Key management method and system based on security verification device
By introducing a key management method based on a security verification device in the key management system, including key partitioning, identity authentication, key self-checking and behavior monitoring, the shortcomings of key management in the prior art under complex security threats are solved, and more efficient and secure key management is achieved.
Patent Information
- Application Number
- CN202510153668.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-12
AI Technical Summary
When facing complex security threats, existing key management methods are difficult to effectively deal with key storage leakage, hijacking threats during distribution, and improper permission control, especially in distributed network environments.
Using a key management method based on a security verification device, by obtaining the permission function analysis of the target database, the key is associated with the permission function for key partitioning, and authentication and permission matching are performed when receiving the user key generation request. At the same time, a key self-checking mechanism is set, the key is checked and updated regularly, and the user's key request behavior is monitored, and a feature image is generated for risk monitoring.
It improves the reliability and security of key management, enhances the security of key protection and distribution, reduces potential security risks, and realizes dynamic and efficient key management.
Smart Images

Figure CN120012160A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key management, and in particular to a key management method and system based on a security verification device. Background Art
[0002] Existing key management methods play an important role in information systems and are widely used in communication, storage, encrypted transactions and other scenarios. The core is to ensure the security and availability of keys. However, with the development of information technology, the security threats faced by key management systems have become increasingly complex, including the risk of key storage leakage, the threat of hijacking during the distribution process, and improper authority control in the key use process. For example, in a distributed network environment, due to the diversity of nodes and the uncertainty of communication links, keys may be illegally intercepted or tampered with, which poses a serious threat to the overall security of the system. In addition, traditional key management methods usually rely on a fixed key storage structure or distribution mechanism. When the system is abnormal or faces a high-risk environment, it is difficult to respond in a timely and effective manner, which may lead to data leakage, user information loss and unforeseen consequences. Summary of the invention
[0003] The present invention overcomes the defects of the prior art and provides a key management method and system based on a security verification device, the important purpose of which is to improve the reliability and security of key management.
[0004] To achieve the above-mentioned purpose, the first aspect of the present invention provides a key management method based on a security verification device, comprising: Obtain a target database that needs to be securely managed, perform authority function analysis on the data stored in the target database, associate keys with authority functions to perform key partitioning, and associate the data stored in the target database with corresponding key partition levels; When receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis shows that the request content matches the permission level, the request data type is extracted to generate an initial key for storage. Setting a key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period; Monitor the target user's key request behavior to obtain historical key request monitoring information, and analyze the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; A feature profile of the target user is generated based on the historical key request habit information and associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed using the corresponding feature profile.
[0005] In this solution, the target database to be managed securely is obtained, the authority function analysis is performed on the data stored in the target database, the key is associated with the authority function to perform key partitioning, and the data stored in the target database is associated with the corresponding key partition level, specifically including: Obtain the target database that needs to be managed securely, obtain a list of all users and roles based on the target database, traverse each user and role to extract permission features, and obtain permission extraction information; Extracting data access scope features corresponding to different permission levels according to the permission extraction information, analyzing access modes of different permission levels to stored data based on the extracted access scope features, and obtaining access mode analysis information; Defining authority functions of each authority level based on the access mode analysis information, associating corresponding authority functions with accessible data types and ranges, and obtaining first analysis information; Perform a key partitioning operation according to the first analysis information, define primary permissions and secondary permissions by the type and range of data accessed by each permission, define a partition key based on the primary permission type and the secondary permission type, and obtain key partitioning information; The data stored in the target database is associated with the corresponding key partition level according to the key partition information, and different key partition levels correspond to different data types.
[0006] In this solution, when receiving the key generation request from the target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis request content matches the permission level, the request data type is extracted to generate an initial key for storage, which specifically includes: The target user sends a key generation request to the target security verification device through a system associated with the target security verification device. When the target security verification device receives the key generation request from the target user, it sends an identity authentication request to the target user to collect identity information; Acquire identity collection information, the identity collection information including biometric identity information and data identity information, compare and analyze the identity collection information with the identity data stored in the target database to determine whether the person is a known identity person; If the target user is a known person, the target user's permission characteristics are extracted to analyze whether the target user has the permission to request key generation; if the target user has the permission, the request data type is extracted through the target user's key generation request information to generate a random key seed; Perform encryption operation on the generated random key seed and the preset security parameter to generate an initial key, store the initial key in the encryption storage unit of the security verification device, and record the key generation time and generator information; When the target security verification device receives the key distribution request, it extracts the key from the encryption storage unit for encryption and packaging after passing the identity verification, and sends the packaged key to the key distribution request user through the secure communication channel.
