An electronic seal security management method for a digital enterprise

By analyzing the attributes and access situation of the user's electronic seal, calculating the attribute replacement coefficient and building an attribute access graph structure, identifying the possibility of high-level users being attacked by conspiracy, solving the problem of low-level users conspiring to attack the high-level user's permissions, and reducing the risk of abnormal access to the digital enterprise management platform.

CN119903531BActive Publication Date: 2025-06-13龙采科技集团有限责任公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510404921.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-13
Estimated Expiration
2045-04-02

AI Technical Summary

Technical Problem

The prior art is difficult to effectively prevent multiple low-level users from conspiring to attack the permission files of advanced users through electronic seals.

Method used

By obtaining and analyzing the attributes of the user's electronic seal and their access status, calculate the attribute replacement coefficient of each user's electronic seal, and constructing an attribute access graph structure, quantifying the current attribute access similarity of any two sets of attributes to identify the possibility that advanced users are subject to conspiracy attacks.

Benefits of technology

It effectively reduces the risk of abnormal access to digital enterprise management platforms, and prevents conspiracy attacks by adjusting the attributes covered by the electronic seal of low-level users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903531B_ABST
    Figure CN119903531B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data processing, and proposes an electronic seal security management method for a digital enterprise, including: obtaining the attributes of all user electronic seals in the digital enterprise management platform and their access situations; obtaining several groups of attributes of each user's electronic seal; analyzing the historical changes of the attributes in the same group of attributes and their overall access situations to obtain the attribute replacement coefficient of each group of attributes; comparing the changes in the access situations of two groups of attributes within a period of time before the current moment to quantify the current attribute access similarity of any two groups of attributes; constructing an attribute access graph structure; analyzing the similarity of the connection relationships between the subgraphs of high-level users and the corresponding nodes of each group of attributes of other users to obtain the likelihood of being attacked by collusion for each high-level user at the current moment, and performing security management on the electronic seals of each user based on this. The present invention aims to solve the problem that multiple low-level users collude to attack the relevant permissions of high-level users through electronic seals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly relates to a method for secure management of electronic seals in a digital enterprise. Background Art

[0002] An electronic seal is an identity identifier generated based on cryptographic technology and presented as an electronic data graph; it effectively binds a digital certificate, a signature key, and a physical seal image to achieve the integrity, authenticity, and non-repudiation of various electronic documents. In digital enterprise management, an authentication center grants access rights to files by determining the attributes covered by a user's electronic seal; due to differences in user privilege levels, a low-level user cannot access some privilege files of a high-level user, and the electronic seal serves as an identity identifier for the user's access rights.

[0003] The electronic seal of a low-level user covers fewer attributes. On the contrary, the higher the privilege level of a high-level user, the more attributes its electronic seal covers due to higher privileges, and the greater the difficulty of cracking; however, since the attributes are shared by multiple users, multiple low-level users may collude to attack the privilege files of high-level users by collecting the attributes of high-level users, and it is impossible to completely avoid collusion attacks from the perspective of privilege access due to the operation method of the authentication center in digital enterprise management; therefore, before a collusion attack, it is necessary to adjust the attributes covered by the electronic seal of a low-level user by modifying the attributes to avoid the occurrence of collusion attacks on the privilege files of high-level users. Summary of the Invention

[0004] The present invention provides a method for secure management of electronic seals in a digital enterprise to solve the problem that multiple existing low-level users collude to attack the relevant privileges of high-level users through electronic seals. The specific technical solutions adopted are as follows:

[0005] The present invention proposes a method for secure management of electronic seals in a digital enterprise, and the method includes the following steps:

[0006] Obtain the attributes of all users' electronic seals in the digital enterprise management platform and their access situations;

[0007] Obtain several groups of attributes of each user's electronic seal; analyze the historical changes of the attributes in the same group and the overall access situation before the attribute changes, and compare the access situations of each user before the corresponding attribute changes to obtain the attribute replacement coefficient of each group of attributes of each user's electronic seal;

[0008] Compare the changes in the access situations of two groups of attributes over a period of time before the current moment, and quantify the current attribute access similarity between any two groups of attributes; combine the attribute replacement coefficients of each group of attributes to construct an attribute access graph structure for each group of attributes of all user electronic seals, where each node in the attribute access graph structure corresponds to each group of attributes of each user electronic seal;

[0009] Analyze the similarity of the connection relationships between the subgraphs of high-level users in the attribute access graph structure and the corresponding nodes of each group of attributes of multiple user electronic seals, and combine the corresponding relationships between the nodes and the user electronic seals to obtain the likelihood of being attacked by collusion for each high-level user at the current moment, and perform security management on the electronic seals of each user based on this.

[0010] Optionally, the method for specifically obtaining several groups of attributes of each user electronic seal is as follows:

[0011] For several attributes included in any user electronic seal, since the receipt of its electronic seal, obtain the start time and end time of each attribute, and thereby obtain the duration of each attribute included in this user electronic seal;

[0012] Splice the end time of any one of the attributes with the attributes having the same start time among the other attributes except this attribute, splice several attributes into a group of attributes, and so on to obtain several groups of attributes of this user electronic seal.

[0013] Optionally, the method for analyzing the historical changes of attributes in the same group of attributes and the overall access situation before the attribute changes, and comparing the access situations of each user before the corresponding attribute changes to obtain the attribute replacement coefficient of each group of attributes of each user electronic seal includes the following specific methods:

[0014] For the th attribute in the th group of attributes of the th user electronic seal, obtain the total access frequency of the permission corresponding to the th attribute from its start time to its end time, and record the access frequency of the permission corresponding to the th attribute every day from its start time to its end time;

[0015] Obtain the ratio of the access frequency on the last day from the start time to the end time of the permission corresponding to the th attribute to the total access frequency, obtain the access frequency increment of the permission corresponding to the th attribute every day relative to the previous day from its start time to its end time, and obtain the The average difference between the incremental access frequency of the last day relative to the penultimate day and the incremental access frequency of each other day relative to the previous day from the start time to the end time of the permissions corresponding to an attribute is used as the product of the average value and the ratio as the abnormal change weight of the th attribute;

[0016] According to the duration of each attribute in the same group of attributes of the same user and the access situation of the user to the permissions corresponding to the attributes through the electronic seal, combined with the abnormal change weight, the attribute replacement coefficient of each group of attributes of each user's electronic seal is obtained.

