A dynamic level encryption data transmission method, device, medium and program product

By employing a dynamic-level encrypted data transmission method, the problems of latency and bandwidth pressure in large file transfers are solved, enabling flexible data encryption and verification, and improving the security and efficiency of data transmission.

CN122496218APending Publication Date: 2026-07-31INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2025-08-21
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies suffer from transmission delays and bandwidth pressures when transferring large files, making it difficult to meet the differentiated security needs of data with varying levels of sensitivity. Furthermore, the verification mechanisms are insufficient in detecting malicious tampering.

Method used

A dynamic-level encrypted data transmission method is adopted. The target hierarchical encryption algorithm is generated through the file preprocessing module, the data is processed in blocks and encrypted sub-blocks are generated, and the trusted verification module is used to decrypt and verify the data, and the current verification result is generated to determine that the transmission is complete.

Benefits of technology

It improves the security and efficiency of data transmission, reduces bandwidth pressure, and ensures the integrity and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122496218A_ABST
    Figure CN122496218A_ABST
Patent Text Reader

Abstract

This invention discloses a dynamic-level encrypted data transmission method, apparatus, medium, and program product, relating to the field of information security and applicable to the fintech sector. The method involves: acquiring the binary file of the data to be transmitted in real time through a file preprocessing module; determining the method using a hierarchical encryption algorithm to generate a target hierarchical encryption algorithm; acquiring and generating a target verification file based on file metadata; dividing the binary file of the data to be transmitted into blocks using a dynamic encryption module to obtain at least one sub-block of the binary file; and generating encrypted sub-blocks of the binary file based on a key positioning function and the target hierarchical encryption algorithm; receiving the target verification file through a trusted verification module at the receiving end, verifying it using a decryption verification algorithm, and generating the current verification result. This invention solves the problems of poor data transmission security, transmission latency, and high bandwidth pressure, ensuring data transmission security and improving data transmission efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security, and in particular to a dynamic-level encrypted data transmission method, apparatus, medium, and program product. Background Technology

[0002] In today's digital age, the security and efficiency of data transmission have become core requirements in critical sectors such as finance, healthcare, and government. While current mainstream solutions offer a degree of security through end-to-end encryption and chunked transmission technologies, they still face numerous challenges.

[0003] In the process of developing this invention, the inventors discovered the following shortcomings in existing technologies: Currently, overall encryption schemes exhibit significant transmission delays and bandwidth pressure when processing large files, especially under fluctuating network conditions; while traditional chunked transmission technologies, due to their use of static keys and uniform encryption strength, struggle to meet the diverse security needs of data with varying sensitivities. More importantly, existing verification mechanisms are significantly inadequate in detecting malicious tampering, posing a serious security risk. Summary of the Invention

[0004] This invention provides a dynamic-level encrypted data transmission method, apparatus, medium, and program product to ensure data transmission security and improve data transmission efficiency.

[0005] According to one aspect of the present invention, a dynamic-level encrypted data transmission method is provided, comprising:

[0006] The file preprocessing module acquires the binary file of the data to be transmitted in real time, and determines the method through a pre-set hierarchical encryption algorithm to generate the target hierarchical encryption algorithm.

[0007] The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module.

[0008] Obtain and generate a target check verification file based on the file metadata corresponding to the binary file of the data to be transmitted;

[0009] The dynamic encryption module divides the binary data file to be transmitted into blocks to obtain at least one sub-block of the binary data file to be transmitted. Based on the pre-set key positioning function and the target hierarchical encryption algorithm, each encrypted sub-block of the binary data file is generated.

[0010] The receiving end's trusted verification module receives the target check and verification file and each of the encrypted sub-blocks of the data binary file, and verifies them using a pre-set decryption and verification algorithm to generate a current verification result. This allows the system to determine whether the data binary file to be transmitted has been successfully transmitted based on the current verification result.

[0011] According to another aspect of the present invention, a dynamic-level encrypted data transmission apparatus is provided, comprising:

[0012] The target hierarchical encryption algorithm generation module is used to obtain the binary file of the data to be transmitted in real time through the file preprocessing module, and generate the target hierarchical encryption algorithm by determining the method through a pre-set hierarchical encryption algorithm.

[0013] The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module.

[0014] The target check and verification file generation module is used to obtain and generate a target check and verification file based on the file metadata corresponding to the binary file of the data to be transmitted;

[0015] The data binary file encryption sub-block generation module is used to divide the data binary file to be transmitted into blocks through the dynamic encryption module to obtain at least one data binary file sub-block to be transmitted, and generate each data binary file encryption sub-block according to the pre-set key positioning function and the target hierarchical encryption algorithm.

