Network communication information encryption transmission method and system

By dynamically adjusting the key level and task allocation, and optimizing the encryption strategy in combination with latency and server capabilities, the problem of insufficient resource utilization in existing technologies is solved, and the security and efficiency of encrypted transmission of network communication information are improved.

CN121125352AActive Publication Date: 2025-12-12SHENZHEN MAXTOPIC TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511652797.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2025-12-12
Estimated Expiration
2045-11-12

AI Technical Summary

Technical Problem

Existing network communication encryption technologies fail to dynamically adjust encryption strategies when faced with high network load, high latency, or bandwidth fluctuations, resulting in insufficient resource utilization, strained or over-allocated computing resources, and impacting system efficiency and reliability.

Method used

By collecting transmission delay and routing node queuing delay parameters, a delay redundancy mask is generated, the key level and length are adjusted, and the HEFT algorithm is used to optimize the encryption task allocation in combination with server processing capacity and topology. The weighted average model is then applied to optimize the encryption control factor.

Benefits of technology

It improves the flexibility and resource utilization efficiency of the encryption system, ensures that the encryption strength is adapted to network conditions, optimizes the allocation of encryption tasks, and enhances the security and efficiency of information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125352A_ABST
    Figure CN121125352A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security protocols, in particular to a network communication information encryption transmission method and system, and the method comprises the following steps: collecting transmission delay and queuing delay, summing up to generate total delay, carrying out error normalization to form a delay redundancy mask, judging an interval, adjusting an encryption level and a key length, and carrying out encryption transmission. The method comprises the following steps of: constructing topological mapping in combination with node processing capacity and communication distance, allocating tasks by an HEFT algorithm, generating a node task table, generating a control factor by weighted average, optimizing encryption hierarchy and task allocation, and improving transmission safety and efficiency. Fluctuation is dynamically coped with, the encryption hierarchy and the key length are adjusted, task allocation is optimized in combination with the node capacity and the communication distance, the efficiency is improved through the HEFT algorithm, excessive or insufficient encryption is avoided through weighted average generation of control factors, and the transmission safety and efficiency are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security protocol, in particular to a network communication information encryption transmission method and system. BACKGROUND

[0002] The technical field of network security protocol includes related methods and mechanisms for ensuring information transmission security in network communication process. The core content is to realize that data in the transmission process is not accessed, tampered or forged by unauthorized access through the development and application of security protocols, mainly covering identity authentication, key distribution, data encryption, integrity verification and communication session control. The whole network security protocol system provides multi-level security mechanisms according to multiple application scenarios and transmission requirements, including data encryption and security control at link layer, network layer and application layer, to ensure that both parties of communication can establish a trusted transmission channel in an insecure network environment, and to regulate the interactive process and information processing rules of secure communication at the technical level.

[0003] Among them, the network communication information encryption transmission method and system refers to the technical scheme of realizing information transmission through a specific encryption method in network communication. For encryption and decryption operations of communication data in the transmission process, it covers key generation and distribution method, symmetric or asymmetric encryption method and encryption handshake process based on protocol, and specifically realizes data encryption and decryption through cryptographic algorithms, and verifies the identity of both parties of communication through the authentication mechanism defined by the protocol. The encryption transmission of network communication information is completed by establishing the steps of encryption session process, exchanging necessary key materials and executing information encoding transmission.

[0004] Although the prior art has a relatively perfect theoretical framework in ensuring information transmission security, there are obvious deficiencies in actual operation. First, the security mechanism of the prior art is often fixed and cannot be dynamically adjusted according to the actual network environment, which makes it still use uniform encryption level and key length when the network load is high, the delay is large or the bandwidth fluctuates, and the network resources are not fully utilized. Second, the existing network encryption process usually ignores the actual processing capacity and load of the routing node, which may cause excessive allocation of encryption tasks on some nodes with tight computing resources, affecting the overall processing efficiency of the system, or the computing resources are not fully utilized on nodes with low load. In addition, the existing technology considers the communication distance more simply and does not consider the influence of multiple topological structures and geographical distribution, which may not be the optimal encryption strategy in multiple scenarios. The existing encryption control mechanism is usually based on a fixed protocol and cannot be adaptively adjusted according to dynamic parameters such as delay, which may cause excessive encryption or decryption load in high-delay network environment, thereby affecting the running efficiency of the system and the reliability of communication. SUMMARY

[0005] To solve the technical problems in the prior art, the embodiment of the present application provides a network communication information encryption transmission method, comprising the following steps: To achieve the above-mentioned purpose, the present application adopts the following technical scheme: a network communication information encryption transmission method, comprising the following steps: S1: Collecting the end-to-end transmission delay parameter and the server queuing delay parameter before the message enters the transmission channel, and performing totalization to obtain a real-time total delay, extracting the error of the current totalization result and the totalization result of the last period, and generating a delay redundancy mask by combining the multi-server queuing delay parameter normalization; S2: Based on the delay redundancy mask, the mask interval is judged and divided into an enhancement zone and a buffer zone, and the nesting level and length of the key are adjusted according to the interval to generate an encryption structure parameter set; S3: Based on the encryption structure parameter set, the server processing capacity and load parameter are collected and the available computing capacity of the server is calculated, and the link communication distance parameter is collected and combined to map to construct a topology capability mapping table; S4: The encryption structure parameter set and the topology capability mapping table are input into the HEFT algorithm to distribute the encryption task, and the encryption task is matched according to the available computing capacity of the server to generate an encryption task table; S5: The topology capability mapping table and the encryption task table are input into the HEFT algorithm to distribute the encryption task, and the encryption task is matched according to the available computing capacity of the server to generate an encryption task table;

[0006] As a further scheme of the present application, the delay redundancy mask includes a normalization coefficient and a real-time total delay, the encryption structure parameter set specifically refers to a nesting level parameter, a key length parameter and an interval category parameter, the topology capability mapping table includes a server available computing capacity, a link communication distance and a load parameter, and the encryption task table specifically refers to a task distribution matrix, a server matching index and a computing resource distribution, and the information encryption transmission result includes an encryption control factor, a nesting level depth and a task distribution mode.

