aims to improve transmission efficiency and communication performance while ensuring data security. Unlike traditional static encryption and fixed authentication mechanisms, dynamic encryption can intelligently select or adjust encryption algorithms, key lengths, encryption strength, and even switch between different encryption protocols based on network conditions (such as bandwidth, latency, and packet loss rate), attack risks (such as sniffing, hijacking, and forgery), or data sensitivity. Dynamic authentication can flexibly adjust authentication frequency and authentication methods (symmetric, asymmetric, multi-factor, etc.) based on node trust levels and environmental changes. Furthermore, this method also performs collaborative optimizations in transmission paths, data fragmentation, retransmission strategies, and caching mechanisms to reduce the performance overhead of dynamic encryption and authentication, achieving a balance between high security and high transmission efficiency.

[0003] Existing technologies have the following shortcomings: Current dynamic encryption mechanisms typically adjust encryption strength dynamically based on network bandwidth, latency, packet loss rate, and other indicators during data transmission to achieve a balance between security and transmission efficiency, in order to adapt to complex and ever-changing network environments. For example, in a high-bandwidth, low-latency network environment, a high-strength encryption algorithm (such as 256-bit encryption) is used to ensure data security; while in a constrained network environment such as low bandwidth or high latency, it automatically switches to low-strength encryption (such as 128-bit or lower) to reduce computational and transmission overhead. However, existing technologies lack effective adaptive capabilities to environmental changes and attack risks during the dynamic adjustment of encryption strength. Especially when the network environment fluctuates abnormally (such as when attackers create congestion or forge high packet loss rates), existing technologies typically adjust encryption strength only based on network indicators, making it difficult to effectively identify abnormal network changes and potential security threats. This can lead to the system easily remaining in a low-strength encryption state for extended periods.

[0004] If a system operates in a weak encryption mode for an extended period, it is highly susceptible to being compromised by attackers through man-in-the-middle eavesdropping, offline brute-force attacks, or other cryptographic analysis methods. This poses a serious threat to the confidentiality of user data and the overall security of the system, resulting in unacceptable security risks.

[0005] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0006] The purpose of this invention is to provide a dynamic encryption and authentication data transmission optimization method. By monitoring nodes collecting multi-dimensional network environment data in real time and combining feature engineering and machine learning to assess network security status, it can accurately identify potential malicious attacks. When an attack is detected, it actively prevents weak encryption downgrades, improves encryption strength and authentication level, shortens key update cycles, and effectively prevents the leakage of sensitive data. At the same time, by combining multi-channel path switching and collaborative response, it isolates risk propagation paths, reduces the attack surface, and significantly improves the security and stability of the communication system in malicious environments, thereby solving the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a data transmission optimization method for dynamic encryption and authentication, comprising the following steps:

[0008] Based on the topology of the communication system and security requirements, plan and deploy monitoring nodes;

[0009] After the monitoring nodes are deployed, multi-dimensional network environment data information at the network layer and application layer is collected in real time, and the collected data is preprocessed to establish a standardized data set.

[0010] After obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the dataset through feature engineering, and the extracted key features are quantitatively analyzed.

[0011] The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0012] When the assessment results indicate that there is a malicious attack in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. At the same time, it proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle to improve the level of communication security protection from the source. In addition, through multi-channel path switching and coordinated response measures, it blocks the risk diffusion path, reduces the attack surface, and ensures that the communication system maintains stable and reliable security protection capabilities under malicious environmental interference.

[0013] Preferably, monitoring nodes are deployed according to the topology and security requirements of the communication system. Specific steps include:

[0014] First, conduct a comprehensive analysis of the communication system's topology to clarify the boundaries, node distribution, communication links, critical business flows, and key security areas of each network region;

[0015] Secondly, based on the types of security threats faced by the system, the level of data sensitivity, and the requirements for business continuity, identify the key areas and communication links that need to be monitored, and clarify the monitoring targets;

[0016] Then, for different locations, monitoring nodes are selected and deployed at key communication nodes to ensure comprehensive coverage of the target network environment;

[0017] Finally, the deployment strategy for monitoring nodes is planned, including the collaborative communication mechanism between nodes, the design of data aggregation and reporting channels, and performance and availability assurance schemes, to ensure that the operation of monitoring nodes has minimal impact on bandwidth and performance, while also possessing real-time performance and reliability.

[0018] Preferably, after obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the dataset through feature engineering. The extracted features include the trend of IP authentication retry count and the failure rate of IPSec encryption negotiation within a unit of time. The trend of IP authentication retry count and the failure rate of IPSec encryption negotiation within a unit of time are quantitatively analyzed to generate authentication retry reference values ​​and encryption negotiation failure reference values, respectively. The authentication retry reference values ​​and encryption negotiation failure reference values ​​are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behavior in the current network environment.

