A data security transmission method based on digital archive multi-protection

By combining quantum key distribution equipment with Logistic chaotic mapping, real-time collection of biometric and network data is achieved, and a dynamic trust assessment model is constructed. This enables quantum-based protection against traditional encryption algorithms, dynamically adjusts node thresholds, improves data transmission security and real-time response capabilities, reduces ransomware response latency, and meets the requirements of financial-grade real-time risk control.

CN120880802BActive Publication Date: 2026-01-02ANHUI LEADER TECHNOLOGY INNOVATION DEVELOPMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511386047.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-02
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

In existing technologies, traditional encryption algorithms are easily cracked by quantum mechanics, the key update frequency is out of sync with network risks, centralized disaster recovery architectures have single point of failure risks, cannot respond to dynamic network threats in real time, and ransomware response is delayed. Zero-trust architectures have high computational overhead and are difficult to achieve millisecond-level real-time gateway decisions.

Method used

A quantum key distribution device is used to generate dynamic session keys. Logistic chaotic mapping is used for nonlinear transformation. Biometric and network data are collected in real time. Risk is calculated through a hidden Markov model. Node thresholds are dynamically adjusted to achieve a multi-layered protection architecture. Zero-knowledge proof is used to verify the authenticity of data. The verification results are fed back to the dynamic trust assessment model in real time to update the risk assessment model. Blockchain notarization is used to achieve time-series-causal traceability of operational behavior. Zero-trust gateway steps are enabled for cross-domain transmission scenarios.

Benefits of technology

It achieves dual protection of physical randomness and algorithmic complexity in the quantum entropy source layer, dynamically matches data types, improves key update frequency and network risk linkage dynamic matching transmission efficiency, improves the risk perception-decision-execution closed loop, enables biological behavior spatiotemporal modeling to improve APT attack identification rate, risk scoring drives the dynamic decay of blockchain node thresholds, disaster recovery switching latency compression, zero-knowledge proof and disaster recovery architecture collaboration, ensures logical consistency of data in different locations, and improves recovery success rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880802B_ABST
    Figure CN120880802B_ABST
Patent Text Reader

Abstract

The application discloses a data security transmission method based on digital file multiple protection, and relates to the field of data security transmission, which comprises the following steps: generating a random seed in real time based on a quantum state, combining a Logistic chaotic mapping to iteratively block the quantum seed, outputting a variable-length key fragment, using a lightweight SM4 algorithm to symmetrically encrypt file data to obtain encrypted data of the fragment; calculating a behavior anomaly probability through a hidden Markov model, calculating a risk score through a safety interval, and triggering a hierarchical response when the score value exceeds a safety threshold; using n nodes to generate a key fragment, and at least k fragments to reconstruct a signature to monitor the state of a blockchain node, and automatically switching to a three-layer architecture when the node anomaly rate exceeds a node threshold. The application has the advantages that: through quantum dynamic key, risk-driven hierarchical response and blockchain disaster recovery switching, an active multiple protection system is constructed to realize quantum attack resistance and dynamically adaptive network risk transmission.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data security transmission, in particular to a data security transmission method based on multiple protections of digital archives. BACKGROUND

[0002] Digital archive security transmission refers to a technical system that uses cryptography, network protocols and distributed storage technology to protect data confidentiality, integrity and availability during the digitalization process of archives. With the evolution of technology, quantum key distribution (QKD) has emerged to enhance key security, blockchain technology is used for distributed node verification, and homomorphic encryption supports ciphertext calculation. However, during the use of existing technologies, the periodic keys of traditional encryption algorithms such as AES are vulnerable to quantum Shor algorithm attacks, NIST predicts that quantum computers can break 2048-bit RSA keys by 2029, the key update frequency is not synchronized with the network risk state, and the rotation frequency cannot be increased in poor network environments, leading to an increased risk of exposure of high-security level archives. At the same time, pseudo-random number generators (PRNGs) rely on algorithmic entropy sources and cannot resist quantum brute force attacks, making them vulnerable to quantum computing threats. Meanwhile, traditional blockchains have a fixed fault tolerance threshold (such as 1 / 3 node fault tolerance), which cannot dynamically respond to node credibility decay, leading to an increase in the duration of malicious node attacks. Centralized disaster recovery centers require manual intervention for switching, with a recovery time (RTO) of more than 30 minutes, which cannot meet the real-time requirements of financial and other scenarios. Off-site data verification relies on traditional hash trees, and the verification delay of a Merkel tree in a thousand-node network can be as high as 500ms, and it cannot prove that the data has not been leaked, which poses a certain risk to centralized disaster recovery systems. In addition, network attacks, device vulnerabilities, and behavioral anomalies are handled independently, and a multi-dimensional dynamic scoring model has not been established, leading to a long response delay for ransomware. The zero trust architecture relies on continuous certificate verification, but traditional zero-knowledge proof (ZKP) calculations have high overhead (single proof takes more than 100ms), making it difficult to achieve millisecond-level real-time gateway decision-making. SUMMARY

[0003] To solve the above technical problems, a data security transmission method based on multiple protections of digital archives is provided, which solves the problems of static key mechanism vulnerability to quantum attacks, centralized disaster recovery architecture single point of failure risk, and passive defense model unable to respond to dynamic network threats in real time.

[0004] To achieve the above purposes, the technical scheme adopted by the present application is as follows:

[0005] A data security transmission method based on multiple protections of digital archives, comprising:

[0006] The quantum key distribution device and the archive transmission terminal are bidirectionally authenticated, a random seed is generated in real time based on a quantum state, quantum seeds are iteratively blocked by combining a Logistic chaotic mapping, nonlinear transformation is performed on chaotic trajectory values, variable-length key fragments are output, recorded as dynamic session keys, symmetric encryption is performed on archive data by using a lightweight SM4 algorithm, encrypted data of the fragments is obtained, and the key update frequency is dynamically adjusted by a monitored real-time transmission index value;

[0007] Real-time collection of biological characteristics, operation behavior trajectories and network environment data of the user equipment, calculation of behavior anomaly probability by an hidden Markov model, calculation of risk score by a security distance, triggering of a hierarchical response when the score value exceeds a security threshold, the risk score being a weighted sum of the device vulnerability score, the HMM behavior anomaly probability and the network attack intensity index, and the security threshold being obtained by presetting historical security event data;

[0008] The encrypted data of the fragments are used to generate key fragments by n nodes, at least k fragments can reconstruct the signature monitoring blockchain node state, when the node anomaly rate exceeds a node threshold, the system is automatically switched to a three-layer architecture of local encrypted storage, a city backup center and a remote key hosting center, wherein k < n, and the node threshold is derived based on the Byzantine fault tolerance theory and calculated by combining a node credibility decay model;

[0009] The filter is used to quickly check the data block integrity, the zero-knowledge proof is used to verify the data authenticity, the checking result is fed back to the dynamic trust evaluation model in real time, the risk score is updated and an audit trajectory is generated, the operation behavior is time-cause traced by block chain notarization, and the zero-trust gateway step is enabled for cross-domain transmission scenarios.

[0010] Preferably, the quantum state-based real-time random seed generation, the iterative blocking of the quantum seed by combining the Logistic chaotic mapping, and the nonlinear transformation of the chaotic trajectory values to output the variable-length key fragments specifically include:

[0011] The quantum key distribution device and the archive transmission terminal are bidirectionally authenticated through a hardware encryption interface, and a quantum entropy source sequence is generated;

[0012] The Logistic chaotic mapping formula is used to iteratively block the quantum seed, wherein the initial value x0 is taken from the quantum entropy source;

[0013] The chaotic trajectory values are nonlinearly compressed for each data block, the compression rate is dynamically matched with the archive data type, and the variable-length key fragments are output;

[0014] The key fragments are combined to generate session keys, and the key length is in a constant ratio with the archive fragment size.

