A data security encryption and decryption resource scheduling method and system

By setting codewords for data sequences and constructing keys of different levels, the problem that symmetric encryption algorithms cannot meet the requirements of multi-level and multi-granularity security control is solved, realizing a flexible data encryption and decryption scheme, ensuring high confidentiality and reasonable information sharing during data storage and transmission.

CN120602162BActive Publication Date: 2026-05-15JINJI FUTURE (SHENZHEN) TECHNOLOGY CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JINJI FUTURE (SHENZHEN) TECHNOLOGY CO LTD
Filing Date
2025-06-13
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing symmetric encryption algorithms can only provide a single level of encryption protection, which cannot meet the needs of multi-layered and multi-granular security control and makes it difficult to distinguish the access permissions of different users.

Method used

By setting codewords for all bases and constructing keys of different levels, and encrypting and encoding data sequences according to the keys of different levels, it ensures that personnel at different levels obtain decryption results with different decryption precision, thereby achieving flexible and refined data security management.

Benefits of technology

It achieves a high degree of confidentiality in the storage and transmission of data, and meets the reasonable usage needs of different personnel within their respective job responsibilities, effectively balancing the contradiction between data security and information sharing, and improving the security and availability of the information system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602162B_ABST
    Figure CN120602162B_ABST
Patent Text Reader

Abstract

The application discloses a data security encryption and decryption resource scheduling method and system, which comprises the following steps: setting code words for all bases; setting different levels of keys according to the code words of all bases; wherein the key of level 1 comprises the code words of all bases; the key of level n comprises the code words of all n-order segment averages, and n is greater than 1; encrypting and encoding a data sequence according to the key of level 1 to obtain an encryption result of the data sequence and storing the encryption result; distributing the keys corresponding to respective levels to different levels of personnel; when the personnel need to check the data sequence, decrypting the data sequence according to the respective keys, and the decrypted data sequences obtained by different levels of personnel have different decryption accuracies. The application meets the reasonable use requirements of different personnel on data within respective working responsibilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology. More specifically, this invention relates to a data security encryption and decryption resource scheduling method and system. Background Technology

[0002] In today's digital age, data security and confidentiality have become paramount. With the rapid development of information technology, massive amounts of data are generated, transmitted, and stored across various fields; this data often contains sensitive information, and its leakage could have serious consequences.

[0003] In some large enterprises and institutions, in order to better protect core secrets, prevent information leakage, and ensure that critical data is only accessed by authorized personnel, it is desirable to set different data access permissions for personnel at different levels.

[0004] While symmetric encryption algorithms offer high encryption efficiency, their key management is complex, and all users with the key can obtain the exact same decryption information, making it difficult to distinguish the access permissions of different users. Therefore, they can only provide a single level of encryption protection and cannot meet the needs of multi-layered and multi-granular security control. Summary of the Invention

[0005] To address the technical problem that the aforementioned symmetric encryption algorithms can only provide a single level of encryption protection and cannot meet the needs of multi-level and multi-granular security control, this invention provides solutions in the following aspects.

[0006] In a first aspect, the present invention provides a data security encryption and decryption resource scheduling method, comprising: setting codewords for all cardinals; setting keys of different levels based on the codewords of all cardinals; wherein, the key of level 1 includes the codewords of all cardinals; level The key includes all Codewords with segmented average of order, ;all The method for obtaining the segmented average and its codeword is as follows: select from all bases. The number of bases is used to arrange and combine them, forming a length of . The number of combinations, obtained in total The length is The number of combinations; the combinations that make up the number of combinations The concatenation result of the codewords of the cardinality is used as the codeword of the combination number; the combination number is calculated. The average of the radix and the representative value of the combination are used; duplicate values ​​are removed from all representative values ​​to obtain all combinations. Piecewise average; the representative value is equal to each The codewords of all combinations of the order segmented average are used as the codewords of each The codeword for the segmented average is obtained; the data sequence is encrypted and encoded according to the level 1 key to obtain the encrypted result of the data sequence and store it; different levels of personnel are assigned keys corresponding to their respective levels; when personnel need to view the data sequence, they decrypt the data sequence according to their respective keys, and the decryption accuracy of the data sequence obtained by personnel of different levels is different.

[0007] Preferably, the cardinality is all the possible data in the data sequence; data with the same value in the data sequence are used as a cardinality.

