Digital archive distribution method based on dynamic optical fragments
The dynamic optical fragment distribution method solves the security and access control problems of traditional digital archive distribution, achieving high security and dynamic access management, and is suitable for the distribution of various digital archive formats.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Filing Date
- 2026-04-15
- Publication Date
- 2026-07-10
AI Technical Summary
Traditional methods of distributing digital archives suffer from security issues such as encrypted files being easily intercepted and cracked, fixed permissions that cannot be dynamically adjusted, and static optical encoding that is easily stolen and restored.
A dynamic optical fragment distribution method is adopted, which generates dynamic optical fragments based on trust levels through format standardization, dynamic fragment generation, node trust assessment and encrypted optical transmission, and transmits them through an optical encryption channel. The target node performs fragment verification and decryption restoration.
It achieves high security, dynamic access control, and anti-interference capabilities for digital archives, reduces the risk of interception and cracking, and is applicable to various digital archive formats.
Smart Images

Figure CN122365573A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure distribution technology for digital archives, specifically a method for distributing digital archives based on dynamic optical fragments. Background Technology
[0002] As a crucial information asset, the secure distribution of digital archives is one of the core issues in the field of archival management. Traditional methods for distributing digital archives are mostly based on digital encryption technologies (such as symmetric and asymmetric encryption), encrypting the entire archive file before transmitting it to the target node over the network. However, these methods have the following drawbacks: the encrypted archive file remains in digital form, making it vulnerable to illegal interception, cracking, and copying; distribution permissions are fixed and cannot be dynamically adjusted based on the trust level of the receiving node, leading to potential abuse of permissions; and digital encryption algorithms are susceptible to being cracked by computing power, making it difficult to guarantee the security of highly confidential digital archives.
[0003] Optical encoding technology is characterized by its non-copyability and strong resistance to interference, which can enhance the security of digital archives. However, most existing optical encoding schemes are static, with a fixed number and distribution of encoded fragments. If some fragments are stolen, there is still a risk that the archives can be recovered. To address this, a digital archive distribution method based on dynamic optical fragments is proposed. Summary of the Invention
[0004] The purpose of this invention is to provide a digital archive distribution method based on dynamic optical fragments to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] A digital archive distribution method based on dynamic optical fragmentation includes the following steps:
[0007] S1. Digital Archive Preprocessing: After standardizing the format of the original digital archive, the digital archive is divided into N data blocks according to the preset block division rules. A unique identifier code is generated for each data block, and each data block and its corresponding unique identifier code are converted into initial optical feature code based on the optical coding algorithm.
[0008] S2. Dynamic optical fragment generation: Construct a dynamic fragment generation rule base, which includes rules for dynamically adjusting the number of fragments, rules for randomizing the distribution location of fragments, and rules for the timeliness of fragment encryption parameters. Based on the rule base, the initial optical feature code corresponding to each data block is decomposed into M groups of dynamic optical fragments. The value of M is dynamically adjusted according to the distribution time and the attributes of the target distribution node, and each group of dynamic optical fragments carries a timeliness tag and a node matching tag.
[0009] S3. Distribution Node Trust Assessment: Construct a node trust assessment model, collect the identity authentication information, historical distribution behavior data, and node security status data of the target distribution node, input them into the model, and output the trust level of the target distribution node. The trust level includes core trust level, ordinary trust level, and temporary trust level.
[0010] S4. Distribution Matching: Based on the trust level of the target distribution node, match the corresponding fragment combination and decryption permission from the dynamic optical fragment set. Among them, core trust level nodes match complete fragment combinations and permanent decryption permission, ordinary trust level nodes match partial fragment combinations and limited time decryption permission, and temporary trust level nodes match the minimum fragment combination and single decryption permission.
[0011] S5. Optical Distribution and Reconstruction: The matched dynamic optical fragments are sent to the target distribution node via an encrypted optical transmission channel. After receiving the fragments, the target node first verifies the fragment's time tag, node matching tag, and integrity. After the verification is successful, the corresponding decryption algorithm is called based on the decryption permission to complete the fragment splicing, restore the initial optical feature code, and then reverse convert it into the original digital file.
