An electronic seal public service management system
By introducing user authorization behavior evaluation and analysis module and authorization adjustment module in the electronic seal public service management system, combining historical authorization behavior data and dynamic IP change abnormal indication correction factor, the problem of insufficient accuracy of remote authorization judgment is solved, and higher authorization judgment accuracy and system security are achieved.
Patent Information
- Application Number
- CN202411452037.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-10-17
AI Technical Summary
In the prior art, the electronic seal public service management system has the problem of insufficient accuracy in remote authorization judgment, which leads to abnormal behaviors that take a long time and a number of times to be detected, and it is easy to cause misjudgment.
It provides an electronic seal public service management system, including an electronic seal user terminal, a central service manager, an electronic seal user authorization behavior information evaluation and analysis module and an authorization adjustment module. Through the analysis of historical authorization behavior data and the comprehensive judgment of dynamic IP change abnormal indication correction factors, the accuracy of remote authorization judgment is improved.
It improves the accuracy of remote authorization judgments for electronic seal public service management, can more accurately identify potential authorization risks, reduce security risks, prevent cyber attacks or abuses, and enhance the security and efficiency of the system.
Smart Images

Figure CN119598478B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic seal data processing, and particularly to an electronic seal public service management system. Background Art
[0002] With the development of information technology, the demand for digital transformation in various fields of society is increasing day by day. Traditional paper documents and physical seals have limitations in terms of processing speed, storage convenience, and security. Therefore, promoting e-government and digital management has become an inevitable trend. An electronic seal is a graphical electronic signature based on cryptography technology that effectively binds digital certificates, signature keys, and physical seal images to achieve the integrity, authenticity, and non-repudiation of electronic documents. With the increase in network attacks and information leakage incidents, the public's attention to information security has been continuously improved, and the encryption and security features of electronic seals meet this social demand.
[0003] The existing electronic seal public service management system is implemented through the following technologies, including: digital signature technology, digital certificate technology, encryption technology, timestamp service, image processing technology, and database management technology; through the above technologies, the electronic seal conducts authorization after reviewing the electronic authorization of enterprises that need authorization.
[0004] For example, an electronic seal authorization method, system, electronic device, and storage medium disclosed in the invention patent announcement with the publication number of CN113591155B includes: collecting and extracting features of the original handwriting data of the electronic signature related to the seal authorization; obtaining and extracting features of the electronic signature data of the current authorization; calculating the similarity between the features of the original handwriting data and the features of the electronic signature data of the current authorization; making a judgment based on the similarity; if the similarity is greater than a preset threshold, it is determined as the signature of the person himself, and the seal authorization information is sent; according to the seal authorization information, the authorization is carried out according to the preset authorization process. The system includes: an original handwriting data module, an original handwriting feature module, a current signature module, a current signature feature module, a calculation and judgment module, and a seal authorization module.
[0005] For example, an intelligent management method for electronic seal authorization disclosed in the invention patent announcement with the announcement number CN117056913B includes: collecting original data, obtaining a number of usage frequency sequences, and designating any one of the usage frequency sequences as the target sequence. Then, the data in the target sequence is divided into several data categories. Based on the central data of all data categories, the category difference of the target sequence is obtained. All data categories in the target sequence are divided into several new categories. Based on the data values, data quantities, and the number of data categories in all new categories, the first density of the target sequence is obtained, thereby obtaining the initial anomaly recognition degree of the target sequence. From this, several first-scale sequences and second-scale sequences are obtained. Then, by combining the data relationships between all first-scale sequences and all second-scale sequences, it is determined whether there are anomalies in the original data.
[0006] However, in the process of implementing the technical solution of the invention in the embodiments of the present application, it is found that the above technology has at least the following technical problems:
[0007] In the prior art, since the evaluation of electronic seal authorization mainly focuses on identity verification and permission identification, or is evaluated through the analysis of data when using the seal in the past, it takes a long time and multiple abnormal behaviors to be detected. Moreover, in the process of remotely authorizing an electronic seal, due to various factors, misjudgments are likely to occur, and there is a problem of insufficient accuracy in the remote authorization judgment of electronic seal public service management. Summary of the Invention
[0008] By providing an electronic seal public service management system in the embodiments of the present application, the problem of insufficient accuracy in the remote authorization judgment of electronic seal public service management in the prior art is solved, and the accuracy of the remote authorization judgment of electronic seal public service management is improved.
[0009] An embodiment of the present application provides an electronic seal public service management system, including: an electronic seal user terminal, a central service manager, a first evaluation and analysis module for electronic seal user authorization behavior information, a second evaluation and analysis module for electronic seal user authorization behavior information, and an electronic seal user authorization adjustment module; wherein, the electronic seal user terminal is used to send a remote authorization request for the electronic seal of the electronic seal user; the central service manager is used to receive the remote authorization request for the electronic seal of the electronic seal user, perform electronic seal identity and permission authentication, and send the electronic seal identity and permission authentication result to the electronic seal user terminal; the first evaluation and analysis module for electronic seal user authorization behavior information is used to obtain historical electronic seal user authorization behavior information data, perform analysis on abnormal electronic seal user authorization behavior, and obtain an abnormal indication value of the electronic seal user authorization behavior; the second evaluation and analysis module for electronic seal user authorization behavior information is used to judge whether to accept the remote authorization request for the electronic seal of the electronic seal user according to the abnormal indication value of the electronic seal user authorization behavior, send the judgment result to the central service manager, if accepted, notify relevant personnel through the central service manager, if not accepted, perform analysis on the abnormal electronic seal user to be evaluated; the electronic seal user authorization adjustment module is used to judge and adjust the authorization of the electronic seal user to be evaluated according to the analysis result of the abnormal electronic seal user to be evaluated.
[0010] Further, the specific process of performing electronic seal identity and permission authentication is as follows: the central service manager includes a central service manager receiving unit, a central service manager matching and verifying unit, and a central service manager matching and sending unit; the central service manager receiving unit: used to receive the remote authorization request for the electronic seal of the electronic seal user; the central service manager matching and verifying unit: used to review the historical electronic seal authorization association data of the electronic seal user according to the predefined electronic seal user authorization review rules based on the historical electronic seal authorization association data of the electronic seal user, and judge whether the identity of the electronic seal user is verified successfully according to the review result; the central service manager matching and sending unit: used to judge whether to extract historical electronic seal user authorization behavior information data according to the electronic seal user identity verification result, if the electronic seal user identity is verified successfully, extract the historical electronic seal user authorization behavior information data, send the information of successful electronic seal user identity verification to the electronic seal user terminal, if the electronic seal user identity is not verified successfully, do not extract the historical electronic seal user authorization behavior information data, and send the information of failed electronic seal user identity verification to the electronic seal user terminal.