[0008] Preferably, setting codewords for all radixes includes: setting codewords of fixed length for all radixes, wherein the codewords consist of 0s and 1s; requiring that the codewords for different radixes be different, and requiring that the fixed length be not less than [a certain value]. , This represents the number of types of all cardinalities. This indicates rounding up to the nearest integer.

[0009] Preferably, setting codewords for all cardinal numbers includes: constructing a binary tree and setting codewords of variable length for all cardinal numbers, wherein the codewords consist of 0s and 1s; requiring that the number of leaf nodes in the constructed binary tree is not less than , This represents the total number of cardinal types; each cardinal is assigned a leaf node, and the paths from the root node to each leaf node in the binary tree are encoded as variable-length codewords for each cardinal.

[0010] Preferably, the different levels include Level 1, Level 2, ..., Level ,grade ,…,grade ,grade , The number of levels, where level 1 is the highest level. It is the lowest level.

[0011] Preferably, when a person needs to view the data sequence, the information management system initiates an identity verification process, requiring the user to enter their registered username and password to verify the legitimacy of the user's identity and ensure that only authorized personnel can access the stored data sequence.

[0012] Preferably, the information management system compares the username and password entered by the user with the user information stored in the database. If the entered username and password do not match or are invalid, the information management system confirms that the user's authentication is incorrect. When a person who needs to view the data sequence fails to authenticate three times in a row, the information management system confirms that the user's authentication has failed and automatically locks the account to prevent unauthorized access.

[0013] Preferably, the information management system compares the username and password entered by the user with the user information stored in the database. If the entered username and password match and are valid, the information management system confirms that the user's identity verification is successful; then, it identifies the user's level and records it as the level. ; through the levels stored in the information management system The key is used to decrypt the encrypted data sequence.

[0014] Preferably, the levels stored in the information management system The key is used to decrypt the encrypted data sequence, and the process also includes: repeating each decoded data... This process yields the final restored data sequence.

[0015] Secondly, the present invention provides a data security encryption and decryption resource scheduling system, including a processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the above-mentioned data security encryption and decryption resource scheduling method is implemented.

[0016] By adopting the above technical solution, a data security encryption and decryption resource scheduling method is generated into a computer program and stored in a memory for loading and execution by a processor. This allows for the creation of a terminal device based on the memory and processor, facilitating its use.

[0017] The beneficial effects of this invention are as follows:

[0018] This invention provides a flexible and sophisticated solution for data encryption and decryption by setting codewords for different cardinalities and constructing keys of different levels based on all cardinalities and their codewords. The level 1 key contains codewords for all cardinalities, enabling comprehensive and meticulous encryption of data sequences. This ensures high confidentiality of data during storage and transmission. Simultaneously, it ensures that different levels of personnel obtain data sequences with varying decryption precision using their respective keys, meeting the reasonable data usage needs of different personnel within their respective job responsibilities. It also satisfies multi-level, multi-granularity security control requirements, effectively balancing the contradiction between data security and information sharing, and improving the security and availability of the entire information system. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating a data security encryption / decryption resource scheduling method according to the present invention;

[0020] Figure 2 This is a schematic diagram illustrating a binary tree;

[0021] Figure 3This schematically illustrates the specific process of obtaining all combinations of length 2 and their codewords based on all radixes and their codewords when all radixes are given codewords of fixed length.

[0022] Figure 4 This schematically illustrates the specific process of obtaining all combinations of length 2 and their codewords based on all radixes and their codewords when all radixes are assigned variable-length codewords.

[0023] Figure 5 This schematically illustrates the specific process of obtaining all combinations of length 3 and their codewords based on all radixes and their codewords when a fixed-length codeword is assigned to all radixes.

[0024] Figure 6 This schematically illustrates the specific process of obtaining all combinations of length 3 and their codewords based on all radixes and their codewords when all radixes are assigned variable-length codewords. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0027] This invention discloses a data security encryption and decryption resource scheduling method, referring to... Figure 1 This includes steps S1 to S3:

[0028] S1. Set codewords for all cardinals, set different levels of keys based on the codewords of all cardinals, and allocate different memory resources for different levels of keys.

[0029] Specifically, the cardinality is all the possible data in the data sequence; data with the same value in the data sequence are used as a cardinality.

