Self-adaptive key life cycle management method and system based on dynamic data

By dynamically calculating key indicators in data and user information, adjusting key generation, transmission and life cycle, the shortcomings of the existing technology inability to effectively deal with data and key security problems in complex network environments, and realize the adaptability and high security of key management.

CN119945673AActive Publication Date: 2025-05-06BEIJING ZHONGYU YONGXIN NETWORK TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510072700.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06
Estimated Expiration
2045-01-17

AI Technical Summary

Technical Problem

The prior art is difficult to effectively deal with data traffic changes, attack threats and key leakage risks in complex and dynamic network environments. It is impossible to dynamically set keys based on stored data status, and the key transmission method is fixed. It is impossible to dynamically adjust the key life cycle according to user login status and data access status.

Method used

By obtaining data storage information, accessing user information and key transmission data, calculating data sensitivity coefficients, data format risk coefficients and key transmission risk indexes, and dynamically adjusting key generation, transmission and life cycles to deal with changes in the network environment and potential threats.

Benefits of technology

It realizes the adaptability and security of key management, and can dynamically adjust key policies based on complex and changing network environments and business scenarios, prevent illegal acquisition and network attacks, and ensure the full security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945673A_ABST
    Figure CN119945673A_ABST
Patent Text Reader

Abstract

The invention discloses an adaptive key life cycle management method and system based on dynamic data, and relates to the technical field of data security, and the method comprises the steps: obtaining data storage information, classifying the stored data according to the data storage information, obtaining data classification information, and obtaining a data sensitivity coefficient based on the data classification information. According to the method, the secret key generation efficiency is improved through data classification information, the traditional single secret key mode is changed through the data confidentiality demand index and accurate matching secret key strength, excessive or insufficient encryption is avoided, a secret key fragment transmission strategy is flexibly determined in combination with abnormal user login and target data confidentiality demands, illegal acquisition is prevented, and the user security is improved. The key is interrupted, adjusted or regenerated in time through the key transmission risk index, so that network attacks are effectively handled, the safety of the whole transmission process is ensured, the adaptability and safety of key management are greatly improved, and the key management method conforms to the requirements of complex and changeable network environments and various service scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a method and system for adaptive key lifecycle management based on dynamic data. Background Art

[0002] With the rapid development of information technology, data informatization has become the mainstream of current social development. Along with it, information security issues have become more prominent, which has also aroused people's attention to information security. Digital security has hindered the rapid development of informatization. At present, cryptographic technology is recognized as an effective solution to information security issues. At present, mobile smart terminals have become essential equipment for people's daily life and work. Terminals involve various information data of users and have become the main source of data security issues. By applying cryptographic technology and cryptographic products to smart terminals, terminal services and user data security will be better protected. Key security management is the basic support for the application of cryptographic technology and the security foundation for cryptographic algorithms. If the key is leaked, it will pose a fatal threat to the entire information system. Therefore, how to manage the key securely is the focus of relevant technical personnel, and the life cycle of the key is a crucial step. The life cycle of the key directly affects the confidentiality of the key.

[0003] At present, the life cycle management of adaptive keys still relies on static rules such as preset key expiration time and fixed update cycle. Although these methods are simple and easy to use, they are often unable to effectively cope with changes in data traffic, threats of attacks, and risks of key leakage in complex and dynamic network environments. They are unable to set keys specifically according to the status of stored data. When transmitting keys, they often only select key transmission methods according to a fixed degree. They are unable to dynamically adjust according to the login status of the accessing user, and are unable to dynamically adjust the key life cycle according to the data access status. Summary of the invention

[0004] In order to solve the above technical problems, an adaptive key lifecycle management method and system based on dynamic data are provided. The technical solution solves the problems proposed in the above background technology that rely on static rules such as preset key expiration time, fixed update cycle, etc. Although these methods are simple and easy to use, they are often unable to effectively respond to changes in data traffic, threats of attacks, and risks of key leakage in complex and dynamic network environments. They are unable to set keys specifically according to the status of stored data. When transmitting keys, they often only select key transmission methods according to fixed procedures. They are unable to dynamically adjust according to the login status of the accessing user, and are unable to dynamically adjust the key lifecycle according to the data access status.

[0005] In order to achieve the above purpose, the technical solution adopted by the present invention is:

[0006] An adaptive key lifecycle management method based on dynamic data, comprising:

[0007] Acquire data storage information, wherein the data storage information includes data attribute information and data format information;

[0008] Classify the stored data according to the data storage information and obtain data classification information;

[0009] Based on the data classification information, a data sensitivity coefficient is obtained, where the data sensitivity coefficient indicates the impact degree of data leakage;

[0010] According to the data format information and based on data risk analysis, different data format risk coefficients are set for different data formats;

[0011] Obtain the data confidentiality requirement index based on the data sensitivity coefficient and data format risk coefficient;

[0012] According to the data confidentiality requirement index and based on the key strength setting, obtaining key generation information, wherein the key generation information includes key length information and key encryption algorithm information;

[0013] Obtaining access user information, wherein the access user information includes access user account information and access user login information;

[0014] According to the access user information, obtain the access user login abnormality index;

[0015] Obtain target access data information of accessing users;

[0016] Obtain key transmission information based on the access user login anomaly index, target access data information and key generation information;

[0017] Acquire key transmission data, wherein the key transmission data includes transmission status data and network attack data during transmission;

[0018] According to the key transmission data, a key transmission risk index is obtained;

[0019] Based on the key transmission risk index, determine whether to interrupt key transmission. If so, destroy the key and regenerate the key. If not, adjust the key life cycle according to the key transmission risk index.

