Security encryption transmission method for 5G message
By constructing a quantitative user behavior model and a dynamic security domain, combined with quantum noise monitoring, the problem of rigid security policies under dynamic topology changes in 5G message transmission was solved, achieving efficient and personalized security protection and improving the security and efficiency of 5G message transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI RENWEI ELECTRONIC TECH CO LTD
- Filing Date
- 2026-04-15
- Publication Date
- 2026-05-12
AI Technical Summary
Existing 5G messaging technologies struggle to achieve fine-grained isolation in the face of dynamic topology changes and multi-tenant cloud environments. They lack real-time awareness and personalized protection of abnormal user behavior, resulting in rigid security strategies that cannot adapt to dynamic network changes and pose blind spots and risks of information leakage.
By collecting historical user behavior data to build a quantitative model, calculating abnormal behavior scores in real time, dynamically adjusting encryption and isolation strategies, constructing independent security domains, using dynamic group key derivation technology for differentiated isolation, and combining quantum noise index to monitor network topology changes, the system achieves dynamic adaptation and personalized protection of security domains.
It enables precise on-demand allocation of security policies, improves the security and efficiency of 5G message transmission, adapts to dynamic network changes, reduces the risk of information leakage, and ensures a balance between security and performance in high real-time scenarios.
Smart Images

Figure CN122028035A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a secure encrypted transmission method for 5G messages. Background Technology
[0002] With the rapid popularization of 5G networks, 5G messaging, as a key communication carrier supporting innovative applications such as augmented reality and the Internet of Things, faces unprecedented challenges in transmission security. Traditional encryption methods mainly employ static strategies, which are insufficient to address the security gaps caused by dynamic topology changes in 5G networks. In multi-tenant cloud environments, fixed-boundary security models cannot achieve fine-grained isolation at the message level and lack effective mechanisms for detecting abnormal user behavior. When faced with scenarios such as base station switching and elastic scaling of edge nodes, existing technologies struggle to adjust security strategies in a timely manner, easily creating blind spots in protection. Furthermore, traditional solutions lack personalized processing capabilities for group communications, failing to distinguish the risk characteristics of different receivers within a group. This results in security strategies that are either overly conservative, impacting efficiency, or overly lenient, leading to leakage risks. This static protection model is severely incompatible with the highly dynamic nature of 5G networks, necessitating the introduction of a new security framework capable of real-time risk perception and automatic adjustment.
[0003] The application of micro-segmentation technology in 5G message transmission still has significant limitations. On the one hand, existing security domain boundary adjustment mechanisms lack quantitative indicators, making it impossible to establish a precise correlation between risk and protection strength. On the other hand, they lack the ability to monitor uncertainties at the network physical layer (such as quantum noise and signal fluctuations), making it difficult to predict security risks that may be caused by topological changes in a timely manner. In one-to-many transmission scenarios, existing solutions struggle to implement differentiated protection for each receiver, and the group key management mechanism is rigid and unable to adapt to dynamically changing threat environments. Furthermore, traditional methods for assessing security gap risks mainly rely on post-event analysis, making it difficult to respond promptly to transient attacks. Due to the lack of behavioral baseline modeling and real-time anomaly detection capabilities, the system cannot accurately identify potential threats, let alone achieve precise dynamic adjustments to security policies. These shortcomings result in existing solutions performing poorly in balancing security and transmission efficiency, failing to meet the high-standard security requirements for message transmission in the 5G era. Summary of the Invention
[0004] This application provides a secure encrypted transmission method for 5G messages. By using dynamic security domains and differentiated isolation technology, it optimizes resource consumption while ensuring high security, and ensures efficient message transmission in high real-time scenarios such as medical emergency and financial transactions, achieving an excellent balance between security and performance.
[0005] This application provides a secure encrypted transmission method for 5G messages, including:
[0006] S1 collects multi-dimensional behavioral data from users' historical history and uses a quantitative model to transform the multi-dimensional behavioral data into quantifiable indicators, which serve as a baseline model for user behavior. S2, captures the user's current multi-dimensional behavioral data when sending messages in real time, compares it with the user behavior baseline model, calculates the behavior anomaly score, and divides the current behavioral data into risk ranges based on the behavior anomaly score. S3: Dynamically adjust encryption and isolation strategies based on the abnormal behavior score, and automatically switch the corresponding risk strategy; if the abnormal behavior score falls back to a low-risk state within a preset time window, the standard strategy is restored. S4 constructs an independent security domain for each message. Before sending a message, a security domain configuration is generated based on the abnormal behavior score. During transmission, the security domain moves with the message and dynamically adapts to the network path. When the receiving end decrypts the message, it must be verified through the security domain; otherwise, the message will self-destruct. S5, in a one-to-many transmission scenario, treats users who exchange messages as an interaction group, calculates behavioral indicators for each information receiver to generate personalized behavioral anomaly scores, and uses dynamic group key derivation technology to achieve differentiated isolation within the group. S6: When distributing messages within a group, the coordinator monitors for abnormal behavior within the group and adjusts risk strategies accordingly.
[0007] Preferably, the calculation of the abnormal behavior score specifically includes: capturing current operation data in real time when the user initiates a 5G message sending request; comparing the real-time data with the corresponding indicators in the user behavior baseline model to calculate the abnormal behavior score, using the following formula: , This represents the current information transmission frequency. It is the baseline value of the transmission frequency. It is the time period deviation coefficient. It represents the abnormality level of the contact, with α, β, and γ being weighting coefficients.
