ESIM card security encryption data transmission system
By generating optimized strategies through digital twin memory and reinforcement learning training, combined with multi-dimensional situational awareness assessment and dynamic matching encryption algorithms, the problem of balancing security and efficiency in eSIM card data transmission is solved, and precise resource management is achieved under different risk scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-10
- Publication Date
- 2026-03-24
AI Technical Summary
Existing eSIM card data transmission suffers from problems such as poor adaptability of static encryption strategies to complex network environments, lack of self-learning optimization capabilities, and difficulty in achieving a coordinated balance between security strength and communication efficiency due to single-dimensional evaluation.
By using a digital twin memory to accumulate historical experience and combining it with reinforcement learning to generate optimization strategies, and through multi-dimensional situational awareness and dynamic weighted evaluation, encryption algorithms are dynamically matched to achieve a precise balance between security strength, communication efficiency, and device resource consumption.
It achieves autonomous and collaborative optimization of anonymity and transmission efficiency in specific social contexts, dynamically adapts to encryption strategies of different risk levels, and ensures a precise balance between security strength and resource consumption.
Smart Images

Figure CN121728451A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of telecommunications technology, specifically to an eSIM card secure encrypted data transmission system. Background Technology
[0002] With the rapid development of IoT, IoV, and mobile communication technologies, embedded SIM cards (eSIM), as a new type of digital identity authentication and communication access technology, are gradually replacing traditional pluggable SIM cards and are widely used in various terminal devices such as smartphones, smart wearable devices, industrial sensors, and vehicle terminals. An eSIM card refers to a digital data file that directly embeds the communication functions of a traditional physical SIM card into the device chip (such as the motherboard of a mobile phone or IoT terminal). It enables communication functions consistent with ordinary SIM cards, such as internet access, making and receiving calls, and sending text messages, without the need for a physical card, and is not bound to a specific operator, supporting flexible service switching. However, as eSIM applications expand to the highly dynamic and high-risk edge environment of IoT, its data transmission faces increasingly severe security challenges. Existing technologies for traditional eSIM data transmission suffer from problems such as poor adaptability of static encryption strategies to complex network environments, lack of self-learning optimization capabilities in transmission strategies, and difficulty in balancing security strength, communication efficiency, and resource consumption due to single-dimensional evaluation.
[0003] Based on this, the present invention provides an eSIM card secure encrypted data transmission system to solve the aforementioned technical problems. Summary of the Invention
[0004] The purpose of this invention is to provide an eSIM card secure encrypted data transmission system. This invention utilizes a closed-loop mechanism that uses a digital twin memory bank to store historical experience, reinforcement learning to generate optimization strategies, and real-time invocation and dynamic adjustment. This achieves autonomous and collaborative optimization of anonymity and transmission efficiency in specific social contexts. Furthermore, based on multi-dimensional situational awareness and dynamic weighted comprehensive risk quantification assessment, it dynamically matches and adapts encryption algorithms to different risk levels, achieving a precise balance between security strength, communication efficiency, and device resource consumption.
[0005] To achieve the above objectives, the present invention provides the following technical solution: This invention provides an eSIM card secure encrypted data transmission system, comprising a social simulation management module, a social behavior learning and strategy evolution module, an adaptive encryption strategy module, a trust collaboration verification module, and an anomaly detection and self-healing module, wherein: The social simulation management module is used to dynamically and human-like identify and securely manage the identity of eSIM devices through a virtual social role generation and authentication mechanism. The social behavior learning and strategy evolution module is used to introduce an interactive memory bank and reinforcement learning mechanism based on digital twins. By reviewing the success and risk events of historical communication, it can autonomously generate and continuously optimize the concealed and efficient data transmission strategy in specific social contexts. The adaptive encryption strategy module dynamically generates and adapts the optimal encryption strategy based on multi-dimensional situational awareness and risk quantification assessment of the social environment, and coordinates the optimization of security strength, communication efficiency and resource consumption. The trust collaboration verification module is used to construct a distributed trust evaluation mechanism modeled after the social credit system. The anomaly detection and self-healing module is used to simulate the immune and repair mechanisms of social groups, to detect and isolate abnormal behaviors in real time, and to coordinate with system components to perform autonomous recovery.
