Big data security transmission method and system based on encryption algorithm
By slicing and classifying the data packets related to customs and trade, and combining this with multi-channel concurrent transmission and zero-knowledge proof-based authentication, the security and differentiated controllability issues of data transmission in cross-border trade are resolved, achieving efficient data security management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SUZHOU CUSTOMS & TRADE BIG DATA CO LTD
- Filing Date
- 2025-12-01
- Publication Date
- 2026-07-21
Smart Images

Figure CN121509031B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication security technology, specifically to a secure transmission method and system for big data customs and trade platforms based on encryption algorithms. Background Technology
[0002] Currently, customs and trade data are characterized by large scale, high frequency, and multi-entity interaction in diversified business collaboration. The data frequently flows between multiple access terminals, which poses serious security risks during the transmission process.
[0003] Traditional data encryption transmission often relies on uniform encryption of the entire data packet or link protection based on a single key, which is insufficient to meet the differentiated security requirements of customs and trade data in terms of privacy, core access, and access permissions. Furthermore, in cross-border trade environments, access entities are often hierarchical organizations with significantly different permissions at different nodes. Traditional technologies struggle to achieve dynamic access control between multiple levels of access endpoints and are easily monitored or have their transmission characteristics captured by attackers, making it difficult to achieve fine-grained end-to-end security management in complex customs and trade business scenarios.
[0004] Therefore, existing technologies still lack a systematic method for secure transmission of big data on customs and trade platforms to comprehensively address the issues of security and differentiated controllability of trade data during multi-terminal transmission. Summary of the Invention
[0005] This application provides a secure transmission method and system for big data customs and trade platforms based on encryption algorithms, which is used to address the technical problems of limited security and controllability of differentiated trade data in multi-terminal transmission in the prior art.
[0006] In view of the above problems, this application provides a secure transmission method and system for big data customs and trade platforms based on encryption algorithms.
[0007] Firstly, this application provides a secure transmission method for a big data customs and trade platform based on encryption algorithms. The method includes: the source end calling an encryption plugin to slice and label customs and trade data packets, perform categorized encryption processing, and determine the ciphertext of the customs and trade data. The categorized encryption includes key encryption for access control policies, encryption of the first derived key of the data slice, and encryption of the second derived key implicitly written in the logical slice protocol. The ciphertext of the customs and trade data is transmitted concurrently in multiple channels. The data port of the first authentication end is intercepted, and permission attribute authentication based on zero-knowledge proof is triggered. If the authentication is successful, the first authentication end calls a decryption plugin to perform restoration and logical reorganization based on data permission granularity under categorized decryption to generate restored customs and trade data.
[0008] Secondly, this application provides a secure transmission system for a big data customs and trade platform based on encryption algorithms. The system includes: an encryption unit: the source end calls an encryption plugin to slice and label customs and trade data packets, performs classified encryption processing, and determines the encrypted customs and trade data. The classified encryption includes key encryption for access control policies, encryption of the first derived key for data slices, and encryption of the second derived key implicitly written in the logical slice protocol; a transmission authentication unit: the encrypted customs and trade data is transmitted concurrently in multiple channels, the data port of the first authentication end is intercepted, and permission attribute authentication based on zero-knowledge proof is triggered; a decryption unit: if authentication is successful, the first authentication end calls a decryption plugin to perform restoration and logical reorganization based on data permission granularity under classified decryption, and generates restored customs and trade data.
[0009] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0010] The secure transmission method for a big data customs and trade platform based on encryption algorithms provided in this application includes: the source end calls an encryption plugin to slice and label customs and trade data packets, performs classified encryption processing to determine the encrypted customs and trade data, performs multi-channel concurrent transmission of the encrypted customs and trade data, intercepts the data port of the first authentication end, and triggers permission attribute authentication based on zero-knowledge proof; if the authentication is successful, the first authentication end calls a decryption plugin to perform restoration and logical reorganization based on data permission granularity under classified decryption to generate restored customs and trade data. This method is used to solve the technical problem of limited security and differentiated controllability of commercial data in multi-terminal transmission in the prior art, and can effectively improve the multi-dimensional secure transmission guarantee of customs and trade data, and ensure differentiated and controllable management of the transmission cycle. Attached Figure Description
[0011] Figure 1 This application provides a schematic diagram of a secure transmission method for a big data customs and trade platform based on encryption algorithms;
[0012] Figure 2 This application provides a schematic diagram of the secure transmission system architecture for a big data customs and trade platform based on encryption algorithms.
[0013] Explanation of reference numerals in the attached diagram: Encryption unit 11, Transmission authentication unit 12, Decryption unit 13. Detailed Implementation
[0014] This application provides a secure transmission method and system for big data customs and trade platforms based on encryption algorithms, which addresses the technical problems of limited security and controllability of trade data during multi-terminal transmission in existing technologies.
[0015] Example 1: As Figure 1As shown, this application provides a secure transmission method for a big data customs and trade platform based on encryption algorithms, the method comprising:
[0016] S1: The source end calls the encryption plugin to slice and label the customs and trade data packets, performs classification encryption processing, and determines the ciphertext of the customs and trade data. The classification encryption includes key encryption of access control policy, encryption of the first derived key of data slice, and encryption of the second derived key written in the logical slice protocol.
