Financial data security management system and method

By designing a financial data security management system, using blockchain networks and asymmetric encryption algorithms and other technologies, the problems of low financial data storage reliability, low transmission security and complex query steps are solved, and efficient and secure financial data management and query are achieved.

CN120046167AInactive Publication Date: 2025-05-27GOLDEN NETWORK (BEIJING) E-COMMERCE CO LTD

Patent Information

Application Number
CN202510137271.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, the local storage reliability of financial data is low, the transmission security is low, and the query steps are complex.

Method used

A financial data security management system was designed, including a financial data security management platform, trusted institutions, cloud data centers and mobile terminals. The system uses a blockchain network for distributed storage, combines asymmetric encryption algorithms and digital identity authentication technology to ensure the security of data transmission, and improves the practicality and protection level of data security management through data encryption classification model and abnormal traffic detection model.

Benefits of technology

It improves the storage reliability and transmission security of financial data, simplifies the data query steps, enhances the authenticity and immutability of data, reduces the complexity of query, and improves the practicality and protection level of financial data security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046167A_ABST
    Figure CN120046167A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data management, and discloses a financial data security management system and method. The system comprises a financial data security management platform, a trusted mechanism, a cloud data center and a plurality of mobile terminals, the financial data security management platform and the trusted mechanism are respectively in communication connection with the plurality of mobile terminals, and the financial data security management platform is in communication connection with the cloud data center. The financial data security management platform is provided with a user permission database, a Hfish honeypot chain network and an abnormal flow detection model, and the cloud data center is provided with a block chain network and a data security classification model. The method comprises a real-time financial data storage method and a real-time financial data query method. According to the invention, the problems of low storage reliability, low transmission security and complex query steps in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data management, and particularly relates to a financial data security management system and method. Background Art

[0002] The financial data of an enterprise is a digital record of the company's economic activities, which reflects the financial position, operating results, and cash flow of the enterprise. Financial data is crucial for management, investors, creditors, employees, and other stakeholders, as it is used for making economic decisions, evaluating the health of the enterprise, and predicting future performance. Therefore, the secure management of financial data has become a key research direction in the prior art.

[0003] The secure management of financial data includes multiple processes and steps for collecting, transmitting, storing, and querying financial data. With the advent of the information age, more and more enterprises have digitalized and platformized the management of financial data, which has improved the practicality of data management to a certain extent. However, there are still defects such as low reliability of locally stored data, low security of data transmitted in plaintext, and complex steps for querying financial data. Summary of the Invention

[0004] In order to solve the problems of low storage reliability, low transmission security, and complex query steps existing in the prior art, the purpose of the present invention is to provide a financial data security management system and method.

[0005] The technical solution adopted by the present invention is as follows:

[0006] A financial data security management system includes a financial data security management platform, a trusted institution, a cloud data center, and a number of mobile terminals. The financial data security management platform and the trusted institution are respectively communicatively connected to the number of mobile terminals, the financial data security management platform is communicatively connected to the cloud data center, and the financial data security management platform is provided with a user permission database, an Hfish honeypot network, and an abnormal traffic detection model. The cloud data center is provided with a blockchain network and a data classification model for data confidentiality.

[0007] Further, the financial data security management platform is provided with a first network interface, a signature verification module, an encryption and decryption module, a user verification module, a firewall, an Hfish management module, a cache database, a user permission database, and an abnormal traffic detection model. The external input end of the first network interface is respectively communicatively connected to the number of mobile terminals, the internal output end of the first network interface is connected to the first input end of the signature verification module through the firewall, the internal input end of the first network interface is connected to the output end of the cache database through the encryption and decryption module, and the external output end of the first network interface is communicatively connected to the cloud data center;

[0008] The first output terminal of the signature verification module is respectively connected to the first input terminal of the user verification module and the input terminal of the cache database through the encryption and decryption module. The second input terminal of the signature verification module is communicatively connected to the trusted institution. The second input terminal of the user verification module is connected to the output terminal of the user permission database. The control terminal of the firewall is respectively connected to the output terminal of the abnormal traffic detection model, the second output terminal of the signature verification module, and the output terminal of the user verification module;

[0009] The input terminal of the Hfish management module is respectively connected to several Hfish honeypots in the Hfish honeypot chain network, and the output terminal of the Hfish management module is connected to the input terminal of the abnormal traffic detection model. Several Hfish honeypots are respectively set in several application programs of the financial data security management platform.

[0010] Further, the user permission database is provided with a user permission form and a user blacklist. The user permission form is provided with user account password data, user permission data, confidentiality level range data, and their corresponding relationships.

[0011] Further, the cloud data center includes a second network interface, a smart contract, an IPFS system, and several data nodes, and the cloud data center is provided with a data confidentiality level classification model;

[0012] The second network interface is communicatively connected to the first network interface of the financial data security management platform and the trusted institution, and the second network interface is respectively connected to the data confidentiality level classification model, the smart contract, the IPFS system, and several data nodes. Several data nodes are distributively connected to form a blockchain network.

