A real-name information management method supporting multi-level authentication
Through multi-level authentication mechanism, hierarchical encryption strategies and distributed storage technology, the shortcomings of traditional real-name information management methods in identity authentication, security and permission management are solved, and more efficient, secure and flexible real-name information management is achieved.
Patent Information
- Application Number
- CN202411973655.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-30
AI Technical Summary
The traditional real-name information management method has shortcomings in identity authentication, security, permission management and abnormal behavior monitoring, and it is difficult to meet the needs of different security levels and user behavior scenarios.
A multi-level authentication mechanism is adopted, including basic identity verification, biometric verification and multi-factor authentication. Combined with hierarchical encryption strategies and distributed storage technology, the authentication level and permission allocation are dynamically adjusted, and user behavior is monitored in real time to identify abnormal behaviors.
It improves the security and flexibility of identity authentication, ensures the security and privacy of real-name information, realizes distributed storage and efficient recovery of real-name information, dynamic permission allocation and flexible access control, and enhances abnormal behavior detection and risk control capabilities.
Smart Images

Figure CN119402290B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent information management, and in particular to a real-name information management method supporting multi-level authentication. Background Art
[0002] With the rapid development of information technology, real-name information management is increasingly used in various industries, especially in the fields of government, finance, medical care, communications, etc. The security and accuracy of real-name information has become the focus of social attention. The core of real-name information management lies in how to ensure the authenticity of user identity, the controllability of information access, and the security of data storage and transmission. However, traditional real-name information management methods face many challenges in practical applications.
[0003] First, traditional authentication methods are single and insecure. Most systems rely only on static information (such as username and password) entered by users for identity authentication, which is vulnerable to threats such as password leakage, replay attacks, and identity forgery. Although biometric authentication and multi-factor authentication have become increasingly popular in recent years, these methods often lack dynamic adjustment capabilities and are difficult to meet the needs of different security levels and user behavior scenarios.
[0004] Secondly, the storage and access of real-name information poses a great security risk. In the traditional centralized storage model, all user information is stored in a single database. If the database is attacked or leaked, it may lead to serious data security incidents. At the same time, there is a lack of a hierarchical protection mechanism for different types of information. Sensitive information (such as user identity information, transaction records, etc.) is treated the same as ordinary information (such as basic user information), which increases security risks.
[0005] Third, there are deficiencies in user rights management and access control methods. Traditional access control usually adopts a role-based access control model (RBAC), and rights allocation is mainly based on static role definitions, making it difficult to dynamically adjust access rights based on users' real-time behavior, operation scope, access time, etc. Especially in distributed systems, the complexity of rights management is further increased.
[0006] In addition, there is a lack of effective monitoring and risk control of abnormal user behavior. When dealing with abnormal user behavior (such as malicious operations, frequent access to sensitive information, etc.), traditional systems rely on preset rules for judgment. This approach lacks flexibility and intelligence and cannot detect and respond to potential security threats in a timely manner.
[0007] Therefore, there is an urgent need for a method that can effectively make up for the shortcomings of traditional real-name information management methods and provide a safer and more efficient solution for real-name information management in various scenarios. Summary of the invention
[0008] In order to overcome the shortcomings of the prior art, the present invention provides a real-name information management method that supports multi-level authentication, which is used to solve the shortcomings of traditional real-name information management methods in identity authentication, security, authority management and abnormal behavior monitoring, thereby achieving more secure, flexible and efficient real-name information management.
[0009] To solve the above problems, the technical solution adopted by the present invention is as follows:
[0010] A real-name information management method supporting multi-level authentication includes the following steps:
[0011] Collect the user's basic identity information through the terminal device and store it through an asymmetric encryption algorithm that encrypts the privacy data attributes;
[0012] Generate multi-level authentication levels based on user usage needs and access permission requirements;
[0013] According to the sensitivity of real-name information, the real-name information is divided into basic information area, permission information area and sensitive information area;
[0014] The basic information area, permission information area and sensitive information area are distributedly stored based on the cascade bipartite graph, and the data in different information areas are encrypted in layers using a hierarchical encryption strategy;
[0015] Based on the multi-level authentication results and combined with the access control strategy, the user's rights are allocated, and controlled access to real-name information is carried out under multi-dimensional verification;
[0016] Monitor user information operation behaviors in real time, analyze user behavior characteristics based on anomaly detection models, and trigger additional verification processes or directly restrict user operations when risky behaviors are identified;
[0017] Among them, multi-dimensional verification includes: authentication level verification, access time window restriction and operation scope restriction; multi-level authentication levels can be dynamically adjusted according to user risk behavior.