[0017] Optionally, the method of obtaining the attribute replacement coefficient of each group of attributes of each user's electronic seal according to the duration of each attribute in the same group of attributes of the same user and the access situation of the user to the permissions corresponding to the attributes through the electronic seal, combined with the abnormal change weight, includes the following specific method:

[0018] Obtain the th user's access frequency to the permissions corresponding to the th attribute in the th group of attributes from the start time to the last day of the end time, and the attribute replacement coefficient of the th user's electronic seal for the th group of attributes is calculated as follows:

[0019]

[0020] Wherein, represents the coefficient of variation of the duration of each attribute in the th group of attributes of the th user's electronic seal, represents the number of attributes in the th group of attributes of the th user's electronic seal, represents the abnormal change weight of the th attribute in the th group of attributes of the th user's electronic seal, represents the access frequency of the permissions corresponding to the th attribute from the start time to the last day of the end time, represents the access frequency of the th user to the last day from the start time to the end time of the th.

[0021] Optionally, the method of comparing the changes in the access situations of two groups of attributes within a period of time before the current moment and quantifying the current attribute access similarity of any two groups of attributes includes the following specific method:

[0022] For the current moment, obtain the attributes of each group of attributes of each user's electronic seal at the current moment as the current attributes of each user. For any two groups of attributes of any two user electronic seals, obtain the access frequency of the current attributes of any one of the two users by the user's electronic seal for each day from the start time to the end time when the current attributes are changed from the user's electronic seal, and arrange them in time sequence to form the access sequence of the current attributes of the user. Obtain the access sequence of the current attributes of the other user, and obtain the DTW distance between the access sequences of the two current attributes of the two users through DTW matching;

[0023] For the access sequences of the two current attributes of the two users, respectively intercept the last three elements of the two access sequences to form two access data segments of the current attributes, and obtain the cosine phase velocity and DTW distance between the two access data segments of the current attributes. The calculation method of the current attribute access similarity of the two groups of attributes of the two user electronic seals is as follows:

[0024]

[0025] Among them, represents the current attribute access similarity between the th group of attributes of the th user's electronic seal and the th group of attributes of the th user's electronic seal, and respectively represent the cosine phase velocity and DTW distance between the two access data segments of the current attributes of the th user and the th user, represents the DTW distance between the access sequences of the two current attributes of the th user and the th user;

[0026] For the attributes corresponding to any two groups of attributes of the same user's electronic seal at the current moment, respectively record them as the current attributes of the two groups of attributes, obtain the start times of the current attributes of the user's electronic seal for the two groups of attributes respectively, and use the start time closest to the current moment to the current moment as the analysis period;

[0027] Obtain the access frequency of the current attributes of the two groups of attributes of the user's electronic seal every day during the analysis period, and respectively form the access frequency sequences of the current attributes of the two groups of attributes in time sequence, and use the cosine similarity between the two access frequency sequences as the current attribute access similarity of the two groups of attributes of the user's electronic seal.

[0028] Optionally, the specific method for constructing an attribute access graph structure for each group of attributes of all users' electronic seals is as follows:

[0029] Users whose number of groups included in the electronic seal is less than the user classification parameter are regarded as low-level users, and others are regarded as high-level users;

[0030] For any high-level user, each group of attributes of the high-level user's electronic seal is regarded as a node, and all the nodes corresponding to the high-level user are fully connected to form a fully connected graph of the high-level user. The node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge value between nodes is set to 1;

[0031] For any low-level user, each group of attributes of the low-level user's electronic seal is regarded as a node, and all the nodes corresponding to the low-level user are fully connected to form a fully connected graph of the low-level user. The node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge value between nodes is set to the current attribute access similarity of different group attributes corresponding to the nodes;

[0032] If the current attribute access similarity of different group attributes of different users is greater than the similarity threshold, the nodes corresponding to the two groups of attributes are connected, and the edge value is set to the corresponding current attribute access similarity;

[0033] By analogy, judge the current attribute access similarity of the nodes corresponding to each user, connect the corresponding nodes and obtain the corresponding edge values; the graph structure formed by the fully connected graphs of each user and the edges connecting the nodes in the fully connected graphs of different users is used as the attribute access graph structure.

[0034] Optionally, the specific method for analyzing the similarity of the connection relationship between the subgraph of high-level users in the attribute access graph structure and the corresponding nodes of each group of attributes of multiple users' electronic seals, and obtaining the possibility of being attacked by collusion for each high-level user at the current moment is as follows:

[0035] Based on the connection relationship between the nodes of users with lower permissions, obtain several similar subgraphs of the fully connected graph of each high-level user from the fully connected graph of the high-level user;

[0036] Analyze the difference relationship between the node values and edge values between the similar subgraph and its corresponding fully connected graph to obtain the graph access similarity between each similar subgraph and its corresponding fully connected graph;

[0037] Based on the nodes included in the similar subgraph and the corresponding users, and the graph access similarity between the similar subgraph and its corresponding fully connected graph, obtain the possibility of being attacked by collusion for each high-level user at the current moment.

[0038] Optionally, the complete connection graph of the high-level user obtains several similar subgraphs of the complete connection graph of each high-level user according to the connection relationship between the nodes of the user with lower permissions. The specific method includes:

[0039] For the complete connection graph of any high-level user, according to the current attributes of the corresponding group attributes of each node in the complete connection graph, obtain several nodes with the same current attributes of the corresponding group attributes in the attribute access graph structure, and according to the connection relationship between the several nodes, obtain several subgraphs with the same structure as the complete connection graph, denoted as several similar subgraphs of the complete connection graph.

