Data security transmission method and system based on multiple encryption
By preprocessing the data to generate multiple transmission components, dynamically adjusting encryption parameters, and constructing an associated structure, the security deficiency of single-layer encryption is solved, and the security and efficiency of data transmission with multiple encryption are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUANENG INFORMATION TECH CO LTD
- Filing Date
- 2025-11-27
- Publication Date
- 2026-04-17
AI Technical Summary
In existing technologies, single-layer encryption methods have insufficient security, cannot cope with the challenges of new computing models such as quantum computing, and cannot provide differentiated security protection. They also have a high risk of key leakage, resulting in low data transmission security and efficiency.
By preprocessing the original data to be transmitted to generate multiple transmission sub-components, analyzing the data content of each sub-component, dynamically adjusting encryption parameters, constructing a first-level association structure and encryption evaluation model, and generating multiple encryption transmission strategies, the security and efficiency of encrypted data transmission are improved.
Multiple encryptions are implemented for data transmission, improving data transmission security and receiver processing efficiency.
Smart Images

Figure CN121887433A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data transmission technology, and in particular to a data security transmission method and system based on multiple encryption. Background Technology
[0002] With the rapid development of internet technology, data transmission on public networks is becoming increasingly frequent, and its security issues are becoming more and more prominent. Currently, the mainstream technical means to ensure data transmission security generally rely on single-layer encryption systems, that is, using a single algorithm to encrypt the data once.
[0003] However, this single encryption method inherently carries security risks. First, with the rapid advancement of computing power, especially the development of new computing models such as quantum computing, the strength of traditional encryption algorithms is facing severe challenges. Once an encryption algorithm is cracked, the security barrier of the entire transmission process will collapse instantly, resulting in complete data leakage. Second, when dealing with different types of sensitive data, a single encryption strength cannot provide differentiated security protection commensurate with the value of the data. Furthermore, existing methods have limited ability to address the risk of key leakage; once the session key is stolen, all encrypted data can be decrypted. Summary of the Invention
[0004] The purpose of this application is to provide a data security transmission method and system based on multiple encryption to solve the above-mentioned technical problems, aiming to improve the efficiency and security of data encryption transmission.
[0005] In some embodiments of this application, multiple transmission sub-components are generated by preprocessing the original data to be transmitted. Based on the analysis of the data content of each transmission sub-component, the encryption parameters are dynamically adjusted to achieve multiple encryption of the original data to be transmitted, thereby improving the security of encrypted data transmission.
[0006] In some embodiments of this application, after aggregating all transmission sub-components, a verification structure for each sub-component set is constructed using a first-level association structure to generate corresponding transmission packets, thereby improving the efficiency of encrypted data transmission and the efficiency of the receiver in processing encrypted data. At the same time, the security of encrypted data transmission is improved through the relevant verification relationships between each transmission packet.
[0007] In some embodiments of this application, a data security transmission method based on multiple encryption is provided, including: Multiple transmission sub-components are generated based on the data to be transmitted, and a first-level association structure is set based on all transmission sub-components. Construct an encryption evaluation model, and generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components; The transmission record packet is obtained according to the preset update time node, and the encryption evaluation model is determined based on the transmission record packet. This involves generating multiple transmission sub-components, including: Establish a sequence of transmission sub-components A, A=(a1, a2, ..., a3) i …a n ), where a i Let be the i-th transmission sub-component; n is the number of transmission sub-components.
[0008] In some embodiments of this application, the cryptographic evaluation model is constructed, including: Construct an evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. b is set sequentially based on the data evaluation value interval B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
[0009] In some embodiments of this application, a first-level association structure is constructed, including: The fusion nodes for each transmission sub-component are set sequentially according to the sequence of transmission sub-components; Construct a fusion substructure based on all fusion nodes; Generate the first-level hash value for each transmission sub-component; A first-level associative structure is generated based on all first-level hash values and the merged substructures.
