Algorithm selection method and device, storage medium and computer program product
By using filtering and mapping functions to assist in selecting PQC algorithm parameters, a first or second encryption configuration that meets encryption requirements can be formed. This solves the problem of inaccurate algorithm selection in existing technologies and improves the accuracy and flexibility of encryption configuration.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
- Filing Date
- 2026-02-05
- Publication Date
- 2026-05-15
AI Technical Summary
In existing technologies, the selective use of PQC algorithms mainly relies on user experience, resulting in insufficient accuracy and flexibility in algorithm configuration selection, and failing to meet the diverse needs of different users for encryption functions, devices, and security.
By filtering the algorithm parameters of the encryption algorithm, a first encryption configuration that meets the encryption requirements is formed, and the optimal configuration is selected based on the distance value; if the requirements are not met, a second encryption configuration that meets the lower limit of security strength is selected, and the optimal configuration is selected based on the loss value. A neural network is used to train the mapping function to assist in the selection.
It improves the accuracy and flexibility of encryption algorithm configuration selection, proactively provides the optimal encryption configuration, reduces the inaccuracy of user manual selection, and adapts to the diverse needs of different device environments.
Smart Images

Figure CN122053152A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technology, and in particular to an algorithm selection method, apparatus, storage medium, and computer program product. Background Technology
[0002] Post-quantum cryptography (PQC) algorithms, represented by lattice cryptography, can solve the cryptographic problems brought about by quantum algorithms to a certain extent because these algorithms do not rely on the difficulty of solving problems such as large integer factorization. There are many PQC algorithms. In practical applications, the algorithm functions are mainly divided into two categories: key encapsulation and digital signature. These algorithms can select different algorithm parameters (key length, etc.) for encapsulation or signature.
[0003] Different PQC algorithms have their own advantages and disadvantages. Therefore, when users have different needs for encryption functions, devices, and security, they should choose the appropriate cryptographic algorithm. However, the current selective use of encryption algorithms mainly relies on user experience and subjective understanding of the algorithms, resulting in insufficient accuracy and effectiveness in algorithm configuration selection and poor flexibility. Summary of the Invention
[0004] This application provides an algorithm selection method, apparatus, storage medium, and computer program product.
[0005] The technical solution of this application is implemented as follows: This application provides an algorithm selection method, including: For each encryption algorithm with a specified function, first algorithm parameters that meet the encryption requirements in a first environment are selected to form each first encryption configuration; wherein, the first environment is the device environment in which the encryption algorithm is deployed, and each first encryption configuration includes an encryption algorithm with the specified function and its first algorithm parameters. If multiple first encryption configurations are obtained, the optimal encryption configuration is selected from them based on the distance value between each first encryption configuration and the encryption requirement; wherein, the distance value between each first encryption configuration and the encryption requirement is used to characterize the degree to which it satisfies the encryption requirement; If no first encryption configuration is obtained, then for each encryption algorithm with the specified function, the second algorithm parameters that meet the lower limit of the security strength in the encryption requirements in the first environment are selected to form each second encryption configuration; wherein, each second encryption configuration includes an encryption algorithm with the specified function and its second algorithm parameters; Based on the loss value between each second encryption configuration and the encryption requirement, the optimal encryption configuration is selected from each second encryption configuration; wherein, the loss value between each second encryption configuration and the encryption requirement is used to characterize the degree to which it does not meet other limiting conditions in the encryption requirement while satisfying the lower limit of security strength.
[0006] In the above method, the encryption requirements also include one or more of the following: storage space limit, communication bandwidth limit, and computational overhead limit.
[0007] The above method also includes: Based on the performance metrics of each first encryption configuration under k dimensions, a set of performance metrics is formed; wherein, a set of performance metrics includes the performance metrics of each first encryption configuration under the same dimension, and the k dimensions include the dimensions to which each limiting condition in the encryption requirement belongs; For each of the k dimensions, under the constraints, calculate the minimum absolute error and maximum absolute error with a set of performance indicators under the same dimension; For each first encryption configuration, calculate the absolute error between the performance index under each of the k dimensions and the limiting conditions under the same dimension, and obtain the original deviation value under each of the k dimensions; For each first encryption configuration, the original deviation value in each of the k dimensions is normalized and mapped based on the minimum absolute error and maximum absolute error under the same dimension, so as to obtain the normalized deviation value in each of the k dimensions. For each first encryption configuration, the normalized deviation values under the k dimensions are weighted and summed to determine the distance value between the configuration and the encryption requirement, using the weights of the performance indicators under different dimensions.