[0017] In the embodiments of this application, the source end first receives the customs and trade data packet to be transmitted and triggers the data processing flow through the encryption plugin. The encryption plugin in this application is responsible for slicing the data packet according to certain rules, dividing the data packet into several smaller data segments, each segment being called a data slice. Breaking down larger data units into smaller units that are easier to encrypt and transmit ensures transmission efficiency and data integrity.
[0018] Furthermore, during the data slicing process, each slice is assigned an attribute label to enable fine-grained control over the data based on different access permissions. The attribute labels identify core data attributes, such as data category and privacy level, allowing data slices to be differentiated during transmission.
[0019] Next, categorized encryption is performed. This means that, based on the security policies set at the source and the data's attribute characteristics, different encryption methods are used for data slices, logical slices, and access control policies. Multiple encryption branches are employed to provide different levels of security for different types of data.
[0020] First, the source end performs key encryption according to the access control policy. Access control policy refers to the rules governing data access, defining which users or devices can access which data, or at what level of data granularity, and typically involves permission management and authentication. By applying encryption to the access control policy, the source end ensures that only authorized users or devices can access specific data slices, or the content granularity within those data slices, thereby protecting diverse access to data.
[0021] Next, the source end uses key derivation to encrypt the data slices and performs steganography encryption on the logical slices.
[0022] In this application, a logical slice refers to a logical unit within data, specifically a diversified combination of data slices, representing information related to the data content structure. By encrypting the logical slices and simultaneously employing a steganography protocol to disguise the encrypted data, the concealment and security of the data during transmission are enhanced.
[0023] Finally, the customs and trade data packets, after the above encryption process, form customs and trade data ciphertext, containing three types of encrypted content: ciphertext encrypted with access control policies, ciphertext encrypted with data slices, and ciphertext encrypted with logical slice steganography. Each ciphertext portion is protected by a different encryption method, and there is an interrelationship between them to ensure multiple layers of security during data transmission. This meets the stringent requirements for data privacy, data integrity, and access control in customs and trade scenarios.
[0024] Furthermore, before the source end invokes the encryption plugin, the steps in this application include:
[0025] Using a QKD device, an initial quantum key pool for transmission authentication is established in the customs and trade platform, wherein the initial quantum key pool is dynamically updated; the pre-transmission task is read to determine the source end and the multi-level access end; a shared key is generated based on the initial quantum key pool; and a transmission key pair based on the shared key is derived by combining the random numbers from both the source end and the multi-level access end, and the transmission key pair is distributed to the source end and the multi-level access end.
[0026] In the application embodiment, an initial quantum key pool for transmission authentication is first established in the customs and trade platform using a QKD device, i.e., a quantum key distribution device. QKD technology achieves secure key distribution based on the principles of quantum mechanics, preventing keys from being stolen during transmission.
[0027] In this application, the initial quantum key pool is a set of quantum keys generated and stored by a QKD device. These keys are used for subsequent encryption and authentication operations and have dynamic update capabilities, meaning that the keys in the key pool are updated according to time or security requirements to ensure the security and validity of the keys. This dynamic update mechanism ensures that the use of keys is not easily attacked, thus improving the overall security of the system.
[0028] Next, the customs and trade platform reads the uploaded pre-transmission task to determine the source and multi-level access terminals. The pre-transmission task typically contains information about the data transmission tasks and timelines required in cross-border trade. The source is the data sender, while the multi-level access terminals are the receivers or data accessers.
[0029] In customs and trade scenarios, multi-level access terminals can include multiple access nodes at different levels, each node able to access specific data according to its permission level. By clearly defining the two parties involved in data transmission and their corresponding permissions, a basis is further provided for subsequent key distribution and data transmission.
[0030] Furthermore, a shared key is generated based on the initial quantum key pool. The shared key in this application is a key determined through the initial quantum key pool between the source and the multi-level access points for communication of the current task. Preferably, the generation of the shared key relies on the security mechanism of the QKD device to ensure that the key cannot be intercepted by a third party during transmission.
[0031] Subsequently, the source end and the multi-level access end combine their respective random numbers to derive a transmission key pair based on a shared key. In the specific implementation, the random number serves as an element in the encryption process. Both the source end and the multi-level access end generate random numbers and perform calculations using the shared key to derive a transmission key pair for data transmission, including an encryption and decryption key. The source end and the multi-level access end use their respective keys for data encryption and decryption, effectively ensuring the synchronization and independence of the keys between the two parties and enhancing the security of the data transmission process.
[0032] Finally, the generated transmission key pairs will be distributed to the source and multiple access points. The key distribution is preferably carried out through a secure communication channel, and the identity of the recipients will be confirmed through authentication to ensure the legitimacy of the keys and the security of transmission.
[0033] In this application, the dynamic updating of the quantum key pool, the generation of shared keys, and the derivation and targeted distribution of transmission key pairs achieved through QKD technology form an efficient and secure key management scheme, providing reliable encryption protection for data transmission on the customs and trade platform.
[0034] Furthermore, before the source end invokes the encryption plugin, the steps in this application include:
[0035] An encryption plugin and a decryption plugin are established and built into the transmission plugin library of the customs and trade platform. As the pre-transmission task is uploaded, the source end migrates and calls the encryption plugin, and the access end migrates and calls the decryption plugin to perform secure transmission management within the task cycle.
