Dynamic hierarchical encryption system for multi-tenant e-commerce data

By combining the fruit fly algorithm with knowledge graphs, the encryption strength of a multi-tenant e-commerce platform is dynamically adjusted, solving the problem that encryption grading in existing technologies lags behind actual needs. This enables adaptive adjustment of encryption strategies and meets real-time requirements, thereby improving the user experience.

CN120915508AInactive Publication Date: 2025-11-07YUNNAN HUAWU TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511027869.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-11-07
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing encryption systems in multi-tenant e-commerce platforms employ fixed-field encryption strategies, making it difficult to dynamically adjust encryption strength based on data usage scenarios. This results in encryption levels lagging behind actual needs, impacting system latency and user experience.

Method used

By employing the fruit fly algorithm in conjunction with knowledge graphs, and through a data perception and hierarchical module, a multi-tenant knowledge graph construction module, a key parameter encoding module, and an encryption strategy execution module, the encryption strength is dynamically adjusted to achieve adaptive adjustment of the encryption strategy.

Benefits of technology

It achieves dynamic adaptive adjustment of encryption strength, reduces computational overhead, ensures system compliance within real-time requirements, and improves user experience in multi-tenant scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915508A_ABST
    Figure CN120915508A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic hierarchical encryption system for multi-tenant e-commerce data, and relates to the technical field of multi-tenant data security, the system comprises an encryption management center, the encryption management center is in communication connection with the following modules: a data sensing and grading module, which is used for collecting multi-source context data of an e-commerce platform, and sending the multi-source context data to the encryption management center; performing basic sensitivity level division on the context data; and the multi-tenant knowledge graph construction module is used for constructing a multi-tenant knowledge graph based on the tenant-data-authority association network in combination with the multi-source context data. According to the method, dynamic self-adaptive adjustment of encryption strength is realized through cooperation of the fruit fly algorithm and the knowledge graph, the system dynamically optimizes combination of key length and the encryption algorithm based on data grading labels and real-time context data, and the fruit fly algorithm searches an optimal solution through iteration, so that the system has high encryption efficiency while ensuring compliance. And encryption delay is controlled within a real-time requirement range, so that the user experience in a multi-tenant scene is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of multi-tenant data security, and particularly relates to a dynamic hierarchical encryption system for multi-tenant e-commerce data. BACKGROUND

[0002] With the popularity of cloud computing and SaaS (Software as a Service) mode, e-commerce platforms are usually based on a multi-tenant architecture to provide shared hardware, software and data storage resources for multiple enterprises or merchants. Although this mode reduces costs and improves resource utilization, it also brings challenges to data security and privacy protection. Moreover, e-commerce platforms have high real-time requirements, and encryption operations may increase system latency, affecting user experience.

[0003] In the prior art, encryption systems mostly use static encryption strategies such as fixed field encryption, which are difficult to dynamically adjust encryption strength according to data usage scenarios, resulting in encryption hierarchy lagging behind actual needs. Therefore, how to construct a multi-tenant knowledge graph using context data including data attributes, user behavior and system status, and dynamically adjust encryption algorithms using a fruit fly algorithm to achieve adaptive adjustment of encryption strength, balancing security and performance, is a problem to be solved by the present application. For this reason, a dynamic hierarchical encryption system for multi-tenant e-commerce data is proposed. SUMMARY

[0004] The purpose of the present application is to provide a dynamic hierarchical encryption system for multi-tenant e-commerce data to solve the problems raised in the background.

[0005] To solve the above technical problems, the technical solution adopted by the present application is as follows: A dynamic hierarchical encryption system for multi-tenant e-commerce data includes an encryption management center, which is communicatively connected to the following modules, wherein: A data perception hierarchical module is used to collect multi-source context data of an e-commerce platform and divide the context data into basic sensitivity levels. A multi-tenant knowledge graph construction module is used to construct a multi-tenant knowledge graph based on a tenant-data-permission association network in combination with multi-source context data, providing a semantic reasoning basis for dynamic key allocation. A key parameter encoding module is used to encode key parameters as demand vectors for fruit fly algorithm iterative search. A key dynamic allocation module is used to combine data hierarchy and knowledge graph to search for optimal key length and encryption algorithm combination based on fruit fly algorithm iterative search, reducing computational overhead. An encryption strategy execution module is used to call an encryption engine to implement differentiated encryption according to the knowledge graph and optimized key, realizing non-perception switching of encryption strategies.

[0006] The further improvement of the technical scheme of the application is that the data perception grading module comprises a multi-source context collection unit and a data attribute analysis unit. The multi-source context collection unit is configured to collect three types of context data of data attributes, user behaviors and system states of the e-commerce platform in real time through API interfaces, log analysis, sensor networks and the like. The data attribute analysis unit extracts the structured features of the data based on the collected context data, and divides the context data into basic sensitivity levels including public, internal, confidential and top secret by combining the pre-constructed data sensitivity division rules, so as to realize the synchronization of grading and business scenarios.

