A communication data security encryption transmission method

By sensing network threat levels and data sensitivity in real time, constructing an adaptive encryption profile and performing distributed key management, the problems of dynamic threat adaptability and key management security in existing technologies are solved, and flexible data encryption and secure transmission are achieved.

CN121012695BActive Publication Date: 2026-02-13XI'AN PETROLEUM UNIVERSITY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511524825.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-02-13
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

Existing data security encryption technologies are slow to respond to network threats, have poor adaptability to dynamic threats and poor encryption security, and face the risk of centralized key management, resulting in poor key management security.

Method used

By sensing network threat levels in real time, calculating data encryption priorities based on data sensitivity, constructing an adaptive encryption profile, generating a core key and performing distributed key management, conducting multi-layered hybrid encryption, and dynamically switching and adjusting as network threat levels change.

Benefits of technology

It improves the dynamic threat adaptability, encryption security, and key management security of communication data transmission, reduces the risk of single point attacks, and ensures the rigor and forward-looking nature of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121012695B_ABST
    Figure CN121012695B_ABST
Patent Text Reader

Abstract

The application discloses a communication data security encryption transmission method, relates to the technical field of data security encryption, and comprises the following steps: calculating data encryption priority according to a network threat level and combining data sensitivity; constructing an adaptive encryption profile according to the data encryption priority, including the number of data groups and the distribution of encryption nodes, and dynamically adjusting the number of data groups and the distribution of encryption nodes according to the data encryption priority; generating a core key and performing distributed key management; performing multi-level hybrid encryption on the data groups and the encryption nodes to generate encrypted data; dynamically switching and adjusting the multi-level hybrid encryption according to the real-time change amount of the network threat level and the data encryption priority; and decrypting and verifying the encrypted data. The application improves the dynamic threat adaptability, encryption security and key management security of communication data transmission by real-time sensing of network threats, adaptive encryption profile, distributed key management and dynamic switching of multi-level hybrid encryption.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of data security encryption, in particular to a communication data security encryption transmission method. BACKGROUND

[0002] With the development of network technology, the threats faced by communication data are increasingly complex, problems such as IP risks and abnormal request frequencies occur frequently, and the risks of data leakage and tampering are increasing. The existing encryption methods are mostly static and fixed, and are difficult to adapt to dynamic threats. The centralized key management is vulnerable to attacks, and the matching degree of encryption strength and data sensitivity and threat level is low. Therefore, it is necessary to study the communication data security encryption transmission method.

[0003] In the prior art, Chinese patent CN119155034A discloses a data security encryption method for a communication network, which comprises the following steps: screening available communication data from to-be-identified original communication data, collecting comprehensive security parameters, calculating a data encryption coefficient, constructing an encryption contour with encryption nodes, generating initial encryption data, extracting encryption features of the initial encryption data, configuring trigger conditions matched with the encryption features, and generating ciphertext data.

[0004] However, the above-mentioned prior art uses static encryption, and the response to network threats is lagging behind. The dynamic threat adaptability and encryption security are poor. At the same time, the key management of the above-mentioned prior art has a centralized risk, and the key management security is poor. SUMMARY

[0005] The application provides a communication data security encryption transmission method to solve the problems of the existing data security encryption technology, such as lagging response to network threats, poor dynamic threat adaptability and encryption security, centralized risk of key management, and poor key management security.

[0006] In one aspect, the application provides a communication data security encryption transmission method, which comprises the following steps:

[0007] Step one, the sender real-time perceives network threats to obtain a network threat level, calculates a data encryption priority according to the network threat level and data sensitivity, and the data encryption priority includes low, medium and high levels.

[0008] Step two, an adaptive encryption contour is constructed according to the data encryption priority, the adaptive encryption contour includes a data group number and an encryption node distribution, and the data group number and the encryption node distribution are dynamically adjusted according to the data encryption priority.

[0009] Step three, a core key is generated based on the data encryption priority, and distributed key management is performed.

[0010] Step four, according to the data encryption priority, select the matching core key pair data group and encryption node multi-level hybrid encryption, generate encrypted data.

