An Adaptive Encryption Protocol Selection and Switching Method and System
By employing an adaptive encryption protocol selection and switching method, and utilizing LSTM models and fuzzy comprehensive evaluation, accurate decision-making based on dynamic network environments and business requirements is achieved. This improves the efficiency and stability of encryption protocol selection and switching, and solves the adaptability and lag problems existing in current technologies.
Patent Information
- Application Number
- CN202610258469.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-04
- Publication Date
- 2026-06-02
AI Technical Summary
Existing encryption protocol selection and switching technologies are difficult to adapt to dynamically changing network environments, business needs, and security postures, resulting in low selection and switching efficiency, poor adaptability, and an inability to achieve global awareness and accurate decision-making.
An adaptive encryption protocol selection and switching method is adopted. By acquiring global link, device and security status information, an initial state vector is constructed, dynamic weights are calculated, short-term security risks are predicted using an LSTM model, and a target protocol is selected by combining fuzzy comprehensive evaluation. Protocol switching is performed when the switching conditions are met.
It achieves global adaptability of encryption protocols, self-optimization of decisions, and stability of switching, improving decision accuracy and scenario generalization ability, and solving the lag and single-model optimization limitations of traditional technologies.
Smart Images

Figure CN122137621A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security transmission technology, and in particular to an adaptive encryption protocol selection and switching method and system. Background Technology
[0002] In the field of data communication, encryption protocols are the core technical means to ensure the confidentiality, integrity, and availability of data transmission. They are widely used in various scenarios that require dynamic protection of data transmission security and continuity, such as the Industrial Internet, mobile edge computing, vehicle-to-everything (V2X) networks, and large-scale Internet of Things (IoT). With the increasing complexity of network environments, the diversification of business needs, and the normalization of security threats, the efficiency, adaptability, and security of the selection and switching of encryption protocols directly affect the performance of the overall data transmission system.
[0003] Current encryption protocol selection and switching technologies mainly fall into two core categories: one is the traditional static configuration scheme, which selects a fixed encryption protocol according to preset rules; the other is the improved dynamic adjustment scheme, including encryption policy adjustment technology based on SDN (Software-Defined Networking) and decision-making technology based on fuzzy comprehensive evaluation. SDN technology enables global network management, providing global data support for encryption policy adjustments; fuzzy comprehensive evaluation technology enables multi-dimensional quantitative decision-making, improving the comprehensiveness of protocol selection. However, both improved schemes still have significant technical bottlenecks, making it difficult to adapt to dynamically changing network environments, business needs, and security postures.
[0004] Therefore, there is an urgent need for an adaptive encryption protocol selection and switching method that integrates global awareness, precise decision-making, and stable switching. Summary of the Invention
[0005] To address the aforementioned issues, this application proposes an adaptive encryption protocol selection and switching method and system, aiming to achieve a balance between global adaptability in encryption protocol selection, self-optimization of decision-making, stability of switching, and forward-looking risk assessment. The specific details are as follows: An adaptive encryption protocol selection and switching method includes the following steps: S1. Obtain global link information, device information, and security status information. Extract data from the above information to obtain network operation data, resource constraint data, and security risk data, and preprocess them to obtain the initial state vector. S2. Calculate the core contribution of each indicator in the initial state vector, and then dynamically generate the initial weights to obtain the initial dynamic weight vector. S3. Based on historical and real-time security time-series data, predict short-term security risk trends using an LSTM model and generate risk warnings. S4. Based on risk warning and business needs, the initial dynamic weight vector is corrected to obtain the final dynamic weight vector; S5. Construct a fuzzy comprehensive evaluation comment set for the protocol. Based on each index in the initial state vector and the final dynamic weight vector, calculate the membership degree of each index in the initial state vector to the comment set through the membership function. Construct an m×n order fuzzy relation matrix R based on the membership degrees of all indicators. S6. Calculate the comprehensive evaluation score of each encryption protocol by combining the final dynamic weight vector and the fuzzy relation matrix R. Select the comprehensive evaluation score The first protocol is the target protocol; S7. Monitor the current protocol's running status in real time. There are preset protocol switching conditions. When any protocol switching condition is detected to be met, the protocol switching process is triggered. Combined with S1-S6, the current target protocol is obtained. S8. Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through the temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