[0019] Preferably, the specific steps for generating authentication retry reference values ​​by quantitatively analyzing the trend of IP authentication retry count changes within a unit of time are as follows:

[0020] During the communication process, let E be the total energy consumption of any monitoring node on the communication path within a unit observation period. i To quantify abnormal changes in energy consumption, a node energy consumption increment factor is introduced, defined by the following formula:

[0021]

[0022] In the formula, E i It is the total energy consumption of the i-th node within the current observation period. It is the baseline energy consumption of node i under historical safe and stable conditions, ΔE i It is the node energy consumption increment factor, which represents the rate of change of node i's energy consumption relative to the baseline energy consumption in the current period;

[0023] Based on the node energy consumption increment factor ΔE i Based on the authentication failure triggering conditions, an authentication retry reference value is generated, and the generation formula is as follows:

[0024]

[0025] In the formula, AARI is the certification retry reference value, and R... i C is the number of authentication retry triggers for the i-th node within the observation period. i is the number of authentication retry source types observed by the i-th node, and n is the total number of all nodes participating in monitoring along the communication path.

[0026] Preferably, the specific steps for generating reference values ​​for encryption negotiation failures by quantitatively analyzing the change curve of the IPSec encryption negotiation failure rate are as follows:

[0027] First, the raw negotiation records of the IPSec protocol encryption negotiation phase are processed. Assume that N negotiation events are observed within one analysis period, and the result of each negotiation is denoted by S. j This indicates that when the i-th negotiation fails, S... j =1, S upon success j =0; To characterize the cumulative and anomalous nature of recent negotiation failures, a negotiation failure increment factor is constructed, and its calculation expression is as follows:

[0028]

[0029] In the formula, F-IF is the negotiation failure increment factor, and S j This is the result of the j-th negotiation, with failure marked as 1 and success marked as 0. N is the total number of negotiations within the current analysis period.

[0030] After obtaining the negotiation failure increment factor F-IF, to further improve the sensitivity to continuous abnormal failures, the maximum length of the consecutive failure segment and the number of successful negotiations are introduced as additional features to construct a reference value for encryption negotiation failure. The calculation expression is as follows:

[0031]

[0032] In the formula, CENFI is the reference value for encryption negotiation failure, M is the length of the segment with the maximum consecutive negotiation failure within the analysis period, and K is the total number of successful negotiations within the analysis period.

[0033] Preferably, the authentication retry reference value and encryption negotiation failure reference value after quantitative analysis are input into a pre-trained machine learning model. The machine learning model generates a network environment security risk coefficient, and the network security risk coefficient is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0034] Preferably, the network security risk coefficient generated when the security status of the current network environment is assessed by a pre-trained machine learning model is compared and analyzed with a pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows:

[0035] If the network security risk coefficient is greater than the preset network security risk coefficient reference threshold, it is determined that there is a malicious attack in the current network environment;

[0036] If the network security risk coefficient is less than or equal to the pre-set network security risk coefficient reference threshold, it is determined that there is no malicious attack in the current network environment.

[0037] Preferably, when the assessment results indicate that there is a malicious attack in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. Simultaneously, the encryption strength of data transmission is proactively increased, authentication measures are added, and the key update cycle is shortened. Furthermore, through multi-channel path switching and coordinated response measures, the specific steps to block risk propagation paths and reduce the attack surface are as follows:

[0038] When a malicious attack is detected in the current network environment, the security policy is automatically adjusted according to the level of risk, increasing the encryption and authentication strength during communication. The encryption and authentication level calculation expression is as follows:

[0039]

[0040] In the formula, S is the security level, representing the current encryption and authentication strength level adopted by the system; S0 is the initial security level; NSRI is the network security risk coefficient; and S... max It is the maximum safety level, α is the safety gain coefficient, and T s (θ, λ) is the dynamic security reference threshold, representing the upper limit of risk tolerance. θ is the business level factor, λ is the load factor, and γ is the security index amplification coefficient.

[0041] After completing the security level adjustment, further isolation of risk propagation paths is achieved by dynamically selecting the optimal communication path through a multi-channel mechanism and suppressing the probability of using risky channels. The communication weight calculation expression for each channel is as follows:

[0042]

[0043] In the formula, w q r is the routing weight used by the q-th communication channel in multi-channel scheduling. q This is the real-time risk assessment value of the q-th communication channel, β is the entropy adjustment factor, M is the total number of communication channels, and r p It is the real-time risk assessment value of the p-th communication channel.

[0044] The technical effects and advantages provided by the present invention in the above technical solution are as follows:

[0045] This invention, through precise identification and real-time response to abnormal changes in the network environment and attack behaviors, fundamentally eliminates the problem that existing dynamic encryption technologies, which rely solely on network performance indicators, are easily induced by attackers to remain in a weak encryption state for extended periods. This ensures adaptive improvement in system security under complex and malicious network environments. Simultaneously, the method proactively manages security protection, enhances encryption strength and authentication measures during data transmission, shortens key update cycles, and promptly blocks risk propagation paths through multi-channel path switching and collaborative response. This effectively reduces the security risks of sensitive data being eavesdropped on by man-in-the-middle, brute-force attacks, or data tampering, significantly improving the overall security and stability of communication systems under malicious interference environments. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0047] Figure 1 This is a flowchart of a data transmission optimization method for dynamic encryption and authentication according to the present invention.

