A verifiable random encryption generation method and system for privacy data protection

By recording task scheduling operation time and state switching, identifying high-sensitivity nodes, adjusting algorithms and parameters, generating verifiable random sequences, and forming a joint signature chain, the problem of key generation depending on seed parameters in existing technologies is solved. This achieves balanced key distribution and full verifiability, improving data security and responsiveness.

CN121485920BActive Publication Date: 2026-05-05BEIJING QIDIAN ZHIYAN DATA TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING QIDIAN ZHIYAN DATA TECHNOLOGY CO LTD
Filing Date
2025-11-13
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

In the process of key stream generation and distribution, existing technologies cannot dynamically monitor node status, lack correlation analysis between operation time and status changes, resulting in key generation relying on seed parameters and pseudo-random sequences, making it difficult to flexibly adjust encryption mechanisms, lacking full-process status tracking and recording, and having limited security auditing and tracing capabilities. This can easily lead to information leakage and data tampering risks in complex multi-node environments.

Method used

By recording the start and end times and state transitions of operations during task scheduling, high-sensitivity nodes are identified, the algorithm call order and parameter relationships are adjusted, verifiable random sequences are generated, key distribution is recorded, and a joint signature chain is formed using a threshold signature mechanism. This enables link tracing and data consistency correction, and supports balanced key distribution parameter allocation and full verifiability.

Benefits of technology

It improves data security, reliability, and dynamic response capabilities in multi-node collaborative environments, enables full verification and traceability of key generation and data distribution, and enhances the flexibility and consistency of data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121485920B_ABST
    Figure CN121485920B_ABST
Patent Text Reader

Abstract

This invention relates to the field of random encryption technology, specifically to a verifiable random encryption generation method and system for privacy data protection. The method includes the following steps: based on cloud-based data encapsulation tasks, recording the timing of scheduling operations and state transitions, identifying high-sensitivity nodes, calling a standard cryptographic stack to adjust the encryption structure and parameters, generating and verifying a random sequence using a verifiable random function, and statistically verifying and correcting the consistency of nodes and the signature chain. This invention maps node operations to the linked encryption structure, automatically archives timing indices and policy signals to transparent log blocks, uses multi-node joint signatures to form a statistically verifiable data link, utilizes the node timing distribution and signature chain connection relationship for continuity verification, and combines distribution parameters and link tracing to achieve full verifiability and traceability of key generation, data distribution, and operation processes, thereby improving data security, reliability, and dynamic response capabilities in a multi-node collaborative environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of random encryption technology, and in particular to a verifiable random encryption generation method and system for privacy data protection. Background Technology

[0002] The field of random encryption mainly involves methods and principles for encrypting and protecting digital information during transmission and storage through randomness mechanisms. The core of this technology includes key generation mechanisms, encryption random number control, encryption function design, and data security verification methods, and it is widely used in scenarios such as network communication, cloud computing, privacy storage, and secure multi-party data exchange. Traditional random encryption refers to data encryption using pseudo-random number generation algorithms combined with symmetric or asymmetric encryption algorithms. This method typically relies on a fixed key distribution system, generating a keystream through linear congruence methods or pseudo-random sequences based on seed parameters, and then combining this with hash functions or modular exponentiation to output encrypted data.

[0003] Existing technologies cannot dynamically monitor node status during key stream generation and distribution. There is a lack of correlation analysis between operation time and state changes. Key generation mainly relies on seed parameters and pseudo-random sequences, making it difficult to flexibly adjust encryption mechanisms for task flow and state changes. The source of randomness is singular, the node operation sequence and state switching are opaque, and there is a lack of full-process state tracking and recording. It is difficult to detect abnormal node responses and data consistency issues. The key distribution and operation process have insufficient verifiability, and the security audit and traceability capabilities are limited. In complex multi-node environments, risks such as information leakage and data tampering are likely to occur, and the flexibility and traceability of data security management are both constrained. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of existing technologies and to propose a verifiable random encryption generation method and system for privacy data protection.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a verifiable random encryption generation method for privacy data protection, comprising the following steps:

[0006] S1: Based on cloud data encapsulation tasks, record the start and end times and state transitions of each operation in task scheduling, calculate the time interval according to the node sequence, identify high-sensitivity nodes with prominent frequency characteristics, and obtain the strategy layer signal set.

[0007] S2: Based on the policy layer signal set, call the standard cryptographic stack, match the algorithm structure and parameter combination, adjust the algorithm call order and parameter relationship, reorganize the encryption process, update the node operation mapping, and obtain the reconstructed form of the mapping structure.

[0008] S3: Based on the reconstructed form of the mapping structure, call the verifiable random function to generate a random sequence, extract the hash features of the input parameters for verification, record the random distribution, compare the sequence consistency under each path, and obtain the key distribution balance parameters;

[0009] S4: Based on the key distribution balance parameters, the key generation and encryption execution data are digested and written into a transparent log block. A threshold signature mechanism is used to merge the signatures of each node to form a joint signature chain, thus obtaining a link tracing dataset.

[0010] S5: Based on the link tracing dataset, analyze the temporal order between nodes and the connection of the signature chain, statistically verify the relationship of strategy signals, extract the signature time features of nodes, locate and correct the deviating nodes, and obtain the structural consistency determination parameters.

[0011] The present invention improves upon this invention by including the following: the policy layer signal set includes a node identifier sequence, a frequency feature code, and a signal association label; the mapping structure reconstruction form includes an algorithm path mapping table, a parameter adaptation list, and a node authentication label; the key distribution balance parameters include a random verification flag, a key distribution index, and a group consistency number; the link tracing dataset includes a log number list, a signature chain number, and a node tracing label; and the structure consistency determination parameters include a correction identifier number, a continuity status code, and a verification record number.

[0012] The present invention is improved in that the step of obtaining the strategy layer signal set is specifically as follows:

[0013] S111: Based on cloud data encapsulation tasks, extract the start and end time information of each data processing operation, organize the node order of each operation in the task scheduling process, analyze the order of operations and node distribution, and combine the time sequence and node arrangement to obtain the operation scheduling sequence.

[0014] S112: Based on the operation scheduling sequence, compare the time sequence and state type of each node, analyze the state change trajectory of the node in the scheduling process, screen the nodes that have undergone state switching, and extract the node group with dynamic change characteristics by combining the node identifier and the switching time to obtain the dynamic node identifier set.

[0015] S113: Based on the dynamic node identifier set, analyze the execution order and process sorting between nodes, summarize the order differences between nodes, extract the arrangement offset of each node in the process, adjust the order according to the node distribution, and obtain the strategy layer signal set.

[0016] The present invention is improved in that the step of obtaining the reconstructed form of the mapping structure is specifically as follows:

[0017] S211: Based on the signal set of the strategy layer, analyze the arrangement order of each group of signals in the node sequence, determine the signal identifier and node position item by item, compare the correspondence between the signal and the node index, identify the mapping state where the arrangement order has changed, and obtain the signal mapping order data.

[0018] S212: Based on the signal mapping sequence data, compare the index order of the nodes with that of the standard encryption parameter structure, analyze the offset that occurs when the nodes are arranged, screen out the node segments with continuous indexes but abrupt changes in order, compare the segment structure identifier with the order mapping relationship, and obtain the mapping offset segment.

[0019] S213: Based on the mapping offset segment, determine the consistency of the order of each segment. For node segments with reversed order or abnormal intervals, adjust the node structure arrangement. By exchanging the positions of associated nodes, optimize the order matching and obtain the reconstructed mapping structure.

[0020] The present invention is improved in that the step of obtaining the key distribution balance parameter is specifically as follows:

[0021] S311: Based on the reconstructed form of the mapping structure, compare the key distribution characteristics of the random sequence in each node segment, analyze the difference between the data distribution of each segment and the corresponding segment in the distributed identity authentication credential structure, and obtain the segment key difference sequence.

[0022] S312: Based on the segmented key difference sequence, identify structural segments with consistent distribution trends within the segments, filter segments whose key distribution change trends are consistent with node distribution parameters, and obtain a set of consistent distribution segments;

[0023] S313: Based on the aforementioned set of consistent distribution segments, statistically analyze the key distribution quantity of each segment and the dispersion between the distributions of each segment, compare the differences in distribution between segments, and use the following formula:

[0024] ;

[0025] Obtain the key distribution balance parameters ,in, This represents the number of segments within the set of consistent segments with disturbance. Representing the Key distribution quantity in each segment, This represents the average key distribution across all segments within the set of perturbed, consistent segments. Representing the The degree of dispersion of key distribution within each segment.

[0026] The present invention is improved in that the steps for obtaining the link tracing dataset are specifically as follows:

[0027] S411: Based on the key distribution balance parameters, analyze the node time series and policy layer signal order information, determine the time correspondence between each node and the policy signal, optimize the arrangement order of the node operation phase, identify the matching items between the node and the signal order, and obtain the node time series signal mapping sequence.

