A digital confirmation management method and system based on data mining
By building an encryption risk assessment model and performing blockchain evidence storage processing, the problem of insufficient encryption of data transmission in digital certificates is solved, and data security and audit reliability are improved.
Patent Information
- Application Number
- CN202510206075.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-25
AI Technical Summary
There is a problem of insufficient encryption of data transmission in the digital certificate, which leads to data leakage and causes serious losses to enterprises and related parties.
Digital proof-of-release is generated by obtaining corporate financial data for encryption, and an encryption risk assessment model is constructed based on the bp neural network algorithm, and the intensity data and risk impact data in the encryption process are obtained, digital proof-of-release is screened, and the screened digital proof-of-release process is processed by blockchain proof-of-release.
Effectively reduce encryption risks, ensure data security, improve the security of corporate financial data, provide a reliable basis for audit work, and enhance trust between enterprises and customers.
Smart Images

Figure CN119691781B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of letter confirmation management, and more specifically, to a digital letter confirmation management method and system based on data mining. Background Art
[0002] In today's digital age, corporate financial audits face increasingly complex challenges. Traditional confirmations are inefficient and suffer from numerous drawbacks, such as tedious manual processing, delayed information transmission, and difficulty ensuring data authenticity. The rapid development of information technology has given rise to digital confirmations. Leveraging digital technology, digital confirmations have automated and intelligently implemented the confirmation process. However, faced with massive amounts of financial data and complex business environments, confirmation management faces numerous challenges. On the one hand, the influx of data creates a significant amount of redundant information during the confirmation process, increasing processing complexity; on the other hand, data authenticity and reliability are difficult to guarantee, posing potential risks. Data mining technology provides a powerful tool for addressing these issues. By deeply mining corporate financial data and historical confirmation data, key information can be extracted and hidden patterns and regularities can be discovered. For example, data mining can be used to analyze the transaction patterns and response patterns of confirmed entities to assess confirmation risks. Furthermore, data mining technology can help companies optimize their confirmation processes and improve their efficiency. Data analysis can promptly identify anomalies and provide decision support.
[0003] Furthermore, with the continuous advancement of cybersecurity technology, digital confirmations face severe security challenges. Data leaks, cyberattacks, and other issues have caused significant losses to businesses. Therefore, strengthening the security protection measures for digital confirmations is imperative.
[0004] The aforementioned technical solutions present at least the following technical issues: Digital confirmations involve a large amount of sensitive financial information and corporate data. Inadequate platform security measures, such as cyberattacks and insufficient data transmission encryption, can lead to data leaks, causing serious losses to businesses and related parties. The present invention addresses these issues by providing a solution. Summary of the Invention
[0005] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a digital letter of credit management method and system based on data mining, which solves the problem of insufficient data transmission encryption leading to data leakage and causing serious losses to enterprises and related parties by constructing an encryption risk assessment model.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] A digital confirmation management method based on data mining includes the following steps: obtaining enterprise financial data and encrypting the enterprise financial data to generate digital confirmations; obtaining strength data and risk impact data during the encryption process and building an encryption risk assessment model based on a BP neural network algorithm; screening digital confirmations according to the output of the encryption risk assessment model and performing blockchain evidence storage processing on the screened digital confirmations.
[0008] In a preferred embodiment, the encryption of corporate financial data to generate digital confirmation is specifically as follows: collecting corporate financial data, using the isnull() function to identify missing values in the data and fill them in; identifying outliers based on a box plot, and replacing out-of-range outliers with upper or lower limits to obtain preprocessed corporate financial data; generating a symmetric key of a fixed length based on a symmetric encryption algorithm; performing an XOR operation on the financial data and the symmetric key to generate ciphertext; generating an asymmetric key pair based on an asymmetric encryption algorithm, the asymmetric key pair including a public key and a private key; encrypting the symmetric key according to the generated public key, storing all data in the financial system after public key encryption, and at the same time, forcing all users in the financial system to enable multi-factor authentication.
