USB key centralized management identity authentication and security enhancement system and method
By adopting a DeepSeek model of multi-dimensional data acquisition and analysis in the enterprise U-Shield centralized management system, the U-Shield operation risks are evaluated and processed in real time, the shortcomings of the existing system in identity authentication and security measures are solved, and more efficient and flexible security control is achieved, and enterprise data and business security is protected.
Patent Information
- Application Number
- CN202510534709.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing enterprise U-Shield centralized management system has the risk of leakage, overprivileged access and difficulty in identifying complex attack scenarios in terms of identity authentication and security measures, resulting in threats to enterprise data and business security.
The DeepSeek training model based on multi-dimensional data acquisition and analysis is adopted to form a small security model, evaluate the U-shield operation risks in real time, and set corresponding operation instructions according to the risk level, including identity authentication, secondary identity verification and high-risk rejection processing.
Effectively identify and block illegal or overridden U-Shield operations, protect corporate data and business security, and correctly identify user identity and take necessary denial measures even if the account password is stolen or the terminal equipment is controlled.
Smart Images

Figure CN120068043A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a system and method for centralized management of identity authentication and security enhancement of USB tokens. Background Art
[0002] With the continuous increase of enterprise online banking USB tokens, bidding USB tokens, social security USB tokens, etc., especially for the financial sharing centers, finance companies, financial enterprises of some medium and large-sized enterprises, and some bidding agency units, the USB tokens originally scattered in individuals' hands are centralized for management. At the same time, the automated and intelligent applications of enterprises are gradually increasing, and the safe, efficient, and convenient centralized management and use of enterprise USB tokens have gradually become the pain points and difficulties of enterprise management.
[0003] Currently, the implementation method for the centralized management of enterprise USB tokens is mainly completed by applying USBServer devices. The enterprise USB token is inserted into the USB port of the USBServer device, and the USBServer management console performs user and permission allocation. By entering the network address of the USBServer, the user account and password on the client software, and then logging in, the USB token is remotely mounted to the local computer in the form of network (usb over network) for corresponding business operations. If it is necessary to press the OK or confirmation button on the USB token, it is necessary to integrate a clicker for remote click and press operations.
[0004] The existing identity authentication and security measures after centralized management of enterprise USB tokens through USBServer are mainly based on user account passwords, user role permissions, and black and white list mechanisms, or external fingerprint and other devices. After the centralized management of enterprise USB tokens, the human and the token are separated, and the enterprise USB token is remotely mounted to the local for use through the network. At this time, there may be risks such as the leakage of the account password of the enterprise USB token centralized control platform, the client being forged requests to bypass the white list mechanism and permission control, and the mounting and click and press operations being controlled by illegal personnel, which affect the business security related to enterprise USB tokens.
[0005] And the existing centralized management of USB tokens has security risks in the following scenarios and situations: 1. The account password of the enterprise USB token centralized management platform is leaked, affecting the use security of enterprise USB tokens; 2. The computer of the enterprise USB token user is controlled, and the related operations of the enterprise USB token are remotely controlled; 3. Illegal users bypass the black and white list mechanism and account permission control system through forged requests; 4. The account password of the enterprise USB token itself is leaked, and the business operations of the USB token are controlled; 5. The usage rights of the handling U shield and the review U shield are stolen by the same person or not controlled and isolated, affecting the enterprise data security and business security; 6. If others need to take over the shift due to business needs or the fingerprint device is forgotten to be carried, in this case of using an external fingerprint device for identity authentication, the U shield cannot be used remotely at this time, directly affecting the normal operation of the business.
[0006] In the current scenario of centralized management of enterprise U shields, the existing identity authentication and security measures cannot avoid the above problems, resulting in relatively large security risks and also bringing inconvenience to users in terms of usage, lacking generality and flexibility. Specifically, there is a relatively high risk of leakage of the account passwords of the enterprise U shield centralized management platform, and the whitelist mechanism is also easily bypassed. In the actual operation of enterprise U shields, such as key links as mounting, clicking and pressing, bill of lading review, stamping, etc., may be maliciously controlled. In addition, once the account and password of the enterprise U shield itself are leaked, the usage rights of the handling shield and the review shield may be stolen and misused, which will seriously threaten the security of enterprise data and business. The existing identity authentication methods, such as authentication based on account passwords, and security protection measures based on user role permissions and whitelist mechanisms, or using fingerprint devices for identity authentication, cannot meet the requirements of enterprise U shields for more efficient, flexible and secure management and control. These measures can neither predict the behavior of illegal or unauthorized access operations in advance, nor block them in a timely manner during the process, and there are also great difficulties in post-event auditing. Summary of the Invention
[0007] Aiming at the deficiencies in the prior art, the present invention provides a system and method for enhancing identity authentication and security in the centralized management of U shields. Based on the existing enterprise U shield centralized management software and hardware and identity authentication, through multi-dimensional data collection and analysis, and a security small model formed after DeepSeek training and reasoning, it enhances the user identity authentication and security management and control after the centralized management of enterprise U shields, can dynamically and real-time evaluate the operation risks of U shields, and take different measures according to the risk levels. Finally, even if the account password is stolen, the user's computer is controlled or there is unauthorized access, it can correctly identify the identity of the user and perform necessary rejection actions, effectively protecting the security of enterprise-related businesses and data.
