A security management method and system based on communication networking

By collecting and splicing user voice and facial features into multi-modal feature vectors, combined with the network key database and special password verification, the problem of low security of simple keys in communication networks is solved, and highly secure and reliable network verification is achieved.

CN119182533BActive Publication Date: 2025-09-19GUANGZHOU SUNNYSITE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411184642.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-27
Publication Date
2025-09-19
Estimated Expiration
2044-08-27

AI Technical Summary

Technical Problem

The existing communication network uses simple character combinations as network keys, which has low security and is prone to data leakage and network insecurity.

Method used

By collecting the voiceprint features and semantic features of user voice information and the facial features of face information, splicing them into multi-modal feature vectors, combining them with the network key database for verification, and performing special password verification and manual re-inspection when necessary, user behavior is dynamically monitored to improve security.

Benefits of technology

It achieves accurate and secure verification based on multiple biometric features, prevents networking keys from being easily stolen, and improves the security and reliability of communication networking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119182533B_ABST
    Figure CN119182533B_ABST
Patent Text Reader

Abstract

The present application discloses a security management method and system based on communication networking. The technical solution provided by the present application combines multiple biometric features of users for network verification, and performs special information rechecks and manual rechecks based on the login status of the network terminal and user account. This allows for accurate security verification using a user's multiple unique biometric features, preventing easy theft of network keys and improving the security and reliability of communication networking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technology, and in particular to a security management method and system based on communication networking. Background Art

[0002] Currently, communication networking is a crucial component of modern communications technology, enabling rapid information transmission and device interoperability. Communication networking involves connecting multiple communication devices or systems through a specific network topology and communication protocols to form a network system capable of mutual communication and resource sharing. This process aims to achieve efficient information transmission, device interoperability, and resource sharing. With the continuous advancement of communication technology, communication networking technology is becoming increasingly secure. By setting a corresponding networking key, each user terminal enters the network authentication key upon network access to verify the terminal's security.

[0003] However, the existing method of using a simple character combination as a network key for network authentication has relatively low security. Once the network key is leaked, it will affect network security, leading to data leakage and unnecessary losses. Summary of the Invention

[0004] The embodiments of the present application provide a security management method and system based on communication networking, which can perform network authentication through multiple unique characteristics of users, improve the security of communication networking, and solve security problems in the communication networking process.

[0005] In a first aspect, an embodiment of the present application provides a security management method based on communication networking, including:

[0006] In response to a network access request from a current networking terminal, parsing a target user account, user voice information, and user facial information carried in the network access request, collecting voiceprint features and semantic features based on the user voice information, collecting facial features based on the user facial information, splicing the voiceprint features, the semantic features, and the facial features into a multi-modal feature vector, traversing a networking key database based on the multi-modal feature vector and the target user account, and performing network verification on the current user terminal based on the traversal result, wherein the networking key database is pre-configured with multi-modal feature keys corresponding to different account information;

[0007] After the networking verification is passed, if the current networking terminal has logged into the current networking system multiple times, the uplink and downlink data of the current networking terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current networking system for the first time, the special expression password or special voice password uploaded by the current networking terminal is collected, and a pre-built repeated verification database is queried based on the special expression password or the special voice password. When matching facial expression information or semantic tone information is queried, the uplink and downlink data of the current networking terminal are encrypted and transmitted based on the multi-mode feature vector. When no matching facial expression information or audio tone information is queried, the network access request is rejected;

[0008] When it is detected that the frequency of switching networking terminals of the target user account reaches a set threshold, the user dynamic video information reported by the current networking terminal is obtained, and the networking terminal of the specified user account is randomly selected in the current networking system to send the user dynamic video information, so as to perform a manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account.

[0009] Furthermore, traversing a networking key database based on the multi-mode feature vector and the target user account, and performing networking verification on the current user terminal based on the traversal result, includes:

[0010] Traversing the networking key database based on the target user account, determining account information that matches the target user account, and extracting the multi-mode feature key configured for the matched account information;

[0011] Calculate the feature similarity between the extracted multimodal feature key and the multimodal feature vector. When the feature similarity reaches the set similarity threshold, determine that the network verification is passed. The similarity threshold is set according to the network access priority of the target user account, and the similarity threshold is positively correlated with the network access priority.

[0012] Furthermore, the encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes:

[0013] Constructing a first key feature sequence based on the multi-mode feature vector, and generating an encryption key sequence according to the first key feature sequence and a set networking key sequence;

[0014] The uplink and downlink data of the current networking terminal are encrypted, transmitted, and decrypted based on the encryption key sequence.

[0015] Furthermore, the encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes:

[0016] Constructing a second key feature sequence based on the multimodal feature vector, and splitting the second key feature sequence into multiple sub-feature sequences according to a set splitting rule;

[0017] Based on the multiple sub-feature sequences, encryption, transmission and decryption operations are performed on different types of uplink and downlink data of the current networking terminal.

[0018] Furthermore, after the network verification is passed, the method further includes:

[0019] Real-time video call information is parsed from uplink data of the current networking terminal, and dynamic video verification of the current networking terminal is performed based on the real-time video call information and the user face information.

[0020] Furthermore, before responding to the network access request of the current networking terminal, the method further includes:

[0021] Semantic prompt information associated with the designated semantic vocabulary is issued, so as to collect the voice information containing the designated semantic vocabulary based on the semantic prompt information.

[0022] Furthermore, when it is detected that the frequency of switching networking terminals of the target user account reaches a set threshold, the method further includes:

[0023] Disable the specified function permissions of the current network terminal, wherein the specified function permissions include at least one of voice call permission, video call permission, and file sharing permission;

[0024] Correspondingly, after manually rechecking the current networking terminal based on the user dynamic video information, the method further includes:

[0025] After the manual re-inspection is detected, the specified function permissions of the current networking terminal are enabled.