[0028] S412: Based on the node timing signal mapping sequence, compare the operating cycle and signal interval of each node, analyze the time interval and synchronization characteristics of the trajectory segment, obtain the trajectory disturbance synchronization index, identify the trajectory synchronization abnormal segment, and obtain the synchronous trajectory deviation segment.

[0029] S413: Based on the synchronization trajectory deviation section, optimize the correspondence between policy signals and node operations within the section, identify the data synchronization content, adjust the node order, and write it into the distributed joint signature structure to obtain the link tracing dataset.

[0030] The present invention is improved in that the step of obtaining the structural consistency determination parameters is specifically as follows:

[0031] S511: Based on the link tracing dataset, compare the identity identifier and signature chain number of each node one by one, determine the correspondence between the node input / output identifier and the link node sequence number, mark the corresponding abnormal nodes through node information matching and verification, and obtain the corresponding sequence of node structure.

[0032] S512: Based on the corresponding sequence of the node structure, compare the node trajectory record with the node order of the signature chain, analyze the consistency between the index and time order of the continuous trajectory segments, determine the continuity of the node connection process, screen for positions with connection breaks or sequence abnormalities, and obtain a set of trajectory continuity anomalies.

[0033] S513: Based on the trajectory continuity anomaly set, and referring to the signature information of adjacent nodes, the anomaly nodes are reorganized, the temporal arrangement and node order of the signature chain are adjusted, the consistency of the link signature data is corrected, and the structural consistency determination parameters are obtained.

[0034] The present invention is improved in that the start and end times of each operation refer to the actual start and end times of each scheduling operation, the state switching process refers to the process by which an operation node or data stream changes from one state to another during the scheduling process, and the standard cryptographic stack refers to a preset cryptographic algorithm, including a set of mainstream encryption, decryption and authentication algorithms.

[0035] A verifiable random encryption generation system for privacy data protection, the system comprising:

[0036] The signal acquisition module encapsulates tasks based on cloud data, records the start and end times and state transitions of each operation in the task scheduling, calculates the time interval according to the node sequence, identifies high-sensitivity nodes with prominent frequency characteristics, and obtains the strategy layer signal set.

[0037] The encryption mapping module, based on the policy layer signal set, calls the standard cryptographic stack to match the algorithm structure and parameter combination, adjusts the algorithm call order and parameter relationship, reorganizes the encryption process, updates the node operation mapping, and obtains the reconstructed form of the mapping structure.

[0038] The random verification module reconstructs the form based on the mapping structure, calls a verifiable random function to generate a random sequence, extracts the hash features of the input parameters for verification, records the random distribution, compares the sequence consistency under each path, and obtains the key distribution balance parameters.

[0039] Based on the key distribution balance parameters, the log signature module records the digest of key generation and encryption execution data, writes it into a transparent log block, and uses a threshold signature mechanism to merge the signatures of each node to form a joint signature chain, thus obtaining a link tracing dataset.

[0040] Based on the link tracing dataset, the consistency correction module analyzes the temporal order between nodes and the connection of the signature chain, statistically verifies the relationship of strategy signals, extracts the signature time features of nodes, locates and corrects deviating nodes, and obtains structural consistency determination parameters.

[0041] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0042] In this invention, the operation frequency characteristics and node timing trajectories are integrated through the strategy layer signal. Combined with adaptive adjustment of the algorithm path and multi-path randomness verification, the balanced distribution of key distribution parameters is supported. The encryption structure is linked through node operation mapping. The timing index and strategy signals are automatically archived to the transparent log block. Multi-node joint signature is used to form a statistically verifiable data link. The continuity is checked by using the node timing distribution and the connection relationship of the signature chain. Abnormal nodes are located and data consistency correction is performed. The distribution parameters and link tracing are combined to realize the full verification and traceability of key generation, data distribution and operation process, thereby improving the data security, reliability and dynamic response capability in a multi-node collaborative environment. Attached Figure Description

[0043] Figure 1 This is a flowchart of the main steps of the present invention;

[0044] Figure 2 This is a flowchart illustrating the acquisition of the strategy layer signal set in this invention.

[0045] Figure 3 This is a flowchart illustrating the process of obtaining the reconstructed form of the mapping structure in this invention.

[0046] Figure 4 This is a flowchart illustrating the process of obtaining the key distribution balance parameters in this invention.

[0047] Figure 5 This is a flowchart illustrating the process of obtaining the link tracing dataset in this invention.

[0048] Figure 6 This is a flowchart illustrating the process of obtaining the structural consistency determination parameters in this invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0050] In the description of this invention, it should be understood that the terms "length," "width," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, in the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0051] Please see Figure 1 This invention provides a technical solution: a method for generating verifiable random encryption for privacy data protection, comprising the following steps:

[0052] S1: Based on cloud data encapsulation tasks, the start and end times and state switching processes of each operation in task scheduling are recorded. The time interval is calculated according to the node order and the state change trajectory is extracted. High-sensitivity nodes are identified based on change frequency and order stability. Nodes with prominent frequency characteristics are marked as policy layer signal sources to obtain the policy layer signal set.

[0053] Definition and quantization calculation of frequency characteristics:

[0054] Frequency characteristics refer to the frequency of state changes or scheduled operations of a single node within a scheduling cycle, reflecting the node's activity level and response density in the overall process.

[0055] The quantitative calculation method can be described as follows:

[0056] The number of times each node is scheduled as an operation node within a preset period (denoted as F) and the number of times each node undergoes a state switch (such as activation, suspension, resumption, etc.) within a preset period (denoted as S) are counted. The two items can be weighted and summed to form a node frequency score: Frequency Feature Score = α × F + β × S;

[0057] Here, α and β are preset weighting factors that reflect the relative impact of operation scheduling and state changes on frequency.

[0058] Or use a single dimension:

[0059] The frequency of state transitions or operation triggers is used as the "frequency characteristic" indicator.

[0060] The frequency characteristic is a weighted sum / single statistic of the frequency of operations and the frequency of state transitions within each node's period.

[0061] Sequence stability refers to the fluctuation range of the operation sequence of a node over multiple scheduling cycles.

[0062] Typically, the order of node operations is compared with the results of the previous sorting round.

[0063] The changes in the order of nodes are reflected by statistical measures such as the standard deviation and mean absolute difference of the ranking changes in the sequence.

[0064] The threshold for determining high-sensitivity nodes can be defined as:

[0065] Normalize and sort the frequency feature scores of all nodes.

[0066] Nodes with scores higher than a certain quantile (such as the 90th percentile) or the mean plus a certain number of standard deviations are identified as high-sensitivity nodes.

[0067] Alternatively, it can be directly defined that a node is considered a high-sensitivity node when its frequency characteristic score is greater than a preset threshold (such as system parameter T).

[0068] High-sensitivity nodes refer to nodes whose frequency characteristic scores are greater than the system's preset threshold or that are in the high-score range of all nodes.

[0069] The frequency characteristic is the weighted sum of the number of operations and the number of state transitions of a node within a period. High-sensitivity nodes are those whose frequency characteristic scores are greater than the system-set threshold. Sequence stability is reflected by the fluctuation range of the node operation sequence.

[0070] After extracting the signal set at the strategy layer, a signal-parameter mapping table needs to be set up to clarify the encryption parameter scheduling rules corresponding to different signal characteristics. The specific logic is as follows:

[0071] Signal features and parameter category mapping: The signal set contents such as node identifier sequence, frequency feature code, and signal association label are respectively mapped to encryption parameter items such as algorithm type, key length, encryption mode, and parameter adaptation options in the standard cryptographic stack.

[0072] Mapping rule definition:

[0073] High-frequency node identifiers correspond to stronger encryption algorithms or longer key parameters;

[0074] Specific signal labels (such as fluctuations, anomalies, and continuous changes) correspond to specific algorithm selection strategies (such as symmetric / asymmetric switching and grouping mode adjustment).

[0075] Changes in the sequence of signals trigger dynamic parameter switching to maintain synchronization with the current data flow state;

[0076] Signal-parameter mapping table: A structured mapping table is defined as follows:

[0077]

[0078] Dynamic adjustment: Based on the current strategy layer signal set, the table is looked up in real time to automatically complete parameter scheduling.

[0079] After obtaining the policy layer signal set, S1 maps each signal feature to the encryption algorithm, key length, encryption mode, and authentication method parameters of the standard cryptographic stack through the signal-parameter mapping table, thereby realizing the dynamic configuration of encryption parameters and process optimization driven by signals.

