A key management system and method based on digital twinning
The key management system based on digital twin technology solves the problem of real-time monitoring in the supervision of commercial cryptography applications, realizes secure data transmission and risk assessment, improves management efficiency, and supports the verification of innovative technologies.
Patent Information
- Application Number
- CN202311190010.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-14
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-09-14
AI Technical Summary
Existing technologies lack real-time monitoring methods for commercial cryptography applications, especially in the fields of government and enterprise informatization. Cryptography management departments find it difficult to fully and quickly grasp the application status of cryptography and rely more on paper or simple electronic reporting.
A key management system based on digital twins is adopted. Data encryption and signature processing are performed through the acquisition probe of the data acquisition layer. The cryptographic application supervision platform is used for signature verification, decryption and cleansing. Risk assessment and status display are carried out in combination with the digital twin digital model.
It enables real-time and comprehensive monitoring of commercial cryptographic applications, ensures data transmission security, improves management and decision-making efficiency, dynamically displays the status of cryptographic applications, and supports the verification of innovative technologies.
Smart Images

Figure CN117353980B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of password management, and more particularly, to a key management system and method based on digital twinning. BACKGROUND
[0002] Password is the security gene of informatization development, and is the core technology to protect network and data security. At present, the commercial password industrialization development process in China is rapid, and outstanding progress has been made in product supply, system construction and other aspects of technological innovation, but the products and technologies are still mainly traditional basic hardware devices, network security devices, PKI products, etc.
[0003] At present, the password industry is developing rapidly, and there are many types of commercial password products and many system transformation systems, involving a wide range of industries. The domestic commercial password application supervision is still in its infancy, and the password management department lacks real-time monitoring means for the password construction of all systems above the third level of information security in the government and enterprise information fields. Most of them still use paper reporting methods, and some provinces have achieved partial electronicization, but only simple construction situation display, and comprehensive, rapid and true grasp of password application situation. SUMMARY
[0004] In view of the above problems, the present application provides a key management system based on digital twinning, comprising: a data acquisition layer and a password application supervision platform based on digital twinning.
[0005] The data acquisition layer acquires target data from the data source through the acquisition probe, encrypts the acquired target data with a preset encryption key, signs the acquired target data with a preset public key, obtains encrypted data with a signature of the target data, and transmits the encrypted data with a signature to the password application supervision platform.
[0006] The key application supervision platform is used for storing the decryption key corresponding to the preset encryption key and the preset public key. After receiving the encrypted data with a signature, the encrypted data with a signature is verified by the preset public key. If it is determined that the encrypted data with a signature comes from the acquisition probe, the encrypted data with a signature is decrypted by the decryption key, and the decrypted data is cleaned to obtain the to-be-processed data. The to-be-processed data is input into a preset digital twinning digital model for calculation to extract the feature information of the to-be-processed data. Based on the feature information, the risk level and public key state of the device corresponding to the data source are determined, and the feature information, risk level and public key state of the device are displayed.
[0007] Optionally, the data acquisition layer comprises a plurality of acquisition probes, each acquisition probe comprising: a data acquisition module, a data encryption module and a data signature module;
[0008] The data acquisition module is configured to acquire target data from a data source.
[0009] The data encryption module is configured to perform encryption processing using a preset encryption key.
[0010] The data signature module is configured to perform signature processing using a preset public key.
[0011] Optionally, the data source comprises at least one of the following: a business system, a cryptographic software product, a cryptographic hardware product and a cryptographic platform product.
[0012] Optionally, the data acquisition layer transmits the encrypted data with the signature to the cryptographic application supervision platform in an encrypted transmission manner.
[0013] Optionally, the key application supervision platform comprises a data processing layer.
[0014] The data processing layer comprises a key management module, a signature verification module, a decryption module and a data cleaning module.
[0015] The key management module is configured to store a decryption key corresponding to the preset encryption key and the preset public key.
[0016] The signature verification module is configured to call the preset public key stored by the key management module to perform signature verification processing on the encrypted data with the signature.
