A communication environment security early warning method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202210651312.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-09
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2042-06-09
AI Technical Summary
[0003]目前,各类通信终端或者通信应用程序虽然会对通信过程进行安全性建设,但并没有对通信环境进行安全性的评估,也无法向用户展示当前通信过程的安全程度,这会导致用户并不了解在进行通信时的安全状况,无法把握在通信时的通信内容是否安全
[0038] The solution of this invention can obtain the first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal. Based on the first security method application information, the communication terminal security coefficient is calculated, and/or based on the second security method application information, the cloud server security coefficient is calculated. Based on at least one of the communication terminal security coefficient and the cloud server security coefficient, a communication environment security assessment result for the current communication environment is determined. If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message is displayed. Since in this invention, the security status of the communication terminal and/or the cloud server can be assessed based on the first security method application information of the communication terminal and the second security method application information of the cloud server, and a warning message is displayed when the assessment result indicates that the communication environment is insecure, a security assessment of the communication environment during the current communication process can be performed. Based on the assessment result, the user is reminded to control the privacy level of the communication content during the communication process.
Smart Images

Figure CN115174418B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and specifically to a communication environment security early warning method, device, electronic device, and storage medium. Background Technology
[0002] With the rapid development of current communication technology, people's forms of communication are becoming more and more diversified. For example, people can communicate via text, voice and video through instant messaging applications.
[0003] Currently, although various communication terminals or applications implement security measures for the communication process, they do not assess the security of the communication environment or demonstrate the current level of security to users. This results in users being unaware of the security status during communication and unable to ascertain whether the content of their communication is secure. Summary of the Invention
[0004] This invention provides a communication environment security early warning method, device, electronic device, and storage medium, which can perform security assessments on the communication environment during the current communication process and remind users based on the assessment results, so that users can control the degree of privacy of the communication content during the communication process.
[0005] This invention provides a communication environment security early warning method, comprising:
[0006] Obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal;
[0007] Based on the application information of the first security method, calculate the communication terminal security coefficient of the communication terminal; and / or,
[0008] Based on the application information of the second security method, calculate the cloud server security coefficient of the cloud server; based on at least one of the communication terminal security coefficient and the cloud server security coefficient, determine the communication environment security assessment result of the current communication environment;
[0009] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0010] Accordingly, embodiments of the present invention also provide a communication environment security early warning device, comprising:
[0011] The information acquisition unit is used to acquire the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal.
[0012] A coefficient calculation unit is used to calculate the communication terminal security coefficient of the communication terminal based on the application information of the first security method; and / or,
[0013] The cloud server security coefficient is calculated based on the application information of the second security method.
[0014] A security assessment unit is used to determine the communication environment security assessment result of the current communication environment based on at least one of the communication terminal security coefficient and the cloud server security coefficient.
[0015] The message prompting unit is used to display a communication environment security prompt message if the communication environment security assessment result indicates that the current communication environment is insecure.
[0016] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a fusion evaluation unit, used to determine the communication network corresponding to the communication terminal in response to the user's communication-initiated operation;
[0017] Obtain the application information of the third security method of the communication network, and calculate the network security coefficient of the communication network based on the application information of the third security method;
[0018] Obtain the current first security method application information of the communication terminal and the current second security method application information of the cloud server;
[0019] Based on the first security method application information and the second security method application information, calculate the communication terminal security coefficient of the communication terminal and the cloud server security coefficient of the cloud server;
[0020] Based on the communication terminal security coefficient, the network security coefficient, and the communication receiver security coefficient, the communication environment security assessment result for the current communication environment is determined.
[0021] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0022] Optionally, the coefficient calculation unit is used to determine unapplied security methods from among the security methods applicable to the communication terminal based on the first security method application information;
[0023] Obtain the first security risk value and the first risk exploitation value corresponding to the unapplied security method;
[0024] Based on the first security risk value and the first risk utilization value, the communication initiator security coefficient of the communication terminal is calculated.
[0025] Optionally, the coefficient calculation unit is used to calculate the risk coefficient corresponding to each of the unapplied security methods at the communication terminal based on the first security risk value and the first risk utilization value.
[0026] Analyze the application information of the first security method to determine the security method that has been applied at the communication terminal;
[0027] The communication terminal security coefficient is calculated based on the applied security methods and the risk coefficients corresponding to each of the unapplied security methods.
[0028] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a timing evaluation unit, used to calculate the time interval between the current time and the time of the most recent communication environment security evaluation result that determined the current communication environment when the communication terminal is in the process of communication;
[0029] When the time interval is greater than the preset detection time interval, the steps of obtaining the third security method application information of the communication network and calculating the network security coefficient of the communication network based on the third security method application information are executed until the communication process ends.
