Sensor data information management system based on chip-level encryption

Through the sensor data information management system based on chip-level encryption, the encryption solution is dynamically adjusted, and the efficiency and security problems of traditional encryption management systems in complex electromagnetic environments are solved, achieving efficient and secure sensing data management.

CN120474853BActive Publication Date: 2025-09-02ZHONGYING QINGCHUANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510986162.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-02
Estimated Expiration
2045-07-17

AI Technical Summary

Technical Problem

When facing complex electromagnetic environments and multi-protocol heterogeneous equipment, existing sensing data encryption management systems are difficult to achieve dynamic adjustments, the encryption efficiency is inefficient, and cannot meet the high real-time and security needs of power plants. They also lack effective clustering analysis and optimization screening of historical data, resulting in a lack of scientificity and forward-looking encryption solutions.

Method used

Through a sensor data information management system based on chip-level encryption, including the target data feature acquisition module, the historical feature information clustering module, the historical encryption parameter set optimization and screening module, the encryption trend prediction module and the dynamic correction module, the encryption scheme is dynamically adjusted, and the target transmission environment feature information and historical encryption parameters are matched and corrected to generate encryption scheme prompts.

Benefits of technology

It realizes dynamic adjustment of encryption schemes according to the characteristics of the transmission environment, improves the efficiency and security of encryption management, ensures the efficiency and security of encryption operations, and enhances the system's adaptability to different transmission environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474853B_ABST
    Figure CN120474853B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of chip-level encryption technology and discloses a sensor data information management system based on chip-level encryption. The system includes a target data feature acquisition module for acquiring target sensor data and transmission environment feature information and indexing historical encryption management data; a historical feature information clustering module for clustering and processing historical transmission environment feature information to obtain a historical encryption parameter set; a historical encryption parameter set optimization and screening module for screening encryption parameter groups and sorting them to obtain a historical encryption parameter sequence; an encryption trend prediction module for predicting encryption enhancement and reduction rates; a dynamic correction module for correcting enhancement and reduction rates based on environmental feature deviations; and an encryption scheme generation module for generating encryption scheme prompts. The system implements dynamic encryption management of sensor data, improving data security and management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of chip-level encryption, and in particular to a sensor data information management system based on chip-level encryption. Background Art

[0002] In key infrastructure areas such as power production, the intelligent upgrade of power plants has put forward higher requirements for the security of sensor data: if the real-time data of key equipment such as turbine vibration monitoring, boiler temperature chain, and excitation control system is tampered with, it may cause unit tripping or even grid fluctuations; traditional encryption solutions are difficult to meet the innovative management needs of power plants' complex electromagnetic environments, high real-time transmission, and multi-protocol heterogeneous device access.

[0003] Traditional encryption methods are mostly software-based, making them difficult to effectively guarantee in the face of increasingly sophisticated cyberattacks. Software encryption is vulnerable to attack and tampering by malware and viruses. Hackers can steal encryption keys or crack encryption algorithms through various means, leading to the leakage or tampering of sensor data. This is particularly true in scenarios such as power plants, where national energy security is crucial. Attackers can forge sensor data to interfere with DCS instructions. Traditional software encryption presents risks such as response lag and key theft when responding to targeted attacks. With the increasing number of sensor types and the diversification of communication protocols, encryption requirements vary across sensors and communication environments. Traditional encryption management systems often use fixed encryption schemes that cannot dynamically adjust to specific transmission environment characteristics, resulting in low encryption efficiency and even insufficient security protection in some complex environments. For example, power plants combine wired industrial buses with wireless sensor networks. Transmission delays and data priorities vary significantly between different areas. Fixed encryption strategies can easily lead to control instruction delays or security blind spots.

[0004] Existing sensor data encryption management systems lack effective clustering analysis and optimization screening mechanisms when processing historical encrypted data. This makes it difficult to extract valuable information from massive amounts of historical data and to accurately predict encryption trends, resulting in encryption schemes that lack scientific and forward-looking nature. In power plant practice, operating condition changes such as unit startup and shutdown, and load adjustments can cause dramatic fluctuations in transmission environment characteristics. If historical encryption models cannot dynamically adapt to such scenarios, operational risks will be significantly increased. Furthermore, when the transmission environment changes, traditional systems cannot promptly modify encryption schemes based on deviations in environmental characteristics, making the encryption schemes out of touch with actual needs and further increasing data security risks. For example, when a power plant network is impacted by sudden traffic, if the encryption system cannot automatically downgrade to ensure the real-time performance of control instructions, it may trigger the protection system to malfunction.

[0005] With the gradual development of chip-level encryption technology, while chip-level encryption provides a certain level of security at the hardware level, combining chip-level encryption with the dynamic management of sensor data to achieve secure management of sensor data throughout its entire lifecycle based on chip-level encryption remains a pressing issue. Existing sensor data management systems based on chip-level encryption have numerous shortcomings in data feature acquisition, historical data processing, encryption trend prediction, and dynamic correction. In particular, they lack targeted optimization for specific power plant scenarios (such as high-temperature and high-humidity physical environments, millisecond-level real-time response, and multi-source heterogeneous protocol compatibility), failing to meet the growing demand for sensor data security management. Therefore, there is an urgent need for a system and method that can dynamically adjust encryption schemes based on the characteristics of the target transmission environment to improve sensor data security and management efficiency. Summary of the Invention

[0006] The purpose of the present invention is to provide a sensor data information management system based on chip-level encryption to solve the problems raised in the above background technology.

[0007] To achieve the above objectives, the present invention provides the following technical solution: a sensor data information management system based on chip-level encryption, the system comprising:

[0008] A target data feature acquisition module, which is used to obtain the target sensor data that the user currently needs to manage, and to collect characteristic information of the target transmission environment in which the target sensor data is currently located. Based on the target sensor data, the module indexes the historical encryption management data of the target sensor data within the user's historical time.

