Data adaptive encryption method based on AI analysis and related equipment
By using AI to analyze and identify data scenarios and features, and dynamically matching encryption algorithms, the problem that existing encryption strategies cannot balance efficiency is solved, thus achieving flexible and efficient data encryption.
Patent Information
- Application Number
- CN202511351270.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-09-22
AI Technical Summary
Existing technologies cannot dynamically adjust encryption strategies based on the characteristics of the data itself and the application scenario, resulting in a tradeoff between encryption and efficiency.
By using AI analysis to obtain metadata of plaintext data, identifying usage scenario information, purpose information, and data characteristic information, dynamically matching symmetric encryption algorithms and asymmetric encryption algorithms, and combining sampling encryption strategies, a flexible encryption method can be achieved.
It achieves a flexible and efficient combination of symmetric and asymmetric algorithms, balancing encryption security and performance, reducing computational resource consumption, and improving encryption speed and coverage.
Smart Images

Figure CN120856476A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data encryption technology, and in particular to an AI-based adaptive data encryption method and related equipment. Background Art
[0002] With the rapid development of the digital economy, the demand for secure data storage and transmission is becoming increasingly urgent. Encryption technology, as a core means of data security, is currently mainly divided into two types: symmetric encryption and asymmetric encryption.
[0003] Symmetric encryption algorithms offer advantages such as high encryption efficiency and low computational overhead, but key management is challenging, making them suitable for scenarios with large data volumes and low to medium security requirements. Asymmetric encryption algorithms achieve high security through public-private key separation, making them suitable for cross-entity communication scenarios with small data volumes and high security requirements, but they suffer from low encryption efficiency and high computational cost, making them unsuitable for real-time processing of large data volumes.
[0004] Existing data encryption technologies mostly adopt a one-size-fits-all approach, failing to dynamically adjust encryption strategies based on the characteristics of the data itself and the application scenario, resulting in a trade-off between encryption and efficiency.
[0005] Therefore, existing technologies still need to be improved and developed. Summary of the Invention
[0006] This invention provides an AI-based adaptive data encryption method and related equipment. The main objective of this invention is to solve the technical problems mentioned in the background section of the prior art.
[0007] The first aspect of this invention provides a data adaptive encryption method based on AI analysis, comprising: Obtain plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; The metadata is extracted from the plaintext data and input into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information and data feature information of the plaintext data; The preset encryption algorithm is matched based on the scenario information, the purpose information, and the data feature information. The preset encryption algorithm includes symmetric encryption algorithm and asymmetric encryption algorithm. If the matching result is the symmetric encryption algorithm, then the plaintext data is encrypted using the symmetric encryption algorithm and combined with the metadata to obtain the first encryption result; If the matching result is the asymmetric encryption algorithm, then the plaintext data is sampled and encrypted using the asymmetric encryption algorithm with encryption density determined based on the scenario, and then combined with the metadata to obtain the second encryption result.
[0008] In an optional embodiment of the first aspect of the present invention, if the matching result is the asymmetric encryption algorithm, then obtaining a second encryption result by combining the plaintext data with the metadata after sampling encryption of the plaintext data based on scenario-determined encryption density using the asymmetric encryption algorithm includes: If the matching result is the asymmetric encryption algorithm, then the scene sensitivity level is determined based on the scene information; The encryption density range of the plaintext data is obtained by using the scene sensitivity level; The plaintext data is encrypted using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption to obtain the ciphertext body; The second encryption result is obtained by combining the ciphertext body and the metadata.
[0009] In an optional embodiment of the first aspect of the present invention, the step of encrypting the plaintext data using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption to obtain the ciphertext body includes: Using the encryption density range as a guide, the structured data, unstructured data, and other data in the plaintext data are encrypted sequentially. The structured data within the plaintext data is classified and encrypted according to the encryption ratio matched with the field sensitivity. The unstructured data in the plaintext data is encrypted using a random sampling method; For the other data in the plaintext data, hierarchical encryption is performed according to the encryption ratio matched by the data importance.
[0010] In an optional embodiment of the first aspect of the present invention, the step of classifying and encrypting the structured data in the plaintext data according to the field sensitivity matching encryption ratio includes: Sensitive fields, non-sensitive fields, and other fields are extracted separately from the structured data; The sensitive fields are encrypted at a 100% ratio, the non-sensitive fields are encrypted at a first preset ratio, and the other fields are not encrypted.
