Encryption communication system based on multistage key distribution

By using a multi-level key distribution encrypted communication system, environmental parameters are collected in real time and dynamic security scoring is performed, enabling three-stage key switching and seamless updates. This solves the systemic defects of traditional encryption systems under advanced persistent threats and improves security and availability.

CN121367588APending Publication Date: 2026-01-20HUANENG SHANXI ENERGY SALES CO LTD +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511453177.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

Existing encryption systems have systemic flaws when dealing with advanced persistent threats (APTs). Traditional key distribution mechanisms cannot respond in real time to device heterogeneity and dynamic changes in network topology, and are difficult to meet the requirements for automated management and control of key materials throughout their entire lifecycle.

Method used

An encrypted communication system based on multi-level key distribution is adopted, which includes a ring defense structure consisting of an environment awareness layer, a policy control layer, a key management layer, a secure transmission layer, a cryptographic service layer, and a hardware isolation layer. Through real-time environmental parameter acquisition, dynamic security scoring, key fragmentation transmission, dual key pool updates, and hardware isolation storage, the system achieves three-stage dynamic switching and seamless updating of keys.

Benefits of technology

It achieves dynamic matching of encryption strength with the environment, resists quantum computing attacks, defends against man-in-the-middle attacks, ensures secure operation and maintenance capabilities without the business's awareness, and improves security and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367588A_ABST
    Figure CN121367588A_ABST
Patent Text Reader

Abstract

According to the encryption communication system based on multi-level key distribution provided by the invention, the environment sensing layer acquires target environment parameters in real time and forms closed-loop feedback with a dynamic security score generated by the strategy control layer, and the key management layer is driven to realize three-stage dynamic switching from an initial key to a session key to a master key; a key fragmentation bidirectional authentication mechanism of a secure transmission layer and a double-key pool non-inductive updating strategy of a password service layer are matched, under the quantum resistance storage guarantee of a hardware isolation layer, an annular defense system with a space-time adaptive characteristic is constructed, and the security and availability are greatly and comprehensively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and particularly relates to an encrypted communication system based on multi-level key distribution. BACKGROUND

[0002] The communication encryption core is applied to the technical fields of government affair level secret communication, financial transaction data transmission and Internet of Things terminal security interaction (such as virtual power plant terminal security), and its technical evolution always develops around two main lines of "counteracting the risk of brute force cracking caused by algorithm power upgrading" and "relieving the complexity of key life cycle management".

[0003] The existing encryption system exposes systematic defects when dealing with advanced persistent threats (APTs): the traditional key distribution mechanism relies on a preset risk assessment model and cannot respond to a composite attack surface composed of device heterogeneity and network topology dynamic changes in real time, and it is difficult to meet the compliance requirements of automatic control of the whole life cycle of key materials. SUMMARY

[0004] Therefore, the present application provides an encrypted communication system based on multi-level key distribution to solve the technical defects in the prior art.

[0005] Specifically, the present application provides an encrypted communication system based on multi-level key distribution, which comprises an annular defense structure composed of an environment perception layer, a policy control layer, a key management layer, a secure transmission layer, a cryptographic service layer and a hardware isolation layer, The environment perception layer is used for real-time collection of target environment parameters at the current time; The policy control layer obtains device fingerprints, network delays and geofencing parameters in the target environment parameters and generates a dynamic security score; The key management layer switches encryption algorithm combinations and manages a three-stage key system of initial keys, session keys and master keys according to the dynamic security score and a dynamically calculated dynamic risk threshold; The secure transmission layer performs key fragmentation transmission through a two-way authentication channel, splits a single key into a client memory segment, a server HSM segment and a third-party notarization platform segment; The cryptographic service layer realizes non-conscious update by using a pre-generated regular key pool and a backup key pool, and triggers two-channel verification switching when the key usage reaches a threshold, wherein the update mode of the regular key pool is high-frequency active update, and the update mode of the backup key pool is low-frequency passive response update; The hardware isolation layer stores historical environment parameters and key bloodline maps.

[0006] In some optional implementations, the dynamic security score is determined according to a twelve-dimensional parameter matrix constituted by device model, operating system version and network topology, and is used to trigger the gradient upgrade from the SM4 single algorithm to the SM2+SM4+SM9 three-level encryption in combination with the preset switching index.

[0007] In some optional implementations, the initial key is configured as the outermost working key, and its validity period is automatically adjusted according to the acquired real-time security environment evaluation result, and the basic time length is set to a second-level interval, wherein, after the initial key is used up, physical-level memory erasure is triggered to make the key material unrecoverable; The session key management adopts a national standard protocol to establish an encrypted channel, and the life cycle of the session key is dynamically controlled by two preset conditions; when any condition is triggered, a key re-negotiation process is started, and through forward security design, the new and old keys are completely isolated, wherein, the two conditions include: whether the current transmission flow is greater than a preset data transmission threshold, and whether the real-time updated session risk value in the session process is greater than a set value.

[0008] In some optional implementations, the master key is stored in a secure chip with physical isolation as a root key, and an initial seed is generated by a physically unclonable method; the secure chip integrates a multi-level protection system, including a metal shielding layer against physical detection, a power balance circuit against side-channel attacks, and a proactive destruction unit with a tamper-proof proactive destruction mechanism.

[0009] In some optional implementations, the key fragmentation transmission adopts an improved geographic stamp verification method, which contains double verification of a timestamp hash chain and base station positioning data, to prevent man-in-the-middle attacks caused by cross-border jump access.

