Commercial password cloud supervision and management information system and method based on credential environment

By building a commercial password cloud supervision and management information system in the information innovation environment, the problem of lack of unified management and security protection in the existing technology is solved, and centralized management and unified supervision of cryptographic equipment and services in the information system is realized, and security and management efficiency are improved.

CN119939571AInactive Publication Date: 2025-05-06JIANGSU AEROSPACE 706 INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510092300.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The lack of a unified commercial password cloud supervision and management system and methods in the existing technology has led to no unified standards for the construction and management of password application work, weak security protection, irregular resource use, scattered sources of risk intelligence, and insufficient dynamic correlation analysis.

Method used

Based on the information innovation environment, a commercial password cloud supervision and management information system is built, including the platform basic support module and the platform business processing module. The platform's basic support module includes a management middle platform, a data middle platform and a technical middle platform, which is used to establish a unified user authentication system, obtain and identify password calling data, and establish a technical support middle platform. The platform business processing module includes an audit system, a supervision system, a notification and early warning system and a situation analysis system, which is used to unify the supervision application system and cryptographic equipment, configure a unified case handling process, conduct notification and early warning processing, and intelligent analysis and display.

Benefits of technology

It realizes centralized management of password equipment and services in the information system, provides unified password resource services, improves the security and management efficiency of password applications, integrates data resources for overall analysis and processing, and reduces duplicate construction and waste of fiscal funds.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939571A_ABST
    Figure CN119939571A_ABST
Patent Text Reader

Abstract

The invention discloses a commercial password cloud supervision and management information system and method based on a credential environment, and relates to the technical field of password security, and the system comprises a platform basic support module and a platform business processing module. The platform basic support module comprises a data middle station, a management middle station and a technology middle station; the platform business processing module comprises an examination system, a notification early warning system, a supervision system and a situation analysis system; under the dual drive of credential creation and password creation, the commercial password cloud supervision and management system is established based on a credential creation localization software and hardware environment, and unified supervision and standard management of password application are realized by using the platform basic support module and the platform business processing module; the information system deployed on the credential cloud obtains multi-dimensional, panoramic, intelligent and full-life-cycle password application monitoring perception and analysis early warning, a password data resource sharing system can also be formed, the password system construction efficiency is improved, and commercial password construction is promoted to be standardized and normalized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptographic security technology, and specifically to a commercial cryptographic cloud supervision management information system and method based on a trusted innovation environment. Background Art

[0002] In the network information age, cryptography is the most important, effective and reliable means to ensure network and information security. The construction of a commercial cryptography cloud supervision platform is an inevitable trend in the development of informatization and the only way to expand digital empowerment to commercial cryptography work across the province.

[0003] "Innovation in information technology" refers to the application and innovation of information technology. As an important measure for my country to develop core information technology, cultivate the industrial ecology, and promote the establishment of Chinese standards, Chinese systems, and Chinese solutions, it is both a historical necessity and a necessary condition for accelerating the progress of "new infrastructure". With the advancement of innovation in information technology, domestic chips, complete machines, operating systems, databases, cryptography, security and other fields have relatively mature products that can be put into use, the industrial ecology is constantly improving, and the application scenarios are constantly enriched.

[0004] The application of Xinchuang and commercial encryption is fundamentally aimed at solving information security problems. At present, there is no unified standard for the construction and management of encryption application work, and it is difficult to conduct unified supervision; security protection is weak, and the deployment of encryption application is not comprehensive; resource use is irregular and inaccurate, and effective supervision is required; risk intelligence sources are scattered, and dynamic correlation analysis is insufficient, and various data resources need to be integrated for overall analysis and processing; for the problems in related technologies, no effective solutions have been proposed yet. Summary of the invention

[0005] The purpose of the present invention is to provide a commercial cryptographic cloud supervision management information system and method based on a trusted innovation environment to solve the problems raised in the prior art.

[0006] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a commercial cryptographic cloud supervision and management information system based on a trust-creating environment, the system comprising: a platform basic support module and a platform business processing module; The basic support modules of the platform include management platform, data platform and technology platform; the management platform is used to establish a unified user authentication system, and restrict the user's access and operation rights by analyzing the user's access device, location and time, and record and store the user's login and operation behavior; the data platform is used to obtain password call data, and the data collection center summarizes the data and uploads it to the data identification center. The data identification center relies on various models in the analysis model library to identify the data, and the identified data is stored or distributed to other modules; the technology platform is used to establish a unified technical support platform, and build a technical support center by using message queues, distributed data processing, large databases, OFD format file template editing, OFD file data extraction and multi-party review technologies and applications; The platform business processing module includes a review system, a supervision system, a notification and warning system, and a situation analysis system; the supervision system is used to uniformly supervise application systems, cryptographic equipment, and cryptographic platforms; the review system is used to configure the platform's unified handling process and conduct process-based supervision of events and physical objects; the notification and warning system is used to perform notification and warning processing after collecting events; and the situation analysis system is used to conduct intelligent analysis and display based on various data on the platform.

[0007] Furthermore, the functions of the management center include unified users, unified authentication, unified authorization, personal signature, audit system and interface management; The unified user is used to establish a unified system and provide a unified identity system for management, use, operation and maintenance personnel and external experts; The unified authentication is used to establish a unified authentication system, and different login authentication methods are divided according to the different permissions of various types of personnel; The unified authentication is used to establish a complete permission system, and users of different types and levels can be quickly assigned permissions after registration. Multi-dimensional risk control analysis methods are used to control user login methods and available permissions in different scenarios, thereby preventing security risks. The personal signature is used to grant all users a trusted personal certificate based on cryptographic technology. During important operations, the user signature is used to record them, ensuring that all actions are traceable and undeniable; The audit system is used to provide the platform with a log audit function, audit all data and operations on the entire platform, and receive logs of cryptographic platforms and devices supervised by the platform, and display and audit them uniformly on the platform. It also supports auditing login logs and operation behavior logs of platform login users; The interface management is used to provide management functions for the platform's own interfaces, and at the same time to perform unified mobile phone management of the cryptographic service interfaces of the cryptographic platforms and devices at all levels under supervision.