[0012] Preferably, the specific process of the optical coding algorithm in step S1 is as follows:
[0013] The binary data stream of the data block is converted into a grayscale image matrix. Based on the principle of optical phase modulation, a phase value is assigned to each pixel of the grayscale image matrix to generate an initial optical feature code containing phase information. The initial optical feature code is in the form of an optical hologram.
[0014] Preferably, the dynamic adjustment rule for the number of fragments in step S2 is as follows:
[0015] Set the base number of fragments Core trust-level nodes correspond to Ordinary trust level nodes correspond to Temporary trust level node corresponding ,in ∈(0,0.5], ∈(0,0.3];
[0016] The randomization rule for the distribution location of the fragments is as follows:
[0017] A random position sequence is generated based on a chaotic mapping algorithm, and the phase information encoded by the initial optical features is randomly split into different dynamic optical fragments according to the sequence;
[0018] The chaotic mapping algorithm is an improved Logistic chaotic mapping algorithm, and its iterative formula is:
[0019]
[0020] in, This is a chaos control parameter, with a value range of 3.57 to 4. The perturbation factor ranges from 0.01 to 0.1, and rand(0,1) is a random number between 0 and 1. The chaotic value is the value of the nth iteration, and the chaotic sequence generated by the iteration is used as the fragmentation key;
[0021] The time limit rule for the fragment encryption parameters is as follows:
[0022] Each set of dynamic optical fragments is assigned a timestamp-based encryption key. The key validity period decreases with the trust level. The validity period of the core trust level key is T, the ordinary trust level key is T / 3, and the temporary trust level key is T / 10. T is the preset basic validity period.
[0023] Preferably, the process of constructing the node trust assessment model in step S3 is as follows:
[0024] S31. Determine the set of evaluation indicators, including the identity authentication dimension. behavioral compliance dimension Security Status Dimension ,and + + =1;
[0025] S32. Quantify the indicators of each dimension. The identity authentication dimension includes the number of authentication methods and the authentication pass rate. The behavior compliance dimension includes the number of historical violations and the compliance rate of file usage. The security status dimension includes the number of node vulnerabilities and the firewall status.
[0026] S33. Use the analytic hierarchy process to determine the sub-weights of each indicator, and combine the fuzzy comprehensive evaluation method to score the quantified indicators and output a trust score of 0-100.
[0027] S34. Set trust level thresholds: core trust level is a score ≥ 85, ordinary trust level is 60 ≤ score < 85, temporary trust level is 40 ≤ score < 60, nodes with a score < 40 are judged as untrusted nodes and are refused distribution.
[0028] Preferably, the construction process of the encrypted optical transmission channel in step S5 is as follows:
[0029] Using optical fiber as the transmission medium, an optical encryption module is added to the transmission link to modulate the polarization state and encrypt the optical signal of dynamic optical fragments. During transmission, the link optical power and polarization state changes are monitored in real time. If abnormal fluctuations are detected, the transmission is immediately interrupted and the abnormal node is marked.
[0030] A digital archive distribution system based on dynamic optical fragmentation includes:
[0031] The document preprocessing module is used to standardize the format of the original digital documents, divide them into blocks, generate unique identifiers, and convert the data blocks into initial optical feature codes.
[0032] The dynamic optical fragment generation module, connected to the archive preprocessing module, is used to decompose the initial optical feature encoding into multiple sets of labeled dynamic optical fragments based on the dynamic fragment generation rule base.
[0033] The node trust assessment module is used to collect multi-dimensional data of the target distribution node and output the node trust level through the node trust assessment model.
[0034] The distribution matching module is connected to the dynamic optical fragment generation module and the node trust assessment module, respectively, and is used to match the target node with the corresponding dynamic optical fragment combination and decryption permission according to the trust level.
[0035] The optical transmission module, connected to the distribution and matching module, is used to construct an encrypted optical transmission channel and directionally distribute the matched dynamic optical fragments to the target node.
[0036] The file restoration module is deployed on the target distribution node side. It is used to receive dynamic optical fragments and complete tag verification, fragment decryption, splicing and inverse conversion to restore the original digital file.