[0010] In some embodiments of this application, the generation of a first-level transmission strategy includes: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.
[0011] In some embodiments of this application, generating the data evaluation value b of the target transmission sub-component includes: b=e*[ β i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; vi is the association value between the target transmission sub-component and the i-th transmission sub-component.
[0012] In some embodiments of this application, generating the first-level transport packets for each subset includes: Establish a sequence of subsets W, W = (w1, w2, ..., w2) i …w n1 ), where w i Let n1 be the i-th subset; n1 is the number of subsets. Based on the sequence of child sets W, wi is sequentially set as the target child set; Obtain the first-level evaluation value of the target subset; The first-level encryption model for the target subset is set based on the first-level evaluation value and the encryption processing model; Generate a sequence of first-level sub-components A1, A1=(a 11 a 12 …a 1i …a 1n2 ), where a 1i n1 represents the i-th first-level sub-component in the target sub-component set; n2 represents the number of first-level sub-components. The encrypted sub-packets of each primary component are generated sequentially according to the primary encryption model; Based on the first-level evaluation value, the number of first-level sub-components n2, and the first-level association structure, the sub-verification structure of the target sub-component set is set. Set the secondary transmission order of the target subset; The first-level transport packet of the target subset is generated based on all encrypted sub-packets, sub-verification structures, and the second-level transport order.
[0013] In some embodiments of this application, determining whether to modify the encryption evaluation model based on the transmission record packet includes: Establish a cryptographic sub-model sequence H, H=(h1, h2…h i …h m), where h i Let m be the encrypted sub-model corresponding to the i-th data evaluation value interval; m is the number of data evaluation value intervals. Obtain transmission record packets according to preset update time nodes; The operational risk values of each encryption sub-model are generated sequentially based on the transmission record packets; Establish a sequence of operational risk values F, F = (f1, f2, ..., f i …f m ), where f i Let m be the i-th operational risk value; m is the number of data evaluation value intervals. Preset operational risk threshold F1; If f i >F1, generates the first-level correction instruction for the i-th encryption sub-model; Generate an updated evaluation value d based on the operational risk value sequence F; Preset update evaluation value threshold D1; If d > D1, generate a second-level correction instruction.
[0014] In some embodiments of this application, generating the updated evaluation value d includes: d=g*[ η i *j i ]; g=U2*[ µ i *f i ]; Where g is the update compensation coefficient; θ2 is the number of transmission monitoring indicators; η i Let j be the influencing factor of the i-th transmission monitoring index; i It is the reference value of the i-th transmission monitoring index generated based on the transmission record packet; U2 is the preset second conversion coefficient; µ i f is the influence factor of the i-th encryption sub-model; i Let be the i-th operational risk value; m is the number of data evaluation value intervals.
[0015] In some embodiments of this application, a data security transmission system based on multiple encryption is provided, including: The central control unit is used to generate multiple transmission sub-components based on the data to be transmitted; Encryption unit, used to construct encryption evaluation model; The update unit is used to obtain the transmission record packet according to the preset update time node, and to determine whether to correct the encryption evaluation model based on the transmission record packet. The central control unit includes: The first processing module is used to generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components. The second processing module is used to establish the sequence of transmission sub-components A, A=(a1, a2…a…). i …a n ), where a i This represents the i-th transmission sub-device; n is the number of transmission sub-devices. The third processing module is used to set the first-level association structure based on all transmission sub-components; The encryption unit includes: The first encryption module is used to construct the evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. The second encryption module is used to sequentially set b according to the data evaluation value range B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
[0016] In some embodiments of this application, the first processing module is further configured to: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; b=e*[ β i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; vi is the association value between the target transmission sub-component and the i-th transmission sub-component; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.
[0017] Compared with the prior art, the data security transmission method and system based on multiple encryption proposed in this application have the following advantages: By preprocessing the original data to be transmitted to generate multiple transmission sub-components, and analyzing the data content of each transmission sub-component, the encryption parameters are dynamically adjusted to achieve multiple encryption of the original data to be transmitted, thereby improving the security of encrypted data transmission.