[0011] Further, the specific process of analyzing the abnormal behavior of electronic seal user authorization is as follows: The first evaluation and analysis module of electronic seal user authorization behavior information includes an electronic seal user authorization behavior information acquisition unit and a historical electronic seal user authorization behavior information processing unit; The electronic seal user authorization behavior information acquisition unit: used to extract the historical electronic seal user authorization behavior information data of the electronic seal user in the central service manager; The historical electronic seal user authorization behavior information processing unit: used to divide the historical electronic seal user authorization behavior information data according to the predefined electronic seal authorization time period, obtain the historical electronic seal user authorization behavior information data under different predefined electronic seal authorization time periods, extract the data set of the machine IP addresses of the electronic seal user terminals received by the central service manager and the total historical data set of the machine IP addresses of the electronic seal user terminals under the predefined electronic seal authorization time period; If the data set of the machine IP addresses of the electronic seal user terminals received by the central service manager under the predefined electronic seal authorization time period belongs to the total historical data set of the machine IP addresses of the electronic seal user terminals, then analyze the historical authorization request times under the predefined electronic seal authorization time period to obtain the electronic seal remote authorization request indication value, combined with the dynamic IP change abnormal indication correction factor, and analyze to obtain the electronic seal user authorization behavior abnormal indication value.
[0012] Further, the specific method for obtaining the dynamic IP change abnormal indication correction factor is as follows: Combine the different dynamic IP addresses when the electronic seal user sends an electronic seal remote authorization request through the electronic seal user terminal and record them as the electronic seal remote authorization request dynamic IP address set; Record the different dynamic IP addresses when the electronic seal user sends an electronic seal remote authorization request through the electronic seal user terminal for the last time as the current dynamic IP address of the electronic seal user terminal; Compare and analyze the current dynamic IP address of the electronic seal user terminal with the electronic seal remote authorization request dynamic IP address set to obtain the dynamic IP change abnormal indication correction value under the predefined electronic seal authorization time period; Extract the total number of types of dynamic IP addresses of the electronic seal user terminal under the predefined electronic seal authorization time period; Thus, analyze and obtain the dynamic IP change abnormal indication correction factor.
[0013] Further, determining whether to accept the remote authorization request of the electronic seal user based on the abnormal indication value of the electronic seal user authorization behavior specifically includes: recording the maximum value of the abnormal indication value of the electronic seal user authorization behavior of the electronic seal user under different predefined electronic seal authorization time periods as the maximum abnormal indication value of the electronic seal user authorization behavior; comparing and analyzing the maximum abnormal indication value of the electronic seal user authorization behavior with a preset first threshold of the abnormal indication value of the electronic seal user authorization behavior, and recording the difference between the two as the abnormal indication value of the electronic seal user authorization behavior; if the abnormal indication value of the electronic seal user authorization behavior is greater than or equal to the first threshold of the abnormal indication value of the electronic seal user authorization behavior, then do not accept the remote authorization request of the electronic seal user of the electronic seal user and send it to the central service manager, and notify the relevant personnel to contact the electronic seal user; if the abnormal indication value of the electronic seal user authorization behavior is less than the first threshold of the abnormal indication value of the electronic seal user authorization behavior and greater than or equal to the second threshold of the abnormal indication value of the electronic seal user authorization behavior, then do not accept the remote authorization request of the electronic seal user of the electronic seal user, and list the electronic seal user as an electronic seal user to be evaluated and send it to the central service manager, and notify the relevant personnel to send a message to the electronic seal user through the central service manager, and the message is used to notify the electronic seal user to send a remote authorization request of the electronic seal again; if the abnormal indication value of the electronic seal user authorization behavior is less than the second threshold of the abnormal indication value of the electronic seal user authorization behavior, then accept the remote authorization request of the electronic seal user of the electronic seal user.
[0014] Further, the abnormal analysis of the electronic seal user to be evaluated is carried out, specifically including: performing a routing trace analysis on the electronic seal user terminal of the electronic seal user to be evaluated through a computer network diagnostic tool to obtain the end IP of the network node to be evaluated, comparing and analyzing the end IP of the network node to be evaluated with the machine IP of the electronic seal user terminal, if they are the same, then notify the relevant personnel to receive and handle the business of the remote authorization request of the electronic seal user sent again online, if they are different, then perform a network fluctuation analysis on the electronic seal user to be evaluated.
[0015] Further, the network fluctuation analysis of the electronic seal user to be evaluated is carried out, specifically including: obtaining the maximum abnormal indication value of the electronic seal user authorization behavior of the electronic seal user to be evaluated; obtaining the number of network connection interruptions of the remote authorization request of the electronic seal by checking the access log on the server side; setting a filter according to the specific port number of the electronic seal user terminal, capturing the data packets of the electronic seal user terminal through a network monitoring tool and the filter to obtain the packet loss rate parameter of the data packets of the remote authorization request of the electronic seal; directly obtaining the number of hops of the network path for the transmission of the data packets of the remote authorization request of the electronic seal through a network diagnostic tool; comprehensively analyzing the above parameters to obtain the abnormal factor of the network fluctuation analysis of the electronic seal user to be evaluated.
[0016] Further, the judgment and adjustment of the authorization of the electronic seal user to be evaluated specifically include: if the abnormal factor of the network fluctuation analysis of the electronic seal user to be evaluated is greater than or equal to the abnormal threshold of the network fluctuation analysis, the electronic seal user to be evaluated is recorded as a first-level electronic seal user to be evaluated.
[0017] Further, the judgment and adjustment of the authorization of the electronic seal user to be evaluated also include: if the abnormal factor of the network fluctuation analysis is less than the abnormal threshold of the network fluctuation analysis, the electronic seal remote authorization request reissued by the electronic seal user is rejected, and relevant personnel are notified to manually review the historical electronic seal user authorization behavior information data of the electronic seal user online.
