A security access method and system for a server

By classifying and encrypting the server data, combining authentication and behavioral credibility assessment, the problem of single security measures in the existing technology is solved, and the security and reliability of server access is improved.

CN119324838BActive Publication Date: 2025-07-18JIANGSU HUAKUN ZHENYU INTELLIGENT TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411865990.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-07-18
Estimated Expiration
2044-12-18

AI Technical Summary

Technical Problem

The existing server network security methods have single security measures, are easily bypassed, and have high risk of data leakage, which cannot effectively prevent various types of cyber attacks and unauthorized access.

Method used

Provides a secure access method for servers, monitors network connection status in real time, classifies data as non-important, important and extremely important, and stores extremely important data encrypted and stored. Combined with identity authentication and behavioral credibility assessment, different access rules are set to improve security.

Benefits of technology

By setting different access rules and behavioral credibility assessments for data of different importance, the security and reliability of server access are improved, effectively preventing unauthorized access and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119324838B_ABST
    Figure CN119324838B_ABST
Patent Text Reader

Abstract

The present invention relates to a secure access method and system for a server, which classifies the accessed data in the server and encrypts and stores extremely important data; the main controller obtains the IP addresses of all controlled servers and establishes connections to conduct data communication and identity verification for the servers; it identifies the type of data to be accessed. If it is unimportant data, it directly conducts identity verification and then directly accesses it. If it is important data or extremely important data, it evaluates the behavior credibility of the visitor; when the accessed data is important data, if the behavior credibility of the visitor is greater than the first preset threshold, the visitor directly accesses the accessed data; when the accessed data is extremely important data, it determines whether the behavior credibility of the visitor is greater than the second preset threshold. If so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data. Through the above access process, the security of access is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular relates to a method and system for secure access to a server. Background Art

[0002] With the popularization of the Internet and the improvement of the degree of informatization, servers play a vital role in the modern information society. However, servers are facing more and more network security threats and risks. According to reports, malicious attacks, data leakage and unauthorized access have become one of the main challenges facing enterprises. Server network access security is a technology that uses multiple authentication methods to detect accessed devices. Once abnormal access is found, the access will be immediately interrupted and an alarm will be issued to protect the security of server data.

[0003] Traditional server network security methods often rely on single security measures, such as authentication, firewalls, intrusion detection systems, and access control, but these methods often fail to provide adequate protection and are easily bypassed or circumvented. For example, hackers can exploit zero-day vulnerabilities to bypass firewalls, use social engineering to obtain user credentials, or directly access servers through physical intrusions. Authentication and access control: Ensure that only authenticated users can access server resources, including login authentication using usernames and passwords, and setting access control policies based on user roles and permissions to limit the resources and operations that users can access. Use firewall technology to filter and control network traffic to prevent unauthorized access and malicious traffic from entering the server. In addition, implement network isolation according to network security policies to separate networks with different security levels and reduce the attack surface.

[0004] Use encryption technology to protect communication data between servers and clients to prevent data from being stolen or tampered with during transmission. Common encryption protocols include SSL / TLS. Regularly perform vulnerability scans and security assessments on servers, and promptly patch discovered security vulnerabilities and weaknesses. At the same time, ensure that security patches for operating systems and applications are installed in a timely manner to reduce the risk of being attacked by known vulnerabilities. Record various system events and activities on the server, including login attempts, file access, system configuration changes, etc. Regularly review and analyze these log data to promptly detect abnormal activities or potential security risks. Deploy intrusion detection and prevention systems to monitor server network traffic and system activities to detect and block potential attacks. These systems can identify and respond based on known attack patterns or abnormal behaviors. Protect server hardware equipment from physical attacks and unauthorized access, such as using physical measures such as secure cabinets, video surveillance, and access control systems.

[0005] Therefore, there is an urgent need to improve the existing server network security methods and provide a more comprehensive and efficient secure access method for servers, which can effectively prevent various types of network attacks and unauthorized access, be able to identify and block known and unknown attacks, and at the same time reduce risks such as data leakage, service interruption, and system crashes. Summary of the Invention

[0006] The purpose of the present invention is to provide a secure access method and system for servers, so as to solve the technical problems of single security measures, low security, and high risk of data leakage existing in the access methods in the prior art.