[0008] Preferably, the user behavior baseline model specifically includes: quantifying multi-dimensional behavioral data based on the user's history, where quantifiable indicators include baseline values for sending frequency, time period deviation coefficients, and contact anomaly rates; and constructing a user behavior baseline model based on the quantifiable indicators.
[0009] Preferably, before sending the message, a security domain configuration is generated based on the abnormal behavior score. Specifically, this includes: after determining the security policy applicable to the current message, the process constructs an independent dynamic security domain for this message, encapsulating the message content and metadata in a secure container; after the security domain is constructed, it enters the transmission process along with the message; when the message arrives at the receiving end, the control logic of the security domain enters the final stage; the receiving party must pass the verification of the security domain before the security domain is unlocked, allowing the receiving party to decrypt and read the encrypted message content; otherwise, if the verification fails or an unauthorized access attempt is made, the security domain will immediately trigger a self-destruct mechanism, causing the message content to become irrecoverably invalid.
[0010] Preferably, the security strategy specifically includes: mapping continuous abnormal behavior scores to discrete risk levels according to preset policy mapping rules, and defining clear security policy parameters for each level; the parameters mainly cover encryption strength and implementing message-level overall isolation under low risk; using the AES-128 algorithm under low risk; upgrading to the AES-256 algorithm under medium risk; and using a more complex compound encryption under high risk; completing one authentication under low risk; adding secondary biometric authentication under medium risk; and enabling continuous authentication mode under high risk to verify each message.
[0011] Preferably, the generation of the security domain configuration based on the behavior anomaly score before message transmission further includes: S41, deploying a quantum random number generator-compatible sensor at the 5G network physical layer to collect quantum noise parameters at a millisecond frequency and quantize them into a quantifiable index, the quantum noise index (QNI); S42, fusing the quantum noise index with the behavior anomaly score, and determining a high-risk topology change event when the quantum noise index increases abnormally and the behavior anomaly score rises; S43, calculating the topology boundary elasticity score of the high-risk topology change event based on the quantum noise index and the topology change event, and dynamically adjusting the security domain boundary based on the boundary elasticity threshold; S44, triggering boundary adjustment when the degree of topology change exceeds the degree threshold, with the original boundary range and the adjusted boundary range serving as the boundary gap; S45, in one-to-many transmission, calculating an independent boundary elasticity score and boundary adjustment coefficient for each receiver and adjusting the boundary.
[0012] Preferably, the quantum noise index QNI includes: channel phase fluctuation value. And photon counting deviation; the formula for calculating the quantum noise index is:
[0013] in, The quantum noise index (QNI) is calculated to be the standard deviation of historical photon counts and normalized to the range of 0 to 1. A value greater than 0.7 indicates that a topological mutation has occurred.
[0014] Preferably, the abnormal increase in the quantum noise index is specifically defined as follows: the determination of abnormal increase depends on a fixed 100-millisecond time window; the change in quantum noise index ΔQNI = |current QNI - historical QNI|, and when ΔQNI ≥ 0.3 or the rate of change of ΔQNI within 100 seconds is ≥ 3 / s, it is determined to be an abnormal increase.
[0015] Preferably, the gap at the boundary includes: deploying probes in the security domain gap area to monitor cross-domain message traffic, abnormal access frequency, and policy difference rate in real time; calculating the correlation between gap risk and external attacks through regression analysis, generating a gap status profile, and triggering adjustment instructions; calculating a gap risk index based on the triggered adjustment instructions; dynamically adjusting the gap width and depth based on the gap risk index; dividing the boundary gap into subdomains according to the gap risk index and message sensitivity, generating quantitative splitting rules for the number, location, and size of subdomains, and performing geometric division of the gap area; independently calculating the gap risk index for each receiver's subdomain in one-to-many transmission, and achieving group-level gap collaborative control through a coordinator.
[0016] Preferably, the geometric division of the gap region specifically includes: initializing subdomain division parameters based on real-time calculated gap risk index and message sensitivity data; and denoting the number of subdomains as... The calculation formula is as follows: ,in, This represents the total number of messages within the current domain. This indicates rounding up; first, determine the subdomain orientation distribution rules. Let the total number of orientations be K, then the formula for calculating the number of orientations allocated to the core domain side is: The number of lateral numbers in the edge domain is Based on the direct proportionality between subdomain size and message sensitivity, the subdomain size ratio is calculated using the following formula: ,in, It is the total area of the gap region. It is the sum of the sensitivity weights of messages within the subdomain; it integrates all parameters to perform geometric division, mapping the number, orientation, and size rules of the subdomains to specific coordinates, forming the geometric layout of the gap region.
[0017] One or more technical solutions provided in this application have at least the following technical effects or advantages: Through a behavior-driven dynamic encryption mechanism, the precise and on-demand allocation of security policies is achieved: on the one hand, risk entropy values are calculated in real time based on user behavior baselines, which can intelligently detect anomalies and automatically trigger encryption upgrades or authentication enhancements, significantly enhancing the proactive defense capabilities against threats such as data leakage and tampering; on the other hand, this method breaks the rigid mode of traditional encryption, and through dynamic security domains and differentiated isolation technology, optimizes resource consumption while ensuring high security, ensuring message transmission efficiency in high real-time scenarios such as medical emergency and financial transactions, and achieving an excellent balance between security and performance.