[0013] Further, the abnormal traffic detection model is constructed based on a deep learning algorithm;

[0014] The data confidentiality level classification model is constructed based on a deep learning algorithm.

[0015] Further, the abnormal traffic detection model is constructed based on the RF-MLP algorithm;

[0016] The data confidentiality level classification model is constructed based on the BiLSTM algorithm.

[0017] A financial data security management method is applied to a financial data security management system. The method includes a real-time financial data storage method and a real-time financial data query method;

[0018] The real-time financial data storage method is based on a financial data security storage architecture composed of a financial data security management platform, a trusted institution, a cloud data center, and a first mobile terminal as a data provider;

[0019] A real-time financial data query method, based on a financial data security query architecture composed of a financial data security management platform, a trusted institution, a cloud data center, and a second mobile terminal serving as a data querier.

[0020] Furthermore, a real-time financial data storage method, including the following steps:

[0021] Based on the trusted institution, perform key initialization and identity registration on all mobile terminals connected to the financial data security management platform to obtain the public-private key pairs and signature information of the mobile terminals, return the private keys in the public-private key pairs and the signature information to the corresponding mobile terminals, and publish the public keys in the public-private key pairs to the financial data security management platform;

[0022] Based on the first mobile terminal serving as a data provider, encrypt and sign the provided user account password data and real-time financial data according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal to obtain the encrypted provided user account password data, the first encrypted real-time financial data, and the first real-time signature data, and upload them to the financial data security management platform;

[0023] Based on the financial data security management platform, use the signature verification module to call the trusted institution to verify the signature of the first real-time signature data. After the signature verification passes, open the firewall and receive the encrypted provided user account password data and the encrypted real-time financial data;

[0024] According to the first public key in the first public-private key pair, use the encryption and decryption module to decrypt the encrypted provided user account password data to obtain the decrypted provided user account password data, and store the encrypted real-time financial data in the cache database;

[0025] Use the user verification module to call the user permission database to verify the user for the decrypted provided user account password data. After the user verification passes, upload the encrypted real-time financial data stored in the cache database to the cloud data center;

[0026] Continuously collect the first real-time traffic data of the first mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to perform abnormal traffic detection on the first real-time traffic data to obtain the corresponding first real-time abnormal traffic detection result;

[0027] Based on the cloud data center, use the data classification model for data classification of the encrypted real-time financial data to obtain the corresponding real-time data classification result, and use the blockchain network to link and chain the encrypted real-time financial data and the real-time data classification result.

[0028] Furthermore, a real-time financial data query method, including the following steps:

[0029] Based on the second mobile terminal acting as a data querier, according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, encrypt and sign the query user account password data and the real-time query data to obtain the encrypted query user account password data, the encrypted real-time query data, and the second real-time signature data, and upload them to the financial data security management platform;

[0030] Based on the financial data security management platform, use the signature verification module to call a trusted institution to verify the second real-time signature data. After the signature verification passes, open the firewall and receive the encrypted query user account password data and the encrypted real-time query data;

[0031] According to the second public key in the second public-private key pair, use the encryption and decryption module to decrypt the encrypted query user account password data and the encrypted real-time query data to obtain the decrypted query user account password data and the decrypted real-time query data, and store the decrypted real-time query data in the cache database;

[0032] Use the user verification module to call the user permission database to verify the decrypted query user account password data. After the user verification passes, obtain the user permission data and the classification range data of the second mobile terminal, and upload the decrypted real-time query data stored in the cache database to the cloud data center;

[0033] Based on the cloud data center, based on the user permission data and the classification range data, according to the decrypted real-time query data, retrieve and match the corresponding encrypted target real-time financial data in the blockchain network, and send it to the financial data security management platform;

[0034] Based on the financial data security management platform, according to the second public key of the second mobile terminal, double-encrypt the encrypted target real-time financial data and the corresponding first public key to obtain the corresponding double-encrypted target real-time financial data and the encrypted first public key, and separately return them to the second mobile terminal;

[0035] Continuously collect the second real-time traffic data of the second mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to perform abnormal traffic detection on the second real-time traffic data to obtain the corresponding second real-time abnormal traffic detection result;

[0036] Based on the second mobile terminal, according to the second private key, decrypt the double-encrypted target real-time financial data and the encrypted first public key once to obtain the corresponding once-decrypted target real-time financial data and the decrypted first public key, and according to the first public key, decrypt the once-decrypted target real-time financial data twice to obtain the corresponding decrypted target real-time financial data.

[0037] Further, if the first real-time abnormal traffic detection result and / or the second real-time abnormal traffic detection result indicates an abnormality, the firewall is used to block the corresponding first mobile terminal and / or the second mobile terminal from accessing the financial data security management platform, and the corresponding provided user account password data and / or the queried user account password data are added to the user blacklist in the user permission database.