[0080] S2: Based on the policy layer signal set, the standard cryptographic stack is called to map and compare the algorithm structure, parameter combination and authentication process. According to the difference between the trigger mode and the algorithm call path in the signal sequence, the algorithm call order and parameter correspondence are adjusted, the encryption operation process is reorganized, the node operation mapping relationship is updated, and the reconstructed form of the mapping structure is obtained.

[0081] VRF solutions may include:

[0082] Based on elliptic curves (such as EC-VRF, which conforms to standards such as RFC 9381), it is suitable for high-security and high-performance scenarios;

[0083] Algorithms based on the large number factorization problem, such as RSA-VRF, can also be used.

[0084] In practical applications, EC-VRF is the preferred choice because it offers a good balance between privacy protection and performance.

[0085] The specific implementation of input seed generation is as follows:

[0086] Node ID: Each participating node has a unique identifier, which is used as part of the seed;

[0087] Operation timestamp: The operation timestamp obtained in real time when VRF is called, which is used to increase the unpredictability of the seed;

[0088] Strategy signal characteristics: The content of the strategy layer signal set obtained from step S1 (such as frequency feature codes, node order information, etc.) can participate in seed construction to further enhance dynamism;

[0089] Previous encryption output digest (optional): Introduce the digest result from the previous encryption process to enhance the entropy source complexity.

[0090] Examples of combination methods:

[0091] Seed = Hash(Node ID || Current Timestamp || Policy Signal Feature || Previous Round Summary).

[0092] Seed generation and VRF call process;

[0093] Collect the current node identifier and obtain the current system or operation timestamp;

[0094] Key parameters in the strategy layer signal set are spliced ​​or salted in a predetermined order;

[0095] After all fields are merged, the original seed is generated using a secure hash algorithm (such as SHA-256);

[0096] The seed is input into the selected EC-VRF or RSA-VRF to achieve random output and verifiability.

[0097] S3: Based on the mapping structure, reconstruct the form, call the verifiable random function to generate a random sequence, extract the hash features of the input parameters and perform delayed verification, record the distribution of random outputs among nodes, compare the sequence consistency under each generation path, select the verified random group as the basis for key generation, organize the randomness verification records, and obtain the key distribution balance parameters.

[0098] If delayed verification fails, the process includes the following steps:

[0099] Failure handling: Immediately discard the currently generated random sequence, treat the random number as invalid, and do not use it as the basis for key generation;

[0100] Retry mechanism: The random sequence generation and verification process is automatically re-executed, and the verifiable random function is called again each time based on new input parameters or random source to avoid reusing failed paths;

[0101] Maximum number of retries: Set a fixed maximum number of retries, such as three. After consecutive verification failures reach the limit, no further attempts will be made.

[0102] Degradation strategy: If the delayed verification still fails after multiple retries, a degradation mechanism will be triggered, and the following measures can be taken:

[0103] Switch to an alternative random source or a different verifiable random function;

[0104] To reduce security requirements, a more reliable but not optimal random sequence generation method is adopted to ensure system availability;

[0105] Record failure events and degradation processes to system logs or transparent log blocks for subsequent security audits and traceability.

[0106] S4: Based on the key distribution balance parameter, the execution data of key generation, policy signal and encryption operation are digested and written into the transparent log block, marked with operation number and time index. The threshold signature mechanism is adopted to distribute the signature task among multiple nodes, and the signature results of each node are merged to form a joint signature chain to obtain the link tracing dataset.

[0107] Transparent log blocks, implementation process:

[0108] Each time a key generation, encryption operation, policy signal, or data correction event occurs, the system encapsulates key information such as event summary, relevant parameters, operation number, and time index into a log record.

[0109] Generate a data digest hash for each log record and chain it with the hash value of the previous log record to achieve a chained link;

[0110] Write logs to transparent log blocks and sign or timestamp the entire block or each log entry.

[0111] It supports batch verification and public auditing of log blocks via Merkle root or block header.

[0112] The threshold signature mechanism adopts a t-of-n threshold strategy, specifically supporting threshold ECDSA or threshold RSA signature algorithms. Key splitting and reconstruction are performed through Shamir SecretSharing, and any t nodes can jointly generate a valid joint signature.

[0113] The threshold signature mechanism uses a t-of-n threshold strategy:

[0114] A valid signature can be generated by any t nodes participating in the signing process, where t is the threshold value and n is the total number of signing nodes.

[0115] For example, if the threshold is set to t=3 and n=5, then any 3 signatures from 5 nodes can be combined to form a valid threshold signature.

[0116] A common implementation of the Shamir threshold signature scheme combined with mainstream public-key signature algorithms is as follows:

[0117] The Shamir Secret Sharing (SSS) scheme is used for private key splitting and reconstruction.

[0118] Threshold ECDSA signature: Divide the ECDSA private key into n parts and t parts to reconstruct the private key for ECDSA signature. This is commonly used in blockchain and multi-party security scenarios.

[0119] Threshold RSA signature: The RSA private key is split into t-of-n parts, and any t nodes can cooperate to generate an RSA signature;

[0120] Optional algorithms also include threshold EdDSA (such as Ed25519 threshold signature), etc.

[0121] Threshold ECDSA or threshold RSA can be used as the core signature algorithm, and the threshold parameters t and n can be flexibly set according to security requirements.

[0122] All signature processes are completed collaboratively according to the t-of-n protocol; a single node cannot generate a valid signature independently.

[0123] S5: Based on the link tracing dataset, perform statistical tests on the temporal order between nodes, the connection of signature chains, and the correspondence of policy signals. Extract the temporal distribution characteristics of each node's signature records, compare the statistical differences between continuous segments, locate the deviating nodes and perform data correction. Then, perform consistency verification on the corrected records to obtain the structural consistency determination parameters.

[0124] In locating off-target nodes and performing data correction, the deviation threshold is when the node time interval, sequential index, or statistical feature exceeds the preset allowable range relative to the global or historical reference baseline. The average value plus or minus multiple standard deviations, preset ratios, or maximum allowable offset distances are often used as the judgment criteria.

[0125] The strategy layer signal set includes node identifier sequences, frequency feature codes, and signal association tags. The mapping structure reconstruction form includes algorithm path mapping table, parameter adaptation list, and node authentication tags. The key distribution balance parameters include random verification markers, key distribution index, and group consistency number. The link tracing dataset includes log number list, signature chain number, and node tracing tag. The structural consistency determination parameters include correction identifier number, continuity status code, and verification record number.

[0126] In S1, task scheduling refers to the arrangement and management of the execution order of each stage of data processing in the cloud system; the start and end time of each operation refers to the actual start and end time of each scheduled operation; the state transition process refers to the entire process of an operation node or data stream changing from one state to another during the scheduling process; the state change trajectory refers to the complete change path formed by the evolution of node states over time; and the order stability refers to the stability or fluctuation range of the node operation order, reflecting the reliability of the order in the scheduling process. The quantitative indicators of order stability are: counting the number of times the node operation order changes within a period of time; the higher the frequency of changes, the lower the order stability; measuring the span of the node order change in each scheduling; the larger the span, the lower the stability; calculating the standard deviation of the time interval between adjacent node operations; the larger the standard deviation, the greater the order fluctuation and the lower the stability; using the similarity measure of two consecutive scheduling operation sequences, such as based on Jaccard similarity or edit distance; the higher the coefficient, the more stable the order; and recording the maximum value of the node order deviating from its baseline or the previous order in a single scheduling; the larger the offset, the lower the stability. High-sensitivity nodes refer to key nodes that respond most significantly and frequently to scheduling changes or data flow changes; policy-layer signal sources refer to signal generation points identified through the analysis of high-sensitivity nodes and used to regulate subsequent security strategies.

[0127] In S2, the standard cryptographic stack refers to the pre-defined cryptographic algorithm system, including a set of mainstream encryption, decryption, and authentication algorithms; mapping and comparison refers to the process of performing rule-based correspondence and comparative analysis on different algorithm structures, parameters, and authentication processes; trigger mode refers to the specific activation method of algorithm selection or parameter adjustment caused by changes in policy signals; correspondence refers to the one-to-one matching rules established between each policy signal and cryptographic algorithm, parameter, and authentication process; encryption operation process refers to the set of logical steps driven by signals and executed sequentially for encryption-related operations; node operation mapping relationship refers to the role allocation and operation correspondence table of each data node in the encryption process.

[0128] In S3, a verifiable random function refers to a random number generation mechanism (such as VRF or VDF) that can be publicly verified and guarantees unpredictable output; delayed verification refers to verifying the true randomness and unpredictability of random numbers after generation through a certain mechanism (such as computational challenges); random output refers to the random sequence or random number obtained after computation by a verifiable random function; distribution refers to the statistical distribution of random numbers across nodes and data intervals; sequence consistency refers to the consistency of random sequences generated by multiple paths under a specific standard; and key generation base refers to the subset of random numbers used to construct security materials such as keys and session keys.

