Dynamic key protection method and system based on AI context awareness

Through the dynamic key protection method of AI context-aware, combined with AI scenario recognition and key interception modules, short-term tokens are generated and sensitive call behaviors are intercepted, which solves the problem of low security in the existing technology and achieves higher security and multi-end device support.

CN120263424AActive Publication Date: 2025-07-04GUANGZHOU TAIDONG TECH CO LTD

Patent Information

Application Number
CN202510735718.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

Existing password management technology cannot effectively intercept sensitive call behavior, and there are security risks of explicit certificate leakage and memory leakage, and the security is low.

Method used

The dynamic key protection method based on AI context awareness is adopted to judge the page legitimacy through the AI scene recognition module, generate short-term tokens, and combine the key intercepting module to intercept sensitive calling behavior, including CPU execution of sensitive instructions, cryptography library function call instructions and context behavior abnormal tendency, and memory-level security monitoring and short-term token mechanism are adopted.

Benefits of technology

It realizes credential encryption and abnormal operation interception, improves the security of password management, prevents plain text leakage and screenshot attacks, supports password security management of multi-term devices, and reduces the attack surface and long-term abuse risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263424A_ABST
    Figure CN120263424A_ABST
Patent Text Reader

Abstract

The invention relates to the field of secret key data processing, in particular to a dynamic secret key protection method and system based on AI context awareness, and the method comprises the steps: firstly responding to a login credential input by a user at a platform end, then calling a preset AI scene recognition module to judge the legality of a platform end page, and if the platform end page is legal, judging whether the platform end page is legal or not; according to the method, a short-term token is generated and returned to the front end of the platform, and in the execution process of the process, the sensitive calling behavior can be recognized in real time, and a preset key interception module is called to intercept the sensitive calling behavior. Compared with the prior art, the method of the invention combines the AI technology to realize certificate encryption and abnormal operation interception, and solves the problem of low security of the existing password management technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of key data processing. More specifically, the present invention relates to a dynamic key protection method and system based on AI context awareness. Background Art

[0002] With the development of information technology, network information security has gradually attracted people's attention. In the process of enterprise employees logging in to a network platform or system using private / public accounts and keys, their password management solutions usually rely on the plugin level or a centralized Vault. Among them, the Chinese patent application with the publication number CN119249402A discloses an account management method, system, electronic device, and medium based on a browser plugin. This method relies on plugins and AI tools to achieve the secure management of user passwords. This password management solution has the following defects: It is unable to intercept sensitive call behaviors (such as screenshot behaviors or the stealing behaviors of malicious kernel information / virtual machines), and users can often directly obtain plaintext credentials, which may pose a risk of memory leakage and there are certain security hazards.

[0003] Therefore, the password management in the prior art has the problem of low security. Summary of the Invention

[0004] To solve the above technical problem of low security in password management, the present invention discloses a dynamic key protection method and system based on AI context awareness.

[0005] In a first aspect, the present invention discloses a dynamic key protection method based on AI context awareness, including: S10: In response to a user inputting a login credential at the platform end, call a preset AI scenario recognition module to determine the legitimacy of the platform end page; S20: If the platform end page is legitimate, generate a short-term token and return it to the platform front end; Wherein, in any one of steps S10 - S20, the method concurrently executes the following steps: Identify sensitive call behaviors, and call a preset key interception module to intercept the sensitive call behaviors.

[0006] Beneficial effects: After the user enters the login credentials on the platform side, if the platform-side page is legal, a short-term token is generated and returned to the platform front end to complete the login. This short-term token is not the plaintext key / credential in the prior art and can effectively prevent plaintext leakage, debugging, and screenshot attacks. On this basis, the method of the present invention can also identify sensitive call behaviors during the generation of the short-term token and perform underlying interception on sensitive call behaviors to avoid hacker attack behaviors. Compared with the prior art, the method of the present invention realizes credential encryption and abnormal operation interception, and solves the problem of low security of the existing password management technology.

[0007] Preferably, identifying sensitive call behaviors and invoking a preset key interception module to intercept sensitive call behaviors includes: Identifying whether there are CPU executing sensitive instructions, cryptographic library function call instructions, or abnormal context behavior tendencies; If so, invoking a preset key interception module to intercept the execution processes of CPU executing sensitive instructions, cryptographic library function call instructions, or abnormal context behavior tendencies.

[0008] Further, the abnormal context behavior tendency is identified by an AI scenario recognition module.