[0037] Preferably, the dynamic optical debris generation module includes:
[0038] The rule management unit is used to maintain the dynamic fragment generation rule base and update rule parameters in real time;
[0039] Fragmentation unit, used to perform fragmentation of the initial optical feature encoding based on the chaotic mapping algorithm;
[0040] The tag encryption unit is used to add time-sensitive tags and node matching tags to the split dynamic optical fragments and generate encryption keys based on timestamps.
[0041] Preferably, the node trust assessment module includes:
[0042] The data acquisition unit is used to collect node authentication information, historical behavior data, and security status data;
[0043] The indicator quantification unit is used to standardize and quantify the collected data.
[0044] The model calculation unit is used to calculate the node trust score and determine the trust level based on the analytic hierarchy process and fuzzy comprehensive evaluation method.
[0045] Preferably, the optical transmission module includes:
[0046] An optical encryption unit is used to perform polarization state modulation and intensity encryption on the optical signals of dynamic optical fragments.
[0047] The transmission monitoring unit is used to monitor the optical power, polarization state, and link connectivity of the transmission link in real time.
[0048] The link control unit is used to interrupt transmission when an anomaly is detected and send an anomaly alarm message to the management terminal.
[0049] Preferably, the file restoration module includes:
[0050] The fragment verification unit is used to verify the timeliness label, node matching label, and fragment integrity of the fragments.
[0051] The decryption unit is used to invoke the corresponding algorithm to decrypt fragments based on decryption permissions.
[0052] The splicing and restoration unit is used to splice the decrypted fragments into the initial optical feature code and then reverse convert it into the original digital file.
[0053] Compared with the prior art, the beneficial effects of the present invention are:
[0054] High security: Digital archives are converted into optical feature codes and broken into dynamic optical fragments. The number, distribution, and encryption parameters of the fragments are dynamically adjusted with time and nodes. Combined with the physical characteristics of optical transmission, the risk of archives being intercepted, cracked, or copied is greatly reduced.
[0055] Precise access control: Based on the node trust assessment model, differentiated fragment combinations and decryption permissions are matched to nodes with different trust levels to achieve dynamic control of distribution permissions and avoid abuse of permissions;
[0056] Strong anti-interference capability: The optical transmission channel incorporates polarization state and light intensity encryption, and monitors the link status in real time, which can quickly identify and respond to transmission anomalies, ensuring the stability of the distribution process;
[0057] Good compatibility: The preprocessing stage standardizes the file format, making it suitable for distribution scenarios of various digital files (such as text, image, and video files), and has strong universality. Attached Figure Description
[0058] Figure 1 This is a schematic diagram of the system architecture of the present invention;
[0059] Figure 2 This is a schematic diagram of the process of the present invention. Detailed Implementation
[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0061] The digital archive distribution method based on dynamic optical fragments provided by this invention includes the following steps:
[0062] Step S1, Digital Archive Preprocessing:
[0063] The original digital archives are standardized (e.g., converted to XML or binary stream format) to eliminate compatibility issues between different formats. The digital archives are divided into N data blocks according to preset segmentation rules (e.g., divided equally by data size or split according to the archive's logical structure). The value of N is set according to the archive size, preferably an integer between 8 and 64. A unique identifier (UUID) is generated for each data block for subsequent fragment tracing and verification. Each data block and its corresponding unique identifier are converted into an initial optical feature code based on an optical coding algorithm.
[0064] The specific process of the optical coding algorithm is as follows: convert the binary data stream of the data block into a grayscale image matrix (the matrix size is adaptively adjusted according to the size of the data block), assign a phase value (the phase value range is 0-2π) to each pixel of the grayscale image matrix based on the principle of optical phase modulation, and generate an initial optical feature code containing phase information through optical holographic imaging technology. This code is in the form of an optical hologram and has unique physical characteristics of optics, which cannot be completely restored by digital copying.