[0007] The further improvement of the technical scheme of the application is that the multi-source context collection unit comprises: API interfaces, log analysis tools and sensor network protocols are deployed on the e-commerce platform, structured data attributes are actively pulled through the API interfaces, log streams are synchronously monitored, and sensor networks are integrated, so as to uniformly access multi-source context data; Based on the pre-defined context data classification rules, the original data is classified into three types of context data of data attributes, user behaviors and system states, and the multi-source context data is standardized, the key fields of time stamp and tenant identifier are unified, the format difference is eliminated, and an analyzable context data set is constructed; A data pipeline is constructed by using the stream processing framework of Kafka, the standardized multi-source data is stored by tenant ID and business scenario partition, three types of contexts are associated by using a stream computing engine, and a context event stream with a time window is generated.

[0008] The further improvement of the technical scheme of the application is that the data attribute analysis unit comprises: The context data output by the multi-source context collection unit is received and analyzed, structured feature fields including data types, field lengths and value range are extracted, and implicit sensitive information is identified by using semantic analysis technology to generate a structured feature vector; Based on the pre-constructed data sensitivity division rules, the category to which the context data belongs is analyzed, and then a suitable basic sensitivity level is divided, which is public, internal, confidential and top secret.

[0009] The further improvement of the technical scheme of the application is that the multi-tenant knowledge graph construction module comprises a graph structured modeling unit and a graph updating unit. The graph structured modeling unit is configured to analyze the collected multi-source context data, and the data sharing requirements and permission differences among tenants, define triples of the knowledge graph, and construct a multi-tenant knowledge graph based on a tenant-data-permission association network. A graph updating unit is configured to dynamically update the knowledge graph through stream computing, and respond to events of tenant expansion and permission change.

[0010] The further improvement of the technical scheme of the present application is that the graph structured modeling unit comprises: The multi-source context data is parsed, the semantic features and the correlation in the context data are analyzed, the cross-tenant data sharing demand and the permission difference are identified in combination with the tenant business scenario, and a demand matrix is formed; Based on the analysis result, the core triple of tenant-data-permission of the knowledge graph is defined, the entity type and the relationship attribute are clarified, and the graph mode supporting dynamic expansion is constructed; According to the triple rule, the tenant, the data resource and the permission policy are mapped into the graph node and the edge, the multi-tenant correlation network is constructed through the graph database, and the structured storage of the data sharing relationship between tenants and the automatic verification of the permission constraint are performed.

[0011] The further improvement of the technical scheme of the present application is that the graph updating unit comprises: The distributed message queue (Kafka) is used to capture the tenant expansion (new tenant / data resource) and the permission change (policy adjustment / role update) in real time, and the event parser is used to convert the original data into a structured message, extract the key fields including tenant ID, change type and timestamp, and ensure the semantic consistency of the event; The parsed event triggers the pre-defined update rule engine, matches the graph operation according to the event type, detects potential conflicts through the version control mechanism, generates a conflict-free incremental update instruction set, and ensures the consistency of the graph data; The update instruction set is executed through the Cypher bulk interface of the graph database to perform atomic writing, synchronously updates the node, the edge and the associated metadata, triggers the incremental synchronization of the graph cache and the search engine after completion.

[0012] The further improvement of the technical scheme of the present application is that the key parameter coding module comprises: The key parameters of the encryption system are structurally parsed, the key key fields including the key length, the encryption algorithm type and the permission identification bit are extracted, and they are mapped to the pre-defined numerical space for normalization processing to eliminate the dimensional difference, ensure the parameter value domain to adapt to the search range of the fruit fly algorithm, and generate a standardized parameter vector; According to the iteration characteristics of the fruit fly algorithm, the standardized parameter vector is decomposed into a plurality of dimensional sub-vectors, each sub-vector corresponds to the individual position in the algorithm, and an initial solution space vector meeting the iteration requirements of the algorithm is formed; The generated vector is subjected to business constraint checking, invalid solutions are removed, and the vector value range is compressed through a nonlinear transformation to meet the convergence condition of the fruit fly algorithm, and finally the optimized demand vector is output for use in iterative search of the algorithm.

[0013] The further improvement of the technical scheme of the application is that the key dynamic allocation module comprises: Based on the data classification result and the permission policy in the knowledge graph, the data is classified and mapped, and based on the classification result, a plurality of initial key parameter combinations (including encryption algorithm type, key length, and permission identification bit) are randomly generated to ensure covering the full parameter space. The fruit fly algorithm is used to simulate the fruit fly olfactory search behavior to perform two-dimensional evaluation on each initial key combination, including security score and performance overhead, wherein the security score quantifies security based on encryption strength and attack resistance, and the performance overhead is analyzed by calculating encryption / decryption time consumption and resource occupancy rate, and then a fitness score is obtained through weighted analysis to screen out candidate combinations balanced in security and efficiency. According to the fitness score, the iteration mechanism of the fruit fly algorithm is used to retain high-score combinations, randomly disturb the parameters of low-score combinations, generate a new generation of key combinations, and repeat the evaluation-screening-disturbance process until the convergence condition is met, so that the fluctuation of the fitness score is less than a preset fluctuation threshold, and a globally optimal key combination is output.