[0018] After aggregating all transmission sub-components, a verification structure for each sub-component set is constructed using a first-level association structure, generating corresponding transmission packets. This improves the efficiency of encrypted data transmission and the efficiency of the receiver in processing encrypted data. At the same time, the security of encrypted data transmission is enhanced through the relevant verification relationships between each transmission packet. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating a preferred embodiment of a data security transmission method based on multiple encryption in this application. Detailed Implementation
[0020] The specific embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate this application, but are not intended to limit the scope of this application.
[0021] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0022] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0023] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0024] like Figure 1 As shown, a preferred embodiment of this application provides a data security transmission method based on multiple encryption, comprising: S101: Generate multiple transmission sub-components based on the data to be transmitted, and set a first-level association structure based on all transmission sub-components; S102: Construct an encryption evaluation model and generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components; S103: Obtain the transmission record packet according to the preset update time node, and determine whether to correct the encryption evaluation model based on the transmission record packet; This involves generating multiple transmission sub-components, including: Establish a sequence of transmission sub-components A, A=(a1, a2, ..., a3) i …a n ), where a i Let be the i-th transmission sub-component; n is the number of transmission sub-components.
[0025] Specifically, it determines whether each user point has a data transmission requirement; if so, it retrieves the data to be transmitted for the corresponding user point.
[0026] Specifically, the data to be transmitted is segmented to generate multiple sub-components to be transmitted. The segmentation rule is to set a data volume threshold for each sub-component and then uniformly divide the data to be transmitted according to the set data volume threshold, so that the data volume in each sub-component is less than the data volume threshold. The data volume threshold can be set according to historical parameters.
[0027] Specifically, constructing an encrypted evaluation model includes: Construct an evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. b is set sequentially based on the data evaluation value interval B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
[0028] Specifically, the data evaluation values are evenly divided according to their range to generate multiple data evaluation value intervals. The number of intervals can be set based on historical parameters, and there is no overlap between the various data evaluation value intervals.
[0029] Specifically, by analyzing historical transmission data, various keywords (i.e., features of important data in the current communication system) are generated, thereby constructing a keyword library, and a corresponding evaluation sub-model is constructed based on semantic parsing technology and the keyword library.
[0030] Specifically, the evaluation sub-model can parse and analyze the data content within a single transmission sub-component to generate a data evaluation value for that transmission sub-component. The higher the data evaluation value, the more important the data content within that transmission sub-component is, and the more complex security encryption strategies need to be adopted.
[0031] Specifically, by analyzing the relevant transmission packets within the target evaluation value range (i.e., the data evaluation values of the transmission sub-components within the transmission packet are within the target evaluation value range), the optimal encryption parameters (including the number of encryption layers, encryption algorithm type, and encryption order) are selected, and the corresponding encryption sub-model is constructed based on these encryption parameters.
[0032] Specifically, when optimizing encryption parameters within the target evaluation value range, it is necessary to first set corresponding efficiency weights and security weights based on the target evaluation value range (the sum of the two is 1; the larger the median of the target evaluation value range, the larger the security weight; the mapping relationship between the two can be set based on historical parameters). By analyzing the encryption parameters of each relevant transmission packet, a weighted processing result is generated for efficiency (a first reference value generated based on transmission efficiency; the higher the transmission efficiency, the larger the corresponding first reference value) and security (a second reference value generated based on the data leakage ratio of relevant transmission packets; the larger the leakage ratio, the larger the corresponding second reference value). Based on the weighted processing result, a running evaluation value is generated. The larger the running evaluation value, the more suitable the corresponding encryption parameters are for encryption operations of transmitted files within the target evaluation value range.
[0033] Specifically, the less runtime resources the encryption and decryption processes consume, the higher the transmission efficiency, and the first and second reference values have the same range.
