A blockchain-based information security data defense method and system

By adopting blockchain technology in the decentralized identity repository in the identity authentication technology, the single point of failure problem of centralized data management and the lack of real-time monitoring in the existing technology are solved, and higher security and faster response capabilities are achieved.

CN119670166BActive Publication Date: 2025-05-13GUANGZHOU SUILIAN TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510152584.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-05-13
Estimated Expiration
2045-02-12

AI Technical Summary

Technical Problem

There are centralized data management and storage methods in the prior art, which can easily lead to single point failure risk and lack real-time monitoring and dynamic response mechanisms, limiting the ability to adapt to complex security threats.

Method used

Decentralized identity repository based on blockchain is adopted to deploy decentralized identity repository through blockchain technology, store user identity information and verification keys, generate identity storage records, perform identity verification, evaluate the legitimacy of user requests, dynamically adjust user access rights, and implement real-time security monitoring and threat analysis.

Benefits of technology

It improves the security of identity authentication and data integrity, reduces the risk of data being illegally modified or leaked, enhances the speed of response to security threats, realizes dynamic permission adjustment and threat analysis, and improves overall security management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119670166B_ABST
    Figure CN119670166B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of identity authentication technology, and specifically to a blockchain-based information security data defense method and system, comprising the following steps: deploying a decentralized identity repository through blockchain technology, and storing user identity information and verification keys in the repository. The present invention improves the security of identity authentication and the integrity of data by combining blockchain technology and decentralized identity repository. The user identity information and verification keys stored on the blockchain benefit from the immutability and transparency of the blockchain, reducing the risk of illegal modification or leakage of data. In addition, by generating an independent verification status identifier for each user request, the security of the verification process is enhanced and the response speed to security threats is improved. Dynamic permission adjustment and threat analysis based on real-time monitoring are also implemented, which can quickly adapt to and respond to changes in the security environment, thereby improving the overall security management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication technology, and in particular to an information security data defense method and system based on blockchain. Background Art

[0002] The field of identity verification technology focuses on ensuring the accuracy of the identity of a user or device. It involves a series of methods and processes used to confirm the identity of an individual. The core of this field is to prevent unauthorized access and ensure the security of information and resources in various network environments. Technical means include cryptography, biometrics, two-factor or multi-factor authentication, etc.

[0003] However, existing technologies usually rely on centralized data management and storage methods, which are prone to single point failure risks. In addition, once attackers break through the security line, they can access a large amount of sensitive data. The lack of real-time monitoring and dynamic response mechanisms limits the ability to adapt to changing security threats. This may lead to inadequate defense measures in the face of complex security challenges such as advanced persistent threats, thereby increasing potential security risks. Summary of the invention

[0004] The purpose of the present invention is to solve the shortcomings existing in the prior art and to propose an information security data defense method and system based on blockchain.

[0005] In order to achieve the above purpose, the present invention adopts the following technical solution, a blockchain-based information security data defense method, comprising the following steps:

[0006] Deploy a decentralized identity repository through blockchain technology, store user identity information and verification keys in the repository, generate identity storage records, authenticate user requests based on the identity storage records, and generate a verification status identifier;

[0007] Based on the verification status identifier, the legitimacy of the user request is evaluated. After passing the legitimacy evaluation, access to the requested resource or service is allowed, an access authorization token is generated, and according to the access authorization token, the user's access rights are dynamically adjusted, and a permission update record is generated;

[0008] Based on the permission update record, implement security monitoring, monitor and record each identity authentication and authorization activity in real time, generate activity monitoring logs, analyze potential security threats based on the activity monitoring logs, and generate threat analysis results;

[0009] Based on the threat analysis results, adjust and optimize the authentication and authorization policies and generate a policy adjustment guide;

[0010] The steps for obtaining the access authorization token are:

[0011] Based on the verification status identifier, review the legitimacy of the user request, and determine whether it complies with the security criteria by analyzing the content of the verification status identifier to obtain a legitimacy evaluation result;

[0012] According to the legitimacy evaluation result, the classification of the user's access rights is calculated, and the calculation formula is:

[0013] ;

[0014] in, is the user access level, is the number of evaluation items, For the The weight factor of the item, For the Safety score of the item;

[0015] Based on the user access permission level, resource access permission is granted and an access authorization token is generated.

