Network information data transmission security method based on advanced encryption standard (AES)

Through the AES-based network information data transmission security method, a multi-level defense system is built using loop iterative generation wheel keys and AES-GCM mode, which solves the problems of update lag of network information security technology and equipment heterogeneity, and realizes efficient, secure and flexible data transmission and adapts to complex network environments.

CN120498646APending Publication Date: 2025-08-15GUANGDONG UNIV OF SCI & TECH

Patent Information

Application Number
CN202510590861.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Existing network information security technologies are difficult to fully respond to multi-level, intelligent and large-scale network attacks, especially in IoT devices, equipment heterogeneity and low computing power constraints lead to lightweight security protocol design performance bottlenecks, and encryption technology is lagging behind, security protection is complex, and there is a lack of a unified and efficient security protection network.

Method used

AES-based network information data transmission security method is adopted to generate round keys through iterative cycles, combining AES-GCM mode, GCM authentication module, key symmetry constraints, forced unique IV, HMAC authentication tag generation, etc., a multi-level defense system is built to ensure the confidentiality, integrity and availability of data transmission, and support flexible security policy configuration.

Benefits of technology

Significantly enhance data security, improve transmission efficiency, simplify implementation and management, adapt to future security trends, provide efficient, reliable and easy-to-use security solutions, resist a variety of attack methods, and are suitable for complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498646A_ABST
    Figure CN120498646A_ABST
Patent Text Reader

Abstract

The invention relates to network information security and cryptography, and provides an AES-based network information data transmission security method, which comprises the following steps of: generating an information key, namely generating a round key through loop iteration; the encryption process of information data transmission comprises the following steps: encrypting a plaintext after preprocessing, and generating an intermediate ciphertext and an integrity verification label; in the information data decryption process, the plaintext is recovered through reverse operation after the label is verified; the data security constraint of the information is carried out, and a multi-level defense system is constructed; aP I mapping for information transmission, and calling an interface to realize encryption, decryption and authentication verification; information data encryption complexity is controlled, complexity is optimized, and big data are encrypted in a blocking mode; the information data security is guaranteed, and the transmission security is ensured. The method significantly enhances data security, improves transmission efficiency, constructs multi-level security defense, provides flexibility and adaptability, simplifies implementation and management, conforms to the future security trend, and provides an efficient, reliable and easy-to-use solution for network information security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network information security and cryptography, and in particular to a network information data transmission security method based on the Advanced Encryption Standard (AES). Background Art

[0002] With the rapid development and widespread application of internet technology, the security of network information data transmission has become increasingly prominent. Currently, cyberattack methods are constantly evolving, and attack paradigms are gradually developing towards multi-layered, intelligent, and large-scale approaches, posing a severe challenge to the existing network information security technology system. Although cryptography-based end-to-end encryption technologies, machine learning-based abnormal behavior detection technologies, and dynamic access control technologies under the zero-trust architecture have formed a collaborative protection framework, existing technologies still have structural flaws and are unable to fully address increasingly complex security threats.

[0003] Specifically, while classical encryption algorithms such as AES provide a certain degree of security for data transmission, they face potential threats from new attack methods such as quantum computing, potentially challenging the strength of mathematical proofs based on difficult number theory problems that underpin their security. Furthermore, industry consensus on post-quantum cryptography standards has yet to be reached, leading to a lag in the advancement of encryption technology. Furthermore, while the application of deep learning models in security has enhanced the intelligence of security protection, issues such as interpretability and vulnerabilities to adversarial attack remain to be addressed. The optimal balance between data privacy and model utility within the federated learning framework is also difficult to achieve, further complicating security protection.

[0004] In the IoT device sector, device heterogeneity and low computing power constraints have led to performance bottlenecks in lightweight security protocol designs, making it difficult to meet the security needs of large-scale IoT devices. There is an inherent contradiction between the exponential growth of system complexity and the closed nature of security verification. For example, multi-tenant isolation in cloud-native environments requires comprehensive protection across the virtualization layer, container management layer, and service chain. Traditional perimeter defense models are no longer suitable for borderless computing scenarios.

[0005] In terms of scientific research, there has been insufficient breakthrough progress at the basic theoretical level. For example, the integration of lattice construction and coding theory of quantum-resistant cryptography still needs in-depth research; there is a large room for optimization at the engineering implementation level. For example, the trade-off between key update cycle and computing delay in multi-party secure computing protocols has not yet reached the optimal level; the fragmentation of cross-industry security standards at the collaborative innovation level is serious, resulting in a significant island effect in the defense system, making it difficult to form a unified and efficient security protection network.

