Security encryption processing method and system for wireless access area control instruction

By conducting multi-dimensional risk quantification analysis and dynamic encryption strategy matching of the wireless access area communication link, the problem of mismatch between encryption strength and transmission stability in the wireless access area was solved, and stable and secure control command transmission was achieved in complex environments.

CN121968091APending Publication Date: 2026-05-01SHENYANG BOLAI DEZI ELECTRONIC TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENYANG BOLAI DEZI ELECTRONIC TECH CO LTD
Filing Date
2026-01-26
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, the encryption strength of the wireless access zone does not match the transmission stability, making it unable to respond effectively in complex, multi-source interference environments, resulting in unstable transmission of control commands.

Method used

By acquiring multi-dimensional network status data of wireless access area communication links, risk quantification analysis is performed, threat factors are extracted and grouped by region, risk levels are identified, encryption strategies and parameters are dynamically matched, and data packet fragmentation mode and checksum rules are optimized to ensure stable transmission in complex environments.

Benefits of technology

It enables fine-grained identification and accurate differentiation of potential threats, dynamically adjusts encryption strength to match risk levels, and ensures stable and secure transmission of control commands in complex wireless environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968091A_ABST
    Figure CN121968091A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of wireless communication security, and discloses a security encryption processing method and system for a wireless access area control instruction. The method comprises the following steps: acquiring network state data and an instruction data packet; performing risk quantification processing according to the network state data to obtain a risk vector; performing threat grouping analysis according to the risk vector to obtain a threat distribution combination; determining an encryption parameter combination according to the threat distribution combination; performing fragmentation and encryption processing on the instruction data packet according to the encryption parameter combination to obtain encrypted instruction content; and performing path verification according to the encrypted instruction content to obtain a secure transmission path. According to the invention, the security encryption processing of the control instruction can be realized under the dynamic network condition, and the reliability and security of instruction transmission are improved.
Need to check novelty before this filing date? Find Prior Art

Description

A secure encryption method and system for wireless access area control commands Technical Field

[0001] This invention relates to the field of network security protection and data encryption technology, and in particular to a secure encryption processing method and system for wireless access area control commands. Background Technology

[0002] Currently, with the continuous development of the Industrial Internet system in the manufacturing, energy, and process control industries, wireless access areas, as important communication entry points in industrial sites, undertake the task of real-time interaction of production control commands. In complex wireless environments with multi-source interference, how to implement Industrial Internet encryption for control commands has become a key technical requirement of widespread concern in industrial sites.

[0003] In existing technologies, fixed encryption strategies, static fragmentation methods, and preset rule bases are typically used to encrypt command data packets in wireless access areas. Risk assessment is often based on single indicators such as link quality, bandwidth usage, or basic interference levels before a uniform encryption process is executed. However, when faced with link fluctuations, channel interference, and random congestion in industrial internet wireless access areas, these methods, relying solely on static strategies, cannot respond to actual risks. This results in insufficient encryption strength in high-risk environments and excessive encryption latency in low-risk environments, thus affecting the real-time transmission of control commands.

[0004] In summary, existing technologies suffer from a mismatch between encryption strength and transmission stability. Summary of the Invention

[0005] This invention provides a secure encryption processing method and system for wireless access area control commands to solve the problem of mismatch between encryption strength and transmission stability in the prior art.

[0006] Firstly, to address the aforementioned technical problems, this invention provides a secure encryption processing method for wireless access area control commands, comprising: acquiring network status data of the wireless access area communication link; performing multi-dimensional risk quantification analysis on the network status data to obtain a risk vector; extracting threat factors and grouping them by region based on the risk vector to obtain a threat distribution combination; identifying threats and assessing risk levels based on the threat distribution combination to obtain a threat level score; generating a parameter combination by matching a preset encryption strategy with the threat level score to obtain an encryption parameter combination; acquiring command data packets; adjusting the fragmentation mode of the command data packets and optimizing the checksum rules of the command data packets based on the encryption parameter combination to obtain an encryption processing scheme; fragmenting and encrypting the command data packets according to the encryption processing scheme to obtain encrypted command content; and performing path risk detection and stability verification based on the encrypted command content to output a secure transmission path.

[0007] Secondly, the present invention provides a secure encryption processing system for wireless access area control commands, comprising: a network status acquisition module, used to acquire network status data of the wireless access area communication link, perform multi-dimensional risk quantification analysis on the network status data to obtain a risk vector; a threat grouping module, used to extract threat factors and group regions according to the risk vector to obtain a threat distribution combination; a risk assessment module, used to identify threats and assess risk levels according to the threat distribution combination to obtain a threat level score; an encryption parameter generation module, used to generate a parameter combination by matching a preset encryption strategy according to the threat level score to obtain an encryption parameter combination; an encryption scheme optimization module, used to acquire command data packets, adjust the fragmentation mode of the command data packets according to the encryption parameter combination, optimize the checksum rules of the command data packets, and obtain an encryption processing scheme; a data packet encryption module, used to fragment and encrypt the command data packets according to the encryption processing scheme to obtain encrypted command content; and a path verification module, used to perform path risk detection and stability verification according to the encrypted command content, and output a secure transmission path.

[0008] Compared with the prior art, the present invention has the following beneficial effects: (1) The present invention obtains multi-dimensional network status features such as delay fluctuation, packet loss, traffic burst and signal attenuation in the wireless access area link, and combines historical behavior data such as connection interruption frequency to perform feature extraction, correlation calculation and clustering grouping, and constructs a risk vector that can reflect the trend of link risk changes, thereby realizing fine-grained identification of potential threats, enabling high-risk areas in the link to be accurately distinguished, and solving the problem that threat judgment in the prior art relies on a single indicator and cannot locate the distribution of complex threats.

[0009] (2) By establishing a dynamic risk level and matching the encryption strategy library according to the dynamic risk level, the present invention adaptively determines parameters such as encryption identifier, key length and fragmentation mode, and check code rules, so that the encryption strength matches the current risk level, thereby enhancing encryption protection in high-risk environments and reducing encryption burden in low-risk environments, thus solving the problems of fixed encryption strategies and mismatch between encryption efficiency and security in the prior art.

[0010] (3) By establishing a path verification mechanism, the present invention avoids unstable paths when there are fluctuations or interference in the link, ensuring the stable transmission of encrypted command content in complex wireless environments, thereby improving the reliability of the arrival of control commands and the overall security performance of the link, and solving the technical problem that the existing technology cannot simultaneously take into account both latency stability and encryption robustness. Attached Figure Description

[0011] Figure 1 is a flowchart illustrating a secure encryption processing method for wireless access area control commands according to the first embodiment of the present invention; Figure 2 is a structural diagram illustrating a secure encryption processing system for wireless access area control commands according to the second embodiment of the present invention. Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0013] Referring to Figure 1, the first embodiment of the present invention provides a secure encryption processing method for wireless access area control commands, comprising the following steps: S11, acquiring network status data of the wireless access area communication link, performing multi-dimensional risk quantification analysis on the network status data to obtain a risk vector; S12, extracting threat factors and grouping regions according to the risk vector to obtain a threat distribution combination; S13, identifying threats and assessing risk levels according to the threat distribution combination to obtain a threat level score; S14, generating a parameter combination by matching a preset encryption strategy according to the threat level score to obtain an encryption parameter combination; S15, acquiring command data packets, adjusting the fragmentation mode of the command data packets according to the encryption parameter combination, optimizing the checksum rules of the command data packets to obtain an encryption processing scheme; S16, fragmenting and encrypting the command data packets according to the encryption processing scheme to obtain encrypted command content; S17, performing path risk detection and stability verification according to the encrypted command content, and outputting a secure transmission path.

