Data security and intelligent encryption transmission method of multi-scene fusion

CN122764489APending Publication Date: 2026-09-15SHANGHAI YUZHAN COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611038097.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-13
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

[0010]针对现有技术存在的不足,本发明为解决现有技术中数据加密传输方案场景适应性差、加密策略智能化程度不足、身份认证与加密流程割裂、缺乏多层级协同加密体系以及缺少闭环优化机制等技术问题,本发明提供一种多场景融合的数据安全与智能加密传输方法、系统及存储介质

Benefits of technology

多场景融合感知与自适应能力。本发明通过多维度场景数据的实时采集与多模态特征融合,能够精准感知当前传输场景的安全需求和资源约束,并据此动态适配加密强度、算法选择和认证策略,实现了真正的场景自适应安全传输,克服了传统方法场景僵化的缺陷。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764489A_ABST
    Figure CN122764489A_ABST
Patent Text Reader

Abstract

The application discloses a multi-scene fusion data security and intelligent encryption transmission method and system and a medium. The method comprises the following steps: collecting multi-dimensional scene data in real time and generating a fusion scene feature vector; identifying a scene type based on a scene classifier and dynamically matching a multi-factor fusion authentication strategy; inputting the fusion feature, scene identifier and authentication credential into an encryption decision network based on deep reinforcement learning to output an optimal encryption scheme parameter set; performing multi-level hybrid encryption including data fragmentation, differential privacy, symmetric encryption, asymmetric packaging and homomorphic encryption; performing intelligent transmission scheduling and chain hash integrity binding; performing adaptive decryption verification at the receiving end; performing full-process security auditing and feeding back to the encryption decision network for online optimization. The application realizes scene-adaptive intelligent encryption decision, multi-level hybrid encryption and closed-loop strategy optimization, and significantly improves the security, efficiency and computability of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security transmission technology, and in particular to a multi-scenario integrated data security and intelligent encrypted transmission method. Specifically, it relates to a multi-scenario integrated data security and intelligent encrypted transmission method, system, and storage medium. Background Technology

[0002] With the rapid development of information technology and the deepening of digital transformation, data transmission security has become a core issue of great concern to all industries. From financial transactions, healthcare, and IoT communications to cloud computing services and remote work, massive amounts of data circulate frequently on networks. Data leaks, tampering, and theft occur frequently, posing serious threats to personal privacy, corporate interests, and even national security.

[0003] Traditional data encryption transmission technologies primarily employ static and fixed security strategies. Examples include channel encryption based on SSL / TLS protocols, virtual private network (VPN) transmission based on IPSec, and combinations of various symmetric / asymmetric encryption algorithms. While these technologies can provide a certain level of security in specific scenarios, they generally suffer from the following drawbacks: First, encryption strategies are rigid and lack scenario adaptability. Existing encrypted transmission schemes typically use the same or similar encryption strength and algorithm selection for all data, failing to provide differentiated protection based on the actual needs of different transmission scenarios. In low-risk scenarios, over-encryption causes unnecessary computational overhead and transmission delays; in high-risk scenarios, insufficient encryption strength makes it difficult to resist targeted attacks.

[0004] Second, the authentication mechanism is disconnected from the encryption process. Existing authentication methods often treat it as a separate step before data transmission, failing to deeply integrate the authentication result with the encryption process. This leaves authenticated data vulnerable to tampering or man-in-the-middle attacks. More importantly, existing solutions lack a dynamic authentication strength adjustment mechanism based on real-time risk assessment. Once set, authentication strategies remain fixed and cannot adapt to dynamically changing security environments.

[0005] Third, the selection of encryption schemes relies on preset rules, lacking sufficient intelligence. Although some research has attempted to dynamically select encryption algorithms based on network conditions—such as calculating scores for available encryption algorithms based on current network conditions and selecting the highest-scoring target encryption algorithm; or dynamically generating encryption configurations based on context-aware collection of external environmental indicators and device computing resource usage—the decision-making mechanisms employed by these schemes remain at the level of rule-based or simple scoring models. They cannot deeply perceive and make intelligent decisions regarding complex and ever-changing transmission environments, and lack the ability to comprehensively weigh different security performance objectives.

[0006] Fourth, there is a lack of multi-level, multi-layered, integrated encryption execution systems. Existing solutions often employ a limited selection of encryption layers, lacking a multi-layered collaborative execution framework that incorporates data sharding, symmetric encryption, asymmetric encapsulation, and homomorphic encryption. This makes it difficult to achieve a balance between security, efficiency, and computability. Especially in scenarios requiring multi-party data aggregation and computation (such as federated learning and multi-party secure computation), traditional encryption methods prevent effective computation of data in ciphertext form, forcing repeated decryption and increasing security risks.

[0007] Fifth, there is a lack of a closed-loop security audit and policy feedback mechanism. Existing technical solutions end after data transmission is completed, failing to form a closed loop from encryption execution to security auditing and policy optimization. This prevents encryption policies from learning from and improving upon historical transmission experience, making it difficult to continuously improve the system's security protection capabilities.

[0008] Furthermore, with the increasing complexity of network environments and the diversification of application scenarios, a single data security transmission solution is no longer sufficient to simultaneously meet the diverse needs of various scenarios such as finance, healthcare, IoT, and cloud computing for security, real-time performance, efficiency, and auditability. For example, financial transaction scenarios have extremely high requirements for data confidentiality and integrity but tolerate a certain degree of latency; IoT device communication scenarios have stringent requirements for energy consumption and real-time performance but relatively low security levels; while healthcare data exchange scenarios need to simultaneously meet multiple requirements such as privacy protection, compliance traceability, and encrypted domain computation.

[0009] Therefore, there is an urgent need for a data security transmission method that can adaptively switch between multiple scenarios, has intelligent decision-making capabilities, adopts multi-level fusion encryption, and has a built-in security audit and policy feedback closed loop to overcome the above-mentioned shortcomings of existing technologies. Summary of the Invention

[0010] To address the shortcomings of existing technologies, this invention provides a multi-scenario integrated data security and intelligent encryption transmission method, system, and storage medium to solve technical problems such as poor scenario adaptability of existing data encryption transmission schemes, insufficient intelligence of encryption strategies, separation of identity authentication and encryption processes, lack of multi-level collaborative encryption system, and lack of closed-loop optimization mechanism.

[0011] The above-mentioned objective of this invention is achieved through the following technical solutions: A multi-scenario integrated data security and intelligent encrypted transmission method includes the following steps: Step S1: Scene Awareness and Feature Extraction Real-time acquisition of multi-dimensional scene data, including: network environment parameters of the transmission device, device context parameters, data attribute feature parameters of the data to be transmitted, and user behavior feature parameters; semantic analysis and feature fusion of the multi-dimensional scene data to generate a fused scene feature vector.

[0012] Specifically, the network environment parameters include, but are not limited to, bandwidth, latency, packet loss rate, jitter, channel quality indicators, and network security situation score; the device context parameters include, but are not limited to, CPU utilization, memory usage, remaining battery power, device type, and system security level; the data attribute characteristic parameters include, but are not limited to, data sensitivity level, data type identifier, data volume, and data source label; and the user behavior characteristic parameters include, but are not limited to, user identity credentials, historical behavior patterns, current operation context, and behavior anomaly index. The comprehensive collection of these parameters ensures the completeness and accuracy of scene perception.