[0008] The above method also includes: Based on the performance metrics of each second encryption configuration under n dimensions, each set of performance metrics is obtained; wherein, a set of performance metrics includes the performance metrics of each second encryption configuration under the same dimension, and the n dimensions include the dimensions to which the limiting conditions in the encryption requirements that are different from the lower limit of the security strength belong; For each of the n dimensions, under the constraints, calculate the minimum absolute error and maximum absolute error of a set of performance indicators under the same dimension; For each second encryption configuration, calculate the absolute error between the performance index and the constraint conditions in each of the n dimensions, and obtain the original deviation value in each of the n dimensions. For each of the second encryption configurations, the original deviation values in each of the n dimensions are normalized and mapped based on the minimum absolute error and maximum absolute error under the same constraint conditions, to obtain the normalized deviation values in each of the n dimensions. For each second encryption configuration, the normalized deviation values under the n dimensions are weighted and summed using the weights of the performance indicators set under different dimensions, and the result is determined as the loss value between the encryption configuration and the encryption requirements.
[0009] The above method also includes: Based on the performance scores of performing encryption operations using the optimal encryption configuration under different dimensions, the weights of the performance indicators under different dimensions are updated.
[0010] The above method also includes: For each first encryption configuration or each second encryption configuration, the first algorithm parameters or the second algorithm parameters are substituted into the mapping function corresponding to the encryption algorithm to obtain the performance indicators under each dimension. Among them, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm and the performance indicators under each dimension in the first environment.
[0011] The above method also includes: Collect performance metrics across various dimensions when performing encryption operations using the optimal encryption configuration; Using the collected performance metrics, train the mapping function corresponding to the encryption algorithm in the optimal encryption configuration; Among them, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm and the performance indicators under each dimension in the first environment.
[0012] This application provides an algorithm selection device, including: a processor, a memory, and a communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is used to execute one or more computer programs stored in the memory to implement the above-described algorithm selection method.
[0013] This application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described algorithm selection method.
[0014] This application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described algorithm selection method.
[0015] This application provides an algorithm selection method, apparatus, storage medium, and computer program product. The method includes: for each encryption algorithm with a specified function, selecting first algorithm parameters that meet encryption requirements in a first environment to form first encryption configurations; wherein the first environment is a device environment for deploying encryption algorithms, and each first encryption configuration includes an encryption algorithm with a specified function and its first algorithm parameters; if multiple first encryption configurations are obtained, selecting the optimal encryption configuration based on the distance value between each first encryption configuration and the encryption requirements; wherein the distance value between each first encryption configuration and the encryption requirements is used to characterize the degree to which it meets the encryption requirements; if no first encryption configuration is obtained, for each encryption algorithm with a specified function, selecting second algorithm parameters that meet the lower limit of security strength in the encryption requirements in the first environment to form second encryption configurations; wherein each second encryption configuration includes an encryption algorithm with a specified function and its second algorithm parameters; selecting the optimal encryption configuration based on the loss value between each second encryption configuration and the encryption requirements; wherein the loss value between each second encryption configuration and the encryption requirements is used to characterize the degree to which it does not meet other limiting conditions in the encryption requirements while meeting the lower limit of security strength. The technical solution provided in this application can proactively offer the optimal encryption configuration, rather than simply allowing users to make manual choices. This greatly solves the problem of users without professional knowledge making inaccurate selections of various encryption algorithms and their parameters, and improves the accuracy and flexibility of algorithm configuration selection. Attached Figure Description
[0016] Figure 1 A flowchart illustrating an algorithm selection method provided in an embodiment of this application; Figure 2 A schematic diagram illustrating the framework of an algorithm selection method provided in an embodiment of this application; Figure 3 A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 1 ; Figure 4 A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 2 ; Figure 5 A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 3 . Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0018] The technical solutions of this application and how they solve the aforementioned technical problems will be described in detail below through embodiments and in conjunction with the accompanying drawings. The embodiments below can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0019] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0020] This application provides an algorithm selection method, which is executed by an algorithm selection device. The algorithm selection device can be any electronic device such as a mobile phone or computer, and this application does not limit it.
