Data dynamic encryption method, system and computer program product

By acquiring real-time time-series data of transmission rate differences in the encryption unit, extracting dynamic acceleration indicators and matching them with anomaly threshold values, and generating anomaly state judgment results, the problem of difficulty in perceiving internal state changes of the encryption unit in existing technologies is solved. This enables active control and dynamic optimization of the encryption unit, improving stability and response efficiency.

CN122204566BActive Publication Date: 2026-07-31ZHEJIANG CARD WINNER INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG CARD WINNER INFORMATION TECH CO LTD
Filing Date
2026-05-18
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies struggle to detect changes in the internal processing state when monitoring and controlling encryption units, resulting in delayed responses and an inability to achieve dynamic optimization and control, thus failing to effectively guarantee the stability and reliability of the encryption unit.

Method used

By acquiring real-time transmission rate difference time-series data recorded by the flow monitoring devices at the inlet and outlet of the encryption unit, dynamic acceleration indicators are extracted, and combined with pre-calibrated abnormal acceleration thresholds, abnormal state judgment results are generated. Online control commands are then output based on the adaptive adjustment strategy library.

Benefits of technology

It enables early warning of abnormal trends within the encryption unit, improves the operational stability and reliability of the encryption unit, ensures the continuity and response efficiency of encryption services, and transforms passive alarms into proactive control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122204566B_ABST
    Figure CN122204566B_ABST
Patent Text Reader

Abstract

This application relates to the field of data encryption technology, and particularly to data dynamic encryption methods, systems, and computer program products. The method includes: acquiring in real-time time-series data of transmission rate differences recorded by flow monitoring devices at the inlet and outlet of the encryption unit during continuous processing of the input data stream; introducing a dynamic acceleration index for the transmission rate difference, shifting the monitoring perspective from the external characteristics of the encrypted data stream to the dynamic changes in the internal processing state of the encryption unit; generating accurate abnormal state judgment results by matching the dynamic acceleration index with an abnormal acceleration threshold; and outputting online control commands based on the abnormal judgment results through a preset encryption parameter adaptive adjustment strategy library. This achieves a transformation from passive alarm to active control, and from manual intervention to automatic optimization, significantly improving the stability and reliability of the encryption unit's operation and effectively ensuring the continuity and response efficiency of encryption services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data encryption technology, and in particular relates to a dynamic data encryption method, system and computer program product. Background Technology

[0002] Dynamic data encryption technology is one of the core means to ensure network and information security. As network security threats become increasingly complex, the stability and processing efficiency of encryption units (such as hardware encryption modules and software encryption services) during the continuous processing of input data streams directly affect the security and reliability of the entire system.

[0003] Currently, monitoring and control of encrypted units primarily rely on the characteristic analysis of the encrypted data stream itself. Existing technologies typically collect metadata of the encrypted data stream (such as packet length, time interval, and forward / reverse traffic ratio) to extract traffic characteristics, and then combine this with machine learning models or rule matching for anomaly detection. For example, anomalies can be determined by analyzing the differences between encrypted data packets transmitted in the forward and reverse directions; or the encrypted transmission status can be assessed through traffic tide measurement and aliasing feature extraction. In addition, some solutions focus on the external behavioral characteristics of the encrypted channel, such as external connections initiated by processes after loading the encryption library, and high-entropy loads.

[0004] However, the detection targets of the aforementioned existing technologies are all focused on the content characteristics of the encrypted data stream itself or external communication behavior. They are unable to detect the decline in processing capacity caused by factors such as data congestion, algorithm bottlenecks, and resource contention within the encryption unit, and cannot capture the dynamic trend of state deterioration. They are often only discovered when the problem is serious, and the control measures are mostly manual interventions, which are slow to respond and costly. Summary of the Invention

[0005] This application provides a data dynamic encryption method, system, and computer program product, which can solve the problems in the prior art where the monitoring object is limited to the external characteristics of the encrypted data stream, it is difficult to perceive changes in the internal processing state of the encryption unit, and the response is lagging and dynamic optimization and control cannot be achieved.

[0006] In a first aspect, embodiments of this application provide a method for dynamic data encryption, including: Real-time acquisition of transmission rate difference time-series data recorded by flow monitoring devices at the inlet and outlet of the encryption unit during continuous processing of the input data stream; Trend analysis is performed on the time-series data of the transmission rate difference to extract a dynamic acceleration index that reflects the rate of change of the rate difference. The dynamic acceleration index is matched with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result indicating the internal state of the encryption unit. Based on the abnormal state determination result, an execution instruction for online control of the encryption unit is output through a preset encryption parameter adaptive adjustment strategy library.

[0007] The technical solutions described in this application embodiment have at least the following technical effects: The data dynamic encryption method provided in this application acquires real-time time-series data of transmission rate differences recorded by flow monitoring devices at the inlet and outlet of the encryption unit during continuous processing of the input data stream. It introduces a dynamic acceleration index for transmission rate differences, shifting the monitoring perspective from external characteristics of the encrypted data stream to dynamic changes in the internal processing state of the encryption unit. This allows for early detection of internal anomalies such as data congestion and algorithm bottlenecks, providing early warning of declining processing capacity. By matching the dynamic acceleration index with anomaly acceleration thresholds, accurate anomaly state judgment results are generated, overcoming the shortcomings of traditional static threshold alarms in capturing trend changes. Based on the anomaly judgment results, online control commands are output through a preset encryption parameter adaptive adjustment strategy library, realizing a shift from passive alarm to active control, and from manual intervention to automatic optimization. This significantly improves the stability and reliability of the encryption unit's operation, effectively ensuring the continuity and response efficiency of encryption services.

[0008] Secondly, embodiments of this application provide a dynamic data encryption system applied to electronic devices, the dynamic data encryption system comprising: The acquisition unit is used to acquire in real time the transmission rate difference time-series data recorded by the flow monitoring devices at the inlet and outlet of the encryption unit during the continuous processing of the input data stream; The parsing unit is used to perform trend analysis on the transmission rate difference time-series data and extract a dynamic acceleration index that reflects the rate of change of the rate difference. The determination unit is used to match the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result that indicates the corresponding internal abnormal state of the encryption unit. The output unit is used to output an execution instruction for online control of the encryption unit based on the abnormal state determination result and the preset encryption parameter adaptive adjustment strategy library.

[0009] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method as described in any of the first aspects above.

[0010] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the method described in any of the first aspects above.

[0011] Fifthly, embodiments of this application provide a computer program product that, when run on an electronic device, causes the electronic device to perform the method described in any one of the first aspects above.

[0012] It is understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant descriptions in the above aspects, and will not be repeated here. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0014] Figure 1 This is a flowchart illustrating a dynamic data encryption method provided in an embodiment of this application; Figure 2 This is a time-series data graph showing the acquisition of transmission rate differences provided in an embodiment of the data dynamic encryption method of this application; Figure 3 This is an analytical diagram of the dynamic acceleration index of a data dynamic encryption method provided in an embodiment of this application; Figure 4 This is a schematic diagram of the structure of a dynamic data encryption system provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0015] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0016] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0017] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0018] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determination" or "if the described condition or event is detected" may be interpreted, depending on the context, as "once determination," "in response to determination," "once the described condition or event is detected," or "in response to the detection of the described condition or event."

[0019] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0020] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0021] Currently, monitoring and control of encrypted units primarily rely on the characteristic analysis of the encrypted data stream itself. Existing technologies typically collect metadata of the encrypted data stream (such as packet length, time interval, and forward / reverse traffic ratio) to extract traffic characteristics, and then combine this with machine learning models or rule matching for anomaly detection. For example, anomalies can be determined by analyzing the differences between encrypted data packets transmitted in the forward and reverse directions; or the encrypted transmission status can be assessed through traffic tide measurement and aliasing feature extraction. In addition, some solutions focus on the external behavioral characteristics of the encrypted channel, such as external connections initiated by processes after loading the encryption library, and high-entropy loads.

[0022] However, the detection targets of the aforementioned existing technologies are all focused on the content characteristics of the encrypted data stream itself or external communication behavior. They are unable to detect the decline in processing capacity caused by factors such as data congestion, algorithm bottlenecks, and resource contention within the encryption unit, and cannot capture the dynamic trend of state deterioration. They are often only discovered when the problem is serious, and the control measures are mostly manual interventions, which are slow to respond and costly.

