Encrypted enterprise network data security access method and system

By building biometric unit and device binding unit in the enterprise network, combining dynamic tokens and quantum random number generators, multiple defects in identity authentication and key management in the prior art are solved, and higher security and adaptability are achieved.

CN120017424AActive Publication Date: 2025-05-16SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD

Patent Information

Application Number
CN202510487146.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-05-16
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

The prior art has many shortcomings in identity authentication and key management of enterprise networks, including low accuracy of biometric authentication, risk of tampering by dynamic token generation mechanism, static key update frequency and undynamic adjustment, random numbers generated by traditional random number generators can be cracked, centralized key storage is easily targeted, and key management mechanisms cannot cope with complex attack methods.

Method used

Multidimensional biological data identification and identity authentication are carried out by building biometric unit and device binding unit, combining dynamic token generation time binding mechanism; using quantum random number generator to generate and roll updating the basic key, and dual protection of multidimensional biological data is carried out through layered encryption; collect resource-sensitive data and login environment data, build an access risk assessment model, and dynamically adjust the key update frequency and time window.

Benefits of technology

It improves the accuracy and tamper-proof ability of identity authentication, enhances the security and attack resistance of keys, realizes dynamic adjustment of key update frequency, improves the adaptability and flexibility of the system, and ensures the security and resource utilization of the enterprise network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017424A_ABST
    Figure CN120017424A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses an encrypted enterprise network data security access method and system, and the method comprises the steps: constructing a biological recognition unit and an equipment binding unit, recognizing multi-dimensional biological data through the biological recognition unit, and carrying out the identity authentication of a user through the combination of a dynamic token generation time binding mechanism; the equipment binding unit associates the identity authentication result with the hardware fingerprint of the security access terminal to generate a digital identity certificate; a basic key is generated and updated in a rolling mode through a quantum random number generator; dual protection is carried out on the multi-dimensional biological data through a hierarchical encryption unit, the hierarchical encryption unit comprises an application layer and a transmission layer, the application layer adopts an SM4 algorithm to encrypt service content data in the multi-dimensional biological data, and the transmission layer adopts an SM2 algorithm to generate a session key to carry out forward secrecy; the security access of enterprise network data is ensured, and the security protection capability of the enterprise network is comprehensively enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and more specifically, to a method and system for securely accessing encrypted enterprise network data. Background Art

[0002] Patent publication number CN118157916A discloses a method for accessing an enterprise network, including: tagging the access data packet sent by the client with a virtual extensible local area network (VXLAN) tag through the regional network aggregation center switch, and forwarding the access data packet to the data center switch according to the VXLAN network access policy; sending the access data packet carrying the VXLAN tag to the zero-trust main server through the data center switch, so that the zero-trust main server verifies the access data packet and notifies the zero-trust gateway to establish a communication tunnel with the client. Constructing the enterprise network as a three-level leaf-spine network topology and introducing VXLAN tags as an identification factor for client identity access at member unit nodes can significantly reduce the risk of the enterprise network and improve the security of the enterprise network. The existing enterprise network data security access method and system with encryption processing has the following main problems: Existing biometric authentication systems usually rely on a single biometric for identity authentication. Since biometrics are easily affected by environmental factors or individual differences, this may lead to low authentication accuracy, or even misidentification or missed identification. In addition, with the advancement of technology, the forgery and attack methods of biometrics are constantly updated, and the existing system is still insufficient in preventing identity forgery; although dynamic tokens can effectively improve the security of the authentication process, the existing token generation mechanism still has certain loopholes in preventing tampering. Some traditional dynamic token generation methods lack high-intensity encryption algorithm support, or the encryption method used is easy to crack, which allows attackers to bypass authentication by tampering with the token content; the existing technology has loopholes in the timeliness of authentication tokens, and hackers may replay old tokens at different time points, resulting in the authentication system failing to provide timely protection when facing rapidly changing attacks; lack of automatic optimization mechanism. When the system environment changes, the time window cannot be automatically adjusted according to real-time biometrics, risk assessment or time difference, affecting the adaptability and flexibility of the authentication process; the mechanism for dynamically updating keys and adjusting the key update frequency is not considered, and the key update process may be too static and lack flexibility; Traditional random number generators may rely on mathematical algorithms or hardware noise, and the random number sequences they generate have certain regularities and may be cracked or predicted, thus affecting the security of the key. Existing keys are often stored in a centralized manner, making them easy targets for attackers. Single point failures or centralized attacks may lead to key leakage or tampering, endangering the security of the entire system. Existing technologies usually use a fixed key update frequency, which cannot be dynamically adjusted according to changes in the enterprise's operating environment or fluctuations in security risks, which may lead to over-updates or under-updates, affecting the security and resource utilization of the system. Traditional key management mechanisms fail to effectively respond to complex attack methods. Existing technologies lack sufficient protection during the storage and transmission of keys. Keys may be illegally accessed during storage or intercepted during transmission, leading to the risk of key leakage. Traditional key update mechanisms fail to respond to sudden risk events faced by enterprises in a timely manner, and are unable to quickly update keys when security threats occur, resulting in reduced system security. In existing technologies, the key update frequency is usually based on preset rules, lacking the ability to make fine adjustments based on specific risk levels, resulting in inflexible security measures and an inability to efficiently respond to risk changes in different scenarios.

[0003] In view of this, the present invention proposes an encrypted enterprise network data security access method and system to solve the above problems. Summary of the invention

[0004] In order to overcome the above-mentioned defects of the prior art and to achieve the above-mentioned purpose, the present invention provides the following technical solution: a method for securely accessing enterprise network data by encryption processing, comprising: S1. Construct a biometric identification unit and a device binding unit, identify multi-dimensional biological data through the biometric identification unit, and authenticate the user by combining the dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; S2. Generate and roll over basic keys through a quantum random number generator; perform dual protection on multidimensional biometric data through a layered encryption unit, which includes an application layer and a transport layer. The application layer uses the SM4 algorithm to encrypt the business content data in the multidimensional biometric data, and the transport layer uses the SM2 algorithm to generate session keys for forward secrecy; S3. Collect resource sensitive data and login environment data, use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model, and predict the access risk coefficient; based on the predicted access risk coefficient, determine whether the enterprise encounters security risks; S4. If the enterprise encounters security risks, it triggers permission downgrade or secondary authentication instructions, uses SM1 encryption chip to encrypt digital identity credentials, uses SM4 algorithm to encrypt resource sensitive data and login environment data, and stores them in the database; S5. If the enterprise has not encountered security risks or the security risks have been resolved, the SM1 decryption algorithm is used to restore the digital identity credentials, decrypt the resource-sensitive data and login environment data in the database, and restore access.

[0005] Preferably, the multi-dimensional biometric data includes biometric data and business content data; the biometric data includes physiological data and behavioral data; the physiological data includes fingerprint data, facial data, iris data, voice data, palm print data and facial blood vessel data; the behavioral data includes the speed of the user inputting characters on the keyboard, the key interval, the pressing time of each key, the moving speed of the user's mouse, the frequency of clicking the mouse and gait data; Business content data includes business transaction data, enterprise operation data and real-time communication data; business transaction data includes order number, product information, transaction time, billing information, payment record, refund record, supplier information and procurement contract; enterprise document data includes enterprise management documents, internal notifications, R&D documents, legal documents, cooperation agreements and audit logs; real-time communication data includes enterprise IM records, shared documents and cloud editing records.