[0015] Preferably, the lightweight SM4 algorithm is used to symmetrically encrypt the archive data to obtain the encrypted data of the fragments, which specifically includes:

[0016] Real-time network data transmission delay time, network effective data transmission rate and real-time working load of the blockchain node are collected, and the network data transmission delay time, network effective data transmission rate and real-time working load of the blockchain node are calculated to obtain a comprehensive index value according to a historical weight coefficient;

[0017] A normal distribution of historical risk scores is obtained, and a 90% quantile is calculated as a safety threshold. When the index value exceeds the safety threshold, a key update mechanism is triggered.

[0018] A quantum key distribution device is called to generate a new quantum random seed, and a new session key is generated by re-running the iteration calculation process of the Logistic chaotic mapping. The newly generated key is injected into the SM4 algorithm through a hardware encryption channel, and the blockchain node shard key is updated synchronously.

[0019] The time interval of key update is inversely associated with the comprehensive index value. The worse the network transmission state is, the higher the key replacement frequency is. The update period is dynamically scaled according to the security level coefficient of the archive. High-security-level archives trigger more frequent key rotation in poor network environments.

[0020] Preferably, the behavior anomaly probability is calculated by the hidden Markov model, the risk score is calculated by the safety distance, and when the score value exceeds the safety threshold, a graded response is triggered, which specifically includes:

[0021] Based on the abnormal behavior samples, network attack feature data and node failure records in historical security events, a time sequence convolutional neural network is used to optimize the abnormal detection boundary, and a dynamic trust evaluation model is constructed. The user biological characteristics, operation behavior trajectory, network environment data and blockchain node state data collected in real time are input into the dynamic trust evaluation model. The behavior anomaly probability is calculated by the hidden Markov model, the device vulnerability score and the network attack intensity index are combined, the comprehensive risk score is calculated according to the weight formula, and the graded response measures are started. The behavior anomaly probability output by the hidden Markov model is one of the input weights of the risk score;

[0022] When the risk score exceeds the safety threshold, a first-level response is triggered, the current session is temporarily frozen, a secondary biological authentication is forcibly started, and a new session key is generated by a quantum key distribution device.

[0023] Based on the secondary response trigger formula A second threshold is calculated, when the risk score exceeds the second threshold, a secondary response is triggered, the encrypted transmission channel is switched to the preset redundant link, the unfinished encrypted data packet is discarded, the minimum number of nodes required for signature is dynamically reduced from k to k-1, and only during the enabling period of the redundant link, wherein T2 is the second threshold, T1 is the security threshold, a is the abnormal rate weight of the blockchain node, J d is the node abnormal rate, and β is the abnormal probability weight of the biological feature w is the abnormal probability of the biological feature

[0024] A risk score increase coefficient is obtained, the difference between 1 and the risk score increase coefficient is calculated, a dynamic node threshold adjustment mechanism is constructed by multiplying the difference value and the basic threshold, and the dynamic node threshold is updated in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism, so that when the risk score continues to rise, the node threshold is reduced according to a linear decay model.

[0025] When the node abnormal rate exceeds the dynamic node threshold, a tertiary response is triggered, the blockchain sharding storage is stopped, the encrypted data stream is switched to local encrypted storage, the data mirroring of the local backup center is synchronously started, and the data integrity is verified through the zero-knowledge proof gateway of the off-site key escrow center.

[0026] Preferably, the calculation of the behavior abnormal probability by the hidden Markov model specifically comprises:

[0027] The biological feature sampling time stamp is aligned with the operation behavior trajectory with millisecond-level precision, a time synchronization matrix is constructed, and the operation behavior trajectory includes a mouse movement coordinate sequence and a keyboard keystroke interval.

[0028] The current biological feature confidence and operation trajectory abnormality are obtained, the spatial pattern of the biological feature and the space-time feature of the operation trajectory are extracted based on a convolutional neural network, and a dynamic correlation coefficient of the two in a risk-sensitive operation window is calculated, wherein the spatial pattern of the biological feature is a fingerprint texture direction gradient, and the space-time feature of the operation trajectory is a mouse acceleration change curve.

[0029] A preset fusion threshold is obtained by calibrating the historical attack features and the dynamic environment, when the dynamic correlation coefficient is less than the fusion threshold, it is determined that the abnormal behavior is high-risk, and the abnormal state transition probability of the hidden Markov model is triggered.

[0030] Preferably, the starting of the hierarchical response measure specifically comprises:

[0031] When the first-level response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and the redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biological authentication;

[0032] When triggering the secondary response, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the switching timestamp is recorded through blockchain notarization;

[0033] When triggering the tertiary response, the abnormal device is isolated and an audit trail is generated, the operation behavior data is encoded into a Merkle tree structure and stored in an off-site key escrow center for time-cause tracing.

[0034] Preferably, when the node abnormality rate exceeds the node threshold, the automatic switching to the three-layer architecture of local encrypted storage, local backup center, and off-site key escrow center specifically includes:

[0035] Based on the Byzantine fault tolerance theory, the response delay, data consistency deviation, and historical credibility decay coefficient of the blockchain node are monitored in real time, and the dynamic node abnormality rate is calculated, where T delay is the node response delay, T max is the maximum allowed delay threshold, D inconsist is the number of bytes of node data difference from the main chain, D threshold is the difference tolerance threshold, C trust is the credibility decay coefficient based on historical behavior, and α, β, and γ are weight coefficients satisfying α+β+γ=1;

[0036] When J d > J threshold , the tertiary response is triggered, where J threshold is the real-time threshold output by the dynamic node threshold adjustment mechanism, and the switching instruction is jointly signed by at least k−1 trusted nodes to take effect, where k is the initial reconstruction threshold;

[0037] The encrypted data fragments that have not been transmitted are temporarily stored in the local solid-state storage encrypted by the local cryptographic algorithm, forming a local encrypted storage layer, and a temporary access token is generated;

[0038] Through dedicated fiber channel synchronization data mirroring, the transmission channel is encrypted using the SM4-GCM mode, and the data block Merkle root hash is recorded to the local blockchain, forming a local backup center layer;

[0039] The key fragments are transmitted to the off-site center after being encrypted by the quantum key, and the data integrity is verified by the escrow center based on zero-knowledge proof. If the verification is passed, a timestamp signature voucher is returned, and an off-site key escrow center layer is constructed;

[0040] When the node abnormality rate exceeds the threshold and the k−1 trusted node signature verification is passed, the tertiary response is triggered. When the node abnormality rate drops to the safety threshold, the data is restored in the priority order of local backup center greater than off-site key escrow center greater than local encrypted storage. In the restoration process, the data time consistency is verified through the Merkle tree structure audit trail.

[0041] Preferably, the combination of zero-knowledge proof verifies the authenticity of the data, and the checking result is fed back to the dynamic trust evaluation model in real time, specifically comprising:

[0042] Only when cross-domain transmission is enabled, a non-interactive zero-knowledge proof is generated for each data slice, the non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies Wherein π i is a proof credential, and com(μ) is a commitment value of the Logistic chaotic parameter μ;

[0043] Through a GPU-accelerated parallel proof verification architecture, the data slice proofs received by the local backup center and the off-site key management center are verified synchronously.

[0044] The verification result is aggregated into a credibility index according to the slice position weight wi, and when the credibility index is less than a historical actual operation threshold, the weight correction of the dynamic trust evaluation model is triggered.

