Defense system for information security of trusted data space
By using a trusted data space information security defense system, dynamically adjusting the number of security key bits and the active verification node environment, the system solves the problem of trustworthiness and efficiency in data sharing under complex network environments, achieves an adaptive balance between security and performance, defends against data leakage and tampering, and provides non-repudiable security auditing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-21
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies struggle to achieve trusted sharing and efficient use of data throughout its entire lifecycle in complex network environments. They lack adaptive dynamic adjustment of the length of security keys, and environmental verification and policy execution are passively separated, making it difficult to dynamically balance security strength and system performance.
The information security defense system employing trusted data space includes a data encryption module, an environment verification module, a response execution module, and a data usage monitoring module. By dynamically selecting the number of security key bits and combining attribute-based encryption or proxy re-encryption technology, it actively verifies the node environment. The trusted data unit embeds execution strategies, monitors usage behavior in real time, and adjusts the key bit length to achieve adaptive balance.
It achieves reliable, efficient and intelligent protection of data sharing in complex network environments, ensuring that data is under control throughout the process, preventing data leakage and tampering, providing non-repudiable security audit capabilities, and maintaining low latency and high availability.
Smart Images

Figure CN121808768A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security defense technology, and in particular to a defense system for information security in a trusted data space. Background Technology
[0002] In complex network environments, with the rapid development of big data, cloud computing, and IoT technologies, data has become a core production factor. Cross-organizational and cross-regional data sharing is crucial for promoting collaborative innovation and improving business efficiency, especially in fields such as healthcare, finance, and the industrial internet. However, traditional data sharing models face severe security challenges: the open and volatile network environment poses risks of malicious nodes and man-in-the-middle attacks; data may be stolen, tampered with, or accessed without authorization during transmission, storage, and use; static and fixed security strategies are difficult to adapt to dynamically changing network conditions and diverse business scenarios, often leading to a trade-off between security and system performance. Imbalance – Overly high security configurations introduce significant latency, impacting real-time performance; while reduced security strength increases the risk of data leakage. Although existing research has introduced technologies such as blockchain, attribute encryption, and trusted computing to enhance data trustworthiness and access control, problems such as static encryption parameters, weak environmental awareness, and lagging policy execution and security adjustments still exist. It is difficult to achieve autonomous dynamic optimization of security strength and sharing efficiency while ensuring data security throughout its entire lifecycle. Therefore, there is an urgent need for a proactive defense system that can deeply integrate environmental verification, dynamic policy execution, and adaptive security parameter tuning to achieve reliable, efficient, and intelligent protection of data sharing in complex network environments.
[0003] Chinese Patent Publication No. CN119854025A discloses a network information security defense detection method and system, including: a website security inspection module, a download security inspection module, an access security inspection module, and a display execution module. In daily internet use, users often encounter network security issues, such as receiving phishing emails disguised as banks or downloading malicious software from untrusted websites, leading to data theft. Identity theft and data leakage increase privacy and financial risks, while man-in-the-middle attacks can potentially exploit unencrypted Wi-Fi networks. Fi networks intercept sensitive information; this shows that the existing information security defense technology suffers from static encryption parameters and passive separation between environmental verification and policy execution, making it difficult to dynamically balance security strength and system performance. Summary of the Invention
[0004] To address this, the present invention provides a defense system for information security in a trusted data space, which overcomes the problems in existing technologies such as the lack of adaptive dynamic adjustment of the number of security key bits, the inability to cope with complex network environments due to the integration of proactive environment verification and context-aware strategy execution, resulting in low efficiency in trusted sharing and use of data throughout its entire lifecycle.