[0030] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a weight acquisition unit, used to acquire the security assessment weights corresponding to the communication terminal, the cloud server and the communication network respectively;
[0031] The fusion evaluation unit is used to calculate the communication environment security evaluation value of the current communication environment based on the communication terminal security coefficient, the network security coefficient, the cloud server security coefficient, and the security evaluation weights corresponding to the communication terminal, the cloud server, and the communication network, respectively.
[0032] Based on the aforementioned communication environment security assessment value, the communication environment security assessment result for the current communication environment is determined.
[0033] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a security level determination unit, used to determine the communication environment security level of the current communication environment based on the communication environment security assessment result;
[0034] The message prompting unit is used to display communication environment security prompt information, which includes the communication environment security level.
[0035] Accordingly, embodiments of the present invention also provide an electronic device, including a memory and a processor; the memory stores an application program, and the processor is used to run the application program in the memory to execute the steps in any of the communication environment security early warning methods provided in the embodiments of the present invention.
[0036] Accordingly, embodiments of the present invention also provide a computer-readable storage medium storing a plurality of instructions adapted for loading by a processor to execute the steps in any of the communication environment security early warning methods provided in the embodiments of the present invention.
[0037] Furthermore, embodiments of the present invention also provide a computer program product, including a computer program or instructions, wherein when the computer program or instructions are executed by a processor, they implement the steps in any of the communication environment security early warning methods provided in embodiments of the present invention.
[0038] The solution of this invention can obtain the first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal. Based on the first security method application information, the communication terminal security coefficient is calculated, and / or based on the second security method application information, the cloud server security coefficient is calculated. Based on at least one of the communication terminal security coefficient and the cloud server security coefficient, a communication environment security assessment result for the current communication environment is determined. If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message is displayed. Since in this invention, the security status of the communication terminal and / or the cloud server can be assessed based on the first security method application information of the communication terminal and the second security method application information of the cloud server, and a warning message is displayed when the assessment result indicates that the communication environment is insecure, a security assessment of the communication environment during the current communication process can be performed. Based on the assessment result, the user is reminded to control the privacy level of the communication content during the communication process. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 This is a schematic diagram of a scenario for the communication environment security early warning method provided in an embodiment of the present invention;
[0041] Figure 2 This is a flowchart of the communication environment security early warning method provided in the embodiments of the present invention;
[0042] Figure 3 This is a schematic diagram of the technical process of the communication environment security early warning method provided in the embodiments of the present invention;
[0043] Figure 4 This is a schematic diagram illustrating the evaluation proportion of different modules in a communication environment provided by an embodiment of the present invention;
[0044] Figure 5 This is a schematic diagram of the communication environment security early warning device provided in an embodiment of the present invention;
[0045] Figure 6 This is another structural schematic diagram of the communication environment security early warning device provided in this embodiment of the invention;
[0046] Figure 7 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0047] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0048] This invention provides a communication environment security early warning method, apparatus, electronic device, and computer-readable storage medium. Specifically, this invention provides a communication environment security early warning method applicable to a communication environment security early warning device, which can be integrated into an electronic device.
[0049] The electronic device can be a terminal or other device, including but not limited to mobile terminals and fixed terminals. For example, mobile terminals include but are not limited to smartphones, smartwatches, tablets, laptops, smart vehicles, etc., while fixed terminals include but are not limited to desktop computers, smart TVs, etc.
[0050] The electronic device can also be a server or other similar device. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, but it is not limited to these.
[0051] The communication environment security early warning method of this invention can be implemented by a server or by a terminal and a server together.
[0052] The following example illustrates the method of implementing a security early warning system for this communication environment using both a terminal and a server.
[0053] like Figure 1 As shown, the communication environment security early warning system provided in this embodiment of the invention includes a terminal 10 and a server 20, etc. The terminal 10 and the server 20 are connected through a network, such as through a wired or wireless network, etc. The terminal 10 can exist as a communication initiator for users to initiate communication and to conduct communication.
[0054] Among them, terminal 10 can be a communication initiator used by the user for communication, and is used to send the current first security method application information to server 20.
[0055] Server 20 can be used to obtain the first security method application information of the current communication terminal and the second security method application information of the cloud server corresponding to the communication terminal, calculate the communication terminal security coefficient of the communication terminal according to the first security method application information, and / or calculate the cloud server security coefficient of the cloud server according to the second security method application information, determine the communication environment security assessment result of the current communication environment based on at least one of the communication terminal security coefficient and the cloud server security coefficient, and send a communication environment security warning message to terminal 10 if the communication environment security assessment result indicates that the current communication environment is insecure.
[0056] Terminal 10 can display communication environment security alert messages.
[0057] It is understood that the communication environment security assessment steps performed by server 20 can also be performed by terminal 10, and this embodiment of the invention does not limit this.
