Security encryption method and system based on applet software

By using a multi-dimensional dynamic behavior determination mechanism and a perturbation time offset sequence, the problem of time predictability of key transmission in mini-program communication is solved, achieving efficient and secure encryption of the mini-program communication process and improving the information security protection capability of the mini-program communication process.

CN121333748APending Publication Date: 2026-01-13FOSHAN ZHIZHI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511646301.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing mini-program communication encryption mechanisms have time-inferable characteristics during key transmission and retrieval. Attackers can build multi-user key inference chains by listening to the time characteristics of user requests and responses, leading to data security threats. Traditional technologies lack dynamic perturbation design for time correlation, making them difficult to defend against.

Method used

By establishing a multi-dimensional dynamic behavior judgment mechanism, collecting user interaction rhythm, terminal clock frequency fluctuations and network response characteristics, generating risk entropy factors and time escaping values, identifying potential temporal risks, and introducing a perturbation time offset sequence during key invocation, dynamically invoking key pair combinations in the asymmetric key pool, thereby enhancing the unmodelability of key distribution behavior.

Benefits of technology

It significantly reduces the risk of key leakage in unstable networks or controlled terminal states, improves the information security protection capabilities of mini-program communication processes, enhances the defense advantages against attackers, increases the complexity and unpredictability of encryption logic, and cuts off the attacker's listening chain based on time characteristics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333748A_ABST
    Figure CN121333748A_ABST
Patent Text Reader

Abstract

The invention discloses a security encryption method and system based on applet software, and particularly relates to the technical field of information security, and the method comprises the following steps: constructing a multi-dimensional dynamic behavior judgment mechanism, collecting user interaction rhythm, terminal clock frequency fluctuation and network response characteristics, and judging whether the user is in a key transmission high-sensitivity risk period; if the time sequence risk exists, extracting a feature to generate a risk entropy factor and a time escape value, and establishing a time sequence evolution model to judge whether disturbance needs to be injected or not; when the key use behavior shows regularity, a disturbance time migration sequence is introduced; dynamically calling an asymmetric key pair in combination with a risk index, and synchronously embedding the asymmetric key pair with a disturbance time sequence; according to the method, the inference risk is evaluated by dynamically identifying a time sequence sensitive environment and constructing a risk entropy factor and a time hidden magnitude value, and a disturbance time migration and asymmetric key embedding mechanism is introduced, so that the unpredictability and the anti-inference capability of a key calling path are enhanced, and high-strength encryption protection of an applet communication process is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, more particularly, the present application relates to a secure encryption method and system based on a small program software. BACKGROUND

[0002] With the increasing popularity of mobile services, small programs as a lightweight application mode are widely deployed in high-sensitive business scenarios such as financial payment, government interaction, and identity authentication. In these scenarios, users often need to complete security operations such as data submission, identity verification, and key exchange through small programs, and the system needs to implement data encryption through network security protocols in each interaction. However, due to the characteristics of strong observability, centralized calling behavior, and terminal diversification, small programs expose obvious time predictability in key scheduling and calling process, providing opportunities for attackers to implement reasoning attacks.

[0003] In the current mainstream small program communication encryption mechanism, key transmission and calling often use static timing or weak dynamic logic, that is, according to the time point of user request initiation, the server generates or distributes keys to complete the encryption and decryption process. Although there is a certain encryption protection at the transmission layer, this mechanism does not usually consider the risk of continuous monitoring and modeling of request and response time by external attackers. When an attacker continuously monitors the communication behavior of multiple small program terminals, he can infer the time distribution of system key calling by comparing the encryption request triggering time of different users, response delay, and other characteristics, and thus build a so-called "multi-user key reasoning chain".

[0004] This attack method has high concealment and batch nature. Once the attacker successfully builds a time difference model and reverses the encryption path or key scheduling rules, he can achieve centralized decryption of a large amount of user data, forming a serious data security threat. Traditional technologies have limited risk identification capabilities, and existing key rotation mechanisms often lack dynamic disturbance design for "time correlation", making it difficult to break the prediction path of external observers from the source. Therefore, a secure encryption method and system based on a small program software is proposed to solve the above problems. SUMMARY

[0005] To achieve the above purpose, the present application provides the following technical solutions: A secure encryption method based on a small program software, comprising the following steps: Before the small program initiates a communication request, a multi-dimensional dynamic behavior judgment mechanism is established to continuously collect user interaction rhythm, terminal clock frequency fluctuation, and network response characteristics to determine whether the current environment is in a timing-sensitive stage of key transmission; If it is determined that there is a potential timing risk, based on historical dynamic behavior characteristic data, a time difference evolution trajectory is identified, a risk entropy factor of key distribution and a time implicit value are generated through multi-dimensional feature fitting, and are used to measure the reasoning predictability level of the current key use scenario; According to the risk entropy factor and the time implicit value, a timing evolution model of the current key call history is established, and whether there is a periodic or trend key distribution characteristic is analyzed by comparing the prediction curve and the regression residual, so as to determine whether a timing disturbance needs to be injected; If the analysis result shows that the key use mode presents a regularization tendency, then a disturbance control parameter set is constructed based on the reasoning strength, a disturbance time offset sequence is introduced in the key call scheduling process, a nonlinear time domain behavior trajectory is generated, and the path of establishing a reverse prediction model by an external observer through a response time difference is cut off; Based on the risk entropy factor and the time implicit value, key pairs in the asymmetric key pool are dynamically called, and the key call order is synchronized and embedded with the disturbance time sequence, so as to enhance the non-modelability of the key distribution behavior in the observation dimension.

[0006] In a preferred embodiment, the user interaction rhythm, terminal clock frequency fluctuation and network response characteristics are collected and calculated by the following steps: After the user applet interface is loaded, the embedded collection logic is started, the touch dwell time, sliding acceleration and click frequency of the user on different components are recorded through time stamp, and the time series data of the user operation behavior is formed to generate the interaction rhythm characteristic curve; During the device running process, the instantaneous value of the terminal processor clock signal is periodically read through system-level calling, and the coefficient of variation of the sequence is calculated based on statistical method to evaluate the degree of terminal clock frequency fluctuation; For network response characteristics, multiple handshake requests are established with the applet server to record the response time delay, packet loss rate and bandwidth fluctuation value of each time, and a network response behavior atlas is constructed; After the above data is standardized, it is sent as input features into the multi-dimensional dynamic behavior judgment mechanism.

[0007] In a preferred embodiment, the multi-dimensional dynamic behavior judgment mechanism refers to: User interaction rhythm characteristic curve, terminal clock frequency fluctuation curve and network response behavior atlas are generated respectively, and are converted into three types of feature vectors to represent the behavior characteristics in the current state; The three types of current feature vectors are compared with the reference feature vectors in the standard state respectively, the Euclidean distance between the current state and the standard state is calculated, and the deviation degree of the current behavior from the stable state is judged; If the Euclidean distance of any one type of feature exceeds the corresponding set distance threshold, the behavior of this type of feature is marked as unstable, and when at least one type of behavior feature is determined to be in an unstable state, it is determined that the current period is a high-sensitivity risk period of key transmission, and the static key distribution behavior is actively terminated in the high-sensitivity risk period.

[0008] In a preferred embodiment, when fitting multi-dimensional features, the following steps are included: Extract time series data from historical terminal clock frequency fluctuation records and network round-trip response time records, and combine the two types of data in chronological order to form a continuous time sequence response chain by synchronizing the time synchronization markers, which is used to construct the system time disturbance basis sequence; Map the time sequence response chain into a multi-dimensional state space using time sequence delay embedding, generate a state point sequence for representing the evolution of the time disturbance trajectory, and perform exponential growth trend analysis on the geometric distance change rate between consecutive state points to extract the time disturbance sensitivity index; Solve the time disturbance sensitivity index continuously on multiple time scales to construct a multi-scale disturbance stability curve, and generate a risk entropy factor of key distribution based on the curve, which reflects the trajectory divergence characteristics and the strength of predictability of the key invocation process in the time dimension.

