Multi-certificate synchronous management method and system
By assigning attributes to the digital signature server and encrypting associations using the ABE algorithm, fine-grained access control of digital certificates is achieved, solving the problems of extensive access management, easy encryption and low synchronization efficiency in traditional certificate management systems, and improving the flexibility and security of the system.
Patent Information
- Application Number
- CN202510142868.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When traditional digital certificate management systems face large-scale and diversified certificate management needs, there are problems such as excessive access management, easy encryption algorithms to be cracked, and high latency and low efficiency of synchronization mechanisms.
A multi-certificate synchronization management method is proposed. By defining attributes related to digital certificates, assign attributes to each digital signature server, and encrypting certificate information using the ABE algorithm, and associate certificate information with attributes during the encryption process. Then, verify that the attributes provided by the digital signature server match the attributes associated with the target digital certificate when encrypting, and if so, decryption and acquisition of certificate information are allowed.
It realizes fine-grained access control based on attributes, improves the flexibility and security of the system, ensures that only servers that meet specific attributes can access or synchronize digital certificate information, effectively prevent unauthorized access, and protects the confidentiality and integrity of digital certificates.
Smart Images

Figure CN120017275A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital certificate management, and in particular to a multi-certificate synchronization management method and system. Background Art
[0002] In traditional digital certificate management systems, certificates are usually stored centrally on one or more servers for clients or servers to access and synchronize when needed. However, with the rise of emerging technologies such as cloud computing, the Internet of Things, and big data, the number and types of digital certificates have increased dramatically, and the requirements for certificate management have also increased. Traditional certificate management methods have gradually exposed problems such as low efficiency and insufficient security. Specifically, there are some of the following defects:
[0003] 1. Traditional certificate management systems often use role-based access control (RBAC) or access control list (ACL)-based methods, which are inadequate when faced with large-scale and diverse certificate management needs. They cannot provide fine-grained access control based on the characteristics and usage scenarios of certificates, resulting in overly extensive access rights management, which can easily lead to security risks.
[0004] Second, traditional certificate encryption methods often rely on a single encryption algorithm or key. Once the encryption algorithm is cracked or the key is leaked, the entire certificate management system will face serious security threats. In addition, traditional encryption methods are often not closely integrated with the attributes and usage scenarios of the certificate, resulting in limited encryption effects and inability to effectively resist attacks targeting specific attributes.
[0005] 3. In a distributed environment, traditional certificate management systems often need to use complex synchronization mechanisms to maintain the consistency of certificates on each node. However, this synchronization mechanism often has problems such as high latency and low efficiency, and cannot meet application scenarios with high real-time requirements. Summary of the invention
[0006] Based on this, the purpose of the present invention is to propose a multi-certificate synchronization management method and system to solve the above-mentioned problems.
[0007] A multi-certificate synchronization management method proposed in the present invention is applied to a digital certificate management platform, and the method includes:
[0008] Defines a set of attributes associated with digital certificates;
[0009] Assigning attributes to each digital signature server;
[0010] When there is a new digital certificate or a digital certificate to be updated, the certificate information is encrypted using the ABE algorithm. During the encryption process, the digital certificate information is associated with a set of attributes;
[0011] When the digital signature server issues a request to access or synchronize the target digital certificate, the attribute information provided by the digital signature server is obtained, and its attributes are verified to match the attributes associated with the target digital certificate when it is encrypted;
[0012] If they match, the digital signature server is allowed to decrypt and obtain the digital certificate information.
[0013] Furthermore, the assignment of attributes to each digital signature server includes:
[0014] Assign a set of initial attributes to the digital signature server based on its identity, role, authority or business requirements;
[0015] Building a risk assessment model based on random forest, and using the risk assessment model to perform real-time analysis on the behavior pattern of the digital signature server to predict potential security risks in real time and output a risk score for the digital signature server;
[0016] The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes.
[0017] Furthermore, the risk assessment model is used to analyze the behavior pattern of the digital signature server in real time to predict potential security risks in real time and output a risk score of the digital signature server, including:
[0018] Obtaining behavior data of the digital signature server to be predicted;
[0019] Extracting key features from the behavior data and inputting them into each decision tree of the risk assessment model, wherein the key features include one or more feature vectors;
[0020] By using each decision tree of the risk assessment model, according to its splitting rule, the data samples are distributed to different leaf nodes, wherein each leaf node represents a predicted value of a risk score;
[0021] The predicted values of the risk scores of all decision trees are averaged to obtain the final prediction result, which is the risk score of the digital signature server.
[0022] Furthermore, each decision tree of the risk assessment model distributes the data samples to different leaf nodes according to its splitting rule, wherein each leaf node represents a predicted value of a risk score, including:
[0023] For each decision tree, starting from the root node, the input feature data is assigned to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes;
[0024] The assigned child node is used as the new current node;
[0025] Based on the features and splitting rules used on the current node, the feature data is distributed to the next child node until a leaf node is reached;
[0026] When feature data is assigned to a leaf node, the risk score prediction value represented by the corresponding leaf node is used as the prediction result of the risk score of the current decision tree.