[0007] In this solution, the key self-checking mechanism is set to check and update the key stored in the encryption storage unit within a preset period through the key self-checking mechanism, specifically including: Extracting the initial keys stored in the target security verification device, clustering the keys based on the partition level of each initial key, and obtaining initial key sets of different partition levels; Perform feature extraction on each initial key set to convert the key into a feature vector, introduce a local sensitive hashing algorithm, and calculate the hash value and index value of each initial key in each initial key set; Creating a hash table, mapping each initial key set and the hash value and index value of each initial key to the hash table, wherein the key of the hash table is the hash value, and the value of the hash table is the index value of the corresponding initial key; Constructing hash chains of different key partitions based on the hash table, and performing key self-checking on the initial key set of each partition level according to a preset period through the hash chains of different key partitions; By calculating the hash value and index value of each initial key in the target initial key set when performing key self-check, and forming a self-checking hash chain, it is compared and analyzed with the stored hash chain; If the self-checking hash chain is inconsistent with the stored hash chain, it means that there is a risk of abnormal key tampering, then the abnormal hash chain position is extracted, and the abnormal initial key is obtained through the abnormal hash chain position; Based on the abnormal initial key, data associated with the abnormal initial key is obtained from the target database, the key is regenerated to obtain a new initial key, the abnormal initial key is replaced by the new initial key, and the hash value and index value of the new initial key are calculated and updated in the stored hash chain.
[0008] In this solution, the target user's key request behavior is monitored to obtain historical key request monitoring information, and the target user's historical key request habits are analyzed based on the historical key request monitoring information to obtain historical key request habit information, which specifically includes: The target security verification device monitors the target user's key request behavior to obtain historical key request monitoring information, wherein the historical key request monitoring information includes user request environment information and user usage behavior information; Introducing a long short-term memory network, and initializing the input layer, hidden layer, and output layer of the long short-term memory network, importing the historical key request monitoring information as input features into the input layer, and taking the historical key request habits of the target user as output targets of the output layer; The time series processing capability of the long short-term memory network is used to extract historical key request monitoring features, and the stacked autoencoder is used to perform feature encoding reconstruction to obtain the reconstructed historical key request monitoring features; A learnable embedding dictionary is set in the hidden layer of the long short-term memory network to represent the time point of the target user's key request behavior, and the spatiotemporal correlation between the target user's historical key request monitoring features and the time nodes is analyzed to generate spatiotemporal correlation features; According to the spatiotemporal correlation feature, a multi-head self-attention mechanism is used to measure the contribution of each historical key request behavior feature of the target user in all request behavior features, and the importance of the corresponding request behavior feature is represented by the contribution to obtain the feature weight distribution; The historical key request habit of the target user performing key request behavior through the security verification device is output according to the feature weight distribution in combination with the spatiotemporal correlation feature to obtain the historical key request habit information.
[0009] In this solution, the characteristic profile of the target user is generated according to the historical key request habit information, and is associated with the corresponding user log. When the target user makes the next request, risk monitoring is performed through the corresponding characteristic profile, specifically including: Obtain historical key request habit information, import the historical key request habit information into a graph neural network, convert the target user's historical key request habits into a graph data format through the graph neural network, and construct a request behavior feature profile of the target user; A request behavior database is set in the target security verification device, and a request behavior feature profile of each user is stored in the request behavior database to monitor abnormal risks when the user performs key request behavior; When the target user makes the next key request, the target security verification device monitors the target user's real-time key request environment and behavior to obtain real-time key request monitoring information, and performs data preprocessing on the obtained real-time key request monitoring information; Generate a search tag through the identity information of the target user, search the request behavior database to obtain the request behavior feature portrait of the target user, and perform similarity calculation with the pre-processed real-time key request information to obtain a cosine similarity value; The calculated cosine similarity value is compared with the preset threshold. If it is greater than the preset threshold, it means that the current key request behavior of the target user is normal. Then, based on the key request requirement of the target user, the corresponding initial key is obtained for encryption and transmission; If it is less than the preset threshold, it means that the current key request behavior of the target user is an abnormal request behavior. Then, the difference between the target user's real-time request behavior and the historical request behavior is analyzed through the target user's request behavior profile to obtain the difference behavior analysis information; A preset risk control strategy corresponding to the differential behavior analysis information is retrieved, and the real-time key request behavior of the target user is controlled according to the obtained risk control strategy.
[0010] A second aspect of the present invention provides a key management system based on a security verification device, the system comprising: a memory, a processor, the memory containing a key management method program based on a security verification device, the key management method program based on a security verification device when executed by the processor implements the following steps: Obtain a target database that needs to be securely managed, perform authority function analysis on the data stored in the target database, associate keys with authority functions to perform key partitioning, and associate the data stored in the target database with corresponding key partition levels; When receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis shows that the request content matches the permission level, the request data type is extracted to generate an initial key for storage. Setting a key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period; Monitor the target user's key request behavior to obtain historical key request monitoring information, and analyze the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; A feature profile of the target user is generated based on the historical key request habit information and associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed using the corresponding feature profile.
[0011] The present invention discloses a key management method and system based on a security verification device, including: performing authority function analysis on data stored in a target database, partitioning keys after associating keys with authority functions, and associating data with corresponding key partition levels. When a key generation request from a target user is received, identity authentication is performed; if the verification is successful and the user authority level matches the request content, an initial key is generated and stored according to the request data type. The method sets a key self-verification mechanism to periodically verify and update the stored keys. At the same time, the key request behavior of the target user is monitored, historical request monitoring information is extracted, and the historical request habits of the target user are obtained through analysis, and a feature portrait is generated and associated with the user log. In subsequent requests, risk monitoring is performed based on the user portrait, thereby achieving efficient and secure dynamic key management, and effectively improving the security and intelligence level of the key management system. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the embodiments or exemplary embodiments of the present invention, the drawings required for use in the embodiments or exemplary descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained according to the drawings without paying creative work.
