An enterprise network data security access method and system with encryption processing
By introducing multi-dimensional biodata identification and quantum random number generator in biometric authentication and dynamic token generation, combining dynamic token time binding mechanism and access risk assessment model, the problems of low authentication accuracy, insufficient anti-counterfeiting capabilities and static key update strategies in the prior art are solved, and higher identity authentication security and key management flexibility are achieved.
Patent Information
- Application Number
- CN202510487146.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-04-18
AI Technical Summary
The prior art has problems such as low authentication accuracy, insufficient anti-counterfeiting capabilities, poor key generation and storage security, and static key update strategies and inability to dynamically adjust them in terms of biometric authentication and dynamic token generation.
Multidimensional biodata identification and identity authentication are carried out by building biometric unit and device binding unit, combining with dynamic token generation time binding mechanism; using quantum random number generator to generate and roll updating the basic key, and double protection of multidimensional biological data is carried out through layered encryption; collect resource-sensitive data and login environment data, build an access risk assessment model to judge security risks, and dynamically adjust the key update frequency according to the risk assessment value.
It improves the accuracy and tamper-proof ability of identity authentication, enhances the security of keys and the flexibility of update strategies, and improves the adaptability and protection capabilities of the system.
Smart Images

Figure CN120017424B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology. More specifically, the present invention relates to a method and system for secure access to enterprise network data with encryption processing. Background Art
[0002] A patent with the publication number CN118157916A discloses a method for accessing an enterprise network, including: attaching a Virtual Extensible LAN (VXLAN) tag to an access data packet sent by a client through a regional network aggregation center switch, and forwarding the access data packet to a data center switch according to the VXLAN network access policy; sending the access data packet carrying the VXLAN tag to a zero-trust master server through the data center switch, so that the zero-trust master server verifies the access data packet and notifies the zero-trust gateway to establish a communication tunnel with the client. Building the enterprise network into a three-level leaf-spine network topology structure and introducing the VXLAN tag as an authentication factor for the access of clients located at member unit nodes can significantly reduce the risks of the enterprise network and improve the security of the enterprise network. The existing methods and systems for secure access to enterprise network data with encryption processing have the following main problems:
[0003] Existing biometric authentication systems usually rely on a single biometric for identity verification. Since biometrics are easily affected by environmental factors or individual differences, this may lead to low authentication accuracy, and even misidentification or missed identification. In addition, with the progress of technology, the means of forging and attacking biometrics are constantly updated, and the existing systems are still insufficient in preventing forged identities; although dynamic tokens can effectively improve the security of the authentication process, there are still certain vulnerabilities in the existing token generation mechanisms in preventing tampering. Some traditional dynamic token generation methods lack support for high-strength encryption algorithms, or the encryption methods used are easily cracked, which enables attackers to bypass authentication by tampering with the token content; there are vulnerabilities in the timeliness of authentication tokens in the existing technology. Hackers may replay old tokens at different time points, resulting in the authentication system failing to provide timely protection when facing rapidly changing attacks; lack of an automatic optimization mechanism. When the system environment changes, it is unable to automatically adjust the time window according to real-time biometrics, risk assessment, or time difference, affecting the adaptability and flexibility of the authentication process; the mechanism for dynamically updating keys and adjusting the key update frequency is not considered, and the key update process may be too static and lack flexibility;
[0004] Traditional random number generators may rely on mathematical algorithms or hardware noise. The generated random number sequences have certain regularities and may be cracked or predicted, thus affecting the security of keys. Existing keys are often stored centrally, making them easy targets for attackers. Single-point failures or centralized attacks may lead to key leakage or tampering, endangering the security of the entire system. Existing technologies usually adopt a fixed key update frequency and cannot dynamically adjust according to changes in the enterprise operation environment or fluctuations in security risks, which may result in over-updating or under-updating, affecting the security and resource utilization of the system. Traditional key management mechanisms fail to effectively cope with complex attack methods. Existing technologies lack sufficient protection during the storage and transmission of keys. Keys may be illegally accessed during storage or intercepted during transmission, leading to the risk of key leakage. Traditional key update mechanisms fail to respond promptly to sudden risk events faced by enterprises and cannot quickly update keys when security threats occur, resulting in a reduction in the security of the system. In existing technologies, the key update frequency is usually based on preset rules and lacks the ability to make refined adjustments according to specific risk levels, resulting in inflexible security measures and an inability to efficiently cope with risk changes in different scenarios.
[0005] In view of this, the present invention proposes an encrypted enterprise network data security access method and system to solve the above problems. Summary of the Invention
[0006] To overcome the above defects of the prior art and to achieve the above object, the present invention provides the following technical solution: An encrypted enterprise network data security access method, comprising:
[0007] S1. Construct a biometric recognition unit and a device binding unit, identify multi-dimensional biometric data through the biometric recognition unit, and perform user authentication by combining a dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the secure access terminal to generate a digital identity credential;
[0008] S2. Generate and roll-update a basic key through a quantum random number generator; perform double protection on multi-dimensional biometric data through a hierarchical encryption unit. The hierarchical encryption unit includes an application layer and a transmission layer. The application layer uses the SM4 algorithm to encrypt the service content data in the multi-dimensional biometric data, and the transmission layer uses the SM2 algorithm to generate a session key for forward secrecy;
[0009] S3. Collect resource-sensitive data and login environment data, use the multi-dimensional biometric data, resource-sensitive data, and login environment data as inputs to an access risk assessment model, and predict an access risk coefficient; judge whether the enterprise has encountered a security risk according to the predicted access risk coefficient;
[0010] S4. If an enterprise encounters security risks, permission downgrading or two-factor authentication instructions are triggered. The digital identity credential is encrypted using an SM1 encryption chip, and the resource-sensitive data and login environment data are encrypted using the SM4 algorithm and stored in the database.
[0011] S5. If the enterprise does not encounter security risks or the security risks have been resolved, the digital identity credential is restored using the SM1 decryption algorithm, and the resource-sensitive data and login environment data in the database are decrypted to resume access.
[0012] Preferably, the multi-dimensional biometric data includes biometric feature data and business content data; the biometric feature data includes physiological feature data and behavioral feature data; the physiological feature data includes fingerprint data, facial data, iris data, voice data, palmprint data, and facial vascular data; the behavioral feature data includes the speed of character input by the user on the keyboard, key press intervals, the pressing time of each key, the moving speed of the user's mouse, the frequency of mouse clicks, and gait data.
[0013] The business content data includes business transaction data, enterprise operation data, and real-time communication data; the business transaction data includes order numbers, product information, transaction times, billing information, payment records, refund records, supplier information, and procurement contracts; the enterprise document data includes enterprise management files, internal notifications, R & D documents, legal documents, cooperation agreements, and audit logs; the real-time communication data includes enterprise IM records, shared documents, and cloud editing records.
[0014] Preferably, the method for authenticating the user by combining the dynamic token generation time binding mechanism includes:
[0015] Performing preliminary user identity authentication through biometric matching, and defining the multi-dimensional biometric data as a multi-dimensional feature vector , where is the th feature in the multi-dimensional biometric data; is the total number of features in the multi-dimensional biometric data; the preset standard multi-dimensional feature vector ; where is the th feature in the standard multi-dimensional feature vector;
[0016] Calculating the similarity between the multi-dimensional feature vector and the standard multi-dimensional feature vector using the cosine similarity. The preset similarity threshold is . If the similarity between the multi-dimensional feature vector and the standard multi-dimensional feature vector is greater than or equal to the preset similarity threshold , then it is preliminarily determined that the user identity authentication is passed.