[0021] In embodiments of this application, a relationship function between the performance metrics of an encryption algorithm and its algorithm parameters can be pre-trained using a neural network in a first environment. The first environment is the device environment in which the encryption algorithm is deployed, such as the device environment of a server. The first environment can be set based on requirements or flexibly selected. Firstly, the cryptographic algorithm library... Offline data collection is performed on the encryption algorithms to test different encryption algorithms. First environment Different algorithm parameters are assigned below Storage space consumed per hour Communication bandwidth Calculation cost and safety strength (The amount of work required to break the cryptographic algorithm, in bits), Algorithm parameters This could be key length, etc. Select a suitable activation function, and use a neural network algorithm to fit the corresponding mapping function to the test data, thus obtaining the storage function. Communication bandwidth function Calculate the cost function Safety strength function .
[0022] In the embodiments of this application, the mapping function, i.e. the storage function, corresponding to each encryption algorithm i Communication bandwidth function Calculate the cost function Safety strength function , used to establish the algorithm parameters of encryption algorithm i in the first environment Performance metrics across various dimensions (storage space) Communication bandwidth Calculation cost and safety strength The correspondence between ).
[0023] In the embodiments of this application, a cryptographic algorithm library This could be a PQC cryptographic algorithm library, where each encryption algorithm can be categorized by function. For example, algorithms can be divided into two categories based on their function: public-key encryption algorithms and public-key encryption algorithms. Signature Algorithm .
[0024] The following details the password selection method provided in this application based on the above content.
[0025] Figure 1 This is a flowchart illustrating an algorithm selection method provided in an embodiment of this application. Figure 1 As shown in the embodiments of this application, the algorithm selection method mainly includes the following steps: S101. For each encryption algorithm with a specified function, select the first algorithm parameters that meet the encryption requirements in the first environment to form each first encryption configuration; wherein, the first environment is the device environment in which the encryption algorithm is deployed, and each first encryption configuration includes an encryption algorithm with a specified function and its first algorithm parameters.
[0026] In the embodiments of this application, the algorithm selection device can select first algorithm parameters that meet the encryption requirements in a first environment for each encryption algorithm with a specified function, and form each first encryption configuration.
[0027] It should be noted that, in the embodiments of this application, referring to the foregoing content, encryption algorithms can be divided according to function. Thus, the user can specify the function of the encryption algorithm to be selected, that is, the specified function mentioned above. The algorithm selection device can first perform preliminary screening according to the specified function and select each encryption algorithm with the specified function. The specific specified function and the encryption algorithm with the specified function are not limited in the embodiments of this application.
[0028] It should be noted that in the embodiments of this application, each first encryption configuration includes an encryption algorithm and its first algorithm parameters. For different first encryption configurations, the encryption algorithms included are different and / or the algorithm parameters are different. In each first encryption configuration, the first algorithm parameters of the encryption algorithm are the algorithm parameters of the encryption algorithm that meet the encryption requirements in the first environment.
[0029] It should be noted that, in the embodiments of this application, the encryption requirements correspond to the performance indicators of the above-mentioned encryption algorithms under different dimensions. These encryption requirements may include limiting conditions under different dimensions, such as the upper limit of storage space under the storage dimension, the upper limit of communication bandwidth under the bandwidth dimension, the upper limit of computational overhead under the computational overhead dimension, and the lower limit of security strength under the security dimension. Specific encryption requirements are not limited in the embodiments of this application.
[0030] Specifically, in the embodiments of this application, the designated function is represented as function f, and the first environment is represented as... The encryption requirement is expressed as , First, based on function Determine whether it is a public-key encryption algorithm or a digital signature algorithm, i.e. Select all encryption algorithms that possess function f. That is, from its different algorithm parameters The first algorithm parameter that satisfies the following equation (1) is selected. : (1) Therefore, the selected encryption algorithm i and its first algorithm parameters are... This forms the first encryption configuration. It should be noted that, for the sake of brevity, the superscript of the function will be used later. Omit.
[0031] S102. If multiple first encryption configurations are obtained, the optimal encryption configuration is selected from them based on the distance value between each first encryption configuration and the encryption requirement; wherein, the distance value between each first encryption configuration and the encryption requirement is used to characterize the degree to which it meets the encryption requirement.
