Multi-Factor Authentication-Based Data Security Transmission Method and System
By using multi-factor authentication and self-tuning authentication modules in the data transmission system, the problem of insufficient security protection of data transmission in the prior art is solved, efficient security protection of data transmission is achieved, and data confidentiality, integrity and availability are ensured.
Patent Information
- Application Number
- CN202510396854.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-04-01
AI Technical Summary
The existing data transmission technology is insufficient in terms of security protection, which can easily lead to data leakage, tampering and transmission interruption.
Using a data security transmission method and system based on multi-factor authentication, by obtaining the authentication factor matrix, zero-trust authentication conditions are constructed in the smallest permission scenario, and combined with the coupling relaxation processing of multi-factor authentication, multi-level authentication conditions are determined, and a self-tuning authentication module is constructed. The system performs security level segmentation during data transmission, determines the micro-segmented channel, and uses dynamic authentication to trigger and secure transmission authentication to ensure the confidentiality, integrity and availability of data transmission.
It realizes efficient security protection based on multi-factor authentication during data transmission, effectively protects the confidentiality, integrity and availability of data transmission, and avoids the risks of data leakage, tampering and transmission interruption.
Smart Images

Figure CN119906586B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security transmission, and particularly to a data security transmission method and system based on multi-factor authentication. Background Art
[0002] Existing data transmission technologies face many severe challenges. On the one hand, traditional authentication methods mostly rely on a single factor, such as a simple combination of username and password. In the face of increasingly complex network attack means, it is extremely easy to be cracked, resulting in the inability to guarantee the confidentiality of data transmission and frequent occurrence of sensitive information leakage incidents. On the other hand, during the transmission process, there is a lack of an effective mechanism to ensure the integrity of data, and malicious attackers have the opportunity to tamper with the data during transmission, causing data errors and business chaos.
[0003] The existing technology has technical problems of insufficient data transmission security protection, which easily leads to data leakage, tampering and transmission interruption. Summary of the Invention
[0004] This application provides a data security transmission method and system based on multi-factor authentication, which is used to solve the technical problems in the existing technology of insufficient data transmission security protection, which easily leads to data leakage, tampering and transmission interruption.
[0005] In view of the above problems, this application provides a data security transmission method and system based on multi-factor authentication.
[0006] In the first aspect of this application, a data security transmission method based on multi-factor authentication is provided. The method includes:
[0007] Obtain an authentication factor matrix, and based on the authentication factor matrix, construct zero-trust authentication conditions in the scenario of minimum privilege; taking the zero-trust authentication conditions as the baseline, through the coupled relaxation processing of multi-factor authentication, determine multi-level authentication conditions, and combine the zero-trust authentication conditions with the multi-level authentication conditions to construct a self-adjusting authentication module, where the self-adjusting authentication module is embedded and assembled in the server; receive a data transmission task, determine the transmission scenario from the source to the destination, perform security level segmentation, determine micro-segmented channels, where data desensitization is used as the pre-transmission processing; for the micro-segmented channels, assist the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication during transmission.
[0008] In the second aspect of this application, a data security transmission system based on multi-factor authentication is provided. The system includes:
[0009] The zero-trust authentication condition construction module is used to obtain the authentication factor matrix and construct the zero-trust authentication conditions in the minimum privilege scenario based on the authentication factor matrix; the multi-level authentication condition determination module is used to determine the multi-level authentication conditions by means of the coupled relaxation processing of multi-factor authentication with the zero-trust authentication conditions as the baseline, and jointly construct the self-adjusting authentication module with the zero-trust authentication conditions and the multi-level authentication conditions, wherein the self-adjusting authentication module is embedded and assembled in the server; the micro-segmented channel determination module is used to receive the data transmission task, determine the transmission scenario from the source to the destination, perform security level segmentation, and determine the micro-segmented channel, where data desensitization is used as the pre-transmission processing; the secure transmission authentication module is used to assist the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication during the transmission for the micro-segmented channel.
[0010] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0011] Obtain the authentication factor matrix, and construct the zero-trust authentication conditions in the minimum privilege scenario based on the authentication factor matrix; use the zero-trust authentication conditions as the baseline, and determine the multi-level authentication conditions by means of the coupled relaxation processing of multi-factor authentication, and jointly construct the self-adjusting authentication module with the zero-trust authentication conditions and the multi-level authentication conditions; receive the data transmission task, determine the transmission scenario from the source to the destination, perform security level segmentation, and determine the micro-segmented channel; for the micro-segmented channel, assist the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication during the transmission. It achieves the technical effect of realizing efficient security protection based on multi-factor authentication during data transmission and ensuring the confidentiality, integrity, and availability of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0013] Figure 1 It is a schematic flow chart of the data secure transmission method based on multi-factor authentication provided in the embodiment of this application;
[0014] Figure 2 It is a schematic structural diagram of the data secure transmission system based on multi-factor authentication provided in the embodiment of this application.
[0015] Description of the reference numerals: The zero-trust authentication condition construction module 10, the multi-level authentication condition determination module 20, the micro-segmented channel determination module 30, and the secure transmission authentication module 40. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] This application provides a data security transmission method and system based on multi-factor authentication to solve the technical problems of insufficient data transmission security protection in the prior art, which are prone to data leakage, tampering, and transmission interruption.