[0018] As a preferred embodiment of the present invention, when generating a multi-level authentication hierarchy, it includes:
[0019] Generate first-level authentication, second-level authentication, and third-level authentication including access permission model;
[0020] The access permission model is shown in Formula 1 and Formula 2:
[0021] (1);
[0022] (2);
[0023] In the formula, For access permissions, is the serial number of the access permission, Define the characteristics and status of access rights. For concurrent access permissions, For non-concurrent access rights, is the level to which the access permission belongs. The time during which the access rights can be accessed. The information area that can be accessed according to the access rights.
[0024] As a preferred embodiment of the present invention, the first level authentication includes: retrieving data from a related database to verify the consistency of the user's basic identity information;
[0025] The second level of authentication includes: verification based on the user's biometrics on the basis of passing the first level of authentication;
[0026] The third level of authentication includes: multi-factor authentication based on the second level of authentication.
[0027] As a preferred embodiment of the present invention, the multi-factor authentication includes:
[0028] The unique legal identifier provided by the user Use DES algorithm to encrypt and get Ciphertext, and The ciphertext is sent to the server;
[0029] The server uses the DES decryption algorithm to Decrypt the ciphertext and determine the unique legal identifier after decryption If it is legal, the random number will be registered , and the only legal identifier after decryption and registration password As Input to the function, generating the first hash value , and returns to the terminal device;
[0030] The terminal device will register the random number , the unique legal identifier generated by the user during the registration phase and registration password As The input of the function generates the second hash value ;
[0031] Determine the first hash value and the second hash value Are they equal? If they are equal, perform the two-way verification step.
[0032] As a preferred implementation mode of the present invention, the two-way verification step includes:
[0033] Providing random numbers , and the unique legal identifier generated during the registration phase and registration password As The input of the function generates the third hash value , as the first session check value ;
[0034] Get DES key and check the value with the first session , the unique legal identifier generated by the user during the registration phase As The input of the function generates the fourth hash value ;
[0035] According to the second hash value , first session check value And the unique legal identifier generated by the user during the registration phase , generate a first two-way verification parameter;
[0036] According to the fourth hash value , first session check value , generate a second two-way verification parameter;
[0037] Get the session key , and combined with the second hash value , random numbers , the unique legal identifier generated by the user during the registration phase , generate a third two-way verification parameter;
[0038] According to the registration random number and random numbers Using the hash value as input, generating a fourth two-way authentication parameter;
[0039] Sending the two-way verification parameter to the server to obtain a first comparison value and a second comparison value;
[0040] If the first comparison value is consistent with the second comparison value, it is considered that the third level authentication is passed.
[0041] As a preferred embodiment of the present invention, when the real-name system information is divided, it includes:
[0042] The real-name information is evenly divided to obtain an initial sensitive information area, an initial permission information area, and an initial basic information area;
[0043] Randomly select a real-name information from the initial sensitive information area , obtain the difference in the number of sensitive attributes of each real-name information in the initial basic information area, and obtain the difference in the number of sensitive attributes of each real-name information in the initial basic information area Real-name information with the smallest difference in the number of sensitive attributes ;
[0044] Obtain real-name information separately and real-name information The difference between the number of sensitive attributes of each real-name information in the initial permission information area and ;
[0045] According to the difference in the number of sensitive attributes and The real-name information in the initial permission information area is divided into the initial sensitive information area and the initial basic information area one by one until the sum of squares of deviations reaches a preset range, thereby obtaining the basic information area, the permission information area and the sensitive information area.
[0046] As a preferred implementation mode of the present invention, when distributed storage is performed based on a cascaded bipartite graph, it includes:
[0047] Divide the basic information area, the permission information area and the sensitive information area into several information blocks respectively;
[0048] Generate a cascade bipartite graph, encode the information blocks in each information area according to the encoding ratio in the cascade bipartite graph, and distribute and store the encoded information blocks and the original information blocks on the nodes of the information area;
[0049] For damaged information area nodes or information blocks, data is obtained from adjacent information area nodes and decoded to reconstruct the data;
[0050] By accessing the information area node in the highest level information area, the information block stored in the related lower level information area node can be retrieved;
[0051] The cascaded bipartite graph defines the relationship between information blocks in different information areas.
[0052] As a preferred embodiment of the present invention, when data in different information areas are encrypted in layers, it includes:
[0053] For the basic information area and the permission information area, PKCS#7 is used to fill them to reach the preset AES packet length;
[0054] Generate an initialization vector randomly, use the key, initialization vector and CBC mode to encrypt the filled basic information area and permission information area through the AES encryption algorithm;
[0055] For the sensitive information area, a prime-order group is selected, a generator on the group is obtained, and a random integer is generated;
[0056] Generate a public key and a master key based on a generator and a random integer;
[0057] It takes the public key, sensitive information area, original policy string and the chameleon hash value of the attribute as input, and associates the attribute with the sensitive information area through the LSSS access structure;
[0058] The output contains the original policy string, a list of attributes extracted from the access policy, and the ciphertext of the Chameleon hash value.
