Decentralized management method, system and storage medium for user registration
By monitoring and analyzing the security indicators and indexes of the registration platform and user behavior data in real time, the problems of the operating risks of the registration platform and insufficient user data security in the existing technology are solved, and the security of the registration platform and user data protection effect are achieved.
Patent Information
- Application Number
- CN202510226297.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-27
AI Technical Summary
During the existing decentralized user account management process, the risk of the registration platform operation leads to the failure of user registration, and the registration data faces the risk of tampering and leaking.
By monitoring the security performance data and user behavior data of the registration platform in real time, the registration platform operation security indicators and user registration security index are analyzed, and compared with the preset definition values and thresholds. If the indicators or indexes are insufficient, warning prompts or additional verifications are performed to ensure that the user data is stored in the blockchain safely.
It effectively improves the security of the registration platform, reduces the risks of user registration failure and data leakage, and ensures the security of user data during transmission and storage.
Smart Images

Figure CN119728080B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptographic data security processing, and specifically to a decentralized management method, system and storage medium for user registration. Background Art
[0002] At present, with the rapid development of Internet technology, user identity management and data storage are facing increasingly complex challenges. With the frequent occurrence of user data leakage, privacy protection has become an important consideration in the design of user registration systems. Cryptography technology is gradually being applied to decentralized identity management to ensure that users do not disclose personal information when registering, and to ensure the integrity and security of user data.
[0003] For example, the invention patent with announcement number CN112035892B announces an account management method for a decentralized electronic contract notarization platform, which specifically includes an account registration method, an account retrieval method, and an account modification method. It obtains an account creation request sent by a user or an existing electronic contract platform, establishes an account after successfully authenticating the user identity, and encrypts the user identity information while establishing the account, and stores the encrypted user identity information on the chain in a distributed storage manner.
[0004] For example, the invention patent with announcement number CN116432207B announces a blockchain-based method for hierarchical management of power data permissions, including: classifying power data by department; initializing n nodes on the blockchain, corresponding to n departments, setting up a key management center, a file management center, and an encryption center; verifying and registering users as the first level of permission; multiple encryption organizations collaborate to perform double-layer encryption on files and keys as the second level of permission for data anti-counterfeiting; and verifying whether the user meets the two-level permissions for the required data.
[0005] However, in the process of implementing the technical solution of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems:
[0006] In the existing decentralized user account management process, users register and verify directly on the registration platform. There is a risk that user registration may fail due to risks in the operation of the registration platform, and the user's registration data will face the risk of being tampered with and leaked. Summary of the invention
[0007] In view of the deficiencies in the prior art, the present invention provides a decentralized management method, system and storage medium for user registration, which can effectively solve the problems involved in the above-mentioned background technology.
[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions: In a first aspect, the present invention provides a decentralized management method for user registration, comprising:
[0009] S1. Registration platform safety monitoring: Real-time monitoring to obtain safety performance data during the operation of the registration platform, and at the same time obtain historical operation data of the registration platform, and obtain the registration platform operation safety index through comprehensive analysis by the data processor, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. On the contrary, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt will be issued for the safety performance of the registration platform;
[0010] S2. User registration security management: real-time monitoring of user behavior data during the registration process, obtaining a user registration security index through data processor analysis, and comparing it with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the user's key during the registration process is directly analyzed; otherwise, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified;
[0011] S3. User key analysis: Obtain the key data of the user during the registration process, and analyze it through the data processor to obtain the registration key complexity evaluation index, and compare it with the registration key complexity evaluation index limit value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index limit value, the user data is directly stored. If the registration key complexity evaluation index is less than the preset registration key complexity evaluation index limit value, the user's key is warned;
[0012] S4. Security analysis of blockchain: Encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to a decentralized management method, and perform security analysis on the blockchain through a data processor to obtain the multi-party security index of the blockchain, which is compared with the multi-party security index threshold of the blockchain preset in the registration management database to obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result.
[0013] As a further method, the registration platform operates a safety indicator, and the specific analysis process is as follows:
[0014] The average number of concurrent users of the registration platform during the operation monitoring period is compared with the allowed number of concurrent users preset in the registration management database to obtain the concurrent user occupancy rate of the registration platform during the operation monitoring period.
[0015] A comprehensive analysis is conducted on the number of vulnerabilities, average interactive response time, concurrent user occupancy rate, average historical vulnerability repair rate, and average historical vulnerability repair time of the registration platform during the operation monitoring cycle to obtain the registration platform operation security index.
[0016] As a further method, the user registration security index, the specific analysis process is:
[0017] Obtain the registration platform operation security indicators of users during the registration process.
[0018] The length of time it takes for a user to input a verification code during the registration period is ratioed to the total number of times the verification code is input, to obtain the average length of time it takes for a user to input a verification code during the registration period.
[0019] The user registration security index is obtained by comprehensively analyzing the registration platform operation security indicators during the user registration process, the average time for users to enter user information during the registration period, the number of incorrect account information input, the number of registration interruptions, the verification code input error rate and the average time for verification code input.
[0020] As a further method, the registration key complexity evaluation index, the specific analysis process is:
[0021] The string length, number of repeated characters, number of character types, secondary verification deviation time, and user registration security index of the user registration key are comprehensively analyzed to obtain the registration key complexity evaluation index. The specific analysis method is as follows:
[0022] ;
[0023] In the formula, Complexity evaluation index for registration keys, The length of the string for the user registration key. The reference length of the string preset for the registration management database, The number of repeated characters in the user registration key. The complex evaluation impact indicator corresponding to the unit value of the number of repeated characters preset in the registration management database, The number of character types for the user's registered key, The complex evaluation impact indicator corresponding to the number of character types preset in the registration management database. The secondary verification deviation time for user registration keys, The amount of time allowed for the secondary validation deviation that is set for the registry database, Register security index for users, A complex assessment impact indicator corresponding to the user registration security index preset for the registration management database.
[0024] As a further method, the multi-party security index of the blockchain, the specific analysis process is:
[0025] A number of users who complete registration at the same time point are recorded as each user, thereby counting the users who complete registration at each time point and marking them as each user in each group;
[0026] Get the registration key complexity evaluation index corresponding to each user in each group.
[0027] The registration key complexity evaluation index corresponding to each user in each group is multiplied by the confusion factor preset in the registration management database to obtain the auxiliary value corresponding to each user in each group in the blockchain.
[0028] The auxiliary values corresponding to each user in each group in the blockchain are analyzed to obtain the multi-party security index of the blockchain.
[0029] The second aspect of the present invention provides a decentralized management system for user registration, including: a registration platform security monitoring module, which is used to monitor and obtain safety performance data during the operation of the registration platform in real time, and at the same time obtain historical operation data of the registration platform, and obtain the registration platform operation safety index through a data processor for comprehensive analysis, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. Conversely, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt is given for the safety performance of the registration platform.
[0030] The user registration security management module is used to monitor the user's behavioral data during the registration process in real time, obtain the user registration security index through data processor analysis, and compare it with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the user's key during the registration process is directly analyzed. Conversely, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified.
[0031] The user key analysis module is used to obtain the key data of the user during the registration process, and analyze it through a data processor to obtain a registration key complexity evaluation index, and compare it with the registration key complexity evaluation index limit value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index limit value, the user data is directly stored; if the registration key complexity evaluation index is less than the preset registration key complexity evaluation index limit value, an early warning prompt is issued for the user's key.