[0030] In one embodiment, a fixed-length codeword consisting of 0s and 1s is assigned to all bases; and to ensure correct decryption of the encrypted data sequence, the codewords for different bases must be different. Therefore, the fixed length must be no less than [a certain value]. , This represents the number of types of all cardinalities. This indicates rounding up to the nearest integer.

[0031] For example, when there are 4 bases, and the 4 bases are 1, 3, 5 and 7 respectively, a codeword of fixed length is set for all bases. In the first case, the codewords for bases 1, 3, 5 and 7 can be set to 00, 01, 10 and 11. In the second case, the codewords for bases 1, 3, 5 and 7 can be set to 000, 001, 010 and 011.

[0032] In another embodiment, a binary tree is constructed, and codewords of variable length are assigned to all cardinalities, consisting of 0s and 1s. Furthermore, to ensure correct decryption of the encrypted data sequence, the codeword of any cardinality must not be a prefix of the codeword of any other cardinality. Therefore, the number of leaf nodes in the constructed binary tree must be at least [number missing]. , This represents the total number of cardinal types; each cardinal is assigned a leaf node, and the paths from the root node to each leaf node in the binary tree are encoded as variable-length codewords for each cardinal.

[0033] For example, when there are four cardinal numbers, namely 1, 3, 5, and 7, and variable-length codewords are assigned to all cardinal numbers, in the first case, according to... Figure 2 In the binary tree shown in (1), if variable-length codewords are assigned to all radixes, then the codewords for radix 1, 3, 5, and 7 can be set to 0, 11, 100, and 101, respectively. In the second case, according to... Figure 2 In the binary tree shown in (2), if a variable-length codeword is set for all bases, then the codewords for bases 1, 3, 5, and 7 can be set to 00, 01, 10, and 110, respectively.

[0034] Furthermore, configure according to requirements. There are several levels, namely Level 1, Level 2, ..., Level 3. ,grade ,…,grade ,grade Among them, level 1 is the highest level. It is the lowest level.

[0035] in, For the number of levels, the number of levels The specific values ​​can be set according to the actual application scenario and needs, and the number of levels. The value is an integer, and its range is [2, 10]. This invention will determine the number of levels. Set it to 3.

[0036] Furthermore, based on the codewords of all cardinalities, different levels of keys are set. The specific process is as follows:

[0037] 1. Use all the codewords of all cardinalities to form a Level 1 key. In other words, the Level 1 key includes codewords of all cardinalities.

[0038] 2. Regarding levels , : Based on all cardinalities and their codewords, obtain all Piecewise average and all Codewords of the order segment average; all The codewords of the segmented average number of levels form a grade. The key, that is, the level The key includes all Codewords of the average of segmented order.

[0039] 3. Allocate different memory resources for keys of different levels: due to the different levels... The key contains all keys of length 1000. The codeword of the combination number, and the length is The total number of combinations is Therefore, higher-level keys contain more codewords and require more memory resources. Consequently, higher-level keys are allocated more memory resources. It is important to allocate appropriate amounts of resources to ensure efficient utilization of system resources.

[0040] Specifically, based on all cardinalities and the codewords of all cardinalities, all... Piecewise average and all The process of encoding words with the order segmented average is as follows:

[0041] (1) Select from all cardinal numbers The number of bases is then arranged and combined, resulting in a total of There are several permutations and combinations; for each permutation and combination... The base number, the composition length is The number of combinations, therefore, a total of The length is The number of combinations.

[0042] For example, when there are four cardinal numbers: 1, 3, 5, and 7, selecting two cardinal numbers from all the cardinal numbers and arranging them in various combinations results in a total of... =16 permutations and combinations, resulting in 16 combinations of length 2. These 16 combinations of length 2 are: (1,1), (1,3), (1,5), (1,7), (3,1), (3,3), (3,5), (3,7), (5,1), (5,3), (5,5), (5,7), (7,1), (7,3), (7,5), (7,7).

[0043] (2) Combining the number of combinations The concatenation result of the codewords of the cardinality is used as the codeword of the combination number.

[0044] For example, when a fixed-length codeword is set for all bases, and the codewords for bases 1, 3, 5, and 7 are set to 00, 01, 10, and 11 respectively, the codewords for these 16 combinations of length 2 are 0000, 0001, 0010, 0011, 0100, 0101, 0110, 0111, 1000, 1001, 1010, 1011, 1100, 1101, 1110, and 1111.