[0014] The further improvement of the technical scheme of the application is that the encryption policy execution module comprises: Based on the permission policy of the knowledge graph and the data classification label, the optimal key combination is matched, and the encryption parameters are obtained from the key dynamic allocation module, bound to the corresponding data node or API interface, and an encryption instruction set is generated. According to the encryption instruction set, the encryption engine API is called, the algorithm library is loaded on demand, the optimized key parameters are injected, and the encryption / decryption operation is triggered, and through the proxy mode, the hot switching is performed to make the encryption process zero-interrupt and compatible with the multi-tenant heterogeneous environment. When the permission policy or the key is updated, the change event is listened to in real time, the current encryption task is suspended through a lightweight lock mechanism, the key combination corresponding to the new policy is switched to, and the engine state is updated synchronously to ensure the continuity of encryption and the consistency of the policy.

[0015] Due to the adoption of the above technical scheme, the application has the following technical progress compared with the prior art: 1. This invention provides a dynamic hierarchical encryption system for multi-tenant e-commerce data. Through the collaboration of the fruit fly algorithm and knowledge graph, the encryption strength is dynamically and adaptively adjusted. The system dynamically optimizes the key length and encryption algorithm combination based on data hierarchical tags and real-time context data. Furthermore, the fruit fly algorithm reduces computational overhead by iteratively searching for the optimal solution, enabling the system to control encryption latency within the real-time requirements while ensuring compliance, thus significantly improving the user experience in multi-tenant scenarios.

[0016] 2. This invention provides a dynamic hierarchical encryption system for multi-tenant e-commerce data. By constructing a knowledge graph based on a tenant-data-permission association network, it achieves fine-grained permission control and dynamic key allocation. Through graph structured modeling, it analyzes the data sharing needs and permission differences among tenants, generating semantic permission policies. At the same time, it responds to tenant expansion or permission change events through streaming computing, ensuring the real-time consistency of permission policies and key allocation, thus meeting the high-concurrency and dynamically changing permission management needs in e-commerce scenarios. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the workflow of the present invention; Figure 2 This is a schematic diagram of the workflow of the key dynamic allocation module of the present invention. Detailed Implementation

[0018] The present invention will now be described in detail with reference to the accompanying drawings.

