Data Intelligent Security Protection Method and System for Computer Terminal Data Interaction

Through security assessment, synthesis conversion, user portrait and encryption processing of computer terminal data interaction, data security and permission control issues are solved, and efficient data protection and access management are achieved.

CN119622714BActive Publication Date: 2025-07-11DONGYING DONGWANG INTERNET INFORMATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411580275.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-07
Publication Date
2025-07-11
Estimated Expiration
2044-11-07

AI Technical Summary

Technical Problem

The prior art has insufficient data security, integrity and availability protection in computer terminal data interaction, unreasonable user permission settings, and low encryption technology, making it difficult to deal with the security risks of complex network topology and diversified data types.

Method used

By collecting data on computer terminal data interaction scenarios, performing security risk assessment and synthesis conversion, encrypting processing, building user portraits, finely dividing access rights, formulating backup plans, and deploying security audit systems, combining generation adversarial networks and quantum encryption algorithms for data protection.

Benefits of technology

It improves the security and availability of data interaction, enhances encryption complexity, precise control of access rights, dynamically adapts to changes in the network environment, and provides effective security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622714B_ABST
    Figure CN119622714B_ABST
Patent Text Reader

Abstract

The present invention discloses a data intelligent security protection method and system for computer terminal data interaction, which relates to the field of network security technology. The method includes the following steps: S1: Collect scene data, perform preprocessing, and conduct security risk assessment; S2: Perform data synthesis conversion and encryption processing on the interaction data; S3: Construct a user profile and establish an intelligent identity authentication mechanism; S4: Divide data access permissions according to user roles and responsibilities; S5: Develop a data backup plan; S6: Deploy a security audit system. By conducting a preliminary security assessment on the interaction scenario, the present invention can detect potential security risks in the process of terminal data interaction; by performing synthesis conversion on the interaction data and then encrypting the data, it can confuse the characteristics of the original data, increase the complexity of encryption, and facilitate the unified management and transmission of data; in addition, by deeply understanding user behavior based on the user profile, it can more accurately set access control permissions, reduce false alarms and interference.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a data intelligent security protection method and system for data interaction of computer terminals. Background Art

[0002] With the development of computer networks, the network topology has become increasingly complex. From traditional local area networks (LANs) to wide area networks (WANs), to today's cloud computing environments and the Internet of Things (IoT), terminal devices may be connected to various different network environments. For example, office terminals within an enterprise may be connected to enterprise servers through a local area network, while at the same time being connected to external cloud service providers through the Internet. Such a complex network topology increases the paths of data interaction and potential security risk points.

[0003] Attackers are constantly developing new attack methods to obtain terminal data. Common attack methods include malware (such as viruses, Trojans, ransomware, etc.), phishing, distributed denial of service attacks (DDoS), man-in-the-middle attacks, etc. For example, malware can be installed on terminal devices and steal data by disguising itself as a legitimate software program or file; phishing obtains data by tricking users into entering sensitive information.

[0004] In today's era, the speed of data generation and accumulation is extremely fast, and the amount of data on terminal devices is also constantly increasing. And a large amount of data increases the frequency and complexity of data interaction, and also poses higher requirements for data security protection. Moreover, in addition to traditional text data, various types of data may exist on terminal devices, such as audio, video, images, sensor data, etc. Different types of data have different characteristics and security requirements.

[0005] The operation behaviors of users on computer terminals are complex and diverse. Users may install various unauthorized software, access insecure websites, click on suspicious links, etc. For example, some users may download software from unofficial channels in order to obtain the functions of certain applications, and these software may contain malicious code, resulting in the risk of data leakage.

[0006] The security awareness levels of different users vary widely. Some users may have a high level of security awareness, follow security operation procedures, and update software and passwords regularly, etc.; while some other users may not pay enough attention to security issues and are easily targeted by attackers. For example, some users may use simple passwords or use the same password for multiple accounts, increasing the risk of account theft.

[0007] Although traditional encryption technologies (such as symmetric encryption and asymmetric encryption) play an important role in protecting data, they also have some limitations. For example, symmetric encryption requires the sharing of keys, and key management is complex; asymmetric encryption has a relatively high computational complexity and low efficiency when dealing with a large amount of data. Moreover, encryption technologies can only protect the confidentiality of data during transmission and storage, and the protection of data integrity and availability is relatively weak. Existing access control technologies with unclear role definitions or unreasonable permission settings may also have vulnerabilities, which can easily lead to users accessing resources that they should not access.

[0008] To solve the above problems, the present invention proposes a data intelligent security protection method and system for computer terminal data interaction. Summary of the Invention

[0009] The main purpose of the present invention is to provide a data intelligent security protection method and system for computer terminal data interaction, which can effectively solve the problems in the background technology.