[0059] As a preferred implementation mode of the present invention, when assigning permissions to users, it includes:
[0060] Providing an access control controller for determining access control policies, through which corresponding access rights are assigned to users according to multi-level authentication results;
[0061] Among them, when assigning corresponding access rights, it includes:
[0062] For the permission information area, the access central controller provides a role group. When any of the second-level authentication and the third-level authentication is passed, the user can access the permission information area as his own subject, and at the same time, he can grant access rights to other subjects who meet the specified roles in the role group to access the permission information area according to his own wishes.
[0063] As a preferred embodiment of the present invention, when analyzing user behavior characteristics based on anomaly detection models, it includes:
[0064] Generate a user behavior analysis table containing fields reflecting the user behavior table, and transform the data in the user behavior analysis table;
[0065] Scan the transaction database, collect the set of frequent items and their corresponding support, sort them in descending order according to the support, and generate a frequent item set table;
[0066] Create the root node of the FP-tree and mark it with null for each transaction in the transaction database Perform binary search to generate frequent item sets of FP-tree;
[0067] By calling the frequent pattern mining algorithm to mine the frequent item sets of the FP-tree, the mined behavior rules are compared one by one with all the behavior rules in the normal historical behavior rule library to identify high-risk behavior, medium-risk behavior and normal behavior.
[0068] Compared with the prior art, the present invention has the following beneficial effects:
[0069] (1) Improving the security and flexibility of identity authentication
[0070] The present invention designs a multi-level authentication mechanism, including basic identity authentication, biometric authentication, and multi-factor authentication, which can dynamically adjust the authentication level according to the user's usage needs and access scenarios, ensuring that the authentication process is both safe and efficient. At the same time, the multi-dimensional verification mechanism (including authentication level verification, access time window restriction, and operation range restriction) further improves the accuracy and dynamic adaptability of authentication, effectively preventing unauthorized access.
[0071] (2) Ensure the security and privacy of real-name information
[0072] The present invention uses an asymmetric encryption algorithm for encrypting the attribute quantity of private data to encrypt and store basic identity information, and adopts a hierarchical encryption strategy to encrypt and protect information areas of different sensitivities (basic information area, permission information area, and sensitive information area), so that the security of different information areas is hierarchically guaranteed. In particular, for the encryption of sensitive information areas, the present invention uses an encryption method based on access policies to associate attributes with information ciphertexts, ensuring that only users who meet specific attribute conditions can access sensitive information, thereby further improving the security of user privacy data.
[0073] (3) Realize distributed storage and efficient recovery of real-name information
[0074] The present invention adopts distributed storage technology, divides the real-name information into multiple information areas and divides it into several information blocks, and encodes and stores the information blocks in combination with the cascaded bipartite graph structure, which not only improves the reliability of information storage, but also reduces the risk of information loss caused by single point failure. In the case of damage to the data node, the data can be obtained and decoded through the adjacent information area nodes, thereby achieving efficient data recovery. In addition, when accessing the high-level information area, the data of the related lower-level information area can be linked to further improve the efficiency of information access and the disaster recovery capability of the system.
[0075] (4) Dynamic permission allocation and flexible access control
[0076] The present invention dynamically allocates user permissions by accessing the central controller according to the user's authentication results and operation scenarios. In particular, after the second-level authentication or the third-level authentication is passed, the invention supports the user's authorization function for the permission information area. The user can not only access the permission information area by himself, but also grant the access rights to other subjects who meet the specified roles in the role group. This dynamic permission allocation method improves the flexibility of the system in complex scenarios, while ensuring the accuracy and security of permission management.
[0077] (5) Enhance abnormal behavior detection and risk control capabilities
[0078] Based on the anomaly detection model, the present invention uses a frequent pattern mining algorithm to perform real-time analysis of user behavior characteristics, and effectively identifies high-risk behaviors, medium-risk behaviors, and normal behaviors by comparing them with the normal historical behavior rule library. Once high-risk behaviors are detected, the present invention can trigger additional verification processes or restrict user operations to ensure that the system can respond to potential security threats in a timely manner, greatly improving the perception and response capabilities to abnormal behaviors.
[0079] (6) Meeting the needs of multiple scenarios
[0080] The present invention can classify the information according to its sensitivity, and adapt to the needs of real-name information management in different scenarios through flexible authentication levels and dynamic authority control strategies, such as data security and privacy protection in government management, risk control in financial services, identity verification in medical insurance, and efficient management in the communications industry. The present invention can achieve the unity of security, flexibility, and reliability in a variety of scenarios, providing versatility and scalability for real-name information management.
[0081] (7) Efficient data processing and access efficiency
[0082] In the process of data encryption, storage and access, the present invention improves the efficiency of data encryption and decryption through the padding optimization of the AES algorithm and the combined design of access strategy and attributes. In data hierarchical storage, through the efficient algorithm design of cascaded bipartite graph and FP-tree, fast data access and behavior rule mining are achieved, providing technical guarantee for the real-time operation of the system.