[0129] In S4, a transparent log block refers to an immutable log recording unit that stores encrypted and operation process-related data and supports public verification and traceability; a threshold signature mechanism refers to a mechanism in which multiple participants jointly generate a valid signature, and the signature is only valid when a certain threshold is reached; a signature task refers to a digital signature operation assigned to different nodes and completed independently or collaboratively; and a joint signature chain refers to a multi-party signature data set that is composed of the signature results of each node and forms a chain structure.

[0130] In S5, statistical testing refers to the method of statistical analysis and consistency judgment of node data, signature chains, and policy signals; temporal distribution characteristics refer to the distribution attributes of node signatures or data operation records on the time axis; statistical differences refer to the numerical differences shown by different nodes or segments in the statistical analysis of operation records, signature chains, and other data; consistency verification refers to the process of re-checking the data after statistical analysis to confirm the consistency and integrity of its structure and content.

[0131] Please see Figure 2 The specific steps for obtaining the policy layer signal set are as follows:

[0132] S111: Based on cloud data encapsulation tasks, extract the start and end time information of each data processing operation, organize the node order of each operation in the task scheduling process, analyze the order of operations and node distribution, and combine the time sequence and node arrangement to obtain the operation scheduling sequence.

[0133] The task management platform retrieves task scheduling logs, reading the start and end times of each operation and calculating the time interval for each operation. All operation records are then sorted from earliest to latest based on their start times. The node numbers corresponding to each operation are extracted from the sorted list, and a time-node mapping table is established. Operations with the same node number are grouped together, and operations within each group are re-sorted by time. The activity time intervals of each node are extracted, and a preliminary node sequence chain is established based on the consecutive occurrences of node numbers. Based on this initial chain, the time interval between adjacent operations is analyzed. If the time difference between two operations is within the set average task switching latency, and the preceding operation is a computational task while the following operation is an upload task, then the operation is considered successful. For each task, the former can be considered as the direct predecessor node of the latter, and the dependency relationship between them can be recorded. This process continues until a complete operation chain is formed. Then, the number of predecessors and successors of nodes in all operation chains is counted, and the dependency relationship between each node and other nodes is recorded. The dependency relationships are integrated to generate a scheduling graph. In the scheduling graph, a set of acyclic paths is gradually identified to ensure that there is no circular dependency path structure. For example, if the task log shows records with node numbers 1, 2, and 3 in sequence, with times ranging from 0 milliseconds to 5 milliseconds, 6 milliseconds to 15 milliseconds, and 16 milliseconds to 25 milliseconds respectively, and the task type is read, encryption, and encapsulation, then an operation scheduling sequence of node 1-2-3 can be established based on the time continuity and task order. This sequence can then serve as the process basis for subsequent analysis.

[0134] S112: Based on the operation scheduling sequence, compare the time sequence and state type of each node, analyze the state change trajectory of the node in the scheduling process, screen the nodes that have undergone state switching, and extract the node group with dynamic change characteristics by combining the node identifier and the switching time to obtain the dynamic node identifier set.

[0135] The system reads the state information of each node during execution, extracts state labels sequentially along the time dimension to form a node state time series, counts the number of state changes for each node within the task execution cycle, summarizes the number of state changes for each node, calculates the average and fluctuation range of the number of state changes for all nodes, and defines a numerical standard for judging whether the state fluctuation is significant. Nodes with a number of state changes higher than this standard are selected. For example, if most of the ten nodes have around three state changes, while some nodes have five or more state transitions, then these nodes can be identified as nodes with frequent state changes. The system further extracts the specific time points of the state transitions and the corresponding node identification information for each node, generating a record list consisting of node numbers and transition times. After classifying the list, a dynamic node group is obtained. Each node in this group exhibits multiple state transition behaviors during task execution. Finally, the distribution of the nodes is further analyzed to determine whether they are concentrated in the critical path or high-density area of ​​the scheduling graph, and they are classified and grouped according to their hierarchical position and the frequency of state changes to form a dynamic node identifier set containing all frequently changing nodes.

[0136] S113: Based on the dynamic node identifier set, analyze the execution order and process sorting between nodes, summarize the order differences between nodes, extract the arrangement offset of each node in the process, adjust the order according to the node distribution, and obtain the strategy layer signal set.

[0137] Extract the positional order of each node in the scheduling process and record the difference between the actual position of each node and its theoretical order. Calculate the sorting offset value for each node, then statistically analyze the overall average and distribution range of all node offset values. Based on the average and distribution range, set an offset judgment threshold. Nodes with offset values ​​exceeding this threshold are identified as sorting anomalies. Further, reorder the nodes according to their order. During the reordering process, ensure that the adjusted order does not disrupt the original task execution time logic. For example, in three groups of nodes, nodes A, B, and C should have A first and C last according to their execution time, but in the initial order... In the sequence, B is placed first. After adjustment, B is moved after C to make the overall order conform to the time logic. After the order adjustment of all abnormal nodes is completed, the order is used as the triggering order of the strategy signal. Then, the number of state changes of the nodes is extracted, and the state switching frequency of each node is calculated within the task cycle. The average value and fluctuation amplitude of the switching frequency of all nodes are statistically calculated. Based on this standard, high-frequency nodes are determined. For example, nodes with frequencies higher than the average plus fluctuation standard are selected as strategy signal sources. Their node number, state change category and change frequency are recorded to form a strategy layer signal set. This signal set will serve as the basis for subsequent algorithm triggering and encryption process control.

[0138] Please see Figure 3 The specific steps for obtaining the reconstructed form of the mapping structure are as follows:

[0139] S211: Based on the policy layer signal set, analyze the arrangement order of each group of signals in the node sequence, determine the signal identifier and node position item by item, compare the correspondence between the signal and the node index, identify the mapping state where the arrangement order changes, and obtain the signal mapping order data.

[0140] Extract the signal identifier and its corresponding node index position from each group of policy signals. Sequentially search the actual occurrence order of each signal source node in the task scheduling chain and construct a signal sequence list. Compare this list with its theoretical arrangement order in the original signal set. For each group of signals, compare the offset between the position number of its signal identifier in the actual node arrangement and the theoretical position number. During the comparison, mark the node number corresponding to each signal and record its position index. For example, if signals S_A, S_B, and S_C are theoretically nodes 3, 5, and 7, but appear at nodes 3, 7, and 5 in the actual arrangement, then signals B and C are marked as having swapped positions. Next, check whether the relative order of all signal pairs matches the original sequence. If the index value of a signal is less than the original value of another signal but its actual position is later, it is determined to be a sequence-change signal. Then, the nodes of such signal changes are numbered and labeled, and a set of all node indices that have deviated from the order is compiled. Combined with the task scheduling trajectory map, the preceding and following connection paths of the signal nodes are extracted. The node segments with offset signals in the path are rearranged to construct a mapping status table. Then, according to the order comparison relationship between the signal identifier and its corresponding node, a set of mapping key-value pairs is constructed, where the key is the signal ID and the value is the node index position. The difference between the actual mapping relationship of the signal on the task chain and the theoretical mapping relationship is checked item by item. All signals that have changed their order and their node mapping positions are recorded, and the signal mapping order data is obtained.

[0141] S212: Based on the signal mapping sequence data, compare the index order of nodes with that of the standard encryption parameter structure, analyze the offset that occurs when nodes are arranged, screen out node segments with continuous indexes but abrupt changes in order, compare the segment structure identifier with the order mapping relationship, and obtain the mapping offset segment.

[0142] The position identifier of each node in the mapping sequence is read one by one and compared with the index position in the preset calling order table in the standard encrypted parameter structure. A node-parameter comparison list is constructed, and the actual node order is checked to see if it is consistent with the parameter order in the standard structure. For nodes with positional offsets, the positive and negative directions of the offset value and the offset step size are recorded. During the comparison process, positions with abrupt changes in consecutive node numbers are screened to determine whether two adjacent nodes have positional reversals or discontinuities. For example, if nodes A, B, and C should be 1, 2, and 3 in the theoretical structure, but are actually arranged as 1, 3, and 2, then nodes C and B have experienced abrupt changes in order, constituting an abnormal mapping segment. As an offset segment marker, it statistically analyzes all node groups that experience such sequential jumps, records the difference between the index values ​​of their first and last nodes and the original structural positions, sorts the absolute values ​​of each node offset, and delineates the intervals with offset amplitudes greater than the baseline offset value as mapped offset segments. The baseline offset value can be determined by the average of all offset values ​​plus the standard fluctuation amount. If node offset values ​​of 1, 2, 0, 3, 5, and 1 appear in a certain task, the baseline offset value can be set to 3. Node segments with offset values ​​of 3 and 5 are filtered out and judged as severely offset segments. Index numbers are established for the start and end nodes of the segment structure, and their sequential information in the mapping relationship table is matched one by one to generate the mapped offset segment index record, thus obtaining the mapped offset segment.