[0008] The first object of the present invention is to provide a system for enhancing identity authentication and security in the centralized management of U shields, including a client, a dynamic multi-dimensional data identifier and instruction library, and a security small model; The client is deployed on the user terminal device, and is used to collect multi-dimensional data of the user terminal device using the USBServer software, and transmit the collected information to the dynamic multi-dimensional data identification and instruction library. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data. The user terminal device includes a PC terminal and a mobile terminal; The dynamic multi-dimensional data identification and instruction library is used to perform structured parsing on the multi-dimensional data of the user terminal device collected by the client to generate a structured multi-dimensional data identifier, and transmit the multi-dimensional data after structured parsing to the security small model; The security small model is obtained by reasoning and training the DeepSeek R1 model based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems, and multi-dimensional data after structured parsing. It is used to generate the U shield operation risk level and operation instructions corresponding to each risk level, and transmit the generated U shield operation risk level and operation instructions corresponding to each risk level to the dynamic multi-dimensional data identification and instruction library; When the user performs a U shield operation, based on the real-time data and historical data of the client, the risk level of the current U shield operation is evaluated in real time, and the U shield operation of the user is allowed / denied according to the operation instructions corresponding to the risk level; The risk level and operation instructions corresponding to each risk level include: Low risk, allowing the user to perform U shield operations; Medium risk, triggering two-factor authentication and allowing the user to perform U shield operations after successful verification; High risk, denying the user to perform U shield operations.
[0009] As a further improvement of the present invention, the client includes: The WatchDog module is used to monitor the hardware information, system environment, network environment, and software service data of the user terminal device, and periodically perform the cumulative calculation of numbers from 1 to 1 million to obtain the RV value; The LocalProxy module is used to take over and proxy all TCP / HTTP / HTTPS protocols through delegation; The UserHook module is used to capture all operations of the user's keyboard and mouse, page elements of different business systems, platform applications, and client applications, as well as user business operation data through delegation and takeover; The ActionChain module is used to execute the delegated action chain for U shield mounting / disconnecting and remote pressing operations, and monitor the access address, business data, and business operations of the business system corresponding to the U shield operation; The AppToken module is used to generate a dynamic token and interact with the mobile terminal to achieve identity authentication.
[0010] As a further improvement of the present invention, the dynamic multi-dimensional data identification and instruction library includes: An environment perception module, configured to parse the data transmitted by the WatchDog module and generate corresponding environmental data records; A behavior perception module, configured to parse the data transmitted by the UserHook module and generate corresponding behavior data records; A service perception module, configured to parse the data transmitted by the ActionChain module and generate corresponding service data records; A feature perception module, configured to process the protocol transmitted by the LocalProxy module, remove the data without service meaning, text markup language symbols, style markup symbols, and js code in the protocol, and generate corresponding feature data records; Safe Broker Engine (SBE), configured to clean the data in each dimension parsed by the environment perception module, the behavior perception module, the service perception module, and the feature perception module, perform context parsing and business logic analysis and assembly on the cleaned data, and classify, identify, and store the data according to the data dimension.
[0011] As a further improvement of the present invention, the training of the security small model includes: Set validity labels for the data in the four dimensions of environment, behavior, service, and feature, and bind the validity labels corresponding to the variable data to the specific operator and the user terminal device to form client structured data records; the variable data includes the service data for the user to execute the service, and the operation data of the user's keyboard and mouse; Structurally process the enterprise rules, internal control requirements, and service data of each business system, set validity labels and expressions, bind the validity labels and expressions to the corresponding department / organization, and form enterprise structured data records; The DeepSeek R1 model performs self-learning, training, and inference based on the client structured data records and the enterprise structured data records, and optimizes the model parameters through manual annotation and test backtracking to obtain the security small model.