[0026] In a second aspect, an embodiment of the present application provides a security management system based on communication networking, including:

[0027] a network verification module, configured to respond to a network access request from a current network terminal, parse a target user account, user voice information, and user facial information carried in the network access request, collect voiceprint features and semantic features based on the user voice information, collect facial features based on the user facial information, concatenate the voiceprint features, the semantic features, and the facial features into a multi-modal feature vector, traverse a network key database based on the multi-modal feature vector and the target user account, and perform network verification on the current user terminal based on the traversal result, wherein the network key database is pre-configured with multi-modal feature keys corresponding to different account information;

[0028] A networking recheck module is configured to, after the networking verification is passed, directly encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector if the current networking terminal has logged into the current networking system multiple times; if the current network terminal logs into the current networking system for the first time, collect the special expression password or special voice password uploaded by the current networking terminal, query a pre-built repeated verification database based on the special expression password or the special voice password, and when matching facial expression information or semantic tone information is queried, encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector; and when no matching facial expression information or audio tone information is queried, reject the network access request;

[0029] The manual re-inspection module is used to obtain the user dynamic video information reported by the current networking terminal when it is detected that the frequency of the target user account switching networking terminals reaches a set threshold, and randomly select the networking terminal of the specified user account in the current networking system to send the user dynamic video information, so as to perform a manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account.

[0030] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0031] memory and one or more processors;

[0032] The memory is used to store one or more programs;

[0033] When the one or more programs are executed by the one or more processors, the one or more processors implement the security management method based on communication networking as described in the first aspect.

[0034] In a fourth aspect, an embodiment of the present application provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to execute the security management method based on communication networking as described in the first aspect.

[0035] The embodiment of the present application responds to the network access request of the current networking terminal, parses the target user account, user voice information and user face information carried in the network access request, collects voiceprint features and semantic features based on the user voice information, collects face features based on the user face information, splices the voiceprint features, semantic features and face features into a multi-mode feature vector, traverses the networking key database based on the multi-mode feature vector and the target user account, and performs networking verification on the current user terminal based on the traversal result. The networking key database pre-configures multi-mode feature keys corresponding to different account information; after the network verification is passed, if the current networking terminal has logged into the current networking system multiple times, the uplink and downlink data of the current networking terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current networking system for the first time, collects the special expression password or special The voice password queries a pre-built re-verification database based on a special expression password or a special voice password. When matching facial expression information or semantic tone information is found, the uplink and downlink data of the current network terminal are encrypted and transmitted based on the multi-modal feature vector. If no matching facial expression information or audio tone information is found, the network access request is rejected. When it is detected that the frequency of the target user account switching network terminals reaches a set threshold, the user dynamic video information reported by the current network terminal is obtained, and the network terminal of the specified user account is randomly selected in the current network system to send the user dynamic video information. The user dynamic video information is then used to perform a manual re-inspection of the current network terminal. Based on the received manual re-inspection result, a decision is made whether to disconnect the network link of the current network terminal. The specified user account has a higher network access priority than the target user account. The above technical means are used to combine multiple biometric features of the user for network verification, and special information re-inspection and manual re-inspection are performed based on the login status of the network terminal and the user account. This can comprehensively utilize multiple unique biometric information of the user for accurate security verification, prevent the easy theft of network keys, and improve the security and reliability of the communication network. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 This is a flow chart of a security management method based on communication networking provided in Example 1 of the present application;

[0037] Figure 2 This is a schematic diagram of the interaction between the networking terminal and the networking server in Example 1 of the present application;

[0038] Figure 3 This is a schematic diagram of identifying multimodal feature vectors in Example 1 of the present application;

[0039] Figure 4 This is the network verification flow chart in Example 1 of the present application;

[0040] Figure 5This is a flowchart of multiple network verification in Example 1 of the present application;

[0041] Figure 6 This is a schematic diagram of the structure of a security management system based on communication networking provided in Example 2 of the present application;

[0042] Figure 7 This is a structural diagram of an electronic device provided in Example 2 of the present application. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solutions and advantages of the present application clearer, the specific embodiments of the present application are further described in detail below in conjunction with the accompanying drawings. It is understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. It should also be noted that, for ease of description, only parts related to the present application, not all of the contents, are shown in the accompanying drawings. Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe each operation (or step) as a sequential process, many of the operations therein can be implemented in parallel, concurrently or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but can also have additional steps not included in the accompanying drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.

[0044] Example 1:

[0045] Figure 1 A flowchart of a communication networking-based security management method provided in Example 1 of the present application is provided. The communication networking-based security management method provided in this embodiment can be executed by a communication networking-based security management device. The communication networking-based security management device can be implemented through software and / or hardware. The communication networking-based security management device can be composed of two or more physical entities or a single physical entity. Generally speaking, the communication networking-based security management device can be a communication device such as a networking server, gateway, or base station.

[0046] This application provides a highly secure and multi-level communication network security management method, which aims to enhance the security and reliability of the networking system by combining multi-modal biometric recognition, special password verification, and dynamic monitoring and manual review mechanisms.

[0047] Among them, when a networking terminal (such as a smart phone, computer, etc.) initiates a network access request, the system (i.e., the security management device based on the communication network) first receives the request and parses the target user account, user voice information, and user face information carried therein. Then, voiceprint features (such as the frequency and amplitude of the voice, etc.) and semantic features (converted to text and analyzed through voice recognition technology) are extracted from the user's voice information; facial features are extracted from the user's face information through face recognition technology, specifically including the position and shape of key points such as facial contours, eyes, nose, and mouth. Then, the extracted voiceprint features, semantic features, and facial features are spliced ​​into a multimodal feature vector, which will serve as the main basis for the subsequent verification process.

[0048] Using the multimodal feature vector and the target user account as query criteria, the system traverses the networking key database. This database pre-stores multimodal feature keys corresponding to different account information and is used to verify user identity. If a matching multimodal feature key is found in the database, verification succeeds and the network terminal is allowed to access the system; otherwise, the access request is denied.

[0049] For network terminals that pass network verification, further login status verification is performed. For network terminals that have logged into the system multiple times, uplink and downlink data is encrypted directly based on multimodal feature vectors to ensure data security. For first-time logins, the system requires the user to upload a special expression password or a special voice password. These passwords are verified by querying a pre-built repeated verification database. If a matching facial expression or semantic tone information is found in the database, data encryption transmission continues based on the multimodal feature vector. If no match is found, the network access request is rejected, preventing potential security risks.