[0018] Further, the judgment and adjustment of the authorization of the electronic seal user to be evaluated also include: after a predefined repeated evaluation time, the abnormal factor of the network fluctuation analysis of the first-level electronic seal user to be evaluated is evaluated again, denoted as the repeated value of the abnormal factor of the network fluctuation analysis. If the repeated value of the abnormal factor of the network fluctuation analysis is greater than or equal to the abnormal threshold of the network fluctuation analysis; relevant personnel are notified to manually check online through a network monitoring tool whether the network path of the data packet transmission of the electronic seal remote authorization request of the electronic seal user is under a network attack; if so, relevant personnel are notified to start a network attack emergency plan through the central service manager; if not, the electronic seal user is notified to adjust the network environment where the electronic seal user terminal is located and reissue the business of the electronic seal remote authorization request, and relevant personnel are notified to receive and handle the business of the electronic seal remote authorization request reissued by the electronic seal user online.
[0019] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0020] 1. By sending a request through the electronic seal user terminal, the central service manager authenticates and gives feedback. The evaluation and analysis of the electronic seal user authorization behavior find that the authorization behavior is abnormal, and the electronic seal user authorization adjustment module processes the abnormal authorization, thereby improving the accuracy of the remote authorization judgment in the public service management of electronic seals and solving the problem of insufficient accuracy in the remote authorization judgment in the public service management of electronic seals in the prior art.
[0021] 2. According to the abnormal indication value of the electronic seal user authorization behavior, it is judged whether to accept the electronic seal remote authorization request of the electronic seal user. By analyzing the abnormal indication value of the user authorization behavior, potential authorization risks can be more accurately identified, thereby improving the security of the system. At the same time, by setting different thresholds, the authorization requests can be managed hierarchically, and different countermeasures can be taken for abnormal behaviors, thereby realizing the effectiveness of risk control.
[0022] 3. Based on the analysis results of the anomalies of the electronic seal user to be evaluated, judge and adjust the authorization of the electronic seal user to be evaluated. By comprehensively analyzing the anomaly factors of network fluctuations, it is possible to more accurately identify the network problems that the electronic seal user to be evaluated may face, such as network fluctuations or attacks. By rejecting the authorization requests of users with abnormal network behaviors and conducting manual reviews, the system reduces security risks and prevents possible network attacks or abuses, thereby achieving the improvement of the adaptability of remote authorization judgment in public service management. Brief Description of the Drawings
[0023] Figure 1 It is a schematic structural diagram of the electronic seal public service management system provided by the embodiment of the present application;
[0024] Figure 2 It is a schematic structural diagram of the central service manager in the electronic seal public service management system provided by the embodiment of the present application. Detailed Embodiment
[0025] By providing an electronic seal public service management system in the embodiment of the present application, the problem of insufficient accuracy in remote authorization judgment in the existing electronic seal public service management is solved. After analyzing and evaluating the authorization behaviors of electronic seal users, the network environment is judged, and finally specific authorization adjustments are given, achieving the effect of improving the accuracy of remote authorization judgment in electronic seal public service management.
[0026] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific embodiments.
[0027] Such as Figure 1As shown in the figure, it is a schematic structural diagram of the electronic seal public service management system provided by the embodiment of the present application. The electronic seal public service management system provided by the embodiment of the present application includes: an electronic seal user terminal, a central service manager, a first evaluation and analysis module for electronic seal user authorization behavior information, a second evaluation and analysis module for electronic seal user authorization behavior information, and an electronic seal user authorization adjustment module; wherein, the electronic seal user terminal is used to send an electronic seal remote authorization request of the electronic seal user; the central service manager is used to receive the electronic seal remote authorization request of the electronic seal user, perform electronic seal identity and permission authentication, and send the electronic seal identity and permission authentication result to the electronic seal user terminal; the first evaluation and analysis module for electronic seal user authorization behavior information is used to obtain historical electronic seal user authorization behavior information data, perform abnormal analysis of the electronic seal user authorization behavior, and obtain an electronic seal user authorization behavior abnormal indication value; the second evaluation and analysis module for electronic seal user authorization behavior information is used to judge whether to accept the electronic seal remote authorization request of the electronic seal user according to the electronic seal user authorization behavior abnormal indication value, send the judgment result to the central service manager, if accepted, notify relevant personnel through the central service manager, if not accepted, perform abnormal analysis of the electronic seal user to be evaluated; the electronic seal user authorization adjustment module is used to judge and adjust the electronic seal user authorization according to the abnormal analysis result of the electronic seal user to be evaluated.
[0028] In this embodiment, for the electronic seal remote authorization request of the electronic seal user, some electronic seal users often travel on business, or the authorized application departments are scattered in different regions. If this is simply used as an evaluation criterion, the normal electronic seal authorization requests of the electronic seal users are likely to be misjudged as abnormal. Moreover, due to the electronic seal remote authorization, relevant personnel cannot directly communicate face-to-face with the electronic seal user, and the analysis of specific situations is not timely and accurate, further reducing the efficiency and accuracy of the electronic seal remote authorization.
[0029] Further, the specific process of electronic seal identity and permission authentication is as follows: The central service manager includes a central service manager receiving unit, a central service manager matching and verifying unit, and a central service manager matching and sending unit; The central service manager receiving unit: is used to receive the remote authorization request of the electronic seal of the electronic seal user; The central service manager matching and verifying unit: is used to review the historical electronic seal authorization association data of the electronic seal user according to the predefined electronic seal user authorization review rules based on the historical electronic seal authorization association data of the electronic seal user, and judge whether the identity of the electronic seal user is verified successfully according to the review result; The central service manager matching and sending unit: is used to judge whether to extract the historical electronic seal user authorization behavior information data according to the electronic seal user identity verification result. If the electronic seal user identity is verified successfully, the historical electronic seal user authorization behavior information data is extracted, and the information of successful electronic seal user identity verification is sent to the electronic seal user terminal. If the electronic seal user identity verification is unsuccessful, the historical electronic seal user authorization behavior information data is not extracted, and the information of failed electronic seal user identity verification is sent to the electronic seal user terminal.
[0030] In this embodiment, as Figure 2 shown, it is a schematic structural diagram of the central service manager in the electronic seal public service management system provided by the embodiment of the present application. The review result only includes that the electronic seal user identity verification is successful or the electronic seal user identity verification is unsuccessful.