[0012] As a further improvement of the present invention, the risk level classification includes: When the identity similarity of the environment label dimension value is equal to 100%, the identity similarity of the service label dimension value is greater than or equal to 90%, the identity similarity of the action label dimension value is greater than or equal to 80%, and the average difference value of the RV value is less than or equal to 10%, the risk level is a low risk when all the above conditions are met; When the identity label dimension value equality is equal to 100%, the business label dimension value equality is greater than or equal to 60% and less than 90%, the action label dimension value equality is greater than or equal to 60% and less than 80%, and the average difference value of the RV value is less than or equal to 20%, if any two of the above three conditions are met, the risk level is medium risk; When the identity label dimension value equality is not equal to 100%, the business label dimension equality is less than 60%, the action label dimension equality is less than 60%, and the average difference value of the RV value is greater than or equal to 60%, if any one of the above four conditions is met, the risk level is high risk.
[0013] As a further improvement of the present invention, the operation instructions corresponding to each risk level include: If the risk level is low risk, the identity authentication is passed, and the user is allowed to perform U shield operations; If the risk level is medium risk, secondary identity verification is triggered, and after the secondary identity verification is passed, the user is allowed to perform U shield operations; If the risk level is high risk, the identity authentication fails, the user is refused to perform U shield operations, the user's desktop, keyboard and mouse are locked, the user is forced to exit the client, and a risk alert is sent to enterprise managers; Among them, the U shield operation is realized by calling the ActionChain module to execute a delegated action chain.
[0014] As a further improvement of the present invention, the secondary identity verification includes: The AppToken module uses the MD value of the hardware information of the current terminal device as a random vector to generate a 6-digit numerical Token. The Token is valid for two minutes and is sent to the mobile terminal; When the user performs a U shield operation, a dynamic password input box pops up, and the Token received by the mobile APP is input in the input box; The SBE compares whether the Token generated by the SBE is the same as the Token input by the user. If they are the same, the user is allowed to perform U shield operations. If they are not the same, it is determined as high risk and the user is refused to perform U shield operations.
[0015] As a further improvement of the present invention, when the U shield is determined to be low risk in all stages of identity authentication, connection mounting, and business operation, in the business submission stage, the input data of the current page captured by the UserHook module is compared with the pre-stored information of the enterprise approval process in real time. If they are inconsistent, the current operation is determined to be high risk, and the ActionChain module is called to execute the following delegated action chain: Forcibly uninstall the U shield and exit the client, lock the keyboard, mouse and screen of the user's terminal device, and send a risk alert to enterprise managers.
[0016] The second objective of the present invention is to provide a method for U shield centralized management identity authentication and security enhancement. Based on the above system, it includes: Data collection and parsing: Collect multi-dimensional data of the user terminal device through the client. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data; Perform structured parsing on the multi-dimensional data collected by the client to generate a structured multi-dimensional data identifier; Model training and risk classification: Based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems, and the multi-dimensional data after structured parsing, infer and train the DeepSeek R1 model to obtain a security sub-model, and generate the U shield operation risk level and operation instructions corresponding to each risk level; Dynamic assessment of operation risk: Based on the real-time data and historical data of the client, real-time evaluate the risk level of the current U shield operation, and allow / deny the user's U shield operation according to the operation instructions corresponding to the risk level; The risk level and the operation instructions corresponding to each risk level include: Low risk: Identity authentication passed, allowing the user to perform U shield operations; Medium risk: Trigger secondary identity authentication, and allow the user to perform U shield operations after the secondary identity authentication passes; High risk: Identity authentication failed, reject the user from performing U shield operations, lock the user's desktop, keyboard and mouse, force the user to exit the client, and send a risk alert to enterprise management personnel; Among them, the U shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0017] Compared with the prior art, the beneficial effects of the present invention are: The trained security sub-model integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise systems, internal control requirements, and enterprise approval processes to achieve dynamic risk inference. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even when the terminal device is controlled, the account password is leaked, and access is unauthorized, etc., it can still correctly identify the user's identity, and then perform delegated chain blocking and rejection of unsafe operations to effectively protect enterprise data and business security.
[0018] Divide different risk levels, and set corresponding operation instructions for each risk level. There is no need for an external fingerprint device, nor for white lists and security control settings. All actions related to using and operating the USB key, as well as actions related to the enterprise USB key business, are dynamically and autonomously decided by the security small model and operation instructions are issued. By calling the ActionChain module to execute the delegated action chain, the operation instructions corresponding to each risk level are realized. When a high-risk operation is recognized, the USB key operation of the user can be quickly rejected to prevent the spread of the attack chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic diagram of the system structure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] The present invention will be further described in detail below with reference to the accompanying drawings: This embodiment provides a system for centralized management of identity authentication and security enhancement of USB keys. The system structure is as Figure 1 shown, and includes a client, a dynamic multi-dimensional data identifier and instruction library, and a security small model; The client is deployed on the user terminal device and includes a PC client and a mobile APP. The PC client is used to collect multi-dimensional data of the user terminal device using the USBServer software, as well as the service proxy and action execution of the terminal device, and transmit the collected information to the dynamic multi-dimensional data identifier and instruction library. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data.