[0010] In some optional implementations, the first calculation formula for calculating the dynamic risk threshold value includes:

[0011] wherein, R is the dynamic risk threshold value, N represents the total number of timestamp characteristics, and the timestamp characteristics at least include at least two of the following characteristics: baseline time offset, session interval variance, operation time period activity, geographic time coordination anomaly, blocking cross-border attack jump, key life cycle fluctuation, fragment transmission time consistency, clock drift compensation value, historical operation time entropy, emergency fuse response time delay and multi-device time coordination signature, is a weight coefficient of the i th timestamp characteristic, which is derived from the baseline portrait calibration of the strategy control layer; is a timestamp offset of the i th timestamp characteristic, which is generated by the clock synchronization module of the secure transmission layer; is a baseline time interval, which is determined according to the historical operation data of the hardware isolation layer; and M is the total number of geographic grids. is an attenuation factor of the jth geographical grid, configured by the regional strategy of the key management layer; is an environmental sensitivity coefficient, dynamically adjusted according to a dynamic security score; is a real-time geographical coordinate hash value, obtained according to a positioning module; is a registered geographical fence center point.

[0012] In some optional implementations, the second calculation formula for calculating the environmental sensitivity coefficient includes:

[0013] wherein K represents the number of network quality indicator categories, and the network quality indicator includes at least two of the following features: network delay, delay fluctuation standard deviation, packet loss rate, bandwidth stability, and link transmission error rate; is a normalization parameter of the kth network quality indicator, obtained according to a target environment parameter; is a standard deviation of the kth network quality indicator; is a historical mean value of the kth network quality indicator, obtained according to a historical environment parameter; is a small constant to prevent division by zero, is a latitude of the current position, is a longitude of the current position; is a dimension of a commonly used geographical position reference point, is a longitude of the commonly used geographical position reference point.

[0014] In some optional implementations, the processing steps of the non-inductive update include: The real-time tracking of the decryption failure rate triggers an automatic key fuse mechanism and switches to a backup key pool when the number of daily failures exceeds a set threshold.

[0015] In some optional implementations, the hardware isolation layer includes a historical key storage area for archiving expired keys and recording key derivation relationships, wherein the key bloodline map is constructed as a Merkle tree structure, each leaf node corresponds to a specific key generation record and / or usage log, and the operation record is implemented by hash chain storage to achieve tamper-proofing and traceability.

[0016] In some optional implementations, the two-way authentication channel adopts a hybrid encryption method, uses an SM2 elliptic curve algorithm in the key negotiation stage, and switches to an SM4 block cipher in the data transmission stage, and the session key strength linearly increases with the dynamic security score.

[0017] At least one embodiment of the application forms a closed-loop feedback through real-time collection of target environment parameters by the environment perception layer and dynamic security scores generated by the strategy control layer, drives the key management layer to realize three-stage dynamic switching from the initial key, the session key to the master key, cooperates with the key fragmentation two-way authentication mechanism of the secure transmission layer and the double-key pool non-inductive update strategy of the password service layer, and under the quantum resistance storage guarantee of the hardware isolation layer, constructs a ring defense system with space-time adaptive characteristics, and realizes a substantial comprehensive improvement of security and availability. BRIEF DESCRIPTION OF DRAWINGS

[0018] Figure 1 is a structural block diagram of an encryption communication system based on multi-level key distribution provided by the application. DETAILED DESCRIPTION

[0019] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present description. However, the present description can be practiced without the specific details, other than those described in this specification, in other ways that are consistent with the present description. It is understood that the present description is not limited in scope to the particular embodiments described herein, which are intended as illustrations of one or more aspects of the present description. Any suitable methods, features, components, and / or functions can be employed without departing from the scope of the present description.

[0020] The terminology used in one or more embodiments of the present description is for the purpose of describing particular embodiments only and is not intended to be limiting of one or more embodiments of the present description. As used in one or more embodiments of the present description and the accompanying claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in one or more embodiments of the present description, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0021] It will be understood that, although the terms first, second, etc. can be used herein to describe various information, these terms are not intended to denote a temporal sequence, but are used only to distinguish one piece of information from another. For example, without departing from the scope of one or more embodiments of the present description, first can also be referred to as second, and similarly, second can also be referred to as first. Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon" or "in response to determining."

[0022] Reference Figure 1 , Figure 1A structural block diagram of an encryption communication system based on multi-level key distribution is shown according to some embodiments of the present specification, which comprises an environment perception layer, a policy control layer, a key management layer, a secure transmission layer, a cryptographic service layer and a hardware isolation layer, which constitute a ring defense structure, the environment perception layer is used to collect the target environment parameters of the current time in real time; the policy control layer obtains the device fingerprint, network delay and geofencing parameters in the target environment parameters, and generates a dynamic security score; the key management layer switches the encryption algorithm combination according to the dynamic security score and the dynamically calculated dynamic risk threshold, and manages the three-stage key system of the initial key, the session key and the master key; the secure transmission layer performs key fragmentation transmission through a two-way authentication channel, splits a single key into a client memory segment, a server HSM segment and a third-party notarization platform segment; the cryptographic service layer uses pre-generated regular key pool and backup key pool to realize non-conscious update, and triggers two-channel verification switching when the key usage reaches the threshold, wherein the update mode of the regular key pool is high-frequency active update, and the update mode of the backup key pool is low-frequency passive response update; the hardware isolation layer stores historical environment parameters and key bloodline atlas.

[0023] The ring defense structure can refer to a layered and cooperative security architecture, for example, a protection system is constructed by a real-time data flow closed loop execution mode of six layers of modules, which can realize the full-link protection of environment perception→policy decision→key control→transmission guarantee→service supply→data traceability.

[0024] The environment perception layer can refer to a module for real-time monitoring of the communication environment, for example, terminal device state, network traffic characteristics and other target environment parameters are collected by a sensor and a log collector execution mode, which can provide basic data for dynamic security evaluation. The target environment parameters can refer to dynamically collected system state data, such as containing signal strength (-70dBm~-30dBm), CPU load rate (0%~100%), base station switching frequency and other index execution mode quantitative environment risk, which can be used to trigger differentiated encryption policy.