[0005] To achieve the above objectives, the present invention provides a defense system for information security in a trusted data space, comprising: The data encryption module is used to select the number of security key bits according to information security requirements, so as to encrypt and encapsulate the original data according to the number of security key bits and generate a trusted data unit. An environment verification module, which is connected to the data encryption module, is used to perform trusted verification on trusted data units arriving at the edge node, and obtain a first verification result and a second verification result. If the first verification result is obtained, the module selects to refuse to decrypt the data or destroy the data according to the current trusted state. The response execution module, which is connected to the environment verification module, is used to determine whether to authorize access based on the current context when the second verification result is obtained. The data usage monitoring module, which is connected to the response execution module, is used to monitor usage behavior and sharing latency during the process of trusted data authorization access in order to determine whether the security key length needs to be adjusted.
[0006] Furthermore, the data encryption module includes: The security parameter selection unit is used to select the corresponding security key bit length from a plurality of preset security levels according to the information security requirements; The data encryption unit is used to determine the corresponding encryption algorithm parameters based on the selected security key length, and to encrypt the original data using an attribute-based encryption algorithm or a proxy re-encryption algorithm to generate ciphertext. A trusted data encapsulation unit is used to encapsulate the ciphertext, the machine-executable usage policy bound to the data, and a lightweight trusted container into a trusted data unit. The trusted container contains embedded logic for performing subsequent verification and policy execution.
[0007] Furthermore, the safety parameter selection unit includes: The initial determination subunit is used to determine the number of bits in the initial security key based on the data attributes. The environment determination subunit is used to determine the current environment based on the end-to-end delay of data transmission. The final selection sub-unit is used to determine the target security key length based on the current environment and the initial security key length.
[0008] Furthermore, the environment verification module includes: The node integrity measurement unit is used to actively measure the software ground state and running process of the edge node in order to calculate the corresponding integrity measurement value. The remote verification unit is used to request and verify the remote verification report issued by the hardware trusted platform module of the edge node. The environment policy verification unit is used to compare the integrity metric value and the remote proof report with the environment requirements specified in the usage policy embedded in the trusted data unit to determine whether the node environment is trustworthy; if it does not meet the requirements, the first verification result is triggered.
[0009] Furthermore, the environmental strategy verification unit includes: The first comparison subunit is used to compare the integrity metric value with the first expected value and analyze whether the actual state is consistent with the expectation. The second comparison subunit is used to compare the hash data in the remote proof report with the second expected value and analyze whether the hash data matches the expectation. The Trust Analysis Subunit is used to determine the trustworthiness of the node environment when the actual state is consistent with the expectation and the hash data matches the expectation. When the actual state is inconsistent with the expectation and / or the hash data does not match the expectation, it triggers the first verification result.
[0010] Furthermore, the response execution module includes: The context evaluation unit is used to collect and evaluate the context information of the current access in real time after obtaining the second verification result. The context information includes at least the requester's identity attributes, access time, geographical location, network environment and node real-time load. The dynamic access control unit is used to perform dynamic policy evaluation based on the context information and the usage policy embedded in the trusted data unit, and to determine whether to authorize access and the scope of authorized operations. The decryption unit is used to decrypt the ciphertext using a key decryption algorithm agreed upon with the data encryption unit only after authorized access, and then provide the plaintext data to the edge node for use.
[0011] Furthermore, the data monitoring module includes: The behavior monitoring and auditing unit is used to monitor and record all data operations during the data usage process, including reading, copying, modifying, transmitting and generating derived data, and compare them with the embedded usage policies in real time to detect and prevent violations. The shared delay analysis unit is used to monitor the entire process delay from the issuance of a data request to successful decryption in real time, which is denoted as the shared delay, and to analyze the correlation between the shared delay and the current number of security key bits. The security parameter dynamic adjustment unit is used to generate adjustment suggestions for the number of security key bits or automatically perform adjustments based on the frequency and type of violation blocking and whether the shared delay exceeds the standard delay, so as to achieve a dynamic balance between security and performance.