[0008] Furthermore, the data center includes a data collection center, a data identification center, an analysis model library, a data subject library, an expert library, a critical review agency library, a solution library, and a critical review report library; The functions of the data collection center include active data acquisition, passive data reception, bypass data monitoring and intelligent reporting and analysis; the data collection center is used to obtain password call data from the password device and the password service platform by means of active acquisition and passive reception, and use the monitoring plug-ins deployed in bypass on the cloud platforms at all levels to regularly monitor and report the password protocols and algorithms in the network communication within the cloud, and analyze the uploaded data or files, extract data and store them in the data table; The functions of the data identification center include log analysis, intelligent reporting analysis, monitoring data analysis and identification rule setting; the data identification center is used to analyze the logs pushed by platforms and devices at all levels, analyze and store the data items defined by the platform, and analyze the files or data in the intelligent reporting module, extract and store the data, analyze the data reported by the plug-in, analyze the data under different network environments and applications, obtain the password-related information contained, and use big data + distributed data processing technology to ensure fast processing and retrieval when massive data is aggregated; The analysis model library includes data analysis models, cryptographic protocol models, data identification models and document models; the analysis model library is used to record the analysis models after various types of data are acquired, the network environment and the models of the performance of cryptographic protocols in the network when using different cryptographic devices and different cryptographic algorithms, so as to help the bypass data monitoring system to quickly analyze the network conditions to which it belongs, and set the data identification methods of the data and logs reported by different platforms and devices, so as to reduce the operation and maintenance work at the code level. At the same time, the establishment of the model facilitates the rapid access of similar products in the later stage, and can customize the specific templates of different documents. The documents made according to the template will be able to be read by the platform for data; The data subject database includes a commercial secret product database, an information project database and a key infrastructure database; the data subject database is used to establish a unified knowledge base for cryptographic products used by various units, record product parameters, usage methods and operation and maintenance methods, record project construction status and security assessment status, and provide the unit with corresponding reminders, suggestions and risk analysis for annual retests and security issues encountered; and is used to record in detail the security construction status of information systems with security protection level 3 and above, provide data support for the monitoring system, and prevent information systems from skipping security facilities; the above-mentioned security protection level 3 refers to the highest level of computer room protection, which is one of the important measures to ensure the security of information systems; The expert database is used to establish a complete commercial cryptography expert database, where experts come from different fields, including but not limited to manufacturers, cryptographic evaluation agencies, government departments, universities, etc.; The said secret evaluation agency database is used to establish a complete secret evaluation agency database, record the time and method of evaluation by different secret evaluation agencies, so as to timely grasp the differences in understanding of commercial encryption policies by different agencies; The solution library is used to establish an information system cryptographic application solution library, and improve the construction method of commercial cryptography by analyzing the information system cryptographic evaluation results; The confidential review report library is used to establish an information system confidential review and evaluation report library, and by analyzing standardized confidential review report files, the confidential review result data is obtained and rectification opinions at all levels are collected.

[0009] Furthermore, the technical middle platform includes an artificial intelligence support center, a secure multi-party computing center, a streaming file conversion center, a data desensitization conversion center, and a message center; The AI ​​support center is used to analyze the data of password operation and password review files, extract effective data and establish a data center; use AI technology to analyze and learn massive amounts of data, and summarize the early warning rules of events in password operation through machine learning, to help various units avoid problems that may arise in password operation in advance; The secure multi-party computing center is used to obtain files that do not involve privacy after desensitizing the relevant documents of each business system, and to review and improve each part of the obtained files, and finally feed back to the original business system; The stream-format file conversion center is used to standardize the cryptographic application solutions and cryptographic evaluation reports, and is used to quickly generate corresponding solution files for newly built systems by filling in standardized information; The data desensitization conversion center is used to desensitize the parts of the scheme and data involving sensitive information; The message center is used to set up and manage all messages on the entire platform, including early warning notifications within the platform and warnings and suggestions issued to units at all levels.

[0010] Furthermore, the review system includes a user center, a matter center, a form center and a handling center; The user center is used to classify users with different roles, thereby providing different business functions; The matter center is used to provide each user with a separate matter processing system, within which most of the matters on the platform can be processed; The form center is used to provide different types of form filling modules, and also provides a file upload method. The platform reads and analyzes the form and automatically completes the form filling work. At the same time, the platform intelligently obtains the required data for approval by filling in the form; The case handling center is used to provide an editable case handling process formulation system, and complete the entire process of proposing, approving and completing different case handling items through customized processes.

[0011] Furthermore, the supervision system includes an intelligent collection center, an application supervision center, a dynamic monitoring center and a joint review center; The intelligent collection center includes program collection and report filing, which is used to collect provincial-level password evaluation programs and results filing, and to collect the use of passwords for e-government and e-certification services; The application supervision center includes application management and interface testing, which is used to supervise the application system. By collecting login logs from the application system, performing https detection on the application system, and judging whether the data of daily calls to the encryption and decryption interface of the password device and the signature verification interface conform to the situation of its password application plan, it determines whether each level of the application system conforms to the password requirements, and promptly reminds non-compliant and abnormal situations, helping supervisors to deal with the units to which the application system belongs according to the violations; The detection content of the dynamic monitoring center includes operation status monitoring and cryptographic service monitoring, which is used to monitor the operation status of the cryptographic platform and equipment, obtain the equipment operation status and the call status of cryptographic services and interfaces in real time, analyze the monitored information, generate corresponding error events in real time, and improve the early warning model through data accumulation, and gradually improve the early warning system through artificial intelligence technology support; The functions of the joint review center include data desensitization and multi-party review, which is used to desensitize data and documents, and can share the desensitized data with expert users for joint review. Under the premise that the data is not released, the opinions of multiple parties can be combined to improve the password construction plan.