[0045] Compared with the prior art, the present application has the following advantages:

[0046] The present application proposes a data security transmission method based on digital archive multi-protection, a quantum entropy source layer is formed by generating a true random entropy source sequence through a hardware encryption interface of a sub-key distribution device. Then, the quantum seed is iteratively blocked based on Logistic mapping, the nonlinear transformation is dynamically controlled through the trajectory value, and the variable-length key slice is output to construct a chaotic encryption layer. The network transmission index value is calculated in real time to drive the key update period, and the dynamic adjustment layer is realized. That is, the quantum entropy source layer, the chaotic encryption layer and the dynamic adjustment layer can be coordinated to realize the dual protection of physical randomness and algorithm complexity, resist brute force cracking by quantum entropy source, and dynamically match data types by chaotic slice. The key update frequency and network risk are linked in real time, the rotation speed of high-density archives in a weak network environment is improved, and the security strength and transmission efficiency are considered;

[0047] The application provides a data security transmission method based on digital file multi-protection, constructs a space-time feature matrix by aligning biological characteristics (fingerprint direction gradient) and operation trajectory (mouse acceleration curve) in milliseconds, forms a multi-factor perception layer, calculates behavior anomaly probability through a CNN-HMM model, fuses device vulnerabilities and network attacks, outputs a risk score, forms a dynamic scoring layer, and finally triggers a three-level response based on the score, drives the threshold linear decay of the blockchain node, and switches to a local-city-remote disaster recovery architecture to construct a collaborative response layer, that is, a risk perception-decision-execution closed loop, so that the space-time modeling of biological behavior improves the APT attack recognition rate, the risk score drives the dynamic decay of the threshold of the blockchain node, the disaster recovery switching delay is compressed, the zero-knowledge proof is coordinated with the disaster recovery architecture, the logical consistency of remote data is ensured, and the recovery success rate is improved. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 It is a flowchart of the application;

[0049] Figure 2 It is a flowchart of the application, which generates a random seed in real time based on a quantum state, iteratively divides the quantum seed by combining a Logistic chaotic mapping, performs nonlinear transformation according to chaotic trajectory values, and outputs a variable-length key fragment;

[0050] Figure 3 It is a flowchart of the application, which uses a lightweight SM4 algorithm to symmetrically encrypt file data and obtain encrypted data fragments;

[0051] Figure 4 It is a flowchart of the application, which calculates behavior anomaly probability through a hidden Markov model, calculates risk score through a safety distance, and triggers a hierarchical response when the score exceeds a safety threshold;

[0052] Figure 5 It is a flowchart of the application, which calculates behavior anomaly probability through a hidden Markov model;

[0053] Figure 6 It is a flowchart of the application, which starts a hierarchical response measure;

[0054] Figure 7 It is a flowchart of the application, which automatically switches to a three-layer architecture of local encryption storage, city backup center and remote key management center when the node anomaly rate exceeds the node threshold;

[0055] Figure 8 It is a flowchart of the application, which verifies the authenticity of data by combining zero-knowledge proof, and feeds back the verification result to the dynamic trust evaluation model in real time. DETAILED DESCRIPTION

[0056] The following description is presented to enable any person skilled in the art to practice the application as claimed. The preferred embodiments disclosed herein are only examples of the many possible variations of the present application.

[0057] Referring to Figure 1 As shown in the figure, a data security transmission method based on digital archive multi-protection includes:

[0058] The quantum key distribution device and the archive transmission terminal are bidirectionally authenticated, a random seed is generated in real time based on a quantum state, the quantum seed is iteratively blocked by combining a Logistic chaotic mapping, nonlinear transformation is performed according to chaotic trajectory values, and a variable-length key fragment is output, which is recorded as a dynamic session key, symmetric encryption is performed on the archive data by using a lightweight SM4 algorithm, encrypted data of the fragment is obtained, and the key update frequency is dynamically adjusted by a monitored real-time transmission index value;

[0059] Biological features, operation behavior trajectories and network environment data of the user equipment are collected in real time, behavior anomaly probability is calculated by using a hidden Markov model, risk score is calculated by using a safety distance, when the score value exceeds a safety threshold, a hierarchical response is triggered, the risk score is the weighted sum of the device vulnerability score, the HMM behavior anomaly probability and the network attack intensity index, and the safety threshold is obtained by presetting historical security event data;

[0060] The encrypted data of the fragment is used to generate key fragments by n nodes, at least k fragments can reconstruct the signature monitoring blockchain node state, when the node anomaly rate exceeds a node threshold, the system is automatically switched to a three-layer architecture of local encrypted storage, a city backup center and a remote key management center, wherein k < n, and the node threshold is derived based on the Byzantine fault tolerance theory and calculated by combining a node credibility decay model;

[0061] The filter is used to quickly check the data block integrity, the zero-knowledge proof is used to verify the data authenticity, the checking result is fed back to the dynamic trust evaluation model in real time, the risk score is updated and an audit trajectory is generated, the operation behavior is time-cause traced by block chain storage, and the zero-trust gateway step is enabled for cross-domain transmission scenarios.

[0062] The Logistic chaotic mapping formula is used The quantum seed is iteratively divided into blocks, and the data blocks are nonlinearly compressed according to the chaotic trajectory value (the compression rate dynamically matches the file data type), and the variable-length key fragments are output, so as to combine the fragments to generate a dynamic session key, the key length is in a proportional relationship with the file fragment size (for example, 1MB data corresponds to a 128-bit key), forming a quantum dynamic key generation system, which generates random seeds in real time through a quantum entropy source, and solves the periodic vulnerability of a pseudo-random number generator (such as AES-CTR) by combining the nonlinear transformation of the Logistic chaotic mapping, expands the key space, resists quantum brute force cracking, and adjusts the update frequency of the dynamic session key according to the transmission index value (network delay / load comprehensive calculation), so that the key rotation frequency of high-density files is improved in a poor network.

[0063] Further deploy biological sensors (fingerprint / iris), operation behavior capture modules (mouse trajectory / keystroke interval), and network probes to collect multi-dimensional data in real time, align the biological characteristics and operation trajectory timestamps (millisecond level), construct a space-time feature matrix (such as a mouse acceleration curve), and when the dynamic correlation coefficient is lower than a preset fusion threshold, trigger the HMM abnormal state transition probability weighting, and simultaneously perform risk scoring , and the weights α+β+γ=1, so that a hierarchical response is triggered, when R>T1, the session is frozen, secondary biological authentication is forced, and the quantum key is updated; when R>T2, the redundant link is switched to, the number of blockchain signature nodes is reduced to k−1, and dynamic risk assessment and hierarchical response are formed.

[0064] A blockchain network containing n nodes is constructed, a Byzantine fault tolerance threshold k (k<n) is preset, the node abnormal rate is calculated, and the three-layer architecture is switched to according to the calculated node abnormal rate, the zero-knowledge proof gateway is enabled for cross-domain transmission, and the proof π is generated for the data fragments i , the verification result is fed back to the dynamic trust evaluation model to correct the weights. The MM model fuses the space-time correlation of biological characteristics and operation behaviors, reduces the false positive rate of anomaly detection, and based on the dynamic node threshold J threshold derived based on Byzantine fault tolerance, in combination with the credibility decay model, the node failure switching delay is shortened, and the disaster recovery efficiency is improved compared with the traditional fixed threshold. At the same time, the zero-knowledge proof and the filter cooperate to verify, so that the data authenticity verification throughput is improved, and the zero-trust gateway forces the cross-domain transmission of “never trust, continuous verification”, in combination with the blockchain storage, the operation behavior is traced back to the whole link, and the audit trajectory generation speed is also improved.