[0010] To achieve the above purpose, the present invention adopts the following technical solutions:

[0011] A data intelligent security protection method for computer terminal data interaction includes the following steps:

[0012] S1: Collect computer terminal data interaction scenario data and perform preprocessing, count risk influencing factors, conduct a security risk assessment on the computer terminal data interaction scenario, and make corresponding data intelligent security protection plans based on this;

[0013] S2: Perform data synthesis conversion on the computer terminal interaction data, and then encrypt the synthesized and converted computer terminal interaction data based on a data encryption algorithm;

[0014] S3: Construct a user profile and establish an intelligent identity authentication mechanism based on the user profile;

[0015] S4: According to the user roles and responsibilities, finely divide data access permissions, classify and label the data, and set corresponding access policies according to the data sensitivity level;

[0016] S5: Develop a data backup plan, regularly back up the data to a storage medium, and test the integrity and recoverability of the backup data;

[0017] S6: Deploy a security audit system, record various information data, simultaneously monitor the activities and running conditions of the computer terminal in real time, and establish a security alarm mechanism for risk alarm.

[0018] Preferably, in the step S1, six influencing factors, namely exposure rate, severity, controllability, complexity, timeliness, and value, are divided according to the data interaction scenario data of the computer terminal, and the security risk level of the interaction scenario of the computer terminal is divided based on these factors.

[0019] Preferably, in the step S2, the data synthesis and conversion are based on an improved variational autoencoder for data synthesis and conversion, specifically as follows:

[0020] The variational autoencoder based on vector quantization pre-trained on a large-scale dataset is used to process the input computer terminal interaction data X0:

[0021] The input data X0 passes through the encoder to obtain the feature JQ, specifically as follows:

[0022] Unsupervised coding is implemented based on an artificial neural network:

[0023]

[0024] Among them, h y1 is the output of the encoder; jh1 is the activation function; and are the weights and thresholds of the neurons during the encoding process;

[0025] According to the codebook KV, the feature closest to each feature in JQ is found and replaced one by one to obtain the quantization feature Q,

[0026]

[0027] Among them, i is the i-th input data, and a kv is the reference feature in the codebook;

[0028] The quantization feature Q is used as the input x0 of the diffusion model. During the forward diffusion process, Gaussian noise is gradually added to x0; for each time step t, the computer terminal interaction synthesis data x after adding noise is calculated according to the following formula t ;

[0029]

[0030] δ t = 1 - λ t ;

[0031]

[0032] Among them, σ t is the noise obeying the Gaussian distribution σ t ~N(0, I); δ t is a variable; is the cumulative product value of the variable δ t ; λt (λ t ∈(0,1)) is the noise time variation table;

[0033] During the reverse denoising process, a noise prediction network ξ θ is trained to predict noise, and its loss function L is defined as follows:

[0034]

[0035] where E(·) is the expectation; t is the time step not greater than T; is a random initial sample that satisfies a specific distribution ; is the data with noise added at the t-th time step; ξ is the noise, following the Gaussian distribution N(0, I); is the noise prediction network ξ θ For the input and the predicted noise at time step t;

[0036] The Gaussian noise is gradually removed through the following formula:

[0037]

[0038] where β follows the Gaussian distribution;

[0039] x0 is gradually constructed through the above steps; the quantized features Q are obtained by quantizing the features obtained after denoising, and then the features are replaced according to the codebook KV, and the following decoder is trained based on the artificial neural network:

[0040]

[0041] where h y2 is the decoder output; jh2 is the activation function; X' is the data to be decoded input to the decoder; and are the weights and thresholds of the neurons during the decoding process;

[0042] Finally, the quantized features Q are transformed into the input data X0;

[0043] The computer terminal interaction data is also trained based on the generative adversarial network, where the generator G takes the input data X0 restored by the decoder or other random noise as input and generates new data;

[0044] The loss function L of the generator G is defined as follows:

[0045]

[0046] where MSE(·) is the mean square error; G(η) is the generated data; y is the real data;

[0047] Then, based on the discriminator, comprehensively discriminate the data generated by the generator;

[0048] The loss function L of the discriminator D is expressed as:

[0049]

[0050] where D(y') is the discrimination result of the discriminator for the input data y'; D(G(η)) is the discrimination result of the discriminator for the generated data G(η);

[0051] During the training process, alternately train the generator and the discriminator;

[0052] Then, based on the quicksort algorithm, select the pivot element z, divide the synthesized array into two parts, recursively perform the quicksort operation on these two parts based on the quicksort algorithm, integrate the pivot element into the encryption key, and perform the encryption operation on the sorted data based on the quantum encryption algorithm.

[0053] Preferably, in the S2, a key storage method of regularly changing the key is also adopted.