[0009] a historical feature information clustering module, the historical feature information clustering module being configured to cluster historical transmission environment feature information within the historical encryption management data to obtain a plurality of clustered historical feature groups, extract historical encryption parameter information sets and a plurality of historical encryption management data sets from the plurality of clustered historical feature groups, and process the obtained plurality of historical encryption parameter sets;

[0010] a historical encryption parameter set optimization and screening module, the historical encryption parameter set optimization and screening module being used to optimize and screen the multiple historical encryption parameter sets respectively, obtain multiple filtered encryption parameter groups, and arrange them in chronological order to obtain multiple historical encryption parameter sequences;

[0011] An encryption trend prediction module, configured to perform encryption trend prediction based on the plurality of historical encryption parameter sequences to obtain an encryption enhancement rate and a weakening rate;

[0012] a dynamic correction module, the dynamic correction module being configured to match the target transmission environment characteristic information with the multiple clustered historical characteristic groups to obtain a matching historical characteristic group, and to correct the encryption enhancement rate and attenuation rate based on a deviation between the target transmission environment characteristic information and the standard matching characteristic information of the matching historical characteristic group to obtain a corrected enhancement rate and a corrected attenuation rate;

[0013] An encryption scheme generation module is used to make encryption scheme decisions based on the modified enhancement rate and the modified weakening rate, obtain encryption scheme prompts, and perform encryption operation prompts.

[0014] Preferably, obtaining target sensor data that the user currently needs to manage, and collecting characteristic information of the target transmission environment in which the target sensor data is currently located, and indexing historical encrypted management data of the target sensor data within the user's historical time based on the target sensor data, include:

[0015] Acquire the target sensor data that the user currently needs to manage, and collect the sensor type and communication protocol parameters of the target sensor data as target transmission environment feature information;

[0016] According to the target sensor data, an index is performed in the historical encryption management record of the user to obtain the historical encryption management data of the target sensor data.

[0017] Preferably, clustering the historical transmission environment feature information in the historical encryption management data to obtain multiple clustered historical feature groups, extracting historical encryption parameter information sets and multiple historical encryption management data sets under the multiple clustered historical feature groups, and processing to obtain multiple historical encryption parameter sets includes:

[0018] Acquire multiple pieces of historical transmission environment feature information in the historical encryption management data, perform clustering processing, and obtain multiple clustered historical feature groups;

[0019] Extracting a standard encryption algorithm structure of target sensor data in the historical encryption management data under the multiple clustered historical feature groups, obtaining a historical encryption parameter information set, and extracting multiple historical key parameter sets and multiple historical encryption operation time sets encrypted and submitted by the user under the multiple clustered historical feature groups;

[0020] Obtaining multiple historical basic parameter sets by classification according to the deviation magnitudes of the multiple historical key parameter sets from the historical encryption parameter information set;

[0021] According to the ratio of the preset operation time threshold and the multiple historical encryption operation time sets, the multiple historical basic parameter sets are corrected and calculated to obtain multiple historical encryption parameter sets.

[0022] Preferably, the plurality of historical encryption parameter sets are optimized and screened respectively to obtain a plurality of screened encryption parameter groups, and the groups are arranged in time sequence to obtain a plurality of historical encryption parameter sequences, including:

[0023] Selecting and obtaining a first baseline encryption parameter from a first historical encryption parameter set in the plurality of historical encryption parameter sets;

[0024] Assigning distribution probabilities based on the differences between other encryption parameters in the first historical encryption parameter set and the first benchmark encryption parameter to obtain a first basic probability distribution, wherein the size of the difference is negatively correlated with the size of the distribution probability;

[0025] Optimizing and screening the first historical encryption parameter set according to the first basic probability distribution to obtain a first screened encryption parameter group;

[0026] Sorting the plurality of encryption parameters in the first screening encryption parameter group according to timestamp information to obtain a first historical encryption parameter sequence;

[0027] Optimize and screen other multiple historical encryption parameter sets and arrange them in time sequence to obtain multiple historical encryption parameter sequences.

[0028] Preferably, optimizing and screening the first historical encryption parameter set according to the first basic probability distribution to obtain a first screened encryption parameter group includes:

[0029] Randomly selecting a preset number of encryption parameters from the first historical encryption parameter set to obtain a first filtered encryption parameter group;

[0030] Assigning distribution probabilities according to differences between encryption parameters in the first screening encryption parameter group and the first benchmark encryption parameters to obtain a first screening probability distribution;

[0031] Calculating the similarity between the first screening probability distribution and the first basic probability distribution as a first screening fitness;

[0032] Randomly extracting a preset number of screening encryption parameters from the first historical encryption parameter set again to obtain a second screening encryption parameter group, and processing the obtained second screening fitness;

[0033] Continue to optimize and filter until convergence, and output the filtering encryption parameter group with the largest filtering fitness as the first filtering encryption parameter group.

[0034] Preferably, performing encryption trend prediction based on the multiple historical encryption parameter sequences to obtain encryption enhancement rate and weakening rate includes:

[0035] According to the sample encryption management data of multiple users, a sample encryption parameter sequence set is collected, and a sample enhancement rate set and a sample attenuation rate set are obtained according to a parameter change identifier in each sample encryption parameter sequence;

[0036] Using the sample encryption parameter sequence set as classification input, using the sample enhancement rate set and the sample attenuation rate set as classification output, to construct an encryption trend predictor;

[0037] Based on the encryption trend predictor, the encryption trend of the plurality of historical encryption parameter sequences is classified to obtain a plurality of feature enhancement rates and a plurality of feature weakening rates;

[0038] The target transmission environment feature information and the similarity of the multiple clustering historical feature groups are analyzed, and the multiple feature enhancement rates and the multiple feature reduction rates are weightedly calculated according to the sizes of the multiple feature similarities to obtain the encryption enhancement rate and reduction rate.

[0039] Preferably, matching the target transmission environment feature information with the multiple clustered historical feature groups to obtain a matching historical feature group, and correcting the encryption enhancement rate and attenuation rate based on a deviation between the target transmission environment feature information and the standard matching feature information of the matching historical feature group to obtain a corrected enhancement rate and a corrected attenuation rate, including:

[0040] Selecting the clustered historical feature group with the greatest similarity as the matching historical feature group, and obtaining standard matching feature information of the matching historical feature group;

[0041] setting an encryption correction coefficient according to a deviation between the target transmission environment feature information and the standard matching feature information of the matching historical feature group;

[0042] The encryption correction coefficient is used to perform correction calculation on the encryption enhancement rate and attenuation rate to obtain a corrected enhancement rate and a corrected attenuation rate.