[0011] In an optional embodiment of the first aspect of the present invention, encrypting the unstructured data in the plaintext data by means of random sampling includes: Obtain the data block information where the unstructured data exists; A random number generator is constructed based on the data block information; Several target data blocks are obtained through the random number generator; The unstructured data in several target data blocks is encrypted.
[0012] In an optional embodiment of the first aspect of the present invention, the hierarchical encryption of the other data in the plaintext data according to the data importance matching encryption ratio includes: The core data, ordinary data, and redundant data in the other data are extracted separately. The core data is encrypted at a 100% ratio, the ordinary data is extracted and encrypted at a second preset ratio, and the redundant data is not encrypted. In an optional embodiment of the first aspect of the present invention, the matching of a preset encryption algorithm based on the scene information, the purpose information, and the data feature information, wherein the preset encryption algorithm includes a symmetric encryption algorithm and an asymmetric encryption algorithm, including: The real-time requirements of the plaintext data are determined based on the scenario information. The security requirements for the plaintext data are determined based on the aforementioned usage information; The data volume requirement for the plaintext data is determined based on the data feature information; The real-time requirements, security requirements, and data volume requirements are respectively matched with the first condition table of the symmetric encryption algorithm and the second condition table of the asymmetric encryption algorithm; Based on the degree of matching between the real-time requirements, security requirements, and data volume requirements and the first and second condition tables, respectively, the target encryption algorithm for the plaintext data is determined.
[0013] A second aspect of the present invention provides an AI-based adaptive data encryption device, the AI-based adaptive data encryption device comprising: The plaintext acquisition module is used to acquire plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; The AI metadata analysis module is used to extract the metadata from the plaintext data and input the metadata into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information and data feature information of the plaintext data. An encryption algorithm matching module is used to match a preset encryption algorithm based on the scenario information, the purpose information, and the data feature information. The preset encryption algorithm includes a symmetric encryption algorithm and an asymmetric encryption algorithm. A symmetric encryption module is used to encrypt the plaintext data using the symmetric encryption algorithm and then combine it with the metadata to obtain a first encryption result if the matching result is the symmetric encryption algorithm. An asymmetric encryption module is used to obtain a second encryption result by sampling and encrypting the plaintext data with a scenario-based encryption density determined by the asymmetric encryption algorithm and then combining it with the metadata if the matching result is the asymmetric encryption algorithm.
[0014] A third aspect of the present invention provides an AI-based adaptive data encryption device, the AI-based adaptive data encryption device comprising: a memory and at least one processor, wherein the memory stores instructions, and the memory and the at least one processor are interconnected via a circuit; The at least one processor invokes the instructions in the memory to cause the AI-based adaptive data encryption device to perform the AI-based adaptive data encryption method as described in any one of the first aspects of the present invention.
[0015] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the AI-based adaptive data encryption method as described in any one of the first aspects of the present invention.
[0016] Beneficial Effects: This invention provides an AI-based adaptive data encryption method and related equipment. The method includes acquiring plaintext data to be encrypted, containing metadata describing the data structure; extracting metadata from the plaintext data and inputting it into an AI model to obtain usage scenario information, purpose information, and data feature information; performing matching based on the scenario information, purpose information, and data feature information, including symmetric encryption algorithms and asymmetric encryption algorithms; if the matching result is a symmetric encryption algorithm, encrypting the plaintext data using the symmetric encryption algorithm and then combining it with the metadata to obtain a first encryption result; if the matching result is an asymmetric encryption algorithm, sampling encryption of the plaintext data using the asymmetric encryption algorithm with encryption density determined based on the scenario, and then combining it with the metadata to obtain a second encryption result. This invention dynamically matches encryption algorithms to plaintext metadata through AI analysis, taking into account the characteristics of both symmetric and asymmetric algorithms, resulting in a more flexible and efficient encryption method. Attached Figure Description
[0017] Figure 1 This is a schematic diagram illustrating an embodiment of the main steps of an AI-based adaptive data encryption method according to the present invention; Figure 2 This is a schematic diagram of an embodiment of the encryption logic of an AI-based adaptive data encryption method according to the present invention; Figure 3 This is a schematic diagram of an embodiment of an AI-based adaptive data encryption device according to the present invention; Figure 4This is a schematic diagram of an embodiment of an AI-based adaptive data encryption device according to the present invention. Detailed Implementation
[0018] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” or “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0019] For ease of understanding, the specific process of the embodiment of the present invention is described below. Figure 1 The first aspect of this invention provides a data adaptive encryption method based on AI analysis, comprising: S100. Obtain the plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; in this invention, the plaintext data is interactive data in the field of finance and taxation, whose secure storage and interaction needs are increasingly urgent. Finance and taxation data has unique characteristics such as strong sensitivity layering, multi-type fusion, and large differences in scenario requirements, thus requiring more flexible encryption strategies. The metadata includes data type, source IP, and timestamp, etc.