[0006] Preferably, the expression for calculating the core contribution of each indicator in the initial state vector in S2 is as follows: There are m cross-level evaluation indicators, the first one being... i The expression for calculating the information gain of each indicator is as follows: ; in, For the first i The attention gain of each cross-layer indicator represents the overall contribution of the current protocol selection decision. For the first i The discrimination coefficient of each indicator For the first i The urgency coefficient of each indicator corresponds to the scenario. For the first j The discrimination coefficient of each indicator For the first j The scenario urgency coefficient corresponding to each indicator; in, ; in, For the first i The variance of each indicator over the historical data collection period. The maximum variance of all indicators; the discrimination coefficient. The value ranges from [0,1], with larger values indicating a stronger ability of the indicator to distinguish between different protocols. Values are assigned based on the dimension to which the indicator belongs, the LSTM risk prediction results, and the business attributes. Security layer indicators , This represents the gain coefficient for the security layer index. The probability of an attack occurring as predicted by the LSTM model; Business layer metrics , This is the gain coefficient for business layer metrics. This is the business real-time requirement coefficient (1.0 / 0.6 / 0.3 for high / medium / low). Other tier indicators =0.1.
[0007] Preferably, the initial weights are dynamically generated, and the expression for the initial dynamic weight vector is as follows: ; in, For the revised first i Dynamic weights for each indicator (elements of the final output weight vector). This is a protocol adaptability adjustment factor; ; in, For the current candidate protocol in the i The basic fit coefficient on each indicator For the first i Standard fit threshold and adjustment factor for each indicator The value range is [1,2]. When the protocol's adaptability to this metric is lower than the standard, Increasing the weight of this indicator indirectly strengthens the fit verification. The denominator is the sum of "attention gain × fit adjustment factor" for all indicators, ensuring that all... The sum of these values is 1, which satisfies the normalization constraint of the weight vector.
[0008] Preferably, the specific content of the risk warning generated in S3 based on historical and real-time security time-series data, using an LSTM model to predict short-term security risk trends, includes: Security risk-related time-series data, including attack frequency time-series, risk level change sequence, and protocol vulnerability exploitation trend data, are extracted from historical logs and real-time collected data. These data are then normalized and smoothed to construct the input time-series vector for the LSTM model. Input the time-series vector into the pre-trained LSTM model to predict the security risk level and the probability of attack within the future target time period; If the predicted risk level is high or the probability of an attack is greater than 80%, a risk warning signal will be generated.
[0009] Preferably, in S4, the initial dynamic weight vector is corrected based on risk warning and business needs to obtain the final dynamic weight vector. The correction triggering conditions include: Condition 1: The LSTM model outputs a high risk level, or the probability of an attack occurring is greater than 80%, triggering a corresponding risk warning signal; Condition 2: The application layer reports a core high real-time business attribute, that is, the data sensitivity level is core and the real-time requirement is high; If any one condition is met, the information gain correction of the corresponding indicator will be initiated; if both conditions are met, the correction will be applied cumulatively.
[0010] Preferably, in step S6, the comprehensive evaluation score of each encryption protocol is calculated by combining the final dynamic weight vector and the fuzzy relation matrix R. The expression is: ; in, This represents the overall compatibility score of the encryption protocol, with a value ranging from [0,1]. A higher score indicates better compatibility of the protocol in the current scenario. For the first i The dynamic weights of each indicator For the first i The maximum membership degree of the protocol in the protocol-specific fuzzy relation matrix corresponding to each indicator, i.e., the maximum membership degree of the protocol in the nth index. i The membership degree corresponding to the optimal adaptation level on each indicator reflects the protocol's core adaptation capability on that indicator. For the first i Business security compatibility coefficient of each indicator; Security layer indicators ; Business layer metrics .
[0011] Other tier indicators =1.0, enabling security risks and business needs to directly influence the score.