[0014] In step S11, it is necessary to acquire network status data of the wireless access area communication link, and perform multi-dimensional risk quantification analysis on the network status data to obtain a risk vector. This includes: acquiring network status data of the wireless access area communication link; wherein, the network status data includes delay time series data, packet loss statistics, traffic burst data, and signal strength attenuation value; calculating delay fluctuation value and delay change rate based on the delay time series data to obtain delay characteristics; obtaining packet loss ratio and identifying continuous packet loss events based on the packet loss statistics to obtain packet loss characteristics; extracting traffic peak intensity and identifying the number of burst segments based on the traffic burst data to obtain traffic characteristics; calculating link stability index based on the signal strength attenuation value to obtain attenuation characteristics; normalizing the delay characteristics, packet loss characteristics, traffic characteristics, and attenuation characteristics and fusing them according to a preset weight ratio to obtain a risk vector.

[0015] It should be noted that the delay characteristics reflect the time fluctuation of the command transmission on the radio access area link. The delay fluctuation value and the delay change rate are calculated from the delay time series data. The delay fluctuation value is used to characterize whether there is periodic congestion in the link. It is obtained by calculating the standard deviation of the delay sequence in the most recent sampling interval, and the 95th percentile difference of the delay sequence is used as the basis for fluctuation test. The delay change rate reflects the sudden change trend.

[0016] Specifically, the most recent sampling interval is the latest 1-second link delay sequence continuously acquired by the monitoring module, with a sampling frequency of 100Hz, corresponding to 100 consecutive sampling points. The delay fluctuation value is obtained by calculating the standard deviation of the delay sequence within this 1-second sampling window. To determine whether there is periodic congestion in the link, the difference between the 95th percentile and the 5th percentile of the delay sequence within this window is used as a fluctuation test index to eliminate the influence of extreme values ​​and more accurately reflect the range of delay fluctuations. The delay change rate is obtained by point-by-point differencing of adjacent sampling points within this 1-second sampling window, and the maximum value among the absolute values ​​of all differences is taken as the delay change rate to characterize sudden change trends.

[0017] It is worth noting that the packet loss characteristics consist of the packet loss ratio and consecutive packet loss events. The packet loss ratio is used to reflect the overall stability of the link, while consecutive packet loss events are used to determine whether there is abnormal interruption behavior.

[0018] It should be noted that the flow characteristics include peak flow intensity and the number of bursts, which are used to characterize the concentration of peak flow; if there are many bursts, it indicates that there may be abnormal flow patterns in the area.

[0019] It is worth noting that the attenuation characteristic is calculated from the signal strength attenuation value to obtain the link stability index, which is used to reflect whether the signal quality of the wireless link is in an unstable state.

[0020] The above features are all derived from real-time network status data. By performing parallel calculations on link latency, packet loss, traffic fluctuations, and signal attenuation, four types of native risk indicators are formed that can characterize the communication status of the wireless access area.

[0021] In one implementation, the latency features, packet loss features, traffic features, and attenuation features are normalized. The normalization adopts a minimum-maximum method based on the extreme values ​​of the sampling interval, where the maximum and minimum values ​​come from the current sampling range of the real-time collected network state data and are fused according to a preset weight ratio.

[0022] The preset weight ratio is determined based on historical network operation data. By statistically comparing the network status under typical past operating conditions with actual risk events, a grid search method is used to select the combination with the highest comprehensive risk identification accuracy from multiple candidate weight combinations as the fixed weight. For example, based on the link monitoring logs of the past three months, candidate weight combinations of latency features, packet loss features, traffic features, and attenuation features are selected, and the combination with the highest identification accuracy is finally determined to be 0.35, 0.25, 0.20, and 0.2.

[0023] After normalization, the various features are linearly fused according to their weights to form a risk vector for subsequent threat identification. Each dimension of the risk vector corresponds to a type of network risk factor, which is used to support subsequent risk distribution classification and high-risk area identification.

[0024] For example, in a link monitoring scenario within a wireless access area, the collected latency timing data includes 200 consecutive sampling points with an adjacent sampling interval of 10ms. The latency ranges from 12ms to 36ms. Through differential calculation, the latency fluctuation value is found to be 7ms, and the maximum latency change rate calculated between adjacent sampling points is 4ms / 10ms. In the packet loss statistics, the total packet loss ratio is 0.03, and the number of consecutive packet loss events is 2. In the traffic burst data, 3 burst traffic segments were observed, with the highest peak intensity being 2.1 times that of the normal load. The signal strength attenuation value decreased by 6dB within the sampling interval, corresponding to a link stability index of 0.42. After normalizing the above parameters, the weight ratios of latency features, packet loss features, traffic features, and attenuation features are set to 0.35, 0.25, 0.20, and 0.20, respectively, and weighted fusion is performed to obtain the risk vector [0.62, 0.40, 0.55, 0.30]. This risk vector is used in subsequent steps to identify major threat patterns and link risk distributions.

[0025] In step S12, threat factors are extracted and grouped by region based on the risk vector to obtain a threat distribution combination. This includes: extracting latency fluctuation parameters, packet loss parameters, traffic burst parameters, and attenuation parameters from the risk vector and integrating them to obtain threat factors; calculating the correlation values ​​between the parameters based on the threat factors to obtain a correlation set; clustering the threat factors based on the correlation set to form a threat grouping result; and adjusting the boundaries and integrating the threat grouping result by region according to a preset risk grouping rule to obtain a threat distribution combination.

[0026] It should be noted that the delay fluctuation parameter is determined by the normalized result of the delay fluctuation value in the delay feature, reflecting whether there is significant fluctuation in the delay of the link within a unit of time; the packet loss parameter is derived from the packet loss ratio and the number of consecutive packet loss events in the packet loss feature, used to describe whether there is unstable packet loss behavior of the link within the same time period. Specifically, the packet loss ratio is used as a base quantity after normalization, and the number of consecutive packet loss events is obtained by proportionalizing the number of events according to the sampling period. The two are linearly combined according to a preset ratio to form the packet loss parameter; the traffic burst parameter is jointly determined by the number of burst segments and the peak traffic intensity in the traffic feature, used to detect whether the communication link experiences abnormal traffic surges in a short period of time.

[0027] Specifically, the number of burst segments is counted and normalized according to a time window, and the peak intensity is normalized according to the maximum load ratio. The two are then merged at a fixed ratio to obtain the traffic burst parameter. The attenuation parameter is calculated from the link stability index in the attenuation characteristics and is used to characterize the rate at which the signal strength decreases over time. The preset ratio is determined based on the historical operating data of the wireless access area over the past month. By statistically analyzing the sensitivity of the packet loss ratio and the number of consecutive packet loss events under different scenarios, the contribution ratio of the two to the overall link stability is determined, and this is used as the basis for setting the ratio. The ratio range can be finely adjusted within ±10% of the sum of 1 to adapt to different load environments. After integrating the above four parameters into threat factors, it is necessary to quantify the changing relationship between each pair of threat factors and calculate the correlation value between each parameter.

[0028] Specifically, within the same sampling interval, delay fluctuation parameters, packet loss parameters, traffic burst parameters, and attenuation parameters are arranged into four sets of equal-length data sequences in chronological order. The normalized co-variance is calculated for any two sets of sequences. The co-variance is obtained by comparing the increment directions of the sequences at the same time point. A value of 1 is recorded when the increment directions of the two sequences are consistent, and 0 is recorded when they are opposite. The average value across all time points, ranging from 0 to 1, is used as the correlation value for the corresponding parameters. The closer the correlation value is to 1, the more consistent the change directions of the two parameters. It should be noted that the tolerance range for consistent increment directions is that the difference in the amplitude of the two increments does not exceed 10% of their respective mean values, to avoid misjudgment caused by minor noise.

