Data security transmission method based on digital archive multi-protection

By employing two-way authentication between quantum key distribution devices and archive transmission terminals, and iterative block partitioning using Logistic chaotic mapping, combined with the lightweight SM4 algorithm and dynamic risk scoring of hidden Markov models, a multi-protection data security transmission method was constructed. This method solves the problems of traditional encryption algorithms being easily cracked by quantum mechanics and single-point failures in centralized disaster recovery architectures, achieving efficient and real-time data security transmission and disaster recovery.

CN120880802AActive Publication Date: 2025-10-31JIANGXI SHENSHUO ELECTRIC CO LTD

Patent Information

Application Number
CN202511386047.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-10-31
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

In existing technologies, traditional encryption algorithms such as AES are easily cracked by the quantum Shor algorithm, the key update frequency is out of sync with network risks, centralized disaster recovery architectures have single point of failure risks and cannot respond to dynamic network threats in real time, and traditional zero-trust architectures have high computational overhead and are difficult to achieve millisecond-level real-time gateway decisions.

Method used

The system employs two-way authentication between quantum key distribution devices and archive transmission terminals. It uses real-time generation of random seeds based on quantum states combined with Logistic chaotic mapping for iterative block division, outputting variable-length key fragments. It uses the lightweight SM4 algorithm for encryption, collects biometric and network data in real time, calculates risk scores through a hidden Markov model, dynamically adjusts the key update frequency, and switches to a three-layer architecture consisting of local encrypted storage, a local backup center, and a remote key hosting center. It also uses zero-knowledge proofs to verify the authenticity of the data.

Benefits of technology

It achieves dual protection of physical randomness in the quantum entropy source layer and algorithmic complexity in the chaotic encryption layer, dynamically adjusts the key update frequency, improves the security and efficiency of high-level archives transmission in harsh network environments, improves the APT attack identification rate through biological behavior spatiotemporal modeling, and dynamically decays the blockchain node threshold, shortens the disaster recovery switching delay, and improves the data logic consistency recovery success rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880802A_ABST
    Figure CN120880802A_ABST
Patent Text Reader

Abstract

The invention discloses a digital archive multi-protection-based data security transmission method, and relates to the field of data security transmission, and the method comprises the steps: generating a random seed in real time based on a quantum state, carrying out the iterative blocking of the quantum seed through combining with Logistic chaotic mapping, outputting variable-length secret key fragmentation, carrying out the symmetric encryption of archive data through employing a lightweight SM4 algorithm, and carrying out the encryption of the archive data. Obtaining encrypted data of the fragments; a behavior anomaly probability is calculated through a hidden Markov model, a risk score is calculated through a safety interval, and when a score value exceeds a safety threshold value, a grading response is triggered; key fragments are generated by adopting n nodes, at least k fragments can reconstruct signatures to monitor the node state of the block chain, and when the node anomaly rate exceeds a node threshold value, a three-layer architecture is automatically switched. The method has the advantages that an active multi-protection system is constructed through a quantum dynamic key, risk-driven hierarchical response and block chain disaster recovery switching, and quantum attack resistance and dynamic adaptation to transmission of network risks are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure data transmission, and more specifically to a secure data transmission method based on multiple layers of protection for digital archives. Background Technology

[0002] Secure transmission of digital archives refers to a technological system that utilizes cryptography, network protocols, and distributed storage technologies to ensure data confidentiality, integrity, and availability during the digitization process. With technological advancements, quantum key distribution (QKD) has emerged to enhance key security, blockchain technology is used for distributed node verification, and homomorphic encryption supports ciphertext computation. However, existing technologies, such as AES, are vulnerable to being cracked by the quantum Shor algorithm due to their periodicity of key updates. NIST predicts that by 2029, quantum computers will be able to crack 2048-bit RSA keys. Furthermore, the key update frequency is out of sync with network risk conditions, and the failure to increase the rotation frequency in adverse network environments increases the risk of exposing highly classified archives. Simultaneously, pseudo-random number generators (PRNGs) rely on algorithmic entropy sources and cannot resist quantum brute-force attacks, creating a key security crisis under the threat of quantum computing. Meanwhile, traditional blockchains with fixed fault tolerance thresholds (such as 1 / 3 node fault tolerance) cannot dynamically respond to the decay of node trust, leading to an increase in the duration of malicious nodes' continued malicious activities. Centralized disaster recovery centers require manual intervention for switching, with a recovery time of over 30 minutes, which cannot meet the real-time requirements of scenarios such as finance. Off-site data verification relies on traditional hash trees, and Merkle tree verification latency in a thousand-node network can reach as high as 500ms, and it cannot prove that the data has not been leaked, thus posing a certain systemic risk to centralized disaster recovery architectures. In addition, risk factors such as network attacks, device vulnerabilities, and abnormal behavior are handled independently without the construction of a multi-dimensional dynamic scoring model, resulting in long ransomware response delays. Zero-trust architectures rely on continuous certificate verification, but traditional zero-knowledge proofs (ZKP) have high computational overhead (single proof time > 100ms), making it difficult to achieve millisecond-level real-time gateway decisions. Summary of the Invention

[0003] To address the aforementioned technical issues, this paper provides a data security transmission method based on multiple protections of digital archives. This technical solution solves the problems mentioned in the background technology, such as the vulnerability of static key mechanisms to quantum attacks, the risk of single point of failure in centralized disaster recovery architecture, and the inability of passive defense models to respond to dynamic network threats in real time.

[0004] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A data security transmission method based on multiple layers of protection for digital archives includes: Perform two-way authentication between the quantum key distribution device and the file transfer terminal, generate a random seed in real time based on the quantum state, perform iterative partitioning on the quantum seed by combining the Logistic chaotic mapping, perform non-linear transformation according to the chaotic trajectory value, and output variable-length key shards, denoted as the dynamic session key. Use the lightweight SM4 algorithm to perform symmetric encryption on the file data to obtain the encrypted sharded data. The key update frequency is dynamically adjusted by the monitored real-time transmission index value. Here, SM4 refers to the lightweight symmetric encryption algorithm released by the State Cryptography Administration and is used to encrypt the file data; Collect the biometric characteristics, operation behavior trajectory, and network environment data of the user device in real time. Calculate the behavior anomaly probability through the hidden Markov model, calculate the risk score through the safety margin. When the score value exceeds the safety threshold, trigger a hierarchical response. The risk score is determined as the weighted sum of the device vulnerability score, the HMM behavior anomaly probability, and the network attack intensity index. The safety threshold is preset through historical security event data; After the encrypted sharded data, use n nodes to generate key shards. At least k shards can be used to reconstruct the signature to monitor the blockchain node status. When the node anomaly rate exceeds the node threshold, automatically switch to the three-layer architecture of local encrypted storage,同城备份中心 (same-city backup center), and off-site key escrow center. Here, k is the minimum number of nodes required for signing in the blockchain network, and k < n, and n is the total number of nodes in the blockchain network. The node threshold is derived based on the Byzantine fault tolerance theory and calculated in combination with the node credibility decay model; Use a filter to quickly verify the integrity of the data block, combine zero-knowledge proof to verify the data authenticity. The verification result is fed back to the dynamic trust evaluation model in real time to update the risk score and generate an audit trail. Achieve the chronological-causal traceability of operation behaviors through blockchain evidence storage, and enable the zero-trust gateway step for cross-domain transmission scenarios.