[0012] Preferably, the protocol switching conditions in S7 include: Network threshold: Latency > preset time or packet loss rate > preset percentage (can be adjusted flexibly according to the scenario); Security threshold: Attack frequency > preset frequency, or detection of exploitation of vulnerabilities in the current protocol, or LSTM model outputs risk warning signal; Performance threshold: When the encryption / decryption time exceeds the device's computing power threshold, or when the terminal's battery power is below a preset percentage, the high-resource-consuming protocol runs for a preset time. Scoring threshold: Comprehensive evaluation score of the protocol over a continuous acquisition period The score is below the preset value.
[0013] An adaptive encryption protocol selection and switching system, comprising: Data acquisition unit: acquires global link information, device information and security status information, extracts data from the above information to obtain network operation data, resource constraint data and security risk data, and preprocesses the data to obtain an initial state vector; Weighting unit: Calculates the core contribution of each indicator in the initial state vector, then dynamically generates the initial weights, and then obtains the initial dynamic weight vector. Based on historical and real-time security time series data, it predicts the short-term security risk trend through the LSTM model, generates risk warnings, and corrects the initial dynamic weight vector based on the risk warnings and business needs to obtain the final dynamic weight vector. Protocol selection unit: Construct a fuzzy comprehensive evaluation comment set for protocols. Based on each index in the initial state vector and the final dynamic weight vector, calculate the membership degree of each index in the initial state vector to the comment set through the membership function. Construct an m×n order fuzzy relation matrix R based on the membership degrees of all indicators. Combine the final dynamic weight vector and the fuzzy relation matrix R to calculate the comprehensive evaluation score S of each encryption protocol. Select the protocol with the highest comprehensive evaluation score S as the target protocol. Protocol determination unit: It monitors the current protocol's operating status in real time and has preset protocol switching conditions. When any protocol switching condition is met, it triggers the protocol switching process to obtain the current target protocol. Protocol switching unit: Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through a temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
[0014] An electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the content of the adaptive encryption protocol selection and switching method when it invokes the computer program in the memory.
[0015] A storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the content of the adaptive encryption protocol selection and switching method.
[0016] In summary, the adaptive encryption protocol selection and switching method and system of the present invention has the following advantages compared with traditional technologies: This application takes comprehensive evaluation as its core, integrates multi-dimensional and cross-layer data to construct a quantitative decision-making system, and achieves three-dimensional weighted optimization of fuzzy evaluation accuracy through an original dynamic weight formula that considers discrimination, scenario urgency, and protocol adaptability. At the same time, it constructs a closed loop linking LSTM prediction and fuzzy decision weighting, quantifies risk prediction results and integrates them into weight and score calculation, and iterates fuzzy evaluation, attention mechanism and LSTM prediction parameters in parallel and combines two-stage parameter calibration. This not only solves the problems of traditional weight solidification, key information overload and single model optimization limitations, but also breaks through the lag defects of traditional passive response, and greatly improves decision accuracy and scenario generalization ability.
[0017] The technical method of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating the steps of an adaptive encryption protocol selection and switching method according to the present invention. Figure 2 This is a unit diagram of an adaptive encryption protocol selection and switching system according to the present invention. Detailed Implementation
[0019] The technical method of the present invention will be further described below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps described in these embodiments do not limit the scope of this application.
[0020] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the scope of this application and its application or use.
[0021] Techniques, systems, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the instruction manual.
[0022] In all the examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.
[0023] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.
[0024] Example 1 An adaptive encryption protocol selection and switching method, such as Figure 1 As shown, it includes the following steps: S1. Obtain global link information, device information, and security status information. Extract network operation data, resource constraint data, and security risk data from the above information and preprocess them to obtain the initial state vector.
[0025] Understandably, the system collects cross-layer network parameters such as physical layer signal strength, network layer topology / bandwidth / latency / packet loss rate, and transport layer transmission reliability; the terminal collects local device computing power, CPU / memory resource utilization, battery level, and other resource parameters; the security monitoring module detects malicious scanning, brute-force attacks, and other attack behaviors in real time, counts attack frequency, classifies risk levels (low / medium / high), and simultaneously collects the known vulnerability status of the current encryption protocol; and the application layer reports the sensitivity level of the data to be transmitted and the real-time requirements of the business (high / medium / low).
