Method and system for encrypting sensitive data based on large model

Through the large model, the data characteristics and usage scenarios are analyzed, and the encryption strategy is dynamically adjusted, which solves the resource waste and performance attenuation problems of traditional encryption methods, and achieves efficient and stable encryption of sensitive data.

CN120455159AActive Publication Date: 2025-08-08SICHUAN UNIV JINCHENG INST

Patent Information

Application Number
CN202510875206.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-08-08
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

Traditional sensitive data encryption methods lack dynamic perception and adaptability, resulting in waste of computing resources and security risks, making it difficult to monitor the performance changes of encryption modules in real time, affecting data encryption efficiency and security.

Method used

A large model is used to analyze the data content characteristics, generate a multi-dimensional sensitivity evaluation matrix and a scenario-risk level correlation model, dynamically adjust the encryption algorithm parameters, combine performance monitoring and compensation measures, generate a scenario adaptive encryption strategy, and use LSTM neural network to predict data trends to optimize encryption strategy.

Benefits of technology

It realizes dynamic encryption strategy adjustments based on data risk levels and usage scenarios, avoid resource waste, improve encryption efficiency and security, ensure stable performance of encryption modules, and reduce management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455159A_ABST
    Figure CN120455159A_ABST
Patent Text Reader

Abstract

The invention discloses a method and system for encrypting sensitive data based on a large model, relates to the field of data security, and solves the problem that a traditional fixed encryption strategy lacks dynamic adaptability. An encryption strategy container is generated through a data evaluation server, an evaluation module analyzes data content characteristics through a large model, a multi-dimensional sensitivity evaluation matrix and a use scene-risk level association model are established, and meanwhile the performance of an encryption module is tested; calculating a risk level according to a data sensitivity weight and a scene risk coefficient, triggering an alarm if the risk level exceeds a threshold value, otherwise, comparing a standard scene risk model to adjust encryption algorithm parameters, and generating a scene self-adaptive dynamic encryption strategy in combination with an encryption efficiency curve after performance compensation; and finally, the encryption gateway executes encryption. The method can improve the resource utilization rate through dynamic adaptive encryption, guarantees the stable efficiency through real-time performance compensation, improves the perspectiveness through intelligent prediction, reduces the safety risk and management cost through whole-process protection, and is suitable for a multi-industry sensitive data protection method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security, and in particular to a method and an encryption system for encrypting sensitive data based on a large model. Background Art

[0002] With the rapid development of information technology, data has become a core asset for businesses and society. Sensitive data, in particular, such as personal identity information, financial data, and trade secrets, once leaked or illegally used, can cause serious losses and harm to individuals, businesses, and the nation. Currently, encryption technology for sensitive data is a key means of protecting data security. Traditional encryption methods for sensitive data mostly rely on fixed encryption algorithms and strategies, lacking the ability to dynamically perceive and adapt to data sensitivity and usage scenarios. For example, in some scenarios, the same encryption algorithm is used regardless of data sensitivity. This not only wastes computing resources but can also expose highly sensitive data to security risks due to insufficient encryption strength. Furthermore, traditional methods struggle to monitor the performance of encryption modules in real time, making it difficult to effectively address performance degradation in a timely manner, thus compromising the efficiency and security of data encryption. Furthermore, existing encryption technologies often rely on manually set fixed weights and rules when assessing data risk levels. These methods lack the flexibility to adapt to dynamic data changes, making them unable to meet complex and ever-changing data security requirements. Summary of the Invention