[0032] The security analysis module of the blockchain is used to encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to a decentralized management method, and perform security analysis on the blockchain through a data processor to obtain the multi-party security index of the blockchain, which is compared with the multi-party security index threshold of the blockchain preset in the registration management database to obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result.
[0033] A third aspect of the present invention provides a storage medium for a decentralized management method for user registration, which is used to store a program, and is characterized in that: when the program is executed by a data processor, the decentralized management method for user registration is implemented.
[0034] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects:
[0035] (1) The present invention obtains safety performance data during the operation of the registration platform through real-time monitoring, ensures that the registration platform can maintain a high level of security at any time, promptly discovers and handles potential safety hazards, and conducts a comprehensive analysis with the historical operation data of the registration platform to obtain the registration platform operation safety index, which can more accurately evaluate the safety performance of the registration platform; compares it with the registration platform operation safety index threshold value preset in the registration management database, and issues a timely warning when the safety index is lower than the threshold value to prevent users from registering on an unsafe platform;
[0036] (2) The present invention can timely discover and handle abnormal registration behavior by real-time monitoring of user behavior data during the registration process, analyze and obtain the user registration security index, and quantify the security of the user's registration behavior; compare it with the user registration security index threshold preset in the registration management database, and when the security index is lower than the threshold, perform additional identity information verification to improve the security of the registration process;
[0037] (3) The present invention obtains the key data of the user during the registration process, analyzes and obtains the registration key complexity evaluation index, ensures that the key set by the user is complex enough and difficult to crack, and compares it with the registration key complexity evaluation index limit value preset in the registration management database. When the key complexity is insufficient, a timely warning is issued to remind the user to enhance the security of the key, and the user data is protected from illegal access through the complex key;
[0038] (4) The present invention encrypts the user data during the registration process according to a preset encryption method to ensure the security of the user data during transmission and storage, and stores the encrypted user data in the blockchain according to the decentralized management method. Through the blockchain technology, the distributed storage of user data is realized, the reliability and security of the data are improved, and the blockchain is subjected to security analysis, so that potential security issues can be discovered and handled in a timely manner. The multi-party security index of the blockchain is obtained and compared with the multi-party security index threshold of the blockchain preset in the registration management database to determine whether it is necessary to issue an early warning prompt for the decentralized management method of user data. When the multi-party security index is lower than the threshold, an early warning is issued in a timely manner to ensure the security of the decentralized management method of user data. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The present invention is further described with the aid of the accompanying drawings, but the embodiments in the accompanying drawings do not constitute any limitation to the present invention. A person skilled in the art can obtain other accompanying drawings based on the following accompanying drawings without creative work.
[0040] Figure 1 It is a schematic diagram of the method steps of the present invention;
[0041] Figure 2 It is a schematic diagram of system module connection of the present invention. DETAILED DESCRIPTION
[0042] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0043] Reference Figure 1As shown, the first aspect of the present invention provides a decentralized management method for user registration, including: S1. Registration platform security monitoring: real-time monitoring to obtain safety performance data during the operation of the registration platform, and at the same time obtain historical operation data of the registration platform, and obtain the registration platform operation safety index through a data processor for comprehensive analysis, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. Conversely, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt is given for the safety performance of the registration platform.
[0044] In this embodiment, the above-mentioned registration platform refers to an online system or application for user registration. This platform may belong to a website, mobile application or other type of digital service. Its main function is to allow new users to create accounts and become official members of the service. The registration platform usually requires users to provide some basic information, such as user name, password, email address, etc. Sometimes more personal information may be required to complete the verification process. This information will be stored in the blockchain. In this embodiment, the registration platform is not just a simple user information collection tool, it also has a security monitoring function, which means that the platform can monitor its security performance in real time during operation, including detecting potential security threats, vulnerabilities and other issues that may affect user experience or data security. It needs to be explained that in the security performance monitoring and analysis process of the registration platform, the data processor is responsible for receiving and processing real-time monitoring data and historical operation data, and then outputting the results of the comprehensive analysis.
[0045] S2. User registration security management: Real-time monitoring of user behavior data during the registration process, analysis of the user registration security index through the data processor, and comparison with the user registration security index threshold preset in the registration management database; if the user registration security index is greater than or equal to the preset user registration security index threshold, the user's key during the registration process is directly analyzed; otherwise, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified.
[0046] S3. User key analysis: Obtain the key data of the user during the registration process, and analyze it through a data processor to obtain the registration key complexity evaluation index, and compare it with the registration key complexity evaluation index limit value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index limit value, the user data is directly stored; if the registration key complexity evaluation index is less than the preset registration key complexity evaluation index limit value, an early warning prompt is issued for the user's key.
[0047] S4. Security analysis of blockchain: Encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to a decentralized management method, and perform security analysis on the blockchain through a data processor to obtain the multi-party security index of the blockchain, which is compared with the multi-party security index threshold of the blockchain preset in the registration management database to obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result.
[0048] It should be explained that the above-mentioned preset encryption method can adopt symmetric encryption and asymmetric encryption methods. Decentralized management does not rely on centralized servers. Data is decentralized and stored and managed, which improves data security and transparency. Transactions are automated and decentralized through smart contracts, reducing transaction costs and risks.
[0049] In this embodiment, when a user registers, the user data is published in the blockchain together with the slot-specific components and attribute-specific components generated according to the current empty slot. The blockchain mainly performs consensus verification on the user's identity and current order (corresponding to the replica position and slot position). Since the user data of the user is aggregated by the DPoS (delegated proof of stake) blockchain consensus method, after the verification is passed, the leader node will confirm and add the user slot-associated identity information to the attribute set to finally determine the relationship between the user identity and the corresponding slot. During the user registration process, the public key and the public key components in the current master public key are also aggregated and broadcasted. The master public key will only be uniformly updated after all slots in the current replica are fully registered. If the user corresponds to the last slot of the current replica, the leader node will broadcast the latest master public key to the entire network.
[0050] In this embodiment, in order to solve the problem of weak scalability of general registration encryption schemes, the algorithm adopts slot registration for registration, has a pre-set upper limit on the number of users, and uses the "power of two" method to generate copies and the number of slots they contain. When a user registers, a slot position will be registered in each copy. Only when the copy is full will the master public key be updated, which effectively improves the efficiency of the system and reduces the demand for centralized nodes; the user's data during the registration process is encrypted according to the preset encryption method. In the encryption stage, in order to ensure the security of the data, the ciphertext is constructed by linear secret sharing. The user randomly generates a secret value and constructs a vector. This method can verify the user's identity attributes during the decryption process. During the user decryption process, the identity is verified from two aspects. One is Its attributes are related to a specific slot, that is, whether it has the key to decrypt a specific slot, but whether its attributes meet the access policy; when encrypting data, the ciphertext is associated with all slot indices, but the decryptor often only has the key of a single slot, so additional auxiliary information is needed for decryption. When the decryption user applies for the auxiliary decryption component, he needs to use the user's own slot-related attributes as the application condition. Therefore, the decryption process can not only determine whether the user's attributes meet the data access policy, but also determine whether the user's attributes are registered in the previous slot to avoid collusion attacks. The subcommittee can calculate the auxiliary decryption component through the auxiliary calculation items provided by all group users. Since the calculation process of the auxiliary decryption component is delivered to the subcommittee, this calculation during the encryption and decryption time process is irrelevant to the user and does not affect efficiency. When decryption is required, the auxiliary decryption of each group is calculated through multi-party collaboration of the subcommittee to achieve decentralization. The members of each copy only calculate the data in their own group, and finally combine with other groups to form a complete slot-related auxiliary decryption item.