[0065] Referring to Figure 2 , the quantum state-based random seed is generated in real time, the quantum seed is iteratively divided into blocks, the chaotic trajectory value is nonlinearly transformed, and the variable-length key fragments are output, which specifically include:

[0066] The quantum key distribution device and the file transmission terminal are authenticated bidirectionally through a hardware encryption interface to generate a quantum entropy source sequence.

[0067] The Logistic chaotic mapping formula is adopted The quantum seed is iteratively divided into blocks, and the initial value x0 is taken from the quantum entropy source.

[0068] Each data block is compressed according to the chaotic trajectory value, and the compression rate dynamically matches the file data type, and a variable-length key fragment is output.

[0069] The combined key fragments generate a session key, and the key length is in a proportional relationship with the file fragment size.

[0070] A special encryption interface (such as a PCI-E encryption card or a hardware security module certified by the national cryptography) is deployed between the quantum key distribution device and the file transmission terminal at the physical layer, and the device identity is bidirectionally verified through quantum digital certificate exchange. After the device authentication, the quantum key distribution device triggers a single-photon emitter to generate a true random sequence based on quantum polarization states as an initial entropy source, and the entropy source length is dynamically adapted to the terminal hardware performance (usually 1024-4096 bits). A chaotic calculation unit is built-in in the encryption terminal, and a Logistic mapping function is loaded . The quantum entropy source sequence is segmented into 32 bits, the hash value of the first segment is taken as the chaotic initial value, and the control parameter μ is dynamically configured according to the file type (such as data μ=3.99, and multimedia data μ=3.57). Parallel iterative calculation is realized through FPGA, and 64-bit chaotic trajectory values are output in each iteration.

[0071] During use, the chaotic trajectory values are input into a nonlinear transformation module: when the trajectory value xn∈[0,0.3), S-box permutation compression is adopted, and a 128-bit fragment is output; when xn∈[0.3,0.7), a cyclic shift + modulo addition operation is performed, and a 192-bit fragment is output; when xn∈[0.7,1], Arnold transformation is performed, and a 256-bit fragment is output. The compression rate dynamically matches the file data type (text 1:4, image 1:8, and video 1:16), and the output fragment information entropy value is ensured to be ≥7.98 through an entropy detection unit. And the key fragments are combined in a proportional relationship according to the file fragment size: 1MB fragment corresponds to 128-bit key; 10MB fragment corresponds to 192-bit key; and 100MB+ fragment corresponds to 256-bit key. The combination process introduces a Hamming code error correction mechanism to ensure the integrity of the fragments through XOR verification. The physical unpredictability of the key generation is ensured through the quantum entropy source, and the dynamic variation of the key fragments is realized in combination with the initial value sensitivity of the Logistic chaotic system. The output key passes all 15 randomness detection items, the key space is expanded compared with traditional methods, the encryption and decryption throughput is improved, and the real-time and secure transmission requirements of high-density files are met.

[0072] Referring to Figure 3 As shown, the symmetric encryption of the archive data using the lightweight SM4 algorithm to obtain the encrypted data of the shards specifically includes:

[0073] Real-time network data transmission delay time, network effective data transmission rate and real-time working load of the blockchain node are collected, and the network data transmission delay time, network effective data transmission rate and real-time working load of the blockchain node are calculated according to the historical weight coefficient to obtain a comprehensive index value;

[0074] The normal distribution of the historical risk score is obtained, and the 90% quantile is calculated as a safety threshold. When the index value exceeds the safety threshold, the key update mechanism is triggered;

[0075] The quantum key distribution device is called to generate a new quantum random seed, and the iteration calculation process of the Logistic chaotic mapping is re-run to generate a new session key. The newly generated key is injected into the SM4 algorithm through a hardware encryption channel, and the blockchain node shard key is updated synchronously;

[0076] The time interval of key update is inversely associated with the comprehensive index value. The worse the network transmission state is, the higher the key replacement frequency is. The update period is dynamically scaled according to the security level coefficient of the archive. High security level archives trigger more frequent key rotation in poor network environment.

[0077] The network probe is deployed to collect network data transmission delay time (end-to-end data packet transmission time), effective data transmission rate (amount of data successfully transmitted per unit time) and real-time working load of the blockchain node (CPU / memory utilization rate) in real time. A historical weight coefficient library (such as delay weight α = 0.4, rate weight β = 0.3, and load weight γ = 0.3) is established, and a comprehensive index value is calculated by a weighted formula: The reference value is preset according to the historical network state, that is, the quantum key distribution device can be called to generate a new quantum random seed, which is transmitted to the chaotic calculation unit through a hardware encryption interface (such as a PCI-E encryption card). Run the Logistic chaotic mapping iteration, and then perform nonlinear transformation (such as S-box permutation and Arnold transformation) according to the chaotic trajectory value. Output variable-length key shards and combine them into a new session key. The new key is injected into the SM4 algorithm core through the hardware security module (HSM), and the key shards of the blockchain node are updated at the same time.

[0078] The inverse relationship between the key update period T and the comprehensive index value I can be set as: , wherein K is a constant, S is a file security level coefficient (high security level file S≥2.0). The worse the network state (the larger the I value), the higher the key rotation frequency, and the high security level file triggers more frequent updates under poor network. Thus, the unpredictability of the key can be ensured through the initial value sensitivity of the quantum entropy source and the Logistic chaotic mapping, the periodic vulnerability of the traditional pseudo-random number generator (such as AES-CTR) is broken through, the key space is expanded, and quantum brute force cracking is effectively resisted. The key update frequency is dynamically bound to the network risk, which can improve the security of the static key scheme. At the same time, the real-time reflection of the network load and delay is comprehensively reflected by the index value, and the adaptive key rotation is realized through the reverse correlation mechanism: when the transmission delay increases or the node load exceeds the limit, the key update period is shortened to milliseconds, avoiding encryption failure due to network congestion. The security level coefficient S of the high security level file further amplifies the adjustment range, ensuring that the key data still maintains high strength protection in a weak network environment. In addition, the lightweight SM4 algorithm combined with the hardware encryption channel improves the encryption throughput and reduces the computational overhead of the traditional TLS protocol. At the same time, the key fragmentation and the blockchain node state synchronization update can also avoid the single point failure risk of centralized key management.

[0079] Referring to Figure 4 The calculation of the behavior anomaly probability by the hidden Markov model, the calculation of the risk score by the security interval, and the triggering of the hierarchical response when the score value exceeds the security threshold value specifically include:

[0080] Based on the abnormal behavior samples, network attack feature data and node failure records in the historical security events, a time sequence convolutional neural network is used to optimize the abnormal detection boundary, and a dynamic trust evaluation model is constructed. The user biological features, operation behavior trajectory, network environment data and blockchain node state data collected in real time are input into the dynamic trust evaluation model, the behavior anomaly probability is calculated by the hidden Markov model, the comprehensive risk score is calculated according to the weight formula combining the device vulnerability score and the network attack intensity index, and the hierarchical response measures are started, wherein the behavior anomaly probability output by the hidden Markov model is one of the input weights of the risk score;

[0081] When the risk score exceeds the security threshold value, the first level response is triggered, the current session is temporarily frozen, the secondary biological authentication is forced to start, and the new session key is generated by the quantum key distribution device;

[0082] Based on the secondary response triggering formula The second threshold value is calculated, when the risk score exceeds the second threshold value, the secondary response is triggered, the encryption transmission channel is switched to the preset redundant link, the data packet that has not been encrypted is discarded, the minimum number of nodes required for signing is dynamically down-regulated from k to k-1, and only during the enabling period of the redundant link, wherein T2 is the second threshold value, T1 is the security threshold value, a is the weight of the abnormal rate of the blockchain node, J dis the node anomaly rate, β is the biometric anomaly probability weight, S w is the biometric anomaly probability;

[0083] The risk score increase coefficient is obtained, the difference between 1 and the risk score increase coefficient is calculated, a dynamic node threshold adjustment mechanism of the product of the difference value and the base threshold is constructed, and the dynamic node threshold is updated in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism. When the risk score continues to rise, the node threshold decreases according to a linear decay model;

[0084] When the node anomaly rate exceeds the dynamic node threshold, a three-level response is triggered, the blockchain sharding storage is stopped, the encrypted data stream is switched to local encrypted storage, the data mirror of the local backup center is started synchronously, and the data integrity is verified through the zero-knowledge proof gateway of the off-site key escrow center.

