Dynamic collaborative access credential security management method and system

By establishing a baseline model of security credentials and real-time dynamic behavior analysis, combined with external management events, automated and closed-loop management of security credentials is achieved, solving the problems of module isolation and delayed response in existing technologies, improving security and permission management efficiency, and reducing business impact.

CN120785648APending Publication Date: 2025-10-14SHENZHEN SNOWBALL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511227591.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

In existing technologies, the security credential management system has isolated modules, delayed responses, and lacks automated closed-loop management capabilities. It is unable to effectively integrate real-time behavioral risk assessments with external management events, resulting in delays in permission management and security risks.

Method used

By establishing a baseline model of security credentials, analyzing their behavior in real time and generating risk indicators, automatically executing restrictive security policies corresponding to the risk indicators, and responding to external management events, we can achieve automated, closed-loop management of security credentials. We use a neural network model based on long-short-term memory networks and attention mechanisms for dynamic behavior analysis, and combine the API core gateway and sidecar agent for policy execution.

Benefits of technology

It achieves coordinated in-depth defense of security modules, improves security and intelligence levels, responds to external management events in seconds, reduces the false positive rate and business impact, and ensures system availability and permission management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785648A_ABST
    Figure CN120785648A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic collaborative access credential security management method and system, belongs to the technical field of network security, and aims to solve the problems of isolation and response lag of a security credential management module. The method comprises the following steps: establishing a normal use behavior baseline model of the security credential; analyzing the current use behavior in real time to generate a risk index; in response to the risk index meeting the risk condition or receiving an external management event, automatically executing a corresponding security policy; after the restrictive strategy is executed, when the risk meets the recovery condition, the restriction is automatically released. Through linkage behavior analysis, permission configuration and gateway management and control, cooperative defense is realized, the security and management efficiency are improved, and the service influence is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a security credential management method and system based on dynamic behavior analysis and event linkage. Background Art

[0002] In modern information technology architectures, such as IoT cloud platforms and large-scale distributed systems, security credentials, such as access keys, are critical elements for authentication and authorization when applications or services make interface calls. Existing methods for managing security credentials are mostly static, for example, hard-coding credential information in device or application configuration files. This static approach carries significant security risks. First, once hard-coded credentials are leaked, attackers can exploit them for unauthorized access. Furthermore, the credential tracking and replacement process is complex, easily creating persistent security vulnerabilities. Second, when employees leave or change positions, if their credential permissions are not promptly and accurately revoked, they can become potential attack vectors and pose a threat to system security. Furthermore, traditional authentication mechanisms typically only verify the format and signature validity of the credentials themselves and are unable to identify anomalous calls made when legitimate credentials have been misused, such as calls initiated at unusual times or locations, or calls executed to perform high-risk, sensitive operations outside of normal usage.

[0003] To address these shortcomings, several dynamic access control methods based on user behavior pattern analysis have emerged in the prior art. These methods analyze historical user access behavior data to establish a behavioral baseline. They then monitor the deviation of current access behavior from this baseline in real time. When anomalies are detected, access control policies are dynamically adjusted to provide defensive measures. However, these solutions still have shortcomings. First, they primarily focus on real-time behavioral risks and fail to effectively integrate with internal enterprise management processes, such as external events like employee status changes in human resources systems. This leads to delays and blind spots in permission lifecycle management, and fails to fundamentally address security risks arising from management events like personnel changes. Second, when the system detects a risk and implements restrictive policies such as service circuit breaking, manual intervention, review, and action are often required to restore service. This lack of automated closed-loop management and self-healing capabilities not only affects system availability but also increases the complexity and cost of operations and maintenance. Consequently, existing security modules such as risk monitoring, permission management, and traffic control often operate as independent "security islands," lacking the ability to collaborate and collaborate, making it difficult to form a unified and efficient defense-in-depth system. Summary of the Invention

[0004] The purpose of this application is to provide a security credential management method and system based on dynamic behavior analysis and event linkage, aiming to solve the technical problems in the existing technology of the security credential management system, such as the isolation of various modules, delayed response, and lack of automated closed-loop management capabilities, so as to build a unified framework that can integrate real-time behavioral risk assessment and external management events, and realize automated and closed-loop management of security credentials.