[0050] In addition, the system continuously monitors the frequency with which the target user account switches networking terminals. If the set threshold is reached, it indicates that the target user account may be engaging in abnormal behavior or presenting a security risk. Upon detecting an anomaly, the system obtains the user's dynamic video information reported by the current networking terminal. It then randomly selects a designated networking terminal (such as an administrator terminal) with a higher network access priority than the target user account in the current networking system and issues the user's dynamic video information. The operator of the designated networking terminal then conducts a manual recheck based on the user's dynamic video information to assess the legitimacy of the current networking terminal or address any anomalies. Based on the recheck results, the system decides whether to disconnect the current networking terminal's networking link to ensure network security and stability.

[0051] Through the above implementation process, not only the security of the communication network is improved, but also the risks of unauthorized access and data leakage are effectively prevented through multi-level verification and monitoring mechanisms.

[0052] The following description will be made by taking the communication network-based security management device as an example to execute the communication network-based security management method. Figure 1 The security management method based on communication networking specifically includes:

[0053] S110. In response to the network access request of the current networking terminal, parse the target user account, user voice information and user face information carried in the network access request, collect voiceprint features and semantic features based on the user voice information, collect face features based on the user face information, splice the voiceprint features, semantic features and face features into a multi-mode feature vector, traverse the networking key database based on the multi-mode feature vector and the target user account, and perform networking verification on the current user terminal based on the traversal result. The networking key database is pre-configured with multi-mode feature keys corresponding to different account information.

[0054] like Figure 2 As shown, the server 11 communicates with each networking terminal 12. When a networking terminal 12 (such as a computer, smart phone, etc.) initiates a network access request, the server 11 first receives the network access request and parses the target user account, user voice information and user face information carried therein, and then extracts multiple modal biometric features from the user voice information and user face information to comprehensively perform network access verification.

[0055] Specifically, refer to Figure 3 This application uses a semantic feature acquisition model based on a neural network to collect semantic features in user voice information, uses a voiceprint feature acquisition model to collect voiceprint features in user voice information, and uses a facial feature acquisition model to collect facial features in user facial information.

[0056] In order to combine semantic features, voiceprint features, and facial features for network access verification, this application integrates multiple different machine learning or deep learning models to collect various modal features by calling existing models or training new models.

[0057] Among them, for the collection of semantic features, existing models of the BERT or GPT series can be used. These models are widely used in natural language processing tasks, especially for understanding and generating text. You can also use pre-trained models to extract semantic features after speech-to-text conversion, by using speech recognition services (such as Google Speech-to-Text, IBM Watson Speech to Text, etc.) to convert speech into text, and then use the NLP model to process the text to obtain semantic features. It is understandable that if the semantic features of a specific field are critical to identity authentication, it may be necessary to train a specific NLP model for that field.

[0058] For voiceprint feature collection, you can use existing voiceprint recognition libraries such as VoxCeleb and Speaker Recognition Toolkit (SRTK). Voiceprint recognition libraries provide pre-trained models for extracting voiceprint features. You can also use models in deep learning frameworks such as TensorFlow and pre-trained models in PyTorch. These models are based on convolutional neural networks (CNN) or recurrent neural networks (RNN) to process user voice information and obtain semantic features. Similarly, in order to more accurately identify the voiceprints of specific groups of people, you can collect voiceprint data from specific groups of people and train a dedicated voiceprint recognition model.

[0059] Facial feature collection can be achieved using facial recognition libraries such as OpenCV, dlib, and FaceNet. These libraries provide pre-trained models for detecting faces and extracting features. If you need to optimize facial recognition for specific populations or environments, you can collect large amounts of labeled facial data and train a dedicated model.

[0060] Finally, the three biometric features collected by the three models are effectively fused using a feature fusion model (semantics, voiceprint, and face). The feature fusion model can perform feature fusion through simple concatenation or use more complex fusion techniques (such as weighted sums and deep learning fusion layers). This application does not impose any fixed restrictions on the specific feature fusion method, so it will not be detailed here.

[0061] The multimodal feature vector and the target user account are further used as query conditions to traverse the networking key database. This database pre-stores multimodal feature keys corresponding to different account information for user identity verification. The multimodal feature key is collected when the user registers the user account. The multimodal feature key is constructed based on the user's original facial features, voiceprint features, and corresponding semantic features. Its collection and splicing method is the same as the multimodal feature vector described above, so it will not be detailed here. If a matching multimodal feature key is found in the database, the verification is successful and the networking terminal is allowed to access the system; otherwise, the network access request is rejected.

[0062] Optionally, refer to Figure 4 , based on the multi-mode feature vector and the target user account, the network key database is traversed, and the network verification of the current user terminal is performed based on the traversal result, including:

[0063] S1101: traverse the networking key database based on the target user account, determine the account information that matches the target user account, and extract the multi-mode feature key configured for the matched account information;

[0064] S1102. Calculate the feature similarity between the extracted multi-mode feature key and the multi-mode feature vector. If the feature similarity reaches a set similarity threshold, determine that the network verification is passed. The similarity threshold is set according to the network access priority of the target user account, and the similarity threshold is positively correlated with the network access priority.

[0065] In the process of traversing the networking key database based on the multi-mode feature vector and the target user account to perform network verification, it is first necessary to search for account information that matches the target user account in the networking key database. The system first uses the target user account as a query condition to traverse the networking key database, which stores multiple account information and its corresponding multi-mode feature key. During the traversal process, the system will compare whether the account information in the database is consistent with the target user account or whether there is a certain mapping relationship (such as account alias, association ID, etc.). Once the matching account information is found, the system will extract the multi-mode feature key configured for the account information and prepare for the next step of feature similarity calculation. Then, by comparing the similarity between the extracted multi-mode feature key and the multi-mode feature vector in the current network access request, it is determined whether the network verification is passed.

[0066] Use feature similarity calculation methods (such as cosine similarity, Euclidean distance, Manhattan distance, etc.) to calculate the similarity between the extracted multimodal feature key and the multimodal feature vector in the current network access request. The result of the similarity calculation will be compared with a set similarity threshold. This similarity threshold is set according to the network access priority of the target user account. The higher the priority of the account, the higher the similarity threshold needs to be set to ensure the high accuracy of the network access verification for the high-priority account. Different users or user groups have different network access priorities. By setting different similarity thresholds according to the network access priority, the system can respond more flexibly to different security needs and scenarios.