[0017] The decryption module is configured to call the preset decryption key stored by the key management module to perform decryption processing on the encrypted data with the signature to obtain decrypted data.
[0018] The data cleaning module is configured to perform data cleaning processing on the decrypted data to obtain to-be-processed data, and the data cleaning processing comprises filtering abnormal data in the decrypted data, the abnormal data comprising at least one of the following: format error data and data value deviation data.
[0019] Optionally, the key application supervision platform comprises a digital twin model layer.
[0020] The data twin model layer comprises a preset digital twin digital model.
[0021] The preset digital twin digital model comprises a data model, a risk model, a prediction model and a cryptographic decision model.
[0022] The data model is used to extract feature information of the to-be-processed data.
[0023] The risk model is used to determine a risk value of the device corresponding to the data source according to the feature information.
[0024] The prediction model is used to determine a risk level of the device corresponding to the data source according to the risk value.
[0025] The cryptographic decision model is used to determine a public key key state according to the feature information.
[0026] The public key key state includes a preset encryption key state, a preset public key state and a preset decryption key state.
[0027] Optionally, the cryptographic decision model is used to determine a public key key state according to the feature information, and the method includes:
[0028] Determining a life cycle corresponding to the public key key, and determining the public key key state based on the life cycle.
[0029] Optionally, the key application supervision platform includes a visual display layer.
[0030] The visual display layer is used to display the feature information, the risk level of the device and the public key key state.
[0031] Optionally, the visual display layer is further used to:
[0032] Simulate device information providing the public key key to obtain a position and a state of a current device providing the public key key and an application situation of the public key key, and display the position and the state of the current device providing the public key key and the application situation of the public key key.
[0033] Simulate an interface calling link of the key application supervision platform to obtain interface calling full-link node information, and display the interface calling full-link node information.
[0034] In another aspect, the application further provides a key management method based on digital twinning, including:
[0035] Collecting target data of a data source by a probe, and performing encryption processing on the collected target data by using a preset encryption key, and performing signature processing on the collected target data by using a preset public key to obtain encrypted data with a signature of the target data.
[0036] The signed encrypted data is verified by the preset public key, if it is determined that the signed encrypted data is from the collection probe, the signed encrypted data is decrypted by the decryption key to obtain decrypted data;
[0037] The decrypted data is cleaned to obtain to-be-processed data, and the to-be-processed data is input into a preset digital twin digital model for calculation to extract feature information of the to-be-processed data;
[0038] The feature information, the risk level of the device and the public key state corresponding to the data source are determined and displayed.
[0039] Compared with the prior art, the application has the following beneficial effects:
[0040] The application provides a key management system based on digital twinning, which comprises a data collection layer and a cryptographic application supervision platform based on digital twinning; the data collection layer collects target data from a data source through a collection probe, and the collected target data is encrypted by a preset encryption key and signed by a preset public key to obtain signed encrypted data of the target data, which is transmitted to the cryptographic application supervision platform; the key application supervision platform is used for storing a decryption key corresponding to the preset encryption key and the preset public key, and after receiving the signed encrypted data, the signed encrypted data is verified by the preset public key, if it is determined that the signed encrypted data is from the collection probe, the signed encrypted data is decrypted by the decryption key to obtain decrypted data, and the decrypted data is cleaned to obtain to-be-processed data, which is input into a preset digital twin digital model for calculation to extract feature information of the to-be-processed data, the feature information, the risk level of the device and the public key state corresponding to the data source are determined and displayed. The application can ensure the security of data transmission and avoid the security risks caused by password use. BRIEF DESCRIPTION OF DRAWINGS
[0041] Figure 1 It is a structure diagram of the system of the application;
[0042] Figure 2 It is a principle diagram of the system of the application;
[0043] Figure 3 It is a flowchart of the method of the application. DETAILED DESCRIPTION
[0044] Exemplary embodiments of the present invention will now be described with reference to the accompanying drawings. However, the present invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to provide a thorough and complete disclosure of the present invention and to fully convey the scope of the present invention to those skilled in the art. The terminology used in the exemplary embodiments shown in the accompanying drawings is not intended to limit the present invention. In the accompanying drawings, identical elements are denoted by the same reference numerals.