[0016] The current verification result generation module is used to receive the target check and verification file and each of the encrypted sub-blocks of the data binary file through the trusted verification module of the receiving end, and to verify them through a pre-set decryption and verification algorithm to generate a current verification result, so as to determine whether the data binary file to be transmitted has been transmitted completely based on the current verification result.

[0017] According to another aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the dynamic-level encrypted data transmission method described in any embodiment of the present invention.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the dynamic-level encrypted data transmission method according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the dynamic-level encrypted data transmission method described in any embodiment of the present invention.

[0020] The technical solution of this invention involves: acquiring the binary file of data to be transmitted in real time through a file preprocessing module; generating a target hierarchical encryption algorithm by determining a pre-set hierarchical encryption algorithm; acquiring and generating a target check / verification file based on the file metadata corresponding to the binary file of data to be transmitted; dividing the binary file of data to be transmitted into blocks through a dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted; generating encrypted sub-blocks of the binary file of data based on a pre-set key positioning function and the target hierarchical encryption algorithm; receiving the target check / verification file and each encrypted sub-block of the binary file of data through a trusted verification module at the receiving end; verifying the encrypted sub-blocks of the binary file of data using a pre-set decryption verification algorithm; generating a current verification result to determine whether the binary file of data to be transmitted has been successfully transmitted based on the current verification result. This solves the problems of poor data transmission security, transmission delay, and high bandwidth pressure in the prior art, ensuring the security of data transmission, improving data transmission efficiency, and reducing bandwidth pressure.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of a dynamic-level encrypted data transmission method provided in Embodiment 1 of the present invention;

[0024] Figure 2 This is a detailed flowchart of a dynamic-level encrypted data transmission method provided according to Embodiment 2 of the present invention;

[0025] Figure 3 This is a schematic diagram of the structure of a dynamic-level encrypted data transmission device according to Embodiment 3 of the present invention;

[0026] Figure 4This is a schematic diagram of the structure of an electronic device provided according to Embodiment 4 of the present invention. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "target," "current," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0029] It is worth noting that the information collected in the technical solution of this application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse; if the user chooses to refuse, the process will proceed to the expert decision-making process.

[0030] Example 1

[0031] Figure 1 This is a flowchart illustrating a dynamic-level encrypted data transmission method according to Embodiment 1 of the present invention. This embodiment is applicable to situations where data is encrypted during transmission. The method can be executed by a dynamic-level encrypted data transmission device, which can be implemented in hardware and / or software. This invention relates to the field of information security and can be applied to the field of financial technology.

[0032] Correspondingly, such as Figure 1 As shown, the method includes:

[0033] S110. The binary file of the data to be transmitted is obtained in real time through the file preprocessing module, and the method is determined by the pre-set hierarchical encryption algorithm to generate the target hierarchical encryption algorithm.

[0034] The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module.

[0035] In this embodiment, the dynamic-level encrypted data transmission system may include a file preprocessing module, a dynamic encryption module, and a trusted verification module. The file preprocessing module and the dynamic encryption module are used for data processing operations at the sending end before data transmission. The trusted verification module is used to verify the received data at the receiving end after data transmission. This dynamic-level encrypted data transmission system is suitable for applications in the financial transaction data field, or for application scenarios such as medical imaging where security and transmission performance requirements differ.

[0036] In this embodiment, data to be transmitted can be exported from the system, and the data can be converted into binary to generate a binary file of the data to be transmitted. The method for determining the hierarchical encryption algorithm can be to apply different levels of encryption algorithms to data with different levels of sensitivity.

[0037] Optionally, the step of acquiring the binary file of the data to be transmitted in real time through the file preprocessing module and generating the target hierarchical encryption algorithm through a pre-set hierarchical encryption algorithm determination method includes: acquiring the binary file of the data to be transmitted in real time through the file preprocessing module and determining the target positioning sensitivity through the sensitivity positioning sub-method in the hierarchical encryption algorithm determination method; determining the target hierarchical encryption function based on the target positioning sensitivity through a pre-set hierarchical encryption function determination sub-method; and generating the target hierarchical encryption algorithm and the target key length corresponding to the target hierarchical encryption algorithm based on the target hierarchical encryption function.

[0038] In this embodiment, different target location sensitivity levels correspond to different target hierarchical encryption functions, and therefore the target hierarchical encryption algorithms and target key lengths are also different.

[0039] For example, assuming the target location sensitivity can be m = {1, 2, 3}, the target hierarchical encryption function can be set to g(m), and a symmetric encryption algorithm and corresponding key length that conform to the standards of the State Cryptography Administration can be selected.

[0040] Specifically, when m=1 (the binary file to be transmitted contains ordinary data), a 128-bit symmetric encryption algorithm can be used. When m=2 (the binary file to be transmitted contains important data), a 192-bit symmetric encryption algorithm can be used; and when m=3 (the binary file to be transmitted contains core data), a 256-bit symmetric encryption algorithm can be used.