[0048] Figure 2 This is a mind map illustrating the method for optimizing data transmission through dynamic encryption and authentication according to the present invention. Detailed Implementation

[0049] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that the description of this disclosure will be more complete and fully convey the concept of the exemplary embodiments to those skilled in the art.

[0050] This invention provides, for example Figure 1 The data transmission optimization method for dynamic encryption and authentication shown includes the following steps:

[0051] Based on the topology of the communication system (such as the distribution of cloud and edge nodes, VPN or private network) and security protection requirements, plan and deploy monitoring nodes.

[0052] These monitoring nodes can be independent hardware probes or software proxies, deployed on critical network traffic nodes or key links to achieve comprehensive monitoring of the communication system. Through reasonable deployment across core components, broad coverage of the network environment can be achieved, collecting multi-dimensional, full-path network data to ensure comprehensive awareness of abnormal behavior. Simultaneously, monitoring nodes possess real-time or periodic data collection and reporting capabilities, enabling timely transmission of monitoring data back to the central system for analysis, ensuring data timeliness and effectiveness. Furthermore, scientifically planning the deployment density and location of monitoring nodes can effectively reduce monitoring blind spots, mitigating the risk of attacks going undetected due to missed detections. During deployment, network bandwidth, load balancing, system disaster recovery capabilities, and deployment costs must be fully considered to prevent monitoring nodes from becoming a network burden or new single points of failure, ensuring the stability and high availability of the monitoring system.

[0053] The deployment of monitoring nodes based on the communication system's topology and security requirements involves the following steps: First, a comprehensive analysis of the communication system's topology is conducted to identify the boundaries of each network area, node distribution, communication links, critical business flows, and key security areas, such as core switching areas, internet egress points, edge access nodes, and cloud service interfaces. Second, considering the types of security threats faced by the system, data sensitivity levels, and business continuity requirements, key monitoring areas and communication links are determined, and monitoring targets are defined (e.g., traffic anomaly detection, attack behavior identification, encryption policy tracking). Third, monitoring nodes, such as hardware traffic probes, software proxies, and distributed sensors, are selected for different locations and deployed at key communication nodes to ensure comprehensive coverage of the target network environment. Finally, a deployment strategy for the monitoring nodes is planned, including inter-node collaborative communication mechanisms, data aggregation and reporting channel design, and performance and availability assurance schemes, to ensure that the operation of the monitoring nodes minimizes the impact on system bandwidth and performance while maintaining real-time performance and reliability.

[0054] After the monitoring nodes are deployed, multi-dimensional network environment data information at the network layer and application layer is collected in real time, and the collected data is preprocessed to establish a standardized data set.

[0055] The collected data includes network layer metrics (such as bandwidth utilization, packet loss rate, round-trip time (RTT), congestion window changes, etc.) and application layer metrics (such as response time, request / response error rate, abnormal log information, user behavior characteristics, etc.), enabling multi-level, comprehensive monitoring of the communication system from the network to applications, fully perceiving the network's operational status, and forming a complete environmental understanding. Through real-time monitoring of multi-dimensional metrics, the system can promptly capture subtle changes such as traffic surges, network congestion, and abnormal retransmissions in high-concurrency or attack-threatened environments, providing a reliable basis for subsequent feature extraction and attack identification. Rich and fine-grained network environment data can provide more accurate and substantial contextual information for feature engineering and machine learning model training and judgment, significantly improving the accuracy of attack identification and the system's adaptive capabilities. In the actual collection process, a hierarchical collection strategy should be rationally designed according to the sensitivity and importance of the data, with high-frequency sampling for key nodes and key metrics, while low-frequency sampling can be used for secondary nodes, thereby balancing system performance overhead and security requirements while ensuring real-time performance and accuracy.

[0056] Raw network environment data often suffers from noise, high redundancy, and inconsistent formats. Therefore, comprehensive preprocessing is necessary. The cleaned and standardized data is then stored in a unified database to provide high-quality foundational data for subsequent analysis. Preprocessing involves several steps: First, data cleaning and denoising filter out obviously erroneous, missing, or anomalous data, smoothing out extreme values ​​to ensure the accuracy and stability of the analysis results. Second, standardization and normalization convert data of different formats and magnitudes into unified feature values ​​or indicators, addressing differences in units and ranges among various indicators. Furthermore, during the training phase, if supervised learning is required, data can be labeled and categorized based on time, network scenario, and user group, facilitating subsequent feature engineering and model building. In practical systems, data preprocessing must balance efficiency and scalability, especially in large-scale distributed environments. Distributed computing frameworks such as Spark and Flink are recommended to ensure the real-time performance, consistency, and reliability of massive data processing, providing robust data support for intelligent system evaluation and dynamic security control.