[0020] Preferably, classifying the stored data according to the data storage information and obtaining the data classification information specifically includes:

[0021] According to the data storage information and based on data traceability, the data is divided into public data and non-public data, where the public data refers to data that can be obtained through any public channel;

[0022] Based on the non-public data, obtain the non-public data timestamp information;

[0023] According to the timestamp information of the non-public data, the non-public data is arranged in order from the most recent to the most recent time, and the order information of the non-public data is obtained;

[0024] Acquire data interval information according to the non-public data sequence information, wherein the data interval information indicates the time interval between adjacent non-public data in the non-public data sequence;

[0025] Taking the maximum value in the data interval information as the first data interval, and taking the minimum value in the data interval information as the second data interval;

[0026] Acquire data time window information according to the first data interval and the second data interval;

[0027] Two adjacent non-public data in the first data interval are used as first non-public data and second non-public data;

[0028] using two adjacent non-public data in the second data interval as third non-public data and fourth non-public data;

[0029] Acquire time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data;

[0030] Among them, if The third non-public data is used as the initial data of the time window. The fourth non-public data is used as the initial data of the time window;

[0031] Based on the initial data of the time window, the non-public data is divided into data sets of several time periods based on the data time window, and data classification information is obtained;

[0032] The data time window is specifically:

[0033]

[0034] Where T is the data time window, t max is the first data interval, t min is the second data time interval.

[0035] Preferably, obtaining the data sensitivity coefficient based on the data classification information specifically includes:

[0036] Obtain non-public data sets based on data classification information;

[0037] Using data attribute information in the data storage information as a data topology criterion to obtain data topology criterion information, wherein the data topology criterion includes personal data, commercial data, industrial data, and medical data;

[0038] Based on the data topology criterion, a data topology relationship diagram is established for the non-public data in each non-public data set;

[0039] According to the data topology diagram, obtain the data sensitivity coefficient of each non-public data;

[0040] The calculation formula of the data sensitivity coefficient is:

[0041]

[0042] Where Q(x) is the data sensitivity coefficient of the xth non-public data, ω i (x) represents the total number of non-public data topologically adjacent to the x-th non-public data under the i-th data topology criterion, τ(i, x) represents the total number of non-public data connected to the topological relationship to which the x-th non-public data belongs under the i-th data topology criterion, A(x) represents the total number of data in the non-public data set to which the x-th non-public data belongs, and n is the total number of data topology criterion types.

[0043] Preferably, the step of obtaining key generation information based on the data confidentiality requirement index and key strength setting specifically includes:

[0044] According to the data format information, obtain the data format type information;

[0045] Based on data risk analysis, data formats are divided into three types: structured data format, semi-structured data format and unstructured data format, and data format classification information is obtained;

[0046] According to the data format classification information, different weights are set for different classified data formats;

[0047] Based on the set weight, obtain the data format risk coefficient corresponding to each data format;

[0048] According to the data sensitivity coefficient and data format risk coefficient, obtain the data confidentiality requirement index of each data;

[0049] Among them, the data sensitivity coefficient of public data is 1;

[0050] According to the data confidentiality requirement index, obtain the maximum value and the average value of the data confidentiality requirement index;

[0051] The ratio of the mean and maximum values ​​of the data confidentiality requirement index is used as the key strength coefficient;

[0052] Based on key generation analysis, obtain the maximum key strength and the corresponding key life cycle;

[0053] The product of the maximum value of the key strength and the key strength coefficient is used as the generated key strength, and the product of the key life cycle and the key strength coefficient is used as the generated key life cycle to obtain key generation information;

[0054] The data confidentiality requirement index is specifically:

[0055]

[0056] Where E(y) represents the data confidentiality requirement index of the y-th data, Q(y) represents the data sensitivity coefficient of the y-th data, K(y) represents the data format risk coefficient of the y-th data, α(y) represents the data format weight of the y-th data, σ(y) represents the total number of data format types of the data format classification to which the data format of the y-th data belongs, and α s represents the data format weight of the sth data format category, σ s Represents the total number of data format types of the sth data format category, where, if s=1, it represents a structured data format, α1=7; if s=2, it represents a semi-structured data format, α2=3; if s=2, it represents an unstructured data format, α3=2.

[0057] Preferably, the step of obtaining the key transmission information according to the access user login anomaly index, access target data information and key generation information specifically includes:

[0058] Get the historical login information of the accessing user;

[0059] Obtain the user's regular login time period based on the user login time in the historical login information of the accessed user;

[0060] Obtain the access user login anomaly index based on the access user information, the access user's historical login information and the user's regular login time period;

[0061] According to the access target data information of the accessing user, a data confidentiality requirement index of the target access data is obtained;

[0062] According to the access user login anomaly index and the data confidentiality requirement index of the target access data, the number of key transmission shards is obtained;

[0063] Get the key strength coefficient;

[0064] The product of the number of key transmission shards and the key strength coefficient is used as the number of key reconstruction shards;

[0065] Based on the number of key transmission shards and the number of key reconstruction shards, the generated key is transmitted in key shards to obtain key transmission information;

[0066] The calculation formula of the access user login abnormality index is:

[0067]

[0068] Where R is the login anomaly index of the access user, ε is the number of account logins per unit time of the access user, δ(t0) represents the user access time anomaly function, where if the user login time t0 belongs to the user's regular login time period, then δ(t0) = 1, if the user login time t0 does not belong to the user's regular login time period, then δ(t0) = |t1-t0|, t1 represents the user's regular login time period node closest to the user login time t0, θ is the unit time, and θ = 0.25h;

[0069] The number of key transmission fragments is specifically:

[0070]

[0071] Where D is the number of key transmission shards, E(j) represents the data confidentiality requirement index of the j-th target access data, E(y) represents the data confidentiality requirement index of the y-th data, m is the total number of target access data, and g is the total number of stored data.

[0072] Preferably, judging whether to interrupt key transmission based on the key transmission risk index specifically includes:

[0073] Acquire normal status data, wherein the normal status data includes normal working data of the CPU and normal working data of the memory;

[0074] Obtain non-public data sets based on data classification information;

[0075] Based on the non-public data set, obtain the distribution status of the target access data in the non-public data set;

[0076] The non-public dataset to which the target access data belongs is used as the feature dataset;

[0077] Obtain access data sensitivity coefficients based on target access data and feature data sets;

[0078] Obtain the key transmission risk index based on the key transmission data, normal status data and access data sensitivity coefficient;

[0079] According to the key transmission risk index, determine whether to interrupt key transmission. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient and regenerate the key. If not, update the key life cycle according to the key transmission risk index.

