A communication encryption processing method based on dynamic key and ring mapping

CN122824435APending Publication Date: 2026-09-25INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610877551.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0005]有鉴于此,本发明的目的在于提供一种基于动态密钥和环形映射的通信加密处理方法,以解决通信过程中易泄密的技术问题

Benefits of technology

报文校验及重组模块,用于在所述校验标签验证通过时,按照所述任务标识、分片序号对多个所述分片报文数据信息进行排序和重组处理,以解析出明文数据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824435A_ABST
    Figure CN122824435A_ABST
Patent Text Reader

Abstract

The application provides a communication encryption processing method based on dynamic key and ring mapping, and relates to the technical field of communication security. When the method is applied to a sending end, the message data information and the service identifier of the request information of a user are received and analyzed. When it is determined that the length of the message data information is greater than a payload carrying threshold, the message data information is fragmented to obtain a set of fragmented message data information. For each fragmented message data information, a combined ciphertext is generated and obtained. When it is determined that the length of the combined ciphertext is less than or equal to the payload carrying threshold, a ring mapping area is generated. All ring mapping areas are encapsulated in a message format corresponding to the service identifier to generate a final message for transmission to a receiving end. The receiving end obtains the plaintext data transmitted by the sending end in a reverse analysis manner. The technical problem of easy leakage in the prior art is solved. The ring mapping area reduces the influence range of leakage and makes the payload distribution uniform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication security technology, and in particular to a communication encryption processing method based on dynamic keys and ring mapping. Background Technology

[0002] With the development of power communication, industrial internet and public network remote operation and maintenance scenarios, business systems need to transmit sensitive information such as topology files, configuration files, control commands, operation logs and user data in open or complex network environments, making communication security increasingly important.

[0003] Existing secure communication transmission schemes typically rely on static session keys, fixed key update cycles, or a single encrypted tunnel to protect data.

[0004] While existing technologies can provide basic confidentiality, traditional static symmetric encryption and long-term session encryption methods transmit data using a single key. During communication, the key is easily obtained when attacked by a network, leading to insecure communication. Furthermore, once the key is obtained, the fact that existing message data is written to fixed locations makes the communication data easily parsed. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a communication encryption method based on dynamic keys and ring mapping to solve the technical problem of easy leakage during communication.

[0006] In a first aspect, embodiments of the present invention provide a communication encryption processing method based on dynamic keys and ring mapping, applied at the sending end, comprising: Receive and parse user request information to obtain message data information and service identifiers for plaintext data to be transmitted; When it is determined that the length of the message data information is greater than the load carrying threshold, the message data information is fragmented to obtain a fragmented message data information set; For each fragment of packet data in the fragmented packet data set, perform the following operations: A temporary session key corresponding to the fragmented message data information is generated. The fragmented message data information is then symmetrically encrypted based on the temporary session key to obtain the data ciphertext. The temporary session key is then encapsulated using the receiving end's public key to obtain the key ciphertext. Based on the data ciphertext and key ciphertext, a combined ciphertext is generated, and when the length of each combined ciphertext is determined to be less than or equal to the load-bearing threshold, a circular mapping area is generated. According to the message format corresponding to the service identifier, all the ring mapping areas are encapsulated, and the encapsulated ring mapping areas are at least a part of the final message. Send the final message.

[0007] In conjunction with the first aspect, embodiments of the present invention provide a first possible implementation of the first aspect, wherein generating combined ciphertext for each of the data ciphertext and key ciphertext includes: The preset encryption algorithm identifier, the length value of the data ciphertext, the data ciphertext, the length value of the key ciphertext, the key ciphertext, and the preset verification tag are concatenated in sequence to generate the combined ciphertext. The preset encryption algorithm identifier is used to characterize the encryption algorithm corresponding to the combined ciphertext, and the preset verification tag is used for the integrity and authentication verification of the combined ciphertext.

[0008] In conjunction with the first aspect, this embodiment of the invention provides a second possible implementation of the first aspect, wherein the combined ciphertext includes: a fragment sequence number and a task identifier; The step of generating a combined ciphertext based on the data ciphertext and the key ciphertext, and generating a ring-shaped mapping area when the length of the combined ciphertext is determined to be less than or equal to the load-bearing threshold, includes: Generate a random number associated with the combined ciphertext, and concatenate the feedback public key fingerprint, the random number, and the task identifier and fragment sequence number of the combined ciphertext to obtain a synchronization seed; The pseudo-random generator is initialized using the synchronization seed, and the initialization result is moduloed with the load carrying threshold to determine the first offset. A circular buffer is constructed with the load-bearing threshold as its length, and the circular buffer is filled with pseudo-random bytes generated by a pseudo-random generator to generate the circular buffer. According to the preset mapping rules, the bytes of the combined ciphertext are written to the circular buffer one by one to obtain the circular mapping area.

[0009] In conjunction with the first aspect, this invention provides a third possible implementation of the first aspect, wherein, in the process of generating a combined ciphertext based on the data ciphertext and the key ciphertext, and when determining that the length of the combined ciphertext is less than or equal to the payload carrying threshold, the position of the target byte written in the circular mapping area of ​​the combined ciphertext is determined in the following manner: Based on the first target sequence number corresponding to the target byte, the offset, and the load carrying threshold, the first target remainder is obtained by modulo operation. Write the target byte to the position of the target remainder in the annular mapping area.

[0010] In conjunction with the first aspect, embodiments of the present invention provide a third possible alternative implementation of the first aspect, wherein writing the combined ciphertext byte by byte to the circular buffer includes: If the sum of the first offset and the length of the combined ciphertext is less than or equal to the load carrying threshold, then at the physical location corresponding to the first offset, the bytes of the combined ciphertext are sequentially written to the circular buffer according to the continuous writing mapping rule to obtain the circular mapping area. If the sum of the first offset and the length of the combined ciphertext is greater than the load-bearing threshold, then at the physical location corresponding to the first offset, the bytes of the first combined ciphertext are sequentially written to the circular buffer, and when it is determined that the length of the second combined ciphertext is less than or equal to the offset, the bytes of the second combined ciphertext are sequentially written to the buffer corresponding to the first offset. The first and second combined ciphertexts constitute the combined ciphertext, and the writing order of the first combined ciphertext has a higher priority than that of the second combined ciphertext.

[0011] In conjunction with the first aspect, embodiments of the present invention provide a third possible implementation of the first aspect, further comprising: If the length of the second combined ciphertext is greater than the first offset, the target fragment packet data information corresponding to the combined ciphertext is determined, and the target fragment packet data information is re-fragmented.

[0012] Secondly, embodiments of the present invention also provide a communication encryption processing method based on dynamic keys and ring mapping, applied at the receiving end, comprising: Receive and parse the protocol header of the final message to obtain the service identifier and multiple ring mapping areas; Obtain the second offset of each of the ring mapping regions, and determine the mapping relationship between the ring mapping region and the combined ciphertext corresponding to the ring mapping region based on the second offset and the load carrying threshold, so as to parse out the bytes of the combined ciphertext; Traverse each byte to determine the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext; The private key decryption function is used to parse the key ciphertext, recover the temporary session key, and the data ciphertext is decrypted using the decryption function corresponding to the temporary session key and the algorithm identifier to obtain fragmented message data information; the fragmented message data information includes: task identifier and fragment sequence number; When the verification tag passes, the data information of multiple fragmented messages is sorted and reassembled according to the task identifier and fragment sequence number in order to parse out the plaintext data.

