A cloud terminal-based personal information security management method and system
By establishing a multi-module information security management system on cloud terminal devices, identifying and controlling user behavior abnormalities, judging information security, and conducting correlation and coupling analysis, the security threat problem of cloud terminal devices in complex network environments is solved, and timely response to abnormal behaviors and guaranteeing information security is achieved.
Patent Information
- Application Number
- CN202411780296.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2044-12-05
AI Technical Summary
The existing technology lacks the ability to analyze abnormal events on cloud terminal devices, and it is difficult to effectively deal with complex network environments and diversified security threats, resulting in poor management of personal information security.
Establish a personal information security management system based on cloud terminals, including cloud server construction module, user request processing module, user behavior abnormality identification module, user access control module, information security abnormality judgment module, information access control module, association coupling analysis module and association strength reporting module. Through these modules, abnormal identification, judgment and control of user behavior and information security, and conduct association coupling analysis to judge the association strength of abnormal results.
It realizes timely discovery and response to abnormal behaviors, ensures the security of personal information, and improves the security of cloud terminal devices and the effectiveness of information access control.
Smart Images

Figure CN119783071B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and more specifically to a cloud terminal-based personal information security management method and system. Background Art
[0002] With the rapid development of cloud computing technology, more and more individuals and enterprises have begun to rely on cloud services to store and process data. Cloud terminal devices serve as the interface for users to interact with cloud services, and their security is crucial to protecting user personal information. As an emerging information technology, cloud computing has powerful data storage, processing and access capabilities. Through cloud computing technology, centralized management, remote access and real-time updates of personal information can be achieved. At the same time, the elastic expansion capability of cloud computing enables the system to dynamically adjust resources according to actual needs to ensure efficient operation. These characteristics provide strong technical support for personal information security management methods based on cloud terminals.
[0003] However, due to the openness of cloud terminal devices and the complexity of the network environment, personal information faces security threats from various aspects. Traditional personal information security management methods often focus on single security measures, such as firewalls, intrusion detection systems, etc. These methods often appear to be powerless when faced with complex network environments and diverse attack methods, and lack the ability to correlate and analyze abnormal events, making it difficult to effectively respond to growing security challenges. Summary of the Invention
[0004] In order to overcome the above-mentioned defects of the prior art, the present invention provides a cloud terminal-based personal information security management system to solve the problems existing in the above-mentioned background technology.
[0005] The present invention provides the following technical solution: a cloud terminal-based personal information security management system, comprising: a cloud server construction module, a user request processing module, a user behavior anomaly identification module, a user access control module, an information security anomaly judgment module, an information access control module, a correlation coupling analysis module, and a correlation strength reporting module;
[0006] The cloud server building module connects the cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between the user and the system.
[0007] The user request processing module authenticates the user, receives the user request after verification, and extracts the user request access data and access information security data;
[0008] The user behavior anomaly identification module establishes a user behavior anomaly identification model to identify user behavior based on the user request data extracted by the user request processing module and the user historical access data stored in the system;
[0009] The user access control module receives the identification results transmitted by the user behavior anomaly identification module, performs information access control, and transmits the user request data of the identified anomaly to the correlation coupling analysis module;
[0010] The information security anomaly judgment module establishes an information security judgment model to judge the security of information based on the access information security data extracted by the user request processing module and the user access permission data stored in the system;
[0011] The information access control module receives the judgment result transmitted by the information security anomaly judgment module, performs information access control, and transmits the cloud terminal data judged to be abnormal to the correlation coupling analysis module;
[0012] The correlation coupling analysis module establishes a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength of abnormal results;
[0013] The association strength reporting module receives the judgment result of the association coupling analysis module and reports the judgment result to the interactive interface.
[0014] Preferably, in the user request processing module, the user's identity is authenticated by logging into the user's personal account, and the user's personal account login method includes account number and password login, fingerprint recognition login and face recognition login.