[0006] The social simulation management module includes a virtual character generation unit, a dynamic authentication unit, and a role permission management unit, wherein: The virtual character generation unit generates differentiated virtual social character identifiers based on device attributes and establishes an anthropomorphic identity baseline. The dynamic authentication unit is used to verify the validity of role identity in real time through multi-factor authentication and dynamically update the identity status. The role-based access control unit is used to allocate data access and transmission permissions based on social role attributes, and to implement hierarchical security control.
[0007] The social behavior learning and strategy evolution module includes a digital twin memory bank unit, a reinforcement learning training unit, and a strategy adaptation unit, wherein: The digital twin memory unit is used to construct a digital mirror of the communication behavior of the eSIM device and store historical interaction data and scene features. The reinforcement learning training unit is used to train the decision-making model through successful / risk event debriefing and optimize the transmission strategy parameters. The strategy adaptation unit is used to invoke the optimal transmission strategy based on the real-time social context, and to dynamically balance concealment and efficiency.
[0008] The reinforcement learning training unit trains the decision model by reviewing successful / risk events to optimize the transmission strategy parameters. The specific operations are as follows: A1: Extract historical communication records, scene features, and behavioral features from the digital twin memory bank units, and label the success status or risk level of each record; A2: Construct a Markov decision process model to model eSIM communication behavior as a state-action-reward triple: ①The status includes the current network environment risk value, device resource availability, and trust level of the interaction object; ②The actions include transmission path selection and transmission timing control; ③ The reward is calculated based on a comprehensive reward function; A3: The specific expression for the comprehensive reward function is defined as follows: In the formula, To improve transmission success rate, E represents energy consumption expenditure, and E represents actual energy consumption. For maximum allowable energy consumption, The delay penalty is t, where t is the transmission delay time. To score for concealment, This refers to the number of communications during peak periods. Total number of communications A4: The strategy network is trained iteratively using the deep Q-network algorithm, representing the weight coefficients. A5: Distribute the converged training model to the policy adaptation unit.
[0009] The strategy adaptation unit invokes the optimal transmission strategy based on the real-time social context to dynamically balance concealment and efficiency. The specific operation is as follows: B1: Collects real-time social context data, including network environment risk level, trust value of interaction objects, device resource status and data transmission requirements, and simultaneously calls the trained policy model issued by the reinforcement learning training unit; B2: Input real-time contextual data into the trained policy model, which then directly infers and outputs the optimal transmission policy parameters that combine concealment and transmission efficiency. B3: Execute the optimal transmission strategy and control the eSIM device to complete the data transmission task; B4: During the strategy execution process, monitor its stealth and transmission efficiency indicators in real time; B5: If the indicator is detected to deviate from the expected threshold continuously, an immediate strategy adjustment will be initiated; at the same time, the complete context of this strategy decision, the execution results and adjustment records will be fed back to the digital twin memory unit as a new piece of experience data.
[0010] The adaptive encryption strategy module includes a multi-dimensional situational awareness unit, a risk quantification assessment unit, and an encryption algorithm scheduling unit, wherein: The multi-dimensional situational awareness unit is used to collect multi-dimensional data on social environmental risks, equipment resource status, and transmission requirements. The risk quantification and assessment unit is used to quantify the risk level of multi-dimensional data and output the basis for adjusting the encryption strategy. The encryption algorithm scheduling unit dynamically matches encryption algorithms based on the evaluation results, and collaboratively optimizes security strength and resource consumption.
[0011] The risk quantification and assessment unit quantifies the risk level of multi-dimensional data and outputs the basis for adjusting the encryption strategy. The specific operation is as follows: C1: Receives input data from the multi-dimensional situational awareness unit, including network attack frequency, neighboring node trust value, device remaining power, and data sensitivity level; C2: Normalize the data for each dimension and calculate the individual risk score based on preset rules or a lightweight model; C3: A dynamic weighted fusion method is used to synthesize individual risk scores into a comprehensive social risk index (SRI). C4: SRI is divided into three levels: SRI<0.3 is low risk, 0.3≤SRI<0.7 is medium risk, and SRI≥0.7 is high risk.