[0058] The following sections provide detailed descriptions of each example. It should be noted that the order in which the embodiments are described is not intended to limit the preferred order of the embodiments.
[0059] This invention will be described from the perspective of a communication environment security early warning device, which can be integrated into a server or terminal.
[0060] like Figure 2 As shown, the specific process of the communication environment security early warning method in this embodiment can be as follows:
[0061] 201. Obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal.
[0062] The communication terminal is the user's terminal used for communication. Specifically, the communication terminal can include a communication initiator (used by the user to initiate communication) and a communication receiver (used by the user to receive communication). For example, the communication initiator and the communication receiver can be a smartphone, smartwatch, computer, etc., used by the user.
[0063] The first security method application information can indicate the application status of the security method corresponding to the communication initiator and / or the communication receiver. For example, the first security method application information may include relevant information about the applied security method, such as the method name and preset method number. Alternatively, the first security method application information may include relevant information about the unapplied security method.
[0064] Specifically, the moment when the first security method application information is obtained can be the moment when the communication application is detected to start. That is, if the communication application is detected to start, the current first security method application information of the communication initiator and / or communication receiver where the communication application is located is obtained.
[0065] Alternatively, it could be the moment the user initiates communication, i.e., step 201 could include:
[0066] In response to a user-initiated communication operation, a communication environment security assessment request is generated;
[0067] Based on the communication environment security assessment request, the current initiator security method application information of the communication initiator is obtained as the current first security method application information of the communication initiator.
[0068] Alternatively, it could be the moment when the user initiates the communication, i.e., step 201 could include:
[0069] In response to the user's acceptance of communication, a communication environment security assessment request is generated;
[0070] Based on the communication environment security assessment request, the current security method application information of the communication receiver is obtained as the current first security method application information of the communication receiver.
[0071] In some optional examples, the security method application information of the initiating end and the security method application information of the receiving end can be obtained separately, and then the information can be fused, with the fused result used as the current first security method application information of the communication end.
[0072] Specifically, information fusion can be achieved through addition or weighted calculation. If weighted calculation is used, the weights of the communication initiator and receiver can be calculated by technicians according to actual needs. This embodiment of the invention does not limit this.
[0073] It is understood that the electronic device acquiring the application information of the first security method can be a terminal, meaning that the application information of the first security method can be collected by the communication initiator and / or the communication receiver itself, or it can be acquired by a server. Specifically, the server can be one that receives the application information of the first security method sent by the communication initiator and / or the communication receiver.
[0074] In practical applications, if users employ cloud communication methods such as remote conferencing or video calls, a security assessment can also be performed on the cloud server involved in the communication process. In this case, the step preceding "obtaining the second security method application information of the cloud server corresponding to the communication endpoint" may specifically include:
[0075] In response to a user initiating a cloud communication operation, determine the cloud server corresponding to the communication terminal;
[0076] Obtain the second security method application information of the cloud server.
[0077] 202. Calculate the communication terminal security coefficient of the communication terminal based on the application information of the first security method; and / or calculate the cloud server security coefficient of the cloud server based on the application information of the second security method.
[0078] The communication end security coefficient can be used to represent the security level of the communication end. Specifically, if the first security method application information is obtained only from the initiator's security method application information, then the communication end security coefficient can be used to represent the security level of the initiator; if the first security method application information is obtained only from the receiver's security method application information, then the communication end security coefficient can be used to represent the security level of the receiver; if the first security method application information is obtained from both the initiator's and receiver's security method application information, then the communication end security coefficient can be used to represent the security levels of both the initiator and receiver.
[0079] In some optional examples, the degree of danger posed by the absence of applicable but unapplied security methods at the communication endpoint can be determined, along with the potential for malicious exploitation of these risks. In other words, the step "calculating the communication initiator security coefficient based on the first security method application information" can specifically include:
[0080] Based on the first security method application information, determine the unapplied security methods from the security methods applicable to the communication terminal;
[0081] Obtain the first security risk value and the first risk exploitation value corresponding to the unapplied security method;
[0082] Based on the first security risk value and the first risk utilization value, the communication terminal security coefficient is calculated.
[0083] In practical applications, there can be at least one security method that can be applied to the communication end. For example, the security methods that can be applied to the communication end may include, but are not limited to, integrity verification, local storage encryption, system patching, and preventing connection to passwordless / weak networks, etc.
[0084] There may be at least one unused security method. Understandably, different unused security methods generally pose different risks to the communication end.
[0085] In this embodiment of the invention, the first security risk value of each security method can be used to describe the risk impact that the corresponding security method may bring if it is applied, and the first risk utilization value of each security method can be used to describe the ease of utilization of the risk that the corresponding security method may bring if it is applied.
[0086] Specifically, when calculating the security factor of the communication terminal, the risk brought by each unapplied security method can be calculated by combining the first security risk value and the first risk utilization value of each unapplied security method, and this risk can be used as the security factor of the communication terminal.