[0013] Preferably, the specific sub-steps for performing semantic analysis and feature fusion on the multi-dimensional scene data to generate a fused scene feature vector include: The network environment parameters, device context parameters, data attribute feature parameters, and user behavior feature parameters are normalized and standardized respectively to eliminate the differences in the dimensions of each parameter; A multimodal feature extraction network is used to encode features of data in each dimension. The multimodal feature extraction network includes: a long short-term memory network (LSTM) encoder for processing network temporal parameters, a graph attention network encoder for processing device context parameters, a convolutional neural network encoder for processing data attribute features, and a transformer network encoder for processing user behavior features. The cross-attention fusion module deeply fuses the feature representations output by each encoder to generate the fused scene feature vector. Specifically, the cross-attention fusion module employs a multi-head attention mechanism to weighted aggregate the feature representations from different modalities. This design of multimodal feature extraction and cross-attention fusion fully leverages the correlations and complementary information between scene data across various dimensions, effectively improving the accuracy of scene perception.

[0014] Step S2: Scene Classification and Identity Authentication Based on the fused scene feature vector, the current data transmission scene is classified and identified by a preset scene classifier, and a scene type identifier is output. The scene classifier is a classifier built based on a multi-class machine learning model, and the scene types include at least: financial transaction scene, medical data exchange scene, IoT device communication scene, cloud computing cross-domain transmission scene, and remote office access scene.

[0015] Based on the scenario type identifier, the corresponding identity authentication strategy is dynamically matched from the preset multi-level identity authentication strategy library. Based on the matched identity authentication strategy, the user's identity is performed for multi-factor fusion authentication, and an authentication pass credential is generated.

[0016] The multi-factor fusion authentication includes at least two or more combinations of static password authentication, biometric authentication, and hardware feature authentication, and the combination method and authentication strength of authentication factors are dynamically adjusted according to the real-time risk assessment results during the authentication process.

[0017] Preferably, the specific implementation of dynamically adjusting the combination of certification factors and certification intensity based on real-time risk assessment results during the certification process includes: Based on the user behavior features and network security situation score in the fused scenario feature vector, calculate the risk score R_risk for the current session; When the risk score R_risk is lower than the first threshold, a single-factor authentication mode is used, which only verifies the user's password. When the risk score R_risk is between the first threshold and the second threshold, a two-factor authentication mode is adopted to verify both the user's password and biometric features. When the risk score R_risk is higher than the second threshold, a three-factor authentication mode is adopted to verify the user's password, biometrics and hardware binding characteristics at the same time. The first threshold and the second threshold are dynamically configured according to the scene type identifier, and different scene types correspond to different threshold configuration parameters.

[0018] This dynamic and adaptive authentication mechanism enables the authentication strength to be intelligently adjusted based on real-time risk assessment results, ensuring the reliability of identity authentication in high-risk scenarios while avoiding excessive authentication overhead in low-risk scenarios.

[0019] Step S3: Adaptive generation of encryption scheme The fused scene feature vector, the scene type identifier, and the authentication credential are input to a deep reinforcement learning-based encryption decision network, which outputs the optimal encryption scheme parameter set.

[0020] The optimal encryption scheme parameter set includes: encryption algorithm identifier, key length, encryption mode, fragmentation strategy parameters, differential privacy noise parameters, and transmission channel priority.

[0021] The encryption decision network makes decisions with the objective function of minimizing the overall security cost, and the formula for calculating the overall security cost is as follows: ,in For the cost of security risks, For performance overhead, For the cost of energy consumption, , , To adaptively adjust the weighting coefficients, these coefficients are dynamically adjusted in real time based on the fused scene feature vector. Through the aforementioned comprehensive security cost function, this invention achieves an optimal dynamic trade-off between security, transmission performance, and energy consumption, avoiding the limitations caused by a single optimization objective in traditional methods.

[0022] Preferably, the encryption decision network based on deep reinforcement learning includes an action space and a state space; wherein, the action space is composed of the discretized values ​​of each parameter in the parameter set of the optimal encryption scheme; and the state space is composed of the fused scene feature vector and the scene type identifier after feature embedding processing. The encryption decision network employs deep... The Direct Quantity Network (DQN) algorithm makes decisions, and its The update formula for the value function is: ,in For learning rate, For instant rewards, Discount factor. Instant reward. Calculated based on actual latency after encrypted transmission, security score, and energy consumption measurements. (Through deep learning...) The reinforcement learning framework of the network enables the invention to continuously learn and optimize encryption decision-making strategies from historical transmission experience, thereby achieving continuous evolution of decision-making capabilities.

[0023] Step S4: Multi-level hybrid encryption execution Based on the optimal encryption scheme parameter set, a multi-level hybrid encryption operation is performed on the data to be transmitted, specifically including: Level 1: Data Sharding and Preprocessing. Based on the sharding strategy parameters, the data to be transmitted is dynamically divided into a sequence of data shard units, each carrying independent integrity verification information. For each data shard unit, differential privacy noise injection is selectively applied according to the sensitivity level in the data attribute characteristic parameters, generating sharded data with noise perturbation. The intensity of the differential privacy noise injection is proportional to the data sensitivity level; that is, highly sensitive data is injected with higher intensity noise to enhance privacy protection.

[0024] The second layer: symmetric key encryption. Based on the symmetric encryption algorithm corresponding to the encryption algorithm identifier and the key length, a session key is generated. Symmetric encryption operations are performed on each data fragment to obtain the first layer of ciphertext data. The session key is a dynamically generated one-time pad session key. The symmetric encryption layer, as the main encryption layer, provides efficient data confidentiality protection.

[0025] The third layer: Asymmetric key encapsulation. An asymmetric encryption algorithm is used to encapsulate and protect the session key, resulting in ciphertext. This ciphertext is then bound to the authentication credentials to generate the key encapsulation header. Through asymmetric encapsulation, the session key is transmitted in ciphertext only between the sender and receiver. Even if the transmission channel is intercepted, an attacker cannot obtain the plaintext of the session key.

[0026] Fourth layer: Homomorphic encryption auxiliary computation layer. A partial homomorphic encryption algorithm is applied to the preset computable fields of the first-layer ciphertext data to generate computational ciphertext that supports ciphertext field computation, enabling the data to complete specified computational operations while in an encrypted state.

[0027] Preferably, the computational ciphertext generated by the homomorphic encryption auxiliary computation layer supports at least one of ciphertext field addition and ciphertext field multiplication operations. During data transmission, when intermediate nodes perform ciphertext field calculations on the computational ciphertext, they can complete the specified aggregation calculation operation (such as data summation, averaging, and other aggregation statistical operations) without decryption. The calculation result is transmitted to the receiving end in ciphertext form, where it is then decrypted. This design allows data to participate in multi-party computation while maintaining an encrypted state, avoiding the security risks caused by repeated decryption and re-encryption of data at computation nodes. It is particularly suitable for scenarios requiring data aggregation, such as federated learning and secure multi-party computation.