[0023] To address the aforementioned issues, this application provides a dynamic data encryption method. This method involves real-time acquisition of transmission rate difference time-series data recorded by flow monitoring devices at the inlet and outlet of the encryption unit during continuous processing of the input data stream. A dynamic acceleration index for the transmission rate difference is introduced, shifting the monitoring perspective from external characteristics of the encrypted data stream to dynamic changes in the internal processing state of the encryption unit. This allows for early detection of internal anomalies such as data congestion and algorithm bottlenecks, providing early warning of declining processing capacity. By matching the dynamic acceleration index with an abnormal acceleration threshold, accurate anomaly judgment results are generated, overcoming the shortcomings of traditional static threshold alarms in capturing trend changes. Based on the anomaly judgment results, online control commands are output through a preset encryption parameter adaptive adjustment strategy library, achieving a shift from passive alarm to active control, and from manual intervention to automatic optimization. This significantly improves the stability and reliability of the encryption unit's operation, effectively ensuring the continuity and response efficiency of the encryption service.

[0024] The data dynamic encryption method provided in this application embodiment can be applied to electronic devices. In this case, the electronic device is the execution subject of the data dynamic encryption method provided in this application embodiment. This application embodiment does not impose any restrictions on the specific type of electronic device.

[0025] It is understandable that electronic devices can be various smart devices. For example, electronic devices can be mobile phones, tablets, wearable devices, in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), desktop computers, smart screens, smart TVs, and other terminal devices.

[0026] To better understand the data dynamic encryption method provided in the embodiments of this application, the specific implementation process of the data dynamic encryption method provided in the embodiments of this application will be described by way of example below.

[0027] Figure 1 A schematic flowchart of the data dynamic encryption method provided in an embodiment of this application is shown. Figure 2 This illustration shows a flowchart of the dynamic data encryption method provided in an embodiment of this application. The dynamic data encryption method includes: S100 acquires in real time the transmission rate difference timing data recorded by the flow monitoring devices at its inlet and outlet during the continuous processing of the input data stream by the encryption unit.

[0028] As can be understood, the encryption unit, also called the encryption processing unit or cryptographic operation unit, is the core object of this method. It is a dedicated hardware / firmware module that integrates a cryptographic algorithm hardware acceleration engine, a high-speed data transceiver interface, a dedicated processor, and secure memory. It is a core security component of network security equipment, industrial encryption gateways, financial encryption machines, and other similar devices. The core workflow is as follows: external business data flows into the encryption unit from the entry point. The dedicated processor schedules the hardware acceleration engine to perform real-time encryption / decryption and integrity verification operations on a packet-by-packet / stream-by-stream basis. After processing, the encrypted data stream is forwarded out from the exit point. The entire process is a continuous streaming process, with minimal impact on forwarding latency and bandwidth. Stability and operational reliability are extremely important. Transmission rate difference time-series data is the core raw input data of this method. It refers to the continuous data sequence formed by arranging the difference in data stream transmission rates between the encryption unit's inlet and outlet in chronological order. Its physical meaning is that under normal conditions, the rate difference between the encryption unit's inlet and outlet is stable within a very small range. When an anomaly occurs, the encryption unit's processing speed slows down and the outlet forwarding rate decreases, and the difference will continue to shrink or even become negative. It is the most direct quantitative indicator reflecting the encryption unit's processing performance. Time-series data is continuous data sampled at fixed time intervals and arranged in chronological order, which can completely reflect the change law of the indicator over time.

[0029] For example, please refer to Figure 2High-precision network traffic monitoring chips can be pre-deployed at the physical inlet and outlet of the encryption unit. The two monitoring devices achieve sub-microsecond time synchronization through the PTP (Precise Time Synchronization Protocol), a high-precision network time synchronization protocol that can control the time synchronization error of multiple devices in the network to the sub-microsecond level, avoiding distortion of rate calculation due to time asynchrony. The sampling frequency of the devices is set according to the rated processing bandwidth of the encryption unit. For example, the sampling frequency of an encryption unit with a bandwidth of 1Gbps is no less than 1kHz, which can capture millisecond-level rate fluctuations. Then, the number of data stream bytes recorded by the inlet and outlet monitoring devices in each sampling period is counted and converted into the instantaneous transmission rate of the inlet and outlet in the corresponding period. The transmission rate difference value of a single sampling point is obtained by subtracting the inlet transmission rate from the outlet transmission rate. The difference values ​​of all sampling points are arranged in chronological order to obtain the transmission rate difference time series data. Finally, outlier removal is performed on the original time series data to remove isolated abnormal sampling points that exceed the normal fluctuation range caused by sudden network jitter. Smoothing is performed by moving average filtering to obtain the transmission rate difference time series data for subsequent analysis, which truly reflects the performance changes of the encryption unit rather than random noise.

[0030] S200 performs trend analysis on the time-series data of transmission rate differences and extracts a dynamic acceleration index that reflects the rate of change of the rate difference.

[0031] This is understandable; the original time-series data on transmission rate differences can be split into subsequences with different characteristics to separate noise, anomalous changes, and long-term trends, thus solving the problem of noise masking true anomalies and trends and changes being indistinguishable when mixed together in the original data. Please refer to [link / reference]. Figure 3 Multiscale wavelet decomposition is a signal processing method adapted to non-stationary data. It can split a piece of raw data that changes over time into multiple sub-data sequences with different frequencies and time scales. It can accurately separate instantaneous sudden fluctuations, long-term trends and random noise in the raw data, solving the problem that traditional methods cannot simultaneously see short-term sudden anomalies and long-term performance change trends.

[0032] In one possible implementation, S200 performs trend analysis on the transmission rate difference time-series data to extract dynamic acceleration indicators reflecting the rate of change of the rate difference, including: S210 performs multi-scale wavelet decomposition on time-series data with different transmission rates to obtain detail components and approximate components in different frequency bands.

[0033] Multi-scale wavelet decomposition is a signal processing method adapted to non-stationary data. It breaks down a time-varying original data set into multiple sub-data sequences with different frequencies and time scales. This allows for the precise separation of instantaneous fluctuations, long-term trends, and random noise from the original data, solving the problem that traditional methods cannot simultaneously reveal both short-term anomalies and long-term performance trends. The detail component represents the high-frequency fluctuations in the original data, corresponding to instantaneous changes and noise, while the approximate component represents the low-frequency components, corresponding to long-term performance trends.

[0034] For example, the Daubechies (db4) wavelet, which is adapted to non-stationary traffic time-series data, can be selected as the mother wavelet. This type of wavelet can simultaneously take into account the localization characteristics of the time and frequency domains without losing the temporal features of the data. The number of decomposition layers is determined according to the sampling frequency and the length of the time-series data, ensuring that the lowest frequency band after decomposition can cover the lowest frequency change that causes the encryption unit performance to degrade. For example, for time-series data with a sampling frequency of 1kHz and a data length of 1000 points, the number of decomposition layers is set to 4. Then, discrete wavelet transform is used to perform multi-level decomposition on the preprocessed transmission rate difference time-series data. Each layer of decomposition... The approximate components of the previous layer are further decomposed into high-frequency detail components and low-frequency approximate components, resulting in four detail components of different frequency bands and one lowest-frequency approximate component. Finally, the physical meaning of each component is defined. The two sets of detail components with the highest frequency correspond to random noise and meaningless instantaneous jitter in the time series data. The remaining two sets of high-frequency detail components correspond to instantaneous mutations and short-term fluctuations related to abnormal events in the time series data, which can reflect the sudden performance changes of the encryption unit. The lowest-frequency approximate component corresponds to the long-term trend of change in the time series data, which can reflect the gradual degradation or recovery law of the encryption unit performance.

[0035] S220 identifies abrupt changes related to anomalous events from detail components and extracts long-term trend terms from approximate components.

[0036] As can be understood, mutation points are significant extreme points in the detailed components that deviate from the normal fluctuation range. They correspond to sudden changes in the working state of the encryption unit, such as hardware freezes, attack injections, and algorithm anomalies, and are direct characteristics of sudden anomalies. The long-term trend term is a smooth trend curve obtained by stripping small fluctuations from the approximate components. It reflects the overall change pattern of the encryption unit's performance over a longer period of time and is the core characteristic of gradual anomalies such as memory leaks and hardware aging.

[0037] For example, effective detail components obtained from decomposition can be selected, and abrupt change points can be identified using the wavelet modulus maxima method. First, the modulus maxima of each detail component is calculated, which is the extreme point where the gradient in the component sequence changes from positive to negative. Then, a mutation judgment threshold is set according to the average level and fluctuation amplitude of the detail component sequence. The threshold is the average value of the sequence plus three times the standard deviation of the sequence fluctuation. Finally, the extreme points whose modulus values ​​exceed the mutation judgment threshold and appear synchronously in multiple detail components are selected as effective mutation points related to the abnormal event. At the same time, the occurrence time and mutation amplitude of each mutation point are recorded. Then, the lowest frequency approximate component is smoothed and fitted to obtain the long-term trend term. When fitting, linear fitting is preferred to avoid overfitting problems caused by high-order fitting, ensuring that the fitted curve and the original data have a high enough fit, so that the trend term can accurately reflect the long-term change law of the original data.

[0038] S230 calculates instantaneous acceleration and trend acceleration based on abrupt change points and long-term trend terms, and uses the weighted fusion result of instantaneous acceleration and trend acceleration as a dynamic acceleration index.

