Digital asset protection system and method
By integrating technical means of data storage encryption, network communication protection and remote desktop control in the digital asset protection system, the problem of data leakage incidents frequently occur in the face of the advancement of network hacking technology and the cracking of international encryption algorithms is solved, and high security in the data transmission process is achieved.
Patent Information
- Application Number
- CN202411876382.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the face of the advancement of network hacking technology and the cracking of international encryption algorithms, data leakage incidents occur frequently, resulting in data security threats.
A digital asset protection system is provided, including a data storage encryption unit, a network communication protection unit and a remote desktop control unit. The data storage encryption unit realizes data encryption and decryption through the key management module, storage management module and policy management module; the network communication protection unit ensures the security of network communication through the National Secret SSL VPN module, security authentication module and traffic monitoring protection module; the remote desktop control unit strengthens the security of data transmission and access through the National Secret key negotiation module and the user identity multi-factor authentication module.
Through technical means such as dynamic key negotiation and multi-factor authentication, the security during data transmission is greatly improved, key leakage and unauthorized access are prevented, and the confidentiality and integrity of data during storage and transmission are ensured.
Smart Images

Figure CN120012124A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data asset protection, and in particular relates to a digital asset protection system and method. Background Art
[0002] In traditional cloud services, storage servers are mainly used to store electronic data such as various materials, pictures, and videos in application systems; while traditional cloud disk services are often used to store data that exceeds the capacity limit of physical hard disks. However, with the continuous advancement of network hacking technology in recent years, data leaks frequently occur in servers and cloud disks in cloud environments, such as the Baidu cloud disk data leak. Once sensitive data such as financial records, private photos, and important documents are leaked, it may not only lead to economic losses, but also cause serious problems such as identity theft and reputation damage. In addition, when companies use cloud disks to store business secrets or customer data, data leaks may bring serious legal consequences and trust crises. Routing storage devices are a common solution for storing electronic data such as pictures, videos, and documents in large quantities and in a centralized manner. This device integrates router and storage functions, allowing users to remotely access data stored on servers through the network. This type of product mainly relies on several key technical components: integrated router and storage device, cloud management platform, remote access client, and multi-user permission management. Through the combination of these technical components, a set of hardware devices can be quickly built and deployed at home to achieve storage services that can be accessed anytime, anywhere. Although this type of device hardwareizes storage, the network connection part still has the risk of being exposed and forcibly cracked.
[0003] Traditional cloud storage and physical storage servers usually use international encryption algorithms to protect data storage and transmission, but as more and more international encryption algorithms are cracked, the security of encrypted data is gradually threatened. In addition, many applications already have built-in cloud storage or physical storage functions, so how to upgrade security on the existing basis has become a thorny issue. Summary of the invention
[0004] In order to solve the above problems existing in the prior art, the present invention provides a digital asset protection system and method. The purpose of the present invention can be achieved through the following technical solutions:
[0005] A digital asset protection system, comprising: a data storage encryption unit, a network communication protection unit and a remote desktop control unit;
[0006] The data storage encryption unit includes a key management module, a storage management module, a policy management module and a data encryption and decryption module; the key management module obtains the SM4 key from the national secret security device and encrypts and stores it in the system, which is used to encrypt and decrypt the electronic data; the storage management module is used to obtain user data management protection information, extract the corresponding storage protection data according to the user data management protection information and perform storage management; the policy management module is used to configure the data protection key and encryption and decryption policy for the storage protection data, and the storage protection data is automatically encrypted and decrypted when the read and write operations are performed after the configuration is completed;
[0007] The network communication protection unit includes a national secret SSL VPN module, a security authentication module, and a traffic monitoring protection module; the national secret SSL VPN module is used to provide users with secure data transmission protection and anti-tampering capabilities for accessing home data in the public network based on national secret security equipment; the security authentication module authenticates the user based on national secret PKI technology and dynamic password technology; the traffic monitoring protection module monitors network traffic based on security policies, automatically intercepts risky or abnormal connection requests and data, and sends an alarm message to the user when an abnormality is found;
[0008] The remote desktop control unit includes a client, a remote desktop service center, a national secret key negotiation module, and a user identity multi-factor authentication module; the client is connected to the remote desktop service center through the dial-up function of the built-in national secret SSLVPN module, which is used to encrypt the transmission and access to stored data; the remote desktop service center performs hierarchical authority management on the user's application permissions and data permissions; the national secret key negotiation module is used to encrypt the encryption key of the data in the data transmission between the client and the remote desktop service center; the user identity multi-factor authentication module is used to control the user to log in to the client according to the personal digital certificate and dynamic token issued by the system.