[0018] By fusing quantum noise index and behavioral anomaly score, high-risk topology change events can be accurately identified. Furthermore, based on the Boundary Elasticity Score (BES), which includes path stability and resource margin, and the boundary adjustment coefficient, the security domain boundary is dynamically and quantitatively adjusted. This scheme effectively overcomes the rigidity problem of micro-isolation boundaries, significantly improves the security adaptability and seamless isolation of 5G networks under dynamic topology changes, and provides forward-looking protection against potential quantum computing threats.
[0019] By introducing a gap risk index, intelligent dynamic management of the security domain in 5G messaging transmission is achieved, significantly improving the system's adaptability to network topology changes. Its core advantage lies in accurately quantifying risks through real-time monitoring and regression analysis, enabling automatic adjustment of gap parameters and effectively preventing the formation of security gaps. In one-to-many transmission scenarios, group-level collaborative control optimizes resource allocation, reducing redundant isolation overhead while ensuring low latency and high reliability in message transmission. The solution also enhances overall anti-attack capabilities, significantly reduces the risk of information leakage, and maintains an excellent balance between security and efficiency in complex network environments for 5G messaging communication. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating a secure encrypted transmission method for 5G messages according to an embodiment of the present invention. Detailed Implementation
[0021] To facilitate understanding of the present invention, a more complete description of this application will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the present invention.
[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0023] Example 1: Figure 1 This is a flowchart illustrating a secure encrypted transmission method for 5G messages according to an embodiment of the present invention.
[0024] like Figure 1 As shown, a secure encrypted transmission method for 5G messages includes the following steps: S1 collects multi-dimensional behavioral data from users' historical history and uses a quantitative model to transform this multi-dimensional behavioral data into quantifiable indicators, which serve as a baseline model for user behavior.
[0025] The historical multi-dimensional behavioral data includes users' historical message interaction data, such as sending frequency (e.g., number of messages per minute), activity level over a time period (based on 24-hour distribution), contact intimacy (e.g., proportion of frequently used contacts), message type distribution (proportion of text and images), and device context (e.g., frequency of location changes). Data sources cover message logs, identity authentication systems, and network probes to ensure full coverage and real-time performance.
[0026] Quantifiable metrics include the baseline value of the transmission frequency ( This involves calculating the user's historical average sending frequency, for example, user A's F_b is 50 messages per hour, and the time period deviation coefficient ( That is, the standard deviation calculated based on historical active periods) and the contact anomaly rate ( This refers to weighted metrics derived from analyzing historical contact networks using graph algorithms. The initial values for these metrics are generated through machine learning clustering and stored in an encrypted database to ensure data security.
[0027] The quantifiable metrics mentioned above collectively constitute the user's behavioral baseline model. This model is automatically updated every 6 hours using a sliding window model, where new data replaces old data to reflect long-term trends in user behavior.
[0028] S2 captures the user's current multi-dimensional behavioral data when sending messages in real time, compares it with the user behavior baseline model, calculates the behavioral anomaly score, and divides the current behavioral data into risk ranges based on the behavioral anomaly score.
[0029] The formula for calculating the behavioral abnormality score is as follows:
[0030] This represents the current information transmission frequency. It is the baseline value of the transmission frequency. It is the time period deviation coefficient. It represents the contact anomaly score, with α, β, and γ being weighting coefficients (initial values α=0.5, β=0.3, γ=0.2), and can be optimized based on historical data training. The larger the value, the more abnormal the behavior.
[0031] Will <0.3 is defined as low risk (normal behavior, maintaining standard strategy), 0.3≤ A value <0.7 is defined as medium risk (mild behavioral abnormality, triggering strategy adjustment). A score of ≥0.7 is defined as high risk (severe behavioral abnormalities, implementation of reinforcement strategies).
[0032] Specifically, when a user initiates a 5G message sending request, the current operation data is captured in real time, including the instantaneous sending frequency, operation time point, and recipient information.
[0033] Real-time data is compared with corresponding metrics in the user behavior baseline model to calculate an anomaly score. This score comprehensively reflects the degree to which current behavior deviates from historical norms; a higher score indicates a greater risk of anomaly.
[0034] Based on a preset dynamic threshold, this score is mapped to three risk levels: low, medium, and high, and the risk status of each message session is marked in real time.
[0035] Based on the real-time risk assessment, the encryption transmission strategy is dynamically adjusted. For low-risk sessions, the standard encryption strategy is maintained. Once an anomaly score is detected and rises to the medium or high-risk range, a strategy upgrade is automatically triggered, such as increasing the encryption algorithm strength, adding authentication steps, or implementing finer-grained data isolation. If the risk score drops back down within a short period, the strategy automatically reverts to the standard state, ensuring that security measures match the real-time risk.
[0036] S3 dynamically adjusts encryption and isolation strategies based on the abnormal behavior score, and automatically switches the corresponding risk strategy; if the abnormal behavior score falls back to a low-risk state within a preset time window, the standard strategy is restored.
[0037] Specifically, based on preset strategy mapping rules, continuous... The scores are mapped to discrete risk levels, and specific security policy parameters are defined for each level. The parameters mainly cover three aspects: encryption strength: AES-128 algorithm is used for low risk; AES-256 algorithm is upgraded for medium risk; and more complex compound encryption is enabled for high risk, such as combining AES-256 with the Chinese national cryptographic algorithm SM9.
[0038] For low-risk scenarios, implement message-level overall isolation; for medium-risk scenarios, add field-level isolation and encrypt sensitive fields (such as amounts) within messages separately; for high-risk scenarios, implement the finest-grained bit-level isolation and encrypt sensitive data in segments.