[0020] S200. Extract the metadata from the plaintext data and input the metadata into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information, and data characteristic information of the plaintext data. In this step, the AI model inputs the metadata (non-sensitive information) of the plaintext data to be encrypted, and the AI model will output the usage scenario (such as "cross-institutional medical data transmission", "internal system log storage"), application purpose (such as "privacy data sharing", "data backup and archiving"), and data characteristics (such as data volume) of the plaintext data, with an accuracy rate of not less than 95%.
[0021] In this invention, the design of training data and AI models can employ supervised learning models (such as random forests and deep learning networks). The training data includes historical data with "scene labels" (e.g., "financial transactions," "medical privacy," "public logs"), "sensitivity level labels" (high / medium / low), and corresponding metadata features (e.g., file type markers like .finance.medical.log, data source IP, timestamp, data size, etc.). Specifically, for example, by labeling "datasets with the .medical tag and originating from hospital servers" as "high-sensitivity medical scenarios" and "datasets with the .log tag and originating from public servers" as "low-sensitivity log scenarios," the training model learns the mapping relationship between metadata and scenarios.
[0022] S300. Match a pre-set encryption algorithm based on the scenario information, the purpose information, and the data feature information. The pre-set encryption algorithm includes symmetric encryption algorithms and asymmetric encryption algorithms. The selection logic of the encryption algorithm in this invention can be summarized as follows: Symmetric encryption algorithms are suitable for scenarios with extremely large data volumes (e.g., TB-level logs, video streams): Symmetric encryption (e.g., AES) is fast (encryption rate can reach over 100MB / s), suitable for processing large amounts of data, avoiding the performance bottleneck of asymmetric encryption; Moderate security requirements (e.g., internal office documents): Symmetric encryption provides sufficient security, and the key management cost is lower than hybrid encryption; High real-time requirements (e.g., real-time monitoring data transmission): Symmetric encryption has low latency (millisecond-level response) to meet real-time requirements. Asymmetric encryption algorithms are suitable for scenarios. For small data volumes (such as keys, instructions, and certificates, ranging from byte to KB): the performance disadvantages of asymmetric encryption (such as RSA and ECC) are negligible for small data volumes, and there is no need to worry about the security of key transmission; for extremely high security requirements (such as financial and medical privacy data): the "public key encryption-private key decryption" mode of asymmetric encryption can avoid the global risks caused by the leakage of symmetric keys; for cross-entity communication (such as user-server data interaction): asymmetric encryption does not require pre-sharing of keys, making it suitable for key management in distributed scenarios.
[0023] In an optional embodiment of step S300 of the present invention, the matching of a preset encryption algorithm based on the scenario information, the purpose information, and the data feature information, wherein the preset encryption algorithm includes a symmetric encryption algorithm and an asymmetric encryption algorithm, includes: determining the real-time requirements of the plaintext data based on the scenario information (e.g., in a financial transaction scenario, the real-time requirements of the scenario are high); determining the security requirements of the plaintext data based on the purpose information (e.g., in a privacy data sharing scenario, the security requirements are high); determining the data volume requirements of the plaintext data based on the data feature information (e.g., if the data volume of the plaintext data is in the TB range, the data volume requirements are high); matching the real-time requirements, the security requirements, and the data volume requirements with a first condition table of the symmetric encryption algorithm (which records the requirements of the symmetric encryption algorithm for one or more of real-time, security, and data volume) and a second condition table of the asymmetric encryption algorithm (which records the requirements of the asymmetric encryption algorithm for one or more of real-time, security, and data volume); and determining the target encryption algorithm for the plaintext data based on the degree of matching between the real-time requirements, the security requirements, and the data volume requirements and the first condition table and the second condition table, respectively. In this invention, the more data items in the condition table that are the same as the real-time requirements, security requirements, and data volume requirements, the higher the degree of matching. If the number of matching items is the same, the target algorithm is determined based on the importance of the matching characteristics.