[0022] Specifically, in this embodiment, the PC client is the Ukey Smart Butler, and the PC client includes: The WatchDog module is used to monitor the hardware information, system environment, network environment, and software service data of the user terminal device; the hardware information includes: the IDs, models, specifications, sizes, frequencies, and current resource utilization rates of the CPU, disk, and memory, and it runs once every 30 seconds to calculate the time-consuming (counted as RV) in milliseconds for adding up the numbers from 1 to 1 million as an operator (the value is accurate to 5 digits); the system environment includes: the system name and version, host name, environment variables, boot time, user name and number of users, U shield serial number, certificate number, certificate expiration time, and U shield account number; the network environment includes: the local IP address, MAC address, network type, network latency in milliseconds, network card name and number, and USBServer IP address; the software service data includes: the system service process name, status, and occupied resource data.
[0023] The LocalProxy module is used to take over and proxy all TCP / HTTP / HTTPS protocols in a delegated manner; the LocalProxy module is the proxy gateway for all local services, and any TCP / HTTP / HTTPS protocol passing through the local area is forwarded by the LocalProxy module.
[0024] The UserHook module is used to capture all operations of the user's keyboard and mouse, page elements of different business systems, platform applications, and client applications, as well as user business operation data through delegated takeover and proxy; among them, the user's keyboard and mouse operations specifically include: the action trajectories of the keyboard and mouse, the sequence of actions, and the time-consuming in milliseconds for each action. The ActionChain module is used to execute the delegated action chain for U shield mounting / disconnecting and remote pressing operations, and monitor the access addresses, business data, and business operations of the business systems corresponding to U shield operations. The AppToken module is used to generate dynamic tokens and interact with the mobile terminal to achieve identity authentication.
[0025] The dynamic multi-dimensional data identification and instruction library is used to structurally analyze the multi-dimensional data of the user terminal device collected by the client to generate structured multi-dimensional data identifiers, and transmit the structurally analyzed multi-dimensional data to the security small model.
[0026] Specifically, the dynamic multi-dimensional data identification and instruction library includes: The environment perception module is used to analyze the data transmitted by the WatchDog module and generate corresponding environmental data records. The behavior perception module is used to analyze the data transmitted by the UserHook module and generate corresponding behavior data records. The business perception module is used to parse the data transmitted by the ActionChain module and generate corresponding business data records; The feature perception module is used to process the protocol transmitted by the LocalProxy module, remove the data without business meaning, text markup language symbols, style markup symbols and js code in the protocol, and generate corresponding feature data records; Among them, the ID of each data record is composed of the first 20 bits of the MD5 value of the combination of the PC-side client login address and the account password; Safe Broker Engine (SBE) is used to clean the data in each dimension parsed by the environment perception module, behavior perception module, business perception module, and feature perception module, perform context parsing and business logic analysis and assembly on the cleaned data, and classify, identify and store the data according to the data dimension.
[0027] The security small model is obtained by the DeepSeek R1 model through inference training based on enterprise rules, internal control requirements, approval processes of each business, business data of each business system, and multi-dimensional data after structured parsing. It is used to generate the U shield operation risk level and operation instructions corresponding to each risk level, and transmit the generated U shield operation risk level and operation instructions corresponding to each risk level to the dynamic multi-dimensional data identification and instruction library.
[0028] Furthermore, the training of the security small model includes: Set validity labels for the data in the four dimensions of environment, behavior, business, and feature, and bind the validity labels corresponding to the variable data with the specific operator and the user terminal device to form client structured data records; the variable data includes business data for the user to perform business, operation data of the user's keyboard and mouse; Structurally process the enterprise rules, internal control requirements, approval processes of each business, and business data of each business system, and set validity labels and expressions. The validity labels and expressions are bound to the corresponding department / organization to form enterprise structured data records; among them, the expression is specifically: meet / do not meet certain conditions, and the corresponding result; The DeepSeek R1 model performs self-learning, training and inference based on the client structured data records and enterprise structured data records, and optimizes the model parameters through manual annotation and test backtracking to obtain the security small model.
[0029] The trained secure small model integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise systems, internal control requirements, and enterprise approval processes, enabling dynamic risk inference. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even when the terminal device is controlled, the account password is leaked, or access is unauthorized, it can still correctly identify the user's identity, and then perform delegated chain blocking and rejection of unsafe operations to effectively protect enterprise data and business security.