[0043] Preferably, making an encryption scheme decision based on the modified enhancement rate and the modified weakening rate, obtaining an encryption scheme prompt, and performing an encryption operation prompt include:

[0044] Collecting a set of sample correction enhancement rates and a set of sample correction attenuation rates, and setting a sample encryption scheme prompt according to the size of each sample correction enhancement rate and sample correction attenuation rate to obtain a set of sample encryption scheme prompts, wherein each sample encryption scheme prompt includes a key adjustment ratio, and the sizes of the sample correction enhancement rate and the sample correction attenuation rate are negatively correlated with the size of the key adjustment ratio;

[0045] The sample modified enhancement rate set and the sample modified weakening rate set are used as decision inputs, and the sample encryption scheme prompt set is used as decision output to construct an encryption scheme decider;

[0046] The encryption scheme decider is used to make an encryption scheme decision on the modified enhancement rate and the modified weakening rate to obtain an encryption scheme prompt.

[0047] Preferably, collecting the sensor type and communication protocol parameters of the target sensing data as target transmission environment characteristic information includes:

[0048] Identify the sensor model and data transmission frequency of the target sensor data as the sensor type;

[0049] Parsing the communication protocol version and encryption handshake parameters of the target sensor data as communication protocol parameters;

[0050] The sensor type and communication protocol parameters are combined to form target transmission environment characteristic information.

[0051] Preferably, the multiple historical basic parameter sets are corrected and calculated based on the ratio of the preset operation time threshold to the multiple historical encryption operation time sets to obtain multiple historical encryption parameter sets, including:

[0052] Calculate the ratio of each historical encryption operation time to the preset operation time threshold to obtain a time correction factor;

[0053] Multiplying each parameter in the plurality of historical basic parameter sets by a corresponding time correction factor to obtain a corrected parameter;

[0054] The modified parameters are combined to form multiple historical encryption parameter sets.

[0055] Compared with the prior art, the present invention has the following beneficial effects:

[0056] The system uses the target data feature acquisition module to acquire target sensor data and transmission environment feature information, and indexes historical encryption management data, providing a comprehensive and accurate data foundation for the development of subsequent encryption schemes. The historical feature information clustering module clusters historical transmission environment feature information to obtain multiple clustered historical feature groups, and then extracts historical encryption parameter information sets, achieving effective organization and management of historical data and laying the foundation for optimized encryption parameter screening.

[0057] The Historical Encryption Parameter Set Optimization and Screening module optimizes and sequentially screens multiple historical encryption parameter sets, making the selected encryption parameters more representative and reliable. The resulting historical encryption parameter sequences provide high-quality data input for encryption trend prediction. The Encryption Trend Forecasting module predicts encryption trends based on multiple historical encryption parameter sequences, obtaining encryption enhancement and weakening rates. This module can scientifically predict encryption trends and provide an important reference for encryption solution decisions.

[0058] The dynamic correction module matches the target transmission environment's characteristic information with clustered historical feature groups and adjusts the encryption enhancement and reduction rates based on deviations, ensuring that the encryption trend prediction results are more consistent with the current actual transmission environment and improving the adaptability of the encryption scheme. The encryption scheme generation module makes encryption scheme decisions based on the corrected enhancement and reduction rates, obtains encryption scheme prompts, and provides operational prompts. This enables dynamic generation and accurate recommendation of encryption schemes, ensuring the efficiency and security of encryption operations.

[0059] Specifically, in terms of data collection and indexing, accurately capturing target transmission environment characteristics, such as sensor types and communication protocol parameters, enables more precise matching of historical encryption management data, providing a reliable basis for subsequent processing. In historical data clustering, clustering historical transmission environment characteristics and extracting and processing historical encryption parameter information effectively taps into the potential value of historical data and improves its utilization. During encryption parameter optimization and screening, an optimization screening method based on probability distribution and screening fitness ensures the optimality of the selected encryption parameter groups, improving encryption parameter quality.

[0060] Encryption trend prediction uses sample data to build a predictor and performs a weighted calculation based on the similarity between the target transmission environment characteristics and clustered historical feature groups, making the predictions more accurate and scientific. Dynamic correction adjusts encryption trend predictions by setting a correction factor based on environmental characteristic deviations, enhancing the system's adaptability to different transmission environments. Encryption scheme decision-making uses a decision-maker to generate encryption scheme prompts based on the corrected enhancement and attenuation rates, enabling intelligent encryption scheme decision-making and improving the efficiency and security of encryption management. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 This is a working principle diagram of the sensor data information management system based on chip-level encryption according to the present invention;

[0062] Figure 2 This is the design diagram of the historical feature information clustering module;

[0063] Figure 3 Flowchart of the optimization and screening module for the historical encryption parameter set;

[0064] Figure 4 Detailed design diagram for optimizing the screening process. DETAILED DESCRIPTION

[0065] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0066] See Figure 1 The present invention relates to a sensor data information management system based on chip-level encryption, and the specific implementation methods are as follows:

[0067] The target data feature acquisition module is used to obtain the target sensor data currently being managed by the user, collect the target transmission environment feature information of the target sensor data, and index the user's historical encryption management data for the target sensor data within a historical period. The historical feature information clustering module clusters the historical transmission environment feature information within the historical encryption management data to obtain multiple clustered historical feature groups. It then extracts historical encryption parameter information sets and multiple historical encryption management data sets from these groups, processing these sets to obtain multiple historical encryption parameter sets. The historical encryption parameter set optimization and screening module optimizes and screens the multiple historical encryption parameter sets to obtain multiple filtered encryption parameter groups, which are then arranged in chronological order to form multiple historical encryption parameter sequences. The encryption trend prediction module predicts encryption trends based on the multiple historical encryption parameter sequences to obtain encryption enhancement and reduction rates. The dynamic correction module matches the target transmission environment feature information with the multiple clustered historical feature groups to obtain matching historical feature groups. The module then corrects the encryption enhancement and reduction rates based on the deviation between the target transmission environment feature information and the standard matching feature information of the matching historical feature groups, obtaining corrected enhancement and correction reduction rates. The encryption scheme generation module makes encryption scheme decisions based on the modified enhancement rate and the modified weakening rate, obtains encryption scheme prompts, and then performs encryption operation prompts.