[0039] It's understandable that two acceleration indicators, one for sudden anomalies and the other for gradual anomalies, can be calculated separately using the mutation point and the long-term trend term. Then, a weighted fusion is used to obtain a comprehensive dynamic acceleration indicator that takes both types of anomalies into account, avoiding the limitations of a single indicator. Instantaneous acceleration, calculated for mutation points, reflects the drastic change in the performance of the encryption unit and is used to detect sudden anomalies. Trend acceleration, calculated for long-term trend terms, reflects the rate of gradual change in the performance of the encryption unit and is used to detect potential anomalies of slow degradation. Weighted fusion involves assigning corresponding weights to the two acceleration indicators and merging them into a single comprehensive indicator. The weight allocation can be adaptively adjusted according to the needs of the scenario.

[0040] For example, when calculating instantaneous acceleration, the transmission rate difference data of two sampling points before and after the time of the abrupt change are selected, centered on the time of the abrupt change. The instantaneous acceleration is obtained by calculating the drastic change in the rate difference. For moments without an abrupt change, the instantaneous acceleration is recorded as 0. The larger the absolute value of the instantaneous acceleration, the more drastic the sudden change in the performance of the encryption unit. When calculating trend acceleration, the rate of long-term performance change is calculated from the changing pattern of the long-term trend term. For a linearly fitted trend term, the trend acceleration is a fixed value, representing a constant rate of performance change. For a nonlinearly fitted trend term, the trend acceleration is a value that changes over time, reflecting the rate of performance change at different times. Then, weighted fusion and weight calibration are performed, assigning corresponding weights to instantaneous acceleration and trend acceleration. The two weights are added together to equal 1. The weights can be calibrated using historical anomaly data, which is to see the distinguishing degree of the two indicators in anomaly detection. The higher the distinguishing degree, the greater the weight of the indicator. For example, for industrial encryption scenarios with high real-time requirements, instantaneous acceleration is given a higher weight, while for financial encryption scenarios with high stability requirements, trend acceleration is given a higher weight. Finally, the two indicators are merged according to their corresponding weights to obtain the final dynamic acceleration indicator. This shifts the monitoring perspective from the external characteristics of the encrypted data stream to the dynamic changes in the internal processing state of the encryption unit, allowing for early detection of internal anomaly trends such as data congestion and algorithm bottlenecks, and enabling early warning of declining processing capacity.

[0041] Instantaneous acceleration weight and trend acceleration weight satisfy A simplified determination method based on basic calibration and pre-adapted scenarios can be adopted, without complex calculations or model dependencies. First, the instantaneous and trend accelerations can be used to calculate the distinguishing power between abnormal and normal operating conditions using historical anomaly data from the encryption unit. The basic weights are then determined based on the proportion of these distinguishing power (higher distinguishing power corresponds to greater weight). Further fine-tuning can then be applied according to scenario requirements; for scenarios with high real-time requirements, such as industrial encryption, the weights can be increased. To 0.6-0.8, downgraded. The target value will be adjusted to 0.2-0.4, focusing on detecting sudden anomalies; for scenarios with high stability requirements, such as financial encryption, the target value will be increased. To 0.6-0.8, downgraded. For values ​​between 0.2 and 0.4, focus on monitoring gradual anomalies; for general commercial scenarios, take... It provides balanced coverage for both types of anomalies, eliminating the need for online dynamic correction; it can be directly and permanently used.

[0042] In one possible implementation, the method further includes, before matching the dynamic acceleration index against a pre-calibrated anomalous acceleration threshold: S510 inputs dynamic acceleration metrics into a pre-trained time-series prediction model to predict the acceleration evolution trajectory within a preset time window.

[0043] It is understandable that abnormal trend prediction can upgrade from post-event detection to pre-event warning. The time series prediction model is a model specifically designed to predict the future trend of sequence data that changes over time. It can learn the data change patterns based on historical and current continuous data and predict the data change trend over a period of time. The preset time window refers to the future duration predicted by the model. Its length is determined by comprehensively considering the rated performance of the encryption unit, the execution time of the control command, and the speed of abnormal development. The core requirement is that the prediction duration must be greater than or equal to twice the maximum execution time of the encryption unit's control command to ensure that the prediction duration can reserve sufficient response time for control. The acceleration evolution trajectory is the curve of dynamic acceleration change over a period of time predicted by the model. By observing the change curve, we can know in advance whether the encryption unit will experience anomalies in the future.

[0044] For example, the selection and training of the time series prediction model can use a Temporal Convolutional Network (TCN) or a Long Short-Term Memory Network (LSTM) that performs well in predicting long time series data as the base model. The model input is a dynamic acceleration sequence of multiple consecutive historical moments, and the output is an acceleration prediction sequence of multiple future moments. The training sample set comes from the historical operating data of the encrypted unit, including dynamic acceleration time series data under normal operating conditions and various abnormal operating conditions. It is divided into training set, validation set and test set in a ratio of 7:2:1. After training, the model is required to have a sufficiently small prediction error on the test set to ensure prediction accuracy. Then, the length of the preset time window is determined. For example, if the execution time of the control command is 500ms, the preset time window is set to 1s. The evolution trajectory prediction is performed. The dynamic acceleration sequence of multiple consecutive moments before the current moment is standardized and input into the trained time series prediction model. The model outputs the acceleration prediction value of each moment within the preset future time window. Arranged in chronological order, the acceleration evolution trajectory is obtained. At the same time, the reasonable fluctuation range of each prediction value is output for subsequent probability calculation.

[0045] S520 calculates the probability of the predicted acceleration exceeding the anomalous threshold and the expected time of exceeding it based on the evolution trajectory.

[0046] Understandably, the predicted evolutionary trajectory can be transformed into quantifiable early warning indicators to provide auxiliary basis for subsequent anomaly judgment. The probability of the predicted acceleration exceeding the anomaly threshold refers to the likelihood that the predicted acceleration value will reach and exceed the abnormal acceleration threshold value within a preset time window in the future. The closer the value is to 1, the higher the probability of an anomaly occurring. The expected time of exceeding the threshold refers to the time point when the predicted acceleration value in the evolutionary trajectory first exceeds the anomaly threshold. The two indicators quantify the probability of an anomaly occurring and the time urgency, respectively, and are the core auxiliary indicators for anomaly early warning.

[0047] For example, it is necessary to define an abnormal acceleration threshold value, which is the same calibration value used for matching in the subsequent S300. This threshold value is the critical value that distinguishes the normal state and abnormal state of the encryption unit. Then, the probability of exceeding the threshold is calculated. Based on the predicted value of the acceleration evolution trajectory and the reasonable fluctuation range, the probability of exceeding the threshold is calculated through a large number of simulations and statistics. By generating multiple sets of acceleration simulation sequences that conform to the fluctuation law, the proportion of sequences that exceed the abnormal threshold within a preset time window is counted. This proportion is the probability of the predicted acceleration exceeding the abnormal threshold. Finally, the expected time of exceeding the threshold is calculated. The predicted sequence of the acceleration evolution trajectory is interpolated to improve the time resolution. The interpolated predicted sequence is traversed, and the moment when the first predicted acceleration value exceeds the abnormal threshold is the expected time of exceeding the threshold. If none of the predicted values ​​within the preset time window exceed the abnormal acceleration threshold, it is determined that there is no expected time of exceeding the threshold.

[0048] S530 uses the probability and the expected time of exceeding the limit as auxiliary decision information.

[0049] Understandably, the two predicted probabilities and the expected time of excess can be packaged into standardized auxiliary judgment criteria to supplement the deficiencies of the current instantaneous indicators. The auxiliary judgment information is an important supplement to the current dynamic acceleration indicators, solving the problem that when judging solely by the current instantaneous indicators, it is impossible to predict potential anomalies and easy to miss judgments. Together with the dynamic acceleration indicators, it constitutes a multi-dimensional judgment criterion for the current state and future trends.

[0050] For example, the probability of exceeding the limit and the expected time of exceeding the limit can be standardized and encapsulated to form structured auxiliary judgment information. The core includes three parts: first, the probability of an anomaly, which is presented as a quantitative value of 0-1; second, the time urgency level, which is divided into four levels: high, medium, low, and none, based on the expected time of exceeding the limit; and third, the warning level, which is divided into three levels: red, yellow, and blue, based on the probability and urgency. This auxiliary judgment information will participate in subsequent anomaly threshold matching together with the dynamic acceleration index, so that the anomaly judgment can not only reflect the current state, but also take into account the future anomaly development trend, which can significantly improve the lead time and accuracy of anomaly detection.

[0051] S300 matches the dynamic acceleration index with the pre-calibrated abnormal acceleration threshold value to generate an abnormal state judgment result indicating the corresponding internal state of the encryption unit.