[0025] The policy control layer can refer to a security policy decision hub that calculates a security score based on integrated device fingerprints (MAC address / IMEI), network latency (RTT measurement), and geofencing (GPS / base station positioning) parameters, which can be used to trigger different levels of protection policies. Device fingerprints can refer to terminal unique identifiers that are processed by SHA-256 hashing algorithms to integrate hardware features such as MAC addresses, IMEI codes, and TPM chip IDs, enabling trusted authentication of device identity. Network latency can refer to communication link quality indicators that measure round-trip time (50 ms-3000 ms) through ICMP probe packets, reflecting the level of risk of man-in-the-middle attacks or network hijacking. Geofencing parameters can refer to location security boundary data, such as virtual electronic fences constructed based on GPS positioning (accuracy ±10 meters) and WiFi fingerprint matching, which can detect abnormal location switching behavior. Dynamic security scores can refer to quantitative risk values, such as fuzzy logic algorithms that evaluate device trustworthiness (0-1), network stability (0-1), and location compliance (0-1), which can be used to activate corresponding levels of encryption schemes.

[0026] The key management layer can refer to a key lifecycle management system that switches algorithm combinations such as AES-256 / SM4 based on dynamic risk thresholds (such as three consecutive authentication failures), which can manage the rotation of initial keys (generated during device registration), session keys (temporarily negotiated), and master keys (root keys). Dynamic risk thresholds can refer to adaptive security benchmarks that dynamically adjust risk determination standards based on historical attack frequencies (such as more than 5 abnormal requests per minute), enabling defense strength to float with threat posture. Encryption algorithm combinations can refer to dynamic cipher suites that automatically switch between symmetric algorithms such as AES / SM4 and asymmetric algorithms such as ECDSA / SM2 based on NIST standards, which can adapt to the security needs of different computing environments. The three-stage key system can refer to a key hierarchical architecture that implements tree-shaped derivation of master keys → initial keys → session keys through key derivation functions (KDF), which can reduce the risk of root key leakage.

[0027] The secure transmission layer can refer to a key distribution secure channel, for example, a key is divided into a client memory segment (volatile storage), a server HSM segment (hardware encryption machine), and a notarization platform segment (blockchain storage) in the execution mode after adopting TLS two-way authentication, which can prevent single-point key leakage. The client memory segment can refer to volatile key storage, which temporarily stores key fragments (survival period < 3 seconds) through memory encryption (such as Intel SGX) execution mode, which can prevent physical extraction attacks. The server HSM (hardware security module) segment can refer to hardware-level key protection, for example, handling key fragments in the encryption machine in the execution mode of FIPS140-2 Level 3 standard, which can resist operating system layer attacks. The third-party notarization platform segment can refer to decentralized storage, which manages key fragments (threshold ≥ 2 / 3) through blockchain smart contract execution mode, which can be used for key recovery arbitration.

[0028] The password service layer can refer to a key supply system, such as maintaining a key pool through pre-generating 500 regular keys (updated every hour) and 100 backup keys (updated daily) execution mode, which can support automatic triggering of biological characteristics + SMS dual-channel verification switching when the key usage reaches 80%. The regular key pool can refer to a set of keys used daily, such as automatically rotating 100 working keys every 24 hours using the AES-256 algorithm, which can ensure key security at a high frequency. The backup key pool can refer to a storage repository of backup keys, such as maintaining 3 groups of backup keys that can be enabled at any time using a hierarchical encryption storage key management system, ensuring that new keys can be switched to after a fuse. The non-sensing update can refer to seamless key switching, for example, preloading new keys (5% capacity early warning) using double buffering technology execution mode, which can avoid encryption service interruption. The two-way authentication channel can refer to a two-way identity verification link, for example, implementing two-way certificate verification between the client and the server through mTLS protocol execution mode, which is used to prevent man-in-the-middle attacks. High-frequency active update can refer to a preventive rotation strategy, such as forcing the update of the regular key pool every 50 encryption operations or 30 minutes execution mode, which can shorten the key effective window period. Low-frequency passive response update can refer to an event-driven rotation, for example, activating the backup key pool only when a brute force attempt is detected, which can save system resources.

[0029] The hardware isolation layer can refer to a physically secure storage unit, which stores environmental parameter history records (retained for 180 days) and key bloodline maps (records key derivation relationships) in the execution mode of TEE trusted execution environment, which is used for audit tracing and security analysis. The key bloodline map can refer to a key derivation relationship tree, which constructs a key family relationship chain by recording the derivation path of master key → session key → temporary key execution mode, which can be used to quickly locate the associated impact range of leaked keys.

[0030] The application will be further described in detail by a specific embodiment: A power plant sets up the encryption communication system based on multi-level key distribution of the application. At 8 o'clock in the morning, the mobile office terminal starts the security access process, and the six-layer components of the system begin to work cooperatively: The environment perception layer collects 12 types of environmental parameters in real time through the built-in sensor array. When it is detected that the device is connected to an overseas VPN node, the policy control layer activates the geofencing analysis module, combines the device fingerprint (such as the CPU serial number hash value) and the network delay fluctuation (measured average 187ms ± 35ms), and calculates that the current dynamic security score has dropped to 65 points (full score 100). At this time, the key management layer adjusts the dynamic risk threshold to 5.7 according to the preset algorithm, triggering the encryption policy to upgrade from the basic SM4 single algorithm to the SM2+SM4+SM9 combined mode.

[0031] The secure transmission layer then establishes a two-way authentication channel, splits the session key into three segments: a 32-byte client memory segment (stored in the RAM protection area), a 64-byte server HSM segment (held by the hardware security module), and a 16-byte notarization platform segment (distributed to the third party through quantum key distribution). This fragmented transmission cooperates with the timestamp hash chain verification to successfully intercept an attempt of a man-in-the-middle attack disguised as a Singapore node.