[0041] In addition, for key management, different key groups of different lengths can be pre-stored in the key store, and the target hierarchical encryption algorithm and the target key length corresponding to the target hierarchical encryption algorithm can be indexed by the m value.

[0042] The advantage of this setup is that by using a hierarchical encryption algorithm to determine the target location sensitivity, target hierarchical encryption function, target hierarchical encryption algorithm, and target key length corresponding to the binary file to be transmitted, different levels of encryption operations can be performed on the binary file to be transmitted, ensuring the flexibility of data transmission, saving bandwidth, and reducing the pressure of data transmission.

[0043] S120. Obtain and generate a target check verification file based on the file metadata corresponding to the binary file of the data to be transmitted.

[0044] The target check and verification file may include the size of the binary data file to be transmitted, the number of lines in the binary data file, and the hash value of the binary data file.

[0045] S130. The dynamic encryption module divides the binary data file to be transmitted into blocks to obtain at least one sub-block of the binary data file to be transmitted. Based on the pre-set key positioning function and the target hierarchical encryption algorithm, each encrypted sub-block of the binary data file is generated.

[0046] Optionally, the step of dividing the binary file of data to be transmitted into blocks by the dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted includes: determining the current block size by a pre-set data packet segmentation strategy; dividing the binary file of data to be transmitted into blocks by the dynamic encryption module according to the current block size and the size of the binary file of data to be transmitted to obtain at least one sub-block of the binary file of data to be transmitted; wherein each sub-block of the binary file of data to be transmitted contains a corresponding unique sequence identifier packet header; wherein the unique sequence identifier packet header includes at least one of the following: file sub-block sequence number, total number of file sub-blocks, original file of file sub-block, and file sub-block timestamp.

[0047] For example, suppose the current block size is BlockSize, and the size of the binary file to be transmitted is h. The binary file to be transmitted can be divided into blocks using a dynamic encryption module, resulting in a number of sub-blocks in the binary file.

[0048] Furthermore, a unique sequence identifier header needs to be added to each sub-block of the binary file to be transmitted. The unique sequence identifier header is composed of the sub-block sequence number, the total number of sub-blocks, the original file of the sub-block, and the timestamp of the sub-block.

[0049] The advantage of this setup is that by dividing the binary file of data to be transmitted into blocks and adding a unique sequence identifier packet header to each block, the operation of splitting and transmitting the file into blocks can be realized. The blocks can be identified through the unique sequence identifier packet header, which improves the efficiency and flexibility of data transmission.

[0050] Optionally, the step of generating encrypted sub-blocks of each data binary file according to a pre-set key positioning function and the target hierarchical encryption algorithm includes: determining the starting key position according to the key positioning function and generating keys for each current file sub-block sequentially according to the target key length; sequentially obtaining a current file sub-block key and encrypting the corresponding data binary file sub-blocks to be transmitted using the target hierarchical encryption algorithm to generate encrypted sub-blocks of each data binary file.

[0051] In this embodiment, the starting key position can be determined by querying key groups of different lengths pre-stored in the key library using a key location function. After determining the starting key position, the current file sub-block key corresponding to each binary file sub-block of data to be transmitted can be determined sequentially based on the target key length.

[0052] Furthermore, based on the target hierarchical encryption algorithm, the corresponding binary data file sub-blocks to be transmitted are encrypted using the current file sub-block key, resulting in encrypted binary data file sub-blocks.

[0053] The advantage of this setup is that by using a key location function to determine the starting key position, the keys for each current file sub-block can be further determined, thus generating encrypted sub-blocks of the data binary file. This block-based encryption operation ensures both the security and flexibility of data transmission.

[0054] Optionally, after sequentially obtaining a current file sub-block key and encrypting each corresponding data binary file sub-block to be transmitted using the target hierarchical encryption algorithm to generate encrypted sub-blocks of each data binary file, the method further includes: transmitting the target check and verification file to the receiving end of the dynamic-level encrypted data transmission system through the dynamic encryption module; and transmitting each encrypted sub-block of the data binary file to the receiving end of the dynamic-level encrypted data transmission system in sequence through the dynamic encryption module.

[0055] In this embodiment, after obtaining the encrypted sub-blocks of each data binary file, each encrypted sub-block needs to be sent to the receiving end. Specifically, the target verification file needs to be sent first, and then the encrypted sub-blocks of each data binary file are transmitted sequentially to the receiving end of the dynamic-level encrypted data transmission system.

[0056] The advantage of this setup is that by transmitting the target check / verification file and the encrypted sub-blocks of each data binary file to the receiving end of the dynamic-level encrypted data transmission system, encrypted data transmission can be achieved, and verification can also be performed based on the target check / verification file, ensuring the reliability and security of data transmission.