[0027] Furthermore, starting from the root node, the input feature data is distributed to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes, including:
[0028] Starting from the root node, select a feature as the split feature according to the split rule used on the current node;
[0029] For the selected splitting feature, a splitting threshold is calculated;
[0030] For the input feature data, its value on the selected split feature is compared with the split threshold;
[0031] If it is less than or equal to the split threshold, the feature data is assigned to the left child node;
[0032] If it is greater than the split threshold, the feature data is assigned to the right child node.
[0033] Furthermore, the initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes, including:
[0034] When the risk score of the digital signature server rises to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a high security level to a medium security level, and the levels of some of its sensitive attributes are reduced accordingly;
[0035] When the risk score of the digital signature server continues to rise and exceeds a second preset threshold, the security level of the digital signature server is adjusted from a medium security level to a low security level, and the levels of all or specific sensitive attributes thereof are removed.
[0036] Furthermore, the initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes, including:
[0037] When the risk score of the digital signature server drops to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a low security level to a medium security level, and the levels of some of its sensitive attributes are increased;
[0038] When the risk score of the digital signature server continues to decrease and is lower than a first preset threshold, the security level of the digital signature server is adjusted from a medium security level to a high security level, and the level of its sensitive attributes is fully restored to increase its access rights.
[0039] Furthermore, the verifying whether the attribute matches the attribute associated with the target digital certificate when it is encrypted includes:
[0040] An attribute verification model is constructed to verify whether the attributes of the digital signature server match the attributes associated with the digital certificate during encryption.
[0041] Furthermore, the verifying by the attribute verification model whether the attribute of the digital signature server matches the attribute associated with the digital certificate during encryption includes:
[0042] Extracting a first attribute feature from the attribute information associated with the digital certificate when it is encrypted;
[0043] Extracting a second attribute feature from the attribute information of the digital signature server;
[0044] Combining the first attribute feature and the second attribute feature into a target feature vector;
[0045] The target feature vector is input into the attribute verification model, and after calculation in the hidden layer, it finally reaches the output layer, and the probability of the attribute matching between the two is output;
[0046] If the probability of attribute matching is greater than the preset probability threshold, it is determined to be a match; otherwise, it is determined to be a mismatch.
[0047] The present invention also proposes a multi-certificate synchronization management system, which is used to implement the multi-certificate synchronization management method mentioned above, and the system includes:
[0048] Attribute definition module: used to define a set of attributes related to digital certificates;
[0049] Attribute assignment module: used to assign attributes to each digital signature server;
[0050] Encryption association module: used to encrypt the certificate information using the ABE algorithm when there is a new digital certificate or a digital certificate to be updated. During the encryption process, the digital certificate information is associated with a set of attributes;
[0051] Attribute matching module: when the digital signature server issues a request to access or synchronize the target digital certificate, it obtains the attribute information provided by the digital signature server and verifies whether its attribute matches the attribute associated with the target digital certificate when it is encrypted;
[0052] Information acquisition module: used to allow the digital signature server to decrypt and obtain the digital certificate information if a match is found.
[0053] In summary, the multi-certificate synchronization management method of the present invention provides an attribute-based fine-grained access control mechanism, which ensures that only servers that meet specific attributes can access or synchronize digital certificate information by assigning specific attributes to digital signature servers and accurately matching them with the attributes associated with digital certificate encryption. This fine-grained access control not only improves the flexibility of the system, but also greatly enhances security, because even if attackers are able to break through certain defenses of the system, they must meet specific attribute requirements to access sensitive information, thereby effectively preventing unauthorized access and protecting the confidentiality and integrity of digital certificate information.
[0054] Secondly, in terms of data security, the attribute-based encryption algorithm is used to encrypt and protect the digital certificate information, allowing the data owner to define a set of attributes as encryption and decryption keys based on the sensitivity and access requirements of the data. In the present invention, after the digital certificate information is associated with a set of attributes, it is encrypted using the ABE algorithm, ensuring that even if the data is stolen during transmission, storage or processing, it cannot be decrypted by unauthorized users. This encryption method provides a high level of data protection and greatly reduces the risk of data leakage.
[0055] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description or will be learned through embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0057] Figure 1 This is a flow chart of a multi-certificate synchronization management method according to Embodiment 1 of the present invention;
[0058] Figure 2 This is a system block diagram of a multi-certificate synchronization management system according to Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0059] In order to facilitate the understanding of the present invention, the present invention will be described more fully below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.
[0060] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may be a central element. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be a central element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.
[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more related listed items.
[0062] Embodiment 1
[0063] See also Figure 1 The present invention proposes a multi-certificate synchronization management method, which is applied to a digital certificate management platform. The method includes steps S101 to S105:
[0064] S101, define a set of attributes related to the digital certificate.