[0007] To solve the above technical problems, the technical solutions adopted by the present invention are as follows:

[0008] In the first aspect, a secure access method for a server is provided, which real-time monitors whether the server is in a network connection. If so, it executes a secure access method for online intrusion. The secure access method for online intrusion includes the following steps:

[0009] S11: Classify the data to be accessed in the server into unimportant data, important data, and extremely important data, and encrypt and store the extremely important data.

[0010] S12: The main controller obtains the IP addresses of all controlled servers and establishes connections, exchanges data with the servers at a specified period, and performs identity verification during the exchange process. It sends an identity verification code to each controlled server. The controlled server receives the verification code and replies with an identity recognition code. The main controller processes the replied identity recognition code to verify the device identity. If the identity verification is passed, step S12 is executed. If the identity verification fails, an abnormal warning is given.

[0011] S13: Identify the type of data to be accessed by the visitor. If it is unimportant data, directly perform identity verification and then directly access it. If it is important data or extremely important data, evaluate the behavior credibility of the visitor.

[0012] S14: When the data to be accessed is important data, judge whether the behavior credibility of the visitor is greater than a first preset threshold. If so, the visitor directly accesses the data to be accessed. If not, access is refused. When the data to be accessed is extremely important data, execute step S15;

[0013] S15: Judge whether the behavior credibility of the visitor is greater than a second preset threshold. If so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data.

[0014] Preferably, it is monitored in real time whether the server is connected to the network. If not, a security access method for offline intrusion is executed, and the specific process is as follows:

[0015] S21: The master controller scans all the connected servers and exchanges data with each server. Based on the data exchange, it monitors whether there is a server that is illegally disconnected. If so, an alarm is triggered and step S22 is executed;

[0016] S22: When the illegally disconnected server loses its connection with the master controller, it automatically encrypts all the internal data strongly and starts a data self - protection program to monitor whether there is an illegal data acquisition behavior and it is successful. If so, a data destruction program is started to automatically destroy the illegally acquired data.

[0017] Preferably, the specific process of encrypting and storing the extremely important data is as follows:

[0018] S111: Convert the data to be encrypted into a string according to the specified rules, and cut the string into substrings of a specified length;

[0019] S112: Encode the substrings, and all the substrings are encoded into a number of binary numbers accordingly;

[0020] S113: Convert the number of binary numbers into characters according to the specified rules, and splice all the characters into a string, and store the spliced string.

[0021] Preferably, the specific process of evaluating the behavior credibility of the visitor in step S13 is as follows:

[0022] S131: Collect all the normal behaviors of the historical visitors of the server within a specified time, and construct a normal behavior sample of the visitors;

[0023] S132: Obtain all the access behaviors of the current visitor, set an initial value for the behavior credibility based on the normal behavior sample of the visitors, and calculate the behavior credibility of the first access behavior based on the initial value of the behavior credibility;

[0024] S133: Calculate the behavior credibility of the second access behavior of the current visitor based on the calculation result of the behavior credibility of the first access behavior of the current visitor;

[0025] S134: Calculate the behavior credibility of the third access behavior of the current visitor based on the calculation result of the behavior credibility of the second access behavior of the current visitor, and so on to calculate the behavior credibility of the current behavior of the current visitor.

[0026] Preferably, the formula for calculating the behavior credibility of the first visit behavior of the current visitor in step S132 is as follows:

[0027] R1 = α * R0 + (1 - α) * (R0 - θ);

[0028] In step S133, the formula for calculating the behavior credibility of the second visit behavior of the current visitor based on the calculation result of the behavior credibility of the first visit behavior of the current visitor is as follows:

[0029] R2 = α * R1 + (1 - α) * (R1 - θ);

[0030] By analogy, in step S134, the formula for calculating the behavior credibility of the current behavior of the current visitor is as follows:

[0031] R n = α * R n-1 + (1 - α) * (R n-1 - θ);

[0032] Among them, R0 is the initial value of the behavior credibility of the current visitor, α is the credibility correction factor within the range of (0, 1), and θ is the preset behavior risk threshold.