[0005] Preferably, the process of generating a random seed in real time based on the quantum state, performing iterative partitioning on the quantum seed by combining the Logistic chaotic mapping, and performing non-linear transformation according to the chaotic trajectory value to output variable-length key shards specifically includes: Perform two-way authentication between the quantum key distribution device and the file transfer terminal through the hardware encryption interface to generate a quantum entropy source sequence; Adopt the Logistic chaotic mapping formula , perform iterative partitioning on the quantum seed, where the initial value x0 is taken from the quantum entropy source; Perform non-linear compression on each data block according to the chaotic trajectory value, and the compression rate dynamically matches the file data type to output variable-length key shards; Combine the key shards to generate a session key, and the key length is in a geometric relationship with the file shard size.

[0006] Preferably, the step of using the lightweight SM4 algorithm to perform symmetric encryption on the archive data to obtain fragmented encrypted data specifically includes: Real-time data collection of network data transmission latency, effective network data transmission rate, and real-time workload of blockchain nodes; calculation of comprehensive index value based on historical weighting coefficients of network data transmission latency, effective network data transmission rate, and real-time workload of blockchain nodes. Obtain the normal distribution of historical risk scores, calculate the 90th percentile as the security threshold, and trigger the key update mechanism when the index value exceeds the security threshold; The quantum key distribution device is invoked to generate a new quantum random seed, the iterative calculation process of the Logistic chaotic map is rerun, a new session key is generated, the newly generated key is injected into the SM4 algorithm through a hardware encryption channel, and the sharding key of the blockchain node is updated synchronously. The key update interval is inversely correlated with the comprehensive index value. The worse the network transmission status, the higher the key replacement frequency. The update cycle is dynamically scaled according to the security level coefficient of the file. High-secret files trigger more frequent key rotation in a bad network environment.

[0007] Preferably, the step of calculating the probability of abnormal behavior using a hidden Markov model, calculating a risk score using a safety distance, and triggering a graded response when the score exceeds a safety threshold specifically includes: Based on abnormal behavior samples, network attack feature data, and node failure records from historical security incidents, a temporal convolutional neural network is used to optimize the anomaly detection boundary and construct a dynamic trust assessment model. Real-time collected user biometrics, operation behavior trajectories, network environment data, and blockchain node status data are input into the dynamic trust assessment model. The probability of abnormal behavior is calculated through a hidden Markov model. Combined with device vulnerability scores and network attack intensity indices, a comprehensive risk score is calculated according to a weighted formula, and graded response measures are initiated. The probability of abnormal behavior output by the hidden Markov model is used as one of the input weights of the risk score. When the risk score exceeds the security threshold, a Level 1 response is triggered, temporarily freezing the current session, forcibly initiating secondary biometric authentication, and generating a new session key through the quantum key distribution device; Based on the second-level response triggering formula Calculate the second threshold. When the risk score exceeds the second threshold, a secondary response is triggered: the encrypted transmission channel is switched to a pre-set redundant link, incomplete encrypted data packets are discarded, and the minimum number of nodes required for signing is dynamically reduced from k to k-1, taking effect only while the redundant link is enabled. Here, T2 is the second threshold, T1 is the security threshold, α is the blockchain node anomaly rate weight, and J... d S represents the node anomaly rate, β represents the biometric anomaly probability weight, and S... w This represents the probability of an anomaly in biological characteristics. Obtain the risk score increase coefficient, calculate the difference between 1 and the risk score increase coefficient, construct a dynamic node threshold adjustment mechanism by multiplying the difference by the base threshold, and update the dynamic node threshold in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism, so that when the risk score continues to rise, the node threshold decreases according to the linear decay model. When the node anomaly rate exceeds the dynamic node threshold, a level 3 response is triggered, stopping the blockchain shard storage, switching the encrypted data stream to local encrypted storage, synchronously starting the data mirroring of the same-city backup center, and verifying data integrity through the zero-knowledge proof gateway of the off-site key escrow center.

[0008] Preferably, the calculation of the abnormal behavior probability using a hidden Markov model specifically includes: The biometric sampling timestamps and operation behavior trajectories are aligned with millisecond-level precision to construct a time synchronization matrix. The operation behavior trajectory includes mouse movement coordinate sequences and keyboard key press intervals. The system obtains the current biometric confidence level and operation trajectory anomaly level, extracts the spatial pattern of biometrics and the spatiotemporal features of operation trajectory based on convolutional neural network, and calculates the dynamic correlation coefficient between the two within the risk-sensitive operation window. The spatial pattern of biometrics is the fingerprint texture direction gradient, and the spatiotemporal features of operation trajectory are the mouse acceleration change curve. Historical attack characteristics are obtained and a preset fusion threshold is set for dynamic environment calibration. When the dynamic correlation coefficient is less than the fusion threshold, it is judged as a high-risk abnormal behavior, triggering the weighted abnormal state transition probability of the Hidden Markov Model.

[0009] Preferably, the initiation of the graded response measures specifically includes: When a Level 1 response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biometric authentication. When a secondary response is triggered, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the timestamp is switched through the blockchain evidence record. When a Level 3 response is triggered, the abnormal device is isolated and an audit trail is generated. The operational behavior data is encoded into a Merkle tree structure and stored in a remote key escrow center for time-series and causal tracing.

[0010] Preferably, the automatic switch to a three-tier architecture of local encrypted storage, same-city backup center, and off-site key hosting center when the node anomaly rate exceeds the node threshold specifically includes: Based on Byzantine fault tolerance theory, the response latency, data consistency deviation, and historical reliability decay coefficient of blockchain nodes are monitored in real time. Calculate the dynamic node anomaly rate, where T delay T represents the node response latency.max D is the maximum allowable delay threshold. inconsist D represents the number of bytes differing between node data and the main chain. threshold C is the difference tolerance threshold. trust Let α be the credibility decay coefficient based on historical behavior, and let α, β and γ be weighting coefficients that satisfy α+β+γ=1; When J d >J threshold Triggering a three-level response, where J threshold The real-time threshold output by the dynamic node threshold adjustment mechanism is used, and the switching instruction is jointly signed by at least k-1 trusted nodes, where k is the initial reconstruction threshold. The encrypted data that has not been fully transmitted is temporarily stored in fragments on a local solid-state storage device encrypted with the national cryptographic algorithm to form a local encrypted storage layer and generate a temporary access token. Data mirroring is synchronized through a dedicated fiber optic channel, the transmission channel is encrypted using SM4-GCM mode, and the Merkle root hash of data blocks is recorded to the local blockchain, forming a local backup center layer. The key fragments are encrypted using quantum key distribution and transmitted to a remote center. The hosting center verifies the data integrity based on zero-knowledge proof. After successful verification, a timestamp signature certificate is returned, thus constructing a remote key hosting center layer. When the node anomaly rate exceeds the threshold and the signature verification of k-1 trusted nodes passes, a level 3 response is triggered. When the node anomaly rate drops to the security threshold, data is restored in the order of priority: same-city backup center > off-site key hosting center > local encrypted storage. During the restoration process, the timing consistency of the data is verified by the Merkle tree structure audit trail.

[0011] Preferably, the step of verifying the authenticity of data using zero-knowledge proofs and feeding the verification results back to the dynamic trust assessment model in real time specifically includes: The zero-knowledge proof gateway is enabled only during cross-domain transfers. A non-interactive zero-knowledge proof is generated for each data fragment. This non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies... , where π i To prove the credentials, com(μ) is the commitment value of the Logistic chaos parameter μ; A GPU-accelerated parallel proof verification architecture is used to simultaneously verify data fragment proofs received by the same-city backup center and the off-site key escrow center. Verification results The credibility index is aggregated according to the weight wi of the fragment location. When the credibility index is lower than the historical actual operating threshold, the weight adjustment of the dynamic trust assessment model is triggered.