[0034] It is understood that in the above embodiments, multiple transmission sub-components are generated by preprocessing the original data to be transmitted, and encryption parameters are dynamically adjusted based on the analysis of the data content of each transmission sub-component, thereby achieving multiple encryption of the original data to be transmitted and improving the security of encrypted data transmission.
[0035] In a preferred embodiment of this application, the construction of a first-level association structure includes: The fusion nodes for each transmission sub-component are set sequentially according to the sequence of transmission sub-components; Construct a fusion substructure based on all fusion nodes; Generate the first-level hash value for each transmission sub-component; A first-level associative structure is generated based on all first-level hash values and the merged substructures.
[0036] Specifically, corresponding fusion nodes are set according to the position of each transmission sub-component in the data to be transmitted, and a fusion substructure is constructed based on all fusion nodes. Through the fusion substructure, the receiver can splice and fuse all transmission sub-components.
[0037] Specifically, the data content of each transmitted sub-component is hashed to generate a corresponding first-level hash value (i.e., the hash value of the data content within the transmitted sub-component). Each first-level hash value is then combined with the corresponding fusion node in the fusion substructure to generate a first-level association structure. Through this first-level association structure, the receiver can verify the decrypted data content of each transmitted sub-component.
[0038] In a preferred embodiment of this application, the generation of a first-level transmission strategy includes: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.
[0039] Specifically, the encryption sub-model corresponding to the data evaluation value with the smallest median value in the data evaluation value range is used to process the first-level association structure and generate the second-level transmission packet (that is, the simplest encryption method is used for the first-level association structure).
[0040] Specifically, the second-level transmission packets are transmitted first, and the remaining first-level transmission packets are sent in descending order of the median of the corresponding data evaluation value interval. The higher the median, the earlier the transmission packet occurs. The first-level transmission order is generated according to the above rules, and the corresponding first-level transmission strategy is generated according to the first-level transmission order.
[0041] Specifically, based on a preset data evaluation value range sequence, each transmission sub-component within the same data evaluation value range is aggregated, and multiple sub-component sets are generated based on the aggregation results.
[0042] Specifically, a single subset includes at least one transmission subset, and the data evaluation values of all transmission subsets within a single subset are within the same data evaluation value range.
[0043] Specifically, the data evaluation value b for generating the target transmission sub-component includes: b=e*[ β i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; v i The association value between the target transmission sub-component and the i-th transmission sub-component.
[0044] Specifically, by presetting a first fixed coefficient, the evaluation compensation coefficient is kept within a preset value range, and [ v i The larger the value of ], the larger the corresponding evaluation compensation coefficient. The mapping relationship between the two can be set according to historical parameters, and the value of the evaluation compensation coefficient is always greater than 1.
[0045] Specifically, the evaluation metrics include, but are not limited to, multiple parameters reflecting the importance of the data, such as keyword quantity, keyword category, primary data entropy value (the less duplicate content within a transmission sub-component, the higher the corresponding primary data entropy value), and secondary data entropy value (the less duplicate content between a transmission sub-component and the remaining transmission sub-components, the higher the corresponding secondary data entropy value). By quantifying each evaluation metric, the reference values for each data evaluation metric are made to fall within the same range.
[0046] Specifically, the higher the reference value of each evaluation indicator, the more important the data content in the target transmission sub-component.
[0047] Specifically, the larger the data evaluation value, the more important the data content within the target transmission sub-component, and the more complex the corresponding encryption process, thereby ensuring the security of the data within the target transmission sub-component.
[0048] Specifically, the impact factors for each evaluation indicator are set based on their correlation with the importance of the data; the greater the correlation, the larger the value of the corresponding impact factor. The mapping relationship between the two can be set based on historical parameters.