[0054] Preferably, in the S3, based on the improved clustering algorithm, collect and identify the multi-dimensional user behavior data, and construct a dynamic user portrait, specifically as follows:

[0055] Collect and preprocess the user behavior data and the computer terminal interaction scenario data; first, perform data dimensionality reduction through several discrete wavelet transforms, where the discrete wavelet transform dynamically adjusts the resolution according to the data distribution; after the gl-th wavelet transform is completed, the data is converted into low-frequency components and high-frequency components; among them, the low-frequency components continue to participate in the next round of discrete wavelet transforms until the specified GL times of discrete wavelet transforms are completed; after several transforms, start clustering from the lowest-frequency component, and gradually iterate upward to cluster the components of higher frequencies:

[0056] Calculate the number of clusters of the initial clustering based on the following elbow method:

[0057]

[0058] where SSE is the sum of squared errors; jl k is the k-th clustering cluster; c k is the center of the k-th clustering cluster; s is the data point in the clustering cluster; ||·|| represents the Euclidean distance;

[0059] Based on the SSE values under different K values, find the elbow point of the corresponding SSE curve as the K value;

[0060] Randomly select K data points as the initial clustering centers;

[0061] For each data point, calculate its distances to each clustering center:

[0062]

[0063] where d0 (d0 ∈ [1, d]) is the dimension of the data point;

[0064] For each clustering cluster, update its clustering center based on the adaptive ant colony algorithm;

[0065] The specific adaptive ant colony algorithm is as follows:

[0066]

[0067] where, is the transition probability of each optional path from point u to point v; yp uv is the value of the pheromone concentration at point (u, v); π1 is the pheromone importance factor; π2 is the importance factor of the heuristic function; qf uv is the heuristic information value; ds1 is the distance from the starting point to the next point; ds2 is the distance from the next point to the target point; ω1 is the weight of ds1; ω2 is the weight of ds2; Θ is the turning coefficient; is the number of turns between the previous point and the next point; ω 2max and ω 2min are the maximum and minimum weights of ω2 respectively; k best is the optimal coefficient value;

[0068] The pheromone is updated as follows:

[0069] yp uv (τ + 1) = (1 - ρ)yp uv (τ) + Δyp uv (τ);

[0070]

[0071]

[0072] where τ is the number of iterations; ρ is the pheromone evaporation coefficient; ρ min is the minimum value of the pheromone evaporation coefficient; Δyp uv (τ) is the change value of yp uv (τ); kl is the ant; ζ is the pheromone carried by the ant; yp is the target value; yp min is the minimum target value;

[0073] Among the target value range, 16 points are selected as the next update points. According to the heuristic mechanism, the clustering error values corresponding to the update points are calculated, and the 3 points with the smallest clustering error values are selected as the target points for the next iterative update.

[0074] Based on the above adaptive genetic algorithm, the distance threshold for the next clustering is dynamically and adaptively searched and narrowed according to the distribution characteristics of the data.

[0075] When the computer terminal conducts data interaction, in addition to the conventional authentication method, the matching degree between the current interaction scenario and the user portrait is automatically analyzed. If the matching degree is lower than the preset matching degree threshold, additional authentication links are added or the continued data interaction is restricted.

[0076] Preferably, in S3, a single sign-on method is also implemented, and the user permissions are regularly audited.

[0077] Preferably, in S4, a smart contract for regulating data interaction behaviors and rules is set up. When a contract rule-violating interaction behavior occurs, the protection mechanism is automatically triggered to block the data interaction and record the violation information.

[0078] Preferably, in S5, a disaster recovery plan for dealing with emergencies is also formulated.

[0079] Preferably, in S6, the data intelligent security protection measures are also regularly evaluated and reviewed.

[0080] A fault detection system based on a mobile communication network, comprising:

[0081] A data collection and evaluation module: used for collecting data interaction scenario data of the computer terminal and conducting security risk assessment, and accordingly formulating a corresponding data intelligent security protection plan;

[0082] A data encryption module: used for performing data synthesis conversion on the computer terminal interaction data, and then encrypting the synthesized and converted computer terminal interaction data based on a data encryption algorithm;

[0083] An identity authentication module: used for constructing a user portrait and establishing an intelligent identity authentication mechanism according to the user portrait;

[0084] An access division module: used for finely dividing data access permissions according to the user roles and responsibilities, classifying and marking the data, and setting corresponding access policies according to the data sensitivity level;

[0085] A data backup module: used for formulating a data backup plan, regularly backing up the data to a storage medium, and testing the integrity and recoverability of the backup data;

[0086] Security Audit Module: It is used to conduct security audits, record various information and data, monitor the activities and operation status of computer terminals in real time, and establish a security alarm mechanism for risk alarms;

[0087] The acquisition and evaluation module includes an acquisition processing unit and a risk assessment unit;

[0088] The acquisition processing unit is used to acquire computer terminal data interaction scenario data and perform preprocessing;

[0089] The risk assessment unit is used to count risk influencing factors, conduct security risk assessment on computer terminal data interaction scenarios, and make corresponding data intelligent security protection plans based on this;

[0090] The data encryption module includes a data synthesis unit and a sorting and encryption unit;

[0091] The data synthesis unit is used to perform data synthesis conversion on computer terminal interaction data;

[0092] The sorting and encryption unit is used to perform fast sorting on the computer terminal interaction data after synthesis conversion based on a data encryption algorithm, and then perform encryption processing.