[0067] If the calculated feature similarity reaches or exceeds the set similarity threshold, the system determines that the network verification has passed and proceeds to the next step of verification. If the feature similarity is lower than the set similarity threshold, the system determines that the network verification has failed, rejects the current user terminal's network access request, and returns a corresponding error message or prompt information.

[0068] It should be noted that the similarity threshold is adaptively set based on the actual network authentication accuracy requirements to ensure that unauthorized access is effectively prevented while avoiding false rejection of legitimate users. This threshold can be adjusted and optimized based on extensive experimental data and actual scenarios.

[0069] Optionally, before responding to the network access request of the current networking terminal, the method further includes:

[0070] Semantic prompt information associated with the specified semantic vocabulary is issued, so as to collect voice information containing the specified semantic vocabulary based on the semantic prompt information.

[0071] By instructing users to input information containing specific semantic vocabulary via voice, the system can enhance security, verification accuracy, and efficiency. The system constructs a set of question-and-answer messages, with semantic prompts serving as the questions and designated semantic vocabulary serving as the answers. The user's voice information is only valid if it contains the designated semantic vocabulary. The system simply collects the user's correct semantic features based on the designated semantic vocabulary to construct a multi-modal feature key, achieving more accurate network access verification.

[0072] During network access verification, the system sends semantic prompts to users, guiding them to include the correct response (specific semantic vocabulary) when speaking a voice message. After receiving the semantic prompts, the user follows the prompts and speaks a voice message containing the specified semantic vocabulary in their network access request. The current network terminal collects this voice message and sends it to the system as part of the network access request. Upon receiving the network access request containing the voice message, the system performs operations such as parsing, feature extraction, and multi-modal feature vector concatenation according to the aforementioned process, achieving efficient and accurate network access verification.

[0073] S120. After the network verification is passed, if the current network terminal has logged into the current network system multiple times, the uplink and downlink data of the current network terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current network system for the first time, the special expression password or special voice password uploaded by the current network terminal is collected, and the pre-built repeated verification database is queried based on the special expression password or special voice password. When matching facial expression information or semantic tone information is queried, the uplink and downlink data of the current network terminal are encrypted and transmitted based on the multi-mode feature vector. When no matching facial expression information or audio tone information is queried, the network access request is rejected.

[0074] After network verification is passed, the system will conduct a network recheck based on the current target user account and the login history of the current network terminal to determine whether to allow network access and determine the subsequent data encryption transmission strategy. This ensures the security of data transmission and improves the flexibility and convenience of user verification.

[0075] The system checks the login history of the current target user account and the current networking terminal.

[0076] If the current target user account has logged into the current network system multiple times through the current network terminal, the recheck is passed and network access is allowed. If the current target user account logs into the current network system for the first time through the current network terminal, the special password collection and verification process will be executed.

[0077] Specifically, the system prompts the user to upload a special expression password or a special voice password. According to the prompt, the user uploads data containing special expressions or special voices through the current networking terminal. The system collects this data and extracts facial expression information or semantic tone information. Based on the extracted information, the pre-built repeated verification database is queried. If matching facial expression information or semantic tone information is found in the database, the re-inspection is passed and network access is allowed. If no matching information is found, the network access request is rejected and a corresponding error message or prompt message is returned. It is understandable that in order to avoid unauthorized network access due to information forgery, repeated verification is required for network access using unfamiliar networking terminals. Considering that the user's special expression information or special voice information containing semantic tone is highly unique and extremely difficult to forge, this part of the user's information is pre-stored and saved in the repeated verification database so that repeated verification can be performed when needed.

[0078] Once the target user account is confirmed to be authorized for network access, the system uses the multi-mode feature vector to encrypt the transmission of uplink and downlink data from the current networked terminal. During data transmission, the system uses the multi-mode feature vector to construct a portion of the encryption key, encrypting and decrypting the transmitted data to ensure data security. By using highly unique multi-mode feature vectors for uplink and downlink data transmission, data can be easily protected from theft. Even other terminals in the network system do not possess the corresponding key information, achieving high data transmission security through high uniqueness.

[0079] Optionally, performing encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes:

[0080] Constructing a first key feature sequence based on the multi-mode feature vector, and generating an encryption key sequence according to the first key feature sequence and a set networking key sequence;

[0081] The uplink and downlink data of the current networking terminal are encrypted, transmitted and decrypted based on the encryption key sequence.

[0082] In the process of encrypting and transmitting uplink and downlink data of the current networking terminal based on the multi-mode feature vector, the multi-mode feature vector is converted into a key feature sequence of a fixed length, namely, the first key feature sequence, using a hash function, an encryption algorithm or a related mathematical transformation method, so as to retain the key information of the multi-mode feature vector and convert it into a form suitable for encryption.

[0083] The system then extracts the predefined, fixed, and shared networking key sequence. The system combines the first key signature sequence with the networking key sequence and generates an encryption key sequence using a corresponding algorithm (such as an XOR operation, a hash function, or a related key generation algorithm). This generates a unique encryption key sequence between the current networking terminal and the system server, valid only for the current session of the current networking terminal.

[0084] During subsequent data transmission, the system uses the generated encryption key sequence to encrypt the uplink and downlink data of the current networked terminal. All transmitted data is encrypted to prevent interception and theft during transmission. After receiving the encrypted data, the current networked terminal uses the same encryption key sequence (generated using the same method after the current networked terminal completes network access) to decrypt the data and restore the original data. This method enables the system to encrypt the uplink and downlink data of the current networked terminal based on multimodal feature vectors, ensuring security and confidentiality during data transmission.

[0085] Optionally, encrypted transmission of uplink and downlink data of the current networking terminal based on the multi-mode feature vector includes:

[0086] Constructing a second key feature sequence based on the multi-mode feature vector, and splitting the second key feature sequence into multiple sub-feature sequences according to a set splitting rule;

[0087] Based on multiple sub-feature sequences, encryption, transmission and decryption operations are performed on different types of uplink and downlink data of the current networking terminals.