[0049] Specifically, by evaluating the sub-model, the data content of each transmission sub-component is analyzed to generate the correlation degree of the data content within each transmission sub-component. The greater the correlation degree, the greater the corresponding correlation value. The mapping relationship between the two can be set according to historical parameters.
[0050] In a preferred embodiment of this application, generating the first-level transmission packets for each subset includes: Establish a sequence of subsets W, W = (w1, w2, ..., w2) i …w n1 ), where w i Let n1 be the i-th subset; n1 is the number of subsets. Based on the sequence of child sets W, wi is sequentially set as the target child set; Obtain the first-level evaluation value of the target subset; The first-level encryption model for the target subset is set based on the first-level evaluation value and the encryption processing model; Generate a sequence of first-level sub-components A1, A1=(a 11 a 12 …a 1i …a 1n2 ), where a 1i n1 represents the i-th first-level sub-component in the target sub-component set; n2 represents the number of first-level sub-components. The encrypted sub-packets of each primary component are generated sequentially according to the primary encryption model; Based on the first-level evaluation value, the number of first-level sub-components n2, and the first-level association structure, the sub-verification structure of the target sub-component set is set. Set the secondary transmission order of the target subset; The first-level transport packet of the target subset is generated based on all encrypted sub-packets, sub-verification structures, and the second-level transport order.
[0051] Specifically, the median of the data evaluation value range corresponding to the target subset is set as the first-level evaluation value of the target subset.
[0052] Specifically, the sub-verification structure includes the hash value of the first-level association structure and the hash value of the first-level evaluation value of the target subset. The receiver prioritizes receiving the second-level transmission packet to obtain the specific parameters and hash value of the first-level association structure. When receiving the first-level transmission packet in a subsequent manner, the receiver uses the hash value of the first-level association structure to determine whether the current first-level transmission packet has been tampered with, and uses the hash value of the first-level evaluation value to determine the encryption sub-model corresponding to each encrypted sub-packet in the current first-level transmission packet, thereby generating the corresponding decryption strategy and improving data transmission and processing efficiency.
[0053] Specifically, after the receiver decrypts all encrypted sub-components in the first-level transmission packet, it uses the first-level association structure to verify each encrypted sub-component. (First, a verification hash value is generated from the content generated after decrypting a single transmission sub-component. Then, bidirectional verification is performed based on the hash value stored in the first-level association structure for that transmission sub-component. If there are no errors, the transmission sub-component is merged with the remaining transmission files based on the fusion node corresponding to it.) This improves the security and processing efficiency of data transmission.
[0054] Specifically, the encryption sub-model for the data evaluation value range corresponding to the target sub-set is defined as the first-level encryption model. Based on the encryption parameters built into the first-level encryption model, each transmission sub-set in the target sub-set is encrypted sequentially, thereby generating encrypted sub-packets for each first-level sub-set.
[0055] Specifically, each transmission sub-component in the target sub-component set is designated as a first-level sub-component.
[0056] It is understood that in the above embodiments, after aggregating all transmission sub-components, the verification structure of each sub-component set is constructed using the first-level association structure, and the corresponding transmission packets are generated, thereby improving the efficiency of data encryption transmission and the efficiency of the receiver in processing encrypted data. At the same time, the security of data encryption transmission is improved through the relevant verification relationship between each transmission packet.
[0057] In a preferred embodiment of this application, determining whether to modify the encryption evaluation model based on the transmission record packet includes: Establish a cryptographic sub-model sequence H, H=(h1, h2…h i …h m ), where h i Let m be the encrypted sub-model corresponding to the i-th data evaluation value interval; m is the number of data evaluation value intervals. Obtain transmission record packets according to preset update time nodes; The operational risk values of each encryption sub-model are generated sequentially based on the transmission record packets; Establish a sequence of operational risk values F, F = (f1, f2, ..., f i …f m ), where f iLet m be the i-th operational risk value; m is the number of data evaluation value intervals. Preset operational risk threshold F1; If f i >F1, generates the first-level correction instruction for the i-th encryption sub-model; Generate an updated evaluation value d based on the operational risk value sequence F; Preset update evaluation value threshold D1; If d > D1, generate a second-level correction instruction.