[0012] The Comprehensive Social Risk Index (SRI) is calculated using the following weighted summation model, with the specific expression as follows: in: For network layer risk scoring, The average trust value of neighboring nodes. This represents the percentage of remaining battery power in the device. Data sensitivity level, These are weighting coefficients that can be dynamically adjusted based on historical attack events.
[0013] The trust collaborative verification module includes a trust factor acquisition unit, a distributed evaluation unit, and a trust level application unit, wherein: The trust factor collection unit is used to collect multi-dimensional trust indicators such as device interaction history and behavioral compliance. The distributed evaluation unit is used to generate real-time trust values for devices through multi-node collaborative computation. The trust level application unit is used to dynamically adjust data interaction permissions based on the trust level.
[0014] The anomaly detection and self-healing module includes an abnormal behavior perception unit, a rapid isolation unit, and a collaborative self-healing unit, wherein: The abnormal behavior sensing unit is used to monitor abnormal communication activities that deviate from the normal behavior baseline in real time. The rapid isolation unit is used to trigger an immediate isolation mechanism for abnormal behavior to prevent the spread of risk. The collaborative self-healing unit is used to coordinate with various modules of the system to repair damaged nodes and restore normal data transmission links.
[0015] Compared with the prior art, the beneficial effects of the present invention are: This invention achieves autonomous and collaborative optimization of anonymity and transmission efficiency in specific social contexts through a closed-loop mechanism that uses a digital twin memory bank to accumulate historical experience, reinforcement learning to generate optimization strategies, and real-time invocation and dynamic adjustment. Based on multi-dimensional situational awareness and dynamic weighted comprehensive risk quantification assessment, it dynamically matches and adapts encryption algorithms to different risk levels, achieving a precise balance between security strength, communication efficiency, and equipment resource consumption. Attached Figure Description
[0016] Figure 1 This is a system diagram of an eSIM card secure encrypted data transmission system according to the present invention.
[0017] Figure 2 This is an overall architecture diagram of an eSIM card secure encrypted data transmission system according to the present invention.
[0018] Figure 3 This is a flowchart of the adaptive encryption strategy scheduling process in an eSIM card secure encrypted data transmission system according to the present invention.
[0019] Explanation of icon numbers: 1. Social Simulation Management Module; 11. Virtual Role Generation Unit; 12. Dynamic Authentication Unit; 13. Role Permission Management Unit; 2. Social Behavior Learning and Strategy Evolution Module; 21. Digital Twin Memory Bank Unit; 22. Reinforcement Learning Training Unit; 23. Strategy Adaptation Unit; 3. Adaptive Encryption Strategy Module; 31. Multi-dimensional Situational Awareness Unit; 32. Risk Quantification Assessment Unit; 33. Encryption Algorithm Scheduling Unit; 4. Trust Collaborative Verification Module; 41. Trust Factor Collection Unit; 42. Distributed Evaluation Unit; 43. Trust Level Application Unit; 5. Anomaly Detection and Self-Healing Module; 51. Abnormal Behavior Perception Unit; 52. Rapid Isolation Unit; 53. Collaborative Self-Healing Unit. Detailed Implementation
[0020] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0021] Example: like Figures 1-3As shown, this embodiment provides an eSIM card secure encrypted data transmission system, including a social simulation management module 1, a social behavior learning and strategy evolution module 2, an adaptive encryption strategy module 3, a trust collaborative verification module 4, and an anomaly detection and self-healing module 5. Specifically: the social simulation management module 1 is used to dynamically and anthropomorphically identify and securely manage the identity of the eSIM device through a virtual social role generation and authentication mechanism; the social behavior learning and strategy evolution module 2 is used to introduce an interactive memory bank based on digital twins and a reinforcement learning mechanism, autonomously generating and continuously optimizing a concealed and efficient data transmission strategy in specific social contexts by reviewing successful and risky events in historical communication; the adaptive encryption strategy module 3 dynamically generates and adapts the optimal encryption strategy based on multi-dimensional situational awareness and risk quantification assessment of the social environment, collaboratively optimizing security strength, communication efficiency, and resource consumption; the trust collaborative verification module 4 is used to construct a distributed trust assessment mechanism modeled after a social credit system; and the anomaly detection and self-healing module 5 is used to simulate the immune and repair mechanisms of social groups, real-time sensing and isolation of abnormal behavior, while simultaneously coordinating with system components for autonomous recovery.