[0017] The following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0018] Embodiment 1, as Figure 1 shown, this application provides a data security transmission method based on multi-factor authentication, and the method includes:
[0019] Step S100: Obtain an authentication factor matrix, and based on the authentication factor matrix, construct zero-trust authentication conditions in a least-privilege scenario.
[0020] Specifically, various types of authentication-related information are widely collected through multiple channels. This information covers multiple dimensions such as user identity information, device characteristics, and network environment, and then an authentication factor matrix is integrated. This matrix comprehensively and meticulously records the key elements for identity authentication and permission judgment. On this basis, zero-trust authentication conditions are constructed around the least-privilege scenario. The least-privilege scenario follows the principle of least privilege, that is, any user or device is only given the minimum privilege required to complete the task before passing strict authentication. The zero-trust authentication conditions are based on this scenario, setting strict verification standards for each authentication factor and abandoning the traditional trust assumption. For example, for a user password, not only is the password strength required to reach a certain standard, but other authentication factors such as fingerprint recognition or SMS verification codes are also required for joint verification; for a device, various aspects such as the device's integrity and the presence of security vulnerabilities are checked. Only when all authentication factors meet the corresponding strict conditions will the access request be considered authenticated, thus laying a solid foundation for subsequent security operations.
[0021] Step S200: Taking the zero-trust authentication conditions as the baseline, performing coupled relaxation processing of multi-factor authentication to determine multi-level authentication conditions, and combining the zero-trust authentication conditions with the multi-level authentication conditions to construct a self-adjusting authentication module, where the self-adjusting authentication module is embedded and assembled in the server.
[0022] Specifically, based on the previously constructed zero-trust authentication conditions as the basic framework, the coupled relaxation processing of multi-factor authentication is carried out to determine multi-level authentication conditions, and a self-adjusting authentication module is constructed. First, the zero-trust authentication conditions are used as a strict baseline standard, which represents the authentication rules under the most stringent security requirements. Then, according to various factors in the actual application scenario, the coupled relaxation processing of multi-factor authentication is carried out. This process involves adjusting the association and dependency relationships between different authentication factors, and determining multi-level authentication conditions that adapt to different risk levels and business requirements by reasonably relaxing or tightening certain combinations of authentication conditions. For example, in a business scenario with low risk and simple operations, the verification intensity of some authentication factors can be appropriately reduced; while in the case of important data or high-risk operations, the authentication requirements are maintained or even increased. Then, the zero-trust authentication conditions are organically combined with these multi-level authentication conditions to jointly construct a self-adjusting authentication module. This module has the ability to intelligently adjust the authentication strategy. It can automatically select appropriate authentication conditions for verification according to real-time access requests, current security risk assessments, and system preset rules. Finally, this self-adjusting authentication module is assembled into the server in an embedded manner, making it a part of the server security protection system, ensuring that the server can authenticate flexibly and accurately according to the actual situation when processing various data access and transmission requests, effectively guaranteeing the security of data and the stability of the system.
[0023] Step S300: Receive a data transmission task, determine the transmission scenario from the source to the destination, perform security level segmentation, and determine the micro-segmented channel, where data desensitization is used as the pre-transmission processing.
[0024] Specifically, when a data transmission task is received, based on the metadata carried by the task, network environment information, source and destination device attributes, etc., the transmission scenario from the source to the destination is determined by combining the Bayesian network algorithm. The Bayesian network analyzes the probabilistic dependence relationships among various factors and comprehensively evaluates the security risk status of the current transmission scenario. Subsequently, security level segmentation is performed. Using the Analytic Hierarchy Process (AHP), factors such as the sensitivity, importance, and usage frequency of the data are used as evaluation indicators to construct a judgment matrix and calculate the weights of each indicator, thereby determining the security level of the data, such as high, medium, and low levels. In the preprocessing step of data desensitization, for structured data, if it contains personal sensitive information such as names and ID numbers, a rule-based replacement algorithm is used. For example, the name is irreversibly hashed using a hash function, and the date of birth part in the ID number is replaced with fixed characters; for numerical sensitive data, such as financial data, the differential privacy algorithm is used to add noise that conforms to the Laplace distribution to perturb the original data, protecting data privacy while ensuring data availability. For unstructured data, such as text contracts, the named entity recognition technology in natural language processing is used to identify sensitive entities, and then they are replaced with general placeholders using regular expressions. Finally, the micro-segmented channels are determined. Using the Dijkstra algorithm, with the security level, bandwidth, latency, etc. of network nodes as weights, and considering the results of security level segmentation, multiple optimal paths that meet different security requirements are found from the source to the destination, and these paths are divided into micro-segmented channels to ensure that data can be transmitted on secure and efficient paths.
[0025] Step S400: For the micro-segmented channels, assist the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication during transmission.
[0026] Specifically, a series of key operations are carried out for the identified micro-segmented channels to ensure data transmission security. When data is ready to be transmitted over the micro-segmented channels, it closely cooperates with the self-adjusting authentication module. First, each starting point of the segments in the micro-segmented channels is used as a key monitoring node. Once data transmission reaches these nodes, the dynamic authentication process is immediately triggered. During this process, various information related to the current transmission is collected in real time, such as the type and size of the transmitted data, the current network environment status, and the status of the device initiating the transmission. The self-adjusting authentication module will automatically adjust the authentication policy based on this real-time information and in combination with the previously constructed zero-trust authentication conditions and multi-level authentication conditions. For example, if there are certain risks in the current network environment, the self-adjusting authentication module will raise the authentication requirements and add additional authentication factors, such as requiring the user to enter a dynamic verification code or perform fingerprint recognition. Subsequently, the self-adjusting authentication module conducts strict security authentication on the data transmission according to the adjusted authentication policy. Only data transmission requests that pass the authentication completely are allowed to continue transmitting over the micro-segmented channels. If the authentication fails, the transmission is immediately terminated and a security alert is issued, thus ensuring the security and integrity of the data during the entire transmission process over the micro-segmented channels.