[0009] In a preferred embodiment, the risk entropy factor of key distribution is generated by the following method: Solve the time disturbance sensitivity index continuously on multiple time scales to form a mapping relationship curve between the time scale and the disturbance response intensity, which reflects the stability of the trajectory divergence behavior under different time windows; Construct the disturbance response values at each scale into a disturbance response vector, and calculate the information entropy value of the vector, which is used to measure the degree of uncertainty of the disturbance distribution in the time dimension; the information entropy value is used as the risk entropy factor of the key distribution, which is used to measure whether the current key invocation behavior has regularity, concentration or predictability tendency under multi-scale time observation.

[0010] In a preferred embodiment, the time hidden quantity value is generated by the following steps: Based on the disturbance peak value distribution sequence composed of terminal clock fluctuation and network response delay, construct a sliding window at a fixed time interval, and calculate the following three indicators in each time window: the number of disturbance peak values; the standard deviation of disturbance intensity; the average time interval between adjacent disturbances; normalize and weighted sum the three indicators to generate the significance score of the window, which is used to measure the continuity and intensity stability of the disturbance behavior in the period; The significance scores of all time windows are constituted into a time series vector, an unsupervised clustering method based on local density peak detection is used to identify high-density areas of disturbance distribution, and by calculating the variance of the concentration of scores and the average duration in these clustering clusters, a time concentration index of disturbance distribution is generated, time concentration index = average score inside the clustering cluster × duration, which is used to quantify the local aggregation trend of disturbance behavior on the time axis; The time concentration index is mapped into a time hiding value according to a preset standardization interval mapping rule, which is used to represent the behavior repeatability and modeling identifiability of the disturbance behavior in the time dimension.

[0011] In a preferred embodiment, determining whether timing disturbance injection is needed refers to: The key call time series is time-aligned with the corresponding risk entropy factor and time hiding value to form a key call behavior trajectory, and a time trend fitting curve is generated based on local neighborhood similarity and step-by-step backtracking prediction error fitting mechanism to represent the time trend of key call behavior; Periodic window segment analysis is performed on the trend fitting curve, the difference between the actual key call value and the fitted value is constituted into a residual sequence, and kurtosis analysis is performed on the residual sequence to determine whether there is a sharp peak concentration phenomenon, skewness analysis is performed to determine whether there is a bias trend, and autocorrelation coefficient of the residual sequence is calculated to detect periodic repetition mode; The residual kurtosis, residual skewness and autocorrelation significance level are comprehensively determined, and when any statistical feature exceeds the set threshold interval, it is determined that the key call behavior has a concentration deviation, a periodic deviation or a trend fluctuation mode.

[0012] In a preferred embodiment, a disturbance time offset sequence is introduced in the key call scheduling process, including the following steps: After identifying that the key call behavior has regularity characteristics, a disturbance control parameter set is generated according to the combination strength of the risk entropy factor and the time hiding value, the disturbance control parameter set includes a disturbance amplitude parameter, a disturbance density parameter and a disturbance duration parameter, which are used to define the time disturbance level and disturbance scheduling period in the key call process; According to the disturbance control parameter set, a disturbance time offset sequence is constructed, by setting a non-uniform time step and a time offset change curve generated according to the preset offset rule based on the disturbance amplitude control parameter, the key call time is offset one by one, so that the key call behavior is no longer triggered at fixed time intervals, and a non-linear time offset mode is formed by continuously adjusting the delay period and the triggering time point; During the execution of the key call, the perturbation time offset sequence is synchronously bound with the key scheduling logic to insert perturbation delay and call timing change in a randomization manner, so that the generated key call time trajectory behaves as unpredictable nonlinear time domain behavior, and the attack uncertainty of the key call path is improved.

[0013] In a preferred embodiment, the dynamic call of the asymmetric key pool and the embedding of the perturbation time sequence are realized based on the risk entropy factor and the time implicit value, including the following steps: According to the risk entropy factor and the time implicit value calculated in the current period, the key call level and the security grouping strategy are set in the key management strategy, a plurality of key pair combinations meeting the level requirement are preselected from the asymmetric key pool to form a candidate key pair set; The perturbation time sequence corresponding to the key call plan is constructed, each time point in the perturbation time sequence is bound with one key pair in the candidate key pair combination one by one to form a key call index chain driven by the perturbation time.

[0014] In a preferred embodiment, a small program software-based secure encryption system specifically includes: The behavior perception module is used to establish a multi-dimensional dynamic behavior judgment mechanism before the small program initiates a communication request, continuously collect user interaction rhythm, terminal clock frequency fluctuation and network response characteristics to judge whether the current environment is in a time sequence sensitive stage of key transmission; The risk assessment module is used to identify the time difference evolution trajectory based on the historical dynamic behavior characteristic data when it is judged that there is potential time sequence risk, generate the risk entropy factor and the time implicit value of the key distribution through multi-dimensional feature fitting to measure the reasoning predictability level of the current key use scene; The time sequence modeling module is used to establish a time sequence evolution model of the current key call history according to the risk entropy factor and the time implicit value, and whether there is periodic or trend key distribution characteristics is compared and analyzed by combining the prediction curve and the regression residual, so as to judge whether time sequence perturbation needs to be injected; The perturbation injection module is used to construct a perturbation control parameter set based on the reasoning strength when the key use mode presents regularization tendency, and introduce a perturbation time offset sequence in the key call scheduling process to generate a nonlinear time domain behavior trajectory, so as to cut off the path of the external observer to establish a reverse prediction model through the response time difference; The key scheduling module is used to call the key pair combination in the asymmetric key pool based on the risk entropy factor and the time implicit value, and synchronously embed the key call sequence and the perturbation time sequence, so as to enhance the non-modelability of the key distribution behavior in the observation dimension.

[0015] The technical effects and advantages of the present application are: The application introduces a multi-dimensional dynamic behavior judgment mechanism before the applet initiates a communication request, fuses three types of time sequence sensitive features of user interaction rhythm, terminal clock frequency fluctuation and network response characteristics, and constructs a pre-judgment system with environment perception capability, thereby improving the environment adaptation capability of key distribution behavior from the source. Unlike the static modeling method of the communication process in the traditional scheme, the application takes the user behavior and device state in actual operation as the trigger signal source, judges whether the current environment is in the time sequence sensitive stage of key transmission in a dynamic perception manner, and automatically stops the static key distribution operation when it is judged as a high risk period. Through the mechanism, the application significantly reduces the leakage risk of the key in unstable network or controlled terminal state, especially in the scene where the attacker may conduct high-frequency detection, time sequence learning or side channel monitoring, and has a preemptive defense advantage. Taking the interaction rhythm as an example, if it is detected that the user operation appears mutation behavior (such as high-frequency clicking, extremely short sliding and staying) and is accompanied by a sharp increase in terminal clock frequency fluctuation and abnormal response delay, it is judged that the current state has weak unpredictability, and the static key injection is stopped in time, which can effectively cut off the monitoring chain of the attacker based on time characteristics, thereby significantly enhancing the information security protection capability of the applet initialization stage.

[0016] After identifying the potential time sequence risk, the application constructs a time difference evolution track through historical dynamic behavior feature data, further extracts multi-dimensional time sequence features based on the track, generates a risk entropy factor and a time hidden value, and measures the predictability level of the current key use scene. This mechanism breaks through the limitation of only doing static analysis on frequency or call sequence in the existing key calling system, constructs a dynamic modeling system of key distribution, and for the first time, the time evolution features of encryption behavior are included in the core index category of safety judgment. Among them, the risk entropy factor is used to reflect the track divergence of key calling behavior in the time scale, and the time hidden value is used to measure the reproducibility and identifiability of the disturbance behavior on the time axis. By taking the two as driving variables, the application can further establish a time sequence evolution model of the current key calling history, and identify whether there is a periodic, centralized or trend distribution rule by comparing the prediction curve and the regression residual. Taking an actual application as an example, if the system continuously monitors that a certain type of key calling presents a low-frequency, high-concentration distribution in a specific time window, and the residual autocorrelation coefficient significantly rises, it means that the behavior has a high risk tendency of being reverse modeled. The application can trigger the intervention mechanism in advance to block the feasibility of the attacker to build a reverse path, thereby significantly improving the complexity and unpredictability of the encryption logic.