[0032] The password service layer synchronously enables the double-key pool mechanism: the regular key pool actively updates the key material at a frequency of 3 times per minute, and when it is monitored that the number of decryption failures per day exceeds the threshold of 5 times, the system automatically switches to the standby key pool within 23 milliseconds, during which the business traffic is not perceived. The security chip of the hardware isolation layer continuously records the key blood relationship, and the root key seed generated by the physically unclonable function cooperates with the anti-detection metal shielding layer (thickness up to 0.5mm) and the dynamic power balance circuit (fluctuation control at ±2.3mA) to ensure that even if the chip is physically acquired, effective information cannot be extracted.

[0033] When the terminal moves to the safe area at 12 o'clock in the afternoon, the environment perception layer detects that the network delay has dropped to 92ms ± 8ms and the geographic coordinates have returned to the recorded fence, and the policy control layer increases the security score to 88 points. The key management layer then extends the initial key validity period from 15 seconds to 2 minutes, and completely clears the historical key traces through the memory erasing instruction. During the whole process, the Merkle tree constructed by the hardware isolation layer has recorded 17 key derivation records, each leaf node contains a 256-bit hash value and a timestamp accurate to nanoseconds, forming a complete key life cycle map.

[0034] In response to a sudden DDOS attack, the system exhibits multi-level cooperative defense capability: the security transmission layer finds 5 abnormal access points through base station positioning data comparison, the password service layer fuses the affected key channel, and the key management layer starts the SM9 algorithm for key re-negotiation. During the attack, the system maintains an effective connection rate of 98.7%, which is 42.6% higher than the traditional encryption scheme.

[0035] The beneficial effects of one of the embodiments in the specification include: through the real-time collection of target environment parameters by the environment perception layer and the dynamic security score generated by the strategy control layer, a closed-loop feedback is formed to drive the key management layer to realize three-stage dynamic switching from the initial key, session key to master key, cooperate with the key fragmentation two-way authentication mechanism of the security transmission layer and the double key pool non-inductive update strategy of the password service layer, under the quantum resistance storage of the hardware isolation layer, a ring defense system with space-time adaptive characteristics is constructed, and finally four core advantages are achieved: (1) dynamic matching ability of environment perception and encryption strength, through a twelve-dimensional parameter matrix to realize the gradient upgrade of SM4 to SM2+SM4+SM9; (2) quantum computing attack resistant key management system, relying on physically unclonable master key generation and merkle tree structure key bloodline tracing; (3) transmission protection mechanism against man-in-the-middle attacks, using geographic stamp verification and timestamp hash chain double verification; (4) business non-aware security operation and maintenance capability, based on the fuse mechanism triggered by decryption failure rate and automatic switching of double-channel key pool, to achieve a substantial comprehensive improvement of security and availability.

[0036] In some optional implementations, the dynamic security score is determined according to a twelve-dimensional parameter matrix composed of device model, operating system version and network topology, for triggering the gradient upgrade from SM4 single algorithm to SM2+SM4+SM9 three-level encryption in combination with preset switching indicators.

[0037] The twelve-dimensional parameter matrix can refer to the feature space of security evaluation, for example, a risk assessment model is constructed by executing methods through 12 types of parameters such as device model (e.g. iPhone14), operating system version (iOS18.2), network topology (star / mesh), etc., which can achieve a fine-grained security rating of 0-100 points. The switching indicator can refer to the trigger condition of algorithm upgrade, such as activating the composite encryption mode when the score is below 65 points for 5 consecutive minutes and the man-in-the-middle attack feature is detected, which can be used to defend quantum computing brute force attacks. The gradient upgrade can refer to a progressive security enhancement mechanism to realize the hierarchical improvement of encryption strength by executing methods in the order of SM4 single algorithm (basic level) → SM2+SM4 (enhanced level) → SM2+SM4+SM9 (ultimate level), which can balance security and system overhead.

[0038] ‌As a specific example:‌ When the Internet of Things gateway detects that the device model is an old model (ESP8266), the operating system has a CVE-2025-1234 vulnerability, and the network topology presents an abnormal star connection, the twelve-dimensional parameter matrix calculates the current security score as 58 points. The system compares the switching indicators and finds that the condition of "score < 60 points for 3 minutes" is met, and the key management layer starts the gradient upgrade, switching the encryption combination from SM4 to an SM2 (key exchange) + SM4 (data encryption) + SM9 (attribute encryption) three-level system. The security transmission layer synchronously updates the key fragment distribution strategy, stores the SM2 public key fragment in the notarization platform blockchain, splits the SM4 session key into gateway TPM chip fragments and cloud HSM fragments, and transmits the SM9 master key fragment through a physically isolated channel. The entire process is completed within 300 ms and the business is not aware.

[0039] The twelve-dimensional parameter matrix realizes stereoscopic evaluation of the security posture, and the gradient upgrade mechanism dynamically adjusts the defense strength, which not only avoids resource waste in low-risk scenarios, but also quickly responds to advanced threats; the elastic switching design of multiple algorithm combinations effectively deals with different attack surfaces, and the coordinated use of SM series national cryptographic algorithms forms a depth defense in the field of cryptography; the automatic decision-making system based on quantitative indicators reduces human intervention delay, so that the system always maintains the optimal security state in a complex network environment.

[0040] In some optional implementations, the initial key is configured as the outermost working key, and its validity period is automatically adjusted according to the obtained real-time security environment evaluation result, and the basic time length is set to a second-level interval, wherein, after the initial key is used up, a physical-level memory is erased to make the key material unrecoverable; The session key management uses a national cryptographic standard protocol to establish an encrypted channel, and the life cycle of the session key is dynamically controlled by two conditions; when any condition is triggered, the key re-negotiation process is started, and the old and new keys are completely isolated through forward security design, wherein, the two conditions include: whether the current transmission traffic is greater than a preset data transmission threshold, and whether the real-time updated session risk value in the session process is greater than a set value.