[0006] Therefore, developing an efficient, secure and flexible network information data transmission security method to cope with the structural defects of existing technologies and increasingly complex security threats has become an urgent need in the current network information security field. Summary of the Invention

[0007] To address the above problems, the present invention aims to solve the security threats faced in the existing network information data transmission process, such as data eavesdropping, tampering, and replay attacks, by comprehensively using symmetric encryption algorithms, secure transmission protocols, and multi-level security constraint mechanisms, thereby ensuring the confidentiality, integrity, and availability of sensitive data during transmission.

[0008] The technical solution adopted by the present invention is: a network information data transmission security method based on AES, comprising the following steps:

[0009] S1. Information key generation step: Generate multiple round keys through cyclic iteration. The initial round key is the original key. Each subsequent round key is generated by combining the previous round key with cyclic shift, byte replacement, and XOR with the round constant until the number of keys required for the number of encryption rounds is generated;

[0010] S2. The encryption process for information data transmission: perform XOR and padding preprocessing on the plaintext and the initialization vector (IV), complete AES encryption through the initial round and the main iteration round, remove the column mixing in the final round to generate the intermediate ciphertext, and then use the GCM authentication module to combine the ciphertext and IV to generate the integrity verification tag AuthTag;

[0011] S3. Information data decryption process steps: After verifying the validity of the authentication tag, reverse the encryption operation steps to restore the ciphertext to plaintext, and restore the original plaintext by XORing the initialization vector and removing the padding data;

[0012] S4, Information data security constraint step: through key symmetry constraint, mandatory unique IV, construction of timestamp Nonce and HMAC-based authentication tag generation, a multi-level defense system is jointly built;

[0013] S5, API mapping step for information transmission: Calling a specific interface to perform authenticated encryption on plaintext and decryption and authentication verification on ciphertext, using AES-GCM mode with padding to convert the plaintext, key, and initialization vector into ciphertext and generate an authentication tag;

[0014] S6, information data encryption complexity control step: control the time complexity and space complexity of the encryption process, and encrypt the big data in blocks according to the specific engine performance;

[0015] S7. Information data security assurance steps: Ensure the security of data transmission through key confidentiality and anti-differential power consumption measures.

[0016] In the S1 information key generation step, the round key is generated by the following formula:

[0017]

[0018] Where W[i] represents each 16-byte block in the extended key, and the g function includes operations such as circular shift, byte replacement, and XOR with the round constant. The result of the circular shift of the previous round key is first XORed with the same shift result after byte replacement, and then XORed with the current round constant to finally generate the new round key.

[0019] In the encryption process step of the S2 information data transmission, the GCM authentication module generates the integrity verification tag AuthTag using the following formula:

[0020]

[0021] where Ai and Cj are the 16-byte blocks of AAD and ciphertext respectively, m and n are the number of blocks of AAD and ciphertext respectively, and |A| and |C| are the lengths of AAD and ciphertext respectively.

[0022] In the S3 information data decryption process, the authentication tag is verified using the following formula:

[0023]

[0024] Where C is the ciphertext, A is the additional authentication data, IV is the initialization vector, AuthTag is the authentication tag generated during encryption, and K is the key.

[0025] The data security constraint step of the S4 information includes the following specific measures:

[0026] S41 key symmetry constraint: ensures key derivation consistency by XORing round keys;

[0027] S42 enforces unique IV: prevents key stream reuse between sessions;

[0028] S43 constructs a timestamp Nonce: This ensures that the encryption process is resistant to replay attacks.

[0029] S44 HMAC-based authentication tag generation: binds ciphertext, IV, and key to achieve data integrity verification.

[0030] In the API mapping step of the S5 information transmission, the encryption process uses the AES-GCM mode combined with PKCS7 padding, and the decryption process verifies the data integrity and restores the plaintext by inputting the ciphertext, key, IV and authentication tag.

[0031] In the S6 information data encryption complexity control step, the time complexity is O(n*m), where n is the number of data blocks and m is the number of rounds; the space complexity is O(k), where k is the key length.