[0045] Unless otherwise specified, the terms used herein (including technical terms) have the meanings commonly understood by those skilled in the art. In addition, it is understood that terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0046] Example 1:
[0047] This invention proposes a key management system based on digital twins, the structure of which is as follows: Figure 1 As shown, the principle is as Figure 2 As shown, the system includes: a data acquisition layer and a cryptographic application supervision platform based on digital twins;
[0048] The data collection layer collects target data from the data source through a collection probe, encrypts the collected target data with a preset encryption key, and signs the collected target data with a preset public key to obtain encrypted data with a signature of the target data, and transmits the encrypted data with a signature to the cryptographic application supervision platform;
[0049] The key application supervision platform is used to store the decryption key corresponding to the preset encryption key and the preset public key. After receiving the encrypted data with the signature, the encrypted data with the signature is verified by the preset public key. If it is determined that the encrypted data with the signature comes from the acquisition probe, the encrypted data with the signature is decrypted with the decryption key to obtain the decrypted data, and the decrypted data is cleaned to obtain the data to be processed. The data to be processed is input into the preset digital twin digital model for calculation to extract the characteristic information of the data to be processed, and the risk level and public key status of the device corresponding to the data source are determined based on the characteristic information, and the characteristic information, the risk level and public key status of the device are displayed.
[0050] The data acquisition layer comprises a plurality of acquisition probes, each acquisition probe comprising a data acquisition module, a data encryption module and a data signature module.
[0051] The data acquisition module is configured to acquire target data from a data source.
[0052] The data encryption module is configured to perform encryption processing using a preset encryption key.
[0053] The data signature module is configured to perform signature processing using a preset public key.
[0054] The data source comprises at least one of a business system, a cryptographic software product, a cryptographic hardware product and a cryptographic platform product.
[0055] The data acquisition layer transmits the encrypted data with the signature to the cryptographic application supervision platform in an encrypted transmission mode.
[0056] The key application supervision platform comprises a data processing layer.
[0057] The data processing layer comprises a key management module, a signature verification module, a decryption module and a data cleaning module.
[0058] The key management module is configured to store a decryption key corresponding to the preset encryption key and the preset public key.
[0059] The signature verification module is configured to call the preset public key stored in the key management module to perform signature verification processing on the encrypted data with the signature.
[0060] The decryption module is configured to call the preset decryption key stored in the key management module to perform decryption processing on the encrypted data with the signature to obtain decrypted data.
[0061] The data cleaning module is configured to perform data cleaning processing on the decrypted data to obtain to-be-processed data, and the data cleaning processing comprises filtering abnormal data in the decrypted data, the abnormal data comprising at least one of format error data and data value deviation data.
[0062] The key application supervision platform comprises a digital twin model layer.
[0063] The data twin model layer comprises a preset digital twin digital model.
[0064] The preset digital twin digital model comprises a data model, a risk model, a prediction model and a cryptographic decision model.
[0065] The data model is used to extract feature information of the to-be-processed data;
[0066] The risk model is used to determine a risk value of the device corresponding to the data source according to the feature information;
[0067] The prediction model is used to determine a risk level of the device corresponding to the data source according to the risk value;
[0068] The cryptographic decision model is used to determine a public key key state according to the feature information;
[0069] The public key key state comprises a preset encryption key state, a preset public key state and a preset decryption key state.
[0070] The cryptographic decision model is used to determine a public key key state according to the feature information, and comprises:
[0071] A life cycle of the public key key is determined, and the public key key state is determined based on the life cycle.
[0072] The key application supervision platform comprises a visual display layer.
[0073] The visual display layer is used to display the feature information, the risk level of the device and the public key key state.