[0029] After obtaining the correlation set, threat factors need to be grouped according to a preset similarity threshold. The similarity threshold is used to determine whether two parameters should be grouped into the same group, and its value is determined based on the statistical results of historical network status data. In this method, historical network status records of the wireless access area under different load conditions are collected. The historical data range is the complete network sampling records of the most recent three months, covering morning and evening peak hours, low-load periods, and abnormal traffic periods. Long-term statistics are performed on the correlation between latency fluctuation parameters, packet loss parameters, traffic burst parameters, and attenuation parameters, and the quantile distribution of all historical correlations is calculated. The 75th percentile is selected as the base value for the similarity threshold. The preset similarity threshold reflects the degree of linkage between parameters in most cases. When the overall load is significantly higher or lower during the monitoring period, the threshold can be fine-tuned within ±5% to avoid global offset affecting the accuracy of grouping.

[0030] In the specific grouping operation, parameter pairs with a correlation degree greater than the similarity threshold are first temporarily grouped together. Then, it is checked whether the correlation degree between each parameter within each group and other parameters within the group meets the similarity threshold requirement. If there is a conflict where parameter A has a high correlation degree with parameter B, parameter B has a high correlation degree with parameter C, but parameter A has a low correlation degree with parameter C, then the parameter pair with the higher correlation degree is retained as the core group. The conflicting parameters are then listed separately, and their final assignment is determined by their maximum correlation degree with other parameters. If the correlation degree between a parameter and the other parameters within the group is lower than the similarity threshold, then the parameter is removed from the original group and grouped separately, or reassigned to a group that meets the conditions based on its maximum correlation degree. The threat grouping results formed in this way can ensure the consistency of the parameters within the group in terms of time-varying patterns, enabling the final threat distribution combination to clearly distinguish different risk characteristic areas.

[0031] When performing partitioning and integration, the group boundaries need to be adjusted according to preset risk grouping rules. These preset risk grouping rules include requirements for the minimum number of parameters in each group, a lower limit for intra-group correlation, and priority grouping requirements for specific parameters. These rules are all determined based on statistical results of historical risk distribution data. Specifically, the lower limit for intra-group correlation is that the correlation between any two parameters within a group must not be lower than the 70th quantile of the corresponding distribution in historical statistics, ensuring minimum consistency in parameter change patterns within the same region. Specifically, by statistically analyzing past risk monitoring records of communication links, the distribution of parameter numbers appearing in typical scenarios for different risk groups is calculated, and the minimum number of parameters required for each group is determined from the common group size range of 60% to 80%. The changes in the lower limit of correlation for various risk factors within the same region are statistically analyzed, and their 70th quantile is used as the minimum standard for intra-group correlation. For parameters that are more indicative of link anomalies, such as delay fluctuation parameters or packet loss parameters, they are set as priority grouping objects based on their frequency of occurrence in historical events.

[0032] In the specific operation of partitioning and integration, if a group contains only one parameter and the maximum correlation between that parameter and any other parameter is lower than a preset correlation threshold, then that parameter is assigned to the adjacent group with the highest correlation, avoiding the formation of unrepresentative isolated areas. If the average correlation between two groups is higher than a preset merging threshold, then these two groups can be merged into a new area; the merging threshold is also determined based on the 75th percentile of historical correlation changes to ensure the rationality of the merging result. By making the above adjustments to the boundaries, the divided areas can conform to the actual operation of the wireless access area in terms of parameter quantity, correlation pattern, and risk characteristic distribution.

[0033] For example, within a certain sampling interval, the delay fluctuation parameter, packet loss parameter, traffic burst parameter, and attenuation parameter each contain 50 measured values ​​at different time points. The increment direction of the delay fluctuation and traffic burst sequences is compared point-by-point. The increment direction of the delay fluctuation parameter sequence at adjacent time points is +, +, 0, -, +, ... +, +, 0, -, +, ... +, +, 0, -, +, ...; the increment direction of the traffic burst parameter is +, +, -, −-, +, ... +, +, -, -, +, ... +, +, -, -, +, ... In 50 comparisons, the two types of sequences have the same direction 41 times, so their correlation value is 41 / 50 = 0.82. With a preset similarity threshold of 0.75, the delay fluctuation parameter and traffic burst parameter are grouped into the same group; the correlations of the packet loss parameter and attenuation parameter are 0.48 and 0.36 respectively, which do not reach the threshold, therefore they are initially divided into two independent groups. According to the preset risk grouping rules, each group must contain at least two parameters, and it is allowed to merge neighboring groups with the highest correlation. Therefore, the group containing the packet loss parameter is merged with the group containing the attenuation parameter to form a second threat region. The final threat distribution combination contains two regions, corresponding to the traffic-related risk region and the link stability-related risk region, respectively.

[0034] In step S13, threat identification and risk level assessment are performed based on the threat distribution combination to obtain a threat level score. This includes: calculating the risk concentration of each group based on the threat distribution combination; calculating the contribution of the threat factors based on the risk concentration, and identifying the dominant threat type based on the contribution; matching the dominant threat type with a preset risk level mapping table to obtain an initial level score; obtaining historical risk records from a preset historical database, performing trend analysis on the historical risk records to obtain trend information, and correcting the initial level score based on the trend information to obtain a threat level score.

[0035] It should be noted that the risk concentration represents the proportion of high-risk areas within each group in the total records, reflecting the spatial or temporal clustering of threats. Calculating the risk concentration requires filtering each record in the threat distribution combination, extracting its risk level field, and comparing it with a preset high-risk threshold. This preset high-risk threshold can be determined based on the 90th percentile of risk levels in historical monitoring data and can be adjusted within ±10%. When the overall risk level shifts during the monitoring period, such as due to increased network traffic or an abnormally stable network state leading to a lower overall risk level, the threshold can be adjusted upwards or downwards accordingly to maintain stable sensitivity in high-risk identification. Only when the risk level of a record exceeds the preset high-risk threshold is it included in the high-risk area set, and the percentage of this set in the total number of records for that group is calculated to obtain the risk concentration.

[0036] The contribution of the threat factors represents the intensity of each parameter's influence on the overall threat level. During calculation, different threat parameters within high-risk areas, such as abnormal traffic peaks and connection interruption frequencies, need to be normalized. Specifically, a minimum-maximum normalization method is used, and the normalization calculation can be expressed as: in, This represents the original parameter value of the current record; This indicates the minimum value of the parameter within the filtering range. Indicates the maximum value. This represents the dimensionless result after normalization.

[0037] Then, a weighted sum is calculated according to predetermined weights, and the contribution can be expressed as: in, Indicates the contribution of the threat factor; The weights corresponding to the normalization parameters of the i-th term are: is the normalized result of the i-th parameter; n is the number of parameters involved in the calculation. The weights can be obtained through historical statistical methods, for example, high-risk parameters account for 60%, medium-risk parameters account for 30%, and low-risk parameters account for 10%. The division of high, medium, and low-risk parameters is determined based on their triggering frequency in historical events and the severity of the corresponding events. The type corresponding to the parameter with the highest contribution is identified as the dominant threat type and used to match it with a preset risk level mapping table to obtain an initial level score.