[0032] In the S7 information data security assurance step, key confidentiality is achieved by:

[0033] If the attacker cannot obtain the key or the private key in the asymmetric encryption transmission, the plaintext cannot be cracked;

[0034] Anti-differential power consumption is achieved through hardware-level protection, and information transmission runs in the TEE security zone, which can resist side-channel attacks.

[0035] The AES-based network information data transmission security method further includes the following steps:

[0036] First, the plaintext to be encrypted is divided into independent groups according to fixed length and encoded into a byte state matrix as a unified operation carrier;

[0037] Then, in each round of iteration, the state matrix first performs a row shift operation and then performs a composite transformation with the current round key, including bitwise XOR and byte substitution operations;

[0038] Finally, through multiple rounds of precise iterative nonlinear transformation and key deep binding mechanism, the plaintext data is gradually converted into high-entropy ciphertext.

[0039] In the multi-round precise iterative nonlinear transformation and key deep binding mechanism, the four-stage dynamic evolution of the state matrix includes:

[0040] Initial stage: After filling the plaintext into a byte matrix, the original linear relationship between bits is destroyed through byte substitution;

[0041] Row shift stage: differential offset reorganization of the bytes in the row of the state matrix;

[0042] Column-wise reconstruction phase: vertical diffusion of bytes within a column is achieved through finite field operations;

[0043] Round key addition phase: The current round key is tightly coupled with the state matrix through a byte-by-byte XOR operation.

[0044] The beneficial effects of the present invention are as follows: the AES-based network information data transmission security method proposed in the present invention has shown significant beneficial effects in improving data security, transmission efficiency, flexibility and adaptability, simplifying implementation and management, and complying with future security trends. It provides an efficient, reliable, and easy-to-use solution for the field of network information security. Compared with the existing technology, it has the following significant beneficial effects:

[0045] Enhanced data security: By adopting the AES symmetric encryption algorithm, combined with multiple encryption modes (such as CBC mode) and initialization vectors (IV), the confidentiality and randomness of data during transmission are significantly enhanced, effectively resisting various cryptographic attacks, including but not limited to brute force cracking, differential attacks, and linear attacks, ensuring the absolute security of sensitive data during transmission.

[0046] Improved transmission efficiency: The AES encryption and decryption algorithm is renowned for its high efficiency, making it particularly well-suited for the frequent data transmission required by network information. This method significantly improves data transmission efficiency by optimizing the encryption process, reducing unnecessary computational overhead and meeting the stringent real-time and high-efficiency requirements of modern network communications.

[0047] Multi-layered security defense: This method not only relies on the security of the strong encryption algorithm itself, but also builds a comprehensive, multi-layered security defense system through multi-layered security constraint mechanisms such as key symmetry constraints, mandatory unique IV, construction of timestamp Nonce, and HMAC-based authentication tag generation. It effectively resists security threats such as key leakage, IV duplication, replay attacks, and data forgery.

[0048] Flexibility and Adaptability: This method supports the selection of key lengths of varying lengths based on data security, providing a high level of security configuration options and enabling users to flexibly adjust security policies based on their specific needs. Furthermore, the integration of the HTTPS protocol and SSL / TLS encryption layer further enhances the integrity and confidentiality of data transmission, making it suitable for a variety of complex network environments and security requirements.

[0049] Simplified Implementation and Management: Encryption and decryption functions are implemented by calling standardized APIs (such as the wx.crypto interface), simplifying the implementation and management of security technologies. Developers can easily integrate this method into existing systems without having to deeply understand the principles of complex encryption algorithms, reducing technical barriers and implementation costs.

[0050] In line with future security trends: In the face of potential threats from new attack methods such as quantum computing, this method is optimized and improved based on classic and widely recognized encryption algorithms such as AES. It not only maintains compatibility with existing security systems, but also lays the foundation for future migration to higher-level security technologies such as quantum-resistant cryptography, which is in line with the long-term development trend of network security technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a schematic diagram of the overall architecture of the present invention;

[0052] Figure 2 It is a schematic diagram of the layered architecture in the present invention;

[0053] Figure 3 It is a schematic diagram of the flow process in the present invention;

[0054] Figure 4 This is a schematic diagram of matrix rotation in the present invention;

[0055] Figure 5 It is a schematic diagram of ciphertext output in the present invention;

[0056] Figure 6 This is the rotation key generation in the present invention. DETAILED DESCRIPTION

[0057] The following describes the specific implementation of the present invention in detail with reference to the accompanying drawings:

[0058] Example 1: A secure method for transmitting network information data based on AES

[0059] like Figure 1-6 As shown, a network information data transmission security method based on AES achieves efficiency, security and flexibility by spontaneously and reasonably using keys according to the importance of data. It can resist various cryptographic attacks and protect the security of sensitive data. For network information data security application scenarios, the AES symmetric encryption algorithm is adopted, which supports key encryption and decryption, and combines the HTTPS protocol and SSL / TLS encryption layer to protect the confidentiality and integrity of data during transmission. The method adopts encryption modes such as CBC and introduces initialization vectors to enhance the randomness and security of encryption. Compared with the existing technology, this method not only adopts strong encryption algorithms and security protocols, but also combines multiple encryption modes to provide flexible security protection, and focuses on key management and secure transmission to ensure the security and reliability of the encryption process. It includes the following steps:

[0060] S1. Information key generation

[0061] First, a key expansion process is implemented to iteratively generate multiple round keys (RoundKeys). The initial round key is the original key (Key). Each subsequent round key is generated by combining the previous round key with a cyclic shift (RotWord), byte substitution (SubWord), and XOR with a round constant (Rcon). Specifically, the result of the cyclic shift of the previous round key is first XORed with the same shift result after byte substitution, and then XORed with the current round constant to generate the new round key. This process is repeated until the required number of keys is generated, providing key material for multi-round encryption of the block cipher algorithm.

[0062]

[0063] W[i] represents each 16-byte block in the extended key, where the g function contains operations such as circular shift, byte replacement, and XOR with the round constant.

[0064] S2. Encryption process of information data transmission

[0065] Through a multi-round encryption and authentication mechanism, plaintext is converted into ciphertext and an authentication tag is generated. The specific process includes: first, XORing and padding the plaintext with the initialization vector (IV), followed by AES encryption through an initial round (including key addition, byte substitution, and row shifting) and 10 main iterations (adding column mixing). In the final round, column mixing is removed to generate an intermediate ciphertext. Finally, the GCM authentication module combines the ciphertext and IV to generate the integrity verification tag AuthTag, achieving authenticated encryption that simultaneously protects data confidentiality and integrity.

[0066] GCM authentication is as follows:

[0067]

[0068] where Ai and Cj are 16-byte blocks of AAD and ciphertext (or padding blocks if less than 16 bytes), m and n are the number of blocks of AAD and ciphertext, and |A| and |C| are the lengths of AAD and ciphertext, respectively.

[0069] S3. Information data decryption process

[0070] After verifying the validity of the authentication tag (AuthTag), the ciphertext is gradually restored to plaintext by reversing the encryption steps (including reverse row shift, reverse byte replacement, reverse column mixing, and round key removal). After decryption, the original plaintext is restored by XORing the initialization vector (IV) and removing the padding data. If the authentication tag verification fails (e.g., the data has been tampered with), an error (⊥) is directly returned, thus achieving both data confidentiality recovery and strong integrity verification.

[0071] Certification label verification:

[0072]

[0073] C is the ciphertext, A is the additional authentication data (AAD), IV is the initialization vector, AuthTag is the authentication tag generated during encryption, and K is the key.

[0074] S4. Data security constraints of information

[0075] Through key symmetry constraints (round key XOR cancellation ensures key derivation consistency), mandatory unique IV (prevents key stream reuse between sessions), construction of timestamp Nonce (protects the encryption process against replay attacks), and HMAC-based authentication tag generation (binding ciphertext, IV and key to achieve data integrity verification), we jointly build a multi-level defense system to ensure the confidentiality, freshness, tamper resistance and session independence of encrypted data, and resist security threats such as key leakage, IV duplication, replay attacks and data forgery.

[0076] 1. Key symmetry constraint (round key XOR offset ensures key derivation consistency)

[0077] Ciphertexti=Plaintexti⊕KeyStreami

[0078] Among them, KeyStreami is the key stream generated by the round key Ki and other parameters (such as a counter).

[0079] 2. Enforce unique IV (to prevent keystream reuse between sessions)

[0080] KeyStream = h(K, IV, other parameters)

[0081] Here, h is a function that generates a key stream based on the key K, the initialization vector IV, and other parameters such as a counter.

[0082] 3. Construct a Nonce with a timestamp (to protect the encryption process from replay attacks)

[0083] N′=(N,T)

[0084] During the encryption process, N′ is used as part of the generated keystream to ensure that each encryption is unique and resistant to replay attacks.