[0051] Specifically, the security performance data during the operation of the registration platform includes the number of vulnerabilities of the registration platform during the operation monitoring cycle, the average interactive response time, and the number of concurrent users at each monitoring time point.
[0052] It should be explained that the number of vulnerabilities of the above-mentioned registration platform within the operation monitoring cycle can be scanned by automated security scanning tools (such as Nessus (automated security scanning tool), OpenVAS (open vulnerability assessment system), etc.) to identify and count known security vulnerabilities, thereby obtaining the number of vulnerabilities; the average interaction response time can record the processing time of each user interaction request on the server side, and then calculate the average value, thereby obtaining the average interaction response time; the number of concurrent users at each monitoring time point can be tracked by real-time monitoring tools (such as Prometheus (open source system monitoring and alarm tool), Grafana (open source data visualization tool), etc.); in this embodiment, the operation monitoring cycle refers to the time period for security performance monitoring of the registration platform, and the monitoring time point is the specific time point for data collection within the operation monitoring cycle. The operation monitoring cycle is usually set according to the actual operation status and security requirements of the registration platform. The monitoring time point can be fixed (such as every hour, every half hour, etc.), or it can be dynamically adjusted according to actual needs.
[0053] In this embodiment, there is a complex mutual influence relationship between the number of vulnerabilities, the average interactive response time, and the number of concurrent users of the registration platform. The existence of vulnerabilities will cause the system performance to deteriorate, thereby increasing the average interactive response time. For example, some vulnerabilities may allow attackers to execute malicious code or conduct denial of service attacks (DoS denial of service attacks), which may cause the system to respond more slowly. On the other hand, if there are a large number of unfixed vulnerabilities in the system, this may increase the complexity and instability of the system, thereby affecting the response speed. When the number of concurrent users increases, the load on the registration platform will also increase accordingly. If the system itself has vulnerabilities, this increased load may trigger or aggravate the impact of these vulnerabilities, further reducing system performance. As the number of concurrent users increases, the registration platform needs to process more requests, which will result in longer response times.
[0054] The historical operation data of the registration platform specifically includes the number of historical vulnerabilities, the number of historical vulnerability repairs and the total time for vulnerability repairs during the historical operation period of the registration platform.
[0055] It should be explained that the number of historical vulnerabilities in the historical operation cycle of the above-mentioned registration platform can be obtained by checking the system log records of the registration platform to obtain all the vulnerabilities discovered in history, the number of historical vulnerability repairs is obtained by checking the vulnerability management records of the registration platform, and the total vulnerability repair time can use automated tools to help track and report the repair progress, and add up these times to get the total time. In this embodiment, the historical operation cycle refers to the operation of the registration platform in the past period of time, and this cycle can be defined according to specific business needs and regulatory requirements.
[0056] Get the number of monitoring times of the registered platform during the running monitoring cycle.
[0057] It should be explained that the number of monitoring times performed by the above-mentioned registration platform during the operation monitoring cycle can be obtained by checking the log file recorded by the server of the registration platform, thereby obtaining the number of monitoring times performed during the operation monitoring cycle.
[0058] The number of concurrent users of the registration platform at each monitoring time point during the operation monitoring cycle is summed to obtain the total number of concurrent users of the registration platform during the operation monitoring cycle, and a ratio analysis is performed with the number of monitoring times of the registration platform during the operation monitoring cycle to obtain the average number of concurrent users of the registration platform during the operation monitoring cycle.
[0059] A ratio analysis is performed on the number of historical vulnerability repairs and the number of historical vulnerabilities of the registered platform during the historical operation cycle to obtain the average historical vulnerability repair rate of the registered platform during the historical operation cycle.
[0060] The total time it takes to fix vulnerabilities on the registered platform during its historical operation cycle is compared to the number of historical vulnerabilities to obtain the average time it takes to fix historical vulnerabilities on the registered platform during its historical operation cycle.
[0061] Specifically, the registration platform operation safety index, the specific analysis process is as follows:
[0062] The average number of concurrent users of the registration platform during the operation monitoring period is compared with the allowed number of concurrent users preset in the registration management database to obtain the concurrent user occupancy rate of the registration platform during the operation monitoring period.
[0063] The number of vulnerabilities, average interactive response time, concurrent user occupancy rate, average historical vulnerability repair rate and average historical vulnerability repair time of the registration platform in the operation monitoring cycle are comprehensively analyzed to obtain the registration platform operation security index. The specific analysis method is as follows:
[0064] ;
[0065] In the formula, is the safety index of the registration platform operation, e is a natural constant, The number of vulnerabilities in the registered platform during the operation monitoring cycle. The operational security impact factor corresponding to the unit value of the vulnerability quantity preset in the registration management database, The average interactive response time of the registration platform during the operation monitoring period. The preset time allowed for interactive responses from the registration management database, is the concurrent user occupancy rate of the registration platform during the operation monitoring period, The operation safety impact factor corresponding to the unit value of the concurrent user occupancy rate preset in the registration management database, The average repair rate of historical vulnerabilities in the historical operation cycle of the registered platform. The operational safety impact factor corresponding to the unit value of the average historical vulnerability repair rate preset in the registration management database, The average time it takes to fix historical vulnerabilities on the registered platform during its historical operation period. The operational safety impact factor corresponding to the unit value of the average repair time of historical vulnerabilities preset in the registration management database.
[0066] It needs to be explained that the number of vulnerabilities of the above-mentioned registration platform during the operation monitoring cycle refers to the total number of security vulnerabilities of the registration platform discovered through security scanning, penetration testing and other means during the operation monitoring cycle; the average interactive response time refers to the average time from the user initiating a request to receiving a server response; the allowed interactive response time preset by the registration management database refers to the maximum response time threshold set by the registration management database; the concurrent user occupancy rate of the registration platform during the operation monitoring cycle refers to the ratio of the average number of concurrent users of the registration platform during the operation monitoring cycle to the allowed number of concurrent users preset by the registration management database; the average historical vulnerability repair rate of the registration platform during the historical operation cycle refers to the ratio of the number of historical vulnerability repairs of the registration platform during the historical operation cycle to the number of historical vulnerabilities; the average historical vulnerability repair time of the registration platform during the historical operation cycle refers to the ratio of the total vulnerability repair time of the registration platform during the historical operation cycle to the number of historical vulnerabilities.
[0067] It should be explained that the operational safety impact factor corresponding to the unit value of the number of vulnerabilities preset in the above-mentioned registration management database represents the degree of influence of the unit value of the number of vulnerabilities on the operational safety indicators of the registration platform. The registration management database stores the corresponding relationship between the unit value of the number of vulnerabilities and its corresponding operational safety impact factor. For example, by inputting the unit value of the number of vulnerabilities into the registration management database, the registration management database can match the operational safety impact factor corresponding to the unit value of the number of vulnerabilities. At the same time, in this example, its value range is (0, 1).
[0068] The operation safety impact factor corresponding to the unit value of the concurrent user allowed occupancy rate preset in the registration management database represents the degree of influence of the unit value of the concurrent user allowed occupancy rate on the operation safety index of the registration platform. The registration management database stores the correspondence between the unit value of the concurrent user allowed occupancy rate and its corresponding operation safety impact factor. For example, by inputting the unit value of the concurrent user allowed occupancy rate into the registration management database, the registration management database can match the operation safety impact factor corresponding to the unit value of the concurrent user allowed occupancy rate. At the same time, in this example, its value range is (0, 1).