[0041] In some optional implementations, the master key is stored in a secure chip with physical isolation as a root key, and an initial seed is generated through a physically unclonable method; the secure chip integrates a multi-level protection system, including a metal shielding layer against physical detection, a power balance circuit against side-channel attacks, and a proactive destruction unit with a tamper-proof proactive destruction mechanism.

[0042] The initial key can refer to the outermost working key, for example, dynamically adjust the validity period (default 30-300 seconds interval) by security environment evaluation module (3 samples per second), can ensure that the key material is not recoverable with physical level memory overwrite (7 times 0xFF fill + random noise). The second level interval can refer to the key time control unit, such as the survival period of 60-180 seconds is flexibly set according to the network jitter rate (±15% fluctuation), which can adapt to the fast switching scene under 5G / 6G network. Physical level memory erase can refer to the anti-recovery clearing technology, which destroys the key storage traces by memory address mapping table traversal (coverage 100%), which is used to prevent cold start attack and other physical extraction methods. Double condition dynamic control can refer to the session key management strategy, which triggers ECC-SM2 key renegotiation when the transmission traffic breaks through the threshold (such as 1GB) or the session risk value (0-100 scale) exceeds 75 points, which can realize forward security protection. Forward security design can refer to the key isolation mechanism, for example, destroy the DH exchange parameter history record when a new session key is generated each time, which can prevent historical communication from being cracked later. Physically unclonable way can refer to PUF technology, which generates initial seed by chip manufacturing difference (transistor threshold voltage fluctuation), which can guarantee the uniqueness of root key with nanoscale physical characteristics. Active destruction unit can refer to the hardware self-destruction module, which melts the storage unit when it detects opening detection (pressure sensor trigger) or temperature anomaly (> 85℃), which is used to resist physical reverse engineering.

[0043] As a specific example: When the smart meter uploads data through NB-IoT, the environment perception layer detects that the signal strength drops sharply (-20dBm), and the policy control layer compresses the initial key validity period to 60 seconds. During transmission, the session key management module finds that: 1) the cumulative transmission amount reaches 1.2GB (exceeding the 1GB threshold); 2) the session risk value rises to 82 points due to replay attack. The system starts SM2 key renegotiation, and the newly generated session key is derived through the PUF module of the security chip, and the old key material is completely destroyed after three-level erasure (logical deletion→physical overwrite→register reset). The whole switching process takes 470ms, during which the data packets keep encrypted continuity through the preset backup key pool.

[0044] The second-level dynamic survival mechanism of the initial key effectively reduces the attack window period, and the physical-level erasure technology completely blocks the possibility of key recovery; the double-condition triggered session key management not only prevents large data leakage risk, but also responds to real-time threats in time; the multi-level protection system of the security chip builds the ultimate defense line at the hardware level, especially the combination of PUF technology and active destruction unit, which can still guarantee the security of the root key when facing extreme scenes such as physical seizure. The whole scheme realizes the full-dimensional security protection from logical encryption to physical protection.

[0045] In some optional implementations, the key fragmentation transmission adopts an improved geo-stamp verification method, including time-stamp hash chain and base station positioning data double verification, to prevent man-in-the-middle attacks caused by cross-border hop access.

[0046] Real-time security environment assessment can refer to a dynamic risk monitoring system, for example, collecting 200 security indicators per second through intrusion detection system (IDS) logs and hardware trusted execution environment (TEE) state execution, for triggering the initial key's fuse mechanism. Physical-level memory erasure can refer to a key destruction technology, to completely clear the key residual charge by applying a 7V reverse voltage pulse to the storage chip's capacitor unit, which can prevent cold boot memory recovery attacks. The geo-stamp verification method can refer to a location binding verification mechanism, for example, combining time-stamp hash chain (SHA-3 value generated every millisecond) and base station CID / RSSI fingerprint execution to verify the transmission terminal location, for identifying VPN disguised geographic deception. Cross-border hop access can refer to a cross-border proxy attack path, which can detect traffic transit behavior by analyzing the TTL jump number mutation of TCP packets and BGP routing table anomalies, and can block man-in-the-middle attacks using cloud service transit.

[0047] ‌As a specific example:‌ When a terminal accesses the system at a foreign airport, real-time security environment assessment detects that GPS positioning does not match base station CID (error > 2km), and the initial key validity period is compressed from the default 60 seconds to 35 seconds. After the key is used up, the security chip performs physical-level memory erasure, and the key fragmentation transmission process activates geo-stamp verification: time-stamp hash chain verifies that the end-to-end delay is < 50ms (hash value matches), and base station positioning data comparison shows that the LAC code is consistent with the customs record list. The system rejects hop connection requests from AWS Singapore nodes (TTL mutation 3 hops), and finally only allows key fragment transmission from local telecom operator IP segments.

[0048] The second-level dynamic validity period setting of the initial key forms a defense depth in the time dimension, combined with the physical-level memory erasure technology to completely eliminate the key residual risk; the improved geo-stamp verification mechanism integrates spatial dimension authentication based on traditional time verification, effectively identifying man-in-the-middle attacks that fake geographic locations; the closed-loop control of real-time environment assessment and key management enables the system to resist advanced cross-border attacks while maintaining high availability standards for financial-level business.

[0049] In some optional implementations, the first calculation formula for calculating the dynamic risk threshold includes:

[0050] wherein R is a dynamic risk threshold, N represents a total number of timestamp features, and the timestamp features comprise at least two of: a baseline time offset, an inter-session interval variance, an operational time period activity, a geotemporal coordination anomaly, a blocked cross-country attack jump, a key life cycle fluctuation, a fragmented transmission time consistency, a clock drift compensation value, a historical operational time entropy, an emergency fuse response latency, and a multi-device time coordination signature. is a weight coefficient of the i-th timestamp feature, derived from a baseline profile calibration of a policy control layer; is a timestamp offset of the i-th timestamp feature, generated by a clock synchronization module of a secure transmission layer; is a baseline time interval, determined according to historical operation data of a hardware isolation layer; and M is a total number of geofences, is a decay factor of the j-th geofence, configured by a regional policy of a key management layer; is an environment sensitive coefficient, dynamically adjusted according to a dynamic security score; is a real-time geolocation hash value, obtained according to a positioning module; is a registered geofence center point.

