Big data security protection and information analysis system and method in Internet of Things environment

By employing a multi-layered security protection mechanism, combined with technologies such as symmetric encryption, asymmetric encryption, distributed storage, and real-time monitoring, the system addresses data leakage and unauthorized access issues in big data security protection and information analysis systems within the Internet of Things (IoT) environment, enabling efficient and secure data processing and analysis.

CN120880754APending Publication Date: 2025-10-31GUANGZHOU XIAODING DIGITAL TECHNOLOGY CO LTD

Patent Information

Application Number
CN202511114323.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

Big data security protection and information analysis systems in the Internet of Things (IoT) environment suffer from problems such as data leakage, tampering, and unauthorized access. Traditional methods cannot adapt to the characteristics of large data volume, numerous devices, and high transmission speed.

Method used

A multi-layered security protection mechanism is adopted, including a data acquisition module, a data encryption module, a data storage module, and a security verification module. It combines symmetric and asymmetric encryption, distributed storage, multi-factor authentication, real-time monitoring, and homomorphic encryption technologies to dynamically adjust data processing strategies.

Benefits of technology

It improves data security and processing efficiency, ensures real-time and efficient data analysis in the Internet of Things environment, prevents unauthorized access and data leakage, and protects user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880754A_ABST
    Figure CN120880754A_ABST
Patent Text Reader

Abstract

The invention discloses a big data security protection and information analysis system and method in an Internet of Things environment, and the method comprises the steps: an Internet of Things device collects data, transmits the data to a storage module through encryption, carries out the encryption processing of the data through a hybrid encryption technology, and carries out the hierarchical storage according to the sensitivity; the system uses multi-factor authentication to verify the legality of the device, and adjusts the access authority according to the behavior of the device; in the data storage and analysis process, homomorphic encryption and data anonymization technologies are applied; the state of the data flow is monitored in real time, abnormity and potential threats are identified, and a processing strategy is dynamically adjusted in combination with intelligent analysis; when a security threat is detected, unauthorized equipment is automatically blocked, and abnormal data flow propagation is prevented; according to the big data security protection and information analysis system and method in the Internet of Things environment, through a multi-level security protection mechanism, it is ensured that big data analysis of the Internet of Things is safe and efficient, and the intelligent decision-making ability and the application efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of big data security protection and information analysis in the Internet of Things (IoT) environment, specifically involving big data security protection and information analysis systems and methods in the IoT environment. Background Technology

[0002] A big data security protection and information analysis system in the Internet of Things (IoT) environment refers to a comprehensive system established within the IoT system to ensure data security, privacy protection, and effective utilization. This system primarily involves big data collection, storage, processing, analysis, and protection mechanisms. IoT devices continuously generate massive amounts of data, which needs to be collected and stored through sensors, smart devices, etc. The big data platform collects data from various IoT terminal devices and stores it in an efficient and reliable manner. This data can include information such as temperature, humidity, and location acquired by sensors. Big data analytics technology processes the collected data to identify valuable information, for example, through... Data mining, machine learning, and artificial intelligence algorithms are used to analyze behavioral patterns and trends in the Internet of Things (IoT) environment to aid in decision-making and optimize device performance. However, data transmission and storage in the IoT environment are vulnerable to attacks such as man-in-the-middle attacks, data breaches, and malware. IoT data often involves user privacy; therefore, privacy protection mechanisms are crucial, requiring measures such as data anonymization and privacy management to ensure that sensitive user information is not leaked. Furthermore, the IoT environment typically includes various types of devices and systems, which may be provided by different vendors, making data sharing and interoperability challenging. This system needs to ensure secure and seamless data exchange and collaboration between different devices and platforms.

[0003] However, in existing big data security protection and information analysis systems under the Internet of Things (IoT) environment, although many technical measures have been taken to ensure the security and effectiveness of data, some defects and challenges still exist. With the rapid development of IoT technology, various smart devices and sensors are constantly being integrated into daily life and industrial applications, generating massive amounts of data. Big data analysis in the IoT environment provides a foundation for various intelligent decisions and automated operations, but it also faces significant challenges in data security and privacy protection. Traditional data protection methods are often unable to adapt to the characteristics of large data volume, numerous devices, and high transmission speed in the IoT environment, which can easily lead to problems such as data leakage, tampering, and unauthorized access. Summary of the Invention

[0004] To address the shortcomings of existing technologies, the purpose of this invention is to provide a big data security protection and information analysis system and method in the Internet of Things (IoT) environment. Through a multi-layered security protection mechanism, it ensures that the big data analysis process in the IoT environment can both protect data security and perform data processing and analysis in real time and efficiently, thereby improving the intelligent decision-making capabilities and application efficiency in the IoT environment.

[0005] The technical solution adopted by this invention to solve its technical problem is:

[0006] Big data security protection and information analysis systems in the Internet of Things (IoT) environment include:

[0007] The data acquisition module is used to collect various types of data generated by IoT devices and send the data to the data storage module through a secure transmission protocol;

[0008] The data encryption module is used to encrypt the collected raw data. It adopts a hybrid strategy of symmetric and asymmetric encryption, and uses symmetric encryption algorithm on small data blocks and asymmetric encryption algorithm on large data blocks.

[0009] The data storage module is used to store encrypted data using a distributed storage architecture. Different levels of encryption strategies are used to store data with different sensitivities. Highly sensitive data is stored using advanced encryption, while low-sensitivity data is stored in storage nodes with lower security levels.

[0010] The security verification module is used to authenticate the identity of each device connected to the IoT system, ensuring that only authorized devices can access the system for data collection, transmission and storage. It uses multi-factor authentication technology, combined with the physical characteristics of the device, to verify identity.

[0011] The real-time monitoring module is used to monitor the status of IoT devices in real time, detect and identify abnormal device behavior, and respond promptly.

[0012] The methods for big data security protection and information analysis in the Internet of Things (IoT) environment include the following steps:

[0013] Various types of data are collected through IoT devices, including monitoring data from environmental sensors, equipment operating status, and user behavior. The collected data is transmitted to the data storage module through an encrypted transmission protocol.

[0014] The original data being transmitted is encrypted. The data encryption process uses a hybrid encryption technique, employing a symmetric encryption algorithm for small data blocks and an asymmetric encryption algorithm for large data blocks.

[0015] The collected data is stored in a tiered manner according to its sensitivity. Highly sensitive data is stored using strong encryption, while ordinary data is stored in storage nodes with a relatively low security level.

[0016] During the data reading and writing process, the system authenticates the device identity, uses a multi-factor authentication scheme to verify the legitimacy of the device, enhances security by combining the physical characteristics of the device with dynamic password generation technology, and dynamically adjusts access permissions based on the device behavior.

[0017] Homomorphic encryption and data anonymization technologies are used in the data storage and analysis process;

[0018] The system monitors the status of data streams in real time, identifies abnormal behavior and potential security threats, and dynamically adjusts data processing strategies in conjunction with intelligent analysis technology.