[0016] Preferably, the steps of obtaining the identity storage record are:

[0017] Deploy a decentralized identity repository through blockchain technology to store user identity information and verification keys and generate storage records;

[0018] According to the storage record, identity authentication preprocessing is performed to integrate the user identity information and the verification key to obtain the identity storage record.

[0019] Preferably, the steps of obtaining the verification status identifier are:

[0020] According to the identity storage record, the identity information submitted by the user request is compared with the stored verification key, and the consistency and integrity of the information are verified by a hash function to obtain a preliminary identity authentication result;

[0021] Based on the preliminary identity verification results, continue to review the user's identity information using multi-factor authentication, compare the biometric data and the answers to the security questions, and obtain detailed identity verification analysis results;

[0022] Based on the detailed identity authentication analysis results, the risk and legitimacy are evaluated to determine whether the user request is legitimate. If the verification passes, a verification status identifier is generated to indicate the user's identity authentication status.

[0023] Preferably, the steps for obtaining the permission update record are:

[0024] Extract the user's current permission level and behavior log based on the access authorization token, analyze the behavior pattern, and obtain a preliminary behavior risk score;

[0025] Based on the preliminary behavioral risk score, a final risk score is calculated using the following formula:

[0026] ;

[0027] in, For the final risk score, For the initial risk score, and is the adjustment coefficient;

[0028] According to the final risk score, the user's access rights are dynamically adjusted and a permission update record is generated.

[0029] Preferably, the steps of obtaining the activity monitoring log are:

[0030] Based on the permission update record, data is captured to synchronously record the information of each user identity authentication and authorization activity, including operation time, operator, operation content and result, to obtain a real-time monitoring data set;

[0031] Information is extracted from the real-time monitoring data set and integrated into a structured activity monitoring log, including a timestamp, a user identifier, an operation type, and an operation result, to obtain an activity monitoring log.

[0032] Preferably, the steps of obtaining the threat analysis result are:

[0033] Based on the activity monitoring log, the overall threat score is calculated using the following formula:

[0034] ;

[0035] in, represents the overall threat score, represents the total number of events, Indicates The risk level of the event;

[0036] Based on the overall threat score, potential security risks are analyzed and threat analysis results are compiled.

[0037] Preferably, the steps of obtaining the policy adjustment guide are:

[0038] By evaluating the threat analysis results, the adaptability and defects of the existing strategies are checked to obtain the strategy evaluation results;

[0039] Based on the policy evaluation results, an authentication and authorization policy is formulated to obtain a new security policy draft;

[0040] Based on the new security policy draft, write the execution steps, operational instructions and expected goals for each policy change to obtain a policy adjustment guide.

[0041] The present invention provides an information security data defense system, comprising:

[0042] The identity authentication storage module deploys a decentralized identity repository through the blockchain to store user identity information and verification keys, generate identity storage records for user requests, and generate identity authentication status;

[0043] The user legitimacy assessment module performs legitimacy assessment on user requests based on the identity authentication status, generates legitimacy assessment results, and allows or denies access to requested resources or services based on the legitimacy assessment results, and generates access authorization tokens;

[0044] The access permission adjustment module dynamically adjusts the user's access permissions according to the access authorization token, records each permission adjustment, generates permission update records, and generates permission dynamic adjustment records;

[0045] The security monitoring and threat analysis module dynamically adjusts records based on permissions, implements real-time security monitoring, records each identity authentication and authorization activity, generates activity monitoring logs, analyzes potential security threats based on activity monitoring logs, and generates threat analysis results;

[0046] The authentication policy optimization module adjusts and optimizes authentication and authorization policies based on threat analysis results and generates policy adjustment guidelines.

[0047] Compared with the prior art, the advantages and positive effects of the present invention are:

[0048] The present invention improves the security of identity authentication and the integrity of data by combining blockchain technology and decentralized identity storage. User identity information and verification keys stored on the blockchain benefit from the immutability and transparency of the blockchain, reducing the risk of illegal modification or leakage of data. In addition, by generating an independent verification status identifier for each user request, the security of the verification process is enhanced and the response speed to security threats is improved. Dynamic permission adjustment and threat analysis based on real-time monitoring are also implemented, which can quickly adapt to and respond to changes in the security environment, thereby improving the overall security management efficiency. Through continuous threat assessment and policy adjustment, it is guaranteed to adapt to future security challenges, thereby improving long-term security and stability. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 It is a schematic diagram of the steps of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0051] See also Figure 1 The present invention provides a technical solution, a blockchain-based information security data defense method, comprising the following steps:

[0052] Deploy a decentralized identity repository through blockchain technology, store user identity information and verification keys in the repository, generate identity storage records, authenticate user requests based on the identity storage records, and generate a verification status identifier;

[0053] Based on the verification status identifier, the legitimacy of the user request is evaluated. After passing the legitimacy evaluation, access to the requested resource or service is allowed, and an access authorization token is generated. Based on the access authorization token, the user's access rights are dynamically adjusted and a permission update record is generated;

[0054] Implement security monitoring based on permission update records, monitor and record each identity authentication and authorization activity in real time, generate activity monitoring logs, analyze potential security threats based on activity monitoring logs, and generate threat analysis results;

[0055] Based on the threat analysis results, adjust and optimize authentication and authorization policies and generate policy adjustment guidelines.

[0056] The steps to obtain the identity storage record are:

[0057] Deploy a decentralized identity repository through blockchain technology to store user identity information and verification keys and generate storage records;

[0058] According to the storage records, identity authentication preprocessing is performed to integrate user identity information and verification keys to obtain identity storage records.

[0059] Specifically, based on the deployed decentralized identity repository environment, user identity information and verification keys are read from existing data, specific identification elements in the user identity information are converted into a fixed-length string through a hash function, and the string is combined with the verification key according to established data organization rules. Subsequently, the pre-written on-chain data write instruction is called in the blockchain node, and the combined data is placed in the block structure and broadcast to the entire network. Each node reaches a consensus on the data content, and after consensus confirmation, the data is completely written into the distributed ledger to form a storage record.

[0060] According to the storage records obtained in the previous step, the user identity information and verification key are extracted from the records, and the extracted user identity information is formatted according to a fixed string encoding scheme. Then, the corresponding key verification module is selected according to the type of verification key, and the key data is verified for the number of bits and structural integrity. If the key bit length exceeds 128 bits, it needs to be re-segmented. The 128-bit length is based on the actual encryption standard requirements, and is set by counting the lengths of commonly used keys and analyzing their distribution patterns. After the verification is completed, the formatted user identity information and the verified verification key are integrated according to the established mapping rules, and the integrated data is updated to the storage structure and marked to obtain the final identity storage record.

[0061] The steps to obtain the verification status identifier are:

[0062] According to the identity storage record, the identity information submitted by the user is compared with the stored verification key, and the consistency and integrity of the information are verified through the hash function to obtain a preliminary identity authentication result;

[0063] Based on the preliminary authentication results, use multi-factor authentication to continue reviewing the user's identity information, compare biometric data and answers to security questions, and obtain detailed authentication analysis results;

[0064] Based on the detailed identity authentication analysis results, the risk and legitimacy are assessed to determine whether the user request is legal. If the verification passes, a verification status indicator is generated indicating the user's identity authentication status.

[0065] Specifically, refer to the identity storage record obtained previously, obtain the stored verification key therefrom, perform unified character encoding on the identity information submitted by the user request and clean up redundant characters, then use a fixed selected SHA256 hash function to generate a hash value for the information, and compare the hash value with the hash value corresponding to the stored verification key character by character. If any character mismatch is found during the comparison process, the difference position is recorded and it is confirmed again whether the hash value length is 256 bits. The 256-bit length is set by referring to the hash length standard commonly used in similar identity authentication cases and selecting the median value. After the comparison is completed, all matching data are summarized to finally obtain a preliminary identity authentication result.

[0066] With reference to the preliminary identity authentication results obtained previously, the biometric data collected and recorded in advance during the user's registration is called, and the biometric data includes fingerprint texture coding information and iris pattern coding information. This information is matched with the corresponding data submitted in the user request item by item for character sequence. Before matching, a structural check is performed on the fingerprint texture coding and iris pattern coding to confirm that the character sequence matches the pixel arrangement order of the 256×256 matrix format, which is set by the biometric acquisition device before leaving the factory and fixed in the internal program. The answers to the security questions answered by the user are checked at the character level with the recorded answers. Finally, the comparison result data of the above-mentioned multi-factor verification is summarized to obtain detailed identity authentication analysis results.