[0085] 4. HMAC-based authentication tag generation (binding ciphertext, IV and key to achieve data integrity verification)

[0086] AuthTag = HMAC(K,C||IV)

[0087] IV is the initialization vector. HMAC (Hash-based Message Authentication Code) can be expressed as a function HMAC, which generates an authentication tag based on the key K and the message (the combination of the ciphertext and IV).

[0088] S5. API mapping for information transmission

[0089] By calling the wx.crypto interface, authenticated encryption is performed on the plaintext (generating ciphertext and integrity tag authTag), as well as decryption and authentication verification. Specifically, the encryption process uses the AES-GCM mode with PKCS7 padding to convert the plaintext, key, and initialization vector (IV) into ciphertext and generate an authentication tag. The decryption process verifies the data integrity by passing in the ciphertext, key, IV, and authentication tag, and then restores the plaintext. This implementation ensures the confidentiality, integrity, and tamper resistance of data transmission through the inherent encryption and authentication binding mechanism of the GCM mode, making it suitable for scenarios where both data security and identity verification are required.

[0090] 1. Key expansion:

[0091] K0,K1,…,K10=KeyExpansion(K)

[0092] 2. Generate a counter

[0093] Counteri=Increment(IV,i)

[0094] 3. Comprehensive decryption

[0095]

[0096] Where C is the ciphertext, T is the authentication tag, K is the key, IV is the initialization vector, A is the additional authentication data, and P′ is the decrypted plaintext (which may be empty or incorrect due to verification failure).

[0097] S6. Information data encryption complexity

[0098] Time complexity: O(n*m), where n is the number of data blocks and m is the number of rounds (10 / 12 / 14).

[0099] Space complexity: O(k), where k is the key length.

[0100] Information transmission restrictions: The JS engine has low performance and encrypts large data in blocks.

[0101] S7. Information Data Security

[0102] 1. Key confidentiality: If the attacker cannot obtain the key or the private key in asymmetric encryption transmission, the plaintext cannot be cracked.

[0103] 2. Anti-differential power consumption: Since information transmission runs in the TEE security zone, hardware-level protection can resist side-channel attacks.

[0104] This embodiment is based on the AES network information data transmission security method, which uses the symmetric encryption algorithm AES. It can select different bit keys based on data security, provide high-level security, and is extremely difficult to crack, effectively protecting users' sensitive data during network information transmission. AES encryption and decryption speeds are fast, which is particularly suitable for the frequent data transmission needs of network information, significantly improving transmission efficiency. Combined with the HTTPS protocol, it ensures the integrity and confidentiality of data during transmission, effectively resists eavesdropping and tampering, and enhances user trust. AES supports multiple operating modes, such as CBC and CTR, which can be flexibly selected according to security requirements to enhance the randomness and security of encryption.

[0105] Step A: When data enters the sending end and is ready for transmission, it starts to be encrypted using AES, which can maintain relative stability. The specific number of rounds and the flow of keys are as follows:

[0106] Step B: First, the plaintext to be encrypted is divided into independent groups of fixed length of 128 bits and encoded into a 4×4 byte state matrix as a unified operation carrier; in each round of iteration, the state matrix first performs a row shift (ShiftRows) operation, breaking the linear correlation between rows by cyclic left shifting of different offsets, prompting the bytes to be redistributed across rows, forming a horizontal diffusion of the vertical data stream; then, the shifted matrix is subjected to a composite transformation with the current round key - first, byte-level mask superposition is achieved through bit-wise XOR, and then combined with the byte substitution (SubBytes) operation over the GF(2^8) finite field, the nonlinear affine transformation is completed using the S-box lookup table, and the bit level between bytes within the matrix is driven based on polynomial multiplication. Coupling forms a complex mapping relationship of multi-byte collaborative control; in the iterative process, row shift and byte substitution enhance the dynamic reconstruction capability of data in row and column dimensions through alternating effects, so that the value of each output byte is jointly determined by multiple bytes of the input matrix through cross-row and cross-column mixed operations. Finally, after completing the first 9 rounds of full iteration (including row shift, byte substitution, round key XOR and column-wise diffusion coupling), some redundant operations are omitted in the last round to adapt to the ciphertext output format, ensuring that the encryption result has an avalanche effect (a single-bit plaintext change can trigger a cascade fluctuation of the entire ciphertext) and strong resistance to differential analysis. The core lies in the construction of a multi-dimensional nonlinear diffusion network through cross-row rotation driven by row shift and column-wise coupling driven by byte substitution.