[0031] When receiving the remote authorization request of the electronic seal of the electronic seal user sent by the electronic seal user terminal, start to extract the historical electronic seal authorization association data of the electronic seal user according to the main index rule of the electronic seal user, review the historical electronic seal authorization association data of the electronic seal user through the predefined electronic seal user authorization review rules, and judge whether the electronic seal user should be authorized.
[0032] The historical electronic seal authorization association data is used to describe all the data used to obtain the electronic seal authorization in the history of the electronic seal user. The historical electronic seal authorization association data mainly includes but is not limited to the face recognition data, company registration data, company legal person data, iris verification data, and login account password data of the electronic seal user.
[0033] The review by the predefined electronic seal user authorization review rules can be to verify the face data and login account password data of the electronic seal user, or to verify the iris verification data and company registration data, which is set manually by the electronic seal authorizing party.
[0034] Further, the specific process of analyzing the abnormal behavior of electronic seal user authorization is as follows: The first evaluation and analysis module of electronic seal user authorization behavior information includes an electronic seal user authorization behavior information acquisition unit and a historical electronic seal user authorization behavior information processing unit; Electronic seal user authorization behavior information acquisition unit: used to extract the historical electronic seal user authorization behavior information data of the electronic seal user in the central service manager; Historical electronic seal user authorization behavior information processing unit: used to divide the historical electronic seal user authorization behavior information data according to the predefined electronic seal authorization time period, obtain the historical electronic seal user authorization behavior information data under different predefined electronic seal authorization time periods, and extract the data set of the machine IP address of the electronic seal user terminal received by the central service manager and the total historical data set of the machine IP address of the electronic seal user terminal under the predefined electronic seal authorization time period; If the data set of the machine IP address of the electronic seal user terminal received by the central service manager under the predefined electronic seal authorization time period belongs to the total historical data set of the machine IP address of the electronic seal user terminal, then an electronic seal remote authorization request indication value is analyzed for the historical authorization request times under the predefined electronic seal authorization time period, and an abnormal indication value of electronic seal user authorization behavior is analyzed in combination with the dynamic IP change abnormal indication correction factor.
[0035] In this embodiment, the abnormal indication value of electronic seal user authorization behavior is used to describe the relative abnormal indication level of the authorization behavior of the electronic seal user in the predefined electronic seal authorization time period.
[0036] The specific method for obtaining the abnormal indication value of electronic seal user authorization behavior is as follows:
[0037]
[0038] If E ∈ F, then
[0039] If Then the electronic seal user is judged as a to-be-evaluated electronic seal user, and the abnormal analysis of the to-be-evaluated electronic seal user is carried out;
[0040] If the identity verification of the electronic seal user passes, it means that the identity of this electronic seal user is correct, but whether the electronic seal authorization can be carried out still requires further evaluation and analysis.
[0041] The historical electronic seal user authorization behavior information data is segmented through the predefined electronic seal authorization time period, so that the historical electronic seal user authorization behavior information data of the electronic seal user is divided into historical electronic seal user authorization behavior information data under different predefined electronic seal authorization time periods.
[0042] Number the predefined electronic seal authorization time periods one by one as Y 0 represents the number of the predefined electronic seal authorization time period, and Y represents the total number of predefined electronic seal authorization time periods.
[0043] represents the Y 0 th electronic seal user authorization behavior anomaly flag value for the predefined electronic seal authorization time period.
[0044] represents the Y 0 th electronic seal remote authorization request indication value for the predefined electronic seal authorization time period.
[0045] represents the Y 0 th authorization success rate of the electronic seal remote authorization request for the predefined electronic seal authorization time period.
[0046] SG AVG represents the average authorization success rate of the electronic seal remote authorization request.
[0047] Monitor the success rate of authorization requests. Frequent authorization failures may indicate anomalies.
[0048] E represents the data set of the machine IP addresses of the electronic seal user terminals received by the central service manager for the Y 0 th predefined electronic seal authorization time period.
[0049] F represents the total historical data set of the machine IP addresses of the electronic seal user terminals.
[0050] An electronic seal user may have multiple electronic seal user terminals, and each electronic seal user terminal generally corresponds to a machine IP address. Generally, the data set of the machine IP addresses of the electronic seal user terminals received by the central service manager should belong to the data set of the machine IP addresses of the electronic seal user terminals. If the data set of the machine IP addresses of the electronic seal user terminals received by the central service manager does not belong to the data set of the machine IP addresses of the electronic seal user terminals, it may be an abnormal situation and relevant personnel need to be notified for inspection and confirmation.
[0051] Classify the total number of electronic seal remote authorization requests sent by the electronic seal user through the electronic seal user terminal under different predefined electronic seal authorization time periods to obtain the number of electronic seal remote authorization requests for the predefined electronic seal authorization time period. Divide the number of electronic seal remote authorization requests for the predefined electronic seal authorization time period by the duration of the predefined electronic seal authorization time period to obtain the electronic seal remote authorization request frequency for the predefined electronic seal authorization time period.
[0052] Indicates the frequency of remote authorization requests for the electronic seal under the Y 0 th predefined electronic seal authorization time period.
[0053] λ AVG Indicates the average frequency of remote authorization requests for the electronic seal.
[0054] Merge the timestamps corresponding to all previous remote authorization requests for the electronic seal of the electronic seal user, including this time, into a data group, denoted as the historical authorization request timestamp data group of the electronic seal user. Arrange and classify the historical authorization request timestamp data group of the electronic seal user according to the predefined time distribution arrangement rule to obtain the weight factors corresponding to different time periods in the historical authorization request timestamp data group of the electronic seal user. For example, if the proportion of the number of times of the historical authorization request of the electronic seal user in the one-hour period from 18:00 to 19:00 in 24 hours to the total number of times is 20%, then the weight of the one-hour period from 18:00 to 19:00 is set to 0.2.
[0055] Number the historical authorization request times of the electronic seal user under the predefined electronic seal authorization time period one by one, C 0 Indicates the serial number of the historical authorization request times, and C represents the total number of historical authorization request times.
[0056] Indicates the weight factor corresponding to the C 0 th historical authorization request time under the Y 0 th predefined electronic seal authorization time period in the historical authorization request timestamp data group of the electronic seal user.
[0057] Indicates the dynamic IP change anomaly indication correction factor for the Y 0 th predefined electronic seal authorization time period.