[0007] As a further scheme of the present application, the specific steps of S1 are: S101: Collecting the end-to-end transmission delay parameter and the server queuing delay parameter before the message enters the transmission channel, and performing totalization to obtain a real-time total delay; S102: Based on the real-time total delay, the delay value obtained by totalization in the last period is obtained, the difference between the two is calculated as the offset of the current delay change, and the queuing delay parameters of multiple routing nodes are called to combine and normalize the offset to obtain a normalized offset coefficient; S103: According to the normalized offset coefficient, the multi-node queuing delay parameter is distributedly adjusted, a corresponding mask is formed, and the difference quantity calculated at present is mapped to generate a time delay redundancy mask.

[0008] As a further scheme of the application, the specific steps of S2 are: S201: Obtain a mask interval based on the time delay redundancy mask parameter, classify a plurality of values into an enhancement area or a buffer area according to an interval threshold, and establish an interval corresponding relationship after the classification is completed to generate a mask interval division value; S202: Adjust the key nesting level based on the mask interval division value, increase the level number according to the enhancement area, reduce the level number according to the buffer area, and arrange the multi-interval level parameter to obtain a level adjustment coefficient; S203: Call the level adjustment coefficient and combine the mask interval division value to correct the key length synchronously, combine the corrected level parameter and the length parameter to generate an encryption structure parameter set.

[0009] As a further scheme of the application, the interval threshold is set by statistically detecting the value distribution of the time delay redundancy mask parameter, calculating the maximum value and the minimum value, and then setting the range interval according to the proportion.

[0010] As a further scheme of the application, the specific steps of S3 are: S301: Based on the encryption structure parameter set, collect the server processing capacity and load parameter, compare the collected processing capacity value and load occupation value, calculate the current available operation capacity of the server to generate a server operation capacity; S302: Call the server operation capacity and collect the link communication distance parameter, map the link communication distance and the operation capacity value, pair according to the combination of the two types of parameters in the same interval to generate a communication capacity mapping value; S303: According to the communication capacity mapping value, combine and arrange the encryption structure parameter set, bind the operation capacity value under a plurality of link distances with the structure parameter set to generate a topology capability mapping table.

[0011] As a further scheme of the application, the specific steps of S4 are: S401: According to the encryption structure parameter set, obtain the computing capacity of a plurality of servers, compare with the available operation capacity of the server, allocate tasks according to the computing resources of the server and the encryption task demand to obtain a task matching quantity; S402: Based on the task matching quantity, match the computing demand of the encryption task, call the HEFT algorithm to optimize the allocation of the encryption task, generate the execution scheduling of the task between a plurality of servers to obtain a task scheduling list; S403: According to the task scheduling list, the time delay in the multi-task execution process is calculated, and the network condition and the computing capability among the multiple nodes are combined to generate an encrypted task table.

[0012] As a further scheme of the present application, the specific steps of S5 are: S501: According to the topology capability mapping table and the encrypted task table, a weighted average model is called to calculate and normalize the capability value and the corresponding time delay value of the multiple nodes in proportion to the weight, and an encrypted control factor is generated; S502: Based on the encrypted control factor, the influence of the encryption nesting level parameter and the task allocation mode on the number of encryption nesting layers and the task division ratio is detected, and the number of nesting layers and the task allocation parameter are adjusted according to the difference to obtain an encryption complexity coefficient; S503: The encryption complexity coefficient is called and compared with the actual time consumption of the task, and the calculation process of the information encryption transmission is updated according to the comparison deviation result to generate an information encryption transmission result.

[0013] As a further scheme of the present application, the encryption complexity coefficient is calculated and set by the operation complexity of the encryption algorithm, the number of nesting levels, the key length, the task allocation mode, and the execution time delay factor.

[0014] The network communication information encryption transmission system comprises: A time delay analysis module collects end-to-end transmission time delay parameters and server queuing delay parameters before the message enters the transmission channel, and sums up the real-time total time delay, extracts the error of the current summation result and the summation result of the last period, and normalizes the multiple server queuing delay parameters to generate a time delay redundancy mask and transmit it to a time delay judgment module; A time delay judgment module judges the mask interval based on the time delay redundancy mask and divides it into an enhancement zone and a buffer zone, and adjusts the nesting level and length of the key according to the interval to generate an encryption structure parameter set and transmit it to a routing topology module; A routing topology module collects server processing capability and load parameters based on the encryption structure parameter set and calculates the available computing capability of the server, and collects link communication distance parameters for combined mapping to construct a topology capability mapping table and transmit it to a task allocation module; A task allocation module inputs the encryption structure parameter set and the topology capability mapping table into a HEFT algorithm to allocate encrypted tasks, matches the encrypted tasks according to the available computing capability of the server, generates an encrypted task table, and transmits it to an encryption control module; The encryption control module generates an encryption control factor by a weighted average model based on the topology capability mapping table and the encryption task table, adjusts the encryption nesting level depth and the task allocation mode according to the encryption control factor, and compares the actual time consumption to generate an information encryption transmission result.