[0069] The operational safety impact factor corresponding to the unit value of the historical vulnerability repair rate preset in the registration management database represents the degree of influence of the unit value of the historical vulnerability repair rate on the operational safety indicators of the registration platform. The registration management database stores the correspondence between the unit value of the historical vulnerability repair rate and its corresponding operational safety impact factor. For example, by inputting the unit value of the historical vulnerability repair rate into the registration management database, the registration management database can match the operational safety impact factor corresponding to the unit value of the historical vulnerability repair rate. At the same time, in this example, its value range is (0, 1).
[0070] The operational safety impact factor corresponding to the unit value of the historical average vulnerability repair time preset in the registration management database represents the degree of influence of the unit value of the historical average vulnerability repair time on the operational safety index of the registration platform. The registration management database stores the correspondence between the unit value of the historical average vulnerability repair time and its corresponding operational safety impact factor. For example, by inputting the unit value of the historical average vulnerability repair time into the registration management database, the registration management database can match the operational safety impact factor corresponding to the unit value of the historical average vulnerability repair time. At the same time, in this example, its value range is (0, 1).
[0071] In this embodiment, when the number of vulnerabilities in the registration platform during the operation monitoring cycle is greater, it means that the potential security threat to the platform is greater, which directly leads to a decrease in the operation safety index of the registration platform; when the average interactive response time of the registration platform during the operation monitoring cycle is longer, or even longer than the preset interactive response allowable time, the longer response time indicates that the platform has performance bottlenecks or insufficient resources when processing user requests, which will also lead to a decrease in the operation safety index of the registration platform; when the concurrent user occupancy rate of the registration platform during the operation monitoring cycle is large, the platform will experience performance degradation, service delays or interruptions when processing a large number of user requests, further reducing the operation safety index of the registration platform; when the average historical vulnerability repair rate of the registration platform in the historical operation cycle is small, the low repair rate means that it takes a long time after the vulnerability is discovered. If the vulnerabilities are not repaired, the risk of being exploited will increase, which will directly lead to a decrease in the registration platform's operating safety indicators. When the average repair time of historical vulnerabilities in the historical operating cycle of the registration platform is long, the long repair time means that the vulnerability repair process is complicated and time-consuming, which increases the risk window period of being exploited, and also reduces the registration platform's operating safety indicators. Therefore, through a detailed analysis of each parameter in the registration platform's operating safety indicators, we can fully understand the current operating status and security status of the registration platform, identify potential security risks and performance bottlenecks, and provide valuable information for platform administrators and developers so that they can take corresponding improvement measures. For example, by improving the interactive response speed and concurrent processing capabilities, improving user experience and system stability, and enhancing the security of the platform by reducing the number of vulnerabilities, increasing the repair rate and shortening the repair time.
[0072] In this embodiment, the registration platform operation safety index is compared with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, it means that the registration platform has shown good safety performance during the current operation monitoring cycle, and all parameters have reached or exceeded the preset safety standards. In this case, the user can safely register through the registration platform; conversely, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, it means that the registration platform has safety hazards or performance problems during the current operation monitoring cycle and has failed to reach the preset safety standards. In this case, it is necessary to give an early warning prompt for the safety performance of the registration platform so that timely measures can be taken to improve and optimize it. The specific early warning prompt can be set in the background management interface of the registration platform. The alarm function, when the safety index is lower than the limit value, the platform automatically triggers an alarm to remind the administrator to check and handle it.
[0073] Furthermore, the user's behavioral data during the registration process specifically includes the average time it takes for the user to input user information, the number of incorrect account information inputs, the time it takes to input a verification code, the total number of verification code inputs, the number of incorrect verification code inputs, and the number of registration interruptions during the registration period.
[0074] It should be explained that the average time it takes for the above-mentioned users to input user information during the registration period can be tracked through the user session management mechanism of the registration platform, from the total time it takes for the user to start entering the first field (such as user name) to the time it completes the input of all required fields, and then divided by the number of fields filled in by the user (or the number of specific key fields, such as user name, password, etc.) to obtain the average time it takes for the user to input information; after the user enters the account information, the registration platform will perform verification. If the verification fails, an error will be recorded. This number of errors can be counted through the back-end logic, thereby obtaining the number of account information input errors; the time it takes to input the verification code can be timed through the interactive design of the front-end interface, and the recorded time can be averaged to obtain the time it takes to input the verification code; every time a user enters a verification code, whether it is successful or unsuccessful, it is recorded as an input, and the total number of verification code inputs can be obtained through statistics from the back-end logic; when the verification code entered by the user does not match the verification code generated by the registration Timing, record an error, and similarly the number of verification code input errors can be obtained by counting the back-end logic; number of registration interruptions, if the user leaves the page or closes the browser tab during the registration process, it can be considered that the registration process is interrupted. This number of interruptions can be detected through the interactive design of the front-end interface, for example, using the beforeunload ("before page unloading" / "before page closing") event to monitor whether the user is about to leave the page. If so, record an interruption. In this embodiment, the registration cycle refers to the time period from the start of registration to the completion of registration. The specific registration cycle depends on the registration operation of each user. When the user visits the registration page, the current timestamp is recorded as the start time through the front-end code (such as JavaScript). When the user completes the registration or interrupts the registration, the current timestamp is recorded again through the front-end code as the end time. The total duration of the user in the registration cycle can be obtained by subtracting the start time from the end time.
[0075] In this embodiment, there is a mutual influence relationship between the average time for user information input, the number of incorrect account information input, the verification code input time, the total number of verification code input times, the number of incorrect verification code input times, and the number of registration interruptions during the registration period. The average time for user information input will be affected by the number of incorrect account information input. When the user enters incorrect information many times, it may take more time to correct the errors, resulting in an increase in the average input time. On the contrary, if the user can input information quickly and accurately, the average input time will be shorter and the number of errors may be reduced accordingly. The verification code input time will be affected by the total number of verification code input times and the number of incorrect verification code input times. If users try to enter the verification code many times but all fail, they may spend more time to carefully check and enter the verification code, resulting in an increase in the input time. The more times the verification code is entered incorrectly, the more time the user may need to spend re-entering and verifying, thereby extending the entire registration process. In a specific embodiment, if the user feels impatient because of incorrect information input or difficulty in entering the verification code, he or she may choose to interrupt the registration process. At the same time, if the registration process is too cumbersome or time-consuming, the user may also choose to interrupt because of losing patience. Conversely, if the registration process is smooth and the user can complete the registration quickly, the number of registration interruptions may be reduced accordingly.
[0076] The number of times the user inputs the verification code incorrectly during the registration period is compared with the total number of times the verification code is input, so as to obtain the error rate of the user inputting the verification code during the registration period.
[0077] Specifically, the user registration security index is analyzed in the following steps:
[0078] Obtain the registration platform operation security indicators of users during the registration process.
[0079] It should be explained that the above-mentioned registration platform operation safety index during the user's registration process refers to the quantitative indicator of the security level provided by the registration platform when the user performs the registration operation. In this embodiment, the analysis method of the registration platform operation safety index during the user's registration process is the same as the above-mentioned analysis method of the registration platform operation safety index during the user's registration process.