[0039] In low-risk situations, one authentication is sufficient; in medium-risk situations, a second biometric authentication is added; in high-risk situations, a continuous authentication mode is enabled, verifying each message.
[0040] When real-time monitoring When the score changes and crosses a preset threshold, the engine will immediately and automatically issue a command to switch to the corresponding risk strategy. For example, when When the score increases from 0.2 (low risk) to 0.5 (medium risk), the encryption algorithm will seamlessly switch from AES-128 to AES-256, and the isolation granularity and authentication frequency will also be adjusted accordingly.
[0041] Simultaneously, a policy rollback mechanism is set up for continuous monitoring. Score, if a session If the score continues to fall back to the low-risk range within a preset time window (e.g., 5 minutes) after triggering a medium or high-risk strategy, the strategy will be automatically restored to the standard state.
[0042] The engine, embedded within the method, is a decision-making mechanism formed by predefined rules and logical judgment processes. Based on the input anomaly score, it automatically and in real-time selects and triggers the corresponding security policy. The rule base upon which the rule engine relies is a collection of "condition-action" pairs: Condition: Risk level ranges divided based on anomaly scores; Action: A specific set of security policy parameter adjustment schemes corresponding to each risk level, including encryption strength, isolation granularity, and authentication frequency.
[0043] The workflow and execution logic of the rules engine are as follows: Input: Real-time calculated abnormal behavior score; Pattern matching: The engine matches the input abnormal behavior score with the predefined risk level range in the rule base to identify the applicable risk level.
[0044] Based on the matched risk level, the engine automatically issues instructions to switch parameters such as encryption, isolation, and authentication to the corresponding policy. This process emphasizes "millisecond-level response" and "no manual intervention required".
[0045] The complexity of the rules engine is also reflected in its dynamic control logic, which includes not only upgrade strategies but also downgrade strategies: Rule: If the abnormal behavior score falls back from the high-risk or medium-risk range and stabilizes in the low-risk range within 5 minutes, a specific "rollback" action is triggered to restore the policy to the standard state.
[0046] S4 constructs an independent security domain for each message. Before sending a message, a security domain configuration is generated based on the abnormal behavior score. During transmission, the security domain moves with the message and dynamically adapts to the network path. When the receiving end decrypts the message, it must be verified through the security domain; otherwise, the message will self-destruct.
[0047] Specifically, after determining the security policy applicable to the current message, the process immediately begins constructing a separate, dynamic security domain for this message. The construction of this security domain begins before the message is sent, and its configuration is directly determined by the behavior anomaly score.
[0048] A security domain is a secure container that encapsulates message content and metadata together. The container's metadata contains core information driving its behavior, such as the sender's behavior metrics and the version number of the policy used; while the encrypted content is the message body processed according to the encryption strength (such as AES-128 or AES-256) corresponding to the anomaly score. This container is implemented using lightweight virtualization technology, ensuring that each security domain has an independent encryption context, fundamentally preventing data leakage between different message domains.
[0049] Once the security domain is constructed, it enters the transmission process along with the message. In complex network paths, the security domain is not static but dynamically adaptable. For example, when a message is transmitted from one edge node to another, the security domain will automatically reconfigure according to the changes in the network environment, ensuring that its protection capabilities continue during the handover process and that it remains bound to the message at all times.
[0050] When the message arrives at the receiving end, the control logic of the security domain enters the final stage.
[0051] The recipient must first pass authentication within the security domain. Only upon successful authentication will the security domain unlock, allowing the recipient to decrypt and read the encrypted message content. Conversely, if authentication fails or an unauthorized access attempt is made, the security domain will immediately trigger a self-destruct mechanism, rendering the message content irrecoverably invalid, thus ensuring that sensitive information is not leaked. The authentication process depends on the authentication frequency policy configured for the security domain and may include verification of keys, digital certificates, or biometric information.
[0052] For a large number of consecutive low-risk messages, the generated security domain configuration template is reused to avoid repeatedly building a complete domain environment for each message. Meanwhile, the verification and decryption operations of the security domain are processed in parallel.
[0053] In a one-to-many transmission scenario, S5 treats users exchanging messages as an interaction group, calculates behavioral indicators for each information receiver to generate a personalized behavioral anomaly score, and uses dynamic group key derivation technology to achieve differentiated isolation within the group.
[0054] Specifically, in one-to-many transmissions, a personalized score for behavioral anomalies is calculated individually for each receiver (r) within the interaction group. , The superscript (r) indicates that the parameter is specific to the receiver r. This represents the current behavior data of receiver r. It is the receiver's own transmission frequency baseline value. It is the receiver time period deviation coefficient. This is the recipient's contact anomaly level. This calculation assigns a current risk level (low, medium, high) to each recipient within the group. For example, in a mass message, recipients identified as high-risk will be marked as individuals requiring individual reinforcement strategies.
[0055] The process employs dynamic group key derivation technology to achieve cryptographic isolation. A master message key is generated for the master message to be sent. .
[0056] Using a key derivation function, and combining each recipient's unique identifier with their personalized behavioral anomaly score, a recipient-specific subkey is derived from the master message key. .
[0057] This mechanism ensures that even when receiving the same master message, each member in the group uses a different key to decrypt it, achieving differentiated isolation at the encryption level.
[0058] S6: When distributing messages within a group, the coordinator monitors for abnormal behavior within the group and adjusts risk strategies accordingly.