[0017] The preset dynamic token consists of the timestamp at the time of token generation, the user's unique identifier, and a quantum random number. A key is exchanged between the user and the authentication server using the Kyber algorithm , and the key and the HMAC function are used to generate the dynamic token: ; where represents the dynamic time token; represents the process of generating the dynamic token using the HMAC function; represents the key obtained by exchanging between the user and the server using the Kyber algorithm; represents the timestamp at the time of token generation; represents the user's unique identifier; represents the random number generated by the quantum random number generator; represents the string concatenation operation;
[0018] The preset valid time window is defined such that the time binding mechanism is: the dynamic token is only valid when the absolute difference between the current timestamp and the timestamp at the time of token generation is less than or equal to the preset valid time window ; the validity of the dynamic token is verified through the dynamic token validity verification formula;
[0019] The dynamic token validity verification formula is: ; where represents the absolute difference between the current timestamp and the timestamp at the time of token generation; represents the current timestamp; represents that if the absolute difference between the current timestamp and the timestamp at the time of token generation is less than or equal to the preset valid time window, the dynamic token is valid; represents that if the absolute difference between the current timestamp and the timestamp at the time of token generation is greater than the preset valid time window, the dynamic token is invalid;
[0020] The preset valid time window is dynamically adjusted through the valid time window adjustment formula, and the valid time window adjustment formula is: ; where is the adjusted valid time window; is a constant factor that adjusts the influence of the total number of multi-dimensional biological data features on the time window; is a constant factor that adjusts the influence of the time difference on the time window;
[0021] Only when the user's identity authentication is passed and the dynamic token is valid can it be determined that the user has finally passed the identity authentication.
[0022] Preferably, the method for generating and rolling up-dating a basic key by a quantum random number generator includes:
[0023] Deploy quantum random number generators, which are distributed in different physical or logical security domains. Each quantum random number generator generates a random number sequence, which serves as the source of the basic key share. Denote the random number sequence generated by each quantum random number generator as , where represents the number of the quantum random number generator, and its value range is from 1 to ;
[0024] Define a dynamic key update policy, which includes defining the basic key update frequency and the adjustment rule for dynamically adjusting the basic key update frequency. The adjustment rule for dynamically adjusting the basic key update frequency includes defining the update time interval based on the basic key update frequency and dynamically adjusting the basic key update frequency according to the enterprise risk assessment value through the update frequency adjustment formula;
[0025] Preset the enterprise risk assessment value as , and the enterprise risk assessment value is obtained through the enterprise risk assessment formula. The enterprise risk assessment formula is: ; where represents the number of user identity authentication failures; represents the number of times of accessing sensitive resource data; represents the number of anomalies in the login environment data; represents the weight factor of the number of user identity authentication failures on the enterprise risk assessment value; represents the weight factor of the number of times of accessing sensitive resource data on the enterprise risk assessment value; represents the weight factor of the number of anomalies in the login environment data on the enterprise risk assessment value;
[0026] The update frequency adjustment formula is: ; where is the basic key update frequency; is the adjusted basic key update frequency; is the risk sensitivity coefficient;
[0027] Dynamically adjust the risk sensitivity coefficient through the risk sensitivity adjustment formula. The risk sensitivity adjustment formula is: ; where is the dynamically adjusted risk sensitivity coefficient; is the number of quantum random number generators; is the risk assessment impact factor; is the base of the natural logarithm;
[0028] Through the SSS protocol, the basic key is split into key shares, and the key shares are distributed in all physical or logical security domains. Each physical or logical security domain stores only one key share, and the key reconstruction threshold is configured as to ensure that at least key shares are required to reconstruct the complete basic key; through the quantum random number generator and the SSS protocol, a new basic key is generated while the old basic key is destroyed.
[0029] Preferably, the method for encrypting the service content data in the multi-dimensional biological data using the SM4 algorithm includes:
[0030] Select the service content data to be encrypted from the multi-dimensional biological data, use the quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, initialize the SM4 encryption algorithm with the 128-bit symmetric key, divide the service content data into data blocks according to 16 bytes. If the number of bytes of the service content data is not a multiple of 16, padding is performed until the length of the service content data reaches a multiple of 16, and each data block is encrypted using the SM4 encryption algorithm. Finally, all the encrypted data blocks are merged to obtain the complete encrypted service content data.
[0031] Preferably, the method for generating a session key using the SM2 algorithm for forward secrecy includes:
[0032] Determine the sender and receiver of the communication, and each party holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received public key of the sender and its own private key;
[0033] The sender calculates the same shared key using the SM2 algorithm based on the received public key of the receiver and its own private key; based on this shared key, both parties further derive the session key for symmetric encryption using the SM2 algorithm to achieve forward secrecy.
[0034] Preferably, the method for constructing the access risk assessment model includes:
[0035] The resource sensitive data includes financial data, core technology data, customer privacy data, and legal compliance data; the login environment data includes the IP address when the user logs in, the device information data used by the user, the time when the user accesses, the login location of the user, and the user behavior log;
[0036] Divide the dataset into a training set, a validation set, and a test set, train the model, evaluate the model performance, and verify the model generalization ability; the sample set is a subset of the dataset, and each sample set includes historical multi-dimensional biological data, resource-sensitive data, and login environment data, as well as the corresponding access risk coefficient; select GBDT as the implementation of the gradient boosting tree model to handle regression tasks;
[0037] Initialize the GBDT parameters, where the GBDT parameters include the maximum number of leaf nodes in each tree, the learning rate, the number of trees, and the maximum depth of the tree; use the historical multi-dimensional biological data, resource-sensitive data, and login environment data as the input data of the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model;
[0038] Use the mean squared error as the loss function to measure the difference between the predicted value and the actual value of the model; in each iteration, GBDT constructs a new decision tree to fit the negative gradient of the loss function in the previous step, uses the negative gradient of the loss function as the learning objective of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function;
[0039] Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters according to its performance feedback until the model performance no longer improves or reaches the preset stop condition; use the trained access risk assessment model to predict the current multi-dimensional biological data, resource-sensitive data, and login environment data to obtain the access risk coefficient.
[0040] Preferably, the method for determining whether an enterprise encounters a security risk according to the predicted access risk coefficient includes:
[0041] Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold;
[0042] If the predicted access risk coefficient is less than the access risk coefficient threshold, it is determined that the enterprise has not encountered a security risk; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is determined that the enterprise has encountered a security risk.
[0043] Preferably, the method for encrypting the digital identity credential using an SM1 encryption chip includes:
[0044] Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity credential, and convert the digital identity credential into ciphertext data using the 128-bit symmetric key and the SM1 algorithm.
[0045] An encrypted enterprise network data security access system includes:
[0046] The multi-modal identity authentication module is composed of a biometric recognition unit and a device binding unit; it recognizes multi-dimensional biometric data through the biometric recognition unit and conducts identity authentication for users by combining a dynamic token generation time binding mechanism; the device binding unit associates the identity authentication result with the hardware fingerprint of the secure access terminal to generate a digital identity credential;
[0047] The dynamic encryption transmission module is used to generate and roll-update the base key through a quantum random number generator; it uses a hierarchical encryption unit to double-protect the multi-dimensional biometric data. The hierarchical encryption unit includes an application layer and a transmission layer. The application layer encrypts the service content data in the multi-dimensional biometric data using the SM4 algorithm, and the transmission layer uses the SM2 algorithm to generate a session key for forward secrecy;
[0048] The intelligent access control module is used to obtain resource sensitive data and login environment data, use the multi-dimensional biometric data, resource sensitive data and login environment data as the input of the access risk assessment model, and predict the access risk coefficient; according to the predicted access risk coefficient, determine whether the enterprise encounters a security risk;
[0049] The data storage encryption module, if the enterprise encounters a security risk, triggers a privilege downgrade or secondary authentication instruction, and uses an SM1 encryption chip to encrypt the digital identity credential, uses the SM4 algorithm to encrypt the resource sensitive data and login environment data, and stores them in the database;
[0050] The data storage decryption module, if the enterprise does not encounter a security risk or the security risk has been lifted, uses the SM1 decryption algorithm to restore the digital identity credential, and decrypts the resource sensitive data and login environment data in the database to restore access.