[0009] In a preferred embodiment, the strength data includes a data encryption strength coefficient, and a specific method for obtaining the data encryption strength coefficient is as follows: obtain the key length and algorithm complexity generated during the symmetric encryption process; calculate the size of the key space based on the generated key length; obtain the key strength index based on the size of the key space, the encryption algorithm, and the ratio of the largest key space size among the key lengths; perform regression analysis based on the complexity of the algorithm and the power operation method used by the algorithm to obtain the algorithm strength factor; combine the key strength index and the algorithm strength factor with the pre-acquired update frequency and security patch response time to obtain the data encryption strength coefficient based on the data encryption strength coefficient calculation formula.
[0010] In a preferred embodiment, the risk impact data includes a key performance delay coefficient, and the specific method for obtaining the key performance delay coefficient is as follows: obtain the key generation delay data in each time period, and perform time series analysis to identify the time period where the system generates a performance bottleneck, and calculate the delay density of each time period; accumulate the delay density in all time periods to obtain the total key generation delay density; calculate the average delay time based on the total key generation delay density and the total duration of system operation; measure the processor load and network bandwidth performance indicators in the simulation environment, calculate the overall processing capacity of the system, and combine the overall processing capacity of the system with the average delay time to calculate the key performance delay coefficient.
[0011] In a preferred embodiment, the risk impact data further includes a key fluctuation impact coefficient. The key fluctuation impact coefficient is obtained by continuously collecting key data at different nodes and recording the key value of each node at each collection time; calculating the entropy value of the key data of each node at each collection time, and marking the key entropy at different nodes at the same time;
[0012] A detection interval including several collection moments is set, and the average value and standard deviation of the key entropy of each node at different moments in the detection interval are calculated to calculate the key fluctuation influence coefficient.
[0013] In a preferred embodiment, the digital confirmation is screened according to the output of the encryption risk assessment model, specifically: a risk threshold is set, the encryption risk assessment coefficient of the digital confirmation is compared with the risk threshold, and a comparison result is obtained, wherein the comparison result includes passing secondary verification and multi-party verification; wherein, in the secondary verification, the digital confirmation is marked as a high-risk confirmation, and a hash function and a symmetric encryption algorithm are selected for re-encryption; in the multi-party verification, the re-encrypted data is split into N fragments, distributed to the end customer through Shamir secret sharing, and a threshold for digital confirmation restoration verification fragments is set. After the verification is passed, a multi-party verification certificate is generated.
[0014] In a preferred embodiment, the blockchain evidence storage processing of the screened digital letters is specifically as follows: the screened digital letters are decomposed into time slices and space slices according to the time dimension, classified and structured, key information is extracted and data is stored; a dual-chain hybrid architecture is constructed, the extracted key information is processed, and a unique hash value is generated; a seed is generated by a quantum random number generator, a public-private key pair is generated based on lattice cryptography, the public key hash is written into the classical chain, and the private key shard is hosted on quantum security hardware; when a quantum computing threat is triggered, the quantum chain verification logic is automatically enabled, and classical hash verification and quantum signature verification are performed.
[0015] The technical effects and advantages of the digital confirmation management method and system based on data mining of the present invention are as follows:
[0016] 1. This invention uses data mining technology to obtain strength data and risk impact data from the encryption process and construct an encryption risk assessment model. By screening digital confirmations, encryption risks are effectively reduced and data security is ensured. Furthermore, these screened digital confirmations are stored on the blockchain, leveraging the blockchain's immutable nature to ensure data integrity and traceability. This process not only improves the security of corporate financial data but also provides a reliable basis for audits and strengthens trust between companies and their customers.
[0017] 2. This invention uses data mining to analyze various factors in the encryption process, providing enterprises with quantitative encryption risk assessment indicators. The encryption risk assessment model, built using the BP neural network algorithm, helps enterprises select encryption algorithms more scientifically and rationally. The screening and re-encryption of digital confirmations enables enterprises to adjust encryption strategies based on risk levels and optimize resource allocation. This not only improves encryption efficiency but also reduces encryption costs, enhancing the overall competitiveness of enterprises. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 The figure is a flow chart of a digital letter of credit management method based on data mining according to the present invention.
