Human resource service system based on information security control
By adopting a multi-factor authentication mechanism of biometric and behavioral data in the human resources service system, combining data encryption and blockchain technology, the privacy and value of sensitive data in the human resources service system are solved, and efficient identity authentication and data security management are achieved.
Patent Information
- Application Number
- CN202510135483.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-30
AI Technical Summary
There are a large number of sensitive data in the human resources service system, resulting in frequent problems such as data leakage, abuse of permissions and legal risks.
The human resources service system based on information security control is adopted, combined with a multi-factor authentication mechanism of biometrics and behavioral data, and through intelligent identity authentication and access control module and data encryption and security audit module, multi-layer verification and data encryption are realized, identity permissions are dynamically adjusted, and user behavior logs are stored and audited through blockchain technology.
It effectively avoids loopholes in a single authentication method, protects the legitimacy of user access, ensures the integrity and confidentiality of data, discovers potential security issues, and provides compliance guarantees.
Smart Images

Figure CN120068039A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security control, and more specifically, to a human resource service system based on information security control. Background Art
[0002] With the in-depth development of economic globalization and digital transformation, human resource services have gradually transformed from traditional offline operations to a data-driven and technology-supported model. However, the following problems are prominent:
[0003] It involves a large amount of sensitive data (such as recruitment information, salary and benefits, performance evaluation), which has strong privacy and high value, and is easily targeted by attacks;
[0004] In traditional management methods, problems such as data leakage, abuse of permissions, and illegal handling occur frequently, resulting in legal risks, economic losses, and damage to the enterprise's reputation;
[0005] In the process of human resource service management, this data has high privacy and high value, and is easily targeted by attacks. Summary of the Invention
[0006] In view of the above problems, the present invention is proposed.
[0007] To solve the above technical problems, the present invention provides the following technical solutions: A human resource service system based on information security control, including,
[0008] An intelligent identity authentication and access control module,
[0009] Construct a multi-factor authentication mechanism that combines biometric and behavioral data. At the same time, introduce biometric recognition technology and behavioral analysis technology, set multiple layers of verification for each user login and access, and conduct user behavior data analysis through historical abnormal data. Trigger an alarm based on the analyzed abnormal behavior and dynamically adjust the identity permissions;
[0010] And, a data encryption and security audit module,
[0011] Use end-to-end technology to encrypt data during the process of data transmission and storage for employees, and store the encrypted user behavior logs through blockchain technology. At the same time, according to the storage records on the blockchain, formulate security audit rules for security log auditing.
[0012] As a preferred solution of the human resource service system based on information security control of the present invention, wherein: The specific method for constructing the multi-factor authentication mechanism that combines biometric and behavioral data is as follows:
[0013] Establish corresponding verification functions for each factor, including, biometric recognition verification function f(X 1)), behavioral analysis verification function f(X 2 )) and password verification function f(X 3 ));
[0014] For the biometric verification function, it identifies the input fingerprint image or facial image data, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes;
[0015] For the behavioral analysis verification function, it identifies the input mouse trajectory and typing habit behavior, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes;
[0016] For the password verification function, it identifies the input password, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes;
[0017] Establish a comprehensive verification function,
[0018] F = f(X 1 )) ∩ f(X 2 )) ∩ f(X 3 ))
[0019] where X 1 , X 2 , X 3 respectively represent the input data during biometric identification, behavioral identification, and password identification, f(X 1 ), f(X 2 ), f(X 3 ) respectively represent the biometric verification function, the behavioral analysis verification function, and the password verification function, and F represents the comprehensive verification function.
[0020] As a preferred solution of the human resource service system based on information security control described in the present invention, wherein: the multi-layer verification for each login and access of the user is performed according to the output result of the comprehensive verification function, specifically as follows:
[0021] When the values of each factor verification function satisfy the formula f(X 1 ) = f(X 2 ) = f(X 3 ) = 1, it indicates that the verification of all current factors passes. At this time, the value of the comprehensive verification function is F = 1, and the corresponding current user identity verification passes;
[0022] When the values of each factor verification function satisfy the formula (f(X 1 ) = 0) ∪ (f(X 2 ) = 0) ∪ (f(X 3) = 0), when the verification function value corresponding to any one factor is 0, at this time the value of the comprehensive verification function is F = 0, corresponding to the current user identity verification failed.