[0040] Optionally, the complete connection graph of the high-level user obtains several similar subgraphs of the complete connection graph of each high-level user according to the connection relationship between the nodes of the user with lower permissions. The specific method includes:

[0041]

[0042] Among them, represents the graph access similarity between any similar subgraph and its corresponding complete connection graph, represents the number of edges of the complete connection graph, represents the th edge value of the similar subgraph, represents the th edge value of the complete connection graph; represents the attribute replacement coefficient of the attribute of the corresponding group of one end point of the th edge in the similar subgraph, represents the attribute replacement coefficient of the attribute of the corresponding group of the other end point of the th edge in the similar subgraph; represents the minimum value function.

[0043] Optionally, the method for obtaining the possibility of being attacked by collusion for each high-level user at the current moment according to the nodes included in the similar subgraph and their corresponding users, and the graph access similarity between the similar subgraph and its corresponding complete connection graph includes the following specific method:

[0044] For the complete connection graph of any high-level user and any similar subgraph thereof, the users corresponding to the nodes included in the similar subgraph are denoted as the participating users of the similar subgraph; the access similarity coefficient of the similar subgraph and the complete connection graph is calculated as follows:

[0045]

[0046] Among them, represents the graph access similarity between any similar subgraph and its corresponding complete connection graph, Indicates the number of nodes in the similar sub - graph, Indicates the number of participating users in the similar sub - graph, Indicates the total number of nodes included in the fully - connected graph of all participating users in the similar sub - graph.

[0047] The beneficial effects of the present invention are as follows: By analyzing the access situations of each attribute under the same - group attributes of the user's electronic seal, the possibility of attribute replacement due to attack on each attribute is quantified based on the change in the access situation; at the same time, combined with the access situation of the user through the electronic seal before the change of each attribute under the same - group attributes, the attribute replacement coefficient of each group of attributes of the user's electronic seal is quantified, reflecting the abnormal possibility of the user's electronic seal to perform an attack on the corresponding permission of the attribute; for different groups of attributes of different users' electronic seals and different groups of attributes of the same user's electronic seal, a similarity analysis of the recent access situations of the corresponding attributes at the current moment is carried out, and this is used as the basis for judging the connection between the nodes of the graph structure and the edge values. The nodes correspond to each group of attributes. By constructing a graph structure, the sub - graphs and connection relationships therein can reflect the overall access relationship between each group of attributes of each user's electronic seal at the current moment, providing a basis for subsequent collusion attack analysis; by analyzing the graph structure of attribute access based on the connection relationship between the sub - graph of the high - level user and other nodes, according to the similar structure and the attribute replacement coefficient corresponding to the nodes and the current attribute access similarity between the nodes, the possibility of low - level users colluding to attack the high - level user's permissions is reflected. Furthermore, by judging the possibility of collusion attack, the security management of the user's electronic seal is carried out, thereby reducing the risk of abnormal access to the digital enterprise management platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following - described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0049] Figure 1 It is a schematic flow chart of a method for electronic seal security management of a digital enterprise provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0051] Please refer to Figure 1 , which shows a flowchart of an electronic seal security management method for a digital enterprise provided by an embodiment of the present invention. The method includes the following steps:

[0052] Step S001: Obtain the attributes of all user electronic seals in the digital enterprise management platform and their access situations.

[0053] The purpose of this embodiment is to give early warnings in advance of the situation where multiple low-level users in the digital enterprise management platform may collude to attack the permissions of high-level users, and to achieve security management by adjusting the attributes covered by the electronic seal. Therefore, it is necessary to analyze the rules and changes of the attributes of each user's electronic seal in the digital enterprise management platform and their access situations, and thus it is necessary to collect the corresponding data and access situations.

[0054] Specifically, in any digital enterprise management platform, obtain all the attributes covered by all user electronic seals since the platform started running, including all the attributes covered by the user electronic seals from the start of the platform running to the current moment, and the time when the attributes changed; at the same time, record each access of each user electronic seal to the platform, and the access frequency of the user electronic seal at different time periods is its access situation.

[0055] Step S002: Obtain several groups of attributes of each user electronic seal; analyze the historical changes of the attributes in the same group of attributes and the overall access situation before the attribute change, and compare the access situations of each user before the corresponding attribute change to obtain the attribute replacement coefficient of each group of attributes of each user electronic seal.

[0056] Preferably, in an embodiment of the present invention, the specific method for obtaining several groups of attributes of each user electronic seal includes:

[0057] It should be noted that since there are replacement situations for the attributes covered by the electronic seal, even if the user electronic seal only covers one attribute at each moment, there will be multiple attributes for the obtained attributes due to replacement. Therefore, it is necessary to analyze multiple attributes as a group of attributes of the user electronic seal, and obtain several groups of attributes of each user electronic seal by extracting and continuously analyzing the start time and end time of the attributes.

[0058] Specifically, for several attributes included in any user's electronic seal, since the receipt of the electronic seal, obtain the start time and end time of each attribute, and thus obtain the duration of each attribute included in the user's electronic seal; splice the end time of any one of the attributes with the attributes having the same start time among the other attributes except this attribute, then according to the analysis of the same start time and end time, splice several attributes into a group of attributes, and so on to obtain several groups of attributes of the user's electronic seal; since after the receipt of the electronic seal, each attribute corresponding to the corresponding moment covered by the electronic seal is at the start time, the number of groups included in the user's electronic seal is the number of attributes with the same start time as the receipt time of the electronic seal; at the same time, when one attribute in each group of attributes ends and the next attribute starts, the same end time and start time are recorded as the time of attribute change in the corresponding group of attributes.

[0059] It should be noted that in the historical change process of the attributes of the user's electronic seal, the attribute change usually includes two situations. One is that the permission under the corresponding attribute is attacked, and it is necessary to modify the corresponding attribute covered by the electronic seals of all users corresponding to the corresponding attribute; the other is that among the electronic seals of several users covering the corresponding attribute, there is a user who cancels the electronic seal, and it is necessary to modify the corresponding attribute to avoid permission leakage caused by cancellation.