[0065] By defining a set of attributes closely related to digital certificates, such as certificate holder, certificate type (such as SSL certificate, code signing certificate, etc.), issuer (specific certificate authority), validity period (the effective time range of the certificate), and security level (divided according to the purpose and importance of the certificate), the system can more finely manage access rights between different certificates. The selection of these attributes should be based on actual business needs and security policies to ensure that they can accurately reflect the characteristics and usage scenarios of the certificate.
[0066] S102, assigning attributes to each digital signature server.
[0067] The digital certificate management platform assigns corresponding attributes to each digital signature server. These attributes are related to the role, function or security requirements of the server, and may include basic attributes, security attributes, functional attributes, etc. For example, server name / identifier (used to uniquely identify each digital signature server, such as ServerA, ServerB, etc.), role (indicating the role of the server in the system, such as certificate issuance server, certificate verification server, etc.), security level (divided according to the importance and sensitivity of the certificate information processed by the server, where a high-security level server may be used to process certificates involving confidential or sensitive information, while a low-security level server may be used to process public or less sensitive certificates), access rights (defining which certificate information the server can access or which operations it can perform. Some servers may only be able to access specific types of certificates (such as SSL certificates) but not other types of certificates (such as code signing certificates)), supported certificate types (some servers may only support SSL certificates, while other servers may support multiple types such as SSL certificates and code signing certificates), processing capacity (how many certificate requests can be processed per second), etc.
[0068] By assigning attributes to digital signature servers, the system can precisely control which servers can access which certificate information based on these attributes. This fine-grained access control is more flexible and secure than traditional role-based or IP-based access control. Only servers with the corresponding attributes can decrypt and access specific certificate information, which greatly reduces the risk of unauthorized access and improves the overall security of the system. By assigning attributes, system administrators can manage and maintain servers more conveniently. For example, problem servers can be quickly located or batch operations can be performed based on the server's attributes.
[0069] S103, when there is a new digital certificate or a digital certificate to be updated, the certificate information is encrypted using the ABE algorithm. During the encryption process, the digital certificate information is associated with a set of attributes.
[0070] When there is a new digital certificate or a digital certificate to be updated, the ABE algorithm is used to encrypt the certificate information. The ABE algorithm is an attribute-based encryption technology that allows data owners to define a set of attributes as encryption and decryption keys based on the sensitivity and access requirements of the data. In this process, the system associates the digital certificate information with the previously defined attribute set, and only the digital signature server that meets these attributes can decrypt the certificate information. This encryption method not only improves data security, but also implements fine-grained access control.
[0071] S104, when the digital signature server issues a request to access or synchronize the target digital certificate, the attribute information provided by the digital signature server is obtained, and its attributes are verified to match the attributes associated with the target digital certificate when it is encrypted.
[0072] When a digital signature server issues a request to access or synchronize a target digital certificate, the digital signature server provides its attribute information to the digital management platform. The digital management platform verifies whether these attributes match the attributes associated with the target digital certificate when it is encrypted. This verification process is the core of attribute-based access control, ensuring that only servers with the correct attributes can access or synchronize specific certificate information.
[0073] S105: If they match, the digital signature server is allowed to decrypt and obtain the digital certificate information.
[0074] If the attributes of the digital signature server match the attributes associated with the target digital certificate when it is encrypted, the server will be allowed to decrypt and obtain the digital certificate information. The server will store the decrypted certificate information locally and perform subsequent certificate processing or verification operations as needed. This step achieves secure synchronization and management of certificate information and ensures the consistency and availability of digital certificates in a distributed environment.
[0075] Based on steps S101 to S105, the present invention provides an attribute-based fine-grained access control mechanism, which ensures that only servers that meet the specific attributes can access or synchronize digital certificate information by assigning specific attributes to the digital signature server and accurately matching the attributes associated with the digital certificate encryption. This fine-grained access control not only improves the flexibility of the system, but also greatly enhances security, because even if attackers are able to break through certain defenses of the system, they must meet specific attribute requirements to access sensitive information, thereby effectively preventing unauthorized access and protecting the confidentiality and integrity of digital certificate information.
[0076] Secondly, in terms of data security, the attribute-based encryption algorithm is used to encrypt and protect the digital certificate information, allowing the data owner to define a set of attributes as encryption and decryption keys based on the sensitivity and access requirements of the data. In the present invention, after the digital certificate information is associated with a set of attributes, it is encrypted using the ABE algorithm, ensuring that even if the data is stolen during transmission, storage or processing, it cannot be decrypted by unauthorized users. This encryption method provides a high level of data protection and greatly reduces the risk of data leakage.
[0077] The following is a further detailed introduction to a multi-certificate synchronization management method according to an embodiment of the present invention:
[0078] Further optionally, in step S102, the assigning of attributes to each digital signature server includes:
[0079] Assign a set of initial attributes to the digital signature server based on its identity, role, authority or business requirements;
[0080] Building a risk assessment model based on random forest, and using the risk assessment model to perform real-time analysis on the behavior pattern of the digital signature server to predict potential security risks in real time and output a risk score for the digital signature server;
[0081] The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes.
