Encryption method and system integrating anomaly detection and risk monitoring

By combining encryption algorithms, blockchain, and machine learning technologies, the system achieves decentralized public keys and redundant storage of private keys. Combined with dynamic security defenses, it solves the security and efficiency problems of existing file encryption and sharing systems, providing an efficient and secure file encryption and sharing system.

CN120979774AActive Publication Date: 2025-11-18TAIZHOU INST OF SCI &TECH NUST
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511259177.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2025-11-18
Estimated Expiration
2045-09-04

AI Technical Summary

Technical Problem

Existing file encryption and sharing systems suffer from simple encryption and decryption methods, weak password strength, and susceptibility to leakage. Centralized key management leads to low security, and the lack of dynamic risk assessment and fine-grained access control makes it difficult to meet the high-frequency collaboration and high security requirements within an organization.

Method used

Employing hybrid encryption algorithms, blockchain, interplanetary networks, and machine learning technologies, public keys are distributed through asymmetric encryption. Public keys are decentralized using blockchain-shared smart contracts, while private keys are fragmented, encrypted, and redundantly stored in the interplanetary network. Combined with machine learning anomaly detection and smart contracts, dynamic security defenses are implemented to achieve fine-grained access control.

Benefits of technology

It provides an efficient, secure, and convenient file encryption and sharing system that achieves decentralized and tamper-proof public keys, secure redundancy and fault-tolerant backup of private keys, and dynamic adjustment of security policies, thereby improving the system's security and operational controllability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979774A_ABST
    Figure CN120979774A_ABST
Patent Text Reader

Abstract

The invention discloses an encryption method and system integrating anomaly detection and risk monitoring. The system comprises a key management module, a key storage module, a file encryption module and a dynamic security defense module. According to the invention, advanced hybrid encryption, blockchain, unsupervised machine learning algorithm, programming and other technologies are utilized to construct an open, credible, safe and efficient encryption and decryption system; secret key pairs are distributed for unit internal users by using hybrid encryption, public key data are coded and compressed and then registered to a block chain sharing smart contract, and private key data are segmented and encrypted and then registered to interstellar network nodes; public and efficient online encryption and decryption, digital signature and verification are provided for file circulation of internal users; machine learning anomaly detection and risk monitoring are fused, behavior-driven dynamic security defense and fine-grained permission control of an intelligent contract are implemented in real time, and system operation is safe and controllable.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of data processing, and in particular to an encryption method and system combining abnormality detection and risk monitoring. BACKGROUND

[0002] With the development of Internet technology, file encryption sharing has become a common demand in daily work and life. Common methods include setting an access password for a file or a compressed package, and the password is generally a combination of limited length numbers, which is transmitted and exchanged in an artificial manner. This traditional file encryption sharing method has many problems such as simple encryption and decryption method, weak password strength, and easy leakage. Therefore, there is an urgent need for a file encryption sharing system that can realize efficient, safe and convenient file encryption sharing.

[0003] With the rapid development of encryption algorithms such as AES, RSA and SM4, and the wide application of blockchain, interstellar network and machine learning, these new information technologies provide technical feasibility for designing an encryption sharing software system combining abnormality detection and improving system security.

[0004] The encryption system combining abnormality detection is a system that uses hybrid encryption algorithm, blockchain, interstellar network, machine learning and programming technology to build an open, trusted, safe and efficient encryption and decryption software system for internal users of an organization. Hybrid encryption technology is used to assign a key pair to the user, a blockchain sharing smart contract and an improved secret sharing algorithm are developed to realize the decentralization and tamper resistance of public key data and the security redundancy and fault tolerance backup of private key data. By combining machine learning abnormality detection and blockchain smart contract technology, a behavior-driven dynamic security defense strategy is implemented in real time according to the user behavior risk value, and a fine-grained permission control method of the smart contract is automatically triggered according to the risk value. Alarm information is fed back to the administrator to realize controllable system operation. The internal users can efficiently, safely and conveniently carry out online file encryption and decryption, file signature and verification and other services.

[0005] Some schemes rely on a single encryption algorithm, or only use symmetric encryption to cause key distribution risk, or only rely on asymmetric encryption to reduce large file processing efficiency; most schemes still use centralized server storage for key management, and once the server is attacked, it will cause "one pot" key leakage; a few schemes that introduce blockchain also stay in the primary stage of key chaining, and are not combined with dynamic risk assessment, making it difficult to realize fine-grained control of permissions and real-time defense; more importantly, existing schemes generally lack the collaborative design of "security-efficiency-convenience", either overemphasizing security leading to a surge in operation complexity, or sacrificing core security mechanisms for the sake of convenience, and cannot meet the dual demands of high-frequency collaboration and high-security requirements within an organization.

[0006] Therefore, building a file encryption and sharing system that integrates hybrid encryption, blockchain, interplanetary networks, and machine learning has become an inevitable choice to solve the current dilemma. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention proposes an encryption method and system that integrates anomaly detection and risk monitoring.

[0008] The present invention adopts the following technical solution:

[0009] An encryption method integrating anomaly detection and risk monitoring includes the following steps:

[0010] (S1) When a registered user within the organization applies for a personal key, the system automatically allocates a secure public and private key pair by calling the hybrid encryption library and authorizes the public key to be made public.

[0011] (S2) Based on the user public key allocated in step (S1), the system encodes and compresses it, then calls the shared smart contract method to register it on the blockchain to achieve decentralization and immutability, and returns the custody certificate after local transaction confirmation, which is recorded in the local database according to the user association relationship;

[0012] (S3) Based on the user's private key allocated in step (S1), the system calls the segmentation algorithm to perform fragment encryption, and the encryption results are registered to different interplanetary network nodes to achieve redundant storage and fault-tolerant backup. The system returns a list of local fragment content identifiers (CIDs) and records them in the local database according to the user association relationship.