[0038] The beneficial effects of the present invention are as follows:

[0039] A financial data security management system and method provided by the present invention perform unified and online security management of financial data through a financial data security management platform, improving the efficiency of data collection and management and the value of financial data; using a cloud data center for distributed data storage to avoid the problem of data loss caused by the collapse of the local database and improving storage reliability; combining an asymmetric encryption algorithm and a digital identity authentication technology, using ciphertext form in data transmission to improve data transmission security, and placing the data encryption and decryption steps in the financial data security management platform to ensure that the data in the cloud data center is stored in ciphertext form, avoiding data leakage caused by attacks on the cloud data center and further improving data security; using a data classification model for financial data classification, differentiating user permissions and restricting query ranges to improve the practicality of security management and the convenience of querying, reducing the query steps; using a decentralized blockchain network for distributed storage of financial data to ensure the authenticity and immutability of data; the Hfish honeypot chain network attracts access traffic data to facilitate the analysis of abnormal behaviors of access traffic data, improving the security of financial data, and using an abnormal traffic detection model to perform real-time detection of user access traffic to improve the protection level of the financial data security management platform.

[0040] Other beneficial effects of the present invention will be further described in the specific implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 is a structural block diagram of the financial data security management system in Embodiment 1.

[0042] Figure 2 is a flow block diagram of the financial data security management method in Embodiment 2. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] The present invention will be further explained below with reference to the accompanying drawings and specific embodiments.

[0044] Embodiment 1:

[0045] As Figure 1As shown in the figure, this embodiment provides a financial data security management system, which includes a financial data security management platform, a trusted institution, a cloud data center, and several mobile terminals. The financial data security management platform and the trusted institution are respectively communicatively connected to several mobile terminals. The financial data security management platform is communicatively connected to the cloud data center. The financial data security management platform is provided with a user permission database, an Hfish honeypot network, and an abnormal traffic detection model. The cloud data center is provided with a blockchain network and a data classification model for data confidentiality levels;

[0046] The financial data security management platform is used to use a signature verification module to call a trusted institution to verify the signature of the first / second real-time signature data. After the signature verification passes, the firewall is opened; use an encryption / decryption module to decrypt the encrypted data; use a user verification module to call the user permission database to verify the user for providing and / or querying user account password data. After the user verification passes, the data stored in the cache database is uploaded to the cloud data center; continuously collect the first and / or second real-time traffic data of the mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to detect abnormal traffic in the real-time traffic data;

[0047] The trusted institution is used to initialize the keys and register the identities of all mobile terminals connected to the financial data security management platform to obtain the public-private key pairs and signature information of the mobile terminals, return the private keys in the public-private key pairs and the signature information to the corresponding mobile terminals, and publish the public keys in the public-private key pairs to the financial data security management platform;

[0048] The cloud data center is used to use the data classification model for data confidentiality levels to classify the encrypted real-time financial data to obtain the corresponding real-time data classification results for data confidentiality levels, and use the blockchain network to link and chain the encrypted real-time financial data and the real-time data classification results for data confidentiality levels; based on the user permission data and the data confidentiality level range data, retrieve and match the corresponding encrypted target real-time financial data in the blockchain network according to the decrypted real-time query data, and send it to the financial data security management platform;

[0049] The mobile terminal encrypts and signs the provided and / or queried user account password data, real-time financial data, and / or real-time query data, and uploads it to the financial data security management platform; decrypts the double-encrypted target real-time financial data and the encrypted first public key once to obtain the corresponding once-decrypted target real-time financial data and the decrypted first public key, and according to the first public key, decrypts the once-decrypted target real-time financial data a second time to obtain the corresponding decrypted target real-time financial data.

[0050] Preferably, the financial data security management platform is provided with a first network interface, a signature verification module, an encryption / decryption module, a user verification module, a firewall, an Hfish management module, a cache database, a user permission database, and an abnormal traffic detection model. The external input end of the first network interface is respectively communicatively connected with a plurality of mobile terminals. The internal output end of the first network interface is connected to the first input end of the signature verification module through the firewall. The internal input end of the first network interface is connected to the output end of the cache database through the encryption / decryption module. And the external output end of the first network interface is communicatively connected with the cloud data center;

[0051] The first output end of the signature verification module is respectively connected to the first input end of the user verification module and the input end of the cache database through the encryption / decryption module. The second input end of the signature verification module is communicatively connected with a trusted institution. The second input end of the user verification module is connected to the output end of the user permission database. The control end of the firewall is respectively connected to the output end of the abnormal traffic detection model, the second output end of the signature verification module, and the output end of the user verification module;

[0052] The input end of the Hfish management module is respectively connected to a plurality of Hfish honeypots in the Hfish honeypot network. And the output end of the Hfish management module is connected to the input end of the abnormal traffic detection model. A plurality of Hfish honeypots are respectively arranged in a plurality of application programs of the financial data security management platform;

[0053] The Hfish honeypot technology of the Hfish honeypot network is a security mechanism used to attract and detect attacks, so as to analyze the behavior of attackers. Setting up Hfish honeypots in the virtual containers of the financial data security management platform means that Hfish honeypots capable of simulating the characteristics of target application programs are deployed in each container, so as to monitor and defend against attacks on the platform application programs;