[0032] In the embodiments of this application, the algorithm selection device performs step S101. If multiple first encryption configurations are obtained, the optimal encryption configuration is further selected based on the distance value between each first encryption configuration and the encryption requirement.
[0033] It should be noted that, in the embodiments of this application, a method for calculating the distance value can be defined to calculate the distance value between each first encryption configuration and the encryption requirement, so as to measure the degree to which each first encryption configuration meets the encryption requirement and select the optimal encryption configuration from it.
[0034] In the embodiments of this application, the algorithm selection device can determine the distance value between each first encryption configuration and the encryption requirement according to the following steps: forming a set of performance indicators based on the performance indicators of each first encryption configuration in k dimensions; wherein, a set of performance indicators includes the performance indicators of each first encryption configuration in the same dimension, and the k dimensions include the dimensions to which each constraint condition in the encryption requirement belongs; for each constraint condition in the k dimensions, calculating the minimum absolute error and the maximum absolute error with the set of performance indicators in the same dimension; for each first encryption configuration, calculating the absolute error between the performance indicator in each of the k dimensions and the constraint condition in the same dimension, obtaining the original deviation value in each of the k dimensions; for each first encryption configuration, normalizing and mapping the original deviation value in each of the k dimensions based on the minimum absolute error and the maximum absolute error of the constraint condition in the same dimension, obtaining the normalized deviation value in each of the k dimensions; for each first encryption configuration, using the weights of the performance indicators in different dimensions, weighted summing of the normalized deviation values in the k dimensions, determining the distance value between it and the encryption requirement.
[0035] It should be noted that, in the embodiments of this application, the algorithm selection device is configured for each first encryption configuration. The specific first algorithm parameters The mapping function corresponding to the encryption algorithm, i.e., the storage function, is substituted into it. Communication bandwidth function Calculate the cost function Safety strength function This can be mapped to performance metrics across various dimensions, i.e. .
[0036] Specifically, in the embodiments of this application, if multiple first encryption configurations are obtained... Each of the first encryption configurations meets the encryption requirements. Define distance value Used to measure different first encryption configurations The greater the distance value, the more adequately the encryption requirements are met. The specific calculation method is as follows: First, calculate the following formula: (2) (3) (4) (5) (6) (7) (8) (9) in, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error.
[0037] Secondly, based on each first encryption configuration Performance metrics ( The distance between the encryption requirement M and the target M is calculated using the following formula. : (10) in These are the weights of performance metrics under the storage, bandwidth, computational overhead, and security dimensions, respectively. These weights can be pre-defined, representing the user's emphasis on storage, bandwidth, computational overhead, and security requirements. Finally, the first encryption configuration with the largest distance value is selected. As the optimal encryption configuration, i.e. .
[0038] It should be noted that the calculation method for the distance value described above in the embodiments of this application is merely exemplary. Of course, other calculation methods can also be used to calculate the distance value. Based on the above calculation method, the distance value between each first encryption configuration and the encryption requirement is positively correlated or proportional to the degree to which each first encryption configuration meets the encryption requirement. Therefore, the first encryption configuration with the largest distance value is selected as the optimal encryption configuration.
[0039] S103. If no first encryption configuration is obtained, for each encryption algorithm with a specified function, select the second algorithm parameters that meet the lower limit of security strength in the encryption requirements under the first environment to form each second encryption configuration; wherein each second encryption configuration includes an encryption algorithm with a specified function and its second algorithm parameters.
[0040] In the embodiments of this application, after performing step S101 to screen the encryption algorithms and their algorithm parameters for the specified functions, it is possible that for each encryption algorithm with the specified functions, there are no first algorithm parameters that meet the encryption requirements in the first environment, so that no first encryption configuration can be formed, that is, no first encryption configuration is obtained. Therefore, for each encryption algorithm with the specified functions, second algorithm parameters that meet the lower limit of security strength in the encryption requirements in the first environment are screened to form each second encryption configuration.
[0041] It should be noted that, in the embodiments of this application, as described in steps S101 and S102 above, the encryption requirements may include multiple dimensions of constraints. In the first environment, the encryption algorithm with the specified function cannot meet all the constraints of all dimensions. Considering that the most important thing in encryption operation is security, the second algorithm parameters that meet the lower limit of the security strength in the encryption requirements are selected first for each encryption algorithm with the specified function in the first environment to form each second encryption configuration.