[0080] If the key transmission risk index G≥1.13, the key transmission is interrupted. If the key transmission risk index G<0.56, the key life cycle is adjusted to f=f0(1+G). If the key transmission risk index 0.56≤G<1.13, the key life cycle is adjusted to Among them, f is the key life cycle, f0 is the generated key life cycle;

[0081] The calculation formula of the key transmission risk index is:

[0082]

[0083] Where G is the key transmission risk index, μ z represents the zth transmission status data, μ0 represents the normal value of the zth transmission status data, d c represents the total number of target access data in the cth feature data set, A c represents the total number of data in the cth feature data set, m is the total number of target access data, M represents the feature data set, max(·) represents the maximum value, and w represents the total number of transmission status data types.

[0084] Furthermore, an adaptive key lifecycle management system based on dynamic data is proposed to implement the above management method, including:

[0085] A main control module, the main control module is used to obtain non-public data sequence information according to non-public data timestamp information, obtain data time window information according to a first data interval and a second data interval, obtain time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, establish a data topology relationship diagram for the non-public data in each non-public data set based on the data topology criterion, use the product of the maximum value of the key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key shard transmission on the generated key based on the number of key transmission shards and the number of key reconstruction shards, obtain key transmission information, determine whether to interrupt key transmission according to the key transmission risk index, if so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient, and regenerate the key, if not, update the key life cycle according to the key transmission risk index;

[0086] An information acquisition module, the information acquisition module is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, acquire non-public data timestamp information based on non-public data, acquire target access data information of access users, key transmission data, transmission status data and network attack data during transmission, and acquire data format type information based on data format information;

[0087] An evaluation module, the evaluation module is used to obtain the data sensitivity coefficient of each non-public data according to the data topology relationship diagram, obtain the data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient, obtain the access user login anomaly index according to the access user information, the access user's historical login information and the user's regular login time period, obtain the access data sensitivity coefficient according to the target access data and the feature data set, and obtain the key transmission risk index according to the key transmission data, the regular status data and the access data sensitivity coefficient;

[0088] The display module interacts with the main control module and is used to output and display data classification information, data confidentiality requirement index, key generation information, key transmission information and key transmission risk index.

[0089] Optionally, the main control module specifically includes:

[0090] A control unit, the control unit is used to use the product of the maximum value of the key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key fragment transmission on the generated key based on the number of key transmission fragments and the number of key reconstruction fragments, obtain key transmission information, and determine whether to interrupt the key transmission according to the key transmission risk index. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient to regenerate the key. If not, update the key life cycle according to the key transmission risk index;

[0091] An information receiving unit, which interacts with the information acquisition module and the evaluation module to receive data and transmit it to the data processing unit;

[0092] A data processing unit, the data processing unit is used to obtain non-public data order information based on non-public data timestamp information, obtain data time window information based on a first data interval and a second data interval, obtain time window initial data based on the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, and establish a data topology relationship diagram for the non-public data in each non-public data set based on a data topology criterion.

[0093] Optionally, the information acquisition module specifically includes:

[0094] A first acquisition unit, the first acquisition unit is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, and acquire non-public data timestamp information based on non-public data;

[0095] The second acquisition unit is used to acquire the target access data information, key transmission data, transmission status data and network attack data during the transmission process of the access user, and acquire the data format type information according to the data format information.

[0096] Optionally, the evaluation module specifically includes:

[0097] A data evaluation unit, the data evaluation unit is used to obtain a data sensitivity coefficient of each non-public data according to the data topology relationship diagram, and obtain a data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient;

[0098] An access evaluation unit, the access evaluation unit is used to obtain a login abnormality index of a visiting user according to the visiting user information, the visiting user's historical login information and the user's regular login time period;

[0099] A key transmission evaluation unit is used to obtain an access data sensitivity coefficient based on target access data and a feature data set, and to obtain a key transmission risk index based on key transmission data, normal status data and access data sensitivity coefficient.

[0100] Compared with the prior art, the present invention has the following beneficial effects:

[0101] The present invention proposes an adaptive key lifecycle management method and system based on dynamic data. The key generation efficiency is improved through data classification information. The key strength is accurately matched through the data confidentiality requirement index, the traditional single key mode is changed, excessive or insufficient encryption is avoided, and the key fragmentation transmission strategy is flexibly determined in combination with user login anomalies and target data confidentiality requirements to prevent illegal acquisition. The key is interrupted, adjusted or regenerated in time through the key transmission risk index, effectively responding to network attacks, ensuring the safety of the entire transmission process, greatly improving the adaptability and security of key management, and meeting the complex and changeable network environment and diverse business scenario requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0102] Figure 1 A flow chart of a method for adaptive key lifecycle management based on dynamic data proposed by the present invention;

[0103] Figure 2This is a flow chart for obtaining data classification information in the present invention;

[0104] Figure 3 A flowchart for obtaining key generation information in the present invention;

[0105] Figure 4 This is a flowchart for obtaining key transmission information in the present invention;

[0106] Figure 5 This is a structural block diagram of an adaptive key lifecycle management system based on dynamic data proposed by the present invention. DETAILED DESCRIPTION

[0107] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art may think of other obvious variations.