[0019] When a potential security threat is detected, the system will automatically activate security protection mechanisms to block unauthorized devices and prevent the spread of abnormal data streams.

[0020] As a preferred method, various types of data are collected through IoT devices, including monitoring data from environmental sensors, device operating status, and user behavior. The collected data is then transmitted to the data storage module via an encrypted transmission protocol.

[0021] IoT devices monitor environmental data in real time through built-in temperature, humidity, gas concentration, and light intensity sensors. They also collect data on temperature, vibration, current, device operating status, user operation commands, and device interaction behavior. The data is collected through sensor interfaces and formatted into a unified data stream.

[0022] For environments with large data volumes and high real-time requirements, symmetric encryption is used to encrypt the collected data. For data with high security requirements, asymmetric encryption is used for key exchange and encryption.

[0023] Data is transmitted using encrypted transmission protocols. For low-bandwidth, low-latency transmission between IoT devices, the MQTT protocol is used, and TLS encryption is used to ensure the security of data transmission.

[0024] After the data arrives at the storage module, the receiving end decrypts the encrypted data using the corresponding key to recover the original data.

[0025] As a preferred method, the transmitted raw data is encrypted. The data encryption process employs a hybrid encryption technique, using a symmetric encryption algorithm for small data blocks and an asymmetric encryption algorithm for large data blocks.

[0026] For small-scale data, use symmetric encryption algorithms for encryption; for larger data blocks, use asymmetric encryption algorithms for encryption.

[0027] Specific encryption process:

[0028] Generate a random symmetric key for encrypting small blocks of data. The size of the symmetric key can be 128 bits, 192 bits, or 256 bits.

[0029] Small data blocks are separated and encrypted using the generated symmetric key. The encrypted data will be transmitted in ciphertext form.

[0030] The processing of large data blocks involves encrypting the symmetric key itself, using an asymmetric encryption algorithm to encrypt the generated symmetric key, and then transmitting the asymmetric encrypted symmetric key along with the encrypted data.

[0031] During transmission, the encrypted small data blocks and the encrypted symmetric key are transmitted together to the receiver;

[0032] Recipient's decryption process:

[0033] The receiver uses its private key to decrypt the encrypted symmetric key and recover the original symmetric key.

[0034] The recovered symmetric key is then used to decrypt the encrypted small data block to obtain the original data content.

[0035] As a preferred approach, the collected data is stored in a tiered manner based on its sensitivity, with highly sensitive data stored using strong encryption and ordinary data stored in storage nodes with relatively lower security levels.

[0036] The collected data is classified into highly sensitive data and ordinary data based on sensitivity.

[0037] Highly sensitive data is protected with strong encryption, and more secure storage methods and stricter access control policies are adopted.

[0038] Ordinary data should be encrypted with low strength or not encrypted at all, and a normal storage strategy should be adopted.

[0039] Data storage architecture design:

[0040] Multi-tiered storage architecture: providing different storage nodes for sensitive data at different levels;

[0041] High-sensitivity data storage layer: Storage nodes designed for highly sensitive data, employing strong encryption algorithms and strict access control mechanisms;

[0042] Ordinary data storage layer: Nodes used for storing ordinary data, employing relatively low security measures;

[0043] Highly sensitive data is encrypted and stored using a symmetric encryption algorithm. For database storage, transparent data encryption is used, while for ordinary data, lower-strength encryption is used.

[0044] During the data collection and processing process, the sensitivity of the data is assessed regularly, and dynamic hierarchical storage is carried out based on the actual content and application scenarios of the data.

[0045] As a preferred approach, during data reading and writing, the system authenticates the device identity, employs a multi-factor authentication scheme to verify the device's legitimacy, enhances security by combining the device's physical characteristics with dynamic password generation technology, and dynamically adjusts access permissions based on device behavior.

[0046] The mathematical formula for setting device authentication is as follows:

[0047] Device authentication functions:

[0048] I device =f(P device F device T password )

[0049] Among them, P device For the physical characteristics of the equipment, F device For the device's biometrics or hardware characteristics; T password A temporary password obtained through dynamic password generation technology;

[0050] Dynamic cryptography is based on time and a pre-shared key. The generated temporary password changes periodically, and its calculation formula is expressed as:

[0051] T password =H(K) device T current )

[0052] Where H is the cryptographic hash function; K device A key shared between the device and the server; T current This is the current timestamp or counter;

[0053] The device behavior analysis section dynamically adjusts access permissions based on the device's behavioral characteristics during the access process. The formula for behavior characteristic analysis is defined as follows:

[0054]

[0055] Among them, B device (t) represents the analysis result of the device's behavior at time point t, A i (t) represents the i-th action performed by the device at time t; f i For behavioral analysis functions;

[0056] Based on the device's authentication status and behavior analysis results, access permissions are dynamically adjusted using the following function:

[0057] A device (t)=g(I device B device (t))

[0058] Among them, A device (t) represents the access permissions of the device at time t; I device For the device's authentication result; B device (t) represents the behavioral analysis results of the device.

[0059] As a preferred method, the approach used in data storage and analysis is homomorphic encryption and data anonymization techniques:

[0060] Suppose that data x is encrypted to obtain ciphertext E(x), and the encryption operation is as follows:

[0061] E(x) = Encrypt(x)

[0062] Where E(x) is the encrypted data, x is the original data, and Encrypt is the encryption operation;

[0063] Given two encrypted data sets E(x1) and E(x2), homomorphic encryption directly performs addition operations on the encrypted data:

[0064]

[0065] in, This represents a homomorphic addition operation;

[0066] Given two encrypted data sets E(x1) and E(x2), homomorphic encryption performs multiplication on the encrypted data:

[0067]

[0068] in, This represents a homomorphic multiplication operation;

[0069] Finally, the result is obtained through decryption:

[0070] D(E(x))=x

[0071] Where D is the decryption operation, E(x) is the encrypted data, and x is the decrypted plaintext data;

[0072] Data anonymization ensures privacy by replacing, deleting, or modifying sensitive data, specifically by anonymizing personal information within sensitive data.

[0073] Mask(x) = Replace(x)

[0074] Where x is the original data, and Mask(x) is the data after anonymization.

[0075] Pseudo-anonymization replaces personal information with pseudonyms, thus decoupling it from a specific individual. Let's say a user's name x is replaced with the pseudonym p:

[0076] Pseudonymize(x) = p

[0077] Where p is a pseudonym, which does not directly reveal personal identity information, but can be restored to the original data under certain circumstances;

[0078] Data anonymization is achieved by aggregating personal data into statistical data within a certain range. This involves establishing a set of user age data x1, x2, ..., x... n The statistical information of these data is calculated and then anonymized:

[0079]

[0080] Where Aggregate represents the aggregation operation, x1, x2, ..., x n Given a set of data, the result is the mean of the data.

[0081] After data anonymization, the stored data x′ no longer contains personally identifiable information, reducing the risk of privacy leaks.

