A method and device for encrypting enterprise internal data keys

By generating a two-dimensional digital map in the office and tracking employee locations in real time, clustering employee movement trajectories, judging position change behavior, and generating dynamic keys, the problem of key updates when employees change positions is solved, achieving efficient data security and improving office efficiency.

CN119815287BActive Publication Date: 2025-10-03E SURFING VISION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411933730.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-10-03
Estimated Expiration
2044-12-26

AI Technical Summary

Technical Problem

When deploying an RFID network in an office, how can dynamic keys be updated in real time based on changes in employee mobility? In particular, when an employee changes positions, keys bound to the new workstation are generated in a timely manner to prevent data leakage caused by incorrect key use. At the same time, how can the smooth replacement of old and new keys be achieved to avoid security vulnerabilities in the data encryption and decryption process?

Method used

By obtaining the pre-established office RFID distribution map, a two-dimensional digital indoor map is generated, employee locations are tracked in real time, employee movement trajectories are clustered, position change behavior is determined, dynamic keys are generated, and keys are updated using a multi-factor dynamic password algorithm. Behavior patterns are continuously monitored and key update strategies and frequencies are dynamically adjusted.

Benefits of technology

It achieves continuous and accurate tracking of employee locations, dynamically generates high-strength encryption keys, improves the company's office efficiency and data security, and ensures data security without loopholes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119815287B_ABST
    Figure CN119815287B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and device for encrypting internal enterprise data keys, belonging to the field of data encryption technology. The method comprises: each employee in the office wears a radio frequency identifier to obtain the employee's location coordinates, continuously tracking changes in the employee's location coordinates to obtain the employee's movement trajectory data within the office; clustering the employee's historical movement trajectory to obtain a clustering model; judging whether the employee has changed positions based on the employee's movement trajectory data within the office and the clustering model; if the judgment result is that the employee has changed positions, updating the employee's area information and determining whether to adjust a pre-set threshold; generating snapshots of the employee's movement status at two time points before and after the change of position to determine whether there is abnormal position change behavior; updating the clustering model; and if the result is abnormal position change behavior, triggering a dynamic key update, encrypting the employee's sensitive data that needs to be encrypted and stored. The present invention continuously tracks the employee's position and dynamically generates an encryption key based on the change pattern of the position.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of enterprise internal data encryption, and in particular relates to an enterprise internal data key encryption method and device. Background Art

[0002] Deploying RFID networks within offices presents the technical challenge of updating dynamic keys in real time based on employee mobility. Employee mobility includes multiple factors, such as location coordinates, movement trajectory, and duration of stay, and the weighting of each factor is difficult to determine. Employee position changes within an office are common due to project adjustments, team reorganizations, or work efficiency optimization. Especially when employee positions change, their existing mobility patterns change dramatically. Keys tied to the new workstations must be generated promptly and the old keys revoked. This ensures that the keys are tied to the employees' actual workstations and prevents data leaks caused by misuse. Furthermore, the frequency of mobility changes must be considered, and the key update frequency must be adjusted adaptively. Furthermore, ensuring a smooth transition between old and new keys during key updates to avoid security vulnerabilities in the data encryption and decryption process is a significant challenge. Therefore, designing a dynamic key update mechanism that comprehensively leverages multiple mobility factors, adapts to the update frequency, and ensures foolproof data security is a pressing technical challenge. Summary of the Invention

[0003] In view of the above-mentioned deficiencies in the existing technology, the purpose of the invention is to provide a method and device for encrypting internal enterprise data keys, which realizes continuous and accurate tracking of employee locations, and dynamically generates high-strength encryption keys based on the changing patterns of location data, significantly improving the office efficiency and data security of the enterprise.

[0004] The first aspect of the present invention provides a method for encrypting enterprise internal data keys, comprising:

[0005] Obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, obtain the employee's location coordinates from each employee wearing an RFID, and record the timestamp of the employee's location change, the employee's location coordinates, and the RFID ID number;

[0006] Match the employee's location coordinates with the pre-established office RFID distribution map to determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain employee movement trajectory data within the office;

[0007] Clustering employees' historical movement trajectories to generate a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it is determined whether the employee has changed locations. If the judgment result is that the employee has changed locations, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff then determines whether to adjust the pre-set threshold based on the employee's position and authority level information.

[0008] Generate employee mobility status snapshots at two time points before and after the job swap, extract features from the mobility status snapshots, optimize feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is abnormal job swap behavior;

[0009] The movement trajectory data before and after the job change is segmented based on key behavioral indicators. The employee's dwell time at the original and new workstations is counted, and the movement and dwell frequencies are calculated. The movement direction change rate indicator is introduced to update the feature vector, and the clustering model is updated based on the updated feature vector.

[0010] If the result is determined to be an abnormal position change, a dynamic key update is triggered. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and simultaneously invalidate the old key associated with the original workstation.

[0011] Use the dynamic key as the key of the symmetric encryption algorithm to encrypt sensitive employee data that needs to be encrypted and stored;

[0012] Continuously monitor employees' movement trajectories and behavior patterns at new workstations, and dynamically adjust key update strategies and frequencies based on employee behavior patterns at new workstations and patterns in the updated clustering model.

[0013] The second aspect of the present invention further provides an enterprise internal data key encryption device, comprising:

[0014] Acquisition module: used to obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, obtain the employee's location coordinates, and record the timestamp of the employee's location change, the employee's location coordinates and the RFID number;

[0015] Continuous tracking module: used to match the employee's location coordinates with the pre-established office RFID distribution map, determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain the employee's movement trajectory data within the office;

[0016] Update module: This module clusters employees' historical movement trajectories to generate a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it determines whether the employee has changed locations. If so, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff then determines whether to adjust the pre-set threshold based on the employee's position and authority level.