[0067] Referring to the detailed identity authentication analysis results obtained previously, the number of data items marked as mismatches in the statistical results is counted, and the legitimacy threshold is set to the median value of the illegal judgment ratio obtained in the historical verification cases. For example, if there are 10 illegal cases in 1,000 cases, the ratio is 1%. This 1% is used as the current legitimacy threshold, and the mismatch ratio is compared with 1%. If the mismatch ratio is less than 1%, the user request is judged to be legal. If it exceeds, it is illegal. For risk assessment, different numerical weights are assigned according to the type of mismatch items. For example, the weight of biometric data mismatch is higher than that of ordinary character answer mismatch. A risk score is calculated and compared with the median risk value selected by the same statistical method. If the risk score is lower than the median value, the verification is passed, and finally a verification status identifier is generated.

[0068] The steps to obtain an access authorization token are:

[0069] Based on the verification status identifier, the legitimacy of the user request is examined, and by analyzing the content of the verification status identifier, it is determined whether it complies with the security criteria and a legitimacy assessment result is obtained;

[0070] According to the legitimacy assessment results, the user access rights are graded and the calculation formula is:

[0071] ;

[0072] in, is the user access level, is the number of evaluation items, For the The weight factor of the item, For the Safety score of the item;

[0073] Based on the user's access level, resource access is granted and an access authorization token is generated.

[0074] Specifically, referring to the verification status identifier obtained previously, the character sequence contained in the identifier is parsed therefrom, these character sequences are divided into segments and counted according to a fixed length, and the number of different segments is counted, and by querying the verification status identifier data set formed previously, character segmentation statistics are performed on 1,000 identifiers that meet legal requirements, and the number distribution of character segments in these identifiers is extracted, and the median of these distributions is selected as the standard value for measuring security criteria. The median standard value is confirmed to be 50 segments through statistical analysis. When counting the number of character segments of the current verification status identifier, if the number of character segments is greater than or equal to 50 segments, it indicates that the identifier meets the previously determined security criteria. If the number of character segments is less than 50 segments, it indicates that the security criteria are not met. Finally, the legality assessment result is recorded based on the comparison result of the number of segments with the median standard value.

[0075] The formula is useful because it introduces the weight factor and safety score The square term of is taken and the cube root is taken after summing up to express the characteristic differences of each evaluation item in a nonlinear form, so as to reflect more dimensional information in the access permission classification calculation;

[0076] The parameter acquisition step is to count the evaluation items one by one according to the evaluation item list contained in the previously obtained legality evaluation result and obtain ;

[0077] The parameter acquisition step is to quantify the statistical frequency of security-related events that appear in the historical analysis of each evaluation item in the previously obtained legitimacy evaluation result, and convert the statistical frequency into a numerical value through a segmented ratio. The specific value of is obtained by taking the median and normalizing the proportion of related events in 1,000 historical access records;

[0078] The parameter acquisition step is to start with the security score quantification process corresponding to each evaluation item in the previously obtained legitimacy evaluation results. The security score is converted into an integer score range of 0-100 by analyzing the biometric matching degree, user environment consistency and historical event statistics corresponding to the user request behavior in the user request. The score distribution of 1000 historical records is selected and standardized. Fall within a reasonable range;

[0079] set up , , , , , , ;

[0080] Calculation process:

[0081] The first step is to calculate each evaluation:

[0082] ;

[0083] ;

[0084] ;

[0085] Take the cube root of each term:

[0086] ;

[0087] Add the three together:

[0088] ;

[0089] Finally, divide by :

[0090] ;

[0091] The results show that is the user access permission level value, and its value indicates the level of permission under the current access conditions. When the value is high, it means that the scores of multiple evaluation results are high under the effect of square amplification and weight. When the value is less than 10, it means that most of the evaluation items are rated low or the weights assigned are low. Indicates that the current user access permission level has reached a specific range, and necessary permission allocation and control of resource access can be performed based on this value.

[0092] Refer to the user access level obtained previously, extract the value from it and convert the access level to Convert to an integer value between 0 and 100, and according to the access policy corresponding to different range segments, The corresponding integer value is combined with the high entropy sequence generated by the random number generator, character encoding is performed on the combined data, and the encoded character sequence is concatenated with the timestamp and the specific identifier. The final character length and structure form are selected for the access authorization token by retrieving internal inherent rules, and the above result is recorded as the final access authorization token.