[0006] Preferably, the method for authenticating a user by combining a dynamic token generation time binding mechanism comprises: Preliminary user authentication is performed through biometric matching, and multidimensional biometric data is defined as a multidimensional feature vector ,in, For multidimensional biological data Features is the total number of features in multidimensional biological data; the preset standard multidimensional feature vector ;in, is the first in the standard multidimensional feature vector Features Calculate multidimensional feature vectors using cosine similarity and the standard multidimensional eigenvector The similarity between them is set to , if the multidimensional feature vector and the standard multidimensional eigenvector The similarity between them is greater than or equal to the preset similarity threshold , it is preliminarily determined that the user identity authentication has passed; The preset dynamic token is composed of the timestamp when the token is generated, the user's unique identifier and the quantum random number. The Kyber algorithm is used to exchange a key between the user and the authentication server. , using the key And HMAC function to generate dynamic token: ;in, Represents a dynamic time token; Indicates the process of dynamic token generation using HMAC function; Represents the key exchanged between the user and the server using the Kyber algorithm; Indicates the timestamp when the token was generated; A unique identifier representing the user; Represents the random number generated by the quantum random number generator; Represents a string concatenation operation; Preset effective time window The time binding mechanism is defined as follows: a dynamic token is valid only when the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window. The validity of the dynamic token is verified by the dynamic token validity verification formula; The dynamic token validity verification formula is: ;in, Represents the absolute difference between the current timestamp and the timestamp when the token was generated; Indicates the current timestamp; Indicates that if the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window, the dynamic token is valid; It means that if the absolute difference between the current timestamp and the timestamp when the token was generated is greater than the preset valid time window, the dynamic token will become invalid; The preset effective time window is dynamically adjusted through the effective time window adjustment formula. The effective time window adjustment formula is: ;in, is the effective time window after adjustment; A constant factor to adjust the effect of the total number of multidimensional biological data features on the time window; A constant factor that adjusts the effect of time difference on the time window; Only when the user identity authentication is passed and the dynamic token is valid can it be determined that the user has finally passed the identity authentication.

[0007] Preferably, the method of generating and rolling updating a basic key by a quantum random number generator comprises: deploy Quantum random number generators are distributed in different physical or logical security domains. Each quantum random number generator generates a random number sequence and serves as the source of the basic key share. The random number sequence generated by each quantum random number generator is recorded as ,in, Indicates the number of the quantum random number generator, ranging from 1 to ; Define a dynamic key update strategy, the dynamic key update strategy includes defining a basic key update frequency and defining an adjustment rule for dynamically adjusting the basic key update frequency; the adjustment rule for dynamically adjusting the basic key update frequency includes defining an update time interval based on the basic key update frequency and dynamically adjusting the basic key update frequency through an update frequency adjustment formula according to an enterprise risk assessment value; The default enterprise risk assessment value is , the enterprise risk assessment value Obtained through the enterprise risk assessment formula; the enterprise risk assessment formula is: ;in, Indicates the number of times the user authentication failed; Indicates the number of times sensitive resource data is accessed; Indicates the number of abnormalities in the login environment data; The weight factor representing the impact of the number of failed user authentications on the enterprise risk assessment value; A weight factor indicating the impact of the number of times sensitive resource data is accessed on the enterprise risk assessment value; The weight factor representing the impact of the number of abnormal login environment data on the enterprise risk assessment value; The update frequency adjustment formula is: ;in, The frequency of updating the basic key; The frequency of updating the basic key after adjustment; is the risk sensitivity coefficient; The risk sensitivity coefficient is adjusted by the risk sensitivity adjustment formula Dynamic adjustment is performed, and the risk sensitivity adjustment formula is: ;in, is the risk sensitivity coefficient after dynamic adjustment; is the number of quantum random number generators; Influencing factors for risk assessment; is the base of natural logarithms; Through the SSS protocol, the basic key is split into key shares, distribute the key shares in all physical or logical security domains, each physical or logical security domain stores only one key share, and configure the key reconstruction threshold to , ensuring at least The complete base key can be reconstructed with key shares; a new base key is generated through the quantum random number generator and the SSS protocol, and the old base key is destroyed at the same time.

[0008] Preferably, the method of encrypting the business content data in the multi-dimensional biometric data using the SM4 algorithm comprises: Select the business content data to be encrypted from the multidimensional biological data, use the quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, use the 128-bit symmetric key to initialize the SM4 encryption algorithm, and divide the business content data into 16 bytes. If the number of bytes of the business content data is not a multiple of 16, it is padded until the length of the business content data reaches a multiple of 16. Each data block is encrypted using the SM4 encryption algorithm, and finally all encrypted data blocks are merged to obtain the complete encrypted business content data.

[0009] Preferably, the method of using the SM2 algorithm to generate a session key for forward secrecy includes: Determine the sender and receiver of the communication, each of which holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received sender's public key and its own private key; The sender uses the SM2 algorithm to calculate the same shared key based on the received public key of the recipient and its own private key; based on the shared key, both parties further use the SM2 algorithm to derive the session key used for symmetric encryption to achieve forward secrecy.

[0010] Preferably, the method for constructing the access risk assessment model includes: The resource sensitive data includes financial data, core technology data, customer privacy data and legal compliance data; the login environment data includes the IP address of the user when logging in, the device information data used by the user, the time of the user's access, the user's login location and the user behavior log; The dataset is divided into training set, validation set and test set to train the model, evaluate the model performance and verify the model generalization ability; the sample set is a subset of the dataset, each sample set includes historical multidimensional biological data, resource sensitive data and login environment data and the corresponding access risk coefficient; GBDT is selected as the implementation of the gradient boosting tree model to handle the regression task; Initialize GBDT parameters, including the maximum number of leaf nodes in each tree, learning rate, number of trees, and maximum depth of trees; use historical multidimensional biological data, resource sensitive data, and login environment data as input data of the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model; Use mean square error as the loss function to measure the difference between the model's predicted value and the actual value; in each iteration, GBDT builds a new decision tree to fit the negative gradient of the loss function of the previous step, uses the negative gradient of the loss function as the learning target of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function; Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters based on its performance feedback until the model performance no longer improves or reaches the preset stopping condition; use the trained access risk assessment model to predict the current multidimensional biological data, resource sensitive data, and login environment data to obtain the access risk coefficient.

[0011] Preferably, the method for judging whether an enterprise encounters a security risk based on the predicted access risk coefficient includes: Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold; If the predicted access risk coefficient is less than the access risk coefficient threshold, it is judged that the enterprise has not encountered security risks; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is judged that the enterprise has encountered security risks.

[0012] Preferably, the method of encrypting a digital identity certificate using an SM1 encryption chip includes: Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity certificate, and use the 128-bit symmetric key and the SM1 algorithm to convert the digital identity certificate into ciphertext data.

[0013] An encrypted enterprise network data security access system, comprising: The multimodal identity authentication module is composed of a biometric unit and a device binding unit. The biometric unit identifies multidimensional biological data and combines the dynamic token generation time binding mechanism to authenticate the user. The device binding unit associates the identity authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential. Dynamic encryption transmission module, used to generate and roll over basic keys through quantum random number generator; use layered encryption unit to double protect multi-dimensional biometric data, layered encryption unit includes application layer and transport layer, application layer uses SM4 algorithm to encrypt business content data in multi-dimensional biometric data, and transport layer uses SM2 algorithm to generate session keys for forward secrecy; The intelligent access control module is used to obtain resource sensitive data and login environment data, and use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model to predict the access risk coefficient; based on the predicted access risk coefficient, it is determined whether the enterprise encounters security risks; Data storage encryption module: If the enterprise encounters security risks, it will trigger permission downgrade or secondary authentication instructions, and use SM1 encryption chip to encrypt digital identity credentials, and use SM4 algorithm to encrypt resource sensitive data and login environment data, and store them in the database; The data storage decryption module uses the SM1 decryption algorithm to recover the digital identity credentials and decrypt the resource-sensitive data and login environment data in the database to restore access if the enterprise has not encountered any security risks or the security risks have been resolved.