[0065] Step S2, Dynamic Optical Debris Generation:
[0066] A dynamic fragment generation rule base is constructed, which includes rules for dynamically adjusting the number of fragments, randomizing the distribution location of fragments, and timeliness rules for fragment encryption parameters. Based on this rule base, the initial optical feature encoding corresponding to each data block is decomposed into M groups of dynamic optical fragments.
[0067] Fragment quantity dynamic adjustment rules: Set the base fragment quantity (Preferred to be 10-30), corresponding to core trust-level nodes ( ∈(0,0.5]), ordinary trust level nodes correspond to M=M0, and temporary trust level nodes correspond to ( ∈(0,0.3]), by adjusting the number of fragments to adapt to the security requirements of nodes with different trust levels;
[0068] Fragment distribution location randomization rule: A random location sequence is generated based on the Logistic chaotic mapping algorithm. The initial value and iteration parameters of the chaotic mapping are dynamically updated with the distribution time. According to this sequence, the phase information encoded by the initial optical features is randomly split into different dynamic optical fragments, so that the fragment distribution has no fixed pattern.
[0069] The chaotic mapping algorithm is an improved Logistic chaotic mapping algorithm, and its iterative formula is:
[0070]
[0071] in, This is a chaos control parameter, with a value range of 3.57 to 4. The perturbation factor ranges from 0.01 to 0.1, and rand(0,1) is a random number between 0 and 1. The chaotic value is the value of the nth iteration, and the chaotic sequence generated by the iteration is used as the fragmentation key;
[0072] Fragment encryption parameter validity rules: Each group of dynamic optical fragments is assigned a timestamp-based encryption key. The key is generated using the AES-256 algorithm. The key validity period decreases with the trust level. The validity period of the core trust level key is T (preferably 30 days), the ordinary trust level key is T / 3, and the temporary trust level key is T / 10. Fragments that exceed the validity period will automatically become invalid.
[0073] Each set of dynamic optical fragments carries a time-limited tag (containing the key's validity period) and a node matching tag (containing the target node's identity) for subsequent verification.
[0074] Step S3, Distribution Node Trust Assessment:
[0075] A node trust assessment model is constructed to determine the trust level of the target distribution node. The specific process is as follows:
[0076] S31. Determine the set of evaluation indicators, including the identity authentication dimension (weight). =0.4), behavioral compliance dimension (weight) =0.35), security status dimension (weight) =0.25), and + + =1;
[0077] S32. Quantify the indicators of each dimension:
[0078] Identity authentication dimensions: Number of authentication methods (0-5 points, such as password authentication 1 point, fingerprint authentication 2 points, hardware key authentication 2 points), authentication pass rate (0-5 points, 100% pass rate 5 points, 1 point deducted for every 20% decrease);
[0079] Behavioral compliance dimensions: number of historical violations (0-5 points, 5 points for no violations, 1 point deducted for each violation), and compliance rate of file usage (0-5 points, 5 points for 100% compliance, 1 point deducted for every 20% decrease).
[0080] Security status dimensions: Number of node vulnerabilities (0-5 points, 5 points for no vulnerabilities, 2 points deducted for each high-risk vulnerability, and 1 point deducted for each low-risk vulnerability), firewall status (5 points for enabled, 0 points for disabled).
[0081] S33. Use the Analytic Hierarchy Process (AHP) to determine the sub-weights of each indicator, and combine the fuzzy comprehensive evaluation method to score the quantified indicators and output a trust score of 0-100.
[0082] S34. Set trust level thresholds: core trust level (score ≥ 85), ordinary trust level (60 ≤ score < 85), temporary trust level (40 ≤ score < 60). Nodes with a score < 40 are judged as untrusted nodes and are refused distribution.
[0083] Step S4, Distribute matching:
[0084] Based on the trust level of the target distribution node, match the corresponding fragment combination and decryption permissions from the dynamic optical fragment set:
[0085] Core Trust Level Node: Matches complete fragment combinations (including all M groups of dynamic optical fragments) and has permanent decryption privileges (the key is valid indefinitely unless manually revoked);
[0086] Ordinary Trust Level Node: Matches partial fragment combinations (including M×0.8 groups of dynamic optical fragments) and has limited time-limited decryption permissions (key validity period T / 3).