[0015] Compared with the prior art, the application has the advantages and positive effects that: In the application, the real-time total time delay is obtained by collecting the transmission time delay parameters and the routing node queuing delay parameters and summing up, which can accurately reflect the actual transmission delay of data in the network, and then the time delay redundancy mask is generated by error extraction and normalization processing with the previous cycle result. This dynamic adjustment method can respond to the time delay fluctuation and load change in the network in real time, and then optimize the allocation of encryption level and key length. According to the judgment of the time delay redundancy mask, the encryption control interval is divided into an enhancement zone and a buffer zone, which can effectively improve the flexibility of the encryption system, so that the encryption task can be automatically adjusted according to the actual network condition, and ensure that the encryption strength in data transmission always adapts to the network condition. In addition, through comprehensive analysis and mapping of multiple parameters such as routing node processing capacity, load and communication distance, the task can be dynamically allocated according to the specific network topology structure, and the use efficiency of computing resources is improved. The introduction of the HEFT algorithm schedules the task based on the actual computing capacity of the node, which not only optimizes the encryption task allocation, but also improves the processing capacity and efficiency of the whole network. The application of the weighted average model makes the generation of the encryption control factor more accurate, further optimizes the encryption level and task allocation mode, avoids the phenomenon of excessive encryption or insufficient encryption, and ensures the matching of the encryption effect and the actual time consumption. This comprehensive dynamic adjustment and task optimization method effectively enhances the security and efficiency of information encryption transmission. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.

[0017] Figure 1 The step flowchart of the application is shown in the figure. Figure 2 The S1 refinement schematic diagram of the application is shown in the figure. Figure 3 The S2 refinement schematic diagram of the application is shown in the figure. Figure 4 The S3 refinement schematic diagram of the application is shown in the figure. Figure 5 The S4 refinement schematic diagram of the application is shown in the figure. Figure 6S5 is a refinement schematic diagram of the present application; Figure 7 The system module diagram of the present application. DETAILED DESCRIPTION

[0018] The technical solutions in the present application will be described below with reference to the drawings.

[0019] In the embodiments of the present application, the words such as "example", "for example" are used to represent as an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.

[0020] In the embodiments of the present application, "image" and "picture" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized. "Of", "corresponding" and "corresponding" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized.

[0021] In the embodiments of the present application, sometimes the subscript such as W1 can be written in the form of non-subscript such as W1, and the meanings expressed are consistent when the distinction is not emphasized.

[0022] In order to make the technical problems, technical solutions and advantages to be solved by the present application more clear, the following will be described in detail with reference to the drawings and specific embodiments.

[0023] Please refer to Figure 1 The network communication information encryption transmission method provided by the embodiments of the present application comprises the following steps: S1: Collecting the end-to-end transmission delay parameter before the message enters the transmission channel and the server queuing delay parameter and performing totalization to obtain a real-time total delay, extracting the error of the current totalization result and the last period totalization result, and generating a delay redundancy mask in combination with the multi-server queuing delay parameter normalization; S2: Judging the mask interval based on the delay redundancy mask and dividing it into an enhancement zone and a buffer zone, and adjusting the nesting level and length of the key according to the interval to generate an encryption structure parameter set; S3: Based on the encryption structure parameter set, collecting the server processing capacity and load parameter and calculating the available operation capacity of the server, and collecting the link communication distance parameter for combination mapping to construct a topology capability mapping table; S4: input the encryption structure parameter set and the topology capability mapping table into the HEFT algorithm to distribute the encryption task, match the encryption task according to the available computing capability of the server, and generate an encryption task table; S5: generate an encryption control factor through a weighted average model based on the topology capability mapping table and the encryption task table, adjust the encryption nesting level depth and the task distribution mode according to the encryption control factor, and compare the actual time consumption to generate an information encryption transmission result.

[0024] The time delay redundancy mask includes a normalization coefficient, a real-time total time delay, the encryption structure parameter set specifically refers to a nesting level parameter, a key length parameter, and an interval category parameter, the topology capability mapping table includes a server available computing capability, a link communication distance, and a load parameter, the encryption task table specifically refers to a task distribution matrix, a server matching index, and a computing resource distribution, and the information encryption transmission result includes an encryption control factor, a nesting level depth, and a task distribution mode.

[0025] Please refer to Figure 2 , and the specific steps of S1 are as follows: S101: collect the end-to-end transmission time delay parameter and the server queuing delay parameter before the message enters the transmission channel, add up the collected end-to-end transmission time delay parameter and the multiple server queuing delay parameters to generate a real-time total time delay; The message sending time is obtained through the client timestamp record, for example, the message sending time is 1530 milliseconds, the message entering time is obtained through the transmission channel entrance monitoring, for example, the message entering time is 1535 milliseconds, the difference value is obtained to obtain the end-to-end transmission time delay parameter 5 milliseconds, and the multiple server queuing delay parameters are collected through the server kernel log, for example, the message arrival time of server 1 is 1540 milliseconds, the processing start time is 1543 milliseconds, the difference value is 3 milliseconds, the message arrival time of server 2 is 1545 milliseconds, the processing start time is 1548 milliseconds, the difference value is 3 milliseconds, the message arrival time of server 3 is 1550 milliseconds, the processing start time is 1554 milliseconds, the difference value is 4 milliseconds, the end-to-end transmission time delay parameter 5 milliseconds is added to the server 1 queuing delay parameter 3 milliseconds, the server 2 queuing delay parameter 3 milliseconds, and the server 3 queuing delay parameter 4 milliseconds, and the sum process is 5+3=8 milliseconds, 8+3=11 milliseconds, and 11+4=15 milliseconds, to generate a real-time total time delay 15 milliseconds.