[0074] The visual display layer is further used to:
[0075] simulate device information providing the public key key, obtain a position and a state of a current device providing the public key key and an application situation of the public key key, and display the position and the state of the current device providing the public key key and the application situation of the public key key.
[0076] simulate an interface calling link of the key application supervision platform, obtain interface calling full-link node information, and display the interface calling full-link node information.
[0077] In the application, the data collection layer collects various data such as password software and hardware configuration, password service calling, password business log and traffic information according to the overall network environment of the three-level system password construction. The collection layer mainly comprises an improved data collection probe. The data collection probe adds a data encryption module and a data signature module on the basis of the data collection function of the traditional network probe. The data encryption adopts a national secret symmetric encryption algorithm to ensure the confidentiality of the transmission data, and the data can be safely and efficiently transmitted even in an untrusted network channel. The data signature module can ensure the identity of each probe is trusted, and avoids man-in-the-middle attack behavior. Meanwhile, the log data transmitted by the collection probe needs to be digitally signed by using the private key of the probe to ensure that the business operation is auditable, traceable and non-repudiable.
[0078] The main function of the supervision platform in the application is to model and simulate the collected legal, reliable and correct data, so as to dynamically and multi-dimensionally display the password application state information through the technical means of digital twinning, and assist the decision-making and business development of the supervision department.
[0079] The function of the password data processing layer is as follows:
[0080] The decryption module uses the decryption key corresponding to the collection probe to decrypt the collected data, so as to restore the real data. Before data decryption, data signature verification operation needs to be performed in priority, to ensure that the identity of the collection probe providing the data is reliable. If the signature verification fails, the data packet is discarded, and the data packet processing efficiency is improved.
[0081] The signature verification module performs signature verification operation on the collected data packet, to avoid man-in-the-middle attack in the transmission process, and to ensure the completeness of the data and the non-repudiation of the operation behavior.
[0082] The key management module manages the public key of the collection probe, and uses the public key for signature verification operation in the signature verification operation.
[0083] The data cleaning module, also known as the data quality management module, filters abnormal data in the data packet, such as format error and data value deviation, to ensure the accuracy of the modeling data.
[0084] The function of the digital twinning model layer is as follows:
[0085] The data model converts the knowledge of the supervision industry standard, engineering experience and theoretical formula into a model library, and combines the password service calling information, traffic information and log information, to be used for data modeling based on machine learning.
[0086] The risk model relies on machine learning algorithm, combines the long-period context access data of the access entity, and describes the behavior baseline of a single entity or a group. The current behavior data of the entity is compared with the dynamic baseline of the single entity or the group, and the behavior deviating from the baseline too much is defined as abnormal, to generate the behavior risk value.
[0087] The prediction model is based on the gray Markov model, to predict the access behavior, dynamically estimate, schedule and supplement the password application resources and possible security risks.
[0088] The password decision model assists the management department in decision-making around the whole life cycle of the key. The decision relies on state monitoring algorithm and fault diagnosis algorithm.
[0089] The function of the visual display layer is as follows:
[0090] Password device information simulation. The IP address, service state, call record and other information of the password device are summarized to simulate the current device location and state.
[0091] Password application information simulation. By summarizing password application information, the password application situation is dynamically displayed to provide a unified business handle for the management department to master the current password application situation.
[0092] Interface call link simulation. Through traffic analysis, the interface call full link node information of password devices, services and the like is dynamically displayed.
[0093] Full supervision business linkage simulation. The supervision department simultaneously supervises the password construction of multiple organizations and multiple systems, and through virtual display, the password construction information distributed in multiple clouds and multiple organization machine rooms is linked and simulated to realize full supervision of the whole province or even the whole country.
[0094] Password application innovation technology verification. In the simulation environment, the innovative technology scheme verification for password application is carried out. Through the direct operation of the virtual environment for the addition, deletion, optimization and modification of the configuration of the password hardware and software and network equipment, the new technology of the password application actual environment can be pre-verified, which is helpful for password technology innovation.