[0143] S213: Based on the mapping offset segment, determine the consistency of the order of each segment. For node segments with reversed order or abnormal intervals, adjust the node structure arrangement. By exchanging the positions of related nodes, optimize the order matching and obtain the reconstructed form of the mapping structure.

[0144] Based on the sequential arrangement of nodes within each interval, each interval is checked to ensure that the actual execution order of nodes remains monotonically increasing. If node numbers in a segment are reversed or there are node groups with significantly different interval values, the segment is considered an inconsistent segment. Inconsistent segments are processed one by one, comparing each node number within the segment with its original order. All pairs of nodes with discontinuous or reversed order numbers are identified, and a set of nodes to be rearranged is constructed. The nodes in this set are then rearranged according to the parameter order in their standard structure, using a node swapping method. The column optimization process records the node position numbers before and after each swap and verifies whether the adjusted order meets the ascending order requirement of the theoretical structure. For example, if the nodes in a segment are arranged as 4, 6, 5, 7, the theoretical order should be 4, 5, 6, 7. In this case, the two middle nodes are swapped and updated to 4, 5, 6, 7. Once the sorting is restored to normal, the segment is marked as optimized. The same process is applied to all such inconsistent segments until the node structure of each segment conforms to the standard encryption parameter calling order. The adjusted node structure order is then recorded as the reconstructed form of the mapping structure.

[0145] Please see Figure 4 The specific steps for obtaining the key distribution balance parameters are as follows:

[0146] S311: Based on the reconstruction of the mapping structure, compare the key distribution characteristics of the random sequence in each node segment, analyze the difference between the data distribution of each segment and the corresponding segment in the distributed identity authentication credential structure, and obtain the segment key difference sequence.

[0147] The random number generation sequence in the complete task is segmented according to the actual division structure between nodes. The random sequence segment and its corresponding time range responsible for each node are extracted. Within this range, the number and distribution density of key generation events are statistically analyzed. A key distribution vector is formed for each segment, recording the numerical distribution pattern of random numbers at each node's processing stage. For example, node A generates 12 sets of keys in its processed segment, with a distribution density of 1.2 sets per millisecond. Node B generates only 4 sets of keys in the same time period, with a density of 0.4 sets per millisecond. At this point, there is a difference in key generation frequency between the two nodes. Subsequently, the standard key generation segment in the distributed identity authentication credential structure is retrieved. In this standard structure, each segment typically has a preset target key distribution ratio or density value. For example, a certain segment must achieve a key generation frequency of at least one set per millisecond. This segment is then used to generate the key generation frequency of each node in the structure. The target key data is compared segment by segment with the actual node segment key data in the current task. The comparison method is to calculate the mean and standard deviation of the key value set in each segment and match them with the standard segment, and record the distribution difference between each segment. Further, a key distribution difference threshold is set for judgment. The threshold can be set with reference to the minimum distribution stability lower limit and maximum fluctuation tolerance in the identity authentication structure. If the deviation between the actual distribution density and the target value exceeds the threshold, it is marked as a key distribution abnormal segment. For example, if the target key density of a segment is 1 group per millisecond, and the actual density is only 0.5 and the threshold is set to 0.3, then the segment is an abnormal distribution segment. After the above judgment is performed on all segments, a set of segment key difference sequences is formed. This sequence records the numerical fluctuation range, direction (high or low) and relative index position of each node segment in the random number distribution, thus forming the data basis for subsequent judgment of consistency and trend matching.

[0148] S312: Based on the segmented key difference sequence, identify structural segments with consistent distribution trends within the segments, filter segments whose key distribution change trends are consistent with node distribution parameters, and obtain a set of consistent distribution segments;

[0149] The algorithm analyzes the changing trend and direction of the key generation density for each segment, calculates the increasing or decreasing relationship of key distribution density changes between multiple consecutive node segments, and forms a trend vector. In the trend vector, it records the change indicators between each segment and its preceding and following segments, such as increase, decrease, or no change. Then, it checks the trend vector against the expected trend set in the node distribution parameters. For example, if the key distribution of nodes 1 to 3 is supposed to be increasing in the node structure setting, then if segment 1 is 0.5, segment 2 is 0.7, and segment 3 is 0.9 in the trend vector, it is considered to have a consistent trend. If segment 2 decreases to 0.4, the trend is inconsistent. Finally, it filters all segments with continuous trends that are consistent with the node's set trend and determines them as distribution... For structural segments with consistent trends, the actual key density value of each segment is compared with the distribution parameters such as the processing capacity and data flow rate of the node it is attached to. If the key distribution density is consistent with the trend of the node's data capacity and processing frequency, the segment is included in the trend-consistent candidate set. Further statistical verification is performed on the candidate set based on the stability of the key distribution value. If the standard deviation is lower than the preset floating tolerance value, for example, the preset floating tolerance is 0.15. If a segment has a key density of [1.0, 1.1, 1.2] and a standard deviation of 0.1, the key generation is considered to have distribution consistency, and it is marked as the final consistent segment. All segments that meet the distribution trend and node parameters and have stable fluctuations are identified and integrated to output the distribution-consistent segment set.

[0150] S313: Based on a set of uniformly distributed segments, statistically analyze the key distribution quantity of each segment and the dispersion between the distributions of each segment, compare the differences in distribution between segments, and use the following formula:

[0151] ;

[0152] Obtain the key distribution balance parameters ,in, This represents the number of segments within the set of consistent segments with disturbance. Representing the Key distribution quantity in each segment, This represents the average key distribution across all segments within the set of perturbed, consistent segments. Representing the The degree of dispersion of key distribution within each segment;

[0153] The key distribution balance parameter is an indicator that measures the balance and volatility of key distribution among segments within a set of perturbed consistent segments using statistical analysis. This parameter reflects the dispersion of key distribution in a random sequence within a specific structural segment, i.e., the degree of deviation and stability of key distribution among segments. It directly reflects the coordination of key distribution within perturbed consistent segments, providing crucial quantitative data for subsequent key management, allocation, and anomaly detection processes, and supporting dynamic optimization and adjustment of distributed identity authentication and privacy protection systems.

[0154] This formula, through a standardized deviation from the mean, reflects the balance between different segments of the key distribution and can sensitively capture synchronization deviations. The smaller the value, the better the balance and synchronization; the larger the value, the more likely there is an imbalance or asynchronous phenomenon between segments.

[0155] The criterion for dividing the number of segments, n, is to distribute the data evenly. This makes the data distribution within each segment more representative and the statistical indicators more robust, making it suitable for scenarios with uneven key distribution. If the number of nodes and the amount of data are highly consistent, then even distribution among nodes can also be used.

[0156] Divide the data equally by volume:

[0157] Based on the actual amount of key data within each node or segment, the total amount of key distribution data is divided into n segments, making the amount of data in each segment approximately the same. For example, if the total number of keys is 10,000, it is divided into 10 segments, with approximately 1,000 keys in each segment.

[0158] A perturbation-consistent segment refers to a set of segments in which the trend of key distribution within a segment is highly similar to the trend of perturbation parameters of the corresponding node within a certain tolerance range.

[0159] Division rules:

[0160] For each node or data segment, statistical analysis is performed on its strategy signal characteristics or node state change rate (such as state switching frequency, frequency characteristic score, order change amplitude, etc.) to form a disturbance parameter sequence.

[0161] The trend of key distribution in each segment as the node arrangement changes can be measured using indicators such as first-order difference, regression slope, and mean change rate.

[0162] The similarity between the key distribution change trend and the corresponding perturbation parameter change trend in each segment is calculated using methods such as Pearson correlation coefficient and cosine similarity.

[0163] Set a threshold for trend similarity (e.g., similarity greater than 0.8). If the similarity between the trend of key distribution change in a segment and the trend of perturbation parameter change exceeds this threshold, the segment is classified as a perturbation-consistent segment.

[0164] If multiple consecutive segments simultaneously meet the consistency threshold, they can be merged into a larger perturbation-consistent segment to enhance statistical stability.

[0165] Perturbation-consistent segments refer to segments where the similarity between the key distribution change trend and the node perturbation parameter change trend exceeds the system's set threshold. When dividing the segments, the key distribution and perturbation trend of each segment must be calculated first, and then the segments are classified by similarity index. Segments that continuously meet the consistency condition can be merged.