[0045] For example, when all bases are assigned variable-length codewords, and the codewords for bases 1, 3, 5, and 7 are set to 0, 11, 100, and 101, the codewords for these 16 combinations of length 2 are 00, 011, 0100, 0101, 110, 1111, 11100, 11101, 1000, 10011, 100100, 100101, 1010, 10111, 101100, and 101101.

[0046] (3) Calculate the number of combinations. The average of the base numbers is used as the representative value for each combination.

[0047] For example, the representative values ​​of these 16 combinations of length 2 are: 1, 2, 3, 4, 2, 3, 4, 5, 3, 4, 5, 6, 4, 5, 6, 7.

[0048] (4) Remove duplicates from all representative values ​​to obtain all Piecewise average; the representative value is equal to each The codewords of all combinations of the order segmented average are used as the codewords of each Codewords of the average of segmented order.

[0049] For example, when a fixed-length codeword is assigned to all cardinals, deduplication is performed on the representative values ​​1, 2, 3, 4, 2, 3, 4, 5, 3, 4, 5, 6, 4, 5, 6, 7 of these 16 combinations of length 2. This yields 7 possible second-order piecewise averages: 1, 2, 3, 4, 5, 6, and 7. Specifically, the codeword for the second-order piecewise average "1" is 0000; and the codewords for the second-order piecewise average "2" are 0001 and 01. 00; For the second-order piecewise average "3", the codewords include: 0010, 0101, 1000; For the second-order piecewise average "4", the codewords include: 0011, 0110, 1001, 1100; For the second-order piecewise average "5", the codewords include: 0111, 1010, 1101; For the second-order piecewise average "6", the codewords include: 1011, 1110; For the second-order piecewise average "7", the codewords include: 1111.

[0050] For example, when assigning variable-length codewords to all cardinals, deduplicating the representative values ​​1, 2, 3, 4, 2, 3, 4, 5, 3, 4, 5, 6, 4, 5, 6, 7 of these 16 combinations of length 2 yields a total of 7 possible second-order piecewise averages: 1, 2, 3, 4, 5, 6, 7. Specifically, for the second-order piecewise average "1", its codeword includes: 00; for the second-order piecewise average "2", its codeword includes: 011, 110; for the second-order piecewise average "3", its codeword includes: 011, 110; for the second-order piecewise average "4", its codeword includes: 011, 110; for the second-order piecewise average "6", its codeword includes: 011, 110; for the second-order piecewise average "7 ... The codewords for the segment average "3" are: 0100, 1111, 1000; for the second-order segment average "4", the codewords are: 0101, 11100, 10011, 1010; for the second-order segment average "5", the codewords are: 100100, 11101, 10111; for the second-order segment average "6", the codewords are: 100101, 101100; and for the second-order segment average "7", the codeword is: 101101.

[0051] For example, when codewords of fixed length are given for all radixes and codewords of variable length are given for all radixes, the combinations of length 2 and their codewords, and the combinations of length 3 and their codewords are obtained respectively:

[0052] (1) When a fixed-length codeword is assigned to all bases, and the codewords for bases 1, 3, 5, and 7 are set to 00, 01, 10, and 11 respectively, the specific process of obtaining all combinations of length 2 and their codewords based on all bases and their codewords is as follows: Figure 3 As shown.

[0053] (2) When all bases are assigned variable-length codewords, and the codewords for bases 1, 3, 5, and 7 are set to 0, 11, 100, and 101 respectively, the specific process of obtaining all combinations of length 2 and their codewords based on all bases and their codewords is as follows: Figure 4 As shown.

[0054] (3) When a fixed-length codeword is assigned to all bases, and the codewords for bases 1, 3, 5, and 7 are set to 00, 01, 10, and 11 respectively, the specific process of obtaining all combinations of length 3 and their codewords based on all bases and their codewords is as follows: Figure 5 As shown.

[0055] (4) When all bases are assigned variable-length codewords, and the codewords for bases 1, 3, 5, and 7 are set to 0, 11, 100, and 101 respectively, the specific process of obtaining all combinations of length 3 and their codewords based on all bases and their codewords is as follows: Figure 6 As shown.

[0056] S2. Encrypt the data sequence using the level 1 key to obtain the encrypted result of the data sequence and store it.