[0058] Furthermore, the specific method for obtaining the dynamic IP change anomaly indication correction factor is as follows: Merge the different dynamic IP addresses used by the electronic seal user to send remote authorization requests for the electronic seal through the electronic seal user terminal and denote it as the set of dynamic IP addresses for remote authorization requests of the electronic seal; Denote the different dynamic IP addresses used by the electronic seal user to send the latest remote authorization request for the electronic seal through the electronic seal user terminal as the current dynamic IP address of the electronic seal user terminal; Compare and analyze the current dynamic IP address of the electronic seal user terminal with the set of dynamic IP addresses for remote authorization requests of the electronic seal to obtain the dynamic IP change anomaly indication correction value under the predefined electronic seal authorization time period; Extract the total number of types of dynamic IP addresses of the electronic seal user terminal under the predefined electronic seal authorization time period; Thus, analyze and obtain the dynamic IP change anomaly indication correction factor.
[0059] In this embodiment, the dynamic IP change anomaly indication correction factor is used to describe the relative indication level of the dynamic IP change anomaly of the electronic seal user's terminal within the predefined electronic seal authorization time period.
[0060] The specific method for obtaining the dynamic IP change anomaly indication correction factor is as follows:
[0061]
[0062] If B ∈ G, then
[0063] If Then
[0064] The dynamic IP address of the electronic seal user's terminal can be assigned by the Internet service provider. For example, the Internet service provider usually has an IP address pool. When the electronic seal user's terminal connects to the network, the Internet service provider assigns an IP address from the IP address pool to the device; or, when the electronic seal user's terminal accesses the network through the network access server, the network access server assigns a dynamic IP address for the user from the IP address pool of the Internet service provider.
[0065] However, if the dynamic IP address of the electronic seal user's terminal changes within a short period of time, it may be under a network attack. For example, an attacker may try to hijack the network connection through a man-in-the-middle attack, which may cause the dynamic IP address to change frequently; the attacker may use IP spoofing technology, making the victim's network traffic appear to be sent from different dynamic IP addresses, which will also cause the dynamic IP address to change frequently; if the attacker obtains the account credentials of the electronic seal user, they may log in to the account on different devices, resulting in a change in the dynamic IP address.
[0066] Merge the different dynamic IP addresses of the electronic seal remote authorization request sent by the electronic seal user through the electronic seal user's terminal and record them as the electronic seal remote authorization request dynamic IP address set, and G represents the electronic seal remote authorization request dynamic IP address set.
[0067] Record the different dynamic IP addresses of the latest electronic seal remote authorization request sent by the electronic seal user through the electronic seal user's terminal as the current dynamic IP address of the electronic seal user's terminal, and B represents the current dynamic IP address of the electronic seal user's terminal.
[0068] Denote the Yth 0The total number of types of dynamic IP addresses of the electronic seal user terminal under a predefined electronic seal authorization time period. For example, if the total number of types of dynamic IP addresses of the electronic seal user terminal under a predefined electronic seal authorization time period is 1, it indicates that the dynamic IP address of the electronic seal user terminal under the predefined electronic seal authorization time period has no change and is very stable. On the contrary, the more types there are, the greater the change.
[0069] Indicates the Yth 0 Dynamic IP change anomaly indication correction value under a predefined electronic seal authorization time period.
[0070] Indicates the Yth 0 Electronic seal remote authorization request frequency under a predefined electronic seal authorization time period.
[0071] Obtain geographical location information:
[0072] Use IP geolocation services (such as MaxMind GeoIP, IP2Location, etc.) to obtain the geographical location information corresponding to the dynamic IP.
[0073] Through the geographical location information of the electronic seal user terminal, such as GPS data.
[0074] Distance calculation: Calculate the straight-line distance or road network distance between the IP geographical location and the user-reported geographical location, denoted as the geographical location difference distance value, with the unit of meters.
[0075] Indicates the Yth 0 Geographical location difference distance value under a predefined electronic seal authorization time period.
[0076] DL AVG Indicates the average of the historical geographical location difference distance averages, extracted from the central service manager.
[0077] Further, determine whether to accept the remote authorization request of the electronic seal user according to the abnormal indication value of the electronic seal user's authorization behavior, which specifically includes: recording the maximum value of the abnormal indication value of the electronic seal user's authorization behavior under different predefined electronic seal authorization time periods as the maximum abnormal indication value of the electronic seal user's authorization behavior; comparing and analyzing the maximum abnormal indication value of the electronic seal user's authorization behavior with the first threshold of the preset abnormal electronic seal user's authorization behavior, and recording the difference between the two as the abnormal indication value of the electronic seal user's authorization behavior; if the abnormal indication value of the electronic seal user's authorization behavior is greater than or equal to the first threshold of the abnormal indication of the electronic seal user's authorization behavior, do not accept the remote authorization request of the electronic seal user and send it to the central service manager, and notify the relevant personnel to contact the electronic seal user; if the abnormal indication value of the electronic seal user's authorization behavior is less than the first threshold of the abnormal indication of the electronic seal user's authorization behavior and greater than or equal to the second threshold of the abnormal indication of the electronic seal user's authorization behavior, do not accept the remote authorization request of the electronic seal user, list the electronic seal user as an electronic seal user to be evaluated and send it to the central service manager, and notify the relevant personnel to send a message to the electronic seal user through the central service manager, and the message is used to notify the electronic seal user to send a remote authorization request for the electronic seal again; if the abnormal indication value of the electronic seal user's authorization behavior is less than the second threshold of the abnormal indication of the electronic seal user's authorization behavior, accept the remote authorization request of the electronic seal user.
[0078] In this embodiment, if the abnormal indication value of the electronic seal user's authorization behavior is greater than or equal to the first threshold of the abnormal indication of the electronic seal user's authorization behavior, it indicates that the degree of the previous abnormal behavior of the electronic seal user is relatively high, which may involve an increase in the degree of abnormal behavior caused by a network attack. It is necessary to notify the relevant personnel to contact the electronic seal user for manual service confirmation, and after the manual service, the relevant personnel can manually modify the historical electronic seal user authorization behavior information data of the electronic seal user. At the same time, considering that in actual situations, there may be multiple electronic seal user terminals for an electronic seal user, or there may be multiple electronic seal users with the same permissions on one electronic seal user terminal, or the electronic seal user travels frequently, resulting in a relatively prominent change in the location of the electronic seal user terminal that issues the remote authorization request for the electronic seal. These actual situations will cause the electronic seal user to send a remote authorization request for the electronic seal normally, but it is easily misjudged and cannot be authorized normally, seriously slowing down the existing software automation processing efficiency. Therefore, a second threshold for the abnormal indication of the electronic seal user's authorization behavior is set. If the electronic seal user is judged as an electronic seal user to be evaluated, further judgment will be made.