[0108] Reference Figure 1 - Figure 4 As shown, an adaptive key lifecycle management method based on dynamic data in an embodiment of the present invention includes:

[0109] Acquire data storage information, wherein the data storage information includes data attribute information and data format information;

[0110] Classify the stored data according to the data storage information and obtain data classification information;

[0111] Specifically, according to the data storage information, the stored data is classified to obtain data classification information, which specifically includes:

[0112] According to the data storage information and based on data traceability, the data is divided into public data and non-public data, where the public data refers to data that can be obtained through any public channel;

[0113] Based on the non-public data, obtain the non-public data timestamp information;

[0114] According to the timestamp information of the non-public data, the non-public data is arranged in order from the most recent to the most recent time, and the order information of the non-public data is obtained;

[0115] Acquire data interval information according to the non-public data sequence information, wherein the data interval information indicates the time interval between adjacent non-public data in the non-public data sequence;

[0116] Taking the maximum value in the data interval information as the first data interval, and taking the minimum value in the data interval information as the second data interval;

[0117] Acquire data time window information according to the first data interval and the second data interval;

[0118] Two adjacent non-public data in the first data interval are used as first non-public data and second non-public data;

[0119] using two adjacent non-public data in the second data interval as third non-public data and fourth non-public data;

[0120] Acquire time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data;

[0121] Among them, if The third non-public data is used as the initial data of the time window. The fourth non-public data is used as the initial data of the time window;

[0122] Based on the initial data of the time window, the non-public data is divided into data sets of several time periods based on the data time window, and data classification information is obtained;

[0123] The data time window is specifically:

[0124]

[0125] Where T is the data time window, t max is the first data interval, t min is the second data time interval.

[0126] In this solution, data is divided into public data and non-public data through data tracing, non-public data is arranged in order of time from far to near, the maximum value in the data interval information is used as the first data interval, and the minimum value in the data interval information is used as the second data interval. According to the first data interval and the second data interval, data time window information is obtained, and according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, the time window initial data is obtained, and according to the time window initial data, the non-public data is divided into data sets of several time periods based on the data time window;

[0127] It can be understood that, as an implementation method in this embodiment, the non-public data is arranged from left to right in the order of time from far to near, the data interval is the time interval between the timestamps of two non-public data, the two non-public data constituting the maximum data interval, the one located on the left is the first non-public data, the one located on the right is the second non-public data, the two non-public data constituting the minimum data interval, the one located on the left is the third non-public data, the one located on the right is the fourth non-public data;

[0128] In this embodiment, the initial data of the time window is taken as the starting point, the data time window is used as the selection basis of the data set, and it is extended to the left and right sides, and the non-public data in each data time window is taken as a non-public data set.

[0129] Based on the data classification information, a data sensitivity coefficient is obtained, where the data sensitivity coefficient indicates the impact degree of data leakage;

[0130] Specifically, based on the data classification information, the data sensitivity coefficient is obtained, including:

[0131] Obtain non-public data sets based on data classification information;

[0132] Using data attribute information in the data storage information as a data topology criterion to obtain data topology criterion information, wherein the data topology criterion includes personal data, commercial data, industrial data, and medical data;

[0133] Based on the data topology criterion, a data topology relationship diagram is established for the non-public data in each non-public data set;

[0134] According to the data topology diagram, obtain the data sensitivity coefficient of each non-public data;

[0135] The calculation formula of the data sensitivity coefficient is:

[0136]

[0137] Where Q(x) is the data sensitivity coefficient of the xth non-public data, ω i (x) represents the total number of non-public data topologically adjacent to the x-th non-public data under the i-th data topology criterion, τ(i, x) represents the total number of non-public data connected to the topological relationship to which the x-th non-public data belongs under the i-th data topology criterion, A(x) represents the total number of data in the non-public data set to which the x-th non-public data belongs, and n is the total number of data topology criterion types.

[0138] In this scheme, by taking the data attribute information in the data storage information as the data topology criterion and taking the data topology criterion as the benchmark, a data topology relationship diagram is established for the non-public data in each non-public data set. According to the data topology relationship diagram, the data sensitivity coefficient of each non-public data is obtained. The sensitivity of different data is represented by the data sensitivity coefficient, thereby achieving accurate analysis of data sensitivity and facilitating the subsequent accurate generation of keys.

[0139] In this embodiment, different data attributes are used as different data topology criteria. Different data topology criteria are used to construct data topology relationships for each non-public data set, forming multiple data topology relationship diagrams. The data sensitivity is evaluated through the data topology relationship diagrams. It can be understood that personal data leakage may lead to identity theft and other security issues, financial data leakage may lead to economic losses and financial fraud, and commercial data leakage may affect the company's competitiveness and market position, etc. The relationship between data cannot be directly analyzed by a single data processing method, but at the same time, the more associations there are between different data, the more likely these data leaks are to result in other data that were not originally leaked being analyzed from these data associations. Therefore, through different data topology criteria, topological relationships are established for the data, thereby improving the accuracy and reliability of data analysis.

[0140] According to the data format information and based on data risk analysis, different data format risk coefficients are set for different data formats;

[0141] Obtain the data confidentiality requirement index based on the data sensitivity coefficient and data format risk coefficient;

[0142] According to the data confidentiality requirement index and based on the key strength setting, obtaining key generation information, wherein the key generation information includes key length information and key encryption algorithm information;

[0143] Specifically, according to the data confidentiality requirement index and based on the key strength setting, key generation information is obtained, including:

[0144] According to the data format information, obtain the data format type information;

[0145] Based on data risk analysis, data formats are divided into three types: structured data format, semi-structured data format and unstructured data format, and data format classification information is obtained;

[0146] According to the data format classification information, different weights are set for different classified data formats;

[0147] Based on the set weight, obtain the data format risk coefficient corresponding to each data format;

[0148] According to the data sensitivity coefficient and data format risk coefficient, obtain the data confidentiality requirement index of each data;

[0149] Among them, the data sensitivity coefficient of public data is 1;

[0150] According to the data confidentiality requirement index, obtain the maximum value and the average value of the data confidentiality requirement index;

[0151] The ratio of the mean and maximum values ​​of the data confidentiality requirement index is used as the key strength coefficient;

[0152] Based on key generation analysis, obtain the maximum key strength and the corresponding key life cycle;

[0153] The product of the maximum value of the key strength and the key strength coefficient is used as the generated key strength, and the product of the key life cycle and the key strength coefficient is used as the generated key life cycle to obtain key generation information;

[0154] The data confidentiality requirement index is specifically:

[0155]

[0156] Where E(y) represents the data confidentiality requirement index of the y-th data, Q(y) represents the data sensitivity coefficient of the y-th data, K(y) represents the data format risk coefficient of the y-th data, α(y) represents the data format weight of the y-th data, σ(y) represents the total number of data format types of the data format classification to which the data format of the y-th data belongs, and α s represents the data format weight of the sth data format category, σ s Represents the total number of data format types of the sth data format category, where, if s=1, it represents a structured data format, α1=7; if s=2, it represents a semi-structured data format, α2=3; if s=2, it represents an unstructured data format, α3=2.