[0019] Example 1, such as Figure 1 , Figure 2 As shown, this invention provides a dynamic hierarchical encryption system for multi-tenant e-commerce data, including an encryption management center. The encryption management center is communication-connected to the following modules, wherein: The data perception and grading module is used to collect multi-source context data from e-commerce platforms and classify the context data into basic sensitivity levels. The data perception and grading module includes a multi-source context collection unit and a data attribute analysis unit. The multi-source context collection unit is configured to collect three types of context data of data attributes, user behaviors and system states of the e-commerce platform, and collect the data in real time through API interfaces, log analysis, sensor networks and the like. The API interfaces, log analysis tools and sensor network protocols are deployed on the e-commerce platform, the structured data attributes are actively pulled through the API interfaces, the log streams are synchronously monitored, the sensor networks are integrated, the multi-source context data is uniformly accessed, the original data is classified into the three types of context data of data attributes, user behaviors and system states based on predefined context data classification rules, the multi-source context data is standardized, the key fields of timestamps and tenant identifiers are unified, the format differences are eliminated, the analyzable context data set is constructed, the data pipeline is constructed by using the stream processing framework of Kafka, the standardized multi-source data is stored according to tenant IDs and business scenarios, the three types of contexts are associated through the stream computing engine, and the context event stream with a time window is generated. The working content of the multi-source context collection unit is as follows: The multi-source context collection unit collects full data of the e-commerce platform by a combination of active pulling and passive listening, wherein, for structured data attributes, a standardized API interface (RESTful / GraphQL) is deployed to actively pull, support page query and incremental synchronization, and ensure data integrity; for semi-structured logs (user operation logs, system error logs, etc.), a log analysis tool of Fluentd / Logstash is integrated to extract key fields based on regular expressions and JSON parsing rules; for physical environment data (computer room temperature and humidity, server load, etc.), IoT devices are integrated through a sensor network protocol (MQTT) to report device status in real time, and then the three types of data are aggregated through a unified gateway to form raw data streams containing data attributes, user behavior, and system status; the data is divided into three types of context based on predefined classification rules, namely data attributes, user behavior, and system status, wherein the data attributes include field name, data type, and storage location, the user behavior includes operation type, access frequency, and device fingerprint, and the system status includes resource load, security event, and network topology; the heterogeneous data is uniformly processed by a standardized engine, the unified timestamp is set to UTC time zone and is accurate to milliseconds, the tenant identifier is replaced by a globally unique ID instead of a system internal code, the numerical fields are normalized to a fixed range, the text fields are de-duplicated and a dictionary mapping is established, and finally a standardized context data set with consistent format and clear semantics is generated to eliminate format barriers between multi-source data; the standardized data is connected to a Kafka stream processing framework, and is stored in partitions according to tenant ID and business scenario to ensure tenant data isolation and efficient use of computing resources; and a real-time computing pipeline is built by a stream computing engine such as Flink / Spark Streaming to perform correlation analysis on the three types of context, including time window aggregation, multi-source event fusion, and state snapshot generation, wherein the user behavior frequency is counted in a 5-minute window for time window aggregation, the data attributes and user behavior are associated as complete transaction events to realize multi-source event fusion, the performance bottleneck points in the event stream are marked in combination with system status data to generate a state snapshot, and then a context event stream with a time window is output; The data attribute analysis unit extracts structured features of data based on the collected context data, divides the context data into basic sensitivity levels including public, internal, confidential, and top secret according to pre-constructed data sensitivity division rules, realizes hierarchical and business scenario synchronization, receives and analyzes the context data output by the multi-source context collection unit, extracts structured feature fields including data type, field length, and value range, identifies implicit sensitive information through semantic analysis technology, generates a structured feature vector, analyzes the category to which the context data belongs based on the pre-constructed data sensitivity division rules, and then divides the appropriate basic sensitivity levels, which are public, internal, confidential, and top secret, respectively. The working content of the data attribute analysis unit is: Receiving the standardized context data output by the multi-source context collection unit, analyzing the data type (such as string, numerical value, date), field length and value range through pattern matching technology, for non-explicit sensitive fields, using semantic analysis technology, combining regular expressions and BERT-based entity recognition to extract implicit sensitive information, and mapping it to a pre-defined feature set, finally, encoding structured features and semantic labels into multi-dimensional vectors; based on the pre-constructed data sensitivity evaluation system, a dynamic index set is constructed from three core dimensions to quantify data sensitivity, including data leakage impact, access frequency and user permission level, wherein, based on the pre-constructed sensitivity division rule base, the structured feature vector is dynamically classified, the rule base uses a decision tree model, combined with business scenario weights and compliance requirements, to define trigger conditions for four basic sensitivity levels including public, internal, confidential and top secret, wherein public is no sensitive feature and value domain is public, such as commodity classification label, internal is low sensitive feature (such as employee ID) or field length reversible information, confidential is high sensitive feature (such as ID card number, bank card number), top secret meets the confidential condition and belongs to core business data (such as transaction password, biological characteristics), by real-time matching of feature vectors and rule base, automatically labeling the basic sensitivity level of each data; The multi-tenant knowledge graph construction module is used to construct a multi-tenant knowledge graph based on a tenant-data-permission association network in combination with multi-source context data, to provide a semantic reasoning basis for dynamic key allocation, and the multi-tenant knowledge graph construction module includes a graph structured modeling unit and a graph updating unit. The graph structured modeling unit is used to analyze the collected multi-source context data, as