[0051] The dynamic risk threshold can refer to a security threshold dynamically calculated by the encryption system according to environmental parameters, such as being realized by a composite operation of timestamp features and geofence data, for triggering an encryption algorithm upgrade or a key rotation mechanism. The timestamp features can refer to time dimension parameters of system operation, for example, a 12-dimensional time feature matrix generated by a clock synchronization module, which can detect time anomaly behavior with millisecond-level precision. The baseline time interval can refer to a standard time reference value of historical operation, such as being determined by a 1000-time historical operation mean value stored by a hardware isolation layer, which can eliminate errors caused by system clock drift. The geofence can refer to the smallest safety calculation unit of spatial position, for example, a 1km×1km hash grid divided for a geofence, which can effectively identify coordinate jumps of cross-country access. The environment sensitive coefficient can refer to an amplification factor of network quality on risk, for dynamically adjusting the strictness of a geofence. The multi-device time coordination signature can refer to a time verification credential of cross-device operation, for example, a threshold signature algorithm for joint signature of time stamps of 3 devices, which can prevent single-device time from being tampered.

[0052] The weight coefficient can refer to an importance parameter of a timestamp feature, for example, derived by a machine learning model of a strategy control layer trained on historical attack data, for dynamically adjusting the contribution of different time features to the risk threshold. The attenuation factor can refer to a risk attenuation coefficient of a geographic grid, such as configuring different geographic areas with β_j values according to a regional threat level database, which can reduce the false positive rate in low-risk areas. The real-time geographic coordinate hash value can refer to an encrypted expression form of location information, for example, generating a 256-bit string by processing GPS coordinates through an SM3 hash algorithm, which can prevent location information from being stolen in plaintext transmission. The registered geographic fence center point can refer to a reference position of legal activity of a device, such as determining by recording Wi-Fi fingerprints and base station triangulation during the first authentication, for detecting abnormal displacement of the device. The timestamp offset can refer to the deviation value of the actual time from the standard time, for example, measured by the atomic clock synchronization system of the security transmission layer to the microsecond level, which can identify attacks that fake timestamps. The clock drift compensation value can refer to the error correction amount of the hardware clock, such as calculating the compensation value by comparing with the Beidou satellite time source through the NTP protocol, which can eliminate the cumulative error of the local clock of the device. The historical operation time entropy can refer to a time regularity index of user behavior, for example, calculating the Shannon entropy value of the operation time distribution in the past 90 days, which is used to detect activities in abnormal time periods. The emergency fuse response delay can refer to the delay time of the risk event triggering the defense, such as the 95% quantile of 23 milliseconds from detecting a cross-border attack to cutting off the connection, which can ensure the real-time blocking of critical operations.

[0053] By constructing a dynamic risk assessment model in the space-time dual dimension, not only does it solve the problem of defense lag caused by traditional fixed thresholds, but also avoids false blocking caused by excessive sensitivity. The coupling calculation of the timestamp hash chain and the geographic grid can effectively identify slow penetration behavior in APT attacks, and the adaptive adjustment of the environmental sensitivity coefficient significantly improves the availability of cross-border business. The space-time dual verification mechanism of the key fragments reduces the success rate of man-in-the-middle attacks to below the theoretical limit, and the consanguinity graph saved by the hardware isolation layer provides a complete evidence chain for post-audit.

[0054] In some optional implementations, the second calculation formula for calculating the environmental sensitivity coefficient includes:

[0055] wherein K represents the number of network quality indicator categories, and the network quality indicator at least includes at least two of the following features: network delay, delay fluctuation standard deviation, packet loss rate, bandwidth stability, and link transmission error rate; is a normalization parameter for the kth network quality indicator, obtained according to a target environment parameter; is the standard deviation of the kth network quality indicator; is a historical average of the kth network quality indicator, obtained according to historical environment parameters; is a minimum constant for preventing division by zero, is a latitude of the current location, is a longitude of the current location; is a dimension of a commonly used geographic location reference point, is a longitude of the commonly used geographic location reference point.

[0056] The network quality indicator can refer to a performance parameter of a communication link, such as real-time measurement of network delay, packet loss rate, and other data through a probe packet, which can dynamically evaluate the reliability of the current transmission channel. The normalization parameter can refer to a standardization coefficient of the indicator weight, such as using a Min-Max scaling algorithm to map each indicator value to the [0, 1] interval, which can eliminate the influence of different dimensions on the calculation result. The standard deviation can refer to the fluctuation degree of the network indicator, such as sampling delay data every 5 seconds and calculating the sliding window standard deviation, which is used to quantify the network jitter risk. The historical average can refer to the long-term benchmark value of network performance, such as calculating the moving average of bandwidth data in the same period in the past 30 days, which can identify the current abnormal fluctuation. The minimum constant can refer to a safety compensation amount for mathematical calculation, such as being fixed at the order of 10^-7, which can avoid formula collapse caused by zero denominator.

[0057] By dynamically calculating the environment-sensitive coefficient, the double-factor risk quantification of network quality and geographic fence is realized, which effectively identifies cross-border stepping stone attacks and network hijacking behaviors; the comparison mechanism of historical average and real-time data can adapt to the fault tolerance needs of different business scenarios, and the minimum constant design guarantees the robustness of the formula; the final output result directly drives the encryption strategy upgrade, forming a closed-loop defense from environment perception to security response, which reduces the false positive rate by more than 37% compared with the static threshold scheme.