[0079] Further, perform abnormal analysis on the electronic seal user to be evaluated, specifically including: performing route tracing analysis on the electronic seal user terminal of the electronic seal user to be evaluated through a computer network diagnostic tool to obtain the end IP of the network node to be evaluated, comparing and analyzing the end IP of the network node to be evaluated with the machine IP of the electronic seal user terminal. If they are the same, notify relevant personnel to receive and handle the business of the electronic seal remote authorization request reissued by the electronic seal user online. If they are different, perform network fluctuation analysis on the electronic seal user to be evaluated.
[0080] In this embodiment, the computer network diagnostic tool can specifically be traceroute (route tracing). When the source host A (electronic seal user terminal) sends a message to the target host B (central service manager) and finds that the message cannot be delivered. At this time, there may be a problem with a certain intermediate node. For example, the router drops packets due to high load. At this time, preliminary detection can be performed through traceroute to locate at which node the network packet is lost; if when the source host A (electronic seal user terminal) sends a message to the target host B (central service manager) and the message can be delivered normally, the central service manager can obtain the IP location of the source host A (electronic seal user terminal) through traceroute. If the obtained IP location of the source host A (electronic seal user terminal) is the same as the actual IP location of the source host A (electronic seal user terminal), it indicates that the network path is normal. Otherwise, it indicates that the network path is abnormal and there may be excessive volatility or network congestion.
[0081] Further, perform network fluctuation analysis on the electronic seal user to be evaluated, specifically including: obtaining the maximum value of the abnormal indication of the electronic seal user authorization behavior of the electronic seal user to be evaluated; obtaining the number of times of network connection interruption of the electronic seal remote authorization request by checking the access log on the server side; setting a filter according to the specific port number of the electronic seal user terminal, and capturing the data packets of the electronic seal user terminal through a network monitoring tool and the filter to obtain the loss rate parameter of the data packets of the electronic seal remote authorization request; directly obtaining the number of hops of the network path for the transmission of the data packets of the electronic seal remote authorization request through a network diagnostic tool; comprehensively analyzing the above parameters to obtain the abnormal factor of network fluctuation analysis.
[0082] In this embodiment, the method for specifically obtaining the abnormal factor of network fluctuation analysis by performing network fluctuation analysis on the electronic seal user to be evaluated is as follows; δ MAX represents the maximum value of the abnormal indication of the electronic seal user authorization behavior.
[0083]
[0084] ω represents the abnormal factor of network fluctuation analysis.
[0085] The current network fluctuation analysis time period for network fluctuation analysis is segmented and numbered according to a predefined network fluctuation analysis time period to obtain a number of network fluctuation analysis time periods, D 0 represents the number of the network fluctuation analysis time period, and D represents the total number of network fluctuation analysis time periods.
[0086] represents the maximum packet loss rate of the electronic seal remote authorization request packet for the D 0 -th network fluctuation analysis time period;
[0087] represents the minimum packet loss rate of the electronic seal remote authorization request packet for the D 0 -th network fluctuation analysis time period;
[0088] represents the average packet loss rate of the electronic seal remote authorization request packet for the D 0 -th network fluctuation analysis time period;
[0089] represents the number of times of network connection interruption of the electronic seal remote authorization request packet for the D 0 -th network fluctuation analysis time period;
[0090] By checking the access logs on the server side, the detailed information of each request is recorded, including success, failure, and network errors, etc. By analyzing the error codes in the logs, such as TCP / IP connection errors, timeouts, etc., the number of network connection interruptions can be counted;
[0091] TS represents the number of hops of the network path for the transmission of the electronic seal remote authorization request packet. The number of hops refers to the number of network devices that the packet must pass through before reaching the destination. Each hop usually represents the process of the packet being transmitted from one network device to another; the more hops, the longer the time usually required for the packet to reach the destination, which may lead to higher latency.
[0092] Use a network diagnostic tool (Traceroute, Tracert in the Windows system), which can trace the path of the packet from the source host to the target host and can be used to obtain the number of hops of the network path for the packet transmission.
[0093] μ 1 represents the preset weight factor of the packet loss rate for the network fluctuation analysis anomaly factor;
[0094] μ 2 represents the preset weight factor of the number of hops of the network path for the packet transmission for the network fluctuation analysis anomaly factor;
[0095] The preset weight factor of the packet loss rate for the abnormal factor of network fluctuation analysis and the preset weight factor of the number of hops of the network path for packet transmission for the abnormal factor of network fluctuation analysis respectively represent the numerical values of the influence degree of the total packet transmission duration on the packet loss rate and the number of hops of the network path for packet transmission on the abnormal factor of network fluctuation analysis.
[0096] The preset weight factor of the abnormal factor of network fluctuation analysis and the preset weight factor of the number of hops of the network path for packet transmission for the abnormal factor of network fluctuation analysis can be directly obtained from the central service manager through a preset mapping relationship. For example, construct a mapping set of the real-time total packet transmission duration and its corresponding preset weight factor of the packet loss rate for the abnormal factor of network fluctuation analysis and the real-time total packet transmission duration and its corresponding preset weight factor of the number of hops of the network path for packet transmission for the abnormal factor of network fluctuation analysis, and input the real-time total packet transmission duration into the mapping set to obtain the preset weight factor of the packet loss rate for the abnormal factor of network fluctuation analysis and the preset weight factor of the number of hops of the network path for packet transmission for the abnormal factor of network fluctuation analysis, where the mapping relationship can be one-to-one or many-to-one.
[0097] Furthermore, if the abnormal factor of network fluctuation analysis of the electronic seal user to be evaluated is greater than or equal to the network fluctuation analysis abnormal threshold, relevant personnel are notified to receive and handle online the business of the electronic seal remote authorization request reissued by the electronic seal user.