[0038] It should be noted that the score range in the preset risk level mapping table is 0–100 points. The specific value can be determined based on statistical analysis of historical event records and can be fine-tuned within ±5%. For example, a certain level may be initially calculated as 50 points, but can be adjusted to between 48 and 52 points based on the latest risk situation, ensuring that the mapping table is adaptable and operable to the current environment in practical applications. All adjustment operations are recorded with the basis and magnitude of the adjustment, ensuring that the mapping table is traceable and repeatable.

[0039] Trend information reflects the changes in historical risk records over time. When acquiring trend information, risk level records from the past three years can be extracted from a preset historical database. A sliding window averaging analysis is performed chronologically, with a window length set to 30 days. The average growth rate or decline rate within each window is calculated to determine the trend type (rising, falling, or stable). Specifically, the average risk level difference between two adjacent days within each window is calculated, and the difference is averaged to obtain the window growth rate. If the growth rate is greater than +2%, it is considered an upward trend; if it is less than -2%, it is considered a downward trend; otherwise, it is considered a stable trend. The trend analysis results are used to adjust the initial risk level score. If the trend is upward, the initial score is increased by the calculated growth rate; if it is downward, it is decreased by the decline rate; if it is stable, it remains unchanged.

[0040] In one implementation, for high-risk areas whose proportion exceeds the preset high-risk threshold, the screening criteria can be specifically set as follows: abnormal traffic peaks exceed twice their historical averages or connection interruption frequencies exceed twice per minute. Contribution calculation uses a weighted sum of normalized peak and interruption frequency data, with weights determined based on historical statistics: high-risk parameters account for 60%, medium-risk for 30%, and low-risk for 10%. The initial score range of the mapping table is 0–100 points. Historical trend analysis uses a sliding time window method with a window length of 30 days. The average growth rate is calculated with each roll, and the trend growth rate can be expressed as: in, Indicates the trend growth rate; Let k be the risk level on day t within the window; k is the number of days of records included in the window (30 in this method); the numerator is the average daily variation of risk levels within the window; and the denominator is the average risk level within the window. For example, if... The average is 50, and the difference is 5. =10%.

[0041] For example, in a certain threat distribution combination, the proportion of high-risk areas is 15%, exceeding the preset high-risk threshold of 10%. After filtering, abnormal traffic peaks and connection interruption frequency records are extracted from this area. The abnormal traffic peak is up to 3 times the normal value, and the connection interruption frequency is 5 times per minute. The normalized traffic peak can be expressed as: The normalized interrupt frequency can be expressed as: Contribution is calculated as follows: Anomaly in traffic peaks was identified as the dominant threat type. The initial threat level score was mapped to 70 points. Historical trend analysis showed that this type of risk had increased by an average of 10% over the past six months. The final threat level score can be expressed as: In step S14, a parameter combination is generated by matching the threat level score with a preset encryption policy to obtain an encryption parameter combination. This includes: matching the threat level score with a preset encryption policy library to obtain a policy candidate set; extracting an encryption identifier and a key length range from the policy candidate set; performing constraint optimization on the key length range to obtain a key length parameter; and combining the encryption identifier and the key length parameter to obtain the encryption parameter combination.

[0042] It should be noted that the preset encryption policy library is a structured data set built based on historical security event records and standard encryption specifications. Each policy record includes the encryption algorithm type, applicable threat level range, key length range, and algorithm priority index.

[0043] It is worth noting that the construction of the preset encryption strategy library first selects algorithm types and their configurable key ranges that meet the application scenario from well-known encryption algorithm standards. Subsequently, based on historical high-risk event records in the historical database of step S13, such as link interruptions and traffic bursts, the performance of each algorithm under different threat level scores is statistically analyzed. First, event data is collected, including event type, occurrence time, and corresponding threat level score; then, the usage effect and stability indicators are calculated respectively.

[0044] The effectiveness of the system is quantified by the link integrity success rate, calculated as the number of successfully transmitted data packets divided by the total number of data packets. Stability is measured by the latency fluctuation coefficient, calculated as the standard deviation of latency divided by the average latency. The weighting ratios of 0.7 (effectiveness) and 0.3 (stability) are determined based on statistical analysis of historical data transmission logs. Multiple regression fitting is performed on data from high-risk events over the past three years, with the link integrity success rate as the dependent variable and the latency fluctuation coefficient as the independent variable. A weighting combination is selected that ensures the coefficient of determination of the fitted model is not less than 0.9. This weighting can be dynamically fine-tuned according to changes in the network environment; for example, when the peak traffic intensity fluctuates by more than 10% of the historical average (based on the traffic characteristics in step S11), it is adjusted within a range of ±5%.

[0045] The database table adopts a relational database structure and includes fields such as algorithm ID, upper and lower bounds of threat level range, key length range, and performance score. The score and range are updated monthly based on the latest event data to adapt to the dynamic risk conditions described in step S14. The above information is organized into a database table, with each record containing an encryption identifier, applicable threat level range, key length range, and algorithm priority index. The database table adopts a relational database structure and includes fields such as algorithm ID, upper and lower bounds of threat level range, key length range, and performance score. The preset encryption policy library can be stored as a database table or a configuration file, and policy records can be obtained through a query interface for threat level matching.

[0046] In one implementation, the threat level score is input into the preset encryption policy library query interface to filter out all records whose applicable threat level range covers the current threat level, forming a policy candidate set. Subsequently, encryption identifiers and key length ranges are extracted from the candidate records, and combined with data packet header feature weights. and load sensitivity weight A weighted score was calculated using historical monitoring data. To ensure comparability of the weights across different time periods, a fixed 10-minute statistical window was used to analyze the network monitoring data. The results are as follows: in, This represents the number of abnormal data packet headers. For the number of sensitive load events, This represents the total number of data packets or load events. The fixed statistical window setting ensures that the weight calculation reflects network behavior characteristics over a uniform time scale, thereby improving the stability of the algorithm's priority determination.

[0047] After weighting the packet header features and payload content sensitivity, the calculated weight values ​​are... and The algorithm is compared with a preset priority threshold of 0.5 to 0.8. If the weight value falls within this range, the corresponding encryption algorithm is determined to have a high priority; if the weight value is lower or higher than this range, the priority is determined to be low, thus assisting in the selection of a suitable encryption algorithm. It should be noted that the preset priority threshold initially ranges from 0.5 to 0.8, obtained by statistically analyzing monitoring data from high-risk areas over the past three years, covering approximately 90% of abnormal events. It can be fine-tuned within ±10% based on the real-time network environment to determine the adaptability of the encryption algorithm in the current threat environment. The fine-tuning mechanism is triggered when an overall shift occurs, such as a significant increase in the network traffic baseline, to avoid overly broad priority determination leading to resource waste or overly narrow priority determination leading to missed detections, thereby maintaining the robustness and accuracy of the system. Key length constraint optimization is performed on candidate records with high algorithm priority, and the optimization calculation is as follows: in This represents the median key length used in historical events. The algorithm performance score ranges from 0 to 100. Finally, the highest priority encryption identifier is combined with... The final combination of encryption parameters is generated by combining them. The algorithm performance is scored, with a value ranging from 0 to 100, to characterize the overall performance of candidate encryption algorithms in historical high-risk scenarios. The score calculation is based on historical event records, normalizing and quantifying three indicators: latency, throughput, and stability, and then weighting and summing them according to preset weights. The specific calculation method is as follows: in, This is the normalized result of the encoding / decoding latency of the algorithm under high load conditions; the lower the latency, the higher the score. This is the normalized result of the algorithm's throughput capacity under historical peak traffic scenarios; This is a normalized result of the algorithm's stability in multiple high-risk events (such as failure rate and retransmission rate). , For the corresponding weights, satisfying In one implementation, values ​​of 0.4, 0.4, and 0.2 can be used, derived from statistical analysis of the algorithm's performance in high-risk areas over the past three years. The normalization method employs minimum-maximum normalization. in This indicates the corresponding original indicator. and These are the minimum and maximum values ​​of this indicator in historical records. The final result is... The value range automatically falls within the 0–100 interval, which is used to reflect the overall performance level of the algorithm in key length optimization.