[0015] Preferably, in the user behavior anomaly identification module, based on the user request data extracted by the user request processing module and the user historical access data stored in the system, a user behavior anomaly identification model is established to identify user behavior. The specific contents are as follows:
[0016] Step S01: Let A represent the request frequency data set extracted at the same interval, A={A1,A2,A3,...,A n}, B represents the access time dataset extracted at the same time interval, B={B1,B2,B3,...,B n}, where n represents the total number of data in the dataset;
[0017] Step S02: Perform a one-time identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: Where Yc1 represents the result of one-time identification of user behavior for the request frequency dataset and the access time dataset, and i represents the data number in the request frequency dataset and the access time dataset;
[0018] Step S03: Perform secondary identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: Where Yc2 represents the secondary recognition result of user behavior for the request frequency dataset and the access time dataset, and i represents the data number in the request frequency dataset and the access time dataset;
[0019] Step S04: Establishing a user behavior anomaly recognition model, the calculation formula is: ΔDy = |Yc1-Yc2|, where ΔDy represents the user behavior anomaly recognition value obtained based on the primary recognition and secondary recognition of the user behavior;
[0020] Step S05: Compare the user behavior abnormality identification value ΔDy with the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data. If the user behavior abnormality identification value ΔDy is greater than or equal to the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data, the identification result is that the user behavior is abnormal. If the user behavior abnormality identification value ΔDy is less than the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data, the identification result is that the user behavior is normal.
[0021] Preferably, in the user access control module, when the result transmitted by the user behavior anomaly identification module is normal recognition, the user is allowed to continue to access the information; when the result transmitted by the user behavior anomaly identification module is abnormal recognition, the abnormal recognition result is marked and the marked abnormal result is transmitted to the correlation coupling analysis module.
[0022] Preferably, the information security anomaly judgment module establishes an information security judgment model based on the access information security data extracted by the user request processing module and the user access permission data stored in the system to judge the security of the information. The specific contents are as follows:
[0023] Step S01: extracting feature data based on user access rights data stored in the system to establish a user access rights data feature database;
[0024] Step S02: When a user accesses a data source, an information security judgment model is established to compare the changes in the user access rights data feature database before and after the user accesses the data source to judge the security of the data information.
[0025] Preferably, the specific contents of establishing the information security judgment model to compare the changes in the user access rights data feature library before and after the user access and judge the security of the data information are as follows:
[0026] Step S01: Calculate the network security coefficient of the user access permission data feature database before the user accesses the network. The calculation formula is: Where Wz represents the network security coefficient of the user access permission data feature database before the user accesses it, f1 represents the network bandwidth of the user access permission data feature database before the user accesses it, f represents the standard value of the network bandwidth of the user access permission data feature database, v1 represents the network transmission rate of the user access permission data feature database before the user accesses it, v represents the standard value of the network transmission rate of the user access permission data feature database, q1 represents the network throughput of the user access permission data feature database before the user accesses it, and q represents the standard value of the network throughput of the user access permission data feature database;
[0027] Step S02: Calculate the network security coefficient of the user access permission data feature database after the user accesses the database. The calculation formula is: Where Wh represents the network security coefficient of the user access permission data feature database after the user accesses it, f2 represents the network bandwidth of the user access permission data feature database after the user accesses it, v2 represents the network transmission rate of the user access permission data feature database after the user accesses it, and q2 represents the network throughput of the user access permission data feature database after the user accesses it.
[0028] Step S03: Calculate the change in the network security coefficient of the user access permission data feature library before and after the user access, using the following formula: ΔWx = |Wz-Wh|, where ΔWx represents the change in the network security coefficient of the user access permission data feature library before and after the user access. Compare the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access with the preset network security coefficient fluctuation threshold Δθ2. If the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access is greater than or equal to the preset network security coefficient fluctuation threshold Δθ2, the judgment result is that the network security is abnormal. If the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access is less than the preset network security coefficient fluctuation threshold Δθ2, the judgment result is that the network security is normal.
[0029] Preferably, in the information access control module, when the result transmitted by the information security anomaly judgment module is normal, the user is allowed to continue to access the information; when the result transmitted by the information security anomaly judgment module is abnormal, the abnormal result is marked and identified, and the marked abnormal result is transmitted to the associated coupling analysis module.