[0087] Alternatively, the security impact of already applied security methods can be incorporated into the calculation of the security factor. That is, the step "calculating the communication terminal security factor based on the first security risk value and the first risk utilization value" includes:
[0088] Based on the first security risk value and the first risk utilization value, calculate the risk coefficient corresponding to each of the unapplied security methods at the communication terminal;
[0089] Analyze the application information of the first security method to determine the security method that has been applied at the communication terminal;
[0090] The communication terminal security coefficient is calculated based on the applied security methods and the risk coefficients corresponding to each of the unapplied security methods.
[0091] For example, the risk resulting from the failure to apply a certain safety method can be represented by a risk coefficient, R = D * E, where 0 <= D <= 1 and 0 <= E <= 1. Here, D is the first risk utilization value of the safety method, and E is the first safety risk value of the safety method.
[0092] In some alternative embodiments, the security factor can be calculated directly based on the number of security methods applied, for example, the security factor of the communication initiator. N represents the number of security methods applied at the communication end, and n represents the number of security methods not applied.
[0093] In some alternative embodiments, the security impact value of each applied security method can be determined, and the communication terminal security coefficient of the communication terminal can be calculated based on the security impact value of the applied security method and the risk coefficient corresponding to each unapplied security method.
[0094] The calculation method for the security factor of the cloud server is similar to that of the aforementioned calculation method for the security factor of the communication sending end, and will not be described again in this embodiment of the invention.
[0095] Specifically, applicable security methods for cloud servers may include, but are not limited to, system patches, installing and enabling firewalls, closing unnecessary services and ports, regular backups, monitoring system logs, local storage encryption, identity authentication, access control, and so on.
[0096] 203. Based on at least one of the communication terminal security coefficient and the cloud server security coefficient, determine the communication environment security assessment result of the current communication environment.
[0097] In this embodiment of the invention, when the security factor of the communication terminal is greater than a preset security threshold, the communication environment security assessment result of the current communication environment can be determined as secure; when the security factor of the communication terminal is not greater than the preset security threshold, the communication environment security assessment result of the current communication environment can be determined as insecure.
[0098] 204. If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0099] The communication environment security alert message may only include information indicating that the current communication environment is insecure, or it may include a selection control for the user to choose whether to continue using the communication application or continue communicating.
[0100] In some alternative embodiments, such as Figure 3 As shown, when a user chooses to communicate, the communication receiving end and the communication network between the communication initiator and the communication receiving end can be determined based on the communication initiation operation of the user. A communication security assessment can also be performed on the communication network, allowing the user to understand the overall security of the communication environment. In other words, after the step "displaying the communication environment security warning message," the communication environment security early warning method provided in this embodiment of the invention may further include:
[0101] In response to a user-initiated communication operation, the communication network corresponding to the communication terminal is determined;
[0102] Obtain the application information of the third security method of the communication network, and calculate the network security coefficient of the communication network based on the application information of the third security method;
[0103] Obtain the current first security method application information of the communication terminal and the current second security method application information of the cloud server;
[0104] Based on the first security method application information and the second security method application information, calculate the communication terminal security coefficient of the communication terminal and the cloud server security coefficient of the cloud server;
[0105] Based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient, the communication environment security assessment result of the current communication environment is determined;
[0106] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0107] The calculation method for the network security coefficient is similar to that for the aforementioned calculation method for the security coefficient of the communication sending end, and will not be described again in this embodiment of the invention.
[0108] Specifically, applicable security methods for communication networks may include, but are not limited to, secure network protocols, encrypted transmission content, PKI encryption, etc. The applicable security methods at the communication receiving end may be the same as or different from those at the communication initiating end; this embodiment of the invention does not limit this.
[0109] Correspondingly, the step "determine the communication environment security assessment result of the current communication environment based on at least one of the communication terminal security coefficient and the cloud server security coefficient" may specifically include:
[0110] The communication environment security assessment result is determined based on the communication terminal security coefficient, the cloud server security coefficient, and the network security coefficient.
[0111] Specifically, the communication environment security assessment result of the current communication environment can be determined as insecure if any one of the security coefficients of the communication initiator, the cloud server, the network security, and the communication receiver is not greater than a preset security threshold.
[0112] Or, such as Figure 4 As shown, before the step "determine the communication environment security assessment result of the current communication environment based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient", the communication environment security early warning method provided in this embodiment of the invention may further include:
[0113] Obtain the security assessment weights corresponding to the communication terminal, the cloud server, and the communication network, respectively;
[0114] The step "Determine the communication environment security assessment result of the current communication environment based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient" includes:
[0115] Based on the security coefficient of the communication terminal, the security coefficient of the network, the security coefficient of the cloud server, and the security assessment weights corresponding to the communication terminal, the cloud server, and the communication network, the communication environment security assessment value of the current communication environment is calculated.