[0027] In a possible implementation manner, step S200 further includes:
[0028] Step S210: Build a permission space according to the least privilege scenario, where the least privilege scenario defines the boundary of the permission space.
[0029] Step S220: Interact with the data communication records, perform a coupled relaxation process of permission scenario segmentation and multi-factor authentication on the permission space, and determine the multi-level authentication conditions.
[0030] Specifically, building a permission space based on the least privilege scenario is an important fundamental step. The least privilege scenario follows the principle of least privilege and stipulates the minimized set of permissions that a user or device can obtain in a specific situation. These permissions are essential for completing specific tasks and also strictly define the boundary of the permission space. Taking each authentication factor in the authentication factor matrix as a reference, the axes of the permission space are determined. For example, if the authentication factors include user identity, device type, operation time, etc., these factors respectively correspond to different axes of the permission space. For the least privilege scenario, the single-factor authentication conditions of each authentication factor under the zero-trust authentication conditions are clarified, such as the password strength requirement for user identity, the compliance requirement for device type, and the allowable range of operation time. Finally, by integrating these space axes and single-factor authentication conditions, a permission space is constructed, providing a basic framework for subsequent determination of multi-level authentication conditions.
[0031] Through the interactive data communication records, conduct in-depth analysis and processing on the established permission space. The data communication records contain rich information, reflecting the permission usage in different scenarios. Based on these records, perform permission scenario segmentation on the permission space. This process divides the permission space into multiple different sub-spaces, each sub-space corresponding to a specific permission scenario, such as the daily office permission scenario, the emergency affairs handling permission scenario, etc. At the same time, perform the coupling relaxation processing of multi-factor authentication. This means adjusting the strictness of multi-factor authentication according to the characteristics of different permission scenarios. In some low-risk permission scenarios, appropriately relax the authentication conditions and reduce the verification requirements for some authentication factors; while in high-risk scenarios, maintain or even strengthen the authentication requirements. Through the collaborative operation of this permission scenario segmentation and coupling relaxation processing, accurately determine the multi-level authentication conditions suitable for different scenarios. These conditions provide rich strategy options for the subsequent construction of the self-adjusting authentication module, helping to improve the flexibility and security of authentication.
[0032] In a possible implementation manner, step S220 further includes:
[0033] Step S221: Cluster the data communication records according to a preset scenario difference to determine N groups of communication records, where N is a positive integer greater than or equal to 1.
[0034] Step S222: Traverse the N groups of communication records to determine N transmission scenario features.
[0035] Step S223: Divide the permission space according to the N transmission scenario features to determine N permission space blocks.
[0036] Step S224: Configure the multi-level authentication conditions for the N permission space blocks, where the multi-level authentication conditions correspond one-to-one with the N permission space blocks.
[0037] Specifically, when conducting permission scenario analysis and determining multi-level authentication conditions, refer to the preset scenario difference, which is set based on the in-depth analysis of historical communication data, security policies, and the summary of past security incidents. It represents a quantitative index for distinguishing different communication scenarios. Then, apply it to the processing of data communication records and use a clustering algorithm to process a large number of data communication records. The clustering algorithm will calculate the similarity between records based on various attributes in the data communication records, such as communication time, communication device, type of business communicated, data traffic size, etc. If the similarity between records exceeds the range specified by the preset scenario difference, they will be grouped together. The data communication records are divided into N groups of communication records, where N is a positive integer greater than or equal to 1.
[0038] Traverse these N groups of communication records one by one. During the traversal, for each group of communication records, deeply explore and refine the corresponding transmission scenario features. These features cover multiple aspects such as the initiation time of communication, the initiating device, the data transmission volume, the communication frequency, and the business types involved in the communication. By analyzing these features, accurately grasp the uniqueness of the transmission scenario represented by each group of communication records, and then determine N transmission scenario features.
[0039] Based on the determined N transmission scenario features, perform a block processing on the previously built permission space. The transmission scenario features reflect different permission requirements in different scenarios. According to these differences, divide the permission space into N different parts, that is, determine N permission space blocks. For example, if it is found that some transmission scenarios mainly involve the reading operation of ordinary office documents, then the corresponding permission space block mainly contains the permissions for operations related to office documents; while for the transmission scenarios involving financial data processing, the corresponding permission space block will focus on the permissions related to financial data.
[0040] For these N permission space blocks, respectively configure the corresponding multi-level authentication conditions. Since different permission space blocks represent different permission scenarios, their faced security risks and required authentication intensities are also different. Therefore, tailor-make the matching multi-level authentication conditions for each permission space block to ensure that these multi-level authentication conditions correspond one by one with the N permission space blocks. For example, for the permission space block involving highly sensitive data, more stringent authentication conditions will be configured, requiring the user to not only provide a password but also perform fingerprint recognition and dynamic verification code verification, etc.; while for the permission space block for general operations, the authentication conditions are relatively loose and only password verification is required. Through such meticulous configuration, the authentication process can better adapt to different permission scenarios, improving security and flexibility.