[0019] Figure 2 This is a structural diagram of a digital letter of credit management system based on data mining in the present invention. DETAILED DESCRIPTION
[0020] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0021] Example 1, Figure 1 The present invention provides a digital confirmation management method based on data mining, which includes the following steps:
[0022] S1, obtain the enterprise financial data, encrypt the enterprise financial data and generate digital confirmation;
[0023] A hybrid encryption algorithm is used to encrypt corporate financial data and generate digital confirmations. This algorithm combines symmetric and asymmetric encryption algorithms. In hybrid encryption, the recipient's public key is used to encrypt the key used in the symmetric encryption algorithm. This allows only the recipient with the corresponding private key to decrypt the symmetric encryption key and, in turn, the corporate financial data.
[0024] The advantages of using a hybrid encryption algorithm are:
[0025] A balance between efficiency and security: Symmetric encryption is fast and can efficiently process large amounts of financial data. Asymmetric encryption offers greater security, particularly during the key exchange process, ensuring the secure transmission of symmetric encryption keys. For example, if an enterprise needs to send encrypted financial data to an auditing agency, hybrid encryption can achieve both rapid data encryption and key security during transmission, preventing data leaks.
[0026] Convenient key management: In asymmetric encryption, the public key can be widely distributed, while the private key is kept by a specific recipient. This approach makes key management more flexible and secure. For example, when encrypting corporate financial data, the public key can be provided to authorized auditors or relevant agencies, while the private key is kept by the company itself or in a designated secure storage location.
[0027] The obtaining of enterprise financial data and encryption of the enterprise financial data are specifically as follows:
[0028] Collect corporate financial data, use the isnull() function to identify missing values in the data, and use different methods to fill in different missing values;
[0029] Identify outliers based on the box plot and replace outliers with upper or lower limits to obtain preprocessed corporate financial data.
[0030] Based on the symmetric encryption algorithm, a symmetric key of fixed length is generated;
[0031] Perform XOR operation on the financial data and the symmetric key to generate ciphertext;
[0032] Generate an asymmetric key pair based on an asymmetric encryption algorithm, wherein the asymmetric key pair includes a public key and a private key;
[0033] Encrypt the symmetric key using the generated public key, and store all data in the financial system after public key encryption. At the same time, multi-factor authentication is mandatory for all users in the financial system.
[0034] Specifically, different methods are used to fill in missing values: for numerical data, the mean and median can be used for filling; for character data, the mode can be used for filling.
[0035] Different methods are used to fill in different missing values, specifically:
[0036] Classify missing values into numerical data, categorical data, and time series data;
[0037] For numerical data, use mean filling, median filling and interpolation methods to fill;
[0038] For categorical data, mode filling, forward filling and backward filling are used for filling processing;
[0039] For time series data, linear interpolation and time-weighted averaging are used for filling;
[0040] Input the above filling strategy into the data processing tool to write the code.
[0041] The method identifies outliers based on the box plot and replaces out-of-range outliers with upper or lower limits, specifically:
[0042] The box plot describes the data through five key statistics: minimum (Min), first quartile (Q1), median (Q2), third quartile (Q3), and maximum (Max);
[0043] The outliers of the box plot are defined as low outliers and high outliers; the low outliers are values less than Q1 - 1.5* IQR, and the high outliers are values greater than Q3 + 1.5* IQR, where IQR is the difference between the third quartile (Q3) and the first quartile (Q1);
[0044] For low outliers, replace low outliers with Q1, and for high outliers, replace high outliers with Q3.
[0045] The multi-factor authentication includes:
[0046] Password (Something You Know): The user first enters their password or PIN. This is the most basic form of authentication, but is generally not secure enough.
[0047] Mobile verification code (Something You Have): Generate a one-time password (OTP) through a mobile phone or other hardware device, such as Google Authenticator, SMS verification code, etc. This adds a physical factor and improves security.
[0048] Biometrics (Something You Are): uses biometric features such as fingerprints, facial recognition, and iris scans for identity verification. The advantage of biometric technology lies in its uniqueness and difficulty in replicating.
[0049] Hardware Token: Users can authenticate using a physical token, such as a USB key or smart card. These devices generate dynamic passwords or use cryptographic authentication to ensure account security.