[0013] (S4) System logged-in users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services;

[0014] (S5) The system automatically retrieves and restores the public key based on the association between the local database user and the custody certificate, which is used by the user to encrypt or digitally sign the circulating file.

[0015] (S6) The system automatically retrieves and restores the private key based on the association between the local database user and the CID list, which is used by the user to decrypt or digitally sign the circulating file;

[0016] The (S7) system integrates machine learning anomaly detection and risk monitoring to implement dynamic security defense and fine-grained access control of smart contracts in real time. Combined with an alarm feedback mechanism, it achieves safe and controllable system operation.

[0017] Furthermore, in step (S1), when an internally registered user applies for a key pair, the system uses a hybrid encryption library and a random number generator to automatically create a key pair according to the PKCS#1 or PKCS#8 standard. The exported public key is not encrypted, while the private key is protected by AES encryption.

[0018] Furthermore, in step (S2), based on the user public key output in step (S1), the system uses CBOR encoding to compress it into a compact binary data format, and then calls the shared smart contract method to register it on the blockchain. The contract uses mapping to store the relationship between the user identifier and the public key data, and the local database records the association between the custodian certificate returned after transaction confirmation and the user.

[0019] Furthermore, in step (S2), the shared smart contract method is registered to the blockchain, and the blockchain smart contract stores the user's public key, including the following steps:

[0020] (S201) Use CBOR encoding to compress the public key into a compact binary data format;

[0021] (S202) Design a mapping in the smart contract to store the relationship between user identifier and public key data so as to share the contract address and isolate the data, call the contract method to upload binary data to the blockchain and return the custody certificate after transaction confirmation;

[0022] (S203) The system's local database records the association between users and custodian certificates.

[0023] Furthermore, in step (S3), the user's private key data is fragmented and encrypted using a segmentation algorithm, including the following steps:

[0024] (S301) The private key is divided into a list of time-limited fragments using a secret sharing algorithm with a predefined total number of shares and a recovery number;

[0025] (S302) Use the national cryptographic algorithm SM4 to encrypt the fragment list to obtain the ciphertext list;

[0026] (S303) Upload the encrypted list to the local node of the StarNet and return the CID list;

[0027] (S304) Serialize the CID list into a JSON object, and record the association between the user and the JSON object in the system's local database.

[0028] Furthermore, in step (S4), system-login users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services.

[0029] Furthermore, the user's encryption or digital signature verification of the transferred file in step (S5) includes the following steps:

[0030] (S501) Obtain the binary data of the user's public key:

[0031] The system will automatically retrieve the custody certificate from the local database based on the sender's or receiver's basic identity information, and use blockchain smart contract methods to obtain the binary data of the user's public key based on the user identifier and operation risk value;

[0032] (S502) Check the validity of the public key:

[0033] CBOR is used to decode binary data into the user's public key, while data integrity verification is performed to check the validity of the public key;

[0034] (S503) Verify the encryption or digital signature of the executable file based on the user's selection:

[0035] When a user selects the file encryption operation, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses the recipient's public key to perform block encryption of the file. Block encryption supports large files. Finally, the encrypted document is sent to the user, and the system interface outputs a message that the file encryption was successful. The server automatically clears the cached user files.

[0036] If a user selects file signature verification, the server will automatically create a user folder and cache the user's uploaded plaintext or ciphertext documents and signature documents in binary mode. If it is ciphertext, it will be decrypted first, and then the sender's public key will be used to verify whether the signature is correct based on the PKCS1_15 padding scheme. Finally, the system interface will output the digital signature verification success or failure information, and the server will automatically clear the cached user files.

[0037] Furthermore, the user's decryption or digital signature of the transferred file in step (S6) includes the following steps:

[0038] First, decrypt and restore the user's private key:

[0039] The system will automatically call the JSON object in the local database based on the identity information of the recipient or sender, deserialize the JSON object into a list of hash values, obtain the ciphertext list from the interplanetary network node based on the hash value list, and call the secret sharing algorithm to decrypt and restore it to the user's private key;

[0040] Then, depending on the user's choice, the executable file can be decrypted or digitally signed.

[0041] When a user selects the file decryption operation, the server automatically creates a user folder and caches the encrypted document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses its own private key to perform file block decryption and connection. Finally, the decrypted plaintext document is sent to the user, the system interface outputs a file decryption success message, and the server automatically clears the cached user files.

[0042] If a user selects to digitally sign a file, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_15 padding scheme, the server uses its own private key to sign the file and finally sends the signed document to the user. The system interface outputs a message indicating that the file has been successfully signed, and the server automatically clears the cached user file.

[0043] Furthermore, step (S7) implements dynamic security defense and fine-grained access control for smart contracts, including the following steps:

[0044] (S701) The system defines security defense rules such as verification code, SMS two-factor authentication, account lockout, and event log, which are divided into three levels of rule combinations, as well as fine-grained permission control of smart contract methods, which are divided into three methods of read and write restrictions;

[0045] (S702) Extract the main features of the original logs by user group, and use principal component analysis to establish a standardized multi-feature dataset including login, RSA operation and time;

[0046] (S703) Use the isolated forest algorithm to build a machine learning anomaly detection model, compare the accuracy after iterative training, determine the optimal parameter values ​​of the model (number of random trees, number of samples, pollution ratio, number of features, random state), and use the optimal model to predict the comprehensive risk value of user behavior.

[0047] (S704) The system executes a combination of tiered defense rules based on the user's risk value, and the smart contract method triggers fine-grained control of the user's operation permissions based on the risk value.

[0048] (S705) The system sends the security defense log as an alarm message to the administrator. At the same time, the smart contract triggers fine-grained permission control logs and writes them to the administrator's smart contract.

[0049] Furthermore, in step (S703), an isolated forest algorithm is used to establish a machine learning anomaly detection model to predict the comprehensive risk value of user behavior, including the following steps:

[0050] (S731) User log data organization;

[0051] The system reads all user login and RSA operation raw logs from the local database and extracts key data. Login behavior includes login success or failure, login IP, and client information. RSA operations include encryption, decryption, and key generation operations, key length, and data size. The timestamps of user operations are also included. Finally, the log data is returned as a Pandas DataFrame.