[0009] Specifically, the encryption and decryption strategy of the policy management module is to perform encryption and decryption processing based on the data transmission information of the client, the data storage encryption unit, and the data storage area using a symmetric encryption algorithm.
[0010] Specifically, the identity authentication method of the security authentication module is: the user's identity information and public key are bound through the digital certificate issued to the user by the system, and the digital signature of the digital certificate is verified by the authentication center. If the verification is passed, the system sends random string information to the user through dynamic password technology. The user signs the random string information with the user's private key and then sends back the identity authentication information. The system performs identity identification and analysis on the user based on the identity authentication information.
[0011] Specifically, the security policy of the traffic monitoring and protection module is to match and analyze the traffic data of key nodes at the network boundary and network entrances and exits based on a rule base, and the rule base includes normal traffic baseline rules, security policy rules, anomaly monitoring rules, equipment and application rules; the normal traffic baseline rules are used to define the traffic rate, protocol type, and data packet size under normal circumstances; the security policy rules contain the organization's security policy, which is used to allow and deny rules for specific ports and protocols; the anomaly monitoring rules are combined with the rules of the intrusion detection system and the intrusion prevention system to identify the characteristics of known attacks; the equipment and application rules are used to perform in-depth analysis of the traffic of the application layer protocol.
[0012] A digital asset protection method, comprising:
[0013] The user initiates a remote desktop connection request through the client, and the client establishes an encrypted connection with the remote desktop service center through the dial-up function of the built-in national secret SSL VPN module;
[0014] After receiving the connection request, the remote desktop service center performs hierarchical permission management on the user's application permissions and data permissions based on the user's identity information and permission level to ensure that the user can only access authorized data and applications;
[0015] After the user successfully logs in, the national secret key negotiation module intervenes and negotiates with the client and the remote desktop service center to produce an encryption key for this data transmission; at the same time, the user identity multi-factor authentication module requires the user to use the personal digital certificate and dynamic token issued by the system for login verification to ensure the legitimacy of the user's identity;
[0016] When the user starts to operate the remote desktop and reads and writes data, the storage management module automatically encrypts and decrypts the data according to the encryption and decryption policies configured by the policy management module to ensure the security of the data during storage and transmission;
[0017] The traffic monitoring and protection module in the network communication protection unit monitors network traffic in real time, performs traffic data matching and analysis on key nodes at the network boundary and ingress and egress, and immediately initiates security policy interception once abnormal traffic or attack behavior is found, and sends an alarm message to the user;
[0018] After the user completes the operation and disconnects the remote desktop connection, the system records the operation log for subsequent auditing and analysis.
[0019] The beneficial effects of the present invention are:
[0020] Through the intervention of the national secret key negotiation module, it is ensured that a unique encryption key is used for each data transmission, which greatly improves the security of the data transmission process. This dynamic key negotiation mechanism effectively prevents the risk of key leakage. Even if the key is intercepted, due to the timeliness of the key, the attacker cannot use the intercepted key to decrypt the data. The introduction of the user identity multi-factor authentication module not only requires the user to enter the password, but also must use a personal digital certificate and a dynamic token. This multi-factor authentication method greatly improves the security of user identity authentication. Even if the password is cracked, without the corresponding digital certificate and dynamic token, the attacker cannot pass the authentication, thereby protecting the user's account security. In terms of data operation, the storage management module automatically encrypts and decrypts the data according to the encryption and decryption strategy configured by the policy management module, ensuring the confidentiality and integrity of the data during storage and transmission. This automated processing reduces errors and omissions in human operations, while avoiding the risk of data leakage caused by improper operation.
[0021] The system can solve the problems of electronic data storage security, sensitive information security, and remote access security for all users. The system described in the present invention can be built on the basis of existing routing storage devices, and only needs to supplement the corresponding national secret security equipment and the system, which reduces the user's expenses at the economic level. At the same time, it can also be compatible with a variety of storage devices and network environments, has high adaptability, and greatly reduces the risk of electronic data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0023] Figure 1 It is a structural diagram of the digital asset protection system in the present invention;
[0024] Figure 2 This is a data encryption and decryption flow chart of the digital asset protection method of the present invention;
[0025] Figure 3 This is a flow chart of the national secret SSLVPN handshake message of the digital asset protection method in the present invention;
[0026] Figure 4 This is a flowchart of the national encryption algorithm key negotiation of the digital asset protection method in the present invention. DETAILED DESCRIPTION
[0027] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the specific implementation methods, structures, features and effects of the present invention are described in detail below in conjunction with the accompanying drawings and preferred embodiments.