[0088] In the process of encrypting and transmitting uplink and downlink data of the current networking terminal based on the multi-mode feature vector,

[0089] The multimodal feature vector can also be converted into multiple sub-feature sequences and used to encrypt different types of data respectively, thereby providing a flexible and efficient data encryption transmission method.

[0090] Similarly, the system constructs a second key feature sequence based on the multi-mode feature vector of the current networking terminal through a hash function, encryption algorithm or related mathematical transformation method.

[0091] The second key signature sequence is then split into multiple sub-signature sequences according to a predetermined splitting rule. The splitting rule can be set based on factors such as data type, data importance, and encryption requirements. For example, the key sequence can be split according to a fixed length sequence, a specific pattern, or different data types.

[0092] Then, based on the uplink and downlink data types of the current networking terminal (such as control instructions, user data, sensitive information, audio and video, etc.), the corresponding sub-signature sequence is selected for encryption. Each sub-signature sequence can be used to encrypt one or more types of data, and is adaptively set based on the actual splitting rules and data encryption strategy.

[0093] During the encryption process, the system uses the selected sub-signature sequence as the encryption key to encrypt the target data. The encrypted data remains encrypted during transmission to prevent unauthorized access. Upon receiving the encrypted data, the receiver decrypts it based on the data type and the sub-signature sequence used for encryption (this sub-signature sequence is also generated using the same method after the current network terminal completes network access). The decryption process is the reverse of the encryption process, aiming to restore the original data.

[0094] Through the above process, the system can realize refined encrypted transmission of different types of uplink and downlink data of the current networking terminals based on multi-mode feature vectors, thereby improving the security and flexibility of data transmission.

[0095] Optionally, after the network verification is passed, the following steps are also included:

[0096] The real-time video call information is parsed from the uplink data of the current networking terminal, and the dynamic video verification of the current networking terminal is performed based on the real-time video call information and the user's facial information.

[0097] After the network verification is passed, in order to further enhance the security of the system, especially when processing sensitive operations such as real-time video calls, the system performs additional dynamic video verification steps to further improve network security.

[0098] For example, in a highly confidential video conferencing scenario, after network verification is passed, the system begins monitoring and analyzing uplink data uploaded by the currently connected endpoints. Within this uplink data, the system specifically focuses on real-time video call information, which may be transmitted in a specific packet format or protocol. The system extracts the video stream, audio stream, and possible metadata (such as timestamps and session IDs) from the data packets. Using the frame data in the video stream, a facial recognition algorithm is used to extract the user's facial information, including key facial features, facial outline, and facial expressions. This extracted facial information is then compared with the facial information stored during the previous verification process. Optionally, the system can also analyze dynamic features in the video stream, such as the user's head movement and facial expressions, to verify the authenticity of the video call. If the system detects any anomalies or inconsistencies (such as mismatched facial information or tampered or fabricated video), it may trigger an alarm or reject the video call request. During a video call, the system continuously monitors and verifies facial information to ensure call continuity and security.

[0099] S130. When it is detected that the frequency of switching networking terminals of the target user account reaches a set threshold, obtain the user dynamic video information reported by the current networking terminal, and randomly select a networking terminal of a specified user account in the current networking system to send the user dynamic video information, so as to perform a manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account.

[0100] Further, refer to Figure 5 After completing network verification and re-verification between the current networking terminal 121 and the server 11, the present application also monitors the frequency of user account switching networking terminals in the networking system and triggers a security response mechanism accordingly. When it is detected that the frequency of switching networking terminals of the target user account is abnormal (i.e., reaches or exceeds a set threshold), the legitimacy of the current network access is verified by selecting the networking terminal 122 of the specified user account, and based on this, it is decided whether to disconnect its networking link.

[0101] When the target user account switching frequency reaches or exceeds a set threshold, the system triggers an exception handling mechanism. The system then instructs the currently connected terminal to report the user's dynamic video information, such as through a real-time video call function or a dedicated video verification interface. Dynamic video information should include the user's real-time video stream, audio stream, and possible authentication information (such as facial features, voice features, etc.).

[0102] The system then randomly selects one or more network terminals of designated user accounts within the current network system as verification nodes. These designated user accounts should have a higher network access priority than the target user account, and their terminals should be trusted or have undergone rigorous verification. For example, in a video conferencing scenario requiring high confidentiality, a high-level conference account or the conference initiator would be selected as the designated user account. The dynamic video information is then sent to the network terminal of the designated user account for manual review.

[0103] The user on the networking terminal with the specified user account reviews the received dynamic video information. For example, they confirm whether the user identity, facial expressions, and voice characteristics in the video are consistent with expectations to determine the legitimacy of the current networking terminal, and then report the manual review results to the server. Based on the received manual review results, the system server makes a decision. If the review results indicate that the current networking terminal is legitimate and the user identity is correct, the system continues to maintain its networking link. If the review results indicate that the current networking terminal is abnormal or the user identity is suspicious, the system immediately disconnects its networking link and takes further security measures (such as banning the account and recording logs).

[0104] Optionally, when it is detected that the frequency of switching networking terminals of the target user account reaches a set threshold, the method further includes:

[0105] Disable the specified function permissions of the current network terminal, which include at least one of voice call permission, video call permission, and file sharing permission;

[0106] Correspondingly, after manually rechecking the current networking terminal based on the user dynamic video information, the following is also included:

[0107] After the manual re-inspection is detected, the specified function permissions of the current networking terminal are enabled.

[0108] When the system detects an abnormal frequency in the target user account switching networking terminals, in addition to possibly disconnecting the networking link, it can also take more detailed security measures, such as temporarily disabling the key functional permissions of the current networking terminal and restoring these permissions after manual review.

[0109] Among them, when the system detects that the frequency of the target user account switching networking terminals reaches or exceeds the set threshold, in addition to triggering the exception handling mechanism, this application will immediately close the specified functional permissions of the current networking terminal. Taking the video conferencing scenario with high confidentiality requirements as an example, these specified functional permissions may include voice call permissions, video call permissions, file sharing permissions, etc., depending on the system's security policy and user needs. Disabling these permissions can limit potential risky behaviors and prevent unauthorized communication and data transmission.