[0013] In conjunction with the second aspect, this embodiment of the invention provides a first possible implementation of the second aspect, wherein the circular mapping region includes: a random number, a task identifier, and a fragment number; then, a second offset of each of the circular mapping regions is obtained, and based on the second offset and a payload carrying threshold, a mapping relationship between the circular mapping region and the combined ciphertext corresponding to the circular mapping region is determined, including: Retrieve the public key fingerprint, and obtain the synchronization seed based on the public key fingerprint, the random number, the task identifier, and the fragment sequence number; The pseudo-random generator is initialized using the synchronization seed, and the load-bearing threshold is moduloed based on the pseudo-random number obtained during initialization to obtain the second target remainder; Based on the second target number corresponding to the target data, the second offset, and the load bearing threshold, the third target remainder is obtained by modulo operation, and the second offset is determined based on the second target remainder; The location of the third target remainder is analyzed, and the byte corresponding to the target sequence number of the combined ciphertext is determined based on the location of the third target remainder, so as to determine the mapping relationship between the circular mapping area and the combined ciphertext corresponding to the circular mapping area. Thirdly, embodiments of the present invention also provide a communication encryption processing device based on dynamic keys and circular mapping, applied at the sending end: The acquisition and parsing module is used to receive and parse user request information in order to obtain message data information and service identifiers of plaintext data to be transmitted. The fragmentation processing module is used to fragment the message data information when it is determined that the length of the message data information is greater than the load carrying threshold, so as to obtain a fragmented message data information set. The ciphertext processing module is used to perform the following operations for each fragment of packet data information in the fragmented packet data information set: generate a temporary session key corresponding to the fragmented packet data information, perform symmetric encryption processing on the fragmented packet data information based on the temporary session key to obtain data ciphertext, and use the receiving end public key to perform public key encapsulation processing on the temporary session key to obtain key ciphertext. A ring mapping area construction module is used to generate a combined ciphertext based on the data ciphertext and the key ciphertext, and to generate a ring mapping area when the length of each combined ciphertext is less than or equal to the load carrying threshold. The message encapsulation module is used to encapsulate all the ring mapping areas according to the message format corresponding to the service identifier, and the encapsulated ring mapping area is at least a part of the final message. The message sending module is used to send the final message.

[0014] Fourthly, embodiments of the present invention also provide a communication encryption processing device based on dynamic keys and ring mapping, applied at a receiving end, comprising: The message receiving and parsing module is used to receive and parse the protocol header of the final message to obtain the service identifier and multiple ring mapping areas; the final message is sent by the sending end corresponding to the receiving end; The ring mapping area parsing module is used to obtain the second offset of each ring mapping area, and determine the mapping relationship between the ring mapping area and the combined ciphertext corresponding to the ring mapping area based on the second offset and the load carrying threshold, so as to parse out the bytes of the combined ciphertext; The data determination module is used to traverse each byte to determine the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext; The ciphertext parsing module is used to parse the key ciphertext using a private key decryption function, recover the temporary session key, and decrypt the data ciphertext using a decryption function corresponding to the temporary session key and the algorithm identifier to obtain fragmented message data information; the fragmented message data information includes: task identifier and fragment sequence number; The message verification and reassembly module is used to sort and reassemble multiple fragmented message data information according to the task identifier and fragment sequence number when the verification tag passes the verification, so as to parse out the plaintext data.

[0015] The embodiments of the present invention bring the following beneficial effects: The communication encryption processing method provided by the present invention, through a dynamic encryption traffic obfuscation method, enables each message or each fragment to have independent key protection, and performs uniform, reversible, and non-transmit-location-table-free distributed mapping of the combined ciphertext in the message payload space, thereby solving the technical problem of easy leakage during communication. At the same time, based on the existence of the ring mapping area, the message data is transmitted in an obfuscated state, which can reduce the impact range after key leakage; and the ring mapping area can adopt a load method of wrapping around the head and tail, and can also be weakly statistically analyzed in the payload space.

[0016] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained in accordance with the structures particularly pointed out in the description, claims and drawings.

[0017] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0018] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0019] Figure 1 A flowchart illustrating the application of the communication encryption processing method provided in this embodiment of the invention to the sending end; Figure 2 This is a schematic diagram illustrating the process of calculating the offset and generating the annular mapping region provided in an embodiment of the present invention; Figure 3 This is a schematic diagram illustrating the workflow of the communication encryption processing method provided in an embodiment of the present invention; Figure 4 A flowchart illustrating the application of the communication encryption processing method provided in this embodiment of the invention to the receiving end; Figure 5 A comparison chart of processing delays for different encryption processing schemes provided in embodiments of the present invention under different payload length conditions; Figure 6 A graph showing the relationship between the number of leaked keys and the proportion of exposed data provided in this embodiment of the invention; Figure 7 This is a comparison chart of load space statistical dispersion under different load scrambling methods provided in embodiments of the present invention; Figure 8 A comparison chart of detection accuracy under machine learning detection conditions for different load obfuscation methods provided in embodiments of the present invention; Figure 9 A block diagram is shown that is suitable for implementing embodiments of the present application. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Currently, communication security involves all industries. In traditional static symmetric encryption or long-term session encryption, the same session key is often reused in multiple messages, multiple file fragments, or a large amount of communication data over a period of time. Once an attacker obtains the session key through side-channel analysis, terminal penetration, key cache leakage, or other means, historical messages associated with that key may be decrypted in a concentrated manner, creating the risk of "single-point key failure leading to the exposure of a large amount of historical data." Even with periodic key updates, a large exposure window may still be formed within the update interval.

[0022] Common methods of traffic obfuscation or network steganography include fixed-position padding, fixed-field payload, and linear random insertion. Fixed-position padding causes the ciphertext to concentrate in a fixed area of ​​the packet payload, creating a clear step-like characteristic in byte distribution, entropy distribution, and variance distribution. Although linear random insertion changes the starting position, it is still prone to the boundary effect of "high in the middle area and low at both ends" at the packet boundaries, allowing attackers to identify abnormal payload locations based on the spatial distribution of the payload.

[0023] Attackers can intercept communication messages and extract features such as payload byte distribution, sliding window entropy, positional variance, and boundary sparsity. They can then train random forests, support vector machines, gradient boosting trees, or neural network classifiers to distinguish between normal business payloads and obfuscated ciphertext payloads. If the ciphertext is unevenly distributed within the message, even if the encryption algorithm itself is secure, abnormal transmission behavior may still be detected.

[0024] For real-time communication services, simply using asymmetric algorithms to encrypt the entire data packet incurs high computational overhead; periodic handshakes or frequent tunnel updates may cause sudden increases in processing latency and communication jitter. Existing solutions struggle to simultaneously achieve low latency, latency stability, control over the impact of key leakage, and statistical concealment of payload space.

[0025] Based on this, the present invention provides a communication encryption processing method based on dynamic keys and ring mapping. This method receives and parses user request information to obtain message data information and service identifiers for plaintext data to be transmitted. When the length of the message data information is determined to be greater than the payload carrying threshold, the message data information is fragmented to obtain a fragmented message data information set. For each fragmented message data information set, a temporary session key is generated. Symmetric encryption processing is performed on the fragmented message data information based on the temporary session key to obtain data ciphertext. The temporary session key is then encapsulated using the receiver's public key to obtain key ciphertext. A combined ciphertext is generated for each data ciphertext and key ciphertext. When the length of each combined ciphertext is determined to be less than or equal to the payload carrying threshold, a ring mapping area is generated. All ring mapping areas are encapsulated according to the message format corresponding to the service identifier to generate the final message for transmission to the receiver.

[0026] Understandably, by using dynamic encryption traffic obfuscation methods, each packet or fragment is protected by an independent key, and the combined ciphertext is uniformly, reversibly, and distributed in the packet payload space without the need for a transmission location table. This reduces the impact of key leakage, weakens the analytical capabilities based on payload space statistical features, and reduces the effectiveness of machine learning detection models in identifying obfuscated ciphertext payloads.

[0027] To facilitate understanding of this embodiment, a communication encryption processing method based on dynamic keys and ring mapping disclosed in this embodiment of the invention will first be described in detail.