[0026] The collected multi-dimensional parameters are normalized (parameters of different dimensions are mapped to the [0,1] interval) to eliminate the difference in dimensions; Kalman filtering algorithm is used to filter noisy data (such as instantaneous fluctuations in network latency); the preprocessed global data and local data are fused to generate a unified state vector st (e.g., st=[bandwidth 0.8, latency 0.2, attack frequency 0.1, sensitivity 0.9, computing power 0.7]).
[0027] S2. Calculate the core contribution of each indicator in the initial state vector, and then dynamically generate the initial weights to obtain the initial dynamic weight vector.
[0028] Furthermore, the expression for calculating the core contribution of each indicator in the initial state vector in S2 is as follows: There are m cross-level evaluation indicators, the first one being... i The expression for calculating the information gain of each indicator is as follows: ; in, For the first i The attention gain of each cross-layer indicator represents the overall contribution of the current protocol selection decision. For the first i The discrimination coefficient of each indicator For the first i The urgency coefficient of each indicator corresponds to the scenario. For the first j The discrimination coefficient of each indicator For the first j The scenario urgency coefficient corresponding to each indicator; in, ; in, For the first i The variance of each indicator over the historical data collection period. The maximum variance of all indicators; the discrimination coefficient. The value ranges from [0,1], with larger values indicating a stronger ability of the indicator to distinguish between different protocols.
[0029] The values are assigned based on the dimension to which the indicator belongs, the LSTM risk prediction results, and the business attributes.
[0030] Based on the dimension to which the indicator belongs and the LSTM risk prediction results, the security layer indicator , This represents the gain coefficient for the security layer index. The attack probability predicted by the LSTM model is a business layer indicator. , This is the gain coefficient for business layer metrics. This is the business real-time requirement coefficient (high / medium / low correspond to 1.0 / 0.6 / 0.3).
[0031] Other tier indicators =0.1.
[0032] The denominator in the formula is a normalization factor for the attention gain of all indicators, ensuring... AG ( i The value range is [0,1], which satisfies the weight normalization requirement.
[0033] Furthermore, initial weights are dynamically generated, resulting in the expression for the initial dynamic weight vector: ; in, For the revised first i Dynamic weights for each indicator (elements of the final output weight vector). As the protocol adaptability adjustment factor, based on the preset basic attributes of each protocol in the encryption protocol library, the expression is: ; in, For the current candidate protocol in the i The basic fit coefficient on each indicator For the first i Standard fit threshold and adjustment factor for each indicator The value range is [1,2]. When the protocol's adaptability to this metric is lower than the standard, Increasing the weight of this indicator indirectly strengthens the fit verification. The denominator is the sum of the attention gain of all indicators multiplied by the fit adjustment factor, ensuring that all... The sum of these values is 1, which satisfies the normalization constraint of the weight vector.
[0034] S3. Based on historical and real-time security time-series data, the LSTM model is used to predict short-term security risk trends and generate risk warnings. The LSTM time-series prediction model is introduced to predict short-term security trends based on historical attack data and real-time risk situation, realizing the transformation from passive response switching to proactive forward-looking switching, and avoiding the lag of switching triggered only after the risk occurs.
[0035] Furthermore, S3 uses an LSTM model to predict short-term security risk trends based on historical and real-time security time-series data, generating risk warnings that include: Security risk-related time-series data, including attack frequency time-series, risk level change sequences, and protocol vulnerability exploitation trend data, are extracted from historical logs and real-time collected data. These data are then normalized and smoothed to construct the input time-series vector for the LSTM model.
[0036] The input time-series vector is fed into a pre-trained LSTM model to predict the security risk level and the probability of an attack occurring within a future target time period.
[0037] If the predicted risk level is high or the probability of an attack is greater than 80%, a risk warning signal will be generated.