[0051] The technical effects and advantages of the encryption processing method and system for enterprise network data security access of the present invention:
[0052] Through biometric matching, it ensures that the authenticated object is a real user, avoiding the risk of forged identities. When generating dynamic tokens, it combines timestamps, user unique identifiers, and quantum random numbers to further enhance the anti-tampering ability of the authentication process. The dynamic token combines a time-binding mechanism and can only pass verification within a specified time window, effectively preventing replay attacks and enhancing the timeliness and security of the system. By introducing the mechanisms of timestamps and valid time windows, even if a hacker obtains a legitimate dynamic token, they cannot use the token for authentication at different times, greatly reducing the possibility of replay attacks. The preset dynamic token and time window mechanism can be flexibly adjusted according to system requirements and authentication requirements. Through the dynamic adjustment formula of the valid time window, it can automatically optimize the time window based on different biometric data feature numbers and time differences, improving the adaptability and flexibility of the authentication process. The multi-factor authentication method combining biometrics and dynamic tokens provides a higher level of security protection, while avoiding the cumbersome operations in traditional authentication methods and improving the user's authentication experience.
[0053] The random number sequence generated by the quantum random number generator ensures that the generation of the base key has high randomness and unpredictability, enhancing the security of the key and reducing the risk of the key being cracked or forged. The quantum random number generators are distributed in different physical or logical security domains, and each generator generates a different random number sequence and serves as the source of the key share, further increasing the complexity and anti-attack ability of the key and avoiding single-point failures or centralized attacks. The dynamic key update strategy ensures the matching of the key update frequency with the enterprise's security requirements by defining the base key update frequency and dynamically adjusting it according to the enterprise's risk assessment value. According to the change of the risk assessment value, the system can timely adjust the key update frequency to adapt to the change of the enterprise's operating environment. By combining factors such as the number of authentication failures, the frequency of accessing sensitive resources, and abnormal login environment data through the enterprise risk assessment formula, it quantifies the enterprise's risk level and precisely adjusts the key update frequency. The mechanism based on risk assessment ensures that the key update strategy matches the actual risk situation of the enterprise, avoiding resource waste and unnecessary frequent updates. The dynamic adjustment of the risk sensitivity coefficient makes the key update frequency more refined and adaptable. Especially when facing sudden risk events, it can quickly respond and take security measures. By combining the quantum random number generator with the SSS protocol, it provides a secure and efficient key management mechanism. The high-strength unpredictability of quantum random numbers combined with the key splitting and threshold reconstruction mechanism makes the storage and use of keys more secure. Brief Description of the Drawings
[0054] Figure 1 It is a schematic flow diagram of a method for secure access to enterprise network data with encryption processing according to the present invention;
[0055] Figure 2 This is a schematic diagram of the structure of an encrypted enterprise network data security access system of the present invention;
[0056] Figure 3 This is a flow chart of the method for generating session keys for forward secrecy using the SM2 algorithm provided in the present invention. DETAILED DESCRIPTION
[0057] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0058] Example 1
[0059] See also Figure 1 and Figure 3 As shown, this embodiment further illustrates an encrypted enterprise network data security access method proposed by the present invention, including:
[0060] With the rapid development of information technology, the security of enterprise network data has gradually become a focus of attention. Enterprises are increasingly dependent on network data transmission and sharing, and are facing increasingly complex security threats and attacks, especially in the fields of identity authentication and key management. Although traditional network security protection measures provide certain guarantees for the security of network data, there are still some problems that need to be solved in practical applications.
[0061] First, biometric authentication technology is widely used in corporate identity authentication, but existing biometric authentication technology usually relies on a single biometric feature (such as fingerprint, face, iris, etc.) for identity authentication. These biometric features may be affected by environmental factors (such as light, temperature, noise, etc.) or individual differences (such as scars, aging, etc.), thereby reducing the accuracy of authentication and may even lead to misidentification or missed identification. In addition, with the advancement of technology, the forgery and simulation technology of biometric features has become increasingly mature. Attackers can bypass authentication by forging biometric features, resulting in insufficient anti-counterfeiting capabilities of the system, which seriously affects the security of the system.
[0062] Secondly, dynamic tokens are widely used to enhance the security of authentication, but there are still some problems in existing dynamic token generation mechanisms. Some traditional dynamic token generation methods use encryption algorithms with insufficient strength, or the encryption methods adopted are easily cracked, resulting in attackers being able to bypass authentication by tampering with the token content. In addition, existing authentication technologies are weak in preventing replay attacks, especially with vulnerabilities in the timeliness of tokens. Hackers can replay old dynamic tokens at different time points, thus successfully bypassing the authentication process, which makes the system unable to provide effective protection in the face of rapidly changing attacks.
[0063] Existing technologies usually lack an automatic optimization mechanism. When the system environment changes, they cannot automatically adjust the time window in the authentication process according to real-time biometric data, risk assessment results, or time differences. This lack of flexibility and adaptability in design leads to the authentication process of the system being unable to dynamically respond to changing security requirements, affecting the accuracy of authentication and the user experience.
[0064] In terms of key management, traditional key generation and storage methods still face many challenges. Many existing key generators rely on mathematical algorithms or hardware noise to generate random numbers. The generation of these random numbers usually has regularity and may be cracked or predicted, thus reducing the security of the keys. In addition, traditional keys are often stored centrally, posing a risk of single point of failure. Once an attacker successfully breaks through the protection of the key storage area, it may lead to key leakage or tampering, thus posing a serious threat to the entire system.
[0065] For the key update mechanism, most existing technologies adopt a fixed update frequency and cannot flexibly adjust the key update frequency according to actual security requirements and the enterprise's operating environment. When the system faces different security risks, it may fail to adjust the key update frequency in a timely manner, resulting in inappropriate timing of key updates and affecting the security of the system. In addition, existing key management mechanisms are insufficient in preventing complex attack methods, especially in the storage and transmission processes of keys, lacking sufficient protection measures, resulting in an increased risk of key leakage.
[0066] To address these technical problems, the present invention proposes a method for secure access to enterprise network data with encryption processing, including:
[0067] S1. Construct a biometric recognition unit and a device binding unit. Identify multi-dimensional biometric data through the biometric recognition unit, and authenticate the user's identity by combining the dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the secure access terminal to generate a digital identity credential;
[0068] S2. Generate and roll - update the base key through a quantum random number generator; double - protect the multi - dimensional biological data through a hierarchical encryption unit, where the hierarchical encryption unit includes an application layer and a transmission layer. The application layer encrypts the service content data in the multi - dimensional biological data using the SM4 algorithm, and the transmission layer generates a session key using the SM2 algorithm for forward secrecy;
[0069] S3. Collect resource - sensitive data and login environment data, use the multi - dimensional biological data, resource - sensitive data, and login environment data as inputs to an access risk assessment model, and predict the access risk coefficient; based on the predicted access risk coefficient, determine whether the enterprise has encountered a security risk;
[0070] S4. If the enterprise has encountered a security risk, then trigger a privilege downgrade or two - factor authentication instruction, encrypt the digital identity credential using an SM1 encryption chip, encrypt the resource - sensitive data and login environment data using the SM4 algorithm, and store them in the database;
[0071] S5. If the enterprise has not encountered a security risk or the security risk has been lifted, then use the SM1 decryption algorithm to restore the digital identity credential, decrypt the resource - sensitive data and login environment data in the database, and restore access.