[0013] Figure 1 A flow chart of a key management method based on a security verification device provided by an embodiment of the present invention; Figure 2 A flow chart of a method for monitoring abnormal key requests provided by an embodiment of the present invention; Figure 3 A block diagram of a key management system based on a security verification device provided by an embodiment of the present invention; The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0014] In order to more clearly understand the above-mentioned purpose, features and advantages of the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.
[0015] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited to the specific embodiments disclosed below.
[0016] Figure 1A flow chart of a key management method based on a security verification device provided by an embodiment of the present invention; like Figure 1 As shown, the present invention provides a flow chart of a key management method based on a security verification device, including: S102, obtaining a target database that needs to be security managed, performing authority function analysis on the data stored in the target database, associating keys with authority functions to perform key partitioning, and associating the data stored in the target database with corresponding key partition levels; S104, upon receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's authority level analysis shows that the request content matches the authority level, the request data type is extracted to generate an initial key for storage; S106, setting a key self-checking mechanism, and verifying and updating the key stored in the encryption storage unit within a preset period through the key self-checking mechanism; S108, monitoring the target user's key request behavior to obtain historical key request monitoring information, and analyzing the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; S110, generating a characteristic profile of the target user according to the historical key request habit information, associating it with the corresponding user log, and performing risk monitoring through the corresponding characteristic profile when the target user makes a request next time.
[0017] It should be noted that the present invention provides a key management method and system based on a security verification device. First, the data in the target database is analyzed for authority and function, and the key is associated with the corresponding authority and function according to the authority level of the data, and the key is partitioned according to the analysis result. At the same time, the data in the target database is associated with the corresponding key partition level to ensure that the mapping of data and key is consistent and secure. When the system receives a key generation request from the target user, the identity of the target user is first verified. If the verification is passed and the user's authority level matches the request content, the data type contained in the request is extracted, and the initial key is generated according to the data characteristics, and stored, thereby ensuring the accuracy of the generated key and the specificity of use. In order to ensure the long-term validity and security of the key, the present invention sets a key self-verification mechanism, which automatically verifies and updates the key stored in the encryption storage unit within a preset time period, reduces the risk of key leakage through a regular verification mechanism, and improves the security of the system. In addition, the present invention monitors the key request behavior of the target user in real time, extracts the monitoring information of the key request by recording and analyzing the historical request behavior of the target user, and mines the key request habits of the user based on these historical information. Based on the acquired habit information, the user's feature profile is further generated and correlated with the corresponding user log to establish a reference for risk monitoring for subsequent requests. When the target user initiates the next key request, the system will use its feature profile to determine whether the request has potential risks, and combine historical data with the degree of matching between the current request content to efficiently identify abnormal behavior, thereby achieving a dynamic, efficient, and secure key management process.
[0018] Further, in a preferred embodiment of the present invention, the step of obtaining a target database that needs to be securely managed, performing authority function analysis on data stored in the target database, associating keys with authority functions to perform key partitioning, and associating data stored in the target database with corresponding key partition levels specifically includes: Obtain the target database that needs to be managed securely, obtain a list of all users and roles based on the target database, traverse each user and role to extract permission features, and obtain permission extraction information; Extracting data access scope features corresponding to different permission levels according to the permission extraction information, analyzing access modes of different permission levels to stored data based on the extracted access scope features, and obtaining access mode analysis information; Defining authority functions of each authority level based on the access mode analysis information, associating corresponding authority functions with accessible data types and ranges, and obtaining first analysis information; Perform a key partitioning operation according to the first analysis information, define primary permissions and secondary permissions by the type and range of data accessed by each permission, define a partition key based on the primary permission type and the secondary permission type, and obtain key partitioning information; The data stored in the target database is associated with the corresponding key partition level according to the key partition information, and different key partition levels correspond to different data types.
[0019] It should be noted that, first, a target database that needs to be managed securely is obtained, and a list of all users and roles is extracted based on the database. Based on the obtained user and role information, each user and role is traversed one by one, and permission features are extracted, and permission information corresponding to each user and role is extracted to form permission extraction information. Subsequently, according to the extracted permission information, the data access scope features corresponding to different permission levels are further analyzed, and by summarizing and analyzing these access scope features, the access modes of different permission levels to the target database storage data are explored, thereby generating access mode analysis information. After completing the analysis of the access mode, the permissions are further defined based on the obtained access mode analysis information. Specifically, corresponding permission functions are divided for each permission level, and these permission functions are associated with the accessible data types and access scopes, thereby generating first analysis information. On this basis, for the generated first analysis information, the method implements a key partitioning operation. By analyzing the characteristics of each permission level on the data access type and access scope, the categories of primary permissions and secondary permissions are delineated, and the partition key is further defined based on the primary permission type and secondary permission type, and finally the key partition information is obtained. Through the key partition information, the data stored in the target database can be associated with the corresponding key partition level, so that different key partition levels can accurately correspond to specific data types. Through such a partition management mechanism, this method not only enhances the hierarchy of data protection, but also improves the matching and security of key management and data access, and effectively reduces the potential security risks caused by cross-authority access.