[0028] Step S5: Intelligent Transmission Scheduling Based on the transmission channel priority in the parameter set of the optimal encryption scheme and combined with the real-time network quality assessment results, the optimal transmission path is selected from multiple available transmission links or multi-path parallel transmission scheduling is performed; an encrypted data packet is constructed, and the first layer ciphertext data, the session key ciphertext, the key encapsulation header, and the scenario type identifier are encapsulated into a unified transmission message format; wherein, the unified transmission message format includes three parts: message header, key header, and data payload, and each encrypted data unit in the data payload is bound for integrity using a chained hash link structure.

[0029] Preferably, the multi-path parallel transmission scheduling includes: Based on the real-time network quality assessment results, path weights are calculated for each available transmission link. The path weights are calculated based on a comprehensive assessment of link bandwidth, latency, packet loss rate, and security trust rating. Based on the sensitivity level of each fragment unit in the data fragment unit sequence, data fragments with different sensitivity levels are allocated to transmission links with corresponding security levels. The chained hash link structure is as follows: the integrity verification field of each data shard unit contains the hash value of the previous shard unit, forming a chained verification relationship. Any missing or tampered data shard unit can be traced and located through the hash chain.

[0030] The aforementioned intelligent transmission scheduling mechanism effectively improves transmission bandwidth utilization and robustness through multi-path parallel transmission, while providing strong support for integrity verification through a chained hash link structure.

[0031] Step S6: Adaptive decryption and integrity verification at the receiving end After receiving the encrypted transmission message, the receiving end parses the message header to obtain the scenario type identifier and key encapsulation header; based on the scenario type identifier, it matches the corresponding decryption strategy, uses the receiving end's private key to decrypt the session key ciphertext and recover the session key; it uses the recovered session key to perform symmetric decryption operation on the data payload to obtain fragmented decrypted data; it performs integrity verification and temporal continuity verification on the fragmented decrypted data through the chained hash link structure, and if the verification passes, it merges and reassembles the data to output the original data.

[0032] Step S7: Security Audit and Policy Feedback The entire data transmission process from steps S1 to S6 above is logged for security audit, generating audit records containing fields such as timestamp, scenario type identifier, encryption algorithm identifier, transmission node identifier, and verification result. These records are then stored in a distributed audit ledger. The performance indicators and actual security effects of the entire data transmission process are used as feedback data and input into the encryption decision network for online updating and optimization of policy parameters.

[0033] Preferably, the distributed audit ledger is an immutable audit ledger built on blockchain technology; the audit records are written to the blockchain in the form of transactions, and each audit record is persistently stored after being verified by a consensus mechanism; the audit ledger is periodically scanned for compliance, and when a security policy deviation or abnormal behavior pattern is detected, an encryption policy adjustment instruction is automatically triggered and the adjustment instruction is fed back to the encryption decision network.

[0034] Through the aforementioned closed-loop security audit and policy feedback mechanism, the encryption decision-making capability of this invention can continuously evolve with the accumulation of system operation data, realizing a fundamental transformation from "static fixed policy" to "dynamic adaptive decision-making".

[0035] This invention also provides a multi-scenario integrated data security and intelligent encrypted transmission system, comprising: The scene perception and feature extraction module is used to collect multi-dimensional scene data in real time, perform semantic analysis and feature fusion on the multi-dimensional scene data, and generate a fused scene feature vector. The scene classification and identity authentication module is connected to the scene perception and feature extraction module. It is used to classify and identify the current data transmission scene based on the fused scene feature vector, and dynamically match the identity authentication strategy according to the scene type identifier to perform multi-factor fusion authentication. An adaptive encryption scheme generation module, connected to the scene classification and identity authentication module, is used for an encryption decision network based on deep reinforcement learning to output the optimal encryption scheme parameter set according to the fused scene feature vector, scene type identifier, and authentication credentials. A multi-level hybrid encryption execution module, connected to the encryption scheme adaptive generation module, is used to perform multi-level hybrid encryption operations on the data to be transmitted according to the optimal encryption scheme parameter set, including data fragmentation preprocessing, symmetric key encryption, asymmetric key encapsulation, and homomorphic encryption auxiliary calculation. The intelligent transmission scheduling module, connected to the multi-level hybrid encryption execution module, is used to select transmission paths and perform multi-path parallel scheduling based on transmission channel priority and real-time network quality assessment results. The adaptive decryption and verification module is used by the receiving end to perform adaptive decryption, integrity verification, and time domain continuity verification after receiving encrypted transmission messages. The security audit and policy feedback module, connected to the above modules, is used to record security audit logs throughout the data transmission process and input the feedback data into the encrypted decision network for online updates of policy parameters.

[0036] Preferably, the encryption decision network in the encryption scheme adaptive generation module is a deep reinforcement learning network that supports online learning. During system operation, the network continuously receives performance indicators and actual security effect data fed back in step S7, and incrementally updates the policy parameters through an experience replay mechanism, so that the decision-making ability of the encryption scheme is continuously optimized as the running data accumulates.

[0037] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described above.

[0038] In summary, compared with the prior art, the present invention has at least one of the following beneficial technical effects: Multi-scenario fusion perception and adaptive capabilities. This invention, through real-time acquisition of multi-dimensional scene data and fusion of multi-modal features, can accurately perceive the security requirements and resource constraints of the current transmission scenario, and dynamically adapt encryption strength, algorithm selection, and authentication strategies accordingly, achieving true scenario-adaptive secure transmission and overcoming the rigidity of traditional methods.

[0039] An intelligent encryption decision-making mechanism. This invention introduces an encryption decision-making network based on deep reinforcement learning, aiming to minimize the overall security cost and achieve an optimal balance between security, performance, and energy consumption. The decision-making network can continuously learn and optimize from historical experience, enabling the encryption strategy to dynamically adjust with changes in the environment. Its decision-making ability and intelligence level far exceed existing schemes based on rules or simple scoring models.

[0040] A multi-layered hybrid encryption execution system. This invention constructs a five-layer encryption architecture: data fragmentation, differential privacy noise injection, symmetric key encryption, asymmetric key encapsulation, and homomorphic encryption-assisted computation. Each layer works collaboratively and complements the others, achieving multi-objective optimization of security, efficiency, and computability. In particular, the homomorphic encryption layer enables ciphertext data to participate in multi-party computations without exposing the plaintext, filling a gap in existing technologies for multi-scenario integrated encryption.

[0041] Dynamically adaptive multi-factor fusion authentication. This invention dynamically adjusts the combination and strength of authentication factors based on real-time risk assessment results. The authentication strategy is deeply bound to the scenario type, and authentication credentials closely related to the encryption process are generated. This achieves seamless integration of identity authentication and encrypted transmission, effectively preventing man-in-the-middle attacks and identity impersonation risks.

[0042] Security audit and policy feedback closed loop. This invention performs tamper-proof blockchain auditing of the entire data transmission process and feeds the audit results and performance indicators back to the encrypted decision-making network, forming a complete closed loop of "perception-decision-execution-audit-feedback", enabling the system's security protection capabilities to continuously improve with the accumulation of operational experience. Attached Figure Description

[0043] Figure 1 The overall flowchart of the multi-scenario integrated data security and intelligent encrypted transmission method provided by the present invention.

[0044] Figure 2 This is a detailed flowchart of step S1, scene perception and feature extraction, in this invention.