[0082] Store(x′)where x′=Anonymous(x)

[0083] Where x′ represents the anonymized data, and Anonymous(x) represents the anonymization process of the data.

[0084] As a preferred approach, the method of dynamically adjusting the data processing strategy by monitoring the status of the data stream in real time, identifying abnormal behavior and potential security threats, and combining this with intelligent analysis technology is as follows:

[0085] Real-time monitoring of the data stream's status uses a time series to represent changes in the data stream, defining a data stream status function:

[0086] S flow (t)=f(D(t,H(t))

[0087] Among them, S flow (t) represents the data stream state at time t; D(t) represents the data stream content or input data at time t; H(t) represents historical data or previous state information at time t.

[0088] Anomaly detection involves monitoring the data stream and combining it with intelligent analysis techniques to identify whether anomalies exist. An anomaly detection function is defined as follows:

[0089] A detect (t)=Detect(S flow (t), θ)

[0090] Among them, A detect (t) represents the anomaly flag detected at time t, where 1 indicates an anomaly and 0 indicates normal; Detect is the anomaly detection algorithm; θ is the anomaly threshold.

[0091] Potential security threat identification is based on anomaly detection results, further combined with known security threat models. The calculation formula is as follows:

[0092] T threat (t)=g(A detect (t), P threat )

[0093] Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the result of the anomaly detection; P threat It is a predictive model or threat database for security threats, containing known threat patterns and attack characteristics;

[0094] Intelligent analytics technology is used to analyze data stream trends, identify patterns, and predict future changes. A model-based intelligent analytics algorithm is established, and the model is represented as follows:

[0095] M analysis (D(t),H(t))=Analyze(D(t),H(t),W)

[0096] Among them, M analysis (D(t), H(t)) represents the analysis results of the intelligent analysis model on the data stream state; W represents the parameters of the intelligent analysis model; Analyze represents the processing performed through intelligent analysis technology;

[0097] Based on the results of real-time monitoring, anomaly detection, and potential threat identification, the system dynamically adjusts its data processing strategy. The function representing the adjustment strategy is as follows:

[0098] P adjust (t)=h(T threat (t), M analysis (D(t), H(t)), α)

[0099] Among them, P adjust (t) represents the data processing strategy adjusted at time t; Tthreat (t) represents the identification result of potential security threats; M analysis (D(t), H(t)) represents the output of the intelligent analysis; α represents the sensitivity coefficient of the adjustment strategy.

[0100] As a preferred method, when a potential security threat is detected, the system will automatically activate a security protection mechanism to block unauthorized devices and prevent the propagation of abnormal data streams.

[0101] The system will detect potential security threats and establish an anomaly detection method A. detect (t) Identify anomalous behavior, or through threat identification model T threat (t) Identifying potential security threats, the detection process is represented as follows:

[0102] T threat (t)=g(A detect (t), P threat )

[0103] Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the anomaly detection result; P threat For threat identification models;

[0104] Once a security threat is detected, the system immediately blocks unauthorized devices. Device identification is performed using device identifiers and authorization verification mechanisms. The formula for blocking unauthorized devices is as follows:

[0105] E block (t)=Block(D unauthorized (t), α)

[0106] Among them, E block (t) represents the device blocking mechanism activated at time t; D unauthorized (t) represents the list of unauthorized devices, determined by the device identifier; α represents the blocking strength or policy parameter.

[0107] The system will prevent the further propagation of abnormal data streams. The propagation of data streams is restricted through access control, traffic limiting, and packet filtering. The formula for preventing the propagation of abnormal data streams is as follows:

[0108] F block (t) = Filter(S) flow (t), T threat (t), β)

[0109] Among them, F block (t) represents the data stream blocking or filtering mechanism initiated at time t; S flow(t) represents the real-time data stream status; T threat (t) represents the identified potential security threats; β represents the sensitivity or policy parameter for data stream filtering.

[0110] To ensure system security, the system initiates alarms, log recording, and automatic response security measures. The calculation formula for the security mechanism is as follows:

[0111] P defense (t)=h(T threat (t), E block (t), F block (t), γ)

[0112] Among them, P defense (t) represents the comprehensive protection mechanism activated at time t; T threat (t) represents the potential threat identification result; E block (t) refers to measures to block unauthorized devices; F block (t) represents the measures to prevent the propagation of abnormal data streams; γ represents the parameters of the protection strategy.

[0113] Another technical problem to be solved by the present invention is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements a big data security protection and information analysis system and method in the Internet of Things environment as described above.

[0114] Another technical problem to be solved by the present invention is to provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a big data security protection and information analysis system and method in an Internet of Things environment.

[0115] The beneficial effects of this invention are:

[0116] By combining symmetric and asymmetric encryption technologies, the efficiency and security of data encryption are improved, overcoming the performance bottlenecks of traditional encryption technologies. Different storage strategies are adopted for data with varying sensitivities, and distributed storage technology enhances data security and reliability. Physical characteristics and behavioral analysis are introduced into identity authentication to ensure that only verified devices can access the system, preventing unauthorized access. Homomorphic encryption and data anonymization technologies are used to protect user privacy, ensuring that sensitive information is not leaked during data analysis. In an IoT environment, data flow can be monitored in real time, and potential security threats can be identified and defended against in a timely manner. Attached Figure Description

[0117] Figure 1 This is a schematic diagram of the big data security protection and information analysis system in the Internet of Things environment of the present invention. Detailed Implementation

[0118] The principles and features of the present invention are described below. The examples given are for illustrative purposes only and are not intended to limit the scope of the invention. The invention is described more specifically by way of example in the following paragraphs. The advantages and features of the invention will become clearer from the following description and claims.

[0119] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0120] Example

[0121] The technical solution adopted by this invention to solve its technical problem is:

[0122] Big data security protection and information analysis systems in the Internet of Things (IoT) environment include:

[0123] The data acquisition module is used to collect various types of data generated by IoT devices and send the data to the data storage module through a secure transmission protocol;

[0124] The data encryption module is used to encrypt the collected raw data. It adopts a hybrid strategy of symmetric and asymmetric encryption, and uses symmetric encryption algorithm on small data blocks and asymmetric encryption algorithm on large data blocks.

[0125] The data storage module is used to store encrypted data using a distributed storage architecture. Different levels of encryption strategies are used to store data with different sensitivities. Highly sensitive data is stored using advanced encryption, while low-sensitivity data is stored in storage nodes with lower security levels.

[0126] The security verification module is used to authenticate the identity of each device connected to the IoT system, ensuring that only authorized devices can access the system for data collection, transmission and storage. It uses multi-factor authentication technology, combined with the physical characteristics of the device, to verify identity.

[0127] The real-time monitoring module is used to monitor the status of IoT devices in real time, detect and identify abnormal device behavior, and respond promptly.