[0003] The present invention aims to overcome the deficiencies of the prior art and provide a method for encrypting sensitive data based on a large model, comprising the following steps: In step 1, the data assessment server generates an encryption policy container and connects it to the assessment module. The assessment module classifies and assesses the target system data, determining the relationship between data type and sensitivity, and the relationship between data usage scenarios and risk levels, before proceeding to step 2. The assessment module then performs a performance test on the target system's encryption module, before proceeding to step 4. Step 2: Calculate the current data risk level based on the correlation between the initial sensitivity of the data and the usage scenario. If the risk level exceeds the set risk threshold, a security alert is triggered. Otherwise, proceed to step 3. Step 3: Compare the risk level of the real-time data usage scenario with the standard scenario risk model to obtain a risk deviation value. Dynamically adjust the encryption algorithm parameters based on the risk deviation value to generate a corrected encryption strategy. Combined with the standard scenario encryption strategy to form a composite encryption scheme, proceed to step 5. In step 4, the evaluation module detects the performance degradation of the encryption module and sends the performance parameters to the key management center. The key management center compensates the encryption module parameters based on the initial encryption performance benchmark and generates a compensated encryption performance curve, which then proceeds to step 5. Step 5: Match the composite encryption scheme with the compensated encryption efficiency curve to generate a scenario-adaptive dynamic encryption strategy; Step 6: Execute data encryption according to the dynamic encryption strategy to complete the protection of sensitive information.

[0004] Furthermore, the evaluation module performs classification evaluation on the target system data including: Analyze data content characteristics through large models, establish a multi-dimensional sensitivity assessment matrix, and generate a data type-sensitivity mapping table; Combined with data flow path analysis, a usage scenario-risk level association model is constructed.

[0005] Furthermore, the detecting of the encryption module performance degradation degree includes: Set baseline encryption performance parameters, obtain encryption delay growth rate and key processing efficiency decay value through time series analysis, and calculate the comprehensive performance decay index.

[0006] Furthermore, the current data risk level is calculated using: Risk level = Σ(data sensitivity weight × scenario risk coefficient) / normalization factor, where the data sensitivity weight coefficient is dynamically generated by the big model.

[0007] Furthermore, the parameter compensation of the encryption module includes: When the encryption delay growth rate is detected to exceed the threshold, the hardware acceleration module is enabled; when the key processing efficiency decays, the key rotation mechanism is triggered and the key storage structure is optimized.

[0008] Furthermore, the dynamic encryption strategy generation includes: Based on the LSTM neural network to predict data usage trends, combined with the reinforcement learning algorithm to optimize the encryption strategy selection, a time-adaptive encryption scheme is formed.

[0009] A sensitive data encryption system, applying the sensitive data encryption method based on a large model, comprises: a data evaluation server, an intelligent analysis module, an encryption gateway, a key management cluster, a risk monitoring center and a security audit module; The data evaluation server, intelligent analysis module, key management cluster, risk monitoring center and security audit module are respectively connected to the encryption gateway for communication.

[0010] The beneficial effects of this invention include: Based on a large-scale model, it conducts in-depth analysis of data content characteristics and usage scenarios, dynamically generates data sensitivity weights and scenario risk factors, and adjusts encryption policies in real time based on changes in data risk levels and usage scenarios. Compared to traditional fixed encryption policies, this method can more accurately match the security requirements of different data, while ensuring data security while avoiding resource waste caused by over-encryption, thereby improving encryption efficiency and resource utilization. By monitoring and analyzing encryption module performance in real time, when performance degradation is detected, it automatically implements compensation measures such as hardware acceleration, key rotation, and storage structure optimization to generate a compensated encryption performance curve. This ensures that the encryption module maintains optimal performance, avoiding increased data encryption latency and security risks caused by performance degradation, and ensuring the efficiency and stability of data encryption. By using LSTM neural networks to predict data usage trends and combining them with reinforcement learning algorithms to optimize encryption strategy selection, the encryption system can proactively detect changes in data usage and proactively adjust encryption strategies, creating a time-adaptive encryption solution. This intelligent prediction and decision-making mechanism enhances the encryption system's foresight and adaptability, enabling it to better cope with complex and changing data security environments. This encryption system encompasses multiple steps, including data assessment, risk analysis, encryption policy development, encryption execution, key management, risk monitoring, and security auditing, forming a comprehensive security protection system for sensitive data throughout its lifecycle. The interoperability and close coordination between modules ensures effective protection of sensitive data at every stage, significantly enhancing its overall security. Automated and intelligent encryption policy adjustments and performance optimization mechanisms reduce manual intervention and management costs. Furthermore, through precise risk assessment and encryption policy matching, potential losses from security incidents such as data leaks are mitigated, ultimately reducing the overall cost of sensitive data security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 The figure is a flowchart of a sensitive data encryption method based on a large model; Figure 2 Schematic diagram of the process of classifying and evaluating target system data for the evaluation module. DETAILED DESCRIPTION

[0012] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings, but the protection scope of the present invention is not limited to the following.