[0042] Specifically, in the embodiments of this application, the designated function is represented as function f, and the first environment is represented as... The encryption requirement is First, based on function Determine whether it is a public-key encryption algorithm or a digital signature algorithm, i.e. Select all encryption algorithms that possess function f. That is, from its different algorithm parameters The middle screening meets the requirements The second algorithm parameter Therefore, the selected encryption algorithm i and its second algorithm parameters are... This forms a second encryption configuration. , .
[0043] S104. Based on the loss value between each second encryption configuration and the encryption requirement, select the optimal encryption configuration from each second encryption configuration; wherein, the loss value between each second encryption configuration and the encryption requirement is used to characterize the degree to which it does not meet other limiting conditions in the encryption requirement while meeting the lower limit of security strength.
[0044] In embodiments of this application, the algorithm selection device can select the optimal encryption configuration from each second encryption configuration based on the loss value between each second encryption configuration and the encryption requirement.
[0045] It should be noted that, in the embodiments of this application, a method for calculating the loss value can be defined to calculate the distance value between each second encryption configuration and the encryption requirement, so as to measure the degree to which each first encryption configuration meets the encryption requirement, and select the optimal encryption configuration from them.
[0046] In the embodiments of this application, the algorithm selection device can determine the loss value between each second encryption configuration and the encryption requirement according to the following steps: Based on the performance indicators of each second encryption configuration in n dimensions, obtain each set of performance indicators; wherein, each set of performance indicators includes the performance indicators of each second encryption configuration in the same dimension, and the n dimensions include the dimensions to which the limiting conditions in the encryption requirement differ from the lower limit of security strength belong; for each limiting condition in the n dimensions, calculate the minimum absolute error and the maximum absolute error with the set of performance indicators in the same dimension; for each second encryption configuration, calculate the absolute error between the performance indicator in each of the n dimensions and the limiting condition in the same dimension, obtaining the original deviation value in each of the n dimensions; for each second encryption configuration, normalize and map the original deviation value in each of the n dimensions based on the minimum absolute error and the maximum absolute error of the limiting condition in the same dimension, obtaining the normalized deviation value in each of the n dimensions; for each second encryption configuration, using the weights of the performance indicators in different dimensions, weighted summation of the normalized deviation values in the n dimensions, determining the loss value between the second encryption configuration and the encryption requirement.
[0047] It should be noted that, in the embodiments of this application, the algorithm selection device is configured for each second encryption configuration. The specific second algorithm parameters The mapping function corresponding to the encryption algorithm, i.e., the storage function, is substituted into it. Communication bandwidth function Calculate the cost function Safety strength function This can be mapped to performance metrics across various dimensions, i.e. .
[0048] Specifically, in the embodiments of this application, if each second encryption configuration is obtained, each second encryption configuration Meets encryption requirements Safety strength lower limit Define the loss value Used to measure different second encryption configurations The degree to which the constraints of other dimensions of encryption requirements are not met; the greater the loss value, the less the constraints of other dimensions of encryption requirements are met. The specific calculation method is as follows: First, calculate the following formula: (11) (12) (13) (14) (15) (16) (17) (18) in, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error, and for The minimum absolute error and the maximum absolute error.
[0049] Secondly, based on each second encryption configuration Performance metrics ( The loss value between the encryption requirement M and the following formula is used to calculate the loss value. : (19) in These are the weights of performance metrics under the storage, bandwidth, and computational overhead dimensions, respectively. These weights can be preset, representing the user's emphasis on storage, bandwidth, and computational overhead. Finally, the second encryption configuration with the largest distance value is selected. As the optimal encryption configuration, i.e. .
[0050] It should be noted that the calculation method for the above-mentioned loss value in the embodiments of this application is only exemplary. Of course, other calculation methods can also be used to calculate the loss value. Among them, based on the above calculation method, the loss value between each second encryption configuration and the encryption requirement is negatively correlated or inversely proportional to the degree to which each second encryption configuration meets the encryption requirement. Therefore, the second encryption configuration with the smallest loss value is selected as the optimal encryption configuration.
[0051] In the embodiments of this application, the algorithm selection device can not only perform the above steps to determine the optimal encryption configuration, but also perform related updates and optimizations, which will be described in detail below.