[0068] Example 1: In a sensor data information management system based on chip-level encryption, the target data feature acquisition module is implemented as follows: The system first obtains the target sensor data that the user currently needs to manage. This target sensor data can be information collected and transmitted by various sensors, such as ambient temperature data collected by a temperature sensor, pressure data collected by a pressure sensor, and humidity data collected by a humidity sensor. While acquiring the target sensor data, the system also collects characteristic information about the target transmission environment in which the target sensor data currently resides, primarily including sensor type and communication protocol parameters.

[0069] For the collection of sensor types, the system will identify the sensor model and data transmission frequency corresponding to the target sensor data. The identification of the sensor model can be achieved by reading the device identification information attached to the sensor when transmitting data. Different types of sensors usually have unique identification codes. The system can parse and identify the code to determine the specific model of the sensor. The data transmission frequency refers to the frequency at which the sensor collects and transmits data, such as once per second, once per minute, etc. The system can obtain this frequency information by analyzing the transmission time interval of the target sensor data. For example, when the target sensor data comes from a certain model of temperature sensor, the system reads its device identification code as XXX, determines the sensor model as XXX through parsing, and analyzes the time interval of its data transmission to determine the data transmission frequency as XXHz.

[0070] In terms of collecting communication protocol parameters, the system will parse the communication protocol version and encryption handshake parameters of the target sensor data. The communication protocol version refers to the specific version number of the communication protocol used during the data transmission process, such as V1.0, V2.0, etc. The system can extract this version number from the protocol header information of the target sensor data. The encryption handshake parameters are the parameters used by the communicating parties when performing an encryption handshake before data transmission, such as the random number generated during the handshake process, the encryption algorithm selection identifier, etc. The system can parse the encryption handshake process information contained in the target sensor data to obtain these parameters. For example, for a certain target sensor data, the system parses its protocol header information and obtains the communication protocol version as V1.0. It then parses the encryption handshake process information and obtains the encryption handshake parameters as XXX.

[0071] The system combines the collected sensor types and communication protocol parameters to form characteristic information about the target transmission environment. Specifically, this information, such as sensor model, data transmission frequency, communication protocol version, and encryption handshake parameters, is integrated according to a specific format. For example, it is stored as structured data, which includes a sensor type field and a communication protocol parameter field. The sensor type field contains model and frequency subfields, and the communication protocol parameter field contains version and handshake parameter subfields.

[0072] After completing the collection of the target transmission environment characteristic information, the system needs to index the user's historical encryption management records based on the target sensor data to obtain the historical encryption management data of the target sensor data. The historical encryption management records store relevant information about the user's past encryption management of various sensor data, including the parameters used in the encryption process, the time of the encryption operation, etc. The system will match the characteristic information of the target sensor data with the data in the historical encryption management records. Specifically, it can search for the corresponding encryption management data in the historical records based on the identification information of the target sensor data, such as the source sensor identification of the data, the type of data, etc. For example, when the target sensor data comes from the temperature sensor of model XXX mentioned above, the system will search for all encryption management records for the sensor data of this model in the historical encryption management records based on the identification information of the sensor, thereby obtaining the historical encryption management data of the target sensor data.

[0073] Example 2: See Figure 2 In a sensor data information management system based on chip-level encryption, the historical feature information clustering module is implemented as follows: the system obtains multiple historical transmission environment feature information within the historical encrypted management data. This historical transmission environment feature information is information related to the data transmission environment collected by the user during previous encryption management of sensor data. Its format and content are consistent with the currently collected target transmission environment feature information, including sensor type (such as sensor model and data transmission frequency) and communication protocol parameters (such as communication protocol version and encryption handshake parameters). For example, the historical encrypted management data may contain transmission environment feature information for different temperature and pressure sensor models at different transmission frequencies and communication protocols.

[0074] After obtaining multiple historical transmission environment feature information, the system clusters this information. Clustering is to classify historical transmission environment feature information with similar characteristics into one category through data mining algorithms, thereby obtaining multiple clustered historical feature groups. Specifically, the system will define a method for calculating feature similarity, such as based on the numerical or text similarity of features such as sensor model, data transmission frequency, communication protocol version, and encryption handshake parameters, and divide historical transmission environment feature information with a similarity higher than a certain threshold into the same clustered historical feature group. For example, for multiple historical transmission environment feature information, where the sensor model is XXX, the data transmission frequency is XXHz, the communication protocol version is V1.0, and the encryption handshake parameters are similar, the information will be clustered into one feature group.

[0075] After clustering, the system needs to extract relevant data from multiple clustered historical feature groups. First, the standard encryption algorithm structure for the target sensor data within the historical encryption management data for each clustered historical feature group is extracted to obtain a set of historical encryption parameter information. The standard encryption algorithm structure includes parameters such as the encryption algorithm type commonly used for that clustered feature group (such as AES, DES, etc.), the algorithm's key length, and the number of iterations. For example, the standard encryption algorithm structure corresponding to a clustered historical feature group is AES-256, with a key length of 256 bits and a number of iterations of 14. This information constitutes the historical encryption parameter information set for that group.

[0076] The system also extracts multiple historical key parameter sets and multiple historical encryption operation time sets submitted by users for encryption under multiple clustered historical feature groups. The historical key parameter set represents the key parameters actually used by the user in previous encryption operations. Different encryption operations may use different keys. The historical encryption operation time set records the specific time of each encryption operation. For example, under a clustered historical feature group, a user may have performed multiple encryption operations, each using a different key. These keys constitute the historical key parameter set, while the time of each operation constitutes the historical encryption operation time set.