[0030] Preferably, in the correlation coupling analysis module, a correlation coupling analysis model is established based on the marked abnormal result and the change in the network security coefficient of the user access permission data feature library before and after the user accesses. The specific content is as follows:
[0031] Step S01: Perform abnormal inversion calculation on user behavior recognition based on the marked abnormal results. The calculation formula is: Yc 异=log2αYc1-Yc2|+log2α(1-|Yc1-Yc2|), where Yc 异 represents the user behavior abnormal inversion index, and α represents the abnormal inversion coefficient;
[0032] Step S02: Perform abnormal inversion calculation on user access judgment based on the marked abnormal result. The calculation formula is: Wh 异 =αWz-ΔWx|+αWh-ΔWx|), where Wh 异 represents the user access anomaly inversion index, and α represents the anomaly inversion coefficient;
[0033] Step S03: Calculate the abnormal correlation coupling index, the calculation formula is: Wherein λ represents the correlation coupling index. If the correlation coupling index λ is greater than or equal to the preset correlation threshold Δλ, the correlation degree of the abnormal result is judged to be strong. If the correlation coupling index λ is less than the preset correlation threshold Δλ, the correlation degree of the abnormal result is judged to be low.
[0034] Preferably, the association strength reporting module receives the judgment result of the association coupling analysis module and reports it to the interactive interface. When the judgment result is that the correlation degree of the abnormal result is strong, it means that the user behavior has a high degree of impact on the network security of the user access permission data feature library, and the user's access behavior is stopped. When the judgment result is that the correlation degree of the abnormal result is low, it means that the user behavior has a low degree of impact on the network security of the user access permission data feature library, and the user is allowed to continue access.
[0035] A cloud terminal-based personal information security management method includes the following steps:
[0036] Step S1: Connect a cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between the user and the system.
[0037] Step S2: Authenticate the user and receive the user's request after the authentication is passed;
[0038] Step S3: Based on the user request data and the user historical access data stored in the system, a user behavior anomaly recognition model is established to identify the user behavior;
[0039] Step S4: Receive the user behavior abnormality identification result and perform information access control;
[0040] Step S5: Based on the access information security data and the user access permission data stored in the system, an information security judgment model is established to judge the security of the information;
[0041] Step S6: Receive the information security anomaly judgment result and perform information access control;
[0042] Step S7: Establish a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength.
[0043] Step S8: reporting the judgment result to the interactive interface.
[0044] Technical effects and advantages of the present invention:
[0045] The present invention is equipped with a cloud server construction module, a user request processing module, a user behavior anomaly identification module, a user access control module, an information security anomaly judgment module, an information access control module, an association coupling analysis module and an association strength reporting module. Based on user request data and user historical access data stored in the system, a user behavior anomaly identification model is established to identify user behavior. Based on access information security data and user access permission data stored in the system, an information security judgment model is established to judge the security of information. Information access control is performed according to the abnormal results. An association coupling model is established to perform association coupling analysis on the abnormal data, the association strength of the abnormal results is judged, abnormal behavior is discovered and responded to in a timely manner, and the security of personal information is ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 This is a flow chart of a cloud terminal-based personal information security management system.
[0047] Figure 2 The figure is a flow chart of a method for personal information security management based on cloud terminals. DETAILED DESCRIPTION
[0048] The technical solutions of the present invention will be clearly and completely described below in conjunction with the drawings in the present invention. In addition, the forms of the various structures described in the following embodiments are merely examples. The cloud terminal-based personal information security management method and system involved in the present invention are not limited to the various structures described in the following embodiments. All other implementations obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0049] like Figure 1 As shown, the present invention provides a cloud terminal-based personal information security management system, including: a cloud server construction module, a user request processing module, a user behavior anomaly identification module, a user access control module, an information security anomaly judgment module, an information access control module, a correlation coupling analysis module, and a correlation strength reporting module;
[0050] The cloud server building module connects the cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between the user and the system.
[0051] The user request processing module authenticates the user, receives the user request after verification, and extracts the user request access data and access information security data;
[0052] The user behavior anomaly identification module establishes a user behavior anomaly identification model to identify user behavior based on the user request data extracted by the user request processing module and the user historical access data stored in the system;
[0053] The user access control module receives the identification results transmitted by the user behavior anomaly identification module, performs information access control, and transmits the user request data of the identified anomaly to the correlation coupling analysis module;
[0054] The information security anomaly judgment module establishes an information security judgment model to judge the security of information based on the access information security data extracted by the user request processing module and the user access permission data stored in the system;
[0055] The information access control module receives the judgment result transmitted by the information security anomaly judgment module, performs information access control, and transmits the cloud terminal data judged to be abnormal to the correlation coupling analysis module;
[0056] The correlation coupling analysis module establishes a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength of abnormal results;
[0057] The association strength reporting module receives the judgment result of the association coupling analysis module and reports the judgment result to the interactive interface.