[0054] Each Hfish honeypot corresponds to a specific application program on the financial data security management platform. The advantage of doing this is that it can more accurately monitor the abnormal behavior and potential attack activities of the application program; when an abnormal situation is detected by the honeypot of an application program, actions can be taken immediately, such as isolating the attack, recording the behavior of the attacker, warning the administrator, or taking other defensive measures; in this implementation, the Hfish honeypot is provided with a traffic probe, which can send the traffic data accessed by the mobile terminal to the Hfish management module for unified analysis and management;

[0055] The signature verification module is used to call a trusted institution to verify the real-time signature data. Only when the signature verification passes can the firewall be opened to receive data sent by the mobile terminal, avoiding malicious attacks that disguise as data sent by the mobile terminal to damage the financial data security management platform and improving the protection level of financial data management.

[0056] The encryption and decryption module is used to encrypt and decrypt data according to the public and private key pairs using the asymmetric encryption and decryption algorithm to ensure that the data is in ciphertext form during long-distance transmission, improving the security of data transmission.

[0057] The user verification module is used to verify the user based on the user account password data after signature verification, obtaining the user's user permission data and confidentiality level range data. Different permissions correspond to different confidentiality level ranges, and the data storage and data query ranges are also different, improving the practicality and functions of financial data security management.

[0058] The abnormal traffic detection model is used to combine several traffic probes in the Hfish honeypot network to detect abnormal traffic in the real-time traffic data, and can discover potential illegal access information, further improving the practicality of financial data security management.

[0059] Preferably, the user permission database is provided with a user permission form and a user blacklist. The user permission form is provided with the user account password data, user permission data, confidentiality level range data, and the corresponding relationships among the three.

[0060] Preferably, the cloud data center includes a second network interface, a smart contract, the InterPlanetary File System (IPFS), and several data nodes, and the cloud data center is provided with a data confidentiality level classification model.

[0061] The second network interface is communicatively connected to the first network interface of the financial data security management platform and the trusted institution, and the second network interface is respectively connected to the data confidentiality level classification model, the smart contract, the IPFS system, and several data nodes. The several data nodes are distributedly connected to form a blockchain network.

[0062] The IPFS system is used to store the encrypted real-time financial data and the real-time data confidentiality level classification results, and return the corresponding real-time data hash value. The hash value plays a key role in the IPFS system, ensuring the unique identification, reliability, and efficient storage of data, and ensuring the traceability and immutability of data.

[0063] Smart contracts are a form of automatically executed and self-managed contracts that allow programming on the blockchain network to automatically execute the terms of the contract. They have the advantages of automatic execution, immutability, transparency, and decentralization. They are used to generate data storage requests based on the real-time data hash value returned by the IPFS system, convert the real-time data hash value into real-time data blocks, and send the data storage request and real-time data blocks to the blockchain network;

[0064] The blockchain network is used to reach consensus on data storage requests. After the consensus is successful, the real-time data blocks are stored on the chain.

[0065] As a preferred method, the abnormal traffic detection model is constructed based on the Random Forest (RF)-Multilayer Perceptron (MLP) algorithm;

[0066] The data classification model is based on the Bidirectional Long Short-Term Memory (BiLSTM) algorithm.

[0067] The RF module uses the internal Classification And Regression Tree (CART) to screen the key features of the input traffic data and extract the key traffic features related to the behavior for subsequent abnormal judgment. The MLP network integrates multiple key traffic features, improving the key traffic features' ability to characterize abnormal behaviors and malicious attacks, and realizing the detection of abnormal traffic.

[0068] The BiLSTM network can mine the potential relationship between financial data and data confidentiality, and can accurately and efficiently classify the data confidentiality of newly input financial data based on the deep structure of the BiLSTM network.

[0069] Embodiment 2:

[0070] like Figure 2 As shown, this embodiment provides a financial data security management method, which is applied to a financial data security management system. The method includes the following steps:

[0071] S1: Real-time financial data storage based on a financial data security storage architecture consisting of a financial data security management platform, a trusted institution, a cloud data center, and a first mobile terminal as a data provider;

[0072] S2: Real-time financial data query is performed based on the financial data security query architecture composed of the financial data security management platform, trusted institutions, cloud data center and the second mobile terminal as the data queryer.