[0052] In the embodiments of this application, the algorithm selection device may further perform the following steps: collecting performance indicators under various dimensions when performing encryption operations using the optimal encryption configuration; and using the collected performance indicators to train the mapping function corresponding to the encryption algorithm in the optimal encryption configuration.
[0053] Specifically, in the embodiments of this application, the optimal encryption configuration is selected and used for encryption or signing, while the actual storage space used during execution is recorded. Communication bandwidth Calculation cost and safety strength and utilize The training data is updated to optimize the mapping function, i.e., the storage function, corresponding to encryption algorithm i in the optimal encryption configuration. Communication bandwidth function Calculate the cost function Safety strength function .
[0054] In the embodiments of this application, the algorithm selection device may further perform the following steps: based on the performance scores of performing encryption operations using the optimal encryption configuration in different dimensions, update the weights of performance indicators in different dimensions.
[0055] It should be noted that in the embodiments of this application, referring to steps S102 and S104, the calculation of distance and loss values involves a weighted summation of normalized bias values across multiple dimensions, utilizing the weights of performance indicators under different dimensions, i.e. These are the weights of performance metrics across storage, bandwidth, computational overhead, and security dimensions. Users can score the selected optimal encryption configuration across these four dimensions: storage, bandwidth, computational overhead, and security strength. The maximum score is 10 points. The weights are updated using the following formula: ,in Then calculate The four weights are renormalized to obtain new weights based on user feedback, thus enabling dynamic updates of the weights.
[0056] In summary, the implementation framework of the technical solution of this application is as follows: Figure 2 As shown, the steps indicated by dashed lines can be performed offline, while the steps indicated by solid lines can be performed online. The technical solution of this application mainly has the following advantages: Taking into account the advantages and disadvantages of different encryption algorithms, an optimal encryption configuration is selected based on varying user device environments, performance, and security requirements. This proactive approach, rather than relying solely on manual selection by the user, significantly addresses the issue of inaccurate selection of various encryption algorithms and their parameters by users lacking specialized knowledge, thereby improving the accuracy and flexibility of algorithm configuration selection.
[0057] Neural network algorithms are used to assist in the function calculation process to achieve accurate mapping function results. Specifically, a neural network algorithm is used to calculate the mapping function between the performance indicators of the encryption algorithm and its parameters in an offline environment where the encryption algorithm is deployed. The optimal encryption configuration is automatically selected based on encryption requirements. An encryption configuration selection scheme is designed, defining distance and loss values. Depending on different situations, the scheme furthest or closest to the encryption requirement is selected as the final scheme. Performance scores based on user feedback are also considered. Furthermore, user requirements are reflected in the weights and updated accordingly, thus correcting and promoting the mapping function.
[0058] Most steps can be performed offline, reducing online computational overhead.
[0059] This application also provides an algorithm selection device. Figure 3 A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 1 .like Figure 3 As shown, the algorithm selection device 1 includes: Algorithm filtering module 11 is used to filter first algorithm parameters that meet the encryption requirements in a first environment for each encryption algorithm with a specified function, forming each first encryption configuration; wherein, the first environment is a device environment for deploying encryption algorithms, and each first encryption configuration includes an encryption algorithm with the specified function and its first algorithm parameters; if multiple first encryption configurations are obtained, the optimal encryption configuration is selected from them based on the distance value between each first encryption configuration and the encryption requirements; wherein, the distance value between each first encryption configuration and the encryption requirements is used to characterize the degree to which it meets the encryption requirements; if no first encryption configuration is obtained, for each encryption algorithm with the specified function, second algorithm parameters that meet the lower limit of security strength in the encryption requirements in the first environment are filtered to form each second encryption configuration; wherein, each second encryption configuration includes an encryption algorithm with the specified function and its second algorithm parameters; and the optimal encryption configuration is selected from each second encryption configuration based on the loss value between each second encryption configuration and the encryption requirements; wherein, the loss value between each second encryption configuration and the encryption requirements is used to characterize the degree to which it does not meet other limiting conditions in the encryption requirements while meeting the lower limit of security strength.
[0060] In one embodiment of this application, the encryption requirements also include one or more of the following: storage space limit, communication bandwidth limit, and computational overhead limit.