[0028] See also Figure 1 , a digital asset protection system, comprising: a data storage encryption unit, a network communication protection unit and a remote desktop control unit;
[0029] The data storage encryption unit includes a key management module, a storage management module, a policy management module and a data encryption and decryption module; the key management module obtains the SM4 key from the national secret security device and encrypts and stores it in the system, which is used to encrypt and decrypt the electronic data; the storage management module is used to obtain user data management protection information, extract the corresponding storage protection data according to the user data management protection information and perform storage management; the policy management module is used to configure the data protection key and encryption and decryption policy for the storage protection data, and the storage protection data is automatically encrypted and decrypted when the read and write operations are performed after the configuration is completed;
[0030] The network communication protection unit includes a national secret SSL VPN module, a security authentication module, and a traffic monitoring protection module; the national secret SSL VPN module is used to provide users with secure data transmission protection and anti-tampering capabilities for accessing home data in the public network based on national secret security equipment; the security authentication module authenticates the user based on national secret PKI technology and dynamic password technology; the traffic monitoring protection module monitors network traffic based on security policies, automatically intercepts risky or abnormal connection requests and data, and sends an alarm message to the user when an abnormality is found;
[0031] The remote desktop control unit includes a client, a remote desktop service center, a national secret key negotiation module, and a user identity multi-factor authentication module; the client is connected to the remote desktop service center through the dial-up function of the built-in national secret SSLVPN module, which is used to encrypt the transmission and access to stored data; the remote desktop service center performs hierarchical authority management on the user's application permissions and data permissions; the national secret key negotiation module is used to encrypt the encryption key of the data in the data transmission between the client and the remote desktop service center; the user identity multi-factor authentication module is used to control the user to log in to the client according to the personal digital certificate and dynamic token issued by the system.
[0032] In this embodiment, the client can be installed in the current mainstream desktop and mobile operating systems such as Windows, Linux, Android, iOS, HarmonyOS, etc., and connected to the remote desktop service center at home through the dial-up function of the built-in national secret SSLVPN to encrypt the transmission and access the stored data. In the remote desktop service center, different remote desktop access services are opened according to the application permissions and data permissions of different users to achieve the minimum range of data access. In the national secret key negotiation function, the client and the remote description service center can directly use the national secret key negotiation protocol to transfer the encryption key of the encrypted data, and the key is only used for the current data transmission. In the user identity multi-factor authentication function, each user can use the internal personal digital certificate issued by this system or authenticate through a dynamic token to log in to the client, remotely access the encrypted data and remote desktop at home, and ensure that the data is protected from unauthorized access. The services provided by this module are suitable for scenarios where members share information, support multi-device synchronization and remote desktop access, and ensure privacy and security. It is suitable for various personal digital asset management needs in daily life.
[0033] Specifically, the encryption and decryption strategy of the policy management module is to perform encryption and decryption processing based on the data transmission information of the client, the data storage encryption unit, and the data storage area using a symmetric encryption algorithm.
[0034] In this embodiment, the encryption and decryption process is as follows: Figure 2 As shown, taking the Harmony application as an example, the encryption and decryption algorithm is based on the symmetric key encryption and decryption algorithm specifications. In the data storage and transmission scenarios, the encryption process calls cryptoFramework.createSymKeyGenerator and SymKeyGen-Erator.generateSymKey to generate a symmetric key with a key algorithm of AES and a key length of 128 bits, and calls cryptoFramework.createCipher, specifying the parameters 'AES128|GCM|PKCS7' to create a Cipher instance with a symmetric key type of AES128, a grouping mode of GCM, and a padding mode of PKCS7 to complete the encryption and decryption operations; in the digital asset protection system, AES128 is used as the symmetric key type, GCM as the grouping mode, and PKCS7 as the padding mode to construct a Cipher instance. The construction of this instance is the core of the encryption and decryption operation, which ensures the security of data during storage and transmission. In order to further enhance the security of data, such as Figure 4As shown in the figure, the key negotiation process of the national secret SM2 algorithm is adopted to generate keys based on the key derivation function (KDF). Through KDF, multiple subkeys can be derived from a master key, and these subkeys are used for different encryption operations, thereby avoiding the reuse of a single key and reducing the risk of key leakage. In actual applications, the system will dynamically select the appropriate encryption algorithm and key according to the user's operation instructions. For example, when a user needs to upload a file to the cloud, the system will automatically trigger the encryption process and encrypt the file using the Cipher instance constructed above. When the encrypted data is stored in the cloud, even if it is obtained by an unauthorized third party, its content cannot be interpreted. In addition, the system also supports regular key updates to meet the security challenges of long-term data storage. By regularly replacing keys, even if the old keys are cracked, attackers cannot decrypt new data, thereby ensuring the long-term security of user assets. By combining flexible key management strategies, users are provided with comprehensive data security protection. Whether it is personal privacy information or important files, they can be properly protected in this system, ensuring that users do not have to worry about data security issues while enjoying the convenience of digital life.