[0028] like Figure 1 As shown, Figure 1 A flowchart illustrating the application of the communication encryption processing method provided in this embodiment of the invention to the sending end is shown. As illustrated, the method includes: Step 101: Receive and parse the user's request information to obtain the message data information and service identifier of the plaintext data to be transmitted.

[0029] It should be noted that the execution subject of the communication encryption processing method provided by the present invention can be a communication encryption processing device, or a server that is equipped with or carries a communication encryption processing device, and other devices that carry the communication encryption processing device provided by the present invention are also excluded.

[0030] Specifically, when users communicate over the network, they send plaintext information through different service formats. At this time, the plaintext information is converted into a message format. These service formats include, but are not limited to, HTTP requests. The plaintext data can be text, files, control commands, configuration data, log data, or data fragments.

[0031] Correspondingly, when the communication encryption processing device receives the request information sent by the user, it parses the user request information to obtain the message information and service identifier of the plaintext data to be transmitted. The service identifier is the corresponding service form, such as video upload service.

[0032] Step 102: When it is determined that the length of the message data information is greater than the load carrying threshold, the message data information is fragmented to obtain a fragmented message data information set.

[0033] To ensure the security of message data transmission, the method provided in this embodiment of the invention can divide message data into multiple fragmented message data by fragmentation processing, and encrypt each fragmented message data to ensure communication security.

[0034] It should be noted that the communication encryption processing device has a pre-stored payload carrying threshold, which is used to indicate the upper limit of the effective payload that can be carried during transmission.

[0035] Specifically, when the encrypted communication processing device acquires message data, if the length of the message data exceeds the payload capacity threshold, it segments the message data. The length of each segment can be determined according to a preset value. This preset value is set by those skilled in the art based on the message type and its corresponding message.

[0036] Furthermore, the encrypted communication processing device can acquire multiple fragmented message data sets. To ensure the accuracy of the plaintext data, the fragments can be tagged during fragmentation processing for subsequent reassembly by the receiving end. Optionally, the tagging can configure the fragment sequence number, total number of fragments, task identifier, and verification field for each fragment.

[0037] Understandably, when the length of the message data is less than or equal to the load capacity threshold, fragmentation is unnecessary, and the entire message data can be processed.

[0038] Step 103: For each fragment of packet data in the fragmented packet data set, perform the following operations: generate a temporary session key corresponding to the fragmented packet data; perform symmetric encryption on the fragmented packet data based on the temporary session key to obtain the data ciphertext; and use the receiving end's public key to encapsulate the temporary session key to obtain the key ciphertext.

[0039] Specifically, for each fragment of message data, a secure random number generator can be used to generate a temporary session key, which can be 128 bits, 192 bits, or 256 bits in length. Understandably, this embodiment employs a single-packet, single-key strategy.

[0040] Optionally, temporary session keys can also be generated through methods such as asymmetric key negotiation or master key derivation.

[0041] Furthermore, the fragmented message data is symmetrically encrypted using a temporary session key to generate ciphertext. The symmetric algorithm can be AES, SM4, or other block cipher algorithms that meet security requirements; preferably, an algorithm with authentication mode, such as AES-GCM or SM4-GCM, can be used.

[0042] For example, the encrypted data can be obtained using the following formula: = ( ) in, For encrypted data, For temporary session keys, For fragmented message data information, It is a symmetric encryption algorithm.

[0043] It should be noted that when the sending end processes the message data, it interacts with the receiving end to obtain the public key returned by the receiving end; and uses the public key to encapsulate the temporary session key to generate public key ciphertext.

[0044] For example, the public key ciphertext can be obtained using the following formula:

[0045] in, public key ciphertext 、 For temporary session keys, Represents public key, This represents a public-key encryption or public-key encapsulation operation. The public-key algorithm can be RSA, SM2, or other public-key encryption / encapsulation algorithms.

[0046] This invention employs an independent session key strategy for each message or fragment of data. Even if the temporary session key corresponding to a particular message is leaked, it will only affect the data of that message or fragment, and will not directly lead to the decryption of other historical message data within the same session. Compared to schemes that reuse session keys for extended periods, this invention achieves finer-grained fault isolation.

[0047] Meanwhile, this invention uses symmetric algorithms to encrypt data and public-key algorithms to encapsulate short session keys, avoiding the high overhead caused by pure asymmetric algorithms directly handling large payloads; at the same time, each message executes a fixed logical process, and the processing latency has strong determinism, making it suitable for industrial communication and power communication scenarios that are sensitive to jitter.

[0048] Step 104: Generate a combined ciphertext based on the data ciphertext and the key ciphertext, and generate a circular mapping area when the length of each combined ciphertext is less than or equal to the load carrying threshold.

[0049] To facilitate accurate parsing at the receiving end, the fields in the combined ciphertext in this embodiment are preferably field length, algorithm identifier, key ciphertext, data ciphertext, and authentication tag.

[0050] It should be noted that the communication encryption processing device pre-stores a table of preset encryption algorithms, which includes encryption algorithms and their corresponding algorithm identifiers. This allows the communication encryption processing device to select an algorithm, facilitating decryption by the receiving end based on the preset algorithm identifiers. Furthermore, the communication encryption processing device stores authentication verification, which is used to mark the ciphertext to prevent tampering during subsequent transmission without the receiving end's knowledge.

[0051] Optionally, the preset encryption algorithm identifier, the length value of the data ciphertext, the data ciphertext, the length value of the key ciphertext, the key ciphertext, and the preset verification tag are concatenated in sequence to generate a combined ciphertext; wherein, the preset encryption algorithm identifier is used to characterize the encryption algorithm corresponding to the combined ciphertext, and the preset verification tag is used for the integrity and authentication verification of the combined ciphertext.

[0052] For example, combined ciphertext can be generated using the following formula: ∥ ∥ ∥ ∥ ∥ Tag ; The symbol “∥” indicates field concatenation. This indicates the combination of ciphertext. Indicates the algorithm identifier. and Used to determine the boundaries of subsequent fields. Tag Used for integrity and authentication verification. If using a non-authenticated encryption mode, a message authentication code can also be used alone.

[0053] Furthermore, a random number related to the combined ciphertext is generated, and the public key fingerprint, the random number, and the task identifier and fragment sequence number of the combined ciphertext are concatenated to obtain a synchronization seed. The synchronization seed is used to initialize the pseudo-random generator, and the initialization result is moduloed with the payload carrying threshold to determine the first offset. A circular buffer is constructed with the payload carrying threshold as its length, and pseudo-random bytes generated by the pseudo-random generator are used to fill the circular buffer to generate the circular buffer. According to a preset mapping rule, the bytes of the combined ciphertext are written to the circular buffer one by one to obtain the circular mapping area.

[0054] It should be noted that the public key fingerprint is obtained through an interaction between the sender and its corresponding receiver. The receiver sends its public key to the sender, and the sender processes the binary raw data of the public key using a hash algorithm to obtain the public key fingerprint. Alternatively, it can be obtained by combining the receiver's certificate fingerprint, the receiver's identity identifier, and the public key hash.

[0055] Furthermore, the aforementioned generated combined ciphertext is generated from fragmented message data information, so the combined ciphertext may include fragment sequence numbers and task identifiers.

[0056] Furthermore, after obtaining the combined ciphertext, the length of the combined ciphertext needs to be compared with the payload carrying threshold. When the length of the combined ciphertext is greater than the payload carrying threshold, a ring area is constructed to transmit the combined ciphertext to the receiving end in an obfuscated manner.

[0057] Specifically, a random number is generated for the current combined ciphertext. The random number is unique within the same receiver and sender session, and its length is preferably no less than 96 bits. The random number can be carried in plaintext in the message header or in the protocol-resolvable field for the receiver to reproduce the obfuscation location.