[0057] After obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the dataset through feature engineering, and the extracted key features are quantitatively analyzed.

[0058] After obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the dataset through feature engineering. The extracted features include the trend of IP authentication retry count per unit time and the curve of IPSec encryption negotiation failure rate. The trend of IP authentication retry count per unit time and the curve of IPSec encryption negotiation failure rate are quantitatively analyzed to generate authentication retry reference values ​​and encryption negotiation failure reference values. The authentication retry reference values ​​and encryption negotiation failure reference values ​​are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behavior in the current network environment.

[0059] An unusually high frequency of authentication retries for a specific IP address within a given timeframe is often a significant indicator of potential malicious attacks on the network. This is because legitimate users typically experience a limited number of authentication failures over a relatively long period. In contrast, unusually frequent authentication retries are often closely linked to brute-force attacks, session hijacking followed by unauthorized authentication attempts, or identity forgery. Attackers typically utilize automated tools to perform large-scale, short-duration, repeated authentication attempts on the target system to obtain valid authentication credentials or session tokens, thereby gaining unauthorized access or performing illegal operations. This behavior not only leads to a sharp increase in the number of authentication retries within a short period but may also be accompanied by abnormal retry rates and elevated failure rates, far exceeding the operational habits and behavioral patterns of normal users. Therefore, unusually frequent IP authentication retries within a given timeframe are a typical characteristic reflecting an attacker's proactive attack, directly indicating a potential security threat in the current network environment and providing crucial criteria for subsequent intrusion detection, risk assessment, and dynamic security policy adjustments.

[0060] The specific steps for generating reference values ​​for authentication retry by quantitatively analyzing the trend of IP authentication retry count changes within a unit of time are as follows:

[0061] During the communication process, let E be the total energy consumption of any monitoring node on the communication path within a unit observation period. i Energy consumption can be derived from a comprehensive set of indicators of resource consumption, such as node CPU load, memory consumption, interface traffic, and authentication module activity (which can be obtained through various measurement tools). To quantify abnormal changes in energy consumption, a node energy consumption increment factor is introduced, defined by the following formula:

[0062]

[0063] In the formula, E i It is the total energy consumption of the i-th node within the current observation period. It is the baseline energy consumption of node i under historical safe and stable conditions, ΔEi It is the node energy consumption increment factor, which represents the rate of change of node i's energy consumption relative to the baseline energy consumption in the current period;

[0064] The above steps directly quantify the relative increase in energy consumption of each node on the communication path compared to the baseline level. If ΔE i A value greater than 0 indicates an abnormally high energy consumption of the node, which may be related to frequent authentication retries, attack traffic, abnormal control requests, etc. There is no need to model the energy consumption value by average or standard deviation, which has stronger instantaneous sensitivity and interpretability.

[0065] Based on the node energy consumption increment factor ΔE i Based on the authentication failure triggering conditions, an authentication retry reference value is generated, and the generation formula is as follows:

[0066]

[0067] In the formula, AARI is the certification retry reference value, and R... i C is the number of authentication retry triggers for the i-th node within the observation period. i is the number of authentication retry source types observed by the i-th node (such as IP address, user ID, terminal ID, etc.), and n is the total number of all nodes participating in monitoring along the communication path.

[0068] By combining the abnormal energy consumption of nodes, the frequency of authentication retry, and the diversity of retry sources, a comprehensive authentication retry reference value is generated to fully reflect the security risks caused by abnormal authentication behavior in the current network. This reference value can effectively distinguish between normal, occasional authentication failures and malicious attacks caused by attackers forging multiple identities and making frequent attempts, providing a reliable criterion for subsequent dynamic security control.

[0069] A higher authentication retry reference value, generated after quantitative analysis of the trend of IP authentication retries per unit time, indicates abnormal authentication retry behavior in the network. This is often caused by malicious attackers using automated tools for brute-force attacks, identity forgery, or session hijacking. Such abnormal authentication retry behavior not only leads to frequent authentication failures but also causes nodes to consume a large amount of energy in a short period, exceeding the range explainable by normal communication traffic, thus reflecting a potential security threat. Conversely, when the authentication retry reference value remains at a low level, it indicates that the energy consumption rate of each node on the communication path is fluctuating normally, without obvious authentication anomalies or energy consumption surges, suggesting that the current network is not at risk of malicious attacks.

[0070] When the failure rate curve during the IPSec encryption negotiation phase shows a significant upward trend, it is generally considered that there is a potential malicious attack in the current network environment. This is because, under normal circumstances, encryption negotiation between the two parties should proceed stably with a low failure rate; an abnormal increase in the failure rate may indicate man-in-the-middle interference, forged negotiation messages, or downgrade attacks. Attackers often force the two parties to fail to establish a secure connection by actively injecting, tampering with, or replaying data packets during the negotiation process, thus significantly increasing the failure rate. Such attacks aim to disrupt the normal security negotiation process, forcing both parties to downgrade to a weaker encryption mode or completely interrupt encryption negotiation, providing opportunities for subsequent data eavesdropping, tampering, or offline cracking. Therefore, monitoring an upward trend in the encryption negotiation failure rate can serve as an important indicator for detecting and warning of potential malicious attacks, providing a basis for subsequent protective measures such as dynamic security control, enhanced identity authentication, and switching security policies, thereby curbing the risk of attackers exploiting negotiation failures to undermine communication security at the source.