[0157] In this scheme, by classifying data formats into three types: structured data format, semi-structured data format and unstructured data format, data format classification information is obtained, and different weights are set for data formats of different categories according to the data format classification information. The ratio of the mean and maximum values ​​of the data confidentiality requirement index is used as the key strength coefficient. Based on the key generation analysis, the maximum value of the key strength and the corresponding key life cycle are obtained. The product of the maximum value of the key strength and the key strength coefficient is used as the generated key strength. The product of the key life cycle and the key strength coefficient is used as the generated key life cycle to obtain the key generation information. The data attributes, format and time factors are fully considered, and the key strength is accurately matched accordingly. The traditional single key mode is changed to avoid excessive or insufficient encryption, which not only ensures the security of sensitive data but also optimizes resource utilization.

[0158] It is understandable that the sensitivity of different types of data formats is also very different. For example, structured data formats such as database tables and spreadsheets usually contain sensitive information such as personal information and financial data, which may lead to large-scale data leaks if leaked. Semi-structured data formats such as JSON and XML are usually used to transmit data and may contain sensitive information. For unstructured data formats such as text files, PDF documents, images, videos, etc., although data in these formats may contain sensitive information, it may not be easy to identify if it is not clearly marked.

[0159] Obtaining access user information, wherein the access user information includes access user account information and access user login information;

[0160] According to the access user information, obtain the access user login abnormality index;

[0161] Obtain target access data information of accessing users;

[0162] Obtain key transmission information based on the access user login anomaly index, target access data information and key generation information;

[0163] Specifically, according to the access user login anomaly index, access target data information and key generation information, key transmission information is obtained, including:

[0164] Get the historical login information of the accessing user;

[0165] Obtain the user's regular login time period based on the user login time in the historical login information of the accessed user;

[0166] Obtain the access user login anomaly index based on the access user information, the access user's historical login information and the user's regular login time period;

[0167] According to the access target data information of the accessing user, a data confidentiality requirement index of the target access data is obtained;

[0168] According to the access user login anomaly index and the data confidentiality requirement index of the target access data, the number of key transmission shards is obtained;

[0169] Get the key strength coefficient;

[0170] The product of the number of key transmission shards and the key strength coefficient is used as the number of key reconstruction shards;

[0171] Based on the number of key transmission shards and the number of key reconstruction shards, the generated key is transmitted in key shards to obtain key transmission information;

[0172] The calculation formula of the access user login abnormality index is:

[0173]

[0174] Where R is the login anomaly index of the access user, ε is the number of account logins per unit time of the access user, δ(t0) represents the user access time anomaly function, where if the user login time t0 belongs to the user's regular login time period, then δ(t0) = 1, if the user login time t0 does not belong to the user's regular login time period, then δ(t0) = |t1-t0|, t1 represents the user's regular login time period node closest to the user login time t0, θ is the unit time, and θ = 0.25h;

[0175] The number of key transmission fragments is specifically:

[0176]

[0177] Where D is the number of key transmission shards, E(j) represents the data confidentiality requirement index of the j-th target access data, E(y) represents the data confidentiality requirement index of the y-th data, m is the total number of target access data, and g is the total number of stored data.

[0178] In this scheme, the access user information, the access user's historical login information and the user's regular login time period are used to obtain the access user's login anomaly index, and the user's login anomaly degree is analyzed by the access user's login anomaly index to facilitate the selection of a suitable key transmission strategy. The number of key transmission shards is obtained according to the access user's login anomaly index and the data confidentiality requirement index of the target access data. The product of the number of key transmission shards and the key strength coefficient is used as the number of key reconstruction shards. Based on the number of key transmission shards and the number of key reconstruction shards, the generated key is transmitted in key shards to obtain key transmission information.

[0179] It is understandable that when transmitting keys, sharding the keys can greatly improve the confidentiality of the keys. Even if some key shards are lost due to a network attack, the complete key will not be leaked. However, if the number of key shards is too large, the key transmission efficiency will be reduced and the time cost will be increased. Therefore, the key shard transmission strategy is flexibly determined by combining user login anomalies and target data confidentiality requirements to prevent illegal acquisition.

[0180] Acquire key transmission data, wherein the key transmission data includes transmission status data and network attack data during transmission;

[0181] According to the key transmission data, a key transmission risk index is obtained;

[0182] Based on the key transmission risk index, determine whether to interrupt key transmission. If so, destroy the key and regenerate the key. If not, adjust the key life cycle according to the key transmission risk index.

[0183] Specifically, based on the key transmission risk index, it is determined whether to interrupt key transmission, including:

[0184] Acquire normal status data, wherein the normal status data includes normal working data of the CPU and normal working data of the memory;

[0185] Obtain non-public data sets based on data classification information;

[0186] Based on the non-public data set, obtain the distribution status of the target access data in the non-public data set;

[0187] The non-public dataset to which the target access data belongs is used as the feature dataset;

[0188] Obtain access data sensitivity coefficients based on target access data and feature data sets;

[0189] Obtain the key transmission risk index based on the key transmission data, normal status data and access data sensitivity coefficient;

[0190] According to the key transmission risk index, determine whether to interrupt key transmission. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient and regenerate the key. If not, update the key life cycle according to the key transmission risk index.