[0128] By employing encryption and distributed storage strategies, data is rigorously protected during collection, transmission, and storage, reducing the risk of data leakage and tampering. Multi-factor authentication, hybrid encryption, and behavioral monitoring ensure different levels of security protection at each layer of the IoT system. Distributed storage and real-time monitoring guarantee data reliability and high system availability, ensuring normal system operation even if some devices or nodes are attacked. Strategies such as tiered storage of sensitive data and a combination of symmetric and asymmetric encryption guarantee high data security while reducing the cost and latency of encryption processing.

[0129] The methods for big data security protection and information analysis in the Internet of Things (IoT) environment include the following steps:

[0130] Various types of data are collected through IoT devices, including monitoring data from environmental sensors, equipment operating status, and user behavior. The collected data is transmitted to the data storage module through an encrypted transmission protocol.

[0131] The original data being transmitted is encrypted. The data encryption process uses a hybrid encryption technique, employing a symmetric encryption algorithm for small data blocks and an asymmetric encryption algorithm for large data blocks.

[0132] The collected data is stored in a tiered manner according to its sensitivity. Highly sensitive data is stored using strong encryption, while ordinary data is stored in storage nodes with a relatively low security level.

[0133] During the data reading and writing process, the system authenticates the device identity, uses a multi-factor authentication scheme to verify the legitimacy of the device, enhances security by combining the physical characteristics of the device with dynamic password generation technology, and dynamically adjusts access permissions based on the device behavior.

[0134] Homomorphic encryption and data anonymization technologies are used in the data storage and analysis process;

[0135] The system monitors the status of data streams in real time, identifies abnormal behavior and potential security threats, and dynamically adjusts data processing strategies in conjunction with intelligent analysis technology.

[0136] When a potential security threat is detected, the system will automatically activate security protection mechanisms to block unauthorized devices and prevent the spread of abnormal data streams.

[0137] Data security is ensured through technologies such as encrypted transmission, hybrid encryption, and homomorphic encryption, preventing tampering, leakage, or misuse during data collection, transmission, storage, and analysis. Sensitive data is encrypted and anonymized to ensure user privacy is not compromised, especially in IoT device and data storage management, protecting users' personal information and behavioral data. Hybrid encryption technology is employed to improve encryption and decryption efficiency while maintaining security. Dynamic access control and intelligent analysis automatically address potential security threats, improving system response speed and efficiency. The system can monitor and intelligently analyze data streams in real time, identify and respond to abnormal behavior, and dynamically adjust data processing strategies to ensure the protection mechanism can flexibly respond to different security threats. Once a security threat is detected, the system can automatically block unauthorized devices and abnormal data streams, reducing manual intervention, improving response speed, and preventing the spread of threats.

[0138] Various types of data are collected through IoT devices, including monitoring data from environmental sensors, device operating status, and user behavior. The collected data is transmitted to the data storage module via an encrypted transmission protocol as follows:

[0139] IoT devices monitor environmental data in real time through built-in temperature, humidity, gas concentration, and light intensity sensors. They also collect data on temperature, vibration, current, device operating status, user operation commands, and device interaction behavior. The data is collected through sensor interfaces and formatted into a unified data stream.

[0140] For environments with large data volumes and high real-time requirements, symmetric encryption is used to encrypt the collected data. For data with high security requirements, asymmetric encryption is used for key exchange and encryption.

[0141] Data is transmitted using encrypted transmission protocols. For low-bandwidth, low-latency transmission between IoT devices, the MQTT protocol is used, and TLS encryption is used to ensure the security of data transmission.

[0142] After the data arrives at the storage module, the receiving end decrypts the encrypted data using the corresponding key to recover the original data.

[0143] This solution employs symmetric encryption to process large volumes of data with high real-time requirements, offering efficient encryption and decryption performance. The TLS encryption protocol ensures data security during transmission, preventing interception or modification of data between IoT devices and storage modules. Various data types are collected through sensor interfaces and formatted into a unified data stream, simplifying data processing and transmission complexity and improving the overall system's data management efficiency. The MQTT protocol is suitable for low-bandwidth, low-latency data transmission in IoT environments, ensuring timely data transmission and processing in environments with high real-time requirements. The solution features a modular design, with independent components for devices, data acquisition, encrypted transmission, and data storage, facilitating future expansion and maintenance. It supports the access of various devices and sensors, handling different types of data sources, and allows for upgrades to encryption algorithms or transmission protocols as needed. The encryption mechanism effectively protects sensitive data such as user operation commands and interactive behaviors, ensuring user privacy is not compromised.

[0144] The original data being transmitted is encrypted using a hybrid encryption technique: a symmetric encryption algorithm is used for small data blocks, while an asymmetric encryption algorithm is used for large data blocks. The method is as follows:

[0145] For small-scale data, use symmetric encryption algorithms for encryption; for larger data blocks, use asymmetric encryption algorithms for encryption.

[0146] Specific encryption process:

[0147] Generate a random symmetric key for encrypting small blocks of data. The size of the symmetric key can be 128 bits, 192 bits, or 256 bits.

[0148] Small data blocks are separated and encrypted using the generated symmetric key. The encrypted data will be transmitted in ciphertext form.

[0149] The processing of large data blocks involves encrypting the symmetric key itself, using an asymmetric encryption algorithm to encrypt the generated symmetric key, and then transmitting the asymmetric encrypted symmetric key along with the encrypted data.

[0150] During transmission, the encrypted small data blocks and the encrypted symmetric key are transmitted together to the receiver;

[0151] Recipient's decryption process:

[0152] The receiver uses its private key to decrypt the encrypted symmetric key and recover the original symmetric key.

[0153] The recovered symmetric key is then used to decrypt the encrypted small data block to obtain the original data content.

[0154] Symmetric encryption algorithms are fast and computationally efficient, making them suitable for processing small-scale data. Asymmetric encryption encrypts only the key, rather than the entire data block, significantly reducing encryption and decryption time for large data blocks and optimizing overall system performance. Using symmetric encryption for small data blocks and asymmetric encryption to protect the key for large data blocks ensures data security and avoids the risk of key exposure. Encrypting the symmetric key with asymmetric encryption protects the key from leakage even if the intermediate transmission link is insecure. Combining symmetric and asymmetric encryption allows for encryption of only the symmetric key when processing large data blocks, avoiding direct asymmetric encryption of the entire data block and reducing computational complexity. Transmitting encrypted small data blocks along with the encrypted symmetric key ensures that even if data is intercepted during transmission, attackers cannot reconstruct the original data, increasing data security during network transmission. Key encryption technology makes key management more flexible and secure, avoiding the risk of key exposure during network transmission.

[0155] The collected data is stored in a tiered manner based on its sensitivity. Highly sensitive data is stored using strong encryption, while ordinary data is stored in storage nodes with relatively lower security levels.

[0156] The collected data is classified into highly sensitive data and ordinary data based on sensitivity.

[0157] Highly sensitive data is protected with strong encryption, and more secure storage methods and stricter access control policies are adopted.