[0045] Figure 3 This is a flowchart of step S2, dynamic identity authentication, in this invention.

[0046] Figure 4 This is a schematic diagram of the encryption decision network structure based on deep reinforcement learning in step S3 of the present invention.

[0047] Figure 5 This is a diagram of the multi-level hybrid encryption execution architecture for step S4 in this invention.

[0048] Figure 6 This is a schematic diagram of the message encapsulation format for intelligent transmission scheduling in step S5 of the present invention.

[0049] Figure 7 This is a schematic diagram of the closed loop of security audit and policy feedback in step S7 of the present invention.

[0050] Figure 8 The module structure diagram of the multi-scenario integrated data security and intelligent encrypted transmission system provided by the present invention. Detailed Implementation

[0051] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0052] Example 1 See Figure 1 As shown, this embodiment provides a multi-scenario integrated data security and intelligent encrypted transmission method, which includes the following steps S1 to S7.

[0053] Step S1: Scene Awareness and Feature Extraction The core task of this step is to conduct comprehensive and multi-dimensional information collection and feature fusion of the current data transmission scenario, so as to provide a high-quality data foundation for subsequent scenario classification and intelligent decision-making.

[0054] S1.1: Multi-dimensional Scene Data Acquisition Real-time collection of the following four types of multi-dimensional scenario data: Network environment parameters include bandwidth, latency (round-trip time), packet loss rate, jitter, channel quality metrics (such as signal strength and signal-to-noise ratio, SNR), and network security posture score (dynamically calculated based on current network security threat intelligence). These parameters reflect the real-time status of current network transmission conditions and the level of security risks.

[0055] Device context parameters include CPU utilization, memory usage, remaining battery power, device type (such as smartphones, IoT sensors, servers, etc.) and system security level (such as operating system patch level, security software installation status, etc.).

[0056] Data attribute characteristic parameters include: data sensitivity level (sensitivity score based on data classification standards, such as high sensitivity / medium sensitivity / low sensitivity), data type identifier (such as financial data, medical records, IoT sensor data, user profiles, etc.), data size (in bytes or data packets), and data source label (such as sensor acquisition, user input, system generation, etc.).

[0057] User behavior characteristic parameters include user identity credentials (identification information that has been preliminarily verified), historical behavior patterns (behavioral profiles based on user's historical behavior statistics), current operation context (the type of operation the user is currently performing and related information), and behavior anomaly index (anomaly score calculated in real time by a behavior analysis model).

[0058] S1.2: Data Preprocessing The collected multi-dimensional scene data of four types were normalized and standardized respectively. Specifically, for numerical parameters, the Min-Max normalization method was used to map them to the [0,1] interval: Categorical parameters are converted into numerical vector representations using one-hot encoding. After this processing, the dimensional differences in the data are eliminated, facilitating subsequent feature fusion.

[0059] S1.3: Multimodal Feature Extraction like Figure 2 As shown, a multimodal feature extraction network is used to encode features for each dimension of the data: Network temporal parameters: Due to the time-series characteristics of the network parameters, a Long Short-Term Memory (LSTM) encoder is used for processing. The input of the LSTM encoder is a snapshot of the network state at multiple consecutive time points, and the output is a temporal feature vector h_net. Through the gating mechanism of forget gates, input gates, and output gates, LSTM can effectively capture the short-term fluctuations and long-term trends of the network state.

[0060] Device context parameters: The devices in the device context parameters have complex graph structure relationships (such as connection topology and dependencies between devices), which are processed using a Graph Attention Network (GAT) encoder. The GAT encoder treats devices as nodes in the graph and the relationships between devices as edges. It calculates the attention weights between adjacent nodes through a multi-head attention mechanism and outputs a graph structure feature vector h_device. The GAT encoder enables the encoding of device context parameters to incorporate inter-device relationship information, improving the richness of feature representation.

[0061] Data attribute features: Since data attribute features are often structured or semi-structured information, a convolutional neural network (CNN) encoder is used for processing. The CNN encoder extracts local patterns and hierarchical features of data attributes through multiple convolution and pooling operations, and outputs a convolutionally encoded feature vector h_data.

[0062] User behavior features: User behavior features exhibit strong sequence dependencies and long-range correlations, which are processed using a Transformer network encoder. The Transformer encoder uses a self-attention mechanism to globally model the user behavior sequence, outputting a behavior feature vector h_behavior. Compared to LSTM, the Transformer can better capture long-range dependencies in the user behavior sequence.

[0063] S1.4: Cross-attention fusion The h_net output from the LSTM encoder, the h_device output from the GAT encoder, the h_data output from the CNN encoder, and the h_behavior output from the transform encoder are input into the cross-attention fusion module. This module uses a multi-head attention mechanism to weighted aggregate the feature representations of different modalities.

[0064] Specifically, h_net is used as the query, and h_device, h_data, and h_behavior are used as the key and value, respectively. A weighted fusion vector is obtained through attention calculation. The multi-head attention mechanism uses multiple attention heads to compute in parallel, with each attention head focusing on a different feature subspace. Finally, the outputs of all attention heads are concatenated and linearly transformed to obtain the fused scene feature vector f_fusion.

[0065] The above-mentioned design of multimodal feature extraction and cross-attention fusion fully explores the correlation and complementary information between scene data in various dimensions, enabling the generated fused scene feature vector to comprehensively and accurately represent the overall state of the current transmission scene, laying a solid foundation for subsequent scene classification and intelligent decision-making.

[0066] Step S2: Scene Classification and Identity Authentication S2.1: Scene Classification and Recognition The fused scene feature vector f_fusion generated in step S1 is input into a preset scene classifier. The scene classifier adopts a multi-class machine learning model based on a multi-layer perceptron. The specific network structure includes: an input layer (with the same dimension as f_fusion), a hidden layer (containing 256 neurons, using the ReLU activation function and Dropout regularization), and an output layer (using the Softmax activation function to output the probability distribution of each category).

[0067] The output of the scene classifier is the scene type identifier scene_type. The scene types include: financial transaction scenario (highest priority, with extremely high requirements for security and transaction integrity), medical data exchange scenario (with special requirements for privacy protection and compliance traceability), Internet of Things device communication scenario (sensitive to energy consumption and real-time performance), cloud computing cross-domain transmission scenario (involving multi-tenant isolation and cross-trust domain authentication), and remote office access scenario (with high requirements for user experience and connection stability).

[0068] S2.2: Dynamic Identity Authentication As shown in Figure 3 , according to the scene type identifier scene_type, the corresponding identity authentication strategy configuration is dynamically matched from the preset multi-level identity authentication strategy library. The authentication strategy library predefines authentication factor combination templates and threshold parameters under different scene types.

[0069] The specific implementation of the dynamic adjustment mechanism for multi-factor fusion authentication is as follows: Risk score calculation: Based on the user behavior characteristics and the network security situation score in the fused scene feature vector, the risk score value R_risk of the current session is calculated by weighted summation: R_risk = w_b·Score_behavior+ w_n·Score_network, wherein Score_behavior is the behavior abnormality index (value range 0~1), Score_network is the network security situation score (value range 0~1, a higher value indicates higher risk), and w_b and w_n are preset weight coefficients.