[0022] It should be noted that the social simulation management module 1 constructs anthropomorphic identities, and the trust collaboration verification module 4 and the adaptive encryption strategy module 3 provide social trust and real-time security status respectively, jointly driving the social behavior learning and strategy evolution module 2 to generate concealed and efficient data transmission intelligence, and the anomaly detection and self-healing module 5 constitutes a system with herd immunity and repair capabilities.
[0023] In this embodiment, it should also be noted that the social simulation management module 1 includes a virtual role generation unit 11, a dynamic authentication unit 12, and a role permission management unit 13, wherein: the virtual role generation unit 11 generates differentiated virtual social role identifiers based on device attributes and establishes a human-like identity baseline; the dynamic authentication unit 12 is used to verify the validity of role identity in real time through multi-factor authentication and dynamically update the identity status; the role permission management unit 13 is used to allocate data access and transmission permissions according to social role attributes and perform hierarchical security control.
[0024] It should be noted that the virtual character generation unit 11 creates a digital identity, which is continuously verified and updated through the dynamic authentication unit 12. Finally, the role permission management unit 13 maps the verified identity to specific data access and transmission permissions.
[0025] Furthermore, it should be noted that the device attributes in the virtual character generation unit 11 include, but are not limited to: eSIM chip model (such as the hardware version of an embedded SIM card), user type (personal / enterprise / industrial grade), historical communication compliance rate (the proportion of no abnormal behavior in the past 30 days), and bound terminal type (mobile phone / IoT sensor / vehicle terminal). A unique virtual social character identifier is generated, which contains a 128-bit identity code. The first 32 bits are the hash value of the device's unique hardware identifier, bits 33-64 are the user type and scene tag, and bits 65-128 are dynamically generated random numbers, forming a human-like identity baseline to ensure identity uniqueness and scene relevance.
[0026] The dynamic authentication unit 12 performs multi-factor real-time verification of role identity: ① Static factor: private key signature verification of virtual role identifier; ② Dynamic factor: real-time device location (located by base station) and network environment characteristics (such as access point MAC address); ③ Behavioral factor: matching degree between recent communication frequency and historical baseline; when any factor verification fails, the identity status is immediately updated to "pending verification" and secondary authentication is triggered (such as sending a verification code to the bound terminal) to avoid identity forgery.
[0027] The role-based access control unit 13 divides permissions into three levels based on the attributes of virtual social roles: Level 1 (highly trusted roles): can transmit sensitive data (such as payment information) and access core nodes; Level 2 (ordinary roles): can only transmit non-sensitive data (such as status information) and access ordinary nodes; Level 3 (lowly trusted roles): transmission frequency is limited, and only receiving data is allowed. Permissions are dynamically adjusted according to identity status (e.g., if authentication fails 3 times consecutively, it will be downgraded to Level 3), realizing hierarchical security control.