[0060] Furthermore, it should be noted that in the process of analyzing the attributes covered by the user's electronic seal, the electronic seal covers one or more attributes. Under one attribute, first, it is necessary to analyze the access frequency before the attribute change. The more frequent the access, the greater the possibility that the attribute permission will be attacked and modified. At the same time, the greater the access frequency of the user itself, the more likely the user may be an abnormal user who attacks the attribute permission; and during the attribute change process, the shorter the duration of each attribute in a group of attributes of the same user, the more frequent the change of the group of attributes of the user's electronic seal. By quantifying the attribute replacement coefficient, it reflects the frequent change of the corresponding group of attributes of the user and the possibility of its abnormal behavior under the corresponding group of attributes.

[0061] Preferably, in an embodiment of the present invention, analyze the historical change of the attributes in the same group of attributes and the overall access situation before the attribute change, and compare the access situations of each user before the corresponding attribute change to obtain the attribute replacement coefficient of each group of attributes of each user's electronic seal. The specific method included is:

[0062] Taking the th attribute in the th group of attributes of the th user's electronic seal as an example, obtain the total access frequency of the permission corresponding to the th attribute from its start time to its end time, where the start time and the end time are both the th user's electronic seal The start time and end time of the th attribute in the group attributes, rather than the start time of the th attribute itself (since the user may receive an electronic seal midway and obtain the th attribute, and there may be a difference between its start time and the start time of the attribute itself), the total access frequency is the number of times all users access through the electronic seal for the corresponding permission during this period; at the same time, record the access frequency of each day from the start time to the end time of the permission corresponding to the th attribute, then the abnormal change weight of the th attribute is calculated as follows:

[0063]

[0064] Among them, represents the total access frequency of the permission corresponding to the th attribute in the th group of attributes of the th user's electronic seal from its start time to the end time, represents the duration of the th attribute (the duration corresponding to the th user's electronic seal under the th group of attributes, in days), represents the access frequency of the last day from the start time to the end time of the permission corresponding to the th attribute, represents the access frequency increment of the th day relative to the th day from the start time to the end time of the permission corresponding to the th attribute, that is, the difference obtained by subtracting the access frequency of the previous day from the access frequency of the next day; represents the access frequency increment of the last day relative to the penultimate day from the start time to the end time of the permission corresponding to the th attribute.

[0065] It should be noted that during the duration of the th attribute in this group of attributes, the greater the proportion of the access frequency of the last day of the corresponding permission in the total access frequency, and the greater the difference between the access frequency increment corresponding to the last day and the access frequency increments of other days, the greater the possibility that the access to the permission corresponding to the th attribute is abnormal, and it is more likely to be caused by an attack for attribute replacement. Then, in the The greater the abnormal change weight of an attribute; specifically, if the access frequency increment corresponding to the last day is smaller than that of other days, the result of the above formula will output a negative number, reflecting that the abnormal change weight of the th attribute is smaller.

[0066] Furthermore, obtain the access frequency of the th user to the permission corresponding to the th attribute from the start time to the last day during its start time to end time. Then, the attribute replacement coefficient of the th group of attributes of the th user's electronic seal is calculated as follows:

[0067]

[0068] Where, represents the coefficient of variation (the ratio of the standard deviation to the mean) of the duration of each attribute in the th group of attributes of the th user's electronic seal, represents the number of attributes in the th group of attributes of the th user's electronic seal, represents the abnormal change weight of the th attribute in the th group of attributes of the th user's electronic seal, represents the access frequency of the permission corresponding to the th attribute from its start time to the last day during its start time to end time, represents the access frequency of the th user to the th from its start time to the last day during its start time to end time.

[0069] Specifically, for the attributes corresponding to each group of attributes at the current moment, its end time is calculated based on the current moment, and the remaining relevant parameters are obtained according to the above method.

[0070] It should be noted that the duration of each attribute under the same group of attributes is relatively small, and there are differences in the durations, resulting in a relatively large standard deviation and thus a relatively large coefficient of variation. Then, it is more likely that each attribute in the same group of attributes is an abnormal attribute replacement situation, and the greater the possibility that the corresponding permissions of this group of attributes have been attacked and changed multiple times; at the same time, the greater the proportion of the access frequency of the corresponding attribute by the electronic seal on the last day to the overall access frequency of the corresponding attribute on the last day, the greater the possibility that the user is an attacker who attacks the corresponding attribute permissions through the electronic seal. The greater the attribute replacement coefficient of its corresponding group of attributes, the more it can reflect the abnormal possibility of the user attacking the corresponding permissions through the electronic seal.

[0071] So far, by analyzing the access situation of each attribute under the same group of attributes of the user's electronic seal, the possibility of attribute replacement due to attack on each attribute is quantified based on the change in the access situation; at the same time, combined with the access situation of the user through the electronic seal before the change of each attribute under the same group of attributes, the attribute replacement coefficient of each group of attributes of the user's electronic seal is quantified to reflect the abnormal possibility of the user attacking the corresponding permissions through the electronic seal.

[0072] Step S003: Compare the changes in the access situations of two groups of attributes within a period of time before the current moment, and quantify the current attribute access similarity of any two groups of attributes; combine the attribute replacement coefficients of each group of attributes to construct an attribute access graph structure for each group of attributes of all user electronic seals.

[0073] Preferably, in an embodiment of the present invention, comparing the changes in the access situations of two groups of attributes within a period of time before the current moment and quantifying the current attribute access similarity of any two groups of attributes includes the following specific methods:

[0074] It should be noted that to analyze the collusion attack of low-level users on high-level users, it should be that at the same moment, multiple low-level users have gathered the corresponding attribute permissions of the high-level user. Since the attributes covered by the electronic seal are unknown among different users, during the process of gathering the corresponding attribute permissions of the high-level user, there will be increasingly similar access behaviors among different users. Therefore, it is necessary to perform a similarity analysis of the access behaviors of the attributes of different groups of different users at the current moment; for different groups of attributes of the same user, since the same user accesses the corresponding attribute permissions through the electronic seal, the analysis time range remains the same, and a similarity analysis of the access behaviors within a certain duration in the near future is performed.