[0009] Beneficial effects: For the interception of sensitive call behaviors, the method of the present invention mainly intercepts in three directions: CPU executing sensitive instructions, cryptographic library function call instructions, and abnormal context behavior tendencies. Among them, the context behavior is identified in combination with an AI scenario recognition module, realizing the effective combination of traditional technology and AI technology, and being able to more accurately intercept sensitive call behaviors and improve the security of password management technology.

[0010] Preferably, invoking a preset AI scenario recognition module to judge the legality of the platform-side page includes: Obtaining context behavior characteristics; Encoding and fusing the context behavior characteristics to obtain a fusion result; Inputting the fusion result into a pre-trained AI scenario recognition module to output a security evaluation score; If the security evaluation score is higher than the security threshold, judge that the platform-side page is legal; If the security evaluation score is lower than the security threshold, judge that the platform-side page is illegal.

[0011] Further, the context behavior characteristics at least include environmental characteristics, user operation characteristics, timing characteristics, and device characteristics.

[0012] Beneficial effects: The method of the present invention effectively combines the multi-modal understanding characteristics of the AI scenario recognition module, can adapt to various context behavior characteristics to calculate a more accurate security evaluation score, and makes the accuracy of judging whether the platform-side page is legal higher.

[0013] Preferably, before step S10, the method of the present invention further includes: In response to the startup of the computer system, drive the virtual machine monitor to load the key interception module; Use EPT (Extended Page Table) to divide the sensitive memory area, and set the NX (Non-Executable) and UC (Uncached) attributes of the page table entries.

[0014] Furthermore, if it is captured that the virtual machine accesses the sensitive memory area, transfer the control right of the virtual machine to the security monitoring module of the virtual machine monitor.

[0015] Beneficial effects: Compared with the traditional plug-in and network-level password management, the present invention adopts security monitoring operations based on the system memory level, performs single and asymmetric encryption at the memory level, and can effectively support the password security management of multi-terminal devices.

[0016] Preferably, before step S10, the method of the present invention further includes: Configure the virtual machine monitor with instructions for capturing the virtual machine's access to the sensitive memory area; Among them, the instructions for capturing the virtual machine's access to the sensitive memory area at least include page table switching instructions, EPT invalidation instructions, field recognition instructions, EPT violation instructions, and CR register access instructions.

[0017] Preferably, after generating the short-term token and returning it to the platform front end, the method of the present invention further includes: Identify whether the short-term token has exceeded the validity period or has been used. If so, destroy the short-term token.

[0018] Beneficial effects: The short-term token of the method of the present invention automatically becomes invalid after expiration. Moreover, the corresponding token is immediately destroyed after each call, and the token is only used once. Compared with traditional long-term credentials, the short-term token reduces the attack surface while maintaining the call efficiency, providing a more secure call guarantee for sensitive operations.

[0019] In a second aspect, the present invention discloses a dynamic key protection system based on AI context awareness. The system includes a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, the dynamic key protection method based on AI context awareness described in the first aspect of the present invention is implemented.

[0020] The beneficial effects of the present invention are as follows: (1) Compared with the prior art, the method of the present invention realizes credential encryption and abnormal operation interception, and solves the problem of low security of existing password management technologies.

[0021] (2) Compared with the prior art, for intercepting sensitive call behaviors, the method of the present invention mainly intercepts in three directions: the CPU executes sensitive instructions, the cryptographic library function call instructions, and the abnormal tendency of context behaviors. Among them, the context behaviors are identified in combination with the AI scenario recognition module, realizing the effective combination of traditional technology and AI technology, and being able to more accurately intercept sensitive call behaviors and improve the security of password management technology.

[0022] (3) Compared with the prior art and compared with traditional plug-in and network-level password management, the present invention adopts security monitoring operations based on the system memory level, performs single and asymmetric encryption at the memory level, and can effectively support the password security management of multi-terminal devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a flowchart of the dynamic key protection method based on AI context awareness in the first embodiment of the method of the present invention; Figure 2 is a schematic diagram of the dynamic key protection system based on AI context awareness in the third embodiment of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present invention.

[0025] Next, the specific implementation manners of the present invention will be described in detail with reference to the accompanying drawings.

[0026] Embodiment 1 As Figure 1 shown, this embodiment discloses a dynamic key protection method based on AI context awareness, including: S10: In response to the user inputting login credentials on the platform side, call the preset AI scenario recognition module to judge the legality of the platform side page.