[0033] Preferably, the first preset threshold of the behavior credibility in steps S14 and S15 is less than the second preset threshold.

[0034] Preferably, the specific process of the main controller decrypting the extremely important encrypted data in step S15 is as follows:

[0035] S151: Split the concatenated string into several characters according to the specified rule;

[0036] S152: Decode the several characters into several binary numbers, and convert the several binary numbers into several substrings correspondingly;

[0037] S153: Restore the substring to obtain a string, and convert the string into decrypted data according to the specified rule.

[0038] Preferably, in step S12, the identity verification during the communication process is cross-verification. During the cross-verification process, the verification code and the identification code are specified by the user, and are updated according to the preset specified period or updated through the verification code dictionary, or automatically generated by the current time and IP information;

[0039] At the same time, a time limit is set when receiving and replying to the verification code. The reply exceeding the preset time will be marked, and the system will give a pre-warning, and the user can receive the information and track it.

[0040] In a second aspect, a secure access system for a server is provided, which is used to implement a secure access method for a server as described in any one of the above, including a main control system, a number of servers, and an identity authentication module. The main control system includes a behavior credibility calculation module, an encryption module, and a decryption module. The main control system is connected to the number of servers;

[0041] The main control system is used to control the number of servers;

[0042] The number of servers is used to store the accessed data;

[0043] The identity authentication module is used to perform cross-verification of identities during the access process of the visitor;

[0044] The behavior credibility calculation module is used to set an initial value of behavior credibility based on the normal behavior samples of the visitor, and calculate the behavior credibility of the first access behavior based on the initial value of behavior credibility; calculate the behavior credibility of the second access behavior of the current visitor based on the calculation result of the behavior credibility of the first access behavior of the current visitor; calculate the behavior credibility of the third access behavior of the current visitor based on the calculation result of the behavior credibility of the second access behavior of the current visitor, and so on to calculate the behavior credibility of the current behavior of the current visitor;

[0045] The encryption module is used to encrypt extremely important data, convert the data to be encrypted into a string according to a specified rule, and cut the string into substrings of a specified length; encode the substrings, and encode all the substrings into a number of binary numbers; convert the number of binary numbers into characters according to a specified rule, and splice all the characters into a string, and store the spliced string;

[0046] The decryption module is used to decrypt extremely important data, split the spliced string into a number of characters according to a specified rule; decode the number of characters into a number of binary numbers, and convert the number of binary numbers into a number of substrings correspondingly; restore the substrings to obtain a string, and convert the string into decrypted data according to a specified rule.

[0047] The beneficial effects of the present invention include:

[0048] The server security access method and system provided by the present invention classify the accessed data in the server and encrypt and store extremely important data; the main controller obtains the IP addresses of all controlled servers and establishes connections, conducts data communication and authentication for the servers; identifies the type of data to be accessed, and if it is unimportant data, directly conducts authentication and then accesses directly. If it is important data or extremely important data, the behavior credibility of the visitor is evaluated; when the accessed data is important data and the behavior credibility of the visitor is greater than the first preset threshold, the visitor directly accesses the accessed data; when the accessed data is extremely important data, it is judged whether the behavior credibility of the visitor is greater than the second preset threshold. If so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data.

[0049] First, by setting the server security access method to security access in different situations for online intrusion and offline intrusion, setting different access rules for different situations, the access process has more comprehensive security access rules, effectively improving the access security of all controlled servers.

[0050] Second, classify the accessed data in the server into unimportant data, important data, and extremely important data, combine encrypting and storing the extremely important data, and set different access rules corresponding to the accessed data of different importance levels, further improving the access security.

[0051] Third, during the access process, based on authentication, combined with calculating the behavior credibility of the visitor's access behavior, further improving the security and reliability of the entire access.

[0052] Finally, set a detailed behavior credibility calculation formula to quantify the credibility of the visitor's access behavior, enabling precise identification of each access behavior and ensuring the secure identification of all access behaviors. Brief Description of the Drawings

[0053] Figure 1 It is a schematic flow chart of the server security access method of the present invention.