[0012] Furthermore, the safety parameter dynamic adjustment unit includes: The parameter analysis subunit is used to obtain the frequency of preventing violations, which is recorded as the actual violation frequency. The actual violation frequency is then compared with the violation frequency threshold. The first adjustment subunit is used to compare the shared delay with the standard delay in response to the actual violation frequency being less than or equal to the violation frequency threshold, in order to determine whether to reduce the number of security key bits. The second adjustment subunit is used to respond when the actual violation frequency is greater than the violation frequency threshold, analyze the type of violation behavior, and determine whether to increase the number of security key bits.
[0013] Furthermore, the trusted data unit generated by the trusted data encapsulation unit has a structure that includes at least: The data body is used to store the encrypted original data ciphertext; The policy section, logically associated with the data body section, stores access control and usage policies described in machine-executable code or a declarative language; The container section encapsulates lightweight, secure container code that can run independently. This container code contains the functional logic of the environment verification module and the response execution module, which are used to proactively perform verification and policy decisions at the nodes where data arrives.
[0014] Furthermore, the system also includes: The blockchain evidence storage module, connected to the data usage monitoring module, is used to store key security events, policy decision logs, data access audit traces, and security parameter adjustment records in the form of hash values on the blockchain network.
[0015] Compared with existing technologies, the advantages of this invention lie in its ability to dynamically select the security key length based on data sensitivity and real-time network latency, and to encapsulate data and executable policies into trusted data units using attribute-based encryption or proxy re-encryption techniques. When data arrives at the edge node, the environment verification module rigorously verifies the trustworthiness of the node environment through integrity metrics and remote authentication. After successful verification, the response execution module dynamically authorizes the data based on the real-time context before decrypting it for use. Subsequently, the data usage monitoring module continuously audits operational behavior and analyzes shared latency, and based on violation frequency and performance indicators, intelligently decides whether to increase or decrease the security key through the collaboration of the analysis subunit and two adjustment subunits. The system employs a multi-bit architecture to achieve an optimal balance between security and performance. All critical events and decisions are recorded on the blockchain, ensuring the immutability of audit traces. Through a dynamic parameter adjustment mechanism, the system proactively adapts to changes in complex network environments, enhancing defense strength when facing attack risks and optimizing response speed when encountering performance bottlenecks, achieving an adaptive balance between security and utility. Its embedded strategies and proactive verification design ensure that data usage is controlled throughout the entire process, and even if data leaves the source, predefined policies can still be executed, effectively preventing data leakage and tampering. Combined with blockchain evidence storage, it provides non-repudiation and fully traceable security audit capabilities. Overall, it can maintain low latency and high availability while ensuring data integrity and confidentiality. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the structure of a defense system for information security in a trusted data space according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the data encryption module in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of the environmental verification module in an embodiment of the present invention; Figure 4 This is a schematic diagram of the response execution module in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.
[0018] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0019] It should be noted that in the description of this invention, the terms "upper", "lower", "left", "right", "inner", "outer", etc., which indicate directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.
[0020] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0021] Please see Figure 1 As shown, this is a schematic diagram of the structure of a defense system for information security in a trusted data space according to an embodiment of the present invention. The present invention provides a defense system for information security in a trusted data space, comprising: The data encryption module is used to select the number of security key bits according to information security requirements, so as to encrypt and encapsulate the original data according to the number of security key bits and generate a trusted data unit. An environment verification module, which is connected to the data encryption module, is used to perform trusted verification on trusted data units arriving at the edge node, and obtain a first verification result and a second verification result. If the first verification result is obtained, the module selects to refuse to decrypt the data or destroy the data according to the current trusted state. If the verification fails, the first verification result is obtained. If the verification passes, a second verification result is obtained; The response execution module, which is connected to the environment verification module, is used to determine whether to authorize access based on the current context when the second verification result is obtained. The decryption unit uses a pre-agreed key to decrypt data for use by the nodes; The data usage monitoring module, which is connected to the response execution module, is used to monitor the usage behavior and sharing latency during the use process after trusted data is authorized for access, in order to determine whether the security key length needs to be adjusted. The blockchain evidence storage module, connected to the data usage monitoring module, is used to store key security events, policy decision logs, data access audit traces, and security parameter adjustment records in the form of hash values on the blockchain network, ensuring that the logs are tamper-proof and traceable.