[0017] Determination module: This module is used to generate employee mobility status snapshots at two time points before and after the position change, extract features from the mobility status snapshots, optimize the feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is any abnormal position change behavior.

[0018] Clustering module: This module segments movement trajectory data before and after job change based on key behavioral indicators, counts employee dwell time at their original and new workstations, calculates movement and dwell frequencies, introduces a movement direction change rate indicator to update feature vectors, and updates the clustering model based on the updated feature vectors.

[0019] Generation module: If the result is determined to be an abnormal position change, it triggers a dynamic key update. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and simultaneously invalidate the old key associated with the original workstation.

[0020] Encryption module: used to use the dynamic key as the key of the symmetric encryption algorithm to encrypt sensitive employee data that needs to be encrypted and stored;

[0021] Dynamic adjustment module: used to continuously monitor the movement trajectories and behavior patterns of employees at new workstations, and dynamically adjust the key update strategy and frequency based on the employee behavior patterns at the new workstations and the patterns in the updated clustering model.

[0022] A third aspect of the present invention further provides an electronic device, comprising: a processor and a memory;

[0023] The processor is used to execute any one of the above enterprise internal data key encryption methods by calling the program or instruction stored in the memory.

[0024] In a fourth aspect, the present invention further proposes a computer-readable storage medium, which stores a program or instruction, and the program or instruction enables a computer to execute any one of the above-mentioned enterprise internal data key encryption methods.

[0025] The beneficial effects of the present invention are as follows: The present invention first establishes a distribution map of radio frequency identifiers in the office, obtains employee location coordinates in real time, and determines the area they are in. When an employee changes positions, a snapshot of their movement status before and after the change is generated, key behavioral indicators are extracted, and the employee behavior pattern clustering model is updated. At the same time, a new key is generated based on the multi-factor dynamic password bound to the new workstation, which is used to encrypt the employee's sensitive data. The present invention also dynamically adjusts the key update strategy and frequency based on the employee's behavioral stability at the new workstation, thereby improving system efficiency while ensuring data security. This method of combining employee location awareness with dynamic key management effectively improves the security of sensitive data in an office environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings are only for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. Throughout the drawings, the same reference numerals represent the same components. Obviously, the drawings described below are only some of the embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings.

[0027] Figure 1 A diagram of a method for encrypting enterprise internal data keys provided by an embodiment of the present invention;

[0028] Figure 2 A diagram of a method for generating employee movement trajectory data in an office provided by an embodiment of the present invention;

[0029] Figure 3 A diagram of a method for determining whether to adjust a preset threshold provided by an embodiment of the present invention;

[0030] Figure 4 A diagram of a method for determining whether abnormal transposition behavior exists provided by an embodiment of the present invention;

[0031] Figure 5 A diagram of a method for updating a clustering model provided by an embodiment of the present invention;

[0032] Figure 6 A diagram of a dynamic key update method provided by an embodiment of the present invention;

[0033] Figure 7 A diagram of an internal enterprise data key encryption device provided by an embodiment of the present invention;

[0034] Figure 8 A schematic block diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0035] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described are part of the embodiments of the present invention, rather than all of the embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work should fall within the scope of protection of the present invention.

[0036] Furthermore, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts disclosed in the present invention.

[0037] In the description of this invention, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The terms "mounted," "connected," and "connected" should be interpreted broadly, meaning, for example, fixed, removable, or integral; mechanical or electrical; direct or indirect through an intermediary; and internal communication between two components. Those skilled in the art will understand the specific meanings of these terms in this invention on a case-by-case basis.

[0038] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of methods and systems consistent with certain aspects of the present invention, as detailed in the appended claims.

[0039] The present invention proposes a method, device, electronic device and storage medium for encrypting internal enterprise data keys, which realizes continuous and accurate tracking of employee locations and dynamically generates high-strength encryption keys based on the changing patterns of location data, significantly improving the company's office efficiency and data security.

[0040] K-means algorithm: K-means is an iterative cluster analysis algorithm. Its steps are to pre-divide the data into K groups, randomly select K objects as the initial cluster centers, and then calculate the distance between each object and each seed cluster center, and assign each object to the cluster center closest to it.

[0041] Method Example

[0042] Figure 1 A diagram of a method for encrypting enterprise internal data keys provided by an embodiment of the present invention.

[0043] The first aspect of the present invention proposes an enterprise internal data key encryption method, combined with Figure 1 , including eight steps from S1 to S8:

[0044] S1: Obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, each employee in the office wears an RFID, obtain the employee's location coordinates, and record the timestamp of the employee's location change, the employee's location coordinates and the RFID number.

[0045] Specifically, in an embodiment of the present invention, a method for generating a two-dimensional digital indoor map, obtaining employee location coordinates, and recording a timestamp of employee location changes, employee location coordinates, and RFID number is described in detail below.

[0046] In some embodiments, the moving speed is calculated based on the distance between two consecutive sampling positions. If the moving speed exceeds a preset speed threshold, the sampling frequency is increased; if the moving speed is lower than the preset speed threshold, the sampling frequency is reduced; based on the RFID network topology, the residence time of the RFID number in different RFID coverage areas is calculated, and the residence time data is clustered using the K-means algorithm to obtain the frequent activity areas of the employees corresponding to the RFID numbers; the Floyd-Warshall algorithm is used to calculate the shortest path in the RFID network, and based on the shortest path and the actual movement trajectory of the RFID number, a network diagram of the frequently used paths of the employees corresponding to the RFID numbers is obtained.