[0014] The technical effects and advantages of the method and system for securely accessing enterprise network data using encryption processing of the present invention are as follows: Through biometric matching, it is ensured that the authentication object is a real user, avoiding the risk of identity forgery. When using dynamic token generation, timestamp, user unique identifier and quantum random number are combined to further enhance the anti-tampering ability of the authentication process; dynamic tokens are combined with time binding mechanism, and can only be verified within the specified time window, effectively preventing replay attacks and enhancing the timeliness and security of the system; by introducing the timestamp and effective time window mechanism, even if hackers obtain a legitimate dynamic token, they cannot use the token again for authentication at a different time, greatly reducing the possibility of replay attacks; the preset dynamic token and time window mechanism can be flexibly adjusted according to system requirements and authentication requirements. Through the dynamic adjustment formula of the effective time window, the time window can be automatically optimized according to different biometric data feature numbers and time differences, improving the adaptability and flexibility of the authentication process; the multi-factor authentication method combining biometrics and dynamic tokens provides a higher level of security, while avoiding the cumbersome operations in traditional authentication methods and improving the user's authentication experience; The random number sequence generated by the quantum random number generator ensures that the generation of the basic key is highly random and unpredictable, enhances the security of the key, and reduces the risk of the key being cracked or forged; the quantum random number generator is distributed in different physical or logical security domains, and each generator generates a different random number sequence and serves as the source of the key share, which further increases the complexity and anti-attack capability of the key and avoids single point failure or centralized attack; the dynamic key update strategy defines the basic key update frequency and dynamically adjusts it according to the enterprise's risk assessment value, ensuring that the key update frequency matches the enterprise's security needs. According to the change of the risk assessment value, the system can adjust the key update frequency in time to adapt to the changes in the enterprise's operating environment. Through the enterprise risk assessment formula combined with factors such as the number of authentication failures, the frequency of sensitive resource access, and the abnormal login environment data, the enterprise's risk level is quantified and the key update frequency is accurately adjusted. Based on the risk assessment mechanism, it ensures that the key update strategy matches the actual risk situation of the enterprise, avoiding resource waste and unnecessary frequent updates. The dynamic adjustment of the risk sensitivity coefficient makes the key update frequency more refined and more adaptable, especially when facing sudden risk events, it can respond quickly and take security measures. The combination of quantum random number generator and SSS protocol provides a secure and efficient key management mechanism. The high intensity unpredictability of quantum random numbers combined with key segmentation and threshold reconstruction mechanism make the storage and use of keys safer. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 A schematic diagram of a method for securely accessing enterprise network data using encryption processing according to the present invention; Figure 2 This is a schematic diagram of the structure of an encrypted enterprise network data security access system of the present invention; Figure 3 This is a flow chart of the method for generating session keys for forward secrecy using the SM2 algorithm provided in the present invention. DETAILED DESCRIPTION

[0016] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0017] Example 1 See also Figure 1 and Figure 3 As shown, this embodiment further illustrates an encrypted enterprise network data security access method proposed by the present invention, including: With the rapid development of information technology, the security of enterprise network data has gradually become a focus of attention. Enterprises are increasingly dependent on network data transmission and sharing, and are facing increasingly complex security threats and attacks, especially in the fields of identity authentication and key management. Although traditional network security protection measures provide certain guarantees for the security of network data, there are still some problems that need to be solved in practical applications.

[0018] First, biometric authentication technology is widely used in corporate identity authentication, but existing biometric authentication technology usually relies on a single biometric feature (such as fingerprint, face, iris, etc.) for identity authentication. These biometric features may be affected by environmental factors (such as light, temperature, noise, etc.) or individual differences (such as scars, aging, etc.), thereby reducing the accuracy of authentication and may even lead to misidentification or missed identification. In addition, with the advancement of technology, the forgery and simulation technology of biometric features has become increasingly mature. Attackers can bypass authentication by forging biometric features, resulting in insufficient anti-counterfeiting capabilities of the system, which seriously affects the security of the system.

[0019] Secondly, dynamic tokens are widely used to improve the security of authentication, but there are still some problems with the existing dynamic token generation mechanism. The encryption algorithms used in some traditional dynamic token generation methods lack sufficient strength, or the encryption methods used are easily cracked, allowing attackers to bypass authentication by tampering with the token content. In addition, the existing authentication technology is weak in preventing replay attacks, especially in the timeliness of tokens. Hackers can replay old dynamic tokens at different time points to successfully bypass the authentication process, which makes the system unable to provide effective protection in time when facing rapidly changing attacks.

[0020] Existing technologies usually lack automatic optimization mechanisms. When the system environment changes, they cannot automatically adjust the time window in the authentication process based on real-time biometric data, risk assessment results, or time differences. This lack of flexibility and adaptability makes the system's authentication process unable to dynamically respond to changing security requirements, affecting the accuracy of authentication and user experience.

[0021] In terms of key management, traditional key generation and storage methods still face many challenges. Many existing key generators rely on mathematical algorithms or hardware noise to generate random numbers. The generation of these random numbers is usually regular and can be cracked or predicted, which reduces the security of the keys. In addition, traditional keys are often stored in a centralized manner, which poses a risk of single point failure. Once an attacker successfully breaks through the protection of the key storage area, it may lead to key leakage or tampering, posing a serious threat to the entire system.

[0022] For the key update mechanism, most existing technologies use a fixed update frequency and cannot flexibly adjust the key update frequency according to actual security needs and the enterprise's operating environment. When the system faces different security risks, it may fail to adjust the key update frequency in a timely manner, resulting in inappropriate key updates and affecting the security of the system. In addition, the existing key management mechanism is not adequate to prevent complex attack methods, especially during the storage and transmission of keys, there is a lack of sufficient protection measures, which increases the risk of key leakage.

[0023] In view of these technical problems, the present invention proposes an encrypted enterprise network data security access method, comprising: S1. Construct a biometric identification unit and a device binding unit, identify multi-dimensional biological data through the biometric identification unit, and authenticate the user by combining the dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; S2. Generate and roll over basic keys through a quantum random number generator; perform dual protection on multidimensional biometric data through a layered encryption unit, which includes an application layer and a transport layer. The application layer uses the SM4 algorithm to encrypt the business content data in the multidimensional biometric data, and the transport layer uses the SM2 algorithm to generate session keys for forward secrecy; S3. Collect resource sensitive data and login environment data, use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model, and predict the access risk coefficient; based on the predicted access risk coefficient, determine whether the enterprise encounters security risks; S4. If the enterprise encounters security risks, it triggers permission downgrade or secondary authentication instructions, uses SM1 encryption chip to encrypt digital identity credentials, uses SM4 algorithm to encrypt resource sensitive data and login environment data, and stores them in the database; S5. If the enterprise has not encountered security risks or the security risks have been resolved, the SM1 decryption algorithm is used to restore the digital identity credentials, decrypt the resource-sensitive data and login environment data in the database, and restore access.