[0158] Ordinary data should be encrypted with low strength or not encrypted at all, and a normal storage strategy should be adopted.

[0159] Data storage architecture design:

[0160] Multi-tiered storage architecture: providing different storage nodes for sensitive data at different levels;

[0161] High-sensitivity data storage layer: Storage nodes designed for highly sensitive data, employing strong encryption algorithms and strict access control mechanisms;

[0162] Ordinary data storage layer: Nodes used for storing ordinary data, employing relatively low security measures;

[0163] Highly sensitive data is encrypted and stored using a symmetric encryption algorithm. For database storage, transparent data encryption is used, while for ordinary data, lower-strength encryption is used.

[0164] During the data collection and processing process, the sensitivity of the data is assessed regularly, and dynamic hierarchical storage is carried out based on the actual content and application scenarios of the data.

[0165] Highly sensitive data is stored with strong encryption and strict access control mechanisms to reduce the risk of data leakage and unauthorized access. Ordinary data is stored with lower encryption strength or no encryption at all, reducing storage resource consumption and computational overhead while ensuring performance. By classifying and dynamically assessing data sensitivity, highly sensitive data is protected with high strength, while ordinary data can be stored in a lighter manner while meeting security requirements, thereby optimizing storage resources and computational efficiency. This architecture allows data of different security levels to be stored on different nodes, avoiding the performance burden caused by excessive encryption, while ensuring that data is appropriately protected at different levels. Ordinary data does not require high-strength encryption or advanced storage measures, thus reducing the consumption of storage and computational resources and making it more cost-effective than full data encryption solutions. Encrypting sensitive data while not overly encrypting ordinary data ensures that resources are allocated reasonably. The data storage architecture can be flexibly adjusted according to the actual content, changes, and application scenarios of the data, supporting continuously expanding or changing data types. This flexibility allows the solution to adapt to different application scenarios and data processing needs; through the design of different storage tiers, it can flexibly cope with different types of data storage needs; the access control policy for highly sensitive data is more stringent, which can ensure that only authorized personnel can access the data, in compliance with data protection and privacy protection regulations.

[0166] During data reading and writing, the system authenticates the device identity, employs a multi-factor authentication scheme to verify the device's legitimacy, enhances security by combining the device's physical characteristics with dynamic password generation technology, and dynamically adjusts access permissions based on device behavior.

[0167] The mathematical formula for setting device authentication is as follows:

[0168] Device authentication functions:

[0169] I device =f(P device F device T password )

[0170] Among them, P device For the physical characteristics of the equipment, F device For the device's biometrics or hardware characteristics; T password A temporary password obtained through dynamic password generation technology;

[0171] Dynamic cryptography is based on time and a pre-shared key. The generated temporary password changes periodically, and its calculation formula is expressed as:

[0172] T password =H(K) device Tcurrent )

[0173] Where H is the cryptographic hash function; K device A key shared between the device and the server; T current This is the current timestamp or counter;

[0174] The device behavior analysis section dynamically adjusts access permissions based on the device's behavioral characteristics during the access process. The formula for behavior characteristic analysis is defined as follows:

[0175]

[0176] Among them, B device (t) represents the analysis result of the device's behavior at time point t, A i (t) represents the i-th action performed by the device at time t; f i For behavioral analysis functions;

[0177] Based on the device's authentication status and behavior analysis results, access permissions are dynamically adjusted using the following function:

[0178] A device (t)=g(I device B device (t))

[0179] Among them, A device (t) represents the access permissions of the device at time t; I device For the device's authentication result; B device (t) represents the behavioral analysis results of the device.

[0180] Using a combination of physical characteristics and dynamic passwords for authentication effectively prevents unauthorized devices from accessing the device. By monitoring and evaluating device access through behavioral analysis, the system can identify whether the device is being used normally as expected. The system dynamically adjusts access permissions based on the device's authentication status and behavioral analysis results, ensuring that each access operation is controlled based on real-time security assessments. Even if an attacker obtains some information about the device, the introduction of dynamic passwords and behavioral analysis makes it difficult for the attacker to maintain control over the device. Using biometrics or hardware characteristics as part of device authentication, combined with dynamic passwords, makes the authentication process both simple and secure.

[0181] In the process of data storage and analysis, the methods of using homomorphic encryption and data anonymization techniques are as follows:

[0182] Suppose that data x is encrypted to obtain ciphertext E(x), and the encryption operation is as follows:

[0183] E(x) = Encrypt(x)

[0184] Where E(x) is the encrypted data, x is the original data, and Encrypt is the encryption operation;

[0185] Given two encrypted data sets E(x1) and E(x2), homomorphic encryption directly performs addition operations on the encrypted data:

[0186]

[0187] in, This represents a homomorphic addition operation;

[0188] Given two encrypted data sets E(x1) and E(x2), homomorphic encryption performs multiplication on the encrypted data:

[0189]

[0190] in, This represents a homomorphic multiplication operation;

[0191] Finally, the result is obtained through decryption:

[0192] D(E(x))=x

[0193] Where D is the decryption operation, E(x) is the encrypted data, and x is the decrypted plaintext data;

[0194] Data anonymization ensures privacy by replacing, deleting, or modifying sensitive data, specifically by anonymizing personal information within sensitive data.

[0195] Mask(x) = Replace(x)

[0196] Where x is the original data, and Mask(x) is the data after anonymization.

[0197] Pseudo-anonymization replaces personal information with pseudonyms, thus decoupling it from a specific individual. Let's say a user's name x is replaced with the pseudonym p:

[0198] Pseudonymize(x) = p

[0199] Where p is a pseudonym, which does not directly reveal personal identity information, but can be restored to the original data under certain circumstances;

[0200] Data anonymization is achieved by aggregating personal data into statistical data within a certain range. This involves establishing a set of user age data x1, x2, ..., x... n The statistical information of these data is calculated and then anonymized:

[0201]

[0202] Where Aggregate represents the aggregation operation, x1, x2, ..., x n Given a set of data, the result is the mean of the data.

[0203] After data anonymization, the stored data x′ no longer contains personally identifiable information, reducing the risk of privacy leaks.

[0204] Store(x′)where x′=Anonymous(x)

[0205] Where x′ represents the anonymized data, and Anonymous(x) represents the anonymization process of the data.

[0206] Homomorphic encryption technology can perform operations on encrypted data without decryption; data anonymization technology ensures that stored personal information is not leaked by replacing, deleting, or modifying sensitive data; pseudo-anonymization replaces personal identity information with pseudonyms, so that data is no longer directly associated with individuals; through data anonymization, personal data is aggregated and statistical information is calculated, so that the stored data no longer contains the identity information of individual users; data anonymization and data desensitization technologies comply with the requirements of privacy protection laws and regulations such as GDPR.

