Cloud Computing-Based Unified Management System, Method and Storage Medium for Password Services

By obtaining the user's login status and information sensitivity level in the government cloud computing platform, re-verify the login password and determine whether you need to enter the password again, it solves the problem of inconsistent information sensitivity level that may be caused by automatic access to all application systems after logging in, reduces the risk of platform attacks and improves user operation convenience.

CN119696903BActive Publication Date: 2025-06-13HENAN RONGCHUANGHE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411878494.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-06-13
Estimated Expiration
2044-12-19

AI Technical Summary

Technical Problem

In cloud computing platforms in the government affairs field, users automatically save login information after logging in and grant permission to access all authorized application systems, which may lead to inconsistent information sensitivity levels, increasing the risk of platform attacks and data leakage, and also affecting users' service efficiency.

Method used

By obtaining the information sensitivity level and login status data of the user's current login application system, the login status coefficient is calculated. If the user switches to an application system with a higher information sensitivity level, re-verify the login password, and judge whether you need to enter the password again for the next login based on the login status coefficient.

Benefits of technology

It effectively reduces the risk of government affairs platforms being attacked and data leaked, improves the convenience of user operations, reduces the impact of user service efficiency, and realizes accurate permission control and security verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696903B_ABST
    Figure CN119696903B_ABST
Patent Text Reader

Abstract

The present invention discloses a unified management system, method and storage medium for password services based on cloud computing, which relates to the technical field of password management. If the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform is not the highest level, the first login status coefficient of the user in the currently logged in application system is obtained; and when the user switches to an application system with a higher preset information sensitivity level than the currently logged in application system, the latest login verification password information is determined and sent to the user for verification login; and the second login status coefficient during the verification login process of the user according to the latest login verification password information is obtained, and it is judged whether the user needs to input the password again for login when logging in next time. In this way, the risk of the government affairs platform being attacked and data leakage can be reduced, making it convenient for users to operate and reducing the impact on the user's work efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of password management, and particularly to a unified management system, method and storage medium for password services based on cloud computing. Background Art

[0002] Cloud computing is a technology that provides computing resources and services through the Internet. Users can obtain remote computing power, storage, network, and application resources on demand without having local hardware devices and infrastructure;

[0003] A unified management system for password services based on cloud computing is a technology that combines the management of login passwords on a service platform with cloud computing. Especially in the government affairs field, there are a large number of users. Relying on the powerful cloud computing ability to manage the passwords of each user logging in to the government affairs platform, efficient management can be achieved;

[0004] To facilitate user login, generally when a user logs in to an application system on a government affairs platform, the current login information will be automatically saved, and the user will be granted access to all authorized application systems on the platform. That is, after the user logs in to an application system and then transfers to other application systems, there is no need to log in again, realizing "one-point login, full-domain access", which simplifies the user's operation and also ensures the consistency of the user's identity in different application systems;

[0005] However, in the actual login process, the information sensitivity level corresponding to the application system that the user first logs in to may not be the highest. Blindly defaulting that the user can access all application systems on the government affairs platform may increase the risk of the government affairs platform being attacked and data leakage. And if password login is required every time when logging in to the government affairs platform, it may cause inconvenience to the user and affect the user's work efficiency. Summary of the Invention

[0006] The object of the present invention is to solve the above-mentioned problems, and provide a unified management system, method and storage medium for password services based on cloud computing.

[0007] In the first aspect of the implementation of the present invention, a unified management method for password services based on cloud computing is first proposed. The method includes:

[0008] Obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and determine whether the preset information sensitivity level of the currently logged-in application system is the highest level;

[0009] If the preset information sensitivity level of the currently logged-in application system is not the highest level, obtain the login status data of the user in the currently logged-in application system, and obtain the first login status coefficient according to the login status data; the login status data includes a login time deviation coefficient, a login behavior anomaly coefficient, a login network instability coefficient, and a current application system access coefficient;

[0010] When the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system, obtain the latest login verification password information according to the first login status coefficient and the preset login verification password information, and send the latest login verification password information to the user for verification login;

[0011] Obtain the login status data during the process of the user verifying the login according to the latest login verification password information, obtain the second login status coefficient, and combine the preset login status coefficient threshold to determine whether the user needs to enter the password again for login when logging in next time.