[0058] In this embodiment, it should be specifically explained that in the user request processing module, the user's identity is authenticated by logging into the user's personal account. The user's personal account login method includes account number and password login, fingerprint recognition login, and face recognition login;
[0059] The user request access data includes a request frequency data set extracted at the same time interval and an access time data set extracted at the same time interval; the access information security data includes the network bandwidth of the user access permission data feature library before the user accesses, the network bandwidth of the user access permission data feature library after the user accesses, the network transmission rate of the user access permission data feature library before the user accesses, the network transmission rate of the user access permission data feature library after the user accesses, the network throughput of the user access permission data feature library before the user accesses, and the network throughput of the user access permission data feature library after the user accesses.
[0060] In this embodiment, it should be specifically explained that, in the user behavior anomaly identification module, based on the user request data extracted by the user request processing module and the user historical access data stored in the system, the user behavior anomaly identification model is established to identify user behavior. The specific contents are as follows:
[0061] Step S01: Let A represent the request frequency data set extracted at the same interval, A={A1,A2,A3,...,A n}, B represents the access time dataset extracted at the same time interval, B={B1,B2,B3,...,B n}, where n represents the total number of data in the dataset;
[0062] Step S02: Perform a one-time identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: Where Yc1 represents the result of one-time identification of user behavior for the request frequency dataset and the access time dataset, and i represents the data number in the request frequency dataset and the access time dataset;
[0063] Step S03: Perform secondary identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: Where Yc2 represents the secondary recognition result of user behavior for the request frequency dataset and the access time dataset, and i represents the data number in the request frequency dataset and the access time dataset;
[0064] Step S04: Establishing a user behavior anomaly recognition model, the calculation formula is: ΔDy = |Yc1-Yc2|, where ΔDy represents the user behavior anomaly recognition value obtained based on the primary recognition and secondary recognition of the user behavior;
[0065] Step S05: Compare the user behavior abnormality identification value ΔDy with the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data. If the user behavior abnormality identification value ΔDy is greater than or equal to the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data, the identification result is that the user behavior is abnormal. If the user behavior abnormality identification value ΔDy is less than the user behavior abnormality identification threshold Δθ1 preset by the cloud terminal based on the user's historical behavior data, the identification result is that the user behavior is normal.
[0066] In this embodiment, it should be specifically explained that in the user access control module, when the result transmitted by the user behavior anomaly identification module is normal recognition, the user is allowed to continue to access the information; when the result transmitted by the user behavior anomaly identification module is abnormal recognition, the abnormal recognition result is marked and the marked abnormal result is transmitted to the associated coupling analysis module.
[0067] In this embodiment, it should be specifically explained that, in the information security anomaly judgment module, based on the access information security data extracted by the user request processing module and the user access permission data stored in the system, the information security judgment model is established to judge the security of the information. The specific contents are as follows:
[0068] Step S01: extracting feature data based on user access rights data stored in the system to establish a user access rights data feature database;
[0069] Step S02: When a user accesses a data source, an information security judgment model is established to compare the changes in the user access rights data feature database before and after the user accesses the data source to judge the security of the data information.
[0070] In this embodiment, it should be specifically explained that the establishment of the information security judgment model compares the changes in the user access rights data feature library before and after the user accesses the data, and judges the security of the data information in detail as follows:
[0071] Step S01: Calculate the network security coefficient of the user access permission data feature database before the user accesses the network. The calculation formula is: Where Wz represents the network security coefficient of the user access permission data feature database before the user accesses it, f1 represents the network bandwidth of the user access permission data feature database before the user accesses it, f represents the standard value of the network bandwidth of the user access permission data feature database, v1 represents the network transmission rate of the user access permission data feature database before the user accesses it, v represents the standard value of the network transmission rate of the user access permission data feature database, q1 represents the network throughput of the user access permission data feature database before the user accesses it, and q represents the standard value of the network throughput of the user access permission data feature database;
[0072] Step S02: Calculate the network security coefficient of the user access permission data feature database after the user accesses the database. The calculation formula is: Where Wh represents the network security coefficient of the user access permission data feature database after the user accesses it, f2 represents the network bandwidth of the user access permission data feature database after the user accesses it, v2 represents the network transmission rate of the user access permission data feature database after the user accesses it, and q2 represents the network throughput of the user access permission data feature database after the user accesses it.