[0052] It is understandable that the qualitative and quantitative determination of the abnormal state of the encryption unit can be completed by comparing real-time indicators with critical thresholds. The pre-calibrated abnormal acceleration threshold is a critical value that distinguishes the normal working state and abnormal state of the encryption unit. It is a quantitative threshold that is comprehensively calibrated based on the design performance of the encryption unit, historical data of normal working conditions, and industry safety standards.

[0053] For example, the abnormal acceleration threshold can be calibrated by first collecting dynamic acceleration data of the encryption unit operating continuously for 72 hours under rated conditions. Based on the average level and fluctuation amplitude of the data, the abnormal acceleration threshold is initially calibrated using the 3σ criterion. Then, through offline anomaly injection testing, various common anomaly scenarios are simulated to verify the effectiveness of the threshold. The threshold is adjusted to ensure that almost all real anomalies can be detected, while controlling the false alarm rate to within 1%. Finally, the threshold is determined. Furthermore, three levels of thresholds—mild, moderate, and severe—can be set according to the severity of the anomaly, with the threshold value doubling at each level. Next, threshold matching and judgment are performed. The absolute value of the real-time dynamic acceleration index is taken and matched with the calibrated multi-level thresholds. The basic judgment rule is that if the absolute value is lower than the mild anomaly threshold, it is judged as normal; if it falls between the mild and moderate thresholds, it is judged as mild anomaly; if it falls between the moderate and severe thresholds, it is judged as moderate anomaly; and if it exceeds the severe threshold, it is judged as severe anomaly. Finally, a structured anomaly state judgment result is generated, which includes at least the judgment time, real-time dynamic acceleration value, threshold value matching result, anomaly level, and whether control is triggered. This result is the direct basis for subsequent online control of encrypted parameters.

[0054] In one possible implementation, S300 matches the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result indicating the corresponding internal abnormality of the encryption unit, including: S310 matches the dynamic acceleration index and auxiliary judgment information with the pre-calibrated abnormal acceleration threshold value to generate the corresponding abnormal state judgment result indicating the internal structure of the encryption unit.

[0055] It is understandable that, based on basic single-indicator matching, auxiliary judgment information including the probability of anomalies and the urgency of time can be introduced to achieve multi-dimensional comprehensive matching between the current instantaneous state and future trend risks, solve the problems of missed judgments and misjudgments that are prone to occur in single-indicator matching, and make the anomaly judgment results more consistent with the real risk status of the encrypted unit.

[0056] For example, a multi-dimensional matching judgment rule is first constructed. This rule combines the instantaneous matching result of the dynamic acceleration index, the probability of anomaly occurrence in the auxiliary judgment information, and the time urgency. The core rule is that an instantaneous match indicating severe anomaly, extremely high probability of anomaly occurrence, and high time urgency is considered an emergency anomaly; an instantaneous match indicating moderate anomaly, relatively high probability of anomaly occurrence, and medium to high time urgency is considered a high-risk anomaly; an instantaneous match indicating mild anomaly, relatively high probability of anomaly occurrence, and medium time urgency is considered a medium-risk anomaly; an instantaneous match indicating normal but extremely high probability of anomaly occurrence and high time urgency is considered a potentially high-risk anomaly; an instantaneous match indicating normal, moderate probability of anomaly occurrence, and medium to low time urgency is considered a potentially low-risk anomaly; and all other cases are considered normal. During the matching process, the three dimensions are judged separately first, and then the judgment rule is used to obtain the comprehensive anomaly state judgment result. The final output result includes not only the basic anomaly level but also refined information such as anomaly risk level, urgency level, and warning level, providing a more accurate basis for subsequent differentiated control.

[0057] Optionally, S310, the dynamic acceleration index and auxiliary judgment information are matched with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state judgment result indicating the corresponding internal abnormal state of the encryption unit, including: S311 compares the dynamic acceleration index with the abnormal acceleration threshold to obtain the instantaneous matching result.

[0058] It is understandable that the instantaneous matching result is a direct judgment of the current working state of the encryption unit. It focuses solely on the comparison between the real-time dynamic acceleration index and the anomaly threshold value, and is characterized by strong real-time performance and direct judgment. Its weight in the subsequent comprehensive judgment is no less than 50%, ensuring that the anomaly judgment does not deviate from the actual current state of the encryption unit. The dynamic acceleration index at the current moment can be taken, its absolute value calculated, and compared with the pre-calibrated three-level anomaly thresholds of mild, moderate, and severe to generate the corresponding instantaneous matching result. If the absolute value is lower than the mild threshold, it is judged as instantaneously normal; if it falls between the mild and moderate thresholds, it is judged as instantaneously mildly abnormal; if it falls between the moderate and severe thresholds, it is judged as instantaneously moderately abnormal; and if it exceeds the severe threshold, it is judged as instantaneously severe abnormal.

[0059] S312, compare the probability of the predicted acceleration exceeding the abnormal threshold with the preset probability threshold to obtain the prediction matching result.

[0060] It is understandable that the predictive matching result is a quantitative judgment of the probability of future anomalies occurring in the encrypted unit, used to predict potential anomaly risks, and is the core of achieving early warning. The probability threshold can be calibrated. Based on the detection performance of historical samples, the optimal probability threshold that balances detection sensitivity and specificity can be found. This threshold can also be adjusted according to the false alarm rate requirements of the business scenario. For example, in high-security financial encryption scenarios, the false alarm rate must be controlled within 0.5%, so the preset probability threshold is set to 0.9. In ordinary encryption scenarios, the threshold can be set to 0.7. Then, predictive matching is performed, comparing the probability of the predicted acceleration exceeding the anomaly threshold with the preset probability threshold to generate a predictive matching result. A probability greater than or equal to the threshold is judged as a high-probability anomaly, a probability between 0.5 and the threshold is judged as a low-probability anomaly, and a probability less than 0.5 is judged as no anomaly risk.

[0061] S313 compares the expected time of delay with the preset time urgency threshold to obtain the time urgency assessment result.

[0062] It is understandable that the preset time urgency threshold is a critical time value that distinguishes the urgency of an anomaly. It is based on the control response time of the encryption unit and the anomaly failure rate, and is designed to allow sufficient time for control execution. The time urgency assessment result reflects the size of the time window from the current moment to the occurrence of the anomaly, determining the urgency of the control. The time urgency threshold can be pre-calibrated, with two preset time thresholds: a high urgency threshold and a medium urgency threshold. The high urgency threshold is calibrated based on the maximum execution time of the encryption unit's control command, taking twice the longest control execution time. For example, if the control execution time is 500ms, the high urgency threshold would be set to 1s. The medium urgency threshold is calibrated based on the average time from an anomaly triggering to failure, and could be set to 5s. Then, a time urgency assessment is performed, comparing the expected time exceeding the threshold with the two thresholds to generate an assessment result. If the expected time exceeding the threshold is less than or equal to the high urgency threshold, it is considered high time urgency; if it is greater than the high urgency threshold but less than or equal to the medium urgency threshold, it is considered medium time urgency; if it is greater than the medium urgency threshold, it is considered low time urgency; and if there is no expected time exceeding the threshold, it is considered no time urgency.

[0063] S314 combines the instantaneous matching result, the predicted matching result, and the time urgency assessment result to generate an abnormal state determination result indicating the corresponding internal state of the encryption unit.

[0064] It is understandable that the individual judgment results from the three dimensions can be integrated to upgrade from single-dimensional judgment to multi-dimensional comprehensive judgment, effectively reducing the false negative and false positive rates of anomaly detection. A quantitative scoring rule can be established, assigning a fixed score to each dimension's judgment result. The higher the anomaly level and the greater the risk, the higher the score. A comprehensive risk score is then calculated, assigning corresponding weights to the scores of the three dimensions. The sum of the three weights equals 1, with the instantaneous matching result having the highest weight, focusing more on the current real state. The comprehensive risk score is obtained by multiplying the scores of the three dimensions by their corresponding weights and then summing them. Finally, based on the range of the comprehensive risk score, corresponding anomaly levels are divided into five levels from high to low: emergency anomaly, high-risk anomaly, medium-risk anomaly, low-risk anomaly, and normal state. The final anomaly state judgment result includes the comprehensive anomaly level, comprehensive risk score, individual judgment results of the three dimensions, and the degree of risk urgency, providing a comprehensive and accurate decision-making basis for subsequent differentiated control.