[0072] The multi - dimensional biological data includes biometric data and service content data; the biometric data includes physiological characteristic data and behavioral characteristic data; the physiological characteristic data includes fingerprint data, facial data, iris data, voice data, palmprint data, and facial vascular data; the behavioral characteristic data includes the speed at which a user enters characters on the keyboard, the key - press interval, the pressing time of each key, the moving speed of the user's mouse, the frequency of clicking the mouse, and gait data; the gait data includes the user's walking pattern and pace rhythm, and gait data can be obtained by combining the accelerometer and gyroscope of a wearable device;
[0073] The service content data includes business transaction data, enterprise operation data, and real - time communication data; the business transaction data includes order numbers, product information, transaction times, billing information, payment records, refund records, supplier information, and procurement contracts; the enterprise document data includes enterprise management files, internal notices, R & D documents, legal documents, cooperation agreements, and audit logs; the real - time communication data includes enterprise IM records, shared documents, and cloud editing records.
[0074] A method for user authentication by combining a dynamic token generation time - binding mechanism includes:
[0075] Perform preliminary user identity authentication through biometric matching, and define the multi - dimensional biological data as a multi - dimensional feature vector , where is the th feature in the multi - dimensional biological data; is the total number of features in the multi-dimensional biological data; the preset standard multi-dimensional feature vector ; where is the th feature in the standard multi-dimensional feature vector;
[0076] Use cosine similarity to calculate the similarity between the multi-dimensional feature vector and the standard multi-dimensional feature vector . The preset similarity threshold is . If the similarity between the multi-dimensional feature vector and the standard multi-dimensional feature vector is greater than or equal to the preset similarity threshold , then it is preliminarily determined that the user identity authentication is passed;
[0077] The preset dynamic token is composed of the timestamp at the time of token generation, the user's unique identifier, and a quantum random number. Use the Kyber algorithm to exchange a key between the user and the authentication server , and use the key and the HMAC function to generate a dynamic token: ; where represents the dynamic time token; represents the process of generating a dynamic token using the HMAC function; represents the key exchanged between the user and the server using the Kyber algorithm; represents the timestamp at the time of token generation; represents the user's unique identifier; represents the random number generated by the quantum random number generator; represents the string concatenation operation;
[0078] Preset the effective time window . To ensure the validity of the dynamic token, define the time binding mechanism as: the dynamic token is only valid when the absolute difference between the current timestamp and the timestamp at the time of token generation is less than or equal to the preset effective time window ; verify the validity of the dynamic token through the dynamic token validity verification formula;
[0079] The dynamic token validity verification formula is: ; where represents the absolute difference between the current timestamp and the timestamp at the time of token generation, usually in seconds; represents the current timestamp; represents that if the absolute difference between the current timestamp and the timestamp at the time of token generation is less than or equal to the preset effective time window, the dynamic token is valid; It indicates that if the absolute difference between the current timestamp and the timestamp when the token was generated is greater than the preset valid time window, the dynamic token becomes invalid;
[0080] For example, assume the current timestamp seconds (12:20:20 on July 5, 2021), the token generation timestamp seconds (11:58:20 on July 5, 2021), and the preset valid time window seconds (i.e., 5 minutes). Then the absolute difference between the current timestamp and the timestamp when the token was generated seconds. Since 120 seconds is less than the preset valid time window of 300 seconds, , the dynamic token is valid;
[0081] It should be noted that the seconds here refers to the number of seconds elapsed from 00:00:00 UTC on January 1, 1970 to 12:20:20 UTC on July 5, 2021. UTC is the globally recognized time standard and is used as the reference time for many modern computer systems and protocols; January 1, 1970 was chosen as the UNIX epoch and UTC is used as the unified time zone, enabling computer systems and networks around the world to process and exchange time on a common basis, avoiding the complexity brought by different time zones;
[0082] The preset valid time window is dynamically adjusted through the valid time window adjustment formula. The valid time window adjustment formula is: ; where is the adjusted valid time window; is the constant factor that adjusts the influence of the total number of multi-dimensional biological data features on the time window; is the constant factor that adjusts the influence of the time difference on the time window; n is the total number of features in the multi-dimensional biological data; is the preset valid time window;
[0083] It should be noted that the design of the effective time window adjustment formula is based on the need for dynamic time window adjustment, aiming to address the limitations of the fixed time window in multi-dimensional biological data analysis. Traditional fixed time window methods usually assume uniform data distribution and consistent time correlation. However, in practical applications, data at different time points may have different importance, and the characteristic dimensions of the data will also affect the reasonable setting of the time window. Therefore, through the time difference, the total number of features, and the adjustment factor, this formula introduces an adaptive adjustment mechanism to optimize the size of the time window to make it more in line with the actual data distribution. The effective time window adjustment formula does not simply linearly scale the time window. Instead, through the influence terms of the time difference and the total number of features in the numerator part, combined with the time difference suppression term in the denominator, it forms a non-linear dynamic adjustment method to ensure that the time window will not increase or decrease infinitely, but can be reasonably adjusted with the change of data. When the time difference is small, the adjusted time window is close to the initial value to ensure the time consistency of the data. When the time difference is large, the time window is appropriately enlarged to avoid losing key information due to too small a time window. At the same time, the formula also introduces the logarithmic term of the total number of features, so that when the data dimension increases, the adjustment of the time window has a smooth characteristic and will not change violently, thereby improving the adaptability of the algorithm.
[0084] Through the effective time window adjustment formula, the non-linear influence of the number of data features and time correlation can be better simulated, and an adaptive adjustment effect is shown when the data time span is large, making the time window adjustment more in line with the actual situation of the data. Traditional time window adjustment methods usually adopt fixed values or simple linear adjustment methods. For example, the time window is directly enlarged or reduced proportionally according to the time difference. This method may be effective when the data distribution is relatively uniform, but in the multi-dimensional data scenario, especially when different numbers of features are involved, the fixed adjustment method may lead to too large or too small a time window, affecting the accuracy of data analysis. And this formula, by introducing the non-linear influence of the time difference and the feature dimension adjustment mechanism, not only enhances the dynamic adaptability of the time window, but also avoids the errors that may be brought by linear adjustment, making it applicable to more complex data environments and improving the flexibility and stability of time window adjustment.
[0085] In addition, the denominator part of the effective time window adjustment formula introduces a time difference suppression term, so that when the time difference increases, the adjustment of the time window will not expand infinitely, but tend to a stable value, avoiding the problem of over-adjustment. Compared with the existing technologies, the effective time window adjustment formula can adaptively adjust the time window according to the data time span and the number of features in a dynamic data environment, not only improving the accuracy of data processing, but also enhancing the applicability under different data distribution conditions, making it more in line with the actual needs of multi-dimensional biological data analysis.
[0086] Only when the user identity authentication is passed and the dynamic token is valid can it be determined that the user finally passes the identity authentication.
[0087] The method for generating and rolling up-dating a basic key through a quantum random number generator includes:
[0088] Deploy a quantum random number generator, which is distributed in different physical or logical security domains. A physical security domain refers to an area protected by physical means. It usually involves data centers, server rooms, office areas, etc., and uses physical isolation and protection measures (such as access control, monitoring, physical firewalls, etc.) to restrict access to devices and information. The design goal of a physical security domain is to prevent unauthorized personnel from directly accessing hardware devices, storage media, and other critical infrastructure.
[0089] For example:
[0090] Data center: A physical security domain may be a data center or a computer room, and only authorized personnel can enter.
[0091] Encryption device: Such as a hardware security module (HSM) or an encryption chip, and these devices are usually placed in a controlled area.
[0092] A logical security domain refers to a virtual isolation area created through software and technical means to protect the security of data and information systems. This isolation is achieved through access control at levels such as networks, operating systems, and databases. A logical security domain does not depend on a physical location, but ensures the security and isolation of data access through configuration and management.
[0093] For example:
[0094] Virtual machine isolation: Use virtualization technology to create multiple logical security domains. Each virtual machine (VM) can be regarded as a logical security domain, and the data and operations therein are isolated from each other.
[0095] Network isolation: Restrict access between different network areas through network access control lists (ACLs) or virtual local area networks (VLANs), so that the data of different departments or user groups cannot be accessed by other groups.