[0061] In one embodiment of this application, the algorithm filtering module 11 is used to form sets of performance indicators based on the performance indicators of each first encryption configuration in k dimensions; wherein, a set of performance indicators includes the performance indicators of each first encryption configuration in the same dimension, and the k dimensions include the dimensions to which each limiting condition in the encryption requirement belongs; for each limiting condition in the k dimensions, the minimum absolute error and maximum absolute error with a set of performance indicators in the same dimension are calculated; for each first encryption configuration, the absolute error between the performance indicator in each of the k dimensions and the limiting condition in the same dimension is calculated to obtain the original deviation value in each of the k dimensions; for each first encryption configuration, the original deviation value in each of the k dimensions is normalized and mapped based on the minimum absolute error and maximum absolute error of the limiting condition in the same dimension to obtain the normalized deviation value in each of the k dimensions; for each first encryption configuration, the normalized deviation value in the k dimensions is weighted and summed using the weights of the performance indicators in different dimensions to determine the distance value between it and the encryption requirement.
[0062] In one embodiment of this application, the algorithm filtering module 11 is used to obtain a set of performance indicators based on the performance indicators of each second encryption configuration in n dimensions; wherein, a set of performance indicators includes the performance indicators of each second encryption configuration in the same dimension, and the n dimensions include the dimensions to which the limiting conditions in the encryption requirement are different from the lower limit of the security strength belong; for each limiting condition in the n dimensions, the minimum absolute error and the maximum absolute error of the set of performance indicators in the same dimension are calculated; for each second encryption configuration, the absolute error of the performance indicator in each of the n dimensions and the limiting conditions in the same dimension is calculated to obtain the original deviation value in each of the n dimensions; for each second encryption configuration, the original deviation value in each of the n dimensions is normalized and mapped based on the minimum absolute error and the maximum absolute error of the limiting conditions in the same dimension to obtain the normalized deviation value in each of the n dimensions; for each second encryption configuration, the normalized deviation values in the n dimensions are weighted and summed using the weights of the performance indicators in different dimensions to determine the loss value between the encryption requirement and the actual encryption requirement.
[0063] In one embodiment of this application, the algorithm filtering module 11 is used to substitute the first algorithm parameters or the second algorithm parameters of each first encryption configuration or each second encryption configuration into the mapping function corresponding to the encryption algorithm therein, and map to obtain the performance indicators under each dimension; wherein, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm in the first environment and the performance indicators under each dimension.
[0064] Figure 4A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 2 .like Figure 4 As shown, in one embodiment of this application, the algorithm selection device 1 includes not only the algorithm screening module 11 described above, but also an algorithm update module 12, which is used to update the weights of performance indicators in different dimensions based on the performance scores of performing encryption operations using the optimal encryption configuration in different dimensions.
[0065] like Figure 4 As shown, in one embodiment of this application, the algorithm selection device 1 further includes: an offline training module 13, used to collect performance indicators under various dimensions when performing encryption operations using the optimal encryption configuration; and to train the mapping function corresponding to the encryption algorithm in the optimal encryption configuration using the collected performance indicators; wherein, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm and the performance indicators under various dimensions in the first environment.
[0066] Based on the same inventive concept Figure 5 A schematic diagram of the structure of an algorithm selection device provided in an embodiment of this application. Figure 3 .like Figure 5 As shown, the algorithm selection device 1 includes: a processor 14, a memory 15, and a communication bus 16; The communication bus 16 is used to realize the communication connection between the processor 14 and the memory 15; The processor 14 is used to execute one or more computer programs stored in the memory 15 to implement the above-described algorithm selection method.
[0067] This application provides a computer program product, including a computer program that, when executed by a processor, implements the above-described algorithm selection method.
[0068] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the aforementioned algorithm selection method. The computer-readable storage medium can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or it can be a device including one or any combination of the above-mentioned memories, such as a mobile phone, computer, tablet device, personal digital assistant, etc.