[0026] S102: based on the real-time total time delay, obtain the time delay value obtained by adding up in the last period, calculate the difference between the two and take it as the offset of the current time delay change, and call the queuing delay parameters of multiple routing nodes, combine them with the offset and normalize to obtain a normalized offset coefficient; Based on the real-time total delay of 15 milliseconds, the delay value of the same service path in the last period of 12 milliseconds is called through the database, the difference is calculated, the subtraction operation is performed, 15 milliseconds minus 12 milliseconds, and the offset of 3 milliseconds is obtained. At the same time, the routing node queuing delay parameters are called, including node A delay 2.1 milliseconds, node B delay 1.8 milliseconds, and node C delay 3.3 milliseconds. The offset of 3 milliseconds is added to the node A delay of 2.1 milliseconds to obtain 5.1 milliseconds, added to the node B delay of 1.8 milliseconds to obtain 4.8 milliseconds, and added to the node C delay of 3.3 milliseconds to obtain 6.3 milliseconds. The sum of all added results is 5.1+4.8+6.3=16.2 milliseconds. The normalization operation is performed on node A, 5.1 / 16.2, to obtain 0.315. The normalization operation is performed on node B, 4.8 / 16.2, to obtain 0.296. The normalization operation is performed on node C, 6.3 / 16.2, to obtain 0.389. The normalized offset coefficients are generated, node A: 0.315, node B: 0.296, and node C: 0.389.

[0027] Table 1: Routing node delay parameter table

[0028] S103: According to the normalized offset coefficients, the multi-node queuing delay parameters are distributedly adjusted to form corresponding masks, which are mapped with the currently calculated difference to generate a time delay redundancy mask. According to the normalized offset coefficients, node A: 0.315, node B: 0.296, and node C: 0.389, the multiplication operation is performed on the node A queuing delay parameter of 2.1 milliseconds, 2.1*0.315=0.6615 milliseconds. The multiplication operation is performed on the node B queuing delay parameter of 1.8 milliseconds, 1.8*0.296=0.5328 milliseconds. The multiplication operation is performed on the node C queuing delay parameter of 3.3 milliseconds, 3.3*0.389=1.2837 milliseconds. The mask vector [0.6615, 0.5328, 1.2837] is formed. The multiplication operation is performed on the mask multi-element and the difference of 3 milliseconds. The node A mapping calculation is 0.6615*3=1.9845 milliseconds. The node B mapping calculation is 0.5328*3=1.5984 milliseconds. The node C mapping calculation is 1.2837*3=3.8511 milliseconds. The time delay redundancy mask is generated, node A: 1.9845 milliseconds, node B: 1.5984 milliseconds, and node C: 3.8511 milliseconds.

[0029] Please refer to Figure 3 , the specific steps of S2 are: S201: Based on the time delay redundancy mask parameter, the mask interval is obtained. According to the interval threshold, the multiple values are classified into enhancement area or buffer area. After the classification is completed, the interval corresponding relationship is established to generate the mask interval division value. Based on the generated latency redundancy mask parameters (node A: 1.9845 ms, node B: 1.5984 ms, node C: 3.8511 ms), the mask parameter values are called one by one, the value range is detected, the comparison operation is performed on the node A value 1.9845 ms, compared with the preset interval threshold lower limit 1.5 ms, 1.9845>1.5 is established, compared with the upper limit 2.5 ms, 1.9845<2.5 is established, it is judged to be in the buffer zone interval, the comparison operation is performed on the node B value 1.5984 ms, 1.5984>1.5 is established and 1.5984<2.5 is established, it is judged to be in the buffer zone interval, the comparison operation is performed on the node C value 3.8511 ms, 3.8511>2.5 is established, it is judged to be in the enhancement zone interval, the interval threshold is set with reference to the delay data statistics, the reference value is obtained by calculating the average value of the mask parameters in the last 10 periods, for example, the mask value sequence [1.2, 1.8, 2.0, 1.5, 2.3, 3.0, 3.5, 1.7, 2.1, 3.2] ms, the sum of all values is 1.2+1.8=3.0, 3.0+2.0=5.0, 5.0+1.5=6.5, 6.5+2.3=8.8, 8.8+3.0=11.8, 11.8+3.5=15.3, 15.3+1.7=17.0, 17.0+2.1=19.1, 19.1+3.2=22.3 ms, divided by the number of periods 10 to get the average value 2.23 ms, taking the average value 2.23 ms as the reference, the buffer zone threshold interval [1.5 ms, 2.5 ms] and the enhancement zone threshold interval (2.5 ms, ∞) are set, according to the judgment result, node A and node B are classified as the buffer zone, and node C is classified as the enhancement zone, the interval corresponding relationship is established, the buffer zone is mapped to identifier 0, and the enhancement zone is mapped to identifier 1, the mask interval division value node A: 0, node B: 0, node C: 1 is generated.

[0030] Table 2: Mask parameter interval threshold table

[0031] S202: Adjust the key nesting level based on the mask interval division value, increase the number of levels according to the enhancement zone, reduce the number of levels according to the buffer zone, and arrange the multi-interval level parameters to obtain a level adjustment coefficient; Based on the mask interval division value node A: 0, node B: 0, node C: 1, adjust the key nesting level, call node A division value 0, judge that it belongs to the buffer area, perform the reduce level number operation, the initial level number is 3 layers, reduce 1 layer to get 2 layers, call node B division value 0, judge that it belongs to the buffer area, reduce 1 layer to get 2 layers, call node C division value 1, judge that it belongs to the enhanced area, perform the increase level number operation, increase 1 layer to get 4 layers, arrange the multi-interval level parameters, node A level value 2, node B level value 2, node C level value 4, calculate the level adjustment coefficient, perform the division operation on node A 2 / initial level 3 to get 0.6667, perform the division operation on node B 2 / 3 to get 0.6667, perform the division operation on node C 4 / 3 to get 1.3333, generate the level adjustment coefficient node A: 0.6667, node B: 0.6667, node C: 1.3333.