[0052] (S732) Feature extraction and processing of log data;

[0053] Based on the generated log data, the logs are processed by user groups. Principal component analysis is used to establish a multi-feature dataset including logins, RSA operations, and time. The login feature includes the number of logins and the number of failed logins. The RSA operation feature includes the proportion of short keys, the encryption ratio, and the data size entropy value. The time feature includes the number of nighttime operations and the frequency per hour. Finally, a feature dataset of all user logs is returned as a Pandas DataFrame.

[0054] (S733) Establish an anomaly detection model and train the model to obtain the optimal parameter values;

[0055] (S734) Using the best model, calculate the abnormal score of the user's new feature data. The normal score is a positive number, and the abnormal score is a negative number. Use the formula 100×(0.5-score / 2) to convert the score into a risk value, which can effectively identify the strength of the deviation of user behavior from the norm.

[0056] Furthermore, step (S733) includes the following steps:

[0057] The first step is to define a list of numerical features and a standardization pipeline, and then combine them to generate a feature matrix.

[0058] The second step is to use initialization parameters (number of random trees, number of samples, pollution ratio, number of features, random state) to build a machine learning model for the Isolation Forest algorithm;

[0059] The third step involves fitting and transforming the user's feature dataset, loading the data for model training and prediction, and simultaneously determining whether the model is abnormal. After multiple iterations, the accuracy is compared to determine the optimal parameter values ​​for the model.

[0060] Furthermore, in step (S704), the system determines and executes a combination of tiered defense rules based on the user's risk value, and the smart contract method triggers fine-grained control of user operation permissions based on the risk value, including the following steps:

[0061] (S741) The system executes corresponding dynamic defense strategies based on the user's risk value:

[0062] The degree of deviation of user behavior from the norm is divided into three levels: slight deviation, moderate deviation, and severe deviation.

[0063] If the risk value is less than or equal to 50, it is considered no deviation, and normal service is performed.

[0064] If 50 < risk value <= 60, it is considered a slight deviation, and the combination of "verification code" + "event log" first-level rules will be executed;

[0065] If 60 < risk value <= 70, it is considered a moderate deviation, and the combination of "SMS two-factor verification" + "event log" secondary rules will be executed;

[0066] If the risk value is greater than 70, it is considered a serious deviation, and a three-level rule combination of "account lockout" and "event log" will be executed.

[0067] (S742) Add risk control to blockchain smart contracts and assign corresponding operation permissions according to the user's risk level;

[0068] The first step is to define a risk level set using an enumeration type, including four risk levels: NORMAL (<50, normal operation), LIMITED (50-60, read and write only for the user's own data), READ_ONLY (60-70, read only), and BANNED (>70, read and write prohibited).

[0069] The second step is to define a risk level judgment function that returns the corresponding risk level based on the user's risk value.

[0070] The third step is to add judgment logic to the smart contract read and write methods, first to determine the user's risk level, and then to execute the corresponding read and write operations.

[0071] An encryption system integrating anomaly detection and risk monitoring is provided to implement the aforementioned encryption method integrating anomaly detection and risk monitoring, comprising a front-end layer, a back-end layer, a middle layer, and a storage layer.

[0072] The front-end layer provides a visual web interface that allows network users to complete registration and login on their own. Logged-in users can create key pairs and authorize the public key to be made public, query the public key information of all authorized users, file encryption and decryption, file digital signature and verification, and other public services.

[0073] The backend layer consists of components of a web server. It accepts different requests submitted by the frontend layer and forwards them to the middle layer. At the same time, it receives the results processed by the middle layer and sends them back to the frontend layer.

[0074] The middle layer consists of various business logic processing modules and security technologies, including key distribution, smart contracts, improved secret sharing algorithms, interplanetary network read / write, file encryption and decryption, file digital signature and verification, system performance optimization, dynamic security defense, database connection interface and other modules;

[0075] The storage layer consists of a local database, a blockchain, and interplanetary network nodes.

[0076] Preferably, the intermediate layer includes four different business logic processing modules: a key distribution module, a key conversion module, a file encryption module, and a dynamic security defense module;

[0077] The key distribution module includes an internal user registration submodule, a key distribution submodule, and a key authorization submodule.

[0078] The key conversion module includes a user public key data encoding and sharing smart contract registration submodule, and a private key data segmentation encryption and interplanetary network node registration submodule;

[0079] The file encryption module includes a file encryption and digital signature submodule and a file decryption and digital signature verification submodule.

[0080] The dynamic security defense module includes a user behavior collection submodule, a dynamic risk assessment submodule, a permission rule enforcement submodule, and a defense feedback submodule.

[0081] Preferably, the encryption system is designed using the MVT pattern.

[0082] The beneficial technical effects achieved by adopting the above technical solution are as follows:

[0083] Leveraging advanced encryption / decryption algorithms, blockchain, machine learning, and programming technologies, this system provides a public encryption / decryption software platform for internal users using an asymmetric encryption / decryption mechanism. It employs blockchain-based shared smart contracts to register user public keys, ensuring decentralization and immutability. A StarNet-based, improved secret-sharing algorithm is used to shard user private keys, achieving secure redundancy and fault-tolerant backup. By integrating machine learning anomaly detection with fine-grained access control via smart contracts, a dynamic security defense mechanism is established, ensuring secure and controllable system access. Furthermore, memory caching technology optimizes system performance. This results in an open, fair, reliable, and efficient online file encryption system, providing users with visualized, self-service encryption / decryption operations and information maintenance services.