[0057] S140. The target check and verification file and each of the encrypted sub-blocks of the data binary file are received by the trusted verification module of the receiving end, and the verification is performed by a pre-set decryption and verification algorithm to generate a current verification result, so as to determine whether the data binary file to be transmitted has been transmitted completely based on the current verification result.

[0058] In this embodiment, after the receiving end receives the target verification file and each encrypted sub-block of the data binary file, it first needs to determine the timestamp of the file sub-blocks, then perform file sub-block decryption and file reassembly operations, and finally perform verification operations on the entire file. Furthermore, it can determine whether the transmission of the data binary file to be transmitted has been completed based on the current verification results.

[0059] The technical solution of this invention involves: acquiring the binary file of data to be transmitted in real time through a file preprocessing module; generating a target hierarchical encryption algorithm by determining a pre-set hierarchical encryption algorithm; acquiring and generating a target check / verification file based on the file metadata corresponding to the binary file of data to be transmitted; dividing the binary file of data to be transmitted into blocks through a dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted; generating encrypted sub-blocks of the binary file of data based on a pre-set key positioning function and the target hierarchical encryption algorithm; receiving the target check / verification file and each encrypted sub-block of the binary file of data through a trusted verification module at the receiving end; verifying the encrypted sub-blocks of the binary file of data using a pre-set decryption verification algorithm; generating a current verification result to determine whether the binary file of data to be transmitted has been successfully transmitted based on the current verification result. This solves the problems of poor data transmission security, transmission delay, and high bandwidth pressure in the prior art, ensuring the security of data transmission, improving data transmission efficiency, and reducing bandwidth pressure.

[0060] Example 2

[0061] Figure 2 This is a detailed flowchart of a dynamic-level encrypted data transmission method according to Embodiment 2 of the present invention. This embodiment is a refinement based on the above embodiments. In this embodiment, the target check and verification file and each of the encrypted sub-blocks of the data binary file are received by the trusted verification module of the receiving end, and verified by a pre-set decryption and verification algorithm to generate the current verification result for further refinement.

[0062] S210. The binary file of the data to be transmitted is obtained in real time through the file preprocessing module, and the method is determined by the pre-set hierarchical encryption algorithm to generate the target hierarchical encryption algorithm.

[0063] S220. Obtain and generate a target check verification file based on the file metadata corresponding to the binary file of the data to be transmitted.

[0064] S230. The dynamic encryption module divides the binary data file to be transmitted into blocks to obtain at least one sub-block of the binary data file to be transmitted. Based on the pre-set key positioning function and the target hierarchical encryption algorithm, each encrypted sub-block of the binary data file is generated.

[0065] S240. The target check and verification file and each of the data binary file encryption sub-blocks are received through the trusted verification module of the receiving end.

[0066] S250. Obtain the file sub-block timestamp in the unique sequence identifier packet header corresponding to each encrypted sub-block of the data binary file, and obtain the preset file sub-block timestamp threshold range.

[0067] The file sub-block timestamp can be used to count the transmission time of each encrypted sub-block in the data binary file. The file sub-block timestamp threshold range can be set to the required transmission time of the file sub-block.

[0068] S260. Determine whether the timestamp of each file sub-block falls within the threshold range of the file sub-block timestamp. If not, proceed to S270; if yes, proceed to S280.

[0069] S270. Discard the encrypted sub-block of the data binary file.

[0070] In this embodiment, assuming that there are cases where the timestamps of file sub-blocks do not fall within the threshold range of file sub-block timestamps, the encrypted sub-blocks of the data binary file can be discarded to prevent replay attacks.

[0071] S280. Based on the size of the binary data file to be transmitted in the target check and verification file, and in conjunction with the key positioning function, determine the starting decryption key position and the decryption key corresponding to each encrypted sub-block of the data binary file; use the decryption key to decrypt each encrypted sub-block of the data binary file to obtain each decrypted sub-block of the data binary file, and verify each decrypted sub-block of the data binary file through the decryption verification algorithm to generate the current verification result.

[0072] Continuing the previous example, assuming the file sub-block timestamps fall within the file sub-block timestamp threshold range, the starting decryption key position can be calculated based on the size of the binary data file to be transmitted in the target check and verification file, combined with the key positioning function. Furthermore, the encryption algorithm is determined based on the target positioning sensitivity and the target hierarchical encryption function. Correspondingly, the corresponding decryption key can be determined based on the starting decryption key position and the unique sequence identifier packet header of each encrypted sub-block of the data binary file.

[0073] Furthermore, using the decryption key and the corresponding decryption algorithm, each encrypted sub-block of the data binary file is decrypted to obtain each decrypted sub-block of the data binary file.