[0166] To analyze the key distribution volume and key fluctuation dispersion under corresponding perturbation periods in each segment of the statistical set, four perturbation-consistent segments are first obtained, numbered 1 to 4, and their original key distribution volume data are extracted. =82、 =120、 =95、 =108, and key change sample sequences are collected for each segment under multiple disturbance nodes, and the dispersion of key fluctuation is calculated. Let the original dispersion data be... =144、 =289、 =121、 =196. Given the inconsistency in the dimensions corresponding to the key distribution quantity and its dispersion, a maximum-minimum normalization method is used to normalize it to meet the requirements of unified calculation. The maximum and minimum values ​​of the key distribution quantity are 120 and 82, respectively, corresponding to the normalized values. The values ​​are 0, 1, 0.342, and 0.684 respectively, with the maximum and minimum dispersion values ​​being 289 and 121, corresponding to the normalized values. The values ​​were 0.137, 1, 0, and 0.446 respectively. Then, the normalized mean of the key distribution was calculated. Based on this, substitute the terms into the formula and calculate them sequentially as follows:

[0167] right =0, =0.137, calculated as follows:

[0168] ;

[0169] right =1, =1, calculated as follows:

[0170] ;

[0171] right =0.342, =0, to prevent division by zero errors, S3 is set to 0.01 for smoothing, then:

[0172] ;

[0173] right =0.684, =0.446, calculated as follows:

[0174] ;

[0175] Substitute each term into the formula to solve:

[0176] ;

[0177] The key distribution balance parameter is divided into three intervals:

[0178] When the parameter is in the range [0, 0.6], it indicates that the key distribution is highly balanced and there is almost no significant deviation between each segment, so it can be directly written into the signature synchronization structure;

[0179] When the parameter is in the range [0.6, 0.8], it indicates that the key distribution is within an acceptable fluctuation range, and a compensation mechanism needs to be implemented before entering the data chain; when the parameter is greater than or equal to 0.8,

[0180] When the parameter is in the range of [0.8, 1.5], it indicates that the key distribution has strong local volatility and does not meet the criteria for directly entering the synchronization structure. It is necessary to trigger the key reconstruction or disturbance trend reorganization process to regenerate the mapping structure or optimize the data flow path.

[0181] The current value of 0.9431 is within the third interval, indicating that the key distribution within the perturbation consistency segment set has strong inconsistency characteristics under the perturbation effect. This result serves as the basis for condition judgment in the subsequent link signature consistency writing process, which means that the current structure needs to enter the structure optimization process to meet the sequence consistency requirements of distributed signature synchronization.

[0182] Please see Figure 5 The specific steps for obtaining the link tracing dataset are as follows:

[0183] S411: Based on the key distribution balance parameter, analyze the node time series and policy layer signal sequence information, determine the time correspondence between each node and the policy signal, optimize the arrangement order of the node operation phase, identify the matching items between the node and the signal sequence, and obtain the node time series signal mapping sequence.

[0184] The process reads the timestamp sequence of each node within the task scheduling cycle, extracts the time identifiers of node startup, operation, and termination, and maps this time information to a node execution timing vector. Then, it calls the signal triggering order from the policy layer signal set, records the triggering time of each signal, constructs a policy signal timing table, and compares the node time sequence with the policy signal triggering sequence. By comparing the time difference between the node's start time and the signal triggering time, it determines whether the node started before or after the policy signal triggering. For example, if node A's startup time is 100ms, and its corresponding policy signal S1 triggering time is 95ms, it is considered that the signal was triggered first, conforming to the order mapping relationship. Conversely, if the signal triggering time is later than the node's startup time, the correspondence is marked as an order conflict. Finally, it summarizes the timing differences between all nodes and signals, and counts the mapping pairs whose differences are within a reasonable range, setting a time deviation allowable value. The allowed range is ±10ms. If the time difference between a node and a signal trigger is within this range, it can be considered a valid match. The correspondence between all nodes and signals in the valid matches is then organized into a key-value structure, where the key is the signal number and the value is the corresponding node number. At the same time, the timing position index of the node when the mapping is successful is recorded. The nodes are then sorted and optimized in order. If there are adjacent nodes in the current mapping order whose order is reversed due to the order of their strategy signals, their positions are swapped and rearranged. For example, if nodes X and Y are initially ordered as Y before X, but their corresponding signal order is X signal before Y signal, their positions are swapped in the sequence. The rearranged sequence is then compared one by one with the node execution order according to the signal order to obtain the node execution order that conforms to the signal control logic. This order is used as the timing mapping path between the node and the signal, and the mapping index and offset information are recorded. The node timing signal mapping sequence is then output.

[0185] S412: Based on the node time-series signal mapping sequence, compare the operating cycle and signal interval of each node to analyze the time interval and synchronization characteristics of the trajectory segment, using the formula:

[0186] ;

[0187] Obtain trajectory disturbance synchronization indicators, identify sections of abnormal trajectory synchronization, and obtain the synchronized trajectory deviation sections, among which... Indicates the first The trajectory disturbance synchronization index of each node. Indicates the first The number of trajectory segments involved in each node. Indicates the first The node The time interval before and after the segment trajectory disturbance. Indicates the first The node The equivalent time-varying offset corresponding to the spatial changes in the segment trajectory. Indicates the first The node Changes in data synchronization delay related to segment disturbances;

[0188] The trajectory disturbance synchronization index measures the difference between the running time interval of each node in different trajectory segments and the temporal changes formed by spatial offset and synchronization delay. Specifically, this index reflects the degree of deviation between the actual trajectory running rhythm of a node and the theoretical synchronization state under the influence of a disturbance event. It can quantitatively reflect the coupling relationship between node behavior and disturbance and synchronization changes. The larger the index value, the more obvious the temporal deviation of the node trajectory under the action of disturbance and synchronization. It is used to screen out sections of the trajectory with abnormal synchronization or significant deviation.

[0189] Analyze the task execution time distribution of each node within the scheduling cycle, extract the start and end times of tasks in the trajectory segment, and calculate the time interval difference between the node trajectory segment and the occurrence of the disturbance event based on the event number and response time marker in the disturbance event record table. Set this as a parameter. For example, if node N5 records a task start time of 10:00:20 and an end time of 10:01:50 in the first task segment, with a task duration of 90 seconds and a disturbance event trigger time of 10:01:00, and the disturbance occurs in the middle of the task, then the interval between the disturbance event and the task start point in this task segment can be calculated to be 40 seconds. Then, the offset path formed by the spatial position change of each trajectory segment is calculated. Assuming the node moves from position A (120.00, 31.00) to position B (120.60, 31.30) in the first trajectory segment, the corresponding spatial distance is 72 meters, and the node's running speed is 6 m / s, the equivalent time of trajectory displacement is calculated based on the distance and speed. Seconds; then obtain the actual synchronization delay of this data segment processing. Assuming the normal system delay is 5 seconds, and the delay of this data segment is recorded as 11 seconds under the influence of the disturbance, then the additional delay caused by the disturbance is... Seconds; the three parameters are processed using a unified normalization method, and the time interval difference is... Maximum task interval normalization is used, and the spatial offset is equivalent to time. Normalization of the maximum displacement time-varying quantity, and the delay change quantity Using average synchronization delay normalization, assuming the maximum task interval in the node group is 120 seconds, the maximum spatial offset equivalent time is 15 seconds, and the average disturbance delay is 8 seconds, the normalization result for the first task segment is: , , ;

[0190] The deviation of the trajectory from its perturbation response is quantified by calculating the difference between the actual task execution time and the combined spatial and temporal delay terms of the trajectory under the influence of perturbation. If node N5 contains 3 trajectory tasks, the original parameters of its second segment are:

[0191] With a task interval of 84 seconds, an equivalent offset time of 9 seconds, and a synchronization delay of 7 seconds, the corresponding normalized value is: , , ;

[0192] The third task interval is 72 seconds, the offset time is 6 seconds, and the delay is 4 seconds, corresponding to the normalized value as follows: , , Substitute the three normalized parameters into the formula for calculation:

[0193] In the first paragraph The difference is ;

[0194] In the second paragraph The difference is ;

[0195] In the third paragraph The difference is The synchronization index is calculated as follows:

[0196] ;

[0197] Based on experience in trajectory synchronization stability analysis and comparison with historical node behavior samples, the index range is set as follows:

[0198] When 0≤ When the value is less than 0.1, it indicates that the relationship between the trajectory and the response to the disturbance behavior is highly stable, and the synchronization consistency between task segments is good, which is judged as a synchronized segment;

[0199] When 0.1≤ When the value is less than 0.2, it indicates that there is a slight deviation between the trajectory and the disturbance, and the synchronization relationship between task segments is affected by the disturbance, resulting in local fluctuations, which is judged as a synchronization transition segment;

[0200] When 0.2≤ When the value is less than 0.35, it indicates a significant imbalance between the trajectory and the disturbance response, with multiple unstable time points, which are identified as synchronization deviation segments.

[0201] when When the value is ≥0.35, it indicates that the trajectory behavior deviates significantly from the disturbance pattern, the consistency of the data structure is disrupted, and it is judged as a synchronization anomaly segment.