[0095] The present application introduces the digital twin technology and concept into the supervision of commercial password application, which is an innovation in the field of supervision of commercial password application. Through virtual dynamic display, the simulation recovery of real physical password application can be realized, and the real situation of password application can be mastered in real time, which is helpful for risk monitoring and password decision.
[0096] In the data collection layer of the supervision of commercial password application, the data collection probe with a password operation module is used, and the collected data is encrypted, signed and the like, so that the safe transmission of the data to the digital twin model layer is realized, and the data is protected from tampering. In the supervision of commercial password application, there is no design for the security protection of the collected password data.
[0097] The password data processing layer of the present application includes a password operation module and a key management module, which performs real-time data decryption and electronic signature verification on the data transmitted by the collection probe, to ensure the authenticity of the received data. The key management module manages the public keys of all collection probes, and can effectively verify the non-repudiation of the data.
[0098] The present application uses a simulation design with password characteristics, realizes the linkage of full supervision password business, and fully simulates and displays the password construction and operation of multiple clouds and multiple machine rooms. At the same time, it can be used for password application innovation technology verification. Since the direct operation in the physical environment has a greater impact on the business, the design of the characteristic simulation breaks the blank that the new password scheme cannot be tried in the virtual environment in advance.
[0099] The application greatly improves the management and decision-making efficiency of the password management department, realizes the virtualization simulation of password application through digital twin technology, enables the password management department to analyze password application risks, predict password construction effects, verify password technical solutions, assist password decision-making, and guide password business compliance and effective development.
[0100] The application ensures the confidentiality, integrity and non-repudiation of the collected data through the modified collection probe, and can accurately reflect the real password application situation.
[0101] The application adopts encryption and signature verification methods to ensure the confidentiality and integrity of the data.
[0102] The application can more effectively reflect the real physical environment information, realize diversified display of multiple networks, and provide core capabilities for verifying technical solution innovations.
[0103] Embodiment 2:
[0104] In another aspect, the application also provides a key management method based on digital twin, as shown in Figure 3 The method comprises the following steps:
[0105] Step 1: collecting target data at a data source through a collection probe, and performing encryption processing on the collected target data with a preset encryption key, and performing signature processing on the collected target data with a preset public key to obtain encrypted data with a signature of the target data;
[0106] Step 2: verifying the encrypted data with a signature through the preset public key, and if it is determined that the encrypted data with a signature comes from the collection probe, then decrypting the encrypted data with a signature with the decryption key to obtain decrypted data;
[0107] Step 3: performing cleaning processing on the decrypted data to obtain to-be-processed data, and inputting the to-be-processed data into a preset digital twin digital model for calculation to extract feature information of the to-be-processed data;
[0108] Step 4: determining the risk level and public key state of the device corresponding to the data source based on the feature information, and displaying the feature information, the risk level of the device and the public key state.
[0109] The application can ensure the security of data transmission and avoid the security risks caused by password use.
[0110] It will be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented in various computer languages, for example, the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0111] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0112] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0114] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0115] It will be apparent to those skilled in the art that various modifications and variations can be made to the present application without departing from the spirit or scope of the application. Thus, it is intended that the present application cover modifications and variations of this application provided they come within the scope of the appended claims and their equivalents.
Claims
1. A key management system based on digital twinning, characterized by, The key management system comprises a data collection layer and a key application supervision platform based on digital twinning. The data collection layer collects target data from a data source through a collection probe, encrypts the collected target data with a preset encryption key, signs the collected target data with a private key of the collection probe, obtains signed and encrypted data of the target data, and transmits the signed and encrypted data to the key application supervision platform. The key application supervision platform stores a decryption key corresponding to the preset encryption key and a public key corresponding to the private key of the collection probe, verifies the signed and encrypted data by using the preset public key after receiving the signed and encrypted data, determines that the signed and encrypted data come from the collection probe, decrypts the signed and encrypted data by using the decryption key to obtain decrypted data, cleans the decrypted data to obtain to-be-processed data, inputs the to-be-processed data into a preset digital twinning digital model for calculation to extract feature information of the to-be-processed data, determines a risk level and a public key state of a device corresponding to the data source based on the feature information, and displays the feature information, the risk level and the public key state.