[0082] Understandably, based on the identity, role, authority or business needs of the digital signature server, a set of initial attributes is assigned to it, so that the server has appropriate permissions and configurations when it is initially deployed to meet its specific business needs and security requirements, such as the server's identity, role, access rights, and business needs. The digital signature server obtains a set of initial attributes that match its functions and responsibilities, which define the server's behavioral boundaries and authority scope.
[0083] The risk assessment model is then used to monitor and evaluate the server's behavior in real time, so as to timely discover and predict potential security risks. The risk assessment model built based on random forest is a powerful integrated learning method that is suitable for processing a large number of features and complex data relationships. It can effectively capture the behavior patterns of digital signature servers and predict risks. The model outputs a numerical value as a risk score, which represents the current security risk level of the server.
[0084] Then, the properties of the digital signature server are adjusted according to the changes in the risk score of the digital signature server, that is, its permissions and configurations are dynamically adjusted according to the real-time risk status of the server to reduce potential security risks. For example, when the risk score of the server increases, it indicates that the security status of the server may be threatened. At this time, by reducing the level of sensitive attributes or removing specific permissions, the potential scope of damage to the server can be limited. The server's properties are dynamically adjusted to adapt to its current security status and business needs. This adjustment helps to minimize security risks while maintaining business continuity.
[0085] This embodiment constructs a dynamic security management framework by combining initial attribute allocation, real-time risk assessment and dynamic attribute adjustment. The framework can flexibly adjust its permissions and configurations according to the real-time behavior and security status of the server, thereby effectively reducing security risks and improving overall security.
[0086] Further optionally, the risk assessment model is used to perform real-time analysis on the behavior pattern of the digital signature server to predict potential security risks in real time and output a risk score of the digital signature server, including:
[0087] Obtain the behavior data of the digital signature server to be predicted, including access logs, signature request records, and system performance indicators;
[0088] Preprocessing the behavioral data, including cleaning, formatting and normalization;
[0089] Extracting key features from the behavior data and inputting them into each decision tree of the risk assessment model, wherein the key features include one or more feature vectors;
[0090] By using each decision tree of the risk assessment model, according to its splitting rule, the data samples are distributed to different leaf nodes, wherein each leaf node represents a predicted value of a risk score;
[0091] The predicted values of the risk scores of all decision trees are averaged to obtain the final prediction result, which is the risk score of the digital signature server.
[0092] Understandably, in the preliminary stage of risk assessment, the behavior data of the digital signature server to be predicted is obtained. These data include but are not limited to access logs, signature request records, and system performance indicators. Access logs record the details of server accesses, such as access time, access objects, and access results. Signature request records reflect the type, quantity, and frequency of signature requests processed by the server, while system performance indicators, such as CPU usage, memory usage, and network throughput, reveal the performance status of the server during operation. The original behavior data is then preprocessed, and the preprocessing work mainly includes data cleaning, formatting, and normalization.
[0093] After preprocessing, features that are critical to risk assessment are extracted from the behavioral data. These features can reflect anomalies or risk points in the server behavior pattern. The extracted features may include abnormal changes in access frequency, success rate of signature requests, sudden drops in system performance indicators, etc. These features are then organized into feature vectors and input into the risk assessment model. In the random forest model, these feature vectors are assigned to each decision tree as the basis for decision tree splitting and prediction.
[0094] In the risk assessment model, each decision tree splits according to the input feature vector to form a series of split nodes and leaf nodes. Each split node corresponds to a feature threshold, and the data sample is assigned to the left subtree or the right subtree according to the feature value until it reaches the leaf node. The leaf node stores the risk score prediction value calculated based on the training data. When a new data sample is assigned to a leaf node, the predicted value of the node is regarded as the risk score of the sample. The integration of multiple decision trees improves the accuracy and stability of risk assessment.
[0095] Finally, the system averages the risk score predictions of all decision trees to obtain the final risk score of the digital signature server. This score comprehensively reflects the current security risk level of the server. According to the risk score, the system can take corresponding security measures to reduce the risk, such as adjusting the server's permissions, conducting security audits, triggering alarm mechanisms, or conducting further investigations and analysis. The entire process analyzes the server's behavior patterns in real time, promptly discovers potential security risks, and takes effective measures to respond, thereby ensuring the safe and stable operation of the digital signature server.
[0096] Further optionally, each decision tree of the risk assessment model distributes the data samples to different leaf nodes according to its splitting rule, wherein each leaf node represents a predicted value of a risk score, including:
[0097] For each decision tree, starting from the root node, the input feature data is assigned to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes;
[0098] The assigned child node is used as the new current node;
[0099] Based on the features and splitting rules used on the current node, the feature data is distributed to the next child node until a leaf node is reached;
[0100] When feature data is assigned to a leaf node, the risk score prediction value represented by the corresponding leaf node is used as the prediction result of the risk score of the current decision tree.