[0058] Based on the obtained random number, a synchronization seed can be generated by concatenating the public key fingerprint, fragment sequence number, and task identifier. Alternatively, the synchronization seed can be generated using the following formula: S = H ( ∥ N ∥ ∥ seq ) The symbol “∥” indicates field concatenation. Represents a public key fingerprint. N Represents a random number. Indicates the task identifier. seq This represents the fragment number; in lightweight implementations, it can also be used... S = ⊕ N As a method of seed generation. H This represents a hash function or key derivation function, and ⊕ represents a bitwise XOR operation. (Introduction) and seq It is an optional enhancement used to further distinguish different messages in multi-fragmentation scenarios.

[0059] Based on the pseudo-random generator in the communication encryption processing device, a synchronization seed can be input into the pseudo-random generator to determine the first offset. Specifically, the first offset can be obtained by performing a modulo operation between the value of the pseudo-random generator initialized with the synchronization seed and the load-bearing threshold.

[0060] For example, the aforementioned processing procedure can be represented by the following formula:

[0061] Indicates the first offset. PRNG () represents a pseudo-random generator, and mod represents the modulo operation. This indicates the load-bearing threshold.

[0062] Compared to traditional random embedding, which requires carrying a location table or index information, easily increasing message overhead and exposing obfuscated structures, this invention only requires the sending end and its corresponding receiving end to share the algorithm rules, and through... , N , , seq The offset can be calculated using reproducible parameters, eliminating the need to include a complete location table in the message data.

[0063] Subsequently, based on the load capacity threshold, a circular buffer with the load capacity threshold as its length is constructed. Random number bytes generated by a pseudo-random generator can be used to fill each byte of the circular buffer to obtain the circular buffer. Optionally, the buffer can be filled using background bytes from a normal service load template, a random filling sequence, or a filling field permitted by the protocol.

[0064] After obtaining the circular buffer, the combined ciphertext is written into the circular buffer according to preset rules. Optionally, based on the first target sequence number, first offset, and load-bearing threshold corresponding to the target byte, the first target remainder is obtained using modulo operation; the target byte is then written to the position of the target remainder in the circular mapping area.

[0065] Specifically, the process involves traversing each byte of the combined ciphertext, taking each byte as the target byte, calculating the sum of the first target sequence number and the first offset corresponding to the target byte, and then performing a modulo operation on the calculated sum and the load carrying threshold to obtain the first target remainder. The first target remainder is then used as the write position, that is, the target byte is written to the position of the first target remainder in the circular mapping area.

[0066] For example, the above processing procedure can be illustrated by the following formula: Idx i =( +i )mod ,i=0,1,..., -1 in, Idx i Indicates the position within the circular buffer. Indicates the length of the combined ciphertext. i This indicates the sequence number corresponding to the byte in the combined ciphertext.

[0067] In summary, each byte in the combined ciphertext can be mapped to the circular buffer and written to the corresponding physical location according to the mapping relationship corresponding to the above formula.

[0068] During the writing process, the following rules must also be followed. Optionally, the rules can be: if the sum of the first offset and the length of the combined ciphertext is less than or equal to the load capacity threshold, then at the physical position corresponding to the first offset, the bytes of the combined ciphertext are written to the circular buffer sequentially according to the continuous writing mapping rule to obtain the circular mapping area; if the sum of the length of the first offset and the length of the combined ciphertext is greater than the load capacity threshold, then at the physical position corresponding to the first offset, the bytes of the first combined ciphertext are written to the circular buffer sequentially, and when it is determined that the length of the second combined ciphertext is less than or equal to the offset, the bytes of the second combined ciphertext are written to the buffer corresponding to the first offset sequentially; wherein, the first combined ciphertext and the second combined ciphertext constitute a combined ciphertext, and the writing order priority of the first combined ciphertext is higher than that of the second combined ciphertext.

[0069] Understandably, after determining the preset mapping rules, the communication encryption processing device also needs to determine whether there is enough space in the circular buffer to write the combined ciphertext under the condition of setting an offset.

[0070] In other words, when the sum of the length of the combined ciphertext and the first offset is less than or equal to the load-bearing threshold, there is enough space in the circular buffer for writing the combined ciphertext. At this time, counting starts from the beginning of the circular buffer. When the count value reaches the first offset, each byte in the combined ciphertext is continuously written from the position of the first offset.

[0071] For example, the sending end generates A circular buffer of 1500 bytes, combined ciphertext length 600 bytes PRNG Output It is 300. Because... + =9 00≤ Therefore, the combined ciphertext is written into the circular buffer from 300 to 899. An attacker cannot determine the start point of the write from the message header alone.

[0072] Conversely, if the continuous linear space from the position corresponding to the first offset to the end of the circular buffer is insufficient to completely write the combined ciphertext, then the beginning and end wrapping method needs to be used to continue writing. At this time, the first difference between the load carrying threshold and the first offset needs to be calculated, and the first difference is used as the length of the first combined ciphertext. Then, the second difference between the length of the combined ciphertext and the length of the first combined ciphertext is calculated, and the second difference is used as the length of the second combined ciphertext.

[0073] For the first ciphertext combination, following the aforementioned processing steps, the physical location corresponding to the first offset is used as the starting point for writing, and each byte of the first ciphertext combination is continuously written into the circular buffer.

[0074] For the second combination of ciphertext, it is necessary to determine whether the second difference is less than the first offset, that is, to determine whether the area corresponding to the first offset can be written into the second combination of ciphertext.

[0075] When the second difference is determined to be less than or equal to the first offset, each byte of the second combined ciphertext is continuously written to the physical location of the circular buffer corresponding to the first offset. This results in a split-bearer structure of "tail segment + header segment" in the physical linear message.

[0076] For example, the sending end generates A circular buffer of 1500 bytes, combined ciphertext length 800 bytes PRNG Output It is 1100. Because... + =1900> Therefore, the first 400 bytes of the combined ciphertext are written to positions 1100 to 1499, and the last 400 bytes are written around to positions 0 to 399. This method allows the ciphertext to span the payload tail and head, reducing the blanking characteristics at fixed boundaries.

[0077] When the second difference is greater than or equal to the first offset, it indicates that even if the buffer is wrapped around the beginning and end, the combined ciphertext cannot be written. At this time, it is necessary to determine the target fragment data information corresponding to the combined ciphertext and re-fragment the target fragment data information.

[0078] For the aforementioned processing steps, the following can be used: Figure 2 The process shown is presented. Figure 2 This is a schematic diagram illustrating the process of calculating the first offset and generating the annular mapping region provided in an embodiment of the present invention. Figure 2 The process is illustrated in the diagram where plaintext data is symmetrically encrypted to generate ciphertext, the session key is encapsulated with a public key to generate key ciphertext, and then the two are further concatenated to form combined ciphertext.

[0079] This invention utilizes a circular buffer and modular mapping to allow combined ciphertext to be written from any starting offset and automatically wraps back to the payload header when it exceeds the payload tail. This mechanism prevents ciphertext from being concentrated in fixed fields or fixed intervals for extended periods, reducing the probability of step features, boundary effects, and silent edges being identified.

[0080] Because the starting position of the combined ciphertext in the circular buffer changes with the message data information, and it can cross the beginning and end boundaries of the payload by wrapping around, the distribution of payload bytes tends to be more uniform, which increases the difficulty for attackers to classify and detect based on features such as fixed position, sliding window boundary, and payload variance.

[0081] Step 105: According to the message format corresponding to the service identifier, encapsulate all ring mapping areas. The encapsulated and processed ring mapping areas constitute at least a part of the final message.

[0082] Step 106: Send the final message.

[0083] Based on the correspondence table between service identifiers and message formats, the target message format corresponding to the service identifier is determined. The multiple ring mapping areas generated according to the aforementioned processing steps are encapsulated according to the target message format to generate the final message for transmission to the receiving end.