[0087] Temporary Trust Level Node: Matches the smallest fragment combination (containing M×0.5 groups of dynamic optical fragments) and has single decryption permission (can only be decrypted once, after which the permission is invalid).
[0088] Decryption permissions are bound to dynamic optical fragments, and only the target node can decrypt the corresponding fragment based on its own permissions.
[0089] Step S5, Optical Distribution and Reduction:
[0090] The matched dynamic optical fragments are combined and directionally sent to the target distribution node via an encrypted optical transmission channel. The specific process is as follows:
[0091] Encrypted optical transmission channel construction: Single-mode fiber is used as the transmission medium, and an optical encryption module is added to the transmission link to perform polarization state modulation (modulation angle random from 0 to 90°) and light intensity encryption (light intensity value is adjusted according to a random sequence) on the optical signal of dynamic optical fragments, thereby improving the anti-interception capability of optical signal transmission.
[0092] Transmission monitoring: During transmission, the transmission monitoring unit monitors the link optical power (normal range is -10dBm to 0dBm) and polarization state changes (fluctuation threshold ±5°) in real time. If abnormal fluctuations are detected, the transmission is immediately interrupted and the abnormal node is marked.
[0093] Fragment verification and restoration: After receiving the fragment, the file restoration module on the target node side first verifies the fragment's timeliness tag, node matching tag, and integrity (through hash verification). If the verification passes, it calls the corresponding decryption algorithm based on decryption permissions to complete the fragment decryption. Then, it completes the fragment splicing according to the inverse process of chaotic mapping to restore the initial optical feature code. Finally, it is converted into the original digital file through an optical decoding algorithm. If the verification fails, the fragment is discarded directly and an alarm is sent to the management terminal.
[0094] The present invention also provides a digital archive distribution system based on dynamic optical fragments for implementing the above method, comprising:
[0095] The system includes: archive preprocessing module, dynamic optical fragment generation module, connected archive preprocessing module, node trust assessment module, distribution matching module, optical transmission module, and archive restoration module.
[0096] The document preprocessing module is used to standardize the format of the original digital documents, divide them into blocks, generate unique identifiers, and convert the data blocks into initial optical feature codes. This module includes a format conversion unit, a block division unit, and an optical coding unit: the format conversion unit unifies the document format, the block division unit splits the documents according to preset rules, and the optical coding unit generates initial optical feature codes based on the principle of optical phase modulation.
[0097] The dynamic optical fragment generation module connects to the archive preprocessing module and is used to decompose the initial optical feature encoding into multiple sets of tagged dynamic optical fragments based on the dynamic fragment generation rule base. This module includes a rule management unit, a fragment splitting unit, and a tag encryption unit: the rule management unit maintains and updates the dynamic fragment generation rules; the fragment splitting unit performs encoding splitting based on a chaotic mapping algorithm; and the tag encryption unit adds time-sensitive and node-matching tags to the fragments and generates encryption keys.
[0098] The node trust assessment module is used to collect multi-dimensional data of target distribution nodes and output the node trust level through the node trust assessment model. This module includes a data acquisition unit, an indicator quantification unit, and a model calculation unit: the data acquisition unit collects node identity, behavior, and security data; the indicator quantification unit standardizes and quantifies the data; and the model calculation unit calculates the trust score and level based on AHP and fuzzy comprehensive evaluation methods.
[0099] The distribution and matching module connects to both the dynamic optical fragment generation module and the node trust assessment module. It matches target nodes with corresponding dynamic optical fragment combinations and decryption permissions based on their trust levels. This module has a built-in permission matching rule base and can retrieve fragment data and node trust level data in real time to achieve accurate matching.
[0100] The optical transmission module connects to the distribution matching module to construct an encrypted optical transmission channel, directionally distributing the matched dynamic optical fragments to the target node. This module includes an optical encryption unit, a transmission monitoring unit, and a link control unit: the optical encryption unit encrypts the polarization state and intensity of the optical signal; the transmission monitoring unit monitors the link status; and the link control unit interrupts transmission and issues an alarm in case of an anomaly.