[0023] As a preferred solution of the human resource service system based on information security control described in the present invention, wherein: the analysis of user behavior data through historical abnormal data is specifically as follows:
[0024] Extract the abnormal behavior data set X from the historical database 2 ′ = [x′ 2,1 , x′ 2,1 ,..., x′ 2,n ;
[0025] Construct a user behavior data set X with the same characteristics as the historical abnormal behavior data set 2 = [x 2,1 , x 2,2 ,..., x 2,m ;
[0026] Calculate the similarity between the two data sets, then there is,
[0027]
[0028] Among them, x 2,j represents the user behavior data feature, including the input speed feature, the mouse movement feature, and the mouse click feature, which is the jth behavior data feature in the user behavior data set, j represents the index serial number of the feature type in the user behavior data set, m represents the upper limit of the number of feature types in the user behavior data set, x′ 2,i represents the historical abnormal data feature, including input speed abnormality, mouse movement abnormality, and mouse click abnormality, which is the ith abnormal behavior data feature in the abnormal behavior data set, i represents the index serial number of the feature type in the abnormal behavior data set, n represents the upper limit of the number of feature types in the abnormal behavior data set, S(x 2,j , x′ 2,i ) represents the similarity between the two data sets.
[0029] As a preferred solution of the human resource service system based on information security control described in the present invention, wherein: the abnormal behavior is judged according to the similarity between the two data, specifically as follows:
[0030] Set the behavior abnormal similarity threshold S T ;
[0031] If the similarity between the two data sets and the abnormal similarity threshold comparison satisfy the formula S(x 2,j , x′ 2,i ) < ST When it indicates that the user behavior corresponding to the user behavior characteristics at this time is not an abnormal behavior, the output result of the behavior analysis verification function at this time is verification passed, and the corresponding user identity authentication is passed;
[0032] If the similarity between two data sets and the abnormal similarity threshold comparison satisfy the formula S(x 2,j , x′ 2,i ) ≥ S T When it indicates that the user behavior corresponding to the user behavior characteristics at this time is an abnormal behavior, the output result of the behavior analysis verification function at this time is verification failed, the corresponding user identity authentication is not passed, and an abnormal behavior alarm is triggered to notify relevant staff for investigation. At the same time, the number of times of failed user identity authentication at the current time is recorded.
[0033] As a preferred solution of the human resource service system based on information security control described in the present invention, wherein: the specific data encryption for the process of data transmission and storage of employees using end-to-end technology is as follows:
[0034] For the data D operated by employees, the data is divided into multiple data blocks of fixed length, D = {d 1 , d 2 ,..., d k}, the length of each data block d i is the same, and i represents the index serial number of the data block;
[0035] Using the encryption function E and the dynamic key K, each data block d i is encrypted, then there is,
[0036]
[0037] The data receiver uses the decryption function to recover the encrypted ciphertext, then there is,
[0038]
[0039] Among them, E represents the encryption function, E -1 represents the decryption function, K i represents the dynamic key corresponding to the data block d i , C i represents the ciphertext data after encrypting the data block d i , d i ′ represents the ciphertext C after encrypting the data block d i , and the restored data of the ciphertext C i ;
[0040] The decrypted data blocks are recombined into the complete decrypted data D′ = {d 1 ′, d 2′,..., d k ′}, and check the data before and after decryption. If the formula D′ = D is satisfied, it means that the decrypted data is consistent with the encrypted data and the data is complete; otherwise, it means that the data is incomplete.
[0041] As a preferred solution of the human resource service system based on information security control according to the present invention, wherein: the security log audit is specifically as follows:
[0042] For the log record l corresponding to the located log block i , then there is
[0043] l i = {t i , U i , A i , O i , R i}
[0044] Wherein, t i represents the user operation time, U i represents the user ID number, A i represents the user operation type, O i represents the user operation target, R i represents the user operation result;
[0045] Using the hash algorithm, generate the unique hash value corresponding to the current log record, then there is
[0046] H(l i ) = Hash(t i U i O i R i )
[0047] For the hash values corresponding to all log records in the block, construct the root hash value of the current block, then there is
[0048] H root = {H(l 1 ), H(l 2 ),..., H(l o )}
[0049] Wherein, H root represents the root hash value of the current block, which is the combination of the hash values of all log records in the current block, l o represents the o-th log record in the current block, o represents the upper limit of the number of log records in the current block, and H(l i ) represents the hash value corresponding to the i-th record in the log data, which is used to determine whether the log record has been tampered with. Specifically:
[0050] If the hash value verification corresponding to the record in the log data satisfies the formula indicating the current log record l i has been tampered with, the log data corresponding to the current log record has been tampered with, the log data is incomplete, and the security audit fails;
[0051] If the hash value verification corresponding to the record in the log data satisfies the formula H(l i ) ∈ H root , it indicates that the current log record l i has not been tampered with, the current log data has not been tampered with, and further verification is performed through the security audit rules.