[0085] Biometric sensors (fingerprint / iris), operation behavior capture modules (millisecond-level record mouse movement coordinate sequence, keyboard keystroke interval), and network probes are deployed to collect user biometric features, operation trajectories, network environment data (such as transmission delay, attack traffic characteristics), and blockchain node status (response time delay, data consistency deviation) in real time. The biometric feature sampling timestamp and operation trajectory are aligned through a time synchronization matrix, and the spatial pattern (such as fingerprint texture direction gradient) of the biometric feature and the spatiotemporal feature (such as mouse acceleration change curve) of the operation trajectory are extracted using a convolutional neural network (CNN). The dynamic correlation coefficient of the biometric feature confidence and the operation trajectory anomaly degree can be calculated. When the coefficient is lower than the preset fusion threshold (calibrated based on historical attack features), the abnormal state transition probability of a hidden Markov model (HMM) is weighted, and the behavior anomaly probability P h is calculated. The real-time risk score is calculated according to the formula, and the 90% percentile of the normal distribution of the historical risk score is taken as the preset security threshold T 1。

[0086] The real-time risk score grading response trigger mechanism can be triggered: when the first-level response (R>T1) is triggered, the current session is temporarily frozen, the transmission rate is limited to 1 / 3 of the original bandwidth, the secondary biometric authentication (such as fingerprint+iris dual verification) is forced to start, the quantum key distribution device is called to generate a new session key, the lightweight SM4 algorithm is injected through the hardware encryption channel, and the redundant encryption rounds are enabled; when the second-level response (R>T2) is triggered, the second threshold T2 is dynamically calculated, the preconfigured redundant link is switched to, the homomorphic encryption layer is superimposed, the SM4 key is re-encrypted using the quantum session key, and the data packets that have not been completed are discarded. The minimum number of blockchain signatures is dynamically downgraded from k to k−1 (only during the effective period of the redundant link), and the switching timestamp is recorded through the blockchain storage record; when the third-level response (R>J d >J threshold ) is triggered, the dynamic node threshold J thresholdAccording to J threshold =J base ×(1−ΔR) real-time update (ΔR is the risk score increment coefficient), stop blockchain sharding storage, switch the encrypted data stream to local national encryption algorithm encrypted solid state storage, start the city backup center data mirroring through the dedicated fiber channel (SM4-GCM mode encryption transmission), transmit the key fragments to the off-site key hosting center through quantum encryption, verify the data integrity based on the zero-knowledge proof gateway (return timestamp signature voucher), isolate abnormal devices and encode the operation behavior data into a Merkle tree structure for storage for time sequence-causal tracing.

[0087] That is, the abnormal detection boundary can be optimized through a time sequence convolutional neural network, the behavior risk can be quantified combined with HMM, the transition from passive defense to active prediction can be realized, and risk-driven adaptive protection can be performed. Based on the dynamic node threshold adjustment mechanism of the risk score, the system resilience is improved on the premise of guaranteeing the byzantine fault tolerance; when the three-level response triggers the off-site disaster recovery, the mirror data integrity is verified through the zero-knowledge proof gateway. At the same time, in the secondary response, the redundant link is superimposed with the homomorphic encryption layer, the SM4 key is protected by the quantum session key, the transmission efficiency (encryption delay <10 ms) and the anti-quantum cracking ability are considered, and the dynamic down-regulation of the signature node number (k→k−1) ensures that the business does not interrupt in a high-risk environment.

[0088] Referring to Figure 5 , the calculating behavior abnormal probability through the hidden Markov model specifically includes:

[0089] The biological feature sampling timestamp is aligned with the operation behavior trajectory in millisecond level accuracy, a time synchronization matrix is constructed, and the operation behavior trajectory includes a mouse movement coordinate sequence and a keyboard stroke interval;

[0090] The current biological feature confidence and operation trajectory abnormality are obtained, the spatial pattern of the biological feature and the space-time feature of the operation trajectory are extracted based on a convolutional neural network, and a dynamic correlation coefficient of the two in a risk-sensitive operation window is calculated, wherein the spatial pattern of the biological feature is a fingerprint texture direction gradient, and the space-time feature of the operation trajectory is a mouse acceleration change curve;

[0091] A preset fusion threshold is obtained by calibrating the historical attack features and the dynamic environment, when the dynamic correlation coefficient is less than the fusion threshold, it is determined that the behavior is a high-risk abnormal behavior, and the abnormal state transition probability of the hidden Markov model is triggered.

[0092] Through a hardware-level interrupt triggering mechanism (such as a USB device polling frequency of 1 kHz), millisecond-level timestamps (accuracy ±0.5 ms) of biological feature sensors (fingerprint / iris scanners) and operation behavior capture devices (mouse, keyboard) are synchronously collected. A time synchronization matrix T sync is constructed, and the biological feature sampling points {t b1, t b2 ,...,t bn} and operation trajectory point {t o1 , t o2 ,...,t om Aligned according to time windows, forming a spatiotemporal mapping matrix {n×m}. A pre-trained convolutional neural network (CNN) is then used to extract the fingerprint texture orientation gradient features. The input fingerprint image is processed through three convolutional layers (3×3 kernels, stride 1), outputting a 128-dimensional histogram of oriented gradients (HOG) feature vector V. b Simultaneously capture the mouse movement coordinate sequence {(x i , y i , t i The instantaneous acceleration curve a(t) = d²s / dt² is calculated using second-order difference, combined with the keyboard typing interval Δt. key Generate spatiotemporal feature vector V o .

[0093] This allows for the calculation of biometric confidence level C within a risk-sensitive operation window (such as the 500ms period during the financial transaction confirmation phase). b With operational trajectory anomaly degree A o dynamic correlation coefficient Where cov is the covariance and σ is the standard deviation. When a user performs a high-risk operation (such as a large transfer), the ρ value is calculated in real time. A dynamic environment calibration model is trained based on a historical attack feature library (containing 2000+ malicious operation samples) and outputs a fusion threshold θ. fuse (Default value 0.85). When ρ < θ fuse When this occurs, it is judged as high-risk abnormal behavior. The abnormal state transition probabilities of the Hidden Markov Model (HMM) are weighted: the state transition probability a is... {ij} Adjust to a {ij} ×(1 + |ρ-θ fuse |), strengthening the transition weights for abnormal states (such as "data theft" state). This leads to the construction of a five-state HMM model (normal, low risk, medium risk, high risk, malicious), trained using the Baum-Welch algorithm with 100,000 historical behavior trajectories. Real-time input V b and V o The feature vector is used to output the probability P of abnormal behavior using the Viterbi algorithm. abnormal .