[0077] The system categorizes historical key parameter sets based on the degree of deviation between them and historical encryption parameter information sets, obtaining multiple historical base parameter sets. The deviation is calculated by comparing the degree of difference between the historical key parameters and the corresponding parameters in the standard encryption algorithm structure. For example, if the standard encryption algorithm structure requires a key length of 256 bits, if a historical key is 256 bits long, the deviation is 0; if it is 128 bits long, the deviation is larger. Based on the magnitude of the deviation, historical key parameter sets are categorized into different historical base parameter sets, with those with smaller deviations grouped into one category and those with larger deviations into another.

[0078] The system needs to perform correction calculations on multiple historical basic parameter sets based on the ratio of a preset operation time threshold to multiple historical encryption operation time sets to obtain multiple historical encryption parameter sets. The specific steps are: First, calculate the ratio of each historical encryption operation time to the preset operation time threshold to obtain a time correction factor. The preset operation time threshold is a time value determined by system settings or industry standards, such as 24 hours. For each historical encryption operation time, if the operation time is 12 hours, the ratio to the threshold of 24 hours is 0.5, and this ratio is the time correction factor.

[0079] Multiply each parameter in multiple historical basic parameter sets by the corresponding time correction factor to obtain the corrected parameter. For example, if a key parameter value in a historical basic parameter set is XXX and the corresponding time correction factor is 0.5, the corrected parameter value is XXX × 0.5. Finally, the corrected parameters are combined to form multiple historical encryption parameter sets. Each historical encryption parameter set contains the encryption parameters after time correction. These parameters can reflect the encryption parameter characteristics at different points in time and the differences from the standard encryption algorithm structure.

[0080] Example 3: See Figure 3 In a sensor data information management system based on chip-level encryption, the implementation of a historical encryption parameter set optimization and screening module is as follows: the system processes a first historical encryption parameter set from multiple historical encryption parameter sets. The first historical encryption parameter set is a specific encryption parameter set obtained through clustering and correction calculations from historical encryption management data. The set contains multiple different encryption parameters. These parameters may be encryption algorithm parameters used at different time points and in different transmission environments, such as key length, number of encryption iterations, and hash algorithm type.

[0081] In the first historical encryption parameter set, the system needs to select a first baseline encryption parameter. The selection of the first baseline encryption parameter can be based on a variety of methods, such as selecting the encryption parameter that appears the most times in the set, or selecting the parameter that best matches the standard encryption algorithm structure of the clustered historical feature group to which the set belongs. For example, if the standard encryption algorithm structure of the clustered historical feature group to which the first historical encryption parameter set belongs is AES-256, with a key length of 256 bits and 14 iterations, then the system may select the parameter in the set that is closest to the 256-bit key length and 14 iterations as the first baseline encryption parameter.

[0082] After determining the first baseline encryption parameter, the system needs to assign a distribution probability based on the difference between the other encryption parameters in the first historical encryption parameter set and the first baseline encryption parameter, thereby obtaining a first basic probability distribution. The difference here refers to the degree of difference in value or characteristics between the other encryption parameters and the first baseline encryption parameter. For example, for the key length parameter, the first baseline encryption parameter is 256 bits. If the other encryption parameters are 256 bits, the difference is 0; if it is 128 bits, the difference is 128. The size of the difference is negatively correlated with the size of the distribution probability, that is, the smaller the difference, the greater the distribution probability of the encryption parameter being selected; the larger the difference, the smaller the distribution probability. The system will calculate the difference between each other encryption parameter and the first baseline encryption parameter, and then assign the corresponding distribution probability based on the ratio of the difference size to form the first basic probability distribution.

[0083] See Figure 4 The system randomly selects a preset number of encryption parameters from the first historical encryption parameter set to obtain a first filtered encryption parameter group. The preset number of encryption parameters is a fixed value set by the system, for example, 50, which means that 50 encryption parameters are randomly selected from the set to form the first filtered encryption parameter group.

[0084] The system again assigns distribution probabilities based on the difference between the encryption parameters in the first screening encryption parameter group and the first baseline encryption parameter, resulting in a first screening probability distribution. Similarly, the difference between each encryption parameter in the group and the first baseline encryption parameter is calculated, and probabilities are assigned based on the principle of negative correlation between the differences, forming the first screening probability distribution.

[0085] The system needs to calculate the similarity between the first screening probability distribution and the first base probability distribution, and use this as the first screening fitness. Similarity can be calculated using various methods, such as Kullback-Leibler divergence and cosine similarity, by comparing the shapes and distribution trends of the two probability distributions to determine their degree of similarity.

[0086] After processing the first filtered encryption parameter set, the system randomly selects a preset number of encryption parameters from the first historical encryption parameter set to obtain a second filtered encryption parameter set. This is then processed using the same steps as above to obtain a second filtered fitness. Specifically, the difference between the parameters in the second filtered encryption parameter set and the first baseline encryption parameters is calculated, a screening probability distribution is assigned, and the similarity with the first baseline probability distribution is calculated to obtain the second filtered fitness.

[0087] The system continues this optimization and screening process, randomly selecting a preset number of encryption parameters to form new screening groups and calculating their fitness until the screening process converges. This convergence can occur when the change in fitness obtained from multiple consecutive screenings is less than a certain threshold, or when a preset maximum number of screenings has been reached. Upon convergence, the system outputs the screening encryption parameter group with the highest fitness as the first screening encryption parameter group.

[0088] After obtaining the first filtered encryption parameter group, the system sorts the encryption parameters within the group by their timestamp information to obtain a first historical encryption parameter sequence. The timestamp information records the time of the encryption operation corresponding to each encryption parameter. The system arranges the encryption parameters according to the order of their timestamps to form a chronological sequence, which facilitates subsequent analysis of encryption parameter trends.

[0089] After optimizing and arranging the first set of historical encryption parameters, the system applies the same method to multiple other sets of historical encryption parameters. For each set, the system sequentially selects baseline encryption parameters, calculates the underlying probability distribution, randomly selects a selection group, calculates the selection fitness, iterates the selection until convergence, outputs the selected parameter groups, and arranges them in chronological order, ultimately obtaining multiple historical encryption parameter sequences.