[0035] Specifically, the identity authentication method of the security authentication module is: the user's identity information and public key are bound through the digital certificate issued to the user by the system, and the digital signature of the digital certificate is verified by the authentication center. If the verification is passed, the system sends random string information to the user through dynamic password technology. The user signs the random string information with the user's private key and then sends back the identity authentication information. The system performs identity identification and analysis on the user based on the identity authentication information.
[0036] Specifically, the security policy of the traffic monitoring and protection module is to match and analyze the traffic data of key nodes at the network boundary and network entrances and exits based on a rule base, and the rule base includes normal traffic baseline rules, security policy rules, anomaly monitoring rules, equipment and application rules; the normal traffic baseline rules are used to define the traffic rate, protocol type, and data packet size under normal circumstances; the security policy rules contain the organization's security policy, which is used to allow and deny rules for specific ports and protocols; the anomaly monitoring rules are combined with the rules of the intrusion detection system and the intrusion prevention system to identify the characteristics of known attacks; the equipment and application rules are used to perform in-depth analysis of the traffic of the application layer protocol.
[0037] A digital asset protection method, comprising:
[0038] The user initiates a remote desktop connection request through the client, and the client establishes an encrypted connection with the remote desktop service center through the dial-up function of the built-in national secret SSL VPN module;
[0039] After receiving the connection request, the remote desktop service center performs hierarchical permission management on the user's application permissions and data permissions based on the user's identity information and permission level to ensure that the user can only access authorized data and applications;
[0040] After the user successfully logs in, the national secret key negotiation module intervenes and negotiates with the client and the remote desktop service center to produce an encryption key for this data transmission; at the same time, the user identity multi-factor authentication module requires the user to use the personal digital certificate and dynamic token issued by the system for login verification to ensure the legitimacy of the user's identity;
[0041] When the user starts to operate the remote desktop and reads and writes data, the storage management module automatically encrypts and decrypts the data according to the encryption and decryption policies configured by the policy management module to ensure the security of the data during storage and transmission;
[0042] The traffic monitoring and protection module in the network communication protection unit monitors network traffic in real time, performs traffic data matching and analysis on key nodes at the network boundary and ingress and egress, and immediately initiates security policy interception once abnormal traffic or attack behavior is found, and sends an alarm message to the user;
[0043] After the user completes the operation and disconnects the remote desktop connection, the system records the operation log for subsequent auditing and analysis.
[0044] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device.
[0045] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0046] The program code included on the computer readable medium can be transmitted with any appropriate medium, including but not limited to wireless, electric wire, optical cable, RF, etc., or any suitable combination of the above. The computer program code for performing the operation of the present invention can be written in one or more programming languages or their combinations, and the programming language includes object-oriented programming languages-such as Java, Smalltalk, C++, and also includes conventional procedural programming languages-such as "C" language or similar programming languages. The program code can be executed completely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on the remote computer, or completely on the remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).
[0047] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment as above, it is not used to limit the present invention. Any technical personnel in this field can make some changes or modify the technical contents disclosed above into equivalent embodiments without departing from the scope of the technical solution of the present invention. However, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present invention without departing from the content of the technical solution of the present invention still fall within the scope of the technical solution of the present invention.
Claims
1. A digital asset protection system, characterized in that: include: Data storage encryption unit, network communication protection unit and remote desktop control unit; The data storage encryption unit encrypts and decrypts the electronic data and performs storage management, configures the data protection key and encryption and decryption strategy for the storage protection data, and after the configuration is completed, the data is automatically encrypted and decrypted when performing read and write operations; The network communication protection unit is used to perform identity authentication and security authentication on users; The remote desktop control unit is responsible for performing security control on the remote desktop to ensure that only authorized users can access and operate the remote desktop.