[0041] In a possible implementation manner, step S210 further includes:
[0042] Step S211: Determine the spatial axis directions with each authentication factor in the authentication factor matrix.
[0043] Step S212: For the minimum permission scenario, determine the single-factor authentication conditions of each authentication factor under the zero-trust authentication condition.
[0044] Step S213: Construct the permission space according to the spatial axis directions and the single-factor authentication conditions.
[0045] Specifically, the spatial axes are determined based on each authentication factor within the authentication factor matrix. The authentication factor matrix encompasses various key elements for identity verification and permission judgment, such as user identity information (e.g., username, password), device characteristics (e.g., device model, device fingerprint), geographical location information, and time information, etc. These different types of authentication factors correspond to different spatial axes, and each axis represents a dimension that affects permissions. For example, taking user identity information as an axis means that the potential permission differences of different user identities can be measured in this dimension; taking device characteristics as an axis can be used to distinguish the differences in permission acquisition of different devices.
[0046] For the least privilege scenario, the single-factor authentication conditions for each authentication factor under zero-trust authentication conditions are determined. The least privilege scenario follows the principle of least privilege. In this scenario, any access request is only granted the minimum privilege required to complete the task before passing strict authentication. The zero-trust authentication conditions are based on this scenario and set strict verification standards for each authentication factor. Taking the authentication factor of user identity information as an example, it is required that the username must conform to a specific naming convention, and the password needs to reach a certain strength, such as containing letters, numbers, and special characters, and the length is not less than 8 digits; for device characteristics, it is required that the device must install a specific version of security software, and the system update of the device must be in the latest state, etc. By formulating such specific single-factor authentication conditions for each authentication factor, the security of access requests in the least privilege scenario is ensured.
[0047] According to the previously determined spatial axes and single-factor authentication conditions, a permission space is constructed. The various spatial axes are combined according to the authentication factor dimensions they represent, and the value range of each axis is limited by the corresponding single-factor authentication conditions. For example, in the permission space constructed with user identity, device characteristics, geographical location, and time as axes, the value range of the user identity axis is determined by the set of users who meet the username and password requirements, the value range of the device characteristics axis is determined by the set of devices that meet the security software and system update requirements, the value range of the geographical location axis is set according to the allowed access geographical locations, and the time axis is determined according to the allowed access time periods. In this way, through the cross-combination of each axis and its value range, a multi-dimensional permission space is constructed, clarifying the permission boundaries under different combinations of authentication factors, and providing an important basic framework for subsequent permission management and authentication condition determination.
[0048] In a possible implementation manner, step S224 further includes:
[0049] Step S2241: Identify the first permission space block, where the first permission space block is a multi-dimensional space block that covers the authentication factor matrix.
[0050] Step S2242: Determine the coupling relaxation degree based on the distances between the boundaries of each block of the first permission space block and the permission space boundaries of the corresponding authentication factors, where the coupling relaxation degree is positively correlated with the distance.
[0051] Step S2243: Adjust the zero-trust authentication conditions according to the coupling relaxation degree to determine the first authentication conditions.
[0052] Specifically, identify the first permission space block from the divided permission space blocks. This first permission space block is a multi-dimensional space block that covers the authentication factor matrix, which means it synthesizes the dimensions formed by multiple authentication factors and covers various permission combination situations under different authentication factors. For example, in a system that includes authentication factors such as user identity, device type, and operation time, the first permission space block includes the permission situations under different combinations of user identities, device types, and operation times.
[0053] Determine the coupling relaxation degree by calculating the distances between the boundaries of each block of the first permission space block and the permission space boundaries of the corresponding authentication factors. For each authentication factor dimension, measure the distance between the boundary of the first permission space block in this dimension and the permission boundary of this authentication factor in the entire permission space. Suppose there is a certain difference between the range of user identities allowed by the first permission space block and the range of user identities covered by the entire permission space in the user identity authentication factor dimension. This difference in distance is one of the bases for calculating the coupling relaxation degree. And it is stipulated here that the coupling relaxation degree is positively correlated with the distance, that is, the larger the distance, the higher the coupling relaxation degree; the smaller the distance, the lower the coupling relaxation degree. This is because a larger distance means that the permission range of this permission space block in this authentication factor has a greater difference from the overall permission space, and the corresponding authentication conditions can be appropriately relaxed, that is, the coupling relaxation degree is higher.
[0054] Adjust the zero-trust authentication conditions according to the determined coupling relaxation degree to further determine the first authentication conditions. If the coupling relaxation degree is high, it means that the permission range of the first permission space block in some authentication factors is relatively loose, then appropriately relax the requirements for the corresponding authentication factors in the zero-trust authentication conditions. For example, if the coupling relaxation degree of the first permission space block is high in the device type authentication factor dimension, and the zero-trust authentication conditions originally require that the device must be of a specific brand and install a specific version of security software, at this time, it can be relaxed to allow some other brand devices or reduce the security software version requirements; conversely, if the coupling relaxation degree is low, maintain or even strengthen the zero-trust authentication conditions. After such adjustment, finally determine the first authentication conditions suitable for the first permission space block to ensure that the authentication conditions match the actual needs of this permission space block and improve the rationality and security of authentication.