[0017] The application further introduces a disturbance time offset sequence after identifying that the key usage mode presents a regularization tendency, and dynamically calls a key pair combination in an asymmetric key pool based on a risk entropy factor and a time implicit value, while synchronously embedding the key calling sequence and the disturbance time sequence, effectively improving the non-modelability of key distribution behavior in the observation dimension. Unlike the mode of key scheduling in the traditional scheme with a fixed period and a preset order, the application constructs a disturbance time offset sequence through a disturbance control parameter set, so that the key calling time point forms a nonlinear drift on the expected calling track, further improving the unpredictability of the time path. Then, the key pair combination in the key pool is classified according to the security level, and a key calling index chain is formed in combination with the disturbance time node, realizing the key distribution logic driven by the disturbance time. This structure has a double nonlinear superposition effect: on the one hand, the disturbance time axis disturbs the observation model of the calling rhythm of external attackers; on the other hand, the combination path of the asymmetric key pair forms a dynamically changing encryption boundary, thereby jointly constructing a high-strength dynamic encryption mechanism with anti-period reasoning, anti-residual modeling and anti-frequency guessing. For example, when the disturbance sequence presents a Poisson distribution form and the key calling trigger node introduces an exponential offset rule, even if the attacker obtains part of the response records at the time points, it is difficult to establish an effective model through regression or curve fitting. The application significantly improves the encryption security level and overall protection resilience of the small program communication process in a strong confrontation scene through the mechanism. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to facilitate the understanding of those skilled in the art, the application will be further described below in conjunction with the drawings; Figure 1 A schematic diagram of a security encryption method based on a small program software in the application.

[0019] Figure 2 A schematic diagram of a security encryption system based on a small program software in the application. DETAILED DESCRIPTION

[0020] The technical solutions in the embodiments of the application will be described clearly and completely below in conjunction with the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of the application.

[0021] Reference Figure 1 - Figure 2 The following embodiments are obtained: Embodiment 1: A security encryption method based on a small program software, comprising the following steps: Before the applet initiates a communication request, a multi-dimensional dynamic behavior judgment mechanism is established to continuously collect user interaction rhythm, terminal clock frequency fluctuation and network response characteristics to determine whether the current environment is in a timing sensitive stage for key transmission; whether the current running environment is in a timing exception or attack-prone state is perceived in advance, a dynamic environment judgment mechanism for key transmission behavior is constructed by collecting the timing regularity of user operation, the stability of terminal clock and the fluctuation of network link, etc., to effectively avoid continuing static key distribution in a high sensitive period and improve the pre-response capability of the system to timing attacks.

[0022] If it is determined that there is a potential timing risk, based on historical dynamic behavior characteristic data, the time difference evolution trajectory is identified, the risk entropy factor of key distribution and the time implicit value are generated by fitting multiple dimensions, which are used to measure the reasoning predictability level of the current key usage scenario; the time characteristic path that the system may expose is fitted and analyzed by using the accumulated dynamic behavior data in the past, the core measurement index related to uncertainty and predictability in disturbance evolution is extracted, the stability of key calling behavior in time dimension is evaluated by risk entropy factor, and the identifiable degree of system disturbance trajectory is judged by time implicit value, thereby providing a scientific decision basis for subsequent disturbance introduction.

[0023] According to the risk entropy factor and the time implicit value, a timing evolution model of the current key calling history is established, and whether there is a periodic or trend key distribution characteristic is analyzed by comparing the prediction curve and the regression residual, so as to determine whether timing disturbance needs to be injected; by constructing an alignment mechanism between the key calling trajectory and the time observation model, whether there is a behavior rule that can be captured by an external reasoning system is identified, if the residual sequence shows periodic concentration, trend deviation and other signs, it means that the current key usage mode of the system may have been learned or fitted, and disturbance mechanism needs to be introduced in time to break the original distribution rule, so as to prevent being established prediction model.

[0024] If the analysis result shows that the key usage mode presents a regularization tendency, disturbance control parameter set is constructed based on reasoning strength, disturbance time offset sequence is introduced in the key calling scheduling process, nonlinear time domain behavior trajectory is generated, and the path of establishing reverse prediction model by response time difference through external observer is cut off; for the identified distribution regularity, disturbance parameters are set according to the strength of prediction ability, the linear, uniform or stable key calling rhythm on the time axis is broken, disturbance time sequence with complex nonlinear structure is introduced, time disturbance of key calling path is realized, and the key behavior rule cannot be captured by external observation, which fundamentally increases the difficulty of prediction modeling.

[0025] Based on the risk entropy factor and the time hidden amount value, the key pair combination in the asymmetric key pool is dynamically called, and the key calling sequence is synchronized and embedded with the disturbance time sequence, so as to enhance the non-modelability of the key distribution behavior in the observation dimension. When performing key scheduling based on disturbance, not only different levels of key pairs are selected according to the evaluation of the system on predictability, but also the key calling behavior is synchronized and bound with the disturbance time point, so that the use trajectory of the key presents a high chaotic characteristic, further improving the non-modelability and the anti-reduction ability of the key sequence under the external observation angle.

[0026] In the embodiment, in order to determine whether the current environment is in the time sequence sensitive stage of key transmission, data collection and feature calculation of user interaction rhythm, terminal clock frequency fluctuation and network response characteristics are required, including the following steps: starting the embedded collection logic after loading the user applet interface, recording the touch dwell time of the user on different interface components, the start and end time and displacement change of the sliding operation, and the click frequency in unit time through time stamp, and then generating the time series data of user operation behavior, and fitting the feature curve of user interaction rhythm according to the time series data. The feature curve reflects the operation rhythm mode of the user in a period of time, such as whether the operation is coherent, whether the behavior is mutated, etc., which is used to identify the operation time sequence disorder caused by possible non-human intervention, automated simulation behavior or environmental abnormalities.

[0027] During the operation of the device, the system reads the instantaneous value of the system clock signal in the terminal processor through bottom calling at a fixed period, and calculates the standard deviation and mean ratio of a series of data by using statistical method, so as to obtain the fluctuation degree parameter for representing the fluctuation degree of clock frequency; when the parameter value is at a high level, it indicates that the terminal device may have high processor load, insufficient power stability or other system level fluctuation risk, which is easy to cause time instability in the process of key generation and transmission.

[0028] For the network response characteristics, the system actively establishes multiple rounds of handshake connection with the server during the running of the applet, records the response time of each round, the ratio of whether the data is received completely, and the upper and lower limit change value of the bandwidth in the same time period by repeatedly sending requests, and constructs a network response behavior graph with time dimension; the graph can directly reflect the changes of transmission delay, jitter strength, packet loss ratio and bandwidth fluctuation in the network path, which is used to judge whether the current network is stable, whether there is potential delay attack or replay risk.

[0029] The user interaction rhythm feature curve, terminal clock frequency fluctuation parameter and network response behavior atlas are normalized respectively, and after being uniformly mapped to a standard feature interval, the three types of data are combined as an input feature vector and sent to a multi-dimensional dynamic behavior judgment mechanism for environment state analysis; this step makes the behavior features of different dimensions comparable and have a unified measurement basis, thereby improving the discrimination accuracy of the system for the key transmission time-sensitive stage, ensuring that the static key is not exposed during the high-sensitive period, and improving the time sequence security of the overall encryption system.