[0011] Step five, according to the real-time change of the network threat level and the data encryption priority, dynamically switch and adjust the multi-level hybrid encryption.

[0012] Step six, the receiving party decrypts and verifies the encrypted data.

[0013] In a possible implementation, step one includes:

[0014] The network threat features are collected in real time by a flow probe, and the network threat features include IP risk score, request frequency abnormality, protocol deviation.

[0015] The network threat level is calculated according to the network threat features.

[0016] The data encryption priority is calculated according to the network threat level and the pre-set data sensitivity.

[0017] In a possible implementation, step two includes:

[0018] The data flow is collected in real time by a flow probe, and the data group quantity is calculated according to the data flow and the data encryption priority.

[0019] The encryption node is generated according to the data group quantity.

[0020] The encryption node distribution, i.e. the activation quantity of the encryption node, is obtained according to the data encryption priority.

[0021] In a possible implementation, in step three, the core key includes: basic key, chaotic mapping key, hash key.

[0022] When the data encryption priority is low, the basic key is generated.

[0023] When the data encryption priority is medium, the basic key and the chaotic mapping key are generated.

[0024] When the data encryption priority is high, the basic key, the chaotic mapping key and the hash key are generated.

[0025] In a possible implementation, in step three, the distributed key management includes:

[0026] The core key is divided into several key fragments by using a secret sharing algorithm.

[0027] Each key fragment is respectively encrypted and stored in a blockchain node, and the encryption key of each key fragment is the private key of the corresponding blockchain node.

[0028] Every preset time interval, the core key is regenerated and divided, and the key fragments are encrypted and stored, and the old key fragments are deleted.

[0029] In a possible implementation, in step four, the multi-level hybrid encryption includes basic encryption, chaotic mapping encryption, and hash encryption.

[0030] The basic encryption includes symmetric encryption and asymmetric encryption.

[0031] When the data encryption priority is low, the data group and the encryption node are subjected to basic encryption.

[0032] When the data encryption priority is medium, the data group and the encryption node are subjected to basic encryption, and the basic-encrypted data is subjected to chaotic mapping encryption.

[0033] When the data encryption priority is high, the data group and the encryption node are subjected to basic encryption, the basic-encrypted data is subjected to chaotic mapping encryption, and the chaotic mapping-encrypted data is subjected to hash encryption.

[0034] In a possible implementation, step five includes:

[0035] Every preset time interval, the real-time change amount of the network threat level is calculated.

[0036] When the real-time change amount exceeds a preset change threshold, the data encryption priority is recalculated.

[0037] According to the new data encryption priority, the multi-level hybrid encryption is dynamically switched and adjusted.

[0038] In a possible implementation, before step one and before step six, the sender and the receiver are subjected to certificateless mutual authentication.

[0039] The certificateless mutual authentication before step one is used to confirm the real identities of the sender and the receiver before data transmission, and to establish a trusted communication basis.

[0040] The certificateless mutual authentication before step six is used to confirm the real identities of the sender and the receiver before decryption verification, and to ensure that the decryption verification is legal.

[0041] In a possible implementation, in step one, the network threat level is subjected to trend prediction to obtain a predicted threat level, and a predicted encryption priority is calculated according to the predicted threat level.

[0042] In step five, when the predicted encryption priority is higher than the data encryption priority at the current time, the predicted encryption priority is used to replace the data encryption priority at the current time.

[0043] In a possible implementation, the prediction model of the trend prediction adopts an LSTM neural network.

[0044] The communication data security encryption transmission method has the following advantages:

[0045] By perceiving network threats in real time, combining adaptive encryption profiles, distributed key management, and dynamic switching of multi-level hybrid encryption, the dynamic threat adaptability, encryption security, and key management security of communication data transmission are improved.

[0046] By calculating the network threat level through IP risk score, request frequency abnormality, and protocol deviation, accurate threat assessment basis is provided for subsequent data encryption priority calculation and dynamic switching of multi-level hybrid encryption.

[0047] By generating core keys of different levels based on the data encryption priority, the key security is ensured to match the data importance.

[0048] By using a secret sharing algorithm to split the core key into several key fragments, each key fragment is encrypted and stored in a blockchain node, and is updated regularly, improving the key security and reducing the risk of single-point attack.