[0069] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0070] This application is described with reference to schematic and / or block diagrams of implementations of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the schematic and / or block diagrams can be implemented by computer program instructions, and combinations of blocks in the schematic and / or block diagrams can be implemented. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the schematic and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0071] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the implementation flow diagram. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0072] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0073] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An algorithm selection method, characterized in that, include: For each encryption algorithm with a specified function, first algorithm parameters that meet the encryption requirements in a first environment are selected to form each first encryption configuration; wherein, the first environment is the device environment in which the encryption algorithm is deployed, and each first encryption configuration includes an encryption algorithm with the specified function and its first algorithm parameters. If multiple first encryption configurations are obtained, the optimal encryption configuration is selected from them based on the distance value between each first encryption configuration and the encryption requirement; wherein, the distance value between each first encryption configuration and the encryption requirement is used to characterize the degree to which it satisfies the encryption requirement; If no first encryption configuration is obtained, then for each encryption algorithm with the specified function, the second algorithm parameters that meet the lower limit of the security strength in the encryption requirements in the first environment are selected to form each second encryption configuration; wherein, each second encryption configuration includes an encryption algorithm with the specified function and its second algorithm parameters; Based on the loss value between each second encryption configuration and the encryption requirement, the optimal encryption configuration is selected from each second encryption configuration; wherein, the loss value between each second encryption configuration and the encryption requirement is used to characterize the degree to which it does not meet other limiting conditions in the encryption requirement while satisfying the lower limit of security strength.
2. The method according to claim 1, characterized in that, The encryption requirements also include one or more of the following: storage space limit, communication bandwidth limit, and computational overhead limit.
3. The method according to claim 1, characterized in that, The method further includes: Based on the performance metrics of each first encryption configuration under k dimensions, each set of performance metrics is formed; wherein, each set of performance metrics includes the performance metrics of each first encryption configuration under the same dimension, and the k dimensions include the dimensions to which each limiting condition in the encryption requirement belongs; For each of the k dimensions, under the constraints, calculate the minimum absolute error and maximum absolute error of a set of performance indicators under the same dimension; For each first encryption configuration, calculate the absolute error between the performance index under each of the k dimensions and the limiting conditions under the same dimension, and obtain the original deviation value under each of the k dimensions; For each first encryption configuration, the original deviation value in each of the k dimensions is normalized and mapped based on the minimum absolute error and maximum absolute error under the same dimension, so as to obtain the normalized deviation value in each of the k dimensions. For each first encryption configuration, the normalized deviation values under the k dimensions are weighted and summed to determine the distance value between the configuration and the encryption requirement, using the weights of the performance indicators under different dimensions.
4. The method according to claim 1, characterized in that, The method further includes: Based on the performance metrics of each second encryption configuration under n dimensions, each set of performance metrics is obtained; wherein, a set of performance metrics includes the performance metrics of each second encryption configuration under the same dimension, and the n dimensions include the dimensions to which the limiting conditions in the encryption requirements that are different from the lower limit of the security strength belong; For each of the n dimensions, under the constraints, calculate the minimum absolute error and maximum absolute error of a set of performance indicators under the same dimension; For each second encryption configuration, calculate the absolute error between the performance index and the constraint conditions in each of the n dimensions, and obtain the original deviation value in each of the n dimensions. For each of the second encryption configurations, the original deviation values in each of the n dimensions are normalized and mapped based on the minimum absolute error and maximum absolute error under the same dimension, to obtain the normalized deviation values in each of the n dimensions. For each second encryption configuration, the normalized deviation values under the n dimensions are weighted and summed using the weights of the performance indicators set under different dimensions, and the result is determined as the loss value between the encryption requirement and the actual encryption requirement.
5. The method according to claim 3 or 4, characterized in that, The method further includes: Based on the performance scores of performing encryption operations using the optimal encryption configuration under different dimensions, the weights of the performance indicators under different dimensions are updated.
6. The method according to any one of claims 1-4, characterized in that, The method further includes: For each first encryption configuration or each second encryption configuration, the first algorithm parameters or the second algorithm parameters are substituted into the mapping function corresponding to the encryption algorithm to obtain the performance indicators under each dimension. Among them, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm and the performance indicators under each dimension in the first environment.
7. The method according to any one of claims 1-4, characterized in that, The method further includes: Collect performance metrics across various dimensions when performing encryption operations using the optimal encryption configuration; Using the collected performance metrics, train the mapping function corresponding to the encryption algorithm in the optimal encryption configuration; Among them, the mapping function corresponding to each encryption algorithm is used to establish the correspondence between the algorithm parameters of the encryption algorithm and the performance indicators under each dimension in the first environment.
8. An algorithm selection device, characterized in that, include: Processor, memory, and communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is configured to execute one or more computer programs stored in the memory to implement the method according to any one of claims 1-7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.