[0030] In the present embodiment, in order to realize the active judgment of the key distribution time sequence security under the current applet running environment, the system designs a complete multi-dimensional dynamic behavior judgment mechanism, which is based on user behavior data, terminal running data and network state data for multi-dimensional feature extraction and difference analysis, and is used to judge whether the current is in the high-sensitive risk period of key transmission. The specific implementation process includes the following steps: generating user interaction rhythm feature curve, terminal clock frequency fluctuation curve and network response behavior atlas respectively, and converting them into three types of feature vectors to represent the behavior features in the current state; in this step, the system continuously records the touch time, sliding trajectory and click frequency of the user on each component of the interface after loading the applet user interface, sorts and structures these operation behaviors by time to generate the interaction rhythm feature curve which can be used for subsequent calculation. At the same time, the system background reads the system clock value sequence of the terminal processor core at a fixed interval, and records the fluctuation of the clock signal in a certain period of time, thereby generating the terminal clock frequency fluctuation curve. Further, the system collects dynamic network state data including response time, data transmission completion rate, network bandwidth change range by repeatedly establishing a handshake process with the server, and constructs a network response behavior atlas with time as the axis. After being standardized, the three types of data are converted into feature vectors of a unified format, which fully represent the user behavior stability, terminal device clock accuracy and network environment quality in the current running state.

[0031] The three types of current feature vectors are compared with the reference feature vectors in the standard state, and the deviation degree of the current behavior from the stable state is judged by calculating the Euclidean distance between the current state and the standard state. In this step, the system first calls the feature data marked as a stable state in the historical collection process to establish the reference vector set of interactive rhythm, clock fluctuation and network state as the built-in reference standard of the system. For example, the standard state of interactive rhythm may be reflected in uniform click frequency, smooth sliding trajectory, and reasonable distribution of dwell time; the standard state of the terminal clock is that the clock frequency remains within a stable range with low frequency variation amplitude; the standard state of network response includes low delay, low packet loss, and high bandwidth. Subsequently, the system calculates the Euclidean distance between the current feature vector and the corresponding standard vector, which is used to quantify the deviation degree between the current state and the ideal stable state. Taking user interactive rhythm as an example, if the current touch timing deviation is large, such as the click density concentrated in a short period of time and the sliding operation showing abnormal speed change, the distance value will be significantly larger, indicating that the interactive state is unstable.

[0032] If the Euclidean distance of any type of feature exceeds the corresponding distance threshold, the behavior of this type is marked as unstable. When at least one type of behavior feature is judged to be in an unstable state, it is determined that the current time is in a high-sensitivity risk period of key transmission, and the static key distribution behavior is actively terminated in the high-sensitivity risk period. To improve the risk recognition ability of the system, the platform sets a specific threshold for each type of feature to determine whether it is in an abnormal interval. This threshold is based on large-scale user sample statistics, such as the distance threshold of interactive rhythm, which can be set to the upper limit of the interval formed by the mean value of a high-frequency operation sample plus two standard deviations. When the distance of the current behavior exceeds this interval, it is determined that the behavior deviates significantly from the stable state in time. The system independently judges each type of feature during operation, and once any type of behavior is marked as unstable, the current time window is immediately classified as a high-sensitivity risk period. In this high-sensitivity risk state, the system immediately suspends the current or upcoming static key distribution action, avoiding the use of key information by external attackers to model and reason in a state of enhanced time observability, thereby reducing the risk of key leakage.

[0033] To ensure the accuracy of the judgment result and the improvement of the system adaptability, the system supports dynamic updating of reference feature vectors and threshold setting mechanism, and continuously optimizes the standard behavior model according to the data accumulated in the long-term running process. For example, after a long time of running, the clock stability data set of a certain type of device may show certain differences. The system will update the standard vector and threshold of the clock frequency fluctuation curve of this device type according to the new data set of this device type, to ensure that the judgment mechanism has the generalization ability across devices and users. Similarly, the rhythm characteristics of user interaction behavior may shift due to changes in application scenarios (such as an increase in the operation intensity of a certain page). The system updates the interaction standard vector library regularly by continuously analyzing the behavior trajectory and feedback results, to improve the accuracy and robustness of the judgment model. Finally, in the whole link process from feature extraction, difference judgment, risk identification to key distribution control, the accurate interception of time-sensitive states is realized, and a dynamic, safe and controllable encryption support framework is provided for key use in the small program environment.

[0034] In the present embodiment, to improve the predictability of key use time sequence behavior, the system introduces a multi-dimensional feature fitting process for constructing a time disturbance model from historical behavior data and generating quantifiable prediction indicators accordingly. This process relies on terminal clock frequency fluctuation records and network response behavior data to model time disturbance characteristics at multiple time scales, and ultimately derives the risk assessment basis for key distribution. Specifically, the following steps are included: Extracting time series data from historical terminal clock frequency fluctuation records and network round-trip response time records, combining the two types of data in chronological order to form a continuous time sequence response chain for constructing the system time disturbance basic sequence by using a unified time synchronization marker; In this step, the system will periodically collect two types of time sequence data from the device end, the first type is the instantaneous frequency record of the terminal internal system clock signal, which usually marks the fluctuation of the processor frequency with millisecond-level precision; The second type is the response time record in the round-trip communication process with the remote server, which represents the communication link stability. In order to fuse these two types of heterogeneous data, the system introduces a unified time synchronization marker strategy, that is, a unified system timestamp is recorded synchronously when each group of data is collected, to ensure that the two types of data are aligned on the same time axis. Then, the system combines the terminal frequency data and network response data in the same time period to construct a response chain arranged in chronological order, called a continuous time sequence response chain. For example, if the terminal frequency fluctuates several times within fifty milliseconds, and the network response is significantly delayed within the same time window, it can be considered that there is a system-level disturbance trend in this period. This response chain serves as the input sequence for subsequent modeling, and has representativeness, continuity and cross-feature fusion capability.

[0035] The time series response chain is mapped into a multi-dimensional state space by using a time delay embedding method, a state point sequence is generated for representing the evolution of the time disturbance trajectory, and an exponential growth trend analysis is performed on the geometric distance variation rate between the continuous state points to extract a time disturbance sensitivity index; this step aims to mine the evolution law and potential nonlinear structure from the time series. The specific method is as follows: the time series response chain is sampled at a fixed time interval, a plurality of continuous sampling points in the past are taken as a state unit, an embedding vector set is constructed in the time dimension, and an multi-dimensional state space is formed. For example, three continuous response values are taken as a state point, a state point sequence is formed by a sliding window, and an evolution trajectory of the disturbance is constructed. The system then analyzes the geometric distance between the state points, and if the distance presents an exponential growth with time, that is, the distance growth rate between the continuous state points is continuously accelerated, it means that the system presents a disturbance amplification trend in the current period. The system extracts a key index for measuring the stability of the time system by curve fitting the growth trend, that is, the time disturbance sensitivity index. The index actually corresponds to the “Lyapunov index” in the existing dynamic system theory, which is a core index for judging whether a system is stable to initial disturbance response. The existing technology has a detailed description, and will not be repeated here. If the index is positive, the system is sensitive to disturbance and the evolution trajectory rapidly diverges, otherwise it indicates that the system has stability. In this embodiment, the system calculates the growth rate of the distance between the state points in the time disturbance trajectory, and the index value calculated is the rewritten time disturbance sensitivity index, which is used to measure the controllability of the time series link in the external observable dimension.

[0036] The time disturbance sensitivity index is continuously solved in multiple time scales, a multi-scale disturbance stability curve is constructed, and a risk entropy factor of the key distribution is generated based on the curve, so that the trajectory divergence characteristics and the strength of predictability of the key calling process in the time dimension are reflected. This step introduces a multi-scale modeling idea. The system repeatedly calculates the time disturbance sensitivity index in different time length sliding windows to capture the dynamic stability of the disturbance in the short term, medium term and long term. For example, the time disturbance sensitivity index is calculated in ten seconds, thirty seconds and sixty seconds, forming an index sequence, which is called a multi-scale disturbance stability curve. The system takes this curve as the disturbance state performance of the key calling time behavior, and extracts multiple characteristic quantities such as distribution range, change trend and index dispersion degree from it. Then, the system constructs a disturbance information vector based on the stability curve, and calculates the information entropy value based on the disturbance information vector. The information entropy value represents the uncertainty degree of the time disturbance mode in multiple time scales. If the index distribution is significantly different in different time windows, the entropy value is high, indicating that the disturbance state is highly dynamic and the key behavior is not easy to predict. If the index distribution is concentrated, the entropy value is low, indicating that there is a regular trend and the key trajectory can be reconstructed by the attacker. The system finally defines the entropy value as the risk entropy factor of the key distribution, which is used to characterize the complexity and unpredictability of the key calling behavior in the time domain.