[0054] Figure 2 It is a schematic flow chart for evaluating the behavior credibility of the visitor of the present invention.

[0055] Figure 3 It is a schematic diagram of a hacker's online intrusion of the present invention. Detailed Description of the Invention

[0056] The following combines the attached Figures 1 to 3 Further detailed description of the present invention will be given:

[0057] Example 1

[0058] See the appendix Figure 1 and Figure 3 As shown, a security access method for a server monitors in real time whether the server is in a network connection. If so, it executes a security access method for online intrusion. The security access method for online intrusion includes the following steps:

[0059] S11: Classify the accessed data in the server into unimportant data, important data, and extremely important data, and encrypt and store the extremely important data. The reason for classifying the accessed data in the server into unimportant data, important data, and extremely important data is that data of different importance levels need to execute different access rules. For example, data that is not important itself can be directly accessed without setting a complex access process, making the access process efficient. For data with a high level of importance, a strict access process must be set to ensure that important data cannot be obtained by illegal visitors and to ensure data security. Combining the encryption storage of extremely important data and setting different access rules corresponding to the accessed data of different importance levels further enhances the security of access.

[0060] S12: The main controller obtains the IP addresses of all controlled servers and establishes connections, exchanges data with the servers at a specified period, and performs identity verification during the exchange process. It sends an identity verification code to each controlled server. The controlled server receives the verification code and replies with an identity recognition code. The main controller processes the replied identity recognition code to verify the device identity. If the identity verification passes, execute step S12. If the identity verification fails, an exception warning is issued. Performing identity recognition is only the basis in the data access process. Only after the identity is legal is it necessary to calculate the subsequent behavior credibility. If the identity is illegal, there is no need to calculate the credibility of the subsequent access behavior, and access can be directly refused to ensure data security.

[0061] S13: Identify the type of data to be accessed by the visitor. If it is unimportant data, directly perform identity verification and then access directly. If it is important data or extremely important data, evaluate the behavior credibility of the visitor. During the access process, based on identity verification, combining the calculation of the behavior credibility of the visitor's access behavior further enhances the security and reliability of the entire access. And a detailed behavior credibility calculation formula is set to quantify the credibility of the visitor's access behavior, enabling precise identification of each access behavior and ensuring the secure identification of all access behaviors.

[0062] S14: If the data to be accessed is important data, determine whether the behavior credibility of the visitor is greater than the first preset threshold. If so, the visitor directly accesses the data to be accessed; if not, access is refused. If the data to be accessed is extremely important data, step S15 is executed;

[0063] S15: Determine whether the behavior credibility of the visitor is greater than the second preset threshold. If so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data. By setting different behavior credibility thresholds for important data and extremely important data, that is, setting different credibility requirements for the access behaviors of important data and extremely important data, further providing different access requirements for different data, and thus improving the security of data access.

[0064] In this embodiment, when it is detected that the server is not in a network connection, a secure access method for offline intrusion is executed. The specific process is as follows:

[0065] S21: The main controller scans all the connected servers and exchanges data with each server. Based on the data exchange, it monitors whether there is an illegally disconnected server. If so, an alarm is triggered and step S22 is executed;

[0066] S22: When the illegally disconnected server loses its connection with the main controller, it automatically encrypts all the internal data strongly and starts a data self - protection program. It monitors whether there is an illegal data acquisition behavior and the acquisition is successful. If so, a data destruction program is started to automatically destroy the illegally acquired data.

[0067] By setting the secure access method of the server for different situations of online intrusion and offline intrusion, setting different access methods and access rules for different situations, the access process has more comprehensive secure access rules, so as to effectively improve the access security of all controlled servers.

[0068] Embodiment 2

[0069] On the basis of Embodiment 1, the specific process of encrypting and storing the extremely important data is as follows:

[0070] S111: Convert the data to be encrypted into a string according to the specified rules, and cut the string into substrings of the specified length;

[0071] S112: Encode the substrings, and all the substrings are encoded into several binary numbers;

[0072] S113: Convert several binary numbers into characters according to specified rules, splice all the characters into a string, and store the spliced string. A highly secure encryption process is achieved through a simple encryption procedure.