[0207] The method for dynamically adjusting data processing strategies by real-time monitoring of data stream status, identification of abnormal behavior and potential security threats, and combination of intelligent analysis technology is as follows:

[0208] Real-time monitoring of the data stream's status uses a time series to represent changes in the data stream, defining a data stream status function:

[0209] S flow (t)=f(D(t,H(t))

[0210] Among them, S flow (t) represents the data stream state at time t; D(t) represents the data stream content or input data at time t; H(t) represents historical data or previous state information at time t.

[0211] Anomaly detection involves monitoring the data stream and combining it with intelligent analysis techniques to identify whether anomalies exist. An anomaly detection function is defined as follows:

[0212] A detect (t)=Detect(S flow (t), θ)

[0213] Among them, A detect (t) represents the anomaly flag detected at time t, where 1 indicates an anomaly and 0 indicates normal; Detect is the anomaly detection algorithm; θ is the anomaly threshold.

[0214] Potential security threat identification is based on anomaly detection results, further combined with known security threat models. The calculation formula is as follows:

[0215] T threat (t)=g(A detect (t), P threat )

[0216] Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the result of the anomaly detection; P threat It is a predictive model or threat database for security threats, containing known threat patterns and attack characteristics;

[0217] Intelligent analytics technology is used to analyze data stream trends, identify patterns, and predict future changes. A model-based intelligent analytics algorithm is established, and the model is represented as follows:

[0218] M analysis (D(t),H(t))=Analyze(D(t),H(t),W)

[0219] Among them, M analysis (D(t), H(t)) represents the analysis results of the intelligent analysis model on the data stream state; W represents the parameters of the intelligent analysis model; Analyze represents the processing performed through intelligent analysis technology;

[0220] Based on the results of real-time monitoring, anomaly detection, and potential threat identification, the system dynamically adjusts its data processing strategy. The function representing the adjustment strategy is as follows:

[0221] P adjust (t)=h(T threat (t), M analysis (D(t), H(t)), α)

[0222] Among them, P adjust (t) represents the data processing strategy adjusted at time t; T threat (t) represents the identification result of potential security threats; M analysis (D(t), H(t)) represents the output of the intelligent analysis; α represents the sensitivity coefficient of the adjustment strategy.

[0223] By monitoring the data stream status in real time, the system can dynamically detect changes in the data stream and promptly identify abnormal behavior and potential security threats. Through intelligent analysis algorithms, the system can automatically identify abnormal behavior. By further analyzing the anomaly detection results and combining them with known threat patterns and attack characteristics, the system can identify potential security threats in advance. Through intelligent analysis technology, the system can analyze the trends and patterns of the data stream and predict future data stream changes. Based on the results of real-time monitoring, anomaly detection, and threat identification, the system can dynamically adjust data processing strategies. Through intelligent monitoring and analysis, the system greatly reduces the need for manual intervention. By integrating intelligent analysis with security threat models, this solution can effectively enhance the protection against potential attacks. Intelligent analysis can not only identify patterns but also make effective adjustments to protection strategies when potential threats are identified, thereby improving the overall security of the system.

[0224] When a potential security threat is detected, the system will automatically activate security protection mechanisms to block unauthorized devices and prevent the propagation of abnormal data streams.

[0225] The system will detect potential security threats and establish an anomaly detection method A. detect (t) Identify anomalous behavior, or through threat identification model T threat (t) Identifying potential security threats, the detection process is represented as follows:

[0226] T threat (t)=g(A detect (t), P threat )

[0227] Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the anomaly detection result; P threat For threat identification models;

[0228] Once a security threat is detected, the system immediately blocks unauthorized devices. Device identification is performed using device identifiers and authorization verification mechanisms. The formula for blocking unauthorized devices is as follows:

[0229] E block (t)=Block(D unauthorized (t), α)

[0230] Among them, E block (t) represents the device blocking mechanism activated at time t; D unauthorized (t) represents the list of unauthorized devices, determined by the device identifier; α represents the blocking strength or policy parameter.

[0231] The system will prevent the further propagation of abnormal data streams. The propagation of data streams is restricted through access control, traffic limiting, and packet filtering. The formula for preventing the propagation of abnormal data streams is as follows:

[0232] F block (t) = Filter(S) flow (t), T threat (t), β)

[0233] Among them, F block (t) represents the data stream blocking or filtering mechanism initiated at time t; S flow (t) represents the real-time data stream status; T threat (t) represents the identified potential security threats; β represents the sensitivity or policy parameter for data stream filtering.

[0234] To ensure system security, the system initiates alarms, log recording, and automatic response security measures. The calculation formula for the security mechanism is as follows:

[0235] P defense (t)=h(T threat (t), E block (t), F block (t), γ)

[0236] Among them, P defense (t) represents the comprehensive protection mechanism activated at time t; T threat (t) represents the potential threat identification result; E block (t) refers to measures to block unauthorized devices; F block (t) represents the measures to prevent the propagation of abnormal data streams; γ represents the parameters of the protection strategy.

[0237] The system monitors data stream status in real time through anomaly detection and threat identification models. Upon detecting a potential security threat, it immediately takes protective measures. Once a potential threat is discovered, the system identifies unauthorized devices using device identifiers and authorization verification mechanisms and immediately blocks these devices. The system prevents the propagation of abnormal data streams through access control, traffic restrictions, and packet filtering. The system dynamically adjusts its protection strategies based on real-time data stream status, identified potential threats, and the output of intelligent analysis models. After system startup, it strengthens protection measures through alarms, logging, and automatic response mechanisms. Alarms promptly notify administrators or security personnel for further analysis, and logging provides evidence for post-incident analysis and tracing.

[0238] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the big data security protection and information analysis system and method in the Internet of Things environment as described above.

[0239] This embodiment also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the big data security protection and information analysis system and method in the Internet of Things environment as described above.

[0240] Choose appropriate encryption algorithms based on different transmission environments and security requirements; process data in layers according to data sensitivity; customize based on existing security protocols; and add additional authentication mechanisms or key exchange strategies.

[0241] During system operation, appropriate encryption strategies are dynamically selected based on data type, transmission channel, and access requirements, and a multi-level verification mechanism is introduced during the encryption process.

[0242] Blockchain technology stores data in a decentralized manner and uses smart contracts to automatically manage data storage, access permissions, and data processing. Distributed file systems can distribute data across multiple nodes and ensure data fault tolerance through replication or redundancy mechanisms.

[0243] Machine learning algorithms are used to learn from the historical behavior data of the equipment to identify normal behavior patterns. Deep learning algorithms are used to analyze the equipment's operating data in real time to predict potential equipment failures or security threats. The intelligent analysis capability dynamically adjusts the monitoring strategy according to changes in equipment, environment and business needs.

[0244] Introducing artificial intelligence can enable comprehensive analysis of data from multiple data sources, identifying the correlations behind device behavior.

[0245] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.

[0246] Those skilled in the art will understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.