[0020] Further, in a preferred embodiment of the present invention, when receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis request content matches the permission level, the request data type is extracted to generate an initial key for storage, specifically including: The target user sends a key generation request to the target security verification device through a system associated with the target security verification device. When the target security verification device receives the key generation request from the target user, it sends an identity authentication request to the target user to collect identity information; Acquire identity collection information, the identity collection information including biometric identity information and data identity information, compare and analyze the identity collection information with the identity data stored in the target database to determine whether the person is a known identity person; If the target user is a known person, the target user's permission characteristics are extracted to analyze whether the target user has the permission to request key generation; if the target user has the permission, the request data type is extracted through the target user's key generation request information to generate a random key seed; Perform encryption operation on the generated random key seed and the preset security parameter to generate an initial key, store the initial key in the encryption storage unit of the security verification device, and record the key generation time and generator information; When the target security verification device receives the key distribution request, it extracts the key from the encryption storage unit for encryption and packaging after passing the identity verification, and sends the packaged key to the key distribution request user through the secure communication channel.
[0021] It should be noted that when the target user initiates a key generation request through the system associated with the target security verification device, the target security verification device first receives the request and sends an identity authentication request to the target user to collect its identity information. The collected identity information includes biometric identity information and data identity information, which will be compared and analyzed with the identity data stored in the target database to determine whether the target user is a known identity person. If the comparison result shows that the user is a known identity person, the system further extracts the target user's authority characteristics and analyzes whether it has the key generation authority. If it is determined that the target user's authority meets the requirements, the system will extract the request data type according to the target user's key generation request information, and generate a random key seed based on this. The generated random key seed is then encrypted with the preset security parameters to generate an initial key. The initial key is stored in the encrypted storage unit in the security verification device, and the key generation time and related information of the generator are recorded to ensure the security of subsequent traceability and management. When the target security verification device receives a key distribution request, it will perform identity verification on the requesting user. After the identity verification passes, the corresponding key is extracted from the encrypted storage unit, and the extracted key is encrypted and encapsulated, and the encapsulated key is distributed to the key distribution request user through a secure communication channel. The entire process ensures that key generation and distribution are completed in a safe and reliable environment, improving the security and operational efficiency of the system.
[0022] Further, in a preferred embodiment of the present invention, the key self-checking mechanism is set, and the key stored in the encryption storage unit is checked and updated within a preset period by the key self-checking mechanism, specifically including: Extracting the initial keys stored in the target security verification device, clustering the keys based on the partition level of each initial key, and obtaining initial key sets of different partition levels; Perform feature extraction on each initial key set to convert the key into a feature vector, introduce a local sensitive hashing algorithm, and calculate the hash value and index value of each initial key in each initial key set; Creating a hash table, mapping each initial key set and the hash value and index value of each initial key to the hash table, wherein the key of the hash table is the hash value, and the value of the hash table is the index value of the corresponding initial key; Constructing hash chains of different key partitions based on the hash table, and performing key self-checking on the initial key set of each partition level according to a preset period through the hash chains of different key partitions; By calculating the hash value and index value of each initial key in the target initial key set when performing key self-check, and forming a self-checking hash chain, it is compared and analyzed with the stored hash chain; If the self-checking hash chain is inconsistent with the stored hash chain, it means that there is a risk of abnormal key tampering, then the abnormal hash chain position is extracted, and the abnormal initial key is obtained through the abnormal hash chain position; Based on the abnormal initial key, data associated with the abnormal initial key is obtained from the target database, the key is regenerated to obtain a new initial key, the abnormal initial key is replaced by the new initial key, and the hash value and index value of the new initial key are calculated and updated in the stored hash chain.
[0023] It should be noted that when the key management is performed through the security verification device, the stored key may be modified by abnormal personnel or other problems, resulting in the risk of tampering and loss of the key. Then, the stored initial key is extracted from the target security verification device, and cluster analysis is performed on the initial key according to the partition level, so as to form an initial key set of different partition levels. After obtaining the partitioned key set, feature extraction is performed on each initial key, and the extracted key feature is used to convert it into a feature vector. Subsequently, the local sensitive hashing algorithm is introduced to calculate the hash value and index value of each initial key in the set to generate a mapping basis for operation and management. Through the hash calculation results, a hash table is created to map the keys in different initial key sets and their corresponding hash values and index values to the hash table. Specifically, the key of the hash table is the hash value of the key, and the value is the index value of the corresponding initial key. After the construction of the hash table is completed, the hash chain of each key partition is further established based on this, and these hash chains are used to perform key self-verification operations on the initial key sets in different partition levels according to the preset period. During the self-checking process, the current hash value and index value of each initial key in the target initial key set are calculated, a new self-checking hash chain is generated, and it is compared and analyzed one by one with the original stored hash chain. If the comparison finds that the self-checking hash chain is inconsistent with the stored hash chain, it is determined that there may be a risk of key abnormality or tampering. In this case, the system further extracts the location of the abnormal hash chain and locates the specific initial key where the abnormality occurs. Subsequently, a new initial key is regenerated through the data in the target database associated with the abnormal initial key to replace the abnormal key. After the newly generated initial key is replaced, its corresponding hash value and index value are calculated synchronously, and the stored hash chain is updated to ensure the integrity of the hash chain and the security of the key system. It ensures that the problem can be quickly located and repaired when a key abnormality or security risk occurs, thereby improving the robustness and security level of the system.