[0094] By using a millisecond-level time synchronization matrix to overcome the precision limitations of traditional second-level alignment, the modeling error of the spatiotemporal correlation between biometric features and operational trajectories is reduced. The fingerprint orientation gradient features extracted by CNN show improved robustness against affine transformation attacks compared to traditional grayscale histograms. Simultaneously, a fusion threshold θ calibrated based on historical attack features is used. fuseIt can dynamically adjust according to the intensity of network attacks, reducing the false positive rate under DDoS attacks. In addition, the HMM abnormal state transition probability weighting mechanism shortens the response time for high-risk behavior detection, thereby improving computational efficiency and meeting the requirements of financial-grade real-time risk control. The spatiotemporal feature combination of mouse acceleration curve and keyboard interval effectively identifies attacks that simulate legitimate operations.

[0095] Reference Figure 6 As shown, the specific measures for initiating a tiered response include:

[0096] When a Level 1 response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biometric authentication.

[0097] When a secondary response is triggered, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the timestamp is switched through the blockchain evidence record.

[0098] When a Level 3 response is triggered, the abnormal device is isolated and an audit trail is generated. The operational behavior data is encoded into a Merkle tree structure and stored in a remote key escrow center for time-series and causal tracing.

[0099] When the risk score output by the dynamic trust assessment model exceeds the security threshold, the Transmission Control Protocol (TCP) layer dynamically adjusts the sliding window size, forcibly reducing the data flow rate. A new session key is generated using a quantum key distribution device and injected into the SM4 algorithm core via a hardware encryption channel, simultaneously enabling redundant rounds of encryption (e.g., adding 8 random rounds to the standard 32-round encryption). Secondary biometric authentication employs fingerprint / iris dual-modal verification, with timestamps and operation trajectories aligned in real-time via a convolutional neural network, ensuring that data packets remain highly protected during authentication.

[0100] When the risk score exceeds the dynamically calculated second threshold, the link switching instruction takes effect with the joint signature of at least k-1 nodes in the blockchain network (k being the initial reconstruction threshold), and the minimum number of signing nodes is dynamically adjusted downwards. The homomorphic encryption layer operates on a dedicated cryptographic chip, using the SM4 key K. sm4 via quantum session key K q Encrypted as EK q (K sm4 The encrypted data is transmitted over redundant links. Blockchain nodes record switch timestamps using lightweight consensus mechanisms (such as Raft), generating immutable operation logs.

[0101] When the node anomaly rate J dWhen the dynamic node threshold is exceeded, stop the blockchain sharding storage, switch the encrypted data stream to the local SM4 / SM9 algorithm encrypted solid-state storage. The abnormal device is blocked by the network isolation module, and the operation behavior data (mouse trajectory, keystroke interval) is encoded into a Merkle tree through a time synchronization matrix, and the tree root hash is stored in a remote center. The city backup is transmitted through a dedicated fiber channel, the data block Merkle root hash is real-time chained, and the remote verification adopts a non-interactive zero-knowledge proof (such as zk-SNARKs), and the binding relationship between the proof data hash Hi and the chaotic parameter μ is verified.

[0102] Thus, the node threshold can be linearly attenuated by the risk score amplification coefficient (ΔR), the response level can be automatically strengthened as the threat escalates (such as k→k−1), the disaster recovery efficiency is improved, and the SM4 key update period is adjusted in reverse through the transmission index value D, so that the key rotation frequency of high-level archives is improved, and the quantum chaotic key (Logistic mapping generation) breaks through the periodic vulnerability of AES-CTR, expands the key space, and the three-level response automatically switches the three-layer storage architecture (local→city→remote), and the data lossless recovery is realized through the Merkle tree time consistency verification, and the recovery time is shortened compared with the RAID array. In addition, the operation behavior data is encoded into a Merkle tree and stored remotely, and the time-causal tracing (such as mouse movement coordinate sequence) of the blockchain evidence is stored, so that the data tampering positioning speed is improved.

[0103] Referring to Figure 7 When the node abnormal rate exceeds the node threshold, the three-layer architecture of local encryption storage, city backup center, and remote key management center is automatically switched, which specifically includes:

[0104] Based on the Byzantine fault tolerance theory, the response time delay, data consistency deviation, and historical credibility attenuation coefficient of the blockchain node are monitored in real time, and the dynamic node abnormal rate is calculated by , wherein T delay is the node response time delay, T max is the maximum allowed time delay threshold, D inconsist is the number of bytes of node data difference from the main chain, D threshold is the difference tolerance threshold, C trust is the credibility attenuation coefficient based on historical behavior, and α, β and γ are weight coefficients and satisfy α+β+γ=1.

[0105] When J d >J threshold , the three-level response is triggered, wherein J threshold is the real-time threshold output by the dynamic node threshold adjustment mechanism, and the switching instruction is jointly signed by at least k−1 trusted nodes to take effect, wherein k is the initial reconstruction threshold.

[0106] The encrypted data fragments of incomplete transmission are temporarily stored in the local state secret algorithm encrypted solid state memory to form a local encrypted storage layer, and a temporary access token is generated;

[0107] Through the dedicated fiber channel synchronous data mirroring, the SM4-GCM mode is used to encrypt the transmission channel, and the Merkle root hash of the data block is recorded to the local blockchain to form the city backup center layer;

[0108] The key fragments are transmitted to the remote center after being encrypted by quantum key, and the data integrity is verified by the hosting center based on zero-knowledge proof, and the timestamp signature voucher is returned after verification, and the remote key hosting center layer is constructed;

[0109] When the node abnormal rate exceeds the threshold and the k-1 trusted nodes are verified, the three-level response is triggered, and when the node abnormal rate decreases to the safety threshold, the data is recovered in the priority order of city backup center> remote key hosting center> local encrypted storage, and the data time sequence consistency is verified through the audit track of the Merkle tree structure in the recovery process.

[0110] Based on the Byzantine fault tolerance theory, the response time delay, data consistency deviation and historical credibility decay coefficient of the blockchain node are collected in real time, the dynamic node abnormal rate is calculated by formula, the risk score increase coefficient is combined, and the node threshold is dynamically adjusted by the linear decay model, so that the threshold is automatically reduced when the risk increases, and the sensitivity to abnormal nodes is improved. That is, when J d >J threshold At least k-1 trusted nodes (k is the initial reconstruction threshold) are needed to jointly sign the switching instruction to take effect. In the local encrypted storage layer, the encrypted data fragments of incomplete transmission are temporarily stored in the solid state memory encrypted by the state secret algorithm (such as SM4 / SM9), a temporary access token is generated to control access permission, in the city backup center layer, through the dedicated fiber channel synchronous data mirroring, the SM4-GCM mode is used to encrypt the transmission channel, and the Merkle root hash of the data block is recorded to the local blockchain in real time to ensure the transmission integrity and traceability, in the remote key hosting layer, the key fragments are transmitted to the remote center after being encrypted by quantum key, and the hosting center verifies the data integrity based on zero-knowledge proof (such as zk-SNARKs), and returns the timestamp signature voucher after verification. When the node abnormal rate decreases to the safety threshold, the data is recovered in the priority order (city backup center> remote hosting center> local storage), and the data time sequence consistency is verified through the audit track of the Merkle tree structure in the recovery process to ensure no tampering.