[0084] The final message can be carried in the payload field of TCP, UDP, HTTP, TLS, dedicated power communication protocol, industrial internet protocol or other upper-layer protocol. This invention does not limit the specific carrier protocol.

[0085] The final message can be encapsulated into an HTTP request body, TLS application data, dedicated communication payload, or other protocol data fields as needed. Ring-shaped random obfuscation operates on the payload space and does not depend on specific protocol semantics; therefore, it can be used as an independent payload space obfuscation layer in conjunction with existing secure transport protocols.

[0086] Based on this, it is possible to use Figure 3 The aforementioned processing procedure will be presented intuitively. Figure 3 This is a schematic diagram illustrating the workflow of the communication encryption processing method provided in an embodiment of the present invention. Figure 3 The example of plaintext messages that do not require fragmentation is used to illustrate this intuitively.

[0087] The embodiments provided by this invention first perform fragmentation or packet-based processing on the plaintext data to be transmitted. A temporary session key is independently generated for each packet or each fragment. Even if the temporary session key corresponding to a packet is leaked, it will only affect that packet or fragment and will not directly lead to the centralized decryption of other historical packets within the same session. Compared to schemes that reuse session keys for extended periods, this invention achieves finer-grained fault isolation. A symmetric encryption algorithm is used to obtain the ciphertext, and the temporary session key is encapsulated using the receiver's public key to form a combined ciphertext. Subsequently, a synchronization seed is generated based on the feedback public key fingerprint, the current random number, and the task identifier. A first offset is obtained through a pseudo-random generator, and the combined ciphertext is written byte-by-byte into the circular buffer using modular arithmetic to obtain a circular mapping area. Through the circular buffer and modular mapping, the combined ciphertext can be written from any first offset and automatically wraps back to the payload header when it exceeds the payload tail. This mechanism avoids the ciphertext from being concentrated in a fixed field or fixed interval for a long time, reducing the probability of step features, boundary effects, and silent edges being identified. Based on the message format corresponding to the service identifier, the ring mapping area is encapsulated. The encapsulated and processed ring mapping area is at least a part of the final message. The final message is sent to ensure the accuracy of the message data transmitted by the sending end.

[0088] Secondly, this invention uses symmetric algorithms to encrypt data and public-key algorithms to encapsulate short session keys, avoiding the high overhead caused by pure asymmetric algorithms directly handling large payloads; at the same time, each message executes a fixed logical process, and the processing latency has strong determinism, making it suitable for industrial communication and power communication scenarios that are sensitive to jitter.

[0089] Furthermore, this invention operates on the message payload space, without limiting it to a specific bearer protocol, and can be combined with existing TCP, UDP, HTTP, TLS, industrial protocols, proprietary communication protocols, or multi-protocol mimicry transmission mechanisms. Symmetric algorithms, public-key algorithms, hash functions, and... PRNG () can also be replaced according to the actual security level. At the same time, based on the fact that the starting position of the combined ciphertext in the payload space (circular buffer) changes with the message, and can cross the beginning and end boundaries of the payload by wrapping around, the payload bytes are more evenly distributed, which increases the difficulty for attackers to classify and detect based on features such as fixed position, sliding window boundary, and payload variance.

[0090] In summary, this invention avoids easy key leakage by setting a separate dynamic temporary session key for message data or message fragment data. After obtaining the combined ciphertext corresponding to the message data based on the temporary session key, the combined ciphertext is mapped to a circular buffer in an obfuscated state using a synchronization seed. The message data is then sent by encapsulating and combining the ciphertext. This method of sending message data in an obfuscated state makes the message data difficult to parse, thereby reducing the impact of leakage. At the same time, the payload method of the circular mapping area weakens the analytical capability based on the statistical features of the payload space and reduces the effectiveness of machine learning detection models in identifying obfuscated ciphertext payloads.

[0091] Reference Figure 4 , Figure 4 This is a schematic diagram illustrating the process of applying the communication encryption processing method provided in this embodiment of the invention to the receiving end. Figure 4 As shown, the method includes: Step 401: Receive and parse the protocol header of the final message to obtain the service identifier and multiple ring mapping areas.

[0092] Once the receiving end receives the final message transmitted by the sending end, the communication encryption processing device will parse the protocol header of the final message to obtain the service identifier and determine the service type based on the service identifier. Based on the message format corresponding to the service type, multiple ring mapping areas are determined to facilitate the parsing and processing of the final message.

[0093] Step 402: Obtain the second offset of each ring mapping area, and determine the mapping relationship between the ring mapping area and the corresponding combined ciphertext based on the second offset and the load carrying threshold, so as to parse out the bytes of the combined ciphertext.

[0094] Optionally, the public key fingerprint is retrieved, and a synchronization seed is obtained based on the public key fingerprint, random number, task identifier, and fragment sequence number. A pseudo-random generator is initialized using the synchronization seed, and a modulo operation is performed on the payload carrying threshold based on the pseudo-random number obtained during initialization to obtain a second target remainder. Based on the second target sequence number, second offset, and payload carrying threshold corresponding to the target data, a third target remainder is obtained using modulo operation, and the second offset is determined based on the second target remainder. The position of the third target remainder is parsed, and the byte corresponding to the target sequence number of the combined ciphertext is determined based on the position of the third target remainder, thus determining the mapping relationship between the circular mapping area and the combined ciphertext corresponding to the circular mapping area.

[0095] Specifically, the public key fingerprint of the receiving end is retrieved. The public key fingerprint acquisition process is similar to that described in the previous embodiments and will not be repeated here. The public key fingerprint corresponding to the retrieved receiving end is then used to calculate a synchronization seed based on the public key fingerprint, a random number, a task identifier, and a fragment sequence number, or by using...S = ⊕ N As a seed generation method, this calculation method is consistent with that of the sending end.

[0096] The same pseudo-random generator is initialized using a synchronously generated seed, and the calculation is performed according to the same principle as in the aforementioned embodiments. =PRNG(S)mod .in, This represents the second target remainder, i.e., the second offset.

[0097] Then, determine the mapping relationship between the circular mapping area and the corresponding combined ciphertext. Optionally, the combined ciphertext can be read in reverse as follows: = B [( + i )mod ], i=0,1,.. ., -1 in, This indicates the first part of the combined ciphertext. i bytes, that is B [] represents the annular mapping region, ( + i) mod The corresponding value represents the remainder of the third objective. The meanings of the other variables are the same as those in the previous embodiments, and will not be repeated here.

[0098] Step 403: Traverse each byte to determine the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext.

[0099] After obtaining the bytes in the combined ciphertext, based on the combined ciphertext generation principle of the aforementioned embodiments, the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext can be determined by traversal.

[0100] Step 404: Use the private key decryption function to parse the key ciphertext, recover the temporary session key, and use the decryption function corresponding to the temporary session key and the algorithm identifier to decrypt the data ciphertext to obtain the fragmented message data information; the fragmented message data information includes: task identifier and fragment sequence number.

[0101] Optionally, the private key can be used using the following formula. Decapsulation Restore session key : =

[0102] in, Represented as a private key, This represents the private key decryption function. The private key is obtained from the receiving end.

[0103] Based on this, the following formula can be used to... and decryption This allows us to obtain fragmented message data information.

[0104] =

[0105] in, This represents the encryption algorithm corresponding to the encryption algorithm identifier.

[0106] Step 405: When the verification tag passes, sort and reassemble the data information of multiple fragmented messages according to the task identifier and fragment sequence number to parse out the plaintext data.

[0107] When multiple fragmented message data are obtained, the verification tag can be used to confirm the accuracy of each fragmented message. After successful confirmation, the task identifier is used as the primary classification criterion. Then, based on the same task identifier, the fragmented message data corresponding to the fragment sequence number is sorted. This process is repeated to obtain multiple fragmented message data under different task identifiers. These fragmented message data are then reassembled according to the task identifiers to obtain the parsed plaintext data.