[0101] The file restoration module is deployed on the target distribution node side to receive dynamic optical fragments and perform tag verification, fragment decryption, splicing, and inverse conversion to restore the original digital file. This module includes a fragment verification unit, a decryption unit, and a splicing and restoration unit: the fragment verification unit performs multi-dimensional verification; the decryption unit decrypts fragments based on permissions; and the splicing and restoration unit performs fragment splicing and optical encoding inverse conversion.
[0102] Example 1:
[0103] Taking the distribution of classified digital archives in a certain government agency as an example, the specific steps of the digital archive distribution method based on dynamic optical fragments of this invention are as follows:
[0104] File preprocessing: Select a 100MB classified text file, convert it into a binary stream format, split it into 10 data blocks (N=10) at 10MB / block, and generate a UUID for each data block; convert the binary stream of each data block into a 1024×1024 grayscale image matrix, assign a phase value of 0-2π to each pixel based on the principle of optical phase modulation, and generate an initial optical feature code in the form of an optical hologram.
[0105] Dynamic optical debris generation: Set the base number of debris =20, =0.3, =0.2; Based on Logistic chaotic mapping (initial value) =0.3, iteration parameter =3.9) Generate a random location sequence, split the initial optical feature encoding into dynamic optical fragments; assign a timestamp-based AES-256 key to the fragments, with the core trust level key having a validity period of T=30 days, the ordinary trust level 10 days, and the temporary trust level 3 days, and add a time-limited tag and a node matching tag.
[0106] Node trust assessment: Select 3 target distribution nodes (nodes A, B, and C), collect data from each node, and quantify it.
[0107] Node A: Identity authentication dimension (3 authentication methods, 100% pass rate, quantitative score of 10 points), behavior compliance dimension (no violations, 100% compliance rate, quantitative score of 10 points), security status dimension (no vulnerabilities, firewall enabled, quantitative score of 10 points), with a comprehensive trust score of 92, is judged as core trust level;
[0108] Node B: Identity authentication dimension (2 authentication methods, 100% pass rate, quantitative score of 8 points), behavioral compliance dimension (no violations, compliance rate of 80%, quantitative score of 9 points), security status dimension (1 low-risk vulnerability, firewall enabled, quantitative score of 9 points), comprehensive trust score of 75, judged as ordinary trust level;
[0109] Node C: Identity authentication dimension (1 authentication method, 80% pass rate, 6 points), behavioral compliance dimension (1 violation, 80% compliance rate, 8 points), security status dimension (no vulnerabilities, firewall enabled, 10 points), overall trust score 55, judged as temporary trust level.
[0110] Distribution matching: Match 26 sets (20×1.3) of complete fragment combinations and permanent decryption permissions for node A; match 16 sets (20×0.8) of fragment combinations and 10-day validity period decryption permissions for node B; match 10 sets (20×0.5) of fragment combinations and single decryption permissions for node C.
[0111] Optical Distribution and Reconstruction: Fragments are transmitted via an encrypted fiber optic channel. The optical encryption module modulates the polarization state of the optical signal to 35° and adjusts the light intensity to -5dBm. During transmission, the link optical power and polarization state are monitored, and no abnormalities are found. After receiving the fragments, each node verifies the tags and integrity. Node A decrypts and splices all fragments to restore the initial optical feature code, which is then converted back to the original file. Nodes B and C complete the decryption and reconstruction according to their respective permissions. After node C decrypts, its permissions automatically expire.
[0112] Example 2:
[0113] This embodiment provides a digital archive distribution system based on dynamic optical fragments, the hardware deployment of which includes:
[0114] Server-side: Deploys file preprocessing module, dynamic optical fragment generation module, node trust assessment module, and distribution matching module, using Intel Xeon E5-2680v4 processor, 128GB memory, and 10TB storage capacity;
[0115] Transmission link: Single-mode fiber optic link, equipped with an optical encryption device (supporting polarization state modulation and optical intensity encryption), optical power monitor, and polarization state analyzer;
[0116] Node-side: Deploys an archive restoration module, using an Intel Core i7-12700 processor, 32GB of memory, and equipped with an optical decoding device.