[0012] Optionally, the login behavior anomaly coefficient includes:

[0013] Obtain the total number of times the user enters the password incorrectly and the duration of each incorrect password entry during the process of the user logging in to the current application system on the government affairs platform, and perform a time series based on the time to obtain an incorrect password entry duration time series; and calculate the mean value of the incorrect password entry duration time series as the input time error coefficient;

[0014] Obtain the total number of times the user enters the password, calculate the time interval between adjacent password entries, obtain a password entry time interval series, calculate the mean value of the password entry time interval series, and divide the mean value by the preset input interval to obtain an input frequency coefficient;

[0015] Perform normalization processing on the input time error coefficient and the input frequency coefficient, and obtain the login behavior anomaly coefficient according to the normalized input time error coefficient and input frequency coefficient.

[0016] Optionally, the login time deviation coefficient and the current application system access coefficient include:

[0017] Obtain the total duration of the user's login during the process of the user logging in to the current application system on the government affairs platform, calculate the absolute difference between the total duration of the login and the preset login duration, and divide the absolute difference by the preset login duration to obtain the login time deviation coefficient;

[0018] Obtain the time interval between each click in the current application system during the user's login on the government affairs platform, calculate the difference between the preset fastest click time interval and the click time interval, and calculate the sum of all differences to obtain a click speed anomaly coefficient;

[0019] Obtain the total number of function modules clicked in the current application system, and multiply the total number of clicked function modules by the click speed anomaly coefficient to obtain the current application system access coefficient.

[0020] Optionally, the login network instability coefficient includes:

[0021] Obtain the network signal values at different times during the process of the user logging in to the current application system on the government affairs platform, sequence them based on time to obtain a network signal sequence, calculate the standard deviation of the network signal sequence, and use the standard deviation as the signal fluctuation value;

[0022] Compare each signal value in the network signal sequence with a preset minimum signal value, and mark the signal values less than the preset minimum signal value as 0; divide the total number of 0s in the network signal sequence by the total number of signal values as the signal disconnection value;

[0023] Perform normalization processing on the signal fluctuation value and the signal disconnection value, and obtain the login network instability coefficient based on the normalized signal fluctuation value and signal disconnection value.

[0024] Optionally, obtaining the first login status coefficient according to the login status data includes:

[0025] Take the login time deviation coefficient, the login behavior anomaly coefficient, the login network instability coefficient, and the current application system access coefficient as the input items of the fuzzy rule, and take the first login status coefficient as the output item;

[0026] Fuzzify the input items and convert the precise input values into fuzzy sets;

[0027] Define fuzzy rules according to the fuzzy sets of the input items and map the input items to the output items;

[0028] Infer the input items according to the fuzzy rules to determine the fuzzy value of the output item;

[0029] For each rule, calculate the membership degree of its antecedent and take the minimum value as the activation degree of the rule;

[0030] Synthesize the results of all rules and calculate the fuzzy set of the output item;

[0031] Convert the fuzzy value of the output item into a precise value, and output the first login status coefficient according to the result of defuzzification.

[0032] Optionally, obtaining the latest login verification password information according to the first login status coefficient and the preset login verification password information includes:

[0033] Split the verification password action of the preset login verification password information according to the preset verification password action library, assign different preset importance values to each split action, and add up the preset importance values of all actions to obtain a preliminary password importance value;

[0034] Calculate the sum of the first login status coefficient and the value 1, multiply the calculated sum by the preliminary password importance value to obtain the final password importance value, and select from the preset verification password action library according to the final password importance value to obtain the latest login verification password information.

[0035] Optionally, determining whether the user needs to re-enter the password for login when logging in next time in combination with the preset login status coefficient threshold includes:

[0036] Obtain the login time deviation coefficient, login behavior anomaly coefficient, login network instability coefficient, and current application system access coefficient during the verification login process of the user according to the latest login verification password information to obtain a second login status coefficient, and compare the second login status coefficient with the preset login status coefficient threshold;

[0037] If the second login status coefficient is less than the preset login status coefficient threshold, the government affairs platform automatically saves the user's login information, and by default, the user can directly log in when logging in next time without needing to re-enter the password to log in to the platform;

[0038] If the second login status coefficient is not less than the preset login status coefficient threshold, the government affairs platform automatically does not save the user's login information, and the user may still need to re-enter the password to log in to the platform when logging in next time.

[0039] In the second aspect of the implementation of the present invention, a unified management system for password services based on cloud computing is proposed. The system includes:

[0040] Judgment module: Obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and judge whether the preset information sensitivity level of the currently logged-in application system is the highest level;

[0041] Login status coefficient module: If the preset information sensitivity level of the currently logged-in application system is not the highest level, obtain the login status data of the user in the currently logged-in application system, and obtain the first login status coefficient according to the login status data; the login status data includes the login time deviation coefficient, login behavior anomaly coefficient, login network instability coefficient, and current application system access coefficient;

[0042] Latest verification module: When the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system, obtain the latest login verification password information according to the first login status coefficient and the preset login verification password information, and send the latest login verification password information to the user for verification login;

[0043] The judgment management module: obtains the login status data during the verification login process when the user verifies the login according to the latest login verification password information, obtains the second login status coefficient, and combines the preset login status coefficient threshold to judge whether the user needs to enter the password again for login when logging in next time.