[0038] S4. Based on risk warning and business needs, the initial dynamic weight vector is corrected to obtain the final dynamic weight vector.
[0039] Furthermore, in S4, the initial dynamic weight vector is corrected based on risk warnings and business needs to obtain the final dynamic weight vector. The correction triggering conditions include: Condition 1: The LSTM model outputs a predicted risk level of "high", or the probability of an attack is greater than 80%, and a corresponding risk warning signal is triggered.
[0040] Condition 2: The application layer reports a core high real-time business attribute, that is, the data sensitivity level is core and the real-time requirement is high.
[0041] If any one condition is met, the information gain correction of the corresponding indicator will be initiated; if both conditions are met, the correction will be applied cumulatively.
[0042] S5. Construct a set of fuzzy comprehensive evaluation comments for the protocol. Based on each index in the initial state vector and the final dynamic weight vector, calculate the membership degree of each index in the initial state vector to the comment set through the membership function. Construct an m×n order fuzzy relation matrix R based on the membership degrees of all indicators.
[0043] S6. Calculate the comprehensive evaluation score of each encryption protocol by combining the final dynamic weight vector and the fuzzy relation matrix R. Select the comprehensive evaluation score The first protocol is the target protocol.
[0044] Furthermore, in S6, the comprehensive evaluation score of each encryption protocol is calculated by combining the final dynamic weight vector and the fuzzy relation matrix R. The expression is: ; in, This represents the overall compatibility score of the encryption protocol, with a value ranging from [0,1]. A higher score indicates better compatibility of the protocol in the current scenario. For the first i The dynamic weights of each indicator For the first i The maximum membership degree of the protocol in the protocol-specific fuzzy relation matrix corresponding to each indicator, i.e., the maximum membership degree of the protocol in the nth index. i The membership degree corresponding to the optimal adaptation level on each indicator reflects the protocol's core adaptation capability on that indicator. For the first i The business security compatibility coefficient of each indicator.
[0045] Assign values based on the dimension to which the indicator belongs and the current business security requirements; security layer indicators Business layer metrics .
[0046] Other tier indicators =1.0, enabling security risks and business needs to directly influence the score.
[0047] S7. Monitor the current protocol's operating status in real time. There are preset protocol switching conditions. When any protocol switching condition is detected to be met, the protocol switching process is triggered. Combined with S1-S6, the current target protocol is obtained.
[0048] Furthermore, the edge execution layer monitors the current protocol's operational status in real time, including encryption / decryption time, CPU / memory resource utilization, data transmission success rate, and battery consumption; simultaneously, it monitors the changing trends of network cross-layer status and security risks. Protocol switching conditions in S7 include: Network threshold: latency > preset time or packet loss rate > preset percentage (can be adjusted flexibly according to the scenario), for example: latency > 100ms or packet loss rate > 5%.
[0049] Security threshold: Attack frequency > preset frequency, or detection of vulnerability exploitation behavior against the current protocol, or LSTM model outputs risk warning signal, e.g., attack frequency > 5 times / minute.
[0050] Performance thresholds: Encryption / decryption time exceeds the device's computing power threshold (e.g., edge terminal > 200ms, cloud server > 50ms), or high resource consumption protocol runs for more than a preset time when the terminal battery power is lower than a preset percentage (high resource consumption protocol runs for more than 1 minute when the terminal battery power is lower than 20%).
[0051] Scoring threshold: Comprehensive evaluation score of the protocol over a continuous acquisition period The score is lower than the preset value (the comprehensive evaluation score of the protocol for three consecutive collection cycles is lower than 60 points (out of 100 points)).
[0052] S8. Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through the temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
[0053] Understandably, an SDN controller can be used to coordinate the source and target terminals, pre-negotiate the key for the target protocol through a temporary encrypted channel (to avoid key leakage during transmission); at the same time, based on the link scheduling capability of SDN, a temporary transmission channel (new link) corresponding to the target protocol can be constructed, while the original protocol channel continues to transmit data, thus achieving parallel transmission of two links.