[0036] In the embodiments described in the application, the encryption plugin is a software component responsible for encrypting data, and the decryption plugin is a software component responsible for decrypting encrypted data. Specifically, by providing modular functionality, the plugins enable the customs and trade platform to flexibly encrypt and decrypt data, ensuring that the security needs of all parties are met during data transmission.
[0037] The transmission plugin library is a library that integrates all plugins related to data transmission, including encryption plugins, decryption plugins, and other functional modules that support data transmission management. The purpose is to enable the platform to dynamically call the corresponding plugins when performing data transmission tasks, so as to adapt to different task requirements and security requirements.
[0038] The encryption plugin in this application adopts a logical architecture of a first processing node and a second encryption node. The second encryption node includes parallel first encryption branches, second encryption branches, and third encryption branches, and embeds differentiated encryption logic. Optionally, a data-driven training method is used to supervise the training of the logical architecture until convergence, thus forming the encryption plugin.
[0039] Similarly, the decryption plugin, based on encryption logic as a priori condition, uses ciphertext decryption and logical combination as logical steps, and is constructed with supervised training to form a decryption plugin with automatic decryption function.
[0040] As the pre-transmission task is uploaded, the plugin invocation operations of the source end and multi-level access ends are initiated. During task upload, the source end needs to migrate and invoke the encryption plugin according to the task requirements and encrypt the data to be transmitted within the task cycle. At this time, the source end performs encryption operations on the data packets, converting the data into ciphertext form to ensure that the data cannot be eavesdropped or tampered with during transmission. Simultaneously, the access end migrates and invokes the decryption plugin, preparing to decrypt the received encrypted data. The decryption plugin processes the encrypted data according to the task requirements, restoring the ciphertext to plaintext data with different permissions.
[0041] In summary, the use of encryption and decryption plugins ensures the security and confidentiality of data during transmission. Furthermore, the mechanisms built into the transmission plugin library enable efficient and secure management of operations at each stage. This not only improves data transmission security but also simplifies the platform's operational processes and enhances the flexibility and scalability of the communication mode.
[0042] Furthermore, the customs and trade data packets are sliced and labeled with attribute tags, and classified encryption processing is performed. Step S1 of this application includes:
[0043] The source end imports the customs and trade data packet into the encryption plugin, triggering the first processing node to perform data fragmentation processing based on data coreness and privacy, determining data slices, logical slices, and access control policies; according to the first encryption branch, the access control policy is encrypted using the distributed transmission key to determine a type of ciphertext portion; according to the second encryption branch, a first derived key is derived from the transmission key to encrypt the data slice, determining a type of ciphertext portion; according to the third encryption branch, a second derived key is derived from the transmission key to encrypt the logical slice after protocol steganography, determining a type of ciphertext portion.
[0044] In this embodiment, the source end imports the customs and trade data packet into the encryption plugin, triggering the first processing node in the encryption process. Specifically, the customs and trade data packet refers to cross-border trade data containing information on customs, logistics, and settlement, which typically contains different types of data with different security requirements.
[0045] The first processing node's task is to perform data sharding based on data coreness and privacy. Data coreness refers to the importance of data to the business process, while privacy refers to the level of sensitive information contained in the data, determining the security level of the data and helping to select appropriate encryption strategies for different types of data.
[0046] In this process, the customs and trade data packets are split into multiple data slices and logical slices. A data slice is a unit that physically divides data according to business logic, while a logical slice is a combination of logic based on the data slices.
[0047] Preferably, the smaller the data slice unit, the more discrete the logical slice, and the lower its reproducibility.
[0048] Simultaneously, permissions are assigned to each data slice according to the data access control policy. These tags indicate which access endpoints can access which data slices, and at what granularity of content within the data slices they can access, thereby controlling the security of data access and ensuring that subsequent classification encryption can provide differentiated protection for different types of data.
[0049] Next, according to the first encryption branch, the source end uses the issued transmission key, that is, the encryption key in the transmission key pair, to encrypt the access control policy and generate a type of ciphertext part.
[0050] The access control policy in this application refers to the definition of multi-level data access permissions based on the task transmission path of the pre-transmission task, including but not limited to factors such as access identity, role permissions, and access time. Through the encrypted access control policy, the source ensures that only legitimate accessing ends can access and intercept data according to their permissions, indicating that the data access control layer is protected.
[0051] Furthermore, through the second encryption branch, a first derived key is derived from the transmission key. In a feasible implementation, a derivation method based on data attribute bases is used here to further encrypt the data slice, generating a two-type ciphertext portion. This ensures that even if the data is intercepted during transmission, unauthorized access terminals cannot obtain the data content. Through this encryption step, the data slice is effectively protected, and the generated two-type ciphertext portion corresponds to the encryption layer of the data content.
[0052] Finally, in the third encryption branch, for the logical slice portion, which represents the diverse combinations of data slices (different permissions have different combination logics, each corresponding to a separate slice), a second derived key is derived from the transmission key to encrypt the logical slice.
[0053] In this application, additional steganography is used to enhance its concealment. For example, read and write commands are used as steganography carriers. At the display level, the data slice and the logical slice are unrelated data, and the logical slice is the most common communication command. This achieves implicit encryption at the logical level on the basis of key encryption, maximizing the protection of transmission security.
[0054] In this process, protocol steganography is performed on logical slices, that is, by modifying the external representation of the data, such as the data format or transmission protocol, for example, by making it appear as a read or write command, to hide the true content of the data and increase the difficulty for the data to be monitored or analyzed by attackers.