[0071] The specific steps for quantitatively analyzing the change curve of the IPSec encryption negotiation failure rate to generate a reference value for encryption negotiation failure are as follows:

[0072] First, the raw negotiation records of the IPSec protocol encryption negotiation phase are processed. Assume that N negotiation events are observed within one analysis period, and the result of each negotiation is denoted by S. j This indicates that when the i-th negotiation fails, S... j =1, S upon success j =0; To characterize the cumulative and anomalous nature of recent negotiation failures, a negotiation failure increment factor is constructed, and its calculation expression is as follows:

[0073]

[0074] In the formula, F-IF is the negotiation failure increment factor, and S j This is the result of the j-th negotiation, with failure marked as 1 and success marked as 0. N is the total number of negotiations within the current analysis period.

[0075] By introducing a secondary weight for the negotiation sequence number, the results of each negotiation in the IPSec encryption negotiation phase are weighted, highlighting the impact of recent negotiation failures on the system's security posture. By calculating the negotiation failure increment factor, potential, time-concentrated encryption negotiation anomalies in the network are effectively quantified, providing key features for subsequent malicious attack identification.

[0076] After obtaining the negotiation failure increment factor F-IF, to further improve the sensitivity to continuous abnormal failures, the maximum length of the consecutive failure segment and the number of successful negotiations are introduced as additional features to construct a reference value for encryption negotiation failure. The calculation expression is as follows:

[0077]

[0078] In the formula, CENFI is the reference value for encryption negotiation failure, M is the segment length of the maximum consecutive negotiation failure within the analysis period, i.e. the maximum number of consecutive failures observed, and K is the total number of successful negotiations within the analysis period.

[0079] By introducing the maximum length of consecutive negotiation failure segments and the number of successful negotiations, combined with a negotiation failure increment factor, a reference value for encrypted negotiation failures is constructed that comprehensively reflects the anomalies and continuity characteristics of the negotiation process. This step can effectively identify consecutive negotiation failures caused by man-in-the-middle attacks, downgrade attacks, and other behaviors, providing a precise basis for anomaly judgment for subsequent dynamic security control.

[0080] A higher reference value for encryption negotiation failure, generated after quantitative analysis of the IPSec encryption negotiation failure rate curve, indicates more frequent negotiation failures within a set time window. This abnormal increase is usually related to malicious attacks, such as man-in-the-middle attacks, forged negotiation messages, or forced downgrade attacks. These attacks intentionally interfere with the normal encryption negotiation process, preventing both parties from successfully establishing a secure connection. Conversely, a lower reference value indicates a stable negotiation process and a low failure rate, typically representing the absence of significant malicious interference or attacks in the current network environment.

[0081] The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0082] The quantitatively analyzed authentication retry reference value and encryption negotiation failure reference value are input into a pre-trained machine learning model. The machine learning model generates a network environment security risk coefficient, which is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment.

[0083] A pre-trained machine learning model refers to a predictive model that is trained offline using machine learning algorithms (such as random forests, support vector machines, deep neural networks, or other statistical learning models) based on historical network data, simulated attack samples, and various normal and abnormal communication environment data before the implementation of a solution. This model can automatically identify security risk characteristics in the network environment. During training, researchers divide the preprocessed dataset into training, validation, and test sets according to a certain ratio. They use key indicators extracted through feature engineering (such as authentication retry reference values ​​and encryption negotiation failure reference values) as input features and label known attack events, abnormal states, or normal environments as output labels. Through continuous iterative learning, the model optimizes its internal parameters and ultimately outputs a predictive result reflecting the current network environment's security risk coefficient when faced with new input data. This process is similar to "infusing" the model with professional knowledge in the security field, enabling it to learn to extract patterns and rules that reveal potential malicious attacks from massive amounts of data, thereby quickly and efficiently determining whether potential threats exist in the network environment during actual operation. Once the trained model is deployed online, it no longer needs to rely on experts to set tedious rules. Instead, it uses an automated prediction mechanism to analyze real-time data, thereby enabling real-time monitoring and assessment of the cybersecurity situation.