[0049] By performing different levels of hybrid encryption according to the data encryption priority, flexible security protection is provided.

[0050] By recalculating the data encryption priority when the real-time change exceeds the preset change threshold, and dynamically switching and adjusting the multi-level hybrid encryption according to the new data encryption priority, the problem of threat response lag is avoided.

[0051] By performing certificateless mutual authentication before data transmission and decryption verification, a trusted communication foundation is established and decryption verification is ensured to be legal, improving the rigor of data security encryption transmission.

[0052] By predicting the trend of the network threat level and calculating the predicted encryption priority, the dynamic switching and adjustment of the multi-level hybrid encryption can be performed in advance when the predicted encryption priority is higher than the data encryption priority, improving the foresight.

[0053] By using an LSTM neural network as the prediction model of the trend prediction of the network threat level, the prediction accuracy is improved, and thus the reliability of the dynamic switching and adjustment of the multi-level hybrid encryption is improved. BRIEF DESCRIPTION OF DRAWINGS

[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the accompanying drawings in the following description only represent some of the embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of these drawings.

[0055] Figure 1 A flowchart of a communication data security encryption transmission method provided by an embodiment of the present application. DETAILED DESCRIPTION

[0056] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments only represent some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0057] As shown in the accompanying drawings, Figure 1 The present application provides a communication data security encryption transmission method, comprising the following steps:

[0058] Step one, the sender perceives network threats in real time to obtain network threat levels, calculates data encryption priorities according to the network threat levels and data sensitivity, and the data encryption priorities include low, medium and high levels.

[0059] Step two, build an adaptive encryption profile according to the data encryption priorities, the adaptive encryption profile includes data group quantity and encryption node distribution, and the data group quantity and the encryption node distribution are dynamically adjusted according to the data encryption priorities.

[0060] Step three, generate core keys based on the data encryption priorities, and perform distributed key management.

[0061] Step four, according to the data encryption priorities, select matching core keys to perform multi-level hybrid encryption on data groups and encryption nodes, and generate encrypted data.

[0062] Step five, dynamically switch and adjust the multi-level hybrid encryption according to the real-time change of the network threat level and the data encryption priority.

[0063] Step six, the receiver decrypts and verifies the encrypted data.

[0064] Exemplarily, step one includes:

[0065] The network threat features are collected in real time by a flow probe, and the network threat features include an IP risk score, a request frequency abnormality degree, and a protocol deviation degree.

[0066] A network threat level is calculated according to the network threat features.

[0067] A data encryption priority is calculated according to the network threat level and a preset data sensitivity.

[0068] Specifically, in the embodiment, the IP risk score is denoted as R ip , and the value is 0 to 1, which is calculated by weighting the historical attack records of the IP address and the reputation of the network segment (for example, the historical attack times account for 60%, and the network segment reputation accounts for 40%). The request frequency abnormality degree is denoted as F req , and the value is 0 to 1, and the calculation method is "standard deviation of current 1-minute request times and past 1-hour average request times ÷ average request times" (the greater the standard deviation, the higher the abnormality degree). The protocol deviation degree is denoted as D proto , and the value is 0 to 1, which is calculated by comparing the "edit distance" (i.e., the number of difference characters ÷ total number of characters) of the current data transmission protocol (such as TCP / UDP) and the standard protocol template (the greater the difference, the higher the deviation degree). In the embodiment, the calculation formula of the network threat level T is as follows:

[0069] .

[0070] Wherein, 、 、 respectively represent the weight coefficients of the IP risk score, the request frequency abnormality degree, and the protocol deviation degree, and the sum of the weight coefficients is 1. In the embodiment, 、 、 respectively take 0.3, 0.3, and 0.4. In other possible embodiments, the weight coefficients can also be determined by the analytic hierarchy process or other analysis methods. 、 、 .

[0071] In the embodiment, the data sensitivity is denoted as S, which is defined by the user or the system in advance, and the value is 0 to 1 (for example, 0=ordinary data, such as public announcement; 1=confidential data, such as transaction password).