[0110] After manually rechecking the current network terminal based on the user's dynamic video information, if the recheck indicates that the current network terminal is legitimate and the user's identity is correct, the system records this result. It then checks the list of specific functional permissions that were previously disabled due to abnormal frequency. Based on the recheck results, the system restores the previously disabled specific functional permissions one by one. This supplementary process enables the system to implement more detailed and flexible security measures when it detects an abnormal frequency of switching network terminals for the target user account, ensuring the security and stability of the network environment.

[0111] In the above, by responding to the network access request of the current networking terminal, parsing the target user account, user voice information and user face information carried in the network access request, collecting voiceprint features and semantic features based on the user voice information, collecting face features based on the user face information, splicing the voiceprint features, semantic features and face features into a multi-mode feature vector, traversing the networking key database based on the multi-mode feature vector and the target user account, and performing network verification on the current user terminal based on the traversal result. The networking key database pre-configures multi-mode feature keys corresponding to different account information; after the network verification is passed, if the current networking terminal has logged into the current networking system multiple times, the uplink and downlink data of the current networking terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current networking system for the first time, collecting the special expression password or special voice uploaded by the current networking terminal The system queries a pre-built re-verification database based on a special expression password or a special voice password. When matching facial expression information or semantic tone information is found, the system encrypts the uplink and downlink data of the current network terminal based on a multi-modal feature vector. If no matching facial expression information or audio tone information is found, the network access request is rejected. When it is detected that the frequency of the target user account switching network terminals reaches a set threshold, the system obtains the user dynamic video information reported by the current network terminal and randomly selects a network terminal of a specified user account in the current network system to send the user dynamic video information. The system then performs a manual re-check of the current network terminal based on the user dynamic video information and decides whether to disconnect the network link of the current network terminal based on the received manual re-check result. The designated user account has a higher network access priority than the target user account. The above technical means are used to combine multiple biometric features of the user for network verification, and perform special information re-check and manual re-check based on the login status of the network terminal and user account. This can comprehensively utilize multiple unique biometric information of the user for accurate security verification, prevent the easy theft of network keys, and improve the security and reliability of the communication network.

[0112] Example 2:

[0113] Based on the above embodiments, Figure 6This is a schematic diagram of the structure of a security management system based on communication networking provided in Example 2 of this application. Figure 6 The communication network-based security management system provided in this embodiment specifically includes:

[0114] The network verification module 21 is configured to respond to a network access request from a current network terminal, parse the target user account, user voice information, and user facial information carried in the network access request, collect voiceprint features and semantic features based on the user voice information, collect facial features based on the user facial information, concatenate the voiceprint features, the semantic features, and the facial features into a multi-modal feature vector, traverse a network key database based on the multi-modal feature vector and the target user account, and perform network verification on the current user terminal based on the traversal result, wherein the network key database is pre-configured with multi-modal feature keys corresponding to different account information;

[0115] The networking recheck module 22 is used to, after the networking verification is passed, directly encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector if the current networking terminal has logged into the current networking system multiple times; if the current network terminal logs into the current networking system for the first time, collect the special expression password or special voice password uploaded by the current networking terminal, query a pre-built re-verification database based on the special expression password or the special voice password, and when matching facial expression information or semantic tone information is queried, encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector; if no matching facial expression information or audio tone information is queried, reject the network access request;

[0116] The manual re-inspection module 23 is used to obtain the user dynamic video information reported by the current networking terminal when it is detected that the frequency of the target user account switching networking terminals reaches a set threshold, and randomly select the networking terminal of the specified user account in the current networking system to send the user dynamic video information, so as to perform a manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account.

[0117] Furthermore, traversing a networking key database based on the multi-mode feature vector and the target user account, and performing networking verification on the current user terminal based on the traversal result, includes:

[0118] Traversing the networking key database based on the target user account, determining account information that matches the target user account, and extracting the multi-mode feature key configured for the matched account information;

[0119] Calculate the feature similarity between the extracted multimodal feature key and the multimodal feature vector. When the feature similarity reaches the set similarity threshold, determine that the network verification is passed. The similarity threshold is set according to the network access priority of the target user account, and the similarity threshold is positively correlated with the network access priority.

[0120] Furthermore, the encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes:

[0121] Constructing a first key feature sequence based on the multi-mode feature vector, and generating an encryption key sequence according to the first key feature sequence and a set networking key sequence;

[0122] The uplink and downlink data of the current networking terminal are encrypted, transmitted, and decrypted based on the encryption key sequence.

[0123] Furthermore, the encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes:

[0124] Constructing a second key feature sequence based on the multimodal feature vector, and splitting the second key feature sequence into multiple sub-feature sequences according to a set splitting rule;

[0125] Based on the multiple sub-feature sequences, encryption, transmission and decryption operations are performed on different types of uplink and downlink data of the current networking terminal.

[0126] Furthermore, after the network verification is passed, the method further includes:

[0127] Real-time video call information is parsed from uplink data of the current networking terminal, and dynamic video verification of the current networking terminal is performed based on the real-time video call information and the user face information.

[0128] Furthermore, before responding to the network access request of the current networking terminal, the method further includes:

[0129] Semantic prompt information associated with the designated semantic vocabulary is issued, so as to collect the voice information containing the designated semantic vocabulary based on the semantic prompt information.

[0130] Furthermore, when it is detected that the frequency of switching networking terminals of the target user account reaches a set threshold, the method further includes:

[0131] Disable the specified function permissions of the current network terminal, wherein the specified function permissions include at least one of voice call permission, video call permission, and file sharing permission;

[0132] Correspondingly, after manually rechecking the current networking terminal based on the user dynamic video information, the method further includes:

[0133] After the manual re-inspection is detected, the specified function permissions of the current networking terminal are enabled.