[0055] By encrypting the steganized logical slice using the second derived key, three types of ciphertext are generated. This not only provides encrypted protection for the logical data content, but also makes the ciphertext more difficult to detect or crack due to the application of steganography.
[0056] In summary, by combining three encryption branches, the source end achieves comprehensive encryption protection for customs and trade data packets, ensuring the security of different types of data during transmission. Each ciphertext portion undergoes specific encryption processing based on the characteristics of the data and access requirements, thus providing multi-layered security for the entire transmission process.
[0057] Furthermore, step S1 of this application includes:
[0058] The first derived key is derived from the attribute base; if the privacy of the data slice is greater than a preset threshold, a pseudo-randomly generated invalid data slice is introduced into the data slice through traffic obfuscation.
[0059] In the application embodiments, the first derived key is derived through attribute base, that is, key derivation based on data slice attributes. In this application, by analyzing the attribute characteristics of the data, such as privacy, coreness, and permissions, the transmission key is used as the original key, and different keys are derived according to the characteristics of the data to perform differentiated encryption, so as to apply different levels of encryption protection to different types of data.
[0060] By deriving keys from attribute bases, appropriate encryption protection can be flexibly assigned to data slices. For example, under privacy attributes, highly sensitive data can be protected with stronger encryption, while low-sensitivity data can be protected with relatively simple encryption strategies.
[0061] Preferably, in this application, when the privacy level of a data slice exceeds a preset threshold, in order to further enhance data security and prevent malicious attackers from analyzing the data transmission pattern, pseudo-randomly generated invalid data slices are introduced through traffic obfuscation. The privacy level is judged based on the amount of privacy information in the data content; if the privacy level of a data slice is high, it indicates that the data contains more sensitive information and requires more stringent protection measures.
[0062] In the specific implementation, invalid data slices are introduced into the data stream based on data slices to change the data transmission characteristics, thereby increasing the difficulty of data traffic analysis. Invalid data slices do not contain actual valid data; they are generated pseudo-randomly to simulate the shape and transmission characteristics of data slices.
[0063] Preferably, the purpose of invalid data slices is to increase the complexity of data transmission, making it difficult for attackers to easily distinguish which data is valid and which is invalid when analyzing data traffic, thereby effectively preventing attacks based on traffic analysis.
[0064] In summary, this approach further enhances the concealment and security of data transmission. Despite the highly sensitive nature of the data itself, attackers will be unable to effectively obtain useful key information during traffic analysis due to traffic obfuscation, thus further improving the security and privacy protection capabilities during data transmission.
[0065] Furthermore, the logical slice is encrypted after protocol steganography. Step S1 of this application includes:
[0066] According to the steganography protocol, a first carrier data format and steganography strength are generated, wherein the first carrier data format is for daily business communication; the logical slice is encrypted using the second derived key to determine the logical slice ciphertext; based on the first carrier data format and steganography strength, the logical slice ciphertext is converted using steganography camouflage based on instruction codes and sequence numbers to determine three types of ciphertext parts.
[0067] In this embodiment of the application, a first carrier data format and steganography strength are generated according to the steganography protocol embedded in the customs and trade platform.
[0068] Specifically, a steganography protocol refers to the rules and procedures for hiding data. In the logic of this application, the aim is to embed logical data content into a seemingly ordinary and difficult-to-detect carrier to enhance the concealment of the data.
[0069] Optionally, the first carrier data format refers to the format used to carry encrypted data. In this invention, the carrier data format is set to the daily business communication type, that is, the selected carrier format is a common daily communication data format, such as in the form of read and write commands. Due to its routineness and high concurrency, it will not arouse suspicion from the monitoring system, thereby increasing the concealment of the data.
[0070] Steganography strength refers to the difficulty and concealment of hiding data. The higher the steganography strength, the stronger the effect of hiding data, and the less likely the data is to be detected or analyzed. In this application, the setting of steganography strength focuses on factors such as sensitivity and the security requirements of the transmission environment to ensure that the data has sufficient protection during transmission.
[0071] Next, the logical slice is encrypted using the second derived key to generate the logical slice ciphertext. A logical slice refers to a logical segment with specific business meaning extracted from the original data. For example, data slicing divides table columns or text into multiple smallest units, and logical slicing is the logical way of combining them.
[0072] Preferably, considering that the readability of data granularity varies under different permissions, the corresponding data slice content restoration and logical combination methods are different under different access terminal permissions, so as to form multiple logical slices.
[0073] In this application, the second derived key is a key derived from the transmission key. It is different from the first derived key, has no derivation constraints, and is used exclusively for the encryption processing of the logical slice part.
[0074] Subsequently, based on the first carrier data format and steganography strength, the source end performs steganography camouflage processing on the encrypted logical slice ciphertext, so that the encrypted logical slice ciphertext can be seamlessly embedded into the first carrier data format without being detected by any monitoring system.
[0075] In this invention, steganography is processed using a method based on instruction codes and sequence numbers for the control and management of data packets. In this process, a new data stream is constructed by combining the encrypted logical slice ciphertext with conventional communication data elements such as instruction codes and sequence numbers based on the first carrier data format.
[0076] For example, steganography makes the data appear as read / write commands, but it contains logically sliced ciphertext, enhancing the concealment of data transmission.