[0101] Further optionally, starting from the root node, according to the features and splitting rules used on the corresponding nodes, the input feature data is distributed to the corresponding child nodes, including:
[0102] Starting from the root node, select a feature as the split feature according to the split rule used on the current node;
[0103] For the selected splitting feature, a splitting threshold is calculated;
[0104] For the input feature data, its value on the selected split feature is compared with the split threshold;
[0105] If it is less than or equal to the split threshold, the feature data is assigned to the left child node;
[0106] If it is greater than the split threshold, the feature data is assigned to the right child node.
[0107] Understandably, in the prediction process of the decision tree, starting from the root node is the logical starting point. The root node is the topmost node of the decision tree, which represents the starting split point of the entire data set.
[0108] Once the split feature is selected, the next step is to calculate a split threshold. The split threshold is a value used to divide the feature data on the selected feature into two parts. The choice of the split threshold can ensure that the data can best reflect its inherent distribution and regularity after splitting.
[0109] The algorithm then traverses the input feature data and extracts the corresponding value on the selected split feature for each piece of data. This value is then compared with the split threshold calculated previously. This comparison process is to determine which child node each piece of data should be assigned to.
[0110] If the value of the feature data on the selected split feature is less than or equal to the split threshold, then the data is assigned to the left child node. The left child node represents a specific risk level that is more closely associated with data below the split threshold.
[0111] On the contrary, if the value of the feature data on the selected split feature is greater than the split threshold, then the data is assigned to the right child node. The right child node also represents a specific risk level, but this level is more closely related to the data above the split threshold.
[0112] Through the above steps, the decision tree can gradually distribute the data to each child node according to the input feature data, according to the established splitting rules and splitting thresholds. This process is recursive until the stop condition is reached. Ultimately, each leaf node will contain a predicted value of the risk score, which is used to predict new input data.
[0113] Further optionally, adjusting the initial attributes of the digital signature server according to the change of the risk score of the digital signature server to obtain the final attributes includes:
[0114] When the risk score of the digital signature server rises to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a high security level to a medium security level, and the levels of some of its sensitive attributes are reduced accordingly;
[0115] When the risk score of the digital signature server continues to rise and exceeds a second preset threshold, the security level of the digital signature server is adjusted from a medium security level to a low security level, and the levels of all or specific sensitive attributes thereof are removed.
[0116] It is understandable that when the risk score of the digital signature server rises to between the first preset threshold and the second preset threshold (including the first preset threshold but excluding the second preset threshold), the adjustment mechanism is triggered. The security level of the digital signature server is adjusted from a high security level to a medium security level. This adjustment reflects that the risks currently faced by the server have increased, but have not yet reached the most serious level. And the levels of some sensitive attributes of the digital signature server are reduced accordingly. Sensitive attributes may include access rights, encryption strength, data protection level, etc. Lowering the levels of these attributes is to reduce potential losses and threats in the event of increased risks.
[0117] When the risk score of the digital signature server continues to rise and exceeds the second preset threshold, a more stringent adjustment mechanism is triggered. The security level of the digital signature server is adjusted from the medium security level to the low security level. This adjustment indicates that the risk currently faced by the server is already very high and more stringent security measures need to be taken. And remove the level of all or specific sensitive attributes of the digital signature server. This means that in extremely high-risk situations, in order to maximize the security of the server and data, it is necessary to deprive the server of some key permissions or functions, or reduce it to the lowest security level.
[0118] Through the above steps, the security level and sensitive attributes of the digital signature server can be dynamically adjusted according to its real-time risk score. This adjustment mechanism helps to take timely measures to protect the security of the server and data when the risk changes. At the same time, it also reflects the "dynamic adaptation" principle in risk management, that is, to flexibly adjust the security policy according to the changes in risk conditions to achieve the best security effect. It should be noted that the setting of the preset threshold should be based on the actual risk assessment results and business needs to ensure the accuracy and effectiveness of the adjustment measures.
[0119] Further optionally, adjusting the initial attributes of the digital signature server according to the change of the risk score of the digital signature server to obtain the final attributes includes:
[0120] When the risk score of the digital signature server drops to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a low security level to a medium security level, and the levels of some of its sensitive attributes are increased;
[0121] When the risk score of the digital signature server continues to decrease and is lower than a first preset threshold, the security level of the digital signature server is adjusted from a medium security level to a high security level, and the level of its sensitive attributes is fully restored to increase its access rights.