[0116] Based on the aforementioned communication environment security assessment value, the communication environment security assessment result for the current communication environment is determined.
[0117] For example, let the security assessment weight of the communication end (communication initiator and communication receiver) be P1, and the security coefficient be C1; let the security assessment weight of the cloud server be P2, and the security coefficient be C2; let the security assessment weight of the communication network be P3, and the security coefficient be C3. Then the security assessment value S of the communication environment can be calculated using the following formula:
[0118] S = P1*C1 + P2*C2 + P3*C3
[0119] For example, the entire communication system can be divided into three parts. Among them, the cloud data center (cloud server) is the core of the system. It not only affects the normal operation of video calls, but also affects the privacy and security of video call content. The security assessment weight of cloud security can account for 45%.
[0120] As the link between the cloud and users for transmitting data, communication networks (IP networks) may be subject to the risk of video call content being eavesdropped if security measures are not in place. The security assessment weight can account for 35% of the network security assessment.
[0121] If the terminal systems of the communication initiator and the communication receiver (user end) have vulnerabilities or other security issues, it may also lead to the risk of theft of communication content such as video call content. The security assessment weighting for terminal security assessment can be 30%.
[0122] In some embodiments, the communication environment security early warning method provided by the present invention may further include:
[0123] When the communication terminal is in the process of communication, calculate the time interval between the current time and the time of the most recent communication environment security assessment result that determined the current communication environment;
[0124] When the time interval is greater than the preset detection time interval, the steps of obtaining the third security method application information of the communication network and calculating the network security coefficient of the communication network based on the third security method application information are executed until the communication process ends.
[0125] In other words, if a user continues to communicate, the security factor of each part of the communication system can be calculated repeatedly at regular intervals to assess the security of the current communication environment and provide real-time alerts to the user on the communication security status until the call ends.
[0126] In some optional embodiments, to facilitate users' understanding of the specific security level of the current communication environment, corresponding security levels can be divided according to the communication environment security assessment results. Before the step of "displaying the communication environment security warning message", the communication environment security early warning method provided in this embodiment of the invention may further include:
[0127] Based on the communication environment security assessment results, the communication environment security level of the current communication environment is determined;
[0128] Accordingly, the step "Display communication environment security alert message" may specifically include:
[0129] Display communication environment security warning information, which includes the communication environment security level.
[0130] As can be seen from the above, the embodiments of the present invention can obtain the current first security method application information of the communication initiator, calculate the communication initiator security coefficient based on the first security method application information, determine the communication environment security assessment result of the current communication environment based on the communication initiator security coefficient, and display a communication environment security prompt message if the communication environment security assessment result indicates that the current communication environment is insecure. Since the security status of the communication initiator is assessed based on the first security method application information of the communication initiator in the embodiments of the present invention, and a prompt message is displayed when the assessment result indicates that the communication environment is insecure, the security of the communication environment in the current communication process can be assessed, and the user can be reminded based on the assessment result, so that the user can control the privacy level of the communication content during the communication process.
[0131] To better implement the above methods, this embodiment of the invention also provides a communication environment security early warning device.
[0132] refer to Figure 5 The device includes:
[0133] The information acquisition unit 501 is used to acquire the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal.
[0134] The coefficient calculation unit 502 is used to calculate the communication terminal security coefficient of the communication terminal based on the application information of the first security method; and / or,
[0135] The cloud server security coefficient is calculated based on the application information of the second security method.
[0136] The security assessment unit 503 is used to determine the communication environment security assessment result of the current communication environment based on at least one of the communication terminal security coefficient and the cloud server security coefficient.
[0137] The message prompting unit 504 is used to display a communication environment security prompt message if the communication environment security assessment result indicates that the current communication environment is insecure.
[0138] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a fusion evaluation unit 505, which is used to determine the communication network corresponding to the communication terminal in response to the user's communication-initiated operation;
[0139] Obtain the application information of the third security method of the communication network, and calculate the network security coefficient of the communication network based on the application information of the third security method;
[0140] Obtain the current first security method application information of the communication terminal and the current second security method application information of the cloud server;
[0141] Based on the first security method application information and the second security method application information, calculate the communication terminal security coefficient of the communication terminal and the cloud server security coefficient of the cloud server;
[0142] Based on the communication terminal security coefficient, the network security coefficient, and the communication receiver security coefficient, the communication environment security assessment result for the current communication environment is determined.
[0143] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0144] Optionally, the coefficient calculation unit 502 is used to determine unapplied security methods from among the security methods applicable to the communication terminal based on the first security method application information;
[0145] Obtain the first security risk value and the first risk exploitation value corresponding to the unapplied security method;
[0146] Based on the first security risk value and the first risk utilization value, the communication initiator security coefficient of the communication terminal is calculated.