[0044] In the third aspect of the implementation of the present invention, a computer-readable storage medium is proposed. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in any one of the above is implemented.

[0045] The beneficial effects of the present invention:

[0046] The present invention proposes a unified management system, method and storage medium for password services based on cloud computing, which can adjust the login passwords of other application systems according to the actual login status of the current application system on the government affairs platform, reduce the risks of the government affairs platform being attacked and data leakage, and can judge whether password login is required every time the user logs in to the government affairs domain platform according to the actual situation, making it convenient for users to operate and reducing the impact on user work efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The following further describes the present invention with reference to the accompanying drawings.

[0048] Figure 1 is a flowchart of a unified management method for password services based on cloud computing;

[0049] Figure 2 is a framework diagram of a unified management system for password services based on cloud computing. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0051] Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0052] The embodiments of the present invention provide a unified management method for password services based on cloud computing. Refer to Figure 1 , Figure 1 is a flowchart of a unified management method for password services based on cloud computing provided by the embodiments of the present invention. The method includes the following steps:

[0053] Obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and determine whether the preset information sensitivity level of the currently logged-in application system is the highest level;

[0054] If the preset information sensitivity level of the currently logged-in application system is not the highest level, obtain the login status data of the user in the currently logged-in application system, and obtain the first login status coefficient according to the login status data; the login status data includes the login time deviation coefficient, the abnormal login behavior coefficient, the unstable login network coefficient, and the current application system access coefficient;

[0055] When the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system, obtain the latest login verification password information according to the first login status coefficient and the preset login verification password information, and send the latest login verification password information to the user for verification login;

[0056] Obtain the login status data during the verification login process of the user according to the latest login verification password information, obtain the second login status coefficient, and combine the preset login status coefficient threshold to judge whether the user needs to enter the password again for login when logging in next time.

[0057] Based on the unified password service management method based on cloud computing provided by the embodiments of the present invention, through the above method, it is possible to adjust the login passwords of other application systems according to the actual login status of the current application system on the government affairs platform, reduce the risk of the government affairs platform being attacked and data leakage, and can judge whether the user needs to perform password login every time when logging in to the government affairs domain platform according to the actual situation, making the user operation convenient and reducing the impact on the user's work efficiency.

[0058] In one embodiment, judging whether the preset information sensitivity level of the currently logged-in application system is the highest level includes:

[0059] If the preset information sensitivity level of the currently logged-in application system is the highest level, at this time, the user will be granted the access right to directly access all other application systems, and there is no need to send an additional login password for verification login;

[0060] If the preset information sensitivity level of the currently logged-in application system is not the highest level, at this time, obtain the login status data of the user in the currently logged-in application system, obtain the first login status coefficient according to the login status data, and re-send the password for login verification when the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system.

[0061] It should be noted that the preset information sensitivity level is set by professionals according to the actual situation, which can comprehensively consider factors such as the nature of the data, legal and regulatory requirements, business needs, and potential risks, reasonably evaluate and classify the data sensitivity of different application systems on the government affairs platform, and determine different sensitivity levels. The specific preset information sensitivity level depends on the actual situation and is not limited and elaborated here.

[0062] In one implementation method, by dynamically evaluating the user login status and the sensitivity level of the application system, precise permission control and security verification are achieved; this method effectively reduces the risk of unauthorized access of low-sensitivity information systems to high-sensitivity information, prevents users from accessing sensitive data without knowing it, thereby reducing the possibility of data leakage; at the same time, it simplifies the login process of high-sensitivity systems and improves the user experience, enabling users to maintain security while effectively improving work efficiency when dealing with high-risk information. This flexible permission management method not only enhances the security of the government affairs platform but also provides convenience for users, contributing to the establishment of a more trustworthy digital government environment.

[0063] In one embodiment, the login behavior anomaly coefficient includes:

[0064] Obtain the total number of times the user incorrectly enters the password and the duration of each incorrect password entry during the process of the user logging in to the current application system on the government affairs platform, and sequence them based on time to obtain the incorrect password entry duration sequence; and calculate the mean value of the incorrect password entry duration sequence as the input time error coefficient.

[0065] Obtain the total number of times the user enters the password, calculate the time interval between adjacent password entries to obtain the password entry time interval sequence, calculate the mean value of the password entry time interval sequence, and divide the mean value by the preset input interval to obtain the input frequency coefficient.