[0083] (8) High-security two-way verification mechanism
[0084] The present invention introduces multi-factor authentication and two-way verification mechanisms in the third-level authentication, and realizes two-way authentication through encryption algorithms (such as DES algorithm and hash algorithm) and random number generation and comparison process. This mechanism can not only effectively verify the legal identity of the user, but also ensure the credibility of the server, prevent possible disguised servers or man-in-the-middle attacks, thereby further improving the security of the authentication process.
[0085] (9) Optimized data partitioning and storage management strategy
[0086] The present invention proposes a squared deviation optimization algorithm based on the difference in the number of sensitive attributes, which is used to scientifically divide the real-name information so that the division results are more in line with the sensitivity requirements of the information area. In distributed storage, the present invention realizes independent protection of data in different information areas through coded storage, and can quickly restore the data when it is damaged, ensuring the high availability of the system operation.
[0087] To sum up, the present invention not only effectively improves the security, flexibility and reliability of information management through the innovative design of multi-level authentication mechanism, distributed storage technology, hierarchical encryption strategy and abnormal behavior monitoring model in real-name information management, but also significantly enhances the system's risk control ability and ability to adapt to different scenarios. It has broad application value and promotion prospects.
[0088] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0089] Figure 1 It is a step diagram of the real-name information management method supporting multi-level authentication provided by the present invention. DETAILED DESCRIPTION
[0090] The real-name information management method supporting multi-level authentication provided by the present invention is as follows: Figure 1 As shown, the following steps are included:
[0091] Step S1: Collect the basic identity information of the user through the terminal device, and store the collected basic identity information through an asymmetric encryption algorithm encrypted by the privacy data attribute;
[0092] Step S2: Generate a multi-level authentication hierarchy including an access rights model according to the user's usage requirements and access rights requirements;
[0093] Step S3: According to the sensitivity of the real-name information, the real-name information is divided into a basic information area, an authority information area and a sensitive information area by using the difference in the number of sensitive attributes;
[0094] Step S4: Distributed storage is performed on the basic information area, the permission information area and the sensitive information area based on a cascaded bipartite graph to improve data availability, and hierarchical encryption strategies are used to encrypt data in different information areas;
[0095] Step S5: assigning permissions to users based on the multi-level authentication results and in combination with the access control policy, and performing controlled access to real-name information under multi-dimensional verification;
[0096] Step S6: Monitor user information operation behavior in real time, analyze user behavior characteristics based on anomaly detection models, and trigger additional verification processes or directly restrict user operations and record risk events when risky behaviors are identified;
[0097] Step S7: Record the entire process of user identity authentication and information operation, generate a security log and store it in a tamper-proof log management system;
[0098] Among them, the access permission model is used for multi-dimensional verification, including: authentication level verification, access time window restriction and operation scope restriction; the multi-level authentication levels can be dynamically adjusted according to user risk behavior.
[0099] Specifically, when dynamically adjusting the multi-level authentication levels, it includes: when the number of times that the user's behavior characteristics are identified as medium-risk behavior or high-risk behavior reaches a threshold, the authentication level required for the user to access the information area is increased by one level; if the authentication level required for the user to access the information area is the highest level, an additional verification process is triggered.
[0100] For example: If access to the basic information area requires any one of the first-level authentication, second-level authentication, and third-level authentication, when the number of times the user's behavior characteristics are identified as medium-risk behavior or high-risk behavior reaches the threshold, the user will need to pass any one of the second-level authentication or third-level authentication to access the basic information area.
[0101] If the access permission information area needs to pass either the second-level authentication or the third-level authentication, when the number of times the user's behavior characteristics are identified as medium-risk or high-risk behaviors reaches a threshold, the user's access permission information area needs to pass the third-level authentication.
[0102] If access to sensitive information areas requires third-level authentication, when the number of times a user's behavior characteristics are identified as medium-risk or high-risk behaviors reaches a threshold, the user will need to complete an additional verification process on top of passing the third-level authentication to access the sensitive information area.
[0103] In the above step S1, when an asymmetric encryption algorithm for encrypting the attribute quantity of the privacy data is used for encryption and storage, it includes:
[0104] The basic identity information is encrypted by using the element generated by the addition loop parameter of the asymmetric encryption algorithm as the master key to obtain the encrypted basic identity information, as shown in Formula 1:
[0105] (1);
[0106] In the formula, To encrypt basic identity information, As basic identity information, is the addition cycle parameter of the asymmetric encryption algorithm, is the multiplication loop parameter of the asymmetric encryption algorithm, for and The bilinear mapping relationship between them;
[0107] The master key is encrypted by the private data attribute to prevent the master key from being exposed, as shown in Formula 2 and Formula 3:
[0108] (2);
[0109] (3);
[0110] In the formula, is the encrypted master key, is the attribute value of privacy data, is the perturbation coefficient of the privacy encrypted plaintext sequence, It is the security attribute parameter of the basic identity information.