[0024] Multidimensional biometric data includes biometric data and business content data; biometric data includes physiological data and behavioral data; physiological data includes fingerprint data, facial data, iris data, voice data, palm print data and facial blood vessel data; behavioral data includes the speed at which the user enters characters on the keyboard, the interval between keystrokes, the pressing time of each key, the speed at which the user's mouse moves, the frequency of clicking the mouse and gait data; gait data includes the user's walking style and pace, and gait data can be obtained by combining the accelerometer and gyroscope of the wearable device; Business content data includes business transaction data, enterprise operation data and real-time communication data; business transaction data includes order number, product information, transaction time, billing information, payment record, refund record, supplier information and procurement contract; enterprise document data includes enterprise management documents, internal notifications, R&D documents, legal documents, cooperation agreements and audit logs; real-time communication data includes enterprise IM records, shared documents and cloud editing records.

[0025] Methods for authenticating users in combination with a dynamic token generation time binding mechanism include: Preliminary user authentication is performed through biometric matching, and multidimensional biometric data is defined as a multidimensional feature vector ,in, For multidimensional biological data Features is the total number of features in multidimensional biological data; the preset standard multidimensional feature vector ;in, is the first in the standard multidimensional feature vector Features Calculate multidimensional feature vectors using cosine similarity and the standard multidimensional eigenvector The similarity between them is set to , if the multidimensional feature vector and the standard multidimensional eigenvector The similarity between them is greater than or equal to the preset similarity threshold , it is preliminarily determined that the user identity authentication has passed; The preset dynamic token is composed of the timestamp when the token is generated, the user's unique identifier and the quantum random number. The Kyber algorithm is used to exchange a key between the user and the authentication server. , using the key And HMAC function to generate dynamic token: ;in, Represents a dynamic time token; Indicates the process of dynamic token generation using HMAC function; Represents the key exchanged between the user and the server using the Kyber algorithm; Indicates the timestamp when the token was generated; A unique identifier representing the user; Represents the random number generated by the quantum random number generator; Represents a string concatenation operation; Preset effective time window In order to ensure the validity of dynamic tokens, the time binding mechanism is defined as follows: a dynamic token is valid only when the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window. The validity of the dynamic token is verified by the dynamic token validity verification formula; The dynamic token validity verification formula is: ;in, Indicates the absolute difference between the current timestamp and the timestamp when the token was generated, usually in seconds; Indicates the current timestamp; Indicates that if the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window, the dynamic token is valid; It means that if the absolute difference between the current timestamp and the timestamp when the token was generated is greater than the preset valid time window, the dynamic token will become invalid; For example, assuming the current timestamp is Seconds (July 5, 2021 12:20:20), token generation timestamp seconds (July 5, 2021 11:58:20), preset effective time window seconds (i.e. 5 minutes). Then the absolute difference between the current timestamp and the timestamp when the token was generated seconds, because 120 seconds is less than the preset effective time window of 300 seconds, so , the dynamic token is valid; It should be noted that Seconds refer to the number of seconds that have passed from 00:00:00 UTC on January 1, 1970 to 12:20:20 UTC on July 5, 2021. UTC is a globally recognized time standard and is used as a reference time for many modern computer systems and protocols. January 1, 1970 was chosen as the UNIX epoch, and UTC was used as a unified time zone, allowing computer systems and networks around the world to process and exchange time on a common basis, avoiding the complexity caused by different time zones. The preset effective time window is dynamically adjusted through the effective time window adjustment formula. The effective time window adjustment formula is: ;in, is the effective time window after adjustment; A constant factor to adjust the effect of the total number of multidimensional biological data features on the time window; is a constant factor that adjusts the effect of time difference on the time window; n is the total number of features in the multidimensional biological data; It is the preset effective time window; It should be noted that the design of the effective time window adjustment formula is based on the demand for dynamic time window adjustment, aiming to solve the limitations of fixed time windows in multidimensional biological data analysis. Traditional fixed time window methods usually assume that data distribution is uniform and time correlation is consistent, but in practical applications, data at different time points may have different importance, and the characteristic dimension of the data will also affect the reasonable setting of the time window. Therefore, this formula introduces an adaptive adjustment mechanism through time difference, total number of features and adjustment factor to optimize the size of the time window to make it more consistent with the actual data distribution. The effective time window adjustment formula does not simply scale the time window linearly, but forms a nonlinear dynamic adjustment method through the influence terms of the time difference and total number of features in the numerator and the time difference suppression term in the denominator, ensuring that the time window will not increase or decrease indefinitely, but can be reasonably adjusted with the change of data. When the time difference is small, the adjusted time window is close to the initial value to ensure the time consistency of the data; when the time difference is large, the time window is appropriately expanded to avoid the loss of key information due to too small a time window. At the same time, the formula also introduces the logarithmic term of the total number of features, so that when the data dimension increases, the adjustment of the time window has a smooth characteristic without drastic changes, thereby improving the adaptability of the algorithm.

[0026] Through the effective time window adjustment formula, the nonlinear influence of the number of data features and time correlation can be better simulated, and the adaptive adjustment effect can be shown when the data time span is large, so that the time window adjustment is more in line with the actual situation of the data. Traditional time window adjustment methods usually use fixed values ​​or simple linear adjustment methods, such as directly enlarging or reducing the time window in proportion to the time difference. This method may be effective when the data distribution is relatively uniform, but in multidimensional data scenarios, especially when different numbers of features are involved, the fixed adjustment method may cause the time window to be too large or too small, affecting the accuracy of data analysis. This formula not only enhances the dynamic adaptability of the time window by introducing the nonlinear influence of time difference and the feature dimension adjustment mechanism, but also avoids the errors that may be caused by linear adjustment, making it suitable for more complex data environments and improving the flexibility and stability of time window adjustment.

[0027] In addition, the denominator of the effective time window adjustment formula introduces a time difference suppression term, so that when the time difference increases, the adjustment of the time window will not expand infinitely, but tend to a stable value, avoiding the problem of over-adjustment. Compared with the existing technology, the effective time window adjustment formula can adaptively adjust the time window according to the time span and feature quantity of the data in a dynamic data environment, which not only improves the accuracy of data processing, but also enhances the applicability under different data distribution conditions, making it more in line with the actual needs of multidimensional biological data analysis.

[0028] Only when the user identity authentication is passed and the dynamic token is valid can it be determined that the user has finally passed the identity authentication.

[0029] Methods for generating and rolling base keys using a quantum random number generator include: deploy Quantum random number generators are distributed in different physical or logical security domains. Physical security domains refer to areas protected by physical means. Usually involving data centers, server rooms, office areas, etc., physical isolation and protection measures (such as access control, monitoring, physical firewalls, etc.) are used to limit access to equipment and information. The design goal of the physical security domain is to prevent unauthorized personnel from directly accessing hardware devices, storage media and other critical infrastructure.

[0030] For example: Data Center: A physical security domain may be a data center or computer room that only authorized personnel can enter.

[0031] Cryptographic devices: such as hardware security modules (HSMs) or cryptographic chips, these devices are usually placed in controlled areas.

[0032] Logical security domain refers to a virtual isolation area created by software and technical means to protect the security of data and information systems. This isolation is achieved through access control at the network, operating system, database and other levels. Logical security domain does not rely on physical location, but ensures the security and isolation of data access through configuration and management.

[0033] For example: Virtual machine isolation: Use virtualization technology to create multiple logical security domains. Each virtual machine (VM) can be regarded as a logical security domain in which data and operations are isolated from each other.