[0057] Specifically, each piece of data in the data sequence is encoded according to the codewords of each base in the level 1 key, and the encoding result of each piece of data is obtained. The concatenation result of the encoding results of all data is used as the encryption result of the data sequence and stored.

[0058] For example, when a fixed-length codeword is set for all radixes, the key for level 1 is: 1: "00", 3: "01", 5: "10", 7: "11". When the data sequence is {7,3,3,3,1,7,3,1,3,7,3,5,1,3,1,5,7,5}, each data in the data sequence is encoded according to the codeword of each radix in the key for level 1, and the encoding result of each data is: 11, 01, 01, 01, 00, 11, 01, 00, 01, 11, 01, 10, 00, 01, 00, 10, 11, 10. The concatenation result of the encoding results of all data is used as the encryption result of the data sequence, and the encryption result of the data sequence is: 110101010011010001110110000100101110.

[0059] For example, when setting variable-length codewords for all cardinals, the level 1 key is: 1: "0", 3: "11", 5: "100", 7: "101"; when the data sequence is {7,3,3,3,1,7,3,1,3,7,3,5,1,3,1,5,7,5}, each data in the data sequence is encoded according to the codewords of each cardinal in the level 1 key, and the encoding results of each data are: 101, 11, 11, 11, 0, 101, 11, 0, 11, 101, 11, 100, 0, 11, 0, 100, 101, 100; the concatenation result of the encoding results of all data is used as the encryption result of the data sequence, and the encryption result of the data sequence is: 101111111010111011101111000110100101100.

[0060] S3. Assign keys corresponding to different levels of personnel; when personnel need to view the data sequence, they decrypt the data sequence according to their respective keys.

[0061] It should be noted that in modern information management systems, in order to ensure data security and confidentiality, keys are usually assigned to personnel based on their responsibilities and authority levels to ensure data security.

[0062] Specifically, the information management system stores users' basic information and account-related information; the basic information includes name, department, position, etc., and the account-related information includes username, password, and bound email address or mobile phone number.

[0063] Furthermore, different levels of personnel are assigned keys corresponding to their respective levels, and each employee's level information is stored in the information management system.

[0064] When personnel need to view data sequences, the information management system needs to verify the user's identity to ensure that only authorized personnel can access sensitive data. Therefore, the verification process is an important part of protecting data security.

[0065] Specifically, when a user requests to view a data sequence, the information management system initiates an identity verification process, requiring the user to enter their registered username and password. The information management system then compares the entered username and password with the user information stored in the database to verify the legitimacy of the user's identity, including:

[0066] 1. If the entered username and password match and are valid, the information management system confirms that the user's identity has been verified.

[0067] 2. If the entered username and password do not match or are invalid, the information management system confirms that the user's authentication is incorrect. If a person who needs to view the data sequence fails to authenticate three times in a row, the information management system confirms that the user's authentication has failed and will automatically lock the account to prevent unauthorized access. This locking mechanism is designed to prevent potential malicious attackers from gaining access by repeatedly trying to guess the correct credentials.

[0068] 3. Once an account is locked, the user will be unable to log in to the information management system to view data sequences. To restore access, the user needs to apply to the Information Department to unlock the account. During the application process, the user needs to provide the following information:

[0069] (1) Basic information of users: including name, department, position, etc., to help the information department confirm the identity of users.

[0070] (2) Account-related information: such as username, bound email address or mobile phone number, so that the information department can quickly locate and process locked accounts.

[0071] (3) Specific details of the lockout: including the time and location of the login attempt and the number of times the verification failed, which helps the information department understand the background of the incident and conduct an investigation.

[0072] 4. After receiving the application, the Information Department will review the user's request according to the internal process. After confirming that the user's identity is correct, the Information Department will unlock the account and require the user to reset the password to enhance the account security.

[0073] Furthermore, once the information management system confirms that the user's identity has been verified, it determines the user's level based on the information stored in the information management system and records it as the level. ; through the levels stored in the information management system The key is used to decrypt the encrypted data sequence. Different levels of personnel obtain decrypted data sequences with varying levels of precision. Each decoded data sequence is then repeated... This process yields the final restored data sequence.