[0073] Preferably, the real-time financial data storage method includes the following steps:

[0074] S1-1: Based on a trusted institution, perform key initialization and identity registration on all mobile terminals connected to the financial data security management platform to obtain the public-private key pair and signature information of the mobile terminals, return the private key and signature information in the public-private key pair to the corresponding mobile terminals, and publish the public key in the public-private key pair to the financial data security management platform, including the following steps:

[0075] S1-1-1: Based on the financial data security management platform, collect the attribute information and entity IDs of all mobile terminals connected to the financial data security management platform, and send a number of attribute information and a number of entity IDs to the trusted institution;

[0076] S1-1-2: Based on the trusted institution, perform key initialization and identity registration on the mobile terminals according to the attribute information and entity IDs to obtain the corresponding public-private key pair and signature information, including the following steps:

[0077] S1-1-2-1: Based on the trusted institution, according to the attribute information of the mobile terminal, use an asymmetric encryption algorithm to generate keys, obtaining public parameters GP, a master secret key MSK, and an initial key PK;

[0078] The formula is:

[0079]

[0080] In the formula, GP is the public parameter; MSK is the master secret key; PK is the initial key; a is a random number in the integer domain Z p ; H 1 、H 2 、H 3 、H 4 、H 5 、H 6 、H u are all target hash functions; g, g 1 、g a are all random numbers of the generators of the cyclic group G; e(g,g) a is the bilinear mapping of the random number g;

[0081] S1-1-2-2: According to the public parameters GP, the master secret key MSK, the initial key PK, and the attribute information V u of the mobile terminal, generate the corresponding public-private key pair of the mobile terminal, and the public-private key pair includes a private key SK u and a public key PK u , and the formula is:

[0082] SK u={MSK, V u , K = g a g ab , L u = g b , (K = H 3 (V u ) b )}

[0083]

[0084] Wherein, SK u is the private key of the mobile terminal u; b is a random number in the integer domain Z p ; L u , K are the private key parameters of the mobile terminal u; H 3 is the target hash function of the public parameter GP; u is the mobile terminal indicator; MSK is the master key; PK is the initial key; PK u is the public key of the mobile terminal u; g b , g a , g ab are random numbers of the generators of the cyclic group G; V u is the attribute information of the mobile terminal u;

[0085] S1-1-2-3: Perform identity registration according to the private key in the public-private key pair and the corresponding entity ID to obtain the signature information of the corresponding mobile terminal;

[0086] The formula is:

[0087]

[0088] Wherein, k' is a random number; K u is the registration parameter of the mobile terminal u; KID u is the registration ID of the mobile terminal u; KID u and the corresponding K u constitute the signature information {K u , KID u}; H 1 is the target hash function; ID u is the entity ID of the mobile terminal u; SK u is the private key of the mobile terminal u; is the prime order; P is the prime field base point;

[0089] S1-1-3: Send the private key in the public-private key pair and the signature information to the corresponding mobile terminal, and publish the public key in the public-private key pair to the financial data security management platform;

[0090] In this embodiment, the financial data security management platform stores the public key, while the cloud data center does not store the public key. Placing the data encryption and decryption steps in the financial data security management platform ensures that the financial data in the cloud data center exists in ciphertext form, avoiding the leakage of financial data caused by an attack on the cloud data center.

[0091] S1-2: Based on the first mobile terminal as the data provider, encrypt and sign the provided user account password data and real-time financial data according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal, obtain the encrypted provided user account password data, the first encrypted real-time financial data, and the first real-time signature data, and upload them to the financial data security management platform.

[0092] The formula is:

[0093] M u =E(SK u ,m u )

[0094] In the formula, M u is the encrypted data of mobile terminal u; E(*) is the asymmetric encryption function; m u is the data to be encrypted by mobile terminal u; SK u is the private key of mobile terminal u; u is the mobile terminal indicator.

[0095] The formula is:

[0096]

[0097] In the formula, r' is a random number; is the prime order; P is the prime field base point; H 2 is the target hash function; k u is the registration parameter of mobile terminal u in the signature information {K u ,KID u}; KID u is the registration ID of mobile terminal u in the signature information {K u ,KID u}; ID u is the entity ID of mobile terminal u; the signature data formed is {ID u ,M u ,γ'={K u ,R u ,B u}}; R u ,B u ,γ' are all signature parameters of mobile terminal u.

[0098] S1-3: Based on the financial data security management platform, use the signature verification module to call a trusted institution to perform signature verification on the first real-time signature data. After the signature verification passes, open the firewall to receive the encrypted user account password data and the encrypted real-time financial data.

[0099] The formula is:

[0100] β u B u P = β u H 2 (R u , M u , ID u , K u )R u + β u K u + β u H 1 (ID u , K u )PK u

[0101] In the formula, β u is the signature verification parameter of the mobile terminal u; PK u is the public key of the mobile terminal u; if the left side of the equation is equal to the right side, the signature verification passes.

[0102] S1-4: According to the first public key in the first public-private key pair, use the encryption and decryption module to decrypt the encrypted user account password data to obtain the decrypted user account password data, and store the encrypted real-time financial data in the cache database.

[0103] The formula is:

[0104] m' u = E - (PK u , M u )

[0105] In the formula, m' u is the decrypted data of the mobile terminal u; E - (*) is the asymmetric decryption function; M u is the encrypted data of the mobile terminal u; PK u is the public key of the mobile terminal u.

[0106] S1-5: Use the user verification module to call the user permission database to perform user verification on the decrypted user account password data. After the user verification passes, upload the encrypted real-time financial data stored in the cache database to the cloud data center.