[0093] Compared with the prior art, the present invention provides a data intelligent security protection method and system for computer terminal data interaction, having the following beneficial effects:

[0094] Through the preliminary security assessment of the computer terminal interaction scenario, the present invention can detect potential security risks in the terminal data interaction process; after performing synthesis conversion on the interaction data and then further data encryption processing, it can confuse the original data characteristics, increase the complexity of encryption, and at the same time increase the availability and applicability of the data, facilitating the unified management and transmission of data; it also deeply understands user behavior based on the user portrait method, can set access control permissions more precisely, reduce false alarms and interference; and can also adapt dynamically with the change of the network environment to provide effective security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0095] Figure 1 It is the method flow chart mentioned in Embodiment 1 of the present invention;

[0096] Figure 2 It is the schematic diagram of the data synthesis process mentioned in Embodiment 1 of the present invention;

[0097] Figure 3 It is the schematic diagram of the improved clustering algorithm process mentioned in Embodiment 1 of the present invention;

[0098] Figure 4 It is the system block diagram mentioned in Embodiment 2 of the present invention.

[0099] In the figure:

[0100] 100, Acquisition and Evaluation Module; 110, Acquisition and Processing Unit; 120, Risk Assessment Unit; 200, Data Encryption Module; 210, Data Synthesis Unit; 220, Sorting and Encryption Unit; 300, Identity Authentication Module; 400, Access Division Module; 500, Data Backup Module; 600, Security Audit Module. Specific Embodiment

[0101] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0102] Embodiment 1:

[0103] Please refer to Figures 1-3 , the data intelligent security protection method for computer terminal data interaction of the present invention includes the following steps:

[0104] S1: Collect computer terminal data interaction scenario data and perform preprocessing, count risk influencing factors, and conduct a security risk assessment on the computer terminal data interaction scenario, and accordingly carry out corresponding data intelligent security protection planning; specifically as follows:

[0105] Comprehensively collect computer terminal data interaction scenario data, including but not limited to network connection types (such as wired, wireless), data transmission objects (internal systems, external partners, Internet users, etc.), and data sensitivity levels (such as personal privacy information, business secrets, ordinary business data, etc.).

[0106] Determine potential security risks based on six influencing factors: exposure rate, severity, controllability, complexity, timeliness, and value, such as network attacks, malware infections, data leaks, etc. Among them, the exposure rate is used to measure the possible frequency of failure time. In-depth analysis can also be carried out with the help of security assessment tools and professional security consulting services.

[0107] Different levels can be divided according to the influence degree of each influencing factor. For example:

[0108] The risk levels include unacceptable risks, major risks, relatively large risks, medium risks, and general risks;

[0109] The controllability includes completely out of control, difficult to control, generally controllable, simply controllable, and completely controllable;

[0110] The complexity includes high complexity, medium complexity, and low complexity;

[0111] Timeliness includes high timeliness, medium timeliness, and low timeliness;

[0112] Value includes high value, medium value, and low value;

[0113] Evaluate the data in the computer terminal data interaction scenario according to the above different influencing factors respectively, comprehensively judge the risk assessment results, and formulate a detailed data intelligent security protection plan based on this, clarifying the protection objectives, strategies, and specific implementation steps.

[0114] S2: Perform data synthesis conversion on the computer terminal interaction data, and then encrypt the synthesized and converted computer terminal interaction data based on the data encryption algorithm; specifically as follows:

[0115] Before encrypting the computer terminal interaction data, first perform data synthesis conversion. The method of performing encryption after data synthesis conversion can greatly improve the data encryption efficiency and better protect the security of the data.

[0116] The data synthesis conversion is based on an improved variational autoencoder for data synthesis conversion, specifically as follows:

[0117] Refer to Figure 2 , and use the variational autoencoder based on vector quantization pre-trained on a large-scale dataset to process the input computer terminal interaction data X0:

[0118] The input data X0 passes through the encoder to obtain the feature JQ, specifically as follows:

[0119] Implement unsupervised coding based on an artificial neural network:

[0120]

[0121] Among them, h y1 is the output of the encoder; jh1 is the activation function; and are the weights and thresholds of the neurons during the encoding process;

[0122] Find the feature closest to each feature in JQ according to the codebook KV and replace them one by one to obtain the quantized feature Q,

[0123]

[0124] Among them, i is the i-th input data, a kv is the reference feature in the codebook;

[0125] Use the quantized feature Q as the input x0 of the diffusion model. During the forward diffusion process, gradually add Gaussian noise to x0; for each time step t, calculate the computer terminal interaction synthetic data x after adding noise according to the following formulat ;

[0126]

[0127] δ t = 1 - λ t ;

[0128]

[0129] where σ t is noise following Gaussian distribution σ t ~ N(0, I); δ t is a variable; is the cumulative product value of variable δ t λ t (λ t ∈(0, 1)) is the noise time variation table, specifically it can be a linear value from 0.0001 to 0.01;

[0130] During the reverse denoising process, train a noise prediction network ξ θ to predict noise, and its loss function L is defined as follows:

[0131]

[0132] where E(·) is the expectation; t is the time step not greater than T; is a random initial sample satisfying a specific distribution ; is the data with t time step noise added; ξ is the noise, following Gaussian distribution N(0, I); is the noise prediction network ξ θ For the predicted noise of the input and time step t;