[0047] S2: Match the employee's location coordinates with the pre-established office RFID distribution map to determine the employee's current office area, and continuously track the changes in the employee's location coordinates to obtain the employee's movement trajectory data in the office.

[0048] Specifically, in an embodiment of the present invention, a method for matching an employee's location coordinates with a pre-established office RFID distribution map, determining the employee's current office area, and continuously tracking changes in the employee's location coordinates to obtain the employee's movement trajectory data within the office is described in detail below.

[0049] S3: Cluster the employee's historical movement trajectory to obtain a clustering model. Based on the employee's movement trajectory data in the office and the clustering model, determine whether the employee has changed positions. If the judgment result is that the employee has changed positions, update the employee's area information and send an abnormal alarm information to the monitoring center. The monitoring center staff determines whether to adjust the pre-set threshold based on the employee's position and authority level information.

[0050] Specifically, in an embodiment of the present invention, a method for obtaining a clustering model, determining whether an employee has changed positions, updating employee location information, and adjusting a preset threshold is described in detail below.

[0051] S4: Generate employee mobility status snapshots at two time points before and after the position change, extract features from the mobility status snapshots, optimize the feature vector dimensions through feature selection algorithms, extract key behavioral indicators, and determine whether there is abnormal position change behavior.

[0052] Specifically, in an embodiment of the present invention, a method for generating a mobile state snapshot, extracting features from the mobile state snapshot, optimizing the feature vector dimension through a feature selection algorithm, extracting key behavior indicators, and determining whether abnormal transposition behavior exists is described in detail below.

[0053] S5: Segment the movement trajectory data before and after the position change based on key behavioral indicators, count the length of time employees spend at their original and new workstations, calculate the movement frequency and stay frequency, introduce the movement direction change rate indicator to update the feature vector, and update the clustering model based on the updated feature vector.

[0054] Specifically, in an embodiment of the present invention, the movement trajectory data before and after the position change is segmented according to key behavioral indicators, the length of time employees stay at the original workstation and the new workstation is counted, the movement frequency and the stay frequency are calculated, and the movement direction change rate indicator is introduced to update the feature vector. The method of updating the clustering model according to the updated feature vector is described in detail below.

[0055] S6: If the result is determined to be an abnormal position change behavior, a dynamic key update is triggered. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and at the same time, the old key associated with the original workstation is revoked.

[0056] Specifically, in the embodiment of the present invention, the method for dynamic key update is described in detail below.

[0057] S7: Use the dynamic key as the key of the symmetric encryption algorithm to encrypt employee sensitive data that needs to be encrypted and stored.

[0058] Specifically, in an embodiment of the present invention, a method for encrypting employee sensitive data that needs to be encrypted and stored is described in detail below.

[0059] S8: Continuously monitor the movement trajectories and behavior patterns of employees at new workstations, and dynamically adjust the key update strategy and frequency based on the employee behavior patterns at the new workstations and the patterns in the updated clustering model.

[0060] Specifically, in an embodiment of the present invention, if the employee's behavior pattern at the new workstation is stable and consistent with the pattern in the updated clustering model, the key update frequency is reduced; conversely, if the employee's behavior pattern fluctuates greatly or does not conform to the updated clustering model, the key update frequency is increased to ensure data security.

[0061] Furthermore, in the above-mentioned method for encrypting internal enterprise data keys, the pre-established office RFID distribution map includes: the location coordinates of each RFID, coverage parameters, and the topological relationship between the RFIDs;

[0062] The 2D digital indoor map includes: precise RFID coordinates, coverage radius, and neighboring RFID numbers;

[0063] Obtaining the employee's location coordinates, including: using a least squares method to calculate the relative position of the radio frequency identifier in a pre-established office radio frequency identifier distribution map, and obtaining the employee's location coordinates based on the relative position and a two-dimensional digitized indoor map;

[0064] Recording the timestamp of employee location changes, the employee's location coordinates, and the radio frequency identifier number includes: using a time series database to record the timestamp of employee location changes, the employee's location coordinates, and the radio frequency identifier number.

[0065] Figure 2 A diagram of a method for generating employee movement trajectory data in an office provided by an embodiment of the present invention.

[0066] Furthermore, in the above-mentioned enterprise internal data key encryption method, the employee's location coordinates are matched with the pre-established office radio frequency identification device distribution map to determine the employee's current office area, and the employee's location coordinate changes are continuously tracked to obtain the employee's movement trajectory data in the office. Figure 2 , including five steps from S21 to S25:

[0067] S21: Using an R-tree as a spatial index structure to store the RFID distribution map, dividing the office area into grid units based on the RFID distribution map, and establishing a mapping relationship between the grid units and the RFIDs;

[0068] S22: Receive the employee's location coordinates, quickly locate the grid cell where the employee's location coordinates are located using the R-tree; determine the employee's current office area based on the mapping relationship between the grid cell and the RFID;

[0069] S23: Continuously collect employee location coordinates using a sliding time window method to obtain an employee location coordinate sequence;

[0070] S24: performing data smoothing processing on the employee position coordinate sequence;

[0071] S25: Fitting the smoothed coordinates using a cubic Bezier curve, where each four consecutive points of the cubic Bezier curve are used as a set of control points; and generating employee movement trajectory data within the office based on the cubic Bezier curve.