[0059] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages: Through a behavior-driven dynamic encryption mechanism, the precise and on-demand allocation of security policies is achieved: on the one hand, risk entropy values are calculated in real time based on user behavior baselines, which can intelligently detect anomalies and automatically trigger encryption upgrades or authentication enhancements, significantly enhancing the proactive defense capabilities against threats such as data leakage and tampering; on the other hand, this method breaks the rigid mode of traditional encryption, and through dynamic security domains and differentiated isolation technology, optimizes resource consumption while ensuring high security, ensuring message transmission efficiency in high real-time scenarios such as medical emergency and financial transactions, and achieving an excellent balance between security and performance.
[0060] Example 2: In Example 1, when the anomaly score increases, the system dynamically adjusts the encryption strength and isolation granularity to address security risks, effectively improving the security of 5G message transmission. However, this solution mainly relies on anomaly detection at the user behavior level and lacks effective responses to uncertainties at the underlying network physical layer (such as random channel fluctuations caused by quantum noise) and the rigidity of micro-isolation boundaries. Dynamic changes in network topology (such as base station switching and elastic scaling of edge nodes) may cause a lag in security domain boundary adjustments, creating protection gaps. Since the severity of topology changes and physical channel disturbances vary significantly in different scenarios, simply adjusting security strategies uniformly based on anomaly scores inevitably leads to insufficient adaptability and inaccurate responses. To achieve more granular dynamic management of security domain boundaries and seamless isolation under topology changes, it is necessary to simultaneously integrate quantum noise indicators and network topology states to quantitatively assess and adjust boundary elasticity in real time.
[0061] In some embodiments, a security domain configuration is generated based on the behavior anomaly score before message sending. Step S4 further includes: S41 deploys a quantum random number generator-compatible sensor at the physical layer of the 5G network to collect quantum noise parameters at millisecond-level frequency and quantize them into a quantifiable index, the quantum noise index (QNI).
[0062] Among them, quantum noise parameters include: channel phase fluctuation value ( (The unit is radians, used to reflect the random changes in the signal phase) and photon counting bias ( The unit is standard deviation, which is used to measure the degree of disturbance during the transmission of optical quantum particles.
[0063] The formula for calculating the quantum noise index is:
[0064] in The QNI calculation result is normalized to the range of 0 to 1, which is the standard deviation of historical photon counts. When its value is greater than 0.7, it indicates high physical channel uncertainty, which may indicate topological changes such as base station handover.
[0065] S42 integrates the quantum noise index with the behavioral anomaly score. When the quantum noise index increases abnormally and the behavioral anomaly score increases, it is determined to be a high-risk topological change event.
[0066] The determination of an abnormal increase relies on a fixed 100-millisecond time window. The change in the quantum noise index ΔQNI = |current QNI - historical QNI|. An abnormal increase is determined when ΔQNI ≥ 0.3 or the rate of change of ΔQNI within 100 seconds ≥ 3 / s. In practical applications, a dynamic threshold is set and must be used in conjunction with an increase in the abnormal behavior score (e.g., an increase in the abnormal behavior score exceeding 0.2). The determination threshold is dynamically updated every 12 hours based on historical data.
[0067] S43 calculates the topological boundary elasticity score of high-risk topological change events based on quantum noise indices and topological change events, and dynamically adjusts the security domain boundary based on the boundary elasticity threshold.
[0068] The formula for calculating the boundary elasticity fraction is as follows:
[0069] Path_Stability is the path stability score (0-1), calculated based on historical transmission success rate, such as a score of 0.95 for a 95% success rate; Resource_Margin is the ratio of remaining node resources (0-1), such as CPU / memory remaining rate.
[0070] The boundary elasticity threshold is as follows: when BES≥0.8, the elasticity is sufficient, and the safe domain is expanded (e.g., merging adjacent domains, the boundary is expanded outward by 10%); when 0.5≤BES<0.8, the elasticity is moderate, and the current boundary is maintained; when BES<0.5, the elasticity is insufficient, and the boundary is shrunken (e.g., the boundary is shrunken inward by 5%, splitting the large domain into subdomains).
[0071] Topology change events are dynamic changes in the connectivity, physical location, or logical path of network components that constitute a 5G message transmission path.
[0072] S44: When the degree of topological change exceeds the degree threshold, boundary adjustment is triggered, and the original boundary range and the adjusted boundary range are used as the gap between the boundaries.
[0073] The degree of change is measured by the rate of change of QNI (ΔQNI). For example, when the rate of change reaches 10%, ΔQNI = 0.1.
[0074] The boundary adjustment formula is:
[0075] Where ΔQNI is the change in the quantum noise index, The reference change is a preset constant threshold (e.g., 0.05), which serves to adjust the fraction... The magnitude of the ratio has a clear meaning; a ratio greater than 1 indicates a drastic change. It is the change in signal transmission angle (unit: degrees) calculated based on the geographical offset of the base station. It is the change in reference angle, which is a preset constant threshold (e.g., 5 degrees). , These are weighting coefficients, satisfying... + =1, used to balance the importance of QNI variation and angle variation.
[0076] The unit for the degree of boundary contraction is millimeters. The correspondence between the degree of boundary contraction and the change in angle can be understood as follows: when the topological change is less than 5%, the boundary edge contracts inward by 0.1 millimeters and the angle changes by 5 degrees. There is a mapping relationship between the degree of boundary contraction and the change in angle, and the specific mapping relationship needs to be determined according to the actual application scenario.