[0037] The risk entropy factor of the key distribution will be used as the input basis for subsequent key calling scheduling and disturbance decision-making to determine whether the current encryption behavior should be actively intervened by the disturbance mechanism. In this stage, the system has completed the quantitative modeling of the time disturbance trajectory through the foregoing process and obtained the risk entropy factor value that can be used to determine the predictability of the key. The system continuously updates this factor during operation. In addition, the system can also perform trend analysis based on the change rate of the risk entropy factor to identify potential security degradation trends in advance and achieve adaptive adjustment of encryption scheduling. Through the above process, the invention realizes the key behavior prediction and intervention capability of the trinity of data layer, model layer and policy layer, effectively enhances the protection capability of the system when facing attacks in the time dimension, and is different from the passive defense mode of traditional static encryption schemes.

[0038] In this embodiment, in order to further improve the accuracy of the system in determining the predictability and modelability of the encryption behavior in the time dimension, the system introduces a time hidden quantity value as a core index for measuring the repeatability and time aggregation of the disturbance. The index is constructed based on the saliency score and distribution characteristics of the disturbance signal, and belongs to a high-order representation method of time domain features. The generation process of the value is based on the disturbance peak value distribution sequence composed of terminal clock fluctuations and network response delays, including the following specific steps: Based on the disturbance peak value distribution sequence composed of terminal clock fluctuation and network response delay, a sliding window is constructed at a fixed time interval, and the following three indicators are calculated in each time window: the number of disturbance peak values; the standard deviation of disturbance intensity; the average time interval between adjacent disturbances; after normalization, the three indicators are weighted and summed to generate the significance score of the window, which is used to measure the continuity and intensity stability of the disturbance behavior in the period; in this step, the system first extracts the disturbance peak value from the continuously monitored terminal clock frequency change record and the network request response delay sequence, that is, to identify the point in the time series whose mutation amplitude exceeds the set threshold. Each time the terminal clock fluctuation exceeds five percent of the base frequency change, or the network response delay is higher than thirty percent of the average value of the stable state delay, it is marked as a disturbance peak value. Under the set sliding window mechanism, such as every ten seconds as a window unit, the system performs three statistical operations on each time window: first, the total number of disturbance peak values appearing in the window is counted, which represents the intensity of disturbance events per unit time; second, the standard deviation of the disturbance amplitude in the window is calculated, which is used to measure the dispersion degree of disturbance intensity; third, the average time interval between any two disturbances in the same window is calculated, which reflects the time continuity of the disturbance event. After maximum and minimum normalization of the three indicators, according to the experience set weight (such as fifty percent bias for disturbance occurrence frequency, thirty percent bias for disturbance intensity fluctuation, and twenty percent for disturbance interval), the weighted sum is obtained. The significance score of the current window, which can be used as a comprehensive evaluation of the local expression intensity of disturbance behavior.

[0039] The significance scores of all time windows are formed into a time series vector, an unsupervised clustering method based on local density peak detection is used to identify high-density areas of disturbance distribution, and by calculating the variance of the concentration of scores and the average duration in these clustering clusters, a time concentration index of disturbance distribution is generated, which is the average score multiplied by the duration of time in the cluster, which is used to quantify the local aggregation trend of disturbance behavior on the time axis; the significance scores of multiple time windows obtained in the previous step are regarded as the disturbance intensity distribution in the continuous time domain, forming a set of time series vectors representing the evolution trend of disturbance characteristics in different time periods. Subsequently, the system uses the density peak algorithm to automatically identify the locally dense areas in the score cluster distribution as high-risk areas without prior cluster number setting. For each identified high-density clustering cluster, the system calculates the average value of all window scores in the cluster and the duration of the time range covered by the cluster, and then multiplies the two to obtain the time concentration index of the cluster. For example, the average significance score in a certain clustering cluster is 0.8, and the coverage time length is 40 seconds, then the time concentration index of the cluster is 32. Multiple clustering clusters will form a time concentration distribution, representing the strength of the concentration trend of disturbance on the time axis, which is of great reference significance for identifying whether the disturbance pattern presents time repeatability and aggregability.

[0040] The time concentration index is mapped to the time hiding value according to the preset standardization interval mapping rule, which is used to represent the behavior repeatability and modeling identifiability of the disturbance behavior in the time dimension; in order to make the time concentration index have unified interpretation ability in the whole encryption strategy scheduling process, the system maps it to a standard index value in the percentage range, which is defined as the time hiding value. Specifically, the system sets the maximum and minimum boundaries of the time concentration index, and maps the original value to the range of zero to one hundred in a linear interpolation manner. For example, if the maximum value of the concentration in all clustering clusters is forty-five and the minimum value is five, then the standard value of the cluster with a concentration of thirty is seventy, which is defined by the system as the time hiding value. The higher the value, the more regular the disturbance behavior is, and the more likely it is to be captured by the prediction model, and its behavior in the time dimension shows high modeling; on the contrary, the lower the value, the more random and unpredictable the disturbance pattern distribution is. This parameter is an important index for evaluating the security level of key usage time behavior, which will jointly determine whether to enter the disturbance scheduling link with the risk entropy factor.

[0041] During the real-time running of the system, the time hidden escape value is combined with the risk entropy factor to drive the security policy switching logic of the key scheduling, so as to ensure that when the disturbance behavior is repeatedly enhanced, the time offset strategy is injected in time to block the prediction path, a dynamic encryption disturbance closed loop is formed, and the resistance of the system to advanced time modeling attacks is significantly improved. By quantitatively evaluating the intensity, repeatability and behavior stability of the time disturbance behavior on the time axis, the system realizes the prediction mechanism of the potential modeling path with the help of the time hidden escape value. Especially in the threat scenario of external attackers listening to the time behavior samples of multiple users for a long time and trying to reconstruct the key calling model, this parameter can effectively reflect the feasibility interval of time modeling, and provide a quantitative basis for the early triggering of the disturbance mechanism. Compared with the decision logic based only on the current disturbance intensity, the introduction of the time hidden escape value enables the system to identify attack risks from the behavior structure dimension, significantly enhances the foresight and response speed of active defense, and is significantly better than the post-response mode of the existing static encryption mechanism.

[0042] In the security encryption method based on the applet software, judging whether to inject timing disturbance is a key step to ensure that the key calling behavior is not predicted by an external model. This step models the time trend of the encryption calling behavior, analyzes the residual error of the prediction deviation, and identifies whether there is a regular behavior, so as to trigger the disturbance mechanism to break the modeling path. The specific process is as follows: the key calling time series is time-aligned with the corresponding risk entropy factor and time hidden escape value to form a key calling behavior trajectory, and a time trend fitting curve is generated based on the local neighborhood similarity and step-by-step backtracking prediction error fitting mechanism to represent the time trend of the key calling behavior. This step first unifies the time granularity of the three key variables on the time axis: the key calling time series, the risk entropy factor and the time hidden escape value, to ensure that a one-to-one correspondence is established at the same time step to form a complete key calling behavior trajectory. Each key calling event records its time point, the called key pair number, the corresponding risk entropy factor value and the time hidden escape value. Based on the behavior trajectory, the system uses the step-by-step backtracking prediction error fitting mechanism to push back a fixed number of historical calling data (for example, twenty records) from any current time point, and finally obtains the time trend fitting curve as the dynamic evolution trend expression of the key calling behavior, to judge whether there is a fitting mode.