[0013] The features and performance of the present invention are further described in detail below with reference to the embodiments.

[0014] like Figure 1 As shown, a sensitive data encryption method based on a large model includes: In step 1, the data assessment server generates an encryption policy container and connects it to the assessment module. The assessment module classifies and assesses the target system data, determining the relationship between data type and sensitivity, and the relationship between data usage scenarios and risk levels, before proceeding to step 2. The assessment module then performs a performance test on the target system's encryption module, before proceeding to step 4. Step 2: Calculate the current data risk level based on the correlation between the initial sensitivity of the data and the usage scenario. If the risk level exceeds the set risk threshold, a security alert is triggered. Otherwise, proceed to step 3. Step 3: Compare the risk level of the real-time data usage scenario with the standard scenario risk model to obtain a risk deviation value. Dynamically adjust the encryption algorithm parameters based on the risk deviation value to generate a corrected encryption strategy. Combined with the standard scenario encryption strategy to form a composite encryption scheme, proceed to step 5. In step 4, the evaluation module detects the performance degradation of the encryption module and sends the performance parameters to the key management center. The key management center compensates the encryption module parameters based on the initial encryption performance benchmark and generates a compensated encryption performance curve, which then proceeds to step 5. Step 5: Match the composite encryption scheme with the compensated encryption efficiency curve to generate a scenario-adaptive dynamic encryption strategy; Step 6: Execute data encryption according to the dynamic encryption strategy to complete the protection of sensitive information.