[0108] In this embodiment, the communication encryption processing method is applied to the receiving end. By implementing the process in the reverse order of the sending end, the obfuscated message data can be sorted and reorganized to obtain complete plaintext data, ensuring the accuracy and integrity of the reception. Understandably, the receiving end recalculates the starting offset based on the same parameters, reads the combined ciphertext from the circular mapping area according to the same circular index order, and completes key decapsulation, data decryption, and integrity verification.

[0109] In summary, the two embodiments provided by this invention, by applying the communication encryption processing method provided by this invention at the sending and receiving ends, and by sharing algorithm rules, achieve [the desired encryption]. F key , N , , seq Offsets can be calculated using reproducible parameters, eliminating the need to include a complete location table in the message and avoiding the pitfalls of traditional random methods. This approach embeds and reduces message overhead caused by carrying location tables or index information, while also avoiding the risk of exposing obfuscated structures. Through hybrid dynamic encryption of plaintext data—that is, without changing the encryption algorithm itself, but by combining "independent key protection per packet" and a "circular buffer"—the ciphertext achieves both cryptographic confidentiality and avoids being concentrated in a fixed area of ​​the payload space. This alleviates the technical problem of easy key leakage in existing technologies and improves communication security.

[0110] In one optional embodiment, the encryption method provided by the present invention can be verified through data simulation experiments, and the encryption method provided by the present invention can be compared and verified with the static AES key form.

[0111] To verify the technical effectiveness of the encrypted communication processing method based on dynamic keys and ring mapping provided in this invention in terms of communication security, real-time performance, and payload spatial concealment, a performance evaluation was conducted in a point-to-point simulated transmission environment based on a general-purpose desktop computer. The point-to-point simulated transmission environment includes a sender, a receiver, and an observable communication link. The sender is used for dynamic key generation, data encryption, public key encapsulation, ciphertext generation, and ring mapping processing of the plaintext data to be transmitted. The receiver is used for reverse reading, key decapsulation, data decryption, and integrity verification according to the same synchronization seed and mapping rules. The observable communication link is used to simulate a scenario where an attacker can intercept messages, observe the message payload spatial distribution, and extract statistical features.

[0112] In this embodiment, the simulation hardware environment uses an Intel Core i7 processor with a clock speed of 2.30GHz and 16GB of memory. The simulation software environment uses Python 3.9, calling the cryptography library to implement symmetric encryption, public key encapsulation, and decapsulation, calling the numpy library to generate background service payloads and statistical payload distribution characteristics, and calling the scikit-learn library to build a machine learning detection model based on payload space features. In the simulation, the message payload carrying threshold is set to 1500 bytes to simulate the message payload space under common Ethernet maximum transmission unit conditions. The background service payload is generated using a dynamic Gaussian distribution to simulate the random perturbation of normal service data within the byte space in power communication, industrial communication, or remote maintenance communication. During the simulation, the plaintext data to be transmitted is divided into test payloads of different lengths, and different encryption or obfuscation processing flows are input for each. For encryption performance testing, the average processing latency and fluctuation range of each scheme under different payload lengths are recorded; for key leakage impact testing, the proportion of historical data that can be recovered after different numbers of keys are obtained is recorded; for payload space statistics testing, the standard deviation of the distribution at different byte offset positions of the message is recorded; for machine learning detection testing, a random forest classifier is used to identify the message payloads generated by different obfuscation methods, and the classifier's detection accuracy is recorded. These metrics are used to measure the real-time processing capability, key leakage isolation capability, payload space uniformity distribution capability, and resistance to identification based on payload statistical features of this invention.

[0113] Figure 5 This diagram compares the processing latency of different encryption schemes provided in this invention under different payload lengths. The experiment sets up three control groups: the first is the static AES scheme, which uses a relatively fixed symmetric session key to encrypt the message payload within the same session or time window, representing traditional low-overhead symmetric encryption methods; the second is the periodic key update TLS scheme, which updates the session key through periodic handshakes or key update mechanisms, representing periodic key maintenance methods in common secure transmission protocols; the third is the block-based pure RSA scheme, which directly uses an asymmetric algorithm to encrypt larger payloads in blocks, representing methods that rely solely on public-key algorithms to process payload data. The dynamic hybrid encryption scheme of this invention serves as the experimental group, using a symmetric algorithm to encrypt message data or fragmented data, and encapsulating a temporary session key with the receiving end's public key, thus forming a combined ciphertext of "data ciphertext + key ciphertext". Figure 5As shown, as the payload length increases from 100 bytes to 1500 bytes, the static AES scheme exhibits the lowest average processing latency, maintaining a low level close to zero. However, due to the reuse of session keys, this scheme lacks leakage isolation capabilities at the single-message or single-fragment level. The periodic key update TLS scheme also has a low average processing latency, but its error range is significantly larger, indicating that it may experience sudden latency jitter during key updates or handshakes. The processing latency of the block-based pure RSA scheme continuously increases with the payload length, rising to approximately 0.18ms when the payload length approaches 1500 bytes, indicating that simply using an asymmetric algorithm to process a large payload incurs a significant computational burden. In contrast, the dynamic hybrid encryption scheme of this invention maintains a relatively stable processing latency of approximately 0.03ms across different payload lengths, significantly lower than the block-based pure RSA scheme, with smaller error fluctuations. These results demonstrate that this invention, through the method of "symmetric encryption of data + public key encapsulation of short session keys," achieves fine-grained key isolation capabilities while maintaining low and stable processing overhead.

[0114] Figure 6 This diagram illustrates the relationship between the number of leaked keys and the proportion of exposed data, as provided in this embodiment of the invention. The experiment uses a static AES key scheme as the control group and the dynamic hybrid encryption scheme of this invention as the experimental group. A static AES key scheme encrypts multiple messages using the same session key or within the same key update cycle. If this session key is obtained by an attacker, all historical messages protected by that session key may be recovered. The dynamic hybrid encryption scheme of this invention generates a temporary session key independently for each message or fragment and encapsulates this temporary session key using the receiving end's public key, ensuring that different messages or fragments do not reuse the same data encryption key for extended periods. Figure 6As shown, when the number of leaked keys is 0, the data exposure ratio of both schemes is close to 0. When the number of leaked keys in the static AES key scheme increases to 1, the data exposure ratio rapidly rises to nearly 100%. Thereafter, as the number of leaked keys continues to increase, the exposure ratio remains high, close to 100%, indicating that once a static session key is obtained, it will lead to the risk of batch exposure of historical messages within the corresponding session window. In contrast, the dynamic hybrid encryption scheme of this invention shows that as the number of leaked keys increases from 1 to 6, the data exposure ratio only increases slowly at a low level, with the curve always close to the horizontal axis. This is because each temporary session key only protects the corresponding single message data information or single fragment message data information. Even if an attacker obtains a temporary session key, they cannot use that key to decrypt other message data information or other fragment message data information. This result demonstrates that this invention can limit the impact of key leakage to the scope of a single message data information or a single fragment message data information, avoiding the problem of batch exposure of historical data caused by single-point key failure in traditional static key schemes.