[0084] Pre-trained machine learning models have high practical value in real-world applications. They intelligently process input network environment data based on key features, such as authentication retry reference values ​​and encryption negotiation failure reference values, after quantitative analysis, ultimately generating a network security risk coefficient. This risk coefficient directly reflects the severity of potential malicious attacks or abnormal behaviors in the current network environment. When the model detects that the input features match patterns exhibited in past abnormal or attack environments, the risk coefficient increases significantly, triggering subsequent security response measures, such as preventing weak encryption downgrades, increasing encryption strength, adding authentication methods, and initiating multi-channel switching. In other words, this pre-trained model can not only quickly assess real-time data but also provide early warnings of potential security vulnerabilities through historical experience and pattern recognition, thus providing strong data support and decision-making basis for the entire network security protection system. With this model, the system can achieve dynamic and intelligent assessment of the network security situation, enabling timely implementation of appropriate security strategies in the face of complex and ever-changing network environments, effectively reducing potential attack risks and ensuring that the communication system is always under high security protection.

[0085] The machine learning model is not limited here. Any machine learning model that can comprehensively analyze the authentication retry reference value AARI and the encryption negotiation failure reference value CENFI to generate the network security risk coefficient NSRI is acceptable. In order to realize the technical solution of this invention, this invention provides a specific implementation method.

[0086] The formula for generating the NSRI (Network Security Risk Index) is as follows:

[0087]

[0088] In the formula, s a and s b These are the preset proportional coefficients for the authentication retry reference value AARI and the encryption negotiation failure reference value CENFI, respectively, and s a and s b All are greater than 0.

[0089] The preset scaling factor s here a and s b These are the weighting parameters used when generating the Network Security Risk Ratio (NSRI) to determine the impact of the Authentication Retry Reference Ratio (AARI) and the Encryption Negotiation Failure Reference Ratio (CENFI) on the overall network security risk. Specifically, these two coefficients represent pre-set proportions by system designers based on experience, historical data, or the security needs of real-world scenarios when comprehensively assessing the current network environment's security status. This configuration allows the system to flexibly adjust and clearly express the relative importance of different characteristic indicators to the overall risk assessment, thereby more effectively capturing and highlighting key security threats or attack behaviors in the network environment during the assessment process, helping the system to take more precise dynamic security control measures.

[0090] As can be seen from the network security risk coefficient, the larger the authentication retry reference value generated by the quantitative analysis of the change trend of the number of IP authentication retries per unit time, and the larger the encryption negotiation failure reference value generated by the quantitative analysis of the change curve of the failure rate in the IPSec encryption negotiation stage, the larger the network security risk coefficient generated when the security status of the current network environment is evaluated by the pre-trained machine learning model, indicating that the risk of malicious attacks in the current network environment is higher, and vice versa.

[0091] The network security risk coefficient generated when the security status of the current network environment is evaluated by a pre-trained machine learning model is compared and analyzed with a pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows:

[0092] If the network security risk coefficient is greater than the preset network security risk coefficient reference threshold, it is determined that there is a malicious attack in the current network environment;

[0093] If the network security risk coefficient is less than or equal to the pre-set network security risk coefficient reference threshold, it is determined that there is no malicious attack in the current network environment.

[0094] When the assessment results indicate that there is a malicious attack in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. At the same time, it proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle, thereby improving the level of communication security protection from the source. In addition, through multi-channel path switching and coordinated response measures, it blocks the risk diffusion path, reduces the attack surface, and ensures that the communication system maintains stable and reliable security protection capabilities even under malicious environmental interference.

[0095] Upon detecting malicious attacks in the network environment, the system proactively adjusts its security strategy through an intelligent response mechanism, comprehensively enhancing its defense capabilities from multiple dimensions to block attack chains, strengthen communication security, and maintain stable system operation. Specifically, firstly, the system prevents automatic degradation of encryption strength caused by network fluctuations or performance degradation, preventing attackers from creating illusions of high latency, congestion, or packet loss to induce the system into a weak encryption state, thus creating an attack vulnerability. Secondly, the system proactively increases the encryption strength of data transmission, such as switching from 128-bit symmetric encryption to 256-bit or enabling more secure asymmetric encryption suites, and adds authentication methods, including multi-factor authentication, dynamic challenge-response mechanisms, and session behavior verification, ensuring the trustworthiness of communication participants at the identity layer. Simultaneously, the system shortens the key update cycle, accelerates key rotation speed, reduces the exploitable window after key leakage, and enhances resistance to attacks such as man-in-the-middle eavesdropping and offline cracking. Furthermore, to prevent attacks from spreading laterally across the network, this mechanism also integrates multi-channel path switching and collaborative defense mechanisms, such as dynamic route reconstruction, isolation of high-risk links, and traffic redistribution, to cut off attack propagation paths, reduce the attack surface, and effectively ensure the availability and data integrity of core communication links. Overall, this step, upon detecting an attack, can quickly construct a multi-layered, three-dimensional dynamic security protection system, ensuring that the communication system maintains stable, reliable, and adaptive security protection capabilities even in malicious environments, providing a solid guarantee for business continuity.