[0090] Example 4: In a sensor data information management system based on chip-level encryption, the encryption trend prediction module is implemented as follows: The system needs to collect sample encryption management data from multiple users. This sample data contains information related to encryption management of sensor data by different users in different scenarios. The sample encryption management data must include a sample encryption parameter sequence and a corresponding parameter change identifier. The sample encryption parameter sequence is composed of multiple encryption parameters arranged in chronological order. The encryption parameters include key length, encryption algorithm type, number of iterations, etc. The parameter change identifier is used to indicate the change trend of each parameter relative to the previous parameter, such as an increase or decrease.

[0091] The system collects a set of sample encryption parameter sequences from the sample encryption management data and, based on the parameter change flags within each sample encryption parameter sequence, generates a set of sample enhancement rates and a set of sample reduction rates. The sample enhancement rate refers to the proportion of encryption parameters in the sample encryption parameter sequence that show an enhancement trend, while the sample reduction rate refers to the proportion of encryption parameters that show a reduction trend. For example, if a sample encryption parameter sequence contains 100 parameters, of which 60 are marked as enhancements and 40 as reductions, the sample's enhancement rate is 60% and its reduction rate is 40%.

[0092] The system uses a set of sample encryption parameter sequences as classification inputs, and a set of sample enhancement rates and a set of sample attenuation rates as classification outputs to construct an encryption trend predictor. This can be implemented using machine learning algorithms such as neural networks and random forests. During the construction process, the system preprocesses the sample data, including data cleaning and feature extraction. This processed data is then fed into the algorithm model for training, adjusting the model parameters so that the model can accurately predict the corresponding enhancement and attenuation rates based on the input encryption parameter sequence.

[0093] After building the encryption trend predictor, the system uses it to categorize encryption trends across multiple historical encryption parameter sequences. Historical encryption parameter sequences are derived from a set of historical encryption parameters, optimized, filtered, and time-series-ordered. Each sequence contains encryption parameters arranged in chronological order. These sequences are fed into the encryption trend predictor, which analyzes each sequence and outputs multiple corresponding feature enhancement rates and feature reduction rates. For example, given a historical encryption parameter sequence, the predictor might output the sequence's enhancement and reduction rates across different time periods or feature dimensions.

[0094] After obtaining multiple feature enhancement rates and multiple feature attenuation rates, the system analyzes the similarity between the target transmission environment feature information and multiple clustered historical feature groups. The target transmission environment feature information refers to the transmission environment characteristics of the target sensor data currently being managed, including sensor type and communication protocol parameters. Clustered historical feature groups are multiple groups derived by clustering historical transmission environment feature information. The system calculates the similarity between the target transmission environment feature information and each clustered historical feature group by defining similarity calculation methods, such as the degree of matching based on features such as sensor model, data transmission frequency, communication protocol version, and encryption handshake parameters.

[0095] Based on the similarities between multiple features, the system performs a weighted calculation of multiple feature enhancement rates and multiple feature attenuation rates to obtain the encryption enhancement rate and attenuation rate. Specifically, the feature enhancement rate and attenuation rate corresponding to each clustered historical feature group are weighted based on their similarity to the target transmission environment feature information, with the higher the similarity, the greater the weight. Each feature enhancement rate is multiplied by its corresponding weight and summed to obtain the final encryption enhancement rate; the encryption attenuation rate is calculated similarly. For example, if the target transmission environment feature information has a similarity of 0.8 with clustered historical feature group A and a similarity of 0.2 with group B, and the feature enhancement rate corresponding to group A is 50% and that corresponding to group B is 30%, then the encryption enhancement rate is 50% × 0.8 + 30% × 0.2 = 46%.

[0096] Throughout the implementation process, the system collects sample encryption management data from a large number of users, constructs an encryption trend predictor, and uses machine learning algorithms to learn the changing patterns of encryption parameters from historical data, thereby predicting encryption trends for new historical encryption parameter sequences. By analyzing the similarity between the target transmission environment characteristics and clustered historical feature groups and performing a weighted calculation based on the similarity, the predicted encryption enhancement and reduction rates are more closely aligned with the current transmission environment characteristics, improving the accuracy and pertinence of the predictions.

[0097] Example 5: In a sensor data information management system based on chip-level encryption, the dynamic correction module and encryption scheme generation module are implemented as follows: The dynamic correction module matches target transmission environment feature information with multiple clustered historical feature groups to obtain matching historical feature groups. The target transmission environment feature information includes sensor type (e.g., model, transmission frequency) and communication protocol parameters (e.g., version, encryption handshake parameters). Clustered historical feature groups are grouped by clustering historical transmission environment feature information, with the feature information within each group having similar characteristics.

[0098] The system matches the target transmission environment feature information by calculating the similarity between the features of each clustered historical feature group. This similarity is calculated based on the degree of matching across each feature dimension. For example, identical sensor models are given a higher weight. Parameters such as transmission frequency and protocol version are matched using numerical or textual similarity algorithms (such as edit distance and cosine similarity). The overall similarity is then calculated by combining the scores of each dimension. The system selects the clustered historical feature group with the greatest similarity as the matching historical feature group and obtains the standard matching feature information for that group, including the average value, typical parameter range, or preset standard parameter combination of the transmission environment features within that group.

[0099] The system sets an encryption correction factor based on the deviation between the target transmission environment's characteristic information and the standard matching characteristic information of the matching historical characteristic group. Deviation calculations are performed separately for each characteristic dimension, such as sensor model differences, transmission frequency deviation values, and protocol version differences. The deviation in each dimension is weighted differently based on its impact on encryption strength, and a comprehensive deviation value is ultimately obtained through weighted summation. The encryption correction factor is positively correlated with the comprehensive deviation value: the greater the deviation, the larger the correction factor, and vice versa. For example, if the sensor transmission frequency of the target transmission environment is 20% higher than the frequency in the standard matching characteristic information, and the weight of this dimension is 0.3, the combined weight of the deviations in the other dimensions is 0.7, and the final comprehensive deviation value is 0.15, then the corresponding encryption correction factor may be set to 1.15 (the specific value is determined by the system's preset mapping relationship).