[0115] Figure 7 This is a comparison chart of the statistical dispersion of payload space under different payload obfuscation methods provided in this embodiment of the invention. The experiment sets up a fixed-position filling scheme and a linear random insertion scheme as control groups, and uses the circular mapping obfuscation scheme of this invention as the experimental group. The fixed-position filling scheme refers to writing the ciphertext payload into a fixed starting position or a fixed carrying area in the message payload space. This method is simple to implement, but the ciphertext tends to concentrate in the same byte offset area for a long time. The linear random insertion scheme refers to randomly selecting the starting position for writing the ciphertext and continuously writing the ciphertext data along the linear payload space. This method can change the starting position of the ciphertext, but when the ciphertext length is large, low-carry-probability areas are still likely to appear at the beginning and end boundaries of the payload. The circular mapping obfuscation scheme of this invention generates a synchronization seed based on the public key fingerprint, random number, task identifier, and fragment sequence number, then uses a pseudo-random generator to obtain the starting offset, and writes the combined ciphertext into a circular buffer through modulo operation, so that the ciphertext automatically wraps back to the beginning of the payload when it exceeds the end of the payload. Figure 7As shown, the standard deviation of the fixed-position filling scheme remains around 75 in the initial load region, but drops rapidly to around 20 after the fixed load region, forming a distinct step-like curve. This indicates that the ciphertext load is concentrated at a fixed position, and attackers can identify the ciphertext load region through abrupt changes in the load space variance. The standard deviation curve of the linear random insertion scheme exhibits a high-in-the-middle and low-at-the-end shape, with the standard deviation approaching 40 in the middle region of the load, while the standard deviation is significantly lower at the beginning and end regions. This indicates that although linear random insertion can randomize the starting position, there is still a problem of insufficient load at the beginning and end boundaries. In contrast, the standard deviation curve of the circular mapping obfuscation scheme of this invention remains around 38 to 40 overall, without obvious step-like changes or significant drops at the beginning and end boundaries. These results demonstrate that this invention, through a circular buffer and a beginning-and-end wraparound writing mechanism, enables the combined ciphertext to form a more uniform occupancy distribution in the load space, which can weaken the fixed-position load characteristics, step characteristics, and boundary effects.

[0116] Figure 8 This is a comparison of the detection accuracy of different payload obfuscation methods provided in this embodiment of the invention under machine learning detection conditions. The experiment uses a random forest classifier as a detection model based on payload space statistical features to simulate the process by which attackers extract features such as byte distribution, local variance, boundary sparsity, and payload space dispersion from intercepted packets, and thereby identify whether there is abnormal ciphertext carried in the packet. The experiment sets three payload conditions: light payload, medium payload, and heavy payload. Light payload corresponds to approximately 300 bytes of ciphertext payload, medium payload to approximately 800 bytes, and heavy payload to approximately 1200 bytes, simulating obfuscated communication scenarios with different service data lengths. Fixed-position padding scheme, linear random insertion scheme, and the circular mapping obfuscation scheme of this invention are respectively used as three types of detected objects. Figure 8As shown, under light, medium, and heavy load conditions, the detection accuracy of the fixed-position filling scheme is approximately 99.70%, 99.30%, and 99.70%, respectively, all close to 100%, indicating that the fixed load-bearing area formed by this scheme in the load space is easily recognized by the machine learning classifier. The linear random insertion scheme has a detection accuracy of approximately 56.70% under light load conditions, increasing to approximately 71.30% under medium load conditions, and further increasing to approximately 89.30% under heavy load conditions. This indicates that as the ciphertext length increases, the effective starting space selectable by the linear writing method is compressed, and the ciphertext is more likely to concentrate in the central region of the load, with the low load-bearing characteristics of the beginning and end boundaries becoming more pronounced, thus leading to an increase in detection accuracy. In contrast, the detection accuracy of the circular mapping obfuscation scheme of this invention is approximately 51.00%, 53.70%, and 49.30% under light, medium, and heavy load conditions, respectively, all close to the level of random guessing. These results demonstrate that under machine learning detection conditions based on the statistical features of the load space, this invention can effectively reduce the classifier's ability to recognize obfuscated ciphertext loads.

[0117] comprehensive Figures 5 to 8 Simulation results show that the embodiments of the present invention, through the combined design of dynamic hybrid encryption and ring mapping obfuscation, can simultaneously achieve three technical effects: First, by generating a temporary session key independently for each message or fragment and transmitting the temporary session key using public key encapsulation, the leakage of a single key only affects the corresponding message or fragment, thereby reducing the risk of batch exposure of historical data; Second, by processing the data payload with a symmetric algorithm and encapsulating only short session keys with a public key algorithm, the high latency caused by processing large payloads with pure asymmetric algorithms is avoided, as well as the latency jitter that may be caused by periodic key update methods; Third, by using synchronization seeds, pseudo-random offsets, ring buffers, and modular operation wraparound write mechanisms, the combined ciphertext is more evenly distributed in the message payload space, reducing the step characteristics, boundary effects, and payload space anomalies present in fixed-position filling and linear random insertion schemes. Therefore, the present invention, without changing the security assumptions of the basic encryption algorithm, can balance the confidentiality of communication data, the isolation of key leakage, the stability of processing latency, and the concealment of the payload space, making it suitable for power communication, industrial internet, remote operation and maintenance of public networks, and other communication scenarios that require both security and real-time performance.

[0118] The device provided in this application embodiment has the same implementation principle and technical effect as the aforementioned method embodiment. For the sake of brevity, any parts not mentioned in the device embodiment can be referred to the corresponding content in the aforementioned method embodiment.

[0119] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0120] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0121] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0122] Figure 9 A block diagram is shown that is suitable for implementing embodiments of the present application. Figure 9 The electronic device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0123] like Figure 9As shown, the electronic device is represented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: one or more processors 410, memory 430, and communication bus 440 connecting different system components (including memory 430 and processing unit 410).

[0124] Communication bus 440 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) buses, Micro Channel Architecture (MAC) buses, Enhanced ISA buses, Video Electronics Standards Association (VESA) local buses, and Peripheral Component Interconnect (PCI) buses.

[0125] Electronic devices typically include a variety of computer-readable media. These media can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, and removable and non-removable media.

[0126] Memory 430 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The electronic device may further include other removable / non-removable, volatile / non-volatile computer system storage media. Memory 430 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this application.

[0127] A program / utility having a set (at least one) of program modules can be stored in memory 430. Such program modules include—but are not limited to—an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules typically perform the functions and / or methods described in the embodiments of this application.

[0128] Processor 410 executes various functional applications and data processing by running programs stored in memory 430, such as implementing embodiments of this application. Figure 1 The methods provided in the illustrated embodiments, and / or implementations of the embodiments of this application. Figure 4 The method provided in the illustrated embodiment.

[0129] This application provides a non-transitory computer-readable storage medium that stores computer instructions, which cause the computer to execute embodiments of this application. Figure 1 The method provided in the illustrated embodiment.

[0130] The aforementioned computer-readable storage medium may be any combination of one or more computer-readable media. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or flash memory, optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium that contains or stores a program that may be used by or in connection with an instruction execution system, apparatus, or device.

[0131] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including—but not limited to—electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of transmitting, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0132] The program code contained on a computer-readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0133] Computer program code for performing the operations of the embodiments of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0134] The foregoing has described specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0135] In the description of the embodiments of this application, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the embodiments of this application. In the embodiments of this application, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in the embodiments of this application, as well as the features of different embodiments or examples.

[0136] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of embodiments of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0137] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order according to the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0138] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0139] It should be noted that the terminals involved in the embodiments of this application may include, but are not limited to, personal computers (PCs), personal digital assistants (PDAs), wireless handheld devices, tablet computers, mobile phones, MP3 players, MP4 players, etc.

[0140] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0141] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0142] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0143] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present application should be included within the scope of protection of the present application.