[0030] Further, the risk level classification includes: When the identity similarity of the environment label dimension value is equal to 100%, the identity similarity of the business label dimension value is greater than or equal to 90%, the identity similarity of the action label dimension value is greater than or equal to 80%, and the average difference value of the RV value is less than or equal to 10%, when all the above conditions are met, the risk level is low risk; When the identity similarity of the environment label dimension value is equal to 100%, the identity similarity of the business label dimension value is greater than or equal to 60% and less than 90%, the identity similarity of the action label dimension value is greater than or equal to 60% and less than 80%, and the average difference value of the RV value is less than or equal to 20%, when any two of the above three conditions are met, the risk level is medium risk; When the identity similarity of the environment label dimension value is not equal to 100%, the identity similarity of the business label dimension is less than 60%, the identity similarity of the action label dimension is less than 60%, and the average difference value of the RV value is greater than or equal to 60%, when any one of the above four conditions is met, the risk level is high risk.
[0031] Further, the operation instructions corresponding to each risk level include: If the risk level is low risk, the identity authentication is passed, and the user is allowed to perform U shield operations.
[0032] If the risk level is medium risk, secondary identity verification is triggered, and the user is allowed to perform U shield operations after the secondary identity verification is passed; the secondary identity verification includes: The AppToken module uses the MD value of the hardware information of the current terminal device as a random vector to generate a 6-digit numerical Token. The Token is valid for two minutes and is sent to the mobile terminal; When the user performs U shield operations, a dynamic password input box pops up, and the Token received by the mobile APP is entered in the input box; The SBE compares whether the Token generated by the SBE is the same as the Token entered by the user. If they are the same, the user is allowed to perform U shield operations. If they are not the same, it is determined as high risk and the user is refused to perform U shield operations.
[0033] If the risk level is high risk, the identity authentication fails, the user is refused to perform U shield operations, the user's desktop, keyboard, and mouse are locked, the user is forced to exit the client, and a risk alert is sent to enterprise administrators.
[0034] In the above operation instructions, the U shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0035] Furthermore, when the U shield is determined to be of low risk during the identity authentication, connection mounting, and business operation phases, during the business submission phase, the input data of the current page captured by the UserHook module is compared in real time with the pre-stored information of the enterprise approval process. If they are inconsistent, the current operation is determined to be of high risk, and the ActionChain module is called to execute the following delegated action chain: Forcibly unmount the U shield and exit the client, lock the keyboard, mouse, and screen of the user's terminal device, and send a risk alert to enterprise administrators.
[0036] The security mini-model divides different risk levels, sets corresponding operation instructions for each risk level, neither requires an external fingerprint device nor white list and security control settings. All actions related to using and operating the U shield, as well as actions related to the enterprise U shield business, are dynamically and autonomously decided by the security mini-model and operation instructions are issued. And by calling the ActionChain module to execute the delegated action chain, the operation instructions corresponding to each risk level are implemented. When a high-risk operation is identified, the user's U shield operation can be quickly rejected to prevent the spread of the attack chain.
[0037] Using the above system, when the user performs U shield operations, the risk level of the current U shield operation can be evaluated in real time based on the real-time data and historical data of the client, and the user's U shield operation can be allowed / denied according to the operation instructions corresponding to the risk level.
[0038] This embodiment provides a method for centralized management of U shield identity authentication and security enhancement. Based on the above system, it includes: Data collection and parsing: Collect multi-dimensional data of the user's terminal device through the client. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data; Perform structured parsing on the multi-dimensional data collected by the client to generate a structured multi-dimensional data identifier; Model training and risk division: Train the DeepSeek R1 model based on enterprise rules, internal control requirements, business data of each business system, and the multi-dimensional data after structured parsing to obtain a security mini-model, and generate the U shield operation risk level and operation instructions corresponding to each risk level; Dynamically assess operational risks: Based on the real-time data and historical data of the client, the risk level of the current U-Shield operation is evaluated in real time, and the user's U-Shield operation is allowed / denied according to the operation instructions corresponding to the risk level; wherein the risk level and the operation instructions corresponding to each risk level include: Low risk: Identity verification is passed, allowing the user to perform USB shield operations; Medium risk: triggers secondary identity verification, and allows the user to perform USB shield operations after passing the secondary identity verification; High risk: Identity authentication fails, the user is denied access to the USB shield, the user's desktop, keyboard and mouse are locked, the user is forced to exit the client, and a risk alert is sent to the enterprise manager; The U-shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0039] The specific steps for dynamically assessing operational risks are as follows: After the user logs in to the PC client (Ukey Smart Manager), the hardware information and environment information of the current user's terminal device are obtained; The hardware information and environment information are obtained respectively to obtain the MD5 value of the hardware information and the MD5 value of the environment information. The MD5 value of the hardware information and the MD5 value of the environment information are used as keywords for fast matching and indexing of the small security model. Send the hardware information MD5 value and environment information MD5 value, user information, user action information within 10 minutes, and current RV value