well as data sharing needs and permission differences between tenants, define triples of the knowledge graph, construct a multi-tenant knowledge graph based on a tenant-data-permission association network, analyze semantic features and association relationships in the context data, identify cross-tenant data sharing needs and permission differences in combination with tenant business scenarios, form a demand matrix, define core triples of tenant-data-permission of the knowledge graph based on the analysis results, clarify entity types and relationship attributes, construct a graph pattern supporting dynamic expansion, map tenants, data resources and permission policies to graph nodes and edges according to triple rules, construct a multi-tenant association network through a graph database, and perform structured storage of inter-tenant data sharing relationships and automatic verification of permission constraints. The working content of the graph structured modeling unit is: Deep analysis of multi-source context data, extraction of semantic features (such as data theme, business meaning) and correlation (such as user-order-goods interaction chain), and analysis of cross-tenant data sharing needs through natural language processing (NLP) technology to analyze unstructured fields (such as user notes, log text), identify implicit business entities and their attributes, and analyze cross-tenant data sharing needs based on demand analysis. Based on demand analysis, a demand matrix is constructed, with tenants as rows and data resources as columns, marking the necessity of sharing (high / medium / low) and the difference in permissions (read-only / editable); Based on the demand matrix, define the core triple structure of the knowledge graph: tenant-data resource-permission policy, and clearly define entity types and relationship attributes, including tenant, data resource, and permission policy, tenant includes tenant ID, industry attribute, and compliance requirements, data resource is divided into structured data, unstructured data, and API interface, permission policy defines access control rules and validity period, for relationship attributes, tenant and data resource are associated through owns (owns) and requests_access (requests_access), data resource and permission policy are associated through governed_by (governed_by), support dynamic expansion, graph pattern uses OWL (Web Ontology Language) description to ensure semantic consistency, and realizes cross-system interaction through JSON-LD; Map triples to nodes and edges of graph database (Neo4j) and perform node modeling, where tenant nodes store metadata, data resource nodes are associated with schema information (such as field type, sensitivity), and permission policy nodes embed rule engine (Drools) to support dynamic condition judgment; Edge modeling, cross-tenant data sharing relationship is represented by SHARED_WITH edge, with permission attribute, DEPENDS_ON edge represents the dependency relationship between data resources, when a tenant initiates a data access request, the graph database traverses the associated path in real time, checks the permission policy, triggers an alarm for illegal access and records the audit log, and meets the compliance requirements; The graph updating unit is used to dynamically update the knowledge graph through stream computing, respond to tenant expansion and permission change events, capture tenant expansion (new tenant / data resource) and permission change (policy adjustment / role update) events in real time through distributed message queue (Kafka), and use event parser to convert raw data into structured messages, extract key fields including tenant ID, change type and timestamp, ensure event semantic consistency, parsed events trigger pre-defined update rule engine, match graph operations according to event type, detect potential conflicts through version control mechanism, generate conflict-free incremental update instruction set, ensure graph data consistency, update instruction set executes atomic write through Cypher bulk interface of graph database, synchronously updates nodes, edges and associated metadata, triggers incremental synchronization of graph cache and search engine after completion, ensures real-time consistency of system data view; The work content of the graph updating unit is: A real-time event stream pipeline is built through a distributed message queue (Kafka), and two types of core events, tenant expansion (new tenant, data resource registration) and permission change (policy adjustment, role update) are subscribed. Among them, the event sources include the tenant management service, the permission control system and the external compliance audit interface, the messages are classified and stored according to the topic partition, the high throughput and low delay are ensured, the event parser uses Schema Registry to dynamically load the event template, and the field mapping and semantic verification are performed on the original JSON / Avro message, and the key fields: tenant ID, change type, timestamp and change content are extracted. Through field-level verification and business rule filtering, the semantic consistency and data quality of the structured event are ensured; the parsed event triggers a pre-defined update rule engine, which defines the event-operation mapping relationship based on the Drools rule language. For event classification processing, including tenant expansion event and permission change event, the tenant expansion event is mapped to the graph node creation operation, and the tenant entity is automatically generated and associated with the default permission policy, and the permission change event is mapped to the edge attribute update operation, and the permission field (HAS_ROLE refers to the function used to check whether a user has a specific role in the permission control) of the HAS_ROLE relationship is modified. The engine detects concurrent update conflicts through the optimistic locking mechanism of the graph database. When two requests simultaneously modify the permission policy of the same tenant, only the operation with the higher version number is allowed to take effect. The conflict event triggers the rollback logic and generates an alarm, and the conflict reason is recorded to the audit log, and then an incremental update instruction set without conflict is generated. The update instruction set is executed through the Cypher batch interface of the graph database to perform atomic writing, and the transaction mechanism is used to ensure the full update or rollback of nodes, edges and metadata, and the Cypher instruction is executed in batches to modify node attributes, edge relationships and indexes. After writing successfully, the graph database returns the update result (success / failure) and the generated new version number, and then the graph database change log is captured to trigger the incremental update of the Redis cache, and the changes are pushed to the Elasticsearch search engine to update the inverted index to ensure the real-time performance of tenant data retrieval results; A key parameter encoding module is configured to encode the key parameters into a demand vector for iterative search of the fruit fly algorithm. A key dynamic allocation module is configured to combine data grading and a knowledge graph to search for an optimal key length and encryption algorithm combination based on the fruit fly algorithm to reduce computational overhead. An encryption strategy execution module is configured to call an encryption engine to implement differential encryption according to the knowledge graph and the optimized key to realize non-perception switching of the encryption strategy.