[0075] Furthermore, it should be noted that during the similarity behavior analysis of different groups of attributes, different groups of attributes with the same attributes at the current moment are not analyzed, that is, during the collusion attack process, to reduce the risk of discovery, multiple users will not participate in the same attribute. Therefore, for different groups of attributes of different users that belong to the same attribute at the current moment, no similarity analysis is required.

[0076] Specifically, for the current moment, obtain the attributes of each group of attributes of each user's electronic seal at the current moment as the current attributes of each user. For any two groups of attributes of any two user electronic seals, where the current attributes of the two groups of attributes are different, obtain the access frequency of each user's electronic seal to its current attribute every day from the start time to the end time when the current attribute of any one of the two users is changed from the user's electronic seal, and arrange them in chronological order to form the access sequence of the current attribute of the user. Similarly, obtain the access sequence of the current attribute of the other user, and obtain the DTW distance between the access sequences of the two current attributes of the two users through DTW matching; preset the analysis duration. In this embodiment, the analysis duration is described using three days. For the access sequences of the two current attributes of the two users, respectively intercept the last three elements of the two access sequences to form two access data segments of the current attributes, that is, the data segment composed of the access frequencies in the last three days at the current moment, and obtain the cosine phase velocity and DTW distance between the two access data segments of the two current attributes. Then, the calculation method for the current attribute access similarity of the two groups of attributes of the two user electronic seals is as follows:

[0077]

[0078] Among them, represents the current attribute access similarity between the th group of attributes of the th user's electronic seal and the th group of attributes of the th user's electronic seal, and respectively represent the cosine phase velocity and DTW distance between the two access data segments of the two current attributes of the th user and the th user, represents the DTW distance between the access sequences of the two current attributes of the th user and the th user.

[0079] It should be noted that the greater the similarity between the recent access situations of the current attributes of different groups of attributes of different user electronic seals at the current moment, and the greater the change in similarity compared to the overall access situation, the more similar the access behaviors between the current attributes of the two groups of attributes, and the greater the current attribute access similarity, the more likely the users corresponding to the two groups of attributes are preparing to collude to attack the high-level user permissions through the electronic seal.

[0080] It should be further noted that for different groups of attributes of the same user's electronic seal, since not all attributes may be required during the permission access process, similar behavior quantification is also needed among different groups of attributes. The more similar the access behaviors among different groups of attributes are, the higher the convergence is, and the greater the possibility that the corresponding user will access multi-attribute permissions multiple times through the electronic seal. Subsequently, the greater the possibility that multiple groups of attributes of the same user will jointly participate in a collusion attack.

[0081] Specifically, for any two groups of attributes of the same user's electronic seal corresponding to the attributes at the current moment, they are respectively recorded as the current attributes of these two groups of attributes. Obtain the start time of the current attributes of these two groups of attributes of the user's electronic seal respectively, and take the time period from the start time closest to the current moment to the current moment as the analysis period; obtain the access frequency of the current attributes of these two groups of attributes of the user's electronic seal every day within the analysis period, and respectively form the access frequency sequences of the current attributes of these two groups of attributes according to the time sequence. Take the cosine similarity between the two access frequency sequences as the access similarity of the current attributes of these two groups of attributes of the user's electronic seal.

[0082] Furthermore, obtain the access similarity of the current attributes of any two groups of attributes according to the above method, including the access similarity of the current attributes of different groups of attributes of different users' electronic seals and the access similarity of the current attributes of different groups of attributes of the same user's electronic seal. Among them, when the current attributes of different groups of attributes are the same, no acquisition is performed.

[0083] It should be noted that for the analysis of collusion attacks, each user's groups of attributes need to be used as nodes, and the access similarity of the current attributes between different groups of attributes is used to determine the connection relationship between nodes. The nodes corresponding to different groups of attributes of the same user need to ensure full connection, that is, the same user can selectively access the permissions corresponding to multiple attributes, rather than not being able to access multiple attributes simultaneously; at the same time, for the nodes corresponding to different groups of attributes of different users, only those with greater access similarity of the current attributes can be connected, that is, the connection relationship between the nodes of low-level users is used to perform similarity comparison with the full connection subgraphs of high-level users subsequently.

[0084] Preferably, in an embodiment of the present invention, in combination with the attribute replacement coefficient of each group of attributes, an attribute access graph structure is constructed for each group of attributes of all users' electronic seals. The specific method includes:

[0085] Preset user classification parameters. In this embodiment, the user classification parameter is described using 4. Users with the number of groups included in the electronic seal less than the user classification parameter are regarded as low-level users, and others are regarded as high-level users. For any high-level user, each group attribute of the high-level user's electronic seal is regarded as a node, and all the nodes corresponding to the high-level user are fully connected to form a fully connected graph of the high-level user. The node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge value between nodes is set to 1. For any low-level user, each group attribute of the low-level user's electronic seal is regarded as a node, and all the nodes corresponding to the low-level user are fully connected to form a fully connected graph of the low-level user. The node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge value between nodes is set to the current attribute access similarity of different group attributes corresponding to the node.

[0086] Furthermore, for users with the number of groups included in the electronic seal greater than 1, the corresponding fully connected graphs are obtained. For users with the number of groups included in the electronic seal equal to 1, directly regard one group attribute as a node. For different group attributes of different users, a similarity threshold is preset. In this embodiment, the similarity threshold is described using 0.6. If the current attribute access similarity of different group attributes of different users is greater than the similarity threshold, connect the nodes corresponding to the two group attributes, and set the edge value to the corresponding current attribute access similarity. And so on, judge the current attribute access similarity of the nodes corresponding to each user, and connect the corresponding nodes and obtain the corresponding edge values. The graph structure formed by the fully connected graphs of each user and the edges connecting the nodes in the fully connected graphs of different users is used as the attribute access graph structure. Then the fully connected graphs of each user are all subgraphs of the attribute access graph structure.

[0087] It should be noted that since the possibility of high-level users participating in a collusion attack is relatively small, and if they participate, the simultaneous participation of multiple attributes they contain in the attack will greatly increase the success rate of the attack. Therefore, the edge values in their fully connected graphs are all set to 1. For the fully connected graphs of low-level users, the current attribute access similarity between their different group attributes is still used as the edge value.