[0147] Optionally, the coefficient calculation unit 502 is used to calculate the risk coefficient corresponding to each of the unapplied security methods at the communication terminal based on the first security risk value and the first risk utilization value.
[0148] Analyze the application information of the first security method to determine the security method that has been applied at the communication terminal;
[0149] The communication terminal security coefficient is calculated based on the applied security methods and the risk coefficients corresponding to each of the unapplied security methods.
[0150] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a timing evaluation unit 506, used to calculate the time interval between the current time and the time of the most recent communication environment security evaluation result that determined the current communication environment when the communication terminal is in the process of communication;
[0151] When the time interval is greater than the preset detection time interval, the steps of obtaining the third security method application information of the communication network and calculating the network security coefficient of the communication network based on the third security method application information are executed until the communication process ends.
[0152] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a weight acquisition unit 507, used to acquire the security assessment weights corresponding to the communication terminal, the cloud server and the communication network respectively;
[0153] The fusion evaluation unit 505 is used to calculate the communication environment security evaluation value of the current communication environment based on the communication terminal security coefficient, the network security coefficient, the cloud server security coefficient, and the security evaluation weights corresponding to the communication terminal, the cloud server, and the communication network, respectively.
[0154] Based on the aforementioned communication environment security assessment value, the communication environment security assessment result for the current communication environment is determined.
[0155] Optionally, the communication environment security early warning device provided in this embodiment of the invention further includes a security level determination unit 508, used to determine the communication environment security level of the current communication environment based on the communication environment security assessment result;
[0156] The message prompting unit is used to display communication environment security prompt information, which includes the communication environment security level.
[0157] As can be seen from the above, the communication environment security early warning device can obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal. Based on the first security method application information, the communication terminal security coefficient of the communication terminal is calculated, and / or based on the second security method application information, the cloud server security coefficient of the cloud server is calculated. Based on at least one of the communication terminal security coefficient and the cloud server security coefficient, the communication environment security assessment result of the current communication environment is determined. If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message is displayed. Since in this embodiment of the invention, the security status of the communication terminal and / or the cloud server can be assessed based on the first security method application information of the communication terminal and the second security method application information of the cloud server, and a warning message is displayed when the assessment result indicates that the communication environment is insecure, the security of the communication environment in the current communication process can be assessed, and the user can be reminded based on the assessment result, so that the user can control the degree of privacy of the communication content during the communication process.
[0158] Furthermore, embodiments of the present invention also provide an electronic device, which may be a terminal or a server, etc. Figure 7 As shown, it illustrates a structural schematic diagram of the electronic device involved in an embodiment of the present invention, specifically:
[0159] The electronic device may include a radio frequency (RF) circuit 701, a memory 702 including one or more computer-readable storage media, an input unit 703, a display unit 704, a sensor 705, an audio circuit 706, a wireless fidelity (WiFi) module 707, a processor 708 including one or more processing cores, and a power supply 709, etc. Those skilled in the art will understand that... Figure 7 The electronic device structure shown does not constitute a limitation on the electronic device and may include more or fewer components than shown, or combine certain components, or have different component arrangements. Wherein:
[0160] RF circuit 701 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and hands it over to one or more processors 708 for processing; additionally, it transmits uplink data to the base station. Typically, RF circuit 701 includes, but is not limited to, an antenna, at least one amplifier, a tuner, one or more oscillators, a Subscriber Identity Module (SIM) card, a transceiver, a coupler, a low-noise amplifier (LNA), a duplexer, etc. Furthermore, RF circuit 701 can also communicate wirelessly with networks and other devices. Wireless communication can use any communication standard or protocol, including but not limited to GSM, GPRS, CDMA, WCDMA, LTE, email, and SMS.
[0161] The memory 702 can be used to store software programs and modules. The processor 708 executes various functional applications and data processing by running the software programs and modules stored in the memory 702. The memory 702 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device (such as audio data, telephone directory, etc.). In addition, the memory 702 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 702 may also include a memory controller to provide access to the memory 702 for the processor 708 and the input unit 703.
[0162] The input unit 703 can be used to receive input digital or character information, and to generate keyboard, mouse, joystick, optical, or trackball signal inputs related to user settings and function control. Specifically, in one embodiment, the input unit 703 may include a touch-sensitive surface and other input devices. The touch-sensitive surface, also known as a touch display or touchpad, can collect user touch operations on or near it (e.g., user operations using fingers, styluses, or any suitable object or accessory on or near the touch-sensitive surface), and drive corresponding connection devices according to a pre-set program. Optionally, the touch-sensitive surface may include a touch detection device and a touch controller. The touch detection device detects the user's touch orientation and the signal generated by the touch operation, transmitting the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, sends it to the processor 708, and can receive and execute commands from the processor 708. Furthermore, various types of touch-sensitive surfaces, such as resistive, capacitive, infrared, and surface acoustic wave, can be used. In addition to the touch-sensitive surface, the input unit 703 may also include other input devices. Specifically, other input devices may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.