[0093] The steps to obtain the permission update record are:

[0094] Based on the access authorization token, extract the user's current permission level and behavior log, analyze the behavior pattern, and obtain a preliminary behavior risk score;

[0095] Based on the preliminary behavioral risk score, the final risk score is calculated using the following formula:

[0096] ;

[0097] in, For the final risk score, For the initial risk score, and is the adjustment coefficient;

[0098] Based on the final risk score, the user's access rights are dynamically adjusted and permission update records are generated.

[0099] Specifically, refer to the access authorization token obtained previously, parse the permission level value and user behavior log data contained therein, compare the timestamp of each access event in the user behavior log with the access resource identifier, retrieve the basic behavior data set for comparison, match the corresponding user behavior event number one by one from the data set, count the number of occurrences of the behavior type one by one according to the event number, if the behavior type includes abnormal requests, frequent repeated requests, and extremely short interval continuous requests, count the cumulative occurrence frequency of the behavior type respectively, and compare the counting result with the pre-defined classification threshold, which is set by taking the median of the frequency distribution of the same type of events in 1,000 historical behavior data. When the frequency of abnormal requests is higher than the median, the risk weight value is increased. When the frequency of frequent repeated requests and extremely short interval continuous requests are both higher than the corresponding median, the risk weight value is further accumulated, and the accumulated risk weight value is converted into a numerical score and associated with the permission level value to finally obtain a preliminary behavior risk score.

[0100] The formula is useful in that it provides a preliminary risk score Introducing the adjustment factor and A logarithmic function is used to nonlinearly amplify the increment under high-risk conditions, so that the final risk score It can better reflect the actual risk distribution characteristics;

[0101] The parameter acquisition step is to scale the current abnormal request ratio with the median value of the abnormal request ratio distribution in 1000 historical behavior data according to the user abnormal request ratio contained in the preliminary behavior risk score obtained above. For example, when the user abnormal request ratio is 5%, the median mapping score corresponding to 5% in 1000 historical data is determined as ;

[0102] The parameter acquisition step is to compare the known final risk scores in 1000 historical data with the corresponding preliminary behavior risk scores. Match one by one, statistics in The median value of the change rate of the final risk score at that time is taken when the logarithmic increase of the median value corresponds to a ratio of 2.0. ;

[0103] The parameter acquisition step is to statistically analyze the logarithmic increase relationship between each point in the distribution range of S value from 0 to 100 and the final risk score in the same 1000 historical data, and select The median value of the corresponding slope distribution of the nearby logarithmic increase curve median feature point is 0.015, so ;

[0104] Calculation process:

[0105] In this case, it is determined , , , first calculate ;

[0106] Substituting this value into the formula:

[0107] ;

[0108] Take the logarithm of this value:

[0109] ;

[0110] Then multiply the logarithmic result by :

[0111] ;

[0112] The results show that is the final risk score value. A value greater than 1 indicates that the risk score has exceeded the basic level. A higher value indicates that the user's behavior pattern matches high-risk behavior more closely. A value below 1 indicates that the risk is in the lower range, in this case This indicates that the risk has increased relative to the basic level, and user access rights can be adjusted accordingly based on this result.

[0113] Referring to the final risk score obtained previously, the risk score value is extracted therefrom, and the permission change records corresponding to this interval are queried in 1000 historical permission adjustment data, and the permission adjustment parameters and the access resource lists of the records under the same interval in these records are compared. The most frequently accessed item in the resource list is used as a reference, and a matching access level is selected for the current user in the permission mapping rule. The access level is combined and encoded with the timestamp and the unique identification tag, and the combined code is processed as a character sequence, and the finally generated permission update record is recorded internally.

[0114] The steps to obtain activity monitoring logs are as follows:

[0115] Based on the permission update record, data is captured and information about each user identity authentication and authorization activity is synchronously recorded, including operation time, operator, operation content and results, to obtain a real-time monitoring data set;

[0116] Information is extracted from the real-time monitoring data set and integrated into a structured activity monitoring log, including timestamp, user ID, operation type and operation result, to obtain the activity monitoring log.