[0111] In the above step S2, when generating a multi-level authentication hierarchy including an access rights model, it includes:
[0112] Generate first-level authentication, second-level authentication, and third-level authentication including access permission model;
[0113] Among them, the access permission model is shown in Formula 1 and Formula 2:
[0114] (1);
[0115] (2);
[0116] In the formula, For access permissions, is the serial number of the access permission, Define the characteristics and status of access rights. For concurrent access permissions, For non-concurrent access rights, is the level to which the access permission belongs. The time during which the access rights can be accessed. Information areas that can be accessed for access rights;
[0117] Among them, the first level authentication, the second level authentication and the third level authentication contain different access rights. .
[0118] Furthermore, the first level authentication includes: retrieving data from the associated database to verify the consistency of the user's basic identity information;
[0119] The second level of authentication includes: verification based on the user's biometrics on the basis of passing the first level of authentication;
[0120] When conducting verification based on user biometrics, it includes:
[0121] Provide a communication random number As a timestamp, and wait for the terminal device to obtain it;
[0122] Obtain the communication random number through the terminal device After that, regenerate another communication random number , and generate authentication random number sets in real time , the authentication random number set Encode to get the sound data signal , and sent to the authentication end for authentication;
[0123] The authentication end receives the sound data signal After that, extract the authentication random number set , and the timestamp Verify whether the timestamp is valid. If not, stop authentication. If yes, perform fingerprint matching.
[0124] If the fingerprint matches, the facial feature matching step is executed. If the fingerprint matches, the authentication is stopped. If the facial feature matches, the verification based on the user's biometrics is considered to have passed. If the facial feature matches, the authentication is stopped.
[0125] The fingerprint matching step includes: judge Whether they match, if so, determine whether the hardware fingerprint feature matches the fingerprint feature recorded in the authentication end;
[0126] The facial feature matching step includes: the authentication end extracts and analyzes the user's facial features, and identifies whether the facial features match the facial features recorded in the authentication end;
[0127] in, The user name set during the user registration phase, The password set during the user registration phase is a random number between the terminal device and the authentication end. The hash value is used as the key for secure communication.
[0128] Furthermore, the third level authentication includes: multi-factor authentication based on the second level authentication;
[0129] Multi-factor authentication, including:
[0130] The unique legal identifier provided by the user Use DES algorithm to encrypt and get Ciphertext, and The ciphertext is sent to the server;
[0131] The server uses the DES decryption algorithm to Decrypt the ciphertext and determine the unique legal identifier after decryption If it is legal, the random number will be registered , and the only legal identifier after decryption and registration password As Input to the function, generating the first hash value , and returns to the terminal device, as shown in Formula 3:
[0132] (3);
[0133] In the formula, for function;
[0134] The terminal device will register the random number , the unique legal identifier generated by the user during the registration phase and registration password As The input of the function generates the second hash value , as shown in Formula 4:
[0135] (4);
[0136] Determine the first hash value and the second hash value Are they equal? If they are equal, perform the two-way verification step;
[0137] Among them, if the server determines that the decrypted unique legal identifier is illegal, or the first hash value and the second hash value If they are not equal, the user is considered to be an illegal user.
[0138] Furthermore, the two-way verification steps include:
[0139] Providing random numbers , and the unique legal identifier generated during the registration phase and registration password As The input of the function generates the third hash value , as the first session check value , as shown in Formula 5:
[0140] (5);
[0141] Get DES key and check the value with the first session , the unique legal identifier generated by the user during the registration phase As The input of the function generates the fourth hash value , as shown in Formula 6:
[0142] (6);
[0143] According to the second hash value , first session check value And the unique legal identifier generated by the user during the registration phase , generate the first two-way verification parameter, as shown in Formula 7:
[0144] (7);
[0145] In the formula, is the first two-way authentication parameter, is an XOR operation;
[0146] According to the fourth hash value , first session check value , generate the second two-way verification parameter, as shown in formula 8:
[0147] (8);
[0148] In the formula, is the second two-way verification parameter;
[0149] Get the session key , and combined with the second hash value , random numbers , the unique legal identifier generated by the user during the registration phase , generate the third two-way verification parameter, as shown in formula 9:
[0150] (9);
[0151] In the formula, is the third two-way verification parameter;
[0152] According to the registration random number and random numbers The hash value is used as the input to generate the fourth two-way verification parameter, as shown in Formula 10:
[0153] (10);
[0154] In the formula, For random numbers As input hash value, is the fourth two-way verification parameter;
[0155] Sending the first two-way verification parameter, the second two-way verification parameter, the third two-way verification parameter, and the fourth two-way verification parameter to the server;
[0156] Using the first two-way verification parameter and the second hash value , generate the second session check value , as shown in Formula 11:
[0157] (11);
[0158] Using the second two-way authentication parameter and the second session verification value , generate the first comparison value, as shown in formula 12:
[0159] (12);
[0160] Using the third two-way verification parameter, the fourth two-way verification parameter and the second hash value , generate the second comparison value, as shown in formula 13:
[0161] (13);
[0162] If the first comparison value is consistent with the second comparison value, it is considered that the third level authentication is passed.