[0012] Furthermore, the notification and warning system includes an event center, a handling center, a plan center and a notification center; The event center is used to centrally manage all events on the entire platform. Event levels can be set in the event center and different handling strategies can be configured for events of different levels. The handling center is used to handle the incidents through various means, including but not limited to notifying relevant units, providing emergency plans and timely assigning experts to help resolve the corresponding incidents as soon as possible; The plan center is used to manage all provincial cryptographic platforms and devices in a unified manner. Through the events and processing methods collected during the operation of the platform, the plan for each scenario is continuously enriched to ensure the healthy operation of provincial cryptographic systems. The notification center is used to report events, handling results, confidential review progress, etc., inform relevant units, and synchronize information to relevant departments in a timely manner.

[0013] Furthermore, the situation analysis system includes an intelligent analysis center and a situation visualization display center; The intelligent analysis center is used to combine the data analyzed by the platform to realize multi-dimensional statistical analysis of the password application status and hidden dangers, and analyze and judge the degree of harm; the intelligent analysis center includes an account password verification module, a mouse and keyboard tapping rhythm collection module, a tapping rhythm modeling module, a tapping rhythm difference calculation module, a tapping rhythm recognition module, and an account password and tapping rhythm comprehensive authentication module; the account password verification module is used to verify the account and password entered by the user; the mouse and keyboard tapping rhythm collection module is used to collect the rhythm of the user tapping the mouse and keyboard; the tapping rhythm modeling module is used to model the rhythm of the user tapping the mouse and keyboard; the tapping rhythm difference calculation module is used to calculate the difference between the variance of the rhythm and the reasonable value according to the user's tapping rhythm model; the tapping rhythm recognition module is used to identify the tapping rhythm of the mouse and keyboard when the user logs in again; the account password and tapping rhythm comprehensive authentication module is used to use the account password combined with the mouse and keyboard tapping rhythm to perform comprehensive authentication on the login of the external application device; The situation visualization display center is used to provide situation awareness and comprehensive analysis overview of the provincial cryptographic application security operation status, assist in analysis and decision-making, and implement precise supervision.

[0014] The commercial cryptographic cloud supervision management information method based on the trust creation environment includes the following steps: S1. Build a unified user system, manage different users in different levels, flexibly adjust permissions based on user login and operation risks, and sign important operations; S2. Build a unified data center, which is used to provide a unified data source for all transaction processing systems; S3. Develop a big data processing module to process logs in queues and store them in distributed databases, process specific data in real time and display and report them; S4. Develop technical support for streaming format files, desensitize OFD files, and delete user information and application information in the documents to facilitate joint review by multiple experts and institutions; S5. Conduct intelligent analysis and judgment on password usage through the intelligent analysis center, and report the analysis and judgment results; S6. Develop intelligent situation visualization display surface and provide multi-scenario and multi-specification display system to assist users in analysis and decision-making.

[0015] Further, in step S3: the method for processing the log is to classify and store the processed data according to the parsing standard, and provide the functions of related structure management, data search and data display, support customized data parsing format, and parse the collected data according to the data source; the specific data includes multi-dimensional comprehensive data of the password security status and network security indicators, wherein the multi-dimensional comprehensive data of the password security status includes event ranking, event classification statistics, alarm classification statistics, real-time traffic display and server performance display; network security quantitative indicators include threats, vulnerabilities and target importance; the method for real-time processing of specific data is to use the status and fault monitoring engine to realize real-time monitoring of the operating status information of the cryptographic equipment in the system, filter the performance and faults, and generate performance and fault alarms; the status and fault monitoring engine includes two functional modules, the performance data filtering and statistical analysis module, and the fault analysis module; at the same time, there is an interface relationship between the real-time fault monitoring engine and the cryptographic security information collection software, storage, alarm, and visualization; based on threat, asset, and organizational visualization, the global network topology is drawn and displayed, as well as the multi-dimensional comprehensive monitoring of the cryptographic security status, and the operating status monitoring of cryptographic devices based on the network topology is supported; for the overall security status, the hierarchical method is used to extract network security quantitative indicators from the basic security information. The quantitative indicators include threats, vulnerabilities, and target importance, etc. The overall cryptographic security threat assessment value and the overall security assessment are calculated from the bottom up, and the global security status changes are displayed in real time and continuously with a curve chart; In step S5: the process of analyzing password usage includes account password verification, mouse and keyboard tapping rhythm recognition; modeling and comprehensive authentication of the user's keyboard tapping rhythm and rhythm difference, and judging whether the rhythm of the user entering the account password belongs to the reasonable deviation value range of keyboard tapping in the rhythm model, which is used as the basis for intelligent analysis.