[0005] To achieve the above objectives, the present application provides a dynamic collaborative access credential security management method, which includes:

[0006] Obtaining a target security credential, and establishing a baseline model of its usage behavior based on the target security credential;

[0007] Analyze the current usage behavior of the security credential in real time, and generate a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model;

[0008] In response to the risk indicator satisfying a preset risk condition, automatically executing a preset restrictive security policy corresponding to the risk indicator;

[0009] In response to receiving a preset external management event, automatically executing a preset security policy corresponding to the external management event;

[0010] After the restrictive security policy is executed, when the risk indicator of the security credential meets a preset restoration condition, the restrictive security policy is automatically lifted.

[0011] Furthermore, the baseline model includes:

[0012] At least one of the commonly used time, commonly used geographical location, call frequency, and commonly used application programming interface (API) set of the security credential.

[0013] Furthermore, the real-time analysis of the current usage behavior of the security credential and the generation of a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model include:

[0014] Using a neural network model based on a long short-term memory network and an attention mechanism, analyzing the current usage behavior of the security credential in real time to obtain a first analysis result;

[0015] Based on the comparison result of the first analysis result and the baseline model, a risk indicator for characterizing the abnormality degree of the current usage behavior is generated.

[0016] Furthermore, in response to the risk indicator satisfying a preset risk condition, automatically executing a preset restrictive security policy corresponding to the risk indicator includes:

[0017] When the risk indicator reaches a first risk threshold, triggering a secondary verification or access throttling strategy;

[0018] When the risk indicator reaches a second risk threshold that is higher than the first risk threshold, triggering an authority downgrade or audit enhancement policy;

[0019] When the risk indicator reaches a third risk threshold that is higher than the second risk threshold, a service fuse policy is triggered.

[0020] Furthermore, the external management event includes: an employee resignation event from a human resources system, or a project closing event from a project management system.

[0021] Furthermore, the preset recovery condition is that the risk indicator is continuously lower than a preset safety threshold within a preset time period.

[0022] Furthermore, the execution of the restrictive security policy and the lifting of the restrictive security policy are performed by the API core gateway deployed at the system entrance.

[0023] Furthermore, the execution of the restrictive security policy and the lifting of the restrictive security policy are performed by a distributed policy enforcement point deployed in the microservice architecture as a sidecar agent.

[0024] To achieve the above objectives, the present application provides a dynamic collaborative access credential security management system, which is applied to any of the above-mentioned dynamic collaborative access credential security management methods, including:

[0025] A baseline model building unit is used to build a baseline model of normal usage behavior for a target security credential;

[0026] a risk indicator generating unit, configured to analyze the current usage behavior of the security credential in real time and generate a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model;

[0027] a first policy execution unit, configured to automatically execute a preset restrictive security policy corresponding to the risk indicator in response to the risk indicator satisfying a preset risk condition;

[0028] a second policy execution unit, configured to automatically execute a preset security policy corresponding to a preset external management event in response to receiving the preset external management event;

[0029] A policy releasing unit is configured to automatically release the restrictive security policy after the restrictive security policy is executed when the risk indicator of the security credential meets a preset restoration condition.

[0030] Compared with the existing technology, the technical solution provided by this application has the following beneficial effects:

[0031] 1. It achieves collaborative defense-in-depth, organically linking multiple security modules such as dynamic behavior analysis, automated permission configuration, and gateway management, breaking the "security island" state of traditional security components operating independently and forming a closed-loop, collaborative defense system from pre-emptive prevention, in-process monitoring to post-event disposal and recovery.

[0032] 2. Improved security and intelligence levels. By introducing a neural network-based behavioral analysis engine, it has achieved a shift from static credential verification to dynamic behavioral pattern recognition, enabling more accurate identification of unknown and abnormal attack behaviors.

[0033] 3. Significantly improved the efficiency of permission management. By responding to external management events, it achieves automatic recovery of permissions in seconds in scenarios such as resignation and project closure, solving the problem of delayed response in traditional manual processing and reducing the security risks caused by poor permission management.

[0034] 4. Reduced business impact and false positive rate. The hierarchical disposal and automatic self-healing mechanism based on refined risk scoring can more accurately locate and block malicious requests compared to traditional extensive management and control strategies, and automatically restore services after the risk is eliminated, minimizing the impact on normal business and ensuring system availability.