[0084] An encryption system integrating anomaly detection and risk monitoring is used to implement the encryption methods for key distribution, conversion, and application mentioned above. It provides encryption, decryption, digital signature, and verification services for online file transfers to internal users. The system employs a hybrid storage architecture to design and develop an open, fair, reliable, secure, and efficient encryption / decryption software system. User public keys are registered using a blockchain-shared smart contract, while user private keys are encrypted using a key-sharing algorithm and then registered on interplanetary network nodes. This achieves decentralization and immutability of public keys, and secure redundancy and fault-tolerant backup of private keys. The system uses memory caching services and encoding compression technology to optimize performance. Furthermore, a dynamic security defense mechanism is implemented by integrating machine learning anomaly detection and fine-grained access control via smart contracts to improve system access security. Attached Figure Description

[0085] Figure 1 This is a flowchart of the encryption / decryption method that integrates anomaly detection and risk monitoring according to the present invention.

[0086] Figure 2 This is a system functional structure diagram provided in the specification of this invention.

[0087] Figure 3 This is a flowchart of dynamic security defense provided in the specification of this invention.

[0088] Figure 4 Personal key management is provided for embodiments of the present invention.

[0089] Figure 5 This invention provides a method for querying and retrieving user-authorized public key information.

[0090] Figure 6 The document encryption and signing provided in the embodiments of the present invention.

[0091] Figure 7 The document decryption and verification provided for embodiments of the present invention. Detailed Implementation

[0092] Combined with appendix Figures 1 to 7 The technical solutions in the embodiments of the present invention have been clearly and completely described. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0093] Example 1:

[0094] like Figure 1 As shown, an encryption method integrating anomaly detection and risk monitoring includes the following steps:

[0095] (S1) When a registered user within the organization applies for a personal key, the system automatically allocates a secure public and private key pair by calling the hybrid encryption library and authorizes the public key to be made public.

[0096] (S2) Based on the user public key allocated in step (S1), the system encodes and compresses it, then calls the shared smart contract method to register it on the blockchain to achieve decentralization and immutability, and returns the custody certificate after local transaction confirmation, which is recorded in the local database according to the user association relationship;

[0097] (S3) Based on the user's private key allocated in step (S1), the system calls the segmentation algorithm to perform fragment encryption, and the encryption results are registered to different interplanetary network nodes to achieve redundant storage and fault-tolerant backup. The system returns a list of local fragment content identifiers (CIDs) and records them in the local database according to the user association relationship.

[0098] (S4) System logged-in users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services;

[0099] (S5) The system automatically retrieves and restores the public key based on the association between the local database user and the custody certificate, which is used by the user to encrypt or digitally sign the circulating file.

[0100] (S6) The system automatically retrieves and restores the private key based on the association between the local database user and the CID list, which is used by the user to decrypt or digitally sign the circulating file;

[0101] The (S7) system integrates machine learning anomaly detection and risk monitoring to implement dynamic security defense and fine-grained access control of smart contracts in real time. Combined with an alarm feedback mechanism, it achieves safe and controllable system operation.

[0102] Furthermore, in step (S1), when an internally registered user applies for a key pair, the system uses a hybrid encryption library and a random number generator to automatically create a key pair according to the PKCS#1 or PKCS#8 standard. The exported public key is not encrypted, while the private key is protected by AES encryption.

[0103] Furthermore, in step (S2), based on the user public key output in step (S1), the system uses CBOR encoding to compress it into a compact binary data format, and then calls the shared smart contract method to register it on the blockchain. The contract uses mapping to store the relationship between the user identifier and the public key data, and the local database records the association between the custodian certificate returned after transaction confirmation and the user.

[0104] Furthermore, in step (S2), the shared smart contract method is registered to the blockchain, and the blockchain smart contract stores the user's public key, including the following steps:

[0105] (S201) Use CBOR encoding to compress the public key into a compact binary data format;

[0106] (S202) Design a mapping in the smart contract to store the relationship between user identifier and public key data so as to share the contract address and isolate the data, call the contract method to upload binary data to the blockchain and return the custody certificate after transaction confirmation;

[0107] (S203) The system's local database records the association between users and custodian certificates.

[0108] Furthermore, in step (S3), the user's private key data is fragmented and encrypted using a segmentation algorithm, including the following steps:

[0109] (S301) The private key is divided into a list of time-limited fragments using a secret sharing algorithm with a predefined total number of shares and a recovery number;

[0110] (S302) Use the national cryptographic algorithm SM4 to encrypt the fragment list to obtain the ciphertext list;

[0111] (S303) Upload the encrypted list to the local node of the StarNet and return the CID list;

[0112] (S304) Serialize the CID list into a JSON object, and record the association between the user and the JSON object in the system's local database.

[0113] Furthermore, in step (S4), system-login users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services.

[0114] Furthermore, the user's encryption or digital signature verification of the transferred file in step (S5) includes the following steps:

[0115] (S501) Obtain the binary data of the user's public key:

[0116] The system will automatically retrieve the custody certificate from the local database based on the sender's or receiver's basic identity information, and use blockchain smart contract methods to obtain the binary data of the user's public key based on the user identifier and operation risk value;

[0117] (S502) Check the validity of the public key:

[0118] CBOR is used to decode binary data into the user's public key, while data integrity verification is performed to check the validity of the public key;

[0119] (S503) Verify the encryption or digital signature of the executable file based on the user's selection:

[0120] When a user selects the file encryption operation, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses the recipient's public key to perform block encryption of the file. Block encryption supports large files. Finally, the encrypted document is sent to the user, and the system interface outputs a message that the file encryption was successful. The server automatically clears the cached user files.

[0121] If a user selects file signature verification, the server will automatically create a user folder and cache the user's uploaded plaintext or ciphertext documents and signature documents in binary mode. If it is ciphertext, it will be decrypted first, and then the sender's public key will be used to verify whether the signature is correct based on the PKCS1_15 padding scheme. Finally, the system interface will output the digital signature verification success or failure information, and the server will automatically clear the cached user files.