[0052] As an optimized solution of the human resource service system based on information security control described in the present invention, wherein: the formulation of security audit rules for security log auditing is specifically as follows:
[0053] Perform security audits on each field in the log record one by one, specifically as follows:
[0054] First, perform a security audit on the user ID number U i . If the user ID number does not conform to the user ID number criterion in the security audit rules, it indicates that the user ID number in the current log record does not exist, which is an abnormal attack behavior, and the log data audit corresponding to the current security record fails;
[0055] If the verification of the user ID number passes, then according to the user ID number, extract the permissions of the current user, and according to the extracted permissions, judge the operation type A i in the log record and the operation target O i . If the operation type and the operation target exceed the permission range of the current user, it indicates that the operation of the current user is unauthorized, and the log data audit corresponding to the current security record fails;
[0056] If the user ID number, the operation type, and the operation target all pass, perform a security judgment on the operation time of the user. If the operation time in the log record is not within the operation time range in the security audit rules, it indicates that the operation of the current user exceeds the working time range, and the log data audit corresponding to the current security record fails;
[0057] If the user ID number, the operation type, the operation target, and the operation time all pass, perform a security judgment on the operation result of the user. If the operation result in the log record is normal, it indicates that the operation of the current user does not cause data anomalies, and the log data audit corresponding to the current security record passes,
[0058] If the operation result in the log record is abnormal, it indicates that the operation of the current user causes data anomalies, and the log data audit corresponding to the current security record fails.
[0059] A computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, a human resource service system based on information security control is implemented.
[0060] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, a human resource service system based on information security control is implemented.
[0061] Advantages of the present invention:
[0062] The present invention combines a multi-factor authentication mechanism with biometric features (such as fingerprints and facial recognition) and behavioral data (such as mouse trajectories and typing habits) to avoid vulnerabilities in single authentication methods;
[0063] Dynamically adjusts identity permissions and triggers warnings based on abnormal behaviors to ensure the legitimacy of user access;
[0064] Uses end-to-end encryption technology to encrypt the transmission and storage of sensitive data to ensure data integrity and confidentiality;
[0065] And adds differential privacy noise to prevent inferring the characteristics of the original data distribution through the frequency patterns of encrypted data;
[0066] Stores user behavior logs through blockchain technology to ensure the immutability of the logs. Based on log audit rules and security audit algorithms, detailed analysis of operation logs is carried out to discover potential security problems;
[0067] The designed hierarchical blockchain architecture (main chain and side chain) optimizes storage efficiency, improves audit performance, and at the same time supports the quick positioning and analysis of audit logs, providing compliance guarantees for enterprises. Description of the Drawings
[0068] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:
[0069] Figure 1 It is a schematic diagram of the overall system step structure of the human resource service system based on information security control of the present invention. Detailed Embodiments
[0070] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.
[0071] In the following description, many specific details are set forth in order to provide a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0072] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation manner of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that excludes other embodiments.
[0073] The present invention is described in detail in conjunction with schematic diagrams. When describing the embodiments of the present invention in detail, for the convenience of explanation, the cross-sectional views showing the device structure will be enlarged locally out of the general scale, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention herein. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.
[0074] At the same time, in the description of the present invention, it should be noted that the terms "first, second, or third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0075] Unless otherwise clearly defined and limited in the present invention, the terms "installation, connection, and coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can also be a mechanical connection, an electrical connection, or a direct connection, and can also be indirectly connected through an intermediate medium, or can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0076] Embodiment 1
[0077] Refer to Figure 1 , for an embodiment of the present invention, a human resource service system based on information security control is provided, including an intelligent identity authentication and access control module and a data encryption and security audit module;
[0078] Specifically, the intelligent identity authentication and access control module is used to authenticate the user's identity and perform access control based on the authenticated identity; the data encryption and security auditing module is used to encrypt the user's behavior data and perform security auditing on the encrypted behavior logs.
[0079] Furthermore, the intelligent identity authentication and access control module constructs a multi-factor authentication mechanism that combines biometric features and behavior data by introducing biometric technology and behavior analysis technology, sets up multiple layers of verification for each user login and access, enhances the security of identity authentication, avoids vulnerabilities in single authentication methods, and at the same time, analyzes the user's behavior data, triggers warnings based on abnormal behaviors, and dynamically adjusts identity permissions.