[0077] Ultimately, by employing various encryption and steganography techniques, the security and confidentiality of the data are comprehensively enhanced during transmission. This not only ensures the security and confidentiality of the data content during transmission but also strengthens its concealment through steganography, making it difficult for malicious monitoring or attackers to crack, thus effectively improving the overall security of data transmission.
[0078] Furthermore, before encrypting the access control policy, step S1 of this application includes:
[0079] Based on the access control policy, determine the data permission granularity of each access terminal; constrain the decrypted content status according to the data permission granularity; and bind the decrypted content status to the access control policy in encrypted form.
[0080] In this embodiment of the application, the data permission granularity of each access terminal is first determined based on the access control policy.
[0081] Access control policies, as rules governing data access permissions, define which users or devices can access specific data and the types of operations they can perform. Data permission granularity refers to the level of detail in data access permissions, describing the specific levels and scope of access. Specifically, access permissions can be categorized into different levels based on factors such as data coreness, privacy, and business requirements. For example, highly sensitive data may only be accessible to specific high-privilege users, while less sensitive data may allow access to a wider range of users; some data may only allow viewing of macro-level content under access restrictions. Therefore, through access control policies, the information source can determine the specific granularity of data that each accessing device can access, based on its role, identity, or permission level.
[0082] Next, based on the granularity of data permissions, the state of the decrypted content is constrained, that is, the specific content after data decryption and the conditions for data access. For example, some data may only be partially displayed after decryption, or may only be fully restored under specific conditions. Determining the granularity of data permissions will affect the constraints on the state of the decrypted content.
[0083] Specifically, when an access terminal requests to decrypt data, the data portion it can access will be determined based on the granularity of its permissions.
[0084] Finally, the decrypted content status is encrypted and bound to the access control policy to ensure that the access permissions of the data during the decryption process are consistent with the access control policy. Only authorized access terminals can access the corresponding data parts within the prescribed permission scope.
[0085] In summary, ciphertext binding not only ensures data security but also enhances access control during data transmission. The ciphertext binding mechanism can effectively prevent data leakage or abuse and ensure that the data content remains within the framework of access control throughout the entire transmission process.
[0086] In summary, this approach not only ensures the confidentiality of data during transmission but also guarantees that each accessing end can only access data within its authorized scope, thus achieving refined access control while protecting data privacy.
[0087] S2: Perform multi-channel concurrent transmission of the encrypted customs and trade data, intercept the data port of the first authentication end, and trigger permission attribute authentication based on zero-knowledge proof.
[0088] S3: If authentication is successful, the first authentication end calls the decryption plugin to perform data permission-based restoration and logical reorganization under the classification decryption, and generate restored customs and trade data.
[0089] In this embodiment, the encrypted customs and trade data is first subjected to multi-path concurrent transmission to improve data transmission efficiency and reliability. Specifically, the data is divided into multiple parallel transmission paths for transmission, thereby avoiding bandwidth bottlenecks and transmission delays of a single path and ensuring that customs and trade data can be transmitted efficiently under different network conditions. In multi-path concurrent transmission, each data packet may be transmitted through different network paths, enhancing the fault tolerance and anti-interference capabilities of the transmission.
[0090] When the data is transmitted to the first authentication terminal, the data port of the first authentication terminal will intercept the received customs and trade data ciphertext, perform security verification and authentication, and ensure that it can only be decrypted and processed after the identity and authorization authentication is passed.
[0091] Next, the first authentication terminal triggers permission attribute authentication based on zero-knowledge proofs. In this invention, zero-knowledge proofs are applied to permission attribute authentication to verify whether a user or device has the permission to access specific data. The first authentication terminal can verify whether the requester has legitimate access rights without revealing the specific data content, thereby effectively ensuring data security and privacy.
[0092] If authentication is successful, the accessing device is considered to have legitimate permissions, and the data decryption process will continue.
[0093] Subsequently, by invoking the decryption plugin, categorized decryption begins, generating restored customs and trade data that conforms to the permissions of the first authentication endpoint. That is, data is decrypted hierarchically according to access control policies and permission granularity. During decryption, the first authentication endpoint restores the data content layer by layer according to the access control policy, ensuring that each access endpoint only obtains the data portion it is authorized to access. Following this, a logical reorganization operation is performed; that is, based on the logical structure and business requirements, the decrypted data fragments are recombined according to specific rules to restore the original data structure and content. This ensures data integrity and the correctness of business logic, thereby making the restored customs and trade data conform to business requirements and correctly identified and utilized by subsequent processing systems.
[0094] In summary, this approach ensures that authorized users can adaptively access the necessary customs and trade data while guaranteeing data security.
[0095] Furthermore, in performing data permission-based restoration and logical reorganization under classification and decryption, step S3 of this application includes:
[0096] The first authentication terminal uses a decryption plugin to decrypt and reassemble the intercepted customs and trade data ciphertext based on the issued transmission key, and determines the restored customs and trade data.
[0097] The decryption and combination steps include: decrypting the first type of ciphertext portion to locate the data permission granularity of the first authentication end in the access control policy; decrypting the second type of ciphertext portion and, based on the data permission granularity, restoring the data slice under the decryption content state constraint to determine the restored data slice; decrypting the third type of ciphertext portion to determine the logical slice, logically recombining the restored data slice to generate the restored customs and trade data.