[0107] S1-6: Continuously collect the first real-time traffic data of the first mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to perform abnormal traffic detection on the first real-time traffic data to obtain the corresponding first real-time abnormal traffic detection result, including the following steps:

[0108] S1-6-1: Continuously collect the first real-time traffic data of the first mobile terminal accessing the financial data security management platform;

[0109] S1-6-2: Use the trained RF structure in the abnormal traffic detection model to extract the feature contribution degrees of several real-time alternative features in the first real-time traffic data;

[0110] The formula is:

[0111]

[0112] In the formula, is the feature contribution degree of the jth real-time alternative feature; is the feature contribution degree of the jth alternative feature in the ith tree of the random forest; i is the CART tree indicator; j is the alternative feature indicator; n is the total number of CARTs;

[0113]

[0114] In the formula, GI m 、GI l 、GI r are the Gini indices of the CART tree nodes m, l, and r of the random forest; p mk is the proportion of the category k in the CART tree node m; K is the total number of categories; m, l, r are the node indicators; k is the category indicator; K is the total number of categories;

[0115] S1-6-3: Perform normalization processing on the feature contribution degrees of several real-time alternative features to obtain the corresponding several normalized feature contribution degrees;

[0116] The formula is:

[0117]

[0118] In the formula, VIM j is the normalized feature contribution degree; J is the total number of real-time alternative features;

[0119] S1-6-4: Generate the feature selection standard values of several real-time alternative features according to the normalized feature contribution degrees;

[0120] The formula is:

[0121]

[0122] In the formula, CFC j is the feature selection standard value of the j-th real-time alternative feature; VIM j' is the feature contribution degree after normalization of the j'-th real-time alternative feature; j' is the alternative feature indicator;

[0123] S1-6-5: According to the feature selection standard value, sort the real-time alternative features in descending order of power, and select the first M real-time alternative features as key features to obtain M real-time key features, where M is the total number of real-time key features;

[0124] S1-6-6: According to the M real-time key features, use the MLP network for feature fusion to obtain the corresponding real-time fusion features;

[0125] S1-6-7: According to the real-time fusion features, perform abnormal traffic detection to obtain the corresponding first real-time abnormal traffic detection result;

[0126] If the first real-time abnormal traffic detection result indicates the existence of an abnormality, use the firewall to block the corresponding first mobile terminal from accessing the financial data security management platform, and add the corresponding user account password data to the user blacklist of the user permission database;

[0127] S1-7: Based on the cloud data center, use the data classification model of data classification levels to classify the encrypted real-time financial data into data classification levels to obtain the corresponding real-time data classification results, and use the blockchain network to link and chain the encrypted real-time financial data and the real-time data classification results, including the following steps:

[0128] S1-7-2: Based on the cloud data center, use the data classification model of data classification levels to classify the encrypted real-time financial data into data classification levels to obtain the corresponding real-time data classification results;

[0129] S1-7-3: Send the encrypted real-time financial data and the real-time data classification results to the IPFS system for storage, and generate the corresponding real-time data hash value;

[0130] S1-7-4: Invoke the smart contract to convert the real-time data hash value into a real-time data block, generate the corresponding real-time data storage request, and send it to several data nodes of the blockchain network;

[0131] S1-7-4: Based on several data nodes, use the Practical Byzantine Fault Tolerance (PBFT) consensus algorithm to perform consensus on the real-time data storage request;

[0132] S1-7-5: After successful consensus, link and chain the real-time data block.

[0133] Preferably, the real-time financial data query method includes the following steps:

[0134] S2-1: Based on the second mobile terminal acting as the data querier, according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, encrypt and sign the query user account password data and the real-time query data to obtain the encrypted query user account password data, the encrypted real-time query data, and the second real-time signature data, and upload them to the financial data security management platform;

[0135] S2-2: Based on the financial data security management platform, use the signature verification module to call a trusted institution to verify the second real-time signature data. After the signature verification passes, open the firewall and receive the encrypted query user account password data and the encrypted real-time query data;

[0136] S2-3: According to the second public key in the second public-private key pair, use the encryption and decryption module to decrypt the encrypted query user account password data and the encrypted real-time query data to obtain the decrypted query user account password data and the decrypted real-time query data, and store the decrypted real-time query data in the cache database;

[0137] S2-4: Use the user verification module to call the user permission database to verify the decrypted query user account password data. After the user verification passes, obtain the user permission data and the classification range data of the second mobile terminal, and upload the decrypted real-time query data stored in the cache database to the cloud data center;

[0138] S2-5: Based on the cloud data center, based on the user permission data and the classification range data, according to the decrypted real-time query data, retrieve and match the corresponding encrypted target real-time financial data in the blockchain network, and send it to the financial data security management platform;

[0139] S2-6: Based on the financial data security management platform, according to the second public key of the second mobile terminal, double-encrypt the encrypted target real-time financial data and the corresponding first public key to obtain the corresponding double-encrypted target real-time financial data and the encrypted first public key, and separately return them to the second mobile terminal;