obtained from the current terminal device to SBE. SBE cleans and structurally analyzes the data sent by the terminal and sends it to the security model. The security model evaluates the risk level of the U shield operation in real time based on historical training data and real-time data. If the risk level is low, the identity authentication is passed, and ActionChain is called to execute the delegated action chain that allows the U-Shield operation; If the risk level is medium, secondary identity authentication is triggered: AppToken uses the current hardware information MD value as a random vector to generate a 6-digit numeric Token, which is valid for two minutes, and sends the Token to the mobile APP; when the user clicks on the Ukey smart housekeeper to connect or press, a dynamic password input box will pop up, and the Token value obtained by the mobile APP will be entered; SBE generates a Token based on the same algorithm, and when the user clicks OK, the input Token value is compared with the Token value generated by SBE to see if they are consistent. If they are consistent, ActionChain is called to remove the operation restrictions of the buttons such as connection, mounting, submission, and confirmation; If the risk level is high risk, identity authentication and security control will not pass, any operation will be rejected, the ActionChain will be called to execute the delegated action chain for rejecting the U shield operation, the Ukey Smart Butler will be exited, the UserHook will be called to lock the desktop, keyboard and mouse, and a warning will be sent to the designated enterprise management personnel through the Ukey Smart Butler mobile APP; If the risk of the enterprise U shield during the identity authentication, connection and mounting and other operation stages is low risk, and it is also low risk when entering the corresponding business system to operate the business, but when submitting business information, according to the business approval flow information judgment, the current submitted document data is inconsistent with the user's real-time input data dynamically obtained by the UserHook, then it is determined that the current page operation is high risk, the UserHook obtains and intercepts the submit or confirm button on the current business system page, triggers the ActionChain delegated action chain, automatically prohibits the operations of the submit and confirm buttons on this page, exits the Ukey Smart Butler, calls the UserHook to lock the current desktop, keyboard and mouse, and sends a warning to the designated enterprise management personnel through the Ukey Smart Butler mobile APP.
[0040] The following describes the effects of the present invention in actual applications through specific scenarios: The fund settlement staff member Li remotely connected and mounted the handling shield of the bank through the USBServer client on his own computer and went out to handle business without logging out. The login account and password of this online banking U shield, as well as the payment password, were leaked to illegal users, and the computer has also been remotely controlled by this illegal user. The main steps for the security small model to enhance identity authentication and security control in this scenario include: 1. The Ukey Smart Butler sends the hardware information, environment information, etc. of the user's terminal computer device to the SBE service module; 2. The Ukey Smart Butler UserHook obtains all the operations of the current illegal user, including the operation behavior track, the order of operations, the duration of each operation, and the time interval between each operation, and matches them with the security risk level of the backend security small model; 3. After detecting that the device information and environment information are consistent, it is judged as low risk here; 4. Compare the obtained operation behavior track, operation order, duration of each operation, and time interval between each operation of the current user with the data in the model. After comparison, the similarity of the dimension information of the business label (normally, it is necessary to log in to the financial system to view the payment approval form under one's own responsibility and copy the payment information to the text editing box for payment filling form backup) and the action label (actions such as opening the financial system and entering the user name and password) is less than 60%. The security small model judges that the current operation is medium to high risk; 5. The secondary identity authentication is sent through the SBE module, and the AppToken service of the Ukey Smart Butler is called to generate a Token and send it to the mobile APP of Xiao Li (the mobile APP of the Ukey Smart Butler). 6. The illegal remote user inputs the login account and password for stealing this shield and clicks the login button to log in. 7. The Ukey Smart Butler pops up a Token input box for secondary identity authentication and calls the UserHook service to lock the computer screen and keyboard and mouse (the part outside the Token input box). 8. If the illegal remote user cannot input the corresponding Token this time or tries to input the Token value multiple times, and the security small model determines it as a high risk, it will automatically uninstall the U shield, exit the Ukey Smart Butler, and completely lock the computer screen and keyboard and mouse, and remind the user and enterprise management personnel through the mobile APP of the Ukey Smart Butler that the current U shield account password may have been leaked and the computer may have been remotely controlled. 9. When the Ukey Smart Butler APP on Xiao Li's mobile phone receives the Token, it also receives a risk warning prompt message. Since Xiao Li knows that he has not operated the computer at this time, that is, he knows that there is an illegal user operating remotely. After Xiao Li goes back, he restarts the computer, performs a Trojan virus scan, and modifies the U shield account password. 10. If the illegal user disguises very professionally and the business behavior and action trajectory are basically consistent with the historical data, and it cannot be determined as a medium or high risk at this time. The illegal user successfully logs in to the bank with the account and password information of the illegally obtained bank online banking U shield and fills in an illegal transfer form. At this time, the real-time filling data obtained by UserHook does not match the enterprise business approval flow data. Then, the current page elements are obtained through UserHook, and the ActionChain delegated action chain is called to lock the confirmation or submission button, and the U shield is automatically uninstalled, the Ukey Smart Butler is exited, the computer screen and keyboard and mouse are completely locked, and the user and enterprise management personnel are reminded through the mobile APP of the Ukey Smart Butler that the current U shield account password may have been leaked and the computer may have been remotely controlled.