[0098] In this embodiment of the application, the decryption plugin is a module used to restore encrypted data. Its main task is to restore the received ciphertext into plaintext data according to specific rules and keys.
[0099] The transmission key is a key shared and used by the source and receiver during the initial transmission process. The first authentication terminal relies on this key to decrypt the data. Through decryption and reassembly steps, the first authentication terminal can recover the complete customs and trade data from the ciphertext, ensuring the integrity and security of the data.
[0100] In this embodiment of the application, the decryption and combination steps include the following key processes:
[0101] First, the first authentication endpoint decrypts a portion of the ciphertext to pinpoint the granularity of its data permissions within the access control policy. The purpose of decrypting this ciphertext is to recover the encrypted content of the access control policy, thereby clarifying the first authentication endpoint's access permissions and pinpointing the specific granularity of the data permissions—that is, the specific range or granularity of data that the authentication endpoint can access during data access. This granularity may include data slices, data fields, or specific records, confirming which parts of the data are visible to the first authentication endpoint.
[0102] Next, the first authentication terminal decrypts the second type of ciphertext and restores the data slice under the constraints of the decrypted content state based on the data permission granularity obtained after decryption. The second type of ciphertext is the encrypted data slice, which contains the actual content of customs and trade data. After decrypting the second type of ciphertext, it is restored according to the previously determined data permission granularity.
[0103] Specifically, the decrypted data slices are constrained according to access control policies, ensuring that the first authentication endpoint can only decrypt and restore the data it is authorized to access. For example, if the first authentication endpoint only has access to certain data slices, other data slices will be excluded. Through this step, the first authentication endpoint restores the data slices and ensures that only the authorized data is recovered.
[0104] Finally, the first authentication terminal decrypts the three types of encrypted text and determines the logical slices, obtains the logical slices containing actual business data, and performs logical reorganization on the restored data slices. That is, after restoring the data content, the data slices are recombined in the correct order and structure according to the business logic to ensure that the restored data meets the business requirements and data structure specifications, and to ensure that customs and trade data can be restored and transmitted correctly in the predetermined format.
[0105] Preferably, for parts without access rights, the decrypted text is presented as garbled characters, which can achieve differentiated restoration based on access control policy constraints under a unified key.
[0106] In summary, the first authentication terminal ultimately generates restored customs and trade data that conforms to the content and structure of the original customs and trade data, and the presentation format is consistent with the permissions of the first authentication terminal. This effectively ensures that the data, after decryption, not only meets security requirements but also provides appropriate access control based on permission granularity.
[0107] Furthermore, the steps in this application also include:
[0108] During the transmission process based on the pre-transmission task, multi-level access terminals perform data port interception and differentiated content restoration under access permission constraints until the pre-transmission task ends; the encryption and decryption plugins are migrated back to the transmission plugin library, and the generated task transmission records are stored in the platform database.
[0109] In this embodiment, multi-level access terminals refer to multiple nodes with different permissions throughout the entire task flow. Typically, different levels of access control are provided based on the sensitivity of the data and the permission level of the access terminals. During data transmission, multiple access terminals may access and process data sequentially or in parallel.
[0110] First, the multi-level access end performs data port interception operations. That is, during data transmission, the access end intercepts the incoming data stream and performs verification and processing while ensuring legitimate access.
[0111] Then, each access terminal performs differentiated content restoration of the data based on access permission constraints. That is, different levels of access terminals will restore different content according to their authorized scope. Specifically, the access terminal will execute the aforementioned multi-level decryption and logical combination steps according to its authorized access permissions to decrypt and restore different parts of the data. The data restoration process is differentiated according to the granularity of each access terminal's permissions, ensuring that each access terminal can only access the data within its authorized scope, thus protecting data security and privacy.
[0112] This process continues until the pre-transmission task is completed—that is, all stages of data transmission have been finished, and all related decryption, data recovery, and access control operations have been executed. At this point, all authorized access devices will be able to obtain their corresponding data content.
[0113] Subsequently, the encryption and decryption plugins involved will be migrated back to the transmission plugin library for use by other tasks or for system management. By migrating the plugins back, effective resource management can be ensured, duplicate plugin loading can be avoided, and system efficiency can be improved.
[0114] During this process, the generated task transmission records will be stored in the customs and trade platform's database. These records include detailed logs of data transmission, such as the transmitted data content, the keys used during transmission, access permissions, and decryption process details. This provides necessary data support for subsequent auditing, security analysis, and troubleshooting, and ensures the transparency and traceability of the entire data transmission process.
[0115] In summary, while ensuring the security and differentiated control of customs and trade data transmission, it is possible to track data transmission in real time and perform retrospective analysis when necessary, thus ensuring the security and compliance of the data transmission process.
[0116] The secure transmission method for big data customs and trade platforms based on encryption algorithms provided in this application has the following technical effects:
[0117] 1. A dynamically updated initial quantum key pool is established based on QKD devices. Combined with random number-derived transmission key pairs from both parties, the possibility of key cracking is eliminated from the source, enhancing the security and immutability of the encryption system. A three-level classification encryption mechanism is adopted, including access control policy key encryption, data slice first derived key encryption, and logical slice protocol steganography and second derived key encryption, providing multi-dimensional protection for customs and trade data transmission security and resisting different types of cracking and theft risks.