[0122] It is understandable that when the risk score of the digital signature server drops to between the first preset threshold and the second preset threshold (including the first preset threshold and excluding the second preset threshold), this change triggers the adjustment mechanism for the server security level and sensitive attributes. The security level of the digital signature server is adjusted from a low security level to a medium security level. This adjustment reflects that the risks currently faced by the server have been reduced, but a certain level of security vigilance still needs to be maintained. And the levels of some sensitive attributes of the digital signature server are correspondingly increased. These sensitive attributes may include access rights, data encryption strength, audit log records, etc. The purpose of increasing the levels of these attributes is to gradually restore the functions and permissions of the server when the risks are reduced, while ensuring a steady improvement in security.
[0123] When the risk score of the digital signature server continues to decrease and is below the first preset threshold, it indicates that the security risk of the server has been further significantly reduced. The security level of the digital signature server is adjusted from the medium security level to the high security level. This adjustment means that the current security status of the server is very good and can undertake higher-risk tasks or provide more services. The sensitive attribute level of the digital signature server is fully restored to increase its access rights. This means that in the case of extremely low risk, the server can be restored to a normal operating state with full permissions and functions, thereby better meeting business needs.
[0124] The risk management strategy of this embodiment dynamically adjusts the security level and sensitive attributes of the digital signature server based on its real-time risk score. This adjustment mechanism not only helps to ensure that the security of the server matches the current risk situation, but also can flexibly adjust the server's functions and permissions according to changes in risks, thereby meeting changes in business needs. At the same time, this also reflects the "dynamic balance" principle in risk management, that is, maximizing the availability and performance of the server while ensuring security.
[0125] Further optionally, in step S104, verifying whether its attribute matches the attribute associated with the target digital certificate when it is encrypted includes:
[0126] An attribute verification model is constructed to verify whether the attributes of the digital signature server match the attributes associated with the digital certificate during encryption.
[0127] Understandably, a model capable of handling attribute verification tasks can be constructed to verify whether the attributes of the digital signature server match the attributes associated with the digital certificate encryption. This model can be a classifier based on machine learning, such as a neural network, a decision tree, a support vector machine, etc. By constructing an attribute verification model, automated and accurate attribute verification can be achieved to ensure the legitimacy and correctness of the digital signature server when processing digital certificates, thereby improving the security and reliability of the entire system.
[0128] Further optionally, the verifying, by the attribute verification model, whether the attribute of the digital signature server matches the attribute associated with the digital certificate during encryption includes:
[0129] Extracting a first attribute feature from the attribute information associated with the digital certificate when it is encrypted;
[0130] Extracting a second attribute feature from the attribute information of the digital signature server;
[0131] Combining the first attribute feature and the second attribute feature into a target feature vector;
[0132] The target feature vector is input into the attribute verification model, and after calculation in the hidden layer, it finally reaches the output layer, and the probability of the attribute matching between the two is output;
[0133] If the probability of attribute matching is greater than the preset probability threshold, it is determined to be a match; otherwise, it is determined to be a mismatch.
[0134] It is understandable that when a digital certificate is encrypted, a series of attribute information will be associated, such as the issuer of the certificate, validity period, public key, etc. These attribute information constitute the identity and authority identification of the digital certificate. Representative features are extracted from these attribute information as the first attribute features, which can accurately reflect the identity and authority of the digital certificate.
[0135] The digital signature server also has its own attribute information, such as the server address, security level, supported encryption algorithms, etc. Similarly, representative features are extracted from these attribute information as the second attribute features, which can accurately reflect the identity and capabilities of the digital signature server.
[0136] The first attribute feature and the second attribute feature are combined into a target feature vector, which contains all the key information of the digital certificate and the digital signature server. When training the model, a label is added to each feature vector to indicate whether the attribute matches. For example, 1 can be used to indicate a match and 0 can be used to indicate a mismatch. In this way, the model can learn how to determine whether the attribute matches based on the feature vector.
[0137] The target feature vector is input into the attribute verification model. The model will process and transform the feature vector through hidden layer calculations. Finally, the model will reach the output layer and output a value representing the attribute matching probability. This value is a number between 0 and 1, indicating the possibility that the attributes of the digital signature server match the attributes associated with the digital certificate encryption.
[0138] Set a preset probability threshold, such as 0.5 or higher. If the probability of attribute matching is greater than this threshold, it is considered a match; otherwise, it is considered a mismatch. The setting of this threshold should be based on actual application requirements and risk tolerance. A higher threshold can improve the accuracy of matching, but may increase some legal rejections; a lower threshold can improve the inclusiveness of matching, but may increase some illegal acceptances.
[0139] This embodiment can realize automatic and accurate attribute verification by constructing an attribute verification model and extracting, combining, inputting and judging feature vectors, ensuring the legitimacy and correctness of the digital signature server when processing digital certificates, thereby improving the security and reliability of the entire system.