[0022] By dynamically selecting the security key length based on data sensitivity and real-time network latency, and employing attribute-based encryption or proxy re-encryption techniques, data and executable policies are encapsulated into trusted data units. When data arrives at the edge node, the environment verification module rigorously verifies the trustworthiness of the node environment through integrity metrics and remote authentication. Only after successful verification does the response execution module dynamically authorize the data based on the real-time context before decrypting it for use. Subsequently, the data usage monitoring module continuously audits operational behavior and analyzes shared latency. Based on violation frequency and performance indicators, and through the collaboration of the analysis subunit and two adjustment subunits, it intelligently decides whether to increase or decrease the security key length to balance security and performance. The system seeks an optimal balance between security and utility, with all critical events and decisions stored on the blockchain to ensure the immutability of audit traces. Through a dynamic parameter adjustment mechanism, the system proactively adapts to changes in complex network environments, enhancing defense strength when facing attack risks and optimizing response speed when encountering performance bottlenecks, achieving an adaptive balance between security and utility. Its embedded strategies and proactive verification design ensure that data usage is controlled throughout the entire process, and even if data leaves the source, predefined policies can still be executed, effectively preventing data leakage and tampering. Combined with blockchain storage, it provides non-repudiation and fully traceable security audit capabilities. Overall, it can maintain low latency and high availability while ensuring data integrity and confidentiality.
[0023] See Figure 2 As shown, it is a structural schematic diagram of the data encryption module in an embodiment of the present invention; Specifically, the data encryption module includes: The security parameter selection unit is used to select the corresponding security key bit length from a plurality of preset security levels according to the information security requirements; The data encryption unit is used to determine the corresponding encryption algorithm parameters based on the selected security key length, and to encrypt the original data using an attribute-based encryption algorithm or a proxy re-encryption algorithm to generate ciphertext. A trusted data encapsulation unit is used to encapsulate the ciphertext, the machine-executable usage policy bound to the data, and a lightweight trusted container into a trusted data unit. The trusted container contains embedded logic for performing subsequent verification and policy execution.
[0024] In this embodiment, a parameter mapping table is provided to map the number of security key bits λ to specific encryption algorithm parameters. For example, for ABE (using bilinear pairing): an elliptic curve group is selected, whose security level matches λ. When λ=112, the BN256 curve (256-bit prime field, providing approximately 112-bit security level) is selected; when λ=128, the BLS12-381 curve (381-bit prime field, providing approximately 128-bit security level) is selected; when λ=192, the BLS24-479 curve (479-bit prime field, providing approximately 192-bit security level) is selected, and so on.
[0025] Based on the curve, determine the bilinear pair e: G1×G2->GT, where G1, G2 and GT are groups with an order of a large prime number p, and the number of bits in p is related to the security level. Other parameters include generators g1∈G1, g2∈G2, and hash functions (which map any string to a group element).
[0026] For PRE (based on bilinear pairing): Similarly, the elliptic curve group matching λ is selected, and bilinear pairs are determined, with similar parameters for generators.