[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. Based on the localized software and hardware environment of xinchuang, we will develop a commercial cryptographic cloud supervision and management information system based on the xinchuang environment for the field of e-government under the dual drive of xinchuang construction and cryptographic construction. By establishing the platform basic support module and platform business processing module, we will realize the centralized management of cryptographic equipment and cryptographic services in the information system, and provide unified cryptographic resource services to the outside world. 2. The infrastructure and cryptographic security products used in the present invention are all domestically produced products, which build a fully trusted operating environment from the bottom-level facilities to the upper-level applications, and realize the unified management, scheduling and monitoring of typical cryptographic hardware equipment and virtual cryptographic computing resources; through the SDF interface of the national secret standard, the call of cryptographic computing resources is realized; the unified management system of commercial cryptographic cloud supervision services integrates the standard key management system, and provides key management, data encryption and decryption, HMAC integrity protection, signature verification, certificate authentication, timestamp and other cryptographic services for the application system through a unified external cryptographic service interface; provides unified cryptographic service application, unified cryptographic service authorization, unified cryptographic service assignment, and unified cryptographic service audit functions for the application system, and the unified management system of commercial cryptographic cloud supervision services supports docking with the superior management system to realize the unified management of cryptographic services by the superior system; 3. The present invention collects the registration information of the result of the password evaluation and the use of the password of the electronic government electronic authentication service, realizes the online collection and notification and early warning of the operation of the password protection system of important networks and information systems; it can connect the provincial commercial password business system, unify the standards and requirements for the construction of the business system, and is conducive to the integration of existing commercial password supervision resources, realize data sharing, analysis and judgment, reduce duplication of construction, and save financial funds; this platform can be widely used in key industries such as finance, transportation, and energy to ensure information security and data security in the Internet era; 4. The present invention forms a complete expert knowledge base, based on the platform's own multiple cryptographic security data information base, to conduct clue expansion analysis on the known and unknown alarm information generated, and automates and localizes the data through traditional manual data expansion mining technology, quickly providing effective technical basis and processing methods for security incidents, customizing the data visualization display center, and displaying all the information on the platform in a carousel, which can better meet the user's usage needs. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 This is a structural block diagram of the commercial cryptographic cloud supervision and management information system based on the trust creation environment of the present invention; Figure 2 A schematic diagram of the service scheduling process of the commercial cryptographic cloud supervision management information method based on the trust innovation environment of the present invention; Figure 3 It is a structural diagram of the intelligent analysis center in the present invention; Numbers in the figure: 1. Platform basic support module; 11. Management center; 111. Unified user; 112. Unified authentication; 113. Unified authentication; 114. Personal signature; 115. Audit system; 116. Interface management; 12. Data center; 121. Data collection center; 1211. Acquisition of data; 1212. Passive reception of data; 1213. Bypass monitoring of data; 1214. Intelligent reporting and analysis; 122. Data identification center; 1221. Log analysis; 1222. Intelligent filling 1223、Monitoring data analysis;1224、Identification rule setting;123、Analysis model library;1231、Data analysis model;1232、Cryptographic protocol model;1233、Data identification model;1234、Document model;124、Data subject library;1241、Commercial secret product library;1242、Informatization project library;1243、Key infrastructure library;1244、Security protection level 3 system library;125、Expert library;126、Security assessment agency library;127、Solution library;128、Security assessment Report library; 13. Technical middle platform; 131. Artificial intelligence support center; 132. Secure multi-party computing center; 133. Streaming file conversion center; 134. Data desensitization conversion center; 135. Message center; 2. Platform business processing module; 21. Review system; 211. User center; 212. Matter center; 213. Form center; 214. Processing center; 22. Supervision system; 221. Intelligent collection center; 2211. Scheme collection; 2212. Report filing; 222. 2221. Application management; 2222. Interface testing; 223. Dynamic monitoring center; 2231. Operation status monitoring; 2232. Cryptographic service monitoring; 224. Joint review center; 2241. Data desensitization; 2242. Multi-party review; 23. Notification and warning system; 231. Event center; 232. Disposal center; 233. Plan center; 234. Notification center; 24. Situation analysis system; 241. Intelligent analysis center; 242. Situation visualization display center. DETAILED DESCRIPTION

[0018] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0019] like Figure 1-Figure 3 As shown, the present invention provides a technical solution, a commercial cryptographic cloud supervision and management information system based on a trust-based innovation environment, the system comprising: a platform basic support module 1 and a platform business processing module 2; The platform basic support module 1 includes a management platform 11, a data platform 12, and a technical platform 13; the management platform 11 is used to establish a unified user authentication system, and restrict the user's access and operation rights by analyzing the user's access device, location and time, and record and store the user's login and operation behavior; the data platform 12 is used to obtain password call data, and the data collection center aggregates the data and uploads it to the data identification center. The data identification center relies on various models in the analysis model library to identify the data, and the identified data is stored or distributed to other modules; the technical platform 13 is used to establish a unified technical support platform, and use the message queue, distributed data processing, large database, OFD format file template editing, OFD file data extraction and multi-party review technology and application methods to build a technical support center; The platform business processing module 2 includes a review system 21, a supervision system 11, a notification and warning system 23 and a situation analysis system 24; the supervision system 21 is used to uniformly supervise application systems, cryptographic equipment, and cryptographic platforms; the review system 22 is used to configure the platform's unified handling process and conduct process-based supervision of events and physical objects; the notification and warning system 23 is used to collect events and perform notification and warning processing; the situation analysis system 24 is used to combine various platform data for intelligent analysis and display.

[0020] The functions of the management platform 11 include unified user 111, unified authentication 112, unified authentication 113, personal signature 114, audit system 115 and interface management 116; The unified user 111 is used to establish a unified system and provide a unified identity system for management, use, operation and maintenance personnel and external experts; The unified authentication 112 is used to establish a unified authentication system, and to divide different login authentication methods according to the different permissions of various types of personnel; The unified authentication 113 is used to establish a complete authority system, and users of different types and levels can quickly be assigned authority after registration. Multi-dimensional risk control analysis methods are used to control user login methods and available authorities in different scenarios, thereby preventing security risks. The personal signature 114 is used to grant all users a trusted personal certificate based on cryptographic technology. During important operations, the user signature is used to record them, ensuring that all actions are traceable and undeniable; The audit system 115 is used to provide the platform with a log audit function, audit all data and operations on the entire platform, and receive logs of the cryptographic platform and equipment supervised by the platform, and display and audit them uniformly on the platform, while supporting the audit of login logs and operation behavior logs of platform login users; The interface management 116 is used to provide management functions for the platform's own interfaces, and to perform unified mobile phone management on the cryptographic service interfaces of the cryptographic platforms and devices at all levels under supervision.