[0058] Specifically, the operational risk threshold can be set based on historical parameters. If the operational risk value of the current encryption sub-model is greater than the preset operational risk threshold, it indicates that the security of the current encryption sub-model is poor and needs to be optimized and corrected in a timely manner (including but not limited to adding encryption algorithms and updating the running order of each algorithm).
[0059] Specifically, by analyzing the attack parameters (data tampering amount, number of leaks, and leakage frequency) of the encrypted sub-packets processed by each encryption sub-model, a corresponding initial risk value is set. The more severe the comprehensive analysis results of the attack parameters, the greater the corresponding initial risk value. The mapping relationship between the two can be set based on historical parameters.
[0060] Specifically, a corresponding compensation risk coefficient is set based on the median of the data evaluation value range corresponding to each encryption sub-model. The larger the median, the larger the corresponding risk compensation coefficient. The mapping relationship between the two can be set based on historical parameters. Furthermore, the value of the compensation risk coefficient is always greater than 1.
[0061] Specifically, the update evaluation value threshold can be set based on historical parameters. If the update evaluation value is greater than the preset update evaluation value threshold, it indicates that the current encryption evaluation model has a large operational deviation, which reduces the overall data transmission security of the system and requires timely optimization of the current encryption evaluation model.
[0062] Specifically, generating the updated evaluation value d includes: d=g*[ η i *j i ]; g=U2*[ µ i *f i ]; Where g is the update compensation coefficient; θ2 is the number of transmission monitoring indicators; η i Let j be the influencing factor of the i-th transmission monitoring index; i It is the reference value of the i-th transmission monitoring index generated based on the transmission record packet; U2 is the preset second conversion coefficient; µ if is the influence factor of the i-th encryption sub-model; i Let be the i-th operational risk value; m is the number of data evaluation value intervals.
[0063] Specifically, transmission monitoring indicators include, but are not limited to, multiple parameters that reflect data transmission efficiency, such as average data encryption time, average data decryption time, average transmission resource usage, and average computing resource usage. By quantifying each transmission monitoring indicator, the reference values of each transmission monitoring indicator are made to be within the same range.
[0064] Specifically, the higher the reference value of each transmission monitoring indicator, the worse the overall data transmission efficiency within the current system.
[0065] Specifically, the influencing factors of each transmission monitoring indicator can be set according to the degree of correlation with data transmission efficiency. The greater the correlation, the larger the reference value of the corresponding influencing factor. The mapping relationship between the two can be set according to historical parameters.
[0066] Specifically, by presetting a second conversion coefficient, the update compensation coefficient is always kept within a preset value range, and [ µ i *f i The larger the value of ], the larger the value of the update compensation coefficient g. The mapping relationship between the two can be set according to historical parameters, and the value range of the update compensation coefficient g is always greater than 1.
[0067] Specifically, the corresponding influence factor is set according to the median of the data evaluation value range corresponding to each encryption sub-model. The larger the median, the larger the corresponding influence factor. The mapping relationship between the two can be set according to historical parameters.
[0068] In another preferred embodiment of the data security transmission method based on multiple encryption based on any of the above preferred embodiments, this preferred embodiment provides a data security transmission system based on multiple encryption, including: The central control unit is used to generate multiple transmission sub-components based on the data to be transmitted; Encryption unit, used to construct encryption evaluation model; The update unit is used to obtain the transmission record packet according to the preset update time node, and to determine whether to correct the encryption evaluation model based on the transmission record packet. The central control unit includes: The first processing module is used to generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components. The second processing module is used to establish the sequence of transmission sub-components A, A=(a1, a2…a…). i …a n ), where a iThis represents the i-th transmission sub-device; n is the number of transmission sub-devices. The third processing module is used to set the first-level association structure based on all transmission sub-components; The encryption unit includes: The first encryption module is used to construct the evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. The second encryption module is used to sequentially set b according to the data evaluation value range B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
[0069] In a preferred embodiment of this application, the first processing module is further configured to: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; b=e*[ β i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; vi is the association value between the target transmission sub-component and the i-th transmission sub-component; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.