[0191] If the key transmission risk index G≥1.13, the key transmission is interrupted. If the key transmission risk index G<0.56, the key life cycle is adjusted to f=f0(1+G). If the key transmission risk index 0.56≤G<1.13, the key life cycle is adjusted to Among them, f is the key life cycle, f0 is the generated key life cycle;

[0192] The calculation formula of the key transmission risk index is:

[0193]

[0194] Where G is the key transmission risk index, μ z represents the zth transmission status data, μ0 represents the normal value of the zth transmission status data, d c represents the total number of target access data in the cth feature data set, A c represents the total number of data in the cth feature data set, m is the total number of target access data, M represents the feature data set, max(·) represents the maximum value, and w represents the total number of transmission status data types.

[0195] In this scheme, the distribution status of the target access data in the non-public data set is obtained based on the non-public data set, and the non-public data set to which the target access data belongs is used as the feature data set. The access data sensitivity coefficient is obtained according to the target access data and the feature data set. The key transmission risk index is obtained according to the key transmission data, the normal status data and the access data sensitivity coefficient. According to the key transmission risk index, it is determined whether to interrupt the key transmission.

[0196] It is understandable that in this scheme, the data in the same non-public data set often have similar timestamps and strong correlation between the data. If the accessed data accounts for too large a proportion of the same data set, the leakage of the accessed data will increase the risk of leakage of other data not included. Therefore, the key transmission risk index is used to monitor the key transmission risk in real time, interrupt, adjust or regenerate the key in time, effectively respond to network attacks, ensure the security of the entire transmission process, greatly improve the adaptability and security of key management, and meet the needs of complex and changeable network environments and diverse business scenarios.

[0197] Reference Figure 5 As shown, further, in combination with the above-mentioned adaptive key lifecycle management method based on dynamic data, an adaptive key lifecycle management system based on dynamic data is proposed, including:

[0198] A main control module, the main control module is used to obtain non-public data sequence information according to non-public data timestamp information, obtain data time window information according to a first data interval and a second data interval, obtain time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, establish a data topology relationship diagram for the non-public data in each non-public data set based on the data topology criterion, use the product of the maximum value of the key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key shard transmission on the generated key based on the number of key transmission shards and the number of key reconstruction shards, obtain key transmission information, determine whether to interrupt key transmission according to the key transmission risk index, if so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient, and regenerate the key, if not, update the key life cycle according to the key transmission risk index;

[0199] An information acquisition module, the information acquisition module is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, acquire non-public data timestamp information based on non-public data, acquire target access data information of access users, key transmission data, transmission status data and network attack data during transmission, and acquire data format type information based on data format information;

[0200] An evaluation module, the evaluation module is used to obtain the data sensitivity coefficient of each non-public data according to the data topology relationship diagram, obtain the data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient, obtain the access user login anomaly index according to the access user information, the access user's historical login information and the user's regular login time period, obtain the access data sensitivity coefficient according to the target access data and the feature data set, and obtain the key transmission risk index according to the key transmission data, the regular status data and the access data sensitivity coefficient;

[0201] The display module interacts with the main control module and is used to output and display data classification information, data confidentiality requirement index, key generation information, key transmission information and key transmission risk index.

[0202] Main control module, specifically including:

[0203] A control unit, the control unit is used to use the product of the maximum value of the key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key fragment transmission on the generated key based on the number of key transmission fragments and the number of key reconstruction fragments, obtain key transmission information, and determine whether to interrupt the key transmission according to the key transmission risk index. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient to regenerate the key. If not, update the key life cycle according to the key transmission risk index;

[0204] An information receiving unit, which interacts with the information acquisition module and the evaluation module to receive data and transmit it to the data processing unit;

[0205] A data processing unit, the data processing unit is used to obtain non-public data order information based on non-public data timestamp information, obtain data time window information based on a first data interval and a second data interval, obtain time window initial data based on the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, and establish a data topology relationship diagram for the non-public data in each non-public data set based on a data topology criterion.

[0206] Information acquisition module, specifically including:

[0207] A first acquisition unit, the first acquisition unit is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, and acquire non-public data timestamp information based on non-public data;

[0208] The second acquisition unit is used to acquire the target access data information, key transmission data, transmission status data and network attack data during the transmission process of the access user, and acquire the data format type information according to the data format information.

[0209] Assessment modules include:

[0210] A data evaluation unit, the data evaluation unit is used to obtain a data sensitivity coefficient of each non-public data according to the data topology relationship diagram, and obtain a data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient;

[0211] An access evaluation unit, the access evaluation unit is used to obtain a login abnormality index of a visiting user according to the visiting user information, the visiting user's historical login information and the user's regular login time period;

[0212] A key transmission evaluation unit is used to obtain an access data sensitivity coefficient based on target access data and a feature data set, and to obtain a key transmission risk index based on key transmission data, normal status data and access data sensitivity coefficient.

[0213] In summary, the advantages of the present invention are: through data storage information, the stored data is classified to obtain data classification information, and through the data classification information, the non-public data in the stored data is divided into multiple data sets, which is convenient for the accurate setting of the key strength later, and the key generation efficiency is improved. Through the data confidentiality requirement index, based on the key strength setting, the key generation information is obtained, and the data attributes, format and time factors are fully considered. The key strength is accurately matched accordingly, the traditional single key mode is changed, and excessive or insufficient encryption is avoided, which not only ensures the security of sensitive data, but also optimizes resource utilization. In combination with user login anomalies and target data confidentiality requirements, the key sharding transmission strategy is flexibly determined to prevent illegal acquisition. At the same time, the key transmission risk is monitored in real time, and the key is interrupted, adjusted or regenerated in time through the key transmission risk index, which effectively responds to network attacks, ensures the safety of the entire transmission process, greatly improves the adaptability and security of key management, and meets the complex and changeable network environment and diverse business scenario requirements.

[0214] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions only describe the principles of the present invention. The present invention may be subject to various changes and improvements without departing from the spirit and scope of the present invention. These changes and improvements fall within the scope of the present invention. The scope of protection claimed by the present invention is defined by the attached claims and their equivalents.