[0020] In embodiment 2, as Figure 1 , Figure 2As shown, on the basis of embodiment 1, the application provides a technical solution: preferably, the key parameter encoding module comprises: The key parameters of the encryption system are structurally analyzed, key key fields including key length, encryption algorithm type and permission identification bit are extracted, and they are mapped to a predefined numerical space for normalization processing to eliminate dimensional differences, ensure that the parameter value domain adapts to the search range of the fruit fly algorithm, generate a standardized parameter vector, according to the iteration characteristics of the fruit fly algorithm, the standardized parameter vector is decomposed into multi-dimensional sub-vectors, each sub-vector corresponds to the individual position in the algorithm, forming an initial solution space vector that meets the iteration requirements of the algorithm, the generated vector is subjected to business constraint verification, invalid solutions are removed, and the vector value domain is compressed through nonlinear transformation to meet the convergence conditions of the fruit fly algorithm, and finally the optimized demand vector is output for algorithm iteration search; The working content of the key parameter encoding module is: The key configuration of the encryption system is structurally analyzed, the original key parameters are analyzed and the key key fields are extracted, including key length, encryption algorithm type and permission identification bit, wherein the key length refers to the number of bits of the encryption key identified from the parameters, which is converted into numerical data, the encryption algorithm type refers to mapping to a predefined numerical code through an algorithm identifier, ensuring that the encryption algorithm type can be quantitatively compared, and the permission identification bit refers to analyzing the binary permission bit, extracting the valid bit and converting it into a decimal number, and the extracted fields are subjected to normalization processing to eliminate dimensional differences, the key length is normalized to [0, 1] according to the maximum value, the encryption algorithm type code remains discrete, and the permission identification bit is normalized after summing the bit weights, generating a standardized parameter vector, ensuring that all parameter value domains adapt to the search range of the fruit fly algorithm; according to the iteration characteristics of the fruit fly algorithm, the standardized parameter vector is decomposed into multi-dimensional sub-vectors, each sub-vector corresponds to the individual position in the algorithm, the key length, encryption algorithm type and permission identification bit are taken as independent dimensions, initial points are generated in the value domain of each dimension through Latin hypercube sampling to avoid local aggregation, the sampling points of each dimension are combined to form N individuals (N is the population size), each individual is composed of a multi-dimensional sub-vector, so that the solution space vector meets the iteration requirements of the fruit fly algorithm, supports random search and direction update based on odor concentration (fitness), and business constraint verification is performed on the generated initial solution space vector to remove invalid solutions, wherein the key length needs to meet the minimum requirement of the algorithm, the permission identification bit needs to meet the minimum permission principle, and the encryption algorithm type needs to match the key usage, and then the vectors that pass the verification are compressed in value domain through Sigmoid function to accelerate the convergence of the algorithm, the discrete dimensions are selected by roulette to maintain diversity, and the optimized demand vector is output for fruit fly algorithm iteration search; The key dynamic allocation module comprises: Based on the data classification results and the permission policy in the knowledge graph, the data is classified and mapped, and based on the classification results, a plurality of initial key parameter combinations (including encryption algorithm type, key length, and permission identification bit) are randomly generated to ensure coverage of the full parameter space. The fruit fly algorithm is used to simulate the olfactory search behavior of fruit flies, and each initial key combination is evaluated in two dimensions, including security score and performance overhead. The security score quantifies security based on encryption strength and attack resistance. The performance overhead is analyzed by calculating the encryption / decryption time and resource occupancy. Then, the fitness score is obtained through weighted analysis, and the candidate combination that balances security and efficiency is selected. According to the fitness score, the iteration mechanism of the fruit fly algorithm is used to retain high-score combinations and randomly disturb the parameters of low-score combinations to generate a new generation of key combinations. The evaluation-selection-disturbance process is repeated until the convergence condition is met, i.e., the fitness score fluctuation is less than the preset fluctuation threshold, and the globally optimal key combination is output. The working content of the key dynamic allocation module is as follows: Based on the data classification results and the pre-defined permission policy in the knowledge graph, a mapping relationship between data, permissions, and encryption requirements is constructed. Based on this mapping, a plurality of initial key parameter combinations are randomly generated to cover the full parameter space. The encryption algorithm type is randomly selected from the support list, the key length is randomly selected within the algorithm's allowed range, and the permission identification bit is generated according to the data classification to comply with the least privilege principle. Then, the parameter distribution uniformity is ensured through Monte Carlo sampling, and the initial combination number is set to twice the population size. The fruit fly algorithm is used to simulate the olfactory search behavior, and each initial key combination is evaluated in two dimensions, including security score and performance overhead. The security score quantifies security based on encryption strength and attack resistance. The performance overhead is calculated by weighting the encryption / decryption time and CPU / memory occupancy. The higher the overhead, the lower the score. The two-dimensional score is calculated through weighted analysis to obtain the fitness score, and the candidate combination that balances security and efficiency is selected, i.e., the combination with a fitness score greater than 0.8 enters the next generation. According to the fitness score, the iteration mechanism of the fruit fly algorithm is used to optimize the key combination. The top 20% high-score combinations are directly retained for the next generation, and the parameters of the bottom 30% low-score combinations are randomly adjusted through Gaussian disturbance. The standard deviation of the fitness score is calculated in each iteration, and the score fluctuation is analyzed. When the fitness score fluctuation is less than the preset fluctuation threshold, the process is terminated, and the globally optimal combination is output. The expression of the security score is as follows: ; In the formula, is the security score, is the actual key length of the current key combination, is the maximum key length supported by the current encryption algorithm, The anti-attack ability of the current encryption algorithm is quantified, and the cryptographic analysis tool is used for evaluation, The theoretical maximum anti-attack ability value of the current algorithm category is 1 for symmetric encryption, and is dynamically set according to the key length for asymmetric encryption. The security is calculated by the key length and the anti-attack ability, and the higher the value, the safer it is. The expression of performance overhead is as follows: ; In the formula, The performance overhead is, The single encryption / decryption time consumption of the current key combination is obtained by benchmark testing, The maximum acceptable time consumption under the target hardware platform, The CPU occupancy rate in the encryption / decryption process, The maximum available CPU resource of the target hardware, The memory occupancy rate in the encryption / decryption process, The maximum available memory of the target hardware, and the performance overhead is calculated by the time consumption, CPU and memory. The higher the value, the greater the overhead. The expression of fitness score is as follows: ; In the formula, The fitness score is, The weight coefficient of the security score, The weight coefficient of the performance overhead, The performance overhead is converted into a positive score, that is, the lower the overhead, the higher the score. The encryption strategy execution module comprises: Based on the knowledge graph, the permission strategy and the data hierarchical label are matched with the optimal key combination, and the encryption parameters are obtained from the key dynamic allocation module. The encryption parameters are bound to the corresponding data node or API interface, and the encryption instruction set is generated. The encryption engine API is called according to the encryption instruction set, the algorithm library is loaded on demand, the optimized key parameters are injected and the encryption / decryption operation is triggered, and the hot switching is performed through the proxy mode, so that the encryption process is zero-interrupted, and the multi-tenant heterogeneous environment is compatible. When the permission strategy or the key is updated, the change event is listened to in real time, the current encryption task is suspended through the lightweight lock mechanism, the key combination corresponding to the new strategy is switched to, and the engine state is updated synchronously, so as to ensure the encryption continuity and the strategy consistency. The working content of the encryption strategy execution module is: Based on the knowledge graph-based permission policy and data hierarchical label, the optimal key combination is matched through the graph traversal algorithm, the basic sensitivity level and access permission (read, write, execute) of the data node are analyzed, and combined with the pre-defined encryption rule in the knowledge graph, the candidate keys meeting the conditions are screened from the key pool, at the same time, the real-time generated encryption parameters are obtained from the dynamic key allocation module, which are bound with the unique identifier of the data node or API interface, to generate a structured encryption instruction set, which includes algorithm type, key ID, parameter configuration and target data range, to ensure that the encryption operation is decoupled from the business logic; according to the encryption instruction set, the encryption engine API is called, the algorithm library (OpenSSL, national SM4 library) is introduced on demand by using the dynamic loading mechanism, to avoid the performance overhead caused by static dependence, after injecting the optimized key parameters, the encryption engine performs hot switching through the proxy mode, that is, the main proxy is responsible for processing the current encryption task, the standby proxy preloads the key combination corresponding to the new strategy, the state is synchronized through the heartbeat detection, when the task is switched, the main proxy transfers the unfinished data fragments to the standby proxy, the zero-copy technology is used to reduce the interrupt delay, to ensure the compatibility in the multi-tenant heterogeneous environment; through the event listening mechanism, the permission policy or key update is captured in real time, the lightweight lock based on distributed Redis lock is used to suspend the current encryption task, to avoid data inconsistency, after the change trigger, the latest strategy is pulled from the knowledge graph, the new key combination is matched and the engine configuration is updated, at the same time, the related tenants are notified through the message queue, in the state synchronization stage, the legality of the new key is verified, and the audit log records the policy change track, finally, the encryption engine automatically checks the data integrity when resuming the task, to ensure the encryption continuity and policy consistency.