[0074] Optionally, the step of verifying each decrypted sub-block of the data binary file using the decryption verification algorithm to generate a current verification result includes: obtaining the file sub-block sequence number in the unique sequence identifier packet header corresponding to each decrypted sub-block of the data binary file; determining whether each file sub-block sequence number has been received completely; if so, combining each decrypted sub-block of the data binary file to generate a target transmission completed data binary file; obtaining the size of the data binary file to be transmitted, the number of lines in the data binary file, and the hash value of the data binary file in the target check and verification file; and using the decryption verification algorithm, determining whether the size of the target transmission completed binary file corresponding to the target transmission completed data binary file is consistent with the size of the data binary file to be transmitted; if so... If the target completed data binary file size is inconsistent with the data binary file size to be transmitted, or if the target completed data binary file size is inconsistent with the data binary file size, or if the target completed data binary file hash value is inconsistent with the data binary file hash value, then a current verification data transmission success result is generated. If any of the following conditions are met: the target completed data binary file size is inconsistent with the data binary file size to be transmitted, or the target completed data binary file size is inconsistent with the data binary file size, or the target completed data binary file hash value is inconsistent with the data binary file hash value, then a current verification data transmission failure result is generated.

[0075] In this embodiment, after obtaining each of the data binary file decryption sub-blocks, it is necessary to determine whether all data binary file decryption sub-blocks have been received based on the file sub-block sequence number. If all have been received, the target transmission completed data binary file can be obtained.

[0076] Furthermore, a decryption verification algorithm is needed to determine whether the size, number of lines, and hash value of the target completed data binary file are the same as those of the data binary file to be transmitted in the target verification file. This will allow us to determine whether the current verification data transmission was successful or failed.

[0077] The advantages of this setup are: it determines whether all data binary file decryption sub-blocks have been received by judging the file sub-block sequence number; and it uses a decryption verification algorithm to determine whether the target data binary file has been successfully transmitted. This ensures the integrity, reliability, and security of data transmission and improves the flexibility of data transmission.

[0078] The technical solution of this invention, after obtaining the decryption sub-blocks of each data binary file, needs to determine whether all data binary file decryption sub-blocks have been received based on the file sub-block sequence number; it needs to use a decryption verification algorithm to determine whether the size, number of lines, and hash value of the target completed data binary file are the same as those of the data binary file to be transmitted in the target verification file, respectively, thereby obtaining the result of successful or failed data transmission verification. This ensures the integrity, reliability, and security of data transmission and improves the flexibility of data transmission.

[0079] Example 3

[0080] Figure 3 This is a schematic diagram of a dynamic-level encrypted data transmission device provided in Embodiment 3 of the present invention. The dynamic-level encrypted data transmission device provided in this embodiment can be implemented by software and / or hardware, and can be configured in a terminal device or server to implement a dynamic-level encrypted data transmission method according to the present invention. Figure 3 As shown, the device includes: a target hierarchical encryption algorithm generation module 310, a target check and verification file generation module 320, a data binary file encryption sub-block generation module 330, and a current verification result generation module 340.

[0081] The target hierarchical encryption algorithm generation module 310 is used to obtain the binary file of the data to be transmitted in real time through the file preprocessing module, and generate the target hierarchical encryption algorithm by determining the method through a pre-set hierarchical encryption algorithm.

[0082] The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module.

[0083] The target check and verification file generation module 320 is used to obtain and generate a target check and verification file based on the file metadata corresponding to the binary file of the data to be transmitted;

[0084] The data binary file encryption sub-block generation module 330 is used to divide the data binary file to be transmitted into blocks through the dynamic encryption module to obtain at least one data binary file sub-block to be transmitted, and generate each data binary file encryption sub-block according to the pre-set key positioning function and the target hierarchical encryption algorithm.

[0085] The current verification result generation module 340 is used to receive the target check and verification file and each of the encrypted sub-blocks of the data binary file through the trusted verification module of the receiving end, and to verify them through a pre-set decryption and verification algorithm to generate a current verification result, so as to determine whether the data binary file to be transmitted has been transmitted completely based on the current verification result.

[0086] The technical solution of this invention involves: acquiring the binary file of data to be transmitted in real time through a file preprocessing module; generating a target hierarchical encryption algorithm by determining a pre-set hierarchical encryption algorithm; acquiring and generating a target check / verification file based on the file metadata corresponding to the binary file of data to be transmitted; dividing the binary file of data to be transmitted into blocks through a dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted; generating encrypted sub-blocks of the binary file of data based on a pre-set key positioning function and the target hierarchical encryption algorithm; receiving the target check / verification file and each encrypted sub-block of the binary file of data through a trusted verification module at the receiving end; verifying the encrypted sub-blocks of the binary file of data using a pre-set decryption verification algorithm; generating a current verification result to determine whether the binary file of data to be transmitted has been successfully transmitted based on the current verification result. This solves the problems of poor data transmission security, transmission delay, and high bandwidth pressure in the prior art, ensuring the security of data transmission, improving data transmission efficiency, and reducing bandwidth pressure.