[0117] During system operation, the server completes file preprocessing, fragment generation, node evaluation and matching, and distributes the fragments to the node end through encrypted optical fiber. The node end completes fragment verification and file restoration. There is no plaintext transmission of digital files throughout the process, ensuring distribution security.
[0118] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A digital archive distribution method based on dynamic optical fragments, characterized in that, Includes the following steps: S1. Digital Archive Preprocessing: After standardizing the format of the original digital archive, the digital archive is divided into N data blocks according to the preset block division rules. A unique identifier code is generated for each data block, and each data block and its corresponding unique identifier code are converted into initial optical feature code based on the optical coding algorithm. S2. Dynamic optical fragment generation: Construct a dynamic fragment generation rule base, which includes rules for dynamically adjusting the number of fragments, rules for randomizing the distribution location of fragments, and rules for the timeliness of fragment encryption parameters. Based on the rule base, the initial optical feature code corresponding to each data block is decomposed into M groups of dynamic optical fragments. The value of M is dynamically adjusted according to the distribution time and the attributes of the target distribution node, and each group of dynamic optical fragments carries a timeliness tag and a node matching tag. S3. Distribution Node Trust Assessment: Construct a node trust assessment model, collect the identity authentication information, historical distribution behavior data, and node security status data of the target distribution node, input them into the model, and output the trust level of the target distribution node. The trust level includes core trust level, ordinary trust level, and temporary trust level. S4. Distribution Matching: Based on the trust level of the target distribution node, match the corresponding fragment combination and decryption permission from the dynamic optical fragment set. Among them, core trust level nodes match complete fragment combinations and permanent decryption permission, ordinary trust level nodes match partial fragment combinations and limited time decryption permission, and temporary trust level nodes match the minimum fragment combination and single decryption permission. S5. Optical Distribution and Reconstruction: The matched dynamic optical fragments are sent to the target distribution node via an encrypted optical transmission channel. After receiving the fragments, the target node first verifies the fragment's time tag, node matching tag, and integrity. After the verification is successful, the corresponding decryption algorithm is called based on the decryption permission to complete the fragment splicing, restore the initial optical feature code, and then reverse convert it into the original digital file.
2. The digital archive distribution method based on dynamic optical fragments according to claim 1, characterized in that, The specific process of the optical coding algorithm described in step S1 is as follows: The binary data stream of the data block is converted into a grayscale image matrix. Based on the principle of optical phase modulation, a phase value is assigned to each pixel of the grayscale image matrix to generate an initial optical feature code containing phase information. The initial optical feature code is in the form of an optical hologram.
3. The digital archive distribution method based on dynamic optical fragments according to claim 1, characterized in that, The dynamic adjustment rule for the number of fragments in step S2 is as follows: Set the base number of fragments Core trust-level nodes correspond to Ordinary trust level nodes correspond to Temporary trust level node corresponding ,in ∈(0,0.5], ∈(0,0.3]; The randomization rule for the distribution location of the fragments is as follows: A random position sequence is generated based on a chaotic mapping algorithm, and the phase information encoded by the initial optical features is randomly split into different dynamic optical fragments according to the sequence; The chaotic mapping algorithm is an improved Logistic chaotic mapping algorithm, and its iterative formula is: in, This is a chaos control parameter, with a value range of 3.57 to 4. The perturbation factor ranges from 0.01 to 0.1, and rand(0,1) is a random number between 0 and 1. The chaotic value is the value of the nth iteration, and the chaotic sequence generated by the iteration is used as the fragmentation key; The time limit rule for the fragment encryption parameters is as follows: Each set of dynamic optical fragments is assigned a timestamp-based encryption key. The key validity period decreases with the trust level. The validity period of the core trust level key is T, the ordinary trust level key is T / 3, and the temporary trust level key is T / 10. T is the preset basic validity period.