[0134] In the above, by responding to the network access request of the current networking terminal, parsing the target user account, user voice information and user face information carried in the network access request, collecting voiceprint features and semantic features based on the user voice information, collecting face features based on the user face information, splicing the voiceprint features, semantic features and face features into a multi-mode feature vector, traversing the networking key database based on the multi-mode feature vector and the target user account, and performing network verification on the current user terminal based on the traversal result. The networking key database pre-configures multi-mode feature keys corresponding to different account information; after the network verification is passed, if the current networking terminal has logged into the current networking system multiple times, the uplink and downlink data of the current networking terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current networking system for the first time, collecting the special expression password or special voice uploaded by the current networking terminal The system queries a pre-built re-verification database based on a special expression password or a special voice password. When matching facial expression information or semantic tone information is found, the system encrypts the uplink and downlink data of the current network terminal based on a multi-modal feature vector. If no matching facial expression information or audio tone information is found, the network access request is rejected. When it is detected that the frequency of the target user account switching network terminals reaches a set threshold, the system obtains the user dynamic video information reported by the current network terminal and randomly selects a network terminal of a specified user account in the current network system to send the user dynamic video information. The system then performs a manual re-check of the current network terminal based on the user dynamic video information and decides whether to disconnect the network link of the current network terminal based on the received manual re-check result. The designated user account has a higher network access priority than the target user account. The above technical means are used to combine multiple biometric features of the user for network verification, and perform special information re-check and manual re-check based on the login status of the network terminal and user account. This can comprehensively utilize multiple unique biometric information of the user for accurate security verification, prevent the easy theft of network keys, and improve the security and reliability of the communication network.

[0135] The communication networking-based security management system provided in the second embodiment of the present application can be used to execute the communication networking-based security management method provided in the above-mentioned first embodiment, and has corresponding functions and beneficial effects.

[0136] Example 3:

[0137] The third embodiment of the present application provides an electronic device, referring to Figure 7The electronic device includes: a processor 31, a memory 32, a communication module 33, an input device 34, and an output device 35. The number of processors in the electronic device may be one or more, and the number of memories in the electronic device may be one or more. The processor, memory, communication module, input device, and output device of the electronic device may be connected via a bus or other means.

[0138] The memory, as a computer-readable storage medium, can be used to store software programs, computer executable programs and modules, such as the program instructions / modules corresponding to the communication networking-based security management method described in any embodiment of the present application. The memory may mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the device, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories can be connected to the device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0139] The communication module is used for data transmission.

[0140] The processor executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory, thereby realizing the above-mentioned security management method based on communication networking.

[0141] The input device can be used to receive input digital or character information and generate key signal input related to user settings and function control of the device. The output device can include a display device such as a display screen.

[0142] The electronic device provided above can be used to execute the communication networking-based security management method provided in the above-mentioned embodiment 1, and has corresponding functions and beneficial effects.

[0143] Example 4:

[0144] The embodiment of the present application also provides a storage medium containing computer executable instructions, which are used to execute a security management method based on communication networking when executed by a computer processor. The security management method based on communication networking includes: responding to a network access request of a current networking terminal, parsing a target user account, user voice information, and user face information carried in the network access request, collecting voiceprint features and semantic features based on the user voice information, collecting face features based on the user face information, splicing the voiceprint features, semantic features, and face features into a multi-mode feature vector, traversing a network key database based on the multi-mode feature vector and the target user account, performing network verification on the current user terminal based on the traversal result, and collecting the network key. The database is pre-configured with a multi-mode feature key corresponding to different account information; after the network verification is passed, if the current network terminal has logged into the current network system multiple times, the uplink and downlink data of the current network terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current network system for the first time, the special expression password or special voice password uploaded by the current network terminal is collected, and the pre-built repeated verification database is queried based on the special expression password or special voice password. When matching facial expression information or semantic tone information is queried, the uplink and downlink data of the current network terminal are encrypted and transmitted based on the multi-mode feature vector. When no matching facial expression information or audio tone information is queried, the network access request is rejected;

[0145] When it is detected that the frequency of switching networking terminals of the target user account reaches the set threshold, the user dynamic video information reported by the current networking terminal is obtained, and the networking terminal of the specified user account is randomly selected in the current networking system to send the user dynamic video information, so as to perform manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account.

[0146] Storage medium - any of various types of memory devices or storage devices. The term "storage medium" is intended to include: installation media, such as CD-ROMs, floppy disks, or tape drives; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (such as hard disks or optical storage); registers or other similar types of memory elements, etc. Storage media may also include other types of memory or combinations thereof. In addition, the storage medium may be located in the first computer system in which the program is executed, or it may be located in a different second computer system that is connected to the first computer system via a network (such as the Internet). The second computer system can provide program instructions to the first computer for execution. The term "storage medium" may include two or more storage media residing in different locations (e.g., in different computer systems connected via a network). The storage medium may store program instructions (e.g., embodied as a computer program) that can be executed by one or more processors.

[0147] Of course, the storage medium containing computer-executable instructions provided in an embodiment of the present application, whose computer-executable instructions are not limited to the security management method based on communication networking as described above, can also execute related operations in the security management method based on communication networking provided in any embodiment of the present application.

[0148] The security management system, storage medium and electronic device based on communication networking provided in the above embodiments can execute the security management method based on communication networking provided in any embodiment of the present application. For technical details not described in detail in the above embodiments, please refer to the security management method based on communication networking provided in any embodiment of the present application.

[0149] The above are only preferred embodiments of the present application and the technical principles employed. The present application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions that are possible for those skilled in the art will not depart from the scope of protection of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments and may include more other equivalent embodiments without departing from the concept of the present application. The scope of the present application is determined by the scope of the claims.