[0202] Since the synchronization index currently calculated for node N5 is 0.249, it is currently at... Within the interval, it is determined that there is a clearly identifiable trajectory disturbance synchronization difference. Based on this result, the trajectory segment number and disturbance number identifier of the node can be further called to derive the data segment sequence with structural adjustment priority, and marked for data signature rewriting and link tracing structure writing operations in subsequent steps.

[0203] S413: Based on the synchronization trajectory deviation section, optimize the correspondence between policy signals and node operations within the section, identify the data synchronization content, adjust the node order and write it into the distributed joint signature structure to obtain the link tracing dataset;

[0204] Extract the starting node, ending node, related signal numbers, and corresponding original trigger times within the segment. Perform time comparison analysis on the node operation records and signal trigger records within each deviation segment. Use the interval between the signal trigger time and the node operation execution time as the judgment benchmark. Calculate the actual time offset of each node-signal pair and compare it with a set time matching threshold, set to 20ms. If the offset exceeds this threshold, it is judged as a time mismatch. Subsequently, organize all time-mismatched node-signal pairs, record their numbers, original order, and the policy stage they belong to. Then, read the context records of the nodes in the operation log to extract their corresponding operation content type, such as whether it is an encryption, decryption, signing, or transmission operation. At the same time, analyze the policy control actions corresponding to the policy signals. The system identifies actions, such as a signal that corresponds to the start of the authentication process. If the current node's operation is data caching, it is determined that it does not match the signal's control action. For such operations, the node order is adjusted, moving the node backward or forward to a position closer to the signal trigger time, so that the operating node can execute within the validity period of the policy control action. After the order is adjusted, the mapping relationship between all nodes and signals in the segment is re-established, and the rearranged order is written into the signature structure data record unit. In the distributed structure, an operation digest is generated for each node, and the signature key pair corresponding to each node is called to perform local signature operations. All signature results are merged in the original task path structure order to generate a chain signature segment. Then, the chain segment is spliced ​​together by attaching the timestamp index between each node to generate a link tracing dataset.

[0205] Please see Figure 6 The specific steps for obtaining the structural consistency determination parameters are as follows:

[0206] S511: Based on the link tracing dataset, compare the identity identifier and signature chain number of each node one by one, determine the correspondence between the node input and output identifiers and the link node sequence number, mark the corresponding abnormal nodes through node information matching and verification, and obtain the corresponding sequence of node structure.

[0207] Extract the identity identifier of each node and its corresponding link number in the signature chain. Compare the link number with the node identity code to determine the relationship. Read the node's input and output identifiers and compare them item by item with the link node sequence numbers marked in the signature chain record. Determine if the node's input and output identifiers correctly reflect its position in the data flow within the link. If a node has sequence number 5 in the link, but its output points to the next node at sequence number 3, then the node's output is inconsistent with the link order. Further, read the upstream and downstream node identities of this node in the data tracking log to construct the transmission path between nodes, and then verify the sequence with the actual node sequence recorded in the signature chain path. Yes, the verification is performed by judging whether the node number is monotonically increasing from left to right according to the logic in the signature chain. If the node has skipped order, backtracking, duplicate numbering, or sequential intersection, the node is marked as an abnormal node, and its position number and the signature chain index involved are recorded. The actual running trajectory of the node is then compared to see if there are any node identifiers that do not appear in the signature chain. If a node is found to have valid input and output records but is missing the corresponding number in the signature chain structure, it is also judged as a structural anomaly, and the reason for the anomaly is recorded as "node not on the chain". All such abnormal nodes are integrated into a set of abnormal identifiers, and a unified number is recorded in the node structure comparison result table. The node structure corresponding sequence is obtained by sorting the nodes according to their identity number order.

[0208] S512: Based on the corresponding sequence of node structure, compare the node trajectory record with the node order of the signature chain, analyze the consistency between the index and time order of the continuous segment of the trajectory, determine the continuity of the node connection process, screen for positions with connection breaks or sequence abnormalities, and obtain the trajectory continuity anomaly set.

[0209] Based on the trajectory time record of each node during task execution and its corresponding sequential position in the signature chain node sequence, a trajectory index table and a signature index table are established. The time sequence of the trajectory record is compared with the order of the nodes appearing in the signature chain for each node to determine if they are consistent. For nodes that execute earlier in time, it is verified whether they are in a preceding position in the signature chain. If node A executes earlier than node B in the time record, but A is after B in the signature chain, this is considered a sequence deviation record, and its starting node, ending node, and the actual time difference between the two nodes are recorded. Further analysis is conducted to determine whether there is a direct time and number mapping relationship between each node in a continuous trajectory segment and its adjacent nodes. If three consecutive nodes are found in a certain trajectory segment... If nodes 10, 11, and 13 have times of 30ms, 35ms, and 50ms respectively, but the corresponding numbers in the signature chain are 10, 13, and 11, then node 11 is placed in the wrong position in the signature chain. This segment is marked as an abnormal sequence segment. If two nodes are found to be continuous in time but interrupted in the signature chain, lacking intermediate node numbers, it is considered a connection break. The start point, end point, and missing position of the break are recorded. If the time of the missing segment is greater than a preset threshold, such as more than 30ms, it is considered a severely broken segment. For such cases, segment-by-segment labeling is performed, and all broken segment numbers are included in the trajectory continuity anomaly set. The indexes of all nodes that have discontinuous connections, abnormal sequences, or broken links are output to form the trajectory continuity anomaly set.

[0210] S513: Based on the trajectory continuity anomaly set, referencing the signature information of adjacent nodes, reorganize the anomaly nodes, adjust the temporal arrangement and node order of the signature chain, correct the consistency of the link signature data, and obtain the structural consistency determination parameters.

[0211] By comparing the signature digest data of adjacent nodes with the start and end node indices of the abnormal segment, the data digest fingerprint information before and after the signature and the signature timestamp value are extracted. The abnormal segment is categorized based on missing signatures, time anomalies, or sequence conflicts. The difference between digest fingerprints is calculated and compared with the normal segment to determine if there are any abnormal nodes with discontinuous digests. If the similarity between the digest fingerprints of two nodes is lower than the baseline similarity threshold (e.g., below 85%), the node is listed as a content-disjointed node, and its position and digest comparison content are recorded. Then, all abnormal nodes are reassembled, and their positions in the signature chain are re-inserted into the chain based on their original timestamps and digest content, ensuring logical continuity of the digests of the nodes before and after the insertion position. The node order is adjusted to ensure that the time in the link structure increases sequentially from front to back. If multiple nodes share the same timestamp after adjustment, they are sorted by node ID from smallest to largest to determine the order. After reordering, the signature chain record is regenerated. The parts of the original signature chain that are broken due to node deletion or replacement are repaired. The updated signature digest data is inserted and the joint signature value is recalculated to ensure that the signature synthesis value of all nodes in the chain is continuous and verifiable. Finally, the reorganized signature chain is compared with the original chain. All records of sequence number changes of newly added nodes, moved nodes and corrected nodes are marked to form a structure repair log. The order index table of the reordered nodes and its signature digest binding record are organized as output parameters for determining structural consistency.

[0212] The reorganization process for abnormal nodes is based on a comprehensive comparison and reordering rule of digest fingerprint information, timestamp, and node ID. The process is manifested as a custom order adjustment and logical continuity correction mechanism, involving the following rule system:

[0213] The system compares the signature digest data of adjacent nodes based on the start and end node indices of the abnormal segment; extracts the digest fingerprint and timestamp, and classifies the node anomaly types (missing, abnormal, conflict); calculates the similarity of the digest fingerprint (if it is lower than the benchmark similarity threshold), and uses this as a criterion for content disconnection; establishes logical continuity rules for timestamps and digests (ensuring that the time increments and the digest content is continuous); when multiple nodes have the same timestamp, they are sorted by node ID in ascending order; after node insertion, the system recalculates the broken chain and synthesizes the signature digest; compares the differences between the old and new chains, and generates a structure repair log bound to the index. This is a rule-driven sequence rearrangement and consistency verification mechanism.

[0214] A verifiable random encryption generation system for privacy data protection, the system comprising:

[0215] The signal acquisition module encapsulates tasks based on cloud data, records the start and end times and state transitions of each operation in the task scheduling, calculates the time interval according to the node sequence, identifies high-sensitivity nodes with prominent frequency characteristics, and obtains the strategy layer signal set.

[0216] The encryption mapping module, based on the policy layer signal set, calls the standard cryptographic stack, matches the algorithm structure and parameter combination, adjusts the algorithm call order and parameter relationship, reorganizes the encryption process, updates the node operation mapping, and obtains the reconstructed form of the mapping structure.