[0070] Dynamic adjustment of authentication strength: According to the comparison result between R_risk and the dynamic threshold (configured by the scene type identifier), the authentication mode is automatically selected: When R_risk<T_low, the single-factor authentication mode (Level-1) is adopted, and only the user password is verified; When T_low ≤ R_risk<T_high, the two-factor authentication mode (Level-2) is adopted, which verifies the user password and biometric features (such as fingerprint or face recognition) simultaneously; When R_risk ≥ T_high, the three-factor authentication mode (Level-3) is adopted, which verifies the user password, biometric features and hardware binding features (such as device serial number or hardware security module key) simultaneously.

[0071] Wherein T_low and T_high are threshold parameters dynamically configured according to scene_type. Different scene types correspond to different threshold configurations. For example, the threshold configuration of financial transaction scenarios is relatively conservative (a lower threshold triggers high-factor authentication), while the threshold configuration of Internet of Things communication scenarios is relatively loose to reduce authentication overhead.

[0072] Multi-factor authentication execution: Based on the determined authentication mode, the corresponding authentication service modules are invoked in parallel to collect the authentication results of each factor and generate an authentication pass credential (Auth_Token). The authentication pass credential is a structured encrypted token containing the user's identity ID, authentication timestamp, authentication factor combination identifier, and signature information, serving as the basis for identity verification in subsequent encryption processes.

[0073] The aforementioned dynamic and adaptive multi-factor fusion authentication mechanism enables the authentication strength to be intelligently adjusted based on real-time risk assessment results, avoiding excessive authentication overhead in low-risk scenarios and insufficient authentication strength in high-risk scenarios.

[0074] Step S3: Adaptive generation of encryption scheme like Figure 4 As shown, this step employs an encryption decision network based on deep reinforcement learning, which intelligently generates the optimal encryption scheme parameter set based on the fused scene feature vector, scene type identifier, and authentication credentials.

[0075] S3.1: Definition of State Space and Action Space The state space is composed of the fused scene feature vector f_fusion and the scene type identifier scene_type after embedding processing, and is represented as state s_t. Among them, the scene type identifier is mapped to a fixed-dimensional embedding vector through the embedding layer and then concatenated with f_fusion to form a complete state representation.

[0076] The action space consists of the discretized values ​​of each parameter in the optimal encryption scheme parameter set, and the range of values ​​for each parameter is as follows: Encryption algorithm identifier: Encoding identifier for symmetric encryption algorithms such as AES128 / AES256 / SM4 / ChaCha20; Key length: discrete values ​​of 128 bits / 192 bits / 256 bits; Encryption mode: Encoding identifier for encryption modes such as CBC / GCM / CTR; Sharding strategy parameters: a combination of discrete values ​​for shard size (e.g., 1KB / 4KB / 16KB / 64KB) and the number of shards; Differential privacy noise parameters: discrete values ​​of noise intensity (ε value) and noise mechanism; Transmission channel priority: Low / Medium / High priority levels.

[0077] S3.2: Deep Q-Network (DQN) Decision Making The cryptographic decision network employs the Deep Q-Network (DQN) algorithm, the core of which is to use a deep neural network to approximate the Q-value function. The network structure includes: an input layer (receiving state s_t), three fully connected hidden layers (256 neurons per layer, using the ReLU activation function), and an output layer (outputting the Q-value of each action in the action space).

[0078] The Q-value function update employs an empirical replay mechanism and a fixed-target network technique to avoid training instability. The Q-value update formula is: ,in The learning rate (empirically, the value ranges from 0.0001 to 0.001). This is the discount factor (usually ranging from 0.9 to 0.99).

[0079] S3.3: Comprehensive Security Cost Function Encrypted decision-making networks minimize overall security costs Make decisions based on the objectives. The formula for calculating the overall security cost is: ; The meanings and calculation methods of each cost component are as follows: (Security Risk Cost): Based on a comprehensive calculation of data sensitivity level, network security situation score, and the attack resistance strength of the selected encryption scheme, this reflects the risk of data leakage that may result from insufficient security of the current encryption scheme.

[0080] (Performance overhead cost): Based on the estimated time consumption of encryption operations, transmission delay and fragmentation processing overhead, it reflects the degree of impact of the encryption scheme on transmission efficiency.

[0081] (Energy Cost): Based on the comprehensive calculation of computing energy consumption, data transmission energy consumption and fragmentation processing energy consumption of encryption operations, it reflects the degree of power consumption of the encryption scheme on the device, which is especially important for energy-constrained devices such as the Internet of Things.

[0082] , , To adaptively adjust the weighting coefficients, the values ​​of these three weighting coefficients are dynamically adjusted in real time based on the fused scenario feature vector. For example, in an IoT device communication scenario, if the remaining battery power is low, then... The energy cost weight will increase accordingly, guiding the decision network to choose a lower-energy encryption scheme; in financial transaction scenarios, The (security risk cost weight) automatically increases, guiding the decision-making network to prioritize encryption schemes with higher security.

[0083] S3.4: Instant Rewards After encrypted transmission is completed, the system calculates the immediate reward r_t based on the actual measurement results. The immediate reward comprehensively considers transmission latency (lower latency, higher reward), security score (higher security score, higher reward), and energy consumption measurement (lower energy consumption, higher reward): . The calculation adopts a normalized weighted summation method, and the weights of each dimension are consistent with the weight coefficients in the comprehensive security cost function to ensure the consistency of the optimization objective.

[0084] Step S4: Multi-level hybrid encryption execution like Figure 5 As shown, this step performs a five-layer hybrid encryption operation on the data to be transmitted based on the optimal encryption scheme parameter set output by the encryption decision network.

[0085] S4.1: First level: Data fragmentation and differential privacy preprocessing (1) Dynamic Data Fragmentation: Based on the fragmentation size setting in the fragmentation strategy parameters, the data to be transmitted is dynamically divided into a sequence of data fragment units {Fragment_1, Fragment_2, …, Fragment_n}. The fragment size can be adaptively adjusted according to network conditions and data type. For example, smaller fragments are used in environments with poor network quality to reduce retransmission overhead, while larger fragments are used for large file transmissions to improve transmission efficiency. Each data fragment unit carries independent integrity verification information, including fragment sequence number, fragment length, and reserved hash field. The setting of integrity verification information provides the basis for subsequent chained hash verification.

[0086] (2) Differential Privacy Noise Injection: For each data shard unit, differential privacy noise injection is selectively applied based on the sensitivity level in the data attribute feature parameters. Data shards with high sensitivity levels are injected with higher intensity noise (i.e., smaller privacy budget ε value), while data shards with low sensitivity levels can skip noise injection to reduce overhead. Differential privacy noise injection uses a Laplace or Gaussian mechanism to add random noise following a specific distribution to the data shards. The data shards after adding noise are noisy perturbation data F'_i. The intensity of the noise injection satisfies ε-differential privacy protection, that is, the impact of adding or deleting any single data record on the output result is limited to a controllable range.

[0087] S4.2: Second level: Symmetric key encryption (1) Session key generation: Based on the encryption algorithm identifier and key length in the optimal encryption scheme parameter set, a one-time pad session key, SessionKey, is generated. The session key generation process combines a true random number source (such as a hardware random number generator or system entropy source) with a key derivation function to ensure the randomness and unpredictability of the key.