[0048] For example, assuming a threat level score of 80, three records—AES, ChaCha20, and RSA—are selected as candidate sets from a pre-defined encryption policy library. The AES key range is 128 to 256 bits, the ChaCha20 key range is 128 to 256 bits, and the RSA key range is 1024 to 2048 bits. Subsequently, the packet header feature weight and payload sensitivity weight are obtained, where the statistical weight... =0.6 is derived from the proportion of abnormal packet headers in the sampling window over the past 10 minutes to the total number of packet headers in that window, and is used as a statistical weight. =0.4 originates from the proportion of sensitive load events to the total number of load events within the same sampling window. Because... and All values ​​fall within the preset priority threshold range of 0.5 to 0.8, therefore AES is classified as high priority. (AES historical median...) =192, performance score =85, calculated as follows Rounded to 193 bits, the final encryption parameters are the AES algorithm and a 193-bit key.

[0049] It is worth noting that this parameter combination generation method can be adjusted in real time according to the network status, and the weights can be recalculated. and Re-filter the policy candidate set and update This ensures that encrypted parameters are both secure and efficient under different threat environments.

[0050] In step S15, an instruction data packet is acquired, and the fragmentation mode of the instruction data packet is adjusted according to the encryption parameter combination. The checksum rules of the instruction data packet are optimized to obtain an encryption processing scheme. This includes: acquiring the instruction data packet; determining the processing parameters for encryption operation according to the encryption parameter combination; acquiring the number of nodes in the current transmission path and calculating the transmission delay value based on the number of nodes; adjusting the fragmentation mode of the instruction data packet according to the processing parameters and the transmission delay value to obtain a target fragmentation mode; determining the redundancy processing requirements generated by the encryption operation according to the processing parameters and determining the checksum generation method according to the redundancy processing requirements to obtain a checksum configuration result; and combining the target fragmentation mode with the checksum configuration result to obtain the encryption processing scheme.

[0051] It should be noted that the instruction data packet represents the task instruction or control information transmitted over the network, which can be obtained by reading it from the data sender through the communication interface; the processing parameters of the encryption operation include the encryption algorithm type, key length, and operation mode. These parameters are provided by a combination of encryption parameters generated by a preset encryption strategy library, which is used to guide the fragmentation mode adjustment and checksum generation. The strategy library automatically re-executes the matching process after each threat level update to ensure that the processing parameters correspond to the threat situation in real time; the number of nodes in the transmission path represents the number of relay nodes that the data packet passes through in the network, which is calculated by counting the total number of nodes on the path through the path database; the transmission delay value represents the cumulative processing and transmission time of the data packet at each node on the path, which is calculated based on the number of nodes and the node processing time characteristics, and is used for fragmentation mode optimization; the redundancy processing requirement represents the amount of additional data generated by the encryption operation to ensure data integrity, which is used to determine the checksum generation method and coverage; the checksum configuration result represents the integrity checksum information generated for each fragmentation unit, which is used to verify the integrity of the fragmented data.

[0052] In one implementation, the formula for calculating the transmission delay value is: Where N is the total number of path nodes. The processing and transmission time characteristics of the i-th node can be obtained by averaging historical monitoring log data of similar paths over the past 30 minutes. This is based on the transmission delay value and a preset delay tolerance range. (Initial value 30 to 80 ms, can be fine-tuned within ±10%), adjust the fragmentation mode. If achieve If it reaches 90%, then increase the number of fragments. To reduce the data transmission load and processing volume of each fragment; if Below A 110% safety buffer reduces the number of fragments, thus decreasing the data transfer and processing load per fragment. The formula for calculating the number of fragments is: in, This refers to the total number of bytes in the instruction data packet. The target shard size is determined by a combination of the average processing capacity of the nodes and the latency tolerance range. Specifically, a smaller value is used when the average processing time of the nodes is high and the latency is close to the upper limit, and a larger value is used when the processing capacity is strong and the latency is close to the lower limit. The shards are arranged in sequence to form the target sharding pattern.

[0053] The redundancy processing requirement is calculated as follows: in, The encryption redundancy ratio is calculated based on historical transmission records over the past 24 hours, covering 95% of verification failure events. It can be fine-tuned within ±5% and used to generate the checksum. If the CRC32 checksum is fixed at 4 bytes per fragment, the total redundancy is 40 bytes. This encryption redundancy ratio... =0.04. The checksum generation method generates a corresponding checksum by performing CRC or hash operations on the data and redundancy of each fragment, and then combining them according to the fragment sequence number to form the checksum configuration result. CRC32 can be used in the implementation to adapt to link environments that emphasize real-time performance; the polynomial parameter of CRC32 can be preset to 0x04C11DB7. For links requiring higher security, SHA-256 can be used, and the lowest 64 bits are truncated from its output as the checksum to balance verification capability and checksum length control.

[0054] The encryption scheme is obtained by combining the target fragmentation pattern with the checksum configuration result. Specifically, each fragment of data is taken sequentially, and the corresponding calculated checksum is appended to the end of the fragment to form a complete fragment unit. This operation is repeated until all fragments of data have been appended with checksums. After combination, all fragment units are arranged in the order of the original instruction data packet to form a continuous fragment sequence, and the fragmentation order information and fragmentation pattern parameters are recorded so that the receiving end can recover the original instruction data packet according to the order and checksum. In this way, it is ensured that the data integrity and order of each fragment can be correctly verified and reassembled by the receiving end.

[0055] For example, if the current instruction data packet size is 1000 bytes, the number of nodes in the transmission path is 10, and the average processing time per node is 5ms, then... The latency tolerance range is 30 to 80 ms. Based on latency adjustment, the data packet is divided into 5 units, each 200 bytes. The encryption redundancy ratio is 0.05, and each fragment is appended with a 10-byte checksum generated using CRC32. The 5 fragments and their corresponding checksums are combined sequentially to form an encryption scheme, achieving a balance between data integrity and transmission efficiency. The 5 ms threshold is set based on the average processing capacity of a typical network node. Based on the 50 ms latency and tolerance range, the target fragment size is calculated to be 1000 / (50 / 5) = 100 bytes, and the actual number of fragments is 1000 / 100 = 10. Each fragment is 100 bytes long, with a redundancy ratio of 0.05 and a checksum length of 5 bytes, generated using CRC32 with a 4-byte checksum.

[0056] In step S16, the instruction data packet is fragmented and encrypted according to the encryption scheme to obtain encrypted instruction content. This includes: performing sensitivity identification on the instruction data packet according to the encryption scheme to obtain a sensitivity level; sorting the instruction data packet into fragments according to the sensitivity level to obtain a fragment index; fragmenting the instruction data packet according to the fragment index to obtain an unencrypted fragment sequence; performing encryption on the unencrypted fragment sequence using the encryption scheme to obtain an encrypted fragment sequence; appending a checksum to the encrypted fragment sequence according to the checksum configuration result to obtain an encrypted fragment sequence with the checksum appended; and reassembling the encrypted fragment sequence with the checksum appended according to the fragment index to obtain the encrypted instruction content.