[0122] Furthermore, the user's decryption or digital signature of the transferred file in step (S6) includes the following steps:

[0123] First, decrypt and restore the user's private key:

[0124] The system will automatically call the JSON object in the local database based on the identity information of the recipient or sender, deserialize the JSON object into a list of hash values, obtain the ciphertext list from the interplanetary network node based on the hash value list, and call the secret sharing algorithm to decrypt and restore it to the user's private key;

[0125] Then, depending on the user's choice, the executable file can be decrypted or digitally signed.

[0126] When a user selects the file decryption operation, the server automatically creates a user folder and caches the encrypted document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses its own private key to perform file block decryption and connection. Finally, the decrypted plaintext document is sent to the user, the system interface outputs a file decryption success message, and the server clears the user's cached file.

[0127] If a user selects to digitally sign a file, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_15 padding scheme, the server uses its own private key to sign the file and finally sends the signed document to the user. The system interface outputs a message indicating that the file has been successfully signed, and the server clears the user's cached file.

[0128] Furthermore, step (S7) implements dynamic security defense and fine-grained access control for smart contracts, including the following steps:

[0129] (S701) The system defines security defense rules such as verification code, SMS two-factor authentication, account lockout, and event log, which are divided into three levels of rule combinations, as well as fine-grained permission control of smart contract methods, which are divided into three methods of read and write restrictions;

[0130] (S702) Extract the main features of the original logs by user group, and use principal component analysis to establish a standardized multi-feature dataset including login, RSA operation and time;

[0131] (S703) Use the isolated forest algorithm to build a machine learning anomaly detection model, compare the accuracy after iterative training, determine the optimal parameter values ​​of the model (number of random trees, number of samples, pollution ratio, number of features, random state), and use the optimal model to predict the comprehensive risk value of user behavior.

[0132] (S704) The system executes a combination of tiered defense rules based on the user's risk value, and the smart contract method triggers fine-grained control of the user's operation permissions based on the risk value.

[0133] (S705) The system sends the security defense log as an alarm message to the administrator. At the same time, the smart contract triggers fine-grained permission control logs and writes them to the administrator's smart contract.

[0134] Furthermore, in step (S703), an isolated forest algorithm is used to establish a machine learning anomaly detection model to predict the comprehensive risk value of user behavior, including the following steps:

[0135] (S731) User log data organization;

[0136] The system reads all user login and RSA operation raw logs from the local database and extracts key data. Login behavior includes login success or failure, login IP, and client information. RSA operations include encryption, decryption, and key generation operations, key length, and data size. The timestamps of user operations are also included. Finally, the log data is returned as a Pandas DataFrame.

[0137] (S732) Feature extraction and processing of log data;

[0138] Based on the generated log data, the logs are processed by user groups. Principal component analysis is used to establish a multi-feature dataset including logins, RSA operations, and time. The login feature includes the number of logins and the number of failed logins. The RSA operation feature includes the proportion of short keys, the encryption ratio, and the data size entropy value. The time feature includes the number of nighttime operations and the frequency per hour. Finally, a feature dataset of all user logs is returned as a Pandas DataFrame.

[0139] (S733) Establish an anomaly detection model and train the model to obtain the optimal parameter values;

[0140] (S734) Using the best model, calculate the abnormal score of the user's new feature data. The normal score is a positive number, and the abnormal score is a negative number. Use the formula 100×(0.5-score / 2) to convert the score into a risk value, which can effectively identify the strength of the deviation of user behavior from the norm.

[0141] Furthermore, step (S733) includes the following steps:

[0142] The first step is to define a list of numerical features and a standardization pipeline, and then combine them to generate a feature matrix.

[0143] The second step is to use initialization parameters (number of random trees, number of samples, pollution ratio, number of features, random state) to build a machine learning model for the Isolation Forest algorithm;

[0144] The third step involves fitting and transforming the user's feature dataset, loading the data for model training and prediction, and simultaneously determining whether the model is abnormal. After multiple iterations, the accuracy is compared to determine the optimal parameter values ​​for the model.

[0145] like Figure 2 As shown, further, in step (S704), the system determines and executes a combination of tiered defense rules based on the user's risk value, and the smart contract method triggers fine-grained control of user operation permissions based on the risk value, including the following steps:

[0146] (S741) The system executes corresponding dynamic defense strategies based on the user's risk value:

[0147] The degree of deviation of user behavior from the norm is divided into three levels: slight deviation, moderate deviation, and severe deviation.

[0148] If the risk value is less than or equal to 50, it is considered no deviation, and normal service is performed.

[0149] If 50 < risk value <= 60, it is considered a slight deviation, and the combination of "verification code" + "event log" first-level rules will be executed;

[0150] If 60 < risk value <= 70, it is considered a moderate deviation, and the combination of "SMS two-factor verification" + "event log" secondary rules will be executed;

[0151] If the risk value is greater than 70, it is considered a serious deviation, and a three-level rule combination of "account lockout" and "event log" will be executed.

[0152] (S742) Add risk control to blockchain smart contracts and assign corresponding operation permissions according to the user's risk level;

[0153] The first step is to define a risk level set using an enumeration type, including four risk levels: NORMAL (<50, normal operation), LIMITED (50-60, read and write only for the user's own data), READ_ONLY (60-70, read only), and BANNED (>70, read and write prohibited).

[0154] The second step is to define a risk level judgment function that returns the corresponding risk level based on the user's risk value.

[0155] The third step is to add judgment logic to the smart contract read and write methods, first to determine the user's risk level, and then to execute the corresponding read and write operations.

[0156] Example 2:

[0157] The following provides an example of file encryption and decryption based on the method and system of this invention, verifying the security, speed, and efficiency of the encryption and decryption of internal user files provided by this system.Figures 4-5 As shown, both the sender and receiver of the file are registered users of this system. They applied for a key using the key distribution module and authorized the public key to be made public.

[0158] This example is divided into two stages, such as Figure 6 As shown, the first stage involves the sender using this system to encrypt and digitally sign the file. The steps are as follows:

[0159] Step S1: The user logs into the system using a browser and enters the system encryption service module.