[0065] Instant matching results Predicted matching results Time urgency assessment results satisfy The core principle is to give high weight to the current state, distribute the remaining weight evenly among the auxiliary dimensions, and directly set the basic weight to [value missing]. , , No complex calculations are required because the instantaneous matching result is a direct feedback of the current actual operating state of the encryption unit and is the core basis for anomaly detection. High weighting ensures that the judgment does not deviate from the actual working conditions, avoiding excessive interference from auxiliary dimensions that could lead to missed or misjudged anomalies. The predicted matching result and the time urgency assessment result are auxiliary dimensions for judging future anomaly trends, not current realities. Evenly distributing the remaining weights can balance trend prediction without weakening the core current state judgment, and can also balance the coverage of the two major early warning factors: the probability of anomaly occurrence and the urgency of its occurrence. Therefore, it can be minimally adjusted according to the scenario: for high-real-time industrial / vehicle encryption scenarios, adjust to [value missing]. , , Because these scenarios have high requirements for anomaly response speed, the weight of time urgency judgment needs to be strengthened to prioritize triggering rapid adjustments; for highly stable financial / government encryption scenarios, the adjustment should be... , , Because these scenarios place greater emphasis on proactively avoiding potential risks, it is necessary to strengthen the predictive weight of the probability of anomalies to achieve proactive prevention and control. For ordinary commercial scenarios, the basic weight can be used directly and fixed, as these scenarios have no special bias and the basic weight can evenly cover the needs of current status and future trend prediction without additional adjustment.

[0066] For example, in S314, the instantaneous matching result, the predicted matching result, and the time urgency assessment result are combined to generate an abnormal state determination result indicating the corresponding internal state of the encryption unit, including: S3141, acquire multi-dimensional operating status data; wherein, the multi-dimensional operating status data includes at least one of the following: CPU utilization, memory usage, encryption algorithm execution time jitter, and random number generator output entropy value.

[0067] It is understandable that comprehensive data on the internal operating status of the encryption unit can be obtained, supplementing the internal operational details that the traffic rate indicator cannot reflect, pinpointing the specific causes of anomalies, and solving the problem that traffic indicators alone cannot distinguish anomaly types. The multi-dimensional operating status data is a comprehensive quantitative representation of the working status of the core hardware and software modules within the encryption unit, covering multiple dimensions such as hardware load, algorithm running status, and security core status. It includes at least one of the following: CPU utilization, memory usage, encryption algorithm execution time jitter, and random number generator output entropy. Data can be collected through the encryption unit's system kernel driver, hardware register interface, and encryption algorithm driver module. The timestamps of all data collection must be synchronized with the sampling time of the traffic rate data, and the collection frequency must be consistent with the traffic sampling frequency to ensure the temporal correlation of the data. CPU utilization is the load percentage of the encryption unit's dedicated processing core, and its statistical period is consistent with the traffic sampling period, reflecting the load status of the encryption core. Memory usage is the proportion of the used capacity of the encryption unit's dedicated security memory to the total capacity, reflecting the memory resource occupancy. Memory leaks will cause this indicator to remain unchanged. The execution time jitter of the encryption algorithm continues to rise. It is the ratio of the fluctuation range of the execution time to the average execution time after statistically analyzing the single execution time of 100 consecutive encryption algorithm executions. The larger the ratio, the more severe the jitter and the less stable the algorithm is. The output entropy value of the random number generator is the degree of disorder of the random numbers output by the random number generator. The disorder of qualified cryptographic-level random numbers should be high enough. If it is too low, it indicates that the random number generator is abnormal and there is a risk to encryption security. Finally, the collected multidimensional data is normalized to map all indicators to the range of 0-1, eliminating the difference in the units of different indicators and preparing for the subsequent model input.

[0068] S3142 takes instantaneous matching results, predicted matching results, time urgency assessment results, and multidimensional running state data as inputs to a pre-trained random forest model, and outputs the anomaly type and its confidence level as the anomaly state determination result.

[0069] It is understandable that pre-trained machine learning models can be used to accurately locate anomaly types, solving the previous problem of only being able to determine whether an anomaly exists, but not what kind of anomaly it is or where it is located. This provides a direct basis for subsequent targeted regulation. Among them, the random forest model is a high-accuracy and anti-interference machine learning classification model. It is composed of multiple independent decision trees and can automatically classify and identify the corresponding results based on the input feature data of multiple dimensions. At the same time, it outputs the reliability of the identification results. The confidence level is the reliability of the model's anomaly type identification results, represented by a value of 0-1. The closer the value is to 1, the greater the model's confidence in the identification results and the lower the probability of misjudgment. It realizes early warning of dynamic changes in the internal processing state of the encryption unit, overcoming the shortcomings of traditional external data static threshold alarms, which are difficult to capture trend changes.

[0070] For example, the training process of the random forest model fully covers all stages, including sample construction, model initialization, basic training, hyperparameter optimization, performance verification, and deployment. A sample set adapted for anomaly detection in encryption units can be constructed. The samples cover valid data for all types of anomaly scenarios, including normal operation of the encryption unit and CPU overload, memory leaks, encryption algorithm execution anomalies, random number generator failures, hardware acceleration engine freezes, DDoS attacks, and hardware interface failures. Each sample is labeled with a corresponding anomaly type tag and includes quantified scores for instantaneous matching results, predicted matching results, and time urgency assessment results, as well as normalized CPU utilization, memory usage, encryption algorithm execution time jitter, and random number generator output entropy, among other multi-dimensional operational status features. The sample set is then preprocessed. Missing values ​​were imputed using the mean imputation method, and outliers were removed using the 3σ criterion. The dataset was then randomly divided into a training set (for model parameter learning), a validation set (for hyperparameter optimization), and a test set (for final performance validation) in a 7:2:1 ratio. The random forest classifier model was initialized, and initial values ​​for the core hyperparameters were set: the number of decision trees (n_estimators) was initially set to 100, the maximum depth of a single decision tree (max_depth) was initially set to None (no depth limit), and the number of feature samples taken during node splits (max_features) was initially set to "sqrt". The initial values ​​for the minimum number of samples (min_samples_split) for node splitting (taking the square root of the total number of features) are set to 2. The core model is built on CART decision trees, using bootstrap sampling to randomly extract multiple different training subsets with replacement from the training set. Each subset trains a decision tree independently, and each tree only randomly selects a subset of features to participate in the selection of the optimal splitting features when splitting nodes, ensuring the independence and diversity between decision trees. Subsequently, basic training is performed based on the training set, with each decision tree completing node splitting and growth with the goal of minimizing the Gini coefficient. After the decision trees are trained, the model defaults to using majority voting to output the final anomaly type determination result, and uses the proportion of decision trees that are determined to be of this type to the total number of decision trees as the confidence score. Then, hyperparameter optimization is carried out, using grid search combined with 5-fold cross-validation, with classification accuracy, single-class anomaly recall, and F1 score on the validation set as the core optimization objectives. The model iterates through the preset hyperparameter combinations (n_estimators: 50-500, step size 50; max_depth: 3-20, step size 1; max_features: sqrt / auto / log2).(min_samples_split: 2-10, step size 1) Select the hyperparameter combination with the best overall performance on the validation set (example optimal combination is n_estimators=200, max_depth=10, max_features='sqrt', min_samples_split=4), and retrain the model based on this combination; then use an independent test set to evaluate the performance of the optimized model, requiring an overall classification accuracy of not less than 98% and a single-class anomaly recognition recall of not less than 95%. If the target is not met, backtrack to optimize feature engineering (such as adding features, adjusting the normalization method) or expand the hyperparameter search range, and re-execute the training and optimization process; finally, save the optimized model that meets the performance target through pickle format serialization to complete the model solidification, and archive the training log (including sample set size, feature dimension, final hyperparameter values, test set evaluation indicators, etc.), deploy it to the anomaly state judgment module of the encryption unit, support online inference, and reserve an incremental training interface. Subsequently, based on newly collected anomaly samples from the encryption unit, the model parameters can be iteratively optimized according to the same process to ensure that the model adapts to the changes in the encryption unit's operating state in the long term. ;

[0071] Based on the abnormal state determination result, the S400 uses a preset encryption parameter adaptive adjustment strategy library to output execution instructions for online control of the encryption unit.

[0072] Understandably, based on the anomaly detection results, corresponding control strategies can be matched to generate directly executable instructions. Without interrupting encryption services, encryption parameters can be adjusted online to eliminate anomalies and restore the normal performance of the encryption unit. The adaptive encryption parameter adjustment strategy library is a pre-built mapping set of anomaly types and control strategies, covering standardized control schemes for various anomaly scenarios of the encryption unit. It includes complete information such as adjustable parameter ranges, adjustment magnitudes, execution methods, priorities, and effect verification methods, serving as the basis for this method's online anomaly control. Online control refers to adjusting encryption operating parameters in real time without interrupting business data flow processing, achieving online anomaly elimination and performance recovery without downtime maintenance. This meets the uninterrupted operation requirements of the encryption unit, realizing a shift from passive alarm to proactive control, and from manual intervention to automatic optimization. This significantly improves the stability and reliability of the encryption unit's operation, effectively ensuring the continuity and response efficiency of encryption services.