[0073] In this embodiment, refer to the appendix Figure 2 , the specific process of evaluating the behavior credibility of the visitor in step S13 is as follows:

[0074] S131: Collect all the normal behaviors of the server's historical visitors within a specified time, and construct a sample of the visitors' normal behaviors;

[0075] S132: Obtain all the access behaviors of the current visitor, set an initial value for the behavior credibility based on the sample of the visitors' normal behaviors, and calculate the behavior credibility for the first access behavior based on the initial value of the behavior credibility;

[0076] S133: Calculate the behavior credibility for the second access behavior of the current visitor based on the calculation result of the behavior credibility of the current visitor's first access behavior;

[0077] S134: Calculate the behavior credibility for the third access behavior of the current visitor based on the calculation result of the behavior credibility of the current visitor's second access behavior, and so on to calculate the behavior credibility for the current behavior of the current visitor.

[0078] During the access process, based on identity authentication, combined with the calculation of the behavior credibility of the visitor's access behavior, the security and reliability of the entire access are further improved.

[0079] Embodiment 3

[0080] Based on Embodiment 1 or Embodiment 2, the formula for calculating the behavior credibility for the first access behavior of the current visitor in step S132 is as follows:

[0081] R1 = α * R0+(1 - α)*(R0 - θ);

[0082] The formula for calculating the behavior credibility for the second access behavior of the current visitor based on the calculation result of the behavior credibility of the current visitor's first access behavior in step S133 is as follows:

[0083] R2 = α * R1+(1 - α)*(R1 - θ);

[0084] The formula for calculating the behavior credibility for the current behavior of the current visitor by analogy in step S134 is as follows:

[0085] R n = α * R n-1+(1 - α)*(R n-1 - θ);

[0086] Wherein, R0 is the initial value of the behavior credibility of the current visitor, α is a credibility correction factor within the range of (0, 1), and θ is a preset behavior risk threshold.

[0087] Set a detailed behavior credibility calculation formula to quantify the credibility of the visitor's access behavior, enabling precise identification of each access behavior, ensuring the secure identification of all access behaviors, more comprehensively realizing the measurement of the credibility of all visitors' access behaviors, and enabling more precise ensuring of data access security during the data access process.

[0088] In this embodiment, the first preset threshold of the behavior credibility in step S14 and step S15 is less than the second preset threshold. Different behavior credibility thresholds are set for important data and extremely important data, and the behavior credibility threshold of extremely important data is greater than that of important data, making the access rules for extremely important data more stringent and further ensuring the security of extremely important data.

[0089] The specific process of the main controller decrypting the encrypted extremely important data in step S15 is as follows:

[0090] S151: Split the concatenated string into several characters according to the specified rule;

[0091] S152: Decode the several characters into several binary numbers, and correspondingly convert the several binary numbers into several substrings;

[0092] S153: Restore the substrings to obtain a string, and convert the string according to the specified rule to obtain decrypted data.

[0093] In step S12, the identity verification during the communication process is cross-verification. During the cross-verification process, the verification code and the identification code are specified by the user, and are updated according to the preset specified period or updated through the verification code dictionary, or automatically generated by the current time and IP information. At the same time, a time limit is set when receiving and replying to the verification code. Responses exceeding the preset time will be marked, and the system will give a pre-warning, and the user can receive the information and conduct tracking.

[0094] A security access system for a server, used to implement a security access method for a server as described in any one of the above, includes a main control system, several servers, and an identity verification module. The main control system includes a behavior credibility calculation module, an encryption module, and a decryption module. The main control system is connected to several servers;

[0095] The main control system is used to control a number of servers;

[0096] The number of servers is used to store the accessed data;

[0097] The identity authentication module is used to perform cross - authentication of identities during the access process of the visitor;

[0098] The behavior credibility calculation module is used to set an initial value of the behavior credibility based on the normal behavior samples of the visitor, and calculate the behavior credibility of the first access behavior based on the initial value of the behavior credibility; calculate the behavior credibility of the second access behavior of the current visitor based on the calculation result of the behavior credibility of the first access behavior of the current visitor; calculate the behavior credibility of the third access behavior of the current visitor based on the calculation result of the behavior credibility of the second access behavior of the current visitor, and so on to calculate the behavior credibility of the current behavior of the current visitor;