[0118] 2. Data and logical slices are split according to data coreness and privacy requirements. These are then paired with a first derived key derived from attribute bases to achieve fine-grained control over data encryption, ensuring the protection of highly private data. Logical slices are steganographically disguised before encryption, enhancing the concealment of data transmission, preventing targeted interception and analysis of ciphertext, and reducing the risk of exposure during transmission. High-privacy data slices introduce traffic obfuscation and invalid data slices, interfering with attackers' identification and extraction of valid data, further enhancing the data's resistance to attacks.
[0119] 3. Zero-knowledge proof-based permission attribute authentication completes identity verification without disclosing sensitive authentication information, ensuring the legitimacy of the accessing party and preventing unauthorized access. The decryption process strictly follows data permission granularity constraints, ensuring that different accessing parties can only restore the content corresponding to their permissions, achieving differentiated control over data access and avoiding excessive data leakage.
[0120] Example 2: Based on the same inventive concept as the secure transmission method for big data customs and trade platforms based on encryption algorithms in the foregoing examples, such as... Figure 2 As shown, this application provides a secure transmission system for a big data customs and trade platform based on encryption algorithms, the system comprising:
[0121] Encryption Unit 11: The source end calls the encryption plugin to slice and label the customs and trade data packets, perform classification encryption processing, and determine the ciphertext of the customs and trade data. The classification encryption includes key encryption of access control policy, encryption of the first derived key of data slice, and encryption of the second derived key written in the logical slice protocol.
[0122] Transmission authentication unit 12: Performs multi-channel concurrent transmission of the ciphertext of customs and trade data, intercepts the data port of the first authentication end, and triggers permission attribute authentication based on zero-knowledge proof.
[0123] Decryption Unit 13: If authentication is successful, the first authentication end calls the decryption plugin to perform data permission-based restoration and logical reorganization under the classification decryption, and generate restored customs and trade data.
[0124] Furthermore, the system is also used to perform the following steps:
[0125] Using a QKD device, an initial quantum key pool for transmission authentication is established in the customs and trade platform, wherein the initial quantum key pool is dynamically updated; the pre-transmission task is read to determine the source end and the multi-level access end; a shared key is generated based on the initial quantum key pool; and a transmission key pair based on the shared key is derived by combining the random numbers from both the source end and the multi-level access end, and the transmission key pair is distributed to the source end and the multi-level access end.
[0126] Furthermore, the system is also used to perform the following steps:
[0127] An encryption plugin and a decryption plugin are established and built into the transmission plugin library of the customs and trade platform. As the pre-transmission task is uploaded, the source end migrates and calls the encryption plugin, and the access end migrates and calls the decryption plugin to perform secure transmission management within the task cycle.
[0128] Furthermore, the encryption unit 11 is also used to perform the following steps:
[0129] The source end imports the customs and trade data packet into the encryption plugin, triggering the first processing node to perform data fragmentation processing based on data coreness and privacy, determining data slices, logical slices, and access control policies; according to the first encryption branch, the access control policy is encrypted using the distributed transmission key to determine a type of ciphertext portion; according to the second encryption branch, a first derived key is derived from the transmission key to encrypt the data slice, determining a type of ciphertext portion; according to the third encryption branch, a second derived key is derived from the transmission key to encrypt the logical slice after protocol steganography, determining a type of ciphertext portion.
[0130] Furthermore, the encryption unit 11 is also used to perform the following steps:
[0131] The first derived key is derived from the attribute base; if the privacy of the data slice is greater than a preset threshold, a pseudo-randomly generated invalid data slice is introduced into the data slice through traffic obfuscation.
[0132] Furthermore, the encryption unit 11 is also used to perform the following steps:
[0133] According to the steganography protocol, a first carrier data format and steganography strength are generated, wherein the first carrier data format is for daily business communication; the logical slice is encrypted using the second derived key to determine the logical slice ciphertext; based on the first carrier data format and steganography strength, the logical slice ciphertext is converted using steganography camouflage based on instruction codes and sequence numbers to determine three types of ciphertext parts.
[0134] Furthermore, the encryption unit 11 is also used to perform the following steps:
[0135] Based on the access control policy, determine the data permission granularity of each access terminal; constrain the decrypted content status according to the data permission granularity; and bind the decrypted content status to the access control policy in encrypted form.
[0136] Furthermore, the decryption unit 13 is also used to perform the following steps:
[0137] The first authentication terminal uses a decryption plugin to decrypt and combine the intercepted customs and trade data ciphertext based on the issued transmission key, and determines the restored customs and trade data.
[0138] The decryption and combination steps include: decrypting the first type of ciphertext portion to locate the data permission granularity of the first authentication end in the access control policy; decrypting the second type of ciphertext portion and, based on the data permission granularity, restoring the data slice under the decryption content state constraint to determine the restored data slice; decrypting the third type of ciphertext portion to determine the logical slice, logically recombining the restored data slice to generate the restored customs and trade data.
[0139] Furthermore, the system is also used to perform the following steps:
[0140] During the transmission process based on the pre-transmission task, multi-level access terminals perform data port interception and differentiated content restoration under access permission constraints until the pre-transmission task ends; the encryption and decryption plugins are migrated back to the transmission plugin library, and the generated task transmission records are stored in the platform database.