[0088] (2) Symmetric Encryption Execution: Using the selected symmetric encryption algorithm (such as AES-256-GCM or SM4) and encryption mode (such as GCM mode), the session key SessionKey is used to perform symmetric encryption operations on each data fragment unit one by one: Ciphertext_i = Enc_sym(SessionKey, F'_i), to obtain the first layer of ciphertext data {Ciphertext_1, Ciphertext_2,…, Ciphertext_n}. For encryption schemes using authentication encryption modes (such as GCM mode), the encryption process simultaneously generates an authentication tag AuthTag_i for integrity verification at the receiving end.

[0089] S4.3: Third level: Asymmetric key encapsulation The session key (SessionKey) is encapsulated and protected using an asymmetric encryption algorithm (such as RSA or SM2): EncapsulatedKey = Enc_asym(PubKey_receiver, SessionKey), where PubKey_receiver is the recipient's public key. The encapsulated session key ciphertext EncapsulatedKey is bound to the authentication credential Auth_Token to generate the key encapsulation header.

[0090] The key encapsulation header contains the following fields: encapsulated key data, authentication token, encryption algorithm identifier, key encapsulation timestamp, and the sender's digital signature. Through this binding, authentication credentials are tightly linked to the encryption process; any tampering with the key encapsulation will invalidate the binding.

[0091] S4.4: Fourth Level: Homomorphic Encryption Auxiliary Computation Layer For the pre-computable fields in the first-layer ciphertext data (i.e., data fields that need to be aggregated and calculated during transmission or at the receiving end), a partial homomorphic encryption algorithm is applied for additional processing. Specifically, the Paillier encryption scheme, which supports additive homomorphism, or the ElGamal variant scheme, which supports multiplicative homomorphism, is used to convert the selected field data from ciphertext form into homomorphic ciphertext that supports ciphertext field computation.

[0092] The computational ciphertext generated by the homomorphic encryption layer has the following characteristics: During data transmission, when intermediate nodes (such as gateways, aggregation servers, etc.) perform ciphertext field calculations on the computational ciphertext, they can complete the specified aggregation calculation operation (such as summing or multiplying multiple ciphertext values) without decryption. The calculation result is transmitted to the receiving end in ciphertext form, and then the receiving end decrypts it using its private key. This design allows data to participate in multi-party computations while maintaining an encrypted state, making it suitable for application scenarios that require data aggregation, such as federated learning aggregation, secure multi-party computation, and statistical analysis.

[0093] S4.5: Encrypted Data Encapsulation Data encrypted at each level is encapsulated in a unified format to provide standardized input for subsequent intelligent transmission scheduling.

[0094] Step S5: Intelligent Transmission Scheduling S5.1: Transmission Path Evaluation and Selection Based on the transmission channel priority in the optimal encryption scheme parameter set and combined with the real-time network quality assessment results, the optimal transmission path is selected from multiple available transmission links or a multi-path parallel transmission scheme is configured.

[0095] The path weight calculation for multiple transmission links takes into account the following factors: Link bandwidth: The higher the available bandwidth, the higher the weight. Latency: The lower the round-trip time, the higher the weight. Packet loss rate (LossRate): The lower the packet loss rate, the higher the weight. TrustLevel: A rating of link trust based on historical transmission records and security authentication results.

[0096] The formula for calculating path weight is: .

[0097] For data transmission tasks requiring high reliability, select the single link with the highest path weight for transmission; for data transmission tasks requiring high throughput, configure multi-path parallel transmission and allocate data fragmentation units to multiple links for concurrent transmission.

[0098] It is worth noting that this invention implements a security-tiered transmission mechanism based on sensitivity levels: according to the sensitivity level of each fragment in the data fragmentation unit sequence, high-sensitivity fragments are allocated to transmission links with high security trust ratings, while low-sensitivity fragments are allocated to ordinary links. This security-tiered transmission mechanism ensures the security of highly sensitive data while fully utilizing the low-cost transmission opportunities for low-sensitivity data, achieving an optimized balance between security and efficiency.

[0099] S5.2: Unified Message Encapsulation like Figure 6 As shown, an encrypted data packet is constructed, and the encrypted data at each level is encapsulated into a unified transmission message format. The unified transmission message format consists of three parts: Message header: contains information such as scenario type identifier, protocol version number, message sequence number, timestamp, message length, and sender identifier.

[0100] Key header: contains session key ciphertext, authentication credentials, encryption algorithm identifier, and key encapsulation timestamp.

[0101] Data payload: Contains encrypted data units {Ciphertext_1, Ciphertext_2, …,Ciphertext_n}. Each encrypted data unit in the data payload is bound to an integrity-based chained hash structure.

[0102] The chained hash link structure is constructed as follows: For a data fragment unit sequence {Fragment_1, Fragment_2, …, Fragment_n}, calculate the hash value H_i = Hash(Fragment_i) of each fragment unit before encryption, and construct a chained verification relationship: Link_i = Hash(H_i || Link_{i-1}), where Link_0 is a preset initial value. The chained hash link structure ensures that the integrity verification field of each data fragment unit includes the hash value of the previous fragment unit, forming a chained dependency. During verification at the receiving end, the absence or tampering of any data fragment unit will disrupt the entire hash chain starting from that fragment, allowing for precise location and traceability of tampering.

[0103] S5.3: Encrypted data transmission The encapsulated encrypted message is sent according to the determined transmission scheduling strategy. In the case of multi-path parallel transmission, each data fragment unit needs to add a path identifier field before sending to facilitate the reassembly and alignment operations at the receiving end.

[0104] Step S6: Adaptive decryption and integrity verification at the receiving end S6.1: Message parsing and scenario matching After receiving an encrypted transmission message, the receiving end first parses the message header to extract information such as the scene type identifier (scene_type), message sequence number, and timestamp. Based on the scene type identifier, it matches the corresponding decryption policy configuration from the local policy library, including the selection of the decryption algorithm and authentication strength requirements.

[0105] S6.2: Session Key Recovery The receiving end uses its private key, `PrivKey_receiver`, to decrypt the ciphertext of the session key in the key header: `SessionKey = Dec_asym(PrivKey_receiver, EncapsulatedKey)`. The recovered session key `SessionKey` provides the key material for subsequent symmetric decryption. During this process, the validity of the authentication credentials and digital signature in the key header is also verified to ensure the session key's reliable origin and lack of tampering.

[0106] S6.3: Symmetric Decryption Using the recovered session key SessionKey, the corresponding symmetric decryption algorithm is selected according to the encryption algorithm identifier in the message header, and the symmetric decryption operation is performed on each ciphertext data unit in the data payload one by one: F'_i = Dec_sym(SessionKey, Ciphertext_i), to obtain the fragmented decrypted data {F'_1, F'_2, …, F'_n}.

[0107] S6.4: Chained Hash Integrity Verification The decrypted fragments are then verified for integrity and temporal continuity using a chained hash linking structure.

[0108] The specific verification process is as follows: For each data shard unit F'_i, calculate its hash value H'_i = Hash(F'_i); Recalculate Link'_i = Hash(H'i || Link'{i-1}) according to the chained link structure; The calculated Link'_i is compared with the reference link value carried in the message.