[0133] Remove Gaussian noise step by step through the following formula:

[0134]

[0135] where β follows Gaussian distribution;

[0136] Construct x0 step by step from the above steps; Quantize the features obtained after denoising to get the quantized feature Q, then perform feature replacement based on the codebook KV, and train the following decoder based on the artificial neural network:

[0137]

[0138] where h y2 is the decoder output; jh2 is the activation function; X' is the data to be decoded input to the decoder; and They are the weights and thresholds of neurons during the decoding process;

[0139] Finally, the quantized feature Q is transformed into the input data X0;

[0140] The interactive data of computer terminals is also trained based on a generative adversarial network. Among them, the generator G takes the input data X0 restored by the decoder or other random noises as input and generates new data;

[0141] The loss function L of the generator G is defined as follows:

[0142]

[0143] Among them, MSE(·) is the mean square error; G(η) is the generated data; y is the real data;

[0144] Then, the discriminator comprehensively discriminates the data generated by the generator;

[0145] The loss function L of the discriminator D is expressed as:

[0146]

[0147] Among them, D(y') is the discrimination result of the discriminator for the input data y'; D(G(η)) is the discrimination result of the discriminator for the generated data G(η);

[0148] During the training process, the generator and the discriminator are alternately trained; first, the discriminator is fixed and the generator is trained to make the generated data more realistic and better able to deceive the discriminator. Then, the generator is fixed and the discriminator is trained to be able to more accurately discriminate the authenticity of the data. Through continuous adversarial training, the performance of both the generator and the discriminator is improved, and finally the generator can generate high-quality synthetic data.

[0149] Through the combination of the above diffusion variational autoencoder and generative adversarial network, first, the original data is processed using the diffusion variational autoencoder, and then the restored features or data are further synthesized and optimized using the generative adversarial network, and more realistic and high-quality synthetic data can be generated.

[0150] Then, based on the quicksort algorithm, a pivot element z is selected, and the synthesized array is divided into two parts, one part is less than the pivot element z, and the other part is greater than the pivot element z. Based on the quicksort algorithm, quicksort operations are recursively performed on these two parts, the pivot element is incorporated into the encryption key, and the encrypted operation of the sorted data is performed based on the quantum encryption algorithm; at the same time, a key storage method of regularly changing the key is adopted to further enhance the security of the data.

[0151] By synthesizing and transforming the data in this way, the characteristics of the original data can be obfuscated, increasing the complexity of encryption. Moreover, further encrypting the data after synthesis and transformation can improve the usability and applicability of the data. The synthesized and transformed data is more suitable for different encryption algorithms, can improve data quality and usability, and is also convenient for unified management and transmission of data.

[0152] S3; Construct a user profile and establish an intelligent identity authentication mechanism based on the user profile; specifically as follows:

[0153] Refer to Figure 3 , collect and preprocess the user behavior data and computer terminal interaction scenario data; first, perform dimensionality reduction on the data through several discrete wavelet transforms, where the discrete wavelet transform dynamically adjusts the resolution according to the data distribution; it can better capture the hierarchical structure and detailed information of the data, providing more accurate feature descriptions for clustering. After the gl-th wavelet transform is completed, the data is converted into low-frequency components and high-frequency components; among them, the decomposed low-frequency components will continue to participate in the next round of discrete wavelet transforms until the specified GL times of discrete wavelet transforms are completed; after multiple transforms, start clustering from the lowest-frequency component, and gradually iterate upward to cluster the components of higher frequencies. Each time clustering is performed, the distance threshold for the next clustering is adaptively reduced based on the ant colony algorithm, increasing the requirements for clustering density and the connection lines between data points; and during each clustering process, the clustering center is dynamically adjusted according to the distribution characteristics of the data;

[0154] During the clustering process, calculate the number of clusters for the initial clustering based on the following elbow method:

[0155]

[0156] where, SSE is the sum of squared errors; jl k is the k-th clustering cluster; c k is the center of the k-th clustering cluster; s is the data point in the clustering cluster; ||·|| represents the Euclidean distance;

[0157] Based on the SSE values under different K values, find the elbow point of the corresponding SSE curve as the K value;

[0158] Randomly select K data points as the initial clustering centers;

[0159] For each data point, calculate its distance to each clustering center:

[0160]

[0161] where, d0 (d0 ∈ [1, d]) is the data point dimension;

[0162] For each cluster, update its cluster center based on the adaptive ant colony algorithm;

[0163] The adaptive ant colony algorithm is as follows:

[0164]

[0165]

[0166] Among them, is the transition probability of each optional path from point u to point v; yp uv is the value of pheromone concentration at point (u, v); π1 is the pheromone importance factor; π2 is the importance factor of the heuristic function; qf uv is the heuristic information value; ds1 is the distance from the starting point to the next point; ds2 is the distance from the next point to the target point; ω1 is the weight of ds1; ω2 is the weight of ds2; Θ is the turning coefficient; is the number of turns between the previous point and the next point; ω 2max and ω 2min are the maximum and minimum values of the weight of ω2 respectively; k best is the best coefficient value;