Claims

1. A security management method based on communication networking, characterized in that: include: In response to a network access request from a current networking terminal, parsing a target user account, user voice information, and user facial information carried in the network access request, collecting voiceprint features and semantic features based on the user voice information, collecting facial features based on the user facial information, splicing the voiceprint features, the semantic features, and the facial features into a multi-modal feature vector, traversing a networking key database based on the multi-modal feature vector and the target user account, and performing network verification on the current user terminal based on the traversal result, wherein the networking key database is pre-configured with multi-modal feature keys corresponding to different account information; After the networking verification is passed, if the current networking terminal has logged into the current networking system multiple times, the uplink and downlink data of the current networking terminal are encrypted and transmitted directly based on the multi-mode feature vector; if the current network terminal logs into the current networking system for the first time, the special expression password or special voice password uploaded by the current networking terminal is collected, and a pre-built repeated verification database is queried based on the special expression password or the special voice password. When matching facial expression information or semantic tone information is queried, the uplink and downlink data of the current networking terminal are encrypted and transmitted based on the multi-mode feature vector. When no matching facial expression information or audio tone information is queried, the network access request is rejected; When it is detected that the frequency of the target user account switching networking terminals reaches a set threshold, the user dynamic video information reported by the current networking terminal is obtained, and the networking terminal of the specified user account is randomly selected in the current networking system to send the user dynamic video information, so as to perform a manual re-inspection of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal according to the received manual re-inspection result. The network access priority of the specified user account is higher than that of the target user account; The traversing the networking key database based on the multi-mode feature vector and the target user account, and performing networking verification on the current user terminal based on the traversal result, includes: Traversing the networking key database based on the target user account, determining account information that matches the target user account, and extracting the multi-mode feature key configured for the matched account information; Calculating the feature similarity between the extracted multimodal feature key and the multimodal feature vector, and determining that the network verification is passed when the feature similarity reaches a set similarity threshold, wherein the similarity threshold is set according to the network access priority of the target user account, and the similarity threshold is positively correlated with the network access priority; wherein a feature similarity calculation method is used to calculate the similarity between the extracted multimodal feature key and the multimodal feature vector, and the feature similarity calculation method includes cosine similarity, Euclidean distance, or Manhattan distance; The encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes: Constructing a first key feature sequence based on the multi-mode feature vector, and generating an encryption key sequence according to the first key feature sequence and a set networking key sequence; Performing encryption, transmission, and decryption operations on the uplink and downlink data of the current networking terminal based on the encryption key sequence; The encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes: Constructing a second key feature sequence based on the multimodal feature vector, and splitting the second key feature sequence into multiple sub-feature sequences according to a set splitting rule; Based on the multiple sub-feature sequences, encryption, transmission and decryption operations are performed on different types of uplink and downlink data of the current networking terminal.

2. The security management method based on communication networking according to claim 1, characterized in that: After the network verification is passed, the following steps are also included: Real-time video call information is parsed from uplink data of the current networking terminal, and dynamic video verification of the current networking terminal is performed based on the real-time video call information and the user face information.

3. The security management method based on communication networking according to claim 1, characterized in that: Before responding to the network access request of the current networking terminal, the method further includes: Semantic prompt information associated with the designated semantic vocabulary is issued, so as to collect the voice information containing the designated semantic vocabulary based on the semantic prompt information.

4. The security management method based on communication networking according to claim 1, characterized in that: When it is detected that the frequency of switching the network terminal of the target user account reaches a set threshold, the method further includes: Disable the specified function permissions of the current network terminal, wherein the specified function permissions include at least one of voice call permission, video call permission, and file sharing permission; Correspondingly, after manually rechecking the current networking terminal based on the user dynamic video information, the method further includes: After the manual re-inspection is detected, the specified function permissions of the current networking terminal are enabled.

5. A security management system based on communication networking, characterized in that: include: a network verification module, configured to respond to a network access request from a current network terminal, parse a target user account, user voice information, and user facial information carried in the network access request, collect voiceprint features and semantic features based on the user voice information, collect facial features based on the user facial information, concatenate the voiceprint features, the semantic features, and the facial features into a multi-modal feature vector, traverse a network key database based on the multi-modal feature vector and the target user account, and perform network verification on the current user terminal based on the traversal result, wherein the network key database is pre-configured with multi-modal feature keys corresponding to different account information; A networking recheck module is configured to, after the networking verification is passed, directly encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector if the current networking terminal has logged into the current networking system multiple times; if the current network terminal logs into the current networking system for the first time, collect the special expression password or special voice password uploaded by the current networking terminal, query a pre-built repeated verification database based on the special expression password or the special voice password, and when matching facial expression information or semantic tone information is queried, encrypt and transmit the uplink and downlink data of the current networking terminal based on the multi-mode feature vector; and when no matching facial expression information or audio tone information is queried, reject the network access request; A manual recheck module is configured to, upon detecting that the frequency of the target user account switching networking terminals reaches a set threshold, obtain user dynamic video information reported by the current networking terminal, and randomly select a networking terminal of a specified user account in the current networking system to send the user dynamic video information, so as to perform a manual recheck of the current networking terminal based on the user dynamic video information, and decide whether to disconnect the networking link of the current networking terminal based on the received manual recheck result. The network access priority of the specified user account is higher than that of the target user account; The traversing the networking key database based on the multi-mode feature vector and the target user account, and performing networking verification on the current user terminal based on the traversal result, includes: Traversing the networking key database based on the target user account, determining account information that matches the target user account, and extracting the multi-mode feature key configured for the matched account information; Calculating the feature similarity between the extracted multimodal feature key and the multimodal feature vector, and determining that the network verification is passed when the feature similarity reaches a set similarity threshold, wherein the similarity threshold is set according to the network access priority of the target user account, and the similarity threshold is positively correlated with the network access priority; wherein a feature similarity calculation method is used to calculate the similarity between the extracted multimodal feature key and the multimodal feature vector, and the feature similarity calculation method includes cosine similarity, Euclidean distance, or Manhattan distance; The encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes: Constructing a first key feature sequence based on the multi-mode feature vector, and generating an encryption key sequence according to the first key feature sequence and a set networking key sequence; Performing encryption, transmission, and decryption operations on the uplink and downlink data of the current networking terminal based on the encryption key sequence; The encrypted transmission of uplink and downlink data of the current networking terminal based on the multimode feature vector includes: Constructing a second key feature sequence based on the multimodal feature vector, and splitting the second key feature sequence into multiple sub-feature sequences according to a set splitting rule; Based on the multiple sub-feature sequences, encryption, transmission and decryption operations are performed on different types of uplink and downlink data of the current networking terminal.

6. An electronic device, characterized in that: include: memory and one or more processors; The memory is used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the communication networking-based security management method as described in any one of claims 1 to 4.

7. A storage medium containing computer-executable instructions, characterized in that: The computer executable instructions, when executed by a computer processor, are used to execute the communication networking-based security management method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Hotel check-in identity check method and system based on face identification

    CN107967453A

  • Identity authentication method, electronic apparatus and computer readable storage medium

    CN108171032A