[0034] Network isolation: Use network access control lists (ACLs) or virtual local area networks (VLANs) to limit access between different network areas so that data from different departments or user groups cannot be accessed by other groups.

[0035] Each quantum random number generator generates a random number sequence and serves as the source of the basic key share; the random number sequence generated by each quantum random number generator is recorded as ,in, Indicates the number of the quantum random number generator, ranging from 1 to ; Define a dynamic key update strategy, which includes defining a basic key update frequency and defining an adjustment rule for dynamically adjusting the basic key update frequency; the adjustment rule for dynamically adjusting the basic key update frequency includes defining an update time interval based on the basic key update frequency (e.g., updating once every hour) and dynamically adjusting the basic key update frequency through an update frequency adjustment formula according to an enterprise risk assessment value; The default enterprise risk assessment value is , enterprise risk assessment value Obtained through the enterprise risk assessment formula; the enterprise risk assessment formula is: ;in, Indicates the number of times the user authentication failed; Indicates the number of times sensitive resource data is accessed; Indicates the number of abnormalities in the login environment data; The weight factor representing the impact of the number of failed user authentications on the enterprise risk assessment value; A weight factor indicating the impact of the number of times sensitive resource data is accessed on the enterprise risk assessment value; The weight factor representing the impact of the number of abnormal login environment data on the enterprise risk assessment value; It should be noted that , and The settings need real-time feedback from the system to adjust. The initial value range is 0.3-0.5, and the default value is 0.4; it means that in the absence of special abnormalities, the number of identity authentication failures has a relatively moderate impact on risk assessment. By analyzing historical data, the contribution of user identity authentication failures to enterprise security is evaluated. If a user fails to log in multiple times (for example, several times in a row), this may mean potential malicious access behavior, increasing enterprise security risks. Therefore, Need to be adjusted based on historical data analysis: If historical data indicates that authentication failures directly lead to security incidents (such as password brute force cracking), increase If historical data shows that the number of authentication failures is less correlated with actual risk events, you can lower the value. value (such as 0.3 or lower); combined with real-time data feedback (such as abnormal login times or abnormal IPs monitored in real time), dynamically adjust , ensuring that the impact of identity authentication is more emphasized when the risk is high; set up The initial value range is 0.2-0.4, and the default value is 0.3, which means that the impact of access to sensitive data on security risks is preliminarily estimated to be medium; by reviewing historical access logs, the contribution of sensitive data access to security risks is analyzed. For example, if some users frequently access a large amount of sensitive data without clear business needs, it may mean a potential risk of data leakage.

[0036] If historical data shows that abnormal behavior in sensitive data access is highly correlated with security incidents (for example, unauthorized access to sensitive data by an insider), you need to increase If historical data shows that the correlation between sensitive data access and security incidents is weak, the value can be appropriately lowered. value (such as 0.2 or lower); combined with real-time access logs, analyze users' access behavior to sensitive data in real time and dynamically adjust , ensuring that the risks of sensitive data access are effectively reflected in actual access behaviors.

[0037] set up The initial value range is 0.2-0.4, and the default value is 0.3; it means that the impact of abnormal login environment on risk assessment is preliminarily estimated to be medium; by analyzing historical environmental abnormality data, the contribution of environmental abnormalities (such as abnormal login geographic location, device fingerprint changes, etc.) to enterprise security is evaluated. For example, if a user logs in during non-office hours or on an uncommon device, it may indicate the risk of account theft.

[0038] If historical data indicates that environmental data anomalies are directly related to malicious behavior (such as account hijacking), you need to increase If historical data shows that abnormal environmental data is not often associated with security incidents, you can appropriately lower the value of value (such as 0.2 or lower); combined with real-time login environment data (such as user's IP location, device fingerprint, operating system information, etc.), dynamically adjust , ensuring that when environmental abnormalities occur, they can be reflected in a timely manner and the risk assessment can be strengthened.

[0039] If historical data analysis shows that the relationship between identity authentication failure and actual security threats is very close (for example, the probability of causing data leakage is high), you can increase the Similarly, if some login environment anomalies (such as abnormal IP addresses) significantly indicate potential attack behavior, the weight of the factor can be increased. , thereby increasing sensitivity to environmental anomalies.

[0040] The update frequency adjustment formula is: ;in, The frequency of updating the basic key; The frequency of updating the basic key after adjustment; is the risk sensitivity coefficient, which controls the impact of the enterprise risk assessment value on the update frequency; The risk sensitivity coefficient is adjusted by the risk sensitivity adjustment formula Dynamically adjust the system's response intensity when facing different risk situations, so as to ensure that the enterprise's network security system can adapt to the ever-changing threat environment and improve its response capabilities. Specifically, the purpose of adjustment can include the following aspects: 1. Enhance the adaptability and flexibility of the system: Dynamically adapt to changes in risk: As the network environment and attack patterns continue to change, the system needs to dynamically adjust the risk sensitivity coefficient based on real-time risk assessment values ​​to ensure that it can adapt to different risk scenarios. For example, when the system detects a high-risk situation (such as an attack attempt, abnormal behavior, etc.), by increasing the risk sensitivity coefficient, the implementation of security protection measures can be strengthened, such as increasing authentication requirements and strengthening access control.

[0041] Adjustment based on the number of quantum random number generators: The more quantum random number generators there are, the stronger the randomness and security generated, and the system can perform more accurate risk assessments with higher security guarantees. Therefore, their number will be adjusted as a factor in the adjustment formula to ensure that the system can reflect higher security when the number of quantum random number generators increases.

[0042] 2. Control the intensity of security response: Control the intensity of response according to the risk assessment value: Risk assessment value It is a key factor in assessing the risks faced by the current system. By adjusting the risk sensitivity coefficient in the formula, the system's response strength can be controlled under different risk situations. For example, when the risk is low, the system can maintain a low risk sensitivity to ensure that the user experience is not affected; but when the risk is high, the system will automatically enhance its security measures, increase the strictness of authentication, access restrictions, etc., to reduce potential threats.

[0043] Balance security and efficiency: By flexibly adjusting the risk sensitivity coefficient, the system can ensure high security while avoiding the impact of excessive protection on business efficiency or user experience. For example, in normal low-risk situations, a lower risk sensitivity coefficient helps ensure a fast system response and a smooth user experience.

[0044] 3. Improve the accuracy and refined management of security protection: Quantitative risk management: The risk sensitivity coefficient adjustment formula can quantify the relationship between security risks and protection responses, providing a more accurate and controllable mechanism for the system. The system can not only adjust according to existing security events (such as identity authentication failure, resource sensitive data access, etc.), but also make adaptive responses according to real-time risk changes in the network, thereby reducing false positives and missed positives.

[0045] Risk classification management: Based on different risk assessment results, the risk sensitivity coefficient can be adjusted in different levels. For example, the system can set different thresholds. When the risk assessment value reaches a certain preset high-risk threshold, the security authentication and audit of access requests will be immediately strengthened to ensure timely action when risks occur.

[0046] 4. Optimize key update strategy: Impact on key update frequency: By adjusting the risk sensitivity coefficient, the system can adjust the update frequency of the basic key according to the real-time risk assessment value (for example, frequently update the key, or delay the update). In high-risk situations, frequent key updates can reduce potential security threats; in low-risk situations, the key update frequency can be appropriately reduced, thereby improving system efficiency and reducing the cost of excessive operations.