[0027] The encryption process is as follows. The choice of encryption algorithm is determined by the upper-level strategy. For example, if data sharing requires attribute-based access control, then ABE is chosen; if ciphertext conversion is required between different users, then PRE is chosen. The attribute-based encryption (ABE) process is as follows: input raw data M, access policy A (defined by the data owner), and public parameters PK (including elliptic curve group, generator, hash function, etc.); specific steps: a. Randomly select a symmetric encryption key K (to encrypt the actual data); b. Encrypt M with K using a symmetric encryption algorithm (such as AES) to obtain the ciphertext C_sym; c. Use ABE to encrypt K so that only users who meet access policy A can decrypt K; specifically, according to the ABE scheme, embed access policy A into the ciphertext to obtain the encrypted key C_key; d. Output ciphertext: C=(C_sym,C_key,A) or pack both together; The PRE encryption process is as follows: input the original data M, the receiver's public key PK_receiver, and public parameters; specific steps: a. Randomly select a symmetric encryption key K, and encrypt M with K to obtain C_sym; b. Encrypt K using the recipient's public key PK_receiver to obtain C_key. Traditional public key encryption (such as ElGamal) or identity-based encryption (IBE) can be used, depending on the PRE scheme. c. Output the ciphertext: C=(C_sym,C_key) and necessary metadata; Specifically, the security parameter selection unit includes: The initial determination subunit is used to determine the number of bits in the initial security key based on the data attributes. The environment determination subunit is used to determine the current environment based on the end-to-end delay of data transmission. The final selection subunit is used to determine the target security key length based on the current environment and the initial security key length. Information security requirements are determined by the current environment and data attributes.
[0028] Select the appropriate security key length based on your information security requirements.
[0029] In this embodiment, the end-to-end latency is the historical statistical latency, not the actual measured latency of this transmission. Data attributes measure data sensitivity. For monitoring data from IoT devices, which has low sensitivity, a security key length of 112-128 is selected. For user behavior data, which has medium sensitivity, a security key length of 128-192 is selected. For medical / financial data, which has high sensitivity, a security key length of 192-256 is selected. For state secrets / military data, which has extremely high sensitivity, a security key length greater than 256 is selected. The latency threshold refers to the maximum end-to-end latency that the business can tolerate without affecting core functions. Exceeding this threshold will significantly impair user experience, system functionality, or business processes. The latency threshold setting is related to the application scenario. For real-time control systems (industrial IoT, autonomous driving), the latency threshold is set to 10-50 milliseconds. For real-time interactive applications (online games, remote surgery), the latency threshold is set to... For interactive applications (video conferencing, voice calls), the latency threshold is set to 200-500 milliseconds. For ordinary data sharing (file transfer, monitoring data), the latency threshold is set to 500-1000 milliseconds. For batch processing analysis (big data analysis, report generation), the latency threshold is set to 1-5 seconds or longer. For the trusted data sharing system in this embodiment, the latency threshold is set between 200 and 1000 milliseconds, preferably 500 milliseconds. If the end-to-end latency is less than or equal to the latency threshold, the information security requirements are determined directly based on the data attributes. When the end-to-end latency is greater than the latency threshold, the corresponding initial security key bit length is reduced, and the reduction level is determined according to the degree of exceedance. If it is a slight exceedance (500-750ms), it is reduced by one level; if it is a moderate exceedance (750-1000ms), it is reduced by two levels; if it is a severe exceedance (>1000ms), the lowest acceptable level is used, with a security baseline of 96 bits.
[0030] See Figure 3 As shown, it is a structural schematic diagram of the environmental verification module in an embodiment of the present invention; Specifically, the environment verification module includes: The node integrity measurement unit is used to actively measure the software ground state and running process of the edge node in order to calculate the corresponding integrity measurement value. The remote verification unit is used to request and verify the remote verification report issued by the hardware trusted platform module of the edge node. The environment policy verification unit is used to compare the integrity metric value and the remote proof report with the environment requirements specified in the usage policy embedded in the trusted data unit to determine whether the node environment is trustworthy; if it does not meet the requirements, the first verification result is triggered.
[0031] Specifically, the environment policy verification unit includes: The first comparison subunit is used to compare the integrity metric value with the first expected value and analyze whether the actual state is consistent with the expectation. The second comparison subunit is used to compare the hash data in the remote proof report with the second expected value and analyze whether the hash data matches the expectation. The Trust Analysis Subunit is used to determine the trustworthiness of the node environment when the actual state is consistent with the expectation and the hash data matches the expectation. When the actual state is inconsistent with the expectation and / or the hash data does not match the expectation, it triggers the first verification result.