[0088] So far, for different group attributes of different users' electronic seals and different group attributes of the same user's electronic seal, a similarity analysis of the recent access situations of the corresponding attributes at the current moment is performed, and this is used as the basis for judging the connection between the nodes of the graph structure and the edge values. The nodes correspond to each group attribute. By constructing the graph structure, the subgraphs and connection relationships therein can reflect the overall access relationship between each group attribute of each user's electronic seal at the current moment, providing a basis for subsequent collusion attack analysis.

[0089] Step S004: Analyze the similarity of the connection relationships between the subgraphs of high-level users in the attribute access graph structure and the corresponding nodes of each group of user electronic seals. Combine the corresponding relationships between the nodes and the user electronic seals to obtain the likelihood of being subject to collusion attacks for each high-level user at the current moment, and perform security management on the electronic seals of each user based on this.

[0090] It should be noted that in the attribute access graph structure, for the fully connected graph composed of high-level users internally, it is necessary to screen subgraphs from the connection relationships between the nodes of low-level users and high-level users with relatively lower levels, and perform similarity analysis with the fully connected graph of high-level users. On the basis of structural similarity, it is necessary to further compare the node values and edge values to perform similarity analysis of access situations on the basis of graph structure similarity; and the fewer different users are included in the similar subgraph, the higher the success rate of the collusion attack, and the less waste of user nodes, the more stable the collusion attack can be improved. Therefore, it is necessary to analyze the nodes in the similar subgraph and their corresponding users to quantify the access similarity coefficient between the similar subgraph and the fully connected graph of high-level users, and then obtain the likelihood of high-level users being subject to collusion attacks based on the access similarity coefficient.

[0091] Preferably, in an embodiment of the present invention, the specific method included in this step is as follows:

[0092] Obtain several similar subgraphs of the fully connected graph of each high-level user according to the connection relationships between the nodes of users with lower permissions for the fully connected graph of high-level users;

[0093] Analyze the difference relationships between the node values and edge values between the similar subgraph and its corresponding fully connected graph to obtain the graph access similarity of each similar subgraph and its corresponding fully connected graph;

[0094] Obtain the likelihood of being subject to collusion attacks for each high-level user at the current moment according to the nodes included in the similar subgraph and their corresponding users, and the graph access similarity between the similar subgraph and its corresponding fully connected graph;

[0095] Judge the likelihood of being subject to collusion attacks, analyze the abnormal access risks of the digital enterprise management platform, and perform security management on the electronic seals of each user.

[0096] As an example, obtaining several similar subgraphs of the fully connected graph of each high-level user according to the connection relationships between the nodes of users with lower permissions for the fully connected graph of high-level users, the specific method included is as follows:

[0097] For any fully-connected graph of a high-level user, based on the current attributes of the corresponding group attributes of each node in the fully-connected graph, obtain several nodes in the attribute access graph structure with the same current attributes as the corresponding group attributes, and based on the connection relationships between the several nodes, obtain several subgraphs with the same structure as the fully-connected graph (the nodes have the same current attributes, and the connection relationships between the nodes are the same as the edges in the fully-connected graph), denoted as several similar subgraphs of the fully-connected graph; specifically, in the acquisition of the above-mentioned several nodes, if the node corresponding user has the same permission level as the high-level user, that is, the number of groups included in the electronic seal is the same, it does not participate in the acquisition.

[0098] As an example, analyze the difference relationship between the node values and edge values between a similar subgraph and its corresponding fully-connected graph, and obtain the graph access similarity between each similar subgraph and its corresponding fully-connected graph. The specific methods included are:

[0099] For any fully-connected graph of a high-level user and any of its similar subgraphs, the calculation method of its graph access similarity is:

[0100]

[0101] Among them, represents the graph access similarity between any similar subgraph and its corresponding fully-connected graph, represents the number of edges of the fully-connected graph, represents the th edge value of the similar subgraph, represents the th edge value of the fully-connected graph, where the edge values in the fully-connected graph of the high-level user are all 1; represents the attribute replacement coefficient of the attribute of the corresponding group of one endpoint (node) of the th edge of the similar subgraph, represents the attribute replacement coefficient of the attribute of the corresponding group of the other endpoint of the th edge of the similar subgraph; represents the minimum value function.

[0102] It should be noted that on the basis of the structural similarity between the fully connected graph and the similar subgraph, it is necessary to further analyze the corresponding node values and edge values. In the fully connected graph of advanced users, all edge values are 1. In the similar subgraph, the closer the edge value is to 1, the greater the similarity of the current attribute access of the corresponding group attributes at both ends of the edge at the current moment, and the greater the possibility of being used as the basis for a collusion attack. At the same time, through the node value for restriction, the node value, that is, the attribute replacement coefficient, reflects the possibility of abnormal changes in the corresponding group attributes. The greater the minimum value of the attribute replacement coefficients at both ends of the edge in the similar subgraph, the greater the possibility of abnormal changes in the corresponding group attributes at both ends. When the possibility of abnormal changes in the corresponding group attributes is relatively large, the greater the edge value and the similarity of the current attribute access, the more likely it is to be preparing for a collusion attack, and the greater the graph access similarity needs to be given.

[0103] As an example, according to the nodes included in the similar subgraph and their corresponding users, and the graph access similarity between the similar subgraph and its corresponding fully connected graph, obtain the possibility of being attacked by collusion for each advanced user at the current moment. The specific method included is as follows:

[0104] For the fully connected graph of any advanced user and any of its similar subgraphs, the users corresponding to the nodes included in the similar subgraph are denoted as the participating users of the similar subgraph; then the access similarity coefficient is calculated as follows:

[0105]

[0106] where, represents the graph access similarity between any similar subgraph and its corresponding fully connected graph, represents the number of nodes in the similar subgraph, represents the number of participating users of the similar subgraph, represents the total number of nodes included in the fully connected graph of all participating users of the similar subgraph.