[0140] Embodiment 2
[0141] See also Figure 2 The present invention proposes a multi-certificate synchronization management system, the system comprising:
[0142] Attribute definition module: used to define a set of attributes related to digital certificates;
[0143] Attribute assignment module: used to assign attributes to each digital signature server;
[0144] Encryption association module: used to encrypt the certificate information using the ABE algorithm when there is a new digital certificate or a digital certificate to be updated. During the encryption process, the digital certificate information is associated with a set of attributes;
[0145] Attribute matching module: when the digital signature server issues a request to access or synchronize the target digital certificate, it obtains the attribute information provided by the digital signature server and verifies whether its attribute matches the attribute associated with the target digital certificate when it is encrypted;
[0146] Information acquisition module: used to allow the digital signature server to decrypt and obtain the digital certificate information if a match is found.
[0147] Further optionally, the attribute allocation module is further used for:
[0148] Assign a set of initial attributes to the digital signature server based on its identity, role, authority or business requirements;
[0149] Building a risk assessment model based on random forest, and using the risk assessment model to perform real-time analysis on the behavior pattern of the digital signature server to predict potential security risks in real time and output a risk score for the digital signature server;
[0150] The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes.
[0151] Further optionally, the attribute allocation module is further used for:
[0152] Obtaining behavior data of the digital signature server to be predicted;
[0153] Extracting key features from the behavior data and inputting them into each decision tree of the risk assessment model, wherein the key features include one or more feature vectors;
[0154] By using each decision tree of the risk assessment model, according to its splitting rule, the data samples are distributed to different leaf nodes, wherein each leaf node represents a predicted value of a risk score;
[0155] The predicted values of the risk scores of all decision trees are averaged to obtain the final prediction result, which is the risk score of the digital signature server.
[0156] Further optionally, the attribute allocation module is further used for:
[0157] For each decision tree, starting from the root node, the input feature data is assigned to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes;
[0158] The assigned child node is used as the new current node;
[0159] Based on the features and splitting rules used on the current node, the feature data is distributed to the next child node until a leaf node is reached;
[0160] When feature data is assigned to a leaf node, the risk score prediction value represented by the corresponding leaf node is used as the prediction result of the risk score of the current decision tree.
[0161] Further optionally, the attribute allocation module is further used for:
[0162] Starting from the root node, select a feature as the split feature according to the split rule used on the current node;
[0163] For the selected splitting feature, a splitting threshold is calculated;
[0164] For the input feature data, its value on the selected split feature is compared with the split threshold;
[0165] If it is less than or equal to the split threshold, the feature data is assigned to the left child node;
[0166] If it is greater than the split threshold, the feature data is assigned to the right child node.
[0167] Further optionally, the attribute allocation module is further used for:
[0168] When the risk score of the digital signature server rises to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a high security level to a medium security level, and the levels of some of its sensitive attributes are reduced accordingly;
[0169] When the risk score of the digital signature server continues to rise and exceeds a second preset threshold, the security level of the digital signature server is adjusted from a medium security level to a low security level, and the levels of all or specific sensitive attributes thereof are removed.
[0170] Further optionally, the attribute allocation module is further used for:
[0171] When the risk score of the digital signature server drops to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a low security level to a medium security level, and the levels of some of its sensitive attributes are increased;
[0172] When the risk score of the digital signature server continues to decrease and is lower than a first preset threshold, the security level of the digital signature server is adjusted from a medium security level to a high security level, and the level of its sensitive attributes is fully restored to increase its access rights.
[0173] Further optionally, the attribute matching module is also used for:
[0174] An attribute verification model is constructed to verify whether the attributes of the digital signature server match the attributes associated with the digital certificate during encryption.
[0175] Further optionally, the attribute matching module is also used for:
[0176] Extracting a first attribute feature from the attribute information associated with the digital certificate when it is encrypted;
[0177] Extracting a second attribute feature from the attribute information of the digital signature server;
[0178] Combining the first attribute feature and the second attribute feature into a target feature vector;
[0179] The target feature vector is input into the attribute verification model, and after calculation in the hidden layer, it finally reaches the output layer, and the probability of the attribute matching between the two is output;
[0180] If the probability of attribute matching is greater than the preset probability threshold, it is determined to be a match; otherwise, it is determined to be a mismatch.
[0181] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
Claims
1. A method for synchronously managing multiple certificates, characterized in that: Applied to a digital certificate management platform, the method includes: Defines a set of attributes associated with digital certificates; Assigning attributes to each digital signature server; When there is a new digital certificate or a digital certificate to be updated, the certificate information is encrypted using the ABE algorithm. During the encryption process, the digital certificate information is associated with a set of attributes; When the digital signature server issues a request to access or synchronize the target digital certificate, the attribute information provided by the digital signature server is obtained, and its attributes are verified to match the attributes associated with the target digital certificate when it is encrypted; If they match, the digital signature server is allowed to decrypt and obtain the digital certificate information.
2. The multi-certificate synchronization management method according to claim 1, characterized in that: The step of assigning attributes to each digital signature server includes: Assign a set of initial attributes to the digital signature server based on its identity, role, authority or business requirements; Building a risk assessment model based on random forest, and using the risk assessment model to perform real-time analysis on the behavior pattern of the digital signature server to predict potential security risks in real time and output a risk score for the digital signature server; The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes.