[0167] The pheromone is updated as follows:

[0168] yp uv (τ + 1) = (1 - ρ)yp uv (τ) + Δyp uv (τ);

[0169]

[0170] Among them, τ is the number of iterations; ρ is the pheromone evaporation coefficient; ρ min is the minimum value of the pheromone evaporation coefficient; Δyp uv (τ) is the change value of yp uv (τ); kl is the ant; ζ is the pheromone carried by the ant; yp is the target value; yp min is the minimum target value;

[0171] In the target value range, select 16 points as the next update points. According to the heuristic mechanism, calculate the clustering error values corresponding to the update points, and select the 3 points with the smallest clustering error values as the target points for the next iteration update;

[0172] Also based on the above adaptive genetic algorithm, dynamically and adaptively search and narrow the distance threshold for the next clustering according to the distribution characteristics of the data;

[0173] The above clustering algorithm adaptively adjusts the clustering center, etc. based on the adaptive genetic algorithm, and can better reflect the changes in clustering.

[0174] When the computer terminal conducts data interaction, in addition to the conventional authentication method, it automatically analyzes the matching degree between the current interaction scenario and the user profile. If the matching degree is lower than the preset matching degree threshold, additional authentication links are added or the continued data interaction is restricted. For example, passwords, fingerprint recognition, face recognition, SMS verification codes, etc. are superimposed, greatly enhancing the security of identity authentication. When performing important data interaction operations, users can also be required to input passwords and receive SMS verification codes simultaneously, or perform fingerprint recognition to ensure that only legitimate users can operate.

[0175] At the same time, the single sign-on method is implemented to facilitate users and improve security, reducing security risks brought by multiple accounts and passwords. User permissions are also regularly audited, and user accounts that no longer require access permissions are deleted in a timely manner to prevent abuse of permissions.

[0176] The method based on the user profile can deeply understand the user's behavior and data characteristics, and set access control permissions more precisely. For example, according to the user's role, historical operation records, and current data interaction context, the user's access permissions to data and resources are dynamically adjusted. For high-risk operations or access requests, additional identity verification (such as multi-factor authentication) can be performed to ensure that only legitimate and authorized users can access sensitive data, preventing abuse of permissions and data leakage.

[0177] S4: According to the user's role and responsibilities, finely divide data access permissions, classify and label the data, and set corresponding access policies according to the data sensitivity level; specifically as follows:

[0178] According to the user's role and responsibilities, finely divide data access permissions. For example, administrators can have the highest permissions, and ordinary employees can only access data related to their work.

[0179] Classify and label the data, and set different access control policies according to the sensitivity level. For highly sensitive data, more strict access control measures can be adopted, such as dual authentication, access approval, etc.

[0180] Technical means such as firewalls and intrusion detection systems can also be used to restrict external network access to the computer terminal, and at the same time, strict control is also carried out on internal network access.

[0181] Smart contracts can also be written to regulate data interaction behaviors and rules. For example, stipulate the conditions for obtaining data access permissions, frequency limits for data interaction, data format standards, etc. Once a violation of the contract rules occurs in the interaction behavior, the protection mechanism is automatically triggered to block the data interaction and record the violation information, realizing automated and intelligent security protection.

[0182] S5: Develop a data backup plan, regularly back up data to storage media, and test the integrity and recoverability of the backup data; specifically as follows:

[0183] Develop a data backup plan, regularly back up important data to secure storage media such as external hard drives, network storage devices, or cloud storage services. Test the integrity and recoverability of the backup data to ensure that data can be quickly and effectively restored in case of data loss or corruption. A disaster recovery plan can also be established to address emergencies such as possible system failures and natural disasters, ensuring data security and business continuity.

[0184] S6: Deploy a security audit system to record various information data, monitor the activities and operations of computer terminals in real time, and establish a security alarm mechanism for risk alarms. Specifically as follows:

[0185] Deploy a security audit system to record information such as user operation behaviors, system events, and network traffic for post - event analysis and auditing. Monitor the network activities, process operations, etc. of computer terminals in real time to promptly detect abnormal behaviors and security threats. Tools such as intrusion detection systems (IDS) and intrusion prevention systems (IPS) can be used. A security alarm mechanism is also established to immediately send alarm messages when security events are detected, notifying relevant personnel for handling.