[0080] The length of time it takes for a user to input a verification code during the registration period is ratioed to the total number of times the verification code is input, to obtain the average length of time it takes for a user to input a verification code during the registration period.
[0081] The user registration security index is obtained by comprehensively analyzing the registration platform operation security indicators during the user registration process, the average time for users to enter user information during the registration period, the number of incorrect account information input, the number of registration interruptions, the verification code input error rate and the average time for verification code input.
[0082] In this embodiment, a comprehensive analysis is performed on the registration platform operation security indicators of the user during the registration process, the average time for the user to input user information, the number of incorrect account information input, the number of registration interruptions, the verification code input error rate, and the average time for verification code input during the registration period in order to comprehensively evaluate the security and efficiency of the user registration process.
[0083] The user registration security index is specifically analyzed by:
[0084] ;
[0085] In the formula, is the user registration security index, e is a natural constant, The registration platform runs security indicators for users during the registration process, The registration security impact indicator corresponding to the registration platform operation security indicator preset in the registration management database, Enter the average length of time a user spends in the user profile during the registration cycle. The reference time for user information input preset in the registration management database, The number of times a user enters incorrect account information during the registration period. The number of incorrect inputs allowed for account information preset in the registration management database. The number of registration interruptions during the registration period. The registration security impact index corresponding to the unit value of the number of registration interruptions preset in the registration management database. The error rate of verification code input by users during the registration period. The registration security impact index corresponding to the unit value of the verification code input error rate preset in the registration management database. The average time it takes for a user to enter a verification code during the registration cycle. The reference time for entering the verification code preset in the registration management database.
[0086] It should be explained that the above-mentioned average time for users to input user information during the registration period refers to the average length of time from the user starting to enter the first user information field (such as user name, password, etc.) to completing the input and submission of all required information; the reference time for user information input preset by the registration management database refers to the average time reference value preset by the registration management database for users to complete information input; the number of incorrect account information input by users during the registration period refers to the number of times the user needs to re-enter the account information during the registration process due to input errors (such as user name already exists, password does not meet the requirements, etc.); the number of allowed account information input errors preset for the registration management database refers to the number of times allowed by the registration management database. The maximum number of times a user is allowed to re-enter the code due to input errors during the registration process; the number of registration interruptions during the user's registration cycle refers to the number of times the registration process is interrupted due to various reasons (such as page refresh, browser closing, etc.) from the beginning to the completion of registration; the verification code input error rate during the user's registration cycle refers to the ratio of the number of times the user enters the verification code incorrectly during the registration process to the total number of verification code inputs; the average verification code input time during the user's registration cycle refers to the average length of time it takes for the user to correctly enter the verification code and submit it; the verification code input reference time preset by the registration management database refers to the reference value of the average time preset by the registration management database for users to correctly enter the verification code.
[0087] The registration security impact index corresponding to the registration platform operation safety index preset in the registration management database represents the index value of the security impact of the registration platform operation safety index on the user registration security index. The registration management database stores the correspondence between the registration platform operation safety index and its corresponding registration security impact index. For example, when the registration platform operation safety index is input into the registration management database, the registration management database can match the registration security impact index corresponding to the registration platform operation safety index. At the same time, in this example, its value range is (0, 1).
[0088] The registration security impact index corresponding to the unit value of the number of registration interruptions preset in the registration management database represents the index value of the degree of security impact of the unit value of the number of registration interruptions on the user registration security index. The registration management database stores the corresponding relationship between the unit value of the number of registration interruptions and its corresponding registration security impact index. For example, by inputting the unit value of the number of registration interruptions into the registration management database, the registration management database can match the registration security impact index corresponding to the unit value of the number of registration interruptions. At the same time, in this example, its value range is (0, 1).
[0089] The registration security impact index corresponding to the unit value of the verification code input error rate preset in the registration management database represents the index value of the security impact of the unit value of the verification code input error rate of the number of registration interruptions on the user registration security index. The registration management database stores the correspondence between the unit value of the verification code input error rate and its corresponding registration security impact index. For example, when the unit value of the verification code input error rate is input into the registration management database, the registration management database can match the registration security impact index corresponding to the unit value of the verification code input error rate. At the same time, in this example, its value range is (0, 1).
[0090] In this embodiment, when the registration platform operation security index of the user during the registration process is low, it means that there are problems with the platform in terms of security, such as more vulnerabilities, slow response speed, poor concurrent processing capabilities, etc. These problems may lead to risks such as user information leakage and service interruption, thereby reducing the user registration security index; when the average time for the user to input user information during the registration period is large or small, that is, the degree of deviation from the preset user information input reference time is large, it indicates that the user has difficulty or deliberately delays when entering information, which may be related to fraud or malicious registration. A longer input time may mean that the user is trying to bypass certain security verifications, while a shorter time may mean that the user has not carefully checked the information, thereby increasing the error rate. These situations will reduce the user registration security index; the number of times the user enters account information incorrectly during the registration period is large, even more than the preset number of account information input errors allowed, indicating that the user may have malicious attempts or operational errors. Multiple input errors will not only increase the system burden, but may also expose the user's true intentions, thereby threatening the security of the system, and at the same time causing the user registration security index to increase. The number of registration interruptions during the registration cycle may mean that the user encountered problems or difficulties during the registration process, such as network connection problems, system errors or user's own reasons. Frequent registration may increase the risk of malicious users taking advantage of interruptions to attack. When the user's verification code input error rate during the registration cycle is high, it may indicate that the user did not correctly identify or enter the verification code, which may be related to the user's attention, operational errors or malicious attempts. The verification code is an important means to prevent malicious registration and automated attacks. Therefore, a high error rate will weaken its protective effect, thereby reducing the user registration security index. The average verification code input time of the user during the registration cycle is large or small, that is, when the deviation from the preset verification code input reference time is large, a longer input time means that the user is trying to bypass the verification code verification, while a shorter time may mean that the user did not carefully check the verification code. Therefore, by conducting a detailed analysis of the various parameters in the user registration security index, potential security risks such as malicious registration and fraud can be discovered and dealt with in a timely manner, which helps to protect user information and system security and improve overall security.
[0091] In this embodiment, the user registration security index is compared with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the user has demonstrated high security during the registration process, and his registration behavior, accuracy and completeness of the input information have all reached high standards. In this case, the system can directly analyze the key generated by the user during the registration process to ensure the security and validity of the key; conversely, if the user registration security index is less than the preset user registration security index threshold, the user has certain security risks during the registration process, which may be due to inaccurate input information, abnormal registration behavior, or the system detecting potential security threats. In this case, the system needs to further verify the user's identity information, which usually includes requiring the user to provide additional identity authentication information (such as ID number, mobile phone number, etc.) to confirm the authenticity and legitimacy of the user. Identity information verification is an important means to prevent malicious registration and protect the system from unauthorized access and attacks.
[0092] Specifically, the key data of the user during the registration process includes the character string length, input time, secondary verification input time, number of repeated characters, and number of character types of the user registration key.