[0058] In some optional implementation manners, the processing steps of the non-inductive update include: tracking the decryption failure rate in real time, and when the number of daily failures exceeds a set threshold, automatically triggering a key fuse mechanism and switching to a backup key pool.

[0059] The decryption failure rate can refer to the proportion of failed ciphertext verification, such as calculating the percentage of the number of failed decryption requests in the total number of requests in a 5-minute time window, which is used to quantify the effectiveness of the current key. The key fuse mechanism can refer to an automatic blocking strategy for security protection, such as stopping the use of the current primary key when the decryption failure rate exceeds 5%, which can prevent continuous attacks caused by key leakage.

[0060] As a specific example: The security gateway real-time statistics decryption failure data, when detecting that the failure rate within 10 minutes increases from 0.3% to 6.2% (threshold 5%), automatically executes the fuse script, blocks the use of the current master key MK-20250806, and generates a security event alarm. From the backup pool, a pre-generated BK-20250801 key is randomly selected and distributed to all terminal nodes through a TLS 1.3 channel. Within 15 seconds after the deployment of the new key, the system verifies that the decryption success rate has recovered to more than 99.98%, and the business traffic is automatically switched to the new key channel.

[0061] Through real-time monitoring of decryption failure rate, early detection of attack behavior is achieved, the key fuse mechanism ensures immediate containment of security threats, the backup key pool design ensures business continuity while improving system flexibility, and the entire processing flow completes security protection upgrade without user awareness. Compared with the traditional manual intervention scheme, the response time is shortened from hours to seconds, and the security risks caused by human operation errors are effectively avoided through the automatic mechanism.

[0062] In some optional implementations, the hardware isolation layer includes a historical key storage area for archiving expired keys and recording key derivation relationships, wherein the key pedigree map is constructed as a Merkle tree structure, each leaf node corresponds to a specific key generation record and / or usage log, and the operation record is implemented by hash chain storage to prevent tampering and traceability.

[0063] The hardware isolation layer can refer to a physical-level security protection mechanism, such as running key management functions independently through an HSM (Hardware Security Module) chip, which can prevent key theft by malicious programs in a physically isolated manner. The historical key storage area can refer to a secure area for archiving expired keys, such as reserving the latest 100 rounds of key update records in the protected storage space of a TPM 2.0 chip, to support audit traceability requirements. The key derivation relationship can refer to the derivation logic between keys, such as deriving session keys SK1-SK10 from the master key MK using the HKDF algorithm, which can establish a verifiable key family spectrum relationship. The Merkle tree structure can refer to a cryptographic hash tree, such as using each key operation record as a leaf node, calculating the parent node hash value layer by layer through the SHA-3 algorithm, which can efficiently verify data integrity. Hash chain storage can refer to a tamper-proof data structure, such as using the hash value of each operation record as the input parameter of the next record, which can form an irreversible verification chain.

[0064] As a specific example: Key archiving: when the master key MK-20250801 expires, the HSM automatically migrates it to the 7th partition of the historical storage area, while recording the association relationship of the 3 derived sub-keys (SK-01 to SK-03); ‌Graph construction‌: the system establishes a Merkle tree with MK-20250801 as the root node, whose leaf nodes contain the generation record (timestamp + operator ID) of the left leaf node SK-01 and the usage log (decryption times + last access time) of the right leaf node SK-02.

[0065] ‌Hash chain update‌: each time a key is operated, the SHA-256 hash value of the previous operation is taken as the input parameter of the current operation to form an unalterable operation sequence; ‌Audit verification‌: auditors can verify the authenticity of 1000 operation records within 15 ms by comparing the Merkle tree root hash with the real-time calculated hash value.

[0066] The hardware isolation layer provides physical-level security to fundamentally eliminate the risk of key leakage at the software level. The historical key storage area meets the data retention requirements of compliance audits, the key bloodline graph realizes panoramic visual monitoring of the key life cycle, the Merkle tree structure greatly reduces the storage space occupation while ensuring verification efficiency, and the hash chain technology ensures the unalterable nature of the operation record. Compared with the traditional database storage method, the whole set of solutions improves the key traceability efficiency by more than 40 times, and achieves financial-level security standards through the cryptography proof mechanism.

[0067] In some optional implementations, the two-way authentication channel adopts a hybrid encryption method, using the SM2 elliptic curve algorithm in the key negotiation stage and switching to the SM4 block cipher in the data transmission stage. The session key strength linearly increases with the dynamic security score.

[0068] ‌Hybrid encryption method‌ can refer to a scheme that combines asymmetric and symmetric encryption, such as using asymmetric encryption to exchange keys in the handshake phase and switching to symmetric encryption for subsequent communication, which can balance security and performance.‌SM2 elliptic curve algorithm‌ can refer to the asymmetric encryption algorithm of the national cryptography standard, such as using a 256-bit elliptic curve over a prime field to achieve key exchange with the security strength of RSA 2048 bits.‌SM4 block cipher‌ can refer to the symmetric encryption algorithm of the national cryptography standard, such as using 128-bit blocks and 32 rounds of nonlinear transformation, which can achieve encryption throughput of more than 20 Gbps under hardware acceleration.

[0069] As a specific example: The client sends a certificate chain containing an SM2 public key, and the server returns an SM2-encrypted random number R1 (128 bytes) after verifying the validity of the certificate; both parties generate a shared key K through the SM2 algorithm, and calculate the initial security score of the session (based on device fingerprint, IP reputation, etc.); when the score drops to 70 points, the SM4 key length is automatically upgraded from 128 bits to 256 bits; use SM4-CTR mode to encrypt business data, re-evaluate the security score every 5 minutes and dynamically adjust the encryption parameters; when the score is lower than 50 points or the idle time is more than 15 minutes, forcibly disconnect the connection and destroy the session key.