[0035] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0037] Figure 1 This is a flowchart of a security credential management method based on dynamic behavior analysis and event linkage provided by an embodiment of the present application;

[0038] Figure 2 This is a schematic diagram of the composition of a security credential management system based on dynamic behavior analysis and event linkage provided by an embodiment of the present application. DETAILED DESCRIPTION

[0039] In order to better understand the technical solution of the present application, the technical solution in the embodiment of the present application will be clearly and completely described below in conjunction with the drawings in the embodiment of the present application. It should be noted that the specific embodiments described here are only used to explain the present application and do not constitute a limitation on the scope of protection of the present application.

[0040] For specific implementation, please refer to Figure 1 , Figure 1 This is a flow chart of a security credential management method based on dynamic behavior analysis and event linkage provided by an embodiment of the present application, the method comprising:

[0041] S1. Obtain a target security credential and establish a baseline model of its usage behavior based on the target security credential;

[0042] S2. Analyze the current usage behavior of the security credential in real time and generate a risk indicator based on the baseline model to characterize the degree of abnormality of the current usage behavior;

[0043] S3. In response to the risk indicator meeting the preset risk condition, automatically executing the preset restrictive security policy corresponding to the risk indicator;

[0044] S4. In response to receiving a preset external management event, automatically executing a preset security policy corresponding to the external management event;

[0045] S5. After the restrictive security policy is executed, when the risk indicator of the security credential meets a preset restoration condition, the restrictive security policy is automatically lifted.

[0046] In specific implementation, as described in step S1, the target security credentials in this application include: an access key; the baseline model includes:

[0047] At least one of the commonly used time, commonly used geographical location, call frequency, and commonly used application programming interface (API) set of the security credential.

[0048] More specifically, establishing a baseline model of target security credential usage behavior mainly includes the following steps:

[0049] 1. Data collection: Collect historical usage behavior data of the target credential over a period of time, including call time, initiation location (mapped to regional information), call frequency, target API interface, and other dimensions.

[0050] 2. Baseline determination: Through statistical analysis and filtering of abnormal data such as temporary testing and network fluctuations, the normal usage behavior characteristics of the credential are determined and a baseline model is formed. Specifically, the following are included:

[0051] Common usage time (e.g., daily business operation time, no nighttime call records);

[0052] Common geographic locations (such as IP segments in specific regions, with no overseas call records);

[0053] Regular call frequency (no sudden high-frequency call records);

[0054] Commonly used API collection (only business-related interfaces, no high-authority management interface call records).

[0055] 3. Model storage: Associate the baseline model with the unique identifier of the target credential and store it in the system's "credential behavior baseline library."

[0056] In a specific implementation, as described in step S2, the method includes: using a neural network model based on a long short-term memory network and an attention mechanism to analyze the current usage behavior of the security credential in real time to obtain a first analysis result;

[0057] Based on the comparison result of the first analysis result and the baseline model, a risk indicator for characterizing the abnormality degree of the current usage behavior is generated.

[0058] In practice, this embodiment of the application employs a neural network model based on a combination of a long-short-term memory network and an attention mechanism to analyze the current usage behavior of the security credentials in real time. This model is particularly well-suited for processing time series data and can effectively capture contextual relationships and abnormal patterns in interface call sequences. The model compares the current behavior with the normal pattern in a baseline model. Because the current behavior deviates significantly from the baseline in multiple dimensions, such as time, location, frequency, and interface calls, the model outputs a very high probability of abnormality.

[0059] In a specific implementation, as described in step S3, in response to the risk indicator meeting the preset risk condition, the preset restrictive security policy corresponding to the risk indicator is automatically executed, including:

[0060] When the risk indicator reaches a first risk threshold, triggering a secondary verification or access throttling strategy;

[0061] When the risk indicator reaches a second risk threshold that is higher than the first risk threshold, triggering an authority downgrade or audit enhancement policy;

[0062] When the risk indicator reaches a third risk threshold that is higher than the second risk threshold, a service fuse policy is triggered.

[0063] In specific implementation, the system presets multiple risk thresholds. Different thresholds correspond to restrictive security policies of different strengths. The specific execution logic is as follows:

[0064] Risk assessment: Compare current risk indicators with preset thresholds to determine the risk level;

[0065] Policy trigger:

[0066] When the risk indicator reaches the low risk threshold, secondary verification or access throttling (limiting call frequency) is triggered;

[0067] When the medium risk threshold is reached, permission downgrade (retaining only basic business permissions) or audit enhancement (focusing on recording call logs) is triggered;

[0068] When the high-risk threshold is reached, the service circuit breaker is triggered (all call requests are rejected);

[0069] Policy execution: The API core gateway executes the corresponding policy, records the operation log and pushes the alarm information to the security management platform.