[0109] If the link values ​​of all fragments pass the comparison, it indicates that the data integrity is good and the fragment order is correct. If the link value verification of a certain fragment fails, according to the characteristics of the chain structure, it can be determined that data corruption or tampering has occurred from that fragment onwards. The receiving end decides whether to request retransmission of the specific fragment or reject the entire message based on the position of the failure.

[0110] For fragments using authentication and encryption modes such as GCM, the validity of the authentication tag AuthTag_i is also verified.

[0111] S6.5: Data Reassembly Output After the integrity verification is passed, the decrypted fragment data is merged and reassembled according to the fragment sequence number to restore the original data content and output to the upper layer application.

[0112] For data shards with differential privacy noise injection, the presence of noise results in a controllable deviation between the decrypted data and the original data, but the usability of the aggregated statistical results is guaranteed. Depending on the application scenario, noise removal or deviation correction operations can be performed after decryption.

[0113] Step S7: Security Audit and Policy Feedback like Figure 7 As shown, this step forms a closed loop of the entire process from encryption execution to security auditing and then to policy optimization.

[0114] S7.1: Security Audit Log Recording A security audit log is recorded for the entire data transmission process from steps S1 to S6 above. Each audit log contains the following fields: Timestamp: Records the time when data transmission occurred; Scene type identifier: The scene type identified in step S2; Encryption algorithm identifier: The encryption scheme selected in step S3; Transmission node identifier: The network identifier of the sending and receiving ends; Verification result field: Result information such as whether integrity verification passed, whether authentication was successful, etc. Performance metrics: Actual measured values ​​such as transmission latency, throughput, and energy consumption.

[0115] S7.2: Distributed Audit Ledger Storage Audit records are stored in a distributed, immutable audit ledger built on blockchain technology. Each audit record is written to the blockchain network in the form of a transaction, and after being verified by a consensus mechanism (such as PBFT or Raft consensus algorithm), it is persistently stored on each node.

[0116] The advantages of a distributed audit ledger are: the immutability of audit records ensures the credibility of compliance traceability; multi-replica storage and consensus mechanisms improve the availability and fault tolerance of the audit system; and the decentralized audit structure avoids the trust dependency problem of single-point auditing.

[0117] S7.3: Compliance Scanning and Anomaly Detection Regularly perform compliance scans on the audit ledgers to compare whether the actual encryption policies match the preset security compliance policies. Trigger an alert when the following anomalies are detected: Security strategy deviation: The actual encryption strength used is lower than the minimum security requirement corresponding to the scenario type; Abnormal behavior pattern: A large number of authentication failures and abnormal changes in encryption parameters occur within a short period of time; Integrity verification failed: Frequent transmission records showing data integrity verification failures.

[0118] S7.4: Strategy Feedback and Online Optimization The performance indicators and actual security effects of the entire data transmission process are used as feedback data and input into the encryption decision network for online updating and optimization of policy parameters.

[0119] The feedback data processing flow is as follows: Collect actual performance metrics for each data transmission (including delay_actual, security_score_actual, and energy_consumed). Generate instant rewards according to the calculation rules in step S3.4. ; Will This will be stored as an experience sample in the experience replay pool. Batch samples are randomly sampled from the experience replay pool for parameter updates in the deep Q-network.

[0120] When an anomaly is detected during a compliance scan, the system automatically triggers an encryption policy adjustment instruction. This instruction is introduced into the state space of the encryption decision network as environmental disturbance information, guiding the network to avoid policy selections that lead to anomalies in subsequent decisions.

[0121] Through the aforementioned closed-loop feedback mechanism, the decision-making capability of the encrypted decision network continues to evolve as system operation data accumulates, achieving a fundamental shift from "static fixed strategy" to "dynamic adaptive decision-making".

[0122] Example 2 This embodiment provides a multi-scenario integrated data security and intelligent encrypted transmission system. For example... Figure 8 As shown, the system includes: The scene perception and feature extraction module is used to perform the function of the aforementioned step S1, namely, to collect multi-dimensional scene data in real time, perform semantic analysis and feature fusion on the multi-dimensional scene data, and generate a fused scene feature vector. The scene classification and identity authentication module is connected to the scene perception and feature extraction module and is used to perform the function of the aforementioned step S2, that is, to classify and identify the current data transmission scene based on the fused scene feature vector, and to dynamically match the identity authentication strategy according to the scene type identifier and perform multi-factor fusion authentication. The encryption scheme adaptive generation module is connected to the scene classification and identity authentication module and is used to perform the function of the aforementioned step S3, namely, the encryption decision network based on deep reinforcement learning, which outputs the optimal encryption scheme parameter set according to the fused scene feature vector, scene type identifier and authentication credentials. The multi-level hybrid encryption execution module is connected to the encryption scheme adaptive generation module and is used to perform the function of the aforementioned step S4, that is, to perform multi-level hybrid encryption operations, including data fragmentation preprocessing, symmetric key encryption, asymmetric key encapsulation and homomorphic encryption auxiliary calculation, on the data to be transmitted according to the optimal encryption scheme parameter set. The intelligent transmission scheduling module is connected to the multi-level hybrid encryption execution module and is used to perform the function of the aforementioned step S5, namely, to select transmission paths and perform multi-path parallel scheduling based on transmission channel priority and real-time network quality assessment results. The adaptive decryption and verification module is used to perform the functions of the aforementioned step S6, namely, after the receiving end receives the encrypted transmission message, it performs adaptive decryption, integrity verification and time domain continuity verification. The security audit and policy feedback module is connected to the above modules and is used to perform the function of step S7 mentioned above, that is, to record the security audit log of the entire data transmission process and input the feedback data into the encrypted decision network for online updating of policy parameters.

[0123] The modules mentioned above interact with each other for data and control through clearly defined module interfaces. Among them, the encryption decision network in the encryption scheme adaptive generation module is a deep reinforcement learning network that supports online learning. During system operation, this network continuously receives performance indicators and actual security effect data from the security audit and policy feedback module. Through an experience replay mechanism, it incrementally updates the policy parameters, so that the decision-making ability of the encryption scheme is continuously optimized as the operating data accumulates.

[0124] The specific implementation methods and working principles of each module of the system in this embodiment are completely consistent with the corresponding method steps in Embodiment 1, and will not be repeated here.

[0125] Example 3 This embodiment provides a computer-readable storage medium on which a computer program is stored. When executed by a processor, the computer program implements the method described in Embodiment 1.

[0126] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware associated with program instructions. The aforementioned computer program can be stored in a computer-readable storage medium, and when executed, it performs the steps of the above-described method embodiments.

[0127] The computer-readable storage medium can be any medium capable of storing data, including but not limited to: non-volatile storage media such as ROM, RAM, disk, optical disk, USB flash drive, solid-state drive (SSD); it can also include transient storage media, such as signal transmission media.