[0072] The data encryption priority is denoted as P, and the calculation formula is as follows:

[0073] .

[0074] Wherein, The threat amplification coefficient is used to make the data encryption priority higher in a high-threat environment. In the embodiment, P≤0.5 is low, 0.5

[0075] For example, step two includes:

[0076] The data flow is collected in real time by the flow probe, and the data group quantity is calculated according to the data flow and the data encryption priority.

[0077] The encryption node is generated according to the data group quantity.

[0078] The encryption node distribution, i.e., the activation quantity of the encryption node, is obtained according to the data encryption priority.

[0079] Specifically, in the embodiment, the data flow Q 实时 is collected in real time, the unit is KB / s, and the calculation formula of the data group quantity x is as follows:

[0080] .

[0081] Wherein, The flow amplification coefficient is 3 in the embodiment; The preset reference flow threshold is 128 KB / s in the embodiment, which can be adjusted according to the network bandwidth; The floor function is used; The smaller value of 10 in the middle bracket and another value is called the first extraction value, and the larger value of 2 and the first extraction value is obtained, that is, the data group quantity x, The maximum data group quantity is limited to 10, and the minimum data group quantity is limited to 2.

[0082] After obtaining the data group quantity x, the communication data can be distributed to x data groups according to the semantic aggregation mode (such as semantic aggregation according to the keywords of “user ID”, “transaction amount”, “timestamp”, etc., to ensure that the data in the same group is semantically related and facilitate subsequent targeted encryption), in other possible embodiments, the communication data can also be distributed to x data groups by using other data grouping modes.

[0083] Specifically, each data group is the basic unit of the adaptive encryption profile, and a data connection channel is established between adjacent data groups for inter-group data interaction. The midpoint of the data connection channel is the encryption node, and there are x-1 encryption nodes.

[0084] The rule of obtaining the encryption node distribution according to the data encryption priority is as follows: when the data encryption priority is low, only the first encryption node and the x-1th encryption node, that is, the first and last two encryption nodes, are activated to reduce the calculation amount; when the data encryption priority is medium, the encryption nodes are activated at intervals, that is, the odd-numbered encryption nodes or the even-numbered encryption nodes are activated to balance the security and efficiency; and when the data encryption priority is high, all the x-1 encryption nodes are activated to maximize the encryption coverage.

[0085] Exemplarily, in step three, the core key comprises: a basic key, a chaotic mapping key and a hash key.

[0086] When the data encryption priority is low, the basic key is generated.

[0087] When the data encryption priority is medium, the basic key and the chaotic mapping key are generated.

[0088] When the data encryption priority is high, the basic key, the chaotic mapping key and the hash key are generated.

[0089] Specifically, in the embodiment, the basic key comprises: a symmetric key and an asymmetric key; the symmetric key comprises: an AES encryption key and an SM4 encryption key; the asymmetric key comprises: an RSA encryption key and an SM2 encryption key; the chaotic mapping key is a confusion sequence generated by using a chaotic mapping algorithm; and the hash key is generated by embedding a hash chain.

[0090] Exemplarily, in step three, the distributed key management comprises:

[0091] The core key is divided into a plurality of key fragments by using a secret sharing algorithm.

[0092] Each key fragment is respectively encrypted and stored in a blockchain node, and the encryption key of each key fragment is the private key of the corresponding blockchain node.

[0093] Every preset time interval, the core key is regenerated and divided, the key fragments are encrypted and stored, and the old key fragments are deleted.

[0094] Specifically, in the embodiment, the secret sharing algorithm uses a Shamir secret sharing algorithm, the core key is divided into n key fragments, n is the total number of blockchain nodes, and only when more than n / 2 key fragments are collected, the core key can be recovered. In the embodiment, every half hour, the core key is regenerated and divided, the key fragments are encrypted and stored, and the old key fragments are deleted.

[0095] Exemplarily, in step four, the multi-level hybrid encryption comprises: basic encryption, chaotic mapping encryption and hash encryption.

[0096] The basic encryption includes symmetric encryption and asymmetric encryption.

[0097] When the data encryption priority is low, the data group and the encryption node are subjected to basic encryption.