[0032] In this embodiment, in the remote proof report of a node, the hash values of PCR0, PCR2, PCR4, and PCR7 must be equal to a first expected value, which is a specific string of hash values. In the node's integrity metric, the software Merkle root must be equal to a second expected value, which is another specific string of hash values. The remote proof report reflects the hardware and boot chain state, while the integrity metric reflects the current software and process state. For example, the first expected value specified in a medical data TDU policy is: "0": "a1b2 (expected BIOS hash)", "2": "c3d4 (expected firmware hash)", "4": The expected bootloader hash is "e5f6", "7": "1a2b" (expected kernel hash), while the hash data in the node's remote proof report is "0": "a1b2" (actual BIOS hash, consistent with expectation)", "2": "ffff" (actual firmware hash, maliciously tampered with!)", "4": "e5f6" (consistent)", "7": "1a2b" (consistent)". Therefore, the second comparison subunit determines that "c3d4" and "ffff" do not match. The expected system file hash tree root is "f7g8...", and the integrity metric value is "f7g8...". Since the first comparison subunit finds the actual state consistent with the expectation, the trust analysis subunit determines that "c3d4" and "ffff" do not match, proving that the node's firmware may have been maliciously flashed, the environment is untrustworthy, and the first verification result needs to be triggered.
[0033] See Figure 4 As shown, it is a structural schematic diagram of the response execution module in an embodiment of the present invention; Specifically, the response execution module includes: The context evaluation unit is used to collect and evaluate the context information of the current access in real time after obtaining the second verification result. The context information includes at least the requester's identity attributes, access time, geographical location, network environment and node real-time load. The dynamic access control unit is used to perform dynamic policy evaluation based on the context information and the usage policy embedded in the trusted data unit, and to determine whether to authorize access and the scope of authorized operations. The decryption unit is used to decrypt the ciphertext using a key decryption algorithm agreed upon with the data encryption unit only after authorized access, and then provide the plaintext data to the edge node for use.
[0034] Specifically, the data monitoring module includes: The behavior monitoring and auditing unit is used to monitor and record all data operations during the data usage process, including reading, copying, modifying, transmitting and generating derived data, and compare them with the embedded usage policies in real time to detect and prevent violations. The shared delay analysis unit is used to monitor the entire process delay from the issuance of a data request to successful decryption in real time, which is denoted as the shared delay, and to analyze the correlation between the shared delay and the current number of security key bits. The security parameter dynamic adjustment unit is used to generate adjustment suggestions for the number of security key bits or automatically perform adjustments based on the frequency and type of violation blocking and whether the shared delay exceeds the standard delay, so as to achieve a dynamic balance between security and performance.
[0035] Specifically, the dynamic adjustment unit for safety parameters includes: The parameter analysis subunit is used to obtain the frequency of preventing violations, which is recorded as the actual violation frequency. The actual violation frequency is then compared with the violation frequency threshold. The first adjustment subunit is used to compare the shared delay with the standard delay in response to the actual violation frequency being less than or equal to the violation frequency threshold, in order to determine whether to reduce the number of security key bits. The second adjustment subunit is used to respond when the actual violation frequency is greater than the violation frequency threshold, analyze the type of violation behavior, and determine whether to increase the number of security key bits.