[0163] In the above step S3, when the real-name information is divided, it includes:
[0164] Add sensitive and non-sensitive attributes to the data in each real-name information;
[0165] According to the number of sensitive attributes in each piece of real-name information, the real-name information is evenly divided from high to low to obtain an initial sensitive information area, an initial permission information area, and an initial basic information area;
[0166] Randomly select a real-name information from the initial sensitive information area , obtain real-name information The difference in the number of sensitive attributes of each real-name information in the initial basic information area;
[0167] Get the real-name information from the initial basic information area Real-name information with the smallest difference in the number of sensitive attributes ;
[0168] Obtain real-name information separately and real-name information The difference between the number of sensitive attributes of each real-name information in the initial permission information area and ;
[0169] The real-name information in the initial permission information area is divided into Divide them one by one from small to large into the initial sensitive information area until the sum of squares of deviations of the initial sensitive information area reaches a preset range, stop dividing, and obtain the sensitive information area;
[0170] The remaining real-name information in the initial permission information area is divided into Divide them one by one from small to large into the initial basic information area until the sum of squares of deviations of the initial basic information area reaches a preset range, stop dividing, obtain the basic information area, and use the initial permission information area at this time as the permission information area;
[0171] Among them, the sum of squares of deviations is shown in formula 14:
[0172] (14);
[0173] In the formula, is the sum of squares of deviations in different information areas, For the initial sensitive information area, It is the initial basic information area; For the The number of sensitive attributes of real-name information, It is the number of real-name information in the information area.
[0174] In the above step S4, when the real-name information is distributedly stored, it includes:
[0175] Divide the basic information area, the permission information area and the sensitive information area into several information blocks respectively;
[0176] Generate a cascade bipartite graph, encode the information blocks in each information area according to the encoding ratio in the cascade bipartite graph, and distribute and store the encoded information blocks and the original information blocks on the nodes of the information area;
[0177] For damaged information area nodes or information blocks, data is obtained from adjacent information area nodes and decoded to reconstruct the data;
[0178] By accessing the information area node in the highest level information area, the information block stored in the related lower level information area node can be retrieved;
[0179] Among them, the cascaded bipartite graph defines the relationship between information blocks between different information areas. During encoding, the upper-level information area node pushes the information block to the related lower-level information area node. The lower-level information area node performs an XOR operation on the received information block to generate a check block of the information area of this layer, and pushes it as an information block to the related lower-level information area node until the last layer.
[0180] In the above step S4, when the data in different information areas are encrypted in layers, it includes:
[0181] For the basic information area and the permission information area, PKCS#7 is used to fill them to reach the preset AES packet length;
[0182] Generate an initialization vector randomly, use the key, initialization vector and CBC mode, and encrypt the filled basic information area and permission information area through the AES encryption algorithm, as shown in Formula 15:
[0183] (15);
[0184] In the formula, For the ciphertext blocks, To use the key AES encryption algorithm is used. For the plaintext blocks, For the ciphertext blocks, is an XOR operation;
[0185] When decrypting, the initialization vector in the ciphertext is extracted and decrypted using the same key and CBC mode, as shown in Formula 16:
[0186] (16);
[0187] In the formula, For the plaintext blocks, To use the key The AES decryption algorithm performed;
[0188] Remove the padding from the padded basic information area and the permission information area obtained after decryption to obtain the original basic information area and the permission information area;
[0189] For the sensitive information area, a prime-order group is selected, a generator on the group is obtained, and a random integer is generated;
[0190] Generate a public key and a master key based on a generator and a random integer;
[0191] It takes the public key, sensitive information area, original policy string and the chameleon hash value of the attribute as input, and associates the attribute with the sensitive information area through the LSSS access structure;
[0192] The output contains the original policy string, a list of attributes extracted from the access policy, and the ciphertext of the Chameleon hash value;
[0193] When decrypting, the public key, the master key, and a set of attributes are taken as input, a random integer is selected to create a private key, and a user key dictionary containing the master key, the auxiliary key, and a list of user attributes is returned. The ciphertext is decrypted using the user key dictionary.
[0194] In the above step S5, when assigning permissions to users, it includes:
[0195] Provide an access control center for determining access control policies, and assign corresponding access rights to users based on multi-level authentication results through the access control center;
[0196] Among them, when assigning corresponding access rights, it includes:
[0197] For sensitive information areas, after passing the third-level authentication, the user is granted access to the sensitive information area through the security label;
[0198] For the basic information area, once any of the first-level authentication, second-level authentication, and third-level authentication is passed, the user can access the basic information area as his / her own subject, and can also grant access rights to other subjects to access the basic information area according to his / her own wishes;
[0199] For the permission information area, the access central controller provides a role group. When any of the second-level authentication and the third-level authentication is passed, the user can access the permission information area as his own subject, and at the same time, he can grant access rights to other subjects who meet the specified roles in the role group to access the permission information area according to his own wishes.