[0070] In one embodiment, as described in step S4, in response to receiving a preset external management event, automatically executing a preset security policy corresponding to the external management event includes:

[0071] When the system receives an external management event, it automatically executes the security policy. Take a typical scenario as an example:

[0072] Event reception: Receive "employee resignation" events pushed by the HR system (including security credentials associated with the resigned employee), or "project closure" events pushed by the PM system (including project-related credentials);

[0073] Policy matching: Query the "External Event-Security Policy Mapping Table" to determine the corresponding policy (e.g., "employee resignation" corresponds to "immediately revoke associated credentials + freeze permissions," "project closure" corresponds to "reclaim project-related credentials permissions");

[0074] Policy execution: Automatically complete credential revocation and permission freezing operations, generate operation logs and synchronize them to the system that initiated the event (such as feedback to the HR system that "credentials have been revoked").

[0075] In a specific implementation, as in step S5, after the restrictive security policy is executed, when the risk indicator of the security credential meets a preset restoration condition, the restrictive security policy is automatically lifted, including:

[0076] After the restrictive policy is executed, the system continuously monitors the risk status of the target credentials:

[0077] Recovery condition judgment: When the risk indicator of the credential remains below the preset security threshold for a period of time (i.e., abnormal behavior is eliminated), the recovery condition is met;

[0078] Policy release: The API core gateway automatically releases restrictive policies (such as restoring service call permissions), generates a release log, and pushes notifications to the security management platform without manual review.

[0079] Furthermore, the execution of the restrictive security policy and the lifting of the restrictive security policy are performed by the API core gateway deployed at the system entrance.

[0080] Furthermore, the execution of the restrictive security policy and the lifting of the restrictive security policy are performed by a distributed policy enforcement point deployed in the microservice architecture as a sidecar agent.

[0081] Compared with the existing technology, the technical solution provided by this application has the following beneficial effects:

[0082] 1. It achieves collaborative defense-in-depth, organically linking multiple security modules such as dynamic behavior analysis, automated permission configuration, and gateway management, breaking the "security island" state of traditional security components operating independently and forming a closed-loop, collaborative defense system from pre-emptive prevention, in-process monitoring to post-event disposal and recovery.

[0083] 2. Improved security and intelligence levels. By introducing a neural network-based behavioral analysis engine, it has achieved a shift from static credential verification to dynamic behavioral pattern recognition, enabling more accurate identification of unknown and abnormal attack behaviors.

[0084] 3. Significantly improved the efficiency of permission management. By responding to external management events, it achieves automatic recovery of permissions in seconds in scenarios such as resignation and project closure, solving the problem of delayed response in traditional manual processing and reducing the security risks caused by poor permission management.

[0085] 4. Reduced business impact and false positive rate. The hierarchical disposal and automatic self-healing mechanism based on refined risk scoring can more accurately locate and block malicious requests compared to traditional extensive management and control strategies, and automatically restore services after the risk is eliminated, minimizing the impact on normal business and ensuring system availability.

[0086] See also Figure 2 , Figure 2 This is a schematic diagram of a security credential management system based on dynamic behavior analysis and event linkage provided by an embodiment of the present application, the system comprising:

[0087] A baseline model building unit 10 is used to build a baseline model of normal usage behavior of a target security credential;

[0088] a risk indicator generating unit 20 for analyzing the current usage behavior of the security credential in real time and generating a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model;

[0089] a first policy execution unit 30, configured to automatically execute a preset restrictive security policy corresponding to the risk indicator in response to the risk indicator satisfying a preset risk condition;

[0090] A second policy execution unit 40 is configured to automatically execute a preset security policy corresponding to a preset external management event in response to receiving the preset external management event;

[0091] The policy releasing unit 50 is configured to automatically release the restrictive security policy after the restrictive security policy is executed when the risk indicator of the security credential meets a preset restoration condition.