[0077] S45, in one-to-many transmission, calculates an independent boundary elasticity score and boundary adjustment coefficient for each receiver and adjusts the boundary.
[0078] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages: By fusing quantum noise index and behavioral anomaly score, high-risk topology change events can be accurately identified. Furthermore, based on the Boundary Elasticity Score (BES), which includes path stability and resource margin, and the boundary adjustment coefficient, the security domain boundary is dynamically and quantitatively adjusted. This scheme effectively overcomes the rigidity problem of micro-isolation boundaries, significantly improves the security adaptability and seamless isolation of 5G networks under dynamic topology changes, and provides forward-looking protection against potential quantum computing threats.
[0079] Example 3: In the secure encrypted transmission method for 5G messages described in Example 2, the security domain boundary is dynamically adjusted by using the quantum noise index and boundary elasticity score, achieving elastic isolation based on physical layer uncertainty and significantly improving the adaptive capability under topology changes. However, in real-world complex network environments, the risk characteristics of security domain gaps (i.e., inter-domain transition areas) vary considerably depending on topology abrupt changes, attack patterns, and sub-domain interaction states. The degree of gap risk is the result of multiple factors coupled between the security domain and external threats, as well as internal policy coordination. Facing gaps with different risk levels, using a uniform boundary adjustment model makes it difficult to accurately quantify the real-time threat of the gaps, easily leading to response delays or mismatched isolation granularity. Especially in multi-receiver scenarios, insufficient inter-domain coordination may amplify the leakage risk of security gaps. Since the correlation between gap risk and indicators such as network attack frequency and policy consistency has historically varied significantly, the protection requirements for gap management inevitably exhibit dynamic differentiation. To further refine the distinction of gap protection mechanisms and achieve more accurate adaptive control, it is necessary to consider the gap risk index for further optimization and improvement.
[0080] In some embodiments, in step S44, the gap at the boundary further includes: S441 deploys probes in the security domain gap area to monitor cross-domain message traffic, abnormal access counts, and policy difference rates in real time; it calculates the correlation between gap risk and external attacks through regression analysis, generates a gap status profile, and triggers adjustment commands.
[0081] Specifically, lightweight probes are deployed in the gap area (i.e. the gap area between security domains) to monitor key indicators in real time at a frequency of once per second, including cross-domain message traffic (unit: messages / second), number of abnormal accesses (unit: times / second), and policy difference rate (unit:%, reflecting the degree of difference in policy versions between subdomains).
[0082] A linear regression model was used to analyze the correlation between gap risk and external attacks. Gap risk was represented by the number of abnormal accesses in the monitoring data (denoted as Y), and external attacks were represented by the attack frequency (in times / second) provided by the threat intelligence platform (denoted as X). The regression model formula is as follows: Y represents the gap risk proxy indicator (number of abnormal accesses); X represents the frequency of external attacks. It is the intercept term, representing the baseline risk without attack. These are regression coefficients, quantifying the impact of each unit increase in X on Y (e.g., =0.05 means that for every 1 attack per second, the number of abnormal accesses increases by 0.05 per second. This represents the error term. Regression coefficients. The linear correlation strength is assessed by estimating using the least squares method and calculating the Pearson correlation coefficient r. If |r| > 0.7 and Significant (p-value < 0.05), indicating a strong correlation.
[0083] Based on the regression results, a gap state profile is generated and an adjustment command is triggered. When there is a strong positive correlation (r>0.7) and the current number of abnormal visits exceeds the threshold (e.g., 10 times / second), the profile is marked as "high risk"; when there is a weak correlation (|r|<0.3), it is marked as "low risk".
[0084] S442 calculates the gap risk index based on the trigger adjustment command; and dynamically adjusts the gap width and depth based on the gap risk index.
[0085] Specifically, the Gap Risk Index (GRI) is calculated using real-time monitoring data (including cross-domain message traffic, abnormal access counts, and policy discrepancy rates). The formula for calculating GRI is:
[0086] Among them, the sensitivity weighted sum is the weighted sum of the core domain message weight (1.0) and the edge domain message weight (0.3), calculated based on the real-time message type distribution; the external attack frequency comes from the threat intelligence platform, and the unit is the number of attacks per second; the subdomain boundary policy consistency ratio is the reciprocal of the policy difference ratio between subdomains (range 0-1), and the larger the difference, the lower the ratio.
[0087] The real-time threat level is assessed based on the calculated Gap Risk Index (GRI). If the GRI > 0.7, it is considered a high-risk level; if the GRI < 0.3, it is considered a low-risk level; otherwise, it is considered a medium-risk level.
[0088] Using conditional rules, the width baseline is adjusted in 10 logical units to adjust the gap width. When GRI > 0.7, the width is set to 25 units; when GRI < 0.3, the width is set to 3 units. The gap depth is adjusted according to the gap depth.
[0089] S443 divides the gaps at the boundary into subdomains based on the gap risk index and message sensitivity, generates quantitative splitting rules for the number, orientation, and size of subdomains, and performs geometric division of the gap region.