[0080] Furthermore, the multi-factor authentication mechanism comprehensively verifies multiple factors, including biometrics, behavior analysis, and passwords. By establishing verification functions corresponding to each factor and comprehensively verifying all verification functions, identity verification is completed. Specifically:
[0081] Establish corresponding verification functions for each factor, including biometric verification function f(X 1 ), behavior analysis verification function f(X 2 ), and password verification function f(X 3 );
[0082] For the biometric verification function, it identifies the input fingerprint image or facial image data, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes;
[0083] For the behavior analysis verification function, it identifies the input mouse trajectory and typing habits and other behaviors, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes;
[0084] For the password verification function, it identifies the input password, and the output result is 0 or 1. 0 indicates that the verification fails, and 1 indicates that the verification passes.
[0085] Furthermore, the comprehensive verification comprehensively analyzes and verifies the verification functions established for each factor. Specifically:
[0086] Establish a comprehensive verification function,
[0087] F = f(X 1 ) ∩ f(X 2 ) ∩ f(X 3 )
[0088] where X 1 , X 2 , X 3Represent the input data for biometric recognition, behavior recognition, and password recognition respectively. f(X 1 )、f(X 2 )、f(X 3 ) represent the biometric recognition verification function, the behavior analysis verification function, and the password verification function respectively. F represents the comprehensive verification function, and the output result is 0 or 1, depending on the values of each factor verification function. Specifically:
[0089] When the values of each factor verification function satisfy the formula f(X 1 ) = f(X 2 ) = f(X 3 ) = 1, it means that the verification of all current factors has passed. At this time, the value of the comprehensive verification function is F = 1, and the corresponding current user identity verification passes;
[0090] When the values of each factor verification function satisfy the formula (f(X 1 ) = 0) ∪ (f(X 2 ) = 0) ∪ (f(X 3 ) = 0), as long as the value of the verification function corresponding to any one factor is 0, at this time, the value of the comprehensive verification function is F = 0, and the corresponding current user identity verification fails.
[0091] Furthermore, the analysis of the user's behavior data through the machine learning algorithm is judged by comparing the similarity between the collected user behavior data and the historical abnormal data. Specifically as follows:
[0092] Extract the abnormal behavior data set X′ 2 = [x′ 2,1 , x′ 2,1 ,..., x′ 2,n from the historical database, where x′ 2,i represents the historical abnormal data characteristics, including abnormal input speed, abnormal mouse movement, and abnormal mouse click. i represents the index serial number of the feature types in the abnormal behavior data set, and n represents the upper limit of the number of feature types in the abnormal behavior data set. At the same time, construct a user behavior data set X 2 = [x 2,1 , x 2,2 ,..., x 2,m with the same characteristics as the historical abnormal behavior data set, where x 2,j represents the user behavior data characteristics, including input speed characteristics, mouse movement characteristics, and mouse click characteristics. j represents the index serial number of the feature types in the user behavior data set, and m represents the upper limit of the number of feature types in the user behavior data set;
[0093] Calculate the similarity between the two data sets, then there is,
[0094]
[0095] Among them, x 2,j represents the user behavior data characteristics, including input speed characteristics, mouse movement characteristics, and mouse click characteristics, and is the j-th behavior data characteristic in the user behavior data set. j represents the index serial number of the characteristic types in the user behavior data set, and m represents the upper limit of the number of characteristic types in the user behavior data set. x' 2,i represents the historical abnormal data characteristics, including input speed abnormality, mouse movement abnormality, and mouse click abnormality, and is the i-th abnormal behavior data characteristic in the abnormal behavior data set. i represents the index serial number of the characteristic types in the abnormal behavior data set, and n represents the upper limit of the number of characteristic types in the abnormal behavior data set. S(x 2,j , x' 2,i ) represents the similarity between the two data sets and is used to determine whether the user's behavior is abnormal. Specifically:
[0096] Set the behavior abnormality similarity threshold S T ;
[0097] If the similarity between the two data sets and the abnormal similarity threshold satisfies the formula S(x 2,j , x' 2,i ) < S T at this time, it means that the user behavior corresponding to the user behavior characteristics is not an abnormal behavior. At this time, the output result of the behavior analysis verification function is verified passed, and the corresponding user identity authentication is passed;
[0098] If the similarity between the two data sets and the abnormal similarity threshold satisfies the formula S(x 2,j , x' 2,i ) ≥ S T at this time, it means that the user behavior corresponding to the user behavior characteristics is an abnormal behavior. At this time, the output result of the behavior analysis verification function is verified not passed, and the corresponding user identity authentication is not passed, and an abnormal behavior alarm is triggered to notify relevant staff for investigation. At the same time, record the number of times of failed user identity authentication currently.