[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention proposes a data security transmission method based on multiple layers of protection for digital archives. A sub-key distribution device generates a true random entropy source sequence through a hardware encryption interface, forming a quantum entropy source layer. Then, based on a Logistic mapping, the quantum seed is iteratively divided into blocks, and nonlinear transformations are dynamically controlled by trajectory values ​​to output variable-length key fragments, constructing a chaotic encryption layer. The key update cycle is driven by real-time calculation of the network transmission index value, realizing a dynamic adjustment layer. This allows the quantum entropy source layer, chaotic encryption layer, and dynamic adjustment layer to work together, achieving dual protection of physical randomness and algorithmic complexity. The quantum entropy source resists brute-force attacks, and the chaotic fragments dynamically match data types. The key update frequency is linked to network risks in real time, improving the rotation speed of high-security archives in weak network environments while balancing security strength and transmission efficiency. This invention proposes a data security transmission method based on multi-layered protection of digital archives. It constructs a spatiotemporal feature matrix by aligning biometric features (fingerprint directional gradient) with operation trajectories (mouse acceleration curve) at millisecond levels, forming a multi-factor perception layer. A CNN-HMM model is used to calculate the probability of abnormal behavior, and device vulnerabilities and network attacks are integrated to output a risk score, forming a dynamic scoring layer. Finally, a three-level response is triggered based on the score, driving the linear decay of blockchain node thresholds and switching to a local-same-city-remote disaster recovery architecture, thus constructing a collaborative response layer. This creates a closed loop of risk perception, decision-making, and execution. The spatiotemporal modeling of biometric behavior improves the APT attack identification rate, the risk score drives the dynamic decay of blockchain node thresholds, disaster recovery switching latency is compressed, and zero-knowledge proofs collaborate with the disaster recovery architecture to ensure the logical consistency of data across different locations, improving the recovery success rate. Attached Figure Description

[0013] Figure 1 This is a schematic diagram of the process of the present invention; Figure 2 This is a schematic diagram of the process in this invention to generate random seeds in real time based on quantum states, iteratively divide the quantum seeds into blocks using Logistic chaotic mapping, perform nonlinear transformations according to chaotic trajectory values, and output variable-length key fragments. Figure 3 This is a schematic diagram illustrating the process of using the lightweight SM4 algorithm to perform symmetric encryption on archive data to obtain fragmented encrypted data in this invention. Figure 4 This is a schematic diagram of the process in this invention that calculates the probability of abnormal behavior using a hidden Markov model, calculates a risk score using a safety distance, and triggers a graded response when the score exceeds a safety threshold. Figure 5 This is a schematic diagram of the process for calculating the probability of abnormal behavior using a hidden Markov model in this invention. Figure 6 This is a schematic diagram of the process for initiating graded response measures in this invention; Figure 7 This is a schematic flowchart of the process for automatically switching to a three - layer architecture of local encrypted storage,同城 backup center, and off - site key escrow center when the node exception rate exceeds the node threshold in the present invention; Figure 8 This is a schematic flowchart of the process for verifying the authenticity of data by combining zero - knowledge proof in the present invention, and the verification result is fed back to the dynamic trust evaluation model in real time. Detailed implementation manners

[0014] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.

[0015] Refer to Figure 1 As shown, a data - secure transmission method based on multiple protections of digital archives includes: Perform two - way authentication between the quantum key distribution device and the archive transmission terminal, generate random seeds in real time based on quantum states, perform iterative partitioning on the quantum seeds by combining Logistic chaotic mapping, perform non - linear transformation according to the chaotic trajectory values, output variable - length key fragments, denoted as dynamic session keys, symmetrically encrypt the archive data using the lightweight SM4 algorithm to obtain fragmented encrypted data, and the key update frequency is dynamically adjusted by the monitored real - time transmission index value; Collect biometric characteristics, operation behavior trajectories, and network environment data of user devices in real time, calculate the behavior anomaly probability through the hidden Markov model, calculate the risk score through the safety margin. When the score value exceeds the safety threshold, trigger a hierarchical response. The risk score is determined as the weighted sum of the device vulnerability score, the HMM behavior anomaly probability, and the network attack intensity index, and the safety threshold is preset through historical security event data; After the fragmented encrypted data, generate key fragments by n nodes, and at least k fragments can reconstruct the signature to monitor the status of blockchain nodes. When the node exception rate exceeds the node threshold, automatically switch to a three - layer architecture of local encrypted storage,同城 backup center, and off - site key escrow center, where k < n, and the node threshold is derived based on the Byzantine fault - tolerance theory and calculated in combination with the node credibility decay model; Use a filter to quickly verify the integrity of data blocks, combine zero - knowledge proof to verify the authenticity of data, feed back the verification result to the dynamic trust evaluation model in real time, update the risk score and generate an audit trail, and achieve time - sequence - causal traceability of operation behaviors through blockchain evidence storage. Enable the zero - trust gateway step for cross - domain transmission scenarios.

[0016] Adopt the Logistic chaotic mapping formula Note: “同城” in the original text should be replaced with the appropriate English expression according to the actual context, such as “same - city” or other more accurate terms. Here it is temporarily left as “同城” for translation., iteratively partition the quantum seeds, and then non-linearly compress the data blocks according to the chaotic trajectory values (the compression ratio dynamically matches the archive data type), output variable-length key shards, and thus combine the shards to generate a dynamic session key. The key length is proportionally related to the archive shard size (e.g., 1 MB of data corresponds to a 128-bit key), forming a quantum dynamic key generation system. Generate random seeds in real time through a quantum entropy source, and combine the non-linear transformation of the Logistic chaotic mapping to solve the periodic vulnerability of the pseudo-random number generator (such as AES-CTR), expand the key space, and resist quantum brute force attacks. At the same time, the dynamic session key adjusts the update frequency according to the transmission index value (a comprehensive calculation of network latency / load), so that the key rotation frequency of high-class archives is increased under poor network conditions.

[0017] Deploy biometric sensors (fingerprint / iris), operation behavior capture modules (mouse trajectory / keystroke interval), and network probes again. Real-time collect multi-dimensional data, and then align the biometric features and the operation trajectory timestamps (millisecond level) to construct a spatio-temporal feature matrix (such as the mouse acceleration curve). When the dynamic correlation coefficient is lower than the preset fusion threshold, trigger the weighted abnormal state transition probability of the HMM and perform risk scoring synchronously. , and at the same time, the weights α + β + γ = 1, then hierarchical response triggering can be carried out. When R > T1, freeze the session, force secondary biometric authentication, and update the quantum key; when R > T2, switch to the redundant link, and reduce the number of blockchain signature nodes to k−1, where k is the initial reconstruction threshold, and k - 1 means temporarily reducing the minimum number of nodes required for signature by one during the secondary response period, forming a dynamic risk assessment and hierarchical response.