[0024] Further, in a preferred embodiment of the present invention, the target user's key request behavior is monitored to obtain historical key request monitoring information, and the target user's historical key request habits are analyzed based on the historical key request monitoring information to obtain historical key request habit information, specifically including: The target security verification device monitors the target user's key request behavior to obtain historical key request monitoring information, wherein the historical key request monitoring information includes user request environment information and user usage behavior information; Introducing a long short-term memory network, and initializing the input layer, hidden layer, and output layer of the long short-term memory network, importing the historical key request monitoring information as input features into the input layer, and taking the historical key request habits of the target user as output targets of the output layer; The time series processing capability of the long short-term memory network is used to extract historical key request monitoring features, and the stacked autoencoder is used to perform feature encoding reconstruction to obtain the reconstructed historical key request monitoring features; A learnable embedding dictionary is set in the hidden layer of the long short-term memory network to represent the time point of the target user's key request behavior, and the spatiotemporal correlation between the target user's historical key request monitoring features and the time nodes is analyzed to generate spatiotemporal correlation features; According to the spatiotemporal correlation feature, a multi-head self-attention mechanism is used to measure the contribution of each historical key request behavior feature of the target user in all request behavior features, and the importance of the corresponding request behavior feature is represented by the contribution to obtain the feature weight distribution; The historical key request habit of the target user performing key request behavior through the security verification device is output according to the feature weight distribution in combination with the spatiotemporal correlation feature to obtain the historical key request habit information.
[0025] It should be noted that, first of all, the key request behavior generated by the target user during use is comprehensively monitored, including the user's request environment information and the user's specific usage behavior information, which together constitute the historical key request monitoring information. Subsequently, the long short-term memory network (LSTM) is introduced, and the input layer, hidden layer and output layer of the network are initialized and configured. The historical key request monitoring information is used as the input feature of the input layer, and the historical key request habits of the target user are used as the target output of the output layer, which are trained and modeled through the network.
[0026] Taking advantage of the ability of the long short-term memory network to process time series data, the input historical key request monitoring information is deeply analyzed and feature extracted, and the extracted monitoring features are encoded and reconstructed in combination with the stacked autoencoder, so as to obtain the reconstructed historical key request monitoring features. On this basis, a learnable embedding dictionary is introduced in the hidden layer of the long short-term memory network to represent the time node when the target user's key request behavior occurs, and the spatiotemporal correlation relationship between the user's behavior characteristics and the time node is further analyzed to generate spatiotemporal correlation relationship features containing these relationships. In order to more accurately measure the importance of user behavior features, a multi-head self-attention mechanism is introduced to conduct an in-depth analysis of the user's historical key request behavior characteristics. This mechanism evaluates the contribution of each feature in all request behaviors according to the relative importance of the historical request behavior features, and quantifies the importance of each request behavior feature through the contribution information, thereby forming a feature weight distribution. Finally, the generated spatiotemporal correlation relationship features and feature weight distribution are combined to output the historical habit information of the target user's key request behavior based on the security verification device, so as to efficiently extract the temporal dynamic features and important patterns in the user's behavior, thereby providing reliable historical key request habit information and providing basic support for subsequent risk assessment and behavior modeling.
[0027] Further, in a preferred embodiment of the present invention, the feature profile of the target user is generated according to the historical key request habit information, and is associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed through the corresponding feature profile, specifically including: Obtain historical key request habit information, import the historical key request habit information into a graph neural network, convert the target user's historical key request habits into a graph data format through the graph neural network, and construct a request behavior feature profile of the target user; A request behavior database is set in the target security verification device, and a request behavior feature profile of each user is stored in the request behavior database to monitor abnormal risks when the user performs key request behavior; When the target user makes the next key request, the target security verification device monitors the target user's real-time key request environment and behavior to obtain real-time key request monitoring information, and performs data preprocessing on the obtained real-time key request monitoring information; Generate a search tag through the identity information of the target user, search the request behavior database to obtain the request behavior feature portrait of the target user, and perform similarity calculation with the pre-processed real-time key request information to obtain a cosine similarity value; The calculated cosine similarity value is compared with the preset threshold. If it is greater than the preset threshold, it means that the current key request behavior of the target user is normal. Then, based on the key request requirement of the target user, the corresponding initial key is obtained for encryption and transmission; If it is less than the preset threshold, it means that the current key request behavior of the target user is an abnormal request behavior. Then, the difference between the target user's real-time request behavior and the historical request behavior is analyzed through the target user's request behavior profile to obtain the difference behavior analysis information; A preset risk control strategy corresponding to the differential behavior analysis information is retrieved, and the real-time key request behavior of the target user is controlled according to the obtained risk control strategy.