[0073] Step S03: Calculate the change in the network security coefficient of the user access permission data feature library before and after the user access, using the following formula: ΔWx = |Wz-Wh|, where ΔWx represents the change in the network security coefficient of the user access permission data feature library before and after the user access. Compare the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access with the preset network security coefficient fluctuation threshold Δθ2. If the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access is greater than or equal to the preset network security coefficient fluctuation threshold Δθ2, the judgment result is that the network security is abnormal. If the change ΔWx in the network security coefficient of the user access permission data feature library before and after the user access is less than the preset network security coefficient fluctuation threshold Δθ2, the judgment result is that the network security is normal.
[0074] In this embodiment, it should be specifically explained that in the information access control module, when the result transmitted by the information security anomaly judgment module is normal, the user is allowed to continue to access the information; when the result transmitted by the information security anomaly judgment module is abnormal, the abnormal result is marked and identified, and the marked abnormal result is transmitted to the associated coupling analysis module.
[0075] In this embodiment, it should be specifically explained that, in the correlation coupling analysis module, a correlation coupling analysis model is established based on the user behavior abnormality identification value and the change in the network security coefficient of the user access permission data feature library before and after the user access, according to the marked abnormal results. The specific content is as follows:
[0076] Step S01: Perform abnormal inversion calculation on user behavior recognition based on the marked abnormal results. The calculation formula is: Yc 异 =log2αYc1-Yc2|+log2α(1-|Yc1-Yc2|), where Yc 异 represents the user behavior abnormal inversion index, and α represents the abnormal inversion coefficient;
[0077] Step S02: Perform abnormal inversion calculation on user access judgment based on the marked abnormal result. The calculation formula is: Wh 异 =αWz-ΔWx|+αWh-ΔWx), where Wh 异 represents the user access anomaly inversion index, and α represents the anomaly inversion coefficient;
[0078] Step S03: Calculate the abnormal correlation coupling index, the calculation formula is: Wherein λ represents the correlation coupling index. If the correlation coupling index λ is greater than or equal to the preset correlation threshold Δλ, the correlation degree of the abnormal result is judged to be strong. If the correlation coupling index λ is less than the preset correlation threshold Δλ, the correlation degree of the abnormal result is judged to be low.
[0079] In this embodiment, it should be specifically explained that the association strength reporting module receives the judgment result of the association coupling analysis module and reports it to the interactive interface. When the judgment result is that the correlation degree of the abnormal result is strong, it means that the user behavior has a high degree of impact on the network security of the user access permission data feature library, and the user's access behavior is stopped. When the judgment result is that the correlation degree of the abnormal result is low, it means that the user behavior has a low degree of impact on the network security of the user access permission data feature library, and the user is allowed to continue access.
[0080] like Figure 2 As shown, in this embodiment, it should be specifically explained that a cloud terminal-based personal information security management method includes the following steps:
[0081] Step S1: Connect a cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between the user and the system.
[0082] Step S2: Authenticate the user and receive the user's request after the authentication is passed;
[0083] Step S3: Based on the user request data and the user historical access data stored in the system, a user behavior anomaly recognition model is established to identify the user behavior;
[0084] Step S4: Receive the user behavior abnormality identification result and perform information access control;
[0085] Step S5: Based on the access information security data and the user access permission data stored in the system, an information security judgment model is established to judge the security of the information;
[0086] Step S6: Receive the information security anomaly judgment result and perform information access control;
[0087] Step S7: Establish a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength.
[0088] Step S8: reporting the judgment result to the interactive interface.
[0089] In this embodiment, it should be specifically explained that the difference between this embodiment and the prior art mainly lies in that this embodiment is equipped with a cloud server construction module, a user request processing module, a user behavior anomaly identification module, a user access control module, an information security anomaly judgment module, an information access control module, an association coupling analysis module and an association strength reporting module. Based on the user request data and the user historical access data stored in the system, a user behavior anomaly identification model is established to identify user behavior. Based on the access information security data and the user access permission data stored in the system, an information security judgment model is established to judge the security of information. Information access control is performed according to the abnormal results. An association coupling model is established to perform association coupling analysis on the abnormal data to judge the association strength of the abnormal results. Through the association analysis of abnormal events, abnormal behavior is discovered and responded to in a timely manner to ensure the security of personal information.