[0140] S2-7: Continuously collect the second real-time traffic data of the second mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to detect the abnormal traffic of the second real-time traffic data to obtain the corresponding second real-time abnormal traffic detection result;

[0141] If the second real-time abnormal traffic detection result indicates an abnormality, use the firewall to block the corresponding second mobile terminal from accessing the financial data security management platform, and add the corresponding query user account password data to the user blacklist in the user permission database;

[0142] S2-8: Based on the second mobile terminal, according to the second private key, perform a first decryption on the doubly encrypted target real-time financial data and the encrypted first public key to obtain the corresponding first-decrypted target real-time financial data and the decrypted first public key, and according to the first public key, perform a second decryption on the first-decrypted target real-time financial data to obtain the corresponding decrypted target real-time financial data.

[0143] A financial data security management system and method provided by the present invention perform unified and online security management on financial data through a financial data security management platform, improving the efficiency of data collection and management and the value of financial data; using a cloud data center for distributed data storage to avoid the problem of data loss caused by the collapse of the local database and improving storage reliability; combining an asymmetric encryption algorithm and digital identity authentication technology, using ciphertext form in data transmission to improve data transmission security, and placing the data encryption and decryption steps in the financial data security management platform to ensure that data in the cloud data center is stored in ciphertext form, avoiding data leakage caused by attacks on the cloud data center and further improving data security; using a data classification model for financial data classification, distinguishing user permissions and restricting query ranges, improving the practicality of security management and the convenience of query, and reducing the query steps; using a decentralized blockchain network for distributed storage of financial data to ensure data authenticity and immutability; the Hfish honeypot chain network attracts access traffic data to facilitate the analysis of abnormal behaviors in access traffic data, improving the security of financial data, and using an abnormal traffic detection model to perform real-time detection on user access traffic to improve the protection level of the financial data security management platform.

[0144] The present invention is not limited to the above optional implementation manners, and anyone can obtain other various forms of products under the inspiration of the present invention. The above specific implementation manners should not be construed as limiting the protection scope of the present invention, and the protection scope of the present invention should be defined by the claims, and the specification can be used to interpret the claims.

Claims

1. A financial data security management system, characterized by: It includes a financial data security management platform, a trusted organization, a cloud data center and several mobile terminals. The financial data security management platform and the trusted organization are respectively connected to the several mobile terminals in communication, and the financial data security management platform is connected to the cloud data center in communication. The financial data security management platform is provided with a user authority database, an Hfish honeypot chain network and an abnormal traffic detection model, and the cloud data center is provided with a blockchain network and a data confidentiality classification model.

2. A financial data security management system according to claim 1, characterized in that: The financial data security management platform is provided with a first network interface, a signature verification module, an encryption and decryption module, a user verification module, a firewall, an Hfish management module, a cache database, a user authority database and an abnormal traffic detection model. The external input end of the first network interface is respectively connected to a plurality of mobile terminals for communication, the internal output end of the first network interface is connected to the first input end of the signature verification module through the firewall, the internal input end of the first network interface is connected to the output end of the cache database through the encryption and decryption module, and the external output end of the first network interface is connected to the cloud data center for communication; The first output end of the signature verification module is connected to the first input end of the user verification module and the input end of the cache database through the encryption and decryption module, the second input end of the signature verification module is connected to the trusted institution for communication, the second input end of the user verification module is connected to the output end of the user authority database, and the control end of the firewall is connected to the output end of the abnormal traffic detection model, the second output end of the signature verification module and the output end of the user verification module respectively; The input end of the Hfish management module is respectively connected to several Hfish honeypots in the Hfish honeypot chain network, and the output end of the Hfish management module is connected to the input end of the abnormal traffic detection model. The several Hfish honeypots are set in a one-to-one correspondence in several applications of the financial data security management platform.

3. A financial data security management system according to claim 2, characterized in that: The user authority database is provided with a user authority form and a user blacklist, and the user authority form is provided with user account password data, user authority data, confidentiality level range data and the corresponding relationship between the three.

4. A financial data security management system according to claim 3, characterized in that: The cloud data center includes a second network interface, a smart contract, an IPFS system, and a number of data nodes, and the cloud data center is provided with a data classification model; The second network interface is communicatively connected to the first network interface of the financial data security management platform and the trusted institution, and the second network interface is respectively connected to the data classification model, the smart contract, the IPFS system and several data nodes, and the several data nodes are distributedly connected to form a blockchain network.

5. A financial data security management system according to claim 1, characterized in that: The abnormal traffic detection model is constructed based on a deep learning algorithm; The data classification model is constructed based on a deep learning algorithm.

6. A financial data security management system according to claim 1, characterized in that: The abnormal traffic detection model is constructed based on the RF-MLP algorithm; The data classification model is constructed based on the BiLSTM algorithm.