[0050] S2, obtains the intensity data and risk impact data of the encryption process, and builds an encryption risk assessment model based on the BP neural network algorithm;
[0051] The strength data includes the data encryption strength coefficient, and the key risk impact data includes the key performance delay coefficient and the key fluctuation impact coefficient;
[0052] The data mining technology includes association rule mining, classification algorithm and cluster analysis. Association rule mining is used to discover the correlation between different factors in the encryption process, and the classification algorithm is used to classify the encryption strength data and risk impact data. Cluster analysis is used to cluster similar encryption processes, so as to obtain the strength data and risk impact data in the encryption process more comprehensively and accurately.
[0053] The Data Encryption Strength Factor provides a quantitative reference for enterprises to evaluate the security of encryption algorithms. By calculating this factor, enterprises can better understand the reliability of the encryption process and select appropriate encryption algorithms and strategies. In practical applications, this factor can help enterprises strike a balance between protecting data security and meeting business needs, ensuring the effectiveness and reliability of encryption technology.
[0054] The specific method for obtaining the data encryption strength coefficient is as follows:
[0055] Obtain the key length and algorithm complexity generated during the symmetric encryption process;
[0056] The size of the key space is calculated based on the generated key length;
[0057] The key strength index is obtained based on the ratio of the key space size to the largest key space size among all encryption algorithms and key lengths;
[0058] The algorithm strength factor is obtained by performing regression analysis based on the complexity of the algorithm and the power operation method used by the algorithm;
[0059] The key strength index, algorithm strength factor, and pre-acquired update frequency and security patch response time are combined to obtain the data encryption strength coefficient based on the data encryption strength coefficient calculation formula.
[0060] The power operation algorithm involves the operation of power (exponentiation result) in mathematics, mainly including multiplication, division and exponentiation of power.
[0061] The core idea of the fast power algorithm is to split the exponent into binary and use the power operation rules to perform fast calculations.
[0062] When the exponent is an even number, the power operation can be converted into the power operation of squaring the base and dividing the exponent by 2; when the exponent is an odd number, the base can be multiplied into the result first, and then the exponent can be subtracted by 1 and converted to an even number.
[0063] The specific steps of the algorithm are:
[0064] The initialization result is 1;
[0065] When the index is greater than 0, loop:
[0066] If the exponent is even, square the base and divide the exponent by 2;
[0067] If the exponent is an odd number, multiply the base by the result and subtract 1 from the exponent (since the base has already been multiplied once, the following operation can be considered an even power operation after squaring the base);
[0068] After the loop ends, the final result is obtained.
[0069] Algorithm complexity:
[0070] The time complexity of the fast exponentiation algorithm is O(logn), where n is the exponent.
[0071] Compared with the O(n) time complexity of brute force solution, the fast power algorithm has significant advantages in processing large exponential power operations.
[0072] The calculation formula of the key strength index is:
[0073]
[0074] The calculation formula of the data encryption strength coefficient is:
[0075]
[0076] in, is the key strength index, is the key length, is the maximum allowed key space, is the data encryption strength coefficient, is the algorithm strength factor, is the update frequency, Response time for security patches.
[0077] The data encryption strength factor has the following benefits for assessing encryption risk:
[0078] Assessing Security: The Data Encryption Strength Factor (DEF) is a quantitative indicator that provides a visual representation of the security level of an encryption algorithm. When assessing encryption risk, enterprises no longer rely solely on vague qualitative descriptions such as "high risk" or "low risk." Instead, they can use specific DEF values to accurately measure the security of encryption algorithms. For example, a DEF value of 0.8 might indicate relatively high security, while a DEF value of 0.3 might indicate a higher security risk. This quantitative approach helps enterprises more objectively compare the security differences between different encryption algorithms.
[0079] Assisted Algorithm Selection: When faced with multiple encryption algorithms, enterprises can use the data encryption strength coefficient to select the algorithm that best suits their needs. If the data handled by the enterprise is highly sensitive, such as financial institutions handling customer fund transaction data, an algorithm with a higher data encryption strength coefficient can be selected to ensure high data security. For data with less stringent security requirements, such as general internal notification documents, the coefficient can be used to select an encryption algorithm that is less costly but still provides sufficient security, thereby achieving a balance between security and cost.