2. The system according to claim 1, characterized in that The data storage encryption unit includes a key management module, a storage management module, a policy management module and a data encryption and decryption module; the key management module obtains the SM4 key from the national secret security device and encrypts and stores it in the system, which is used to encrypt and decrypt electronic data; The storage management module is used to obtain user data management protection information, extract corresponding storage protection data according to the user data management protection information and perform storage management; the policy management module is used to configure data protection keys and encryption and decryption policies for the storage protection data, and the storage protection data is automatically encrypted and decrypted when read and write operations are performed after the configuration is completed.
3. The system according to claim 1, characterized in that The network communication protection unit includes a national secret SSL VPN module, a security authentication module, and a traffic monitoring protection module; the national secret SSL VPN module is used to provide secure data transmission protection and anti-tampering capabilities for users to access home data in the public network based on national secret security equipment; the security authentication module authenticates the user based on national secret PKI technology and dynamic password technology; The traffic monitoring protection module monitors network traffic based on security policies, automatically intercepts risky or abnormal connection requests and data, and sends an alarm message to the user when an abnormality is found.
4. The system according to claim 1, characterized in that The remote desktop control unit includes a client, a remote desktop service center, a national secret key negotiation module, and a user identity multi-factor authentication module; the client is connected to the remote desktop service center through the dial-up function of the built-in national secret SSLVPN module for encrypted transmission and access to stored data; The remote desktop service center performs hierarchical authority management on the user's application permissions and data permissions; the national secret key negotiation module is used to encrypt the encryption key of data in the data transmission between the client and the remote desktop service center; the user identity multi-factor authentication module is used to control the user to log in to the client according to the personal digital certificate and dynamic token issued by the system.
5. The system according to claim 1, characterized in that The encryption and decryption strategy of the policy management module is to use a symmetric encryption algorithm to perform encryption and decryption processing on the data transmission information of the client, the data storage encryption unit, and the data storage area.
6. The system according to claim 1, characterized in that The identity authentication method of the security authentication module is: the user's identity information and public key are bound by the digital certificate issued to the user by the system, and the digital signature of the digital certificate is verified by the authentication center. If the verification is successful, the system sends random string information to the user through dynamic password technology, and the user signs the random string information with the user's private key and then sends back the identity authentication information. The system performs identity identification and analysis on the user based on the identity authentication information.
7. The system according to claim 1, characterized in that The security strategy of the traffic monitoring protection module is to perform matching analysis on the traffic data of key nodes at the network boundary and network entrances and exits based on a rule base.
8. The system according to claim 7, characterized in that The rule base includes normal traffic baseline rules, security policy rules, anomaly monitoring rules, equipment and application rules.
9. The system according to claim 8, characterized in that The rule base includes normal traffic baseline rules, security policy rules, anomaly monitoring rules, equipment and application rules; the normal traffic baseline rules are used to define the traffic rate, protocol type, and packet size under normal circumstances; the security policy rules contain the organization's security policy, which is used to allow and deny specific ports and protocols; the anomaly monitoring rules are combined with the rules of the intrusion detection system and the intrusion prevention system to identify the characteristics of known attacks; The device and application rules are used to perform in-depth analysis on the traffic of the application layer protocol.
10. A digital asset protection method applied to the digital asset protection system according to any one of claims 1 to 9, characterized in that: include: The user initiates a remote desktop connection request through the client, and the client establishes an encrypted connection with the remote desktop service center through the dial-up function of the built-in national secret SSL VPN module; After receiving the connection request, the remote desktop service center performs hierarchical permission management on the user's application permissions and data permissions based on the user's identity information and permission level; After the user successfully logs in, the national secret key negotiation module intervenes and negotiates with the client and the remote desktop service center to determine the encryption key for this data transmission; at the same time, the user identity multi-factor authentication module requires the user to use the personal digital certificate and dynamic token issued by the system for login verification; When the user starts to operate the remote desktop and reads and writes data, the storage management module automatically encrypts and decrypts the data according to the encryption and decryption policies configured by the policy management module; The traffic monitoring protection module in the network communication protection unit monitors network traffic in real time, performs traffic data matching analysis on key nodes at the network boundary and ingress and egress, and sends warning messages to users; After the user completes the operation and disconnects the remote desktop connection, the system records the operation log.
Citation Information
Patent Citations
Domestic commercial cryptography algorithm based cloud storage encryption system and implementation method thereof
CN104462998A
Private cloud platform data encryption and decryption system based on national cryptographic algorithm
CN111865609A
Computer network engineering safety control system
CN117155678A
Mobile office data security access system based on encrypted mirror image transmission
CN118433704A
Dynamic password authentication method based on digital certificate implement
CN1477810A