[0093] It should be explained that the string length of the above user registration key is obtained by using the string processing function in the programming language. For example, in the Java programming language, the password.length() (function for obtaining the string length) function can be used to obtain the string length of the user registration key; the input duration is to record a timestamp when the user starts inputting and to record the timestamp again when the input ends. This can be achieved by using the date and time functions in the programming language. For example, in JavaScript (programming language), Date.now() (static method) can be used to obtain the current timestamp (in milliseconds), and the difference between the two timestamps can be calculated to obtain the input duration; The method for obtaining the input duration of the second verification is the same as the method for obtaining the input duration mentioned above. You only need to record the timestamps at the beginning and end of the second verification and calculate the difference. The number of repeated characters can be obtained by traversing the string and using a counter to count the number of times each character appears, and then finding the character with the most occurrences and its number. The number of character types uses the set() function (built-in function) to convert the string into a set to remove repeated characters, and then uses a for loop (loop statement) to traverse each character in the key to check each character in the string to determine whether it is a letter (case-sensitive), a number, or a special character. Finally, the type of each character in the string is summarized and counted to obtain the number of character types.
[0094] In this embodiment, the longer the key string is, the longer the time required for user input and the secondary verification input time are. The long key may contain more character types, reducing the possibility of repeated characters. At the same time, it may contain more character types, thereby increasing the complexity and security of the key.
[0095] Subtract the input duration from the secondary verification input duration of the user registration key to obtain the secondary verification deviation duration of the user registration key.
[0096] Furthermore, the registration key complexity evaluation index is specifically analyzed as follows:
[0097] The string length, number of repeated characters, number of character types, secondary verification deviation time, and user registration security index of the user registration key are comprehensively analyzed to obtain the registration key complexity evaluation index. The specific analysis method is as follows:
[0098] ;
[0099] In the formula, Complexity evaluation index for registration keys, The length of the string for the user registration key. The reference length of the string preset for the registration management database, The number of repeated characters in the user registration key. The complex evaluation impact indicator corresponding to the unit value of the number of repeated characters preset in the registration management database, The number of character types for the user's registered key, The complex evaluation impact indicator corresponding to the number of character types preset in the registration management database. The secondary verification deviation time for user registration keys, The amount of time allowed for the secondary validation deviation that is set for the registry database, Register security index for users, A complex assessment impact indicator corresponding to the user registration security index preset for the registration management database.
[0100] It should be explained that the string length of the above-mentioned user registration key refers to the actual number of characters in the password or key entered by the user during the registration process; the string reference length preset by the registration management database refers to the recommended length of the key preset by the registration management database; the number of repeated characters in the user registration key refers to the number of repeated characters in the key entered by the user; the number of character types in the user registration key refers to the number of different types of characters contained in the key entered by the user, which types usually include letters (uppercase and lowercase), numbers and special characters; the secondary verification deviation time of the user registration key refers to the difference between the secondary verification input time and the input time of the user registration key; the secondary verification deviation allowable time preset by the registration management database refers to the maximum time difference set by the management database to allow the user to perform secondary verification.
[0101] The complex assessment impact index corresponding to the repeated character unit value preset in the registration management database represents the index value of the degree of complex impact of the repeated character unit value on the registration key complexity assessment index. The registration management database stores the correspondence between the repeated character unit value and its corresponding complex assessment impact index. For example, by inputting the repeated character unit value into the registration management database, the registration management database can match the complex assessment impact index corresponding to the repeated character unit value. At the same time, in this example, its value range is (0, 1).
[0102] The complex assessment impact index corresponding to the character type quantity unit value preset in the registration management database represents the index value of the degree of complex impact of the character type quantity unit value on the registration key complexity assessment index. The registration management database stores the correspondence between the character type quantity unit value and its corresponding complex assessment impact index. For example, by inputting the character type quantity unit value into the registration management database, the registration management database can match the complex assessment impact index corresponding to the character type quantity unit value. At the same time, in this example, its value range is (0, 1).
[0103] The complex assessment impact index corresponding to the user registration security index preset in the registration management database represents the indicator value of the degree of complex impact of the user registration security index on the complex assessment index of the registration key. The registration management database stores the correspondence between the user registration security index and its corresponding complex assessment impact index. For example, by inputting the user registration security index into the registration management database, the registration management database can match the complex assessment impact index corresponding to the user registration security index. At the same time, in this example, its value range is (0, 1).
[0104] In this embodiment, when the string length of the user registration key is shorter, or even smaller than the preset string reference length, the shorter string length will reduce the complexity of the key, thereby increasing the risk of being cracked; more repeated characters will reduce the randomness and unpredictability of the key, thereby weakening the strength of the password; a smaller number of character types means that the password is easier to guess or crack by brute force; the secondary verification deviation time of the user registration key is shorter, or even shorter than the preset secondary verification deviation allowable time. The user may have used an easy-to-remember key, resulting in insufficient complexity, which is easy to guess or crack. Therefore, a smaller deviation time will lead to a decrease in the registration key complexity assessment index; a lower user registration security index usually means that the user's account may be at a higher risk; therefore, through a detailed analysis of each parameter in the key complexity assessment index, the complexity of the registration key can be more comprehensively assessed, thereby more accurately reflecting its security.
[0105] In this embodiment, the registration key complexity evaluation index is compared with the registration key complexity evaluation index limit value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index limit value, it means that the registration key meets or exceeds the system's security requirements, and therefore the user data can be directly stored; if the registration key complexity evaluation index is less than the preset registration key complexity evaluation index limit value, it means that the registration key is not secure enough and there is a risk of being cracked or guessed. In this case, the platform should issue an early warning prompt for the user's key. The specific early warning prompt can be achieved by popping up a warning window when the user registers or logs in, clearly informing the user that the key is not secure enough and suggesting that the user regenerate a more complex key.
[0106] Specifically, the multi-party security indicators of the blockchain are analyzed in the following steps:
[0107] A number of users who complete the registration at the same time point are recorded as each user, thereby counting the users who complete the registration at each time point and marking them as each user in each group.
[0108] In this embodiment, the registration time of each user is recorded in real time in the background of the registration platform. When the user completes the registration process, the system will automatically record the exact time when the user completes the registration. According to the previously determined time point, all users are grouped according to the time point when they complete the registration. Users who complete the registration at the same time point will be classified into the same group. It should be noted here that since user registration is a continuous process, theoretically there may be users who complete the registration at each time point, but in fact there may be no users who register at certain time points. At such time points, no users will be included in the group. For the user groups formed at each time point, they are given a unique identifier (such as group number, user number) for subsequent analysis and reference. In this way, a set of users who have completed the registration at each time point is obtained. The users in each set have completed the registration at the same time point. Finally, the users who have completed the registration at each time point are counted.
[0109] Get the registration key complexity evaluation index corresponding to each user in each group.
[0110] It should be explained that the registration key complexity evaluation index corresponding to each user in the above-mentioned groups refers to the registration key complexity evaluation index calculated for each user in each such user group. This means that for each user, there is a corresponding registration key complexity evaluation index. In this embodiment, the registration key complexity evaluation index corresponding to each user in each group is the same as the above-mentioned registration key complexity evaluation index, and both are indicators for evaluating the complexity and security of the registration key. However, the registration key complexity evaluation index is a general concept that can be used to evaluate the registration key of any user, and the registration key complexity evaluation index corresponding to each user in each group is the instantiation of this general concept in a specific application scenario (i.e., user groups divided according to certain standards). In other words, the latter is the specific application and performance of the former in a specific user group. Therefore, the registration key complexity evaluation index corresponding to each user in each group is the same as the analysis process and method of the above-mentioned registration key complexity evaluation index.
[0111] The registration key complexity evaluation index corresponding to each user in each group is multiplied by the confusion factor preset in the registration management database to obtain the auxiliary value corresponding to each user in each group in the blockchain.