[0141] Through the foregoing detailed description of the secure transmission method for a big data customs and trade platform based on encryption algorithms, those skilled in the art can clearly understand the secure transmission method and system for a big data customs and trade platform based on encryption algorithms in this embodiment. As for the apparatus disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and relevant parts can be referred to the description in the method section.
[0142] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A secure transmission method for a big data customs and trade platform based on encryption algorithms, characterized in that: The method includes: The source end calls the encryption plugin to slice and label the customs and trade data packets, performs classified encryption processing, and determines the ciphertext of the customs and trade data. The classified encryption includes key encryption of access control policy, encryption of the first derived key of data slice, and encryption of the second derived key written in the logical slice protocol. The encrypted customs and trade data is transmitted concurrently via multiple channels. The data port of the first authentication end is intercepted, and permission attribute authentication based on zero-knowledge proof is triggered. If authentication is successful, the first authentication end calls the decryption plugin to perform restoration and logical reorganization based on data permission granularity under the classification decryption, and generates restored customs and trade data; The customs and trade data package is split into multiple data slices and logical slices. A data slice is a unit that physically divides the data according to business logic, while a logical slice is a combination of logic based on the data slices. The customs and trade data packets are sliced and labeled with attribute tags, and classified encryption is performed, including: The source end imports the customs and trade data packet into the encryption plugin, triggers the first processing node, performs data sharding processing based on data coreness and privacy, and determines data shards, logical shards and access control policies. Based on the first encryption branch, the access control policy is encrypted using the transmitted key to determine a type of ciphertext portion; Based on the second encryption branch, a first derived key is derived from the transmission key to encrypt the data slice and determine the second type of ciphertext portion; Based on the third encryption branch, a second derived key is derived from the transmission key, and the logical slice is encrypted after protocol steganography to determine three types of ciphertext parts; Perform data permission-based restoration and logical reorganization under classification decryption, including: The first authentication terminal uses a decryption plugin to decrypt and combine the intercepted customs and trade data ciphertext based on the issued transmission key, and determines the restored customs and trade data. The decryption and reassembly steps include: By decrypting the ciphertext portion, the data permission granularity of the first authentication end in the access control policy can be located. By decrypting the second type of ciphertext, and based on the data permission granularity, the data slice is restored under the constraints of the decrypted content state to determine the restored data slice; By decrypting the three types of ciphertext, logical slices are determined, and the restored data slices are logically reorganized to generate the restored customs and trade data.
2. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 1, characterized in that, Before the source calls the encryption plugin, it includes: An initial quantum key pool for transmission authentication is established in the customs and trade platform using QKD devices, wherein the initial quantum key pool is dynamically updated. Read the pre-transmission task to identify the source and multi-level access points; Generate a shared key based on the initial quantum key pool; By combining the random numbers generated by the source end and the multi-level access end, a transmission key pair based on the shared key is derived, and the transmission key pair is distributed to the source end and the multi-level access end.
3. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 2, characterized in that, Before the source calls the encryption plugin, it includes: Establish encryption and decryption plugins, and embed the encryption and decryption plugins into the transmission plugin library of the customs and trade platform; As the pre-transmission task is uploaded, the source end calls the encryption plugin, and the access end calls the decryption plugin to perform secure transmission management within the task cycle.
4. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 1, characterized in that, The first derived key is derived from the attribute base; If the privacy level of the data slice is greater than a preset threshold, a pseudo-randomly generated invalid data slice is introduced into the data slice through traffic obfuscation.
5. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 1, characterized in that, Encryption processing of the logical slice after protocol steganography includes: According to the steganography protocol, a first carrier data format and steganography strength are generated, wherein the first carrier data format is a daily business communication type; The logical slice is encrypted using the second derived key to determine the logical slice ciphertext; Based on the data format and steganography strength of the first carrier, the logical slice ciphertext is converted using steganography based on instruction codes and serial numbers to determine three types of ciphertext parts.
6. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 1, characterized in that, Before encrypting the access control policy, the following steps are included: Based on the access control policy, determine the granularity of data permissions for each access endpoint; Constrain the status of decrypted content based on the data permission granularity; The state of the decrypted content is encrypted and bound to the access control policy.
7. The secure transmission method for a big data customs and trade platform based on encryption algorithms as described in claim 3, characterized in that, During the transmission process based on the pre-transmission task, multi-level access terminals perform data port interception and differentiated content restoration under access permission constraints until the pre-transmission task ends. The encryption and decryption plugins are migrated back to the transmission plugin library, and the generated task transmission records are stored in the platform database.
8. A secure transmission system for a big data customs and trade platform based on encryption algorithms, characterized in that: The system is used to execute the secure transmission method for a big data customs and trade platform based on encryption algorithms as described in any one of claims 1-7, the system comprising: Encryption Unit: The source end calls the encryption plugin to slice and label the customs and trade data packets, perform classification encryption processing, and determine the customs and trade data ciphertext. The classification encryption includes key encryption of access control policy, encryption of the first derived key of data slice, and encryption of the second derived key written in the logical slice protocol. Transmission authentication unit: performs multi-channel concurrent transmission of the ciphertext of customs and trade data, intercepts the data port of the first authentication end, and triggers permission attribute authentication based on zero-knowledge proof; Decryption Unit: If authentication is successful, the first authentication end calls the decryption plugin to perform restoration and logical reorganization based on data permission granularity under the classification decryption, and generate restored customs and trade data.