[0043] The trend fitting curve is subjected to a periodic window piecewise analysis, a residual sequence is formed by the difference between the actual key call value and the fitted value, and the residual sequence is subjected to kurtosis analysis to determine whether there is a peak concentration phenomenon, skewness analysis to determine whether there is a bias trend, and autocorrelation coefficient calculation of the residual sequence to detect periodic repetition patterns; after obtaining the trend fitting curve, the system compares it with the real key call sequence, calculates the deviation between the actual call value at each time point and the corresponding predicted value, and then forms a continuous residual sequence. The residual sequence is the core basis for judging whether the key usage behavior has a predictable regularity. In order to analyze the sequence in depth, the system extracts three types of statistical features respectively: first, kurtosis analysis, if there are a large number of concentrated large deviations in a short time in the residual sequence, the kurtosis value will be significantly higher than the standard of normal distribution, indicating that there is a risk of key call high-frequency concentration deviation; second, skewness analysis, if the key call deviates from the fitted value in a certain direction, the skewness will deviate from zero, indicating that there is a prediction tendency guided by one-sided trend; third, calculate the autocorrelation coefficient of the residual sequence, if the residual shows repeated patterns and reaches a significant correlation level within a fixed cycle length, it means that the system behavior has periodic fluctuations and is easily captured by external models.

[0044] The residual kurtosis, residual skewness and autocorrelation significance level are comprehensively determined, and when any statistical feature exceeds the set threshold interval, it is determined that the key call behavior appears concentrated deviation, periodic deviation or trend fluctuation pattern; this step quantifies the three types of statistical features obtained in the previous step into judgment indexes and compares them with the system preset safety threshold. Among them, the kurtosis threshold can be set to three and a half or more, the skewness threshold is set to a neutral interval of plus or minus zero point five, and exceeding this range is a bias trend interval; the autocorrelation significance level is judged by a confidence interval of ninety-five percent, and exceeding this interval indicates that the residual distribution has periodicity. When any of the above indexes exceeds its set safety interval range, the system determines that the current key call behavior has a modelable pattern tendency, indicating that the attacker has a certain probability to restore the key call trajectory through the time series prediction model. In this case, the system enters the next step, i.e. determining whether to perform time series disturbance operation to block the modeling risk of key behavior.

[0045] The determination result is fed back to the perturbation control parameter set generation module, the perturbation time offset sequence is triggered in the key calling scheduling logic, a new nonlinear key calling track is constructed, and the path for an external observer to model and predict through the response time difference is cut off; after determining that there is regularized key usage behavior, the system takes the residual sequence features obtained by analysis as one of the perturbation decision input variables, combines the risk entropy factor and the current weight value of the time stealth amount, and jointly drives the construction of the perturbation control parameter set. The control parameter set includes three quantitative dimensions of perturbation strength, perturbation frequency and perturbation duration, which are used to determine the time offset strategy to be taken in subsequent key calling. For example, in the case where the residual kurtosis is higher than the set threshold of fifty percent, the system increases the perturbation strength to the maximum level and shortens the perturbation period to form a high-frequency perturbation strategy. Correspondingly, the perturbation time offset sequence will use non-uniform time steps to disrupt the key calling time points, so that the key calling time track presents a nonlinear jump trend. By introducing this mechanism, the system effectively shields the original predictable path in the key usage track, blocks the possibility of establishing a reverse model by an external modeler relying on the response time difference, and thus forms a dynamic, adaptive and highly concealed time sequence encryption defense chain.

[0046] In the embodiment, to generate a time trend fitting curve for judging whether the key calling behavior has a periodic trend or a predictable rule, the system jointly completes the fitting mechanism by using local neighborhood similarity and step-by-step prediction error. Specifically, first, in the key calling behavior track, the current time point is selected as the analysis reference point, and a fixed number of historical key calling records are selected in time sequence to form a local behavior window. The historical calling data in the window are regarded as local behavior samples. In the local window, the system calculates the calling interval, the risk entropy factor variation range and the gradient change of the time stealth amount between each historical calling point and the adjacent calling point as the time dynamic characteristics of the point. By comparing the characteristics with the corresponding characteristics of other historical points, adjacent historical fragments with similar behavior structure can be identified, that is, a local neighborhood is formed.

[0047] In determining whether two historical behavior segments have similarity, the system jointly measures multiple behavior feature dimensions, including: the change trend of key call interval, the fluctuation direction and amplitude of risk entropy factor, and the growth or convergence characteristics of time stealth value in consecutive time segments. Specifically, first, the system traces several fixed interval historical behavior segments forward from the current reference point, and extracts equal-length key call time series, risk entropy factor series, and time stealth value series from each segment. For each historical segment and the current reference segment, the system calculates the sum of the absolute difference of the key call time interval series, whether the trend direction of the risk entropy factor curve is consistent (i.e., increasing or decreasing), and whether the fluctuation amplitude of the time stealth value is in the same level interval. If two or more of the above three judgment indicators meet the following conditions: first, the average difference of the key call interval does not exceed the preset time stability deviation threshold; second, the fluctuation direction of the risk entropy factor is consistent at most time points, for example, more than a certain percentage of points remain consistent; third, the maximum difference of the time stealth value does not exceed the set disturbance level fluctuation upper limit, then the historical behavior segment and the current reference segment are considered to have structural similarity and can be included in the current local neighborhood. This way does not rely on the absolute value comparison of a single feature, but through the fusion judgment of trend structure, fluctuation level, and time sequence rhythm, which is more in line with the behavior similarity evaluation requirements in complex dynamic encryption environment.

[0048] The system uses the historical call values in the local neighborhood of the current reference point as the fitting basis to establish a progressive trend prediction path. Specifically, starting from the earliest historical point in the window, the trend is fitted step by step in time sequence to the current point, and the expected call behavior of the next point is predicted based on the values already fitted, thereby forming a trend prediction sequence based on historical behavior within the window. The system aligns the generated trend prediction sequence with the actual call trajectory on the time axis, and records the deviation value between the two as the prediction residual. This residual sequence will be used as an important basis for judging whether the key call has a centralized deviation, a periodic shift, or a trend fluctuation in the subsequent steps. In this way, the overall model can effectively avoid excessive sensitivity to short-term abnormal behavior, and improve the local accuracy and stability of the trend fitting of the key call trajectory.

[0049] This implementation discloses a technical solution that introduces a perturbation time offset sequence during key call scheduling to cut off the temporal inference path built by external attackers based on response time differences, thereby improving the unpredictability of key usage behavior. This method closely revolves around key steps such as constructing a perturbation control parameter set, generating a perturbation time offset sequence, establishing nonlinear temporal behavior, and embedding scheduling logic, ensuring that the perturbation mechanism possesses high concealment and flexibility at the time domain level. Once key call behavior is identified as having regular characteristics, the system immediately initiates the perturbation parameter configuration mechanism. This mechanism integrates two indicators: the risk entropy factor and the time concealment value. First, both are numerically normalized to ensure consistency in their value ranges. Then, risk weights are set according to empirical rules, where the risk entropy factor represents the uncertainty of the trajectory distribution of key call behavior in the time dimension, and the time concealment value represents the degree of repetition of perturbation behavior in time and space. Finally, the perturbation level score is obtained by multiplying the normalized values ​​by their respective risk weights and performing a weighted sum. The disturbance level score will be mapped to a disturbance control parameter set, which includes the following three items: first, a disturbance amplitude parameter representing the instantaneous offset magnitude triggered by the disturbance; second, a disturbance density parameter representing the disturbance frequency per unit time; and third, a disturbance duration parameter representing the total duration of the disturbance. For example, with a risk entropy factor of 0.8, a time concealment value of 0.6, and weights of 0.6 and 0.4 respectively, the disturbance level score is 0.72, corresponding to a disturbance amplitude parameter of 200 milliseconds, a disturbance density parameter of four times per minute, and a disturbance duration of 20 minutes.