[0072] For example, an R-tree is used as a spatial index structure to store the RFID distribution map. The office area is divided into 5m x 5m grid cells, each associated with a corresponding RFID coverage area. A mapping relationship between grid cells and RFIDs is established. After obtaining the employee's location coordinates, the R-tree is used to quickly locate the grid cell. The mapping relationship between grid cells and RFIDs is used to determine the employee's current office area. If the employee's location falls on the boundary of multiple grid cells, the office area corresponding to the RFID with the highest signal strength is selected. A sliding time window method is used to record changes in employee location coordinates. A 30-second time window is set, sliding every 5 seconds. Within each time window, employee location coordinates are continuously collected at 1-second intervals to form a coordinate sequence. The coordinate sequence is smoothed using a moving average method, taking the average of the two preceding and following points as the smoothed coordinates to eliminate noise points. The coordinate sequence is then fitted with a cubic Bezier curve, with every four consecutive points serving as a set of control points to generate employee movement trajectory data within the office. The resulting movement trajectory data includes a timestamp, smoothed coordinate points, and the corresponding Bezier curve parameters.

[0073] Figure 3 A diagram of a method for determining whether to adjust a preset threshold value provided by an embodiment of the present invention.

[0074] Furthermore, in the above-mentioned internal data key encryption method, the historical movement trajectory of employees is clustered to obtain a clustering model, and whether the employee has changed positions is determined based on the employee's movement trajectory data in the office and the clustering model. If the judgment result is that the employee has changed positions, the employee's area information is updated, and an abnormal alarm information is sent to the monitoring center. The staff of the monitoring center determines whether to adjust the preset threshold according to the employee's position and authority level information, and combines Figure 3 , including six steps from S31 to S36:

[0075] S31: Based on the employee's historical trajectory data, a K-means clustering algorithm is used to perform cluster analysis to determine the center points of the employee's main daily activity areas. If the employee is a new employee or has just changed workstations, their trajectory data from the first week is used for clustering. The clustering results are updated daily until the clustering model stabilizes.

[0076] S32: Obtain employee movement trajectory data, segment the trajectory data using a sliding time window method, and obtain the average movement speed and trajectory direction within each time window;

[0077] S33: Calculate the Euclidean distance between the employee's current location and the cluster center, and determine whether the employee has left the regular activity area based on the Euclidean distance;

[0078] S34: If the Euclidean distance exceeds a preset threshold, it is determined that the employee has left the regular activity area;

[0079] S35: For employees who have left their regular activity area, their stay time in the new area is calculated; if the stay time exceeds a preset time threshold, a position change is determined, the employee's area information is updated, and an abnormal alarm information is sent to the monitoring center;

[0080] S36: Obtain the employee's position and authority level information, and the monitoring center staff determines whether to adjust the preset threshold and the preset time threshold based on the employee's position and authority level information.

[0081] Exemplarily, the sliding time window method is used to segment the employee movement trajectory data, and the window size is set to 5 minutes, sliding every 30 seconds. The average movement speed and trajectory direction in each time window are calculated, and the trajectory direction is determined by calculating the vector of the first and last two points in the window; the K-means clustering algorithm is used to perform cluster analysis on the employee historical trajectory data to obtain the center points of the main areas of employees' daily activities and establish an employee activity area model; for new employees or employees who have just changed their workstations, their trajectory data for the first week is used for clustering, and the clustering results are updated once a day until the model is stable; by calculating the Euclidean distance between the current position and the cluster center, it is judged whether the employee has left the regular activity area, and three thresholds of 1 meter, 3 meters, and 5 meters are set. Different levels of judgment measures are taken according to different distances to further verify potential relocation events, and the employee's stay time in the new area is calculated. If it exceeds 5 minutes, the relocation is confirmed, the employee's area information is updated, and an abnormal alarm message is sent to the monitoring center. If the employee returns to the original area within 5 minutes, the relocation judgment is canceled. Adjust the judgment criteria based on the employee's position and authority level. For employees who need to move frequently, appropriately increase the preset threshold and preset time threshold.

[0082] Figure 4 A diagram of a method for determining whether abnormal transposition behavior exists provided by an embodiment of the present invention.

[0083] Furthermore, in the above-mentioned enterprise internal data key encryption method, employee mobility status snapshots are generated at two time points before and after the position change, and features are extracted from the mobility status snapshots. The feature vector dimension is optimized through the feature selection algorithm, key behavior indicators are extracted, and it is determined whether there is abnormal position change behavior. Figure 4 , including four steps from S41 to S44:

[0084] S41: extracting employee location data in the time period before and after the position change from the time series database, and generating a movement status snapshot including timestamp, coordinates, speed, and direction;

[0085] S42: Using the sliding time window method, we extract features from the employee's movement status snapshots and calculate the average speed, dwell time, movement distance, and direction change frequency to obtain the behavioral feature vectors of the original and new workstations.

[0086] S43: performing standardization on each eigenvector, performing dimensionality reduction on the standardized eigenvector, calculating the eigenvalue and eigenvector, sorting by eigenvalue, selecting the first few eigenvectors whose cumulative contribution rate exceeds a preset contribution rate threshold as principal components, and forming an optimized eigenvector;

[0087] S44: Calculate the Euclidean distance between the optimized feature vectors before and after the transposition, and determine the difference between the Euclidean distance and a preset threshold. If the Euclidean distance is greater than the preset threshold, determine that the transposition behavior is abnormal;

[0088] Among them, the key behavioral indicator is the principal component eigenvector.