[0028] In this embodiment, it should also be noted that the social behavior learning and strategy evolution module 2 includes a digital twin memory bank unit 21, a reinforcement learning training unit 22, and a strategy adaptation unit 23, wherein: the digital twin memory bank unit 21 is used to construct a digital mirror of the eSIM device's communication behavior and store historical interaction data and scene features; the reinforcement learning training unit 22 is used to train the decision model through successful / risk event review and optimize transmission strategy parameters; the specific operations are as follows: A1: Extract historical communication records, scene features, and behavioral features from the digital twin memory bank unit 21, and label the success status or risk level of each record; A2: Construct a Markov decision process model and model the eSIM communication behavior as a state-action-reward triplet: ① Wherein, the state includes the current network environment risk value, device resource availability, and trust level of the interaction object; ② The action includes transmission path selection and transmission timing control; ③ The reward is calculated based on a comprehensive reward function; A3: Define the specific expression of the comprehensive reward function as: In the formula, To improve transmission success rate, E represents energy consumption expenditure, and E represents actual energy consumption. For maximum allowable energy consumption, The delay penalty is t, where t is the transmission delay time. To score for concealment, This refers to the number of communications during peak periods. Total number of communications A4: Iteratively train the policy network using the deep Q-network algorithm; A5: Distribute the converged model to the policy adaptation unit 23. Policy adaptation unit 23: Used to invoke the optimal transmission strategy based on the real-time social context, dynamically balancing concealment and efficiency. Specific operations are as follows: B1: Real-time collection of current social context data, including network environment risk level, trust value of interacting objects, device resource status, and data transmission requirements, and synchronously invoking the trained policy model issued by the reinforcement learning training unit 22; B2: Inputting real-time context data into the trained policy model, which directly infers and outputs the optimal transmission strategy parameters after considering both concealment and transmission efficiency; B3: Executing the optimal transmission strategy to control the eSIM device to complete the data transmission task; B4: Real-time monitoring of concealment and transmission efficiency indicators during policy execution; B5: If the indicators continuously deviate from the expected threshold, immediate policy adjustment is initiated; simultaneously, the complete context of this policy decision, execution results, and adjustment records are fed back as new experience data to the digital twin memory unit 21.
[0029] It should be noted that the digital twin memory bank unit 21 is based on experience. The reinforcement learning training unit 22 reviews and learns from historical experience to generate an optimized strategy model. The strategy adaptation unit 23 executes the model decision in a real environment and feeds the execution results back to the memory bank.
[0030] Furthermore, it should be noted that the deep Q-network in A4 uses a 3-layer fully connected neural network (input layer dimension = number of state features, hidden layer node count = 64, 32, output layer dimension = action space size); experience replay pool capacity. Sample size: 32; Learning rate: 0.001; Discount factor: [Missing information - likely a number of samples or parameters] In the ε-greedy strategy, ε decreases linearly from 0.9 to 0.1. If the indicator is detected to deviate from the threshold for 5 consecutive seconds in B5 (e.g., concealment > 30% or latency > 1.5 times the threshold), it will immediately switch to the suboptimal strategy (the strategy with the second highest Q value). After adjustment, it will continue to monitor for 30 seconds. If it still does not meet the standard, it will trigger the emergency incremental training of reinforcement learning training unit 22 (prioritizing the use of the 100 most recent abnormal data samples).
[0031] In this embodiment, it should also be noted that the adaptive encryption strategy module 3 includes a multi-dimensional situational awareness unit 31, a risk quantification assessment unit 32, and an encryption algorithm scheduling unit 33, wherein: the multi-dimensional situational awareness unit 31 is used to collect multi-dimensional data on social environmental risks, equipment resource status, and transmission requirements; the risk quantification assessment unit 32 is used to quantify the risk level of the multi-dimensional data and output the basis for adjusting the encryption strategy; the specific operation is as follows: C1: Receive input data from the multi-dimensional situational awareness unit 31, including network attack frequency, neighboring node trust value, remaining device power, and data sensitivity level; C2: Normalize the data of each dimension and calculate the individual risk score based on preset rules or a lightweight model; C3: Use a dynamic weighted fusion method to synthesize the individual risk scores into a comprehensive social risk index (SRI); the comprehensive social risk index (SRI) is calculated using the following weighted summation model, the specific expression of which is: in: For network layer risk scoring, The average trust value of neighboring nodes. This represents the percentage of remaining battery power in the device. Data sensitivity level, This refers to weighting coefficients that can be dynamically adjusted based on historical attack events. C4: SRI is divided into three levels: SRI < 0.3 is low risk, 0.3 ≤ SRI < 0.7 is medium risk, and SRI ≥ 0.7 is high risk. Encryption Algorithm Scheduling Unit 33: Dynamically matches encryption algorithms based on the evaluation results, collaboratively optimizing security strength and resource consumption. It should be noted that the multi-dimensional situational awareness unit 31 is responsible for collecting internal and external environmental data, the risk quantification assessment unit 32 fuses and quantifies the perceived data to generate the comprehensive social risk index SRI, and the encryption algorithm scheduling unit 33 dynamically allocates encryption resources based on the risk assessment conclusions.