[0111] Thus, the threshold value can be dynamically adjusted based on the Byzantine fault tolerance and credibility decay model, so that the disaster recovery response speed is improved, the node fault switching delay is shortened, and the three-layer architecture (local-city-remote) realizes disaster recovery level coverage: the local layer guarantees zero switching (RTO≈0), the city layer guarantees RPO=0 through fiber encryption and Merkle root hash, and the remote layer provides logical consistency through quantum encryption and zero-knowledge proof. At the same time, the SM4 encryption of solid-state storage reduces the local layer overhead; the SM4-GCM mode encrypts the city fiber channel, reduces the computing load, and the quantum encryption key fragmentation combined with zero-knowledge proof can solve the key distribution risk of RSA remote transmission, and the verification throughput is improved through the GPU parallel architecture. In addition, the Merkle tree audit trail supports time-causal tracing, which improves the positioning speed of traditional checksum data tampering, improves the data consistency of the recovery process, optimizes resource allocation through the priority recovery mechanism, and can solve the problem of key data delay caused by unordered recovery.

[0112] Referring to Figure 8 As shown, the combination of zero-knowledge proof verifies the authenticity of the data, and the verification result is fed back to the dynamic trust evaluation model in real time, which specifically includes:

[0113] Only when cross-domain transmission is enabled, a zero-knowledge proof gateway is generated for each data fragment, and the non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies Where π i is the proof credential, and com(μ) is the commitment value of the Logistic chaotic parameter μ;

[0114] Through the GPU-accelerated parallel proof verification architecture, the data fragment proofs received by the city backup center and the remote key hosting center are verified synchronously;

[0115] The verification result is aggregated into a credibility index according to the fragment position weight wi, and when the credibility index is less than the historical actual running threshold value, the weight correction of the dynamic trust evaluation model is triggered.

[0116] A special gateway hardware is deployed at the cross-domain transmission boundary node, and is activated only when cross-domain communication is detected. At the same time, the gateway integrates a non-interactive zero-knowledge proof (zk-SNARKs) generation module, and the input parameters are the data fragment hash value H i and the Logistic chaotic mapping parameter μ, and the output is the proof credential π i . The commitment value com(μ) of μ is generated through the Pedersen commitment algorithm and is bound to π iIn this process, the authenticity of the parameters is ensured. During the proof generation phase, after the data fragments are encrypted with SM4, the hash Hi=SHA256(datai) is extracted, and the Logistic chaotic mapping parameter μ (from the quantum key distribution device) is called to calculate the commitment com(μ)=g μ h r (g and h are generators, r is a random number). Prove π using zk-SNARKs circuits. i Satisfying relation V erify (π i H i com(μ))=1. A multi-GPU cluster is used to build the verification engine, with each GPU thread independently processing a single shard proof π. i The local backup center and the remote key hosting center simultaneously receive fragmented data. The verification engine directly connects to the storage nodes in both locations via a high-speed RDMA network to achieve real-time parallel verification. During the parallel verification phase, the local and remote centers will share the received fragmented data {π i H i Distribute the data to the GPU verification queue, and simultaneously execute the verification output v in parallel on the GPU thread. i .

[0117] The weight w is dynamically set according to the fragment location (e.g., edge / core region). i (core area w) i =0.7, edge w i =0.3), design a weight allocation algorithm. The aggregation module is based on weight w. i Calculate T rustindex By comparing with historical thresholds (the 90th percentile calculated based on data from the past 30 days), the aggregation formula can be used: T rustindex =∑(v i ×w i ), where v i ∈{0,1} represents the single-shard verification result. Through the dynamic trust evaluation model interface, when T... rustindex When the value falls below the historical operating threshold (such as the 90th percentile), a model weight correction signal is triggered, adjusting the node credibility weight in the risk score (such as increasing the blockchain node weight γ from 0.3 to 0.5).

[0118] It can be achieved through μ and H iThe binding of the chaos parameter prevents the chaos parameter from being tampered with, and resists parameter replacement attacks. The tampering detection rate is improved. The non-interactive proof reduces the cross-domain communication rounds and reduces the risk of man-in-the-middle attacks. At the same time, GPU parallel verification increases the throughput, meets the real-time requirements of synchronous verification in the same city / remote place, and the weight aggregation mechanism reduces invalid alarms and reduces the model false alarm rate. In addition, based on the dynamic correction of the historical threshold, when the system is subjected to continuous attacks, the sensitive parameter weight is automatically strengthened, and the recovery time is shortened compared with the static model.

[0119] In summary, the advantages of the present application are that by using quantum dynamic key, risk-driven hierarchical response and blockchain disaster recovery switching, an active multi-protection system is constructed to realize efficient and secure transmission against quantum attacks and dynamically adapting to network risks.

[0120] The basic principles, main features and advantages of the present application are shown and described above. Those skilled in the art should understand that the present application is not limited by the above examples, and the above examples and descriptions in the specification are only the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection required by the present application is defined by the appended claims and their equivalents.

Claims

1. A data security transmission method based on multiple layers of protection for digital archives, characterized in that, Including: Perform two-way authentication between the quantum key distribution device and the file transfer terminal, generate a random seed in real time based on the quantum state, perform iterative partitioning on the quantum seed in combination with the Logistic chaotic mapping, perform non-linear transformation according to the chaotic trajectory value, and output variable-length key shards, denoted as the dynamic session key. Use the lightweight SM4 algorithm to symmetrically encrypt the file data to obtain sharded encrypted data, and the key update frequency is dynamically adjusted by the monitored real-time transmission index value; Collect the biometric characteristics, operation behavior trajectory, and network environment data of the user device in real time, calculate the behavior anomaly probability through the hidden Markov model, calculate the risk score through the safety margin, and trigger a hierarchical response when the score value exceeds the safety threshold. The risk score is the sum of the device vulnerability score, the HMM behavior anomaly probability, and the network attack intensity index weighted. The safety threshold is preset through historical security event data; For the sharded encrypted data, use n nodes to generate key shards, and at least k shards can reconstruct the signature to monitor the status of the blockchain nodes. When the node anomaly rate exceeds the node threshold, automatically switch to a three-layer architecture of local encrypted storage,同城备份中心, and off-site key escrow center, where k < n, and the node threshold is derived based on the Byzantine fault tolerance theory and calculated in combination with the node credibility decay model; Use a filter to quickly verify the integrity of the data block, verify the data authenticity in combination with zero-knowledge proof, and the verification result is fed back to the dynamic trust assessment model in real time to update the risk score and generate an audit trail. Achieve the time-sequence and causal traceability of operation behaviors through blockchain evidence storage, and enable the zero-trust gateway step for cross-domain transmission scenarios. The zero-trust gateway performs mandatory continuous verification on cross-domain transmission; The specific process of symmetrically encrypting the file data using the lightweight SM4 algorithm to obtain sharded encrypted data includes: Collect the network data transmission delay time, network effective data transmission rate, and the real-time workload of the blockchain nodes in real time, and calculate the comprehensive index value according to the historical weight coefficients of the network data transmission delay time, network effective data transmission rate, and the real-time workload of the blockchain nodes; Obtain the normal distribution of the historical risk scores, calculate the 90th percentile as the safety threshold, and trigger the key update mechanism when the index value exceeds the safety threshold; Invoke the quantum key distribution device to generate a new quantum random seed, re-run the iterative calculation process of the Logistic chaotic mapping to generate a new session key, inject the newly generated key into the SM4 algorithm through the hardware encryption channel, and synchronously update the sharded keys of the blockchain nodes; Inversely associate the time interval of key update with the comprehensive index value. When the network transmission state is worse, the key replacement frequency is higher, and the update period is dynamically scaled according to the security level coefficient of the file. High-classified files trigger more frequent key rotations in a bad network environment; The specific process of calculating the behavior anomaly probability through the hidden Markov model, calculating the risk score through the safety margin, and triggering a hierarchical response when the score value exceeds the safety threshold includes: Based on abnormal behavior samples, network attack feature data, and node failure records from historical security incidents, a temporal convolutional neural network is used to optimize the anomaly detection boundary and construct a dynamic trust assessment model. Real-time collected user biometrics, operation behavior trajectories, network environment data, and blockchain node status data are input into the dynamic trust assessment model. The probability of abnormal behavior is calculated through a hidden Markov model. Combined with device vulnerability scores and network attack intensity indices, a comprehensive risk score is calculated according to a weighted formula, and graded response measures are initiated. The probability of abnormal behavior output by the hidden Markov model is used as one of the input weights of the risk score. When the risk score exceeds the security threshold, a Level 1 response is triggered, temporarily freezing the current session, forcibly initiating secondary biometric authentication, and generating a new session key through the quantum key distribution device; Based on the second-level response triggering formula Calculate the second threshold. When the risk score exceeds the second threshold, a secondary response is triggered: the encrypted transmission channel is switched to a pre-set redundant link, incomplete encrypted data packets are discarded, and the minimum number of nodes required for signing is dynamically reduced from k to k-1, taking effect only while the redundant link is enabled. Here, T2 is the second threshold, T1 is the security threshold, α is the blockchain node anomaly rate weight, and J... d S represents the node anomaly rate, β represents the biometric anomaly probability weight, and S... w This represents the probability of an anomaly in biological characteristics. Obtain the risk score increase coefficient, calculate the difference between 1 and the risk score increase coefficient, construct a dynamic node threshold adjustment mechanism by multiplying the difference by the base threshold, and update the dynamic node threshold in real time based on the real-time risk score and the dynamic node threshold adjustment mechanism, so that when the risk score continues to rise, the node threshold decreases according to the linear decay model. When the node anomaly rate exceeds the dynamic node threshold, a level 3 response is triggered, stopping the blockchain shard storage, switching the encrypted data stream to local encrypted storage, synchronously starting the data mirroring of the same-city backup center, and verifying data integrity through the zero-knowledge proof gateway of the off-site key escrow center.