[0066] Normalize the input time error coefficient and the input frequency coefficient, and obtain the login behavior anomaly coefficient based on the normalized input time error coefficient and input frequency coefficient.

[0067] It should be noted that obtaining the login behavior anomaly coefficient based on the normalized input time error coefficient and input frequency coefficient can be, for example, In the formula, Dax is the login behavior anomaly coefficient, Wv and Pn are the normalized input time error coefficient and input frequency coefficient respectively, a1 and a2 are the preset proportionality coefficients of Wv and Pn respectively, and both f1 and f2 are greater than 0; in addition, a1 and a2 are set by professionals according to the actual situation. Generally, the sum of a1 and a2 is 1. For example, a1 and a2 can be 0.5 and 0.5 respectively, or other numbers, and the specific values are not limited.

[0068] It should be noted that, through the login log records of users on the government affairs platform, the timestamps and durations of users' input passwords are automatically collected to construct a sequence of error input durations; by monitoring the time differences between each password input, a sequence of password input intervals is formed, and other acquisition methods can also be used, which will not be specifically limited and elaborated; in addition, the preset input interval is set by professionals according to the actual situation, which will not be specifically elaborated and limited.

[0069] It should be noted that the login behavior anomaly coefficient refers to the average duration of the user's incorrect password input and the interval time between the user's password inputs during the process of the user logging in to the current application system on the government affairs platform; if the average duration of the user's incorrect password input is longer and the interval time between the user's password inputs is longer, it indicates that the login status during the process of the user logging in to the current application system on the government affairs platform is worse. When the user switches to an application system with a higher preset information sensitivity level than the current logged-in application system, it is necessary to resend the login verification password information for verification login, and the resending of the login verification password information is more complex. The reason is that when the user logs in to the current application system on the government affairs platform, the longer the average duration of incorrect password input and the password input interval time, it usually means that the user encounters more difficulties during the login process, which may indicate a lower familiarity with the system or potential security risks, such as the possibility of password forgetting or account theft. Such a poor login status directly affects the security of the system. Therefore, when the user switches to an application system with a higher preset information sensitivity level, it is necessary to resend the login verification password information and perform complex verification. This is because high-sensitivity application systems usually process more confidential and important information. If the user's login status is poor, the additional verification steps can effectively reduce the risk of unauthorized access to sensitive information, ensuring that only users who have passed strict identity verification can access these systems, thereby protecting the security and integrity of the data.

[0070] In one implementation manner, through the above calculation method, the login behavior anomaly coefficient can be directly and comprehensively calculated, making the judgment of the subsequent login status coefficient more accurate.

[0071] In an embodiment, the login time deviation coefficient and the current application system access coefficient include:

[0072] Obtain the total duration of the user's login during the process of the user logging in to the current application system on the government affairs platform, calculate the absolute difference between the total duration of the login and the preset login duration, and divide the absolute difference by the preset login duration to obtain the login time deviation coefficient;

[0073] Obtain the time interval between each click in the current application system during the user's login on the government affairs platform, calculate the difference between the preset fastest click time interval and the click time interval, and calculate the sum of all differences to obtain the click speed anomaly coefficient;

[0074] Obtain the total number of function modules clicked in the current application system, and multiply the total number of function modules clicked by the click speed anomaly coefficient to obtain the current application system access coefficient.

[0075] It should be noted that the preset login duration and the preset fastest click time interval are set by professionals according to the actual situation, and will not be elaborated and limited here; in addition, during the process of the user logging in to the current application system on the government affairs platform, the total login duration can be obtained through the login log record on the government affairs platform, or it can be obtained by other means, which will not be limited and elaborated here;

[0076] It should be noted that the time interval between each click and the total number of function modules clicked in the current application system can be obtained through the login log record on the government affairs platform, or it can be obtained by other means, which will not be limited and elaborated here;

[0077] It should be noted that the login time deviation coefficient refers to the degree to which the actual login duration of the user deviates from the preset login duration during the process of logging in to the current application system on the government affairs platform. If the degree of deviation of the actual login duration from the preset login duration is greater, it means that the login status during the process of logging in to the current application system on the government affairs platform is worse. When the user switches to an application system with a higher preset information sensitivity level than the current logged-in application system, it is necessary to resend the login verification password information for verification login, and the resending of the login verification password information is more complex. The reason is that the login time deviation coefficient represents the difference between the actual login duration of the user on the government affairs platform and the preset normal login time; if the actual login time significantly deviates from the preset time (for example, too long), this usually indicates that the user has encountered problems during the login process, such as entering the wrong password multiple times or needing to re-enter the verification code; this situation may reflect the abnormality of the user's operation or the existence of potential security risks, such as the account being tried to be logged in by an unfamiliar person; therefore, when the user switches to a system with a higher preset information sensitivity level than the current application system, in order to ensure security, the system will resend more complex login verification password information; this is because the sensitive information system requires higher access security to prevent unauthorized access and data leakage, ensure that the visitor is a genuine authorized user, and reduce security risks.