[0055] In a possible implementation manner, step S300 further includes:
[0056] Step S310: Determine the transmission data according to the data transmission task, and identify the sensitive data part and the non-sensitive data part.
[0057] Step S320: Introduce a data desensitization rule. Specifically, byte substitution - row shift - column confusion - round key addition is used as the desensitization method, and according to the data sensitive characteristics, the data desensitization rule is determined according to the desensitization level setting under at least one desensitization method.
[0058] Step S330: Identify the sensitive data part, initialize the data desensitization rule by performing sensitive feature recognition, perform desensitization processing on the sensitive data part, and determine the desensitized data.
[0059] Step S340: Integrate the desensitized data and the non-sensitive data part as the pre-transmission data.
[0060] Specifically, when a data transmission task is received, a comprehensive analysis is immediately performed on the data involved in the task. First, clarify what specific data is included in this transmission task, covering various forms of data content such as various files, database records, real-time messages, etc. Then, use the pre-set sensitive data recognition strategy to distinguish between sensitive and non-sensitive data parts. These strategies are formulated based on various factors such as the type, format, and context environment of the data. For example, according to the common sensitive data type library, data with specific formats such as ID card numbers, bank card numbers, and business secrets can be identified as sensitive data; judged from the context environment of the data, if personal contact information appears in a document related to user privacy, it will also be recognized as sensitive data. For some public information, such as general industry terms and common basic statistical data, they are classified as non-sensitive data. Through this detailed identification method, the sensitive and non-sensitive parts in the transmission data are accurately divided.
[0061] Introduce a data desensitization rule. Here, byte substitution, row shift, column confusion, and round key addition are used as the desensitization methods. According to the sensitive characteristics of the data, such as data type, data usage, and the possible risk level, set the corresponding desensitization level under at least one desensitization method, and then determine the specific data desensitization rule. For example, for highly sensitive bank card number data, use both byte substitution and round key addition methods, and set a higher desensitization level to ensure full protection of the data; for relatively less sensitive phone numbers, perhaps only use the row shift method and set a lower desensitization level.
[0062] After the sensitive data part in the transmission data has been identified, deeply analyze the characteristics of this sensitive data. By scanning and parsing the data's structure, content pattern, and possible identification information, such as determining whether the data is in the format of an ID card number or contains specific sensitive words, to accurately extract sensitive features. These sensitive features are used to initialize the pre-set data desensitization rules. The data desensitization rules are formulated based on different sensitive features and security requirements, covering various desensitization methods and different desensitization levels. After completing the rule initialization, perform desensitization processing on the sensitive data part according to the established rules. This process involves byte substitution, replacing the bytes in the data with other values; row shifting, changing the arrangement order of the data in the storage structure; column confusion, scrambling the organization form of the data columns; and round key addition, encrypting the data in combination with a specific key and other operations. After these processing steps, the original form of the sensitive data is changed, thus generating desensitized data, effectively reducing the risk of sensitive data during transmission and ensuring data security.
[0063] Fuse the desensitized data after desensitization processing with the non-sensitive data part identified previously, and use the fused data as the pre-transmission data. In this way, the pre-transmission data not only ensures the availability of the data but also reduces the security risk of the data during transmission through the desensitization processing of the sensitive data, laying a foundation for the subsequent secure data transmission.
[0064] In a possible implementation manner, step S300 further includes:
[0065] Step S350: Decompose the transmission scenario into a hardware scenario and a channel scenario.
[0066] Step S360: According to the hardware scenario, perform a first segmentation based on the hardware scenario transition to determine the first micro-segmented channel.
[0067] Step S370: According to the channel scenario, perform a second segmentation based on the channel scenario transition to determine the second micro-segmented channel.
[0068] Step S380: Fuse the first micro-segmented channel and the second micro-segmented channel to determine the micro-segmented channel.
[0069] Specifically, the overall scenario of data transmission is analyzed and disassembled into two main parts: hardware scenario and channel scenario. The hardware scenario mainly covers various hardware devices involved in data transmission, including source devices, sink devices, and various network devices involved in the transmission path. The performance, security, and connection relationship between these hardware devices constitute the hardware scenario. The channel scenario focuses on the communication channel on which data transmission depends, including the type of channel (such as wired channel, wireless channel), channel bandwidth, latency, stability, and security threats faced by the channel.
[0070] A segmentation based on the transition of hardware scenarios is performed according to the characteristics of the hardware scenarios. This means that the data transmission path is initially divided at the hardware level according to factors such as the changes in hardware devices, the differences in security levels of different hardware devices, and the connection relationship between them. For example, if there are servers with different security levels or different types of terminal devices in the transmission path, the transmission path is divided into different segments based on these differences. Each segment corresponds to a relatively independent hardware environment, thereby determining the first micro-segment channel. This division helps to implement security measures in a targeted manner based on the security requirements of different hardware environments.