4. The digital archive distribution method based on dynamic optical fragments according to claim 1, characterized in that, The process of constructing the node trust assessment model in step S3 is as follows: S31. Determine the set of evaluation indicators, including the identity authentication dimension. behavioral compliance dimension Security Status Dimension ,and + + =1; S32. Quantify the indicators of each dimension. The identity authentication dimension includes the number of authentication methods and the authentication pass rate. The behavior compliance dimension includes the number of historical violations and the compliance rate of file usage. The security status dimension includes the number of node vulnerabilities and the firewall status. S33. Use the analytic hierarchy process to determine the sub-weights of each indicator, and combine the fuzzy comprehensive evaluation method to score the quantified indicators and output a trust score of 0-100. S34. Set trust level thresholds: core trust level is a score ≥ 85, ordinary trust level is 60 ≤ score < 85, temporary trust level is 40 ≤ score < 60, nodes with a score < 40 are judged as untrusted nodes and are refused distribution.
5. The digital archive distribution method based on dynamic optical fragments according to claim 1, characterized in that, The process of constructing the encrypted optical transmission channel in step S5 is as follows: Using optical fiber as the transmission medium, an optical encryption module is added to the transmission link to modulate the polarization state and encrypt the optical signal of dynamic optical fragments. During transmission, the link optical power and polarization state changes are monitored in real time. If abnormal fluctuations are detected, the transmission is immediately interrupted and the abnormal node is marked.
6. A digital archive distribution system based on dynamic optical fragments, employing the digital archive distribution method based on dynamic optical fragments as described in any one of claims 1-5, characterized in that, The system includes: The document preprocessing module is used to standardize the format of the original digital documents, divide them into blocks, generate unique identifiers, and convert the data blocks into initial optical feature codes. The dynamic optical fragment generation module, connected to the archive preprocessing module, is used to decompose the initial optical feature encoding into multiple sets of labeled dynamic optical fragments based on the dynamic fragment generation rule base. The node trust assessment module is used to collect multi-dimensional data of the target distribution node and output the node trust level through the node trust assessment model. The distribution matching module is connected to the dynamic optical fragment generation module and the node trust assessment module, respectively, and is used to match the target node with the corresponding dynamic optical fragment combination and decryption permission according to the trust level. The optical transmission module, connected to the distribution and matching module, is used to construct an encrypted optical transmission channel and directionally distribute the matched dynamic optical fragments to the target node. The file restoration module is deployed on the target distribution node side. It is used to receive dynamic optical fragments and complete tag verification, fragment decryption, splicing and inverse conversion to restore the original digital file.
7. The digital archive distribution system based on dynamic optical fragments according to claim 6, characterized in that, The dynamic optical debris generation module includes: The rule management unit is used to maintain the dynamic fragment generation rule base and update rule parameters in real time; Fragmentation unit, used to perform fragmentation of the initial optical feature encoding based on the chaotic mapping algorithm; The tag encryption unit is used to add time-sensitive tags and node matching tags to the split dynamic optical fragments and generate encryption keys based on timestamps.
8. The digital archive distribution system based on dynamic optical fragments according to claim 6, characterized in that, The node trust assessment module includes: The data acquisition unit is used to collect node authentication information, historical behavior data, and security status data; The indicator quantification unit is used to standardize and quantify the collected data. The model calculation unit is used to calculate the node trust score and determine the trust level based on the analytic hierarchy process and fuzzy comprehensive evaluation method.
9. The digital archive distribution system based on dynamic optical fragments according to claim 6, characterized in that, The optical transmission module includes: An optical encryption unit is used to perform polarization state modulation and intensity encryption on the optical signals of dynamic optical fragments. The transmission monitoring unit is used to monitor the optical power, polarization state, and link connectivity of the transmission link in real time. The link control unit is used to interrupt transmission when an anomaly is detected and send an anomaly alarm message to the management terminal.
10. The digital archive distribution system based on dynamic optical fragments according to claim 6, characterized in that, The file restoration module includes: The fragment verification unit is used to verify the timeliness label, node matching label, and fragment integrity of the fragments. The decryption unit is used to invoke the corresponding algorithm to decrypt fragments based on decryption permissions. The splicing and restoration unit is used to splice the decrypted fragments into the initial optical feature code and then reverse convert it into the original digital file.