[0107] Furthermore, take the maximum value among the access similarity coefficients of all similar subgraphs of the fully connected graph as the possibility of being attacked by collusion for the corresponding advanced user at the current moment.

[0108] It should be noted that the maximum access similarity coefficient in the similar subgraph can best reflect the occurrence of a collusion attack. The greater it is, the more likely there is a collusion attack on the advanced user's permissions.

[0109] As an example, to judge the possibility of being attacked by collusion, analyze the abnormal access risk of the digital enterprise management platform, and conduct security management on the electronic seals of each user. The specific method included is as follows:

[0110] Preset an attack threshold. In this embodiment, the attack threshold is described as 0.7. If the likelihood of any senior user being subject to a collusive attack is greater than the attack threshold, it is necessary to promptly replace the attribute permissions included in their electronic seal. The senior user corresponding to the maximum value among the likelihoods of all senior users being subject to collusive attacks is given priority for replacement. For the electronic seals of users with the same attributes as those covered by the electronic seal of the replaced senior user, the corresponding attributes will all be changed. Continue to calculate the likelihood of the senior user being subject to a collusive attack at this time according to the above method, and so on, to monitor possible collusive attacks in real time and reduce the risk of unauthorized access to the permissions of electronic seals in the digital enterprise management platform.

[0111] Thus, by analyzing the structure of the attribute access graph based on the connection relationship between the subgraph of senior users and other nodes, and according to the similar structure, the attribute replacement coefficient corresponding to the nodes, and the current attribute access similarity between the nodes, the likelihood of junior users collusively attacking the permissions of senior users is reflected. Furthermore, by judging the likelihood of collusive attacks, the security management of user electronic seals is carried out, thereby reducing the risk of unauthorized access in the digital enterprise management platform.

[0112] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for electronic seal security management of a digital enterprise, characterized in that: The method comprises the following steps: Obtain the attributes and access status of all users' electronic seals in the digital enterprise management platform; Obtain several groups of attributes of each user's electronic seal; analyze the historical changes of attributes in the same group of attributes and the overall access situation before the attribute changes, and compare the access situation of each user before the corresponding attribute changes, and obtain the attribute replacement coefficient of each group of attributes of each user's electronic seal; Compare the changes in the access conditions of the two groups of attributes within a period of time before the current moment, and quantify the current attribute access similarity of any two groups of attributes; combine the attribute replacement coefficient of each group of attributes, and construct an attribute access graph structure for each group of attributes of all users' electronic seals, wherein each node in the attribute access graph structure corresponds to each group of attributes of each user's electronic seal; The similarity of the connection relationship between the subgraph of senior users in the attribute access graph structure and the nodes corresponding to each group of attributes of multiple users' electronic seals is analyzed, and the possibility of collusion attack for each senior user at the current moment is obtained in combination with the corresponding relationship between the nodes and the user's electronic seals, so as to perform security management of the electronic seals of each user.

2. According to the electronic seal security management method of a digital enterprise according to claim 1, it is characterized in that: The specific method for obtaining the several groups of attributes of each user's electronic seal is as follows: For any number of attributes contained in the electronic seal of a user, the start time and end time of each attribute are obtained since the electronic seal is obtained, and the duration of each attribute contained in the electronic seal of the user is obtained accordingly; The end time of any attribute is concatenated with the attributes with the same start time among the attributes other than the attribute, and several attributes are concatenated into a group of attributes, and so on to obtain several groups of attributes of the user's electronic seal.

3. The electronic seal security management method for a digital enterprise according to claim 2 is characterized in that: The method of analyzing the historical changes of attributes in the same group of attributes and the overall access situation before the attribute changes, and comparing the access situation of each user before the corresponding attribute changes, to obtain the attribute replacement coefficient of each group of attributes of each user's electronic seal includes the following specific methods: For User electronic seal In the group attributes property, get the The total access frequency of the corresponding permission from its start time to its end time, and record the The access frequency of each attribute corresponding to the permission from its start time to its end time on each day; Get the The ratio of the access frequency of the last day from the start time to the end time of the permission corresponding to the attribute to the total access frequency is obtained. The access frequency increment of each day from the start time to the end time of the corresponding permission of the attribute relative to the previous day is obtained. The average of the differences between the access frequency increment of the last day relative to the second last day and the access frequency increment of other days relative to the previous day from the start time to the end time of the corresponding permission of the attribute, and the product of the mean and the ratio is taken as the value of the first The abnormal change weight of each attribute; According to the duration of each attribute in the same group of attributes of the same user, and the access of the user to the corresponding authority of the attribute through the electronic seal, combined with the abnormal change weight, the attribute replacement coefficient of each group of attributes of each user's electronic seal is obtained.

4. The electronic seal security management method for a digital enterprise according to claim 3 is characterized in that: The method of obtaining the attribute replacement coefficient of each group of attributes of each user's electronic seal based on the duration of each attribute in the same group of attributes of the same user and the access of the user to the corresponding authority of the attribute through the electronic seal in combination with the abnormal change weight includes: Get the A user uses an electronic seal to In the group attributes The attribute corresponds to the access frequency of the permission from its start time to the last day of the end time. User electronic seal Attribute replacement coefficient of group attributes The calculation method is: in, Indicates User electronic seal The coefficient of variation of the duration of each attribute in the group attribute, Indicates User electronic seal the number of attributes in the group attribute, Indicates User electronic seal In the group attributes The abnormal change weight of each attribute, Indicates the The access frequency of each attribute corresponding to the permission from its start time to the last day of the end time. Indicates The user uses an electronic seal to The visit frequency of the last day from its start time to the end time.