[0117] Specifically, referring to the permission update record obtained previously, the corresponding permission change timestamp and identity information of the executed operation are parsed therefrom, and this information is compared with the user identity authentication and authorization activity record. For each identified authentication and authorization operation, the unique identification number of the operation is read, and by querying the previously summarized operation type definition table, it is determined whether the current operation belongs to an identity authentication action or an authorization action according to the unique identification number. Then, when counting the operation time, the time data is converted into the standard UTC time format. When recording the corresponding operator, the matching identity identification code is queried from the previously established user identification data set. When associated with the operation content, the corresponding activity type number is extracted from the operation content definition set. Then, the operation result is classified in the form of Boolean values, such as 1 for success and 0 for failure. All matched data are merged and summarized, and sorted in chronological order. The sorted operation information is integrated to form a continuously updated data stream, and all matched data are summarized to obtain a real-time monitoring data set.

[0118] Referring to the real-time monitoring data set obtained previously, read the relevant information including timestamp, user ID and operation result one by one, convert the timestamp uniformly according to the pre-established minute and second precision format, obtain the corresponding user name or number by querying the user ID data set, and classify and map the operation type number of each operation record based on the operation type number in the operation content definition set, such as authentication operation is recorded as Class A, authorization operation is recorded as Class B, and the Boolean value of the operation result is defined as "successful" if it is 1, and defined as "failed" if it is 0. Rearrange and combine these standardized information to ensure that the order of timestamp, user ID, operation type and operation result is consistent, and finally splice and integrate the above information to obtain the activity monitoring log.

[0119] The steps to obtain threat analysis results are as follows:

[0120] Based on the activity monitoring log, the overall threat score is calculated using the following formula:

[0121] ;

[0122] in, represents the overall threat score, represents the total number of events, Indicates The risk level of the event;

[0123] Analyze potential security risks based on the overall threat score and compile threat analysis results.

[0124] Specifically, the formula is useful in that it can be used to classify the risk level of each event. The squares are accumulated and averaged, and the average is squared to obtain the overall threat score. It can better highlight the impact of high-risk events in the overall situation;

[0125] The parameter acquisition step is to obtain the number of events in the activity monitoring log obtained above. For example, if 5 events are recorded in a monitoring period, ;

[0126] The parameter acquisition step is to extract the attribute characteristics corresponding to each event from the activity monitoring log, including abnormal access frequency, number of suspicious request types, and number of repeated accesses during non-peak hours. These non-numeric data are converted into integer risk levels between 0 and 100 through quantitative rules. The quantitative rules count the proportion of similar events in 1,000 historical event data, select the median as the standardized mapping point, and map the proportion corresponding to the current event characteristics to a score range of 0-100. In the example, the risk levels of 5 events are set as , , , , ;

[0127] Calculation process:

[0128] First, sum the squares of the risk level of each event:

[0129] , , , , ;

[0130] Add these values: 900+2025+3600+5625+2500=14650;

[0131] Find the average: ;

[0132] Square root of 2930: ;

[0133] The final overall threat score ;

[0134] This result shows that when A value between 0 and 30 indicates a low overall risk, a value between 30 and 50 indicates a medium overall risk, and a value greater than 50 indicates a high overall risk. This indicates that the current overall threat score has reached a high level and that this value can be used to further analyze potential security risks in subsequent steps.

[0135] Referring to the overall threat score obtained previously, the numerical value of the score is read out from it, and the score is interval-located to map it to the historical risk score distribution. According to the score distribution obtained from the previous analysis of 1,000 historical records, the score interval is divided into 5 sections, and the corresponding risk interpretation value is marked in each section. After substituting the current score into the corresponding interval section, the established reference rule table is retrieved, and the event type defined in the reference rule table is compared with the typical risk characteristics of the corresponding section of the score. Relevant historical event description documents and corresponding security description parameters are selected from them, and these description parameters are matched with the event type of the current score. According to the matching results, a list of event numbers close to the current score is extracted, and the event description data prepared in advance is called for these event numbers. The event numbers are further sorted and counted according to the time sequence and the severity of the events, the relationship between the events is recorded and specific risk attributes are marked, and the marked risk attribute information is compared with the authority allocation record. According to the number comparison, the appropriate description elements are extracted, and finally all the matched data are summarized to obtain the threat analysis results.

[0136] The steps to obtain the policy adjustment guide are:

[0137] By evaluating the threat analysis results, the adaptability and defects of the existing strategies are checked to obtain the strategy evaluation results;

[0138] Based on the policy evaluation results, formulate authentication and authorization policies and obtain a new security policy draft;

[0139] Based on the draft of the new security policy, write the execution steps, operational instructions and expected goals for each policy change to obtain a policy adjustment guide.