[0098] When the data encryption priority is medium, the data group and the encryption node are subjected to basic encryption, and the basic-encrypted data is subjected to chaotic mapping encryption.

[0099] When the data encryption priority is high, the data group and the encryption node are subjected to basic encryption, the basic-encrypted data is subjected to chaotic mapping encryption, and the chaotic-mapping-encrypted data is subjected to hash encryption.

[0100] Specifically, in the embodiment, when the data encryption priority is low, the data group is encrypted by calling an AES encryption key in the basic key (low corresponds to the AES-128 algorithm), and the encryption node is only subjected to CRC check.

[0101] In the embodiment, when the data encryption priority is medium, the data group is encrypted by calling an AES encryption key in the basic key (medium corresponds to the AES-256 algorithm), the encryption node is encrypted by calling an RSA encryption key in the basic key (medium corresponds to the RSA-2048 algorithm), and the basic-encrypted data is subjected to chaotic mapping encryption by calling a hybrid mapping key (in the embodiment, a Logistic mapping algorithm is used to generate a confusion sequence as the hybrid mapping key).

[0102] In the embodiment, when the data encryption priority is high, the data group is encrypted by calling an SM4 encryption key in the basic key, the encryption node is encrypted by calling an SM2 encryption key in the basic key, the basic-encrypted data is subjected to chaotic mapping encryption by calling a hybrid mapping key (in the embodiment, a Logistic mapping algorithm is used to generate a confusion sequence as the hybrid mapping key), and the chaotic-mapping-encrypted data is subjected to hash encryption by calling a hash key (the hash value of the previous encryption node is embedded in the encryption information of the ith encryption node).

[0103] Exemplarily, step five includes:

[0104] Every interval of a preset time, the real-time change amount of the network threat level is calculated.

[0105] When the real-time change amount exceeds a preset change threshold, the data encryption priority is recalculated.

[0106] The multi-level hybrid encryption is dynamically switched and adjusted according to the new data encryption priority.

[0107] Specifically, in the present embodiment, the real-time change amount of the network threat level is calculated every 2 seconds As shown in the following formula:

[0108]

[0109] wherein, represents the real-time network threat level, represents the network threat level 2 seconds ago. In the present embodiment, when the real-time change amount of the network threat level exceeds 0.2, the data encryption priority is immediately recalculated, and the multi-level hybrid encryption is dynamically switched and adjusted according to the new data encryption priority. When the new data encryption priority is higher than the original data encryption priority, the new multi-level hybrid encryption strategy is immediately switched back to step four; when the new data encryption priority is lower than the original data encryption priority, the new multi-level hybrid encryption strategy is switched back to step four after a delay (10 seconds in the present embodiment).

[0110] Exemplarily, before step one and before step six, both the sender and the receiver perform a certificateless mutual authentication.

[0111] The certificateless mutual authentication before step one is used to confirm the true identity of the sender and the receiver before data transmission, and to establish a trusted communication foundation.

[0112] The certificateless mutual authentication before step six is used to confirm the true identity of the sender and the receiver before decryption verification, and to ensure that the decryption verification is legal.

[0113] Specifically, in the present embodiment, the certificateless mutual authentication before step one is as follows: the sender generates an authentication request containing its own identity, generates a temporary random number and signs it using its own private key, and sends the identity, the temporary random number and the signature to the receiver; after receiving the request, the receiver first verifies the sender's signature (verified by the sender's public key), and if the signature is valid, generates its own identity, a new temporary random number, and signs it using its own private key, and returns these information to the sender; the sender verifies the receiver's signature (verified by the receiver's public key), and if the verification is passed, the two parties confirm each other's true identity, complete the mutual authentication, establish a trusted communication foundation, and then enter the process of step one.

[0114] ​The certificateless two-way authentication process prior to step six is ​​as follows: After receiving the encrypted data, the receiver sends an authentication request to the sender, requesting the sender to provide current authentication information; the sender generates an identity credential containing the current timestamp, signs it with its own private key, and sends it to the receiver; the receiver verifies the signature (using the sender's public key) and the validity of the timestamp (ensuring the information has not expired). If the verification is successful, the sender's identity is confirmed to be legitimate, and then the decryption verification process in step six is ​​initiated.