[0096] Each quantum random number generator generates a random number sequence, which serves as the source of the basic key share; denote the random number sequence generated by each quantum random number generator as , where represents the number of the quantum random number generator, and its value range is from 1 to ;
[0097] Define a dynamic key update policy, which includes defining the basic key update frequency and the adjustment rules for dynamically adjusting the basic key update frequency; the adjustment rules for dynamically adjusting the basic key update frequency include defining the update time interval based on the basic key update frequency (for example, updating once per hour) and dynamically adjusting the basic key update frequency according to the enterprise risk assessment value through the update frequency adjustment formula;
[0098] Preset the enterprise risk assessment value as , and the enterprise risk assessment value is obtained through the enterprise risk assessment formula; the enterprise risk assessment formula is: ; where represents the number of times of user identity authentication failure; represents the number of times of accessing sensitive resource data; represents the number of anomalies in the login environment data; represents the weight factor of the number of times of user identity authentication failure on the enterprise risk assessment value; represents the weight factor of the number of times of accessing sensitive resource data on the enterprise risk assessment value; represents the weight factor of the number of anomalies in the login environment data on the enterprise risk assessment value;
[0099] It should be noted that , and need to be adjusted according to the real-time feedback of the system. The initial value range of setting is 0.3 - 0.5, and the default value is 0.4; it means that in the case of no special anomalies, the impact of the number of times of identity authentication failure on risk assessment occupies a relatively moderate proportion. By analyzing historical data, evaluate the contribution of the number of times of user identity authentication failure to enterprise security. If a user fails to log in multiple times (for example, fails several times in a row), this may mean potential malicious access behavior and increase the enterprise security risk. Therefore, needs to be adjusted according to historical data analysis:
[0100] If historical data shows that identity authentication failure directly leads to a security incident (such as brute force password cracking), then increase value (such as setting it to 0.6 or higher); if historical data shows that the correlation between the number of times of identity authentication failure and actual risk events is low, value can be reduced (such as setting it to 0.3 or lower); combined with real-time data feedback (such as the number of abnormal logins or abnormal IPs monitored in real time), dynamically adjust to ensure that the impact of identity authentication can be more emphasized in high-risk situations;
[0101] Set The initial value range of is 0.2 - 0.4, and the default value is 0.3, indicating that the impact of the behavior of accessing sensitive data on security risks is initially estimated to be medium; by reviewing historical access logs, analyze the contribution of sensitive data access to security risks. For example, if some users frequently access a large amount of sensitive data without clear business needs, it may imply the potential risk of data leakage.
[0102] If historical data shows that the abnormal behavior of sensitive data access is highly correlated with security incidents (such as unauthorized access to sensitive data by internal personnel), then it is necessary to increase 's value (such as 0.5 or higher); if historical data shows that the correlation between the access of sensitive data and security incidents is weak, then can be appropriately reduced 's value (such as 0.2 or lower); combined with real-time access logs, analyze the access behavior of users to sensitive data in real time and dynamically adjust to ensure that the risks of sensitive data access are effectively reflected in actual access behaviors.
[0103] Set 's initial value range to 0.2 - 0.4, and the default value is 0.3; it indicates that the impact of abnormal situations in the login environment on risk assessment is initially estimated to be medium; by analyzing historical environmental abnormal data, evaluate the contribution of environmental anomalies (such as abnormal login geographical locations, changes in device fingerprints, etc.) to enterprise security. For example, a user logging in during non-office hours or on an infrequently used device may indicate the risk of account hijacking.
[0104] If historical data shows that environmental data anomalies are directly related to malicious behaviors (such as account hijacking), then it is necessary to increase 's value (such as set to 0.5 or higher). If historical data shows that environmental data anomalies are not often related to security incidents, then 's value can be appropriately reduced (such as set to 0.2 or lower); combined with real-time login environment data (such as the user's IP location, device fingerprint, operating system information, etc.), dynamically adjust to ensure that when environmental anomalies occur, they can be promptly reflected and the risk assessment can be increased.
[0105] If through historical data analysis, it is found that the relationship between identity authentication failures and actual security threats is very close (for example, the probability of causing data leakage incidents is high), then the weight of can be appropriately increased and set to 0.6, while reducing the weights of other factors. Similarly, if some anomalies in the login environment (such as abnormal IP addresses) significantly predict potential attack behaviors, then can be increased to increase the sensitivity to environmental anomalies.
[0106] The update frequency adjustment formula is: ; among them, is the basic key update frequency; is the adjusted basic key update frequency; is the risk sensitivity coefficient, which controls the impact of the enterprise risk assessment value on the update frequency;
[0107] The risk sensitivity coefficient is dynamically adjusted through the risk sensitivity adjustment formula, and the response intensity of the system in the face of different risk situations is dynamically adjusted, so as to ensure that the enterprise network security system can adapt to the changing threat environment and improve the response ability. Specifically, the purposes of the adjustment can include the following aspects:
[0108] 1. Enhance the adaptability and flexibility of the system:
[0109] Dynamically adapt to risk changes: As the network environment and attack patterns are constantly changing, the system needs to dynamically adjust the risk sensitivity coefficient according to the real-time risk assessment value to ensure that it can adapt to different risk scenarios. For example, when the system detects a high-risk situation (such as an attack attempt, abnormal behavior, etc.), by increasing the risk sensitivity coefficient, the execution intensity of security protection measures can be increased, such as raising the authentication requirements and strengthening access control.
[0110] Adjust according to the number of quantum random number generators: The more the number of quantum random number generators, the stronger the generated randomness and security. The system can perform more accurate risk assessment under higher security guarantees. Therefore, the number of quantum random number generators is used as a factor in the adjustment formula to ensure that when the number of quantum random number generators increases, the system can reflect higher security.
[0111] 2. Control the intensity of security response:
[0112] Control the response intensity according to the risk assessment value: The risk assessment value is a key factor in evaluating the risks faced by the current system. By adjusting the risk sensitivity coefficient in the adjustment formula, the response intensity of the system in different risk situations can be controlled. For example, in a low-risk situation, the system can maintain a low risk sensitivity to ensure that the user experience is not affected; but in a high-risk situation, the system will automatically enhance its security protection measures, increase the strictness of authentication, access restrictions, etc., to reduce potential threats.
[0113] Balance security and efficiency: By flexibly adjusting the risk sensitivity coefficient, the system can ensure high security while avoiding affecting business efficiency or user experience due to excessive protection. For example, in normal low-risk situations, a lower risk sensitivity coefficient helps to ensure the rapid response of the system and a smooth user experience.
[0114] 3. Improve the accuracy and refined management of security protection:
[0115] Quantitative risk management: The risk sensitivity coefficient adjustment formula can quantify the relationship between security risks and protection responses, providing a more accurate and controllable mechanism for the system. The system can not only adjust based on existing security events (such as identity authentication failures, access to sensitive resource data, etc.), but also make adaptive responses according to real-time risk changes in the network, thereby reducing false alarms and missed alarms.
[0116] Risk classification management: According to different risk assessment results, the risk sensitivity coefficient can be adjusted in a graded manner. For example, the system can set different thresholds. When the risk assessment value reaches a preset high-risk threshold, the security authentication and auditing of access requests are immediately strengthened to ensure timely action when risks occur.
[0117] 4. Optimize the key update strategy:
[0118] Affect the key update frequency: By adjusting the risk sensitivity coefficient, the system can adjust the update frequency of the base key according to the real-time risk assessment value (for example, update the key frequently or delay the update). In high-risk situations, frequent key updates can reduce potential security threats; while in low-risk situations, the key update frequency can be appropriately reduced to improve system efficiency and reduce the cost of excessive operations.