[0054] Following the priority order of P1, P2, and P3, the session context of the original protocol (such as data sequence number, encryption parameters, and transmission progress) is synchronized to the target protocol, prioritizing the data migration of high real-time core services; the full data transmission task is gradually migrated to the new link; when the data transmission success rate of the new link is monitored to be stable above 99% and the high-priority service migration completion rate is 100%, the original protocol channel is closed to complete the seamless handover.
[0055] Record switching time, new and old protocol types, switching trigger reason (including whether it is triggered by risk prediction), transmission interruption duration (target is 0), and migration time of services of each priority, and synchronously feed back the switching log information to the system.
[0056] When the amount of data in the historical decision log pool accumulates to a preset threshold (e.g., 500 records), or the system detects a scenario adaptation deviation (e.g., after 10 consecutive protocol selections, the running status score is below 70 points), or the LSTM risk prediction error exceeds 20%, the system collaborative optimization process is triggered.
[0057] With the objective functions of maximizing the overall performance score of the protocol and minimizing the risk prediction error, the following core parameters are synchronously and iteratively updated using the state vector, attention weight, fuzzy score, performance score, risk prediction data, and switching log from the historical decision log as training samples: (The Bayesian optimization algorithm is then used to update these parameters.) 1. Initial weights of indicators in the comprehensive evaluation model.
[0058] 2. Original formula core parameters (including gain coefficient) for the attention mechanism module , Protocol adaptability adjustment factor Indicator standard adaptation threshold ).
[0059] 3. Network parameters of the LSTM risk prediction model (such as the number of hidden layer neurons and the number of iteration steps).
[0060] 4. The business security adaptation coefficient in the protocol comprehensive adaptation score formula Basic coefficient.
[0061] For example, in core industrial data transmission scenarios, the optimized attention mechanism increases the information gain weight of security indicators from 0.4 to 0.55. The calibration value has been optimized from 1.6 to 1.7, further enhancing the security adaptability for high-risk scenarios.
[0062] Example 2 An adaptive encryption protocol selection and switching system, such as Figure 2 As shown, the system can be configured with an SDN controller, with a status acquisition cycle of 100ms, adapting to mainstream data transmission interface protocols (such as OpenFlow), establishing communication links between the SDN controller and each terminal and edge node, ensuring real-time global data transmission, including: Data acquisition unit: Acquires global link information, device information, and security status information; extracts network operation data, resource constraint data, and security risk data from the above information; and preprocesses the data to obtain the initial state vector.
[0063] Weighting unit: Calculates the core contribution of each indicator in the initial state vector, then dynamically generates the initial weights, and finally obtains the initial dynamic weight vector. Based on historical and real-time security time series data, it predicts short-term security risk trends through an LSTM model, generates risk warnings, and corrects the initial dynamic weight vector based on the risk warnings and business needs to obtain the final dynamic weight vector.
[0064] Protocol selection unit: Constructs a fuzzy comprehensive evaluation comment set for protocols. Based on each index in the initial state vector and the final dynamic weight vector, it calculates the membership degree of each index in the initial state vector to the comment set through the membership function. Based on the membership degrees of all indicators, it constructs an m×n order fuzzy relation matrix R. Combining the final dynamic weight vector and the fuzzy relation matrix R, it calculates the comprehensive evaluation score S of each encryption protocol and selects the protocol with the highest comprehensive evaluation score S as the target protocol.
[0065] Protocol determination unit: It monitors the current protocol's operating status in real time and has preset protocol switching conditions. When any protocol switching condition is met, it triggers the protocol switching process to obtain the current target protocol.
[0066] Protocol switching unit: Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through a temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
[0067] The entire system requires initial configuration, as detailed below: Encryption protocol library construction: Integrate symmetric encryption protocols (AES-128 / 256, SM4), asymmetric encryption protocols (SM2, RSA-2048 / 4096), and hybrid encryption protocols (TLS 1.3, IPSec) to form an extensible encryption protocol library, and label the basic attributes of each protocol such as key strength, computational complexity, and resource consumption.