[0024] S400. If the matching result is the symmetric encryption algorithm, then the plaintext data is encrypted using the symmetric encryption algorithm and combined with the metadata to obtain the first encryption result. In an exemplary scenario of the present invention, the symmetric encryption algorithm is mainly used for data encryption scenarios with large data volume, medium security and high real-time performance. The main advantage of the symmetric encryption algorithm is its high security. The key length of the symmetric encryption can be adjusted as needed to achieve very high security.
[0025] S500. If the matching result is the asymmetric encryption algorithm, then the plaintext data is sampled and encrypted using the asymmetric encryption algorithm with a scenario-based encryption density determination, and then combined with the metadata to obtain a second encryption result. The advantage of asymmetric encryption algorithms is flexible key management; each user has their own public and private keys, making key management more flexible. Based on the characteristics of symmetric and asymmetric encryption algorithms, in one practical application of this invention, symmetric and asymmetric encryption can be combined to further balance security and performance. For example, an asymmetric encryption algorithm can be used to securely exchange symmetric keys, and then symmetric encryption can be used to encrypt the actual data.
[0026] In an optional embodiment of step S500 of the present invention, if the matching result is the asymmetric encryption algorithm, then obtaining the second encryption result by combining the plaintext data with the metadata after sampling encryption based on scenario-determined encryption density using the asymmetric encryption algorithm includes: S501. If the matching result is the asymmetric encryption algorithm, then the scene sensitivity level is determined based on the scene information. In this invention, the scene sensitivity level includes highly sensitive scenes (such as financial transactions and medical privacy), moderately sensitive scenes (such as user registration information), and low sensitive scenes (such as backups of public announcements).
[0027] S502. Obtain the encryption density range of the plaintext data based on the scene sensitivity level; encryption density definition: Encryption density = (encrypted data volume / total data volume) × 100%, quantified according to the scene sensitivity level threshold: High sensitivity scene: encryption density ≥ 90%; Medium sensitivity scene: encryption density 50%-80%; Low sensitivity scene: encryption density ≤ 30%.
[0028] S503. Encrypt the plaintext data using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption to obtain the ciphertext body. This step may include using the encryption density range as a guide to sequentially encrypt structured data, unstructured data, and other data in the plaintext data (the encryption process stops when the plaintext encryption density reaches the lower or upper limit of the encryption density range). For the structured data in the plaintext data, categorize and encrypt it according to the encryption ratio matched by field sensitivity. For the unstructured data in the plaintext data, encrypt it using random sampling. For the other data in the plaintext data, perform hierarchical encryption according to the encryption ratio matched by data importance. This invention reduces the amount of data requiring high-level encryption through sampling encryption, while maintaining security and increasing encryption speed by 30%-60% (especially for big data scenarios), and reducing computing resource (CPU / memory) consumption by more than 40%. It is compatible with mainstream encryption standards (such as AES-256, RSA-2048, ECC-256) and can be directly integrated into existing systems, reducing interface development costs. Through AI, it accurately identifies scenarios and matches encryption density, achieving a high-sensitivity data encryption coverage rate of ≥90%, avoiding performance waste caused by over-encryption or security risks caused by insufficient encryption.
[0029] More specifically, the classification and encryption of the structured data in the plaintext data according to the field sensitivity matching encryption ratio includes: extracting sensitive fields, non-sensitive fields, and other fields from the structured data separately; encrypting the sensitive fields at 100% ratio, encrypting the non-sensitive fields at a first preset ratio, and leaving the other fields unencrypted. In this invention, structured data (such as a database table) is exemplified by: encryption by field, encrypting only sensitive fields (such as "ID number" and "bank card number"), while non-sensitive fields (such as "gender" and "region") are in plaintext. For example, in a user table, "phone number" and "payment password" are encrypted (60%, meeting the density requirement for medium-sensitivity scenarios), while the remaining fields are in plaintext.
[0030] The encryption of unstructured data within the plaintext data using a random sampling method includes: obtaining data block information of the unstructured data; constructing a random number generator based on the data block information; obtaining several target data blocks through the random number generator; and encrypting the unstructured data within the several target data blocks. In this invention, unstructured data (such as logs or video streams) is encrypted by proportional sampling, using a pseudo-random number generator (with a seed bound to a data hash value to ensure unpredictable randomness) to randomly select data blocks for encryption. For example, in low-sensitivity logs, 20% of entries are randomly sampled and encrypted (meeting a density of ≤30%), while the remaining plaintext entries are appended with hash checksums.