[0078] It should be noted that the current application system access coefficient refers to the degree to which the time interval between each click in the current application system during the user's login on the government affairs platform is faster than the preset fastest click time interval and the total number of function modules clicked; if the degree to which the click time interval is faster than the preset fastest click time interval is greater and the total number of function modules clicked is greater, it indicates that the login status during the process of logging in to the current application system on the government affairs platform is worse. When the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system, it is necessary to resend the login verification password information for verification login, and resending the login verification password information is more complex. The reason is that this may indicate that the user's operation speed is abnormal and exceeds the usage behavior of normal users. This situation may mean that the user is operating through an automated script, or attempting to quickly browse and operate a large number of function modules to detect system vulnerabilities, or even may be performing malicious behavior. Therefore, this login status is regarded as abnormal and there are potential security risks.

[0079] In one embodiment, the login network instability coefficient includes:

[0080] Obtain the network signal values at different times during the process of the user logging in to the current application system on the government affairs platform, sequence them based on time to obtain a network signal sequence, calculate the standard deviation of the network signal sequence, and use the standard deviation as the signal fluctuation value;

[0081] Compare each signal value in the network signal sequence with the preset minimum signal value, and mark the signal values less than the preset minimum signal value as 0; divide the total number of 0s in the network signal sequence by the total number of signal values as the signal disconnection value;

[0082] Perform normalization processing on the signal fluctuation value and the signal disconnection value, and obtain the login network instability coefficient based on the normalized signal fluctuation value and signal disconnection value.

[0083] It should be noted that the present invention can calculate the login network instability coefficient using the following formula. The calculation expression is: QW = b1×ED + b2×RF; where QW is the login network instability coefficient, ED and RF are the normalized signal fluctuation value and signal disconnection value respectively, b1 and b2 are the preset proportionality coefficients of ED and RF respectively, and both b1 and b2 are greater than 0.

[0084] It should be noted that b1 and b2 are also set by professionals according to the actual situation. Generally, the sum of b1 and b2 is 1. For example, b1 and b2 can be 0.5 and 0.5 respectively, or other numbers, and specific values are not limited.

[0085] It should be noted that the preset minimum signal value is set by professionals according to the actual situation, and no specific limitations and elaborations are made here; the network signal value refers to the signal strength, which represents the network signal strength of the device logging in to the government affairs platform in the current application system. For example, it can be the WI-FI signal strength value, or it can be others, depending on the actual situation; in addition, during the process of a user logging in to the current application system on the government affairs platform, the network signal values at different times can be obtained through the login logs on the government affairs platform, or it can be obtained by other means, and no specific limitations and elaborations are made here.

[0086] It should be noted that the login network instability coefficient refers to the degree of network fluctuation and the degree of network disconnection during the process of a user logging in to the current application system on the government affairs platform. If the degree of network fluctuation is greater and the degree of network disconnection is greater, it means that the login status during the process of logging in to the current application system on the government affairs platform is worse. When the user switches to an application system with a higher preset information sensitivity level than the current logged-in application system, it is necessary to resend the login verification password information for verification login, and the resending of the login verification password information is more complex. The reason is that the login network instability coefficient reflects the network stability of the user during the login process on the government affairs platform. If the degree of network fluctuation is greater or the number of network disconnections increases, it means that the user may encounter frequent interruptions or delays during login, which will not only increase the time for the user to input the password, but also may cause multiple login failures, thus reducing the reliability of successful login; when the user switches to an application system with a higher information sensitivity level, the system will require the resending of the login verification password information to ensure the security of identity verification. This process requires more complex operations because high-sensitivity systems usually carry more important data and functions, so the security requirements are higher. The system must verify the user's identity in an unstable network environment to prevent potential unauthorized access and data leakage risks. Such additional verification steps help protect the security of sensitive information and ensure that only authenticated users can access higher-level application systems, thereby improving the security of the entire government affairs platform.