[0140] Specifically, evaluate the security issues involved one by one, such as vulnerable links in the authentication process and excessive permissions in the authorization process. For each security issue, analyze its frequency of occurrence and potential impact, such as records of authentication failures and statistics of improper authorized access events, to assess the severity of the security vulnerability. For each vulnerability, determine the corresponding security threshold. For example, an authentication attempt failure rate of more than 5% is considered a critical issue and requires special attention. In this process, assess the priority of each issue based on the severity and frequency of security incidents, and compile this information into policy evaluation results.

[0141] Develop new authentication and authorization policies based on recommendations from policy assessment results. First, redesign the authentication process to ensure that each stage of multi-factor authentication meets current security standards, such as setting the minimum security level for two-factor authentication to a combination of encrypted physical tokens and biometrics. Then, reconfigure the permission granting mechanism to ensure that each authorization level has clear permission binding and access control lists, such as limiting data access rights and requiring regular reassessment through dynamic permission audits.

[0142] Write a policy adjustment guide that details how to implement new authentication and authorization policies. From developing an implementation timeline, identifying the required resources, to describing the expected operational impact and potential risks. The specific implementation steps for each policy change include how to configure system settings, update security protocols, and test the effectiveness of new measures. For example, an updated authentication process needs to be tested with simulated attacks in a test environment to verify the defense capabilities of the new measures.

[0143] The present invention provides an information security data defense system, comprising:

[0144] The identity authentication storage module deploys a decentralized identity repository through the blockchain to store user identity information and verification keys, generate identity storage records for user requests, and generate identity authentication status;

[0145] The user legitimacy assessment module performs legitimacy assessment on user requests based on the identity authentication status, generates legitimacy assessment results, and allows or denies access to requested resources or services based on the legitimacy assessment results, and generates access authorization tokens;

[0146] The access permission adjustment module dynamically adjusts the user's access permissions according to the access authorization token, records each permission adjustment, generates permission update records, and generates permission dynamic adjustment records;

[0147] The security monitoring and threat analysis module dynamically adjusts records based on permissions, implements real-time security monitoring, records each identity authentication and authorization activity, generates activity monitoring logs, analyzes potential security threats based on activity monitoring logs, and generates threat analysis results;

[0148] The authentication policy optimization module adjusts and optimizes authentication and authorization policies based on threat analysis results and generates policy adjustment guidelines.

[0149] The above are only preferred embodiments of the present invention and are not intended to limit the present invention in other forms. Any technician familiar with the profession may use the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention still falls within the protection scope of the technical solution of the present invention.

Claims

1. A blockchain-based information security data defense method, characterized in that: The following steps are involved: Deploy a decentralized identity repository through blockchain technology, store user identity information and verification keys in the repository, generate identity storage records, authenticate user requests based on the identity storage records, and generate a verification status identifier; Based on the verification status identifier, the legitimacy of the user request is evaluated. After passing the legitimacy evaluation, access to the requested resource or service is allowed, an access authorization token is generated, and according to the access authorization token, the user's access rights are dynamically adjusted, and a permission update record is generated; Based on the permission update record, implement security monitoring, monitor and record each identity authentication and authorization activity in real time, generate activity monitoring logs, analyze potential security threats based on the activity monitoring logs, and generate threat analysis results; Based on the threat analysis results, adjust and optimize the authentication and authorization policies and generate a policy adjustment guide; The steps for obtaining the verification status identifier are: According to the identity storage record, the identity information submitted by the user request is compared with the stored verification key, and the consistency and integrity of the information are verified by a hash function to obtain a preliminary identity authentication result; Based on the preliminary identity verification results, continue to review the user's identity information using multi-factor authentication, compare the biometric data and the answers to the security questions, and obtain detailed identity verification analysis results; According to the detailed identity authentication analysis results, the number of data items marked as mismatches in the detailed identity authentication analysis results is counted, and the legitimacy threshold is set to the median value of the illegal judgment ratio obtained by statistics in historical verification cases. If the mismatch ratio is less than the legitimacy threshold, the user request is judged to be legal, and if it exceeds the legitimacy threshold, it is illegal. For risk assessment, different numerical weights are assigned according to the type of mismatch items, and a risk score is calculated and the median of the risk score is selected by the same statistical method for comparison. If the risk score is lower than the median, the verification is passed, and a verification status identifier indicating the user's identity authentication status is generated; The steps for obtaining the access authorization token are: Based on the verification status identifier, parse the character sequence contained in the verification status identifier, count the character sequence in segments according to a fixed length, and count the number of different segments, query the verification status identifier data set formed previously, perform character segmentation statistics on the identifiers that meet the legal requirements, extract the number distribution of character segments in the identifiers that meet the legal requirements, select the median of the number distribution as the measurement standard value of the security criterion, if the number of character segments of the current verification status identifier is greater than or equal to the measurement standard value, it indicates that the verification status identifier meets the security criterion, if the number of character segments is lower than the measurement standard value, it indicates that the security criterion is not met, and obtain the legality evaluation result based on the comparison result of the number of character segments and the measurement standard value; According to the legitimacy evaluation result, the classification of the user's access rights is calculated, and the calculation formula is: ; in, is the user access level, is the number of evaluation items, For the The weight factor of the item, For the Safety score of the item; Based on the user access permission level, resource access permission is granted and an access authorization token is generated.