[0041] The security small model trained by the present invention integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise system, internal control requirements, and enterprise approval process, and can realize dynamic risk reasoning. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even when the terminal device is controlled, the account password is leaked, and access is overauthorized, etc., it can still normally identify the user identity, and then perform delegated chain blocking and rejection on unsafe operations to effectively protect enterprise data and business security.
[0042] By dividing different risk levels and setting corresponding instructions for each risk level, there is no need for an external fingerprint device, nor for white lists and security control settings. All actions related to using and operating the USB key, as well as actions related to the enterprise USB key business, are dynamically and autonomously decided by the security small model and instructions are issued. And by calling the ActionChain module to execute the delegated action chain, the instructions corresponding to each risk level are realized. When a high-risk operation is recognized, the USB key operation of the user can be quickly rejected to prevent the spread of the attack chain.
[0043] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A U-Shield centralized management identity authentication and security enhancement system, characterized in that: Including client, dynamic multi-dimensional data identification and instruction library, and small security model; The client is deployed on the user terminal device, and is used to collect multi-dimensional data of the user terminal device using the USBServer software, and transmit the collected information to the dynamic multi-dimensional data identification and instruction library, wherein the multi-dimensional data includes user terminal device environment data, user behavior data, user-executed business data, and protocol feature data, and the user terminal device includes a PC terminal and a mobile terminal; The dynamic multi-dimensional data identifier and instruction library are used to perform structured analysis on the multi-dimensional data of the user terminal device collected by the client to generate a structured multi-dimensional data identifier, and transmit the structured analyzed multi-dimensional data to the security model; The security mini-model is obtained by DeepSeek R1 model based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems and multi-dimensional data reasoning training after structured analysis, and is used to generate U-shield operation risk levels and operation instructions corresponding to each risk level, and transmit the generated U-shield operation risk levels and operation instructions corresponding to each risk level to the dynamic multi-dimensional data identifier and instruction library; When a user performs a U-shield operation, the risk level of the current U-shield operation is evaluated in real time based on the real-time data and historical data of the client, and the user's U-shield operation is allowed / rejected according to the operation instructions corresponding to the risk level; The risk levels and the corresponding operation instructions for each risk level include: Low risk: users are allowed to perform U-shield operations. Medium risk: secondary identity verification is triggered and users are allowed to perform U-shield operations after passing the verification. High risk: users are denied U-shield operations.
2. The system according to claim 1, characterized in that The client comprises: WatchDog module, used to monitor the hardware information, system environment, network environment and software service data of user terminal devices, and periodically perform cumulative calculations of numbers from 1 to 1 million to obtain the RV value; LocalProxy module, used to proxy all TCP / HTTP / HTTPS protocols; UserHook module, which is used to capture all keyboard and mouse operations of users, page elements of different business systems, platform applications and client applications, and user business operation data through a delegated takeover agent; ActionChain module, used to execute the delegated action chain of USB shield mounting / disconnecting and remote pressing operations, and monitor the access address, business data and business operations of the business system corresponding to the USB shield operation; AppToken module, used to generate dynamic tokens and interact with the mobile terminal to achieve identity authentication.
3. The system according to claim 2, characterized in that The dynamic multi-dimensional data identification and instruction library includes: The environment perception module is used to parse the data transmitted by the WatchDog module and generate corresponding environmental data records; The behavior perception module is used to parse the data transmitted by the UserHook module and generate corresponding behavior data records; The business perception module is used to parse the data transmitted by the ActionChain module and generate corresponding business data records; The feature perception module is used for the protocol transmitted by the LocalProxy module, removes data, text markup language symbols, style markup symbols and js codes that have no business meaning in the protocol, and generates corresponding feature data records; Safe Broker Engine (SBE) is used to clean the data of various dimensions analyzed by the environment perception module, behavior perception module, business perception module, and feature perception module, perform context analysis and business logic analysis and assembly on the cleaned data, and classify, identify, and store the data according to the data dimensions.