[0080] Considering Updates and Maintenance: This factor factors in update frequency and security patch response time. This allows enterprises to fully consider the dynamic security of encryption algorithms when assessing encryption risk. Timely updates and rapid security patch response can effectively reduce the risk of encryption algorithm compromise. For example, even if an encryption algorithm initially performs well in terms of key strength index and algorithm strength factor, if its update frequency is low and its security patch response time is long, its data encryption strength factor may decrease, alerting enterprises to the high encryption risk associated with this algorithm.
[0081] Comprehensive reliability assessment: By combining multiple factors, such as key length and algorithm complexity, the data encryption strength coefficient is calculated, comprehensively evaluating the reliability of the encryption process. Key length and algorithm complexity reflect the encryption algorithm's inherent attack resistance, while update frequency and security patch response time reflect its ability to respond to new threats. This comprehensive assessment helps enterprises identify potential risks in encryption algorithms. For example, an algorithm may have a large key space but low algorithmic complexity, making it vulnerable to specific types of attacks. Alternatively, a complex algorithm may have been inactive for a long time, increasing encryption risks.
[0082] The Key Performance Delay Coefficient (KDP) is a comprehensive metric used to evaluate the performance of a key generation system. It takes into account multiple factors, including key generation latency, overall system processing capacity, and potential performance bottlenecks. Higher KDP values indicate greater key generation latency and poorer system performance within a given system processing capacity. Specifically, the KDP calculates the density of key generation delays in each time period and incorporates weighting factors for system processing capacity and performance bottlenecks to comprehensively assess the performance of the key generation system. This coefficient not only reflects the direct delay in key generation but also takes into account system resource utilization and potential performance limitations.
[0083] The specific method for obtaining the key performance delay coefficient is as follows:
[0084] Key performance evaluation is performed in a simulated environment to obtain key generation delay data for each time period. Time series analysis is performed on the measured key generation delay data to identify the time periods where system performance bottlenecks occur and calculate the delay density for each time period.
[0085] The delay density in all time periods is accumulated to obtain the total key generation delay density;
[0086] Calculate the average delay time based on the total key generation delay density and the total system operation time;
[0087] Measure the processor load and network bandwidth performance indicators in the simulation environment, calculate the overall system processing capacity, and calculate the key performance delay coefficient by combining the overall system processing capacity with the average delay time.
[0088] The calculation formula for the key generation delay density is:
[0089]
[0090] The overall processing capacity of the system is specifically:
[0091]
[0092] The calculation formula of the key performance delay coefficient is:
[0093]
[0094] in, for key generation latency density, is the total number of time periods during which the system is running. is the key generation delay time for the i-th time period, is the duration of the i-th time period, is the key performance delay coefficient, For the overall processing capacity of the system, is the processor load in the i-th time period, is the network bandwidth in the i-th time period.
[0095] The key performance delay factor has the following benefits for assessing encryption risk:
[0096] Accurately locate performance bottlenecks and risky periods: During the process of obtaining key performance delay coefficients, time series analysis is used to identify time periods where system performance bottlenecks occur. This helps enterprises pinpoint periods of potential encryption risk. For example, during peak business hours, key generation delays are more frequent, potentially indicating increased system vulnerability. Because delays can disrupt the encryption process, attackers could exploit these windows to conduct man-in-the-middle attacks or other malicious operations. By identifying these high-risk periods, enterprises can strengthen security monitoring and preventative measures during these times.
[0097] Quantifying encryption system performance risk: Calculating the total key generation delay density and average delay time quantifies the delays in the key generation process. Encryption risk is closely related to system performance. Excessive delays can prevent the encryption system from responding to security threats in a timely manner. For example, if the average delay of an encryption system is too long, it may not be able to quickly update keys or complete encryption operations in the face of malicious brute force attacks, thereby increasing the risk of data leakage. Using the key performance delay coefficient, enterprises can quantify this performance risk and intuitively understand the impact of encryption system performance on encryption risk.
[0098] Comprehensively consider the correlation between system resources and encryption risk: When calculating the key performance delay coefficient, overall system processing capacity indicators such as processor load and network bandwidth are also taken into account. This allows enterprises to comprehensively assess the impact of system resources on encryption risk. For example, when processor load is excessive or network bandwidth is insufficient, the key performance delay coefficient will increase accordingly, indicating that the encryption risk of the enterprise system will also increase under such resource constraints. Based on this information, enterprises can rationally allocate system resources, optimize the operating environment of the encryption system, and reduce encryption risks caused by insufficient system resources.