2. The key management system of claim 1, wherein, The data collection layer comprises a plurality of collection probes, each of which comprises a data collection module, a data encryption module and a data signing module. The data collection module is configured to collect target data from a data source. The data encryption module is configured to encrypt the collected target data with a preset encryption key. The data signing module is configured to sign the collected target data with a private key of the collection probe.
3. The key management system of claim 1, wherein, The data source comprises at least one of a business system, a key software product, a key hardware product and a key platform product.
4. The key management system of claim 1, wherein, The data collection layer transmits the signed and encrypted data to the key application supervision platform in an encrypted transmission mode.
5. The key management system of claim 1, wherein, The key application supervision platform comprises a data processing layer. The data processing layer comprises a key management module, a verification module, a decryption module and a data cleaning module. The key management module is configured to store a decryption key corresponding to the preset encryption key and a public key corresponding to the private key of the collection probe. The verification module is configured to call the public key corresponding to the private key of the collection probe stored in the key management module to verify the signed and encrypted data. The decryption module is configured to call the preset decryption key stored in the key management module to decrypt the signed and encrypted data to obtain decrypted data. The data cleaning module is configured to clean the decrypted data to obtain to-be-processed data, and the data cleaning process comprises filtering abnormal data in the decrypted data, wherein the abnormal data comprises at least one of format error data and data value deviation data.
6. The key management system of claim 1, wherein, The key application supervision platform comprises a digital twinning model layer. The digital twin model layer comprises a preset digital twin digital model; The preset digital twin digital model comprises a data model, a risk model, a prediction model, and a key decision model; The data model is used to extract feature information of the to-be-processed data; The risk model is used to determine a risk value of a device corresponding to the data source according to the feature information; The prediction model is used to determine a risk level of the device corresponding to the data source according to the risk value; The key decision model is used to determine a public key state according to the feature information; The public key state comprises a preset encryption key state, a preset public key state, and a preset decryption key state.
7. The key management system of claim 6, wherein, The key decision model is used to determine a public key state according to the feature information, comprising: Determining a life cycle of the public key, and determining the public key state based on the life cycle.
8. The key management system of claim 1, wherein, The key application supervision platform comprises a visual display layer; The visual display layer is used to display the feature information, the risk level of the device, and the public key state.
9. The key management system of claim 8, wherein, The visual display layer is further used to: Simulate device information providing a public key to obtain a position and a state of a current device providing the public key and an application situation of the public key, and display the position and the state of the current device providing the public key and the application situation of the public key; Simulate an interface calling link of the key application supervision platform to obtain interface calling full-link node information, and display the interface calling full-link node information. 10.A key management method based on digital twinning, characterized in that, The key management method comprises: Collecting target data of a data source by a collection probe, encrypting the collected target data by a preset encryption key, and signing the collected target data by a private key of the collection probe to obtain encrypted data with a signature of the target data; Verifying the encrypted data with the signature by a public key corresponding to the private key of the collection probe, and if it is determined that the encrypted data with the signature is from the collection probe, decrypting the encrypted data with the signature by a decryption key corresponding to the preset encryption key to obtain decrypted data; Cleaning the decrypted data to obtain to-be-processed data, inputting the to-be-processed data into a preset digital twin digital model for calculation to extract feature information of the to-be-processed data; Determining a risk level of a device corresponding to the data source and a public key state based on the feature information, and displaying the feature information, the risk level of the device, and the public key state.
Citation Information
Patent Citations
Digital twin data secure storage method and device, electronic equipment and storage medium
CN115484032A
Synchronous group key negotiation method in digital twin network
CN116192381A