[0031] The hierarchical encryption of other data in the plaintext data, based on the data importance matching encryption ratio, includes: extracting core data, ordinary data, and redundant data from the other data separately; encrypting the core data at 100% ratio; encrypting the ordinary data at a second preset ratio; and leaving the redundant data unencrypted. In this invention, exemplarily, hierarchical encryption (e.g., core-ordinary-redundant data) is as follows: core data (e.g., transaction amount, medical record diagnosis results) is 100% encrypted, ordinary data (e.g., transaction time, examination items) is 50% encrypted, and redundant data (e.g., duplicate verification fields) is unencrypted.
[0032] S504. Combine the ciphertext body and the metadata to obtain the second encryption result. See also Figure 2In simple terms, the basic logic of the encryption process of this invention can be as follows: Input plaintext data (including metadata), extract the metadata (plaintext) and input it into the AI model to identify the scenario and purpose; select a symmetric / asymmetric encryption algorithm based on the scenario and data characteristics (e.g., select ECC for highly sensitive small data and AES for low-sensitivity large data); encrypt the data according to the encryption density corresponding to the scenario, using the above sampling strategy to generate mixed data of "plaintext metadata + ciphertext body"; the encrypted data can be securely transmitted or stored, the ciphertext part is only decrypted with the corresponding key, and the plaintext metadata is used by the receiver to identify the data structure (does not contain sensitive information).
[0033] The main technical means used in the AI-based adaptive data encryption method of this invention are as follows: AI technology is used to identify data usage scenarios and application purposes; specifically, a model is trained through metadata features to achieve accurate mapping between scenarios and sensitivity levels; a single encryption algorithm (symmetric or asymmetric) is selected based on data characteristics (data volume, security requirements, real-time performance) to reduce the complexity of hybrid encryption; a quantified encryption density is defined (≥90% / 50%-80% / ≤30% for high / medium / low sensitivity scenarios), and differentiated sampling encryption strategies (field-level encryption, proportional sampling encryption, hierarchical encryption) are designed for structured / unstructured data; the decryption process combines key matching, plaintext metadata integration, and integrity verification (such as hash comparison) to ensure data security and integrity.
[0034] See Figure 3 The second aspect of the present invention provides an AI-based adaptive data encryption device, the AI-based adaptive data encryption device comprising: Plaintext acquisition module 10 is used to acquire plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; AI metadata analysis module 20 is used to extract the metadata from the plaintext data and input the metadata into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information and data feature information of the plaintext data; The encryption algorithm matching module 30 is used to match a preset encryption algorithm based on the scene information, the purpose information and the data feature information. The preset encryption algorithm includes a symmetric encryption algorithm and an asymmetric encryption algorithm. The symmetric encryption module 40 is used to encrypt the plaintext data using the symmetric encryption algorithm and then combine it with the metadata to obtain a first encryption result if the matching result is the symmetric encryption algorithm. The asymmetric encryption module 50 is used to obtain a second encryption result by sampling and encrypting the plaintext data with a scenario-based encryption density determined by the asymmetric encryption algorithm and then combining it with the metadata if the matching result is the asymmetric encryption algorithm.
[0035] In an optional embodiment of the second aspect of the present invention, the asymmetric encryption module includes: A scene sensitivity determination unit is used to determine the scene sensitivity level based on the scene information if the matching result is the asymmetric encryption algorithm. An encryption density range determination unit is used to obtain the encryption density range of the plaintext data based on the scene sensitivity level. The sampling encryption unit is used to encrypt the plaintext data using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption, so as to obtain the ciphertext body. An encryption result generation unit is used to combine the ciphertext body and the metadata to obtain the second encryption result.
[0036] In an optional embodiment of the second aspect of the present invention, the sampling encryption unit includes: The sequential encryption subunit is used to encrypt the structured data, unstructured data and other data in the plaintext data in sequence, guided by the encryption density range. The structured data encryption subunit is used to classify and encrypt the structured data in the plaintext data according to the field sensitivity matching encryption ratio. An unstructured data encryption subunit is used to encrypt the unstructured data in the plaintext data by means of random sampling. Other data encryption subunits are used to perform hierarchical encryption on the other data in the plaintext data according to the encryption ratio matched by data importance.