[0018] Construct a blockchain network with n nodes, preset the Byzantine fault tolerance threshold k (k < n), then calculate the node abnormality rate, and autonomously switch to a three-layer architecture according to the calculated node abnormality rate. Enable the zero-knowledge proof gateway during cross-domain transmission to generate a proof π for the data shards. <L i , and feedback the verification result to the dynamic trust assessment model to correct the weights. Let the MM model fuse the spatio-temporal correlation of biometric features and operation behaviors, reducing the false positive rate of anomaly detection. At the same time, based on the dynamically derived node threshold J of Byzantine fault tolerance threshold , combined with the credibility decay model, shorten the node failure switching delay and improve the disaster tolerance efficiency compared with the traditional fixed threshold. At the same time, the collaborative verification of zero-knowledge proof and filters improves the throughput of data authenticity verification. The "never trust, always verify" of the zero-trust gateway for forced cross-domain transmission, combined with blockchain evidence storage to achieve full-link traceability of operation behaviors, also improves the speed of generating audit traces. [[ID=S13]]

[0019] Refer to Figure 2As shown, the process of generating random seeds in real time based on quantum states, iteratively dividing the quantum seeds into blocks using Logistic chaotic mapping, performing nonlinear transformations according to chaotic trajectory values, and outputting variable-length key slices specifically includes: The quantum key distribution device and the file transmission terminal are mutually authenticated through a hardware encryption interface, generating a quantum entropy source sequence; Using the Logistic chaotic mapping formula The quantum seed is iteratively divided into blocks, where the initial value x0 is taken from the quantum entropy source; Each data block is nonlinearly compressed based on the chaotic trajectory value, and the compression rate is dynamically matched to the archive data type to output variable-length key fragments; The session key is generated by combining key fragments, and the key length is proportional to the file fragment size.

[0020] A dedicated encrypted interface (such as a PCI-E encryption card or a nationally certified hardware security module) is deployed at the physical layer between the quantum key distribution device and the file transmission terminal. Two-way authentication of the device identity is achieved through quantum digital certificate exchange. After successful authentication, the quantum key distribution device triggers a single-photon emitter to generate a truly random sequence based on quantum polarization states as the initial entropy source. The length of the entropy source dynamically adapts to the terminal hardware performance (typically 1024-4096 bits). A chaotic computing unit is built into the encrypted terminal, loading a Logistic mapping function. The quantum entropy source sequence is input in 32-bit segments. The hash value of the first segment is used as the initial chaotic value. The control parameter μ is dynamically configured according to the file type (e.g., μ=3.99 for data and μ=3.57 for multimedia data). Parallel iterative calculation is implemented through FPGA, and a 64-bit chaotic trajectory value is output in each iteration.

[0021] During use, the chaotic trajectory value is input into the nonlinear transformation module: when the trajectory value xn∈[0,0.3), S-box permutation compression is used, outputting a 128-bit fragment; when xn∈[0.3,0.7), cyclic shift + modular addition is performed, where cyclic shift + modular addition means performing a cyclic left / right shift operation on the chaotic trajectory value, followed by a modulo 2^64 addition operation to enhance the nonlinear transformation strength, outputting a 192-bit fragment; when xn∈[0.7,1], Arnold transformation is performed, outputting a 256-bit fragment. This allows for dynamic matching of the archive data type with the compression ratio (text 1:4, image 1:8, video 1:16), and the entropy detection unit ensures that the entropy value of the output fragment information is ≥7.98. Furthermore, the key fragments are combined proportionally according to the archive fragment size: 1MB fragment corresponds to a 128-bit key; 10MB fragment corresponds to a 192-bit key; and 100MB+ fragment corresponds to a 256-bit key. The combination process incorporates a Hamming code error correction mechanism, using XOR verification to ensure fragment integrity. This allows for the physical unpredictability of key generation through a quantum entropy source, combined with the initial value sensitivity of a Logistic chaotic system to achieve dynamic mutation of key fragments. This ensures the output key passes all 15 randomness checks, expands the key space compared to traditional methods, and increases encryption / decryption throughput, meeting the real-time secure transmission requirements of high-secret documents.

[0022] Reference Figure 3 As shown, the symmetric encryption of the archive data using the lightweight SM4 algorithm to obtain the fragmented encrypted data specifically includes: Real-time data collection of network data transmission latency, effective network data transmission rate, and real-time workload of blockchain nodes; calculation of comprehensive index value based on historical weighting coefficients of network data transmission latency, effective network data transmission rate, and real-time workload of blockchain nodes. Obtain the normal distribution of historical risk scores, calculate the 90th percentile as the security threshold, and trigger the key update mechanism when the index value exceeds the security threshold; The quantum key distribution device is invoked to generate a new quantum random seed, the iterative calculation process of the Logistic chaotic map is rerun, a new session key is generated, the newly generated key is injected into the SM4 algorithm through a hardware encryption channel, and the sharding key of the blockchain node is updated synchronously. The key update interval is inversely correlated with the comprehensive index value. The worse the network transmission status, the higher the key replacement frequency. The update cycle is dynamically scaled according to the security level coefficient of the file. High-secret files trigger more frequent key rotation in a bad network environment.

[0023] Deploy network probes to collect real-time network data transmission latency (end-to-end packet transmission time), effective data transmission rate (amount of data successfully transmitted per unit time), and real-time workload of blockchain nodes (CPU / memory utilization). Establish a historical weight coefficient database (e.g., latency weight α=0.4, rate weight β=0.3, load weight γ=0.3), and calculate the comprehensive index value using a weighted formula. The baseline value is preset based on the historical network state. A new quantum random seed can then be generated by calling the quantum key distribution device and transmitted to the chaotic computing unit via a hardware encryption interface (such as a PCI-E encryption card). The Logistic chaotic mapping iteration is run, and then nonlinear transformations (such as S-box permutation and Arnold transform) are performed based on the chaotic trajectory values. Variable-length key fragments are output and combined to form a new session key. The new key is injected into the SM4 algorithm core through the Hardware Security Module (HSM), simultaneously updating the key fragments of the blockchain nodes.

[0024] This can be achieved by setting an inverse relationship between the key update period T and the comprehensive index value I: Where K is a constant and S is the security level coefficient of the archive (S≥2.0 for high-level archives). The worse the network condition (the larger the I value), the higher the key rotation frequency, and high-level archives trigger more frequent updates under poor network conditions. Thus, by leveraging the initial value sensitivity of the quantum entropy source and the Logistic chaotic mapping, the unpredictability of the key can be guaranteed, overcoming the periodic vulnerability of traditional pseudo-random number generators (such as AES-CTR), expanding the key space, and effectively resisting quantum brute-force attacks. The key update frequency is dynamically bound to network risk, which can improve security compared to static key schemes. At the same time, the comprehensive index value reflects the network load and latency in real time, and adaptive key rotation is achieved through a reverse correlation mechanism: when the transmission latency surges or the node load exceeds the limit, the key update cycle is shortened to the millisecond level, avoiding encryption failure due to network congestion. The security level coefficient S of high-level archives is further amplified to ensure that critical data maintains high-strength protection even in weak network environments. In addition, the lightweight SM4 algorithm combined with the hardware encryption channel increases encryption throughput and reduces computational overhead compared to the traditional TLS protocol. Meanwhile, key sharding and blockchain node status are updated synchronously, which can also avoid the risk of single point of failure in centralized key management.

