The invention relates to the technical field of
network security, in particular to a distributed
key management and
encryption communication method oriented to a
big data environment. The method comprises the following steps: establishing a
system architecture and configuring safety parameters; generating a
master key and a
session key through the random number; segmenting the
master key into a plurality of segments and storing the segments to different nodes; encrypting the
session key by using the public key of the
receiver, distributing the
session key through the
secure channel, and decrypting the session key by the
receiver to obtain the session key; constructing a
Merkle tree through an AES-GCM function, and introducing a
network adaptation factor into an
encryption process by considering that security requirements and
network conditions of data
encryption in different environments are different; and regularly updating a secret key, implementing an
access control strategy, and recording a log to perform
system audit so as to guarantee long-term security. According to the invention, the efficient AES-GCM encryption
algorithm is used, so that the speed and security of data encryption are improved. By implementing the
access control strategy, only the authorized user can access and operate the key, and the security of the
system is improved.