[0073] For example, an adaptive adjustment strategy library for encryption parameters can be pre-built. This library employs a three-level mapping structure: exception type, exception level, and adjustment strategy. First, a set of adjustable encryption parameters is determined, filtering out those that can be adjusted online without interrupting service. These parameters include encryption algorithm complexity level, number of data processing threads, send / receive buffer size, encrypted data block length, random number generator refresh rate, CPU core scheduling strategy, and hardware acceleration module enable status. Then, the adjustable range of each parameter is defined, and offline testing is used to determine the safe adjustable range for each parameter, ensuring that parameter adjustments do not cause encryption service interruption or encryption compliance failure. Next, exception-strategy mapping rules are formulated. For each exception type and level, a corresponding parameter adjustment strategy is developed. For example, for severe CPU overload exceptions, the corresponding strategy is to reduce the CPU complexity level. The algorithm complexity was optimized, unnecessary processing threads were closed, and hardware acceleration modules were enabled. Offline exception injection testing was conducted to verify the exception elimination effect of each strategy, optimize parameter adjustment range, and ensure that exceptions in the encryption unit can be effectively suppressed within 1 second after strategy execution, while encryption performance meets business requirements. Based on the exception type, exception level, and confidence level in the exception status judgment results, the corresponding optimal control strategy is matched in the strategy library to generate structured execution instructions. These instructions include instruction priority, parameter name to be adjusted, original value, adjusted value, execution time, execution timeout, and effect verification method. The execution instructions are sent to the encryption hardware and software modules through the encryption unit's driver layer control interface. Atomic operations are used during instruction execution to ensure consistency of parameter adjustments and avoid issues such as business disconnection and data packet loss.

[0074] In one possible implementation, S400, based on the abnormal state determination result, adaptively adjusts the strategy library using preset encryption parameters, and outputs execution instructions for online control of the encryption unit, including: S410, when the output abnormal confidence level is higher than the first preset threshold, directly select the emergency control instruction corresponding to the abnormal confidence level from the preset encryption parameter adaptive adjustment strategy library and execute it.

[0075] It is understandable that when the output anomaly confidence level is higher than the first preset threshold, i.e. for high-confidence emergency anomaly scenarios, the detection process is skipped and strong regulation is directly executed to prevent the anomaly from further deteriorating and causing serious consequences. The first preset threshold is the critical value that distinguishes between high-confidence anomalies and medium-to-low-confidence anomalies. It can be calibrated based on the validation results of the random forest model. The lowest confidence level with a classification accuracy of 99.5% or higher is taken as the first preset threshold. The default value is 0.9. In high-safety scenarios, it can be further increased to 0.95 to further reduce the risk of misjudgment. The emergency regulation command is the highest priority command with the most direct regulation effect formulated in the strategy library for high-confidence, high-risk anomalies. When the anomaly confidence level is higher than the first preset threshold, it indicates that the model's identification of the anomaly type is highly reliable and that the encryption unit has a clear high-risk anomaly. The detection process is skipped directly, and the corresponding emergency control instruction is matched from the policy library according to the anomaly type and level. The instruction priority is set to the highest level and executed in real time without additional confirmation process. The emergency control instruction adopts a one-step adjustment method, and the parameter adjustment range is the maximum safe adjustment range corresponding to the anomaly type in the policy library, ensuring that the anomaly can be quickly suppressed. At the same time, before the emergency control instruction is executed, the current encryption parameter configuration is backed up. If a business anomaly occurs after the instruction is executed, it can be immediately rolled back to the original configuration. Status monitoring is started immediately after the instruction is executed to track the performance recovery of the encryption unit in real time and ensure the control effect.

[0076] S420: When the output anomaly confidence level is lower than the first preset threshold but higher than the second preset threshold, the adaptive detection process is started, and the control command is output according to the result of the adaptive detection process.

[0077] It is understandable that when the output anomaly confidence level is lower than the first preset threshold but higher than the second preset threshold, i.e., for potential anomaly scenarios with medium confidence, the authenticity of the anomaly can be verified before control measures are implemented. This balances anomaly prevention and business stability, avoiding performance degradation caused by misjudgments. The second preset threshold is the critical value that distinguishes between medium-confidence anomalies and low-confidence invalid anomalies. It can be calibrated based on the model's misjudgment rate, taking the lowest confidence level at which the model's classification accuracy reaches above 70% as the second preset threshold. The default value is 0.6. If the recognition result accuracy is less than 70% below this threshold, it is judged as an invalid anomaly. The adaptive detection process is a refined detection process that verifies the authenticity of anomalies and locates the causes of anomalies by injecting a controllable detection data stream to obtain more accurate state response data from the encrypted unit, achieving verification before control.

[0078] For example, the adaptive detection process is initiated only when the anomaly confidence level is between the second preset threshold and the first preset threshold. If the confidence level is lower than the second preset threshold, it is determined to be in a normal state, and no detection or control is initiated, only continuous monitoring. The adaptive detection process consists of four steps: adaptive configuration of detection parameters, injection of detection pulses, collection of response data, feature analysis and anomaly verification. The entire detection process is carried out while the encryption unit is processing business data streams normally. The detection traffic accounts for no more than 10% of the rated bandwidth of the encryption unit to ensure that normal business is not affected. Finally, based on the results of the detection process, anomaly verification and location are completed, the corresponding control strategy is matched, and the execution instruction is output.

[0079] Optionally, S420, when the output anomaly confidence level is lower than a first preset threshold but higher than a second preset threshold, an adaptive detection process is initiated, and control instructions are output based on the results of the adaptive detection process, including: S421, when the output anomaly confidence level is lower than the first preset threshold but higher than the second preset threshold, the adaptive detection process is started, and the rate and duration of the detection data stream are dynamically adjusted according to the real-time confidence level. The detection pulse is injected into the encryption unit, and the first response data at the inlet and outlet are obtained. The rate of the detection data stream is inversely proportional to the real-time confidence level, and the detection duration is inversely proportional to the real-time confidence level.

[0080] It is understandable that the adaptive detection process dynamically adjusts the detection intensity based on the uncertainty of the anomaly, minimizing interference with normal business operations while ensuring detection accuracy. Real-time confidence is the anomaly type confidence score output in the anomaly state determination result. A lower score indicates higher uncertainty in anomaly identification, requiring a higher detection rate and longer detection time to obtain richer response data and improve the accuracy of anomaly verification. The probe pulse is a test data packet used to detect the state of the encryption unit and match normal business characteristics. The first response data is the full data collected at the inlet and outlet of the encryption unit after processing the probe pulse, reflecting the performance response of the encryption unit. It is the core basis for subsequent anomaly verification. In-band idle time slot injection is the probe pulse injection method used in this step. It inserts test probe data packets into the transmission gaps of the normal business data stream, without preempting the bandwidth of the normal business, and will not affect the normal transmission and encryption processing of the business data stream.

[0081] For example, the detection parameters are first adaptively configured. The rate and duration of the detection data stream are inversely proportional to the real-time confidence level. That is, the lower the confidence level, the higher the uncertainty of the anomaly, the higher the detection rate, and the longer the detection time. Conversely, the higher the confidence level, the lower the uncertainty, the lower the detection rate, and the shorter the detection time. The maximum detection rate does not exceed 10% of the rated bandwidth of the encryption unit, and the maximum detection time does not exceed 1 second to avoid affecting normal business. Then, the detection pulse is inserted into the idle time slot of the normal business data stream through the in-band idle time slot injection method. The injection process is controlled by the traffic scheduling chip at the inlet to ensure that the timestamp of the detection pulse is accurate and traceable. Finally, the synchronous traffic monitoring devices at the inlet and outlet collect data such as the inlet sending time, outlet receiving time, transmission rate, processing delay, and packet loss rate of each detection pulse. At the same time, the CPU utilization rate, memory utilization rate, and other multi-dimensional operating status data of the encryption unit during the detection process are collected synchronously. All data are associated and stored according to the unique identifier of the detection pulse to form complete first response data.

[0082] S422 performs feature analysis on the first response data to obtain high-resolution state features, and outputs control instructions after matching the high-resolution state features with the encryption parameter adaptive adjustment strategy library.

[0083] It is understandable that by refining the analysis of the probe response data, the authenticity of anomalies can be verified and accurately located, and control instructions that fit the actual state of the encryption unit can be output, avoiding the loss of business performance caused by blind adjustments. High-resolution state features are refined features extracted from the first response data that can accurately reflect the performance details of the encryption unit. Compared with the original rate difference time series data, its time granularity is finer and its feature dimensions are more complete, which can effectively verify the authenticity of medium-confidence anomalies and accurately locate the specific cause of the anomalies.