[0099] The encryption module is used to encrypt extremely important data, convert the data to be encrypted into a string according to the specified rules, and cut the string into substrings of a specified length; encode the substrings, and encode all the substrings into a number of binary numbers; convert the number of binary numbers into characters according to the specified rules, and splice all the characters into a string, and store the spliced string;

[0100] The decryption module is used to decrypt extremely important data, split the spliced string into a number of characters according to the specified rules; decode the number of characters into a number of binary numbers, and convert the number of binary numbers into a number of substrings correspondingly; restore the substrings to obtain a string, and convert the string into decrypted data according to the specified rules.

[0101] In summary, for the secure access method and system of the server provided by the present invention, by classifying the accessed data in the server and encrypting and storing extremely important data; the main controller obtains the IP addresses of all controlled servers and establishes connections to conduct data communication and identity authentication for the servers; identifies the type of data to be accessed, if it is unimportant data, directly conduct identity authentication and then directly access, if it is important data or extremely important data, evaluate the behavior credibility of the visitor; when the accessed data is important data and the behavior credibility of the visitor is greater than the first preset threshold, the visitor directly accesses the accessed data; when the accessed data is extremely important data, determine whether the behavior credibility of the visitor is greater than the second preset threshold, if so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data.

[0102] Set the secure access method for the server to secure access under different scenarios of online intrusion and offline intrusion. Set different access rules for different scenarios by setting different access methods, so that the access process has more comprehensive security access rules, effectively improving the access security of all controlled servers. Classify the accessed data in the server into unimportant data, important data, and extremely important data, combine with encrypting and storing the extremely important data, and set different access rules corresponding to the accessed data of different importance levels, further enhancing the security of access. During the access process, based on identity authentication, combine with the calculation of the behavior credibility of the accessor's access behavior, further enhancing the security and reliability of the entire access. Set a detailed behavior credibility calculation formula to quantify the credibility of the accessor's access behavior, enabling precise identification of each access behavior and ensuring the secure identification of all access behaviors.

Claims

1. A security access method for a server, characterized in that, Monitor in real time whether the server is connected to the network. If so, execute the security access method for online intrusion. The security access method for online intrusion includes the following steps: S11: Classify the data to be accessed in the server into unimportant data, important data, and extremely important data. Encrypt and store the extremely important data; S12: The main controller obtains the IP addresses of all controlled servers and establishes connections, exchanges data with the servers at a specified period, and performs identity verification during the exchange process. Send an identity verification code to each controlled server. The controlled server receives the verification code and replies with an identity recognition code. The main controller processes the replied identity recognition code to verify the device identity. If the identity verification is passed, execute step S12. If the identity verification fails, issue an anomaly warning; S13: Identify the type of data to be accessed by the visitor. If it is unimportant data, directly perform identity verification and then directly access it. If it is important data or extremely important data, evaluate the behavior credibility of the visitor; S14: When the data to be accessed is important data, determine whether the behavior credibility of the visitor is greater than the first preset threshold. If so, the visitor directly accesses the data to be accessed. If not, access is refused. When the data to be accessed is extremely important data, execute step S15; S15: Determine whether the behavior credibility of the visitor is greater than the second preset threshold. If so, the main controller decrypts the encrypted extremely important data, and the visitor accesses the decrypted extremely important data; If not, execute the security access method for offline intrusion. The specific process is as follows: S21: The main controller scans all connected servers and exchanges data with each server. Based on the data exchange, monitor whether there is an illegally disconnected server. If so, start the alarm and then execute step S22; S22: When the illegally disconnected server loses its connection with the main controller, it automatically strongly encrypts all internal data and starts the data self - protection program. Monitor whether there is an illegal data acquisition behavior and it is successful. If so, start the data destruction program to automatically destroy the illegally acquired data; The specific process of encrypting and storing the extremely important data is as follows: S111: Convert the data to be encrypted into a string according to the specified rules, and cut the string into substrings of a specified length; S112: Encode the substrings, and encode all substrings into several binary numbers; S113: Convert several binary numbers into characters according to the specified rules, and splice all characters into a string, and store the spliced string; The specific process of evaluating the behavior credibility of the visitor in S13 is as follows: S131: Collect all normal behaviors of the server's historical visitors within a specified time, and construct a normal behavior sample of the visitor; S132: Obtain all access behaviors of the current visitor, set an initial value for the behavior credibility based on the normal behavior sample of the visitor, and calculate the behavior credibility for the first access behavior based on the initial value of the behavior credibility; S133: Calculate the behavioral credibility of the current visitor's second access behavior based on the calculation result of the behavioral credibility of the current visitor's first access behavior; S134: Calculate the behavioral credibility of the current visitor's third access behavior based on the calculation result of the behavioral credibility of the current visitor's second access behavior, and so on to calculate the behavioral credibility of the current visitor's current behavior; The formula for calculating the behavioral credibility of the current visitor's first access behavior in step S132 is as follows: R1 = α * R0 + (1 - α) * (R0 - θ); The formula for calculating the behavioral credibility of the current visitor's second access behavior based on the calculation result of the behavioral credibility of the current visitor's first access behavior in step S133 is as follows: R2 = α * R1 + (1 - α) * (R1 - θ); The formula for calculating the behavioral credibility of the current visitor's current behavior by analogy in step S134 is as follows: R n = α * R n-1 + (1 - α) * (R n-1 - θ); Among them, R0 is the initial value of the behavioral credibility of the current visitor, α is the credibility correction factor within the range of (0, 1), and θ is the preset behavioral risk threshold; The specific process of the main controller decrypting the extremely important encrypted data in step S15 is as follows: S151: Split the concatenated string into several characters according to the specified rules; S152: Decode the several characters into several binary numbers, and convert the several binary numbers into several substrings correspondingly; S153: Restore the substring to get a string, and convert the string according to the specified rules to obtain the decrypted data.