[0025] Reference Figure 4 As shown, the step of calculating the probability of abnormal behavior using a hidden Markov model, calculating a risk score using a safety distance, and triggering a graded response when the score exceeds a safety threshold specifically includes: Based on abnormal behavior samples, network attack feature data, and node failure records from historical security incidents, a temporal convolutional neural network is used to optimize the anomaly detection boundary and construct a dynamic trust assessment model. Real-time collected user biometrics, operation behavior trajectories, network environment data, and blockchain node status data are input into the dynamic trust assessment model. The probability of abnormal behavior is calculated through a hidden Markov model. Combined with device vulnerability scores and network attack intensity indices, a comprehensive risk score is calculated according to a weighted formula, and graded response measures are initiated. The probability of abnormal behavior output by the hidden Markov model is used as one of the input weights of the risk score. When the risk score exceeds the security threshold, a Level 1 response is triggered, temporarily freezing the current session, forcibly initiating secondary biometric authentication, and generating a new session key through the quantum key distribution device; Based on the second-level response triggering formula Calculate the second threshold. When the risk score exceeds the second threshold, a secondary response is triggered: the encrypted transmission channel is switched to a pre-set redundant link, incomplete encrypted data packets are discarded, and the minimum number of nodes required for signing is dynamically reduced from k to k-1, taking effect only while the redundant link is enabled. Here, T2 is the second threshold, T1 is the security threshold, α is the blockchain node anomaly rate weight, and J... d S represents the node anomaly rate, β represents the biometric anomaly probability weight, and S... w This represents the probability of an anomaly in biological characteristics. Obtain the risk score increase coefficient, calculate the difference between 1 and the risk score increase coefficient, construct a dynamic node threshold adjustment mechanism by multiplying the difference by the base threshold, and update the dynamic node threshold in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism, so that when the risk score continues to rise, the node threshold decreases according to the linear decay model. When the node anomaly rate exceeds the dynamic node threshold, a level 3 response is triggered, stopping the blockchain shard storage, switching the encrypted data stream to local encrypted storage, synchronously starting the data mirroring of the same-city backup center, and verifying data integrity through the zero-knowledge proof gateway of the off-site key escrow center.

[0026] The system deploys biosensors (fingerprint / iris), an operation behavior capture module (recording mouse movement coordinate sequences and keyboard keystroke intervals at millisecond levels), and network probes to collect user biometrics, operation trajectories, network environment data (such as transmission latency and attack traffic characteristics), and blockchain node status (response latency and data consistency deviations) in real time. It aligns biometric sampling timestamps with operation trajectories using a time synchronization matrix. A convolutional neural network (CNN) is used to extract spatial patterns of biometrics (such as fingerprint texture orientation gradients) and spatiotemporal features of operation trajectories (such as mouse acceleration change curves). This allows for the calculation of the dynamic correlation coefficient between biometric confidence and operation trajectory anomaly. When this coefficient falls below a preset fusion threshold (calibrated based on historical attack features), a weighted anomalous state transition probability calculation of a Hidden Markov Model (HMM) is triggered, outputting the behavior anomaly probability P. h Then, calculate the real-time risk score according to the formula, and take the 90th quantile of the historical risk scores to preset the safety threshold T. 1。

[0027] This can be achieved through a real-time risk scoring and tiered response trigger mechanism: In a Level 1 response (R>T1), the current session is temporarily frozen, the transmission rate is limited to 1 / 3 of the original bandwidth, secondary biometric authentication (such as fingerprint + iris dual verification) is forcibly initiated, a new session key is generated by the quantum key distribution device, and a lightweight SM4 algorithm is injected through a hardware encryption channel, enabling redundant encryption rounds; In a Level 2 response (R>T2), the second threshold T2 is dynamically calculated, switching to a pre-set redundant link, overlaying a homomorphic encryption layer, re-encrypting the SM4 key using the quantum session key, discarding incompletely encrypted data packets, and dynamically reducing the minimum number of blockchain signature nodes from k to k−1 (only during the period when the redundant link is effective), while simultaneously switching the timestamp through blockchain evidence storage records; In a Level 3 response (J... d >J threshold When ), the dynamic node threshold J threshold Press J threshold =J base ×(1−ΔR) Real-time update (ΔR is the risk score amplification coefficient), stop blockchain shard storage, switch the encrypted data stream to a local solid-state storage encrypted with national cryptographic algorithms, start data mirroring of the same-city backup center through a dedicated fiber optic channel (SM4-GCM mode encrypted transmission), transmit key shards to the off-site key escrow center via quantum encryption, verify data integrity based on a zero-knowledge proof gateway (return timestamp signature certificate), isolate abnormal devices and encode the operation behavior data into a Merkle tree structure for storage, for time-series-causal traceability.

[0028] This allows for the optimization of anomaly detection boundaries through temporal convolutional neural networks, combined with Hidden Markov Models (HMMs) to quantify behavioral risks, enabling a shift from passive defense to proactive prediction and risk-driven adaptive protection. Furthermore, a dynamic node threshold adjustment mechanism based on risk scoring enhances system resilience while ensuring Byzantine fault tolerance. When a Level 3 response triggers off-site disaster recovery, zero-knowledge proof gateways verify the integrity of mirrored data. Simultaneously, in the Level 2 response, redundant links are overlaid with homomorphic encryption layers, and quantum session keys protect the SM4 key, balancing transmission efficiency (encryption latency <10ms) with resistance to quantum cracking. Dynamically reducing the number of signature nodes (k→k−1) ensures uninterrupted service in high-risk environments.

[0029] Reference Figure 5 As shown, the calculation of the probability of abnormal behavior using a hidden Markov model specifically includes: The biometric sampling timestamps and operation behavior trajectories are aligned with millisecond-level precision to construct a time synchronization matrix. The operation behavior trajectory includes mouse movement coordinate sequences and keyboard key press intervals. The system obtains the current biometric confidence level and operation trajectory anomaly level, extracts the spatial pattern of biometrics and the spatiotemporal features of operation trajectory based on convolutional neural network, and calculates the dynamic correlation coefficient between the two within the risk-sensitive operation window. The spatial pattern of biometrics is the fingerprint texture direction gradient, and the spatiotemporal features of operation trajectory are the mouse acceleration change curve. Historical attack characteristics are obtained and a preset fusion threshold is set for dynamic environment calibration. When the dynamic correlation coefficient is less than the fusion threshold, it is judged as a high-risk abnormal behavior, triggering the weighted abnormal state transition probability of the Hidden Markov Model.

[0030] Using a hardware-level interrupt triggering mechanism (such as a USB device polling frequency of 1kHz), millisecond-level timestamps (accuracy ±0.5ms) are synchronously acquired from biometric sensors (fingerprint / iris scanners) and user behavior capture devices (mouse, keyboard). A time synchronization matrix T is then constructed. sync Biometric sampling points {t b1 , t b2 ,...,t bn} and operation trajectory point {t o1 , t o2 ,...,t om Aligned according to time windows, forming a spatiotemporal mapping matrix {n×m}. A pre-trained convolutional neural network (CNN) is then used to extract the fingerprint texture orientation gradient features. The input fingerprint image is processed through three convolutional layers (3×3 kernels, stride 1), outputting a 128-dimensional histogram of oriented gradients (HOG) feature vector V. b Simultaneously capture the mouse movement coordinate sequence {(x i , y i , t iThe instantaneous acceleration curve a(t) = d²s / dt² is calculated using second-order difference, combined with the keyboard typing interval Δt. key Generate spatiotemporal feature vector V o .

[0031] This allows for the calculation of biometric confidence level C within a risk-sensitive operation window (such as the 500ms period during the financial transaction confirmation phase). b With operational trajectory anomaly degree A o dynamic correlation coefficient Where cov is the covariance and σ is the standard deviation. When a user performs a high-risk operation (such as a large transfer), the ρ value is calculated in real time. A dynamic environment calibration model is trained based on a historical attack feature library (containing 2000+ malicious operation samples) and outputs a fusion threshold θ. fuse (Default value 0.85). When ρ < θ fuse When this occurs, it is judged as high-risk abnormal behavior. The abnormal state transition probabilities of the Hidden Markov Model (HMM) are weighted: the state transition probability a is... {ij} Adjust to a {ij} ×(1 + |ρ-θ fuse |), strengthening the transition weights for abnormal states (such as "data theft" state). This leads to the construction of a five-state HMM model (normal, low risk, medium risk, high risk, malicious), trained using the Baum-Welch algorithm with 100,000 historical behavior trajectories. Real-time input V b and V o The feature vector is used to output the probability P of abnormal behavior using the Viterbi algorithm. abnormal .