[0027] In this embodiment, the above login credentials mainly refer to the user's account and password for logging in to the platform side. The platform side can be any one of WeChat, Taobao, JD.com, or the system internal management system. The AI scenario recognition module adopts a deep learning model, which can be a deep learning model based on the Transformer or lightweight CNN framework.

[0028] In other embodiments, the AI scenario recognition module can also be replaced with a module that combines a lightweight rule engine and AI.

[0029] S20: If the platform-side page is legal, generate a short-term token and return it to the platform front-end.

[0030] In this embodiment, the above short-term token refers to an authentication token Token.

[0031] Among them, in any one of steps S10 - S20, the method of this embodiment executes the following steps in parallel: Identify sensitive call behaviors, and call a preset key interception module to intercept sensitive call behaviors.

[0032] Through the above technical solution, after the user inputs login credentials (account and password) on the platform side, if the platform-side page is legal, a short-term token is generated and returned to the platform front-end to complete the login. Compared with the prior art, this short-term token is not a plaintext key / credential and cannot be directly obtained by the user. Such a short-term token can effectively prevent plaintext leakage, debugging, and screenshot attacks. In addition, during the process of generating the short-term token, the method of this embodiment can also identify sensitive call behaviors and perform underlying interception on sensitive call behaviors.

[0033] Compared with the prior art, the method of this embodiment realizes credential encryption and abnormal operation interception, and solves the problem of low security of existing password management technologies.

[0034] Further, identifying sensitive call behaviors and calling a preset key interception module to intercept sensitive call behaviors in the above steps includes: Identify whether there are CPU execution of sensitive instructions, cryptographic library function call instructions, or abnormal context behavior tendencies.

[0035] If so, call a preset key interception module to intercept the execution processes of CPU execution of sensitive instructions, cryptographic library function call instructions, or abnormal context behavior tendencies.

[0036] Specifically, the abnormal context behavior tendency is identified by an AI scenario recognition module. The above key interception module adopts a hierarchical architecture design, and it designs a three-level interception architecture to achieve full-link monitoring of sensitive operations, which are: Hardware layer interception: Capture sensitive instructions (such as the memory operation instruction MOV[CR3], RAX) through CPU virtualization extensions (such as the VMX operation of Intel VT-x), and trigger a VMExit event.

[0037] System call layer interception: Replace the system call table of the guest machine at the Hypervisor layer, and redirect password-related APIs (such as CryptAcquireContext) to the security module.

[0038] Behavior analysis layer interception: The AI scenario recognition module analyzes the virtual machine process behavior sequence in real time to identify abnormal key call patterns (such as batch exporting keys outside working hours).

[0039] Exemplarily, the sensitive discrimination operations based on the three-level interception architecture are shown in Table 1: Table 1

[0040] It should be noted that the above Table 1 is only for exemplary illustration, and in specific application scenarios, the above exemplary features can be adjusted adaptively.

[0041] Through the above technical solutions and the architecture design of the key interception module, the method of this embodiment realizes effective interception in three directions: CPU executing sensitive instructions, calling instructions of cryptographic library functions, and abnormal tendency of context behavior by combining AI technology, can intercept sensitive call behaviors more accurately, and further improves the security of password management.

[0042] Preferably, in order to configure a good operating environment for the key interception module, before this step S10, the method of this embodiment further includes: S100: In response to the startup of the computer system, drive the virtual machine monitor (Hypervisor) to load the key interception module.

[0043] In this embodiment, in the computer system kernel driver or virtualization monitoring layer, all password / key loading and calling operations are intercepted into the secure area and protected by hardware-accelerated AES-GCM or TEE (such as Intel SGX) symmetric encryption.

[0044] S200: Use EPT to divide the sensitive memory area and set the NX and UC attributes of the page table entries.

[0045] In addition to the configurations of the above steps S100 - S200, the configuration process of the method of this embodiment further includes: S300: Configure the virtual machine monitor to capture instructions for the virtual machine to access the sensitive memory area.

[0046] Among them, the instructions for the virtual machine to access the sensitive memory area to be captured at least include page table switching instructions, EPT invalidation instructions, field identification instructions, EPT violation instructions, and CR register access instructions.

[0047] Specifically, set an exception interception flag in the VMCS (Virtual Machine Control Structure) to monitor privileged instructions such as MOV CR3 (page table switching), INVEPT (EPT invalidation), etc.

[0048] Identify the instruction type through the VMX_EXIT_REASON field, for example: VM_EXIT_REASON_EPT_VIOLATION (EPT violation); VM_EXIT_REASON_CR_ACCESS (CR register access).