[0084] For example, firstly, multi-dimensional feature analysis is performed on the first response data to extract core features, including the average processing delay of the probe pulse, the amplitude of delay fluctuation, the variation law of transmission rate difference, packet loss rate, and the correlation between probe rate and processing delay. After extraction, the features are standardized to obtain a high-resolution state feature vector. Then, anomaly authenticity verification and type confirmation are performed. The high-resolution state feature vector is input into a pre-trained anomaly classification model for re-classification of anomalies, obtaining the verified anomaly type and final confidence score. If the final confidence score is lower than a second preset threshold, it is determined that there is no real anomaly, no control command is output, and only continuous monitoring is performed. If the final confidence score is higher than or equal to the second preset threshold, it is determined that there is no real anomaly, no control command is output, and only continuous monitoring is performed. If a threshold is set, the existence of the anomaly is confirmed, and the process proceeds to the strategy matching stage. Finally, based on the verified anomaly type and level, a corresponding fine-grained control strategy is matched from the encryption parameter adaptive adjustment strategy library. The parameter adjustment range of this fine-grained control strategy is smaller than that of the emergency control command, and a gradual adjustment method is adopted to avoid impacting the business. The final control command includes the parameters to be adjusted, the adjustment range, the phased execution steps, the execution interval, and the effect verification node, ensuring that the control process is stable and controllable. This realizes the transformation from passive alarm to active control, and from manual intervention to automatic optimization, significantly improving the stability and reliability of the encryption unit and effectively ensuring the continuity and response efficiency of the encryption service.

[0085] For example, anomaly classification models can be completed through engineered feature threshold calibration and anomaly rule mapping, which is simple, efficient, and adaptable to rapid on-site deployment. First, multi-dimensional feature analysis can be performed on the first response data to extract core high-resolution state features such as average processing latency of probe pulses, latency fluctuation amplitude, rate of change of transmission rate difference, packet loss rate, and correlation coefficient between probe rate and processing latency. Z-score standardization is used to eliminate the dimensional differences of different features, resulting in a standardized high-resolution state feature set. Then, based on multiple probe tests under rated, non-abnormal operating conditions of the encryption unit, the normal threshold range of each high-resolution feature is calibrated. Simultaneously, for common encryption unit anomalies such as CPU overload, memory leak, encryption algorithm execution anomalies, and hardware acceleration engine lag, an offline anomaly injection test is used to pre-set anomaly type-feature anomaly rule base to clarify the feature over-threshold combinations corresponding to each anomaly (e.g., CPU overload corresponds to "average processing latency exceeding the normal threshold and latency increasing linearly with probe rate increase," memory leak corresponds to "latency fluctuation amplitude continuously exceeding the threshold and rate of change of transmission rate difference being negative and the absolute value gradually increasing," and encryption algorithm anomaly corresponds to "average processing latency suddenly increasing beyond the threshold and packet loss rate being 0 and latency fluctuation amplitude exceeding the threshold"). Subsequently, the standardized feature set is compared with the pre-set normal threshold range. If all features are within the normal range, the process is directly... If no real anomaly is detected, no control commands are output; only continuous status monitoring of the encryption unit is performed. If a feature exceeds the threshold, a precise match is made against a preset anomaly type-feature anomaly rule base to determine the unique corresponding anomaly type, thus completing anomaly authenticity verification and type localization. Finally, based on the matched anomaly type and the degree of feature exceeding the threshold (mild exceedance: within 10% of the normal range, moderate exceedance: 10%-30% exceedance, severe exceedance: more than 30% exceedance), the anomaly level is classified and directly compared with the preset "anomaly type-anomaly" rule base in the encryption parameter adaptive adjustment strategy library. The "level" fine-grained control strategy is mapped one-to-one. This strategy still adopts a gradual adjustment method, with parameter adjustment ranges smaller than those of emergency control commands. Based on the matched control strategy, a structured control execution command is generated. The command clearly includes the name of the parameter to be adjusted, the adjustment range in stages, the execution interval of each stage, and the effect verification node. At the same time, performance verification indicators are set after each adjustment (such as the average processing delay of the probe pulse after adjustment should fall back to within 80% of the normal threshold range), ensuring that the control process is stable and controllable, fundamentally avoiding business performance loss caused by blind adjustment, greatly simplifying the calculation process and making it easy to operate and maintain.

[0086] In one possible implementation, after outputting the execution instructions to perform online control of the encryption unit, the method further includes: S610 injects a diagnostic data stream at a reference rate into the encryption unit within a preset diagnostic time period and acquires second response data at the inlet and outlet.

[0087] It is understandable that standardized diagnostic data can be used to verify the effectiveness of control commands and provide a basis for subsequent secondary control. The preset diagnostic period is a time window specifically used to detect the control effect after the control command is executed. It is divided into two stages: the parameter waiting period and the diagnostic execution period. The parameter waiting period is the waiting time after the control command is executed to ensure that the parameter adjustment of the encryption unit has taken full effect. The duration is determined according to the parameter taking time of the encryption unit and can be 100ms-500ms. The diagnostic execution period is a fixed-duration diagnostic data injection and collection period, which can be set to 500ms. The baseline rate diagnostic data stream is a test data stream with fixed parameters and standardized characteristics. It is used to provide a unified benchmark for detecting the control effect and avoid the impact of fluctuations in business data streams on the accuracy of the test results. The baseline rate is usually set to 5% of the rated processing bandwidth of the encryption unit. The second response data is the response data after the encryption unit processes the diagnostic data stream and is the core basis for evaluating the control effect.

[0088] For example, first wait for the parameter waiting period to end to ensure that the encryption parameter adjustment has been fully effective. Then, during the diagnostic execution period, inject a diagnostic data stream at the reference rate into the encryption unit using the in-band idle time slot injection method. The diagnostic data stream uses continuous data packets with fixed packet length and fixed intervals, without encryption payload, to ensure the standardization of the data stream. Finally, through synchronous flow monitoring devices at the inlet and outlet, collect data such as the inlet timestamp, outlet timestamp, inlet rate, outlet rate, transmission rate difference, and processing delay of each diagnostic data packet during the diagnostic execution period. Arrange these data packets in chronological order to form the second response data. The sampling frequency is consistent with the original rate data acquisition frequency.

[0089] S620 performs time-domain analysis on the second response data and extracts the rate of increase of the rate difference as a function of time.

[0090] It is understandable that time-domain analysis is a statistical analysis of the changes in the second response data over time. It extracts the recovery trend of the transmission rate difference after the control is executed. The rising curve is a smooth curve of the transmission rate difference changing over time. Its physical meaning is to reflect the recovery process of the data processing performance of the encryption unit. The rising trend of the curve represents the gradual recovery of performance. The rising rate is the slope of the curve, which quantifies the speed of performance recovery and is the core indicator for evaluating the control effect.

[0091] For example, the transmission rate difference sequence in the second response data can be smoothed by a moving average filter to remove the influence of random noise and obtain a smoothed rate difference sequence. Then, a linear fit can be performed on the smoothed sequence to obtain a smooth rising curve that reflects the trend of rate difference over time. The slope of this curve is the rising rate. The steeper the slope, the greater the rising rate, indicating that the performance of the encryption unit recovers faster. If the curve is flat or even goes down, it means that the performance has not recovered or is even deteriorating.

[0092] S630 compares the rising rate with the preset benchmark rising rate to obtain the rate deviation. If the rate deviation is not within the preset range, it is determined that the abnormality has not been effectively cleared, triggering secondary control and generating alarm information.

[0093] It is understandable that the preset baseline rise rate is the standard rise rate obtained by the encryption unit in a normal and abnormal state when performing the diagnostic process. It is the average rise rate obtained by the encryption unit in 100 repeated diagnostics before leaving the factory, under standard operating conditions and without abnormalities. It is the benchmark for evaluating whether the control effect meets the standard. The rate deviation is the relative deviation between the actual rise rate and the baseline rise rate, reflecting the gap between the actual recovery effect and the expected effect. The preset range is the acceptable range of the deviation. The default setting is that the actual rise rate is not less than 80% of the baseline rise rate. Secondary control is an upgraded and optimized control process executed for scenarios where the first control fails. Alarm information is the standardized reporting information generated for scenarios where the abnormality is not cleared.

[0094] For example, the relative rate deviation can be calculated by comparing the actual detected rate of rise with the benchmark value. If the actual rate of rise is not less than 80% of the benchmark value, the anomaly is considered to have been effectively cleared and the control is successful. If it is less than 80%, the anomaly is considered to have not been effectively cleared and the control is considered to have failed. If the control is considered to have failed, a second control is immediately triggered. Based on the second response data and multi-dimensional operating status data collected during the diagnostic period, the anomaly type is re-identified and the level is determined. Then, an upgraded control strategy is matched from the strategy library. The adjustment range is increased on the basis of the original control parameters, or a backup control scheme is switched. After the second control execution command is issued, the diagnostic process is restarted to verify the control effect. If the second control fails three times in a row, the shutdown protection process is triggered. At the same time, structured alarm information is generated, including the encryption unit device ID, alarm occurrence time, original anomaly type, first control execution status, diagnostic test result, rate deviation value, current encryption unit status, and second control execution status. The alarm information is reported to the device management platform through a standard protocol and recorded in the local log for easy traceability and handling by maintenance personnel.