[0074] For example, when a fixed-length codeword is assigned to all cardinals, the process of decrypting the encrypted data sequence based on different levels of keys is as follows:

[0075] (1) When a fixed-length codeword is set for all bases, the encryption result of the data sequence is: 110101010011010001110110000100101110; and the key for level 1 is: 1: "00", 3: "01", 5: "10", 7: "11"; the key for level 2 is: 1: "0000", 2: "0001, 0100", 3: "0010, 0101, 1000", 4: "0011, 0110, 1001, 1100", 5: "0111, 1010, 1101", 6: "1011, 1110", 7: "1111".

[0076] (2) When decrypting the encryption result of the data sequence according to the level 1 key, the codewords obtained are: 11,01,01,01,00,11,01,00,01,11,01,10,00,01,00,10,11,10, and the decryption result is: 7,3,3,3,1,7,3,1,3,7,3,5,1,3,1,5,7,5.

[0077] (3) When decrypting the encryption result of the data sequence according to the level 2 key, the codewords obtained are: 1101,0101,0011,0100,0111,0110,0001,0010,1110, and the decryption result is: 5,3,4,2,5,4,2,3,6. The final restored data sequence is {5,5,3,3,4,4,2,2,5,5,4,4,2,2,3,3,6,6}.

[0078] (4) When decrypting the encryption result of the data sequence according to the level 3 key, the codewords obtained are: 110101,010011,010001,110110,000100,101110, and the decryption result is: 4.3,3.7,2.3,5,1.7,5.7. The final restored data sequence is {4.3,4.3,4.3,3.7,3.7,3.7,2.3,2.3,2.3,5,5,5,1.7,1.7,1.7,5.7,5.7,5.7}.

[0079] For example, when setting codewords of variable length for all cardinals, the process of decrypting the encrypted data sequence according to different levels of keys is as follows:

[0080] (1) When a variable-length codeword is set for all bases, the encryption result of the data sequence is: 10111111101011101110111000110100101100; and the key for level 1 is: 1: "0", 3: "11", 5: "100", 7: "101"; the key for level 2 is: 1: "00", 2: "011, 110", 3: "0100, 1111, 1000", 4: "0101, 11100, 10011, 1010", 5: "100100, 11101, 10111", 6: "100101, 101100", 7: "101101".

[0081] (2) When decrypting the encryption result of the data sequence according to the level 1 key, the codewords obtained are: 101,11,11,11,0,101,11,0,11,101,11,100,0,11,0,100,101,100. The final decryption result is: 7,3,3,3,1,7,3,1,3,7,3,5,1,3,1,5,7,5.

[0082] (3) When decrypting the encryption result of the data sequence according to the level 2 key, the codewords obtained are: 10111,1111,0101,110,11101,11100,011,0100,101100, and the decryption result is: 4.3,3.7,2.3,5,1.7,5.7. The final restored data sequence is {4.3,4.3,4.3,3.7,3.7,3.7,2.3,2.3,2.3,5,5,5,1.7,1.7,1.7,5.7,5.7,5.7}.

[0083] (4) When decrypting the encryption result of the data sequence according to the level 3 key, the codewords obtained are: 1011111,110101,11011,10111100,0110,100101100, and the decryption result is: 4.3,3.7,2.3,5,1.7,5.7. The final restored data sequence is {4.3,4.3,4.3,3.7,3.7,3.7,2.3,2.3,2.3,5,5,5,1.7,1.7,1.7,5.7,5.7,5.7}.

[0084] It should be noted that for Level 1 personnel, the decrypted result is identical to each data point in the data sequence; that is, Level 1 personnel can decrypt and obtain the complete data sequence. For Level 2 personnel, the decrypted result is the average of two adjacent data points in the data sequence; that is, Level 2 personnel can only decrypt and obtain the average of two adjacent data points, not the complete data sequence. For Level 3 personnel, the decrypted result is the average of three adjacent data points in the data sequence; that is, Level 3 personnel can only decrypt and obtain the average of three adjacent data points, not the complete data sequence. Therefore, the decryption accuracy of the data sequence obtained by personnel at different levels varies.

[0085] Furthermore, this invention provides a flexible and sophisticated solution for data encryption and decryption by setting codewords for different cardinalities and constructing keys of different levels based on all cardinalities and their codewords. The level 1 key contains codewords for all cardinalities, enabling comprehensive and meticulous encryption of data sequences. This ensures high confidentiality of data during storage and transmission. Simultaneously, it ensures that different levels of personnel obtain data sequences with varying decryption precision using their respective keys, meeting the reasonable data usage needs of different personnel within their respective job responsibilities. It also satisfies multi-level, multi-granularity security control requirements, effectively balancing the contradiction between data security and information sharing, and improving the security and availability of the entire information system.