[0099] It should be noted that for the number of times N of failed user identity authentication, it is used to dynamically adjust the access rights corresponding to the user identity. Specifically:
[0100] If within the unit time period T, the number of times of failed user identity authentication exceeds the threshold upper limit N T , then reduce the access rights corresponding to the current user identity;
[0101] If within the unit time period T, the number of times of failed user identity authentication does not exceed the threshold upper limit N at this timeT , the access rights corresponding to the current user identity are maintained;
[0102] For the unit time period T and the threshold upper limit N T The setting of the numerical value is set by the implementer according to the actual application scenario. Only examples are given in this embodiment, and the specific numerical value is not limited.
[0103] Furthermore, in the data encryption and security audit module, when employees perform data transmission and storage, end-to-end technology is used to encrypt the data to ensure that the data will not be tampered with or leaked during data transmission and storage. At the same time, blockchain technology is used to store data access and security logs, and the immutability of the blockchain is used to ensure the integrity of subsequent audit logs.
[0104] Furthermore, the use of end-to-end technology for data encryption is to apply end-to-end technology for data encryption during the process of employees' data transmission and data storage. The specific implementation is as follows:
[0105] For the data D operated by the employee, the data is divided into multiple data blocks of fixed length, D = {d 1 , d 2 ,..., d k}, the length of each data block d i is the same, and i represents the index serial number of the data block;
[0106] Using the encryption function E and the dynamic key K, each data block d i is encrypted, then there is
[0107]
[0108] where E represents the encryption function, and K i represents the dynamic key corresponding to the data block d i , and C i represents the ciphertext data after the data block d i is encrypted;
[0109] The data recipient uses the decryption function to recover the encrypted ciphertext, then there is
[0110]
[0111] where E -1 represents the decryption function, K i represents the dynamic key corresponding to the data block d i , C i represents the ciphertext data after the data block d i is encrypted, and d i ' represents the data block d iThe encrypted ciphertext C i The restored data;
[0112] Recombine the decrypted data blocks into the complete decrypted data D′ = {d 1 ′, d 2 ′,..., d k ′}, and check the data before and after decryption. If the formula D′ = D is satisfied, it means that the decrypted data is consistent with the data before encryption and the data is complete. Otherwise, it means that the data is incomplete.
[0113] It should be noted that in order to prevent the distribution characteristics of the original data from being inferred through the frequency pattern of the encrypted data, differential privacy noise N i is added during data encryption, specifically:
[0114] When encrypting the data block d i , add the corresponding differential privacy noise N i , then there is
[0115] C i = d i + N i
[0116] When decrypting the data, remove the added differential privacy noise, then there is
[0117] d i ′ = C i - N i
[0118] where d i represents the data block, N i represents the differential privacy noise corresponding to the data block d i , C i represents the ciphertext data after encrypting the data block d i , and d i ′ represents the restored data of the ciphertext C after encrypting the data block d i . i The restored data.
[0119] Furthermore, the use of blockchain technology for data access and storage of security logs is to store user behavior logs through blockchain technology and conduct security log audits according to the storage records on the blockchain. The specific implementation is as follows:
[0120] Based on the blockchain, store the operation logs of users, then there is
[0121] Store log records in the form of blocks. Each block stores a set of log records. Moreover, the fields of the log records stored in each block include the content stored in the block, the hash value corresponding to the block, the timestamp when the block was created, and the set of log records stored in the block;
[0122] The fields of each set of log records include the operation time of the user, the unique ID number of the user, the type of user operation, the target of the user operation, and the result of the user operation;
[0123] Collect log data and group the collected log data in chronological order. Then,
[0124] L j ={l k |t k ∈[T j-1 ,T j}
[0125] where l k represents the k-th log record in the log data, and L j represents the set of log records stored in the j-th block, satisfying the formula L j ={l 1 ,l 2 ,...,l m}, T j represents the creation timestamp of the j-th block, T j-1 represents the creation timestamp of the (j - 1)-th block, and t k represents the operation time of the k-th log record.