[0112] It should be explained that the confusion factor preset in the above-mentioned registration management database is a factor used to transform data, and its purpose is usually to protect the privacy and security of the data. In this embodiment, the confusion factor is used as a complexity evaluation index of the registration key to increase the complexity and difficulty of cracking the key. The confusion factor is provided by a professional encryption technology service provider and is randomly generated based on the encryption algorithm used, and is pre-stored in a secure area of the registration management database to ensure its security and confidentiality.
[0113] The corresponding auxiliary values of each user in each group in the blockchain are analyzed to obtain the multi-party security index of the blockchain. The specific analysis formula is:
[0114] ;
[0115] In the formula, It is a multi-party security indicator of blockchain. is the number of each group, g = 1, 2, 3...h, h is the total number of groups, u is the number of each user, u = 1, 2, 3...n, n is the total number of users, is the auxiliary value corresponding to the u-th user in the g-th group in the blockchain, The multi-party security impact index corresponding to the auxiliary value corresponding to the user in the blockchain preset for the registration management database.
[0116] It should be explained that the multi-party security impact index corresponding to the auxiliary value of the user in the blockchain preset in the above-mentioned registration management database represents the index value of the security impact of the auxiliary value corresponding to the user in the blockchain on the multi-party security indicators of the blockchain. The registration management database stores the correspondence between the auxiliary value corresponding to the user in the blockchain and its corresponding multi-party security impact index. For example, the auxiliary value corresponding to the user in the blockchain is input into the registration management database, and the registration management database can match the multi-party security impact index corresponding to the auxiliary value corresponding to the user in the blockchain. At the same time, in this example, its value range is (0, 1).
[0117] In this embodiment, the smaller the auxiliary value corresponding to each user in the blockchain, the smaller the value of the multi-party security index of the blockchain is obtained, indicating that the user's registration key complexity evaluation index is still low after adjustment by the confusion factor, which means that the key itself may not be complex enough and can be easily cracked or guessed. A lower multi-party security index means that the blockchain system may be more vulnerable to malicious attacks, such as data tampering. Blockchain is usually used to store and protect sensitive data. If the multi-party security index is low, it may mean that the system's ability to protect data is not strong enough, which may lead to security issues such as data leakage and privacy infringement.
[0118] In this embodiment, the multi-party security index of the blockchain is compared with the multi-party security index threshold of the blockchain preset in the registration management database.
[0119] If the multi-party security index of the blockchain is greater than or equal to the multi-party security index threshold of the blockchain preset in the registration management database, the security of the current blockchain has reached the preset standard, the overall protection capability of the blockchain is strong, and it can better protect the security and privacy of user data. Therefore, the comparison result is recorded as the first comparison result, which usually indicates that the blockchain is in a secure state.
[0120] On the contrary, if the multi-party security index of the blockchain is less than the multi-party security index threshold of the blockchain preset in the registration management database, the security of the current blockchain is lower than the preset standard, the overall protection capability of the blockchain is weak, and there is a risk of being attacked or leaking data. Therefore, the comparison result is recorded as the second comparison result. In this case, in order to promptly remind system administrators and users to pay attention to potential security risks and take corresponding measures to prevent them, it is necessary to give early warning prompts to the decentralized management method. The specific early warning prompt can be to send early warning notifications to platform administrators through internal platform messages to remind managers to immediately pay attention to and deal with potential risks.
[0121] Reference Figure 2 As shown, the second aspect of the present invention provides a decentralized management system for user registration, including: a registration platform security monitoring module, a user registration security management module, a user key analysis module, a blockchain security analysis module and a registration management database.
[0122] The registration platform security monitoring module is connected to the user registration security management module, the user registration security management module is connected to the user key analysis module, the user key analysis module is connected to the security analysis module of the blockchain, and the registration platform security monitoring module, the user registration security management module, the user key analysis module and the security analysis module of the blockchain are all connected to the registration management database.
[0123] The registration platform security monitoring module is used to monitor and obtain safety performance data during the operation of the registration platform in real time, and at the same time obtain historical operation data of the registration platform, obtain the registration platform operation safety index through comprehensive analysis through the data processor, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. Conversely, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt is issued for the safety performance of the registration platform.
[0124] The user registration security management module is used to monitor the user's behavior data during the registration process in real time, obtain the user registration security index through data processor analysis, and compare it with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the user's key during the registration process is directly analyzed; otherwise, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified.
[0125] The user key analysis module is used to obtain the key data of the user during the registration process, and analyze it through a data processor to obtain a registration key complexity evaluation index, and compare it with the registration key complexity evaluation index boundary value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index boundary value, the user data is directly stored; if the registration key complexity evaluation index is less than the preset registration key complexity evaluation index boundary value, an early warning prompt is issued for the user's key.
[0126] The security analysis module of the blockchain is used to encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to the decentralized management method, and perform security analysis on the blockchain through a data processor to obtain a multi-party security index of the blockchain, compare it with the multi-party security index threshold of the blockchain preset in the registration management database, obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result.
[0127] The registration management database is used to store a preset registration platform operation security index limit value, a preset user registration security index threshold, a preset registration key complexity evaluation index limit value, a preset blockchain multi-party security index threshold, a preset concurrent user allowed number, a preset operation security impact factor corresponding to a unit value of a vulnerability number, a preset interactive response allowed time, a preset operation security impact factor corresponding to a unit value of a concurrent user allowed occupancy rate, a preset operation security impact factor corresponding to a unit value of a historical vulnerability average repair rate, a preset operation security impact factor corresponding to a unit value of a historical vulnerability average repair time, a preset user information input reference time, and a preset account information. The number of incorrect inputs allowed, the registration security impact index corresponding to the preset unit value of the number of registration interruptions, the registration security impact index corresponding to the preset unit value of the verification code input error rate, the preset reference time for verification code input, the preset reference length of the character string, the complex assessment impact index corresponding to the preset unit value of the number of repeated characters, the complex assessment impact index corresponding to the preset unit value of the number of character types, the preset allowed time for secondary verification deviation, the complex assessment impact index corresponding to the preset user registration security index, the preset confusion factor, the multi-party security impact index corresponding to the preset auxiliary value of the user in the blockchain, and the registration security impact index corresponding to the preset registration platform security indicator.
[0128] A third aspect of the present invention provides a storage medium for a decentralized management method for user registration, which is used to store a program, and is characterized in that: when the program is executed by a data processor, the decentralized management method for user registration is implemented.
[0129] The above contents are merely examples and explanations of the structure of the present invention. The technicians in this technical field may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined in this specification, they should all fall within the protection scope of the present invention.