[0070] The two-way authentication mechanism fundamentally eliminates the risk of man-in-the-middle attacks, the hybrid encryption scheme improves data transmission efficiency while ensuring forward security, the application of national cryptographic algorithms meets the requirements of Cybersecurity Protection 2.0 and the security evaluation of cryptographic applications, the dynamic scoring system realizes intelligent balance between security protection and performance consumption, and the whole set of solutions can reduce more than 30% of the waste of computing resources compared with static encryption strategies, while the anti-cracking ability of key business data is improved to the level of quantum security.

[0071] The preferred embodiments of the above disclosure are only used to help explain the present disclosure. Alternative embodiments do not describe all the details and do not limit the invention to the specific embodiments described. Obviously, according to the content of the present invention, many modifications and changes can be made. The present disclosure selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present disclosure. The present disclosure is limited by the claims and their entire scope and equivalents.

Claims

1. A multi-level key distribution based encrypted communication system, characterized by, The ring defense structure comprises an environment perception layer, a policy control layer, a key management layer, a secure transmission layer, a cryptographic service layer and a hardware isolation layer, The environment perception layer is used for collecting target environment parameters of the current time in real time; The policy control layer obtains device fingerprints, network delays and geofencing parameters in the target environment parameters, and generates a dynamic security score; The key management layer switches encryption algorithm combinations and manages a three-stage key system of initial keys, session keys and master keys according to the dynamic security score and a dynamically calculated dynamic risk threshold value; The secure transmission layer performs key fragmentation transmission through a two-way authentication channel, splits a single key into a client memory segment, a server HSM segment and a third-party notarization platform segment; The cryptographic service layer implements no-sense update by using a pre-generated regular key pool and a backup key pool, and triggers two-channel verification switching when the key usage reaches a threshold value, wherein the update mode of the regular key pool is high-frequency active update, and the update mode of the backup key pool is low-frequency passive response update; The hardware isolation layer stores historical environment parameters and key bloodline atlas.

2. The system of claim 1, wherein, The dynamic security score is determined according to a twelve-dimensional parameter matrix composed of device models, operating system versions and network topologies, and is used to trigger gradient upgrading from SM4 single algorithm to SM2+SM4+SM9 three-level encryption in combination with preset switching indicators.

3. The system of claim 2, wherein, The initial key is configured as an outermost working key, and its validity period is automatically adjusted according to the obtained real-time security environment evaluation result, and the basic time length is set to a second-level interval, wherein the initial key triggers physical-level memory erasure after use, so that the key material cannot be recovered; The session key management establishes an encryption channel by using a national standard protocol, and the life cycle of the session key is dynamically controlled by two conditions; when any condition is triggered, a key re-negotiation process is started, and the old and new keys are completely isolated through forward security design, wherein the two conditions include whether the current transmission flow is greater than a preset data transmission threshold value, and whether a session risk value updated in real time during the session is greater than a set value.

4. The system of claim 3, wherein, The master key is stored in a secure chip with physical isolation as a root key, and an initial seed is generated by a physically unclonable method; the secure chip integrates a multi-level protection system, including a metal shielding layer against physical detection, a power balance circuit against side-channel attacks, and an active destruction unit provided with an active destruction mechanism against tampering.

5. The system of claim 4, wherein, The key fragmentation transmission adopts an improved geographic stamp verification method, which contains time stamp hash chain and base station positioning data double verification, to prevent man-in-the-middle attacks caused by cross-border access.

6. The system of claim 5, wherein, The first calculation formula for calculating the dynamic risk threshold value includes: wherein R is the dynamic risk threshold, N represents the total number of timestamp features, and the timestamp features include at least two of the following: a reference time offset, a session interval variance, an operation period activity, a geographic time coordination anomaly, a blocked cross-country attack jump, a key life cycle fluctuation, a fragment transmission time consistency, a clock drift compensation value, a historical operation time entropy, an emergency fuse response delay, and a multi-device time coordination signature, is a weight coefficient of the i-th timestamp feature, derived from a reference image calibration of a policy control layer; is a timestamp offset of the i-th timestamp feature, generated by a clock synchronization module of a secure transmission layer; is a reference time interval, determined according to historical operation data of a hardware isolation layer; M is the total number of geographic grids, is a decay factor of the j-th geographic grid, configured by a regional policy of a key management layer; is an environment sensitive coefficient, dynamically adjusted according to a dynamic security score; is a real-time geographic coordinate hash value, obtained according to a positioning module; is a registered geographic fence center point.

7. The system of claim 6, wherein, The second calculation formula for calculating the environment sensitivity coefficient includes: wherein K represents the number of network quality indicator categories, the network quality indicator at least comprising at least two of the following features: network latency, latency fluctuation standard deviation, packet loss rate, bandwidth stability, and link transmission error rate; is a normalization parameter for the kth network quality indicator, obtained according to the target environment parameter; is a standard deviation for the kth network quality indicator; is a historical mean for the kth network quality indicator, obtained according to the historical environment parameter; is a small constant to prevent division by zero, is a latitude of the current location, is a longitude of the current location; is a latitude of the common geographical location reference point, is a longitude of the common geographical location reference point.

8. The system of claim 1, wherein, The processing steps of the no-sense update include: Real-time tracking of decryption failure rate, when the number of daily failures exceeds a set threshold value, the key fusing mechanism is automatically triggered and switched to the backup key pool.

9. The system of claim 1, wherein, The hardware isolation layer includes a historical key storage area for archiving expired keys and recording key derivation relationships, wherein the key pedigree is constructed as a Merkle tree structure, each leaf node corresponds to a specific key generation record and / or usage log, and tamper-proof traceability of operation records is achieved through hash chain storage.

10. The system of claim 1, wherein, The bidirectional authentication channel adopts a hybrid encryption method, uses an SM2 elliptic curve algorithm in the key negotiation phase, switches to an SM4 block cipher in the data transmission phase, and the session key strength linearly increases with the dynamic security score.

Citation Information

Cited By

  • Power distribution terminal key management method and system based on trusted computing

    CN121690575A