[0160] Step S2: In the form, the user selects the encryption option, enters the public key access account of the file recipient, selects the digital signature option, browses and uploads local plaintext files, and submits the form data to the server.

[0161] Step S3: The server automatically creates a user folder and caches files in binary format. First, it accesses the account using the recipient's public key and calls the public key management module to obtain the user's public key from the blockchain. The public key is used to perform block encryption on the file, and the generated ciphertext file is cached in the user folder. Next, based on the user's identity information, it calls the private key management module to obtain the user's private key fragmented ciphertext from the interplanetary network. After decryption, the fragments are merged to recover the private key. The private key is then used to digitally sign the file, and the signed file is cached in the user folder. Then, the zipFile library is used to compress and merge the ciphertext and signature files in memory without loss. The compressed file is cached in the user folder. Finally, the compressed file is sent to the user, and the encryption and digital signature results are output on the system page. The server automatically clears the cached user files.

[0162] like Figure 7 As shown, the second stage involves the recipient using this system to decrypt and verify the file after receiving the encrypted file and signature from the sender. The steps are as follows:

[0163] Step S1: The user logs into the system using a browser and enters the system decryption service module.

[0164] Step S2: In the form, the user selects the file type as encrypted, browses the uploaded local encrypted file, selects the signature verification option, enters the public key access account of the file sender, browses the uploaded sender's signed file, and submits the form data to the server.

[0165] Step S3: The server automatically creates a user folder and caches two files in binary format. First, based on the current user's identity information, it calls the private key management module to obtain the user's private key fragmented ciphertext from the interplanetary network. After decryption, it merges and restores the private key. The private key is then used to decrypt and concatenate the ciphertext file in blocks, and the resulting plaintext file is cached in the user folder. Next, based on the file sender's public key access account, it calls the public key management module to obtain the public key from the blockchain. The public key is used to verify the plaintext file and the signature file. Finally, the plaintext file is sent to the user, and the system page outputs the decryption and signature verification results. The server automatically clears the cached user files.

[0166] This example demonstrates simultaneous file encryption and digital signing. If the sender chooses only encryption or digital signing, the system can automatically send the encrypted file to the user after encryption, or automatically send the signed file after digital signing. Similarly, if the recipient chooses only decryption or signature verification, the system can automatically send the plaintext file to the user after decryption, or automatically output a message indicating whether the signature verification was successful or not on the system's web interface after signature verification.

[0167] Example 3:

[0168] The following provides an example of real-time implementation of behavior-driven dynamic security defense and fine-grained access control of smart contracts based on the method and system described above in this invention, verifying the fusion of machine learning anomaly detection and risk monitoring provided by this system. This example consists of four stages.

[0169] The first stage involves user behavior feature collection and processing, including principal component analysis of raw user logs to establish a standardized multi-feature dataset. The steps are as follows:

[0170] Step S1: Obtain key data from user logs;

[0171] Read the raw logs of all users from the system's local database, including key data such as login, RSA operations, and timestamps of user operations, and return the log data log_df as a Pandas DataFrame.

[0172] Step S2: Feature extraction and processing of log data;

[0173] Based on the log data generated in step S1, the data is processed by user group, and a multi-feature dataset is established through principal component analysis. The login features include the number of login attempts and the number of failed login attempts. The RSA operation features include the proportion of short keys, the encryption ratio, and the entropy value of the data size. The time features include the number of operations at night and the frequency per hour. The feature dataset log_features of the user logs is returned as a Pandas DataFrame.

[0174] The second stage is user behavior anomaly detection. This involves establishing a machine learning anomaly detection model, training the optimal model, and predicting the overall risk value of user behavior. The steps are as follows:

[0175] Step S1: Define a list of numerical features and a standardization pipeline, and perform combined processing to generate a feature matrix;

[0176] Step S2: Use the Isolation Forest algorithm to build a machine learning anomaly detection model;

[0177] Step S3: Fit and transform the user's feature dataset, load the data for model training and prediction, and obtain a judgment on whether the model is abnormal. After multiple rounds of iteration, compare the accuracy and determine the optimal parameter values ​​of the model (number of random trees, number of samples, contamination ratio, number of features, random state).

[0178] Step S4: Using the best model, calculate the anomaly score for the user's new feature data. Normal scores are positive, and abnormal scores are negative.

[0179] Step S5: Use the formula 100×(0.5-score / 2) to convert the anomaly score into the user's comprehensive risk value.

[0180] The third stage involves implementing a combination of tiered security rules and fine-grained access control for smart contracts, with the following steps:

[0181] Step S1: The system determines whether to execute normal service or select to execute a combination of security rules based on the real-time comprehensive risk value of user behavior.

[0182] Step S2: The blockchain shared smart contract method determines whether to perform normal read / write operations or restrict read / write permissions based on the risk value of each user request, thereby achieving fine-grained permission control of the smart contract.

[0183] The fourth stage is the feedback of defensive incidents, and the steps are as follows:

[0184] The system will send the logs of the execution of security defense rules as alarm information to the administrator. At the same time, logs involving fine-grained control of the smart contract methods that trigger the smart contract will also be written to the administrator's smart contract.

[0185] Example 4:

[0186] like Figure 3 As shown, an encryption system integrating anomaly detection and risk monitoring is used to implement the above-mentioned encryption method integrating anomaly detection and risk monitoring, including a front-end layer, a back-end layer, a middle layer, and a storage layer;

[0187] The front-end layer provides a visual web interface that allows network users to complete registration and login on their own. Logged-in users can create key pairs and authorize the public key to be made public, query the public key information of all authorized users, file encryption and decryption, file digital signature and verification, and other public services.

[0188] The backend layer consists of components of a web server. It accepts different requests submitted by the frontend layer and forwards them to the middle layer. At the same time, it receives the results processed by the middle layer and sends them back to the frontend layer.