[0087] Based on the above embodiments, the target hierarchical encryption algorithm generation module 310 can be specifically used to: obtain the binary file of the data to be transmitted in real time through the file preprocessing module, and determine the target positioning sensitivity through the sensitivity positioning sub-method in the hierarchical encryption algorithm determination method; determine the target hierarchical encryption function according to the target positioning sensitivity through the pre-set hierarchical encryption function determination sub-method; and generate the target hierarchical encryption algorithm and the target key length corresponding to the target hierarchical encryption algorithm according to the target hierarchical encryption function.

[0088] Based on the above embodiments, the target check and verification file includes the size of the binary data file to be transmitted, the number of lines in the binary data file, and the hash value of the binary data file.

[0089] Based on the above embodiments, the data binary file encryption sub-block generation module 330 can be specifically used to: determine the current block size through a pre-set data packet segmentation strategy; and, according to the current block size and the size of the data binary file to be transmitted, perform block processing on the data binary file to be transmitted through a dynamic encryption module to obtain at least one data binary file sub-block to be transmitted; wherein each data binary file sub-block to be transmitted contains a corresponding unique sequence identifier packet header; wherein the unique sequence identifier packet header includes at least one of the following: file sub-block sequence number, total number of file sub-blocks, original file of the file sub-block, and file sub-block timestamp.

[0090] Based on the above embodiments, the data binary file encrypted sub-block generation module 330 can also be specifically used to: determine the starting key position according to the key positioning function, and generate each current file sub-block key in sequence according to the target key length; obtain a current file sub-block key in sequence, and encrypt the corresponding data binary file sub-block to be transmitted according to the target hierarchical encryption algorithm to generate each data binary file encrypted sub-block.

[0091] Based on the above embodiments, a transmission module is also included, which can be specifically used to: after sequentially obtaining a current file sub-block key, encrypting each corresponding data binary file sub-block to be transmitted using the target hierarchical encryption algorithm to generate encrypted sub-blocks of each data binary file, transmit the target check and verification file to the receiving end of the dynamic-level encrypted data transmission system through the dynamic encryption module; and transmit each encrypted sub-block of the data binary file to the receiving end of the dynamic-level encrypted data transmission system in sequence through the dynamic encryption module.

[0092] Based on the above embodiments, the current verification result generation module 340 can be specifically used to: receive the target check and verification file and each of the encrypted sub-blocks of the data binary file through the trusted verification module of the receiving end; obtain the file sub-block timestamp in the unique sequence identifier packet header corresponding to each encrypted sub-block of the data binary file, and obtain a preset file sub-block timestamp threshold range; determine whether each file sub-block timestamp falls within the file sub-block timestamp threshold range respectively; if not, discard the encrypted sub-block of the data binary file; if so, determine the starting decryption key position and the decryption key corresponding to each encrypted sub-block of the data binary file according to the size of the data binary file to be transmitted in the target check and verification file, combined with the key positioning function; use the decryption key to decrypt each encrypted sub-block of the data binary file respectively to obtain each decrypted sub-block of the data binary file, and verify each decrypted sub-block of the data binary file respectively through the decryption verification algorithm to generate the current verification result.

[0093] Based on the above embodiments, the current verification result generation module 340 can also be specifically used for: obtaining the file sub-block sequence number in the unique sequence identifier packet header corresponding to each of the data binary file decryption sub-blocks; determining whether each of the file sub-block sequence numbers has been received completely; if so, combining each of the data binary file decryption sub-blocks to generate a target transmission completed data binary file; obtaining the size of the data binary file to be transmitted, the number of lines in the data binary file, and the hash value of the data binary file in the target check and verification file; and determining, through the decryption and verification algorithm, whether the size of the target transmission completed binary file corresponding to the target transmission completed data binary file is consistent with the size of the data binary file to be transmitted; if so, determining whether the target transmission completed data binary file size is consistent with the size of the data binary file to be transmitted. The system checks whether the number of lines in the target completed data binary file corresponding to the target completed data binary file is consistent with the number of lines in the data binary file. If they are consistent, it checks whether the hash value of the target completed data binary file corresponding to the target completed data binary file is the same as the hash value of the data binary file. If they are the same, it generates a current verification data transmission success result. If any of the following conditions are met: the size of the target completed data binary file is inconsistent with the size of the data binary file to be transmitted, or the number of lines in the target completed data binary file is inconsistent with the number of lines in the data binary file, or the hash value of the target completed data binary file is different from the hash value of the data binary file, it generates a current verification data transmission failure result.

[0094] The dynamic-level encrypted data transmission device provided in the embodiments of the present invention can execute the dynamic-level encrypted data transmission method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0095] Example 4

[0096] Figure 4 A schematic diagram of an electronic device 10, which can be used to implement Embodiment 4 of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0097] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0098] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0099] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as dynamic-level encrypted data transmission methods.