[0070] According to the first concept of this application, multiple transmission sub-components are generated by preprocessing the original data to be transmitted. Based on the analysis of the data content of each transmission sub-component, the encryption parameters are dynamically adjusted to achieve multiple encryption of the original data to be transmitted, thereby improving the security of encrypted data transmission.
[0071] According to the second concept of this application, after aggregating all transmission sub-components, a verification structure for each sub-component set is constructed using a first-level association structure to generate corresponding transmission packets, thereby improving the efficiency of encrypted data transmission and the efficiency of the receiver in processing encrypted data. At the same time, the security of encrypted data transmission is improved through the relevant verification relationships between each transmission packet.
[0072] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and substitutions can be made without departing from the technical principles of this application, and these improvements and substitutions should also be considered within the scope of protection of this application.
Claims
1. A data security transmission method based on multiple encryption, characterized in that, include: Multiple transmission sub-components are generated based on the data to be transmitted, and a first-level association structure is set based on all transmission sub-components. Construct an encryption evaluation model, and generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components; The transmission record packet is obtained according to the preset update time node, and the encryption evaluation model is determined based on the transmission record packet. This involves generating multiple transmission sub-components, including: Establish a sequence of transmission sub-components A, A=(a1, a2, ..., a3) i …a n ), where a i Let be the i-th transmission sub-component; n is the number of transmission sub-components.
2. The data security transmission method based on multiple encryption as described in claim 1, characterized in that, Constructing an encrypted evaluation model, including: Construct an evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. b is set sequentially based on the data evaluation value interval B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
3. The data security transmission method based on multiple encryption as described in claim 2, characterized in that, Constructing a first-level relational structure includes: The fusion nodes for each transmission sub-component are set sequentially according to the sequence of transmission sub-components; Construct a fusion substructure based on all fusion nodes; Generate the first-level hash value for each transmission sub-component; A first-level associative structure is generated based on all first-level hash values and the merged substructures.
4. The data security transmission method based on multiple encryption as described in claim 3, characterized in that, Generate a primary transmission policy, including: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.
5. The data security transmission method based on multiple encryption as described in claim 4, characterized in that, The data evaluation value b for the target transmission sub-component is generated, including: b=e*[ b i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; vi is the association value between the target transmission sub-component and the i-th transmission sub-component.
6. The data security transmission method based on multiple encryption as described in claim 4, characterized in that, Generate the first-level transport packets for each subset, including: Establish a sequence of subsets W, W = (w1, w2, ..., w2) i …w n1 ), where w i Let n1 be the i-th subset; n1 is the number of subsets. Based on the sequence of child sets W, wi is sequentially set as the target child set; Obtain the first-level evaluation value of the target subset; The first-level encryption model for the target subset is set based on the first-level evaluation value and the encryption processing model; Generate a sequence of first-level sub-components A1, A1=(a 11 a 12 …a 1i …a 1n2 ), where a 1i n1 represents the i-th first-level sub-component in the target sub-component set; n2 represents the number of first-level sub-components. The encrypted sub-packets of each primary component are generated sequentially according to the primary encryption model; Based on the first-level evaluation value, the number of first-level sub-components n2, and the first-level association structure, the sub-verification structure of the target sub-component set is set. Set the secondary transmission order of the target subset; The first-level transport packet of the target subset is generated based on all encrypted sub-packets, sub-verification structures, and the second-level transport order.