[0107] Step C gradually converts plaintext data into high-entropy ciphertext through multiple rounds of precise iterative nonlinear transformation and key deep binding mechanism. The core lies in the four-stage dynamic evolution of the state matrix: in the initial stage, after filling the plaintext into a 4×4 byte matrix, byte substitution (SubBytes) destroys the original linear relationship between bits through S-box nonlinear mapping to achieve preliminary data obfuscation; the row shift (ShiftRows) stage is characterized by cross-row cyclic shift, and the bytes in the rows of the state matrix are differentially offset and reorganized. The local regularity of the data arrangement is broken by the staggered interleaving of bytes between rows, combined with the column-wise Galois field polynomial reconstruction (the vertical dimension diffusion of bytes in the column is achieved through finite field operations) to form multi-dimensional information interleaving in the row and column space; the final round key addition (AddRoundKey) stage tightly couples the current round key with the state matrix through byte-by-byte XOR operations, ensuring that each round of transformation is deeply bound to the key stream information. Through the synergistic effects of nonlinear substitution, intra-row cyclic shift, intra-column reconstruction, and key XOR fusion, these four stages make the state matrix become a composite nonlinear function of plaintext and multi-round keys after 10 rounds (AES-128) or 14 rounds (AES-256) of iteration. The final output ciphertext is completely decoupled from the original plaintext in terms of statistical characteristics, and the complex cross-diffusion characteristics between rows and columns effectively block cryptographic attack paths such as differential analysis and linear analysis, building a multi-layer defense system based on high-order nonlinearity and dynamic key binding.

[0108] Step D: Similar to plaintext, the key is also represented by a matrix. The received key matrix is expanded into a 44-byte sequence through the key encoding function. The first four bytes of the sequence are the original key, which is used as the initial key in the encryption operation; the next 40 bytes are divided into 10 groups of 4 bytes each, which serve as the rotation key.

[0109] Finally, the user's input operations undergo a series of encryption and decryption and are finally securely transmitted to the receiving end.

[0110] Example 2: A secure method for transmitting network information data based on AES (Advanced Encryption Standard)

[0111] The overall framework and logic of this embodiment are the same as those of Example 1. More specifically, this embodiment relates to a method for achieving efficient, secure, and flexible data transmission security assurance during data transmission by using the AES symmetric encryption algorithm, combined with the HTTPS protocol and SSL / TLS encryption layer, and the GCM (Galois / Counter Mode) authentication mechanism. The method specifically includes the following steps:

[0112] Step S1: Information key generation

[0113] 1. Initialize the original key. The length can be 128 bits, 192 bits, or 256 bits, depending on data security requirements.

[0114] 2. Execute the key expansion process to generate multiple round keys (RoundKeys). The initial round key is the original key Key. Each subsequent round key is generated by combining the previous round key with a combination of cyclic shift (RotWord), byte substitution (SubWord), and XOR with the round constant (Rcon).

[0115] 3. In a specific implementation, as shown in Example 1, define a function g that includes a circular shift, byte replacement, and XOR with a round constant. The result of the circular shift of the previous round key is first XORed with the same shifted result after byte replacement, and then XORed with the current round constant to generate the new round key.

[0116] 4. Repeat the above process until the number of keys required for the number of encryption rounds is generated (10 rounds for AES-128, 12 rounds for AES-192, and 14 rounds for AES-256).

[0117] Step S2: Encryption process of information data transmission

[0118] 1. Receive the plaintext data to be encrypted and generate a unique initialization vector IV.

[0119] 2. Perform XOR and padding on the plaintext and the initialization vector IV to ensure that the data length is an integer multiple of the AES encryption block size (128 bits).

[0120] 3. AES-style encryption is performed through an initial round (including key addition, byte substitution, and row shifting) and main iteration rounds (9 for AES-128, 11 for AES-192, and 13 for AES-256, each of which includes key addition, byte substitution, row shifting, and column mixing). The final round removes the column mixing to generate the intermediate ciphertext.

[0121] 4. Generate the integrity verification tag AuthTag by combining the ciphertext and IV through the GCM authentication module. The GCM authentication formula is the same as that in Example 1.