[0189] The middle layer consists of various business logic processing modules and security technologies, including key distribution, smart contracts, improved secret sharing algorithms, interplanetary network read / write, file encryption and decryption, file digital signature and verification, system performance optimization, dynamic security defense, database connection interface and other modules;

[0190] The storage layer consists of a local database, a blockchain, and interplanetary network nodes.

[0191] The middleware layer comprises four different business logic processing modules: a key distribution module, a key conversion module, a file encryption module, and a dynamic security defense module. The key distribution module includes sub-modules for internal user registration, key distribution, and public key authorization. The key conversion module includes sub-modules for user public key data encoding and shared smart contract registration, and sub-modules for private key data segmentation and encryption and interplanetary network node registration. The file encryption module includes sub-modules for file encryption and digital signature, and sub-modules for file decryption and digital signature verification. The dynamic security defense module includes sub-modules for user behavior collection, dynamic risk assessment, permission rule enforcement, and defense feedback.

[0192] This software platform is designed using the MVT model, and comprehensively utilizes technologies such as domestic and international encryption standards, blockchain, interplanetary networks, secret sharing algorithms and unsupervised machine learning algorithms, data encoding and compression, and Python. It addresses the security issues in the online file transfer process for internal users and develops public software systems for file encryption and decryption, digital signatures and verification.

[0193] It should be noted that, in this document, positional terms such as above, below, left, and right are used merely for descriptive purposes. Moreover, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0194] Of course, the above description is only a preferred embodiment of the present invention. The present invention is not limited to the above-described embodiments. It should be noted that any equivalent substitutions or obvious modifications made by those skilled in the art under the guidance of this specification fall within the scope of this specification and should be protected by the present invention.

Claims

1. An encryption method integrating anomaly detection and risk monitoring, characterized in that, Includes the following steps: (S1) When a registered user within the organization applies for a personal key, the system automatically allocates a secure public and private key pair by calling the hybrid encryption library and authorizes the public key to be made public. (S2) Based on the user public key allocated in step (S1), the system encodes and compresses it, then calls the shared smart contract method to register it on the blockchain to achieve decentralization and immutability, and returns the custody certificate after local transaction confirmation, which is recorded in the local database according to the user association relationship; (S3) Based on the user's private key allocated in step (S1), the system calls the segmentation algorithm to perform fragment encryption, and the encryption results are registered to different interplanetary network nodes to achieve redundant storage and fault-tolerant backup. The system returns a list of local fragment content identifiers (CIDs) and records them in the local database according to the user association relationship. (S4) System logged-in users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services; (S5) The system automatically retrieves and restores the public key based on the association between the local database user and the custody certificate, which is used by the user to encrypt or digitally sign the circulating file. (S6) The system automatically retrieves and restores the private key based on the association between the local database user and the CID list, which is used by the user to decrypt or digitally sign the circulating file; The (S7) system integrates machine learning anomaly detection and risk monitoring to implement dynamic security defense and fine-grained access control of smart contracts in real time. Combined with an alarm feedback mechanism, it achieves safe and controllable system operation.

2. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, In step (S1), when an internally registered user applies for a key pair, the system uses a hybrid encryption library and a random number generator to automatically create a key pair according to the public key encryption standard PKCS#1 or PKCS#8. The exported public key is not encrypted, while the private key is encrypted and protected using the Advanced Data Encryption Standard (AES).

3. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, In step (S2), based on the user public key output in step (S1), the system uses a concise binary object to represent CBOR encoding and compress it into a compact binary data format, and then calls a shared smart contract method to register it on the blockchain. The contract uses mapping to store the relationship between the user identifier and the public key data. The local database records the association between the custodian certificate returned after transaction confirmation and the user.

4. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, The shared smart contract method in step (S2) is registered to the blockchain, and the blockchain smart contract stores the user's public key, including the following steps: (S201) Use CBOR encoding to compress the public key into a compact binary data format; (S202) Design a mapping in the smart contract to store the relationship between user identifier and public key data so as to share the contract address and isolate the data, call the contract method to upload binary data to the blockchain and return the custody certificate after transaction confirmation; (S203) The system's local database records the association between users and custodian certificates.

5. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, The step (S3) calls a segmentation algorithm to encrypt the user's private key data in segments, including the following steps: (S301) The private key is divided into a list of time-limited fragments using a secret sharing algorithm with a predefined total number of shares and a recovery number; (S302) Use the national cryptographic algorithm SM4 to encrypt the fragment list to obtain the ciphertext list; (S303) Upload the encrypted list to the local node of the StarNet and return the CID list; (S304) Serialize the CID list into a JSON object, and record the association between the user and the JSON object in the system's local database.

6. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, In step (S4), system-logged users can query and retrieve all authorized public key information of users, and use public file encryption and decryption, digital signature and verification services.

7. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, The user's encryption or digital signature verification of the transferred file in step (S5) includes the following steps: (S501) Obtain the binary data of the user's public key: The system will automatically retrieve the custody certificate from the local database based on the sender's or receiver's basic identity information, and use blockchain smart contract methods to obtain the binary data of the user's public key based on the user identifier and operation risk value; (S502) Check the validity of the public key: CBOR is used to decode binary data into the user's public key, while data integrity verification is performed to check the validity of the public key; (S503) Verify the encryption or digital signature of the executable file based on the user's selection: When a user selects the file encryption operation, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses the recipient's public key to perform block encryption and concatenation of the file. Block encryption supports large files. Finally, the encrypted document is sent to the user, and the system interface outputs a message that the file encryption was successful. The server automatically clears the cached user files. If a user selects file signature verification, the server will automatically create a user folder and cache the user's uploaded plaintext or ciphertext documents and signature documents in binary mode. If it is ciphertext, it will be decrypted first, and then the sender's public key will be used to verify whether the signature is correct based on the PKCS1_15 padding scheme. Finally, the system interface will output the digital signature verification success or failure information, and the server will automatically clear the cached user files.