[0021] The data center 12 includes a data collection center 121, a data identification center 122, an analysis model library 123, a data subject library 124, an expert library 125, a critical review agency library 126, a solution library 127 and a critical review report library 128; The functions of the data collection center 121 include active data acquisition 1211, passive data reception 1212, bypass data monitoring 1213 and intelligent reporting analysis 1214; the data collection center 121 is used to obtain password call data from the password device and the password service platform by means of active acquisition and passive reception, and use the monitoring plug-ins deployed in bypass on the cloud platforms at all levels to regularly monitor and report the password protocols and algorithms in the network communication within the cloud, and analyze the uploaded data or files, extract data and store them in the data table; The functions of the data identification center 122 include log analysis 1221, intelligent reporting analysis 1222, monitoring data analysis 1223 and identification rule setting 1224; the data identification center 122 is used to analyze the logs pushed by platforms and devices at all levels, analyze and store the data items defined by the platform, and analyze the files or data in the intelligent reporting module, extract and store the data, analyze the data reported by the plug-in, analyze the data under different network environments and applications, obtain the password-related information contained, and use big data + distributed data processing technology to ensure fast processing and retrieval when massive data is aggregated; The analysis model library 123 includes a data analysis model 1231, a cryptographic protocol model 1232, a data identification model 1233 and a document model 1234; the analysis model library 123 is used to record the analysis model after various types of data are acquired, the network environment and the model of the performance of the cryptographic protocol in the network when using different cryptographic devices and different cryptographic algorithms, so as to help the bypass data monitoring system to quickly analyze the network conditions to which it belongs, and set the data identification method of the data and logs reported by different platforms and devices, so as to reduce the operation and maintenance work at the code level. At the same time, through the establishment of the model, it is convenient to quickly access similar products in the later stage, and specific templates of different documents can be customized. The documents made according to the template will be able to be read by the platform for data; The data subject database 124 includes a commercial secret product database 1241, an information project database 1242 and a key infrastructure database 1243; the data subject database 124 is used to establish a unified knowledge base for cryptographic products used by various units, record product parameters, usage methods and operation and maintenance methods, record project construction status and security assessment status, and provide the unit with corresponding reminders, suggestions and risk analysis for annual retests and security issues encountered; and is used to record in detail the security construction status of information systems with security protection level 3 and above, provide data support for the monitoring system, and prevent information systems from skipping security facilities; the above-mentioned security protection level 3 refers to the highest level of computer room level protection, which is one of the important measures to ensure the security of information systems; The expert database 125 is used to establish a complete commercial cryptography expert database, where experts come from different fields, including but not limited to manufacturers, cryptographic evaluation agencies, government departments, universities, etc.; The cryptographic evaluation agency database 126 is used to establish a complete cryptographic evaluation agency database, and record the time and method of evaluation by different cryptographic evaluation agencies, so as to timely grasp the differences in understanding of commercial encryption policies by different agencies; The solution library 127 is used to establish an information system cryptographic application solution library, and improve the construction method of commercial cryptography by analyzing the information system cryptographic evaluation results; The confidential review report library 128 is used to establish an information system confidential review and evaluation report library, and obtain confidential review result data and collect rectification opinions at all levels by analyzing standardized confidential review report files.

[0022] The technical platform 13 includes an artificial intelligence support center 131, a secure multi-party computing center 132, a streaming file conversion center 133, a data desensitization conversion center 134 and a message center 135; The artificial intelligence support center 131 is used to analyze the data of password operation and password review files, extract effective data to establish a data center; use artificial intelligence technology to analyze and learn massive amounts of data, and summarize the early warning rules of events in password operation through machine learning, so as to help various units avoid possible problems in password operation in advance; The secure multi-party computing center 132 is used to obtain files that do not involve privacy after desensitizing the relevant documents of each business system, and to review and improve each part of the obtained files, and finally feed back to the original business system; The stream format file conversion center 133 is used to standardize the cryptographic application solutions and cryptographic evaluation reports, and is used to quickly generate corresponding solution files by filling in standardized information for newly built systems; The data desensitization conversion center 134 is used to desensitize the parts of the scheme and data involving sensitive information; The message center 135 is used to set up and manage all messages on the entire platform, including early warning notifications within the platform and warnings and suggestions issued to units at all levels.

[0023] The review system 21 includes a user center 211, an event center 212, a form center 213 and a document processing center 214; The user center 211 is used to classify users with different roles, thereby providing different business functions; The event center 212 is used to provide each user with a separate event processing system, in which most of the event processing of the platform can be completed; The form center 213 is used to provide different types of form filling modules and a file upload method. The platform reads and analyzes the form and automatically completes the form filling work. At the same time, the platform intelligently obtains the required data for approval by filling in the form; The case handling center 214 is used to provide an editable case handling process formulation system, and complete the entire process of proposing, approving and completing different case handling items through customized processes.

[0024] The supervision system 22 includes an intelligent collection center 221, an application supervision center 222, a dynamic monitoring center 223 and a joint review center 224; The intelligent collection center 221 includes a plan collection 2211 and a report filing 2212, which are used to collect provincial-level secret evaluation plans and result filings, and to collect the use of e-government and e-certification service passwords; The application supervision center 222 includes application management 2221 and interface testing 2222, which are used to supervise the application system. By collecting login logs from the application system, performing https detection on the application system, and judging whether the data of daily calls to the encryption and decryption interface of the password device and the signature verification interface conform to the situation of its password application plan, it determines whether each level of the application system conforms to the password requirements, and promptly reminds non-compliant and abnormal situations, helping supervisors to deal with the units to which the application system belongs according to the violations; The detection content of the dynamic monitoring center 223 includes operation status monitoring 2231 and cryptographic service monitoring 2232, which is used to monitor the operation status of the cryptographic platform and equipment, obtain the equipment operation status and the call status of the cryptographic service and interface in real time, analyze the monitored information, generate corresponding error events in real time, and improve the early warning model through data accumulation, and gradually improve the early warning system through artificial intelligence technology support; The functions of the joint review center 224 include data desensitization 2241 and multi-party review 2242, which are used to desensitize data and documents, and can share the desensitized data with expert users for joint review. Under the premise that the data is not released, the opinions of multiple parties are combined to improve the password construction plan.