[0036] In this embodiment, the violation frequency threshold is set to 5 times / hour, the standard latency is set to 500ms, the minimum security key length is 112, and the maximum security key length is 384. By collecting latency data, the actual violation frequency (times / hour) is calculated. When the actual violation frequency is less than or equal to the violation frequency threshold, a tiered judgment is made based on the degree of latency exceeding the standard. The shared latency is compared with the standard latency. If the latency exceeds the standard by less than 10%, the security key length is reduced by 8 bits; if the latency exceeds the standard by less than 30%, the λ value is reduced by approximately 10%; if the latency exceeds the standard by less than 50%, the λ value is reduced by 15%; if the latency exceeds the standard by more than 50%, a weighted total score is calculated based on the security score and the latency score. The weighted total score = (security score × security weight) + (latency exceedance ratio × latency weight), where the security weight = 0.3 and the latency weight = 0.7. The weighted total score is then adjusted with the threshold of 0.7. In contrast, if the weighted total score is greater than the adjustment threshold, the λ value is not reduced, and an emergency alarm is issued. If the weighted total score is less than or equal to the adjustment threshold, the λ value is reduced by 25%. For example, if the actual latency is 900ms, the weighted total score = (1.0 × 0.3) + (0.8 × 0.7) = 0.3 + 0.56 = 0.86 > the threshold of 0.7, so the focus is on maintaining security and not reducing the λ value. When the actual violation frequency is greater than the violation frequency threshold, the type of violation is analyzed to determine the magnitude of the λ value increase. The types of violation events include cryptography-related (such as data tampering), data protection-related, access control-related (such as unauthorized access), and authentication-related. The increase for cryptography-related violations is 26 bits, for data protection-related violations it is 24 bits, for access control-related violations it is 16 bits, and for authentication-related violations it is 8 bits.
[0037] Specifically, the trusted data unit generated by the trusted data encapsulation unit has a structure that includes at least: The data body is used to store the encrypted original data ciphertext; The policy section, logically associated with the data body section, stores access control and usage policies described in machine-executable code or a declarative language; The container section encapsulates lightweight, secure container code that can run independently. This container code contains some functional logic of the environment verification module and the response execution module, and is used to proactively perform verification and policy decisions at the node where the data arrives.
[0038] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A defense system for information security in a trusted data space, characterized in that, include: The data encryption module is used to select the number of security key bits according to information security requirements, so as to encrypt and encapsulate the original data according to the number of security key bits and generate a trusted data unit. An environment verification module, which is connected to the data encryption module, is used to perform trusted verification on trusted data units arriving at the edge node and obtain a first verification result or a second verification result. If the first verification result is obtained, the module selects to refuse to decrypt the data or destroy the data based on the current trusted state. The response execution module, which is connected to the environment verification module, is used to determine whether to authorize access based on the current context when the second verification result is obtained. The data usage monitoring module, which is connected to the response execution module, is used to monitor usage behavior and sharing latency during the process of trusted data authorization access in order to determine whether the security key length needs to be adjusted.
2. The information security defense system for trusted data space according to claim 1, characterized in that, The data encryption module includes: The security parameter selection unit is used to select the corresponding security key bit length from a plurality of preset security levels according to the information security requirements; The data encryption unit is used to determine the corresponding encryption algorithm parameters based on the selected security key length, and to encrypt the original data using an attribute-based encryption algorithm or a proxy re-encryption algorithm to generate ciphertext. A trusted data encapsulation unit is used to encapsulate the ciphertext, the machine-executable usage policy bound to the data, and a lightweight trusted container into a trusted data unit. The trusted container contains embedded logic for performing subsequent verification and policy execution.
3. The information security defense system for trusted data space according to claim 2, characterized in that, The safety parameter selection unit includes: The initial determination subunit is used to determine the number of bits in the initial security key based on the data attributes. The environment determination subunit is used to determine the current environment based on the end-to-end delay of data transmission. The final selection sub-unit is used to determine the target security key length based on the current environment and the initial security key length.
4. The information security defense system for trusted data space according to claim 1, characterized in that, The environment verification module includes: The node integrity measurement unit is used to actively measure the software ground state and running process of the edge node in order to calculate the corresponding integrity measurement value. The remote verification unit is used to request and verify the remote verification report issued by the hardware trusted platform module of the edge node. The environment policy verification unit is used to compare the integrity metric value and the remote proof report with the environment requirements specified in the usage policy embedded in the trusted data unit to determine whether the node environment is trustworthy; if it does not meet the requirements, the first verification result is triggered.