[0186] Embodiment 2:

[0187] Please refer to Figure 4 , a fault detection system based on a mobile communication network according to the present invention, includes:

[0188] An acquisition and evaluation module 100: used to acquire data interaction scenario data of computer terminals and conduct security risk assessments, and based on this, conduct corresponding data intelligent security protection planning;

[0189] A data encryption module 200: used to perform data synthesis conversion on computer terminal interaction data, and then encrypt the synthesized and converted computer terminal interaction data based on a data encryption algorithm;

[0190] An identity authentication module 300: used to construct a user profile and establish an intelligent identity authentication mechanism based on the user profile;

[0191] An access division module 400: used to finely divide data access permissions according to user roles and responsibilities, classify and label data, and set corresponding access policies according to the data sensitivity level;

[0192] A data backup module 500: used to develop a data backup plan, regularly back up data to storage media, and test the integrity and recoverability of the backup data;

[0193] Security audit module 600: It is used to conduct security audits, record various information data, monitor the activities and operating conditions of computer terminals in real time, and establish a security alarm mechanism for risk alarms;

[0194] The acquisition and evaluation module 100 includes an acquisition and processing unit 110 and a risk assessment unit 120;

[0195] The acquisition and processing unit 110 is used to acquire computer terminal data interaction scenario data and perform preprocessing;

[0196] The risk assessment unit 120 is used to count risk influencing factors, conduct security risk assessments on computer terminal data interaction scenarios, and make corresponding data intelligent security protection plans based on this;

[0197] The data encryption module 200 includes a data synthesis unit 210 and a sorting and encryption unit 220;

[0198] The data synthesis unit 210 is used to perform data synthesis conversion on computer terminal interaction data;

[0199] The sorting and encryption unit 220 is used to perform fast sorting on the computer terminal interaction data after synthesis conversion based on a data encryption algorithm, and then perform encryption processing.

[0200] As mentioned above, it is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and should be covered by the protection scope of the present invention.

Claims

1. A data intelligent security protection method for computer terminal data interaction, characterized in that: It includes the following steps: S1: Collect computer terminal data interaction scenario data and perform preprocessing, count risk influencing factors, conduct security risk assessment on the computer terminal data interaction scenario, and accordingly carry out corresponding data intelligent security protection planning; S2: Perform data synthesis conversion on the computer terminal interaction data, and then encrypt the synthesized and converted computer terminal interaction data based on a data encryption algorithm; S3: Construct a user profile and establish an intelligent identity authentication mechanism based on the user profile; S4: According to the user roles and responsibilities, finely divide data access permissions, classify and label the data, and set corresponding access policies according to the data sensitivity level; S5: Develop a data backup plan, regularly back up the data to a storage medium, and test the integrity and recoverability of the backup data; S6: Deploy a security audit system, record various information data, simultaneously monitor the activities and running conditions of the computer terminal in real time, and establish a security alarm mechanism for risk alarm; In S2, the data synthesis conversion is based on an improved variational autoencoder for data synthesis conversion, specifically as follows: Process the input computer terminal interaction data using a vector quantization-based variational autoencoder pre-trained on a large-scale dataset for processing: Input data Obtain features through the encoder The details are as follows: Implement unsupervised encoding based on an artificial neural network: ; Among them, is the encoder output; is the activation function; and are the weights and thresholds of neurons during the encoding process; According to the codebook Search for the feature closest to each feature in and perform one-by-one replacement to obtain the quantized feature , ; Among them, is the th data input, is the reference feature in the codebook; Take the quantized features as the input of the diffusion model , and during the forward diffusion process, gradually add Gaussian noise to ; for each time step , calculate the computer terminal interaction synthetic data after adding noise according to the following formula ; ; ; ; wherein, is noise obeying a Gaussian distribution ; is a variable; is a variable cumulative product value of; is a noise time variation table; During the reverse denoising process, a noise prediction network is trained to predict the noise, and its loss function is defined as follows: ; wherein, is the expectation; is not greater than time steps; is a random initial sample that satisfies a specific distribution ; is the data with time step noise added; is the noise, following a Gaussian distribution ; is the noise prediction network for the input and the time step predicted noise; Gradually remove Gaussian noise through the following formula: ; ; Among them, obeys a Gaussian distribution; Gradually constructed by the above steps ; Quantize the features obtained after denoising to obtain quantized features , and then perform feature replacement according to the codebook , and train the following decoder based on an artificial neural network: ; Among them, is the decoder output; is the activation function; is the data to be decoded input to the decoder; and are the weights and thresholds of neurons in the decoding process; Finally, the quantization features are transformed into input data ; It also trains the computer terminal interaction data based on a generative adversarial network, where the generator uses the input data recovered by the decoder or other random noise as input to generate new data; The loss function of the generator is defined as follows: ; Among them, is the mean squared error; is the generated data; is the real data; Then comprehensively discriminate the data generated by the generator based on a discriminator; The loss function of the discriminator is expressed as: ; Among them, is the discrimination result of the discriminator for the input data ; is the discrimination result of the discriminator for the generated data ; During the training process, alternately train the generator and the discriminator; Then, based on the quicksort algorithm, select a pivot element , divide the synthesized array into two parts, recursively perform quicksort operations on these two parts based on the quicksort algorithm, incorporate the pivot element into the encryption key, and perform encryption operations on the sorted data based on the quantum encryption algorithm.

2. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S1, six influencing factors including exposure rate, severity, controllability, complexity, timeliness, and value are divided according to the computer terminal data interaction scenario data, and accordingly the security risk level of the computer terminal interaction scenario is divided.

3. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S2, a key storage method of regularly changing keys is also adopted.

4. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S3, collect and identify multi-dimensional user behavior data based on an improved clustering algorithm to construct a dynamic user profile, specifically as follows: Collect and preprocess user behavior data and computer terminal interaction scenario data; first, perform dimensionality reduction on the data through several discrete wavelet transforms, where the discrete wavelet transform dynamically adjusts the resolution according to the data distribution; after completing the th wavelet transform, the data is converted into low-frequency components and high-frequency components; among them, the low-frequency components continue to participate in the next round of discrete wavelet transforms until the specified th discrete wavelet transform is completed; after several transforms, clustering starts from the lowest-frequency component and gradually iterates upward to cluster the components of higher frequencies: Calculate the number of clusters of the initial clustering based on the following elbow method: ; Among them, is the sum of squared errors; is the th clustering cluster; is the center of the th clustering cluster; is the data point in the clustering cluster; represents the Euclidean distance; Based on the values under different K values, find the elbow point of the corresponding SSE curve as the K value; Randomly select K data points as the initial clustering centers; For each data point, calculate its distance to each clustering center: ; Among them, is the data point dimension; For each clustering cluster, update its clustering center based on an adaptive ant colony algorithm; The specific adaptive ant colony algorithm is as follows: ; ; ; Among them, is the transition probability of each optional path from point to point ; is the value of the pheromone concentration at point; is the pheromone importance factor; is the importance factor of the heuristic function; is the heuristic information value; is the distance from the starting point to the next point; is the distance from the next point to the target point; is 's weight; is 's weight; is the turning coefficient; is the number of turns between the previous point and the next point; and are respectively 's maximum and minimum weights; is the optimal coefficient value; Pheromone update is as follows: ; ; ; ; Among them, is the number of iterations; is the pheromone evaporation coefficient; is the minimum value of the pheromone evaporation coefficient; is the change value of; is the ant; is the pheromone carried by the ant; is the target value; is the minimum target value; In the target value range, select 16 points as the next update points, calculate the corresponding clustering error values of the update points according to the heuristic mechanism, and select the 3 points with the smallest clustering error values as the target points for the next iterative update; Dynamically and adaptively search and narrow the distance threshold for the next clustering according to the distribution characteristics of the data; When the computer terminal conducts data interaction, in addition to the conventional authentication method, automatically analyze the matching degree between the current interaction scenario and the user profile. If the matching degree is lower than the preset matching degree threshold, add additional authentication links or restrict the continued interaction of the data.

5. The data intelligent security protection method for computer terminal data interaction according to claim 4, characterized in that: In S3, a single sign-on method is also implemented, and user permissions are regularly audited.

6. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S4, set an intelligent contract for regulating data interaction behaviors and rules. When there is an interaction behavior that violates the contract rules, automatically trigger a protection mechanism to prevent data interaction and record the violation information.

7. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S5, a disaster recovery plan for dealing with emergencies is also developed.

8. The data intelligent security protection method for computer terminal data interaction according to claim 1, characterized in that: In S6, the data intelligent security protection measures are also regularly evaluated and reviewed.

9. A fault detection system, applicable to the data intelligent security protection method for computer terminal data interaction described in any one of claims 1-8, characterized in that: Including: The acquisition and evaluation module (100): used to collect computer terminal data interaction scenario data and conduct security risk assessment, and based on this, conduct corresponding data intelligent security protection planning; The data encryption module (200): used to perform data synthesis conversion on computer terminal interaction data, and then encrypt the synthesized and converted computer terminal interaction data based on the data encryption algorithm; The identity authentication module (300): used to construct a user profile and establish an intelligent identity authentication mechanism according to the user profile; The access division module (400): used to finely divide data access permissions according to user roles and responsibilities, classify and label data, and set corresponding access policies according to the data sensitivity level; The data backup module (500): used to formulate a data backup plan, regularly back up data to a storage medium, and test the integrity and recoverability of the backup data; The security audit module (600): used to conduct security audits, record various information data, and at the same time, monitor the activities and running conditions of computer terminals in real time, and establish a security alarm mechanism for risk alarms; The acquisition and evaluation module (100) includes an acquisition and processing unit (110) and a risk assessment unit (120); The acquisition and processing unit (110) is used to collect computer terminal data interaction scenario data and conduct preprocessing; The risk assessment unit (120) is used to count risk influencing factors and conduct security risk assessment on computer terminal data interaction scenarios, and based on this, conduct corresponding data intelligent security protection planning; The data encryption module (200) includes a data synthesis unit (210) and a sorting and encryption unit (220); The data synthesis unit (210) is used to perform data synthesis conversion on computer terminal interaction data; The sorting and encryption unit (220) is used to perform quick sorting processing on the synthesized and converted computer terminal interaction data based on the data encryption algorithm, and then perform encryption processing.

Citation Information

Patent Citations

  • Data encryption protection method and system based on block chain

    CN113949591A

  • Private data full life cycle protection method and system based on data platform

    CN117972779A

  • Virtual cloud desktop resource cycle life management method

    CN118467161A

  • Color picture generation method based on potential diffusion model

    CN118887315A