[0119] 5. Improve the intelligence of protection measures:
[0120] Automated decision-making: Through this adjustment mechanism, the system can automatically adjust the risk sensitivity coefficient according to real-time data (such as the number of quantum random number generators and the risk assessment value), and trigger different security measures according to different risk scenarios. For example, when the risk is low, the system can reduce the intensity of security measures to ensure smooth business; while when the risk is high, the system will increase the intensity of security measures, thus forming an intelligent and automated security protection system.
[0121] The risk sensitivity adjustment formula is: ; where is the risk sensitivity coefficient after dynamic adjustment; is the number of quantum random number generators; is the risk assessment impact factor, indicating the degree of influence of the risk assessment value on the risk sensitivity coefficient; is the base of the natural logarithm;
[0122] It should be noted that the risk sensitivity adjustment formula introduces the number of quantum random number generators and the enterprise risk assessment value , reflecting the balance between the security of the system and risks. When there are more quantum random number generators, the system has a higher level of security. At this time, the risk sensitivity coefficient should be relatively high to cope with potential higher threats. When the risk assessment value is high, the system should automatically increase protective measures to ensure a quick response to high-risk situations; dynamically adjust the risk sensitivity coefficient according to the real-time enterprise risk assessment value and the security capabilities of the system (represented by the number of quantum random number generators). This adjustment mechanism enables the system to flexibly respond to different security threats. Whether the security is enhanced or the risk increases, it can be adjusted within a reasonable range;
[0123] As the external environment and system state change, the risk sensitivity needs to be adjusted flexibly. An overly fixed sensitivity may cause the system to be either overly sensitive or insensitive. By introducing a dynamic adjustment mechanism, the formula can achieve precise adjustment of risks under complex environmental conditions, enabling the system to react based on new information; traditional methods for adjusting risk sensitivity are often too complex, relying on multiple calculations and complex physical derivations. The risk sensitivity adjustment formula is expressed through a simple logical function, which can avoid excessive complex calculations while retaining a high degree of flexibility and adaptability. The simplicity of the formula enables engineers and technicians to quickly understand and implement it, and it can be flexibly adjusted according to specific application scenarios.
[0124] For example, the risk sensitivity coefficient is 0.4, the system deploys 5 quantum random number generators, the current enterprise risk assessment value is 7, and the risk assessment impact factor is 0.2. Then the dynamically adjusted risk sensitivity coefficient ;
[0125] Through the SSS protocol, the basic key is split into key shares, and the key shares are distributed in all physical or logical security domains. Each physical or logical security domain stores only one key share, and the key reconstruction threshold value is configured as , ensuring that at least key shares are required to reconstruct the complete basic key; in this solution, the basic key is split into key shares, and each key share is stored in a different physical or logical security domain. To prevent single-point failures or leaks, no single key share can reconstruct the complete basic key. The threshold value determines how many key shares are necessary to reconstruct the basic key; through the quantum random number generator and the SSS protocol, a new basic key is generated while the old basic key is destroyed.
[0126] The method for encrypting the service content data in multi-dimensional biological data using the SM4 algorithm includes:
[0127] Select the business content data to be encrypted from the multi-dimensional biological data, use a quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, initialize the SM4 encryption algorithm with the 128-bit symmetric key, and divide the business content data into data blocks according to 16 bytes. If the number of bytes of the business content data is not a multiple of 16, padding is performed until the length of the business content data reaches a multiple of 16. Use the SM4 encryption algorithm to encrypt each data block, and finally merge all the encrypted data blocks to obtain the complete encrypted business content data.
[0128] The method for generating a session key using the SM2 algorithm for forward secrecy includes:
[0129] Determine the sender and receiver of the communication, and each party holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received public key of the sender and its own private key;
[0130] The sender calculates the same shared key using the SM2 algorithm based on the received public key of the receiver and its own private key; based on this shared key, both parties further use the SM2 algorithm to derive the session key for symmetric encryption to achieve forward secrecy.
[0131] The method for constructing an access risk assessment model includes:
[0132] Resource sensitive data includes financial data, core technology data, customer privacy data, and legal compliance data; financial data includes financial statement data, tax information data, bank account data, and invoice data; core technology data includes patent data and source code data; customer privacy data includes customer personal information, contact information, and payment information data; legal compliance data includes compliance inspection record data, contract clause data, and legal litigation record data; login environment data includes the IP address when the user logs in, the device information data used by the user, the time when the user accesses, the user's login location, and the user behavior log; the user behavior log includes the operation records of the user in the system, such as click stream, page access order, operation type, etc.;
[0133] Divide the data set into a training set, a validation set, and a test set, train the model, evaluate the model performance, and verify the model generalization ability; the sample set is a subset of the data set, and each sample set includes historical multi-dimensional biological data, resource sensitive data, and login environment data, as well as the corresponding access risk coefficient; select GBDT as the implementation of the gradient boosting tree model to handle the regression task;
[0134] Initialize the GBDT parameters, where the GBDT parameters include the maximum number of leaf nodes in each tree, the learning rate, the number of trees, and the maximum depth of the trees; use historical multi-dimensional biological data, resource-sensitive data, and login environment data as the input data of the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model.
[0135] Use the mean squared error as the loss function to measure the difference between the predicted value and the actual value of the model; in each iteration, GBDT constructs a new decision tree to fit the negative gradient of the loss function in the previous step, uses the negative gradient of the loss function as the learning objective of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function.
[0136] Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters according to its performance feedback until the model performance no longer improves or reaches the preset stop condition; use the trained access risk assessment model to predict the current multi-dimensional biological data, resource-sensitive data, and login environment data to obtain the access risk coefficient.
[0137] The method for judging whether an enterprise encounters a security risk based on the predicted access risk coefficient includes:
[0138] Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold;
[0139] If the predicted access risk coefficient is less than the access risk coefficient threshold, it is judged that the enterprise has not encountered a security risk; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is judged that the enterprise has encountered a security risk.
[0140] The method for encrypting digital identity credentials using an SM1 encryption chip includes:
[0141] Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity credentials, and convert the digital identity credentials into ciphertext data using the 128-bit symmetric key and the SM1 algorithm.
[0142] The preset access risk coefficient threshold is set by the staff. Different access risk coefficients are collected through the secure access terminal, and the average value of multiple access risk coefficients is taken as the preset access risk coefficient threshold. Similarly, the preset similarity threshold is set. Similarly, the method for encrypting resource-sensitive data and login environment data using the SM4 algorithm is the same as the method for encrypting the business content data in multi-dimensional biological data using the SM4 algorithm;
[0143] A method for restoring digital identity credentials using the SM1 decryption algorithm and decrypting resource-sensitive data and login environment data in a database includes:
[0144] Obtain the encrypted digital identity credentials, which have been encrypted by the SM1 encryption algorithm previously. Use the SM1 decryption algorithm to decrypt the encrypted digital identity credentials and restore them to the original credential data for user identity confirmation. Obtain the encrypted resource-sensitive data from the database, which has been encrypted by the SM4 encryption algorithm during the previous processing. Use the SM4 key to decrypt the encrypted resource-sensitive data and restore it to the original content.
[0145] In this embodiment, through biometric matching, it is ensured that the authentication object is a real user, avoiding the risk of forged identities. When generating dynamic tokens, a timestamp, a user-unique identifier, and quantum random numbers are combined to further enhance the anti-tampering ability of the authentication process. The dynamic token is combined with a time-binding mechanism and can only pass the verification within a specified time window, effectively preventing replay attacks and enhancing the timeliness and security of the system. By introducing the mechanism of timestamp and effective time window, even if a hacker obtains a legitimate dynamic token, it cannot be used for authentication at different times again, greatly reducing the possibility of replay attacks. The preset dynamic token and time window mechanism can be flexibly adjusted according to system requirements and authentication requirements. Through the dynamic adjustment formula of the effective time window, the time window can be automatically optimized according to different biometric data feature numbers and time differences, improving the adaptability and flexibility of the authentication process. The multi-factor authentication method combining biometrics and dynamic tokens provides a higher level of security protection and at the same time avoids the cumbersome operations in traditional authentication methods, improving the user's authentication experience.