[0057] It should be noted that the sensitivity level is used to reflect the responsiveness of data content to leakage risks and network fluctuations during transmission. It is derived from the load sensitivity score and data packet header feature value recorded in the encryption processing scheme. The calculation method is to match the load sensitivity score with the data packet header feature value in the mapping interval of the preset sensitivity model, and obtain the final level by interval weighting based on the relative position of the two in the interval.

[0058] The load sensitivity score is calculated based on the response amplitude of data packets to changes in link congestion, recorded in real time during transmission. Specifically, link load values ​​and arrival times are recorded for five consecutive cycles at a fixed collection window (e.g., every 5 seconds). The link load value characterizes the current link pressure and serves as the basis for distinguishing load conditions in different cycles. The arrival time difference between adjacent cycles is then calculated, and the difference is used to determine whether it is caused by congestion, considering the corresponding load conditions. When the link load value of an adjacent cycle increases relative to the previous cycle, and the arrival time of that cycle also increases relative to the previous cycle (i.e., both load and arrival time show an upward trend), the arrival time difference is recorded as a valid difference caused by congestion. If the load does not increase or the arrival time does not increase, the difference is considered unrelated to congestion and is not included in subsequent calculations. Based on this, the average of all valid differences is taken as the arrival time fluctuation amplitude of the data packet within the five cycles. This time fluctuation amplitude is then normalized to minimum and maximum based on the minimum and maximum arrival time fluctuation amplitudes in historical records, resulting in a load sensitivity score between 0 and 1.

[0059] The packet header feature values ​​reflect the contribution of instruction type, priority, and access control fields in the current packet header to sensitivity. Specifically, first, the values ​​of each basic field are obtained from the current packet header. Then, these values ​​are compared with the value ranges of similar fields in historical records, and each field is converted into a standardized value between 0 and 1 using a min-max normalization method. To reflect the relative importance of different fields to sensitivity, weights are assigned to each field based on historical statistics; for example, instruction type has a higher weight, priority is next, and access control fields have the lowest weight. Finally, the standardized values ​​of each field are weighted and combined to obtain the packet header feature values.

[0060] The preset sensitivity model is an interval mapping model constructed based on historical transmission data, formed by the statistical distribution of load sensitivity scores collected during the operation phase and data packet header feature values. To determine the boundaries of each interval, the historical score sequence is arranged in ascending order, and the overall numerical range is divided into continuous sub-intervals of equal width. For example, the range between the minimum and maximum scores is divided into ten equal segments. The specific steps of the interval weighting method are as follows: subtract the lower bound of the interval from the load sensitivity score, and then divide by the difference between the upper and lower bounds of the interval to obtain the position ratio of the load sensitivity score within its interval. The proportion of the data packet header feature value within its interval is obtained by subtracting its lower bound from the data packet header feature value and then dividing by the difference between the upper and lower bounds of the interval. Then according to the preset weight and Calculate the weighted sensitivity value: M in, and Preset weights are used to fuse load sensitivity scores and packet header feature values. Specifically, based on historical encrypted packet records, a load sensitivity score sequence, a packet header feature value sequence, and a corresponding historical sensitivity value sequence M are constructed. The Pearson correlation coefficient between the load sensitivity score sequence and the sensitivity value sequence is then calculated. And the Pearson correlation coefficient between the data packet header feature value sequence and the sensitivity value sequence. ;Will and Take the absolute value and normalize linearly to [0, 1] to obtain the initial weights. and During the operational phase, when the network congestion rate in the recent period is 10% higher than the long-term average, the system should be improved. When the data packet header fields change significantly, improve... The adjustment range is limited to ±5% of the initial weights to ensure model stability.

[0061] The weighted sensitivity value M falls within the interval [0, 1]. To convert M into a discrete level, an interval linear quantization method is used for mapping, dividing the interval [0, 1] into ten equal segments. The final sensitivity level L is calculated as follows: The value of L ranges from 1 to 10. When M = 0, the fixed mapping is level 1.

[0062] Load sensitivity is used to represent the degree to which data content is sensitive to network congestion. Packet header features are used to characterize instruction type, priority, and access control fields. The two types of parameters are fused according to the above interval weighting method. The relative influence ratio of the two in the overall sensitivity is controlled by the weight, and they jointly determine the sensitivity level. Fragmentation index is used to characterize the arrangement order of instruction packets after fragmentation. It is determined by the fragmentation granularity and sorting method corresponding to the sensitivity level.

[0063] Specifically, the fragmentation granularity is obtained by querying a preset mapping table, which is generated based on a linear regression relationship between historical sensitivity levels and transmission success rate (number of successfully transmitted data packets divided by the total number of data packets). For example, levels 1–3 correspond to the fragmentation number range [2,3]. The final fragmentation number is rounded up by dividing the total number of bytes in the data packets by the midpoint of the range, and the result does not exceed the upper limit of the range.

[0064] When determining the final number of fragments, the number range is determined based on the sensitivity level, and then divided according to a fixed ratio based on the size of the instruction data packet. For example, the specific number of fragments is obtained by dividing the total number of bytes in the instruction data packet by the midpoint of the range. The sorting method is determined by the final number of fragments, and fragment index values ​​are formed by sequentially numbering fragments from 1 to the total number of fragments, realizing a clear correspondence between the index and the fragment content. The unencrypted fragment sequence is the set of basic data units obtained after the instruction data packet is divided according to the index; the checksum configuration result directly adopts the checksum bit length and generation rules defined in the encryption processing scheme in step S14.

[0065] In one implementation, the sensitivity level can be determined based on the matching results of historical sensitivity ranges, load sensitivity scores, and packet header feature values ​​stored in the encryption scheme. The fragmentation mode can be generated based on the fragmentation granularity parameters corresponding to the sensitivity level, with higher sensitivity levels corresponding to finer fragmentation modes. It should be noted that the historical sensitivity range is obtained through statistical analysis of load sensitivity scores from long-term transmission records. The set of load sensitivity scores for consecutive data packets recorded in chronological order is used as the load sensitivity score sequence. The 10th and 90th percentile values ​​of this sequence are taken as the upper and lower boundaries of the main distribution segment; this interval is the historical sensitivity range. The load sensitivity score reflects the data's sensitivity to network fluctuations, and the packet header feature values ​​correspond to a set of feature ranges in the database. The sensitivity level is generated based on the degree of matching between the current score interval and the corresponding feature range.

[0066] It's worth noting that the sensitivity threshold is derived from statistical results of historical transmission data. By statistically analyzing the distribution of sensitivity scores over long-term operation, the 70th percentile of the scores is used as the threshold benchmark, and fine-tuned within a range of no more than 5% above or below this percentile to ensure the threshold adapts to risk sensitivity under different communication environments. Specifically, when the current network node congestion rate is 10% higher than the historical average, the threshold is increased to classify more data as highly sensitive; conversely, when the node congestion rate is 10% lower than the historical average, the threshold is decreased to allow more data to fall into the normal sensitivity range.

[0067] In this embodiment, the length of the checksum is derived from a preset checksum scheme corresponding to the instruction type and link reliability level. It can be selected between an 8-bit and a 16-bit checksum. When the instruction type is control-related and the link reliability level is ≥0.8, an 8-bit checksum is used; when the instruction type is parameter update-related or the link reliability level is <0.8, a 16-bit checksum is used. The encryption actions are executed in the order specified in the encryption processing scheme, prioritizing high-sensitivity fragments and then processing the remaining fragments sequentially according to their index, ensuring that critical content is prioritized for protection during the encryption process.