[0071] During the data transmission process, in order to ensure data security and achieve more refined transmission path management, secondary segmentation based on channel scenario transition is carried out to determine the second micro-segment channel. First, comprehensive information about the transmission channel from the source to the destination is obtained, including the technical parameters of the channel, the current load status, etc. At the same time, the historical transmission records of the transmission channel are called, and the information confrontation points are mined with the help of data analysis technology. These information confrontation points not only identify the confrontation type, such as network attack, signal interference or data tampering, but also clarify the confrontation level, from low risk to high risk, so as to quantify the degree of security threat faced by the channel. Next, the preset confrontation transition amount is used as the key constraint condition, which is a value set in advance based on the system security strategy and the expected assessment of channel risks. According to the mined information confrontation points and the preset confrontation transition amount, the transmission channel is reasonably divided. For example, near the area where there is a high confrontation level information confrontation point, it is segmented according to the interval distance specified by the preset confrontation transition amount, so that the area with a higher degree of threat is separated from other parts to form a relatively independent channel segment. In this way, the entire transmission channel is divided into multiple segments, which are the second micro-segment channel. This secondary segmentation based on channel scene transition can target the parts of the channel with potential security risks and build a more reliable path system for secure data transmission.
[0072] Fuse the first micro-segmented channel and the second micro-segmented channel. By comprehensively considering the segmentation results of the hardware scenario and the channel scenario, integrate the micro-segmented channels at the two levels, and finally determine the micro-segmented channel that meets the requirements of data secure transmission. This fused micro-segmented channel takes into account both the differences and security requirements of hardware devices and combines the security status of the channel itself, providing a more reliable guarantee for the security and stability of data during transmission.
[0073] In a possible implementation manner, step S370 further includes:
[0074] Step S371: Obtain the transmission channel from the source to the destination.
[0075] Step S372: Invoke the historical transmission records of the transmission channel to mine information confrontation points, where each information confrontation point is marked with a confrontation type and a confrontation level.
[0076] Step S373: According to the information confrontation points, perform a secondary segmentation based on the channel scenario transition with a preset confrontation transition amount as a constraint.
[0077] Specifically, obtain the transmission channel from the source to the destination. This operation involves a comprehensive scan and identification of the data transmission link to clarify the physical or logical channels that the data actually passes through in the network environment. Whether it is the optical fiber or cable line in a wired network or the specific frequency band channel in a wireless network, it is included in the system's acquisition scope to ensure that the acquired transmission channel information is complete and accurate.
[0078] Invoke the historical transmission records of this transmission channel. These historical records contain various detailed information about the channel during past data transmissions, such as transmission time, transmission data volume, transmission interruption situations, etc. By using data mining algorithms to deeply analyze these records, information confrontation points are mined. Information confrontation points refer to the key nodes that interfere with the normal transmission of data and affect transmission security during the transmission process, and each information confrontation point is accurately marked with a confrontation type and a confrontation level. The confrontation types include network attacks (such as malicious intrusion by hackers, DDoS attacks), signal interference (such as electromagnetic interference causing signal attenuation or loss), data tampering (illegally modifying the data content during transmission), etc.; the confrontation level is divided according to factors such as the severity of interference and occurrence frequency. For example, a low level may indicate occasional minor interference, while a high level means frequent and serious security threats.
[0079] Based on the previously mined information confrontation points, with the preset confrontation transition amount as the key constraint condition, carry out the secondary segmentation work based on the channel scenario transition. Conduct in-depth analysis on each information confrontation point, considering its confrontation type (such as malware attack, signal interference, or illegal data interception, etc.) and confrontation level (ranging from occasional minor interference with low risk to frequent severe threats with high risk). The preset confrontation transition amount is a quantization standard set in advance based on the system security policy, past channel risk assessment, and the expectation for transmission stability. When facing an information confrontation point, centered on this point, divide the transmission channel in combination with the interval distance specified by the preset confrontation transition amount. For information confrontation points with a high confrontation level, due to their greater threat to data transmission, divide the surrounding area according to a relatively small preset confrontation transition amount, so as to isolate the severely threatened channel area and form a separate channel segment; while for information confrontation points with a low confrontation level, because their risk is relatively low, the segmentation interval will be appropriately increased according to the preset confrontation transition amount. Through such operations, the transmission channel is divided into multiple parts with different security characteristics, and these parts are the second micro-segmented channels, providing a more refined and reliable channel plan for subsequent data security transmission.
[0080] In a possible implementation manner, step S400 further includes:
[0081] Step S410: Use the segmentation start of the micro-segmented channel as a dynamic transmission authentication node to assist the self-adjusting authentication module in triggering the permission scenario authentication of the micro-segmented channel, and generate an authentication pop-up window based on the authentication factor matrix.
[0082] Specifically, set the start point of each segment of the micro-segmented channel as a dynamic transmission authentication node. When data transmission reaches these nodes, immediately start the permission scenario authentication process and cooperate closely with the self-adjusting authentication module. The self-adjusting authentication module will comprehensively consider various authentication factors involved in the current transmitted data based on the authentication factor matrix, and these factors cover multiple dimensions such as user identity, device information, transmission time, data type, etc. Based on these factors, generate an authentication pop-up window based on the authentication factor matrix. For example, if the current transmitted data involves highly sensitive information, the authentication pop-up window may require the user to input an additional dynamic verification code and perform fingerprint recognition to strengthen the authentication process; if the transmission environment is a public network with a high risk, the pop-up window may require the device to re-perform a security scan and upload the scan report. The generation of this authentication pop-up window aims to ensure that at each key transmission node of the micro-segmented channel, the authentication process can be flexibly and accurately triggered according to the real-time transmission scenario and authentication factors, comprehensively guarantee the security of data transmission, and prevent unauthorized data access and transmission behaviors.