[0092] It should be noted that through the above-mentioned strategies, the baseline model establishment unit constructs a benchmark framework for normal usage behavior of security credentials, providing a reliable reference for subsequent risk identification. The risk indicator generation unit relies on this baseline to analyze the current behavior of credentials in real time, accurately quantifying the degree of anomalies, and achieving an upgrade from static verification to dynamic perception. The first policy execution unit automatically triggers corresponding restrictive policies based on risk indicators to ensure timely risk control. The second policy execution unit automatically executes security policies in conjunction with external management events, resolving the lag problem of traditional manual permission changes. The policy removal unit automatically removes restrictions after the risk is eliminated, forming a closed-loop management system. This set of units operates in tandem, breaking the "island" dilemma of traditional security modules and establishing a full-process security management system from defining normal credential behavior, real-time risk identification, hierarchical policy response, to external event linkage and automatic self-healing. This system significantly improves the accuracy of identifying abnormal behavior and the timeliness of security control, while significantly improving the efficiency of permission management. At the same time, automatic self-healing reduces the impact of manual intervention on business, effectively balancing system security and availability.

[0093] It can be understood that the same or similar parts of the above embodiments can be referenced to each other, and the contents not described in detail in some embodiments can refer to the same or similar contents in other embodiments.

[0094] It should be noted that, in the description of this application, the terms "first," "second," etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. In addition, in the description of this application, unless otherwise specified, the meaning of "plurality" or "multiple" is at least two.

[0095] It should be understood that when an element is referred to as being "fixed to" or "disposed on" another element, it can be directly on the other element or there may be an intermediate element at the same time; when an element is referred to as being "connected to" another element, it can be directly connected to the other element or there may be an intermediate element at the same time. In addition, the "connection" used here may include wireless connection; the wording "and / or" used includes any unit and all combinations of one or more associated listed items.

[0096] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application belong.

[0097] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0098] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0099] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0100] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.

[0101] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present application. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0102] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A dynamic collaborative access credential security management method, characterized in that: include: Obtaining a target security credential, and establishing a baseline model of its usage behavior based on the target security credential; Analyze the current usage behavior of the security credential in real time, and generate a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model; In response to the risk indicator satisfying a preset risk condition, automatically executing a preset restrictive security policy corresponding to the risk indicator; In response to receiving a preset external management event, automatically executing a preset security policy corresponding to the external management event; After the restrictive security policy is executed, when the risk indicator of the security credential meets a preset restoration condition, the restrictive security policy is automatically lifted.

2. The method according to claim 1, characterized in that The baseline model includes: At least one of the commonly used time, commonly used geographical location, call frequency, and commonly used application programming interface (API) set of the security credential.

3. The method according to claim 1, characterized in that The real-time analysis of the current usage behavior of the security credential and the generation of a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model include: Using a neural network model based on a long short-term memory network and an attention mechanism, analyzing the current usage behavior of the security credential in real time to obtain a first analysis result; Based on the comparison result of the first analysis result and the baseline model, a risk indicator for characterizing the abnormality degree of the current usage behavior is generated.

4. The method according to claim 1, wherein In response to the risk indicator satisfying a preset risk condition, automatically executing a preset restrictive security policy corresponding to the risk indicator includes: When the risk indicator reaches a first risk threshold, triggering a secondary verification or access throttling strategy; When the risk indicator reaches a second risk threshold that is higher than the first risk threshold, triggering an authority downgrade or audit enhancement policy; When the risk indicator reaches a third risk threshold that is higher than the second risk threshold, a service fuse policy is triggered.

5. The method according to claim 1, wherein The external management events include: employee resignation events from the human resources system, or project closing events from the project management system.

6. The method according to claim 1, characterized in that The preset recovery condition is that the risk indicator is continuously lower than a preset safety threshold within a preset time period.

7. The method according to claim 1, characterized in that The execution and release of the restrictive security policy are performed by the API core gateway deployed at the system entrance.

8. The method according to claim 1, characterized in that The execution of the restrictive security policy and the lifting of the restrictive security policy are performed by a distributed policy enforcement point deployed in the microservice architecture as a sidecar agent.

9. A dynamic collaborative access credential security management system, applied to a dynamic collaborative access credential security management method according to any one of claims 1 to 8, characterized in that: include: A baseline model building unit is used to build a baseline model of normal usage behavior for a target security credential; a risk indicator generating unit, configured to analyze the current usage behavior of the security credential in real time and generate a risk indicator for characterizing the degree of abnormality of the current usage behavior based on the baseline model; a first policy execution unit, configured to automatically execute a preset restrictive security policy corresponding to the risk indicator in response to the risk indicator satisfying a preset risk condition; a second policy execution unit, configured to automatically execute a preset security policy corresponding to a preset external management event in response to receiving the preset external management event; A policy releasing unit is configured to automatically release the restrictive security policy after the restrictive security policy is executed when the risk indicator of the security credential meets a preset restoration condition.