[0163] Display unit 704 can be used to display information input by the user or information provided to the user, as well as various graphical user interfaces of electronic devices. These graphical user interfaces can be composed of graphics, text, icons, video, and any combination thereof. Display unit 704 may include a display panel, optionally configured as a liquid crystal display (LCD), organic light-emitting diode (OLED), or similar form. Furthermore, a touch-sensitive surface may cover the display panel. When the touch-sensitive surface detects a touch operation on or near it, it transmits the information to processor 708 to determine the type of touch event. Subsequently, processor 708 provides corresponding visual output on the display panel according to the type of touch event. Although in Figure 7 In this context, the touch-sensitive surface and the display panel are two separate components for implementing input and output functions. However, in some embodiments, the touch-sensitive surface and the display panel can be integrated to achieve both input and output functions.
[0164] The electronic device may also include at least one sensor 705, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel according to the ambient light level, and the proximity sensor can turn off the display panel and / or backlight when the electronic device is moved to the ear. As a type of motion sensor, a gravity acceleration sensor can detect the magnitude of acceleration in various directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc. Other sensors that may be configured in the electronic device, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.
[0165] Audio circuitry 706, a speaker, and a microphone provide an audio interface between the user and the electronic device. Audio circuitry 706 converts received audio data into electrical signals, transmits them to the speaker, and the speaker converts them into sound signals for output. Conversely, the microphone converts collected sound signals into electrical signals, which are then received by audio circuitry 706, converted back into audio data, and processed by processor 708. The processed data is then transmitted via RF circuitry 701 to, for example, another electronic device, or output to memory 702 for further processing. Audio circuitry 706 may also include an earphone jack to facilitate communication between external headphones and the electronic device.
[0166] WiFi is a short-range wireless transmission technology. Electronic devices using the WiFi module 707 can help users send and receive emails, browse web pages, and access streaming media, providing users with wireless broadband internet access. Although Figure 7 WiFi module 707 is shown, but it is understood that it is not a necessary component of the electronic device and can be omitted as needed without changing the nature of the invention.
[0167] The processor 708 is the control center of the electronic device, connecting various parts of the phone via various interfaces and lines. It executes software programs and / or modules stored in the memory 702, and calls data stored in the memory 702 to perform various functions and process data. Optionally, the processor 708 may include one or more processing cores; preferably, the processor 708 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 708.
[0168] The electronic device also includes a power supply 709 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 708 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 709 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0169] Although not shown, the electronic device may also include a camera, Bluetooth module, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 708 in the electronic device loads the executable files corresponding to the processes of one or more applications into the memory 702 according to the following instructions, and the processor 708 runs the applications stored in the memory 702 to realize various functions, as follows:
[0170] Obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal;
[0171] Based on the application information of the first security method, calculate the communication terminal security coefficient of the communication terminal; and / or,
[0172] Based on the application information of the second security method, calculate the cloud server security coefficient of the cloud server; based on at least one of the communication terminal security coefficient and the cloud server security coefficient, determine the communication environment security assessment result of the current communication environment;
[0173] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0174] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be performed by instructions, or by instructions controlling related hardware. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0175] To this end, embodiments of the present invention provide a computer-readable storage medium storing a plurality of instructions that can be loaded by a processor to execute steps in any of the communication environment security early warning methods provided in the embodiments of the present invention. For example, the instructions can execute the following steps:
[0176] Obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal;
[0177] Based on the application information of the first security method, calculate the communication terminal security coefficient of the communication terminal; and / or,
[0178] Based on the application information of the second security method, calculate the cloud server security coefficient of the cloud server; based on at least one of the communication terminal security coefficient and the cloud server security coefficient, determine the communication environment security assessment result of the current communication environment;
[0179] If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
[0180] For details on the implementation of each of the above operations, please refer to the previous examples, which will not be repeated here.
[0181] The computer-readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0182] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the communication environment security early warning methods provided in the embodiments of the present invention, the beneficial effects that any of the communication environment security early warning methods provided in the embodiments of the present invention can achieve can be realized, as detailed in the preceding embodiments, and will not be repeated here.
[0183] According to one aspect of this application, a computer program product or computer program is also provided, comprising computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the methods provided in the various optional implementations of the above embodiments.