[0146] The random number sequence generated by the quantum random number generator ensures the high randomness and unpredictability of the generation of the basic key, enhances the security of the key, and reduces the risk of the key being cracked or forged; the quantum random number generators are distributed in different physical or logical security domains, and each generator generates a different random number sequence and serves as the source of the key share, further increasing the complexity and anti-attack ability of the key and avoiding single-point failures or centralized attacks; the dynamic key update strategy ensures the matching of the key update frequency with the enterprise's security requirements by defining the basic key update frequency and dynamically adjusting it according to the enterprise's risk assessment value. According to the change of the risk assessment value, the system can timely adjust the key update frequency to adapt to the change of the enterprise's operating environment. By combining the enterprise risk assessment formula with factors such as the number of authentication failures, the access frequency of sensitive resources, and the abnormality of login environment data, the risk level of the enterprise is quantified, and the key update frequency is accurately adjusted. Based on the risk assessment mechanism, the key update strategy is ensured to match the actual risk situation of the enterprise, avoiding resource waste and unnecessary frequent updates. The dynamic adjustment of the risk sensitivity coefficient makes the key update frequency more refined and adaptable. Especially when facing sudden risk events, it can quickly respond and take security measures. By combining the quantum random number generator with the SSS protocol, a secure and efficient key management mechanism is provided. The high-strength unpredictability of the quantum random number combined with the key splitting and threshold reconstruction mechanism makes the storage and use of the key more secure.
[0147] Embodiment 2
[0148] Please refer to Figure 2 As shown, an enterprise network data security access system for encryption processing in this embodiment includes:
[0149] The multi-modal identity authentication module is composed of a biometric recognition unit and a device binding unit; the multi-dimensional biometric data is recognized through the biometric recognition unit, and the user is authenticated by combining the dynamic token generation time binding mechanism; the device binding unit associates the identity authentication result with the hardware fingerprint of the secure access terminal to generate a digital identity credential;
[0150] The dynamic encryption transmission module is used to generate and roll-update the basic key through the quantum random number generator; the multi-dimensional biometric data is double-protected by the hierarchical encryption unit, and the hierarchical encryption unit includes an application layer and a transmission layer. The application layer uses the SM4 algorithm to encrypt the service content data in the multi-dimensional biometric data, and the transmission layer uses the SM2 algorithm to generate a session key for forward secrecy;
[0151] An intelligent access control module is used to obtain resource-sensitive data and login environment data, take multi-dimensional biometric data, resource-sensitive data and login environment data as inputs of an access risk assessment model, and predict an access risk coefficient; according to the predicted access risk coefficient, determine whether an enterprise encounters a security risk;
[0152] A data storage encryption module, if an enterprise encounters a security risk, triggers a privilege downgrade or two-factor authentication instruction, encrypts digital identity credentials using an SM1 encryption chip, encrypts resource-sensitive data and login environment data using the SM4 algorithm, and stores them in a database;
[0153] A data storage decryption module, if an enterprise does not encounter a security risk or the security risk has been lifted, uses the SM1 decryption algorithm to restore digital identity credentials, and decrypts resource-sensitive data and login environment data in the database to restore access.
[0154] Since the electronic device introduced in this embodiment is the electronic device used to implement the method and system for secure access to enterprise network data based on an encryption process in the embodiments of the present application, based on the method and system for secure access to enterprise network data based on an encryption process introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device used in the method and system for secure access to enterprise network data based on an encryption process in the embodiments of the present application, it falls within the scope of protection of the present application.
[0155] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0156] The above is only a preferred embodiment of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for ordinary technical users in the technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.
Claims
1. A method for securely accessing enterprise network data by encryption, characterized in that: include: S1. Construct a biometric identification unit and a device binding unit, identify multi-dimensional biological data through the biometric identification unit, and authenticate the user by combining the dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; S2. Generate and roll over basic keys through a quantum random number generator; perform dual protection on multidimensional biometric data through a layered encryption unit, which includes an application layer and a transport layer. The application layer uses the SM4 algorithm to encrypt the business content data in the multidimensional biometric data, and the transport layer uses the SM2 algorithm to generate session keys for forward secrecy; S3. Collect resource sensitive data and login environment data, use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model, and predict the access risk coefficient; based on the predicted access risk coefficient, determine whether the enterprise encounters security risks; S4. If the enterprise encounters security risks, it triggers permission downgrade or secondary authentication instructions, uses SM1 encryption chip to encrypt digital identity credentials, uses SM4 algorithm to encrypt resource sensitive data and login environment data, and stores them in the database; S5. If the enterprise has not encountered security risks or the security risks have been resolved, the SM1 decryption algorithm is used to restore the digital identity credentials, decrypt the resource-sensitive data and login environment data in the database, and restore access.
2. The method for securely accessing enterprise network data by encryption processing according to claim 1, characterized in that: The multi-dimensional biometric data includes biometric characteristic data and business content data; the biometric characteristic data includes physiological characteristic data and behavioral characteristic data; Physiological characteristic data include fingerprint data, facial data, iris data, voice data, palm print data and facial blood vessel data; behavioral characteristic data include the speed of user inputting characters on the keyboard, key interval, pressing time of each key, user mouse movement speed, mouse click frequency and gait data; Business content data includes business transaction data, enterprise operation data and real-time communication data; business transaction data includes order number, product information, transaction time, billing information, payment record, refund record, supplier information and procurement contract; enterprise operation data includes enterprise management documents, internal notifications, R&D documents, legal documents, cooperation agreements and audit logs; real-time communication data includes enterprise IM records, shared documents and cloud editing records.
3. The method for securely accessing enterprise network data by encryption processing according to claim 2, characterized in that: The method for authenticating a user by combining a dynamic token generation time binding mechanism comprises: Preliminary user authentication is performed through biometric matching, and multidimensional biometric data is defined as a multidimensional feature vector ,in, For multidimensional biological data Features is the total number of features in multidimensional biological data; the preset standard multidimensional feature vector ;in, is the first in the standard multidimensional feature vector Features Calculate multidimensional feature vectors using cosine similarity and the standard multidimensional eigenvector The similarity between them is set to , if the multidimensional feature vector and the standard multidimensional eigenvector The similarity between them is greater than or equal to the preset similarity threshold , it is preliminarily determined that the user identity authentication has passed; The preset dynamic token is composed of the timestamp when the token is generated, the user's unique identifier and the quantum random number. The Kyber algorithm is used to exchange a key between the user and the authentication server. , using the key And HMAC function to generate dynamic token: ;in, Represents a dynamic time token; Indicates the process of dynamic token generation using HMAC function; Represents the key exchanged between the user and the server using the Kyber algorithm; Indicates the timestamp when the token was generated; A unique identifier representing the user; Represents the random number generated by the quantum random number generator; Represents a string concatenation operation; Preset effective time window The time binding mechanism is defined as follows: a dynamic token is valid only when the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window. The validity of the dynamic token is verified by the dynamic token validity verification formula; The dynamic token validity verification formula is: ;in, Represents the absolute difference between the current timestamp and the timestamp when the token was generated; Indicates the current timestamp; Indicates that if the absolute difference between the current timestamp and the timestamp when the token was generated is less than or equal to the preset valid time window, the dynamic token is valid; It means that if the absolute difference between the current timestamp and the timestamp when the token was generated is greater than the preset valid time window, the dynamic token will become invalid; The preset effective time window is dynamically adjusted through the effective time window adjustment formula. The effective time window adjustment formula is: ;in, is the effective time window after adjustment; A constant factor to adjust the effect of the total number of multidimensional biological data features on the time window; A constant factor that adjusts the effect of time difference on the time window; Only when the user identity authentication is passed and the dynamic token is valid can it be determined that the user has finally passed the identity authentication.