2. The information security data defense method based on blockchain according to claim 1 is characterized in that: The steps for obtaining the identity storage record are: Deploy a decentralized identity repository through blockchain technology to store user identity information and verification keys and generate storage records; According to the storage record, identity authentication preprocessing is performed to integrate the user identity information and the verification key to obtain the identity storage record.

3. The information security data defense method based on blockchain according to claim 1 is characterized in that: The steps for obtaining the activity monitoring log are: Based on the permission update record, data is captured to synchronously record the information of each user identity authentication and authorization activity, including operation time, operator, operation content and result, to obtain a real-time monitoring data set; Extracting information from the real-time monitoring data set and integrating it into a structured activity monitoring log, including a timestamp, a user identifier, an operation type, and an operation result, to obtain an activity monitoring log; The steps for obtaining the threat analysis results are as follows: Based on the activity monitoring log, the overall threat score is calculated using the following formula: ; in, represents the overall threat score, represents the total number of events, Indicates The risk level of the event; Based on the overall threat score, potential security risks are analyzed and threat analysis results are compiled.

4. The information security data defense method based on blockchain according to claim 1 is characterized in that: The steps for obtaining the permission update record are: Extract the user's current permission level and behavior log based on the access authorization token, analyze the behavior pattern, and obtain a preliminary behavior risk score; Based on the preliminary behavioral risk score, a final risk score is calculated using the following formula: ; in, For the final risk score, For the initial risk score, and is the adjustment coefficient; According to the final risk score, the user's access rights are dynamically adjusted and a permission update record is generated.

5. The information security data defense method based on blockchain according to claim 1 is characterized in that: The steps for obtaining the policy adjustment guide are: By evaluating the threat analysis results, the adaptability and defects of the existing strategies are checked to obtain the strategy evaluation results; Based on the policy evaluation results, an authentication and authorization policy is formulated to obtain a new security policy draft; Based on the new security policy draft, write the execution steps, operational instructions and expected goals for each policy change to obtain a policy adjustment guide.

6. An information security data defense system according to the information security data defense method based on blockchain according to any one of claims 1 to 5, characterized in that: include: The identity authentication storage module deploys a decentralized identity repository through the blockchain to store user identity information and verification keys, generate identity storage records for user requests, and generate identity authentication status; The user legitimacy assessment module performs legitimacy assessment on user requests based on the identity authentication status, generates legitimacy assessment results, and allows or denies access to requested resources or services based on the legitimacy assessment results, and generates access authorization tokens; The access permission adjustment module dynamically adjusts the user's access permissions according to the access authorization token, records each permission adjustment, generates permission update records, and generates permission dynamic adjustment records; The security monitoring and threat analysis module dynamically adjusts records based on permissions, implements real-time security monitoring, records each identity authentication and authorization activity, generates activity monitoring logs, analyzes potential security threats based on activity monitoring logs, and generates threat analysis results; The authentication policy optimization module adjusts and optimizes authentication and authorization policies based on threat analysis results and generates policy adjustment guidelines.

Citation Information

Patent Citations

  • Zero-trust security processing method and system for Internet of Things equipment authentication encryption

    CN116248277A

  • Digital identity authentication method based on block chain technology

    CN117216740A

  • Mobile office data security access system based on encrypted mirror image transmission

    CN118433704A