[0028] It should be noted that the target user's historical key request habit information is obtained and imported into the graph neural network for processing, and the target user's historical key request habits are converted into a graph data format, thereby constructing a characteristic profile of the target user's request behavior. The characteristics and habitual behaviors of the user in the key request process are recorded in detail, providing data support for subsequent monitoring and analysis. After the construction is completed, the characteristic profile is stored in the request behavior database in the target security verification device, which is used to store the request behavior characteristic profiles of all users as an important basis for monitoring potential abnormal risks in the user's key request behavior. When the target user makes a key request again, the target security verification device will monitor the target user's request environment and behavior characteristics in real time and generate real-time key request monitoring information. After data preprocessing of these monitoring information, the processed data is associated with the target user's characteristic profile stored in the request behavior database, and the corresponding search tag is generated using the target user's identity information, and the target user's request behavior characteristic profile is quickly retrieved from the database. Subsequently, the preprocessed real-time monitoring information is similarity calculated with the historical profile, and the cosine similarity method is used to evaluate the consistency of the real-time behavior and the historical behavior, thereby obtaining a similarity value. Next, the calculated cosine similarity value is compared with the preset threshold. If the cosine similarity value is greater than the threshold, it indicates that the current key request behavior of the target user meets the characteristics of its historical request behavior and is normal behavior. At this time, the system will extract the corresponding initial key according to the specific key request requirements of the target user, and encrypt and securely transmit it. If the cosine similarity value is less than the preset threshold, it indicates that the current request behavior of the target user is abnormal. The system will analyze the request behavior profile of the target user, deeply compare the difference between the current real-time request behavior and the historical request behavior, and generate differential behavior analysis information. Finally, based on the above differential behavior analysis information, further retrieve the preset risk control strategy that matches the current abnormal behavior, and implement control on the key request behavior of the target user according to the strategy. Dynamic risk assessment and security response based on historical data and real-time monitoring are realized, providing an efficient security guarantee mechanism for key request behavior.
[0029] Figure 2 A flow chart of a method for monitoring abnormal key requests provided by an embodiment of the present invention; like Figure 2 As shown, the present invention provides a flow chart of a key request anomaly monitoring method, including: S202, obtaining historical key request monitoring information, taking the historical key request monitoring information as input, inputting the historical key request monitoring information into a long short-term memory network for analysis, and extracting historical key request monitoring features using the time series processing capability of the long short-term memory network; S204, using a stacked autoencoder to perform feature encoding reconstruction to obtain a reconstructed historical key request monitoring feature, analyzing the spatiotemporal correlation between the historical key request monitoring feature of the target user and the time node, and generating a spatiotemporal correlation feature; S206, using a multi-head self-attention mechanism to measure the contribution of each historical key request behavior feature of the target user in all request behavior features according to the spatiotemporal correlation relationship features, and finally obtaining historical key request habit information; S208, converting the target user's historical key request habits into a graph data format through a graph neural network and constructing a request behavior feature profile of the target user, which is stored in a request behavior database for monitoring abnormal risks when the user performs key request behavior; S210, when the target user makes the next key request, real-time key request monitoring information is obtained, a search tag is generated according to the identity information of the target user, and a request behavior feature portrait of the target user is obtained by searching the request behavior database; S212, calculate the similarity between the target user's request behavior feature portrait and the pre-processed real-time key request information to obtain a cosine similarity value, determine whether there is a risk, and retrieve the corresponding preset risk control strategy for control.
[0030] It should be noted that the historical key request monitoring information of the target user includes the environmental data and behavior data of the key request made by the user in the past period of time. Subsequently, the historical key request monitoring information is input into the long short-term memory network (LSTM) for in-depth analysis. As a special recurrent neural network, LSTM has a strong time series processing capability and can extract key features from historical key requests. These features reflect the key request behavior patterns of users at different time points. Next, the stacked autoencoder is used to encode and reconstruct the features extracted from LSTM to obtain the reconstructed historical key request monitoring features. This process helps to further refine and purify the features so that they can better represent the key request behavior of the user. Then, the spatiotemporal correlation relationship between these reconstructed features and time nodes is analyzed to generate spatiotemporal correlation relationship features. It reveals how the key request behaviors of users at different time nodes are related to each other. After obtaining the spatiotemporal correlation relationship features, the multi-head self-attention mechanism is used to measure the contribution of each historical key request behavior feature of the target user to all request behavior features. The multi-head self-attention mechanism can assign different weights to each feature, thereby identifying the features that have the greatest impact on user behavior. Finally, the historical key request habit information of the target user is obtained, which is a comprehensive summary of the user's past key request behavior. In order to more intuitively display the user's key request habits, the historical key request habits are converted into a graph data format through a graph neural network, and a request behavior feature portrait of the target user is constructed. This portrait graphically displays the user's key request behavior characteristics. When the user makes the next key request, real-time key request monitoring information is obtained, and a search tag is generated based on the user's identity information. Then, the request behavior feature portrait related to the user is retrieved from the request behavior database. By calculating the similarity between the real-time request information and the feature portrait, it is determined whether the current request is consistent with the user's historical behavior, thereby determining whether there is a potential risk. If a risk is detected, the corresponding preset risk control strategy will be retrieved, and corresponding measures will be taken to control it to ensure data security.
[0031] Furthermore, in a key management method based on a security verification device provided by the present invention, the following steps are also included: A self-protection mechanism is set based on the safety verification device, and the operation status of the target safety verification device is monitored through the set self-protection mechanism to obtain operation status monitoring information; Extracting the power supply characteristics of the internal power supply module of the target safety verification device according to the operation status monitoring information, and performing time sequencing to obtain a power supply characteristic sequence; Inputting the power supply feature sequence into an anomaly detection model constructed based on a generative adversarial network for model training, retaining the model parameters after the training is completed and outputting the trained anomaly detection model; The real-time power supply characteristics of the power supply module are obtained by real-time monitoring of the target safety monitoring device, and the real-time power supply characteristics are input into the abnormality detection model for analysis to determine whether an abnormal power supply condition occurs, thereby obtaining abnormal power supply detection information; The abnormal power supply detection information is compared with a preset threshold value. If the abnormal power supply detection information is less than the preset threshold value, it means that the target safety verification device has a power supply battery realization condition; When the power supply battery fails, the target security verification device provides a short power supply through the backup energy storage capacitor based on the set self-protection mechanism to perform a self-destruction operation on the stored key.