[0047] 5. Improve the intelligence of protective measures: Automated decision-making: Through this adjustment mechanism, the system can automatically adjust the risk sensitivity coefficient according to real-time data (such as the number of quantum random number generators and risk assessment values), and trigger different security measures according to different risk scenarios. For example, when the risk is low, the system can reduce the intensity of security measures to ensure smooth business; when the risk is high, the system will increase the intensity of security measures, thus forming an intelligent and automated security protection system.

[0048] The risk sensitivity adjustment formula is: ;in, is the risk sensitivity coefficient after dynamic adjustment; is the number of quantum random number generators; is the risk assessment influencing factor, which indicates the degree of influence of the risk assessment value on the risk sensitivity coefficient; is the base of natural logarithms; It should be noted that the risk sensitivity adjustment formula introduces the number of quantum random number generators and the enterprise risk assessment value. , which reflects the balance between the security and risk of the system. When the number of quantum random number generators is large, the system has higher security protection, and the risk sensitivity coefficient should be relatively high at this time to cope with potential higher threats; when the risk assessment value is high, the system should automatically increase protection measures to ensure a rapid response to high-risk situations; dynamically adjust the risk sensitivity coefficient according to the real-time enterprise risk assessment value and the security capability of the system (represented by the number of quantum random number generators). This adjustment mechanism enables the system to flexibly respond to different security threats, whether it is security enhancement or risk increase, it can be adjusted within a reasonable range; As the external environment and system status change, risk sensitivity needs to be adjusted flexibly. Too fixed sensitivity may cause the system to be oversensitive or insensitive. By introducing a dynamic adjustment mechanism, the formula can accurately adjust the risk under complex environmental conditions, allowing the system to respond to new information. Traditional risk sensitivity adjustment methods are often too complicated and require multiple calculations and complex physical derivations. The risk sensitivity adjustment formula is expressed through simple logical functions, which can avoid too many complex calculations while retaining a high degree of flexibility and adaptability. The simplicity of the formula allows engineers and technicians to quickly understand and implement it, and it can be flexibly adjusted according to specific application scenarios.

[0049] For example, the risk sensitivity coefficient is 0.4, the system has deployed 5 quantum random number generators, the current enterprise risk assessment value is 7, and the risk assessment impact factor is 0.2, then the risk sensitivity coefficient after dynamic adjustment ; Through the SSS protocol, the basic key is split into key shares, distribute the key shares in all physical or logical security domains, each physical or logical security domain stores only one key share, and configure the key reconstruction threshold to , ensuring at least key shares are needed to reconstruct the complete base key; in this scheme, the base key is split into Key shares, each key share is stored in a different physical or logical security domain. To prevent single point failure or leakage, no single key share can reconstruct the complete basic key. The threshold value It is determined how many key shares are necessary to reconstruct the base key; a new base key is generated through a quantum random number generator and the SSS protocol, while the old base key is destroyed.

[0050] The method of encrypting business content data in multi-dimensional biological data using the SM4 algorithm includes: Select the business content data to be encrypted from the multidimensional biological data, use the quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, use the 128-bit symmetric key to initialize the SM4 encryption algorithm, and divide the business content data into 16 bytes. If the number of bytes of the business content data is not a multiple of 16, it is padded until the length of the business content data reaches a multiple of 16. Each data block is encrypted using the SM4 encryption algorithm, and finally all encrypted data blocks are merged to obtain the complete encrypted business content data.

[0051] Methods for using the SM2 algorithm to generate session keys for forward secrecy include: Determine the sender and receiver of the communication, each of which holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received sender's public key and its own private key; The sender uses the SM2 algorithm to calculate the same shared key based on the received public key of the recipient and its own private key; based on the shared key, both parties further use the SM2 algorithm to derive the session key used for symmetric encryption to achieve forward secrecy.

[0052] The methods for constructing access risk assessment models include: Resource sensitive data includes financial data, core technology data, customer privacy data and legal compliance data; financial data includes financial statement data, tax information data, bank account data and invoice data; core technology data includes patent data and source code data; customer privacy data includes customer personal information, contact information and payment information data; legal compliance data includes compliance inspection record data, contract terms data and legal litigation record data; login environment data includes the IP address of the user when logging in, the device information data used by the user, the time of the user's access, the user's login location and the user behavior log; the user behavior log includes the user's operation record in the system, such as click flow, page access sequence, operation type, etc. The dataset is divided into training set, validation set and test set to train the model, evaluate the model performance and verify the model generalization ability; the sample set is a subset of the dataset, each sample set includes historical multidimensional biological data, resource sensitive data and login environment data and the corresponding access risk coefficient; GBDT is selected as the implementation of the gradient boosting tree model to handle the regression task; Initialize GBDT parameters, including the maximum number of leaf nodes in each tree, learning rate, number of trees, and maximum tree depth; use historical multidimensional biological data, resource-sensitive data, and login environment data as input data for the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model; Use mean square error as the loss function to measure the difference between the model's predicted value and the actual value; in each iteration, GBDT builds a new decision tree to fit the negative gradient of the loss function of the previous step, uses the negative gradient of the loss function as the learning target of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function; Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters based on its performance feedback until the model performance no longer improves or reaches the preset stopping condition; use the trained access risk assessment model to predict the current multidimensional biological data, resource sensitive data, and login environment data to obtain the access risk coefficient.

[0053] Based on the predicted access risk coefficient, methods for determining whether an enterprise encounters security risks include: Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold; If the predicted access risk coefficient is less than the access risk coefficient threshold, it is judged that the enterprise has not encountered security risks; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is judged that the enterprise has encountered security risks.

[0054] Methods for encrypting digital identity credentials using the SM1 encryption chip include: Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity certificate, and use the 128-bit symmetric key and the SM1 algorithm to convert the digital identity certificate into ciphertext data.

[0055] The preset access risk coefficient threshold is set by the staff. Different access risk coefficients are collected through the security access terminal, and the average value of multiple access risk coefficients is taken as the preset access risk coefficient threshold. Similarly, the preset similarity threshold is set. Similarly, the method of using the SM4 algorithm to encrypt resource sensitive data and login environment data is consistent with the method of using the SM4 algorithm to encrypt business content data in multi-dimensional biological data; Methods for using the SM1 decryption algorithm to recover digital identity credentials and decrypt resource-sensitive data and login environment data in the database include: Obtain the encrypted digital identity credentials, which have been previously encrypted using the SM1 encryption algorithm. Use the SM1 decryption algorithm to decrypt the encrypted digital identity credentials and restore them to the original credential data for confirming the user's identity. Obtain the encrypted resource-sensitive data from the database, which have been encrypted using the SM4 encryption algorithm in the previous processing. Use the SM4 key to decrypt the encrypted resource-sensitive data and restore them to the original content.