[0068] Evaluation metrics and protocol space definition: A four-layer cross-dimensional evaluation metric set is clearly defined: 1. Physical layer + network layer metrics (signal strength, network topology, bandwidth, latency, packet loss, packet rate); 2. Transport layer + security layer metrics (transmission reliability, attack frequency, risk level, protocol vulnerability status); 3. Application layer business attribute metrics (data sensitivity level: ordinary / sensitive / core, business real-time requirements); 4. Terminal resource constraint metrics (device computing power, encryption / decryption resource utilization, battery power); Simultaneously, protocol adaptation rules are preset based on device computing power and business type (e.g., low-computing-power edge terminals do not support RSA-4096, and lightweight encryption protocols are preferred for real-time services), narrowing the scope of ineffective decisions.
[0069] An electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the content of the adaptive encryption protocol selection and switching method when it invokes the computer program in the memory.
[0070] A storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the content of the adaptive encryption protocol selection and switching method.
[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical methods of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical methods of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical methods to deviate from the spirit and scope of the technical methods of the present invention.
Claims
1. An adaptive encryption protocol selection and switching method, characterized in that, Includes the following steps: S1. Obtain global link information, device information, and security status information. Extract data from the above information to obtain network operation data, resource constraint data, and security risk data, and preprocess them to obtain the initial state vector. S2. Calculate the core contribution of each indicator in the initial state vector, and then dynamically generate the initial weights to obtain the initial dynamic weight vector. S3. Based on historical and real-time security time-series data, predict short-term security risk trends using an LSTM model and generate risk warnings. S4. Based on risk warning and business needs, the initial dynamic weight vector is corrected to obtain the final dynamic weight vector; S5. Construct a fuzzy comprehensive evaluation comment set for the protocol. Based on each index in the initial state vector and the final dynamic weight vector, calculate the membership degree of each index in the initial state vector to the comment set through the membership function. Construct an m×n order fuzzy relation matrix R based on the membership degrees of all indicators. S6. Calculate the comprehensive evaluation score of each encryption protocol by combining the final dynamic weight vector and the fuzzy relation matrix R. Select the comprehensive evaluation score The first protocol is the target protocol; S7. Monitor the current protocol's running status in real time. There are preset protocol switching conditions. When any protocol switching condition is detected to be met, the protocol switching process is triggered. Combined with S1-S6, the current target protocol is obtained. S8. Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through the temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
2. The adaptive encryption protocol selection and switching method according to claim 1, characterized in that, The expression for calculating the core contribution of each indicator in the initial state vector in S2 is as follows: There are m cross-level evaluation indicators, the first one being... i The expression for calculating the information gain of each indicator is as follows: ; in, For the first i The attention gain of each cross-layer indicator represents the overall contribution of the current protocol selection decision. For the first i The discrimination coefficient of each indicator For the first i The urgency coefficient of each indicator corresponds to the scenario. For the first j The discrimination coefficient of each indicator For the first j The scenario urgency coefficient corresponding to each indicator; in, ; in, For the first i The variance of each indicator over the historical data collection period. This represents the maximum variance of all indicators; Security layer indicators , This represents the gain coefficient for the security layer index. The probability of an attack occurring as predicted by the LSTM model; Business layer metrics , This is the gain coefficient for business layer metrics. This is a coefficient representing the real-time requirements of the business. Other tier indicators =0.
1.
3. The adaptive encryption protocol selection and switching method according to claim 2, characterized in that, The initial weights are dynamically generated, and the expression for the initial dynamic weight vector is as follows: ; in, For the revised first i Dynamic weights for each indicator (elements of the final output weight vector). This is a protocol adaptability adjustment factor; ; in, For the current candidate protocol in the i The basic fit coefficient on each indicator For the first i The standard adaptation threshold for each indicator.