[0049] Furthermore, if the virtual machine is detected accessing a sensitive memory area, the control of the virtual machine will be transferred to the security monitoring module of the virtual machine monitor.

[0050] Through the above design, the Hypervisor ensures the security of each virtual machine through memory isolation. For example, Hyper-V manages the physical memory of partitions through EPT, allowing non-privileged partitions to only access their own memory. Any out-of-bounds access will trigger a VMExit, and the Hypervisor can intercept and handle the exception. In addition, the Hypervisor can also replace the system call table or key APIs of the guest operating system and switch the execution to the secure path controlled by the Hypervisor when calling cryptographic operations. To implement security monitoring in the Hypervisor, memory pages to be protected can be marked when the virtual machine is loaded, and unauthorized modification of the page table can be prevented.

[0051] Therefore, the Hypervisor realizes deep security intervention in the virtualization layer, with the functions of transparently intercepting sensitive calls, isolating memory spaces, and encrypting data transmission, and can ensure that malicious kernels or virtual machine escapes cannot steal keys.

[0052] In other embodiments, the above method can also be extended to the container / Serverless environment to achieve cloud-native key protection.

[0053] Furthermore, during the key transmission and storage process, in order to always encrypt sensitive data. This method uses symmetric algorithms such as AES-GCM to encrypt passwords / keys at the Hypervisor layer, and the encryption key can be stored in a TEE (Trusted Execution Environment) or secure hardware. When the host operating system or the Hypervisor accesses the virtual machine memory, only the encrypted data can be seen, and the plaintext cannot be obtained. The plaintext of the key only exists in the transient state of the CPU register. For example, it is loaded into the register when calling a critical instruction and immediately cleared or encrypted and stored after processing. Similar to the AMD SEV-ES technology, the content of the CPU register is encrypted when the virtual machine pauses, further ensuring that the plaintext of the key will not be leaked in the memory. Even if the hypervisor has permissions, only the encrypted ciphertext can be accessed.

[0054] Compared with the prior art, the present invention adopts a security monitoring operation based on the system memory hierarchy, performs single and asymmetric encryption at the memory level, and can effectively support the password security management of multi-terminal devices. The method of this embodiment has higher sensitivity and stronger security for sensitive call behaviors.

[0055] Furthermore, after generating the short-term token and returning it to the platform front-end in step S20, the method of this embodiment further includes: Identifying whether the short-term token has exceeded the validity period or has been used, and if so, destroying the short-term token.

[0056] Through the above technical solution, after verifying the call legality, the method of this embodiment uses the short-term session token to replace the plaintext key for subsequent access. The token has a built-in validity period (configurable, such as 60 seconds or 5 minutes), and it will automatically expire without additional operations. The setting of the validity period takes into account both security and practicality, significantly reducing the risk of long-term abuse of the key. The token automatically expires after expiration, and the corresponding token is immediately destroyed after each call is completed. The token is only used once. By monitoring the token usage in real time, for detected abnormal behaviors (such as token replay or cross-application use), the relevant tokens are immediately revoked and an alarm is issued. Compared with traditional long-term credentials, the short-term token reduces the attack surface while maintaining the call efficiency, providing a more secure call guarantee for sensitive operations.

[0057] Exemplarily, the generation logic of the short-term token of the method of this embodiment is as follows: 1. Data binding: Bind the token to the domain name of the current session (such as api.payment.com) and the operation type (only decryption). 2. Signature mechanism: Use the Hypervisor root key to perform HMAC-SHA256 signature on the token to generate an immutable string. Token = HMAC(SecretKey, UserID+Timestamp+Domain); 3. Validity period control: Embed a timestamp in the short-term token (such as a validity period of 60 seconds), and the revocation mechanism is automatically triggered after expiration.

[0058] It should be further explained that in this embodiment, the short-term token generation includes a key ID, a generation timestamp, and a random number, and a master key is used for digital signature (or HMAC) to ensure integrity. Each short-term token is bound to a specific access context, including the allowed domain name / application identifier and operation permissions (such as read-only, decryption, etc.). The signature and binding policies can ensure that the token can only be used in the specified environment and cannot be exported. The method of this embodiment verifies the token legality within the Hypervisor or TEE, thereby achieving refined access control.

[0059] Furthermore, to facilitate auditing and log analysis, all token acquisition and usage operations are recorded in the security log. Combined with the intelligent log analysis module, abnormal behaviors (such as unexpected process access or abnormal frequency) are detected in real time and alarms are triggered.