[0037] In an optional embodiment of the second aspect of the present invention, the structured data encryption subunit includes: The field extraction unit is used to extract sensitive fields, non-sensitive fields, and other fields from the structured data separately. The field encryption unit is used to encrypt the sensitive fields at a 100% ratio, extract the non-sensitive fields and encrypt them at a first preset ratio, and leave the other fields unencrypted.
[0038] In an optional embodiment of the second aspect of the present invention, the unstructured data encryption subunit includes: The data block information acquisition unit is used to acquire the data block information of the unstructured data. A random number generator construction unit is used to construct a random number generator based on the data block information; The target data block acquisition unit is used to obtain a number of target data blocks through the random number generator. An unstructured data encryption unit is used to encrypt the unstructured data in a plurality of target data blocks.
[0039] In an optional embodiment of the second aspect of the present invention, the other data encryption subunits include: The data hierarchical extraction unit is used to extract core data, ordinary data, and redundant data from the other data separately; The data hierarchical encryption unit is used to encrypt the core data at a 100% ratio, extract the ordinary data at a second preset ratio for encryption, and leave the redundant data unencrypted. In an optional embodiment of the second aspect of the present invention, the encryption algorithm matching module includes: A real-time determination unit is used to determine the real-time requirements of the plaintext data based on the scenario information; A security determination unit is used to determine the security requirements of the plaintext data based on the usage information. A data volume determination unit is used to determine the data volume requirement of the plaintext data based on the data feature information. The condition table matching unit is used to match the real-time requirements, the security requirements, and the data volume requirements with the first condition table of the symmetric encryption algorithm and the second condition table of the asymmetric encryption algorithm, respectively. An encryption algorithm determination unit is used to determine the target encryption algorithm for the plaintext data based on the degree of matching between the real-time requirements, the security requirements, and the data volume requirements and the first condition table and the second condition table, respectively.
[0040] Figure 4 This is a schematic diagram of the structure of an AI-based adaptive data encryption device according to an embodiment of the present invention. This AI-based adaptive data encryption device can vary significantly due to differences in configuration or performance, and may include one or more processors 60 (central processing units, CPUs) (e.g., one or more processors) and memory 70, and one or more storage media 80 (e.g., one or more mass storage devices) for storing applications or data. The memory and storage media can be temporary or persistent storage. The program stored in the storage media may include one or more modules (not shown in the diagram), each module including a series of instruction operations on the AI-based adaptive data encryption device. Furthermore, the processor may be configured to communicate with the storage media and execute the series of instruction operations in the storage media on the AI-based adaptive data encryption device.
[0041] The AI-based adaptive data encryption device of this invention may further include one or more power supplies 90, one or more wired or wireless network interfaces 100, one or more input / output interfaces 110, and / or one or more operating systems, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art will understand that... Figure 4 The illustrated structure of the AI-based adaptive encryption device does not constitute a limitation on the AI-based adaptive encryption device and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.
[0042] The present invention also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium, wherein the computer-readable storage medium stores instructions that, when the instructions are executed on a computer, cause the computer to perform the steps of the AI-based adaptive data encryption method.
[0043] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the system or system / unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0044] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0045] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data adaptive encryption method based on AI analysis, characterized in that, include: Obtain plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; The metadata is extracted from the plaintext data and input into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information and data feature information of the plaintext data; The preset encryption algorithm is matched based on the scenario information, the purpose information, and the data feature information. The preset encryption algorithm includes symmetric encryption algorithm and asymmetric encryption algorithm. If the matching result is the symmetric encryption algorithm, then the plaintext data is encrypted using the symmetric encryption algorithm and combined with the metadata to obtain the first encryption result; If the matching result is the asymmetric encryption algorithm, then the plaintext data is sampled and encrypted using the asymmetric encryption algorithm with encryption density determined based on the scenario, and then combined with the metadata to obtain the second encryption result.
2. The AI-based adaptive data encryption method according to claim 1, characterized in that, If the matching result is the asymmetric encryption algorithm, then obtaining the second encryption result by sampling and encrypting the plaintext data using the asymmetric encryption algorithm with a scenario-based encryption density determination, and then combining it with the metadata, includes: If the matching result is the asymmetric encryption algorithm, then the scene sensitivity level is determined based on the scene information; The encryption density range of the plaintext data is obtained by using the scene sensitivity level; The plaintext data is encrypted using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption to obtain the ciphertext body; The second encryption result is obtained by combining the ciphertext body and the metadata.