[0122] Step S3: Information data decryption process

[0123] 1. Receive ciphertext data, initialization vector IV, additional authentication data AAD, and authentication tag AuthTag generated during encryption.

[0124] 2. On the premise of verifying the validity of the authentication tag, reverse the encryption operation steps (including reverse row shift, reverse byte replacement, reverse column mixing and round key removal) to gradually restore the ciphertext to plaintext.

[0125] 3. The verification of the authentication tag is implemented using the formula in Example 1. If AuthTag′=AuthTag, the verification is successful and decryption continues; otherwise, an error (⊥) is directly returned.

[0126] 4. After decryption is completed, the original plaintext is restored by XORing the initialization vector IV and removing the padding data. Step S4: Data security constraints of information

[0127] 1. Key symmetry constraint: Ensure the consistency of key derivation through round key XOR cancellation to prevent security threats caused by key leakage.

[0128] 2. Enforce unique IV: Generate a unique initialization vector IV for each encryption session to prevent key stream reuse between sessions.

[0129] 3. Construct a timestamp-protected Nonce: Embed timestamp information in the initialization vector IV to protect the encryption process from replay attacks.

[0130] 4. HMAC-based authentication tag generation: In the GCM authentication module, the HMAC (Hash-based Message Authentication Code) mechanism is used to bind the ciphertext, IV, and key to achieve data integrity verification.

[0131] Step S5: API mapping for information transmission

[0132] 1. Call the wx.crypto interface (or the encryption library interface in the corresponding programming language) to perform authenticated encryption on the plaintext (generate ciphertext and integrity tag authTag).

[0133] 2. The encryption process uses AES-GCM mode combined with PKCS7 padding to convert plaintext, key and initialization vector IV into ciphertext and generate an authentication tag.

[0134] 3. The decryption process calls the corresponding decryption interface by passing in the ciphertext, key, IV and authentication tag, and restores the plaintext after verifying the data integrity.

[0135] Step S6: Information data encryption complexity control

[0136] 1. The time complexity of the control encryption process is O(n*m), where n is the number of data blocks and m is the number of rounds (10 for AES-128, 12 for AES-192, and 14 for AES-256).

[0137] 2. The control space complexity is O(k), where k is the key length.

[0138] 3. For low-performance environments such as JS engines, large data is encrypted in blocks.

[0139] Step S7: Information data security assurance

[0140] 1. Key confidentiality: Ensure the security of keys during transmission and storage. If an attacker cannot obtain the key or the private key in asymmetric encryption transmission, they cannot decrypt the plaintext.

[0141] 2. Anti-differential power consumption: Resist side-channel attacks (such as differential power consumption analysis) through hardware-level protection measures (such as TEE security zone).

[0142] This embodiment provides a secure method for network information data transmission based on AES, which can efficiently, securely, and flexibly protect sensitive data during network information transmission. Through multiple rounds of precise iterative nonlinear transformations and a deep key binding mechanism, the encryption result is ensured to have an avalanche effect and strong resistance to differential analysis, effectively resisting various cryptographic attacks. At the same time, combined with the HTTPS protocol and SSL / TLS encryption layer, as well as the GCM authentication mechanism, the integrity and confidentiality of data during transmission are ensured, significantly enhancing user trust.

Claims

1. A network information data transmission security method based on AES, characterized by: The following steps are involved: S1. Information key generation step: Generate multiple round keys through cyclic iteration. The initial round key is the original key. Each subsequent round key is generated by combining the previous round key with cyclic shift, byte replacement, and XOR with the round constant until the number of keys required for the number of encryption rounds is generated; S2. The encryption process for information data transmission: perform XOR and padding preprocessing on the plaintext and the initialization vector (IV), complete AES encryption through the initial round and the main iteration round, remove the column mixing in the final round to generate the intermediate ciphertext, and then use the GCM authentication module to combine the ciphertext and IV to generate the integrity verification tag AuthTag; S3. Information data decryption process steps: After verifying the validity of the authentication tag, reverse the encryption operation steps to restore the ciphertext to plaintext, and restore the original plaintext by XORing the initialization vector and removing the padding data; S4, Information data security constraint step: through key symmetry constraint, mandatory unique IV, construction of timestamp Nonce and HMAC-based authentication tag generation, a multi-level defense system is jointly built; S5, API mapping step for information transmission: Calling a specific interface to perform authenticated encryption on plaintext and decryption and authentication verification on ciphertext, using AES-GCM mode with padding to convert the plaintext, key, and initialization vector into ciphertext and generate an authentication tag; S6, information data encryption complexity control step: control the time complexity and space complexity of the encryption process, and encrypt the big data in blocks according to the specific engine performance; S7. Information data security assurance steps: Ensure the security of data transmission through key confidentiality and anti-differential power consumption measures.