[0015] Specifically, step 1: data evaluation and encryption module performance testing As the starting point of the entire encryption process, the data assessment server undertakes the critical task of generating the encryption policy container. The encryption policy container is a structured data storage unit designed with a layered architecture, consisting of a basic policy layer, a scenario adaptation layer, and a dynamic adjustment layer. The basic policy layer stores general encryption rules and algorithm templates; the scenario adaptation layer reserves interfaces for integrating specialized policies for different data usage scenarios; and the dynamic adjustment layer provides space for subsequent policy adjustments based on data risk and encryption module performance. The encryption policy container establishes a stable connection with the assessment module through a standardized API, ensuring efficient data and instruction transmission. like Figure 2As shown, the assessment module leverages the powerful data analysis capabilities of the large model to classify and evaluate target system data. The large model utilizes a Transformer architecture and a multi-head attention mechanism to deeply analyze data content features. Taking text data as an example, the large model analyzes keywords, semantic structures, and contextual relationships within the text, extracting sensitive features such as names, ID numbers, and bank card numbers. Based on these features, a multi-dimensional sensitivity assessment matrix is constructed. This matrix is organized by data type on the horizontal axis and sensitivity level on the vertical axis, with each cell corresponding to the sensitivity score of a data type under different dimensions. By learning and training from a large amount of historical data, an accurate data type-sensitivity mapping table is generated. Furthermore, the assessment module integrates data flow path analysis to construct a usage scenario-risk level correlation model. This data flow path analysis utilizes graph database technology, representing each operational node and transmission link within the system as a graph. Using graph algorithms, graph algorithms analyze the data flow risks in different scenarios and determine the corresponding risk level for each usage scenario. In addition, the evaluation module also performs performance testing on the target system's encryption module. First, baseline encryption performance parameters are set, including but not limited to encryption speed, decryption speed, key generation time, and encrypted data throughput. Using time series analysis, the various performance indicators of the encryption module are continuously monitored during operation to obtain encryption delay growth rates and key processing efficiency decay values. The encryption delay growth rate is calculated by calculating the rate of change of encryption operation time within adjacent time intervals; the key processing efficiency decay value is determined by comparing the difference between the current key generation, update, and verification time and the initial baseline time. Based on these data and the product of their respective weights, a comprehensive performance decay index is calculated. This index comprehensively considers multiple factors, including encryption delay and key processing efficiency, and can fully reflect the performance decay of the encryption module. Step 2: Data risk level calculation and alarm triggering After determining the correlation between data type and sensitivity, and between data usage scenarios and risk levels, the current data risk level is calculated based on the correlation between the initial data sensitivity and usage scenarios. The calculation formula used here is: Risk Level = Σ(Data Sensitivity Weight × Scenario Risk Factor) / Normalization Factor. The data sensitivity weight and scenario risk factor are dynamically generated by the big model through learning from a large amount of historical and real-time data. The big model utilizes a reinforcement learning algorithm, using the frequency and impact of data security incidents as reward signals to continuously optimize the generation of weights and factors. The normalization factor is used to normalize the calculated results, ensuring that the risk level falls within a uniform and comparable range. If the calculated risk level exceeds the set risk threshold, the system will immediately trigger a security alert. The alert information will be notified to relevant security management personnel through multiple channels, including SMS, email, and system pop-up notifications, so that timely countermeasures can be taken. If the risk level does not exceed the threshold, the system proceeds to step three. Step 3: Dynamically adjust encryption policy The risk level of the real-time data usage scenario is compared with the standard scenario risk model. The standard scenario risk model is constructed by analyzing and summarizing a large number of typical data usage scenarios and stored in the system's knowledge base. The comparison process uses the cosine similarity algorithm to calculate the similarity between the real-time scenario risk level vector and the standard scenario risk level vector, thereby obtaining a risk deviation value. Based on this risk deviation value, encryption algorithm parameters are dynamically adjusted. For example, for the common AES encryption algorithm, parameters such as key length and number of encryption rounds are adjusted based on the risk deviation value. When the risk deviation value is large, the key length and number of encryption rounds are increased to improve encryption strength; otherwise, the parameters are appropriately reduced to reduce computing resource consumption. By dynamically adjusting encryption algorithm parameters, a corrected encryption policy is generated. This corrected encryption policy is then combined with the standard scenario encryption policy to form a composite encryption scheme. The standard scenario encryption policy is a pre-defined encryption policy for different standard usage scenarios and has a certain degree of versatility and stability. Step 4: Encryption module parameter compensation After the evaluation module detects performance degradation in the encryption module, it sends the performance parameters to the key management center. If the encryption latency growth rate exceeds a threshold, the key management center automatically activates the hardware acceleration module. The hardware acceleration module uses a dedicated encryption acceleration chip, such as an FPGA or ASIC, to increase encryption speed and reduce encryption latency through hardware parallel computing. When key processing efficiency degrades, a key rotation mechanism is triggered and the key storage structure is optimized. This key rotation mechanism automatically replaces the old key with a new one at a predetermined time interval or when the number of key uses reaches a certain threshold, ensuring key security. The optimized key storage structure utilizes distributed storage technology, distributing the key storage across multiple secure nodes and employing encryption and redundant backup strategies to improve key storage reliability and security. Through these parameter compensation methods, a compensated encryption performance curve is generated, reflecting the performance changes of the encryption module after parameter compensation. Step 5: Generate dynamic encryption policy The composite encryption scheme is matched to the compensated encryption efficiency curve. This matching process utilizes regression analysis methods from machine learning, using performance indicators from the encryption efficiency curve as independent variables and the encryption algorithm parameters and strategies within the composite encryption scheme as dependent variables to build a regression model. By training on historical data, the regression model accurately predicts the most suitable encryption strategy for different encryption efficiency conditions. Furthermore, data usage trends are predicted using an LSTM neural network. LSTM neural networks are capable of processing long sequences of data and learning temporal dependencies during data usage, predicting trends such as data usage frequency and usage scenarios over time. This is combined with a reinforcement learning algorithm to optimize encryption strategy selection. This algorithm prioritizes data encryption security and efficiency, continuously trying different encryption strategies and adjusting strategy selection based on feedback signals. This results in a time-adaptive encryption scheme, known as a dynamic, scenario-adaptive encryption strategy. Step 6: Data encryption execution Based on the generated dynamic encryption policy, the system performs data encryption operations through the encryption gateway. Acting as a security barrier for data entering and exiting the system, the encryption gateway intercepts and encrypts data in real time. During the encryption process, the appropriate encryption algorithm and parameters are selected in strict accordance with the dynamic encryption policy to encrypt sensitive data, ensuring effective protection of sensitive information. During transmission and storage, encrypted data can only be decrypted and accessed by users or systems with the correct key and qualified permissions, thus ensuring the full lifecycle security of sensitive data. Applying this large-model-based sensitive data encryption method, the system primarily comprises a data assessment server, an intelligent analysis module, an encryption gateway, a key management cluster, a risk monitoring center, and a security audit module. Each module communicates with the encryption gateway, enabling secure data transmission and interaction. The data assessment server is responsible for generating encryption policy containers and collaborates with the assessment module to complete classification assessments of target system data and performance testing of encryption modules, providing foundational data for subsequent encryption policy development. The intelligent analysis module, leveraging large-scale modeling technology, conducts in-depth analysis of the data provided by the data assessment server. This includes establishing a multidimensional sensitivity assessment matrix, building a usage scenario-risk level correlation model, calculating data risk levels, and generating dynamic weights and coefficients. This provides intelligent decision-making support for dynamic encryption policy adjustments. The encryption gateway, as the data encryption execution unit, encrypts and decrypts data entering and leaving the system according to dynamic encryption policies, ensuring data security during transmission and storage. The key management cluster is responsible for key generation, storage, distribution, rotation, and management. By interacting with the encryption module, it implements parameter compensation for encryption modules, ensuring key security and stable performance of the encryption system. The risk monitoring center monitors data risk levels and system security status in real time. When risk levels exceed thresholds or abnormal security events are detected, a security alert is triggered and relevant personnel are notified for action. The security audit module audits and records the operation and data flow of the entire encryption system to facilitate subsequent security tracing and analysis, ensuring that the system's operation complies with security specifications and legal and regulatory requirements.