7. A financial data security management method, applied to the financial data security management system according to any one of claims 1 to 6, characterized in that: The method includes a real-time financial data storage method and a real-time financial data query method; The real-time financial data storage method is based on a financial data security storage architecture consisting of a financial data security management platform, a trusted institution, a cloud data center, and a first mobile terminal as a data provider; The real-time financial data query method is based on a financial data security query architecture composed of a financial data security management platform, a trusted institution, a cloud data center, and a second mobile terminal serving as a data queryer.

8. A financial data security management method according to claim 7, characterized in that: The real-time financial data storage method comprises the following steps: Based on the trusted institution, all mobile terminals connected to the financial data security management platform are initialized with keys and registered with identities, and the public-private key pair and signature information of the mobile terminal are obtained. The private key and signature information in the public-private key pair are returned to the corresponding mobile terminal, and the public key in the public-private key pair is published to the financial data security management platform; Based on the first mobile terminal as the data provider, the provided user account password data and the real-time financial data are encrypted and signed according to the first private key and the first signature information in the first public-private key pair of the first mobile terminal, the encrypted provided user account password data, the first encrypted real-time financial data and the first real-time signature data are obtained, and uploaded to the financial data security management platform; Based on the financial data security management platform, a signature verification module is used to call a trusted institution to perform signature verification on the first real-time signature data. After the signature verification is passed, the firewall is opened to receive the encrypted user account password data and the encrypted real-time financial data; Decrypting the encrypted user account password data using an encryption / decryption module according to the first public key in the first public / private key pair, obtaining the decrypted user account password data, and storing the encrypted real-time financial data in a cache database; Use the user verification module to call the user authority database and perform user verification on the decrypted user account password data. After the user verification is passed, the encrypted real-time financial data stored in the cache database is uploaded to the cloud data center; Continuously collect first real-time traffic data of the first mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to perform abnormal traffic detection on the first real-time traffic data to obtain a corresponding first real-time abnormal traffic detection result; Based on the cloud data center, the encrypted real-time financial data is classified using a data classification model to obtain the corresponding real-time data classification results. The encrypted real-time financial data and the real-time data classification results are linked to the blockchain network.

9. A financial data security management method according to claim 8, characterized in that: The real-time financial data query method comprises the following steps: Based on the second mobile terminal as the data inquirer, the query user account password data and the real-time query data are encrypted and signed according to the second private key and the second signature information in the second public-private key pair of the second mobile terminal, and the encrypted query user account password data, the encrypted real-time query data and the second real-time signature data are obtained, and uploaded to the financial data security management platform; Based on the financial data security management platform, the signature verification module is used to call the trusted institution to perform signature verification on the second real-time signature data. After the signature verification is passed, the firewall is opened to receive the encrypted query user account password data and the encrypted real-time query data; Decrypt the encrypted query user account password data and the encrypted real-time query data using the encryption and decryption module according to the second public key in the second public-private key pair, obtain the decrypted query user account password data and the decrypted real-time query data, and store the decrypted real-time query data in the cache database; Use the user verification module to call the user authority database to perform user verification on the decrypted user account password data. After the user verification is passed, the user authority data and confidentiality level range data of the second mobile terminal are obtained, and the decrypted real-time query data stored in the cache database is uploaded to the cloud data center; Based on the cloud data center, user authority data and confidentiality range data, according to the decrypted real-time query data, the corresponding encrypted target real-time financial data is retrieved in the blockchain network and sent to the financial data security management platform; Based on the financial data security management platform, the encrypted target real-time financial data and the corresponding first public key are double-encrypted according to the second public key of the second mobile terminal to obtain the corresponding double-encrypted target real-time financial data and the encrypted first public key, and are returned to the second mobile terminal separately; Continuously collect second real-time traffic data of the second mobile terminal accessing the financial data security management platform, and use the abnormal traffic detection model to perform abnormal traffic detection on the second real-time traffic data to obtain a corresponding second real-time abnormal traffic detection result; Based on the second mobile terminal, the double-encrypted target real-time financial data and the encrypted first public key are decrypted once according to the second private key to obtain the corresponding once-decrypted target real-time financial data and the decrypted first public key, and the once-decrypted target real-time financial data is decrypted twice according to the first public key to obtain the corresponding decrypted target real-time financial data.

10. A financial data security management method according to claim 9, characterized in that: If the first real-time abnormal traffic detection result and / or the second real-time abnormal traffic detection result shows that there is an abnormality, a firewall is used to block the corresponding first mobile terminal and / or second mobile terminal from accessing the financial data security management platform, and the corresponding user account password data and / or user account password data are added to the user blacklist of the user authority database.

Citation Information

Patent Citations

  • IMA processor system information security management method

    CN105530092A

  • Abnormity detection method and system based on mine real-time monitoring data

    CN118484752A

  • Database security defense method and system

    CN118965450A

  • Block chain digital asset security management method and system

    CN119090431A

  • Integrated system tamper-proofing method and system based on block chain

    CN119210683A

Cited By

  • Data security defense method and device for financial management system

    CN120768684A