[0115] For example, in step one, the network threat level is trend-predicted to obtain a predicted threat level, and a predicted encryption priority is calculated based on the predicted threat level.

[0116] In step five, when the predicted encryption priority is higher than the current data encryption priority, the predicted encryption priority replaces the current data encryption priority.

[0117] For example, the prediction model for the trend prediction employs an LSTM neural network.

[0118] Specifically, in this embodiment, the sequence of network threat levels over the past 5 minutes ( , ,..., A network threat level is assigned every 2 seconds, among which (This represents the network threat level at the current time t). An LSTM neural network is used to predict the network threat level 10 seconds later, i.e., the predicted threat level, denoted as [predicted threat level]. As shown in the following formula:

[0119] .

[0120] in, This indicates that an LSTM neural network is used for trend prediction based on the sequence within parentheses. Furthermore, it predicts threat levels. The predicted encryption priority can be calculated. As shown in the following formula:

[0121] .

[0122] When predicting encryption priority When the data encryption priority is higher than the current time, use the predicted encryption priority. Replace the current data encryption priority. Then step five becomes based on the predicted encryption priority. Dynamic switching and adjustment of multi-layered hybrid encryption improves foresight.

[0123] The embodiment of the application improves the dynamic threat adaptability, encryption security and key management security of communication data transmission by real-time sensing of network threats, combining adaptive encryption profile, distributed key management and dynamic switching of multi-level hybrid encryption.

[0124] The network threat level is calculated by IP risk score, request frequency abnormality and protocol deviation, providing accurate threat assessment basis for subsequent data encryption priority calculation and dynamic switching of multi-level hybrid encryption.

[0125] Different levels of core keys are generated based on data encryption priority to ensure that the key security matches the data importance.

[0126] The core key is divided into several key fragments by using a secret sharing algorithm, each key fragment is encrypted and stored in a blockchain node, and is updated regularly, improving the key security and reducing the risk of single-point attack.

[0127] Flexible security is provided by different levels of hybrid encryption according to data encryption priority.

[0128] When the real-time change exceeds the preset change threshold, the data encryption priority is recalculated, and the multi-level hybrid encryption is dynamically switched and adjusted according to the new data encryption priority, avoiding the problem of threat response lag.

[0129] Certificateless two-way authentication is performed before data transmission and decryption verification, establishing a trusted communication foundation and ensuring decryption verification is legal, improving the rigor of data security encryption transmission.

[0130] The network threat level is predicted, and the predicted encryption priority is calculated, so that the dynamic switching and adjustment of multi-level hybrid encryption can be performed in advance when the predicted encryption priority is higher than the data encryption priority, improving the foresight.

[0131] The LSTM neural network is used as the prediction model for network threat level trend prediction, improving the prediction accuracy and thus improving the reliability of the dynamic switching and adjustment of multi-level hybrid encryption.

[0132] Although the preferred embodiments of the application have been described, those skilled in the art can make additional changes and modifications to the embodiments once they know the basic inventive concept. Therefore, the appended claims are intended to include the preferred embodiments and all changes and modifications falling within the scope of the application.

[0133] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A method for secure encrypted transmission of communication data, characterized in that, Includes the following steps: Step 1: The sender detects network threats in real time, obtains the network threat level, and calculates the data encryption priority based on the network threat level and data sensitivity. The data encryption priority includes low, medium and high levels. Step 2: Construct an adaptive encryption profile based on the data encryption priority. The adaptive encryption profile includes the number of data groups and the distribution of encryption nodes. The number of data groups and the distribution of encryption nodes are dynamically adjusted according to the data encryption priority. Step 3: Generate a core key based on the data encryption priority and perform distributed key management; Step 4: Based on the data encryption priority, select a matching core key to perform multi-level hybrid encryption on the data group and encryption nodes to generate encrypted data; Step 5: Dynamically switch and adjust the multi-layered hybrid encryption based on the real-time changes in the network threat level and the data encryption priority; Step six: The recipient decrypts and verifies the encrypted data; Step two includes: Data traffic is collected in real time using a traffic probe, and the number of data groups is calculated based on the data traffic and the data encryption priority. An encrypted node is generated based on the number of data groups; The distribution of encrypted nodes, i.e. the number of activated encrypted nodes, is obtained based on the data encryption priority. The formula for calculating the number of data sets x is as follows: , Among them, Q 实时 This represents the real-time data flow; P represents the data encryption priority. Indicates the flow amplification factor; This indicates the preset baseline flow rate threshold; Indicates rounding down; This means first taking the smaller value between 10 and another value from the parentheses, called the first extract value, then taking the larger value between 2 and the first extract value, to get the number of data sets x. The maximum number of data sets is 10, and the minimum is 2. Each data group is the basic unit of the adaptive encryption profile. A data connection channel is established between adjacent data groups for data exchange between groups. The midpoint of the data connection channel is the encryption node, and there are a total of x-1 such nodes.