[0032] By using a millisecond-level time synchronization matrix to overcome the precision limitations of traditional second-level alignment, the modeling error of the spatiotemporal correlation between biometric features and operational trajectories is reduced. The fingerprint orientation gradient features extracted by CNN show improved robustness against affine transformation attacks compared to traditional grayscale histograms. Simultaneously, a fusion threshold θ calibrated based on historical attack features is used. fuse It can dynamically adjust according to the intensity of network attacks, reducing the false positive rate under DDoS attacks. In addition, the HMM abnormal state transition probability weighting mechanism shortens the response time for high-risk behavior detection, thereby improving computational efficiency and meeting the requirements of financial-grade real-time risk control. The spatiotemporal feature combination of mouse acceleration curve and keyboard interval effectively identifies attacks that simulate legitimate operations.

[0033] Reference Figure 6 As shown, the specific measures for initiating a tiered response include: When a Level 1 response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biometric authentication. When a secondary response is triggered, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the timestamp is switched through the blockchain evidence record. When a Level 3 response is triggered, the abnormal device is isolated and an audit trail is generated. The operational behavior data is encoded into a Merkle tree structure and stored in a remote key escrow center for time-series and causal tracing.

[0034] When the risk score output by the dynamic trust assessment model exceeds the security threshold, the Transmission Control Protocol (TCP) layer dynamically adjusts the sliding window size, forcibly reducing the data flow rate. A new session key is generated using a quantum key distribution device and injected into the SM4 algorithm core via a hardware encryption channel, simultaneously enabling redundant rounds of encryption (e.g., adding 8 random rounds to the standard 32-round encryption). Secondary biometric authentication employs fingerprint / iris dual-modal verification, with timestamps and operation trajectories aligned in real-time via a convolutional neural network, ensuring that data packets remain highly protected during authentication.

[0035] When the risk score exceeds the dynamically calculated second threshold, the link switching instruction takes effect with the joint signature of at least k-1 nodes in the blockchain network (k being the initial reconstruction threshold), and the minimum number of signing nodes is dynamically adjusted downwards. The homomorphic encryption layer operates on a dedicated cryptographic chip, using the SM4 key K. sm4 via quantum session key K q Encrypted as EK q (K sm4 The encrypted data is transmitted over redundant links. Blockchain nodes record switch timestamps using lightweight consensus mechanisms (such as Raft), generating immutable operation logs.

[0036] When the node anomaly rate J d When the dynamic node threshold is exceeded, blockchain sharding storage is stopped, and the encrypted data stream is switched to a local solid-state storage device encrypted with the national cryptographic algorithm (SM4 / SM9). Abnormal devices are blocked from connecting by the network isolation module. Operational behavior data (mouse trajectory, keystroke intervals) is encoded into a Merkle tree using a time synchronization matrix, and the root hash is stored in a remote center. Local backups are transmitted via a dedicated fiber optic channel. Data block Merkle root hashes are uploaded to the blockchain in real time. Remote verification uses non-interactive zero-knowledge proofs (such as zk-SNARKs) to prove the binding relationship between the data hash Hi and the chaotic parameter μ.

[0037] This allows for the linear decay of node thresholds through the risk score amplification coefficient (ΔR), automatically strengthening the response level as the threat escalates (e.g., k→k−1), thus improving disaster recovery efficiency. Simultaneously, the transmission index value D reversely adjusts the SM4 key update cycle, increasing the frequency of high-security archive key rotation. Furthermore, the quantum chaotic key (generated by Logistic mapping) overcomes the periodic vulnerability of AES-CTR, expanding the key space. The three-level response automatically switches to a three-tier storage architecture (local→same city→remote location), achieving lossless data recovery through Merkle tree time-series consistency verification, shortening recovery time compared to RAID arrays. In addition, operational behavior data is encoded into a Merkle tree and stored remotely, combined with the time-series-causal traceability of blockchain evidence (e.g., mouse movement coordinate sequences), improving the speed of data tampering location.

[0038] Reference Figure 7 As shown, the automatic switch to a three-tier architecture of local encrypted storage, same-city backup center, and off-site key hosting center when the node anomaly rate exceeds the node threshold specifically includes: Based on Byzantine fault tolerance theory, the response latency, data consistency deviation, and historical reliability decay coefficient of blockchain nodes are monitored in real time. Calculate the dynamic node anomaly rate, where T delay T represents the node response latency. max D is the maximum allowable delay threshold. inconsist D represents the number of bytes differing between node data and the main chain. threshold C is the difference tolerance threshold. trust Let α be the credibility decay coefficient based on historical behavior, and let α, β and γ be weighting coefficients that satisfy α+β+γ=1; When J d >J threshold Triggering a three-level response, where J threshold The real-time threshold output by the dynamic node threshold adjustment mechanism is used, and the switching instruction is jointly signed by at least k-1 trusted nodes, where k is the initial reconstruction threshold. The encrypted data that has not been fully transmitted is temporarily stored in fragments on a local solid-state storage device encrypted with the national cryptographic algorithm to form a local encrypted storage layer and generate a temporary access token. Data mirroring is synchronized through a dedicated fiber optic channel, the transmission channel is encrypted using SM4-GCM mode, and the Merkle root hash of data blocks is recorded to the local blockchain, forming a local backup center layer. The key fragments are encrypted using quantum key distribution and transmitted to a remote center. The hosting center verifies the data integrity based on zero-knowledge proof. After successful verification, a timestamp signature certificate is returned, thus constructing a remote key hosting center layer. When the node anomaly rate exceeds the threshold and the signature verification of k-1 trusted nodes passes, a level 3 response is triggered. When the node anomaly rate drops to the security threshold, data is restored in the order of priority: same-city backup center > off-site key hosting center > local encrypted storage. During the restoration process, the timing consistency of the data is verified by the Merkle tree structure audit trail.

[0039] Based on Byzantine fault tolerance theory, the system collects real-time data on blockchain node response latency, data consistency deviation, and historical reliability decay coefficient. A dynamic node anomaly rate is calculated using a formula, and combined with a risk score amplification coefficient, a linear decay model dynamically adjusts node thresholds. This automatically lowers the threshold when risk increases, improving sensitivity to anomaly nodes. This can be achieved in J... d >J threshold At this time, at least k-1 trusted nodes (k being the initial reconstruction threshold) are required to jointly sign the switching command. In the local encrypted storage layer, incomplete encrypted data fragments are temporarily stored in solid-state storage encrypted with national cryptographic algorithms (such as SM4 / SM9), generating temporary access tokens to control access permissions. In the same-city backup center layer, data mirroring is synchronized via a dedicated fiber optic channel, using the SM4-GCM mode for encrypted transmission, and the Merkle root hash of the data blocks is recorded in real-time to the local blockchain to ensure transmission integrity and traceability. In the off-site key escrow layer, key fragments are transmitted to the off-site center via quantum key encryption. The escrow center verifies data integrity based on zero-knowledge proofs (such as zk-SNARKs), and returns a timestamp signature credential upon successful verification. When the node anomaly rate drops to the security threshold, data is restored in priority order (same-city backup center > off-site escrow center > local storage). During the restoration process, the data temporal consistency is verified through an audit trail of a Merkle tree structure to ensure no tampering.