[0096] When the assessment results indicate that the current network environment is subject to malicious attacks, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. Simultaneously, it proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle. Furthermore, through multi-channel path switching and coordinated response measures, the specific steps to block risk propagation paths and reduce the attack surface are as follows:

[0097] When a malicious attack is detected in the current network environment, the security policy is automatically adjusted according to the level of risk, increasing the encryption and authentication strength during communication. The encryption and authentication level calculation expression is as follows:

[0098]

[0099] In the formula, S is the security level, representing the current encryption and authentication strength level adopted by the system; S0 is the initial security level; NSRI is the network security risk coefficient; and S... max The maximum security level represents the highest security policy level allowed by the system design. α is the security gain coefficient, used to control the impact of the risk coefficient on the security level improvement. T s (θ, λ) is the dynamic security reference threshold, representing the upper limit of risk tolerance. θ is the service level factor, representing the importance level of the current communication service, such as core service, ordinary service, and low priority service. λ is the load factor, reflecting the level of system resource consumption (such as CPU, memory, and link utilization). γ is the security exponential amplification coefficient, an exponential amplification parameter used to increase the response sensitivity under high risk.

[0100] The above steps non-linearly increase the security protection level according to the degree of risk, preventing low-strength encryption from being exploited by attackers in high-risk scenarios, while preventing performance loss due to excessive encryption, and achieving a dynamic balance between performance and security.

[0101] After completing the security level adjustment, further isolation of risk propagation paths is achieved by dynamically selecting the optimal communication path through a multi-channel mechanism and suppressing the probability of using risky channels. The communication weight calculation expression for each channel is as follows:

[0102]

[0103] In the formula, w q r is the routing weight used by the q-th communication channel in multi-channel scheduling. q This is the real-time risk assessment value of the q-th communication channel, reflecting the current security threat level of that channel. β is the entropy adjustment factor, which adjusts the risk value r. q For channel weight w q The coefficient affecting the intensity, M is the total number of communication channels, r p It is the real-time risk assessment value of the p-th communication channel.

[0104] The above steps effectively avoid high-risk channels and limit the spread of attack paths by dynamically adjusting the channel usage weights, ensuring that data traffic preferentially passes through low-risk channels, thereby achieving security optimization of communication paths and attack surface compression.

[0105] This invention, through precise identification and real-time response to abnormal changes in the network environment and attack behaviors, fundamentally eliminates the problem that existing dynamic encryption technologies, which rely solely on network performance indicators, are easily induced by attackers to remain in a weak encryption state for extended periods. This ensures adaptive improvement in system security under complex and malicious network environments. Simultaneously, the method proactively manages security protection, enhances encryption strength and authentication measures during data transmission, shortens key update cycles, and promptly blocks risk propagation paths through multi-channel path switching and collaborative response. This effectively reduces the security risks of sensitive data being eavesdropped on by man-in-the-middle, brute-force attacks, or data tampering, significantly improving the overall security and stability of communication systems under malicious interference environments.

[0106] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0107] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

[0108] It should be noted that, in this document, the use of relational terms such as "first" and "second" is merely for distinguishing one entity or operation from another, and does not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0109] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0110] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0111] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0112] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0113] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0114] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0115] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A method for optimizing data transmission with dynamic encryption and authentication, characterized in that, Includes the following steps: Based on the topology of the communication system and security requirements, plan and deploy monitoring nodes; After the monitoring nodes are deployed, multi-dimensional network environment data information at the network layer and application layer is collected in real time, and the collected data is preprocessed to establish a standardized data set. After obtaining high-quality preprocessed data, key features characterizing potential malicious attacks on the current network are extracted from the dataset through feature engineering, and the extracted key features are quantitatively analyzed. The key features after quantitative analysis are input into a pre-trained machine learning model. The machine learning model is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment. When the assessment results indicate that there is a malicious attack in the current network environment, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. At the same time, it proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle, thereby improving the level of communication security protection from the source. In addition, through multi-channel path switching and coordinated response measures, it blocks the risk diffusion path, reduces the attack surface, and ensures that the communication system maintains stable and reliable security protection capabilities even under malicious environmental interference. The extracted features include those per unit time. Trends in the number of authentication retries and The change curve of the failure rate during the encryption negotiation phase is analyzed and quantitatively. Reference values ​​for authentication retry and encryption negotiation failure are generated respectively. The reference values ​​for authentication retry and encryption negotiation failure are used to identify whether there are identity authentication anomalies and encryption process anomalies caused by active attack behavior in the current network environment. For a unit of time The specific steps for quantitatively analyzing the trend of authentication retry frequency changes and generating authentication retry reference values ​​are as follows: During the communication process, let the total energy consumption of any monitoring node on the communication path within a unit observation period be . To quantify abnormal changes in energy consumption, a node energy consumption increment factor is introduced, defined by the following formula: In the formula, It is the [number]th ... Total energy consumption of each node It is a node The baseline value of energy consumption under historical safe and stable conditions. It is the node energy consumption increment factor, representing the node's energy consumption increment factor. The rate of change of energy consumption relative to the baseline energy consumption during the current period; Based on node energy consumption increment factor Based on the authentication failure triggering conditions, an authentication retry reference value is generated, and the generation formula is as follows: In the formula, This is a reference value for authentication retry. It is the first The number of authentication retry triggers for each node within the observation period. It is the first The number of authentication retry source types observed by each node. It represents the total number of all nodes participating in the monitoring along the communication path.