[0068] The link reliability level is obtained by normalizing and weighting the key quality indicators of the path. Specifically, the calculation involves first performing minimum-maximum normalization on packet loss rate, latency jitter, and signal strength attenuation, denoted as . Then according to the preset weight Calculate the reliability score: The value range is mapped to 0–1, and the weight The R value is determined through a grid search based on historical monitoring data, minimizing the fitting error between R and the actual transmission success rate. Specifically, before system deployment, a large number of transmission logs under different link conditions are recorded. The packet loss rate, latency jitter, and signal strength attenuation in each record are correlated with the actual transmission success rate. Then, multiple candidate combinations are selected at fixed intervals within the weight value range [0, 1], and substituted into the above formula for calculating R. The average deviation between R and the actual transmission success rate under each weight group is calculated, and finally, the combination with the smallest average deviation is selected as the preset weight. This process ensures that the weights are derived from actual link statistics, rather than being arbitrarily set, so that the reliability level can accurately reflect the link status.

[0069] For example, during the encryption process of a command data packet, the load sensitivity score of the packet is obtained as 0.82, and the relative position of the packet header feature value in the corresponding interval is 75%. The load sensitivity score and the packet header feature value are mapped to their respective interval positions, with the load sensitivity score having a position ratio of 0.8 and the packet header feature value having a position ratio of 0.75. According to the preset weights obtained from historical data statistics, the load sensitivity weight is 0.6 and the packet header feature value weight is 0.4, and the weighted fusion value M is calculated as M = 0.6 × 0.8 + 0.4 × 0.75 = 0.78. The comprehensive sensitivity value M is linearly quantized and mapped to a discrete level system according to the interval, initially obtaining level 8. This sensitivity level is used to guide the fragmentation granularity and sorting rules, so that highly sensitive data content receives priority protection during the encryption process.

[0070] Based on the finer granularity of the fragmentation generated at this level, the instruction data packet is divided into six uniformly sized fragments, and each fragment is assigned a consecutive index from 1 to 6. After segmenting the instruction content according to this index, an unencrypted fragment sequence is obtained. Subsequently, following the processing order of the encryption scheme, since the data fields corresponding to fragments 1, 2, and 3 are contained in the high-sensitivity field area of ​​the data packet header (such as instruction type, permission fields, etc.), they are prioritized for encryption. Fragments 1, 2, and 3 are encrypted first, followed by fragments 4, 5, and 6, forming the corresponding encrypted fragment sequence. When adding a checksum, according to the checksum configuration result, an 8-bit checksum is added to each encrypted fragment, appended to the end of the fragment for subsequent transmission integrity verification. Finally, according to the initial fragment index, the encrypted fragments with the added checksum are recombined in order from 1 to 6 to form the final encrypted instruction content.

[0071] In step S17, path risk detection and stability verification are performed based on the encrypted instruction content, and a secure transmission path is output. This includes: extracting the arrival time value based on the encrypted instruction content and verifying the checksum of the encrypted instruction content to obtain a verification result; analyzing the latency characteristics of the path based on the arrival time value and calculating the fragmentation error ratio based on the verification result to obtain a stability index; matching the latency characteristics and the stability index with preset path filtering conditions to obtain a candidate path set; determining the target path based on the candidate path set and outputting a secure transmission path.

[0072] It should be noted that the arrival time value is used to characterize the actual transmission time of the encrypted instruction content from the source to the destination node. This can be obtained by recording the timestamps of each fragment arriving at the receiving end hop by hop after entering the link. The receiving end can locate the corresponding sending time by comparing the index. Specifically, the index matching is implemented using a key-value mapping hash table structure, where the key of the hash table is the fragment index value and the value is the corresponding sending timestamp. When the receiving end parses the fragment, it can locate the original sending timestamp in O(1) time complexity by using the index value as the query key.

[0073] It is worth noting that the verification result originates from the checksum added during encryption. Recalculating the checksum requires using the same algorithm type and parameters as the encryption scheme, such as the CRC32 polynomial 0x04C11DB7 or the SHA-256 hash function. Fragment integrity is determined by comparing each bit. The fragmentation error ratio is calculated by dividing the number of erroneous fragments by the total number of fragments. The stability index is used to comprehensively evaluate the reliability of the path in terms of latency fluctuations and fragmentation integrity, and serves as the basis for subsequent path selection.

[0074] In one implementation, the arrival time value can be obtained by subtracting the segment transmission timestamp from the segment reception timestamp. For example, the receiving end reads the reception timestamp of segment 5 and subtracts it from the transmission timestamp of segment 5 recorded in the encrypted instruction content to obtain the arrival time value of that segment. The latency characteristic can be determined by statistically analyzing the average arrival time and arrival time fluctuation amplitude of several recent segments. For example, the sliding standard deviation of the arrival time values ​​of the most recent 30 segments can be used as a fluctuation index. The preset path filtering conditions are based on historical data of all successful paths in the past month, and the 90th percentile of the average latency and error ratio is calculated as the benchmark value. The latency upper limit is set to 120% of the benchmark value, and the error ratio upper limit is set to 80% of the benchmark value to ensure coverage of 95% of normal fluctuation scenarios; the period of one month can avoid the impact of short-term fluctuations, and the threshold ratio is determined based on the distribution characteristics of historical data.

[0075] For example, the average latency of historically stable paths can be increased by 20% as the allowable latency upper limit, and 80% of the highest historical acceptable error ratio can be used as the current error ratio upper limit for screening. Based on these thresholds, paths that simultaneously meet the latency and error ratio requirements can be included in the candidate path set. From this set, the optimal path is selected as the target path based on node load or continuous latency stability, ensuring that data can be transmitted in a stable, low-risk link.

[0076] For example, during the transmission of encrypted command content, the sending end records the transmission timestamps for 60 fragments sequentially, such as the transmission time intervals for fragments 1 to 60 being the same. The receiving end records the reception timestamp for each fragment; for example, the arrival time of a fragment is between 42ms and 58ms, with an average of 50ms, and the standard deviation of the arrival time of the most recent 30 fragments is approximately 5ms. After verifying all fragments, if two fragments fail verification, the fragment error ratio is 2 / 60, approximately 3.3%. The path filtering criteria determined based on historical transmission records are: average latency must be less than 60ms, latency fluctuation must be less than 15ms, and the fragment error ratio must be less than 5%. If the current path meets these requirements, it can be included in the candidate path set. If another path has an average latency of 47ms at the same time, but its error ratio reaches 8%, then that path is excluded because its error ratio exceeds the threshold. Finally, the path that meets the filtering criteria and has a low node load is selected as the target path, and the output is the secure transmission path.

[0077] In summary, this invention discloses a secure encryption processing method for wireless access area control commands. Through the coordinated processing of risk quantification, fragmented encryption, and path filtering, it achieves stable transmission of command data packets in complex wireless access environments, thereby improving link anti-interference capability and overall security.

[0078] Referring to Figure 2, a second embodiment of the present invention provides a secure encryption processing system for wireless access area control commands, comprising: a network status acquisition module, used to acquire network status data of the wireless access area communication link, perform multi-dimensional risk quantification analysis on the network status data to obtain a risk vector; a threat grouping module, used to extract threat factors and group regions according to the risk vector to obtain a threat distribution combination; a risk assessment module, used to identify threats and assess risk levels according to the threat distribution combination to obtain a threat level score; an encryption parameter generation module, used to generate a parameter combination by matching a preset encryption strategy according to the threat level score to obtain an encryption parameter combination; an encryption scheme optimization module, used to acquire command data packets, adjust the fragmentation mode of the command data packets according to the encryption parameter combination, optimize the checksum rules of the command data packets, and obtain an encryption processing scheme; a data packet encryption module, used to fragment and encrypt the command data packets according to the encryption processing scheme to obtain encrypted command content; and a path verification module, used to perform path risk detection and stability verification according to the encrypted command content, and output a secure transmission path.