[0032] Furthermore, it should be noted that the dynamic weights in C3... When the frequency of network attacks exceeds 5 times per minute Increased to 0.4 Reduced to 0.1; when the data sensitivity level is high, Increased to 0.4 Reduce to 0.1; when the device battery level is <20%, Reduced to 0.1 Increased to 0.35. The encryption algorithm scheduling unit 33 dynamically matches encryption algorithms based on risk level: ① Low risk: Uses lightweight encryption algorithms (such as AES-128), with a key update cycle of 24 hours, reducing resource consumption; ② Medium risk: Uses enhanced encryption algorithms (such as AES-256), shortening the key update cycle to 12 hours, balancing security and efficiency; ③ High risk: Uses hybrid encryption algorithms (ECC+AES-256), through dynamic key negotiation (updating the session key every 5 minutes), and enables redundant transmission verification to ensure data integrity.
[0033] In this embodiment, it should also be noted that the trust collaboration verification module 4 includes a trust factor collection unit 41, a distributed evaluation unit 42, and a trust level application unit 43, wherein: the trust factor collection unit 41 is used to collect multi-dimensional trust indicators of device interaction history and behavioral compliance; the distributed evaluation unit 42 is used to generate real-time trust values of the device through multi-node collaborative calculation; and the trust level application unit 43 is used to dynamically adjust data interaction permissions according to the trust level.
[0034] It should be noted that the multi-dimensional behavioral evidence gathered by the trust factor collection unit 41 is used by the distributed evaluation unit 42 to generate an objective real-time trust value through a consensus mechanism, and finally the trust level application unit 43 maps the quantified trust level into precise data interaction permissions.
[0035] Furthermore, it should be noted that the multi-dimensional trust indicators in the trust factor collection unit 41 include: ① Historical interaction success rate: number of successful communications with other nodes / total number of communications; ② Behavioral compliance: whether there are abnormal data requests (such as frequent access to sensitive ports) and whether the transmitted data conforms to the protocol specifications; ③ Recommended trust value: the evaluation of it by other highly trusted nodes (0-1); ④ Penalty record: the number of times it has been marked as "abnormal" in the past 7 days.
[0036] The distributed evaluation unit 42 uses "multi-node collaborative computing" to generate real-time trust values. The specific operation is as follows: ① Each node calculates the initial trust value locally. (Based on its own interaction records); ② Through a consensus algorithm (such as PBFT) Perform cross-validation to remove outliers (deviation from the mean > 3σ); ③ Calculate the global confidence value. (n is the number of nodes participating in the verification, n≥3); ④ The trust value is updated every 30 minutes. If abnormal behavior (such as data forgery) is detected, the trust value is recalculated immediately.
[0037] In this embodiment, it should also be noted that the anomaly detection and self-healing module 5 includes an abnormal behavior perception unit 51, a rapid isolation unit 52, and a collaborative self-healing unit 53, wherein: the abnormal behavior perception unit 51 is used to monitor abnormal communication activities that deviate from the normal behavior baseline in real time; the rapid isolation unit 52 is used to trigger an immediate isolation mechanism for abnormal behavior to prevent the spread of risk; and the collaborative self-healing unit 53 is used to coordinate with various modules of the system to repair damaged nodes and restore normal data transmission links.
[0038] It should be noted that the abnormal behavior perception unit 51 continuously monitors the system status. Once a threat is detected, the rapid isolation unit 52 immediately activates as a security barrier to curb the spread of risk, and then coordinates with the self-healing unit 53 to link system resources for damage recovery.