[0126] Calculate the hash value corresponding to the block. Then,
[0127] H(B j ) = Hash(H(B j-1 )L j T j )
[0128] where H(B j-1 ) represents the hash value of the previous block, L j represents the set of log records stored in the current block, T j represents the creation timestamp of the current block, and H(B j ) represents the hash value corresponding to the current block.
[0129] For the storage of log data, each block is associated with the previous and next blocks and forms an immutable chain structure for data storage.
[0130] It should be noted that for storing log data using blockchain technology, in order to prevent storage and performance bottlenecks caused by an excessive amount of log data, a hierarchical blockchain form is used for storage, including a main chain for storing block hash values and key metadata, and a side chain for storing specific log data. The metadata stored in the main chain is used to provide efficient traceability and indexing functions. The side chain stores block log data according to time. Moreover, the interaction between the main chain and the side chain is also connected based on hash values. The hash values corresponding to the side chain are stored in the main chain, and the connection method is the same as the hash connection method between blocks.
[0131] Furthermore, the security log audit is based on the blockchain structure. By using the unique user ID number and timestamp stored in the block, the block where the log is located is quickly located, and the corresponding log record is extracted. The extracted log record is subjected to a security audit as follows:
[0132] For the log record l corresponding to the located log block i , then there is
[0133] l i ={t i ,U i ,A i ,O i ,R i}
[0134] Among them, t i represents the user operation time, U i represents the user ID number, A i represents the user operation type, O i represents the user operation target, R i represents the user operation result;
[0135] Using the hash algorithm, a unique hash value corresponding to the current log record is generated. Then there is
[0136] H(l i ) = Hash(t i U i O i R i )
[0137] For the hash values corresponding to all log records in the block, the root hash value of the current block is constructed. Then there is
[0138] H root ={H(l 1 ),H(l 2 ),...,H(l n )}
[0139] Among them, H rootRepresents the root hash value of the current block, which is the combination of the hash values of all log records in the current block, H(l i ) represents the hash value corresponding to the i-th record in the log data, which is used to determine whether the log record has been tampered with. Specifically:
[0140] If the hash value verification of the record in the log data satisfies the formula represents the current log record l i has been tampered with, the log data corresponding to the current log record has been tampered with, the log data is incomplete, and the security audit fails;
[0141] If the hash value verification of the record in the log data satisfies the formula H(l i ) ∈ H root , it means that the current log record l i has not been tampered with, the current log data has not been tampered with, and further verification is performed through the security audit rules.
[0142] Furthermore, the audit rule is to match the untampered log records with the preset security audit rules, and perform security log auditing according to the matching results. The security audit rules are the security log audit criteria set by the implementers according to actual needs. The specific criteria are not limited in this embodiment and are set by the implementers themselves. The specific audit is as follows:
[0143] Preset security audit rule R s , and match the untampered log record l i with the security audit rule. Specifically:
[0144] The security audit rule performs security audit matching for all fields in the log record, including security audit of operation time, user ID number, user operation type, user operation target, and user operation result;
[0145] Performing security audit on the untampered log record according to the preset security audit rule, then
[0146] Performing security audit on each field in the log record one by one, specifically as follows:
[0147] First, perform security audit on the user ID number U i . If the user ID number does not conform to the user ID number criterion in the security audit rule, it means that the user ID number in the current log record does not exist, which is an abnormal attack behavior, and the audit of the log data corresponding to the current security record fails;
[0148] If the verification of the user ID number passes, then according to the user ID number, extract the permissions of the current user, and according to the extracted permissions, judge the operation type A in the log recordi With the operation target O i If the operation type and the operation target exceed the permission scope of the current user, it indicates that the operation of the current user is unauthorized, and the log data audit corresponding to the current security record fails;
[0149] If the user ID number, the operation type, and the operation target all pass, the operation time of the user is judged for security. If the operation time in the log record is not within the operation time range in the security audit rule, it indicates that the operation of the current user exceeds the working time range, and the log data audit corresponding to the current security record fails;
[0150] If the user ID number, the operation type, the operation target, and the operation time all pass, the operation result of the user is judged for security.
[0151] If the operation result in the log record is normal, it indicates that the operation of the current user does not cause data anomalies, and the log data audit corresponding to the current security record passes.
[0152] If the operation result in the log record is abnormal, it indicates that the operation of the current user causes data anomalies, and the log data audit corresponding to the current security record fails.
[0153] It should be noted that for the security logs with failed log data audits, they are uniformly recorded and stored in the abnormal behavior database to provide an accurate historical comparison data basis for subsequent abnormal behavior analysis.