[0100] In some embodiments, the dynamic-level encrypted data transmission method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the dynamic-level encrypted data transmission method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the dynamic-level encrypted data transmission method by any other suitable means (e.g., by means of firmware).

[0101] The method includes: acquiring the binary file of data to be transmitted in real time through a file preprocessing module, and generating a target hierarchical encryption algorithm by determining the method through a pre-set hierarchical encryption algorithm; wherein, the dynamic-level encrypted data transmission system is constructed based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module; acquiring and generating a target check and verification file based on file metadata corresponding to the binary file of data to be transmitted; performing block processing on the binary file of data to be transmitted through the dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted, and generating each encrypted sub-block of the binary file of data based on a pre-set key positioning function and the target hierarchical encryption algorithm; receiving the target check and verification file and each encrypted sub-block of the binary file of data through the trusted verification module of the receiving end, and verifying it through a pre-set decryption verification algorithm to generate a current verification result, so as to determine whether the binary file of data to be transmitted has been transmitted completely based on the current verification result.

[0102] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0103] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0104] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0105] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0106] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0107] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0108] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0109] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

[0110] Example 5

[0111] Embodiment 5 of the present invention also provides a computer-readable storage medium, wherein the computer-readable instructions, when executed by a computer processor, are used to execute a dynamic-level encrypted data transmission method. The method includes: acquiring a binary file of data to be transmitted in real time through a file preprocessing module, and generating a target hierarchical encryption algorithm by determining a method using a pre-set hierarchical encryption algorithm; wherein the dynamic-level encrypted data transmission system is constructed based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module; acquiring and generating a target check / verification file based on file metadata corresponding to the binary file of data to be transmitted; performing block processing on the binary file of data to be transmitted through the dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted, and generating each encrypted sub-block of the binary file of data according to a pre-set key positioning function and the target hierarchical encryption algorithm; receiving the target check / verification file and each encrypted sub-block of the binary file of data through a trusted verification module at the receiving end, and verifying it using a pre-set decryption verification algorithm to generate a current verification result, so as to determine whether the transmission of the binary file of data to be transmitted is complete based on the current verification result.

[0112] Of course, the computer-executable instructions provided in the embodiments of the present invention, which include a computer-readable storage medium, are not limited to the method operations described above, but can also perform related operations in the dynamic-level encrypted data transmission provided in any embodiment of the present invention.

[0113] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0114] It is worth noting that in the above-described embodiments of dynamic-level encrypted data transmission, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.

[0115] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method of dynamic key encryption data transmission, characterized by, include: The file preprocessing module acquires the binary file of the data to be transmitted in real time, and determines the method through a pre-set hierarchical encryption algorithm to generate the target hierarchical encryption algorithm. The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module. Obtain and generate a target check verification file based on the file metadata corresponding to the binary file of the data to be transmitted; The dynamic encryption module divides the binary data file to be transmitted into blocks to obtain at least one sub-block of the binary data file to be transmitted. Based on the pre-set key positioning function and the target hierarchical encryption algorithm, each encrypted sub-block of the binary data file is generated. The receiving end's trusted verification module receives the target check and verification file and each of the encrypted sub-blocks of the data binary file, and verifies them using a pre-set decryption and verification algorithm to generate a current verification result. This allows the system to determine whether the data binary file to be transmitted has been successfully transmitted based on the current verification result.

2. The method according to claim 1, characterized in that, The process of acquiring the binary file of the data to be transmitted in real time through the file preprocessing module and generating the target hierarchical encryption algorithm through a pre-set hierarchical encryption algorithm determination method includes: The binary file of the data to be transmitted is obtained in real time through the file preprocessing module, and the sensitivity of the target location is determined by the sensitivity positioning sub-method in the hierarchical encryption algorithm method. Based on the target location sensitivity, the target hierarchical encryption function is determined by a pre-set hierarchical encryption function determination sub-method. Based on the target hierarchical encryption function, a target hierarchical encryption algorithm and a target key length corresponding to the target hierarchical encryption algorithm are generated.

3. The method according to claim 2, characterized in that, The target check and verification file includes the size of the binary data file to be transmitted, the number of lines in the binary data file, and the hash value of the binary data file. The step of dividing the binary file of data to be transmitted into blocks using the dynamic encryption module to obtain at least one sub-block of the binary file of data to be transmitted includes: The current block size is determined by a pre-set packet segmentation strategy; Based on the current block size and the size of the binary file to be transmitted, the binary file to be transmitted is divided into blocks by the dynamic encryption module to obtain at least one sub-block of the binary file to be transmitted. Each sub-block of the binary file containing the data to be transmitted contains a corresponding unique sequence identifier packet header; The unique sequence identifier header includes at least one of the following: file sub-block number, total number of file sub-blocks, original file of the file sub-block, and file sub-block timestamp.