[0090] Specifically, the subdomain partitioning parameters are initialized based on the real-time calculated Gap Risk Index (GRI) and message sensitivity data. The GRI is derived from the real-time monitoring results of step S442 (range 0-1), while message sensitivity is dynamically weighted according to message type (core domain messages have a weight of 1.0, and edge domain messages have a weight of 0.3). For example, if the current gap region contains 10 messages, with core domain messages accounting for 60%, then the overall weighted sensitivity sum is 10 × 0.6 × 1.0 + 10 × 0.4 × 0.3 = 6 + 1.2 = 7.2. The number of subdomains is denoted as... The calculation formula is as follows: ,in, This represents the total number of messages within the current domain. This indicates rounding up. The formula ensures the number of subdomains is proportional to the risk level and message size, but is capped at 8 to avoid over-splitting. For example, when GRI = 0.8 and... When =50, .
[0091] First, determine the subdomain orientation distribution rules. Orientation allocation is based on spatial weights according to message sensitivity, with a 30% increase in subdomain distribution density in the core domain (high-risk area). Specifically, assuming the total number of orientations is K (usually preset according to the topology, such as 8 directions), the formula for calculating the number of orientations allocated to the core domain is: The number of lateral numbers in the edge domain is For example, if K=8, then the number of lateral numbers in the core domain is... The edge domain side has two orientations.
[0092] Based on the direct proportionality between subdomain size and message sensitivity, the subdomain size ratio is calculated to ensure that highly sensitive messages receive greater isolation. The calculation formula is as follows: ,in, It is the total area of the gap region (in logical units). This is the sum of the sensitivity weights of messages within a subdomain. For example, if a subdomain contains 3 core messages (weight sum = 3.0), and the total sensitivity sum is 10, then its size accounts for 30%.
[0093] All parameters are integrated for geometric partitioning. The number, orientation, and size rules of subdomains are mapped to specific coordinates to form the geometric layout of the gap regions. After partitioning, each subdomain independently manages its encryption policy and access control. The entire process iterates every 5 minutes, or is immediately triggered for repartitioning when the GRI changes, ensuring adaptability to network changes.
[0094] S445 independently calculates the gap risk index for each receiver's subdomain in a one-to-many transmission, and achieves group-level gap coordinated control through a coordinator.
[0095] Specifically, for each receiver's subdomain, a gap risk index (GRI) is independently calculated based on its specific message flow and network environment. The calculation is performed in real time, utilizing the receiver's message sensitivity data, the frequency of specific external attacks (from a threat intelligence platform targeting its network paths), and the subdomain policy consistency ratio (reflecting the difference between this subdomain and other domains in the group). The calculation frequency remains consistent with Example 2, updating every 100 milliseconds to ensure real-time performance.
[0096] The coordinator (a logical control unit) aggregates the GRI values of all receivers and calculates the group-level average GRI (denoted as GRI). ):
[0097] Where N is the number of receivers, It is the GRI value of the i-th receiver. The coordinator also monitors the variance of the GRI distribution within the group to identify uneven risk (such as triggering an alarm when the variance is greater than 0.1).
[0098] Based on the group-level average GRI coordinator issuing group-level control commands, if If the value is ≥0.7, the overall isolation level is increased (e.g., the depth of all subdomain gaps is increased by 1 layer); if If the GRI is less than 0.3 and the variance is less than 0.05, the isolation level is reduced (e.g., the gap width is uniformly reduced by 20%). For high-risk individual receivers (GRI > 0.7), the coordinator triggers an independent reinforcement strategy (e.g., additional authentication is enabled in their subdomains).
[0099] Control commands are transmitted to each subdomain through message header metadata to adjust gap parameters (width, depth) in real time.
[0100] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages: By introducing a gap risk index, intelligent dynamic management of the security domain in 5G messaging transmission is achieved, significantly improving the system's adaptability to network topology changes. Its core advantage lies in accurately quantifying risks through real-time monitoring and regression analysis, enabling automatic adjustment of gap parameters and effectively preventing the formation of security gaps. In one-to-many transmission scenarios, group-level collaborative control optimizes resource allocation, reducing redundant isolation overhead while ensuring low latency and high reliability in message transmission. The solution also enhances overall anti-attack capabilities, significantly reduces the risk of information leakage, and maintains an excellent balance between security and efficiency in complex network environments for 5G messaging communication.
[0101] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A secure encrypted transmission method for 5G messages, characterized in that, include: S1 collects multi-dimensional behavioral data from users' historical history and uses a quantitative model to transform the multi-dimensional behavioral data into quantifiable indicators, which serve as a baseline model for user behavior. S2, captures the user's current multi-dimensional behavioral data when sending messages in real time, compares it with the user behavior baseline model, calculates the behavior anomaly score, and divides the current behavioral data into risk ranges based on the behavior anomaly score. S3 dynamically adjusts encryption and isolation strategies based on abnormal behavior scores and automatically switches the corresponding risk strategies. If the abnormal behavior score falls back to a low-risk state within a preset time window, the standard strategy will be restored. S4 constructs an independent security domain for each message. Before sending a message, a security domain configuration is generated based on the abnormal behavior score. During transmission, the security domain moves with the message and dynamically adapts to the network path. When the receiving end decrypts the message, it must be verified through the security domain; otherwise, the message will self-destruct. S5, in a one-to-many transmission scenario, treats users who exchange messages as an interaction group, calculates behavioral indicators for each information receiver to generate personalized behavioral anomaly scores, and uses dynamic group key derivation technology to achieve differentiated isolation within the group. S6: When distributing messages within a group, the coordinator monitors for abnormal behavior within the group and adjusts risk strategies accordingly.