[0154] Furthermore, if the function is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention essentially or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the system described in various embodiments of the present invention. And the aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0155] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definitional sequence list of executable instructions for implementing logical functions, which can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in conjunction with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0156] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.
[0157] Furthermore, to provide a concise description of the exemplary embodiments, all features of the actual embodiments may not be described (i.e., those features that are not relevant to the currently contemplated best mode of carrying out the invention or those features that are not relevant to the implementation of the invention).
[0158] It should be understood that in the development of any actual implementation, as in any engineering or design project, numerous specific implementation decisions can be made. Such development efforts may be complex and time-consuming, but for those of ordinary skill in the art who benefit from this disclosure, without undue experimentation, such development efforts will be a routine task of design, fabrication, and production.
[0159] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. The human resources service system based on information security control is characterized by: include, Intelligent identity authentication and access control module, Build a multi-factor authentication mechanism that combines biometrics and behavioral data, introduce biometrics and behavioral analysis technology, set up multiple layers of verification for each user login and access, and analyze user behavior data through historical abnormal data, trigger warnings based on analyzed abnormal behaviors and dynamically adjust identity permissions; And, data encryption and security audit module, End-to-end technology is used to encrypt employee data transmission and storage processes, and the encrypted user behavior logs are stored through blockchain technology. At the same time, security audit rules are formulated to conduct security log audits based on the storage records on the blockchain.
2. The human resources service system based on information security control as claimed in claim 1, characterized in that: The multi-factor authentication mechanism combining biometrics and behavioral data is specifically as follows: Establish corresponding verification functions for each factor, including biometric verification function f(X1), behavior analysis verification function f(X2) and password verification function f(X3); For the biometric verification function, the input fingerprint image or facial image data is recognized, and the output result is 0 or 1, 0 means the verification failed, and 1 means the verification passed; For the behavior analysis verification function, the input mouse trajectory and typing habit behavior are identified, and the output result is 0 or 1, 0 means verification failed, and 1 means verification passed; For the password verification function, the input password is identified and the output result is 0 or 1, 0 means the verification failed, and 1 means the verification passed; Establish a comprehensive verification function, F=f(X1)∩f(X2)∩f(X3) Among them, X1, X2, and X3 represent the input data for biometric identification, behavioral identification, and password identification, respectively; f(X1), f(X2), and f(X3) represent the biometric verification function, behavioral analysis verification function, and password verification function, respectively; and F represents the comprehensive verification function.
3. The human resources service system based on information security control as claimed in claim 2, characterized in that: The multi-layer verification for each login and access of the user is performed according to the output result of the comprehensive verification function, as follows: When the value of each factor verification function satisfies the formula f(X1)=f(X2)=f(X3)=1, it means that the verification of all current factors has passed. At this time, the value of the comprehensive verification function is F=1, and the corresponding current user identity authentication has passed; When the value of each factor verification function satisfies the formula (f(X1)=0)∪(f(X2)=0)∪(f(X3)=0), as long as the verification function corresponding to any factor takes the value of 0, the value of the comprehensive verification function is F=0, and the corresponding current user identity authentication fails.
4. The human resources service system based on information security control as claimed in claim 3, characterized in that: The user behavior data analysis through historical abnormal data is specifically as follows: Extract the abnormal behavior data set X′2=[x′ 2,1 ,x′ 2,1 ,...,x′ 2,n ]; Construct a user behavior data set X2=[x 2,1 ,x 2,2 ,...,x 2,m ]; To calculate the similarity between two data sets, we have: Among them, x 2,j represents the user behavior data features, including input speed features, mouse movement features, and mouse click features. It is the jth behavior data feature in the user behavior data set. j represents the index sequence number of the feature type in the user behavior data set. m represents the upper limit of the number of feature types in the user behavior data set. x′ 2,i represents the historical abnormal data features, including abnormal input speed, abnormal mouse movement, and abnormal mouse click. It is the i-th abnormal behavior data feature in the abnormal behavior data set. i represents the index sequence number of the feature type in the abnormal behavior data set, and n represents the upper limit of the number of feature types in the abnormal behavior data set. S(x 2,j ,x′ 2,i ) represents the similarity between two data sets.