5. The information security defense system for trusted data space according to claim 4, characterized in that, The environment policy verification unit includes: The first comparison subunit is used to compare the integrity metric value with the first expected value and analyze whether the actual state is consistent with the expectation. The second comparison subunit is used to compare the hash data in the remote proof report with the second expected value and analyze whether the hash data matches the expectation. The Trust Analysis Subunit is used to determine the trustworthiness of the node environment when the actual state is consistent with the expectation and the hash data matches the expectation. When the actual state is inconsistent with the expectation and / or the hash data does not match the expectation, it triggers the first verification result.
6. The information security defense system for trusted data space according to claim 1, characterized in that, The response execution module includes: The context evaluation unit is used to collect and evaluate the context information of the current access in real time after obtaining the second verification result. The context information includes at least the requester's identity attributes, access time, geographical location, network environment and node real-time load. The dynamic access control unit is used to perform dynamic policy evaluation based on the context information and the usage policy embedded in the trusted data unit, and to determine whether to authorize access and the scope of authorized operations. The decryption unit is used to decrypt the ciphertext using a key decryption algorithm agreed upon with the data encryption unit only after authorized access, and then provide the plaintext data to the edge node for use.
7. The information security defense system for trusted data space according to claim 6, characterized in that, The data monitoring module includes: The behavior monitoring and auditing unit is used to monitor and record all data operations during the data usage process, including reading, copying, modifying, transmitting and generating derived data, and compare them with the embedded usage policies in real time to detect and prevent violations. The shared delay analysis unit is used to monitor the entire process delay from the issuance of a data request to successful decryption in real time, which is denoted as the shared delay, and to analyze the correlation between the shared delay and the current number of security key bits. The security parameter dynamic adjustment unit is used to generate adjustment suggestions for the number of security key bits or automatically perform adjustments based on the frequency and type of blocking violations and whether the shared delay exceeds the standard delay, so as to achieve a dynamic balance between security and performance.
8. The information security defense system for trusted data space according to claim 7, characterized in that, The safety parameter dynamic adjustment unit includes: The parameter analysis subunit is used to obtain the frequency of preventing violations, which is recorded as the actual violation frequency. The actual violation frequency is then compared with the violation frequency threshold. The first adjustment subunit is used to compare the shared delay with the standard delay in response to the actual violation frequency being less than or equal to the violation frequency threshold, in order to determine whether to reduce the number of security key bits. The second adjustment subunit is used to respond when the actual violation frequency is greater than the violation frequency threshold, analyze the type of violation behavior, and determine whether to increase the number of security key bits.
9. The information security defense system for trusted data space according to claim 2, characterized in that, The trusted data unit generated by the trusted data encapsulation unit has a structure that includes at least: The data body is used to store the encrypted original data ciphertext; The policy section, logically associated with the data body section, stores access control and usage policies described in machine-executable code or a declarative language; The container section encapsulates lightweight, secure container code that can run independently. This container code contains the functional logic of the environment verification module and the response execution module, which are used to proactively perform verification and policy decisions at the nodes where data arrives.
10. The information security defense system for trusted data space according to claim 1, characterized in that, The system also includes: The blockchain evidence storage module, connected to the data usage monitoring module, is used to store key security events, policy decision logs, data access audit traces, and security parameter adjustment records in the form of hash values on the blockchain network.
Citation Information
Patent Citations
Network information security defense detection method and system
CN119854025A
Payment method based on NFC electronic tag
CN119295071A
Industrial internet data security access method and device based on cloud edge collaboration
CN119628976A
Distributed data security protection system based on Internet of Things nodes
CN119766556A
Network information data transmission security method based on advanced encryption standard (AES)
CN120498646A