[0128] This invention provides a multi-scenario integrated data security and intelligent encrypted transmission method, system, and storage medium, possessing the following industrial practical value: First, it is applicable to the differentiated secure transmission needs of multiple industries. The scenario-adaptive mechanism of this invention allows for flexible application in multiple industries such as finance, healthcare, energy, transportation, and government affairs. Each industry can configure scenario types and authentication strategies according to its own business characteristics and security standards, without the need for repeated development of the underlying encrypted transmission system. Second, it supports secure data transmission for large-scale IoT and edge computing. This invention addresses the energy consumption and real-time constraints of IoT device communication scenarios by setting differentiated weight configurations and authentication strength adjustment mechanisms, enabling efficient operation on resource-constrained devices while ensuring basic security. Third, it provides data security protection for cloud computing and multi-party computation scenarios. The homomorphic encryption auxiliary computation layer introduced in this invention allows encrypted data to participate in aggregation computation without exposing plaintext, which is of great significance for application scenarios requiring cross-domain data aggregation, such as data sharing and federated learning in cloud environments. Fourth, it meets the regulatory requirements for compliance auditing and security traceability. The blockchain-based distributed audit ledger built into this invention provides immutable and traceable secure audit records, meeting the data security compliance requirements of fields such as finance and healthcare. In summary, this invention represents a significant technological advancement and has promising industrial application prospects.

[0129] The embodiments described herein are preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Therefore, all equivalent changes made in accordance with the structure, shape, and principle of the present invention should be covered within the scope of protection of the present invention.

Claims

1. A multi-scenario fusion data security and intelligent encryption transmission method, characterized in that, Includes the following steps: Step S1: Collect multi-dimensional scene data in real time, perform semantic analysis and feature fusion on the multi-dimensional scene data, and generate a fused scene feature vector; Step S2: Based on the fused scene feature vector, classify and identify the current data transmission scene using a scene classifier, and output a scene type identifier; dynamically match the identity authentication strategy according to the scene type identifier, perform multi-factor fusion authentication on the user identity, and generate an authentication pass credential; Step S3: Input the fused scene feature vector, the scene type identifier, and the authentication credentials into the encryption decision network based on deep reinforcement learning. The encryption decision network outputs the optimal encryption scheme parameter set. Step S4: Based on the optimal encryption scheme parameter set, perform multi-level hybrid encryption operation on the data to be transmitted. The multi-level hybrid encryption operation includes: data fragmentation and preprocessing, symmetric key encryption, asymmetric key encapsulation, and homomorphic encryption auxiliary calculation layer. Step S5: Based on the transmission channel priority in the parameter set of the optimal encryption scheme, and combined with the real-time network quality assessment results, select a transmission path or schedule multi-path parallel transmission; construct an encrypted data packet, and encapsulate the encrypted data into a unified transmission message format, wherein each encrypted data unit in the data payload adopts a chain hash link structure for integrity binding; Step S6: After receiving the encrypted transmission message, the receiving end parses the message to obtain the scenario type identifier, uses the receiving end's private key to decrypt the session key and perform symmetric decryption, performs integrity verification and time domain continuity verification through the chain hash link structure, and reassembles and outputs the original data after the verification is passed. Step S7: Record the security audit log of the entire data transmission process and store it in the distributed audit ledger; use the performance indicators and actual security effects of the transmission process as feedback data and input them into the encryption decision network for online updating of policy parameters.

2. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S1, the multi-dimensional scene data includes network environment parameters, device context parameters, data attribute feature parameters, and user behavior feature parameters; the semantic analysis and feature fusion includes: normalizing the data of each dimension, using a multimodal feature extraction network to encode the features of the data of each dimension, and then using a cross-attention fusion module to deeply fuse the feature representations output by each encoder to generate the fused scene feature vector.

3. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S2, the multi-factor fusion authentication dynamically adjusts the combination of authentication factors and the authentication intensity based on the real-time risk assessment results: when the risk score is lower than the first threshold, a single-factor authentication mode is used; when the risk score is between the first threshold and the second threshold, a two-factor authentication mode is used; and when the risk score is higher than the second threshold, a three-factor authentication mode is used. The first threshold and the second threshold are dynamically configured according to the scenario type identifier.

4. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S3, the encryption decision network includes a state space and an action space. The action space is composed of the discretized values ​​of each parameter in the optimal encryption scheme parameter set. The optimal encryption scheme parameter set includes: encryption algorithm identifier, key length, encryption mode, sharding strategy parameter, differential privacy noise parameter, and transmission channel priority. The encryption decision network makes decisions with minimizing the overall security cost as the objective function. The calculation of the overall security cost includes security risk cost, performance overhead cost, and energy consumption cost. The weight coefficients of each cost are dynamically adjusted in real time according to the fusion scenario feature vector.

5. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S4, the homomorphic encryption auxiliary computation layer generates computational ciphertext that supports ciphertext field computation. During data transmission, the intermediate node performs ciphertext field computation on the computational ciphertext without decryption. The computation result is transmitted to the receiving end in ciphertext form and then decrypted by the receiving end.

6. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S5, the multi-path parallel transmission scheduling includes: calculating path weights for each available transmission link based on the real-time network quality assessment results, and allocating data fragments with different sensitivity levels to transmission links with corresponding security levels based on the sensitivity level of the data fragmentation unit; the chained hash link structure is as follows: the integrity verification field of each data fragmentation unit contains the hash value of the previous fragmentation unit, forming a chained verification relationship.

7. The multi-scenario fusion data security and intelligent encrypted transmission method according to claim 1, characterized in that, In step S7, the distributed audit ledger is an immutable audit ledger built on blockchain technology. Audit records are written into the blockchain in the form of transactions and are persistently stored after being verified by the consensus mechanism. When a security policy deviation or abnormal behavior pattern is detected, an encryption policy adjustment instruction is automatically triggered and fed back to the encryption decision network.

8. A multi-scenario integrated data security and intelligent encrypted transmission system, characterized in that, include: The scene perception and feature extraction module is used to collect multi-dimensional scene data in real time and generate a fused scene feature vector; The scene classification and identity authentication module is connected to the scene perception and feature extraction module, and is used to classify and identify the current data transmission scene and perform multi-factor fusion authentication. An adaptive encryption scheme generation module, connected to the scene classification and identity authentication module, is used to output the optimal encryption scheme parameter set from the encryption decision network based on deep reinforcement learning. A multi-level hybrid encryption execution module, connected to the encryption scheme adaptive generation module, is used to perform multi-level hybrid encryption operations, including data fragmentation preprocessing, symmetric key encryption, asymmetric key encapsulation, and homomorphic encryption-assisted calculation, according to the optimal encryption scheme parameter set. The intelligent transmission scheduling module is connected to the multi-level hybrid encryption execution module and is used for transmission path selection and multi-path parallel scheduling. The adaptive decryption and verification module is used by the receiving end to perform adaptive decryption and integrity verification after receiving encrypted transmission messages. The security audit and policy feedback module, connected to the above modules, is used to record security audit logs throughout the data transmission process and input the feedback data into the encrypted decision network for online updates of policy parameters.

9. A multi-scenario integrated data security and intelligent encrypted transmission system according to claim 8, characterized in that, The encryption decision network in the encryption scheme adaptive generation module is a deep reinforcement learning network that supports online learning. During system operation, this network continuously receives performance indicators and actual security effect data fed back by the security audit and policy feedback module, and incrementally updates policy parameters through an experience playback mechanism.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the multi-scenario fusion data security and intelligent encrypted transmission method as described in any one of claims 1 to 7.