4. The method for securely accessing enterprise network data by encryption processing according to claim 3 is characterized in that: The method for generating and rolling updating a basic key by a quantum random number generator comprises: deploy Quantum random number generators are distributed in different physical or logical security domains. Each quantum random number generator generates a random number sequence and serves as the source of the basic key share. The random number sequence generated by each quantum random number generator is recorded as ,in, Indicates the number of the quantum random number generator, ranging from 1 to ; Define a dynamic key update strategy, the dynamic key update strategy includes defining a basic key update frequency and defining an adjustment rule for dynamically adjusting the basic key update frequency; the adjustment rule for dynamically adjusting the basic key update frequency includes defining an update time interval based on the basic key update frequency and dynamically adjusting the basic key update frequency through an update frequency adjustment formula according to an enterprise risk assessment value; The default enterprise risk assessment value is , the enterprise risk assessment value Obtained through the enterprise risk assessment formula; the enterprise risk assessment formula is: ;in, Indicates the number of times the user authentication failed; Indicates the number of times sensitive resource data is accessed; Indicates the number of abnormalities in the login environment data; The weight factor representing the impact of the number of failed user authentications on the enterprise risk assessment value; A weight factor indicating the impact of the number of times sensitive resource data is accessed on the enterprise risk assessment value; The weight factor representing the impact of the number of abnormal login environment data on the enterprise risk assessment value; The update frequency adjustment formula is: ;in, The frequency of updating the basic key; The frequency of updating the basic key after adjustment; is the risk sensitivity coefficient; The risk sensitivity coefficient is adjusted by the risk sensitivity adjustment formula Dynamic adjustment is performed, and the risk sensitivity adjustment formula is: ;in, is the risk sensitivity coefficient after dynamic adjustment; is the number of quantum random number generators; Influencing factors for risk assessment; is the base of natural logarithms; Through the SSS protocol, the basic key is split into key shares, distribute the key shares in all physical or logical security domains, each physical or logical security domain stores only one key share, and configure the key reconstruction threshold to , ensuring at least The complete base key can be reconstructed with key shares; a new base key is generated through the quantum random number generator and the SSS protocol, and the old base key is destroyed at the same time.
5. The method for securely accessing enterprise network data by encryption processing according to claim 4 is characterized in that: The method of encrypting the business content data in the multi-dimensional biological data by using the SM4 algorithm comprises: Select the business content data to be encrypted from the multidimensional biological data, use the quantum random number generator to generate a 128-bit symmetric key for the SM4 algorithm, use the 128-bit symmetric key to initialize the SM4 encryption algorithm, and divide the business content data into 16 bytes. If the number of bytes of the business content data is not a multiple of 16, it is padded until the length of the business content data reaches a multiple of 16. Each data block is encrypted using the SM4 encryption algorithm, and finally all encrypted data blocks are merged to obtain the complete encrypted business content data.
6. The method for securely accessing enterprise network data by encryption processing according to claim 5, characterized in that: The method for using the SM2 algorithm to generate a session key for forward secrecy includes: Determine the sender and receiver of the communication, each of which holds a pair of public and private keys; the sender sends its public key to the receiver, and the receiver sends its public key to the sender; the receiver calculates the shared key using the SM2 algorithm based on the received sender's public key and its own private key; The sender uses the SM2 algorithm to calculate the same shared key based on the received public key of the recipient and its own private key; based on the shared key, both parties further use the SM2 algorithm to derive the session key used for symmetric encryption to achieve forward secrecy.
7. The method for securely accessing enterprise network data by encryption processing according to claim 6, characterized in that: The method for constructing the access risk assessment model includes: The resource sensitive data includes financial data, core technology data, customer privacy data and legal compliance data; the login environment data includes the IP address of the user when logging in, the device information data used by the user, the time of the user's access, the user's login location and the user behavior log; The dataset is divided into training set, validation set and test set to train the model, evaluate the model performance and verify the model generalization ability; the sample set is a subset of the dataset, each sample set includes historical multidimensional biological data, resource sensitive data and login environment data and the corresponding access risk coefficient; GBDT is selected as the implementation of the gradient boosting tree model to handle the regression task; Initialize GBDT parameters, including the maximum number of leaf nodes in each tree, learning rate, number of trees, and maximum depth of trees; use historical multidimensional biological data, resource sensitive data, and login environment data as input data of the model, and the corresponding access risk coefficient as the output label to train the access risk assessment model; the access risk assessment model is a gradient boosting tree model; Use mean square error as the loss function to measure the difference between the model's predicted value and the actual value; in each iteration, GBDT builds a new decision tree to fit the negative gradient of the loss function of the previous step, uses the negative gradient of the loss function as the learning target of the new tree, and adjusts the contribution of the new tree to the final result through the learning rate to minimize the loss function; Use the validation set to evaluate the performance of the model, tune the model, and adjust the model parameters based on its performance feedback until the model performance no longer improves or reaches the preset stopping condition; use the trained access risk assessment model to predict the current multidimensional biological data, resource sensitive data, and login environment data to obtain the access risk coefficient.
8. The method for securely accessing enterprise network data by encryption processing according to claim 7, characterized in that: The method for judging whether an enterprise encounters security risks according to the predicted access risk coefficient includes: Preset an access risk coefficient threshold, and compare the predicted access risk coefficient with the preset access risk coefficient threshold; If the predicted access risk coefficient is less than the access risk coefficient threshold, it is judged that the enterprise has not encountered security risks; if the predicted access risk coefficient is greater than or equal to the access risk coefficient threshold, it is judged that the enterprise has encountered security risks.
9. The method for securely accessing enterprise network data by encryption processing according to claim 8, characterized in that: The method of encrypting a digital identity certificate using an SM1 encryption chip includes: Select a 128-bit symmetric key, load the selected symmetric key into the SM1 encryption chip, use the SM1 algorithm inside the encryption chip to encrypt the digital identity certificate, and use the 128-bit symmetric key and the SM1 algorithm to convert the digital identity certificate into ciphertext data.
10. An encrypted enterprise network data security access system, used to implement the encrypted enterprise network data security access method according to any one of claims 1 to 9, characterized in that: include: The multimodal identity authentication module consists of a biometric unit and a device binding unit; The biometric unit recognizes multi-dimensional biometric data and authenticates the user by combining a dynamic token generation time binding mechanism; the device binding unit associates the authentication result with the hardware fingerprint of the security access terminal to generate a digital identity credential; Dynamic encryption transmission module, used to generate and roll over basic keys through quantum random number generator; use layered encryption unit to double protect multi-dimensional biometric data, layered encryption unit includes application layer and transport layer, application layer uses SM4 algorithm to encrypt business content data in multi-dimensional biometric data, and transport layer uses SM2 algorithm to generate session keys for forward secrecy; The intelligent access control module is used to obtain resource sensitive data and login environment data, and use multi-dimensional biological data, resource sensitive data and login environment data as inputs of the access risk assessment model to predict the access risk coefficient; based on the predicted access risk coefficient, it is determined whether the enterprise encounters security risks; Data storage encryption module: If the enterprise encounters security risks, it will trigger permission downgrade or secondary authentication instructions, and use SM1 encryption chip to encrypt digital identity credentials, and use SM4 algorithm to encrypt resource sensitive data and login environment data, and store them in the database; The data storage decryption module uses the SM1 decryption algorithm to recover the digital identity credentials and decrypt the resource-sensitive data and login environment data in the database to restore access if the enterprise has not encountered any security risks or the security risks have been resolved.
Citation Information
Patent Citations
Access method, device and system for enterprise network
CN118157916A
Data security interaction system and method based on Internet
CN116527372A
Implementation method of secure and trusted physical network gateway
CN116760633A