2. The data security transmission method based on multiple protections of digital archives according to claim 1, characterized in that, The process of generating random seeds in real time based on quantum states, iteratively dividing the quantum seeds into blocks using Logistic chaotic mapping, performing nonlinear transformations based on chaotic trajectory values, and outputting variable-length key slices specifically includes: The quantum key distribution device and the file transmission terminal are mutually authenticated through a hardware encryption interface, generating a quantum entropy source sequence; Using the Logistic chaotic mapping formula The quantum seed is iteratively divided into blocks, where the initial value x0 is taken from the quantum entropy source; Each data block is nonlinearly compressed based on the chaotic trajectory value, and the compression rate is dynamically matched to the archive data type to output variable-length key fragments; The session key is generated by combining key fragments, and the key length is proportional to the file fragment size.

3. The data security transmission method based on multiple protections of digital archives according to claim 2, characterized in that, The calculation of abnormal behavior probability using a hidden Markov model specifically includes: The biometric sampling timestamps and operation behavior trajectories are aligned with millisecond-level precision to construct a time synchronization matrix. The operation behavior trajectory includes mouse movement coordinate sequences and keyboard key press intervals. The system obtains the current biometric confidence level and operation trajectory anomaly level, extracts the spatial pattern of biometrics and the spatiotemporal features of operation trajectory based on convolutional neural network, and calculates the dynamic correlation coefficient between the two within the risk-sensitive operation window. The spatial pattern of biometrics is the fingerprint texture direction gradient, and the spatiotemporal features of operation trajectory are the mouse acceleration change curve. Historical attack characteristics are obtained and a preset fusion threshold is set for dynamic environment calibration. When the dynamic correlation coefficient is less than the fusion threshold, it is judged as a high-risk abnormal behavior, triggering the weighted abnormal state transition probability of the Hidden Markov Model.

4. The data security transmission method based on multiple protections of digital archives according to claim 3, characterized in that, The specific measures for initiating a tiered response include: When a Level 1 response is triggered, the current session transmission rate is limited to one-third of the original bandwidth, and redundant encryption rounds of the lightweight SM4 algorithm are enabled during the secondary biometric authentication. When a secondary response is triggered, a homomorphic encryption layer is superimposed on the redundant link, the SM4 key is re-encrypted using a quantum dynamic session key, and the timestamp is switched through the blockchain evidence record. When a Level 3 response is triggered, the abnormal device is isolated and an audit trail is generated. The operational behavior data is encoded into a Merkle tree structure and stored in a remote key escrow center for time-series and causal tracing.

5. A data security transmission method based on multiple protections for digital archives according to claim 4, characterized in that, The automatic switch to a three-tier architecture—local encrypted storage, same-city backup center, and off-site key hosting center—when the node failure rate exceeds the node threshold specifically includes: Based on Byzantine fault tolerance theory, the response latency, data consistency deviation, and historical reliability decay coefficient of blockchain nodes are monitored in real time. Calculate the dynamic node anomaly rate, where T delay T represents the node response latency. max D is the maximum allowable delay threshold. inconsist D represents the number of bytes differing between node data and the main chain. threshold C is the difference tolerance threshold. trust Let α be the credibility decay coefficient based on historical behavior, and let α, β and γ be weighting coefficients that satisfy α+β+γ=1; When J d >J threshold Triggering a three-level response, where J threshold The real-time threshold output by the dynamic node threshold adjustment mechanism is used, and the switching instruction is jointly signed by at least k-1 trusted nodes, where k is the initial reconstruction threshold. The encrypted data that has not been fully transmitted is temporarily stored in fragments on a local solid-state storage device encrypted with the national cryptographic algorithm to form a local encrypted storage layer and generate a temporary access token. Data mirroring is synchronized through a dedicated fiber optic channel, the transmission channel is encrypted using SM4-GCM mode, and the Merkle root hash of data blocks is recorded to the local blockchain, forming a local backup center layer. The key fragments are encrypted using quantum key distribution and transmitted to a remote center. The hosting center verifies the data integrity based on zero-knowledge proof. After successful verification, a timestamp signature certificate is returned, thus constructing a remote key hosting center layer. When the node anomaly rate exceeds the threshold and the signature verification of k-1 trusted nodes passes, a level 3 response is triggered. When the node anomaly rate drops to the security threshold, data is restored in the order of priority: same-city backup center > off-site key hosting center > local encrypted storage. During the restoration process, the timing consistency of the data is verified by the Merkle tree structure audit trail.

6. A data security transmission method based on multiple protections for digital archives according to claim 5, characterized in that, The process of verifying data authenticity using zero-knowledge proofs, with the verification results fed back to the dynamic trust assessment model in real time, specifically includes: The zero-knowledge proof gateway is enabled only during cross-domain transfers. A non-interactive zero-knowledge proof is generated for each data fragment. This non-interactive zero-knowledge proof contains the binding relationship between the data hash value Hi and the chaotic encryption parameter μ, and satisfies... , where π i To prove the credentials, com(μ) is the commitment value of the Logistic chaos parameter μ; A GPU-accelerated parallel proof verification architecture is used to simultaneously verify data fragment proofs received by the same-city backup center and the off-site key escrow center. Verification results The credibility index is aggregated according to the weight wi of the fragment location. When the credibility index is lower than the historical actual operating threshold, the weight adjustment of the dynamic trust assessment model is triggered.

Citation Information

Patent Citations

  • Data security transmission method in cloud platform salary management system

    CN120498768A

  • Distributed intelligent authentication method based on dynamic multi-modal fusion

    CN120546922A