[0087] In one embodiment, obtaining the first login status coefficient according to the login status data includes:

[0088] Taking the login time deviation coefficient, the login behavior anomaly coefficient, the login network instability coefficient, and the current application system access coefficient as the input items of the fuzzy rule, and taking the first login status coefficient as the output item;

[0089] Fuzzifying the input items to convert the precise input values into fuzzy sets;

[0090] Defining fuzzy rules according to the fuzzy sets of the input items to map the input items to the output item;

[0091] According to the fuzzy rules, reason about the input items to determine the fuzzy value of the output item;

[0092] For each rule, calculate the membership degree of its antecedent and take the minimum value as the activation degree of the rule;

[0093] Synthesize the results of all rules to calculate the fuzzy set of the output item;

[0094] Convert the fuzzy value of the output item into an exact value, and output the first login status coefficient according to the result of defuzzification.

[0095] It should be noted that the above steps are explained as follows:

[0096] First, determine the login time deviation coefficient, login behavior anomaly coefficient, login network instability coefficient, and current application system access coefficient as the input items of the fuzzy rules; in this way, the influence of multiple factors on the login status can be comprehensively considered;

[0097] Fuzzification: In this stage, convert the exact value of each input item into a fuzzy set. For example, the login time deviation coefficient can be divided into fuzzy levels such as "low", "medium", and "high" to better reflect the actual user behavior status;

[0098] Define fuzzy rules: According to the fuzzy sets of the input items, define fuzzy rules. For example, if the "login behavior anomaly coefficient" is high and the "current application system access coefficient" is high, then the output "first login status coefficient" should also be in a high state. These rules will help understand the influence of different input combinations on the output.

[0099] Inference process: In this step, through fuzzy inference, map the input items to the output items. Use the fuzzy rules to calculate the fuzzy values of the output items in different situations and evaluate the overall login status of the user.

[0100] Calculate the rule activation degree: For each rule, calculate the membership degree of its antecedent part and take its minimum value as the activation degree of the rule. In this way, it can be determined which rules have the greatest influence on the output item.

[0101] Result synthesis: Synthesize the activation degrees of all rules to calculate the fuzzy set of the output item. This step ensures that the comprehensive influence of all input items is fully considered.

[0102] Defuzzification: Finally, convert the fuzzy value of the output item into an exact value to obtain the first login status coefficient. Usually, techniques such as the centroid method or the maximum membership degree method are used for defuzzification.

[0103] In one implementation method, the above method can handle uncertainty and ambiguity, especially when facing complex user behaviors. By integrating multiple factors and using fuzzy logic, the system can more accurately evaluate the user's login status and timely identify potential abnormal behaviors.

[0104] In one embodiment, obtaining the latest login verification password information according to the first login status coefficient and the preset login verification password information includes:

[0105] Split the verification password actions of the preset login verification password information according to the preset verification password action library, assign different preset importance values to each split action, and add up the preset importance values of all actions to obtain the preliminary password importance value;

[0106] Calculate the sum of the first login status coefficient and the value 1, multiply the calculated sum by the preliminary password importance value to obtain the final password importance value, and select from the preset verification password action library according to the final password importance value to obtain the latest login verification password information.

[0107] It should be noted that the preset login verification password information, the preset verification password action library, and the preset importance value of each action are set by professionals according to the actual situation. For example, the preset importance value of an ordinary digital login password is 0.5, and the preset importance value of a face verification password is 0.7, etc. The specific numbers are determined according to the actual situation and are not limited and elaborated; in addition, in addition to face actions, the preset verification password action library also includes fingerprint password verification, voice verification, etc., which are specifically determined according to the actual situation and are not limited and elaborated;

[0108] In one implementation method, through the above method, it is possible to obtain the verification password information when the user switches to an application system with a higher sensitivity level than the preset information of the currently logged-in application system according to the actual situation, which is more in line with the actual situation and reduces the risk of data leakage.

[0109] In one embodiment, determining whether the user needs to enter the password again for the next login in combination with the preset login status coefficient threshold includes:

[0110] Obtain the login time deviation coefficient, login behavior anomaly coefficient, login network instability coefficient, and current application system access coefficient during the verification login process of the user according to the latest login verification password information, obtain the second login status coefficient, and compare the second login status coefficient with the preset login status coefficient threshold;

[0111] If the second login status coefficient is less than the preset login status coefficient threshold, the government affairs platform automatically saves the user's login information and defaults that the user can directly log in for the next login without entering the password again to log in to the platform;

[0112] If the second login status coefficient is not less than the preset login status coefficient threshold, the government affairs platform automatically does not save the user's login information, and the user may still need to enter the password again to log in to the platform when logging in next time.

[0113] It should be noted that the preset login status coefficient threshold is set by professionals according to the actual situation, which is determined according to the actual situation and will not be limited or elaborated; and the password that the user needs to enter when logging in next time is generally the default initial password of the government affairs platform, such as identity card information, verification code, etc., which is determined according to the actual situation and will not be limited or elaborated.