[0032] S203: Call the level adjustment coefficient and combine the mask interval division value to correct the key length synchronously, combine the corrected level parameters and length parameters to generate the encryption structure parameter set; Call the level adjustment coefficient node A: 0.6667, node B: 0.6667, node C: 1.3333 and combine the mask interval division value node A: 0, node B: 0, node C: 1 to correct the key length synchronously, call node A value 0 based on the division value, judge that it is a buffer area, the initial key length is 128 bits, perform the length reduction operation, the reduction proportion refers to the coefficient 0.6667, calculate the corrected length 128*0.6667=85.3376 bits, take the integer to get 85 bits, call node B value 0, judge that it is a buffer area, 128*0.6667=85.3376 bits take the integer to get 85 bits, call node C value 1, judge that it is an enhanced area, perform the length increase operation, the increase proportion refers to the coefficient 1.3333, calculate the corrected length 128*1.3333=170.6624 bits take the integer to get 171 bits, perform the combination operation on the corrected level parameters node A level value 2, node B level value 2, node C level value 4 and the length parameters node A length 85 bits, node B length 85 bits, node C length 171 bits, node A is combined into a tuple (2, 85), node B is combined into a tuple (2, 85), node C is combined into a tuple (4, 171), generate the encryption structure parameter set A: (2, 85), B: (2, 85), C: (4, 171).

[0033] Please refer to Figure 4 , the specific steps of S3 are: S301: Based on the encryption structure parameter set, collect the server processing capacity and load parameters, compare the collected processing capacity value and load occupation value, calculate the current available operation capacity of the server, and generate the server operation capacity; Based on the encryption structure parameter set A: (2, 85), B: (2, 85), C: (4, 171), the server processing capacity parameters are collected, for example, the processing capacity of node A is obtained by the system performance monitoring tool CPU peak operation capacity 1000GFlops, the load occupancy parameters are collected by the real-time interface of the operating system CPU usage rate 70%, the processing capacity value 1000GFlops and the load occupancy value 70% are called, the comparison operation is performed, the load occupancy value is compared with the preset high load threshold 70%, the threshold is set with reference to the 10 period load data sequence [65, 68, 72, 75, 70, 69, 73, 71, 74, 70]%, the sum of all values 65+68=133, 133+72=205, 205+75=280, 280+70=350, 350+69=419, 419+73=492, 492+71=563, 563+74=637, 637+70=707% is calculated, and the period number 10 is divided to be equal to the average value 70%, the high load threshold is set as 70%, 70% is in the high load interval, the current available operation capacity of the server is calculated, the subtraction operation 1-70% divided by 100 is 0.3, the multiplication operation processing capacity value 1000GFlops multiplied by 0.3 is 300GFlops, similarly, node B collects the processing capacity 900GFlops and the load 65%, judges that 65% is less than 70% in the low load interval, calculates 900 (1-0.65)=315GFlops, node C collects the processing capacity 1200GFlops and the load 50%, judges that 50% is less than 70% in the low load interval, calculates 1200 (1-0.5)=600GFlops, generates the server operation capacity node A: 300GFlops, node B: 315GFlops, node C: 600GFlops.

[0034] S302: Call the server operation capacity and collect the link communication distance parameters, map the link communication distance and the operation capacity value, pair according to the combination of the two parameters in the same interval, and generate the communication capacity mapping value; Call server computing power {A: 300 GFlops, B: 315 GFlops, C: 600 GFlops}, collect link communication distance parameters, for example, the distance between node A and the data center is 50 kilometers calculated by GPS coordinates, the distance between node B is 150 kilometers, and the distance between node C is 300 kilometers. The link communication distance is numerically mapped with the computing power value, the distance interval threshold is set, the international network standard is referred to for division, the distance less than 100 kilometers is the near range interval threshold, 100 to 500 kilometers is the medium range interval threshold, and greater than 500 kilometers is the long range interval threshold. The mapping rule defines the near range interval computing power multiplier 1.0, the medium range multiplier 0.8, and the long range multiplier 0.5. Node A distance 50 kilometers less than 100, classified as near range, mapping value calculation 300 1.0=300, node B distance 150 kilometers between 100 to 500, classified as medium range, mapping value calculation 315 0.8=252, node C distance 300 kilometers medium range, mapping value calculation 600 0.8=480, generate communication capability mapping value node A: 300, node B: 252, node C: 480.

[0035] S303: According to the communication capability mapping value, combine and arrange the parameter set of the encryption structure, bind the computing power value under multiple link distances with the structure parameter set, and generate a topology capability mapping table;

[0036] According to the communication capability mapping value {A: 300, B: 252, C: 480} combined with the encryption structure parameter set A: (2, 85), B: (2, 85), C: (4, 171), combine and arrange, call node A communication capability mapping value 300 and encryption structure parameter level 2 length 85 bits, bind as tuple (300, 2, 85), node B mapping value 252 and level 2 length 85 bits bind as tuple (252, 2, 85), node C mapping value 480 and level 4 length 171 bits bind as tuple (480, 4, 171), bind the computing power value under multiple link distances with the structure parameter set, and generate a topology capability mapping table.

[0037] Table 3: Topology capability mapping table

[0038] Please refer to Figure 5 , the specific steps of S4 are:

[0039] S401: According to the encryption structure parameter set, obtain the computing power of multiple servers, and compare with the available computing power of the server. According to the computing resources of the server and the encryption task demand, task allocation is carried out, and the task matching amount is obtained; Based on the encryption structure parameter set A: (2, 85), B: (2, 85), C: (4, 171), obtain the computing power of multiple servers, call the computing power parameters of node A through the server performance monitoring interface to collect CPU peak processing power 1000GFlops, node B collects 900GFlops, and node C collects 1200GFlops, call the available operation capability parameters of the server to obtain the available capability of node A 300GFlops, node B 315GFlops, and node C 600GFlops from the S301 result, perform a comparison operation, calculate the resource utilization value, the formula is available capability divided by computing power multiplied by 100%, node A calculates 300 / 1000 100=30%, node B calculates 315 / 900 100=35%, and node C calculates 600 / 1200 100=50%, set the load threshold interval, refer to the 10-period utilization data sequence [25, 30, 40, 45, 35, 38, 42, 48, 32, 28]%, sum all values 25+30=55, 55+40=95, 95+45=140, 140+35=175, 175+38=213, 213+42=255, 255+48=303, 303+32=335, 335+28=363%, divide by the number of periods 10 to get the average value 36.3%, set the low load threshold interval [0%, 40%] and the high load threshold interval (40%, 100%), judge that the value of node A 30% is less than 40% and is in the low load interval, the value of node B 35% is less than 40% and is in the low load, and the value of node C 50% is greater than 40% and is in the high load, according to the calculation resource and the encryption task demand, perform task allocation, define the task demand parameters, task 1 size 200GFlops, task 2 size 150GFlops, and task 3 size 300GFlops, call the available capability of node A 300GFlops, compare the task 1 demand 200GFlops less than 300GFlops, perform the allocation operation, node A allocates task 1, the remaining capability 300-200=100GFlops, call the available capability of node B 315GFlops, compare the task 2 demand 150GFlops less than 315GFlops, allocate task 2, the remaining capability 315-150=165GFlops, call the available capability of node C 600GFlops, compare the task 3 demand 300GFlops less than 600GFlops, allocate task 3, the remaining capability 600-300=300GFlops, calculate the task matching amount, sum the allocated task size 200+150+300=650GFlops, and generate the task matching amount 650GFlops.

[0040] Table 4: Server capability and task allocation table

[0041] S402: Based on the task matching amount, the computing demand of the encryption task is matched, the HEFT algorithm is called to optimize the allocation of the encryption task, the execution scheduling of the task between multiple servers is generated, and a task scheduling list is obtained; Based on the task matching amount 650GFlops, the computing demand of the encryption task is matched, the task demand parameters task1 size 200GFlops, task2 size 150GFlops, and task3 size 300GFlops are called, the estimated execution time of each task on the server is calculated, the formula is task size divided by server available capacity, node A available capacity 300GFlops, task1 execution time 200 / 300≈0.6667 hours, node B available capacity 315GFlops, task2 execution time 150 / 315≈0.4762 hours, node C available capacity 600GFlops, task3 execution time 300 / 600=0.5 hours, the specific action of calling the HEFT algorithm to optimize the allocation is called, the task priority is calculated, and the tasks are sorted in ascending order according to the execution time, task2 time 0.4762 hours has the highest priority, task1 time 0.6667 hours is second, and task3 time 0.5 hours, the sorted task sequence is [task2, task3, task1], the tasks are allocated to the servers to minimize the total completion time, the initial time is 0 hours, task2 is allocated to node B, the start time is 0 hours, the end time is 0+0.4762=0.4762 hours, task3 is allocated to node C, the start time is 0 hours (in parallel), the end time is 0+0.5=0.5 hours, task1 is allocated to node A, the start time is 0 hours, and the end time is 0+0.6667=0.6667 hours, the total completion time is max(0.4762, 0.5, 0.6667)=0.6667 hours, the above content is arranged, node B executes task2 in the time period [0, 0.4762], node C executes task3 in the time period [0, 0.5], and node A executes task1 in the time period [0, 0.6667], a task scheduling list is obtained, task2, B, [0, 0.4762], task3, C, [0, 0.5], and task1, A, [0, 0.6667].

[0042] S403: According to the task scheduling list, the time delay in the multi-task execution process is calculated, the network status and computing capacity between multiple nodes are combined, and an encryption task table is generated; According to the task scheduling list, task 2, B, [0, 0.4762], task 3, C, [0, 0.5], task 1, A, [0, 0.6667], calculate the time delay during multi-task execution, call the task execution time period, task 2 delay equals the end time minus the start time 0.4762-0=0.4762 hours, task 3 delay 0.5-0=0.5 hours, task 1 delay 0.6667-0=0.6667 hours, combined with the network status and computing power between multiple nodes, collect network status parameters inter-node delay, node A to B delay 0.02 hours through ping test, node B to C delay 0.03 hours, node C to A delay 0.025 hours, calculate the total task delay including processing delay plus network delay, task 2 total delay 0.4762+0 (no dependent network delay)=0.4762 hours, task 3 total delay 0.5+0=0.5 hours, task 1 total delay 0.6667+0=0.6667 hours, bind task identifier, server node, total delay value, task 2 entry (task 2, B, 0.4762), task 3 entry (task 3, C, 0.5), task 1 entry (task 1, A, 0.6667), generate encrypted task table (task 2: B: 0.4762), (task 3: C: 0.5), (task 1: A: 0.6667).

[0043] Please refer to Figure 6 , the specific steps of S5 are: S501: According to the topology capability mapping table and the encrypted task table, call the weighted average model to calculate and normalize the capability values and corresponding delay values of multiple nodes in proportion to the weight, and generate an encrypted control factor;

[0044] Based on the topology capability mapping table (table 3: node A computing power 300 GFlops, encryption level 2, key length 85 bits, node B 252 GFlops level 2, length 85 bits, node C 480 GFlops level 4, length 171 bits) and the encrypted task table (node A task 1 delay 0.6667 hours, node B task 2 delay 0.4762 hours, node C task 3 delay 0.5 hours), call the weighted average model, set the capability value weight (refer to the security requirement specification, assign weight 0.7 when encryption level ≥ 3, assign 0.5 when level < 3, node A level 2 takes 0.5, node B level 2 takes 0.5, node C level 4 takes 0.7), delay value weight (according to real-time requirements, set delay threshold 0.6 hours, assign weight 0.4 if exceeding the threshold, assign 0.2 if not exceeding, node A delay 0.6667>0.6 takes 0.4, node B delay 0.4762<0.6 takes 0.2, node C delay 0.5<0.6 takes 0.2), calculate the node weighted value, node A: Node B: Node C: Summation weighting value Normalized Node A: Node B: Node C: Generate encryption control factor Node A: 0.2982, Node B: 0.2429, Node C: 0.4589.