[0098] In this embodiment, if the abnormal factor of network fluctuation analysis of the electronic seal user to be evaluated is greater than or equal to the network fluctuation analysis abnormal threshold, it indicates that the current network environment of the electronic seal user is unstable or there is network congestion, resulting in abnormal evaluation of the electronic seal user authorization of the electronic seal user, but further evaluation and analysis are required.
[0099] Furthermore, the judgment and adjustment of the authorization of the electronic seal user to be evaluated also include: if the abnormal factor of network fluctuation analysis is less than the network fluctuation analysis abnormal threshold, the electronic seal remote authorization request reissued by the electronic seal user is rejected, and relevant personnel are notified to manually review online the historical electronic seal user authorization behavior information data of the electronic seal user.
[0100] In this embodiment, if the abnormal factor of network fluctuation analysis of the electronic seal user to be evaluated is less than or equal to the network fluctuation analysis abnormal threshold, it indicates that the current network environment of the electronic seal user is stable, or the network is unobstructed, resulting in normal evaluation of the electronic seal user authorization of the electronic seal user. However, due to the relatively high degree of past abnormal behavior of the electronic seal user to be evaluated, authorization is not allowed, and at the same time, relevant personnel need to manually review the historical data of the electronic seal user.
[0101] Further, for the judgment and adjustment of the authorization of the electronic seal user to be evaluated, it further includes: after a predefined repeated evaluation time, the abnormal factor of the network fluctuation analysis of the first-level electronic seal user to be evaluated is evaluated again, denoted as the repeated value of the abnormal factor of the network fluctuation analysis. If the repeated value of the abnormal factor of the network fluctuation analysis is greater than or equal to the abnormal threshold of the network fluctuation analysis, relevant personnel are notified to manually check online through a network monitoring tool whether the network path of the data packet transmission of the electronic seal remote authorization request of the electronic seal user is under a network attack. If so, relevant personnel are notified to start a network attack emergency plan through the central service manager. If not, the electronic seal user is notified to adjust the network environment where the electronic seal user terminal is located and resend the business of the electronic seal remote authorization request, and relevant personnel are notified to receive and process the business of the resubmitted electronic seal remote authorization request of the electronic seal user online.
[0102] In this embodiment, if the network fluctuation is still abnormal after the predefined repeated evaluation time, it indicates that a network attack may have occurred, and a network monitoring tool needs to be called. For example, Wireshark: capture and analyze data packets to check for abnormal traffic patterns or destinations. If it is a network attack, call the network attack emergency plan. If not, notify the electronic seal user to adjust the network environment where the electronic seal user terminal is located.
[0103] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0104] The present invention is described with reference to the flowcharts and / or block diagrams of systems, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0105] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the function specified in one or more of the processes and / or blocks Figure 1 in the process or processes and / or blocks Figure 1 specified in the block or blocks.
[0106] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the function specified in one or more of the processes and / or blocks Figure 1 in the process or processes and / or blocks Figure 1 specified in the block or blocks.
[0107] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.
[0108] It is obvious that those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An electronic seal public service management system, characterized in that: It includes an electronic seal user terminal, a central service manager, a first evaluation and analysis module for electronic seal user authorization behavior information, a second evaluation and analysis module for electronic seal user authorization behavior information, and an electronic seal user authorization adjustment module; Wherein, the electronic seal user terminal is used to send the electronic seal user's electronic seal remote authorization request; The central service manager is used to receive the electronic seal remote authorization request of the electronic seal user, perform the electronic seal identity authority authentication, and send the electronic seal identity authority authentication result to the electronic seal user terminal; The electronic seal user authorization behavior information first evaluation and analysis module is used to obtain historical electronic seal user authorization behavior information data, perform electronic seal user authorization behavior abnormality analysis, and obtain an electronic seal user authorization behavior abnormality indication value; The second evaluation and analysis module of the electronic seal user authorization behavior information is used to judge whether to accept the electronic seal user's electronic seal remote authorization request according to the electronic seal user authorization behavior abnormality indication value, and send the judgment result to the central service manager. If accepted, the relevant personnel are notified through the central service manager. If not accepted, the abnormal analysis of the electronic seal user to be evaluated is performed; The electronic seal user authorization adjustment module is used to judge and adjust the authorization of the electronic seal user to be evaluated according to the abnormal analysis result of the electronic seal user to be evaluated; The specific process of analyzing the abnormal authorization behavior of electronic seal users is as follows: The electronic seal user authorization behavior information first evaluation and analysis module includes an electronic seal user authorization behavior information acquisition unit and a historical electronic seal user authorization behavior information processing unit; The electronic seal user authorization behavior information acquisition unit is used to extract the historical electronic seal user authorization behavior information data of the electronic seal user in the central service manager; The historical electronic seal user authorization behavior information processing unit is used to divide the historical electronic seal user authorization behavior information data according to the predefined electronic seal authorization time period, obtain the historical electronic seal user authorization behavior information data under different predefined electronic seal authorization time periods, and extract the data set of the machine IP address of the electronic seal user terminal received by the central service manager under the predefined electronic seal authorization time period and the total historical data set of the machine IP address of the electronic seal user terminal; If the data set of the machine IP address of the electronic seal user terminal received by the central service manager within the predefined electronic seal authorization time period belongs to the total historical data set of the machine IP address of the electronic seal user terminal, then the number of historical authorization requests within the predefined electronic seal authorization time period is analyzed to obtain the electronic seal remote authorization request indication value, and combined with the dynamic IP change abnormal indication correction factor, the electronic seal user authorization behavior abnormal indication value is analyzed to obtain.
2. The electronic seal public service management system as claimed in claim 1, characterized in that: The specific process of electronic seal identity authentication is as follows: The central service manager includes a central service manager receiving unit, a central service manager matching verification unit and a central service manager matching sending unit; The central service manager receiving unit is used to receive an electronic seal remote authorization request from an electronic seal user; The matching verification unit of the central service manager is used to review the historical electronic seal authorization associated data of the electronic seal user according to the historical electronic seal authorization associated data of the electronic seal user through the predefined electronic seal user authorization review rules and determine whether the electronic seal user identity is successfully verified according to the review result; The central service manager matching and sending unit is used to determine whether to extract historical electronic seal user authorization behavior information data based on the electronic seal user identity authentication result. If the electronic seal user identity authentication is successful, the historical electronic seal user authorization behavior information data is extracted and the information of successful electronic seal user identity authentication is sent to the electronic seal user terminal. If the electronic seal user identity authentication is unsuccessful, the historical electronic seal user authorization behavior information data is not extracted and the information of failed electronic seal user identity authentication is sent to the electronic seal user terminal.