Claims

1. An adaptive key lifecycle management method based on dynamic data, characterized in that: include: Acquire data storage information, wherein the data storage information includes data attribute information and data format information; Classify the stored data according to the data storage information and obtain data classification information; Based on the data classification information, a data sensitivity coefficient is obtained, where the data sensitivity coefficient indicates the impact degree of data leakage; According to the data format information and based on data risk analysis, different data format risk coefficients are set for different data formats; Obtain the data confidentiality requirement index based on the data sensitivity coefficient and data format risk coefficient; According to the data confidentiality requirement index and based on the key strength setting, obtaining key generation information, wherein the key generation information includes key length information and key encryption algorithm information; Obtaining access user information, wherein the access user information includes access user account information and access user login information; According to the access user information, obtain the access user login abnormality index; Obtain target access data information of accessing users; Obtain key transmission information based on the access user login anomaly index, target access data information and key generation information; Acquire key transmission data, wherein the key transmission data includes transmission status data and network attack data during transmission; According to the key transmission data, a key transmission risk index is obtained; Based on the key transmission risk index, determine whether to interrupt key transmission. If so, destroy the key and regenerate the key. If not, adjust the key life cycle according to the key transmission risk index.

2. The adaptive key lifecycle management method based on dynamic data according to claim 1, characterized in that: The step of classifying the stored data according to the data storage information and obtaining the data classification information specifically includes: According to the data storage information and based on data traceability, the data is divided into public data and non-public data, where the public data refers to data that can be obtained through any public channel; Based on the non-public data, obtain the non-public data timestamp information; According to the timestamp information of the non-public data, the non-public data is arranged in order from the most recent to the most recent time, and the order information of the non-public data is obtained; Acquire data interval information according to the non-public data sequence information, wherein the data interval information indicates the time interval between adjacent non-public data in the non-public data sequence; Using the maximum value in the data interval information as the first data interval, and using the minimum value in the data interval information as the second data interval; Acquire data time window information according to the first data interval and the second data interval; Two adjacent non-public data in the first data interval are used as first non-public data and second non-public data; using two adjacent non-public data in the second data interval as third non-public data and fourth non-public data; Acquire time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data; Among them, if The third non-public data is used as the initial data of the time window. The fourth non-public data is used as the initial data of the time window; Based on the initial data of the time window, the non-public data is divided into data sets of several time periods based on the data time window, and data classification information is obtained; The data time window is specifically: Where T is the data time window, t max is the first data interval, t min is the second data time interval.

3. The adaptive key lifecycle management method based on dynamic data according to claim 1, characterized in that: The obtaining of the data sensitivity coefficient based on the data classification information specifically includes: Obtain non-public data sets based on data classification information; Using data attribute information in the data storage information as a data topology criterion to obtain data topology criterion information, wherein the data topology criterion includes personal data, commercial data, industrial data, and medical data; Based on the data topology criterion, a data topology relationship diagram is established for the non-public data in each non-public data set; According to the data topology diagram, obtain the data sensitivity coefficient of each non-public data; The calculation formula of the data sensitivity coefficient is: Where Q(x) is the data sensitivity coefficient of the xth non-public data, ω i (x) represents the total number of non-public data topologically adjacent to the x-th non-public data under the i-th data topology criterion, τ(i, x) represents the total number of non-public data connected to the topological relationship to which the x-th non-public data belongs under the i-th data topology criterion, A(x) represents the total number of data in the non-public data set to which the x-th non-public data belongs, and n is the total number of data topology criterion types.

4. The adaptive key lifecycle management method based on dynamic data according to claim 1, characterized in that: The obtaining of key generation information according to the data confidentiality requirement index and based on the key strength setting specifically includes: According to the data format information, obtain the data format type information; Based on data risk analysis, data formats are divided into three types: structured data format, semi-structured data format and unstructured data format, and data format classification information is obtained; According to the data format classification information, different weights are set for different classified data formats; Based on the set weight, obtain the data format risk coefficient corresponding to each data format; According to the data sensitivity coefficient and the data format risk coefficient, obtain the data confidentiality requirement index of each data; Among them, the data sensitivity coefficient of public data is 1; According to the data confidentiality requirement index, obtain the maximum value and the average value of the data confidentiality requirement index; The ratio of the mean and maximum values ​​of the data confidentiality requirement index is used as the key strength coefficient; Based on key generation analysis, obtain the maximum key strength and the corresponding key life cycle; The product of the maximum value of the key strength and the key strength coefficient is used as the generated key strength, and the product of the key life cycle and the key strength coefficient is used as the generated key life cycle to obtain key generation information; The data confidentiality requirement index is specifically: Where E(y) represents the data confidentiality requirement index of the y-th data, Q(y) represents the data sensitivity coefficient of the y-th data, K(y) represents the data format risk coefficient of the y-th data, α(y) represents the data format weight of the y-th data, σ(y) represents the total number of data format types of the data format classification to which the data format of the y-th data belongs, and α s represents the data format weight of the sth data format category, σ s Represents the total number of data format types of the sth data format category, where, if s=1, it represents a structured data format, α1=7; if s=2, it represents a semi-structured data format, α2=3; if s=2, it represents an unstructured data format, α3=2.

5. The method for adaptive key lifecycle management based on dynamic data according to claim 1, characterized in that: The obtaining of key transmission information according to the access user login abnormality index, access target data information and key generation information specifically includes: Get the historical login information of the accessing user; Obtain the user's regular login time period based on the user login time in the historical login information of the accessed user; Obtain the access user login anomaly index based on the access user information, the access user's historical login information and the user's regular login time period; According to the target data information of the access user, a data confidentiality requirement index of the target access data is obtained; According to the access user login anomaly index and the data confidentiality requirement index of the target access data, the number of key transmission shards is obtained; Get the key strength coefficient; The product of the number of key transmission shards and the key strength coefficient is used as the number of key reconstruction shards; Based on the number of key transmission shards and the number of key reconstruction shards, the generated key is transmitted in key shards to obtain key transmission information; The calculation formula of the access user login abnormality index is: Where R is the login anomaly index of the access user, ε is the number of account logins per unit time of the access user, δ(t0) represents the user access time anomaly function, where if the user login time t0 belongs to the user's regular login time period, then δ(t0) = 1, if the user login time t0 does not belong to the user's regular login time period, then δ(t0) = |t1-t0|, t1 represents the user's regular login time period node closest to the user login time t0, θ is the unit time, and θ = 0.25h; The number of key transmission fragments is specifically: Where D is the number of key transmission shards, E(j) represents the data confidentiality requirement index of the j-th target access data, E(y) represents the data confidentiality requirement index of the y-th data, m is the total number of target access data, and g is the total number of stored data.