5. The electronic seal security management method for a digital enterprise according to claim 1 is characterized in that: The specific method of comparing the changes in the access conditions of the two groups of attributes within a period of time before the current moment and quantifying the current attribute access similarity of any two groups of attributes includes: For the current moment, obtain the attributes of each group of attributes of each user's electronic seal at the current moment as the current attributes of each user. For any two groups of attributes of any two users' electronic seals, obtain the access frequency of the current attributes of any one of the two users from the start time to the end time when the user's electronic seal is changed to the current attribute, and arrange them in time sequence to form the access sequence of the user's current attribute. Obtain the access sequence of the current attribute of another user, and obtain the DTW distance between the two access sequences of the two current attributes of the two users through DTW matching; For the access sequences of the two current attributes of the two users, the last three elements of the two access sequences are respectively intercepted to form the access data segments of the two current attributes, and the cosine phase velocity and DTW distance between the access data segments of the two current attributes are obtained. The current attribute access similarity of the two sets of attributes of the electronic seals of the two users is calculated as follows: in, Indicates User electronic seal Group attributes and User electronic seal the current attribute access similarity of the group attributes, and Respectively represent User and The cosine phase velocity and DTW distance between the access data segments of the two current attributes of a user, Indicates User and The DTW distance between the access sequences of two current attributes of a user; For any two sets of attributes of the same user's electronic seal that correspond to each other at the current moment, the attributes are recorded as the current attributes of the two sets of attributes, and the start time of the current attributes of the user's electronic seal for the two sets of attributes is obtained, and the start time closest to the current moment to the current moment is used as the analysis period; The access frequency of the user's electronic seal to the current attributes of the two groups of attributes on each day during the analysis period is obtained, and the access frequency sequences of the current attributes of the two groups of attributes are respectively constructed in chronological order, and the cosine similarity between the two access frequency sequences is used as the current attribute access similarity of the two groups of attributes of the user's electronic seal.

6. The electronic seal security management method for a digital enterprise according to claim 1 is characterized in that: The specific method of constructing the attribute access graph structure for each group of attributes of all user electronic seals is as follows: The users whose electronic seals contain groups with a number less than the user classification parameter are regarded as low-level users, and the others are regarded as high-level users; For any senior user, each group of attributes of the senior user's electronic seal is regarded as a node, and each node corresponding to the senior user is fully connected to form a fully connected graph of the senior user, in which the node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge values ​​between nodes are all set to 1; For any low-level user, each group attribute of the low-level user's electronic seal is regarded as a node, and each node corresponding to the low-level user is fully connected to form a fully connected graph of the low-level user, in which the node value is assigned as the attribute replacement coefficient of the corresponding group attribute, and the edge value between nodes is set as the current attribute access similarity of different group attributes corresponding to the node; If the current attribute access similarity of different groups of attributes of different users is greater than the similarity threshold, the nodes corresponding to the two groups of attributes are connected, and the edge value is set to the corresponding current attribute access similarity; Similarly, the current attribute access similarity of each user's node is judged, and the corresponding nodes are connected and the corresponding edge values ​​are obtained; the graph structure composed of the fully connected graph of each user and the edges connecting the nodes in the fully connected graphs of different users is used as the attribute access graph structure.

7. The electronic seal security management method for a digital enterprise according to claim 6 is characterized in that: The method of analyzing the similarity of the connection relationship between the subgraph of the senior user in the attribute access graph structure and the nodes corresponding to the attributes of each group of the electronic seals of multiple users, and combining the corresponding relationship between the nodes and the electronic seals of the users, to obtain the possibility of each senior user being attacked by collusion at the current moment includes the following specific methods: For the fully connected graph of the advanced users, several similar subgraphs of the fully connected graph of each advanced user are obtained based on the connection relationship between the nodes of the users with lower authority; Analyze the difference between the node value and edge value between the similar subgraph and its corresponding fully connected graph, and obtain the graph access similarity between each similar subgraph and its corresponding fully connected graph; According to the nodes included in the similar subgraph and their corresponding users, as well as the graph access similarity between the similar subgraph and its corresponding fully connected graph, the possibility of each high-level user being attacked by collusion at the current moment is obtained.

8. The electronic seal security management method for a digital enterprise according to claim 7 is characterized in that: The fully connected graph of the advanced user is used to obtain several similar subgraphs of the fully connected graph of each advanced user based on the connection relationship between the nodes of the users with lower authority, including the specific method of: For any advanced user's fully connected graph, based on the current attributes of the corresponding group attributes of each node in the fully connected graph, several nodes with the same current attributes of the corresponding group attributes in the attribute access graph structure are obtained, and based on the connection relationship between the several nodes, several subgraphs with the same structure as the fully connected graph are obtained, which are recorded as several similar subgraphs of the fully connected graph.

9. The electronic seal security management method for a digital enterprise according to claim 8, characterized in that: The fully connected graph of the advanced user is used to obtain several similar subgraphs of the fully connected graph of each advanced user based on the connection relationship between the nodes of the users with lower authority, including the specific method of: in, Represents the graph access similarity between any similar subgraph and its corresponding fully connected graph, represents the number of edges in the fully connected graph, Indicates the similar subgraph The edge value of the edge, Indicates the first The edge value of the edge; Indicates the similar subgraph One endpoint of the edge corresponds to the attribute replacement coefficient of the group attribute. Indicates the similar subgraph The other end point of the edge corresponds to the attribute replacement coefficient of the group attribute; Represents a minimum value function.

10. The electronic seal security management method for a digital enterprise according to claim 7, characterized in that: The method of obtaining the possibility of collusion attack of each high-level user at the current moment based on the nodes included in the similar subgraph and their corresponding users, and the graph access similarity between the similar subgraph and its corresponding fully connected graph, includes the following specific methods: For any high-level user's fully connected graph and any similar subgraph thereof, the user corresponding to the node contained in the similar subgraph is recorded as the participating user of the similar subgraph; the access similarity coefficient between the similar subgraph and the fully connected graph is The calculation method is: in, Represents the graph access similarity between any similar subgraph and its corresponding fully connected graph, represents the number of nodes in the similar subgraph, represents the number of users participating in the similar subgraph, The total number of nodes included in the fully connected graph of all participating users of the similar subgraph.

Citation Information

Patent Citations

  • Literary work management system, method and device based on block chain

    CN115587910A

  • Trusted infrastructure support system, method and techniques for secure electronic commerce, electronic transactions, commerce process control and automation distributted computing and rights manageme

    CN1234892A