[0040] This allows for dynamic adjustment of thresholds based on Byzantine fault tolerance and reliability decay models, improving disaster recovery response speed and reducing node failover latency. The three-layer architecture (local-same-city-remote) achieves layered disaster recovery coverage: the local layer ensures zero failover (RTO≈0), the same-city layer guarantees RPO=0 through fiber optic encryption and Merkle root hashing, and the remote layer provides logical consistency through quantum encryption and zero-knowledge proofs. Simultaneously, the national cryptographic algorithm (SM4) encrypts solid-state storage to reduce local layer overhead; SM4-GCM mode encrypts the same-city fiber optic channel, reducing computational load; quantum encryption key sharding combined with zero-knowledge proofs addresses the key distribution risks of RSA remote transmission, and verification throughput is improved through GPU parallel architecture. Furthermore, Merkle tree audit trails support time-series-causal tracing, improving speed compared to traditional checksums and data tampering location, enhancing data consistency during recovery, and optimizing resource allocation through a priority recovery mechanism, resolving critical data delays caused by disordered recovery.

[0041] Reference Figure 8As shown, the process of verifying data authenticity using zero-knowledge proofs and feeding the verification results back to the dynamic trust assessment model in real time specifically includes: The zero-knowledge proof gateway is enabled only during cross-domain transfers. A non-interactive zero-knowledge proof is generated for each data fragment. This non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies... , where π i To prove the credentials, com(μ) is the commitment value of the Logistic chaos parameter μ; A GPU-accelerated parallel proof verification architecture is used to simultaneously verify data fragment proofs received by the same-city backup center and the off-site key escrow center. Verification results The credibility index is aggregated according to the weight wi of the fragment location. When the credibility index is lower than the historical actual operating threshold, the weight adjustment of the dynamic trust assessment model is triggered.

[0042] Dedicated gateway hardware is deployed at the cross-domain transmission boundary node, activating only when cross-domain communication is detected. The gateway also integrates a non-interactive zero-knowledge proof (zk-SNARKs) generation module, with the data fragment hash value H as the input parameter. i And the Logistic chaotic mapping parameter μ, output proof π i The commitment value com(μ) of μ is generated using the Pedersen commitment algorithm and is bound to π. i In this process, the authenticity of the parameters is ensured. During the proof generation phase, after the data fragments are encrypted with SM4, the hash Hi=SHA256(datai) is extracted, and the Logistic chaotic mapping parameter μ (from the quantum key distribution device) is called to calculate the commitment com(μ)=g μ h r (g and h are generators, r is a random number). Prove π using zk-SNARKs circuits. i Satisfying relation V erify (π i H i com(μ))=1. A multi-GPU cluster is used to build the verification engine, with each GPU thread independently processing a single shard proof π. i The local backup center and the remote key hosting center simultaneously receive fragmented data. The verification engine directly connects to the storage nodes in both locations via a high-speed RDMA network to achieve real-time parallel verification. During the parallel verification phase, the local and remote centers will share the received fragmented data {π i H i Distribute the data to the GPU verification queue, and simultaneously execute the verification output v in parallel on the GPU thread. i .

[0043] The weight w is dynamically set according to the fragment location (e.g., edge / core region). i (core area w) i =0.7, edge w i =0.3), design a weight allocation algorithm. The aggregation module is based on weight w. i Calculate T rustindex By comparing with historical thresholds (the 90th percentile calculated based on data from the past 30 days), the aggregation formula can be used: T rustindex =∑(v i ×w i ), where v i ∈{0,1} represents the single-shard verification result. Through the dynamic trust evaluation model interface, when T... rustindex When the value falls below the historical operating threshold (such as the 90th percentile), a model weight correction signal is triggered, adjusting the node credibility weight in the risk score (such as increasing the blockchain node weight γ from 0.3 to 0.5).

[0044] It can be achieved through μ and H i The binding prevents chaotic parameters from being tampered with, resisting parameter substitution attacks and improving the tamper detection rate. Non-interactive proof reduces cross-domain communication rounds, lowering the risk of man-in-the-middle attacks. Meanwhile, GPU parallel verification increases throughput, meeting the real-time requirements of synchronous verification in the same city / different locations, while the weight aggregation mechanism reduces invalid alarms and lowers the model false positive rate. Furthermore, dynamic correction based on historical thresholds automatically strengthens the weights of sensitive parameters when the system is subjected to sustained attacks, shortening the recovery time compared to static models.

[0045] In summary, the advantages of this invention are: by constructing a proactive multi-layered protection system through quantum dynamic keys, risk-driven hierarchical response, and blockchain disaster recovery switching, it achieves efficient and secure transmission that resists quantum attacks and dynamically adapts to network risks.

[0046] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A data security transmission method based on multiple layers of protection for digital archives, characterized in that, Including: Perform two-way authentication between the quantum key distribution device and the file transfer terminal, generate a random seed in real time based on the quantum state, perform iterative partitioning on the quantum seed in combination with the Logistic chaotic mapping, perform a non-linear transformation according to the chaotic trajectory value, and output variable-length key shards, denoted as the dynamic session key. Use the lightweight SM4 algorithm to perform symmetric encryption on the file data to obtain partitioned encrypted data, and the key update frequency is dynamically adjusted by the monitored real-time transmission index value; Collect the biometric characteristics, operation behavior trajectory, and network environment data of the user device in real time, calculate the behavior anomaly probability through the hidden Markov model, calculate the risk score through the safety margin. When the score value exceeds the safety threshold, trigger a hierarchical response. The risk score is determined as the weighted sum of the device vulnerability score, the HMM behavior anomaly probability, and the network attack intensity index. The safety threshold is preset through historical security event data; After partitioning the encrypted data, use n nodes to generate key shards, and at least k shards can be used to reconstruct the signature to monitor the status of the blockchain nodes. When the node anomaly rate exceeds the node threshold, automatically switch to a three-layer architecture of local encrypted storage,同城备份中心(Please provide the English name for this part), and off-site key escrow center, where k < n, and the node threshold is derived based on the Byzantine fault tolerance theory and calculated in combination with the node credibility decay model; Use a filter to quickly verify the integrity of the data block, verify the data authenticity in combination with zero-knowledge proof, and the verification result is fed back to the dynamic trust evaluation model in real time to update the risk score and generate an audit trail. Implement the temporal-causal traceability of the operation behavior through blockchain evidence storage, and enable the zero-trust gateway step for cross-domain transmission scenarios.

2. The data security transmission method based on multiple protections of digital archives according to claim 1, characterized in that, The specific process of generating a random seed in real time based on the quantum state, performing iterative partitioning on the quantum seed in combination with the Logistic chaotic mapping, and performing a non-linear transformation according to the chaotic trajectory value to output variable-length key shards includes: Perform two-way authentication between the quantum key distribution device and the file transfer terminal through the hardware encryption interface to generate a quantum entropy source sequence; Using the Logistic chaotic mapping formula The quantum seed is iteratively divided into blocks, where the initial value x0 is taken from the quantum entropy source; Perform non-linear compression on each data block according to the chaotic trajectory value, and the compression rate dynamically matches the file data type to output variable-length key shards; Combine the key shards to generate a session key, and the key length is in a geometric ratio relationship with the file shard size.

3. The data security transmission method based on multiple protections of digital archives according to claim 2, characterized in that, The specific process of using the lightweight SM4 algorithm to perform symmetric encryption on the file data to obtain partitioned encrypted data includes: Collect the network data transmission delay time, network effective data transmission rate, and the real-time workload of the blockchain nodes in real time. Calculate the comprehensive index value according to the historical weight coefficient of the network data transmission delay time, network effective data transmission rate, and the real-time workload of the blockchain nodes; Obtain the normal distribution of the historical risk score, calculate the 90% quantile as the safety threshold, and trigger the key update mechanism when the index value exceeds the safety threshold; Invoke the quantum key distribution device to generate a new quantum random seed, re-run the iterative calculation process of the Logistic chaotic mapping to generate a new session key. The newly generated key is injected into the SM4 algorithm through the hardware encryption channel, and the shard key of the blockchain node is updated synchronously; The key update interval is inversely correlated with the comprehensive index value. The worse the network transmission status, the higher the key replacement frequency. The update cycle is dynamically scaled according to the security level coefficient of the file. High-secret files trigger more frequent key rotation in a bad network environment.