[0247] The above embodiments of the present invention are not intended to limit the scope of protection of the present invention. The implementation of the present invention is not limited thereto. All other modifications, substitutions or alterations made to the above structure of the present invention based on the above content of the present invention, in accordance with ordinary technical knowledge and common practice in the field, without departing from the basic technical idea of ​​the present invention, shall fall within the scope of protection of the present invention.

Claims

1. A big data security protection and information analysis system in an Internet of Things (IoT) environment, characterized in that, Including: The data acquisition module is used to collect various types of data generated by IoT devices and send the data to the data storage module through a secure transmission protocol; The data encryption module is used to encrypt the collected raw data. It adopts a hybrid strategy of symmetric and asymmetric encryption, and uses symmetric encryption algorithm on small data blocks and asymmetric encryption algorithm on large data blocks. The data storage module is used to store encrypted data using a distributed storage architecture. Different levels of encryption strategies are used to store data with different sensitivities. Highly sensitive data is stored using advanced encryption, while low-sensitivity data is stored in storage nodes with lower security levels. The security verification module is used to authenticate the identity of each device connected to the IoT system, ensuring that only authorized devices can access the system for data collection, transmission and storage. It uses multi-factor authentication technology, combined with the physical characteristics of the device, to verify identity. The real-time monitoring module is used to monitor the status of IoT devices in real time, detect and identify abnormal device behavior, and respond promptly.

2. A method for big data security protection and information analysis in an Internet of Things (IoT) environment, characterized in that, Includes the following steps: Various types of data are collected through IoT devices, including monitoring data from environmental sensors, equipment operating status, and user behavior. The collected data is transmitted to the data storage module through an encrypted transmission protocol. The original data being transmitted is encrypted. The data encryption process uses a hybrid encryption technique, employing a symmetric encryption algorithm for small data blocks and an asymmetric encryption algorithm for large data blocks. The collected data is stored in a tiered manner according to its sensitivity. Highly sensitive data is stored using strong encryption, while ordinary data is stored in storage nodes with a relatively low security level. During the data reading and writing process, the system authenticates the device identity, uses a multi-factor authentication scheme to verify the legitimacy of the device, enhances security by combining the physical characteristics of the device with dynamic password generation technology, and dynamically adjusts access permissions based on the device behavior. Homomorphic encryption and data anonymization technologies are used in the data storage and analysis process; The system monitors the status of data streams in real time, identifies abnormal behavior and potential security threats, and dynamically adjusts data processing strategies in conjunction with intelligent analysis technology. When a potential security threat is detected, the system will automatically activate security protection mechanisms to block unauthorized devices and prevent the spread of abnormal data streams.

3. The method for big data security protection and information analysis in the Internet of Things environment according to claim 2, characterized in that, Various types of data are collected through IoT devices, including monitoring data from environmental sensors, device operating status, and user behavior. The collected data is transmitted to the data storage module via an encrypted transmission protocol as follows: IoT devices monitor environmental data in real time through built-in temperature, humidity, gas concentration, and light intensity sensors. They also collect data on temperature, vibration, current, device operating status, user operation commands, and device interaction behavior. The data is collected through sensor interfaces and formatted into a unified data stream. For environments with large data volumes and high real-time requirements, symmetric encryption is used to encrypt the collected data. For data with high security requirements, asymmetric encryption is used for key exchange and encryption. Data is transmitted using encrypted transmission protocols. For low-bandwidth, low-latency transmission between IoT devices, the MQTT protocol is used, and TLS encryption is used to ensure the security of data transmission. After the data arrives at the storage module, the receiving end decrypts the encrypted data using the corresponding key to recover the original data.

4. The method for big data security protection and information analysis in the Internet of Things environment according to claim 3, characterized in that, The original data being transmitted is encrypted using a hybrid encryption technique: a symmetric encryption algorithm is used for small data blocks, while an asymmetric encryption algorithm is used for large data blocks. The method is as follows: For small-scale data, use symmetric encryption algorithms for encryption; for larger data blocks, use asymmetric encryption algorithms for encryption. Specific encryption process: Generate a random symmetric key for encrypting small blocks of data. The size of the symmetric key can be 128 bits, 192 bits, or 256 bits. Small data blocks are separated and encrypted using the generated symmetric key. The encrypted data will be transmitted in ciphertext form. The processing of large data blocks involves encrypting the symmetric key itself, using an asymmetric encryption algorithm to encrypt the generated symmetric key, and then transmitting the asymmetric encrypted symmetric key along with the encrypted data. During transmission, the encrypted small data blocks and the encrypted symmetric key are transmitted together to the receiver; Recipient's decryption process: The receiver uses its private key to decrypt the encrypted symmetric key and recover the original symmetric key. The recovered symmetric key is then used to decrypt the encrypted small data block to obtain the original data content.

5. The method for big data security protection and information analysis in an Internet of Things environment according to claim 4, characterized in that, The collected data is stored in a tiered manner based on its sensitivity. Highly sensitive data is stored using strong encryption, while ordinary data is stored in storage nodes with relatively lower security levels. The collected data is classified into highly sensitive data and ordinary data based on sensitivity. Highly sensitive data is protected with strong encryption, and more secure storage methods and stricter access control policies are adopted. Ordinary data should be encrypted with low strength or not encrypted at all, and a normal storage strategy should be adopted. Data storage architecture design: Multi-tiered storage architecture: providing different storage nodes for sensitive data at different levels; High-sensitivity data storage layer: Storage nodes designed for highly sensitive data, employing strong encryption algorithms and strict access control mechanisms; Ordinary data storage layer: Nodes used for storing ordinary data, employing relatively low security measures; Highly sensitive data is encrypted and stored using a symmetric encryption algorithm. For database storage, transparent data encryption is used, while for ordinary data, lower-strength encryption is used. During the data collection and processing process, the sensitivity of the data is assessed regularly, and dynamic hierarchical storage is carried out based on the actual content and application scenarios of the data.

6. The method for big data security protection and information analysis in an Internet of Things environment according to claim 5, characterized in that, During data reading and writing, the system authenticates the device identity, employs a multi-factor authentication scheme to verify the device's legitimacy, enhances security by combining the device's physical characteristics with dynamic password generation technology, and dynamically adjusts access permissions based on device behavior. The mathematical formula for setting device authentication is as follows: Device authentication functions: I device =f(P device ,F device ,T password ) Among them, P device For the physical characteristics of the equipment, F device For the device's biometrics or hardware characteristics; T password A temporary password obtained through dynamic password generation technology; Dynamic cryptography is based on time and a pre-shared key. The generated temporary password changes periodically, and its calculation formula is expressed as: T password =H(K device ,T current ) Where H is the cryptographic hash function; K device A key shared between the device and the server; T current This is the current timestamp or counter; The device behavior analysis section dynamically adjusts access permissions based on the device's behavioral characteristics during the access process. The formula for behavior characteristic analysis is defined as follows: Among them, B device (t) represents the analysis result of the device's behavior at time point t, A i (t) represents the i-th action performed by the device at time t; f i For behavioral analysis functions; Based on the device's authentication status and behavior analysis results, access permissions are dynamically adjusted using the following function: A device (t)=g(I device ,B device (t)) Among them, A device (t) represents the access permissions of the device at time t; I device For the device's authentication result; B device (t) represents the behavioral analysis results of the device.