[0060] Based on the above technical description, the method of this embodiment has at least the following beneficial effects: 1. Imperceptible interception is achieved at the Hypervisor layer. The key is stored in encrypted form throughout the process and is only briefly displayed in plain text in the CPU decryption register.

[0061] 2. When an attacker bypasses system call interception through ROP chain, EPT violation detection at the hardware layer can intercept illegal memory access for a second time.

[0062] 3. Short-term tokens have an anti-replay mechanism. Each short-term token contains a random number Nonce and a session chain hash, which can prevent cross-session replay.

[0063] 4. Comprehensive encryption protection at the memory level is achieved, and the plaintext credentials are only briefly decrypted in the CPU register, which can effectively prevent any form of memory leakage.

[0064] 5. A short-term token mechanism is used to replace static passwords / API Keys. The short-term token has a short life cycle and its scope of use can be finely controlled.

[0065] 6. End-to-end auditing and protection are realized, forming a closed loop from call interception, scenario identification to token management and log analysis, providing full-process security protection.

[0066] Embodiment 2 Based on the first embodiment, this embodiment is mainly optimized for AI scene recognition. This embodiment discloses a dynamic key protection method based on AI context perception, in which a preset AI scene recognition module is called to judge the legitimacy of the platform-side page, including: S11: Obtain contextual behavior features.

[0067] The above-mentioned contextual behavior characteristics at least include environmental characteristics, user operation characteristics, timing characteristics and device characteristics.

[0068] More specifically, the following is an exemplary description of contextual behavior features: Environmental characteristics: current window title (such as "Payment Platform-Login"), process path (C:\Program Files\Browser\chrome.exe).

[0069] Operational characteristics: API call sequence (CryptGenRandom→CryptProtectData).

[0070] Temporal features: operating frequency (e.g., 5 key requests per second trigger risk control).

[0071] Device features: hardware fingerprint (TPM chip serial number), network environment (IP geographical location), facial features or multi-factor linkage authentication features.

[0072] Specifically, in the process of obtaining context behavior features, machine learning is used to intelligently perceive the current call environment, and the input features include but are not limited to the active window name, process name and parent process information, the UI element hierarchy of the active window (such as control type, input box identifier, button position, etc.), the current web page URL and network access features, etc. Referring to context-aware authentication, the security and convenience can be improved by fusing environment and operation context information. For example, when the user enters a password on the payment page, the browser window URL and UI structure provide a legitimacy prompt; while when a non-browser or unknown window requests a key, it can be regarded as an abnormal context to raise vigilance.

[0073] S12: Encode and fuse the context behavior features to obtain a fusion result.

[0074] Specifically, to balance real-time performance and effect, the AI scenario recognition module of the present invention selects a lightweight neural network model, such as a streamlined Transformer or a small convolutional neural network (CNN). The AI scenario recognition module first encodes discrete text features (such as window name, URL, process name) and fuses them with structured numerical features (such as network data statistics). For the UI hierarchy, graph embedding methods or interface screenshots can be used as inputs. And features are extracted through CNN. The Transformer architecture weights and fuses each feature through the self-attention mechanism to generate a context-aware representation vector. For resource-constrained scenarios, techniques such as knowledge distillation and pruning can be introduced to further compress the scale of the AI model so that it can run efficiently on edge devices or in secure containers.

[0075] S13: Input the fusion result into a pre-trained AI scenario recognition module to output a security evaluation score.

[0076] S14: If the security evaluation score is higher than the security threshold, determine that the platform-side page is legal.

[0077] S15: If the security evaluation score is lower than the security threshold, determine that the platform-side page is illegal.

[0078] Through the above technical solution, the trained model outputs a security assessment score based on the input fusion result to comprehensively judge the legality and risk level of the current password call request, and then triggers different policies according to the prediction result. When the score is higher than the security threshold, a temporary access token is issued; when it is lower than the security threshold, the request is rejected and an alarm is triggered or multi-factor authentication is initiated. Context-aware authentication can significantly improve the system's adaptability and reliability. In addition, the system relying on the method of this embodiment can continuously monitor the user's behavior during operation and perform online fine-tuning of the model or dynamically adjust the threshold based on newly collected samples, thereby further improving the detection accuracy.