[0099] The key fluctuation impact coefficient is an important metric used to measure key stability and security. In cryptographic systems, keys are crucial for ensuring information security. The key fluctuation impact coefficient is primarily used to assess the degree of key volatility under the influence of various factors. From a stability perspective, it reflects the key's fluctuations in both time and space. By calculating the key fluctuation impact coefficient, this volatility can be quantified. From a security perspective, excessive key fluctuation may indicate a key is more vulnerable to cracking or attack. This instability in the key state may cause anomalies in the encryption and decryption processes, increasing security risks. This coefficient helps security personnel promptly identify potential security risks and provides an important basis for optimizing key systems.
[0100] The specific method for obtaining the key fluctuation influence coefficient is as follows:
[0101] Continuously collect key data at different nodes and record the key value of each node at each collection moment; the different nodes include key generation nodes, key distribution nodes, and key update nodes;
[0102] Based on the principle of Shannon entropy, the entropy value of the key data of each node at each collection moment is calculated, and the key entropy at different nodes at the same moment is marked;
[0103] Set a detection interval including several collection moments, and calculate the average value and standard deviation of the key entropy of each node at different moments within the detection interval;
[0104] Calculate the fluctuation coefficient of key entropy at different time nodes based on the mean value and standard deviation of key entropy;
[0105] The key fluctuation impact coefficient is calculated based on the fluctuation coefficient of the key entropy.
[0106] The selection of the detection interval includes the following requirements:
[0107] 1. Frequency and requirements of data collection:
[0108] Frequency requirements: The detection interval should be set based on the frequency of data collection. If data is collected very frequently (e.g., multiple times per second), the detection interval may need to be shorter to capture data changes promptly. Conversely, if data is collected less frequently (e.g., once a day), the detection interval can be extended accordingly.
[0109] Demand-oriented: The length of the detection interval is determined based on the specific needs of the analysis or monitoring. For example, if the focus is on short-term fluctuations in the data, the detection interval should be shorter; if the focus is on long-term trends, the detection interval can be longer.
[0110] 2. Data characteristics and stability:
[0111] Data stability: For data with high stability, a longer detection interval may be more appropriate because such data does not change much over a short period of time. For data with high volatility, a shorter detection interval may more accurately reflect the actual data.
[0112] Data distribution: Consider the distribution characteristics of the data, such as whether there are periodic changes, seasonal fluctuations, etc. These factors will affect the selection of the detection interval to ensure that these characteristics can be captured within the detection interval.
[0113] 3. Computing resources and efficiency:
[0114] Computing resources: The selection of the detection interval also needs to consider available computing resources. A shorter detection interval means more data points need to be processed, which may increase the computational burden. Therefore, when choosing the detection interval, it is necessary to balance the need for computing resources with the need for data accuracy.
[0115] Efficiency considerations: To improve analysis efficiency, an appropriate detection interval length is usually selected to reduce computing time and resource consumption while maintaining data accuracy.
[0116] The calculation formula of the average value of the key entropy is:
[0117]
[0118] The calculation formula of the standard deviation of the key entropy is:
[0119]
[0120] The calculation formula of the key fluctuation influence coefficient is:
[0121]
[0122] in, is the average value of key entropy, is the total number of moments in the detection interval, is the probability of the key appearing, is the standard deviation of the key entropy, is the key fluctuation influence coefficient.
[0123] The encryption risk assessment model is specifically:
[0124]
[0125] in, is the encryption risk assessment coefficient, is the preset data encryption strength coefficient weight factor, is the preset key performance delay coefficient weight factor, is the preset key fluctuation influence coefficient weight factor, is the data encryption strength coefficient, is the key performance delay coefficient, is the key fluctuation influence coefficient.
[0126] S3, screens digital letters of credit based on the output of the encryption risk assessment model, and performs blockchain storage on the screened digital letters of credit.