[0100] After obtaining the encryption correction coefficient, the system corrects the encryption enhancement rate and reduction rate output by the encryption trend prediction module. This correction is performed by multiplying the encryption enhancement rate by the encryption correction coefficient and dividing the encryption reduction rate by the encryption correction coefficient (or adjusting it using other preset mathematical relationships) to obtain the corrected enhancement rate and corrected reduction rate. For example, if the original encryption enhancement rate is 30%, the encryption reduction rate is 20%, and the encryption correction coefficient is 1.15, then the corrected enhancement rate is 30% × 1.15 = 34.5%, and the corrected reduction rate is 20% ÷ 1.15 ≈ 17.39%.

[0101] After dynamic correction is completed, the encryption scheme generation module begins to work. This module first collects a set of sample correction enhancement rates and a set of sample correction reduction rates. These sample data come from multiple historical encryption management scenarios. Each sample contains the corresponding correction enhancement rate, correction reduction rate, and the encryption scheme prompt actually adopted by the user. The system sets a sample encryption scheme prompt based on the size of each sample correction enhancement rate and sample correction reduction rate to form a sample encryption scheme prompt set. Among them, the sample encryption scheme prompt includes the key adjustment ratio, and the size of the sample correction enhancement rate and sample correction reduction rate is negatively correlated with the size of the key adjustment ratio. For example, if the correction enhancement rate of a sample is 40% and the correction reduction rate is 10%, the key adjustment ratio may be set to decrease by 15%; if the correction enhancement rate of another sample is 20% and the correction reduction rate is 30%, the key adjustment ratio may be set to increase by 10%. The specific mapping relationship is preset by the system based on the statistical rules of historical data.

[0102] The system uses a set of sample correction enhancement rates and a set of sample correction reduction rates as decision inputs and a set of sample encryption scheme prompts as decision outputs to construct an encryption scheme decider. This decider can be implemented based on regression or classification models in machine learning, such as support vector machines (SVMs) and gradient boosting trees. During the construction process, the system performs preprocessing on the sample data, including normalization and feature engineering. Model parameters are then adjusted through training, enabling the model to accurately predict corresponding encryption scheme prompts based on the input correction enhancement and reduction rates.

[0103] After building the encryption scheme decision maker, the system inputs the correction enhancement rate and correction reduction rate output by the dynamic correction module into the decision maker, which then makes an encryption scheme decision and obtains encryption scheme prompts. These prompts include specific key adjustment suggestions (such as the number of bits to increase or decrease the key length, key update frequency adjustment, etc.), encryption algorithm type recommendations (such as switching from AES-128 to AES-256), or encryption operation process optimization suggestions. For example, if the input correction enhancement rate is 34.5% and the correction reduction rate is 17.39%, the decision maker may output an encryption scheme prompt such as "It is recommended to increase the current key length from 128 bits to 256 bits and adjust the key update frequency from every 24 hours to every 12 hours."

[0104] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.

[0105] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A sensor data information management system based on chip-level encryption, characterized in that: The system comprises: The target data feature acquisition module is used to obtain the target sensor data that the user currently needs to manage, and to collect the target transmission environment feature information of the target sensor data. Based on the target sensor data, the module indexes the historical encryption management data of the target sensor data within the user's historical time. a historical feature information clustering module, configured to cluster the historical transmission environment feature information in the historical encryption management data to obtain a plurality of clustered historical feature groups, extract historical encryption parameter information sets and a plurality of historical encryption management data sets from the plurality of clustered historical feature groups, and process the obtained plurality of historical encryption parameter sets; A historical encryption parameter set optimization and screening module is used to optimize and screen the multiple historical encryption parameter sets respectively to obtain multiple filtered encryption parameter groups, and arrange them in time sequence to obtain multiple historical encryption parameter sequences; An encryption trend prediction module, configured to perform encryption trend prediction based on the plurality of historical encryption parameter sequences to obtain an encryption enhancement rate and a weakening rate; a dynamic correction module, configured to match the target transmission environment characteristic information with the multiple clustered historical characteristic groups to obtain a matching historical characteristic group, and to correct the encryption enhancement rate and attenuation rate based on a deviation between the target transmission environment characteristic information and the standard matching characteristic information of the matching historical characteristic group to obtain a corrected enhancement rate and a corrected attenuation rate; The encryption scheme generation module is used to make encryption scheme decisions based on the modified enhancement rate and the modified weakening rate, obtain encryption scheme prompts, and perform encryption operation prompts.

2. The sensor data information management system based on chip-level encryption according to claim 1, characterized in that: Acquire the target sensor data that the user currently needs to manage, and collect characteristic information of the target transmission environment in which the target sensor data is currently located. Based on the target sensor data, index the historical encrypted management data of the target sensor data within the user's historical time, including: Acquire the target sensor data that the user currently needs to manage, and collect the sensor type and communication protocol parameters of the target sensor data as target transmission environment feature information; According to the target sensor data, an index is performed in the historical encryption management record of the user to obtain the historical encryption management data of the target sensor data.

3. The sensor data information management system based on chip-level encryption according to claim 1, characterized in that: Clustering the historical transmission environment feature information in the historical encryption management data to obtain a plurality of clustered historical feature groups, extracting a set of historical encryption parameter information and a plurality of historical encryption management data sets under the plurality of clustered historical feature groups, and processing to obtain a plurality of historical encryption parameter sets, including: Acquire multiple pieces of historical transmission environment feature information in the historical encryption management data, perform clustering processing, and obtain multiple clustered historical feature groups; Extracting a standard encryption algorithm structure of target sensor data in the historical encryption management data under the multiple clustered historical feature groups, obtaining a historical encryption parameter information set, and extracting multiple historical key parameter sets and multiple historical encryption operation time sets encrypted and submitted by the user under the multiple clustered historical feature groups; Obtaining multiple historical basic parameter sets by classification according to the deviation magnitudes of the multiple historical key parameter sets from the historical encryption parameter information set; According to the ratio of the preset operation time threshold and the multiple historical encryption operation time sets, the multiple historical basic parameter sets are corrected and calculated to obtain multiple historical encryption parameter sets.