[0016] Example 1: Encryption of Sensitive Data of Financial Industry Customers A commercial bank needs to encrypt and protect sensitive data such as customer account information, transaction records, and identity authentication data. Data usage scenarios include over-the-counter transactions, online banking transfers, customer information inquiries, and risk assessment model training. Different scenarios have significantly different requirements for data sensitivity and real-time performance (for example, real-time transfers require low-latency encryption, while model training allows for higher-strength encryption).

[0017] The specific process includes the following: Data classification evaluation: The evaluation module analyzes customer data using a large model (a financial-specific model based on the BERT architecture): Text data (such as ID card number and account name): Use named entity recognition (NER) technology to extract sensitive fields and build a "data type-sensitivity" mapping table. For example, the sensitivity level of "bank card number" is defined as level 5 (the highest level), and the sensitivity level of "account balance" is level 4.

[0018] Transaction flow data: Identify high-frequency trading patterns through time series analysis. Combined with the data flow path (counter system → core database → risk control system), build a "use scenario-risk level" association model. For example, the "cross-border transfer" scenario involves cross-border data transmission, and the risk level is defined as level 4 (the highest level is 5).

[0019] The baseline parameters were set as follows: 100MB / s encryption speed for the symmetric AES-256 encryption algorithm, and a key generation time of ≤1ms. 72 hours of continuous monitoring revealed that during peak hours (9:00-11:00), encryption latency increased by 15% (exceeding the 10% threshold), and key processing efficiency decreased by 20% (compared to the initial baseline). The calculated overall performance degradation index was 0.85 (on a scale of 0-1, with higher values indicating more severe degradation).