[0025] The notification and warning system 23 includes an event center 231, a handling center 232, a plan center 233 and a notification center 234; The event center 231 is used to uniformly manage all events on the entire platform. Event levels can be set in the event center and different handling strategies can be configured for events of different levels; The handling center 232 is used to handle the incident through various means, including but not limited to notifying relevant units, providing emergency plans and timely assigning experts to help solve the corresponding incident in the first place; The plan center 233 is used to manage all provincial cryptographic platforms and devices in a unified manner, and continuously enrich the plans for each scenario through the events and processing methods collected during the operation of the platform, so as to safeguard the healthy operation of provincial cryptographic systems; The notification center 234 is used to report events, handling results, confidential review progress, etc., inform relevant units, and synchronize information to relevant departments in a timely manner.

[0026] The situation analysis system 24 includes an intelligent analysis center 241 and a situation visualization display center 242; The intelligent analysis center 241 is used to combine the data analyzed by the platform to realize multi-dimensional statistical analysis of the password application status and hidden dangers, and analyze and judge the degree of harm; the intelligent analysis center includes an account password verification module, a mouse and keyboard tapping rhythm collection module, a tapping rhythm modeling module, a tapping rhythm difference calculation module, a tapping rhythm recognition module, and an account password and tapping rhythm comprehensive authentication module; the account password verification module is used to verify the account and password entered by the user; the mouse and keyboard tapping rhythm collection module is used to collect the rhythm of the user tapping the mouse and keyboard; the tapping rhythm modeling module is used to model the rhythm of the user tapping the mouse and keyboard; the tapping rhythm difference calculation module is used to calculate the difference between the variance of the rhythm and the reasonable value according to the user's tapping rhythm model; the tapping rhythm recognition module is used to identify the tapping rhythm of the mouse and keyboard when the user logs in again; the account password and tapping rhythm comprehensive authentication module is used to use the account password combined with the mouse and keyboard tapping rhythm to perform comprehensive authentication on the login of the external application device; The situation visualization display center 242 is used to provide situation awareness and comprehensive analysis overview of the provincial cryptographic application security operation status, assist in analysis and decision-making, and implement precise supervision.

[0027] The commercial cryptographic cloud supervision management information method based on the trust creation environment includes the following steps: S1. Build a unified user system, manage different users in different levels, flexibly adjust permissions based on user login and operation risks, and sign important operations; S2. Build a unified data center, which is used to provide a unified data source for all transaction processing systems; S3. Develop a big data processing module to process logs in queues and store them in distributed databases, process specific data in real time and display and report them; S4. Develop technical support for streaming format files, desensitize OFD files, and delete user information and application information in the documents to facilitate joint review by multiple experts and institutions; S5. Conduct intelligent analysis and judgment on password usage through the intelligent analysis center, and report the analysis and judgment results; S6. Develop intelligent situation visualization display surface and provide multi-scenario and multi-specification display system to assist users in analysis and decision-making.

[0028] In step S3: the method for processing the log is to classify and store the processed data according to the parsing standard, and provide the functions of related structure management, data search and data display, support customized data parsing format, and parse the collected data according to the data source; the specific data includes multi-dimensional comprehensive data of the password security status and network security indicators, wherein the multi-dimensional comprehensive data of the password security status includes event ranking, event classification statistics, alarm classification statistics, real-time traffic display and server performance display; network security quantitative indicators include threats, vulnerabilities and target importance; the method for real-time processing of specific data is to use the status and fault monitoring engine to realize real-time monitoring of the operating status information of the cryptographic equipment in the system, filter the performance and faults, and generate performance and fault information. Fault alarm; the status and fault monitoring engine includes two functional modules, performance data filtering and statistical analysis module, and fault analysis module; at the same time, there is an interface relationship between the real-time fault monitoring engine and the password security information collection software, storage, alarm, and visualization; based on threat, asset, and organizational visualization, the global network topology is drawn and displayed, as well as the multi-dimensional comprehensive monitoring of the password security status, and the operation status monitoring of the password equipment based on the network topology is supported; for the overall security status, the hierarchical method is used to extract network security quantitative indicators from the basic security information. The quantitative indicators include threats, vulnerabilities, and target importance, etc. The overall password security threat assessment value and the overall security assessment are calculated from the bottom up, and the global security status changes are displayed in real time and continuously with a curve chart; In step S5: the process of analyzing password usage includes account password verification, mouse and keyboard tapping rhythm recognition; modeling and comprehensive authentication of the user's keyboard tapping rhythm and rhythm difference, and judging whether the rhythm of the user entering the account password belongs to the reasonable deviation value range of keyboard tapping in the rhythm model, which is used as the basis for intelligent analysis.

[0029] The present invention aims at building a commercial cryptographic cloud supervision and management service system in the field of e-government through domestic products. The underlying facilities adopt domestic servers, storage and other trust-innovation products. The cryptographic resource pool is built with domestic software and hardware cryptographic products such as cryptographic servers, signature verification servers, and identity authentication systems. All cryptographic products support national secret algorithms, and support multiple national secret algorithms such as SM1, SM2, SM3, SM4, SM7, and SM9 to support the needs of different users and different business systems. With the help of the above-mentioned technical scheme of the present invention, by dual-driven trust-innovation construction and cryptographic construction based on the trust-innovation domestic software and hardware environment, a commercial cryptographic cloud supervision and management information system and method based on the trust-innovation environment are studied for the field of e-government. The present invention builds a commercial cryptographic cloud supervision and management service platform for the field of e-government on the trust-innovation environment, relies on the security facilities of the government external network trust-innovation cloud, adopts commercial cryptographic technology, products and services to encrypt and protect important and core data transmitted and stored in the system, conducts security authentication of user identities, and affixes electronic signatures to business documents to enhance the security protection capabilities of the cloud platform. This system can be widely used in key industries such as finance, transportation, and energy to ensure information security and data security in the network era.