[0032] It should be noted that when the security verification device performs daily key management, when the corresponding power supply battery fails, human damage or abnormal intrusion may occur. In order to prevent the stored data from being leaked or the controlled equipment from being used abnormally, the stored keys need to be self-destructed to avoid abnormal risks. By setting a self-protection mechanism, a double-layer security detection mechanism is formed with the physical security detection mechanism set by the security verification device, so that after the physical security detection mechanism is bypassed, the software level can still identify abnormal conditions, thereby improving the security of key management.
[0033] Figure 3 A key management system 3 based on a security verification device is provided in one embodiment of the present invention. The system includes: a memory 31 and a processor 32. The memory 31 contains a key management method program based on a security verification device. When the key management method program based on a security verification device is executed by the processor 32, the following steps are implemented: Obtain a target database that needs to be securely managed, perform authority function analysis on the data stored in the target database, associate keys with authority functions to perform key partitioning, and associate the data stored in the target database with corresponding key partition levels; When receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis shows that the request content matches the permission level, the request data type is extracted to generate an initial key for storage. Setting a key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period; Monitor the target user's key request behavior to obtain historical key request monitoring information, and analyze the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; A feature profile of the target user is generated based on the historical key request habit information and associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed using the corresponding feature profile.
[0034] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0035] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0036] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0037] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: a mobile storage device, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.
[0038] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention can be essentially or partly reflected in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0039] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A key management method based on a security verification device, characterized in that: include: Obtain a target database that needs to be securely managed, perform authority function analysis on the data stored in the target database, associate keys with authority functions to perform key partitioning, and associate the data stored in the target database with corresponding key partition levels; When receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis shows that the request content matches the permission level, the request data type is extracted to generate an initial key for storage. Setting a key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period; Monitor the target user's key request behavior to obtain historical key request monitoring information, and analyze the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; A feature profile of the target user is generated based on the historical key request habit information and associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed using the corresponding feature profile.
2. A key management method based on a security verification device according to claim 1, characterized in that: The obtaining of the target database to be securely managed, performing authority function analysis on the data stored in the target database, associating the key with the authority function to perform key partitioning, and associating the data stored in the target database with the corresponding key partition level specifically includes: Obtain the target database that needs to be managed securely, obtain a list of all users and roles based on the target database, traverse each user and role to extract permission features, and obtain permission extraction information; Extracting data access scope features corresponding to different permission levels according to the permission extraction information, analyzing access patterns of different permission levels to stored data based on the extracted access scope features, and obtaining access pattern analysis information; Defining authority functions of each authority level based on the access mode analysis information, associating corresponding authority functions with accessible data types and ranges, and obtaining first analysis information; Perform a key partitioning operation according to the first analysis information, define primary permissions and secondary permissions by the type and range of data accessed by each permission, define a partition key based on the primary permission type and the secondary permission type, and obtain key partitioning information; The data stored in the target database is associated with the corresponding key partition level according to the key partition information, and different key partition levels correspond to different data types.
3. A key management method based on a security verification device according to claim 1, characterized in that: When receiving the key generation request from the target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis request content matches the permission level, the request data type is extracted to generate an initial key for storage, which specifically includes: The target user sends a key generation request to the target security verification device through a system associated with the target security verification device. When the target security verification device receives the key generation request from the target user, it sends an identity authentication request to the target user to collect identity information; Acquire identity collection information, the identity collection information including biometric identity information and data identity information, compare and analyze the identity collection information with the identity data stored in the target database to determine whether the person is a known identity person; If the target user is a known person, the target user's permission characteristics are extracted to analyze whether the target user has the permission to request key generation; if the target user has the permission, the request data type is extracted through the target user's key generation request information to generate a random key seed; Perform encryption operation on the generated random key seed and the preset security parameter to generate an initial key, store the initial key in the encryption storage unit of the security verification device, and record the key generation time and generator information; When the target security verification device receives the key distribution request, it extracts the key from the encryption storage unit for encryption and packaging after passing the identity verification, and sends the packaged key to the key distribution request user through the secure communication channel.
4. A key management method based on a security verification device according to claim 1, characterized in that: The setting of the key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period, specifically includes: Extracting the initial keys stored in the target security verification device, clustering the keys based on the partition level of each initial key, and obtaining initial key sets of different partition levels; Perform feature extraction on each initial key set to convert the key into a feature vector, introduce a local sensitive hashing algorithm, and calculate the hash value and index value of each initial key in each initial key set; Creating a hash table, mapping each initial key set and the hash value and index value of each initial key to the hash table, wherein the key of the hash table is the hash value, and the value of the hash table is the index value of the corresponding initial key; Constructing hash chains of different key partitions based on the hash table, and performing key self-checking on the initial key set of each partition level according to a preset period through the hash chains of different key partitions; By calculating the hash value and index value of each initial key in the target initial key set when performing key self-checking, and forming a self-checking hash chain, it is compared and analyzed with the stored hash chain; If the self-checking hash chain is inconsistent with the stored hash chain, it means that there is a risk of abnormal key tampering, then the abnormal hash chain position is extracted, and the abnormal initial key is obtained through the abnormal hash chain position; Based on the abnormal initial key, data associated with the abnormal initial key is obtained from the target database, the key is regenerated to obtain a new initial key, the abnormal initial key is replaced by the new initial key, and the hash value and index value of the new initial key are calculated and updated in the stored hash chain.