[0050] The system initiates the disturbance time offset sequence construction process based on the disturbance control parameter set. During construction, a complete intervention period is first determined, with the period length equal to the time range defined by the disturbance duration parameter. Within this period, the system calculates the number of disturbances to be inserted according to the disturbance density parameter. For example, in a 20-minute period, if the disturbance density parameter is four times per minute, then 80 disturbance points need to be generated within this period. The system sets an initial offset interval for each disturbance point, which determines the maximum offset time based on the disturbance amplitude parameter. For example, if the disturbance amplitude is 200 milliseconds, then the initial offset range for each disturbance point is between zero and 200 milliseconds. The system then generates non-uniformly distributed offset moments from this range, forming a disturbance time step sequence. Furthermore, to avoid excessive regularity, the system introduces a pseudo-random disturbance interpolation mechanism, further inserting small disturbance interventions based on the offset moments to achieve local fluctuations in the disturbance curve.

[0051] The constructed perturbation time offset sequence will be bound to the scheduling logic during the key invocation execution process. The binding method adopts an index mapping pattern, meaning that the original planned time point corresponding to each key invocation event will be matched one-to-one with the offset time point generated in the perturbation time offset sequence. This matching process can employ a time-sliding mapping strategy, ensuring that the key invocation plan and the perturbation offset sequence maintain a consistent chronological order but differ in absolute time points. After binding, the system will dynamically adjust the key invocation trigger point, successively delaying or advancing the key generation and distribution operations. This operation will not change the key's generation mechanism or usage method, but it will alter the key's externally visible behavior on the timeline, thereby effectively disrupting time-based attack paths.

[0052] As the perturbation time offset sequence is actually executed, the key call time trajectory will form a non-linear, non-uniformly spaced temporal behavior pattern. For example, if the original key call time point is once every thirty seconds, after perturbation offset processing, the call interval may exhibit non-linear intervals such as twenty-nine seconds, thirty-two seconds, and twenty-seven seconds. If combined with a perturbation density of four times per minute and a duration of twenty minutes, a maximum of eighty different call interval patterns can be formed within twenty minutes. This highly dynamic and non-linear temporal behavior will greatly increase the difficulty for attackers to perform reverse reasoning modeling based on time series, thereby improving the system's security protection level.

[0053] This implementation discloses a method for dynamically calling an asymmetric key pool based on a risk entropy factor and a time-hidden value, and for temporally embedding key call behavior with a perturbation time series. The core objective is to make the key call path highly irregular and unmodelable, disrupting time-indexed key prediction models. The system initiates a key call level judgment mechanism within the current time period based on the generated risk entropy factor and time-hidden value. The key call level describes the required security protection strength for the current key usage. Specifically, the risk entropy factor represents the predictable risk of the current key usage behavior in a time series; a higher value indicates a more modelable behavior. The time-hidden value represents the identifiability of time perturbations; a higher value indicates more obvious repetitive behavior. The system sets a security level classification standard based on the product of these two values; for example, a product less than 0.3 is low-level, between 0.3 and 0.6 is medium-level, and above 0.6 is high-level. Based on the judgment results, the system will select multiple key pair combinations from the asymmetric key pool that meet the current level requirements; these combinations constitute a candidate key pair set.

[0054] A perturbation time series corresponding to the key invocation plan is constructed. This perturbation time series is built based on a previously generated perturbation time offset series, maintaining the original order but with the time points processed to exhibit non-linear, unequal intervals. For example, in a five-minute invocation plan, the original plan is for key invocation every thirty seconds, but the perturbation time series might be twenty-seven seconds, thirty-five seconds, twenty-eight seconds, or thirty-two seconds, with the time intervals constantly changing. During the construction process, the system appends a perturbation identifier to each time point for subsequent key indexing and binding.

[0055] The system binds each time point in the perturbation time series to a key pair in the candidate key pair set. The binding method employs a positional consistency indexing strategy to ensure a one-to-one correspondence between the perturbation time point and a key pair. If the perturbation sequence contains eighty time points but only sixty candidate key pairs, the system will expand or repeat the mapping of the key pair set to maintain the continuity of the mapping logic. For example, the sixty-first perturbation point can be rebound to the first key pair, forming a closed-loop mapping chain and preventing index loss. The key pair number bound to each perturbation time point is scheduled and invoked during the execution phase, thereby completing one asymmetric encryption operation.

[0056] After executing the key invocation plan of the above mapping chain, an unmodelable key distribution path will be formed over the entire perturbation time series. Since each key pair is invoked at irregular, non-periodic time points, and the corresponding invocation behavior is deeply embedded in the non-linear perturbation path, even if an attacker intercepts the key invocation time points, they cannot construct a regular index model from the time series. Furthermore, a one-time random tag can be attached to the key pair during the invocation process to further disrupt the external observation path of the key pool's internal structure. Ultimately, this achieves the goal of fully dynamic, non-deterministic, and unmodelable key distribution behavior, enhancing the overall system's security resilience.

[0057] Example 2: A secure encryption system based on a WeChat Mini Program, specifically including: The behavior awareness module is used to establish a multi-dimensional dynamic behavior judgment mechanism before the mini program initiates a communication request. It continuously collects user interaction rhythm, terminal clock frequency fluctuations and network response characteristics to determine whether the current environment is in a time-sensitive stage of key transmission. The risk assessment module is used to identify the time difference evolution trajectory based on historical dynamic behavioral feature data when potential time-series risks are determined. It generates the risk entropy factor and time concealment value of the key distribution through multi-dimensional feature fitting, which are used to measure the level of reasoning predictability of the current key usage scenario. The time series modeling module is used to establish a time series evolution model of the current key call history based on the risk entropy factor and the time escaping value, and to analyze whether there are periodic or trend-like key distribution characteristics by comparing the prediction curve and the regression residual, so as to determine whether time series perturbation needs to be injected. The perturbation injection module is used to construct a perturbation control parameter set based on inference strength when the key usage pattern shows a regular tendency, and to introduce a perturbation time offset sequence during the key call scheduling process to generate a nonlinear time domain behavior trajectory, thereby cutting off the path for external observers to build a reverse prediction model through response time difference; The key scheduling module is used to call key pair combinations in the asymmetric key pool based on the risk entropy factor and the time escaping value, and to synchronize the key calling order with the perturbation time series, thereby enhancing the unmodelability of key distribution behavior in the observation dimension.

[0058] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0059] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0060] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0061] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0062] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A secure encryption method based on WeChat Mini Program software, characterized in that, Includes the following steps: Before the mini-program initiates a communication request, a multi-dimensional dynamic behavior judgment mechanism is established to continuously collect user interaction rhythm, terminal clock frequency fluctuations and network response characteristics to determine whether the current environment is in a time-sensitive stage of key transmission. If potential temporal risks are identified, the evolution trajectory of time difference is identified based on historical dynamic behavioral characteristic data. Risk entropy factor and time escaping value of key distribution are generated through multi-dimensional feature fitting to measure the level of reasoning predictability of the current key usage scenario. Based on the risk entropy factor and the time escaping value, a time-series evolution model of the current key call history is established. By combining the prediction curve and the regression residual, it is analyzed whether there are periodic or trend-like key distribution characteristics, so as to determine whether time-series perturbation needs to be injected. If the analysis results show that the key usage pattern tends to be regular, then a set of perturbation control parameters is constructed based on the inference strength, and a perturbation time offset sequence is introduced in the key call scheduling process to generate a nonlinear time domain behavior trajectory, cutting off the path for external observers to establish a reverse prediction model through response time difference; Based on the risk entropy factor and the time escaping value, key pair combinations in the asymmetric key pool are dynamically called, and the key calling order is synchronized with the perturbation time series to enhance the unmodelability of key distribution behavior in the observation dimension.