[0045] S502: Based on the encryption control factor, detect the influence of the encryption nesting level parameter and the task allocation method on the number of encryption nesting layers and the task division ratio, and adjust the number of nesting layers and the task allocation parameter according to the difference, to obtain the encryption complexity coefficient; Based on the encryption control factor Node A: 0.2982, Node B: 0.2429, Node C: 0.4589, for the encryption nesting level parameter (Node A level 2, Node B level 2, Node C level 4) and the task allocation ratio (Node A task amount 200 / 650≈0.3077, Node B 150 / 650≈0.2308, Node C 300 / 650≈0.4615), detect the difference between the control factor and the task ratio, Node A: Node B: Node C: Set the difference threshold value 0.01 (refer to the 10-period difference average calculation: sequence [0.008, 0.013, 0.009, 0.012, 0.007, 0.011, 0.010, 0.014, 0.006, 0.009] sum 0.099, average 0.0099≈0.01), judge Node A difference 0.0095<0.01 not to adjust the level, Node B difference 0.0121>0.01 need to increase the level, Node C difference 0.0026<0.01 not to adjust the level, Node B original level 2 increases by 1 layer to 3 layers, and the task allocation ratio is adjusted, Node B original ratio 0.2308 multiplied by level adjustment coefficient 3 / 2=1.5 to get 0.3462, the total ratio is normalized again 0.3077+0.3462+0.4615=1.1154, Node A new ratio 0.3077 / 1.1154≈0.2759, Node B new ratio 0.3462 / 1.1154≈0.3104, Node C new ratio 0.4615 / 1.1154≈0.4137, get the encryption complexity coefficient Node A: (level 2, ratio 0.2759), Node B: (level 3, ratio 0.3104), Node C: (level 4, ratio 0.4137).

[0046] Table 5: Complexity coefficient adjustment table

[0047] As shown in Table 5, the adjusted task proportion is shown with the encryption level.

[0048] S503: Call the encryption complexity coefficient, and compare it with the actual time consumption of the task. According to the comparison deviation result, update the calculation process of information encryption transmission, and generate information encryption transmission result; Call encryption complexity coefficient nodes A: (2, 0.2759), node B: (3, 0.3104), node C: (4, 0.4137), and compare with the actual time consumption of the task (node A task 1 time consumption 0.6667 hours, node B task 2 time consumption 0.4762 hours, node C task 3 time consumption 0.5 hours), calculate the expected time consumption, the formula is task size x level coefficient / available capacity, the level coefficient benchmark value 2 layers take 1.0, node A expected: hours, node B level 3 coefficient 1.5, expected: hours, node C level 4 coefficient 2.0, expected: hours, calculate the deviation amount of node A: , node B: , node C: , set the deviation threshold 0.3 (according to the maximum delay fluctuation rate allowed by the communication standard protocol 30%), node B deviation 0.2381 <0.3 not update, node C deviation 0.5 >0.3 need update, node C uses new level coefficient 1.8 (reduce 0.2 based on benchmark 2.0), recalculate task time consumption hours, deviation Still above threshold, update coefficient to 1.6, time consumption hours, deviation Equal to the threshold, generate information encryption transmission result node A: 0.6667 hours, node B: 0.4762 hours, node C: 0.8 hours.

[0049] Please refer to Figure 7 , network communication information encryption transmission system, comprising: Delay analysis module, collect end-to-end transmission delay parameters and server queuing delay parameters before the message enters the transmission channel, and totalize to get real-time total delay, extract error from the current total result and the last cycle total result, and combine with multiple server queuing delay parameters to generate delay redundancy mask and pass to delay judgment module; Delay judgment module, based on delay redundancy mask to judge mask interval and divide into enhancement zone and buffer zone, and adjust the nesting level and length of the key according to the interval, generate encryption structure parameter set and pass to routing topology module; A routing topology module collects server processing capacity and load parameters and calculates server available computing capacity based on the encryption structure parameter set, simultaneously collects link communication distance parameters for combined mapping, constructs a topology capacity mapping table and delivers it to the task allocation module; A task allocation module inputs the encryption structure parameter set and the topology capacity mapping table into the HEFT algorithm to allocate encryption tasks, matches the encryption tasks according to the server available computing capacity, generates an encryption task table and delivers it to the encryption control module; An encryption control module generates an encryption control factor through a weighted average model based on the topology capacity mapping table and the encryption task table, adjusts the encryption nesting level depth and the task allocation mode according to the encryption control factor and compares it with the actual time consumption to generate an information encryption transmission result.

[0050] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for encrypted transmission of network communication information, characterized in that, Includes the following steps: S1: Collect the end-to-end transmission delay parameters and server queuing delay parameters before the message enters the transmission channel and sum them to obtain the real-time total delay. Extract the error between the current summing result and the previous period's summing result, and combine the multi-server queuing delay parameters for normalization to generate a delay redundancy mask. S2: Based on the aforementioned delay redundancy mask, determine the mask interval and divide it into an enhancement area and a buffer. Adjust the nesting level and length of the key according to the interval to generate an encryption structure parameter set. S3: Based on the encrypted structure parameter set, collect server processing capacity and load parameters and calculate the available computing power of the server. At the same time, collect link communication distance parameters and combine them for mapping to construct a topology capability mapping table. S4: Input the encrypted structure parameter set and topology capability mapping table into the HEFT algorithm to allocate encryption tasks, match the encryption tasks according to the available computing power of the server, and generate an encryption task table. S5: The topology capability mapping table and the encryption task table are used to generate an encryption control factor through a weighted average model. The encryption nesting level depth and task allocation method are adjusted according to the encryption control factor and compared with the actual time consumption to generate the information encryption transmission result.

2. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The delay redundancy mask includes a normalization coefficient and a real-time total delay. The encryption structure parameter set specifically refers to nesting level parameters, key length parameters, and interval category parameters. The topology capability mapping table includes available server computing power, link communication distance, and load parameters. The encryption task table specifically includes a task allocation matrix, server matching index, and computing resource distribution. The information encryption transmission result includes an encryption control factor, nesting level depth, and task allocation method.

3. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The specific steps of S1 are as follows: S101: Collect end-to-end transmission delay parameters and server queuing delay parameters before the message enters the transmission channel. Summate the collected end-to-end transmission delay parameters and multiple server queuing delay parameters to generate the real-time total delay. S102: Based on the real-time total delay, obtain the delay value obtained by summing the previous period, calculate the difference between the two and use it as the offset of the current delay change, and at the same time call the queuing delay parameters of multiple routing nodes, combine them with the offset and normalize them to obtain the normalized offset coefficient. S103: Distribute the queuing delay parameters of the multi-node according to the normalized offset coefficient to form a corresponding mask, and map it with the currently calculated difference to generate a delay redundancy mask.

4. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The specific steps of S2 are as follows: S201: Obtain the mask interval based on the time delay redundancy mask parameter, classify the mask interval into an enhancement area or a buffer according to the interval threshold, establish the interval correspondence after classification, and generate the mask interval division value. S202: Adjust the key nesting level based on the mask interval division value, increase the number of levels corresponding to the enhancement area, decrease the number of levels corresponding to the buffer area, and sort out the multi-interval level parameters to obtain the level adjustment coefficient; S203: Call the level adjustment coefficient and combine it with the mask interval division value to simultaneously correct the key length. Combine the corrected level parameters with the length parameters to generate an encryption structure parameter set.

5. The method for encrypted transmission of network communication information according to claim 4, characterized in that, The interval threshold is set by statistically detecting the numerical distribution of the delay redundancy mask parameter, calculating the maximum and minimum values, and then dividing the range interval proportionally.

6. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The specific steps for S3 are as follows: S301: Based on the encrypted structure parameter set, collect the server processing capacity and load parameters, compare the collected processing capacity value with the load occupancy value, calculate the server's current available computing capacity, and generate the server computing capacity. S302: Call the server's computing power and collect the link communication distance parameters, map the link communication distance to the computing power value, pair the two types of parameters according to the combination of the same range, and generate a communication capability mapping value; S303: Based on the communication capability mapping value and the encrypted structure parameter set, the computing capability values ​​under multiple link distances are combined and organized to bind the corresponding structure parameter sets, and a topology capability mapping table is generated.

7. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The specific steps of S4 are as follows: S401: Based on the encrypted structure parameter set, obtain the computing power of multiple servers, compare it with the available computing power of the servers, allocate tasks according to the computing resources of the servers and the encryption task requirements, and obtain the task matching quantity. S402: Based on the task matching quantity, match it with the computational requirements of the encryption task, call the HEFT algorithm to optimize the allocation of the encryption task, generate the execution schedule of the task among multiple servers, and obtain the task schedule list. S403: Based on the task scheduling list, calculate the latency during the execution of multiple tasks, and generate an encrypted task table by combining the network conditions and computing capabilities among multiple nodes.

8. The method for encrypted transmission of network communication information according to claim 1, characterized in that, The specific steps of S5 are as follows: S501: Based on the topology capability mapping table and the encryption task table, call the weighted average model to calculate and normalize the capability values ​​and corresponding latency values ​​of multiple nodes according to the weight ratio, and generate the encryption control factor. S502: Based on the encryption control factor, for the encryption nesting level parameters and task allocation method, detect the impact on the number of encryption nesting levels and the task division ratio, and adjust the number of nesting levels and task allocation parameters according to the differences to obtain the encryption complexity coefficient. S503: Call the encryption complexity coefficient and compare it with the actual time consumed by the task. Update the calculation process of information encryption transmission based on the comparison deviation result and generate information encryption transmission result.

9. The method for encrypted transmission of network communication information according to claim 8, characterized in that, The encryption complexity coefficient is calculated and set based on the computational complexity of the encryption algorithm, the number of nesting levels, the key length, the task allocation method, and the execution delay factor.

10. A network communication information encryption transmission system, characterized in that, The system is used to implement the network communication information encryption transmission method according to any one of claims 1-9, and the system comprises: The delay analysis module collects end-to-end transmission delay parameters and server queuing delay parameters before the message enters the transmission channel and sums them to obtain the real-time total delay. It extracts the error between the current summation result and the summation result of the previous period, and combines the normalization of the multi-server queuing delay parameters to generate a delay redundancy mask and transmit it to the delay discrimination module. The delay discrimination module determines the mask interval based on the delay redundancy mask and divides it into an enhancement area and a buffer. It also adjusts the nesting level and length of the key according to the interval, generates an encrypted structure parameter set, and transmits it to the routing topology module. The routing topology module, based on the encrypted structure parameter set, collects server processing capacity and load parameters and calculates the available computing power of the server. At the same time, it collects link communication distance parameters, performs combined mapping, constructs a topology capability mapping table, and transmits it to the task allocation module. The task allocation module inputs the encrypted structure parameter set and topology capability mapping table into the HEFT algorithm to allocate encryption tasks, matches the encryption tasks according to the available computing power of the server, generates an encryption task table, and transmits it to the encryption control module. The encryption control module generates an encryption control factor by using a weighted average model to map the topology capability table and the encryption task table. Based on the encryption control factor, it adjusts the encryption nesting level depth and task allocation method and compares the results with the actual time consumption to generate the encrypted information transmission result.

Citation Information

Patent Citations

  • Distributed data encryption transmission system

    CN117955749A

  • Security channel networking method based on edge computing power

    CN119814582A

  • Cloud platform scheduling method and system based on multi-source Internet of Things perception

    CN120281821A

  • Verifiable safe and efficient federated learning method

    CN120358015A