4. The system according to claim 2 or 3, characterized in that: The training of the small security model includes: Set validity labels for the four dimensions of environment, behavior, business, and features, and bind the validity labels corresponding to the variable data with specific operators and user terminal devices to form client structured data records; the variable data includes business data of the user executing the business, and the operation data of the user's keyboard and mouse; Structuring the business data of enterprise rules, internal control requirements, and various business systems, and setting validity labels and expressions. The validity labels and expressions are bound to the corresponding departments / organizations to form enterprise structured data records; The DeepSeek R1 model performs self-learning, training, and reasoning based on client structured data records and enterprise structured data records, and optimizes model parameters through manual labeling and test backtracking to obtain a safe small model.
5. The system according to claim 4, characterized in that The risk level classification includes: The sameness of the environment tag dimension value is equal to 100%, the sameness of the business tag dimension value is greater than or equal to 90%, the sameness of the action tag dimension value is greater than or equal to 80%, and the average difference of the RV value is less than or equal to 10%. If all the above conditions are met, the risk level is low risk; When the sameness of the environment tag dimension value is equal to 100%, the sameness of the business tag dimension value is greater than or equal to 60% and less than 90%, the sameness of the action tag dimension value is greater than or equal to 60% and less than 80%, and the average difference of the RV value is less than or equal to 20%, the above three conditions are met. Any two risk levels are medium risk; The sameness of the environment label dimension value is not equal to 100%, the sameness of the business label dimension is less than 60%, the sameness of the action label dimension is less than 60%, and the average difference of the RV value is greater than or equal to 60%. If any of the above four conditions is met, the risk level is high.
6. The system according to claim 5, characterized in that The operation instructions corresponding to each risk level include: If the risk level is low, the identity authentication is passed, and the user is allowed to perform U-shield operations; If the risk level is medium, the secondary identity verification will be triggered. After the secondary identity verification is passed, the user is allowed to perform U-shield operations; If the risk level is high, the identity authentication fails, the user is denied access to the USB shield, the user's desktop, keyboard and mouse are locked, the user is forced to exit the client, and a risk alert is sent to the enterprise manager; The U-shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
7. The system according to claim 6, characterized in that The secondary identity verification includes: The AppToken module uses the hardware information MD value of the current terminal device as a random vector to generate a 6-digit numerical token with a validity period of two minutes, and sends the token to the mobile terminal; When the user is operating the USB shield, a dynamic password input box pops up and the user enters the token received by the mobile app in the input box; SBE compares the Token generated by SBE with the Token input by the user to see if they are consistent. If they are consistent, the user is allowed to perform U-Shield operations. If they are inconsistent, it is judged as high risk and the user is denied U-Shield operations.
8. The system according to claim 6, characterized in that When the U-Shield is judged as low risk in the identity authentication, connection mounting and business operation stages, in the business submission stage, the current page input data captured by the UserHook module is compared with the pre-stored information of the enterprise approval process in real time. If there is a discrepancy, the current operation is judged as high risk, and the ActionChain module is called to execute the following delegated action chain: Forcefully uninstall the USB shield and exit the client, lock the keyboard, mouse and screen of the user's terminal device, and send a risk alert to the enterprise manager.
9. A method for centralized management of identity authentication and security enhancement of U-Shield, based on the system according to any one of claims 1 to 8, characterized in that: include: Data collection and analysis: Collect multi-dimensional data of user terminal devices through the client, the multi-dimensional data including user terminal device environment data, user behavior data, user-executed business data and protocol feature data; Performing structured analysis on the multi-dimensional data collected by the client to generate structured multi-dimensional data identifiers; Model training and risk classification: Based on corporate rules, internal control requirements, approval processes of various businesses, business data of various business systems, and multi-dimensional data reasoning after structured analysis, DeepSeek R1 model is trained to obtain a small security model, and generate U-Shield operation risk levels and operation instructions corresponding to each risk level; Dynamically assess operational risks: Based on the client's real-time and historical data, the risk level of the current U-Shield operation is evaluated in real time, and the user's U-Shield operation is allowed / denied according to the operation instructions corresponding to the risk level; The risk levels and the corresponding operation instructions for each risk level include: Low risk: Identity verification is passed, allowing the user to perform USB shield operations; Medium risk: triggers secondary identity verification, and allows the user to perform USB shield operations after passing the secondary identity verification; High risk: Identity authentication fails, the user is denied access to the USB shield, the user's desktop, keyboard and mouse are locked, the user is forced to exit the client, and a risk alert is sent to the enterprise manager; The U-shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
Citation Information
Patent Citations
Zero-trust system based on USB key
CN117978429A
USB key centralized management identity authentication and security enhancement system and implementation method
CN118094510A
Enterprise evaluation method and device, storage medium and computer equipment
CN118396448A
Terminal zero-trust security capability system based on trusted environment perception
CN119155116A
Brokered authentication with risk sharing
US20180234464A1