4. The adaptive encryption protocol selection and switching method according to claim 2, characterized in that, S3 uses historical and real-time security time-series data and an LSTM model to predict short-term security risk trends and generate risk warnings. The specific content of these warnings includes: Security risk-related time-series data, including attack frequency time-series, risk level change sequence, and protocol vulnerability exploitation trend data, are extracted from historical logs and real-time collected data. These data are then normalized and smoothed to construct the input time-series vector for the LSTM model. Input the time-series vector into the pre-trained LSTM model to predict the security risk level and the probability of attack within the future target time period; If the predicted risk level is high or the probability of an attack is greater than 80%, a risk warning signal will be generated.
5. The adaptive encryption protocol selection and switching method according to claim 4, characterized in that, In S4, the initial dynamic weight vector is corrected based on risk warnings and business needs to obtain the final dynamic weight vector. The correction trigger conditions include: Condition 1: The LSTM model outputs a high risk level, or the probability of an attack occurring is greater than 80%, triggering a corresponding risk warning signal; Condition 2: The application layer reports a core high real-time business attribute, that is, the data sensitivity level is core and the real-time requirement is high; If any one condition is met, the information gain correction of the corresponding indicator will be initiated; if both conditions are met, the correction will be applied cumulatively.
6. The adaptive encryption protocol selection and switching method according to claim 5, characterized in that, In S6, the comprehensive evaluation score of each encryption protocol is calculated by combining the final dynamic weight vector and the fuzzy relation matrix R. The expression is: ; in, The overall adaptation score for the encryption protocol, For the first i The dynamic weights of each indicator For the first i The maximum membership degree in the protocol-specific fuzzy relation matrix corresponding to each indicator. For the first i Business security compatibility coefficient of each indicator; Security layer indicators ; Business layer metrics .
7. The adaptive encryption protocol selection and switching method according to claim 6, characterized in that, The protocol switching conditions in S7 include: Network threshold: Latency > preset time or packet loss rate > preset percentage; Security threshold: Attack frequency > preset frequency, or detection of exploitation of vulnerabilities in the current protocol, or LSTM model outputs risk warning signal; Performance threshold: When the encryption / decryption time exceeds the device's computing power threshold, or when the terminal's battery power is below a preset percentage, the high-resource-consuming protocol runs for a preset time. Scoring threshold: Comprehensive evaluation score of the protocol over a continuous acquisition period The score is below the preset value.
8. An adaptive encryption protocol selection and switching system, characterized in that, include: Data acquisition unit: acquires global link information, device information and security status information, extracts data from the above information to obtain network operation data, resource constraint data and security risk data, and preprocesses the data to obtain an initial state vector; Weighting unit: Calculates the core contribution of each indicator in the initial state vector, then dynamically generates the initial weights, and then obtains the initial dynamic weight vector. Based on historical and real-time security time series data, it predicts the short-term security risk trend through the LSTM model, generates risk warnings, and corrects the initial dynamic weight vector based on the risk warnings and business needs to obtain the final dynamic weight vector. Protocol selection unit: Construct a fuzzy comprehensive evaluation comment set for protocols. Based on each index in the initial state vector and the final dynamic weight vector, calculate the membership degree of each index in the initial state vector to the comment set through the membership function. Construct an m×n order fuzzy relation matrix R based on the membership degrees of all indicators. Combine the final dynamic weight vector and the fuzzy relation matrix R to calculate the comprehensive evaluation score S of each encryption protocol. Select the protocol with the highest comprehensive evaluation score S as the target protocol. Protocol determination unit: It monitors the current protocol's operating status in real time and has preset protocol switching conditions. When any protocol switching condition is met, it triggers the protocol switching process to obtain the current target protocol. Protocol switching unit: Based on the real-time requirements of the business, the switching priority is divided. The key of the target protocol is pre-negotiated through a temporary encryption channel and a temporary transmission channel corresponding to the current target protocol is constructed. According to the priority order, the session context of the original protocol is synchronized to the target protocol to realize the switching of the encryption protocol.
9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor, when calling the computer program in the memory, implements the content of the adaptive encryption protocol selection and switching method as described in any one of claims 1 to 7.
10. A storage medium, characterized in that, The storage medium stores computer-executable instructions, which, when loaded and executed by a processor, implement the content of the adaptive encryption protocol selection and switching method as described in any one of claims 1 to 7.