[0217] The random verification module reconstructs the form based on the mapping structure, calls a verifiable random function to generate a random sequence, extracts the hash features of the input parameters for verification, records the random distribution, compares the sequence consistency under each path, and obtains the key distribution balance parameters.

[0218] The log signature module records the digest of key generation and encryption execution data based on the key distribution balance parameter, writes it into the transparent log block, and uses a threshold signature mechanism to merge the signatures of each node to form a joint signature chain, thus obtaining the link tracing dataset.

[0219] The consistency correction module, based on the link tracing dataset, analyzes the temporal order between nodes and the connection of the signature chain, statistically examines the relationship of strategy signals, extracts the signature time features of nodes, locates and corrects deviating nodes, and obtains structural consistency determination parameters.

[0220] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A method for generating verifiable random encryption for privacy data protection, characterized in that, Includes the following steps: S1: Based on cloud data encapsulation tasks, record the start and end times and state transitions of each operation in task scheduling, calculate the time interval according to the node sequence, identify high-sensitivity nodes with prominent frequency characteristics, and obtain the strategy layer signal set. S2: Based on the signal set of the policy layer, call the standard cryptographic stack, match the algorithm structure and parameter combination, adjust the algorithm call order and parameter relationship, reorganize the encryption process, update the node operation mapping, and obtain the reconstructed form of the mapping structure; S3: Based on the reconstructed form of the mapping structure, call the verifiable random function to generate a random sequence, extract the hash features of the input parameters for verification, record the random distribution, compare the sequence consistency under each path, and obtain the key distribution balance parameters; S4: Based on the key distribution balance parameters, the key generation and encryption execution data are digested and written into a transparent log block. A threshold signature mechanism is used to merge the signatures of each node to form a joint signature chain, thus obtaining a link tracing dataset. S5: Based on the link tracing dataset, analyze the temporal order between nodes and the connection of the signature chain, statistically examine the relationship of strategy signals, extract the signature time features of nodes, locate and correct off-target nodes, and obtain structural consistency determination parameters.

2. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The strategy layer signal set includes node identifier sequences, frequency feature codes, and signal association tags. The mapping structure reconstruction form includes an algorithm path mapping table, a parameter adaptation list, and node authentication tags. The key distribution balance parameters include random verification markers, key distribution indexes, and group consistency numbers. The link tracing dataset includes a log number list, signature chain numbers, and node tracing tags. The structure consistency determination parameters include correction identifiers, continuity status codes, and verification record numbers.

3. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The specific steps for obtaining the policy layer signal set are as follows: S111: Based on cloud data encapsulation tasks, extract the start and end time information of each data processing operation, organize the node order of each operation in the task scheduling process, analyze the order of operations and node distribution, and combine the time sequence and node arrangement to obtain the operation scheduling sequence. S112: Based on the operation scheduling sequence, compare the time sequence and state type of each node, analyze the state change trajectory of the node in the scheduling process, screen the nodes that have undergone state switching, and extract the node group with dynamic change characteristics by combining the node identifier and the switching time to obtain the dynamic node identifier set. S113: Based on the dynamic node identifier set, analyze the execution order and process sorting between nodes, summarize the order differences between nodes, extract the arrangement offset of each node in the process, adjust the order according to the node distribution, and obtain the strategy layer signal set.

4. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The specific steps for obtaining the reconstructed form of the mapping structure are as follows: S211: Based on the signal set of the strategy layer, analyze the arrangement order of each group of signals in the node sequence, determine the signal identifier and node position item by item, compare the correspondence between the signal and the node index, identify the mapping state where the arrangement order has changed, and obtain the signal mapping order data. S212: Based on the signal mapping sequence data, compare the index order of the nodes with that of the standard encryption parameter structure, analyze the offset that occurs when the nodes are arranged, screen out the node segments with continuous indexes but abrupt changes in order, compare the segment structure identifier with the order mapping relationship, and obtain the mapping offset segment. S213: Based on the mapping offset segment, determine the consistency of the order of each segment. For node segments with reversed order or abnormal intervals, adjust the node structure arrangement. By exchanging the positions of associated nodes, optimize the order matching and obtain the reconstructed mapping structure.

5. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The specific steps for obtaining the key distribution balance parameter are as follows: S311: Based on the reconstructed form of the mapping structure, compare the key distribution characteristics of the random sequence in each node segment, analyze the difference between the data distribution of each segment and the corresponding segment in the distributed identity authentication credential structure, and obtain the segment key difference sequence. S312: Based on the segmented key difference sequence, identify structural segments with consistent distribution trends within the segments, filter segments whose key distribution change trends are consistent with node distribution parameters, and obtain a set of consistent distribution segments; S313: Based on the aforementioned set of consistent distribution segments, statistically analyze the key distribution quantity of each segment and the dispersion between the distributions of each segment, compare the differences in distribution between segments, and use the following formula: ; Obtain the key distribution balance parameters ,in, This represents the number of segments within the set of consistent segments with disturbance. Representing the Key distribution quantity in each segment, This represents the average key distribution across all segments within the set of perturbed, consistent segments. Representing the The degree of dispersion of key distribution within each segment.

6. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The specific steps for obtaining the link tracing dataset are as follows: S411: Based on the key distribution balance parameters, analyze the node time series and policy layer signal order information, determine the time correspondence between each node and the policy signal, optimize the arrangement order of the node operation phase, identify the matching items between the node and the signal order, and obtain the node time series signal mapping sequence. S412: Based on the node timing signal mapping sequence, compare the operating cycle and signal interval of each node, analyze the time interval and synchronization characteristics of the trajectory segment, obtain the trajectory disturbance synchronization index, identify the trajectory synchronization abnormal segment, and obtain the synchronous trajectory deviation segment. S413: Based on the synchronization trajectory deviation section, optimize the correspondence between policy signals and node operations within the section, identify the data synchronization content, adjust the node order, and write it into the distributed joint signature structure to obtain the link tracing dataset.

7. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The specific steps for obtaining the structural consistency determination parameters are as follows: S511: Based on the link tracing dataset, compare the identity identifier and signature chain number of each node one by one, determine the correspondence between the node input / output identifier and the link node sequence number, mark the corresponding abnormal nodes through node information matching and verification, and obtain the corresponding sequence of node structure. S512: Based on the corresponding sequence of the node structure, compare the node trajectory record with the node order of the signature chain, analyze the consistency between the index and time order of the continuous trajectory segments, determine the continuity of the node connection process, screen for positions with connection breaks or sequence abnormalities, and obtain a set of trajectory continuity anomalies. S513: Based on the trajectory continuity anomaly set, and referring to the signature information of adjacent nodes, the anomaly nodes are reorganized, the temporal arrangement and node order of the signature chain are adjusted, the consistency of the link signature data is corrected, and the structural consistency determination parameters are obtained.

8. The verifiable random encryption generation method for privacy data protection according to claim 1, characterized in that, The start and end times of each operation refer to the actual start and end times of each scheduled operation. The state switching process refers to the process by which an operation node or data stream changes from one state to another during the scheduling process. The standard cryptographic stack refers to a preset set of cryptographic algorithms, including a collection of mainstream encryption, decryption, and authentication algorithms.

9. A verifiable random encryption generation system for privacy data protection, characterized in that, The system is used to implement the verifiable random encryption generation method for privacy data protection as described in any one of claims 1-8, and the system comprises: The signal acquisition module encapsulates tasks based on cloud data, records the start and end times and state transitions of each operation in the task scheduling, calculates the time interval according to the node sequence, identifies high-sensitivity nodes with prominent frequency characteristics, and obtains the strategy layer signal set. The encryption mapping module, based on the policy layer signal set, calls the standard cryptographic stack to match the algorithm structure and parameter combination, adjusts the algorithm call order and parameter relationship, reorganizes the encryption process, updates the node operation mapping, and obtains the reconstructed form of the mapping structure. The random verification module reconstructs the form based on the mapping structure, calls a verifiable random function to generate a random sequence, extracts the hash features of the input parameters for verification, records the random distribution, compares the sequence consistency under each path, and obtains the key distribution balance parameters. Based on the key distribution balance parameters, the log signature module records the digest of key generation and encryption execution data, writes it into a transparent log block, and uses a threshold signature mechanism to merge the signatures of each node to form a joint signature chain, thus obtaining a link tracing dataset. Based on the link tracing dataset, the consistency correction module analyzes the temporal order between nodes and the connection of the signature chain, statistically verifies the relationship of strategy signals, extracts the signature time features of nodes, locates and corrects deviating nodes, and obtains structural consistency determination parameters.

Citation Information

Patent Citations

  • Artificial intelligence data privacy protection system based on block chain and federal learning

    CN120408697A

  • Block chain-based flood storage and detention area ecological compensation execution tracing processing method and system

    CN120725694A