2. The security encryption method based on mini-program software according to claim 1, characterized in that, User interaction rhythm, terminal clock frequency fluctuations, and network response characteristics are collected and calculated through the following steps: After the user's mini-program interface is loaded, the embedded data acquisition logic is started. The user's touch dwell time, swipe acceleration and click frequency on different components are recorded by timestamp to form time series data of user operation behavior, which is used to generate interaction rhythm feature curves. During device operation, the instantaneous value of the terminal processor clock signal is periodically read through system-level calls, and the coefficient of variation of the sequence is calculated based on statistical methods to assess the degree of fluctuation of the terminal clock frequency. To address network response characteristics, a network response behavior graph was constructed by establishing multiple handshake requests with the mini-program server, recording the latency, packet loss rate, and bandwidth fluctuation values ​​of each response. After standardizing the above data, it is used as input features and fed into the multidimensional dynamic behavior determination mechanism.

3. The security encryption method based on mini-program software according to claim 2, characterized in that, The multidimensional dynamic behavior determination mechanism refers to: The user interaction rhythm feature curve, the terminal clock frequency fluctuation curve, and the network response behavior map are generated respectively, and then transformed into three types of feature vectors to represent the behavioral characteristics in the current state. The three current feature vectors are compared with the reference feature vectors in the standard state. The degree of deviation between the current behavior and the stable state is determined by calculating the Euclidean distance between the current state and the standard state. If the Euclidean distance of any type of feature exceeds the corresponding set distance threshold, then that type of behavior is marked as being in an unstable state. When at least one type of behavior feature is determined to be in an unstable state, it is determined that the current key transmission is in a high-risk period, and the static key distribution behavior is actively suspended during the high-risk period.

4. The security encryption method based on mini-program software according to claim 3, characterized in that, When fitting multidimensional features, the following steps are included: Time series data is extracted from historical terminal clock frequency fluctuation records and network round-trip response time records. By using a unified time synchronization marker, the two types of data are combined in chronological order to form a continuous time-series response chain, which is used to construct the basic sequence of system time disturbances. A time-delay embedding method is used to map the time-series response chain into a multi-dimensional state space to generate a sequence of state points to characterize the evolution of time-perturbation trajectories. An exponential growth trend analysis is performed on the rate of change of geometric distance between consecutive state points to extract the time-perturbation sensitivity index. The time perturbation sensitivity index is continuously solved across multiple time scales to construct a multi-scale perturbation stability curve. Based on this curve, a risk entropy factor for key distribution is generated, which reflects the trajectory divergence characteristics and predictability of the key retrieval process in the time dimension.

5. A secure encryption method based on a mini-program software according to claim 4, characterized in that, The risk entropy factor of the key distribution is generated in the following way: The temporal perturbation sensitivity index is continuously solved at multiple time scales to form a mapping curve between the time scale and the perturbation response intensity, which reflects the stability of trajectory divergence behavior under different time windows. The perturbation response values ​​at each scale are constructed into a perturbation response vector, and its information entropy value is calculated. The information entropy value is used to measure the degree of uncertainty of the perturbation distribution in the time dimension; this information entropy value is used as the risk entropy factor of the key distribution.

6. A secure encryption method based on a mini-program software according to claim 5, characterized in that, The time-stealth value is generated through the following steps: Based on the disturbance peak distribution sequence composed of terminal clock fluctuations and network response delays, a sliding window is constructed at fixed time intervals. In each time window, the following three indicators are calculated: the number of occurrences of disturbance peaks; the standard deviation of disturbance intensity; and the average time interval between adjacent disturbances. After normalizing the three indicators, a weighted sum is performed to generate the significance score of the window, which is used to measure the continuity and intensity stability of disturbance behavior during that period. The significance scores of all time windows are used to construct a time series vector. An unsupervised clustering method based on local density peak detection is used to identify high-density regions of perturbation distribution. By calculating the variance and average duration of the score concentration in these clusters, a time concentration index of perturbation distribution is generated. The time concentration index = average score within the cluster × duration is used to quantify the local clustering trend of perturbation behavior on the time axis. The time concentration index is converted into a time escaping value according to a preset standardized interval mapping rule.

7. A secure encryption method based on a mini-program software according to claim 6, characterized in that, Determining whether timing perturbations need to be injected refers to: The key call time series is time-aligned with the corresponding risk entropy factor and time escaping value to form the key call behavior trajectory. A time series trend fitting curve is generated based on the local neighborhood similarity and the step-back prediction error fitting mechanism to characterize the time trend of key call behavior. Perform periodic window segmental analysis on the trend fitting curve, construct a residual sequence from the difference between the actual key call value and the fitted value, perform kurtosis analysis on the residual sequence to determine if there is a peak concentration phenomenon, perform skewness analysis to determine if there is a bias trend, and calculate the autocorrelation coefficient of the residual sequence to detect periodic repetition patterns. The determination is made by combining residual kurtosis, residual skewness, and autocorrelation significance level. When any statistical feature exceeds the set threshold range, the key call behavior is identified as exhibiting a concentrated deviation, periodic shift, or trend fluctuation pattern.

8. A secure encryption method based on a mini-program software according to claim 7, characterized in that, Introducing a perturbation time offset sequence during key invocation scheduling includes the following steps: After identifying regular characteristics of key call behavior, a set of disturbance control parameters is generated based on the combined strength of the risk entropy factor and the time escaping value. The set of disturbance control parameters includes disturbance amplitude parameters, disturbance density parameters, and disturbance duration parameters, which are used to define the time disturbance level and disturbance scheduling cycle in the key call process. Based on the disturbance control parameter set, a disturbance time offset sequence is constructed. By setting a non-uniform time step and a time offset change curve generated according to a preset offset rule based on the disturbance amplitude control parameter, the key call time is offset successively. During the execution of the key invocation, the perturbation time offset sequence is synchronously bound to the key scheduling logic, and perturbation delay and invocation timing changes are inserted in a randomized manner.

9. A secure encryption method based on a mini-program software according to claim 8, characterized in that, The dynamic invocation and perturbation time series embedding of asymmetric key pools based on risk entropy factors and time escaping values ​​includes the following steps: Based on the risk entropy factor and time concealment value calculated for the current period, key call level and security grouping strategy are set in the key management strategy. Multiple key pair combinations that meet the requirements of the level are pre-selected from the asymmetric key pool to form a candidate key pair set. Construct a perturbation time series corresponding to the key invocation plan, and map and bind each time point in the perturbation time series to a key pair in the candidate key pair combination to form a perturbation time-driven key invocation index chain.

10. A security encryption system based on WeChat Mini Program software, comprising a security encryption method based on WeChat Mini Program software as described in any one of claims 1-9, characterized in that, Specifically, it includes: The behavior awareness module is used to establish a multi-dimensional dynamic behavior judgment mechanism before the mini program initiates a communication request. It continuously collects user interaction rhythm, terminal clock frequency fluctuations and network response characteristics to determine whether the current environment is in a time-sensitive stage of key transmission. The risk assessment module is used to identify the time difference evolution trajectory based on historical dynamic behavioral feature data when potential time-series risks are determined. It generates the risk entropy factor and time concealment value of the key distribution through multi-dimensional feature fitting, which are used to measure the level of reasoning predictability of the current key usage scenario. The time series modeling module is used to establish a time series evolution model of the current key call history based on the risk entropy factor and the time escaping value, and to analyze whether there are periodic or trend-like key distribution characteristics by comparing the prediction curve and the regression residual, so as to determine whether time series perturbation needs to be injected. The perturbation injection module is used to construct a perturbation control parameter set based on inference strength when the key usage pattern shows a regular tendency, and to introduce a perturbation time offset sequence during the key call scheduling process to generate a nonlinear time domain behavior trajectory, thereby cutting off the path for external observers to build a reverse prediction model through response time difference; The key scheduling module is used to call key pair combinations in the asymmetric key pool based on the risk entropy factor and the time escaping value, and to synchronize the key calling order with the perturbation time series, thereby enhancing the unmodelability of key distribution behavior in the observation dimension.