[0020] Taking the "real-time cross-border transfer" scenario as an example, the data includes "bank card number" (weight 0.3), "transaction amount" (weight 0.2), and "payee information" (weight 0.2), and the corresponding scenario risk coefficients are 0.9, 0.8, and 0.7 respectively.

[0021] Risk level calculation: Σ(0.3×0.9 + 0.2×0.8 + 0.2×0.7) / 1.5 (normalization factor) = (0.27+0.16+0.14) / 1.5 = 0.57 / 1.5 = Level 3.8 (exceeding the threshold of Level 3), triggering a security alert. The system automatically freezes the abnormal transfer and notifies the risk control department.

[0022] Comparing the real-time scenario "cross-border transfer" risk level 3.8 with the standard scenario risk model (preset cross-border transfer standard risk level 3), the cosine similarity calculation risk deviation value is 0.2 (deviation > 0.1).

[0023] Adjust AES-256 parameters: temporarily increase the key length from 256 bits to 512 bits (hardware acceleration support required), increase the number of encryption rounds from 14 to 16, generate a corrected encryption strategy, and combine it with the standard scenario strategy (AES-256 + SHA-256 hash) to form a composite solution: "AES-512 (16 rounds) + SHA-512 hash + dynamic key rotation (renewing the key after each transaction)."

[0024] If the encryption delay growth rate is detected to exceed the threshold, the key management center automatically enables the FPGA hardware acceleration module, increasing the encryption speed to 200MB / s and reducing the delay to 5ms.

[0025] In response to the decline in key processing efficiency, the key rotation mechanism is triggered (originally rotated once every 24 hours, temporarily adjusted to rotate every 1,000 transactions), and key storage is migrated from the centralized database to a distributed key-value storage system (such as the Redis cluster), increasing the key retrieval speed by 30%.

[0026] The LSTM neural network predicts that cross-border transfer requests will increase by 20% in the next hour. The reinforcement learning algorithm optimizes the strategy: enabling "lightweight encryption + real-time key verification" for high-frequency transfer scenarios and maintaining high-strength encryption for low-frequency, large-value transfer scenarios, balancing efficiency and security.

[0027] The composite scheme is matched with the compensated performance curve (encryption speed 180MB / s, key generation time 0.8ms) to generate a scenario-adaptive strategy: AES-256 (14 rounds) + hardware acceleration is used during peak hours, and AES-512 (16 rounds) is used during off-peak hours.

[0028] The encryption gateway intercepts cross-border transfer data and selects AES-256 (14 rounds) + hardware acceleration based on dynamic strategies. The encrypted data is transmitted to the cross-border payment system through the HTTPS channel. The decryption end must simultaneously verify the timestamp, device fingerprint and dynamic key to ensure that the data has not been tampered with.

[0029] Intelligent analysis module: Receive transaction logs in real time and dynamically update sensitivity weights through large financial models (for example, the weight of nighttime transactions is automatically increased by 0.1 due to higher risks).

[0030] Key management cluster: Linked with the hardware acceleration module, it dynamically allocates FPGA resources based on transaction peaks to avoid resource waste.

[0031] Risk Monitoring Center: Combines real-time transaction data with historical fraud models to dynamically adjust risk thresholds (e.g., temporarily lowering the threshold from Level 3 to Level 2.5 during holidays).

[0032] Example 2: Encryption of Sensitive Data in Electronic Medical Records in the Medical Industry A tertiary hospital needs to protect sensitive patient data, including electronic medical records, diagnostic images, and medication records. These data are used in a variety of scenarios, including outpatient care, remote consultations, scientific research analysis, and medical insurance reimbursement. Different scenarios require different levels of data privacy protection (for example, scientific research analysis requires de-identification, while remote consultations require real-time, high-strength encryption).

[0033] The specific process includes the following: Data classification evaluation: The evaluation module analyzes medical record data using a large medical model (a medical-specific model based on GPT-4): Text data (diagnosis conclusion, medication dosage): Use medical entity recognition technology to extract sensitive fields such as "disease name" and "allergy history" and build a mapping table. For example, the sensitivity level of "tumor diagnosis result" is level 5, and the sensitivity level of "outpatient number" is level 3.