[0056] In this embodiment, biometric matching is used to ensure that the authentication object is a real user, avoiding the risk of identity forgery. When using dynamic token generation, timestamps, user unique identifiers and quantum random numbers are combined to further enhance the tamper-proof capability of the authentication process. The dynamic token is combined with a time binding mechanism, and can only be verified within a specified time window, effectively preventing replay attacks and enhancing the timeliness and security of the system. By introducing a timestamp and a valid time window mechanism, even if a hacker obtains a legitimate dynamic token, he or she cannot use the token again for authentication at a different time, greatly reducing the possibility of replay attacks. The preset dynamic token and time window mechanism can be flexibly adjusted according to system requirements and authentication requirements. Through the dynamic adjustment formula of the valid time window, the time window can be automatically optimized according to different biometric data feature numbers and time differences, thereby improving the adaptability and flexibility of the authentication process. The multi-factor authentication method that combines biometrics and dynamic tokens provides a higher level of security, while avoiding the cumbersome operations in traditional authentication methods and improving the user's authentication experience. The random number sequence generated by the quantum random number generator ensures that the generation of the basic key is highly random and unpredictable, enhances the security of the key, and reduces the risk of the key being cracked or forged; the quantum random number generator is distributed in different physical or logical security domains, and each generator generates a different random number sequence and serves as the source of the key share, which further increases the complexity and anti-attack capability of the key and avoids single point failure or centralized attack; the dynamic key update strategy defines the basic key update frequency and dynamically adjusts it according to the enterprise's risk assessment value, ensuring that the key update frequency matches the enterprise's security needs. According to the change of the risk assessment value, the system can adjust the key update frequency in time to adapt to the changes in the enterprise's operating environment. Through the enterprise risk assessment formula combined with factors such as the number of authentication failures, the frequency of sensitive resource access, and the abnormal login environment data, the enterprise's risk level is quantified and the key update frequency is accurately adjusted. Based on the risk assessment mechanism, it ensures that the key update strategy matches the actual risk situation of the enterprise, avoiding resource waste and unnecessary frequent updates. The dynamic adjustment of the risk sensitivity coefficient makes the key update frequency more refined and more adaptable, especially when facing sudden risk events, it can respond quickly and take security measures. The combination of quantum random number generator and SSS protocol provides a secure and efficient key management mechanism. The high intensity unpredictability of quantum random numbers combined with key segmentation and threshold reconstruction mechanism make the storage and use of keys safer.

[0057] Example 2 See also Figure 2 As shown, this embodiment provides an enterprise network data security access system for encryption processing, including: The multimodal identity authentication module is composed of a biometric unit and a device binding unit. The biometric unit identifies multidimensional biological data and combines the dynamic token generation time binding mechanism to authenticate the user. The device binding unit associates the identity authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential. Dynamic encryption transmission module, used to generate and roll over basic keys through quantum random number generator; use layered encryption unit to double protect multi-dimensional biometric data, layered encryption unit includes application layer and transport layer, application layer uses SM4 algorithm to encrypt business content data in multi-dimensional biometric data, and transport layer uses SM2 algorithm to generate session keys for forward secrecy; The intelligent access control module is used to obtain resource sensitive data and login environment data, and use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model to predict the access risk coefficient; based on the predicted access risk coefficient, it is determined whether the enterprise encounters security risks; Data storage encryption module: If the enterprise encounters security risks, it will trigger permission downgrade or secondary authentication instructions, and use SM1 encryption chip to encrypt digital identity credentials, and use SM4 algorithm to encrypt resource sensitive data and login environment data, and store them in the database; The data storage decryption module uses the SM1 decryption algorithm to recover the digital identity credentials and decrypt the resource-sensitive data and login environment data in the database to restore access if the enterprise has not encountered any security risks or the security risks have been resolved.

[0058] Since the electronic device introduced in this embodiment is an electronic device used to implement the enterprise network data security access method and system based on an encryption processing in the embodiment of this application, based on the enterprise network data security access method and system introduced in the embodiment of this application, the technical personnel of this field can understand the specific implementation of the electronic device of this embodiment and its various variations, so how the electronic device implements the method in the embodiment of this application is not described in detail here. As long as the technical personnel of this field implement the electronic device used by the enterprise network data security access method and system with an encryption processing in the embodiment of this application, it belongs to the scope of protection of this application.

[0059] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters and thresholds in the formula are set by technicians in this field according to actual conditions.

[0060] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technical users in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A method for securely accessing enterprise network data by encryption, characterized in that: include: S1. Construct a biometric identification unit and a device binding unit, identify multi-dimensional biological data through the biometric identification unit, and authenticate the user by combining the dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; S2. Generate and roll over basic keys through a quantum random number generator; perform dual protection on multidimensional biometric data through a layered encryption unit, which includes an application layer and a transport layer. The application layer uses the SM4 algorithm to encrypt the business content data in the multidimensional biometric data, and the transport layer uses the SM2 algorithm to generate session keys for forward secrecy; S3. Collect resource sensitive data and login environment data, use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model, and predict the access risk coefficient; based on the predicted access risk coefficient, determine whether the enterprise encounters security risks; S4. If the enterprise encounters security risks, it triggers permission downgrade or secondary authentication instructions, uses SM1 encryption chip to encrypt digital identity credentials, uses SM4 algorithm to encrypt resource sensitive data and login environment data, and stores them in the database; S5. If the enterprise has not encountered security risks or the security risks have been resolved, the SM1 decryption algorithm is used to restore the digital identity credentials, decrypt the resource-sensitive data and login environment data in the database, and restore access.

2. The method for securely accessing enterprise network data by encryption processing according to claim 1, characterized in that: The multi-dimensional biometric data includes biometric characteristic data and business content data; the biometric characteristic data includes physiological characteristic data and behavioral characteristic data; Physiological characteristic data include fingerprint data, facial data, iris data, voice data, palm print data and facial blood vessel data; behavioral characteristic data include the speed of user inputting characters on the keyboard, key interval, pressing time of each key, user mouse movement speed, mouse click frequency and gait data; Business content data includes business transaction data, enterprise operation data and real-time communication data; business transaction data includes order number, product information, transaction time, billing information, payment record, refund record, supplier information and procurement contract; enterprise document data includes enterprise management documents, internal notifications, R&D documents, legal documents, cooperation agreements and audit logs; real-time communication data includes enterprise IM records, shared documents and cloud editing records.

3. The method for securely accessing enterprise network data by encryption processing according to claim 2, characterized in that: The method for authenticating a user by combining a dynamic token generation time binding mechanism comprises: Preliminary user authentication is performed through biometric matching, and multidimensional biometric data is defined as a multidimensional feature vector ,in, For multidimensional biological data Features is the total number of features in multidimensional biological data; the preset standard multidimensional feature vector ;in, is the first in the standard multidimensional feature vector Features Calculate multidimensional feature vectors using cosine similarity and the standard multidimensional eigenvector The similarity between them is set to , if the multidimensional feature vector and the standard multidimensional eigenvector The similarity between them is greater than or equal to the preset similarity threshold , it is preliminarily determined that the user identity authentication has passed; The preset dynamic token is composed of the timestamp when the token is generated, the user's unique identifier and the quantum random number. The Kyber algorithm is used to exchange a key between the user and the authentication server. , using the key And HMAC function to generate dynamic token: ;in, Represents a dynamic time token; Indicates the process of dynamic token generation using HMAC function; Represents the key exchanged between the user and the server using the Kyber algorithm; Indicates the timestamp when the token was generated; A unique identifier representing the user; Represents the random number generated by the quantum random number generator; Represents a string concatenation operation; Preset effective time window The time binding mechanism is defined as follows: a dynamic token is valid only when the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window. The validity of the dynamic token is verified by the dynamic token validity verification formula; The dynamic token validity verification formula is: ;in, Represents the absolute difference between the current timestamp and the timestamp when the token was generated; Indicates the current timestamp; Indicates that if the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window, the dynamic token is valid; It means that if the absolute difference between the current timestamp and the timestamp when the token was generated is greater than the preset valid time window, the dynamic token will become invalid; The preset effective time window is dynamically adjusted through the effective time window adjustment formula. The effective time window adjustment formula is: ;in, is the effective time window after adjustment; A constant factor to adjust the effect of the total number of multidimensional biological data features on the time window; A constant factor that adjusts the effect of time difference on the time window; Only when the user identity authentication is passed and the dynamic token is valid can it be determined that the user has finally passed the identity authentication.