[0184] The foregoing has provided a detailed description of a communication environment security early warning method, device, electronic device, and storage medium provided by the embodiments of the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for early warning of communication environment security, characterized in that, include: Obtain the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal; Based on the application information of the first security method, calculate the communication terminal security coefficient of the communication terminal; And / or, The cloud server security coefficient is calculated based on the application information of the second security method. Based on at least one of the communication terminal security coefficient and the cloud server security coefficient, determine the communication environment security assessment result of the current communication environment; If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed. The step of calculating the communication terminal security coefficient based on the application information of the first security method includes: Based on the first security method application information, determine the unapplied security methods from the security methods applicable to the communication terminal; Obtain the first security risk value and the first risk exploitation value corresponding to the unapplied security method; Based on the first security risk value and the first risk utilization value, calculate the risk coefficient corresponding to each of the unapplied security methods at the communication terminal; Analyze the application information of the first security method to determine the security method that has been applied at the communication terminal; The communication terminal security coefficient is calculated based on the applied security methods and the risk coefficients corresponding to each of the unapplied security methods. The calculation method for the security factor of the cloud server is similar to that of the aforementioned calculation method for the security factor of the communication terminal.
2. The communication environment security early warning method according to claim 1, characterized in that, After displaying the communication environment security alert message, the method further includes: In response to a user-initiated communication operation, the communication network corresponding to the communication terminal is determined; Obtain the application information of the third security method of the communication network, and calculate the network security coefficient of the communication network based on the application information of the third security method; Obtain the current first security method application information of the communication terminal and the current second security method application information of the cloud server; Based on the first security method application information and the second security method application information, calculate the communication terminal security coefficient of the communication terminal and the cloud server security coefficient of the cloud server; Based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient, the communication environment security assessment result of the current communication environment is determined; If the communication environment security assessment result indicates that the current communication environment is insecure, a communication environment security warning message will be displayed.
3. The communication environment security early warning method according to claim 2, characterized in that, The method further includes: When the communication terminal is in the process of communication, calculate the time interval between the current time and the time of the most recent communication environment security assessment result that determined the current communication environment; When the time interval is greater than the preset detection time interval, the steps of obtaining the third security method application information of the communication network and calculating the network security coefficient of the communication network based on the third security method application information are executed until the communication process ends.
4. The communication environment security early warning method according to claim 2, characterized in that, Before determining the communication environment security assessment result of the current communication environment based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient, the method further includes: Obtain the security assessment weights corresponding to the communication terminal, the cloud server, and the communication network, respectively; The step of determining the communication environment security assessment result based on the communication terminal security coefficient, the network security coefficient, and the cloud server security coefficient includes: Based on the security coefficient of the communication terminal, the security coefficient of the network, the security coefficient of the cloud server, and the security assessment weights corresponding to the communication terminal, the cloud server, and the communication network, the communication environment security assessment value of the current communication environment is calculated. Based on the aforementioned communication environment security assessment value, the communication environment security assessment result for the current communication environment is determined.
5. The communication environment security early warning method according to any one of claims 1-4, characterized in that, Before displaying the communication environment security alert message, the method further includes: Based on the communication environment security assessment results, the communication environment security level of the current communication environment is determined; The displayed communication environment security alert message includes: Display communication environment security warning information, which includes the communication environment security level.
6. A communication environment security early warning device, characterized in that, include: The information acquisition unit is used to acquire the current first security method application information of the communication terminal and the second security method application information of the cloud server corresponding to the communication terminal. The coefficient calculation unit is used to calculate the communication terminal security coefficient of the communication terminal based on the application information of the first security method. And / or, The cloud server security coefficient is calculated based on the application information of the second security method. A security assessment unit is used to determine the communication environment security assessment result of the current communication environment based on at least one of the communication terminal security coefficient and the cloud server security coefficient. The message prompting unit is used to display a communication environment security prompt message if the communication environment security assessment result indicates that the current communication environment is insecure. The step of calculating the communication terminal security coefficient based on the application information of the first security method includes: Based on the first security method application information, determine the unapplied security methods from the security methods applicable to the communication terminal; Obtain the first security risk value and the first risk exploitation value corresponding to the unapplied security method; Based on the first security risk value and the first risk utilization value, calculate the risk coefficient corresponding to each of the unapplied security methods at the communication terminal; Analyze the application information of the first security method to determine the security method that has been applied at the communication terminal; The communication terminal security coefficient is calculated based on the applied security methods and the risk coefficients corresponding to each of the unapplied security methods. The calculation method for the security factor of the cloud server is similar to that of the aforementioned calculation method for the security factor of the communication terminal.
7. An electronic device, characterized in that, It includes a memory and a processor; the memory stores an application program, and the processor runs the application program within the memory to perform the steps in the communication environment security early warning method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor to execute the steps of the communication environment security early warning method according to any one of claims 1 to 5.
9. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the steps of the communication environment security early warning method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Power distribution terminal safety monitoring method and device based on proxy implementation
CN107566334A
Information security risk assessment method and device, equipment and storage medium
CN111444514A