6. The adaptive key lifecycle management method based on dynamic data according to claim 1, characterized in that: The determining whether to interrupt key transmission based on the key transmission risk index specifically includes: Acquire normal status data, wherein the normal status data includes normal working data of the CPU and normal working data of the memory; Obtain non-public data sets based on data classification information; Based on the non-public data set, obtain the distribution status of the target access data in the non-public data set; The non-public dataset to which the target access data belongs is used as a feature dataset; Obtain access data sensitivity coefficients based on target access data and feature data sets; Obtain the key transmission risk index based on the key transmission data, normal status data and access data sensitivity coefficients; According to the key transmission risk index, determine whether to interrupt key transmission. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient and regenerate the key. If not, update the key life cycle according to the key transmission risk index. If the key transmission risk index G≥1.13, the key transmission is interrupted. If the key transmission risk index G<0.56, the key life cycle is adjusted to f=f0(1+G). If the key transmission risk index 0.56≤G<1.13, the key life cycle is adjusted to Among them, f is the key life cycle, f0 is the generated key life cycle; The calculation formula of the key transmission risk index is: Where G is the key transmission risk index, μ z represents the zth transmission status data, μ0 represents the normal value of the zth transmission status data, d c represents the total number of target access data in the cth feature data set, A c represents the total number of data in the cth feature data set, m is the total number of target access data, M represents the feature data set, max(·) represents the maximum value, and w represents the total number of transmission status data types.

7. An adaptive key lifecycle management system based on dynamic data, used to implement the management method according to any one of claims 1 to 6, characterized in that: include: A main control module, the main control module is used to obtain non-public data sequence information according to non-public data timestamp information, obtain data time window information according to a first data interval and a second data interval, obtain time window initial data according to the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, establish a data topology relationship diagram for the non-public data in each non-public data set based on the data topology criterion, use the product of the maximum key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key shard transmission on the generated key based on the number of key transmission shards and the number of key reconstruction shards, obtain key transmission information, determine whether to interrupt key transmission according to the key transmission risk index, if so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient, and regenerate the key, if not, update the key life cycle according to the key transmission risk index; An information acquisition module, the information acquisition module is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, acquire non-public data timestamp information based on non-public data, acquire target access data information of access users, key transmission data, transmission status data and network attack data during transmission, and acquire data format type information based on data format information; An evaluation module, the evaluation module is used to obtain the data sensitivity coefficient of each non-public data according to the data topology relationship diagram, obtain the data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient, obtain the access user login anomaly index according to the access user information, the access user's historical login information and the user's regular login time period, obtain the access data sensitivity coefficient according to the target access data and the feature data set, and obtain the key transmission risk index according to the key transmission data, the regular status data and the access data sensitivity coefficient; The display module interacts with the main control module and is used to output and display data classification information, data confidentiality requirement index, key generation information, key transmission information and key transmission risk index.

8. The adaptive key lifecycle management system based on dynamic data according to claim 7, characterized in that: The main control module specifically includes: A control unit, the control unit is used to use the product of the maximum value of the key strength and the key strength coefficient as the generated key strength, use the product of the key life cycle and the key strength coefficient as the generated key life cycle, obtain key generation information, perform key fragment transmission on the generated key based on the number of key transmission fragments and the number of key reconstruction fragments, obtain key transmission information, and determine whether to interrupt the key transmission according to the key transmission risk index. If so, use the product of the key transmission risk index and the key strength coefficient as the new key strength coefficient to regenerate the key. If not, update the key life cycle according to the key transmission risk index; An information receiving unit, which interacts with the information acquisition module and the evaluation module to receive data and transmit it to the data processing unit; A data processing unit, the data processing unit is used to obtain non-public data order information based on non-public data timestamp information, obtain data time window information based on a first data interval and a second data interval, obtain time window initial data based on the first non-public data, the second non-public data, the third non-public data and the fourth non-public data, and establish a data topology relationship diagram for the non-public data in each non-public data set based on a data topology criterion.

9. The adaptive key lifecycle management system based on dynamic data according to claim 7, characterized in that: The information acquisition module specifically includes: A first acquisition unit, the first acquisition unit is used to acquire data storage information, data attribute information, data format information, access user information, access user account information and access user login information, and acquire non-public data timestamp information based on non-public data; The second acquisition unit is used to acquire the target access data information, key transmission data, transmission status data and network attack data during the transmission process of the access user, and acquire the data format type information according to the data format information.

10. The adaptive key lifecycle management system based on dynamic data according to claim 7, characterized in that: The evaluation module specifically includes: A data evaluation unit, the data evaluation unit is used to obtain a data sensitivity coefficient of each non-public data according to the data topology relationship diagram, and obtain a data confidentiality requirement index of each data according to the data sensitivity coefficient and the data format risk coefficient; An access evaluation unit, the access evaluation unit is used to obtain a login abnormality index of a visiting user according to the visiting user information, the visiting user's historical login information and the user's regular login time period; A key transmission evaluation unit is used to obtain an access data sensitivity coefficient based on target access data and a feature data set, and to obtain a key transmission risk index based on key transmission data, normal status data and access data sensitivity coefficient.

Citation Information

Patent Citations

  • Method for analyzing data authority control based on Handle identification

    CN112417511A

  • Key management method and system based on Vault

    CN118523908A

  • Encryption key lifecycle management

    US20170257214A1

  • Key management in a distributed system

    US8724815B1