[0200] In the above step S6, when analyzing the user behavior characteristics based on the anomaly detection model, it includes:
[0201] Load security logs, identify users by user ID, and create a user behavior list, which includes: user ID, time, and operation content;
[0202] Create a new table and name it with the user ID, add the user behavior list to the table, and get a user behavior analysis table that contains fields reflecting the user behavior table;
[0203] Transform the data in the user behavior analysis table, including: dividing the attribute values into equal distances for the data of the quantity multi-value attribute, and directly mapping each category into a Boolean value for the data of the category multi-value attribute;
[0204] Scan the transaction database, collect the set of frequent items and their corresponding support, sort them in descending order according to the support, and generate a frequent item set table;
[0205] Create the root node of the FP-tree and mark it with null for each transaction in the transaction database Perform binary search to generate frequent item sets of FP-tree;
[0206] The frequent item sets of the FP-tree are mined by calling the frequent pattern mining algorithm, and the mined behavior rules are compared one by one with all the behavior rules in the normal historical behavior rule library;
[0207] If the difference between the mined behavior rules and the minimum support and minimum credibility of all behavior rules in the normal historical behavior rule library is not within the preset range, it is judged as a high-risk behavior;
[0208] If the difference between the mined behavior rules and the minimum support or minimum credibility of all behavior rules in the normal historical behavior rule library is not within the preset range, it is judged as a medium-risk behavior;
[0209] If the difference between the minimum support and the minimum credibility of the mined behavior rule and any behavior rule in the normal historical behavior rule library is within the preset range, it is judged as normal behavior;
[0210] The binary search process includes: selecting frequent items in the transaction and arranging them according to the order in the frequent item set table to obtain the arranged frequent item set table ,in, is the first frequent item, is the remaining frequent items; if the arranged frequent item set table If not empty, call ,like If not empty, recursively call ,in, For business.
[0211] Specifically, Functions related to binary search tree operations, The execution process includes: Have children Make ,but The count is increased by 1, if the transaction Childlessness makes , a new node is created , and set its count to 1, linking to its parent transaction , and also link it to the same Node.
[0212] The above-mentioned embodiments are only preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and substitutions made by technicians in this field on the basis of the present invention shall fall within the scope of protection required by the present invention.
Claims
1. A real-name information management method supporting multi-level authentication, characterized in that: The following steps are involved: Collect the user's basic identity information through the terminal device and store it through an asymmetric encryption algorithm that encrypts the privacy data attributes; Generate multi-level authentication levels based on user usage needs and access permission requirements; According to the sensitivity of real-name information, the real-name information is divided into basic information area, permission information area and sensitive information area; The basic information area, permission information area and sensitive information area are distributedly stored based on the cascade bipartite graph, and the data in different information areas are encrypted in layers using a hierarchical encryption strategy; Based on the multi-level authentication results and combined with the access control strategy, the user's rights are allocated, and controlled access to real-name information is carried out under multi-dimensional verification; Monitor user information operation behaviors in real time, analyze user behavior characteristics based on anomaly detection models, and trigger additional verification processes or directly restrict user operations when risky behaviors are identified; Among them, multi-dimensional verification includes: authentication level verification, access time window restriction and operation scope restriction; multi-level authentication levels can be dynamically adjusted according to user risk behavior; Among them, when generating a multi-level authentication hierarchy, it includes: Generate first-level authentication, second-level authentication, and third-level authentication including access permission model; The access permission model is shown in Formula 1 and Formula 2: (1); (2); In the formula, For access permissions, is the serial number of the access permission, Define the characteristics and status of access rights. For concurrent access permissions, For non-concurrent access rights, is the level to which the access permission belongs. The time during which the access rights can be accessed. Information areas that can be accessed for access rights; When distributed storage is performed based on cascaded bipartite graphs, it includes: Divide the basic information area, the permission information area and the sensitive information area into several information blocks respectively; Generate a cascade bipartite graph, encode the information blocks in each information area according to the encoding ratio in the cascade bipartite graph, and distribute and store the encoded information blocks and the original information blocks on the nodes of the information area; For damaged information area nodes or information blocks, data is obtained from adjacent information area nodes and decoded to reconstruct the data; By accessing the information area node in the highest level information area, the information block stored in the related lower level information area node can be retrieved; The cascaded bipartite graph defines the relationship between information blocks in different information areas.
2. The real-name information management method supporting multi-level authentication according to claim 1, characterized in that: The first level of authentication includes: retrieving data from the associated database to verify the consistency of the user's basic identity information; The second level of authentication includes: verification based on the user's biometrics on the basis of passing the first level of authentication; The third level of authentication includes: multi-factor authentication based on the second level of authentication.