[0089] For example, based on the employee repositioning detection results, employee location data for 5 minutes before and after the repositioning is obtained from a time series database to generate a snapshot of the movement state, including timestamps, coordinates, speed, and direction. A sliding time window method is used to extract features from the movement state snapshot to determine average speed, dwell time, movement distance, and frequency of direction changes. Once feature extraction is complete, the features are normalized using a Z-score. Principal component analysis is used to reduce the dimension of the normalized feature vectors and determine whether the cumulative contribution rate of the feature vectors exceeds 95%. If the cumulative contribution rate exceeds 95%, the Euclidean distance between the optimized feature vectors before and after the repositioning is calculated. A determination is made as to whether the Euclidean distance exceeds a preset threshold. If so, the repositioning behavior is determined to be abnormal.

[0090] Figure 5 A diagram of a method for updating a clustering model provided by an embodiment of the present invention.

[0091] Furthermore, in the above-mentioned enterprise internal data key encryption method, the movement trajectory data before and after the position change is segmented according to the key behavior indicators, the employee's stay time at the original and new workstations is counted, the movement frequency and stay frequency are calculated, the movement direction change rate indicator is introduced to update the feature vector, and the updated feature vector is clustered and analyzed to obtain a clustering model. Figure 5 , including five steps from S51 to S55:

[0092] S51: Segment the trajectory data before and after the transposition according to key behavioral indicators;

[0093] S52: Calculate the average speed, moving distance, and number of direction changes within the sliding window to obtain the mean and variance of the three time scale features;

[0094] S53: Using the quartile method to process the speed distribution of the employee's historical data, determine the speed threshold, and if the speed is lower than the speed threshold, accumulate the dwell time to obtain the dwell time; if the speed is higher than the speed threshold, accumulate the move time to obtain the move time;

[0095] S54: Calculate the number of direction changes per unit time and divide it by the moving distance to obtain a moving direction change rate indicator. If the moving distance is less than a preset distance value, use the time interval instead of the moving distance as the denominator.

[0096] S55: Use the Gaussian mixture model to perform cluster analysis on the updated eigenvectors, use the expectation-maximization algorithm to iteratively optimize the model parameters, determine the optimal number of clusters based on the Bayesian information criterion, and obtain the updated cluster centers and covariance matrix.

[0097] For example, according to the extracted key behavioral indicators, three sliding windows of 1 minute, 5 minutes and 15 minutes are set, the trajectory data before and after the position change are segmented, the average speed, moving distance and number of direction changes in each window are calculated, and then the mean and variance of the three time scale features are calculated as new comprehensive features; the employee's stay time at the original workstation and the new workstation are counted respectively, and the personalized speed threshold is determined by the speed distribution of the employee's historical data using the quartile method, the time period with the speed lower than the speed threshold is accumulated to obtain the stay time, and the proportion of the stay time to the total observation time is calculated as the stay frequency; the movement frequency is calculated, the time period with the speed greater than the speed threshold is accumulated to obtain the movement time, and the difference is calculated. The movement frequency is obtained by the total observation time, and the movement direction change rate indicator is introduced. It is obtained by calculating the number of direction changes in unit time and dividing it by the movement distance. When the movement distance is less than the preset distance value, the preset distance value here is a value close to zero, such as 0.5m, and the time interval is used instead of the movement distance as the denominator; the Gaussian mixture model is used to perform cluster analysis on the updated feature vector. First, the K-means algorithm is used to obtain the initial cluster center, and the covariance matrix of each class is calculated as the initial value. Then, the expectation maximization algorithm is used to iteratively optimize the model parameters. The Bayesian information criterion is used to automatically select the optimal number of clusters to obtain the updated cluster center and covariance matrix for subsequent behavior pattern recognition and anomaly detection.

[0098] Figure 6 A diagram of a dynamic key update method provided by an embodiment of the present invention.

[0099] Furthermore, in the above-mentioned enterprise internal data key encryption method, a dynamic key update is triggered, and according to the mobile status snapshot of the employee after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and at the same time abolish the old key associated with the original workstation, combined with Figure 6 , including six steps from S61 to S66:

[0100] S61: Based on the employee ID, new workstation coordinates, and timestamp, the SHA-256 hash algorithm is used to calculate the basic key seed. The speed and direction information in the movement trajectory data are quantized into a numerical value, and an XOR operation is performed with the basic key seed. The dynamic key is generated using the HMAC-SHA256 algorithm.

[0101] S62: Encrypt the dynamic key using the RSA asymmetric encryption algorithm to obtain an encrypted ciphertext;

[0102] S63: Bind the encrypted ciphertext to the new workstation ID and store it in the security key manager;

[0103] S64: Retrieve the old key identifier associated with the original workstation from the security key manager;

[0104] S65: Determine whether the old key identifier exists. If the old key identifier exists, mark the state of the old key identifier as revoked.

[0105] S66: Determine the expiration time of the old key identifier according to a preset security policy, and delete the old key identifier from the security key manager when the expiration time arrives.

[0106] For example, when an employee relocation event is detected, a snapshot of the employee's movement status is obtained from the real-time positioning system, and the employee ID, new workstation coordinates, timestamp, and movement trajectory data are extracted as input parameters for key updates. The middle time between two consecutive position sampling points is used as the relocation time point. Using the SHA-256 hash algorithm, the employee ID, new workstation coordinates, and timestamp are concatenated and the hash value is calculated to obtain the basic key seed. The speed and direction information in the movement trajectory data are quantified into a numerical value, and an XOR operation is performed with the basic key seed. Then, the HMAC-SHA256 algorithm is used to generate a dynamic key. The generated dynamic key is encrypted using the system public key through the RSA asymmetric encryption algorithm. The encrypted ciphertext is bound to the new workstation ID and stored in the secure key manager. At the same time, the encrypted new key is pushed to the employee terminal device, and the number of retries and intervals are set. If the push fails, a key reset instruction is sent through the backup channel. Retrieve the old key ID associated with the original workstation from the security key manager, mark its status as revoked, and set a random expiration time between 1 and 24 hours based on the enterprise security policy. After the expiration time is reached, permanently delete the old key information from the security key manager.