[0090] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
[0091] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A cloud terminal-based personal information security management system, characterized by: include: The cloud server building module connects the cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between users and the system. The user request processing module authenticates the user, receives the user request after verification, and extracts the user request access data and access information security data; The user behavior anomaly identification module establishes a user behavior anomaly identification model based on the user request data extracted by the user request processing module and the user historical access data stored in the system to identify user behavior: Create a request frequency dataset A and an access time dataset B, and perform a one-time user behavior recognition on the request frequency dataset and the access time dataset. The recognition formula is: , perform secondary recognition of user behavior on the request frequency dataset and access time dataset, and the recognition formula is: ; Establish a user behavior anomaly recognition model, the calculation formula is: ; The user access control module receives the recognition results transmitted by the user behavior anomaly recognition module, performs information access control, and transmits the user request data of the identified anomaly to the correlation coupling analysis module; The information security anomaly judgment module establishes an information security judgment model to judge the security of information based on the access information security data extracted by the user request processing module and the user access permission data stored in the system; The information access control module receives the judgment results transmitted by the information security anomaly judgment module, performs information access control, and transmits the cloud terminal data judged to be abnormal to the correlation coupling analysis module; The correlation coupling analysis module establishes a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength of abnormal results; The correlation strength reporting module receives the judgment result of the correlation coupling analysis module and reports the judgment result to the interactive interface.
2. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the user request processing module, the user's identity is authenticated by logging into the user's personal account. The user's personal account login method includes account number and password login, fingerprint recognition login and face recognition login.
3. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the user behavior anomaly identification module, based on the user request data extracted by the user request processing module and the user historical access data stored in the system, a user behavior anomaly identification model is established to identify user behavior. The specific contents are as follows: Step S01: Let A represent the request frequency dataset extracted at the same interval time, , B represents the access time dataset extracted at the same interval time, , where n represents the total number of data in the dataset; Step S02: Perform a one-time identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: ,in It represents the result of one-time identification of user behavior for the request frequency dataset and access time dataset, i represents the data number in the request frequency dataset and access time dataset; Step S03: Perform secondary identification of user behavior on the request frequency dataset and the access time dataset. The identification formula is: ,in It represents the secondary recognition result of user behavior for the request frequency dataset and access time dataset, and i represents the data number in the request frequency dataset and access time dataset; Step S04: Establish a user behavior anomaly recognition model, the calculation formula is: ,in Indicates the user behavior anomaly identification value obtained based on the primary and secondary identification of user behavior; Step S05: Identify the abnormal behavior of the user The user behavior anomaly recognition threshold preset by the cloud terminal based on the user's historical behavior data Compare and identify abnormal user behavior. Greater than or equal to the user behavior anomaly recognition threshold preset by the cloud terminal based on the user's historical behavior data , then the recognition result is that the user behavior is abnormal. If the user behavior abnormal recognition value Smaller than the user behavior anomaly recognition threshold preset by the cloud terminal based on the user's historical behavior data , the recognition result is that the user behavior is normal.
4. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the user access control module, when the result transmitted by the user behavior anomaly identification module is normal recognition, the user is allowed to continue to access information; when the result transmitted by the user behavior anomaly identification module is abnormal recognition, the abnormal recognition result is marked and the marked abnormal result is transmitted to the correlation coupling analysis module.
5. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the information security anomaly judgment module, based on the access information security data extracted by the user request processing module and the user access permission data stored in the system, an information security judgment model is established to judge the security of information. The specific contents are as follows: Step S01: extracting feature data based on user access rights data stored in the system to establish a user access rights data feature database; Step S02: When a user accesses a data source, an information security judgment model is established to compare the changes in the user access rights data feature database before and after the user accesses the data source to judge the security of the data information.