[0034] Imaging data (CT / MRI images): Lesion areas are identified using a convolutional neural network (CNN) and combined with DICOM file metadata (patient name, examination time) to build an "imaging data-risk level" model. For example, an image containing the patient's face has a risk level of 4.

[0035] Data flow path: outpatient system → electronic medical record library → image archiving system → scientific research platform. The access rights of different nodes vary significantly (for example, if the scientific research platform needs to be de-identified, the risk level will be reduced by 1 level).

[0036] Baseline parameters: Asymmetric encryption algorithm RSA-4096, encryption speed 50 times / second, key exchange latency ≤ 2ms. Monitoring revealed that when batch processing 1,000 images, encryption latency increased by 25% (exceeding the 15% threshold), key processing efficiency decreased by 30%, and the overall performance degradation index was 0.92.

[0037] Taking the "remote consultation" scenario as an example, the data includes "diagnosis conclusion" (weight 0.4), "patient name" (weight 0.3), and "imaging lesion area" (weight 0.2), and the scenario risk coefficients are 0.9, 0.8, and 0.8 respectively.

[0038] Risk level calculation: Σ(0.4×0.9 + 0.3×0.8 + 0.2×0.8) / 1.6 = (0.36+0.24+0.16) / 1.6 = 0.76 / 1.6 = Level 4.75 (exceeding the threshold of Level 4). An alarm is triggered, and the system automatically blocks unauthorized consultation requests and records them in a log.

[0039] The real-time "remote consultation" scenario, with a risk level of 4.75, was compared to the standard scenario model (preset remote consultation risk level 4), with a risk deviation of 0.15 (>0.1). RSA parameters were adjusted: the key length was increased from 4096 bits to 8192 bits, and elliptic curve cryptography (ECC) was used for key exchange. A correction strategy was generated and combined with the standard strategy (RSA-4096 + AES-256) to form a composite solution: "RSA-8192 + ECC key exchange + AES-512 (20 rounds)."

[0040] When encryption latency exceeded a threshold, the ASIC encryption accelerator was activated, increasing RSA-8192 encryption speed to 100 times per second and reducing latency to 1ms. To address declining key processing efficiency, a key rotation mechanism was triggered (from weekly rotation to every 500 consultations). Blockchain technology was also used to store key hashes, ensuring that key storage cannot be tampered with and improving retrieval efficiency by 40%.

[0041] An LSTM neural network predicted a 30% increase in nighttime emergency department consultations. A reinforcement learning algorithm optimized the strategy by using RSA-4096 + AES-256 (14 rounds) + fast key negotiation for emergency cases and a high-strength strategy for routine consultations to reduce emergency response delays. This combined approach matched the compensated performance curve (RSA encryption speed 90 times / second, key exchange latency 1.2ms) to generate a policy using lightweight encryption during emergency hours and high-strength encryption during non-emergency hours. This strategy was combined with dynamic permission verification (e.g., chief physicians have full access to data, while residents only have access to selected fields).

[0042] The encryption gateway intercepts consultation data and encrypts sensitive areas including lesion images using AES-512 fragmentation, while non-sensitive areas (such as examination numbers) use AES-256. The encrypted data is transmitted through a dedicated medical cloud channel, and the receiving end must pass two-factor authentication (dynamic token + biometric recognition) for decryption.

[0043] Intelligent analysis module: Dynamically adjusts data sensitivity based on ICD-10 diagnostic codes (e.g., the weight of infectious disease diagnosis is automatically increased by 0.2).

[0044] Key management cluster: Linked with medical devices, it allocates temporary session keys to mobile terminals (such as doctor tablets), which are automatically destroyed after the session ends.

[0045] Security Audit Module: Records encryption policies and key usage logs for each consultation and generates compliance reports (meeting HIPAA / GDPR requirements).