[0083] Embodiment 2. Based on the same inventive concept as the data security transmission method based on multi-factor authentication in the foregoing embodiment, as Figure 2 shown, the present application provides a data security transmission system based on multi-factor authentication. The system in the embodiment of the present application and the method embodiment are based on the same inventive concept. Among them, the system includes:
[0084] A zero-trust authentication condition construction module 10, configured to obtain an authentication factor matrix, and construct zero-trust authentication conditions in a least-privilege scenario according to the authentication factor matrix.
[0085] A multi-level authentication condition determination module 20, configured to use the zero-trust authentication conditions as a baseline, perform coupled relaxation processing of multi-factor authentication to determine multi-level authentication conditions, and combine the zero-trust authentication conditions and the multi-level authentication conditions to construct a self-adjusting authentication module, where the self-adjusting authentication module is embedded and assembled in the server.
[0086] A micro-segmented channel determination module 30, configured to receive a data transmission task, determine a transmission scenario from the source to the destination, perform security level segmentation, and determine a micro-segmented channel, where data desensitization is used as a pre-transmission processing.
[0087] A secure transmission authentication module 40, configured to assist the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication during transmission for the micro-segmented channel.
[0088] Further, the system is also used to implement the following functions:
[0089] Build a permission space according to the least-privilege scenario, where the least-privilege scenario defines the boundary of the permission space; interact with the data communication record, perform permission scenario segmentation and coupled relaxation processing of multi-factor authentication on the permission space, and determine the multi-level authentication conditions.
[0090] Further, the system is also used to implement the following functions:
[0091] Cluster the data communication records according to a preset scenario difference to determine N groups of communication records, where N is a positive integer greater than or equal to 1; traverse the N groups of communication records to determine N transmission scenario features; divide the permission space according to the N transmission scenario features to determine N permission space blocks; configure the multi-level authentication conditions for the N permission space blocks, where the multi-level authentication conditions correspond to the N permission space blocks one by one.
[0092] Further, the system is also used to implement the following functions:
[0093] Determine the spatial axis using each authentication factor within the authentication factor matrix; for the least privilege scenario, determine the single-factor authentication conditions for each authentication factor under the zero-trust authentication condition; construct the privilege space based on the spatial axis and the single-factor authentication conditions.
[0094] Furthermore, the system is also used to implement the following functions:
[0095] Identify the first privilege space block, where the first privilege space block is a multi-dimensional space block covering the authentication factor matrix; determine the coupling relaxation degree based on the distance between the boundaries of each block of the first privilege space block and the privilege space boundaries of the corresponding authentication factors, where the coupling relaxation degree is positively correlated with the distance; adjust the zero-trust authentication condition according to the coupling relaxation degree to determine the first authentication condition.
[0096] Furthermore, the system is also used to implement the following functions:
[0097] Determine the transmission data according to the data transmission task, and identify the sensitive data part and the non-sensitive data part; introduce data desensitization rules, where byte substitution - row shift - column confusion - round key addition is used as the desensitization method, and according to the data sensitive characteristics, determine the data desensitization rules based on the desensitization level settings under at least one desensitization method; identify the sensitive data part, initialize the data desensitization rules by performing sensitive feature recognition, perform desensitization processing on the sensitive data part to determine the desensitized data; fuse the desensitized data and the non-sensitive data part as the pre-transmission data.
[0098] Furthermore, the system is also used to implement the following functions:
[0099] Perform a first segmentation based on the hardware scenario transition to determine the first micro-segmented channel; perform a second segmentation based on the channel scenario transition to determine the second micro-segmented channel; fuse the first micro-segmented channel and the second micro-segmented channel to determine the micro-segmented channel.
[0100] Furthermore, the system is also used to implement the following functions:
[0101] Obtain the transmission channel from the source to the destination; call the historical transmission records of the transmission channel to mine information confrontation points, where each information confrontation point is marked with an confrontation type and an confrontation level; perform a second segmentation based on the channel scenario transition with a preset confrontation transition amount as a constraint according to the information confrontation points.
[0102] Furthermore, the system is also used to implement the following functions:
[0103] Taking the start of the micro-segmented channel as the dynamic transmission authentication node, assist the self-adjusting authentication module to trigger the permission scenario authentication of the micro-segmented channel, and generate an authentication pop-up window based on the authentication factor matrix.
[0104] It should be noted that the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of this specification have been described. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0105] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included within the protection scope of the present application.
[0106] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.
Claims
1. A data security transmission method based on multi-factor authentication, characterized in that: The method comprises: Obtain an authentication factor matrix, and construct zero-trust authentication conditions in a minimum privilege scenario based on the authentication factor matrix; Taking the zero-trust authentication condition as a baseline, determining a multi-level authentication condition by coupling relaxation processing of multi-factor authentication, combining the zero-trust authentication condition with the multi-level authentication condition, and constructing a self-adjusting authentication module, wherein the self-adjusting authentication module is embedded in a server; Receive data transmission tasks, determine the transmission scenario from the source to the destination, perform security level segmentation, and determine micro-segment channels, among which data desensitization is used as a pre-transmission processing; For the micro-segmented channel, assisting the self-adjusting authentication module to perform dynamic authentication triggering and secure transmission authentication along with transmission; Determining the multi-level authentication conditions includes: Clustering the data communication records according to the preset scenario differences to determine N groups of communication records, where N is a positive integer greater than or equal to 1; Traversing the N groups of communication records to determine N transmission scenario features; Divide the permission space into blocks according to the N transmission scenario features to determine N permission space blocks; For the N permission space blocks, configuring the multi-level authentication condition, wherein the multi-level authentication condition corresponds one-to-one to the N permission space blocks; For the N permission space blocks, configuring the multi-level authentication conditions includes: identifying a first authority space block, the first authority space block being a multidimensional space block covering the authentication factor matrix; Determine coupling relaxation according to the distance between each block boundary of the first authority space block and the authority space boundary of the corresponding authentication factor, wherein the coupling relaxation is positively correlated with the distance; According to the coupling relaxation, the zero-trust authentication condition is adjusted to determine a first authentication condition.