3. The AI-based adaptive data encryption method according to claim 2, characterized in that, The method of encrypting the plaintext data using the asymmetric encryption algorithm with the encryption density range limited by sampling encryption to obtain the ciphertext body includes: Using the encryption density range as a guide, the structured data, unstructured data, and other data in the plaintext data are encrypted sequentially. The structured data within the plaintext data is classified and encrypted according to the encryption ratio matched with the field sensitivity. The unstructured data in the plaintext data is encrypted using a random sampling method; For the other data in the plaintext data, hierarchical encryption is performed according to the encryption ratio matched by the data importance.
4. The AI-based adaptive data encryption method according to claim 3, characterized in that, The method of classifying and encrypting the structured data in the plaintext data according to the field sensitivity matching encryption ratio includes: Sensitive fields, non-sensitive fields, and other fields are extracted separately from the structured data; The sensitive fields are encrypted at a 100% ratio, the non-sensitive fields are encrypted at a first preset ratio, and the other fields are not encrypted.
5. The AI-based adaptive data encryption method according to claim 3, characterized in that, The encryption of the unstructured data in the plaintext data using a random sampling method includes: Obtain the data block information where the unstructured data exists; A random number generator is constructed based on the data block information; Several target data blocks are obtained through the random number generator; The unstructured data in several target data blocks is encrypted.
6. The AI-based adaptive data encryption method according to claim 3, characterized in that, The other data in the plaintext data are encrypted hierarchically according to the encryption ratio based on data importance, including: The core data, ordinary data, and redundant data in the other data are extracted separately. The core data is encrypted at a 100% ratio, the ordinary data is extracted and encrypted at a second preset ratio, and the redundant data is not encrypted.
7. The AI-based adaptive data encryption method according to claim 6, characterized in that, The matching of preset encryption algorithms based on the scene information, the purpose information, and the data feature information, wherein the preset encryption algorithms include symmetric encryption algorithms and asymmetric encryption algorithms, including: The real-time requirements of the plaintext data are determined based on the scenario information. The security requirements for the plaintext data are determined based on the aforementioned usage information; The data volume requirement for the plaintext data is determined based on the data feature information; The real-time requirements, security requirements, and data volume requirements are respectively matched with the first condition table of the symmetric encryption algorithm and the second condition table of the asymmetric encryption algorithm; Based on the degree of matching between the real-time requirements, security requirements, and data volume requirements and the first and second condition tables, respectively, the target encryption algorithm for the plaintext data is determined.
8. A data adaptive encryption device based on AI analysis, characterized in that, The AI-based adaptive data encryption device includes: The plaintext acquisition module is used to acquire plaintext data to be encrypted, wherein the plaintext data contains metadata describing the data structure; The AI metadata analysis module is used to extract the metadata from the plaintext data and input the metadata into a pre-trained AI model for analysis to obtain the usage scenario information, purpose information and data feature information of the plaintext data. An encryption algorithm matching module is used to match a preset encryption algorithm based on the scenario information, the purpose information, and the data feature information. The preset encryption algorithm includes a symmetric encryption algorithm and an asymmetric encryption algorithm. A symmetric encryption module is used to encrypt the plaintext data using the symmetric encryption algorithm and then combine it with the metadata to obtain a first encryption result if the matching result is the symmetric encryption algorithm. An asymmetric encryption module is used to obtain a second encryption result by sampling and encrypting the plaintext data with a scenario-based encryption density determined by the asymmetric encryption algorithm and then combining it with the metadata if the matching result is the asymmetric encryption algorithm.
9. A data adaptive encryption device based on AI analysis, characterized in that, The AI-based adaptive data encryption device includes: a memory and at least one processor, wherein the memory stores instructions, and the memory and the at least one processor are interconnected via a circuit. The at least one processor invokes the instructions in the memory to cause the AI-based adaptive data encryption device to perform the AI-based adaptive data encryption method as described in any one of claims 1-7.
10. A computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by the processor, it implements the AI-based adaptive data encryption method as described in any one of claims 1-7.
Citation Information
Patent Citations
Financial data access analysis system and using method thereof
CN106845946A
Tamper resistant software-mass data encoding
US20030163718A1