Claims

1. A communication encryption processing method based on dynamic keys and ring mapping, characterized in that, Applied to the sending end, including: Receive and parse the user's request information to obtain the message data information and service identifier of the plaintext data to be transmitted; When it is determined that the length of the message data information is greater than the load carrying threshold, the message data information is fragmented to obtain a fragmented message data information set; For each fragment of packet data in the fragmented packet data set, perform the following operations: A temporary session key corresponding to the fragmented message data information is generated. The fragmented message data information is then symmetrically encrypted based on the temporary session key to obtain the data ciphertext. The temporary session key is then encapsulated using the receiving end's public key to obtain the key ciphertext. A combined ciphertext is generated based on the data ciphertext and the key ciphertext, and a circular mapping area is generated when the length of the combined ciphertext is determined to be less than or equal to the load carrying threshold. According to the message format corresponding to the service identifier, all the ring mapping areas are encapsulated, and the encapsulated ring mapping areas are at least a part of the final message. Send the final message.

2. The communication encryption processing method according to claim 1, characterized in that, The generation of combined ciphertext for each of the data ciphertext and key ciphertext includes: The preset encryption algorithm identifier, the length value of the data ciphertext, the data ciphertext, the length value of the key ciphertext, the key ciphertext, and the preset verification tag are concatenated in sequence to generate the combined ciphertext. The preset encryption algorithm identifier is used to characterize the encryption algorithm corresponding to the combined ciphertext, and the preset verification tag is used for integrity and authentication verification of the combined ciphertext.

3. The communication encryption processing method according to claim 1, characterized in that, The combined ciphertext includes: fragment sequence number and task identifier; The step of generating a combined ciphertext based on the data ciphertext and the key ciphertext, and generating a ring-shaped mapping area when the length of the combined ciphertext is determined to be less than or equal to the load-bearing threshold, includes: Generate a random number associated with the combined ciphertext, and concatenate the feedback public key fingerprint, the random number, and the task identifier and fragment sequence number of the combined ciphertext to obtain a synchronization seed; The pseudo-random generator is initialized using the synchronization seed, and the initialization result is moduloed with the load-bearing threshold to determine the first offset. A circular buffer is constructed with the load-bearing threshold as its length, and the circular buffer is filled with pseudo-random bytes generated by a pseudo-random generator to generate the circular buffer; According to the preset mapping rules, the bytes of the combined ciphertext are written to the circular buffer one by one to obtain the circular mapping area.

4. The communication encryption processing method according to claim 3, characterized in that, Based on the data ciphertext and key ciphertext, a combined ciphertext is generated. When the length of the combined ciphertext is determined to be less than or equal to the payload carrying threshold, the position of the target byte written to the combined ciphertext within the circular mapping area is determined using the following method during the generation of the circular mapping area: Based on the first target sequence number corresponding to the target byte, the first offset, and the load carrying threshold, the first target remainder is obtained by modulo operation. Write the target byte to the position of the target remainder in the annular mapping area.

5. The communication encryption processing method according to claim 3, characterized in that, Write the combined ciphertext byte by byte to the circular buffer, including: If the sum of the first offset and the length of the combined ciphertext is less than or equal to the load carrying threshold, then at the physical location corresponding to the first offset, the bytes of the combined ciphertext are sequentially written to the circular buffer according to the continuous writing mapping rule to obtain the circular mapping area. If the sum of the first offset and the length of the combined ciphertext is greater than the load carrying threshold, then at the physical location corresponding to the first offset, the bytes of the first combined ciphertext are sequentially written to the circular buffer, and when it is determined that the length of the second combined ciphertext is less than or equal to the first offset, the bytes of the second combined ciphertext are sequentially written to the buffer corresponding to the first offset. The first and second combined ciphertexts constitute the combined ciphertext, and the writing order of the first combined ciphertext has a higher priority than that of the second combined ciphertext.

6. The communication encryption processing method according to claim 5, characterized in that, Also includes: If the length of the second combined ciphertext is greater than the first offset, the target fragment packet data information corresponding to the combined ciphertext is determined, and the target fragment packet data information is re-fragmented.

7. A communication encryption processing method based on dynamic keys and ring mapping, characterized in that, Applied to the receiving end, including: Receive and parse the protocol header of the final message to obtain the service identifier and multiple ring mapping areas; Obtain the second offset of each of the ring mapping regions, and determine the mapping relationship between the ring mapping region and the combined ciphertext corresponding to the ring mapping region based on the second offset and the load carrying threshold, so as to parse out the bytes of the combined ciphertext; Traverse each byte to determine the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext; The private key decryption function is used to parse the key ciphertext, recover the temporary session key, and the data ciphertext is decrypted using the decryption function corresponding to the temporary session key and the algorithm identifier to obtain fragmented message data information; the fragmented message data information includes: task identifier and fragment sequence number; When the verification tag passes, the data information of multiple fragmented messages is sorted and reassembled according to the task identifier and fragment sequence number in order to parse out the plaintext data.

8. The communication encryption processing method according to claim 7, characterized in that, The circular mapping area includes: a random number, a task identifier, and a fragment number; then, a second offset is obtained for each of the circular mapping areas, and based on the second offset and the payload carrying threshold, the mapping relationship between the circular mapping area and the corresponding combined ciphertext is determined, including: Retrieve the public key fingerprint, and obtain the synchronization seed based on the public key fingerprint, the random number, the task identifier, and the fragment sequence number; The pseudo-random generator is initialized using the synchronization seed, and the load-bearing threshold is moduloed based on the pseudo-random number obtained during initialization to obtain the second target remainder; Based on the second target sequence number corresponding to the target data in the circular buffer, the second offset, and the load bearing threshold, the third target remainder is obtained by modulo operation, and the second offset is determined based on the second target remainder; The position of the third target remainder is analyzed, and the byte corresponding to the target sequence number of the combined ciphertext is determined based on the position of the third target remainder, so as to determine the mapping relationship between the circular mapping area and the combined ciphertext corresponding to the circular mapping area.

9. A communication encryption processing device based on dynamic keys and ring mapping, characterized in that, Applied to the sending end, including: The acquisition and parsing module is used to receive and parse user request information in order to obtain message data information and service identifiers of plaintext data to be transmitted. The fragmentation processing module is used to fragment the message data information when it is determined that the length of the message data information is greater than the load carrying threshold, so as to obtain a fragmented message data information set. The ciphertext processing module is used to perform the following operations for each fragment of packet data information in the fragmented packet data information set: generate a temporary session key corresponding to the fragmented packet data information, perform symmetric encryption processing on the fragmented packet data information based on the temporary session key to obtain data ciphertext, and use the receiving end public key to perform public key encapsulation processing on the temporary session key to obtain key ciphertext. A ring mapping area construction module is used to generate a combined ciphertext based on the data ciphertext and the key ciphertext, and to generate a ring mapping area when the length of each combined ciphertext is less than or equal to the load carrying threshold. The message encapsulation module is used to encapsulate all the ring mapping areas according to the message format corresponding to the service identifier, and the encapsulated ring mapping area is at least a part of the final message. The message sending module is used to send the final message.

10. A communication encryption processing device based on dynamic keys and ring mapping, characterized in that, Applied to the receiving end, including: The message receiving and parsing module is used to receive and parse the protocol header of the final message to obtain the service identifier and multiple ring mapping areas; the final message is sent by the sending end corresponding to the receiving end; The ring mapping area parsing module is used to obtain the second offset of each ring mapping area, and determine the mapping relationship between the ring mapping area and the combined ciphertext corresponding to the ring mapping area based on the second offset and the load carrying threshold, so as to parse out the bytes of the combined ciphertext; The data determination module is used to traverse each byte to determine the algorithm identifier, key ciphertext, data ciphertext, and verification tag of the combined ciphertext; The ciphertext parsing module is used to parse the key ciphertext using a private key decryption function, recover the temporary session key, and decrypt the data ciphertext using a decryption function corresponding to the temporary session key and the algorithm identifier to obtain fragmented message data information; the fragmented message data information includes: task identifier and fragment sequence number; The message verification and reassembly module is used to sort and reassemble multiple fragmented message data information according to the task identifier and fragment sequence number when the verification tag passes the verification, so as to parse out the plaintext data.