6. The cloud terminal-based personal information security management system according to claim 5, characterized in that: The specific contents of establishing the information security judgment model to compare the changes in the user access rights data feature database before and after the user access and judge the security of the data information are as follows: Step S01: Calculate the network security coefficient of the user access permission data feature database before the user accesses the network. The calculation formula is: ,in Indicates the network security coefficient of the user access permission data feature database before the user accesses it. Indicates the network bandwidth of the user access permission data feature database before the user accesses it. Indicates the network bandwidth standard value of the user access permission data feature database. Indicates the network transmission rate of the user access permission data feature database before the user accesses it. Indicates the standard value of the network transmission rate of the user access permission data feature database. Indicates the network throughput of the user access permission data feature database before the user accesses it. Indicates the network throughput standard value of the user access permission data feature database; Step S02: Calculate the network security coefficient of the user access permission data feature database after the user accesses the database. The calculation formula is: ,in Indicates the network security coefficient of the user access permission data feature database after the user accesses it. Indicates the network bandwidth of the user access permission data feature database after the user accesses it. Indicates the network transmission rate of the user access permission data feature database after the user accesses it. Indicates the network throughput of the user access permission data feature database after the user accesses it; Step S03: Calculate the change in the network security coefficient of the user access permission data feature database before and after the user accesses the network. The calculation formula is: ,in Indicates the change in the network security coefficient of the user access permission data feature database before and after the user accesses. The preset network security coefficient fluctuation threshold For comparison, if the change in the network security coefficient of the user access permission data feature database before and after the user accesses Greater than or equal to the preset network security coefficient fluctuation threshold , then the judgment result is network security anomaly. If the change in the network security coefficient of the user access permission data feature database before and after the user accesses Less than the preset network security coefficient fluctuation threshold , the judgment result is that the network security is normal.
7. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the information access control module, when the result transmitted by the information security anomaly judgment module is normal, the user is allowed to continue to access the information. When the result transmitted by the information security anomaly judgment module is abnormal, the abnormal result is marked and identified, and the marked abnormal result is transmitted to the association coupling analysis module.
8. The cloud terminal-based personal information security management system according to claim 1, characterized in that: In the correlation coupling analysis module, a correlation coupling analysis model is established based on the marked abnormal results, the user behavior abnormality identification value and the change in the network security coefficient of the user access permission data feature library before and after the user access. The specific content is as follows: Step S01: Perform abnormal inversion calculation on user behavior recognition based on the marked abnormal results. The calculation formula is: ,in Indicates the user behavior abnormal inversion index, represents the anomalous inversion coefficient, Indicates the result of a one-time identification of user behavior for the request frequency dataset and access time dataset. Indicates the secondary identification results of user behavior for the request frequency dataset and access time dataset; Step S02: Perform abnormal inversion calculation on user access judgment based on the marked abnormal result. The calculation formula is: ,in Indicates the user access abnormal inversion index, represents the anomalous inversion coefficient, Indicates the network security coefficient of the user access permission data feature database before the user accesses it. Indicates the network security coefficient of the user access permission data feature database after the user accesses it. Indicates the change in the network security coefficient of the user access permission data feature database before and after the user accesses; Step S03: Calculate the abnormal correlation coupling index, the calculation formula is: ,in Represents the correlation coupling index. If the correlation coupling index Greater than or equal to the preset correlation threshold , then the correlation degree of the abnormal results is judged to be strong. If the correlation coupling index Less than the preset correlation threshold , then the correlation degree of the abnormal results is judged to be low.
9. The cloud terminal-based personal information security management system according to claim 1, characterized in that: The association strength reporting module receives the judgment result of the association coupling analysis module and reports it to the interactive interface. When the judgment result shows that the correlation degree of the abnormal result is strong, it means that the user behavior has a high degree of impact on the network security of the user access permission data feature library, and the user's access behavior is stopped. When the judgment result shows that the correlation degree of the abnormal result is low, it means that the user behavior has a low degree of impact on the network security of the user access permission data feature library, and the user is allowed to continue access.
10. A cloud-based terminal personal information security management method, for using the cloud-based terminal personal information security management system according to any one of claims 1 to 9, characterized in that: The following steps are involved: Step S1: Connect a cloud server to multiple cloud terminal devices. The cloud server stores and processes user data, and the cloud terminal devices provide an interactive interface between the user and the system. Step S2: Authenticate the user and receive the user's request after the authentication is passed; Step S3: Based on the user request data and the user historical access data stored in the system, a user behavior anomaly recognition model is established to identify the user behavior; Step S4: Receive the user behavior abnormality identification result and perform information access control; Step S5: Based on the access information security data and the user access permission data stored in the system, an information security judgment model is established to judge the security of the information; Step S6: Receive the information security anomaly judgment result and perform information access control; Step S7: Establish a correlation coupling model to perform correlation coupling analysis on abnormal data and determine the correlation strength; Step S8: reporting the judgment result to the interactive interface.
Citation Information
Patent Citations
Network access control system equipment fingerprint information identification technology
CN118317315A