[0114] In one implementation manner, it can balance the user experience and system security; by flexibly determining whether to re-enter the password according to the user's login status coefficient, the system can simplify the login process and improve the user's convenience without sacrificing security; when the user's login status is good, they can quickly enter the system when logging in next time, reducing unnecessary verification steps, making it convenient for users to operate and reducing the impact on the user's work efficiency; while when detecting anomalies or potential risks, it is mandatory to require re-verification to enhance the account protection measures; this intelligent management method effectively improves the security protection level and ensures the overall security and availability of the government affairs platform.

[0115] Based on the same inventive concept, the embodiment of the present invention also provides a unified management system for password services based on cloud computing. See Figure 2 , Figure 2 is the framework diagram of the unified management system for password services based on cloud computing provided by the embodiment of the present invention. The system includes:

[0116] Judgment module: Obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and judge whether the preset information sensitivity level of the currently logged-in application system is the highest level;

[0117] Login status coefficient module: If the preset information sensitivity level of the currently logged-in application system is not the highest level, obtain the login status data of the user in the currently logged-in application system, and obtain the first login status coefficient according to the login status data; the login status data includes the login time deviation coefficient, the login behavior anomaly coefficient, the login network instability coefficient, and the current application system access coefficient;

[0118] Latest verification module: When the user switches to an application system with a higher preset information sensitivity level than the currently logged-in application system, obtain the latest login verification password information according to the first login status coefficient and the preset login verification password information, and send the latest login verification password information to the user for verification login;

[0119] Judgment management module: obtain the login status data of the user during the verification login process according to the latest login verification password information, obtain the second login status coefficient, and combine the preset login status coefficient threshold to determine whether the user needs to enter the password again to log in next time.

[0120] Based on the cloud computing-based unified management system for password services provided by the embodiment of the present invention, through the above method, it is possible to adjust the login passwords of other application systems according to the actual login status of the current application system on the government affairs platform, thereby reducing the risk of the government affairs platform being attacked and data leaks, and can determine whether a user needs to log in with a password every time he logs in to the government affairs platform according to the actual situation, thereby making it convenient for users to operate and reducing the impact on user efficiency.

[0121] In another embodiment provided by the present invention, a computer-readable storage medium is also provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned cloud computing-based unified management methods for cryptographic services are implemented.

[0122] In another embodiment provided by the present invention, a computer program product including instructions is also provided, which, when executed on a computer, enables the computer to execute any unified management of cryptographic services based on cloud computing in the above-mentioned embodiments.

[0123] The above is a detailed description of an embodiment of the present invention, but the content is only a preferred embodiment of the present invention and cannot be considered to limit the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.

Claims

1. A unified management method for cryptographic services based on cloud computing, characterized in that: The following steps are involved: Obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and determine whether the preset information sensitivity level of the application system currently logged in is the highest level; If the preset information sensitivity level of the currently logged-in application system is not the highest level, the user's login status data in the currently logged-in application system is obtained, and a first login status coefficient is obtained according to the login status data; the login status data includes a login time deviation coefficient, a login behavior abnormality coefficient, a login network instability coefficient, and a current application system access coefficient; When the user switches to an application system with a higher information sensitivity level than the currently logged-in application system, the latest login verification password information is obtained according to the first login state coefficient and the preset login verification password information, and the latest login verification password information is sent to the user for verification login; Acquire the login status data of the user during the verification login process according to the latest login verification password information, obtain the second login status coefficient, and determine whether the user needs to enter the password again to log in next time in combination with the preset login status coefficient threshold; Obtaining the first login status coefficient according to the login status data includes: The login time deviation coefficient, login behavior abnormality coefficient, login network instability coefficient and current application system access coefficient are used as input items of fuzzy rules, and the first login state coefficient is used as output item; Fuzzify the input items and convert the exact input values ​​into fuzzy sets; Define fuzzy rules based on the fuzzy sets of input items to map input items to output items; According to the fuzzy rules, the input items are inferred to determine the fuzzy value of the output items; For each rule, calculate the membership of its predecessor and take the minimum value as the activation of the rule; Synthesize the results of all rules and calculate the fuzzy set of output items; Convert the fuzzy value of the output item into an accurate value, and output the first login state coefficient according to the defuzzification result; The latest login verification password information is obtained according to the first login state coefficient and the preset login verification password information, including: Split the password verification action of the preset login verification password information according to the preset password verification action library, assign a different preset importance value to each of the split actions, and add the preset importance values ​​of all actions to obtain a preliminary password importance value; Calculate the sum of the first login state coefficient and the value 1, and multiply the calculated sum by the preliminary password importance value to obtain the final password importance value, and select from the preset verification password action library according to the final password importance value to obtain the latest login verification password information.