[0039] Furthermore, it should be noted that the isolation mechanism in the rapid isolation unit 52 is divided into three levels: Level 1 isolation: Suspend communication with abnormal nodes and restrict their data sending permissions; Level 2 isolation: If an attack is detected (such as injecting malicious code), cut off the physical connection and record the MAC address; Level 3 isolation: For nodes that continue to attack (>5 minutes), add them to the blacklist and synchronize them to all nodes in the network.
[0040] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0041] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. An eSIM card secure encrypted data transmission system, characterized in that, It includes a social simulation management module (1), a social behavior learning and strategy evolution module (2), an adaptive encryption strategy module (3), a trust collaboration verification module (4), and an anomaly detection and self-healing module (5), among which: The social simulation management module (1) is used to dynamically and humanize the identity of eSIM devices and manage their security through a virtual social role generation and authentication mechanism. The social behavior learning and strategy evolution module (2) is used to introduce an interactive memory bank and reinforcement learning mechanism based on digital twins. By reviewing the success and risk events of historical communication, it can autonomously generate and continuously optimize the concealed and efficient data transmission strategy in specific social situations. The adaptive encryption strategy module (3) dynamically generates and adapts the optimal encryption strategy based on multi-dimensional situational awareness and risk quantification of the social environment, and performs collaborative optimization of security strength, communication efficiency and resource consumption. The trust collaboration verification module (4) is used to construct a distributed trust evaluation mechanism in imitation of the social credit system. The anomaly detection and self-healing module (5) is used to simulate the immune and repair mechanisms of social groups, to detect and isolate abnormal behaviors in real time, and to coordinate with system components to perform autonomous recovery.
2. The eSIM card secure encrypted data transmission system according to claim 1, characterized in that, The social simulation management module (1) includes a virtual character generation unit (11), a dynamic authentication unit (12), and a role permission management unit (13), wherein: The virtual character generation unit (11) generates differentiated virtual social character identifiers based on device attributes and establishes an anthropomorphic identity baseline; The dynamic authentication unit (12) is used to verify the validity of the role identity in real time through multi-factor authentication and dynamically update the identity status. The role permission management unit (13) is used to allocate data access and transmission permissions according to social role attributes and to carry out hierarchical security control.
3. The eSIM card secure encrypted data transmission system according to claim 1, characterized in that, The social behavior learning and strategy evolution module (2) includes a digital twin memory bank unit (21), a reinforcement learning training unit (22), and a strategy adaptation unit (23), wherein: The digital twin memory unit (21) is used to construct a digital mirror of the communication behavior of the eSIM device and store historical interaction data and scene features; The reinforcement learning training unit (22) is used to train the decision model through successful / risk event debriefing and optimize the transmission strategy parameters. The strategy adaptation unit (23) is used to call the optimal transmission strategy according to the real-time social context to achieve a dynamic balance between concealment and efficiency.
4. The eSIM card secure encrypted data transmission system according to claim 3, characterized in that, The reinforcement learning training unit (22) trains the decision model through successful / risk event debriefing to optimize the transmission strategy parameters. The specific operation is as follows: A1: Extract historical communication records, scene features and behavioral features from the digital twin memory bank unit (21), and mark the success status or risk level of each record; A2: Construct a Markov decision process model to model eSIM communication behavior as a state-action-reward triple: ①The status includes the current network environment risk value, device resource availability, and trust level of the interaction object; ②The actions include transmission path selection and transmission timing control; ③ The reward is calculated based on a comprehensive reward function; A3: The specific expression for the comprehensive reward function is defined as follows: In the formula, To improve transmission success rate, E represents energy consumption expenditure, and E represents actual energy consumption. For maximum allowable energy consumption, The delay penalty is t, where t is the transmission delay time. To score for concealment, This refers to the number of communications during peak periods. Total number of communications A4: The strategy network is trained iteratively using the deep Q-network algorithm, representing the weight coefficients. A5: Distribute the converged training model to the policy adaptation unit (23).