5. A key management method based on a security verification device according to claim 1, characterized in that: The monitoring of the target user's key request behavior to obtain historical key request monitoring information, and analyzing the target user's historical key request habits based on the historical key request monitoring information to obtain the historical key request habit information specifically includes: The target security verification device monitors the target user's key request behavior to obtain historical key request monitoring information, wherein the historical key request monitoring information includes user request environment information and user usage behavior information; Introducing a long short-term memory network, and initializing the input layer, hidden layer, and output layer of the long short-term memory network, importing the historical key request monitoring information as input features into the input layer, and taking the historical key request habits of the target user as output targets of the output layer; The time series processing capability of the long short-term memory network is used to extract historical key request monitoring features, and the stacked autoencoder is used to perform feature encoding reconstruction to obtain the reconstructed historical key request monitoring features; A learnable embedding dictionary is set in the hidden layer of the long short-term memory network to represent the time point of the target user's key request behavior, and the spatiotemporal correlation between the target user's historical key request monitoring features and the time nodes is analyzed to generate spatiotemporal correlation features; According to the spatiotemporal correlation feature, a multi-head self-attention mechanism is used to measure the contribution of each historical key request behavior feature of the target user in all request behavior features, and the importance of the corresponding request behavior feature is represented by the contribution to obtain the feature weight distribution; The historical key request habit of the target user performing key request behavior through the security verification device is output according to the feature weight distribution in combination with the spatiotemporal correlation feature to obtain the historical key request habit information.
6. A key management method based on a security verification device according to claim 1, characterized in that: The generating of a characteristic profile of the target user according to the historical key request habit information and associating it with the corresponding user log, and performing risk monitoring through the corresponding characteristic profile when the target user makes a next request, specifically includes: Obtain historical key request habit information, import the historical key request habit information into a graph neural network, convert the target user's historical key request habits into a graph data format through the graph neural network, and construct a request behavior feature profile of the target user; A request behavior database is set in the target security verification device, and a request behavior feature profile of each user is stored in the request behavior database to monitor abnormal risks when the user performs key request behavior; When the target user makes the next key request, the target security verification device monitors the target user's real-time key request environment and behavior to obtain real-time key request monitoring information, and performs data preprocessing on the obtained real-time key request monitoring information; Generate a search tag through the identity information of the target user, search the request behavior database to obtain the request behavior feature portrait of the target user, and perform similarity calculation with the pre-processed real-time key request information to obtain a cosine similarity value; The calculated cosine similarity value is compared with the preset threshold. If it is greater than the preset threshold, it means that the current key request behavior of the target user is normal. Then, based on the key request requirement of the target user, the corresponding initial key is obtained for encryption and transmission; If it is less than the preset threshold, it means that the current key request behavior of the target user is an abnormal request behavior. Then, the difference between the target user's real-time request behavior and the historical request behavior is analyzed through the target user's request behavior profile to obtain the difference behavior analysis information; A preset risk control strategy corresponding to the differential behavior analysis information is retrieved, and the real-time key request behavior of the target user is controlled according to the obtained risk control strategy.
7. A key management system based on a security verification device, characterized in that: The system includes: a memory and a processor, wherein the memory includes a key management method program based on a security verification device, and when the key management method program based on a security verification device is executed by the processor, the following steps are implemented: Obtain a target database that needs to be securely managed, perform authority function analysis on the data stored in the target database, associate keys with authority functions to perform key partitioning, and associate the data stored in the target database with corresponding key partition levels; When receiving a key generation request from a target user, the target user is authenticated. If the authentication is successful and the target user's permission level analysis shows that the request content matches the permission level, the request data type is extracted to generate an initial key for storage. Setting a key self-checking mechanism, through which the key stored in the encryption storage unit is checked and updated within a preset period; Monitor the target user's key request behavior to obtain historical key request monitoring information, and analyze the target user's historical key request habits based on the historical key request monitoring information to obtain historical key request habit information; A feature profile of the target user is generated based on the historical key request habit information and associated with the corresponding user log. When the target user makes a next request, risk monitoring is performed using the corresponding feature profile.
Citation Information
Patent Citations
Storage for encrypted data with enhanced security
CN107113292A
Authority management method and device based on secret key, medium and electronic equipment
CN111783075A
User information grading protection method and system
CN115422557A
Enterprise-level data encryption and access control method and system
CN118410505A
Security management and retrieval method based on Internet of Vehicles data
CN119150349A
Cited By
Key management method and system based on security verification
CN120915441A
Key management method and system based on security check
CN120915441B
Electronic component security authentication method and system
CN120974506A
Key governance method for binding key purpose and data security semantic obligation
CN122204319A