[0079] It should be noted that the secure encryption processing system for wireless access area control commands provided in this embodiment of the invention is used to execute all the process steps of the secure encryption processing method for wireless access area control commands in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.

[0080] This invention also provides an electronic device. The electronic device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a secure encryption processing program for radio access area control (RAC) instructions. When the processor executes the computer program, it implements the steps in the above-described embodiments of the secure encryption processing method for RAC instructions, such as step S11 shown in FIG1. ​​Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above-described device embodiments, such as a network status acquisition module.

[0081] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.

[0082] The electronic device may be a desktop computer, laptop, handheld computer, or smart tablet, etc. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. It may include more or fewer components than described above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.

[0083] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device via various interfaces and lines.

[0084] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0085] Wherein, if the modules / units integrated in the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0086] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0087] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A secure encryption method for wireless access area control commands, characterized in that, include: Obtain network status data of the wireless access area communication link, perform multi-dimensional risk quantification analysis on the network status data, and obtain a risk vector; Based on the risk vector, threat factors are extracted and regions are grouped to obtain a threat distribution combination; based on the threat distribution combination, threat identification and risk level assessment are performed to obtain a threat level score; based on the threat level score, a parameter combination is generated after matching a preset encryption strategy to obtain an encryption parameter combination; an instruction data packet is obtained, and based on the encryption parameter combination, the fragmentation mode of the instruction data packet is adjusted and the checksum rule of the instruction data packet is optimized to obtain an encryption processing scheme; According to the encryption scheme, the instruction data packet is fragmented and encrypted to obtain encrypted instruction content; based on the encrypted instruction content, path risk detection and stability verification are performed, and a secure transmission path is output.

2. The secure encryption processing method for wireless access area control commands according to claim 1, characterized in that, The process of acquiring network status data of the wireless access area communication link and performing multi-dimensional risk quantification analysis on the network status data to obtain a risk vector includes: acquiring network status data of the wireless access area communication link; wherein the network status data includes latency time series data, packet loss statistics, traffic burst data, and signal strength attenuation values; calculating latency fluctuation values ​​and latency change rates based on the latency time series data to obtain latency characteristics; obtaining packet loss characteristics by acquiring the packet loss ratio and identifying continuous packet loss events based on the packet loss statistics; extracting peak traffic intensity and identifying the number of burst segments based on the traffic burst data to obtain traffic characteristics; calculating link stability indicators based on the signal strength attenuation values ​​to obtain attenuation characteristics; and normalizing and fusing the latency characteristics, packet loss characteristics, traffic characteristics, and attenuation characteristics according to a preset weight ratio to obtain a risk vector.

3. The secure encryption processing method for wireless access area control commands according to claim 1, characterized in that, The step of extracting threat factors and grouping them by region based on the risk vector to obtain a threat distribution combination includes: extracting latency fluctuation parameters, packet loss parameters, traffic burst parameters, and attenuation parameters from the risk vector and integrating them to obtain threat factors; calculating the correlation degree values ​​between the parameters based on the threat factors to obtain a correlation degree set; clustering the threat factors based on the correlation degree set to form a threat grouping result; and adjusting the boundaries and integrating the threat grouping result by region according to a preset risk grouping rule to obtain a threat distribution combination.

4. The secure encryption processing method for wireless access area control commands according to claim 3, characterized in that, The step of identifying threats and assessing risk levels based on the threat distribution combinations to obtain a threat level score includes: calculating the risk concentration of each group based on the threat distribution combinations; calculating the contribution of the threat factors based on the risk concentration, and identifying the dominant threat type based on the contribution; matching the dominant threat type with a preset risk level mapping table to obtain an initial level score; obtaining historical risk records from a preset historical database, performing trend analysis on the historical risk records to obtain trend information; and correcting the initial level score based on the trend information to obtain a threat level score.

5. The secure encryption processing method for wireless access area control commands according to claim 1, characterized in that, The step of generating a parameter combination by matching the threat level score with a preset encryption policy to obtain an encryption parameter combination includes: matching the threat level score with a preset encryption policy library to obtain a policy candidate set; extracting an encryption identifier and a key length range from the policy candidate set; performing constraint optimization on the key length range to obtain a key length parameter; and combining the encryption identifier and the key length parameter to obtain the encryption parameter combination.

6. The secure encryption processing method for wireless access area control commands according to claim 1, characterized in that, The process of acquiring the instruction data packet, adjusting the fragmentation mode of the instruction data packet according to the encryption parameter combination, optimizing the checksum rules of the instruction data packet, and obtaining an encryption processing scheme includes: acquiring the instruction data packet; determining the processing parameters for encryption operations according to the encryption parameter combination; acquiring the number of nodes in the current transmission path and calculating the transmission delay value based on the number of nodes; adjusting the fragmentation mode of the instruction data packet according to the processing parameters and the transmission delay value to obtain a target fragmentation mode; determining the redundancy processing requirements generated by the encryption operations according to the processing parameters, and determining the checksum generation method according to the redundancy processing requirements to obtain a checksum configuration result; and combining the target fragmentation mode with the checksum configuration result to obtain the encryption processing scheme.

7. The secure encryption processing method for wireless access area control commands according to claim 6, characterized in that, The step of fragmenting and encrypting the instruction data packet according to the encryption scheme to obtain encrypted instruction content includes: performing sensitivity identification on the instruction data packet according to the encryption scheme to obtain a sensitivity level; sorting the instruction data packet into fragments according to the sensitivity level to obtain a fragment index; fragmenting the instruction data packet according to the fragment index to obtain an unencrypted fragment sequence; performing encryption on the unencrypted fragment sequence using the encryption scheme to obtain an encrypted fragment sequence; appending a checksum to the encrypted fragment sequence according to the checksum configuration result to obtain an encrypted fragment sequence with the checksum appended; and reassembling the encrypted fragment sequence with the checksum appended according to the fragment index to obtain the encrypted instruction content.

8. The secure encryption processing method for wireless access area control commands according to claim 1, characterized in that, The step of performing path risk detection and stability verification based on the encrypted instruction content and outputting a secure transmission path includes: extracting the arrival time value based on the encrypted instruction content and verifying the checksum of the encrypted instruction content to obtain a verification result; analyzing the latency characteristics of the path based on the arrival time value and calculating the fragmentation error ratio based on the verification result to obtain a stability index; matching the latency characteristics and the stability index with preset path filtering conditions to obtain a candidate path set; determining the target path based on the candidate path set and outputting a secure transmission path.

9. A secure encryption processing system for wireless access area control commands, characterized in that, include: The network status acquisition module is used to acquire network status data of the wireless access area communication link, and to perform multi-dimensional risk quantification analysis on the network status data to obtain a risk vector. The threat grouping module is used to extract threat factors and group regions based on the risk vector to obtain a threat distribution combination; the risk assessment module is used to identify threats and assess risk levels based on the threat distribution combination to obtain a threat level score. An encryption parameter generation module is used to generate a parameter combination based on the threat level score and a preset encryption strategy to obtain an encryption parameter combination; an encryption scheme optimization module is used to obtain an instruction data packet, adjust the fragmentation mode of the instruction data packet according to the encryption parameter combination, optimize the checksum rules of the instruction data packet, and obtain an encryption processing scheme; a data packet encryption module is used to fragment and encrypt the instruction data packet according to the encryption processing scheme to obtain encrypted instruction content. The path verification module is used to perform path risk detection and stability verification based on the encrypted instruction content, and output a secure transmission path.