5. The eSIM card secure encrypted data transmission system according to claim 3, characterized in that, The strategy adaptation unit (23) calls the optimal transmission strategy according to the real-time social context to dynamically balance concealment and efficiency. The specific operation is as follows: B1: Real-time collection of current social context data, including network environment risk level, trust value of interactive objects, device resource status and data transmission requirements, and synchronous invocation of the trained policy model issued by the reinforcement learning training unit (22); B2: Input real-time contextual data into the trained policy model, which then directly infers and outputs the optimal transmission policy parameters that combine concealment and transmission efficiency. B3: Execute the optimal transmission strategy and control the eSIM device to complete the data transmission task; B4: During the strategy execution process, monitor its stealth and transmission efficiency indicators in real time; B5: If the indicator is detected to deviate from the expected threshold continuously, an immediate strategy adjustment will be initiated; at the same time, the complete context of this strategy decision, the execution results and adjustment records will be fed back to the digital twin memory unit as a new piece of experience data (21).
6. The eSIM card secure encrypted data transmission system according to claim 1, characterized in that, The adaptive encryption strategy module (3) includes a multi-dimensional situational awareness unit (31), a risk quantification assessment unit (32), and an encryption algorithm scheduling unit (33), wherein: The multi-dimensional situational awareness unit (31) is used to collect multi-dimensional data on social environmental risks, equipment resource status and transmission requirements. The risk quantification assessment unit (32) is used to quantify the risk level of multi-dimensional data and output the basis for adjusting the encryption strategy. The encryption algorithm scheduling unit (33) dynamically matches encryption algorithms based on the evaluation results and collaboratively optimizes security strength and resource consumption.
7. The eSIM card secure encrypted data transmission system according to claim 6, characterized in that, The risk quantification assessment unit (32) quantifies the risk level of multi-dimensional data and outputs the basis for adjusting the encryption strategy. The specific operation is as follows: C1: Receives input data from the multi-dimensional situational awareness unit (31), including network attack frequency, neighboring node trust value, device remaining power and data sensitivity level; C2: Normalize the data for each dimension and calculate the individual risk score based on preset rules or a lightweight model; C3: A dynamic weighted fusion method is used to synthesize individual risk scores into a comprehensive social risk index (SRI). C4: SRI is divided into three levels: SRI<0.3 is low risk, 0.3≤SRI<0.7 is medium risk, and SRI≥0.7 is high risk.
8. The eSIM card secure encrypted data transmission system according to claim 7, characterized in that, The Comprehensive Social Risk Index (SRI) is calculated using the following weighted summation model, with the specific expression as follows: in: For network layer risk scoring, The average trust value of neighboring nodes. This represents the percentage of remaining battery power in the device. Data sensitivity level, These are weighting coefficients that can be dynamically adjusted based on historical attack events.
9. The eSIM card secure encrypted data transmission system according to claim 1, characterized in that, The trust collaborative verification module (4) includes a trust factor acquisition unit (41), a distributed evaluation unit (42), and a trust level application unit (43), wherein: The trust factor collection unit (41) is used to collect multi-dimensional trust indicators such as device interaction history and behavioral compliance. The distributed evaluation unit (42) is used to generate a real-time trust value for the device through multi-node collaborative computation. The trust level application unit (43) is used to dynamically adjust data interaction permissions according to the trust level.
10. The eSIM card secure encrypted data transmission system according to claim 1, characterized in that, The anomaly detection and self-healing module (5) includes an abnormal behavior perception unit (51), a rapid isolation unit (52), and a collaborative self-healing unit (53), wherein: The abnormal behavior sensing unit (51) is used to monitor abnormal communication activities that deviate from the normal behavior baseline in real time. The rapid isolation unit (52) is used to trigger an immediate isolation mechanism for abnormal behavior to prevent the spread of risk. The collaborative self-healing unit (53) is used to link various modules of the system to repair damaged nodes and restore normal data transmission links.
Citation Information
Patent Citations
Edge computing scheduling method and system for heterogeneous multi-source sensor
CN119960950A
Self-adaptive data encryption method based on risk driving
CN120185948A
Security guarantee system for cross-domain communication and data sharing of network platform software
CN120567551A
Network data security processing method and platform
CN121125243A
Intelligent network security policy optimization system based on SPF algorithm
CN121441571A