4. The data security transmission method based on multiple protections of digital archives according to claim 3, characterized in that, The process of calculating the probability of abnormal behavior using a Hidden Markov Model, calculating a risk score using a safety distance, and triggering a tiered response when the score exceeds a safety threshold specifically includes: Based on abnormal behavior samples, network attack feature data, and node failure records from historical security incidents, a temporal convolutional neural network is used to optimize the anomaly detection boundary and construct a dynamic trust assessment model. Real-time collected user biometrics, operation behavior trajectories, network environment data, and blockchain node status data are input into the dynamic trust assessment model. The probability of abnormal behavior is calculated through a hidden Markov model. Combined with device vulnerability scores and network attack intensity indices, a comprehensive risk score is calculated according to a weighted formula, and graded response measures are initiated. The probability of abnormal behavior output by the hidden Markov model is used as one of the input weights of the risk score. When the risk score exceeds the security threshold, a Level 1 response is triggered, temporarily freezing the current session, forcibly initiating secondary biometric authentication, and generating a new session key through the quantum key distribution device; Based on the second-level response triggering formula Calculate the second threshold. When the risk score exceeds the second threshold, a secondary response is triggered: the encrypted transmission channel is switched to a pre-set redundant link, incomplete encrypted data packets are discarded, and the minimum number of nodes required for signing is dynamically reduced from k to k-1, taking effect only while the redundant link is enabled. Here, T2 is the second threshold, T1 is the security threshold, α is the blockchain node anomaly rate weight, and J... d S represents the node anomaly rate, β represents the biometric anomaly probability weight, and S... w This represents the probability of an anomaly in biological characteristics. Obtain the risk score increase coefficient, calculate the difference between 1 and the risk score increase coefficient, construct a dynamic node threshold adjustment mechanism by multiplying the difference by the base threshold, and update the dynamic node threshold in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism, so that when the risk score continues to rise, the node threshold decreases according to the linear decay model. When the node anomaly rate exceeds the dynamic node threshold, a level 3 response is triggered, stopping the blockchain shard storage, switching the encrypted data stream to local encrypted storage, synchronously starting the data mirroring of the same-city backup center, and verifying data integrity through the zero-knowledge proof gateway of the off-site key escrow center.

5. A data security transmission method based on multiple protections for digital archives according to claim 4, characterized in that, The calculation of abnormal behavior probability using a hidden Markov model specifically includes: The biometric sampling timestamps and operation behavior trajectories are aligned with millisecond-level precision to construct a time synchronization matrix. The operation behavior trajectory includes mouse movement coordinate sequences and keyboard key press intervals. The system obtains the current biometric confidence level and operation trajectory anomaly level, extracts the spatial pattern of biometrics and the spatiotemporal features of operation trajectory based on convolutional neural network, and calculates the dynamic correlation coefficient between the two within the risk-sensitive operation window. The spatial pattern of biometrics is the fingerprint texture direction gradient, and the spatiotemporal features of operation trajectory are the mouse acceleration change curve. Historical attack characteristics are obtained and a preset fusion threshold is set for dynamic environment calibration. When the dynamic correlation coefficient is less than the fusion threshold, it is judged as a high-risk abnormal behavior, triggering the weighted abnormal state transition probability of the Hidden Markov Model.

6. A data security transmission method based on multiple protections for digital archives according to claim 5, characterized in that, The specific measures for initiating a tiered response include: When a Level 1 response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biometric authentication. When a secondary response is triggered, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the timestamp is switched through the blockchain evidence record. When a Level 3 response is triggered, the abnormal device is isolated and an audit trail is generated. The operational behavior data is encoded into a Merkle tree structure and stored in a remote key escrow center for time-series and causal tracing.

7. A data security transmission method based on multiple protections for digital archives according to claim 6, characterized in that, The automatic switch to a three-tier architecture—local encrypted storage, same-city backup center, and off-site key hosting center—when the node failure rate exceeds the node threshold specifically includes: Based on Byzantine fault tolerance theory, the response latency, data consistency deviation, and historical reliability decay coefficient of blockchain nodes are monitored in real time. Calculate the dynamic node anomaly rate, where T delay T represents the node response latency. max D is the maximum allowable delay threshold. inconsist D represents the number of bytes differing between node data and the main chain. threshold C is the difference tolerance threshold. trust Let α be the credibility decay coefficient based on historical behavior, and let α, β and γ be weighting coefficients that satisfy α+β+γ=1; When J d >J threshold Triggering a three-level response, where J threshold The real-time threshold output by the dynamic node threshold adjustment mechanism is used, and the switching instruction is jointly signed by at least k-1 trusted nodes, where k is the initial reconstruction threshold. The encrypted data that has not been fully transmitted is temporarily stored in fragments on a local solid-state storage device encrypted with the national cryptographic algorithm to form a local encrypted storage layer and generate a temporary access token. Data mirroring is synchronized through a dedicated fiber optic channel, the transmission channel is encrypted using SM4-GCM mode, and the Merkle root hash of data blocks is recorded to the local blockchain, forming a local backup center layer. The key fragments are encrypted using quantum key distribution and transmitted to a remote center. The hosting center verifies the data integrity based on zero-knowledge proof. After successful verification, a timestamp signature certificate is returned, thus constructing a remote key hosting center layer. When the node anomaly rate exceeds the threshold and the signature verification of k-1 trusted nodes passes, a level 3 response is triggered. When the node anomaly rate drops to the security threshold, data is restored in the order of priority: same-city backup center > off-site key hosting center > local encrypted storage. During the restoration process, the timing consistency of the data is verified by the Merkle tree structure audit trail.

8. A data security transmission method based on multiple protections of digital archives according to claim 7, characterized in that, The process of verifying data authenticity using zero-knowledge proofs, with the verification results fed back to the dynamic trust assessment model in real time, specifically includes: The zero-knowledge proof gateway is enabled only during cross-domain transfers. A non-interactive zero-knowledge proof is generated for each data fragment. This non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies... , where π i To prove the credentials, com(μ) is the commitment value of the Logistic chaos parameter μ; A GPU-accelerated parallel proof verification architecture is used to simultaneously verify data fragment proofs received by the same-city backup center and the off-site key escrow center. Verification results The credibility index is aggregated according to the weight wi of the fragment location. When the credibility index is lower than the historical actual operating threshold, the weight adjustment of the dynamic trust assessment model is triggered.

Citation Information

Patent Citations

  • Block chain network based on quantum key and data safety transmission method

    CN113765665A

  • Information security management method and system based on sensitive data

    CN120449206A

  • Data security transmission method in cloud platform salary management system

    CN120498768A

  • Distributed intelligent authentication method based on dynamic multi-modal fusion

    CN120546922A

  • Multi–stage fully homomorphic encryption and compression system for secure data processing and analysis

    US20250158637A1

Cited By

  • Method and system for detecting electronic file transfer in secret-related network environment

    CN121309142A

  • Multi-modal education data security processing method and system based on national cryptographic algorithm and homomorphic encryption

    CN121664422A

  • Electric power archive management method and system based on man-machine interaction

    CN121744371A