8. The encryption method for integrating anomaly detection and risk monitoring according to claim 1, characterized in that, In step (S6), the user decrypts or digitally signs the file, first by decrypting and restoring the user's private key: The system will automatically call the JSON object in the local database based on the identity information of the recipient or sender, deserialize the JSON object into a list of hash values, obtain the ciphertext list from the interplanetary network node based on the hash value list, and call the secret sharing algorithm to decrypt and restore it to the user's private key; Then, depending on the user's choice, the executable file can be decrypted or digitally signed. When a user selects the file decryption operation, the server automatically creates a user folder and caches the encrypted document uploaded by the user in binary mode. Based on the PKCS1_OAEP padding scheme, the server uses its own private key to perform file block decryption and connection. Finally, the decrypted plaintext document is sent to the user, the system interface outputs a file decryption success message, and the server automatically clears the cached user files. If a user selects to digitally sign a file, the server automatically creates a user folder and caches the plaintext document uploaded by the user in binary mode. Based on the PKCS1_15 padding scheme, the server uses its own private key to sign the file and finally sends the signed document to the user. The system interface outputs a message indicating that the file has been successfully signed, and the server automatically clears the cached user file.

9. The encryption method integrating anomaly detection and risk monitoring according to claim 1, characterized in that, The implementation of dynamic security defense and fine-grained access control for smart contracts in step (S7) includes the following steps: (S701) The system definition requires security defense rules such as verification codes, SMS two-factor authentication, account locking, and event logs, as well as fine-grained permission control methods for smart contracts; (S702) Extract the main features of the original logs by user group, and use principal component analysis to establish a standardized multi-feature dataset; (S703) Use the isolated forest algorithm to build a machine learning anomaly detection model, determine the optimal parameter values ​​of the model through iterative training, and predict the comprehensive risk value of user behavior; (S704) The system executes a combination of tiered defense rules based on the user's risk value, and the smart contract triggers a fine-grained control method for user operation permissions based on the risk value. (S705) The system sends the security defense log as an alarm message to the administrator. At the same time, the smart contract triggers fine-grained permission control logs and writes them to the administrator's smart contract.

10. The encryption method for integrating anomaly detection and risk monitoring according to claim 9, characterized in that, Step (S703) uses the isolated forest algorithm to build a machine learning anomaly detection model to predict the comprehensive risk value of user behavior, including the following steps: (S731) User log data organization; The system reads all user login and RSA operation raw logs from the local database and extracts key data. Login behavior includes login success or failure, login IP, and client information. RSA operations include encryption, decryption, and key generation operations, key length, and data size. The timestamps of user operations are also included. Finally, the log data is returned as a Pandas DataFrame. (S732) Feature extraction and processing of log data; Based on the generated log data, the logs are processed by user groups. Principal component analysis is used to establish a multi-feature dataset including logins, RSA operations, and time. The login feature includes the number of logins and the number of failed logins. The RSA operation feature includes the proportion of short keys, the encryption ratio, and the data size entropy value. The time feature includes the number of nighttime operations and the frequency per hour. Finally, a feature dataset of all user logs is returned as a Pandas DataFrame. (S733) Establish an anomaly detection model and train the model to obtain the optimal parameter values; (S734) Using the best model, calculate the anomaly score of the user’s new feature data and convert the score into a risk value.

11. The encryption method for integrating anomaly detection and risk monitoring according to claim 10, characterized in that, The step (S733) includes the following steps: The first step is to define a list of numerical features and a standardization pipeline, and then combine them to generate a feature matrix. The second step is to use initialization parameters (number of random trees, number of samples, pollution ratio, number of features, random state) to build a machine learning model for the Isolation Forest algorithm; The third step involves fitting and transforming the user's feature dataset, loading the data for model training and prediction, and simultaneously determining whether the model is abnormal. After multiple iterations, the accuracy is compared to determine the optimal parameter values ​​for the model.

12. An encryption system integrating anomaly detection and risk monitoring, characterized in that, The encryption method for implementing the fusion of anomaly detection and risk monitoring as described in any one of claims 1-11 includes a front-end layer, a back-end layer, a middle layer, and a storage layer; The front-end layer provides a visual web interface that allows users to complete registration and login in a self-service manner. Logged-in users can create key pairs and authorize the public key to be made public, query the public key information of all authorized users, file encryption and decryption, file digital signature and verification, and other services. The backend layer consists of components of a web server. It accepts different requests submitted by the frontend layer and forwards them to the middle layer. At the same time, it receives the results processed by the middle layer and sends them back to the frontend layer. The middle layer consists of various business logic processing modules and security technologies, including key distribution, smart contracts, improved secret sharing algorithms, interplanetary network node read / write, file encryption and decryption, file digital signature and verification, system performance optimization, dynamic security defense, database connection interface and other modules; The storage layer consists of a local database, a blockchain, and interplanetary network nodes.

13. The encryption system integrating anomaly detection and risk monitoring according to claim 12, characterized in that, The middle layer includes four different business logic processing modules: key distribution module, key conversion module, file encryption module, and dynamic security defense module; The key distribution module includes an internal user registration submodule, a key distribution submodule, and a key authorization submodule. The key conversion module includes a user public key data encoding and sharing smart contract registration submodule, and a private key data segmentation encryption and interplanetary network node registration submodule; The file encryption module includes a file encryption and digital signature submodule and a file decryption and digital signature verification submodule. The dynamic security defense module includes a user behavior collection submodule, a dynamic risk assessment submodule, a permission rule execution submodule, and a defense feedback submodule.

Citation Information

Patent Citations

  • Power network attack detection method and system based on isolated forest algorithm

    CN112686775A

  • Mimicry distributed SM9 rapid identification key generation method and system

    CN115174069A

  • Block chain data sharing and security verification method based on DID

    CN119210800A

  • Electronic signature security management method and system based on block chain

    CN119808175A

  • Archive management method based on AI and encrypted storage

    CN119961216A