3. The real-name information management method supporting multi-level authentication according to claim 2, characterized in that: The multi-factor authentication includes: The unique legal identifier provided by the user Use DES algorithm to encrypt and get Ciphertext, and The ciphertext is sent to the server; The server uses the DES decryption algorithm to Decrypt the ciphertext and determine the unique legal identifier after decryption If it is legal, the random number will be registered , and the only legal identifier after decryption and registration password As Input to the function, generating the first hash value , and returns to the terminal device; The terminal device will register the random number , the unique legal identifier generated by the user during the registration phase and registration password As The input of the function generates the second hash value ; Determine the first hash value and the second hash value Are they equal? If they are equal, perform the two-way verification step.
4. The real-name information management method supporting multi-level authentication according to claim 3, characterized in that: The two-way verification step includes: Providing random numbers , and the unique legal identifier generated during the registration phase and registration password As The input of the function generates the third hash value , as the first session check value ; Get DES key and checksum value with the first session , the unique legal identifier generated by the user during the registration phase As The input of the function generates the fourth hash value ; According to the second hash value , first session check value And the unique legal identifier generated by the user during the registration phase , generate a first two-way verification parameter; According to the fourth hash value , first session check value , generate a second two-way verification parameter; Get the session key , and combined with the second hash value , random numbers , the unique legal identifier generated by the user during the registration phase , generate a third two-way verification parameter; According to the registration random number and random numbers Using the hash value as input, generating a fourth two-way authentication parameter; Sending the two-way verification parameter to the server to obtain a first comparison value and a second comparison value; If the first comparison value is consistent with the second comparison value, it is considered that the third level authentication is passed.
5. The real-name information management method supporting multi-level authentication according to any one of claims 1 to 4, characterized in that: When classifying real-name information, it includes: The real-name information is evenly divided to obtain an initial sensitive information area, an initial permission information area, and an initial basic information area; Randomly select a real-name information from the initial sensitive information area , obtain the difference in the number of sensitive attributes of each real-name information in the initial basic information area, and obtain the difference in the number of sensitive attributes of each real-name information in the initial basic information area Real-name information with the smallest difference in the number of sensitive attributes ; Obtain real-name information separately and real-name information The difference between the number of sensitive attributes of each real-name information in the initial permission information area and ; According to the difference in the number of sensitive attributes and The real-name information in the initial permission information area is divided into the initial sensitive information area and the initial basic information area one by one until the sum of squares of deviations reaches a preset range, thereby obtaining the basic information area, the permission information area and the sensitive information area.
6. The real-name information management method supporting multi-level authentication according to claim 5, characterized in that: When performing layered encryption on data in different information areas, it includes: For the basic information area and the permission information area, PKCS#7 is used to fill them to reach the preset AES packet length; Generate an initialization vector randomly, use the key, initialization vector and CBC mode to encrypt the filled basic information area and permission information area through the AES encryption algorithm; For the sensitive information area, a prime-order group is selected, a generator on the group is obtained, and a random integer is generated; Generate a public key and a master key based on a generator and a random integer; It takes the public key, sensitive information area, original policy string and the chameleon hash value of the attribute as input, and associates the attribute with the sensitive information area through the LSSS access structure; The output contains the original policy string, a list of attributes extracted from the access policy, and the ciphertext of the Chameleon hash value.
7. The real-name information management method supporting multi-level authentication according to any one of claims 1 to 4, characterized in that: When assigning permissions to users, include: Providing an access control controller for determining access control policies, through which corresponding access rights are assigned to users according to multi-level authentication results; Among them, when assigning corresponding access rights, it includes: For the permission information area, the access central controller provides a role group. When any of the second-level authentication and the third-level authentication is passed, the user can access the permission information area as his own subject, and at the same time, he can grant access rights to other subjects who meet the specified roles in the role group to access the permission information area according to his own wishes.
8. The real-name information management method supporting multi-level authentication according to any one of claims 1 to 4, characterized in that: When analyzing user behavior characteristics based on anomaly detection models, it includes: Generate a user behavior analysis table containing fields reflecting the user behavior table, and transform the data in the user behavior analysis table; Scan the transaction database, collect the set of frequent items and their corresponding support, sort them in descending order according to the support, and generate a frequent item set table; Create the root node of the FP-tree and mark it with null for each transaction in the transaction database Perform binary search to generate frequent item sets of FP-tree; By calling the frequent pattern mining algorithm to mine the frequent item sets of the FP-tree, the mined behavior rules are compared one by one with all the behavior rules in the normal historical behavior rule library to identify high-risk behavior, medium-risk behavior and normal behavior.
Citation Information
Patent Citations
Remote access data processing method and device, equipment and storage medium
CN117371048A
Zero-trust network construction method and system
CN117811764A