[0021] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto, any skilled person in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application.

Claims

1. A dynamic hierarchical encryption system for multi-tenant e-commerce data, comprising an encryption management center, characterized in that, The encryption management center is communicatively connected with the following modules, wherein: The data-aware grading module is configured to collect multi-source context data of the e-commerce platform, and divide the context data into basic sensitivity levels; The multi-tenant knowledge graph construction module is configured to construct a multi-tenant knowledge graph based on a tenant-data-permission association network in combination with the multi-source context data; The key parameter encoding module is configured to encode the key parameters into a demand vector for iterative search of the fruit fly algorithm; The key dynamic allocation module is configured to combine the data grading and the knowledge graph, and search for an optimal key length and encryption algorithm combination based on the fruit fly algorithm iterative search; The encryption strategy execution module is configured to call an encryption engine to implement differential encryption according to the knowledge graph and the optimized key.

2. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 1, wherein, The data-aware grading module includes a multi-source context collection unit and a data attribute analysis unit; The multi-source context collection unit is configured to collect three types of context data, i.e., data attributes, user behaviors, and system states of the e-commerce platform; The data attribute analysis unit is configured to extract structured features of the data based on the collected context data, and divide the context data into basic sensitivity levels including public, internal, confidential, and top secret in combination with pre-constructed data sensitivity division rules.

3. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 2, wherein, The multi-source context collection unit includes: An API interface, a log analysis tool, and a sensor network protocol are deployed on the e-commerce platform, the structured data attributes are actively pulled through the API interface, the log stream is synchronously monitored, and the sensor network is integrated to uniformly access the multi-source context data; Based on pre-defined context data classification rules, the original data is classified into three types of context data, i.e., data attributes, user behaviors, and system states, and the multi-source context data is standardized, the key fields of time stamp and tenant identifier are unified, and an analyzable context data set is constructed; A data pipeline is constructed using the stream processing framework of Kafka, the standardized multi-source data is stored in partitions according to tenant ID and business scenario, three types of context are associated through a stream computing engine, and a context event stream with a time window is generated.

4. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 2, wherein, The data attribute analysis unit includes: The context data output by the multi-source context collection unit is received and parsed, structured feature fields including data type, field length, and value range are extracted, and implicit sensitive information is identified through semantic analysis technology to generate a structured feature vector; Based on the pre-constructed data sensitivity division rules, the category to which the context data belongs is analyzed, and then a suitable basic sensitivity level is divided, which is public, internal, confidential, and top secret.

5. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 2, wherein, The multi-tenant knowledge graph construction module includes a graph structured modeling unit and a graph updating unit; The graph structured modeling unit is configured to analyze the collected multi-source context data, and the data sharing needs and permission differences among tenants, define triples of the knowledge graph, and construct a multi-tenant knowledge graph based on a tenant-data-permission association network; The graph updating unit is configured to dynamically update the knowledge graph through stream computing, and respond to events of tenant expansion and permission change.

6. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 5, wherein, The graph structured modeling unit includes: The multi-source context data is parsed, semantic features and correlation in the context data are analyzed, a cross-tenant data sharing demand and a permission difference are identified in combination with a tenant business scenario, and a demand matrix is formed; Based on the analysis result, a tenant-data-permission core triple of a knowledge graph is defined, an entity type and a relationship attribute are clarified, and a graph mode supporting dynamic expansion is constructed; According to the triple rule, a tenant, a data resource and a permission policy are mapped into a graph node and an edge, a multi-tenant correlation network is constructed through a graph database, and a structured storage of a data sharing relationship between tenants and an automatic check of a permission constraint are performed.

7. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 6, wherein, The graph updating unit comprises: Real-time capture of tenant expansion and permission change events is performed through a distributed message queue, and an event parser is used to convert raw data into structured messages, and key fields including tenant ID, change type and timestamp are extracted; The parsed event triggers a pre-defined updating rule engine, the graph operation is matched according to the event type, potential conflicts are detected through a version control mechanism, and a non-conflict incremental updating instruction set is generated; The updating instruction set performs atomic writing through a Cypher bulk interface of the graph database, synchronously updates nodes, edges and associated metadata, and triggers incremental synchronization of the graph cache and the search engine after completion.

8. The dynamic hierarchical encryption system of multi-tenant e-commerce data of claim 5, wherein, The key parameter encoding module comprises: The key parameters of the encryption system are structurally parsed, key key fields including key length, encryption algorithm type and permission identification bit are extracted, and are mapped to a pre-defined numerical space for normalization processing to generate a standardized parameter vector; According to the iteration characteristics of the fruit fly algorithm, the standardized parameter vector is decomposed into a multi-dimensional sub-vector, each sub-vector corresponds to an individual position in the algorithm, and an initial solution space vector meeting the iteration requirements of the algorithm is formed; The generated vector is subjected to business constraint verification, invalid solutions are removed, and the vector value domain is compressed through nonlinear transformation, so that it meets the convergence condition of the fruit fly algorithm, and finally an optimized demand vector is output.

9. The dynamic hierarchical encryption system of multi-tenant e-commerce data according to claim 8, wherein, The key dynamic allocation module comprises: Based on the data grading result and the permission policy in the knowledge graph, the data is graded and mapped, and based on the grading result, a plurality of initial key parameter combinations are randomly generated; The fruit fly algorithm is used to simulate the olfactory search behavior of fruit flies, and each initial key combination is evaluated in two dimensions, including security score and performance overhead, wherein the security score quantifies security based on encryption strength and attack resistance, and the performance overhead is analyzed by calculating encryption / decryption time and resource occupancy rate, and then the fitness score is obtained through weighted analysis, and the candidate combination balanced in security and efficiency is selected; According to the fitness score, the iteration mechanism of the fruit fly algorithm is used to retain high-score combinations, randomly disturb parameters of low-score combinations, generate new generation of key combinations, and repeat the evaluation-selection-disturbance process until the convergence condition is met, so that the fluctuation of the fitness score is less than a preset fluctuation threshold, and a globally optimal key combination is output.

10. The dynamic hierarchical encryption system of multi-tenant e-commerce data of claim 9, wherein, The encryption strategy execution module comprises: Based on the knowledge graph of the right policy and data classification label, the optimal key combination is matched, and the encryption parameters are obtained from the key dynamic allocation module, which is bound to the corresponding data node or API interface to generate an encryption instruction set; According to the encryption instruction set, the encryption engine API is called, the algorithm library is loaded on demand, the optimization key parameters are injected and the encryption / decryption operation is triggered, and the hot switching is performed through the proxy mode, which is compatible with the multi-tenant heterogeneous environment; When the right policy or key is updated, the change event is listened to in real time, the current encryption task is suspended through the lightweight lock mechanism, the key combination corresponding to the new policy is switched to, and the engine state is updated synchronously.

Citation Information

Cited By

  • Paperless interaction permission distribution method and system based on user group and role mapping

    CN121365415A

  • Multi-level security RAG retrieval method, system and device and storage medium

    CN122087872A