7. The method for big data security protection and information analysis in an Internet of Things environment according to claim 6, characterized in that, In the process of data storage and analysis, the methods of using homomorphic encryption and data anonymization techniques are as follows: Suppose that data x is encrypted to obtain ciphertext E(x), and the encryption operation is as follows: E(x) = Encrypt(x) Where E(x) is the encrypted data, x is the original data, and Encrypt is the encryption operation; Given two encrypted data sets E(x1) and E(x2), homomorphic encryption directly performs addition operations on the encrypted data: in, This represents a homomorphic addition operation; Given two encrypted data sets E(x1) and E(x2), homomorphic encryption performs multiplication on the encrypted data: in, This represents a homomorphic multiplication operation; Finally, the result is obtained through decryption: D(E(x))=x Where D is the decryption operation, E(x) is the encrypted data, and x is the decrypted plaintext data; Data anonymization ensures privacy by replacing, deleting, or modifying sensitive data, specifically by anonymizing personal information within sensitive data. Mask(x) = Replace(x) Where x is the original data, and Mask(x) is the data after anonymization. Pseudo-anonymization replaces personal information with pseudonyms, thus decoupling it from a specific individual. Let's say a user's name x is replaced with the pseudonym p: Pseudonymize(x) = p Where p is a pseudonym, which does not directly reveal personal identity information, but can be restored to the original data under certain circumstances; Data anonymization is achieved by aggregating personal data into statistical data within a certain range. This involves establishing a set of user age data x1, x2, ..., x... n The statistical information of these data is calculated and then anonymized: Where Aggregate represents the aggregation operation, x1, x2, ..., x n Given a set of data, the result is the mean of the data. After data anonymization, the stored data x′ no longer contains personally identifiable information, reducing the risk of privacy leaks. Store(x′)where x′=Anonymous(x) Where x′ represents the anonymized data, and Anonymous(x) represents the anonymization process of the data.

8. The method for big data security protection and information analysis in an Internet of Things environment according to claim 7, characterized in that, The method for dynamically adjusting data processing strategies by real-time monitoring of data stream status, identification of abnormal behavior and potential security threats, and combination of intelligent analysis technology is as follows: Real-time monitoring of the data stream's status uses a time series to represent changes in the data stream, defining a data stream status function: S flow (t)=f(D(t),H(t)) Among them, S flow (t) represents the data stream state at time t; D(t) represents the data stream content or input data at time t; H(t) represents historical data or previous state information at time t. Anomaly detection involves monitoring the data stream and combining it with intelligent analysis techniques to identify whether anomalies exist. An anomaly detection function is defined as follows: A detect (t)=Detect(S flow (t),θ) Among them, A detect (t) represents the anomaly flag detected at time t, where 1 indicates an anomaly and 0 indicates normal; Detect is the anomaly detection algorithm; θ is the anomaly threshold. Potential security threat identification is based on anomaly detection results, further combined with known security threat models. The calculation formula is as follows: T threat (t)=g(A detect (t),P threat ) Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the result of the anomaly detection; P threat It is a predictive model or threat database for security threats, containing known threat patterns and attack characteristics; Intelligent analytics technology is used to analyze data stream trends, identify patterns, and predict future changes. A model-based intelligent analytics algorithm is established, and the model is represented as follows: M analysis (D(t),H(t))=Analyze(D(t),H(t),W) Among them, M analysis (D(t), H(t)) represents the analysis results of the intelligent analysis model on the data stream state; W represents the parameters of the intelligent analysis model; Analyze represents the processing performed through intelligent analysis technology; Based on the results of real-time monitoring, anomaly detection, and potential threat identification, the system dynamically adjusts its data processing strategy. The function representing the adjustment strategy is as follows: P adjust (t)=h(T threat (t),M analysis (D(t),H(t)),α) Among them, P adjust (t) represents the data processing strategy adjusted at time t; T threat (t) represents the identification result of potential security threats; M analysis (D(t),H(t)) represents the output of the intelligent analysis; α represents the sensitivity coefficient of the adjustment strategy.

9. The method for big data security protection and information analysis in an Internet of Things environment according to claim 8, characterized in that, When a potential security threat is detected, the system will automatically activate security protection mechanisms to block unauthorized devices and prevent the propagation of abnormal data streams. The system will detect potential security threats and establish an anomaly detection method A. detect (t) Identify anomalous behavior, or through threat identification model T threat (t) Identifying potential security threats, the detection process is represented as follows: T threat (t)=g(A detect (t),P threat ) Among them, T threat (t) represents the potential security threat identified at time t; A detect (t) represents the anomaly detection result; P threat For threat identification models; Once a security threat is detected, the system immediately blocks unauthorized devices. Device identification is performed using device identifiers and authorization verification mechanisms. The formula for blocking unauthorized devices is as follows: E block (t)=Block(D unauthorized (t),α) Among them, E block (t) represents the device blocking mechanism activated at time t; D unauthorized (t) represents the list of unauthorized devices, determined by the device identifier; α represents the blocking strength or policy parameter. The system will prevent the further propagation of abnormal data streams. The propagation of data streams is restricted through access control, traffic limiting, and packet filtering. The formula for preventing the propagation of abnormal data streams is as follows: F block (t)=Filter(S flow (t),T threat (t),β) Among them, F block (t) represents the data stream blocking or filtering mechanism initiated at time t; S flow (t) represents the real-time data stream status; T threat (t) represents the identified potential security threats; β represents the sensitivity or policy parameter for data stream filtering. To ensure system security, the system initiates alarms, log recording, and automatic response security measures. The calculation formula for the security mechanism is as follows: P defense (t)=h(T threat (t),E block (t),F block (t),γ) Among them, P defense (t) represents the comprehensive protection mechanism activated at time t; T threat (t) represents the potential threat identification result; E block (t) refers to measures to block unauthorized devices; F block (t) represents the measures to prevent the propagation of abnormal data streams; γ represents the parameters of the protection strategy.

10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the big data security protection and information analysis method in the Internet of Things environment as described in any one of claims 2-9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the big data security protection and information analysis method in the Internet of Things environment as described in any one of claims 2-9.

Citation Information

Patent Citations

  • Privacy computing security system based on domestic cryptographic algorithm

    CN119128944A

  • Internet of Things service management system based on regional digital economy

    CN119519928A

  • Distributed data security protection system based on Internet of Things nodes

    CN119766556A

  • Interface joint debugging analysis method and system for data privacy security

    CN120277691A

  • Intelligent valve actuator remote monitoring and fault early warning system based on Internet of Things

    CN120386261A

Cited By

  • Local data acquisition system and method based on handheld terminal

    CN121619576A