3. The electronic seal public service management system as claimed in claim 1, characterized in that: The method for obtaining the dynamic IP change abnormal indication correction factor is: The different dynamic IP addresses of the electronic seal user sending the electronic seal remote authorization request through the electronic seal user terminal are combined and recorded as the electronic seal remote authorization request dynamic IP address set; Record the latest different dynamic IP address of the electronic seal user sending the electronic seal remote authorization request through the electronic seal user terminal as the current dynamic IP address of the electronic seal user terminal; Compare and analyze the current dynamic IP address of the electronic seal user terminal with the dynamic IP address set of the electronic seal remote authorization request to obtain the dynamic IP change abnormal indication correction value in the predefined electronic seal authorization time period; Extracting the total number of types of dynamic IP addresses of electronic seal user terminals within a predefined electronic seal authorization time period; The dynamic IP change abnormal indication correction factor is obtained through this analysis.
4. The electronic seal public service management system as claimed in claim 1, characterized in that: The step of judging whether to accept the electronic seal remote authorization request of the electronic seal user according to the abnormal authorization behavior indication value of the electronic seal user specifically includes: The maximum value of the electronic seal user authorization behavior abnormality mark value in different predefined electronic seal authorization time periods is recorded as the maximum value of the electronic seal user authorization behavior abnormality mark value; Compare and analyze the maximum value of the abnormal indication of the electronic seal user's authorization behavior with the preset first threshold value of the abnormal electronic seal user's authorization behavior, and record the difference between the two as the abnormal indication value of the electronic seal user's authorization behavior; If the electronic seal user authorization behavior abnormality indication value is greater than or equal to the electronic seal user authorization behavior abnormality indication first threshold value, the electronic seal user's electronic seal remote authorization request is not accepted and sent to the central service manager, and the relevant personnel are notified to contact the electronic seal user; If the electronic seal user authorization behavior abnormality indication value is less than the electronic seal user authorization behavior abnormality indication first threshold value and is greater than or equal to the electronic seal user authorization behavior abnormality indication second threshold value, the electronic seal user's electronic seal remote authorization request is not accepted, and the electronic seal user is listed as an electronic seal user to be evaluated and sent to the central service manager, and the central service manager notifies relevant personnel to send a message to the electronic seal user, and the message is used to notify the electronic seal user to send an electronic seal remote authorization request again; If the electronic seal user's authorization behavior abnormality indication value is less than the electronic seal user's authorization behavior abnormality indication second threshold value, the electronic seal user's electronic seal remote authorization request is accepted.
5. The electronic seal public service management system as claimed in claim 1, characterized in that: The abnormal analysis of the electronic seal user to be evaluated specifically includes: Through computer network diagnostic tools, the electronic seal user terminal of the electronic seal user to be evaluated is subjected to route tracing analysis to obtain the endpoint IP of the network node to be evaluated, and the endpoint IP of the network node to be evaluated is compared and analyzed with the machine IP of the electronic seal user terminal. If they are the same, the relevant personnel are notified to receive and handle the electronic seal remote authorization request issued again by the electronic seal user online. If they are not the same, a network fluctuation analysis is performed on the electronic seal user to be evaluated.
6. The electronic seal public service management system as claimed in claim 5, characterized in that: The network fluctuation analysis of the electronic seal user to be evaluated specifically includes: Obtain the maximum value of the abnormal mark of the electronic seal user authorization behavior of the electronic seal user to be evaluated; By checking the access log on the server side, obtain the number of network connection interruptions for electronic seal remote authorization requests; A filter is set according to the port number of the electronic seal user terminal, and the data packet of the electronic seal user terminal is captured through the network monitoring tool and the filter to obtain the loss rate parameter of the data packet of the electronic seal remote authorization request; Directly obtain the number of hops of the network path for data packet transmission of the electronic seal remote authorization request through the network diagnostic tool; By comprehensively analyzing the above parameters, the network fluctuation analysis anomaly factor of the electronic seal user to be evaluated is obtained.
7. The electronic seal public service management system as claimed in claim 6, characterized in that: The judgment and adjustment of the authorization of the electronic seal user to be evaluated specifically includes: If the network fluctuation analysis anomaly factor of the electronic seal user to be evaluated is greater than or equal to the network fluctuation analysis anomaly threshold, the electronic seal user to be evaluated is recorded as a first-level electronic seal user to be evaluated.
8. The electronic seal public service management system as claimed in claim 6, characterized in that: The judgment and adjustment of the authorization of the electronic seal user to be evaluated also includes: If the network fluctuation analysis anomaly factor is less than the network fluctuation analysis anomaly threshold, the electronic seal user's re-issued electronic seal remote authorization request will be rejected, and relevant personnel will be notified to manually review the electronic seal user's historical electronic seal user authorization behavior information data online.
9. The electronic seal public service management system as claimed in claim 7, characterized in that: The judgment and adjustment of the authorization of the electronic seal user to be evaluated also includes: After the predefined repeated evaluation time, the network fluctuation analysis anomaly factor of the first-level electronic seal user to be evaluated is evaluated again, recorded as the network fluctuation analysis anomaly factor repeated value. If the network fluctuation analysis anomaly factor repeated value is greater than or equal to the network fluctuation analysis anomaly threshold; Then notify relevant personnel to manually check online through network monitoring tools whether the network path of the data packet transmission of the electronic seal user's electronic seal remote authorization request has been attacked by the network; If so, notify relevant personnel to initiate the network attack emergency plan through the central service manager; If not, the electronic seal user is notified to adjust the network environment where the electronic seal user terminal is located and re-issue the electronic seal remote authorization request, and the relevant personnel are notified to receive and handle the electronic seal remote authorization request re-issued by the electronic seal user online.
Citation Information
Patent Citations
Electronic seal authorization method, system, electronic device and storage medium
CN113591155B
A Smart Management Method for Electronic Seal Authorization
CN117056913B
Remote authorization seal intelligent management system
CN112959833A
Electronic seal system accessed to digital mailbox and method for accessing digital mailbox
CN118300807A