2. The secure encrypted transmission method for communication data according to claim 1, characterized in that, Step one includes: Network threat characteristics are collected in real time using traffic probes. These characteristics include IP risk scores, request frequency anomalies, and protocol deviations. Calculate the network threat level based on the network threat characteristics; The data encryption priority is calculated based on the network threat level and the pre-set data sensitivity.

3. The secure encrypted transmission method for communication data according to claim 1, characterized in that, In step three, the core key includes: a basic key, a chaotic mapping key, and a hash key; When the data encryption priority is low, a base key is generated; When the data encryption priority is medium, a base key and a chaos mapping key are generated. When the data encryption priority is high, a base key, a chaos mapping key, and a hash key are generated.

4. The secure encrypted transmission method for communication data according to claim 1, characterized in that, Step three, the distributed key management includes: The core key is divided into several key fragments using a secret sharing algorithm; Each key fragment is encrypted and stored separately in a blockchain node, and the encryption key for each key fragment is the private key of the corresponding blockchain node. At preset intervals, the core key is regenerated, divided, and the key fragments are encrypted and stored, while the old key fragments are deleted.

5. The secure encrypted transmission method for communication data according to claim 1, characterized in that, In step four, the multi-layered hybrid encryption includes: basic encryption, chaotic mapping encryption, and hash encryption; The basic encryption includes: symmetric encryption and asymmetric encryption; When the data encryption priority is low, basic encryption is performed on the data group and the encryption node; When the data encryption priority is medium, basic encryption is performed on the data group and the encryption node, and chaotic mapping encryption is performed on the data after basic encryption. When the data encryption priority is high, basic encryption is performed on the data group and the encryption node, chaotic mapping encryption is performed on the data after basic encryption, and hash encryption is performed on the data after chaotic mapping encryption.

6. The secure encrypted transmission method for communication data according to claim 1, characterized in that, Step five includes: The real-time change in the network threat level is calculated at preset intervals. When the real-time change exceeds the preset change threshold, the data encryption priority is recalculated. The multi-layered hybrid encryption is dynamically switched and adjusted according to the new data encryption priority.

7. The secure encrypted transmission method for communication data according to claim 1, characterized in that, Before step one and before step six, certificateless two-way authentication is performed between the sender and the receiver. The certificateless two-way authentication prior to step one is used to verify the true identities of the sender and receiver before data transmission, establishing a foundation for trusted communication; The certificateless two-way authentication prior to step six is ​​used to verify the true identities of the sender and receiver before decryption verification, ensuring that the decryption verification is legitimate.

8. The secure encrypted transmission method for communication data according to claim 1, characterized in that, In step one, the network threat level is trend-predicted to obtain the predicted threat level, and the predicted encryption priority is calculated based on the predicted threat level. In step five, when the predicted encryption priority is higher than the current data encryption priority, the predicted encryption priority replaces the current data encryption priority.

9. A method for secure encrypted transmission of communication data according to claim 8, characterized in that, The trend prediction model uses an LSTM neural network.

Citation Information

Patent Citations

  • Data security encryption method for communication network

    CN119155034A

  • Database security secrecy system based on storage encryption

    CN119272341A

  • Data encryption transmission method and device in hybrid cloud environment, equipment and storage medium

    CN120768621A