4. The method according to claim 3, characterized in that, The step of generating encrypted sub-blocks of each data binary file based on a pre-set key positioning function and the target hierarchical encryption algorithm includes: Based on the key positioning function, the starting key position is determined, and combined with the target key length, the keys for each current file sub-block are generated sequentially. The key of a current file sub-block is obtained in sequence, and the corresponding data binary file sub-blocks to be transmitted are encrypted using the target hierarchical encryption algorithm to generate encrypted sub-blocks of each data binary file.

5. The method according to claim 4, characterized in that, After sequentially obtaining a current file sub-block key and encrypting each corresponding data binary file sub-block to be transmitted using the target hierarchical encryption algorithm to generate encrypted sub-blocks of each data binary file, the process further includes: The target verification file is transmitted to the receiving end of the dynamic encryption data transmission system through the dynamic encryption module. The dynamic encryption module transmits each encrypted sub-block of the binary data file sequentially to the receiving end of the dynamic-level encrypted data transmission system.

6. The method according to claim 5, characterized in that, The trusted verification module at the receiving end receives the target check and verification file and each of the encrypted sub-blocks of the data binary file, and verifies them using a pre-set decryption and verification algorithm to generate the current verification result, including: The target verification file and each of the data binary file encryption sub-blocks are received by the trusted verification module at the receiving end. Obtain the file sub-block timestamp from the unique sequence identifier packet header corresponding to each encrypted sub-block of the data binary file, and obtain the preset file sub-block timestamp threshold range; Determine whether the timestamp of each file sub-block falls within the threshold range of the file sub-block timestamp. If not, discard the encrypted sub-block of the data binary file. If so, based on the size of the binary data file to be transmitted in the target check and verification file, and in conjunction with the key positioning function, determine the starting decryption key position and the decryption key corresponding to each encrypted sub-block of the data binary file; use the decryption key to decrypt each encrypted sub-block of the data binary file to obtain each decrypted sub-block of the data binary file, and verify each decrypted sub-block of the data binary file through the decryption verification algorithm to generate the current verification result.

7. The method according to claim 6, characterized in that, The process of verifying each decrypted sub-block of the data binary file using the decryption verification algorithm to generate the current verification result includes: Obtain the file sub-block sequence number from the unique sequence identifier packet header corresponding to each decrypted sub-block of the data binary file; Determine whether the sequence number of each file sub-block has been received. If so, combine the decrypted sub-blocks of each data binary file to generate the target transmission completed data binary file. Obtain the size of the binary data file to be transmitted, the number of lines in the binary data file, and the hash value of the binary data file from the target check and verification file; The decryption verification algorithm determines whether the size of the target completed data binary file is consistent with the size of the data binary file to be transmitted. If so, it determines whether the number of lines in the target completed data binary file is consistent with the number of lines in the data binary file. If they are consistent, it determines whether the hash value of the target completed data binary file is the same as the hash value of the data binary file. If they are the same, a verification result for successful data transmission is generated. If any of the following conditions are met: the size of the target completed binary file is inconsistent with the size of the data binary file to be transmitted, or the number of lines in the target completed binary file is consistent with or inconsistent with the number of lines in the data binary file, or the hash value of the target completed binary file is different from the hash value of the data binary file, then a current verification data transmission failure result is generated.

8. A dynamic-level encrypted data transmission device, characterized in that, include: The target hierarchical encryption algorithm generation module is used to obtain the binary file of the data to be transmitted in real time through the file preprocessing module, and generate the target hierarchical encryption algorithm by determining the method through a pre-set hierarchical encryption algorithm. The dynamic-level encrypted data transmission system is built based on a trusted platform control module; the dynamic-level encrypted data transmission system includes a file preprocessing module, a dynamic encryption module, and a trusted verification module. The target check and verification file generation module is used to obtain and generate a target check and verification file based on the file metadata corresponding to the binary file of the data to be transmitted; The data binary file encryption sub-block generation module is used to divide the data binary file to be transmitted into blocks through the dynamic encryption module to obtain at least one data binary file sub-block to be transmitted, and generate each data binary file encryption sub-block according to the pre-set key positioning function and the target hierarchical encryption algorithm. The current verification result generation module is used to receive the target check and verification file and each of the encrypted sub-blocks of the data binary file through the trusted verification module of the receiving end, and to verify them through a pre-set decryption and verification algorithm to generate a current verification result, so as to determine whether the data binary file to be transmitted has been transmitted completely based on the current verification result.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute a dynamic-level encrypted data transmission method as described in any one of claims 1-7.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements a dynamic-level encrypted data transmission method according to any one of claims 1-7.