Claims
1. A decentralized management method for user registration, characterized in that: include: S1. Registration platform safety monitoring: Real-time monitoring to obtain safety performance data during the operation of the registration platform, and at the same time obtain historical operation data of the registration platform, and obtain the registration platform operation safety index through comprehensive analysis by the data processor, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. On the contrary, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt will be issued for the safety performance of the registration platform; S2. User registration security management: real-time monitoring of user behavior data during the registration process, obtaining a user registration security index through data processor analysis, and comparing it with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the user's key during the registration process is directly analyzed; otherwise, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified; S3. User key analysis: Obtain the key data of the user during the registration process, and analyze it through the data processor to obtain the registration key complexity evaluation index, and compare it with the registration key complexity evaluation index limit value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index limit value, the user data is directly stored. If the registration key complexity evaluation index is less than the preset registration key complexity evaluation index limit value, the user's key is warned; S4. Security analysis of blockchain: encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to the decentralized management method, and perform security analysis on the blockchain through a data processor to obtain a multi-party security index of the blockchain, compare it with the multi-party security index threshold of the blockchain preset in the registration management database, obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result; The multi-party security indicators of the blockchain are specifically analyzed as follows: A number of users who complete registration at the same time point are recorded as each user, thereby counting the users who complete registration at each time point and marking them as each user in each group; Obtain the registration key complexity evaluation index corresponding to each user in each group; The registration key complexity evaluation index corresponding to each user in each group is multiplied by the confusion factor preset in the registration management database to obtain the auxiliary value corresponding to each user in each group in the blockchain; The auxiliary values corresponding to each user in each group in the blockchain are analyzed to obtain the multi-party security index of the blockchain.
2. The decentralized management method for user registration according to claim 1, characterized in that: The security performance data of the registration platform during operation, specifically including the number of vulnerabilities of the registration platform during the operation monitoring cycle, the average interactive response time, and the number of concurrent users at each monitoring time point; The historical operation data of the registration platform, specifically including the number of historical vulnerabilities, the number of historical vulnerability repairs, and the total duration of vulnerability repairs during the historical operation period of the registration platform; Obtain the number of monitoring times of the registered platform during the operation monitoring cycle; The number of concurrent users of the registration platform at each monitoring time point in the operation monitoring cycle is summed to obtain the total number of concurrent users of the registration platform in the operation monitoring cycle, and the sum is compared with the number of monitoring times of the registration platform in the operation monitoring cycle to obtain the average number of concurrent users of the registration platform in the operation monitoring cycle; Perform a ratio analysis on the number of historical vulnerability repairs and the number of historical vulnerabilities of the registered platform during its historical operation cycle to obtain the average repair rate of historical vulnerabilities of the registered platform during its historical operation cycle; The total time it takes to fix vulnerabilities on the registered platform during its historical operation cycle is compared to the number of historical vulnerabilities to obtain the average time it takes to fix historical vulnerabilities on the registered platform during its historical operation cycle.
3. The decentralized management method for user registration according to claim 2, characterized in that: The specific analysis process of the registration platform operation safety indicators is as follows: The average number of concurrent users of the registration platform during the operation monitoring period is compared with the allowed number of concurrent users preset in the registration management database to obtain the concurrent user occupancy rate of the registration platform during the operation monitoring period; A comprehensive analysis is conducted on the number of vulnerabilities, average interactive response time, concurrent user occupancy rate, average historical vulnerability repair rate, and average historical vulnerability repair time of the registration platform during the operation monitoring cycle to obtain the registration platform operation security index.
4. The decentralized management method for user registration according to claim 1, characterized in that: The user's behavior data during the registration process specifically includes the average time it takes for the user to enter user information, the number of incorrect account information inputs, the time it takes to enter a verification code, the total number of verification code inputs, the number of incorrect verification code inputs, and the number of registration interruptions during the registration period; The number of times the user inputs the verification code incorrectly during the registration period is compared with the total number of times the user inputs the verification code, so as to obtain the error rate of the user inputting the verification code during the registration period.
5. The decentralized management method for user registration according to claim 4, characterized in that: The specific analysis process of the user registration security index is as follows: Obtain the user's registration platform operation security indicators during the registration process; The average time for the user to input the verification code during the registration period is calculated by comparing the time it takes the user to input the verification code with the total number of times the verification code is input. The user registration security index is obtained by comprehensively analyzing the registration platform operation security indicators during the user registration process, the average time for users to enter user information during the registration period, the number of incorrect account information input, the number of registration interruptions, the verification code input error rate and the average time for verification code input.
6. The decentralized management method for user registration according to claim 1, characterized in that: The key data of the user during the registration process, specifically including the string length of the user registration key, input time, secondary verification input time, number of repeated characters, and number of character types; Subtract the input duration from the secondary verification input duration of the user registration key to obtain the secondary verification deviation duration of the user registration key.
7. The decentralized management method for user registration according to claim 6, characterized in that: The specific analysis process of the registration key complexity evaluation index is as follows: The string length, number of repeated characters, number of character types, secondary verification deviation time, and user registration security index of the user registration key are comprehensively analyzed to obtain the registration key complexity evaluation index. The specific analysis method is as follows: ; In the formula, Complexity evaluation index for registration keys, The length of the string for the user registration key. The reference length of the string preset for the registration management database, The number of repeated characters in the user registration key. The complex evaluation impact indicator corresponding to the unit value of the number of repeated characters preset in the registration management database, The number of character types for the user's registered key, The complex evaluation impact indicator corresponding to the number of character types preset in the registration management database. The secondary verification deviation time for user registration keys, The amount of time allowed for the secondary validation deviation that is set for the registry database, Register security index for users, A complex assessment impact indicator corresponding to the user registration security index preset for the registration management database.
8. A system using the decentralized management method for user registration as claimed in any one of claims 1 to 7, characterized in that: include: The registration platform safety monitoring module is used to monitor and obtain the safety performance data of the registration platform in real time during operation, and obtain the historical operation data of the registration platform at the same time, and obtain the registration platform operation safety index through comprehensive analysis by the data processor, and compare it with the registration platform operation safety index limit value preset in the registration management database. If the registration platform operation safety index is greater than or equal to the registration platform operation safety index limit value preset in the registration management database, the user can register through the registration platform. On the contrary, if the registration platform operation safety index is less than the preset registration platform operation safety index limit value, an early warning prompt is issued for the safety performance of the registration platform; The user registration security management module is used to monitor the user's behavior data during the registration process in real time, obtain the user registration security index through data processor analysis, and compare it with the user registration security index threshold preset in the registration management database. If the user registration security index is greater than or equal to the preset user registration security index threshold, the key of the user during the registration process is directly analyzed. On the contrary, if the user registration security index is less than the preset user registration security index threshold, the user's identity information is verified; A user key analysis module is used to obtain the key data of the user during the registration process, and analyze it through a data processor to obtain a registration key complexity evaluation index, and compare it with the registration key complexity evaluation index boundary value preset in the registration management database. If the registration key complexity evaluation index is greater than or equal to the preset registration key complexity evaluation index boundary value, the user data is directly stored; if the registration key complexity evaluation index is less than the preset registration key complexity evaluation index boundary value, an early warning prompt is issued for the user's key; The security analysis module of the blockchain is used to encrypt user data according to a preset encryption method, store the encrypted user data in the blockchain according to a decentralized management method, and perform security analysis on the blockchain through a data processor to obtain the multi-party security index of the blockchain, which is compared with the multi-party security index threshold of the blockchain preset in the registration management database to obtain a comparison result, and finally determine whether it is necessary to issue an early warning prompt for the decentralized management method based on the comparison result.
9. A storage medium for a decentralized management method for user registration, used for storing a program, characterized in that: When the program is executed by a data processor, it implements the decentralized management method for user registration as described in any one of claims 1-7.
Citation Information
Patent Citations
A decentralized electronic contract storage platform account management method
CN112035892B
A Blockchain-Based Hierarchical Management Method for Electricity Data Access Control
CN116432207B
Network information security early warning method and system based on block chain technology
CN118540144A
Web3.0-oriented decentralized identity registration, authentication and recovery method and system
CN119135341A