2. The data security transmission method based on multi-factor authentication as claimed in claim 1, characterized in that: The multi-factor authentication coupling relaxation process is used to determine the multi-level authentication conditions, including: According to the minimum permission scenario, a permission space is constructed, wherein the minimum permission scenario defines the boundary of the permission space; Interacting data communication records, performing permission scenario segmentation and multi-factor authentication coupling relaxation processing on the permission space, and determining the multi-level authentication conditions.
3. The data security transmission method based on multi-factor authentication as claimed in claim 2, characterized in that: According to the minimum permission scenario, build a permission space, including: Determine a spatial axis using each authentication factor in the authentication factor matrix; For the minimum privilege scenario, determine the single-factor authentication conditions of each authentication factor under the zero-trust authentication condition; The permission space is constructed according to the spatial axis and the single-factor authentication condition.
4. The data security transmission method based on multi-factor authentication as claimed in claim 1, characterized in that: Data desensitization is used as a pre-transmission processing, including: According to the data transmission task, determine the transmission data, and identify the sensitive data part and the non-sensitive data part; Introducing data desensitization rules, wherein byte substitution-row shift-column confusion-round key addition is used as a desensitization method, and according to the data sensitivity characteristics, the data desensitization rules are determined by setting a desensitization level under at least one desensitization method; Identify the sensitive data portion, initialize the data desensitization rule by performing sensitive feature identification, perform desensitization processing on the sensitive data portion, and determine desensitized data; The desensitized data and the non-sensitive data portion are merged as pre-transmission data.
5. The data security transmission method based on multi-factor authentication as claimed in claim 1, characterized in that: Decomposing the transmission scenario into a hardware scenario and a channel scenario; According to the hardware scenario, a segmentation based on the hardware scenario transition is performed to determine the first micro-segment channel; According to the channel scenario, perform secondary segmentation based on channel scenario transition to determine a second micro-segment channel; The first micro-segment channel and the second micro-segment channel are merged to determine the micro-segment channel.
6. The data security transmission method based on multi-factor authentication as claimed in claim 5, characterized in that: According to the channel scenario, secondary segmentation based on channel scenario transition is performed, including: Obtaining a transmission channel from a signal source to a signal sink; Calling the historical transmission records of the transmission channel to mine information confrontation points, wherein each information confrontation point is marked with a confrontation type and a confrontation level; According to the information confrontation point, a secondary segmentation based on channel scene transition is performed with a preset confrontation transition amount as a constraint.
7. The data security transmission method based on multi-factor authentication as claimed in claim 1, characterized in that: The segment start of the micro-segment channel is used as a dynamic transmission authentication node to assist the self-adjusting authentication module in triggering the permission scenario authentication of the micro-segment channel and generate an authentication pop-up window based on the authentication factor matrix.
8. A data security transmission system based on multi-factor authentication, characterized in that: The system is used to implement the data security transmission method based on multi-factor authentication according to any one of claims 1 to 7, and the system includes: A zero-trust authentication condition construction module is used to obtain an authentication factor matrix and construct a zero-trust authentication condition in a minimum authority scenario based on the authentication factor matrix; A multi-level authentication condition determination module, used to determine the multi-level authentication condition based on the zero-trust authentication condition as a baseline and the coupling relaxation process of multi-factor authentication, and to combine the zero-trust authentication condition with the multi-level authentication condition to construct a self-adjusting authentication module, wherein the self-adjusting authentication module is embedded in the server; The micro-segment channel determination module is used to receive data transmission tasks, determine the transmission scenario from the source to the destination, perform security level segmentation, and determine the micro-segment channel, wherein data desensitization is used as a pre-transmission processing; A secure transmission authentication module, used for assisting the self-adjusting authentication module in performing dynamic authentication triggering and secure transmission authentication along with transmission for the micro-segmented channel; The system is also used to implement the following functions: According to the preset scenario difference, clustering the data communication records to determine N groups of communication records, where N is a positive integer greater than or equal to 1; traversing the N groups of communication records to determine N transmission scenario features; according to the N transmission scenario features, dividing the permission space into blocks to determine N permission space blocks; configuring the multi-level authentication conditions for the N permission space blocks, where the multi-level authentication conditions correspond one-to-one to the N permission space blocks; Identify a first permission space block, where the first permission space block is a multidimensional space block covering the authentication factor matrix; determine the coupling relaxation based on the distance between each block boundary of the first permission space block and the permission space boundary of the corresponding authentication factor, wherein the coupling relaxation is positively correlated with the distance; adjust the zero-trust authentication condition according to the coupling relaxation to determine the first authentication condition.
Citation Information
Patent Citations
Power data boundary protection method
CN118278030A