Claims

1. A method for encrypting sensitive data based on a large model, characterized in that: The steps include: In step 1, the data assessment server generates an encryption policy container and connects it to the assessment module. The assessment module classifies and assesses the target system data, determining the relationship between data type and sensitivity, and the relationship between data usage scenarios and risk levels, before proceeding to step 2. The assessment module then performs a performance test on the target system's encryption module, before proceeding to step 4. Step 2: Calculate the current data risk level based on the correlation between the initial sensitivity of the data and the usage scenario. If the risk level exceeds the set risk threshold, a security alert is triggered. Otherwise, proceed to step 3. Step 3: Compare the risk level of the real-time data usage scenario with the standard scenario risk model to obtain a risk deviation value. Dynamically adjust the encryption algorithm parameters based on the risk deviation value to generate a corrected encryption strategy. Combined with the standard scenario encryption strategy to form a composite encryption scheme, proceed to step 5. In step 4, the evaluation module detects the performance degradation of the encryption module and sends the performance parameters to the key management center. The key management center compensates the encryption module parameters based on the initial encryption performance benchmark and generates a compensated encryption performance curve, which then proceeds to step 5. Step 5: Match the composite encryption scheme with the compensated encryption efficiency curve to generate a scenario-adaptive dynamic encryption strategy; Step 6: Execute data encryption according to the dynamic encryption strategy to complete the protection of sensitive information.

2. The method for encrypting sensitive data based on a large model according to claim 1, characterized in that: The evaluation module performs classification evaluation on the target system data, including: Analyze data content characteristics through large models, establish a multi-dimensional sensitivity assessment matrix, and generate a data type-sensitivity mapping table; Combined with data flow path analysis, a usage scenario-risk level association model is constructed.

3. The method for encrypting sensitive data based on a large model according to claim 1, characterized in that: Detecting the encryption module performance degradation includes: Set baseline encryption performance parameters, obtain encryption delay growth rate and key processing efficiency decay value through time series analysis, and calculate the comprehensive performance decay index.

4. The method for encrypting sensitive data based on a large model according to claim 2, characterized in that: The calculation of the current data risk level adopts: Risk level = Σ(data sensitivity weight × scenario risk coefficient) / normalization factor, where the data sensitivity weight is dynamically generated by the big model.

5. The method for encrypting sensitive data based on a large model according to claim 3, characterized in that: The parameter compensation for the encryption module includes: When the encryption delay growth rate is detected to exceed the threshold, the hardware acceleration module is enabled; when the key processing efficiency decays, the key rotation mechanism is triggered and the key storage structure is optimized.

6. The method for encrypting sensitive data based on a large model according to claim 1, characterized in that: The dynamic encryption strategy generation includes: Based on the LSTM neural network to predict data usage trends, combined with the reinforcement learning algorithm to optimize the encryption strategy selection, a time-adaptive encryption scheme is formed.

7. A system for encrypting sensitive data based on a large model, characterized in that: The method for encrypting sensitive data based on a large model according to any one of claims 1 to 6 comprises: a data evaluation server, an intelligent analysis module, an encryption gateway, a key management cluster, a risk monitoring center, and a security audit module; The data evaluation server, intelligent analysis module, key management cluster, risk monitoring center and security audit module are respectively connected to the encryption gateway for communication.

Citation Information

Patent Citations

  • Method and system for encrypting sensitive data based on large model

    CN117978439A

  • Cloud-based EMM encryption method and system

    CN119155065A

  • Data encryption method and device, equipment and storage medium

    CN119272294A

  • Processing method and system for dynamic encryption of enterprise sensitive data

    CN119449369A

  • Deep reinforcement learning optimization algorithm based on adaptive encryption framework

    CN119513891A

Cited By

  • Enterprise project digital management and control method and equipment based on AI large model, and medium

    CN120911778A

  • An AI large model-based enterprise project digital management and control method, device and medium

    CN120911778B

  • Multi-dimensional encryption transmission protection method and system for cross-border payment

    CN121056243A

  • Multi-dimensional encryption transmission protection method and system for cross-border payment

    CN121056243B

  • Digital twinning-oriented multi-modal reinforcement learning adaptive encryption method and device

    CN121217442A