4. The sensor data information management system based on chip-level encryption according to claim 1, characterized in that: The plurality of historical encryption parameter sets are respectively optimized and screened to obtain a plurality of screened encryption parameter groups, and are arranged in chronological order to obtain a plurality of historical encryption parameter sequences, including: Selecting and obtaining a first baseline encryption parameter from a first historical encryption parameter set in the plurality of historical encryption parameter sets; Assigning distribution probabilities based on the differences between other encryption parameters in the first historical encryption parameter set and the first benchmark encryption parameter to obtain a first basic probability distribution, wherein the size of the difference is negatively correlated with the size of the distribution probability; Optimizing and screening the first historical encryption parameter set according to the first basic probability distribution to obtain a first screened encryption parameter group; Sorting the plurality of encryption parameters in the first screening encryption parameter group according to timestamp information to obtain a first historical encryption parameter sequence; Optimize and screen other multiple historical encryption parameter sets and arrange them in time sequence to obtain multiple historical encryption parameter sequences.

5. The sensor data information management system based on chip-level encryption according to claim 4, characterized in that: Optimizing and screening the first historical encryption parameter set according to the first basic probability distribution to obtain a first screened encryption parameter group includes: Randomly selecting a preset number of encryption parameters from the first historical encryption parameter set to obtain a first filtered encryption parameter group; Assigning distribution probabilities according to differences between encryption parameters in the first screening encryption parameter group and the first benchmark encryption parameters to obtain a first screening probability distribution; Calculating the similarity between the first screening probability distribution and the first basic probability distribution as a first screening fitness; Randomly extracting a preset number of screening encryption parameters from the first historical encryption parameter set again to obtain a second screening encryption parameter group, and processing the obtained second screening fitness; Continue to optimize and filter until convergence, and output the filtering encryption parameter group with the largest filtering fitness as the first filtering encryption parameter group.

6. The sensor data information management system based on chip-level encryption according to claim 1, characterized in that: Performing encryption trend prediction based on the multiple historical encryption parameter sequences to obtain encryption enhancement rate and weakening rate includes: According to the sample encryption management data of multiple users, a sample encryption parameter sequence set is collected, and a sample enhancement rate set and a sample attenuation rate set are obtained according to a parameter change identifier in each sample encryption parameter sequence; Using the sample encryption parameter sequence set as classification input, using the sample enhancement rate set and the sample attenuation rate set as classification output, to construct an encryption trend predictor; Based on the encryption trend predictor, the encryption trend of the plurality of historical encryption parameter sequences is classified to obtain a plurality of feature enhancement rates and a plurality of feature weakening rates; The target transmission environment feature information and the similarity of the multiple clustering historical feature groups are analyzed, and the multiple feature enhancement rates and the multiple feature reduction rates are weightedly calculated according to the sizes of the multiple feature similarities to obtain the encryption enhancement rate and reduction rate.

7. The sensor data information management system based on chip-level encryption according to claim 6, characterized in that: Matching the target transmission environment feature information with the multiple clustered historical feature groups to obtain a matching historical feature group, and correcting the encryption enhancement rate and reduction rate according to a deviation between the target transmission environment feature information and the standard matching feature information of the matching historical feature group to obtain a corrected enhancement rate and a corrected reduction rate, including: Selecting the clustered historical feature group with the greatest similarity as the matching historical feature group, and obtaining standard matching feature information of the matching historical feature group; setting an encryption correction coefficient according to a deviation between the target transmission environment feature information and the standard matching feature information of the matching historical feature group; The encryption correction coefficient is used to perform correction calculation on the encryption enhancement rate and attenuation rate to obtain a corrected enhancement rate and a corrected attenuation rate.

8. The sensor data information management system based on chip-level encryption according to claim 1, characterized in that: According to the modified enhancement rate and the modified weakening rate, an encryption scheme decision is made, an encryption scheme prompt is obtained, and an encryption operation prompt is performed, including: Collecting a set of sample correction enhancement rates and a set of sample correction attenuation rates, and setting a sample encryption scheme prompt according to the size of each sample correction enhancement rate and sample correction attenuation rate to obtain a set of sample encryption scheme prompts, wherein each sample encryption scheme prompt includes a key adjustment ratio, and the sizes of the sample correction enhancement rate and the sample correction attenuation rate are negatively correlated with the size of the key adjustment ratio; The sample modified enhancement rate set and the sample modified weakening rate set are used as decision inputs, and the sample encryption scheme prompt set is used as decision output to construct an encryption scheme decider; The encryption scheme decider is used to make an encryption scheme decision on the modified enhancement rate and the modified weakening rate to obtain an encryption scheme prompt.

9. The sensor data information management system based on chip-level encryption according to claim 2, characterized in that: The sensor type and communication protocol parameters of the target sensing data are collected as target transmission environment characteristic information, including: Identify the sensor model and data transmission frequency of the target sensor data as the sensor type; Parsing the communication protocol version and encryption handshake parameters of the target sensor data as communication protocol parameters; The sensor type and communication protocol parameters are combined to form target transmission environment characteristic information.

10. The sensor data information management system based on chip-level encryption according to claim 3, characterized in that: According to the ratio of the preset operation time threshold and the multiple historical encryption operation time sets, the multiple historical basic parameter sets are corrected and calculated to obtain multiple historical encryption parameter sets, including: Calculate the ratio of each historical encryption operation time to the preset operation time threshold to obtain a time correction factor; Multiplying each parameter in the plurality of historical basic parameter sets by a corresponding time correction factor to obtain a corrected parameter; The modified parameters are combined to form multiple historical encryption parameter sets.

Citation Information

Patent Citations

  • Industrial personal computer hardware security module integration method and system

    CN118842576A

  • Data encryption transmission system and method

    CN119544242A