[0107] In some embodiments, the execution status and results of each step are recorded in real time, and a detailed operation log is generated for subsequent auditing and troubleshooting.

[0108] In some embodiments, the above method is also used for internal data encryption in hospitals, schools, factories, etc.

[0109] Device embodiment

[0110] Figure 7 A diagram of an internal enterprise data key encryption device provided by an embodiment of the present invention.

[0111] The second aspect of the present invention also proposes an enterprise internal data key encryption device, combined with Figure 7 ,include:

[0112] Acquisition module 71: for acquiring a pre-established office RFID distribution map, generating a two-dimensional digital indoor map based on the pre-established office RFID distribution map, acquiring the employee's location coordinates, and recording the timestamp of the employee's location change, the employee's location coordinates, and the RFID ID number of the employee;

[0113] Continuous tracking module 72: used to match the employee's location coordinates with a pre-established office RFID distribution map, determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain the employee's movement trajectory data within the office;

[0114] Update module 73: Clustering the employee's historical movement trajectory to obtain a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it determines whether the employee has changed positions. If the judgment result is that the employee has changed positions, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff determines whether to adjust the pre-set threshold based on the employee's position and authority level information.

[0115] Determination module 74: used to generate employee mobility status snapshots at two time points before and after the position change, perform feature extraction on the mobility status snapshots, optimize feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is abnormal position change behavior;

[0116] Clustering module 75: used to segment the movement trajectory data before and after the job change based on key behavioral indicators, count the employee's stay time at the original and new workstations, calculate the movement frequency and stay frequency, introduce the movement direction change rate indicator to update the feature vector, and update the clustering model based on the updated feature vector;

[0117] Generating module 76: for triggering a dynamic key update if the result of the determination is that the position change is abnormal. Based on the employee's movement status snapshot after the position change, a new key associated with the new workstation is generated using a multi-factor dynamic password algorithm, while the old key associated with the original workstation is revoked.

[0118] Encryption module 77: used to use the dynamic key as the key of the symmetric encryption algorithm to encrypt employee sensitive data that needs to be encrypted and stored;

[0119] Dynamic adjustment module 78: used to continuously monitor the movement trajectory and behavior pattern of employees at the new workstation, and dynamically adjust the key update strategy and frequency according to the employee behavior pattern at the new workstation and the pattern in the updated clustering model.

[0120] A third aspect of the present invention further provides an electronic device, comprising: a processor and a memory;

[0121] The processor is used to execute any one of the above enterprise internal data key encryption methods by calling the program or instruction stored in the memory.

[0122] In a fourth aspect, the present invention further proposes a computer-readable storage medium, which stores a program or instruction, and the program or instruction enables a computer to execute any one of the above-mentioned enterprise internal data key encryption methods.

[0123] Figure 8 This is a schematic block diagram of an electronic device provided by an embodiment of the present invention.

[0124] like Figure 8As shown, the electronic device includes: at least one processor 801, at least one memory 802 and at least one communication interface 803. The various components in the electronic device are coupled together through a bus system 804. The communication interface 803 is used to transmit information between external devices. It can be understood that the bus system 804 is used to achieve connection and communication between these components. In addition to including a data bus, the bus system 804 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 8 Various buses are labeled as bus system 804 .

[0125] It can be understood that the memory 802 in this embodiment can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories.

[0126] In some embodiments, the memory 802 stores the following elements, executable units or data structures, or a subset or an extended set thereof: an operating system and application programs.

[0127] The operating system includes various system programs, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and handle hardware-based tasks. Application programs include various application programs, such as media players and browsers, which are used to implement various application services. Programs that implement any of the methods provided in the embodiment of the present invention for encrypting enterprise internal data keys can be included in the application programs.

[0128] In an embodiment of the present invention, the processor 801 calls the program or instructions stored in the memory 802, specifically, the program or instructions stored in the application, and the processor 801 is used to execute the steps of each embodiment of an enterprise internal data key encryption method provided in an embodiment of the present invention.

[0129] Obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, obtain the employee's location coordinates from each employee wearing an RFID, and record the timestamp of the employee's location change, the employee's location coordinates, and the RFID ID number;

[0130] Match the employee's location coordinates with the pre-established office RFID distribution map to determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain employee movement trajectory data within the office;

[0131] Clustering employees' historical movement trajectories to generate a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it is determined whether the employee has changed locations. If the judgment result is that the employee has changed locations, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff then determines whether to adjust the pre-set threshold based on the employee's position and authority level information.

[0132] Generate employee mobility status snapshots at two time points before and after the job swap, extract features from the mobility status snapshots, optimize feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is abnormal job swap behavior;

[0133] The movement trajectory data before and after the job change is segmented based on key behavioral indicators. The employee's dwell time at the original and new workstations is counted, and the movement and dwell frequencies are calculated. The movement direction change rate indicator is introduced to update the feature vector, and the clustering model is updated based on the updated feature vector.

[0134] If the result is determined to be an abnormal position change, a dynamic key update is triggered. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and simultaneously invalidate the old key associated with the original workstation.