3. The multi-certificate synchronization management method according to claim 2, characterized in that: The risk assessment model is used to analyze the behavior pattern of the digital signature server in real time to predict potential security risks in real time and output a risk score of the digital signature server, including: Obtaining behavior data of the digital signature server to be predicted; Extracting key features from the behavior data and inputting them into each decision tree of the risk assessment model, wherein the key features include one or more feature vectors; By using each decision tree of the risk assessment model, according to its splitting rule, the data samples are distributed to different leaf nodes, wherein each leaf node represents a predicted value of a risk score; The predicted values of the risk scores of all decision trees are averaged to obtain the final prediction result, which is the risk score of the digital signature server.
4. The method for synchronously managing multiple certificates according to claim 3, characterized in that: Each decision tree of the risk assessment model distributes the data samples to different leaf nodes according to its splitting rule, wherein each leaf node represents a predicted value of a risk score, including: For each decision tree, starting from the root node, the input feature data is assigned to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes; The assigned child node is used as the new current node; Based on the features and splitting rules used on the current node, the feature data is distributed to the next child node until a leaf node is reached; When feature data is assigned to a leaf node, the risk score prediction value represented by the corresponding leaf node is used as the prediction result of the risk score of the current decision tree.
5. The multi-certificate synchronization management method according to claim 4, characterized in that: Starting from the root node, the input feature data is distributed to the corresponding child nodes according to the features and splitting rules used on the corresponding nodes, including: Starting from the root node, select a feature as the split feature according to the split rule used on the current node; For the selected splitting feature, a splitting threshold is calculated; For the input feature data, its value on the selected split feature is compared with the split threshold; If it is less than or equal to the split threshold, the feature data is assigned to the left child node; If it is greater than the split threshold, the feature data is assigned to the right child node.
6. The method for synchronously managing multiple certificates according to claim 2, characterized in that: The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes, including: When the risk score of the digital signature server rises to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a high security level to a medium security level, and the levels of some of its sensitive attributes are reduced accordingly; When the risk score of the digital signature server continues to rise and exceeds a second preset threshold, the security level of the digital signature server is adjusted from a medium security level to a low security level, and the levels of all or specific sensitive attributes thereof are removed.
7. The multi-certificate synchronization management method according to claim 2, characterized in that: The initial attributes of the digital signature server are adjusted according to the change of the risk score of the digital signature server to obtain the final attributes, including: When the risk score of the digital signature server drops to between the first preset threshold and the second preset threshold, the security level of the digital signature server is adjusted from a low security level to a medium security level, and the levels of some of its sensitive attributes are increased; When the risk score of the digital signature server continues to decrease and is lower than a first preset threshold, the security level of the digital signature server is adjusted from a medium security level to a high security level, and the level of its sensitive attributes is fully restored to increase its access rights.
8. The multi-certificate synchronization management method according to claim 1, characterized in that: The verifying whether the attribute matches the attribute associated with the target digital certificate when it is encrypted includes: An attribute verification model is constructed to verify whether the attributes of the digital signature server match the attributes associated with the digital certificate during encryption.
9. The method for synchronously managing multiple certificates according to claim 8, characterized in that: The verifying, by the attribute verification model, whether the attribute of the digital signature server matches the attribute associated with the digital certificate during encryption includes: Extracting a first attribute feature from the attribute information associated with the digital certificate when it is encrypted; Extracting a second attribute feature from the attribute information of the digital signature server; Combining the first attribute feature and the second attribute feature into a target feature vector; The target feature vector is input into the attribute verification model, and after calculation in the hidden layer, it finally reaches the output layer, and the probability of the attribute matching between the two is output; If the probability of attribute matching is greater than the preset probability threshold, it is determined to be a match; otherwise, it is determined to be a mismatch.
10. A multi-certificate synchronization management system, used to implement the multi-certificate synchronization management method according to any one of claims 1 to 9, characterized in that: The system comprises: Attribute definition module: used to define a set of attributes related to digital certificates; Attribute assignment module: used to assign attributes to each digital signature server; Encryption association module: used to encrypt the certificate information using the ABE algorithm when there is a new digital certificate or a digital certificate to be updated. During the encryption process, the digital certificate information is associated with a set of attributes; Attribute matching module: when the digital signature server issues a request to access or synchronize the target digital certificate, it obtains the attribute information provided by the digital signature server and verifies whether its attribute matches the attribute associated with the target digital certificate when it is encrypted; Information acquisition module: used to allow the digital signature server to decrypt and obtain the digital certificate information if a match is found.
Citation Information
Patent Citations
Method for cloud data confidentiality protection and access control
CN104378386A
Customer risk index screening method and system based on random forest
CN110334737A
Cross-domain access application control method and device for electronic evidence user
CN116614261A
Security detection method and system for information access
CN119363367A
Cybersecurity System Having Digital Certificate Reputation System
US20210344667A1