7. The data security transmission method based on multiple encryption as described in claim 6, characterized in that, Determining whether to modify the encryption evaluation model based on the transmitted record packets includes: Establish a cryptographic sub-model sequence H, H=(h1, h2…h i …h m ), where h i Let m be the encrypted sub-model corresponding to the i-th data evaluation value interval; m is the number of data evaluation value intervals. Obtain transmission record packets according to preset update time nodes; The operational risk values of each encryption sub-model are generated sequentially based on the transmission record packets; Establish a sequence of operational risk values F, F = (f1, f2, ..., f i …f m ), where f i Let m be the i-th operational risk value; m is the number of data evaluation value intervals. Preset operational risk threshold F1; If f i >F1, generates the first-level correction instruction for the i-th encryption sub-model; Generate an updated evaluation value d based on the operational risk value sequence F; Preset update evaluation value threshold D1; If d > D1, generate a second-level correction instruction.
8. The data security transmission method based on multiple encryption as described in claim 7, characterized in that, Generate an updated evaluation value d, including: d=g*[ η i *j i ]; g=U2*[ µ i *f i ]; Where g is the update compensation coefficient; θ2 is the number of transmission monitoring indicators; η i Let j be the influencing factor of the i-th transmission monitoring index; i It is the reference value of the i-th transmission monitoring index generated based on the transmission record packet; U2 is the preset second conversion coefficient; µ i f is the influence factor of the i-th encryption sub-model; i Let be the i-th operational risk value; m is the number of data evaluation value intervals.
9. A data security transmission system based on multiple encryption, employing the data security transmission method based on multiple encryption as described in any one of claims 1-8, characterized in that, include: The central control unit is used to generate multiple transmission sub-components based on the data to be transmitted; Encryption unit, used to construct encryption evaluation model; The update unit is used to obtain the transmission record packet according to the preset update time node, and to determine whether to correct the encryption evaluation model based on the transmission record packet. The central control unit includes: The first processing module is used to generate a primary transmission strategy based on the encryption evaluation model and all transmission sub-components. The second processing module is used to establish the sequence of transmission sub-components A, A=(a1, a2…a…). i …a n ), where a i This represents the i-th transmission sub-device; n is the number of transmission sub-devices. The third processing module is used to set the first-level association structure based on all transmission sub-components; The encryption unit includes: The first encryption module is used to construct the evaluation sub-model; Multiple data evaluation value ranges are set based on the evaluation sub-model; Establish a data evaluation value interval sequence B, B=(b1,b2…b i …b m ), where b i Let m be the interval for evaluating the i-th data value; m is the number of data evaluation value intervals. The second encryption module is used to sequentially set b according to the data evaluation value range B. i The target evaluation value range; An encryption sub-model is defined based on a preset encryption strategy library, specifying the target evaluation value range. Sequentially set up encrypted sub-models for each data evaluation value range; Construct an encryption processing model based on all encryption sub-models; An encryption evaluation model is generated based on the encryption processing model and the evaluation sub-model.
10. The data security transmission system based on multiple encryption as described in claim 9, characterized in that, The first processing module is also used for: Based on the sequence of transmission sub-components A, set a sequentially. i Transmit sub-components to the target; Generate the data evaluation value b of the target transmission sub-component based on the evaluation sub-model; b=e*[ b i *s i ]; e=U1*[ v i ]; Where e is the evaluation compensation coefficient; θ1 is the number of evaluation indicators; β i Let s be the influence factor of the i-th evaluation indicator; i It is a reference value for generating the i-th evaluation index based on the target transmission sub-component; U1 is a preset first conversion coefficient; vi is the association value between the target transmission sub-component and the i-th transmission sub-component; Generate data evaluation values for each transmission sub-component in sequence; All transmission sub-components are aggregated, and multiple sub-component sets are generated based on the aggregation results. The first-level transmission packets for each subset are generated sequentially according to the encryption processing model; Generate secondary transmission packets based on the encryption processing model and the primary association structure; A first-level transmission strategy is generated based on the second-level transmission packets and all first-level transmission packets.