[0135] Use the dynamic key as the key of the symmetric encryption algorithm to encrypt sensitive employee data that needs to be encrypted and stored;

[0136] Continuously monitor employees' movement trajectories and behavior patterns at new workstations, and dynamically adjust key update strategies and frequencies based on employee behavior patterns at new workstations and patterns in the updated clustering model.

[0137] Any of the methods for encrypting enterprise internal data keys provided in an embodiment of the present invention can be applied to the processor 801 or implemented by the processor 801. The processor 801 can be an integrated circuit chip having signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 801 or by instructions in the form of software. The above-mentioned processor 801 can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0138] The steps of any method in the enterprise internal data key encryption method provided in the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software units in the decoding processor. The software unit can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 802, and processor 801 reads the information in memory 802 and, in conjunction with its hardware, completes the steps of the method.

[0139] Those skilled in the art will appreciate that although some embodiments described herein include some features and not others included in other embodiments, the combination of features from different embodiments is intended to be within the scope of the invention and to form different embodiments.

[0140] Those skilled in the art will understand that the description of each embodiment has its own focus, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0141] Although the embodiments of the present invention are described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations shall fall within the scope defined by the appended claims. The above are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or substitutions within the technical scope disclosed by the present invention, and such modifications or substitutions shall be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

[0142] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A method for encrypting enterprise internal data keys, characterized in that: include: Obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, obtain the employee's location coordinates from each employee wearing an RFID, and record the timestamp of the employee's location change, the employee's location coordinates, and the RFID ID number; Match the employee's location coordinates with the pre-established office RFID distribution map to determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain employee movement trajectory data within the office; Clustering employees' historical movement trajectories to generate a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it is determined whether the employee has changed locations. If the judgment result is that the employee has changed locations, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff then determines whether to adjust the pre-set threshold based on the employee's position and authority level information. Generate employee mobility status snapshots at two time points before and after the job swap, extract features from the mobility status snapshots, optimize feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is abnormal job swap behavior; The movement trajectory data before and after the job change is segmented based on key behavioral indicators. The employee's dwell time at the original and new workstations is counted, and the movement and dwell frequencies are calculated. The movement direction change rate indicator is introduced to update the feature vector, and the clustering model is updated based on the updated feature vector. If the result is determined to be an abnormal position change, a dynamic key update is triggered. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and simultaneously invalidate the old key associated with the original workstation. Use the dynamic key as the key of the symmetric encryption algorithm to encrypt sensitive employee data that needs to be encrypted and stored; Continuously monitor employees' movement trajectories and behavior patterns at new workstations, and dynamically adjust key update strategies and frequencies based on employee behavior patterns at new workstations and patterns in the updated clustering model.

2. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: The pre-established office RFID distribution map includes: location coordinates of each RFID, coverage parameters, and topological relationships between RFIDs; The 2D digital indoor map includes: precise RFID coordinates, coverage radius, and neighboring RFID numbers; Obtaining the employee's location coordinates, including: using a least squares method to calculate the relative position of the radio frequency identifier in a pre-established office radio frequency identifier distribution map, and obtaining the employee's location coordinates based on the relative position and a two-dimensional digitized indoor map; Recording the timestamp of employee location changes, the employee's location coordinates, and the radio frequency identifier number includes: using a time series database to record the timestamp of employee location changes, the employee's location coordinates, and the radio frequency identifier number.

3. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: Match the employee's location coordinates with the pre-established office RFID distribution map to determine the employee's current office area. Continuously track the employee's location coordinate changes to obtain employee movement trajectory data within the office, including: An R-tree is used as a spatial index structure to store the RFID distribution map. The office area is divided into grid cells according to the RFID distribution map, and a mapping relationship between grid cells and RFIDs is established. Receive the employee's location coordinates and quickly locate the grid cell where the employee's location coordinates are located through the R-tree; determine the employee's current office area based on the mapping relationship between the grid cell and the RFID; The sliding time window method is used to continuously collect employee location coordinates to obtain the employee location coordinate sequence; Perform data smoothing on employee location coordinate sequences; The smoothed coordinates are fitted using a cubic Bezier curve, where every four consecutive points are used as a set of control points. The movement trajectory data of employees in the office is generated based on the cubic Bezier curve.

4. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: Clustering the employee's historical movement trajectory to obtain a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it is determined whether the employee has changed positions. If the judgment result is that the employee has changed positions, the employee's location information is updated and an abnormal alarm information is sent to the monitoring center. The monitoring center staff determines whether to adjust the pre-set threshold based on the employee's position and authority level information, including: Based on employees' historical trajectory data, we use the K-means clustering algorithm to perform cluster analysis and determine the center points of the main areas of employees' daily activities. If the employee is a new employee or has just changed workstations, we use their trajectory data from the first week to perform clustering. The clustering results are updated daily until the clustering model stabilizes. Obtain employee movement trajectory data, segment the trajectory data using the sliding time window method, and obtain the average movement speed and trajectory direction within each time window; Calculate the Euclidean distance between the employee's current location and the cluster center, and use the Euclidean distance to determine whether the employee has left the regular activity area; If the Euclidean distance exceeds the preset threshold, it is determined that the employee has left the regular activity area; For employees who are determined to have left their regular activity area, their stay time in the new area is calculated; if the stay time exceeds the preset time threshold, a change of location is determined, the employee's area information is updated, and an abnormal alarm information is sent to the monitoring center; The employee's position and authority level information is obtained, and the monitoring center staff determines whether to adjust the preset threshold and the preset time threshold based on the employee's position and authority level information.

5. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: Generate employee mobility status snapshots at two points in time before and after the job swap, extract features from the mobility status snapshots, optimize the feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is abnormal job swap behavior. This includes: Extract employee location data from the time series database for the period before and after the position change, and generate a movement status snapshot containing timestamps, coordinates, speed, and direction; Using the sliding time window method, we extract features from snapshots of employee movement status and calculate the average speed, dwell time, movement distance, and direction change frequency to obtain the behavioral feature vectors of the original and new workstations. Each eigenvector is normalized, and the dimensionality reduction process is performed on the normalized eigenvectors. The eigenvalue and eigenvector are calculated, and the eigenvalues ​​and eigenvectors are sorted by eigenvalues. The first few eigenvectors whose cumulative contribution rates exceed the preset contribution rate threshold are selected as principal components to form the optimized eigenvectors. Calculate the Euclidean distance between the optimized feature vectors before and after the transposition, and determine the difference between the Euclidean distance and the preset threshold. If the Euclidean distance is greater than the preset threshold, it is determined to be an abnormal transposition behavior; Among them, the key behavioral indicator is the principal component eigenvector.

6. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: The movement trajectory data before and after the position change is segmented based on key behavioral indicators. The employee's stay time at the original and new workstations is counted, and the movement frequency and stay frequency are calculated. The movement direction change rate indicator is introduced to update the feature vector. The updated feature vector is clustered and analyzed to obtain a clustering model, including: The trajectory data before and after the transposition were segmented according to key behavioral indicators; Calculate the average speed, moving distance, and number of direction changes within the sliding window to obtain the mean and variance of the three time scale features; The quartile method is used to process the speed distribution of employee historical data and determine the speed threshold. If the speed is lower than the speed threshold, the dwell time is accumulated; if the speed is higher than the speed threshold, the moving time is accumulated. Calculate the number of direction changes per unit time divided by the moving distance to obtain the moving direction change rate indicator. If the moving distance is less than the preset distance value, use the time interval instead of the moving distance as the denominator; The Gaussian mixture model is used to perform cluster analysis on the updated eigenvectors. The expectation maximization algorithm is used to iteratively optimize the model parameters. The optimal number of clusters is determined according to the Bayesian information criterion to obtain the updated cluster centers and covariance matrix.

7. The method for encrypting enterprise internal data keys according to claim 1, characterized in that: The triggering of dynamic key update, based on the employee's mobile status snapshot after the position change, uses a multi-factor dynamic password algorithm to generate a new key bound to the new workstation and simultaneously abolish the old key associated with the original workstation, including: The basic key seed is calculated using the SHA-256 hash algorithm based on the employee ID, new workstation coordinates, and timestamp. The speed and direction information in the movement trajectory data is quantified into a numerical value, and an XOR operation is performed with the basic key seed to generate a dynamic key using the HMAC-SHA256 algorithm. The dynamic key is encrypted using the RSA asymmetric encryption algorithm to obtain encrypted ciphertext; Bind the encrypted ciphertext to the new workstation ID and store it in the security key manager; Retrieving the old key identifier associated with the original workstation from the security key manager; Determine whether the old key identifier exists. If the old key identifier exists, mark the state of the old key identifier as revoked. According to a preset security policy, the expiration time of the old key identifier is determined, and when the expiration time arrives, the old key identifier is deleted from the security key manager.

8. An enterprise internal data key encryption device, characterized in that: include: Acquisition module: used to obtain a pre-established office RFID distribution map, generate a two-dimensional digital indoor map based on the pre-established office RFID distribution map, obtain the employee's location coordinates, and record the timestamp of the employee's location change, the employee's location coordinates and the RFID number; Continuous tracking module: used to match the employee's location coordinates with the pre-established office RFID distribution map, determine the employee's current office area, and continuously track the employee's location coordinate changes to obtain the employee's movement trajectory data within the office; Update module: This module clusters employees' historical movement trajectories to generate a clustering model. Based on the employee's movement trajectory data within the office and the clustering model, it determines whether the employee has changed locations. If so, the employee's location information is updated and an abnormality alarm is sent to the monitoring center. The monitoring center staff then determines whether to adjust the pre-set threshold based on the employee's position and authority level. Determination module: This module is used to generate employee mobility status snapshots at two time points before and after the position change, extract features from the mobility status snapshots, optimize the feature vector dimensions using a feature selection algorithm, extract key behavioral indicators, and determine whether there is any abnormal position change behavior. Clustering module: This module segments movement trajectory data before and after job change based on key behavioral indicators, counts employee dwell time at their original and new workstations, calculates movement and dwell frequencies, introduces a movement direction change rate indicator to update feature vectors, and updates the clustering model based on the updated feature vectors. Generation module: If the result is determined to be an abnormal position change, it triggers a dynamic key update. Based on the employee's mobile status snapshot after the position change, a multi-factor dynamic password algorithm is used to generate a new key bound to the new workstation and simultaneously invalidate the old key associated with the original workstation. Encryption module: used to use the dynamic key as the key of the symmetric encryption algorithm to encrypt sensitive employee data that needs to be encrypted and stored; Dynamic adjustment module: used to continuously monitor the movement trajectories and behavior patterns of employees at new workstations, and dynamically adjust the key update strategy and frequency based on the employee behavior patterns at the new workstations and the patterns in the updated clustering model.

9. An electronic device, characterized in that: include: processor and memory; The processor is used to execute an enterprise internal data key encryption method as described in any one of claims 1 to 7 by calling the program or instruction stored in the memory.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a program or instruction, and the program or instruction enables a computer to execute an enterprise internal data key encryption method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Intelligent encryption communication method and system used between wireless routers

    CN118612719A

  • Enterprise sensitive data security access management method and system

    CN118656870A