5. The human resources service system based on information security control as claimed in claim 4, characterized in that: The abnormal behavior is determined based on the similarity between the two data, as follows: Set the behavior anomaly similarity threshold S T ; If the similarity between the two data sets and the abnormal similarity threshold satisfy the formula S(x 2,j ,x′ 2,i )<S T , it means that the user behavior corresponding to the user behavior feature is not abnormal behavior. At this time, the output result of the behavior analysis verification function is verification passed, and the corresponding user identity authentication is passed; If the similarity between the two data sets and the abnormal similarity threshold satisfy the formula S(x 2,j ,x′ 2,i )≥S T , it means that the user behavior corresponding to the user behavior feature is abnormal behavior. At this time, the output result of the behavior analysis verification function is verification failure, the corresponding user identity authentication fails, and an abnormal behavior alarm is triggered to notify relevant staff to investigate. At the same time, the number of times the user's current identity authentication fails is recorded.
6. The human resources service system based on information security control as claimed in claim 5, characterized in that: The process of encrypting employee data transmission and storage using end-to-end technology is as follows: For the data D operated by the employee, the data is divided into multiple fixed-length data blocks, D = {d1, d2, ..., d k }, each data block d i The length of is the same, i represents the index sequence number of the data block; Using encryption function E and dynamic key K, for each data block d i To encrypt, we have The data receiver uses the decryption function to recover the encrypted ciphertext, then, Where E represents the encryption function, E -1 represents the decryption function, K i Represents data block d i The corresponding dynamic key, C i Represents data block d i Encrypted ciphertext data, d′ i Description data block d i Encrypted ciphertext C i Recovered data; The decrypted data blocks are reassembled into the completed decrypted data D′={d′1, d′2, ..., d′ k }, and check the data before and after decryption. If the formula D′=D is satisfied, it means that the decrypted data is consistent with the data before encryption and the data is complete. Otherwise, it means that the data is incomplete.
7. The human resources service system based on information security control as claimed in claim 6, characterized in that: The security log audit is as follows: For the log record corresponding to the located log block l i , then there is, l i ={t i ,U i ,A i ,O i ,R i } Among them, t i Indicates the user operation time, U i Indicates the user ID number, A i Indicates the user operation type, O i Indicates the user operation target, R i Indicates the result of user operation; Using the hash algorithm, we can generate a unique hash value corresponding to the current log record. Then, H(l i )=Hash(t i ||U i ||O i ||R i ) For the hash values corresponding to all log records in the block, construct the root hash value of the current block, then, H root ={H(l1),H(l2),...,H(l o )} Among them, H root Indicates the root hash value of the current block, which is the sum of the hash values of all log records in the current block. o represents the oth log record in the current block, o represents the upper limit of the number of log records in the current block, H(l i ) represents the hash value corresponding to the i-th record in the log data, which is used to determine whether the log record has been tampered with. Specifically: If the hash value verification corresponding to the record in the log data satisfies the formula Indicates the current log record i The log data corresponding to the current log record has been tampered with, the log data is incomplete, and the security audit has failed; If the hash value verification corresponding to the record in the log data satisfies the formula H(l i )∈H root , indicating the current log record l i The current log data has not been tampered with, and is further verified by security audit rules.
8. The human resources service system based on information security control as claimed in claim 7, characterized in that: The specific details of formulating security audit rules for security log audit are as follows: Perform security audits on each field in the log record one by one, as follows: First, for user ID number U i During security audit, if the user ID does not meet the user ID criteria in the security audit rules, it means that the user ID in the current log record does not exist, which is an abnormal attack behavior, and the log data audit corresponding to the current security record fails; If the user ID number is verified, the current user's permissions are extracted based on the user ID number, and the operation type in the log record is determined based on the extracted permissions. i With the operation target O i If the operation type and operation target exceed the current user's authority, it means that the current user's operation exceeds the authority, and the log data audit corresponding to the current security record fails; If the user ID number, operation type, and operation target are all passed, the user's operation time is judged for security. If the operation time in the log record is not within the operation time range in the security audit rule, it means that the current user's operation is beyond the working time range, and the log data audit corresponding to the current security record fails; If the user ID number, operation type, operation target, and operation time are all passed, the user's operation result is judged to be safe. If the operation result in the log record is normal, it means that the current user's operation has not caused data abnormality, and the log data audit corresponding to the current security record has passed. If the operation result in the log record is abnormal, it means that the current user's operation caused the data to be abnormal, and the log data audit corresponding to the current security record fails.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the system according to any one of claims 1 to 8 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the system according to any one of claims 1 to 8 is implemented.
Citation Information
Cited By
Salary payment system and method based on data security management
CN121746104A