[0127] The digital confirmations are screened based on the output of the encryption risk assessment model, specifically:
[0128] When the encryption risk assessment coefficient of the digital confirmation is lower than the preset first risk threshold, the digital confirmation is determined to be qualified and passed;
[0129] When the encryption risk assessment value is lower than the preset second risk threshold and higher than the preset first risk threshold, a local secondary verification is performed, the digital confirmation is marked as a high-risk confirmation, and a hash function and symmetric encryption algorithm are selected for re-encryption;
[0130] When the encryption risk assessment value is higher than the preset second risk threshold, re-encryption combined with multi-party verification is triggered, and the re-encrypted data is split into N fragments and distributed to the regulator, auditor, and enterprise through Shamir secret sharing;
[0131] The digital confirmation and restoration verification of the fragments provided by 2 / 3 parties will be obtained. After the verification is passed, all parties will jointly sign to generate a multi-party verification certificate.
[0132] The blockchain evidence storage process for the screened digital letters is specifically as follows:
[0133] The screened digital confirmations are broken down into time slices and space slices according to the time dimension, classified and structured, and key information is extracted. The key information includes the confirmation number, the sender and recipient information, the specific content of the confirmation, and the timestamp.
[0134] Build a dual-chain hybrid architecture, which includes a classical chain and a quantum chain, and the quantum chain has a pre-embedded quantum-resistant signature layer;
[0135] The Classic Chain uses the SHA-3 hash algorithm to process the extracted key information and generate a unique hash value;
[0136] Generate a seed through a quantum random number generator, generate a public and private key pair based on lattice cryptography, write the public key hash into the classical chain, and shard the private key to the quantum secure hardware;
[0137] When a quantum computing threat is triggered, the quantum chain verification logic is automatically enabled, requiring that the stored evidence data must pass both classical hash verification and quantum signature verification.
[0138] Example 2, Figure 2 The present invention provides a digital letter of credit management system based on data mining, which includes the following modules: a data encryption module, a risk assessment model building module and a digital letter of credit screening and evidence storage module;
[0139] Data encryption module: collects and encrypts enterprise financial data to generate digital confirmations;
[0140] Risk assessment model building module: obtains the intensity data and risk impact data of the encryption process, and builds an encryption risk assessment model based on the BP neural network algorithm;
[0141] Digital confirmation screening and evidence storage module: used to screen digital confirmations based on the output of the encryption risk assessment model, and perform blockchain evidence storage on the screened digital confirmations.
[0142] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.
[0143] The above embodiments may be implemented in whole or in part through software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments may be implemented in whole or in part in the form of a computer program product.
[0144] Those skilled in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0145] In addition, each functional module in each embodiment of the present application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0146] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0147] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A digital confirmation management method based on data mining, characterized in that: The following steps are involved: Obtain enterprise financial data, encrypt the enterprise financial data and generate digital confirmation; Obtain the intensity data and risk impact data during the encryption process, and build an encryption risk assessment model based on the bp neural network algorithm; Strength data includes data encryption strength coefficient, which can be obtained as follows: Get the key length and algorithm complexity generated during symmetric encryption; Calculate the size of the key space based on the generated key length; The key strength index is obtained based on the ratio of the key space size to the largest key space size among all encryption algorithms; The calculation formula of key strength index is: in, is the key strength index, is the key length, It is the largest key space size among all encryption algorithms; The algorithm strength factor is obtained by performing regression analysis based on the complexity of the algorithm and the power operation method used by the algorithm; Calculate the data encryption strength coefficient by combining the key strength index and algorithm strength factor with the pre-acquired update frequency and security patch response time; The risk impact data includes the key performance delay coefficient, which can be obtained as follows: Obtain key generation delay data in each time period, perform time series analysis, identify the time period where the system generates performance bottlenecks, and calculate the delay density of each time period; The total key generation delay density is obtained by summing up the delay densities in all time periods; Calculate the average delay time based on the total key generation delay density and the total system operation time; Measure the processor load and network bandwidth performance indicators in the simulation environment, calculate the overall system processing capacity, combine the overall system processing capacity with the average delay time, and calculate the key performance delay coefficient; Digital confirmations are screened based on the output of the encrypted risk assessment model, and the screened digital confirmations are processed for blockchain storage.