[0079] Through real-time AI decision-making and policy switching, the method of this embodiment realizes intelligent access control. Compared with the prior art, the method of this embodiment does not require manual configuration of rules and can automatically identify diverse usage scenarios through a deep learning model, which can reduce misjudgment and operation and maintenance costs.

[0080] Preferably, the method of this embodiment can also adapt to the AI model update mechanism and incrementally train according to the new scenario to improve the recognition accuracy.

[0081] Embodiment III As Figure 2 shown, this embodiment discloses a dynamic key protection system based on AI context awareness. The system includes a processor and a memory, and the memory stores computer program instructions. When the computer program instructions are executed by the processor, the dynamic key protection method based on AI context awareness described in Embodiment I or Embodiment II is implemented.

[0082] Although this specification has shown and described multiple embodiments of the present invention, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Those skilled in the art will think of many changes, alterations, and alternative ways without departing from the spirit and scope of the present invention. It should be understood that various alternative solutions to the embodiments of the present invention described herein can be adopted in the practice of the present invention.

Claims

1. A dynamic key protection method based on AI context awareness, characterized in that, Including: S10: In response to a user entering login credentials on the platform side, call a preset AI scenario recognition module to determine the legitimacy of the platform-side page; S20: If the platform-side page is legitimate, generate a short-term token and return it to the platform front end; Wherein, in any one of steps S10 - S20, the method concurrently executes the following steps: Identify sensitive call behaviors, and call a preset key interception module to intercept the sensitive call behaviors.

2. The dynamic key protection method based on AI context awareness according to claim 1, characterized in that Identifying sensitive call behaviors and calling a preset key interception module to intercept the sensitive call behaviors includes: Identify whether there are CPU executing sensitive instructions, cryptographic library function call instructions, or a tendency of abnormal context behaviors; If so, call a preset key interception module to intercept the execution processes of CPU executing sensitive instructions, cryptographic library function call instructions, or a tendency of abnormal context behaviors.

3. The dynamic key protection method based on AI context awareness according to claim 2, wherein The tendency of abnormal context behaviors is identified by the AI scenario recognition module.

4. The dynamic key protection method based on AI context awareness according to claim 3, wherein Calling a preset AI scenario recognition module to determine the legitimacy of the platform-side page includes: Obtain context behavior characteristics; Encode and fuse the context behavior characteristics to obtain a fusion result; Input the fusion result into a pre-trained AI scenario recognition module to output a security evaluation score; If the security evaluation score is higher than the security threshold, determine that the platform-side page is legitimate; If the security evaluation score is lower than the security threshold, determine that the platform-side page is illegitimate.

5. The dynamic key protection method based on AI context awareness according to claim 4, wherein The context behavior characteristics at least include environmental characteristics, user operation characteristics, timing characteristics, and device characteristics.

6. The dynamic key protection method based on AI context awareness according to claim 1, characterized in that Before step S10, the method further includes: In response to the startup of the computer system, drive the virtual machine monitor to load the key interception module; Use EPT to divide the sensitive memory area and set the NX and UC attributes of the page table entry.

7. The dynamic key protection method based on AI context awareness according to claim 6, characterized in that If it is captured that the virtual machine accesses the sensitive memory area, transfer the control right of the virtual machine to the security monitoring module of the virtual machine monitor.

8. The dynamic key protection method based on AI context awareness according to claim 6, wherein Before step S10, the method further includes: Configure the virtual machine monitor with instructions for capturing the virtual machine's access to the sensitive memory area; Wherein, the instructions for capturing the virtual machine's access to the sensitive memory area at least include page table switching instructions, EPT invalidation instructions, field identification instructions, EPT violation instructions, and CR register access instructions.

9. The dynamic key protection method based on AI context awareness according to claim 1, wherein After generating the short-term token and returning it to the platform front end, the method further includes: Identify whether the short-term token has exceeded the validity period or has been used. If so, destroy the short-term token.

10. A dynamic key protection system based on AI context awareness, characterized in that, Including a processor and a memory, the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the dynamic key protection method based on AI context awareness according to any one of claims 1 - 9 is implemented.

Citation Information

Patent Citations

  • Immediate access conferring method aiming at low interference of mobile platform

    CN103116716A

  • Virtual hardware characteristic-based system and method for efficiently isolating kernel modules

    CN106203082A

  • H5 non-login user session tracking method

    CN110933078A

  • Certificate-based digital signature system and method

    CN116881981A

  • Linux malicious code detection method and system based on virtual machine introspection

    CN117725583A

Cited By

  • Artificial intelligence agent method and system for login

    CN122226466A