2. The AES-based network information data transmission security method according to claim 1, characterized in that: In the S1 information key generation step, the round key is generated by the following formula: Where W[i] represents each 16-byte block in the extended key, and the g function includes operations such as circular shift, byte replacement, and XOR with the round constant. The result of the circular shift of the previous round key is first XORed with the same shift result after byte replacement, and then XORed with the current round constant to finally generate the new round key.

3. The AES-based network information data transmission security method according to claim 1, characterized in that: In the encryption process step of the S2 information data transmission, the GCM authentication module generates the integrity verification tag AuthTag using the following formula: where Ai and Cj are the 16-byte blocks of AAD and ciphertext respectively, m and n are the number of blocks of AAD and ciphertext respectively, and |A| and |C| are the lengths of AAD and ciphertext respectively.

4. The AES-based network information data transmission security method according to claim 1, characterized in that: In the S3 information data decryption process, the authentication tag is verified using the following formula: Where C is the ciphertext, A is the additional authentication data, IV is the initialization vector, AuthTag is the authentication tag generated during encryption, and K is the key.

5. The AES-based network information data transmission security method according to claim 1, characterized in that: The data security constraint step of the S4 information includes the following specific measures: S41 key symmetry constraint: ensures key derivation consistency by XORing round keys; S42 enforces unique IV: prevents key stream reuse between sessions; S43 constructs a Nonce with a timestamp: ensuring that the encryption process is resistant to replay attacks; S44 HMAC-based authentication tag generation: binds ciphertext, IV, and key to achieve data integrity verification.

6. The AES-based network information data transmission security method according to claim 1, characterized in that: In the API mapping step of the S5 information transmission, the encryption process uses the AES-GCM mode combined with PKCS7 padding, and the decryption process verifies the data integrity and restores the plaintext by inputting the ciphertext, key, IV and authentication tag.

7. The AES-based network information data transmission security method according to claim 1, characterized in that: In the S6 information data encryption complexity control step, the time complexity is O(n*m), where n is the number of data blocks and m is the number of rounds; the space complexity is O(k), where k is the key length.

8. The AES-based network information data transmission security method according to claim 1, characterized in that: In the S7 information data security assurance step, key confidentiality is achieved by: If the attacker cannot obtain the key or the private key in the asymmetric encryption transmission, the plaintext cannot be cracked; Anti-differential power consumption is achieved through hardware-level protection, and information transmission runs in the TEE security zone, which can resist side-channel attacks.

9. The AES-based network information data transmission security method according to claim 1, characterized in that: The following steps are also included: First, the plaintext to be encrypted is divided into independent groups according to fixed length and encoded into a byte state matrix as a unified operation carrier; Then, in each round of iteration, the state matrix first performs a row shift operation and then performs a composite transformation with the current round key, including bitwise XOR and byte substitution operations; Finally, through multiple rounds of precise iterative nonlinear transformation and key deep binding mechanism, the plaintext data is gradually converted into high-entropy ciphertext.

10. The AES-based network information data transmission security method according to claim 9, characterized in that: In the multi-round precise iterative nonlinear transformation and key deep binding mechanism, the four-stage dynamic evolution of the state matrix includes: Initial stage: After filling the plaintext into a byte matrix, the original linear relationship between bits is destroyed through byte substitution; Row shift stage: differential offset reorganization of the bytes in the row of the state matrix; Column-wise reconstruction phase: vertical diffusion of bytes within a column is achieved through finite field operations; Round key addition phase: The current round key is tightly coupled with the state matrix through a byte-by-byte XOR operation.

Citation Information

Patent Citations

  • SM4-GCM algorithm and application in network security protocol

    CN111555859A

  • Data security transmission method and system based on autonomous security interaction protocol

    CN118784337A

  • Load control terminal program trusted loading method and electronic equipment

    CN119892522A

Cited By

  • Hierarchical nested data encryption method supporting fine-grained access control

    CN121217463A

  • Widely applicable communication network encrypted data transmission method

    CN121567320A

  • Defense system for information security of trusted data space

    CN121808768A