[0030] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A commercial cryptographic cloud supervision and management information system based on a trusted innovation environment, characterized by: The system includes: Platform basic support module (1) and platform business processing module (2); The platform basic support module (1) includes a management platform (11), a data platform (12) and a technical platform (13); the management platform (11) is used to establish a unified user authentication system, and restrict the user's access and operation rights by analyzing the user's access device, location and time, and record and store the user's login and operation behavior; the data platform (12) is used to obtain password call data, and the data collection center summarizes the data and uploads it to the data identification center. The data identification center relies on the model in the analysis model library to identify the data, and the identified data is stored or distributed to other modules; the technical platform (13) is used to establish a unified technical support platform, and use the message queue, distributed data processing, large database, OFD format file template editing and OFD file data extraction technology and application methods to build a technical support center; The platform business processing module (2) includes a review system (21), a supervision system (22), a notification and warning system (23) and a situation analysis system (24); the supervision system (21) is used to uniformly supervise the application system, cryptographic equipment and cryptographic platform; the review system (22) is used to configure the platform's unified case handling process and conduct process-based supervision of events and physical objects; the notification and warning system (23) is used to collect events and perform notification and warning processing; the situation analysis system (24) is used to combine various platform data for intelligent analysis and display.

2. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized by: The functions of the management platform (11) include unified users (111), unified authentication (112), unified authorization (113), personal signature (114), audit system (115) and interface management (116); The unified user (111) is used to establish a unified system to provide a unified identity system for management, use, operation and maintenance personnel and external experts; The unified authentication (112) is used to establish a unified authentication system, and to divide different login authentication methods according to the different permissions of various types of personnel; The unified authentication (113) is used to establish a complete authority system, allocate authority to users of different types and levels after registration, and control the user login method and available authority in different scenarios; The personal signature (114) is used to grant all users a trusted personal certificate based on cryptographic technology, and to record important operations using the user's signature; The audit system (115) is used to provide a log audit function for the platform, audit all data and operations on the entire platform, and receive logs of the password platform and equipment supervised by the platform, and display and audit them uniformly on the platform, while supporting the audit of login logs and operation behavior logs of platform login users; The interface management (116) is used to provide management functions for the platform's own interfaces, and to perform unified mobile phone management on the cryptographic service interfaces of the cryptographic platforms and devices at all levels under supervision.

3. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized in that: The data center (12) includes a data collection center (121), a data identification center (122), an analysis model library (123), a data subject library (124), an expert library (125), a critical evaluation agency library (126), a solution library (127) and a critical evaluation report library (128); The functions of the data collection center (121) include active data acquisition (1211), passive data reception (1212), bypass data monitoring (1213) and intelligent reporting and analysis (1214); the data collection center (121) is used to obtain password call data from the password device and the password service platform by means of active acquisition and passive reception, and to use the monitoring plug-ins deployed in bypass on the cloud platforms at all levels to regularly monitor and report the password protocols and algorithms in the network communication within the cloud, and to analyze the uploaded data or files, extract data and store them in the data table; The functions of the data identification center (122) include log analysis (1221), intelligent reporting analysis (1222), monitoring data analysis (1223) and identification rule setting (1224); the data identification center (122) is used to analyze the logs pushed by platforms and devices at all levels, analyze and store the data items defined by the platform, and analyze the files or data in the intelligent reporting module, extract and store the data, analyze the data reported by the plug-in, and analyze the data under different network environments and applications to obtain the password information contained therein; The analysis model library (123) includes a data analysis model (1231), a cryptographic protocol model (1232), a data identification model (1233) and a document model (1234); the analysis model library (123) is used to record the analysis model after various types of data are acquired, the network environment and the model of the performance of the cryptographic protocol in the network when using different cryptographic devices and different cryptographic algorithms, to help the bypass data monitoring system analyze the network conditions, and to set the data identification method of the data and logs reported by different platforms and devices. At the same time, the establishment of the model facilitates the access of similar products in the later stage, and customizes the specific templates of different documents. The documents made according to the template will be able to be read by the platform; The data subject database (124) includes a commercial secret product database (1241), an information project database (1242) and a key infrastructure database (1243); the data subject database (124) is used to establish a unified knowledge base for cryptographic products used by various units, record product parameters, usage methods and operation and maintenance methods, record project construction status and security assessment status, and provide reminders, suggestions and risk analysis for annual retests and security issues encountered; and is used to record the security construction status of information systems of security protection level 3 and above; The expert database (125) is used to establish a commercial cryptography expert database; The cryptographic evaluation agency database (126) is used to establish a complete cryptographic evaluation agency database, record the time and method of evaluation by different cryptographic evaluation agencies, and thus grasp the differences in understanding of commercial encryption policies by different agencies; The solution library (127) is used to establish an information system cryptographic application solution library, and improve the construction method of commercial cryptography by analyzing the information system cryptographic evaluation results; The confidential review report library (128) is used to establish an information system confidential review and evaluation report library, and to obtain confidential review result data and collect rectification opinions at all levels by analyzing standardized confidential review report files.

4. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized in that: The (13) platforms in the technology include an artificial intelligence support center (131), a secure multi-party computing center (132), a streaming file conversion center (133), a data desensitization conversion center (134) and a message center (135); The artificial intelligence support center (131) is used to analyze the cryptographic operation and cryptographic review file data and establish a data center; use artificial intelligence technology to analyze and learn the data, and summarize the early warning rules of events occurring in the cryptographic operation through machine learning; The secure multi-party computing center (132) is used to obtain files that do not involve privacy after desensitizing the documents of each business system, and to review and improve the obtained files, and finally feed back to the original business system; The stream format file conversion center (133) is used to standardize and organize cryptographic application solutions and cryptographic evaluation reports; The data desensitization conversion center (134) is used to perform desensitization processing on the part involving sensitive information in the scheme and data; The message center (135) is used to set up and manage all messages on the entire platform, including early warning notifications within the platform and warnings and suggestions issued to units at all levels.

5. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized in that: The review system (21) includes a user center (211), a matter center (212), a form center (213) and a case handling center (214); The user center (211) is used to classify different users, thereby providing different business functions; The matter center (212) is used to provide a separate matter processing system for each user; The form center (213) is used to provide different types of form filling modules and a file upload method, and the platform reads and analyzes the form to automatically complete the form filling work. At the same time, the platform intelligently obtains the required data for approval through the form filling; The case handling center (214) is used to provide an editable case handling process formulation system, and complete the entire process of submitting, approving and completing different case handling items through customized processes.

6. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized in that: The supervision system (22) includes an intelligent collection center (221), an application supervision center (222), a dynamic monitoring center (223) and a joint review center (224); The intelligent collection center (221) includes a plan collection (2211) and a report filing (2212), which is used to collect provincial-level password evaluation plans and result filings, and to collect the use of passwords for e-government and e-certification services; The application supervision center (222) includes application management (2221) and interface testing (2222), which are used to supervise the application system, and to determine whether each level of the application system complies with the password requirements by collecting login logs from the application system, performing https detection on the application system, and judging whether the data of daily calls to the password device encryption and decryption interface and the signature verification interface comply with the password application plan, and to remind the non-compliant and abnormal situations; The monitoring contents of the dynamic monitoring center (223) include operation status monitoring (2231) and cryptographic service monitoring (2232), which are used to monitor the operation status of cryptographic platforms and devices, obtain the operation status of devices and the calling status of cryptographic services and interfaces in real time, analyze the monitored information, generate error events in real time, and improve the early warning model through data accumulation, and improve the early warning system through artificial intelligence technology support; The functions of the joint review center (224) include data desensitization (2241) and multi-party review (2242), which are used to desensitize data and documents, and share the desensitized data with expert users for joint review, thereby improving the password construction plan.

7. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized by: The notification and warning system (23) includes an event center (231), a handling center (232), a plan center (233) and a notification center (234); The event center (231) is used to uniformly manage all events on the entire platform. The event level can be set in the event center and different handling strategies can be configured for events of different levels; The handling center (232) is used to handle the incident, and the handling methods include but are not limited to notifying relevant units, providing emergency plans and assigning experts; The emergency plan center (233) is used to manage all provincial cryptographic platforms and devices in a unified manner, and to enrich emergency plans for various scenarios using events and processing methods collected during platform operation; The notification center (234) is used to notify events, handling results, and confidential review progress.

8. The commercial cryptographic cloud supervision and management information system based on the trust creation environment according to claim 1 is characterized by: The situation analysis system (24) comprises an intelligent analysis center (241) and a situation visualization display center (242); The intelligent analysis center (241) is used to combine the data analyzed by the platform to realize multi-dimensional statistical analysis of the password application status and hidden dangers, and analyze and judge the degree of harm; the intelligent analysis center includes an account password verification module, a mouse and keyboard tapping rhythm collection module, a tapping rhythm modeling module, a tapping rhythm difference calculation module, a tapping rhythm recognition module, and an account password and tapping rhythm comprehensive authentication module; the account password verification module is used to verify the account and password input by the user; the mouse and keyboard tapping rhythm collection module is used to collect the rhythm of the user tapping the mouse and keyboard; the tapping rhythm modeling module is used to model the rhythm of the user tapping the mouse and keyboard; the tapping rhythm difference calculation module is used to calculate the difference between the variance of the rhythm and the reasonable value according to the user's tapping rhythm model; the tapping rhythm recognition module is used to recognize the tapping rhythm of the mouse and keyboard when the user logs in again; the account password and tapping rhythm comprehensive authentication module is used to use the account password combined with the mouse and keyboard tapping rhythm to perform comprehensive authentication on the login of the external application device; The situation visualization display center (242) is used to provide situation awareness and comprehensive analysis overview of the provincial cryptographic application security operation status.

9. A commercial cryptographic cloud supervision and management information method based on a trusted innovation environment, characterized by: The following steps are involved: S1. Build a unified user system, manage different users in different levels, flexibly adjust permissions based on user login and operation risks, and sign important operations; S2. Build a unified data center, which is used to provide a unified data source for all transaction processing systems; S3. Develop a big data processing module to process logs in queues and store them in distributed databases, process specific data in real time and display and report them; S4. Develop technical support for streaming format files, desensitize OFD files, and delete user information and application information in the documents; S5. Conduct intelligent analysis and judgment on password usage through the intelligent analysis center, and report the analysis and judgment results; S6. Develop intelligent situation visualization display and provide a display system to assist users in analysis and decision-making.

10. The commercial cryptographic cloud supervision management information method based on the trust creation environment according to claim 9 is characterized in that: In step S3: the log processing method is to classify and store the processed data according to the parsing standard, and provide related structure management, data search and data display functions, support customized data parsing format, and parse the collected data according to the data source; The specific data includes multi-dimensional comprehensive data of the password security status and network security indicators; wherein the multi-dimensional comprehensive data of the password security status includes event ranking, event classification statistics, alarm classification statistics, real-time traffic display and server performance display; network security quantitative indicators include threats, vulnerabilities and target importance; the method for real-time processing of specific data is to use the status and fault monitoring engine to realize real-time monitoring of the operating status information of the password equipment in the system, filter the performance and faults, and generate performance and fault alarms; In step S5: the process of analyzing password usage includes account password verification, mouse and keyboard tapping rhythm recognition; modeling and comprehensive authentication of the user's keyboard tapping rhythm and rhythm difference, and judging whether the rhythm of the user entering the account password belongs to the reasonable deviation value range of keyboard tapping in the rhythm model, which is used as the basis for intelligent analysis.

Citation Information

Patent Citations

  • E-government domestic cloud password service platform based on credential environment

    CN115102786A

  • Commercial password application supervision platform

    CN117592072A

  • Password operation security management system, method and equipment and storage medium

    CN118869319A

Cited By

  • Multi-module fusion development base design method and system based on credential management and service

    CN120723213A