[0086] This invention also discloses a data security encryption and decryption resource scheduling system, including a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, a data security encryption and decryption resource scheduling method according to the present invention is implemented.

[0087] The system also includes other components well known to those skilled in the art, such as communication buses and communication interfaces, the settings and functions of which are known in the art and will not be described in detail here.

Claims

1. A data security encryption / decryption resource scheduling method, characterized in that, include: Assign codewords to all cardinals; based on the codewords of all cardinals, assign keys of different levels; where level 1 keys include the codewords of all cardinals; level The key includes all Codewords with segmented average of order, Allocate different memory resources for different levels of keys; all The method for obtaining the segmented average and its codeword is as follows: select from all bases. The number of bases is used to arrange and combine them, forming a length of . The number of combinations, obtained in total The length is The number of combinations, Represents the total number of cardinalities; the number of combinations. The concatenation result of the codewords of the cardinality is used as the codeword of the combination number; the combination number is calculated. The average of the individual bases is used as the representative value of the combination number; Remove duplicates from all representative values ​​to obtain all Piecewise average; the representative value is equal to each The codewords of all combinations of the order segmented average are used as the codewords of each Codewords of segmented average; The data sequence is encrypted using the Level 1 key to obtain the encrypted result of the data sequence, and then stored. Personnel at different levels are assigned keys corresponding to their respective levels; when personnel need to view data sequences, they decrypt the data sequences according to their respective keys, and the decryption accuracy of the data sequences obtained by personnel at different levels is different.

2. The data security encryption / decryption resource scheduling method according to claim 1, characterized in that, The cardinality is all the possible data in the data sequence; data with the same value in the data sequence are used as a cardinality.

3. The data security encryption / decryption resource scheduling method according to claim 1, characterized in that, The step of setting codewords for all cardinals includes: Assign a codeword of fixed length to all bases, the codeword consisting of 0s and 1s; the codewords must be different for different bases, and the fixed length must be no less than [a certain value]. , This indicates rounding up to the nearest integer.

4. The data security encryption / decryption resource scheduling method according to claim 1, characterized in that, The step of setting codewords for all cardinals includes: By constructing a binary tree, assign variable-length codewords to all cardinal numbers, consisting of 0s and 1s; the number of leaf nodes in the constructed binary tree must be no less than [a certain value]. Assign a leaf node to each radix, and encode the path from the root node to each leaf node in the binary tree as a variable-length codeword for each radix.

5. A data security encryption / decryption resource scheduling method according to claim 1, characterized in that, The different levels include Level 1, Level 2, ..., Level ,grade ,…,grade ,grade , The number of levels, where level 1 is the highest level. It is the lowest level.

6. The data security encryption / decryption resource scheduling method according to claim 1, characterized in that, When personnel need to view the data sequence, the information management system initiates an identity verification process, requiring the user to enter their registered username and password to verify the legitimacy of the user's identity and ensure that only authorized personnel can access the stored data sequence.

7. A data security encryption / decryption resource scheduling method according to claim 6, characterized in that, The information management system will compare the username and password entered by the user with the user information stored in the database. If the entered username and password do not match or are invalid, the information management system will confirm that the user's authentication is incorrect. When a person who needs to view the data sequence fails to authenticate three times consecutively, the information management system confirms that the user's authentication has failed and automatically locks the user's account to prevent unauthorized access.

8. A data security encryption / decryption resource scheduling method according to claim 6, characterized in that, The information management system compares the username and password entered by the user with the user information stored in the database. If the entered username and password match and are valid, the information management system confirms that the user's identity has been verified; then it identifies the user's level and records it as the level. ; The levels stored in the information management system The key is used to decrypt the encrypted data sequence.

9. A data security encryption / decryption resource scheduling method according to claim 8, characterized in that, The levels stored in the information management system The key is used to decrypt the encrypted data sequence, and the process also includes: repeating each decoded data... This process yields the final reconstructed data sequence.

10. A data security encryption / decryption resource scheduling system, characterized in that, include: A processor and a memory, wherein the memory stores computer program instructions that, when executed by the processor, implement a data security encryption / decryption resource scheduling method according to any one of claims 1-9.