2. The digital confirmation management method based on data mining according to claim 1 is characterized in that: The encryption of enterprise financial data to generate digital confirmation is specifically as follows: Collect corporate financial data, use the isnull() function to identify missing values in the data and fill them in; Identify outliers based on the box plot and replace outliers with upper or lower limits to obtain preprocessed corporate financial data; Based on the symmetric encryption algorithm, a symmetric key of fixed length is generated; Perform XOR operation on financial data and symmetric key to generate ciphertext; Generate an asymmetric key pair based on an asymmetric encryption algorithm, wherein the asymmetric key pair includes a public key and a private key; The symmetric key is encrypted according to the generated public key, and the encrypted symmetric key and the ciphertext generated by the symmetric encryption are stored in the financial system. At the same time, multi-factor authentication is forcibly enabled for all users in the financial system.
3. The digital confirmation management method based on data mining according to claim 2 is characterized in that: The risk impact data also includes a key fluctuation impact coefficient, and the specific acquisition method is as follows: At different nodes, key data is continuously collected, and the key value of each node at each collection moment is recorded; Calculate the entropy value of the key data of each node at each collection time, and mark the key entropy at different nodes at the same time; A detection interval including several collection moments is set, and the average value and standard deviation of the key entropy of each node at different moments are calculated within the detection interval, and the key fluctuation influence coefficient is calculated.
4. The digital confirmation management method based on data mining according to claim 3 is characterized in that: The digital confirmation is screened according to the output of the encryption risk assessment model, specifically: Setting a risk threshold, comparing the encrypted risk assessment coefficient of the digital confirmation with the risk threshold, and obtaining a comparison result, wherein the comparison result includes secondary verification and multi-party verification; Among them, in the secondary verification, the digital confirmation is marked as a high-risk confirmation, and a hash function and a symmetric encryption algorithm are selected for re-encryption; In multi-party verification, the re-encrypted data is split into N fragments and distributed to end customers through Shamir secret sharing. A threshold for digital confirmation restoration verification fragments is set. After the verification is passed, a multi-party verification certificate is generated.
5. The digital confirmation management method based on data mining according to claim 4 is characterized in that: The blockchain evidence storage process of the screened digital letter of credit is specifically as follows: The screened digital confirmations are decomposed into time slices and space slices according to the time dimension, classified and structured, and key information is extracted and stored; Build a dual-chain hybrid architecture, extract key information for processing, and generate a unique hash value; Generate seeds through quantum random number generator, generate public and private key pairs based on lattice cryptography, write public key hash into the classical chain, and shard the private key to quantum security hardware; When a quantum computing threat is triggered, the quantum chain verification logic is automatically enabled, through classical hash verification and quantum signature verification.
6. The digital confirmation management method based on data mining according to claim 5 is characterized in that: The calculation formula of the key generation delay density is: The calculation formula of the key performance delay coefficient is: in, For key generation latency density, is the total number of time periods during which the system is running, is the key generation delay time for the i-th time period, is the duration of the i-th time period, is the key performance delay coefficient, For the overall processing capacity of the system, is the processor load in the i-th time period, is the network bandwidth in the i-th time period.
7. The digital confirmation management method based on data mining according to claim 6 is characterized in that: The calculation formula of the average value of the key entropy is: The calculation formula of the standard deviation of the key entropy is: The calculation formula of the key fluctuation influence coefficient is: in, is the average value of key entropy, is the total number of moments in the detection interval, is the probability of the key appearing, is the standard deviation of the key entropy, is the key fluctuation influence coefficient.
8. A system for digital confirmation management method based on data mining as claimed in any one of claims 1 to 7, characterized in that: It includes the following modules: data encryption module, risk assessment model building module and digital confirmation screening and evidence storage module; Data encryption module: collects and acquires corporate financial data, encrypts the data and generates digital confirmations; Risk assessment model building module: obtains the intensity data and risk impact data in the encryption process, and builds an encryption risk assessment model based on the bp neural network algorithm; Digital confirmation screening and storage module: used to screen digital confirmations based on the output of the encryption risk assessment model, and perform blockchain storage processing on the screened digital confirmations.
Citation Information
Patent Citations
Domestic data protection method and system based on SM2 domestic cryptographic algorithm
CN115801239A
Enterprise risk assessment method, system and device and storage medium
CN116611690A
Block chain-based function management method and device, and storage medium
CN116842553A
High-speed encryption method and device for business data of electric power internet of things
CN117692257A