2. The unified management method of cryptographic services based on cloud computing according to claim 1, characterized in that: The login behavior abnormality coefficient includes: Obtain the total number of times the user incorrectly enters the password and the duration of each incorrect password input during the process of the user logging into the current application system on the government affairs platform, and sequence them based on time to obtain the sequence of duration of incorrect password input; And calculate the mean of the duration series of incorrectly input passwords as the input time error coefficient; Obtain the total number of times the user enters the password, and calculate the time interval between two adjacent password inputs to obtain a password input time interval sequence, calculate the mean of the password input time interval sequence, and divide the mean by the preset input interval to obtain an input frequency coefficient; The input time error coefficient and the input frequency coefficient are normalized, and the login behavior abnormality coefficient is obtained according to the normalized input time error coefficient and the input frequency coefficient.

3. The unified management method of cryptographic services based on cloud computing according to claim 1, characterized in that: The login time deviation coefficient includes: The total duration of the user's login in the current application system on the government platform is obtained, and the absolute difference between the total login duration and the preset login duration is calculated, and the absolute difference is divided by the preset login duration to obtain the login time deviation coefficient.

4. The unified management method of cryptographic services based on cloud computing according to claim 1, characterized in that: The current application system access coefficient includes: Obtain the time interval of each click in the current application system when the user logs in to the government affairs platform, calculate the difference between the preset fastest click time interval and the click time interval, and calculate the sum of all differences to obtain the click speed abnormality coefficient; The total number of function modules clicked in the current application system is obtained, and the total number of function modules clicked is multiplied by the click speed abnormality coefficient to obtain the current application system access coefficient.

5. The unified management method of cryptographic services based on cloud computing according to claim 1, characterized in that: The login network instability coefficient includes: Obtain the network signal values ​​at different times when the user logs into the current application system on the government affairs platform, and perform sequence analysis based on time to obtain the network signal sequence, calculate the standard deviation of the network signal sequence, and use the standard deviation as the signal fluctuation value; Compare each signal value in the network signal sequence with a preset minimum signal value, and mark the signal value less than the preset minimum signal value as 0; divide the total number of 0s in the network signal sequence by the total number of signal values ​​to obtain the signal disconnection value; The signal fluctuation value and the signal disconnection value are normalized, and the login network instability coefficient is obtained according to the normalized signal fluctuation value and signal disconnection value.

6. The unified management method of cryptographic services based on cloud computing according to claim 1, characterized in that: Combining the preset login status coefficient threshold to determine whether the user needs to enter the password again to log in next time includes: Obtain the login time deviation coefficient, login behavior abnormality coefficient, login network instability coefficient and current application system access coefficient of the user in the process of verifying the login according to the latest login verification password information, obtain the second login state coefficient, and compare the second login state coefficient with the preset login state coefficient threshold; If the second login status coefficient is less than the preset login status coefficient threshold, the government affairs platform automatically saves the user's login information, and the default user can log in directly the next time without having to enter the password to log in to the platform again; If the second login status coefficient is not less than the preset login status coefficient threshold, the government affairs platform will automatically not save the user's login information, and the user will still need to enter the password again to log in to the platform the next time.

7. A unified management system for cryptographic services based on cloud computing, used to implement the unified management method for cryptographic services based on cloud computing according to any one of claims 1 to 6, characterized in that: The system comprises: Judgment module: obtain the preset information sensitivity level of the application system currently logged in by the user on the government affairs platform, and judge whether the preset information sensitivity level of the application system currently logged in is the highest level; Login status coefficient module: if the preset information sensitivity level of the currently logged-in application system is not the highest level, the user's login status data in the currently logged-in application system is obtained, and the first login status coefficient is obtained according to the login status data; the login status data includes the login time deviation coefficient, the login behavior abnormality coefficient, the login network instability coefficient and the current application system access coefficient; Latest verification module: when the user switches to an application system with a higher information sensitivity level than the currently logged-in application system, the latest login verification password information is obtained according to the first login state coefficient and the preset login verification password information, and the latest login verification password information is sent to the user for verification login; Judgment management module: obtain the login status data of the user during the verification login process according to the latest login verification password information, obtain the second login status coefficient, and combine the preset login status coefficient threshold to determine whether the user needs to enter the password again to log in next time.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Application login verification method, device and system

    CN110912901A

  • Identity verification method and device, computer equipment and readable storage medium

    CN111343168A