[0095] Corresponding to the data dynamic encryption method in the above embodiments, this application also provides a data dynamic encryption system, wherein each unit of the system can implement each step of the data dynamic encryption method. Figure 4 A structural block diagram of the data dynamic encryption system provided in the embodiments of this application is shown. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0096] Reference Figure 4 The data dynamic encryption system includes: The acquisition unit is used to acquire in real time the transmission rate difference time-series data recorded by the flow monitoring devices at the inlet and outlet of the encryption unit during the continuous processing of the input data stream; The parsing unit is used to perform trend analysis on the transmission rate difference time-series data and extract a dynamic acceleration index that reflects the rate of change of the rate difference. The determination unit is used to match the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result that indicates the corresponding internal abnormal state of the encryption unit. The output unit is used to output an execution instruction for online control of the encryption unit based on the abnormal state determination result and the preset encryption parameter adaptive adjustment strategy library.

[0097] It should be noted that the information interaction and execution process between the above systems / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0098] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit module can exist physically separately, or two or more unit modules can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0099] This application also provides an electronic device. Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5As shown, the electronic device 6 of this embodiment includes: at least one processor 60 ( Figure 5 Only one is shown in the image), at least one memory 61 ( Figure 5 (Only one is shown in the image) and a computer program 62 stored in the at least one memory 61 and executable on the at least one processor 60, wherein when the processor 60 executes the computer program 62, it causes the electronic device 6 to implement the steps in any of the above-described data dynamic encryption method embodiments, or causes the electronic device 6 to implement the functions of each unit in the above-described system embodiments.

[0100] For example, the computer program 62 may be divided into one or more units, which are stored in the memory 61 and executed by the processor 60 to complete this application. The one or more units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program 62 in the electronic device 6.

[0101] Electronic device 6 can be a computing device or terminal device such as a mobile phone, tablet computer, desktop computer, laptop, handheld computer, and cloud server. This electronic device may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will understand that... Figure 5 This is merely an example of electronic device 6 and does not constitute a limitation on electronic device 6. It may include more or fewer components than shown, or combine certain components, or different components, such as input / output devices, network access devices, buses, etc.

[0102] The processor 60 can be a Central Processing Unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0103] In some embodiments, the memory 61 may be an internal storage unit of the electronic device 6, such as a hard disk or memory of the electronic device 6. In other embodiments, the memory 61 may be an external storage device of the electronic device 6, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 6. Furthermore, the memory 61 may include both internal and external storage units of the electronic device 6. The memory 61 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 61 can also be used to temporarily store data that has been output or will be output.

[0104] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0105] This application provides a computer program product that, when run on an electronic device, causes the electronic device to perform the steps in any of the above method embodiments.

[0106] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0107] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0108] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0109] In the embodiments provided in this application, it should be understood that the disclosed dynamic data encryption method can be implemented in other ways. For example, the embodiments of the dynamic data encryption method described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0110] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0111] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A data dynamic encryption method, characterized by, The method includes: Real-time acquisition of transmission rate difference time-series data recorded by flow monitoring devices at the inlet and outlet of the encryption unit during continuous processing of the input data stream; Trend analysis is performed on the time-series data of the transmission rate difference to extract a dynamic acceleration index that reflects the rate of change of the rate difference. The dynamic acceleration index is matched with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result indicating the internal state of the encryption unit. Based on the abnormal state determination result, an execution instruction for online control of the encryption unit is output through a preset encryption parameter adaptive adjustment strategy library; The step of performing trend analysis on the time-series data of the transmission rate difference to extract a dynamic acceleration index reflecting the rate of change of the rate difference includes: Multi-scale wavelet decomposition is performed on the time-series data with different transmission rates to obtain detail components and approximate components in different frequency bands; Identify abrupt changes related to anomalous events from the detailed components and extract long-term trend terms from the approximate components; Based on the abrupt change point and the long-term trend term, instantaneous acceleration and trend acceleration are calculated respectively, and the weighted fusion result of instantaneous acceleration and trend acceleration is used as a dynamic acceleration index.

2. The method of claim 1, wherein, Before matching the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold, the method further includes: The dynamic acceleration index is input into a pre-trained time series prediction model to predict the acceleration evolution trajectory within a preset time window in the future. Based on the evolution trajectory, calculate the probability that the predicted acceleration exceeds the abnormal threshold and the expected time of exceeding it; The probability and the expected time of excess are used as auxiliary determination information; The step of matching the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result indicating the corresponding internal abnormality of the encryption unit includes: The dynamic acceleration index and the auxiliary judgment information are matched with the pre-calibrated abnormal acceleration threshold value to generate the corresponding abnormal state judgment result indicating the internal structure of the encryption unit.

3. The method of claim 2, wherein, The step of matching the dynamic acceleration index and the auxiliary judgment information with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state judgment result indicating the corresponding internal abnormality of the encryption unit includes: The dynamic acceleration index is compared with the abnormal acceleration threshold to obtain an instantaneous matching result; The probability that the predicted acceleration exceeds the abnormal threshold is compared with a preset probability threshold to obtain the prediction matching result; The estimated time of delay is compared with a preset time urgency threshold to obtain a time urgency assessment result; The instantaneous matching result, the predicted matching result, and the time urgency assessment result are combined to generate an abnormal state determination result indicating the corresponding internal state of the encryption unit.

4. The method as described in claim 3, characterized in that, The step of combining the instantaneous matching result, the predicted matching result, and the time urgency assessment result to generate an abnormal state determination result indicating the corresponding internal state of the encryption unit includes: Acquire multidimensional operational status data; wherein, the multidimensional operational status data includes at least one of the following: CPU utilization rate, memory usage rate, encryption algorithm execution time jitter, and random number generator output entropy value; The instantaneous matching result, the predicted matching result, the time urgency assessment result, and the multidimensional running state data are input into the pre-trained random forest model, and the anomaly type and its confidence level are output as the anomaly state determination result.

5. The method as described in claim 1, characterized in that, Based on the abnormal state determination result, and through a preset encryption parameter adaptive adjustment strategy library, the step of outputting execution instructions for online control of the encryption unit includes: When the output anomaly confidence level is higher than the first preset threshold, an emergency control command corresponding to the anomaly confidence level is directly selected from the preset encryption parameter adaptive adjustment strategy library and executed. When the output anomaly confidence level is lower than the first preset threshold but higher than the second preset threshold, the adaptive detection process is initiated, and a control command is output according to the result of the adaptive detection process.

6. The method as described in claim 5, characterized in that, When the output anomaly confidence level is lower than a first preset threshold but higher than a second preset threshold, an adaptive detection process is initiated, and control instructions are output based on the results of the adaptive detection process, including: When the output anomaly confidence level is lower than the first preset threshold but higher than the second preset threshold, an adaptive detection process is initiated, and the rate and duration of the detection data stream are dynamically adjusted according to the real-time confidence level. A detection pulse is injected into the encryption unit, and the first response data at the inlet and outlet are obtained. The rate of the detection data stream is inversely proportional to the real-time confidence level, and the detection duration is inversely proportional to the real-time confidence level. The first response data is subjected to feature analysis to obtain high-resolution state features. The high-resolution state features are then matched with the encryption parameter adaptive adjustment strategy library, and an adjustment command is output.

7. The method as described in claim 1, characterized in that, After outputting the execution instruction to perform online control of the encryption unit, the method further includes: During the preset diagnostic period, a diagnostic data stream at a reference rate is injected into the encryption unit, and second response data at the inlet and outlet are obtained. Perform time-domain analysis on the second response data to extract the rate of increase of the rate difference as a function of time. The rate of ascent is compared with a preset benchmark rate of ascent to obtain the rate deviation. If the rate deviation is not within the preset range, it is determined that the abnormality has not been effectively cleared, triggering secondary control and generating alarm information.

8. A dynamic data encryption system, characterized in that, For implementing the method as described in any one of claims 1 to 7, the dynamic data encryption system comprises: The acquisition unit is used to acquire in real time the transmission rate difference time-series data recorded by the flow monitoring devices at the inlet and outlet of the encryption unit during the continuous processing of the input data stream; The parsing unit is used to perform trend analysis on the transmission rate difference time-series data and extract a dynamic acceleration index that reflects the rate of change of the rate difference. The determination unit is used to match the dynamic acceleration index with a pre-calibrated abnormal acceleration threshold value to generate an abnormal state determination result that indicates the corresponding internal abnormal state of the encryption unit. The output unit is used to output an execution instruction for online control of the encryption unit based on the abnormal state determination result and the preset encryption parameter adaptive adjustment strategy library.

9. A computer program product, characterized in that, When the computer program product is run on an electronic device, it causes the electronic device to perform the method as described in any one of claims 1 to 7.