2. The secure encrypted transmission method for 5G messages as described in claim 1, characterized in that, The calculation of the abnormal behavior score specifically includes: capturing current operation data in real time when a user initiates a 5G message sending request; comparing the real-time data with the corresponding indicators in the user behavior baseline model to calculate the abnormal behavior score, using the following formula: , This represents the current information transmission frequency. It is the baseline value of the transmission frequency. It is the time period deviation coefficient. It represents the abnormality level of the contact, with α, β, and γ being weighting coefficients.
3. The secure encrypted transmission method for 5G messages as described in claim 2, characterized in that, The user behavior baseline model specifically includes: quantifying multi-dimensional behavioral data based on user history, with quantifiable indicators including baseline value of sending frequency, time period deviation coefficient, and contact abnormality; and constructing a user behavior baseline model based on the quantifiable indicators.
4. The secure encrypted transmission method for 5G messages as described in claim 1, characterized in that, Before sending the message, a security domain configuration is generated based on the abnormal behavior score. Specifically, this includes: after determining the security policy applicable to the current message, the process constructs an independent dynamic security domain for this message, encapsulating the message content and metadata in a secure container; after the security domain is constructed, it enters the transmission process along with the message; when the message arrives at the receiving end, the control logic of the security domain enters the final stage; the receiving party must pass the verification of the security domain before the security domain is unlocked, allowing the receiving party to decrypt and read the encrypted message content; otherwise, if the verification fails or an unauthorized access attempt is made, the security domain will immediately trigger a self-destruct mechanism, causing the message content to become irrecoverably invalid.
5. The secure encrypted transmission method for 5G messages as described in claim 4, characterized in that, The security strategy specifically includes: mapping continuous abnormal behavior scores to discrete risk levels according to preset policy mapping rules, and defining clear security policy parameters for each level; the parameters mainly cover encryption strength and implementing message-level overall isolation under low risk; using the AES-128 algorithm under low risk; upgrading to the AES-256 algorithm under medium risk; and using a more complex compound encryption under high risk; completing one authentication under low risk; adding secondary biometric authentication under medium risk; and enabling continuous authentication mode under high risk, verifying each message.
6. The secure encrypted transmission method for 5G messages as described in claim 1, characterized in that, The process of generating a security domain configuration based on anomaly scores before message transmission further includes: S41, deploying a quantum random number generator-compatible sensor at the 5G network physical layer to collect quantum noise parameters at millisecond-level frequencies and quantize them into a quantifiable index, the quantum noise index (QNI); S42, fusing the quantum noise index with the anomaly scores, and determining a high-risk topology change event when the quantum noise index increases abnormally and the anomaly score rises; S43, calculating the topology boundary elasticity score of the high-risk topology change event based on the quantum noise index and the topology change event, and dynamically adjusting the security domain boundary based on the boundary elasticity threshold; S44, triggering boundary adjustment when the degree of topology change exceeds the degree threshold, with the original boundary range and the adjusted boundary range serving as the boundary gap; S45, in one-to-many transmission, calculating an independent boundary elasticity score and boundary adjustment coefficient for each receiver and adjusting the boundary.
7. The secure encrypted transmission method for 5G messages as described in claim 6, characterized in that, The quantum noise index QNI includes: channel phase fluctuation value And photon counting deviation; the formula for calculating the quantum noise index is: in, The quantum noise index (QNI) is calculated to be the standard deviation of historical photon counts and normalized to the range of 0 to 1. A value greater than 0.7 indicates that a topological mutation has occurred.
8. The secure encrypted transmission method for 5G messages as described in claim 7, characterized in that, The abnormal increase in the quantum noise index is specifically defined as follows: the determination of abnormal increase depends on a fixed 100-millisecond time window; the change in quantum noise index ΔQNI = |current QNI - historical QNI|, and when ΔQNI ≥ 0.3 or the rate of change of ΔQNI within 100 seconds ≥ 3 / s, it is determined to be an abnormal increase.
9. The secure encrypted transmission method for 5G messages as described in claim 6, characterized in that, The gaps at the boundaries include: deploying probes in the security domain gap area to monitor cross-domain message traffic, abnormal access frequency, and policy difference rate in real time; calculating the correlation between gap risk and external attacks through regression analysis, generating a gap status profile, and triggering adjustment instructions; calculating the gap risk index based on the triggered adjustment instructions; dynamically adjusting the gap width and depth based on the gap risk index; dividing the boundary gap into subdomains according to the gap risk index and message sensitivity, generating quantitative splitting rules for the number, location, and size of subdomains, and performing geometric division of the gap area; independently calculating the gap risk index for each receiver's subdomain in one-to-many transmission, and achieving group-level gap collaborative control through a coordinator.
10. The secure encrypted transmission method for 5G messages as described in claim 9, characterized in that, The geometric division of the gap region specifically includes: initializing subdomain division parameters based on real-time calculated gap risk index and message sensitivity data; and denoting the number of subdomains as... The calculation formula is as follows: ,in, This is the total number of messages within the current domain. This indicates rounding up; first, determine the subdomain orientation distribution rules. Let the total number of orientations be K, then the formula for calculating the number of orientations allocated to the core domain side is: The number of lateral numbers in the edge domain is Based on the direct proportionality between subdomain size and message sensitivity, the subdomain size ratio is calculated using the following formula: ,in, It is the total area of the gap region. It is the sum of the sensitivity weights of messages within the subdomain; it integrates all parameters to perform geometric division, mapping the number, orientation, and size rules of the subdomains to specific coordinates, forming the geometric layout of the gap region.