4. The method for securely accessing enterprise network data by encryption processing according to claim 3 is characterized in that: The method for generating and rolling updating a basic key by a quantum random number generator comprises: deploy Quantum random number generators are distributed in different physical or logical security domains. Each quantum random number generator generates a random number sequence and serves as the source of the basic key share. The random number sequence generated by each quantum random number generator is recorded as ,in, Indicates the number of the quantum random number generator, ranging from 1 to ; Define a dynamic key update strategy, the dynamic key update strategy includes defining a basic key update frequency and defining an adjustment rule for dynamically adjusting the basic key update frequency; the adjustment rule for dynamically adjusting the basic key update frequency includes defining an update time interval based on the basic key update frequency and dynamically adjusting the basic key update frequency through an update frequency adjustment formula according to an enterprise risk assessment value; The default enterprise risk assessment value is , the enterprise risk assessment value Obtained through the enterprise risk assessment formula; the enterprise risk assessment formula is: ;in, Indicates the number of times the user authentication failed; Indicates the number of times sensitive resource data is accessed; Indicates the number of abnormalities in the login environment data; The weight factor representing the impact of the number of failed user authentications on the enterprise risk assessment value; A weight factor indicating the impact of the number of times sensitive resource data is accessed on the enterprise risk assessment value; The weight factor representing the impact of the number of abnormal login environment data on the enterprise risk assessment value; The update frequency adjustment formula is: ;in, The frequency of updating the basic key; The frequency of updating the basic key after adjustment; is the risk sensitivity coefficient; The risk sensitivity coefficient is adjusted by the risk sensitivity adjustment formula Dynamic adjustment is performed, and the risk sensitivity adjustment formula is: ;in, is the risk sensitivity coefficient after dynamic adjustment; is the number of quantum random number generators; Influencing factors for risk assessment; is the base of natural logarithms; Through the SSS protocol, the basic key is split into key shares, distribute the key shares in all physical or logical security domains, each physical or logical security domain stores only one key share, and configure the key reconstruction threshold to , ensuring at least The complete base key can be reconstructed with key shares; a new base key is generated through the quantum random number generator and the SSS protocol, and the old base key is destroyed at the same time.

5. The method for securely accessing enterprise network data by encryption processing according to claim 4 is characterized in that: The method of encrypting the business content data in the multi-dimensional biological data by using the SM4 algorithm comprises: Select the business content data to be encrypted from the multidimensional biological data, use the quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, use the 128-bit symmetric key to initialize the SM4 encryption algorithm, and divide the business content data into 16 bytes. If the number of bytes of the business content data is not a multiple of 16, it is padded until the length of the business content data reaches a multiple of 16. Each data block is encrypted using the SM4 encryption algorithm, and finally all encrypted data blocks are merged to obtain the complete encrypted business content data.

6. The method for securely accessing enterprise network data by encryption processing according to claim 5, characterized in that: The method for using the SM2 algorithm to generate a session key for forward secrecy includes: Determine the sender and receiver of the communication, each of which holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received sender's public key and its own private key; The sender uses the SM2 algorithm to calculate the same shared key based on the received public key of the recipient and its own private key; based on the shared key, both parties further use the SM2 algorithm to derive the session key used for symmetric encryption to achieve forward secrecy.

7. The method for securely accessing enterprise network data by encryption processing according to claim 6, characterized in that: The method for constructing the access risk assessment model includes: The resource sensitive data includes financial data, core technology data, customer privacy data and legal compliance data; the login environment data includes the IP address of the user when logging in, the device information data used by the user, the time of the user's access, the user's login location and the user behavior log; The dataset is divided into training set, validation set and test set to train the model, evaluate the model performance and verify the model generalization ability; the sample set is a subset of the dataset, each sample set includes historical multidimensional biological data, resource sensitive data and login environment data and the corresponding access risk coefficient; GBDT is selected as the implementation of the gradient boosting tree model to handle the regression task; Initialize GBDT parameters, including the maximum number of leaf nodes in each tree, learning rate, number of trees, and maximum depth of trees; use historical multidimensional biological data, resource sensitive data, and login environment data as input data of the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model; Use mean square error as the loss function to measure the difference between the model's predicted value and the actual value; in each iteration, GBDT builds a new decision tree to fit the negative gradient of the loss function of the previous step, uses the negative gradient of the loss function as the learning target of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function; Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters based on its performance feedback until the model performance no longer improves or reaches the preset stopping condition; use the trained access risk assessment model to predict the current multidimensional biological data, resource sensitive data, and login environment data to obtain the access risk coefficient.

8. The method for securely accessing enterprise network data by encryption processing according to claim 7, characterized in that: The method for judging whether an enterprise encounters security risks according to the predicted access risk coefficient includes: Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold; If the predicted access risk coefficient is less than the access risk coefficient threshold, it is judged that the enterprise has not encountered security risks; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is judged that the enterprise has encountered security risks.

9. The method for securely accessing enterprise network data by encryption processing according to claim 8, characterized in that: The method of encrypting a digital identity certificate using an SM1 encryption chip includes: Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity certificate, and use the 128-bit symmetric key and the SM1 algorithm to convert the digital identity certificate into ciphertext data.

10. An encrypted enterprise network data security access system, used to implement the encrypted enterprise network data security access method according to any one of claims 1 to 9, characterized in that: include: The multimodal identity authentication module consists of a biometric unit and a device binding unit; The biometric unit recognizes multi-dimensional biometric data and authenticates the user by combining a dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; Dynamic encryption transmission module, used to generate and roll over basic keys through quantum random number generator; use layered encryption unit to double protect multi-dimensional biometric data, layered encryption unit includes application layer and transport layer, application layer uses SM4 algorithm to encrypt business content data in multi-dimensional biometric data, and transport layer uses SM2 algorithm to generate session keys for forward secrecy; The intelligent access control module is used to obtain resource sensitive data and login environment data, and use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model to predict the access risk coefficient; based on the predicted access risk coefficient, it is determined whether the enterprise encounters security risks; Data storage encryption module: If the enterprise encounters security risks, it will trigger permission downgrade or secondary authentication instructions, and use SM1 encryption chip to encrypt digital identity credentials, and use SM4 algorithm to encrypt resource sensitive data and login environment data, and store them in the database; The data storage decryption module uses the SM1 decryption algorithm to recover the digital identity credentials and decrypt the resource-sensitive data and login environment data in the database to restore access if the enterprise has not encountered any security risks or the security risks have been resolved.

Citation Information

Patent Citations

  • Access method, device and system for enterprise network

    CN118157916A

  • Data security interaction system and method based on Internet

    CN116527372A

  • Implementation method of secure and trusted physical network gateway

    CN116760633A

  • Enterprise sensitive data security access management method and system

    CN118656870A

  • Internet of Things data processing method and system based on block chain

    CN119249401A

Cited By

  • Data encryption method based on enterprise data security management

    CN120389915A

  • Key management system for bank-enterprise direct connection multi-level encryption transmission

    CN120474850A

  • Container mirror image security management method and system

    CN120597288A

  • Real-time data high-speed encryption method suitable for high-speed network

    CN121814471A

  • Non-intrusive inference and management method and system applied to voucher ownership of business application system

    CN122120044A