2. The security access method of a server according to claim 1, characterized in that, The first preset threshold in step S14 is less than the second preset threshold in step S15.

3. A security access method for a server according to claim 1, characterized in that, In step S12, the identity verification during the communication process is cross-verification. During the cross-verification process, the verification code and the identification code are specified by the user, and are updated according to the preset specified period, or updated through the verification code dictionary, or automatically generated by the current time and IP information; At the same time, a time limit is set when receiving and replying to the verification code. Responses exceeding the preset time will be marked, and the system will give a pre-warning, and the user can receive the information and track it.

4. A security access system for a server, which is used to implement the security access method for a server according to any one of claims 1-3, characterized in that, It includes a main control system, several servers, and an identity verification module. The main control system includes a behavioral credibility calculation module, an encryption module, and a decryption module. The main control system is connected to several servers; The main control system is used to control several servers; The several servers are used to store the accessed data; The identity verification module is used to perform cross-verification of the identity during the access process of the visitor; The behavioral credibility calculation module is used to set the initial value of the behavioral credibility based on the normal behavior samples of the visitor, and calculate the behavioral credibility of the first access behavior based on the initial value of the behavioral credibility; Calculate the behavioral credibility of the current visitor's second access behavior based on the calculation result of the behavioral credibility of the current visitor's first access behavior; Calculate the behavior credibility of the current visitor's third access behavior based on the calculation result of the behavior credibility of the current visitor's second access behavior, and so on to calculate the behavior credibility of the current visitor's current behavior; The encryption module is used to encrypt extremely important data, convert the data to be encrypted into a string according to specified rules, and cut the string into substrings of a specified length; encode the substrings, and encode all the substrings into a number of binary numbers; convert the number of binary numbers into characters according to specified rules, and splice all the characters into a string, and store the spliced string; The decryption module is used to decrypt extremely important data, split the spliced string into a number of characters according to specified rules; decode the number of characters into a number of binary numbers, and convert the number of binary numbers into a number of substrings correspondingly; restore the substrings to obtain a string, and convert the string into decrypted data according to specified rules.

Citation Information

Patent Citations

  • Data security control method and data security control platform

    CN104796290A

  • Power network security protection method based on zero trust

    CN115189927A