2. The data transmission optimization method for dynamic encryption and authentication according to claim 1, characterized in that, Based on the communication system's topology and security requirements, the deployment of monitoring nodes involves the following steps: A comprehensive analysis of the communication system's topology is conducted to clarify the boundaries of each network area, node distribution, communication links, critical business flows, and key security areas. Based on the types of security threats faced by the system, the level of data sensitivity, and business continuity requirements, identify the key areas and communication links that need to be monitored, and clarify the monitoring targets; For different locations, select monitoring nodes and deploy them at key communication nodes to ensure comprehensive coverage of the target network environment; The deployment strategy for planning monitoring nodes includes collaborative communication mechanisms between nodes, design of data aggregation and reporting channels, and performance and availability assurance schemes to ensure that the operation of monitoring nodes has minimal impact on bandwidth and performance, while also possessing real-time performance and reliability.

3. The data transmission optimization method for dynamic encryption and authentication according to claim 1, characterized in that, right The specific steps for quantitatively analyzing the change curve of the failure rate during the encryption negotiation phase to generate a reference value for encryption negotiation failure are as follows: First, the collected The original negotiation records from the protocol's encryption negotiation phase are processed, assuming a total of [number] observations are made within one analysis period. Each negotiation event, the result of each negotiation is... It means that when the first When the second negotiation fails When successful To characterize the cumulative and anomalous nature of recent negotiation failures, a negotiation failure increment factor is constructed, and its calculation expression is as follows: In the formula, It is an incremental factor for negotiation failure. It is the first The outcome of each negotiation is recorded as follows: failure is marked as 1, and success is marked as 0. This represents the total number of negotiations within the current analysis period; In obtaining the negotiation failure increment factor Subsequently, to further enhance the sensitivity to consecutive abnormal failures, the maximum length of consecutive failed segments and the number of successful negotiations are introduced as additional features to construct a reference value for encryption negotiation failures. The calculation expression is as follows: In the formula, This is a reference value for failed encryption negotiation. It is the length of the segment with the largest consecutive negotiation failures within the analysis period. It represents the total number of successful negotiations within the analysis period.

4. The data transmission optimization method for dynamic encryption and authentication according to claim 1, characterized in that, The quantitatively analyzed authentication retry reference value and encryption negotiation failure reference value are input into a pre-trained machine learning model. The machine learning model generates a network environment security risk coefficient, which is used to assess the security status of the current network environment and determine whether there are potential malicious attacks in the current network environment.

5. The data transmission optimization method for dynamic encryption and authentication according to claim 4, characterized in that, The network security risk coefficient generated when the security status of the current network environment is evaluated by a pre-trained machine learning model is compared and analyzed with a pre-set network security risk coefficient reference threshold to determine whether there is a potential malicious attack in the current network environment. The judgment logic is as follows: If the network security risk coefficient is greater than the preset network security risk coefficient reference threshold, it is determined that there is a malicious attack in the current network environment; If the network security risk coefficient is less than or equal to the pre-set network security risk coefficient reference threshold, it is determined that there is no malicious attack in the current network environment.

6. The data transmission optimization method for dynamic encryption and authentication according to claim 5, characterized in that, When the assessment results indicate that the current network environment is subject to malicious attacks, a dynamic security control mechanism is triggered to proactively prevent weak encryption downgrades caused by network fluctuations. Simultaneously, it proactively increases the encryption strength of data transmission, adds authentication measures, and shortens the key update cycle. Furthermore, through multi-channel path switching and coordinated response measures, the specific steps to block risk propagation paths and reduce the attack surface are as follows: When a malicious attack is detected in the current network environment, the security policy is automatically adjusted according to the level of risk, increasing the encryption and authentication strength during communication. The encryption and authentication level calculation expression is as follows: In the formula, It refers to the security level, indicating the strength of encryption and authentication measures currently employed by the system. This is the initial security level. It is the cybersecurity risk coefficient. It is the highest security level. It is the safety gain coefficient. It is a dynamic safety reference threshold, representing the upper limit of risk tolerance. It is a business level factor. It is the load factor. It is the safety index amplification factor; After completing the security level adjustment, further isolation of risk propagation paths is achieved by dynamically selecting the optimal communication path through a multi-channel mechanism and suppressing the probability of using risky channels. The communication weight calculation expression for each channel is as follows: In the formula, It is the first The routing of communication channels in multi-channel scheduling uses weights. It is the first Real-time risk assessment value of each communication channel It is an entropy regulating factor. It is the total number of communication channels. It is the first Real-time risk assessment value for each communication channel.

Citation Information

Patent Citations

  • Security encryption transmission system for game data

    CN119561787A