A system and method for centralized management of identity authentication and security enhancement of USB tokens
Through the combination of the DeepSeek R1 model and ActionChain module, the dynamic risk assessment and operation instructions of the enterprise U-Shield centralized management system are realized, and the security risks in the enterprise U-Shield centralized management are solved, ensuring the security and flexibility of enterprise data and business.
Patent Information
- Application Number
- CN202510534709.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing enterprise U-Shield centralized management system has security risks such as account password leakage, terminal equipment being controlled, overpriced access and inflexible identity authentication methods, resulting in illegal control of business operations, affecting corporate data and business security.
The security small model based on the DeepSeek R1 model is adopted to evaluate the U-shield operation risks in real time through multi-dimensional data acquisition and analysis, and set operation instructions according to the risk level, including low-risk allowable operations, medium-risk triggered secondary verification, high-risk rejection operations, and combined with the ActionChain module to execute a delegated action chain to achieve dynamic risk management.
Effectively identify user identities, prevent illegal operations, prevent attack chains from spreading, ensure corporate data and business security, avoid dependence on external fingerprint devices and whitelists, and achieve more efficient and flexible security control.
Smart Images

Figure CN120068043B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a system and method for centralized management of identity authentication and security enhancement of USB tokens. Background Art
[0002] With the continuous increase of enterprise online banking USB tokens, bidding USB tokens, social security USB tokens, etc., especially for the financial shared centers, finance companies, financial enterprises of some medium and large-sized enterprises, and some bidding agency units, the USB tokens originally scattered in individuals' hands are centralized after collection, and at the same time, the automation and intelligence applications of enterprises are gradually increasing. The safe, efficient and convenient centralized management and use of enterprise USB tokens have gradually become the pain points and difficulties of enterprise management.
[0003] Currently, the implementation method for centralized management of enterprise USB tokens is mainly completed by applying USBServer devices. The enterprise USB token is inserted into the USB port of the USBServer device, and the USBServer management console performs user and permission allocation. By entering the network address of the USBServer, the user account and password on the client software, and then logging in, the USB token is remotely mounted to the local computer in the form of network (usb over network) for corresponding business operations. If it is necessary to press the OK or confirmation button on the USB token, it is necessary to integrate a pressing clicker for remote click and press operations.
[0004] The existing identity authentication and security measures after centralized management of enterprise USB tokens through USBServer are mainly based on user account passwords, user role permissions, and black and white list mechanisms, or external devices such as fingerprint devices. After the centralized management of enterprise USB tokens, the separation of the person and the token occurs, and the enterprise USB token is remotely mounted to the local for use through the network. At this time, there may be risks such as the leakage of the account password of the enterprise USB token centralized control platform, the forgery of requests by the client to bypass the white list mechanism and permission control, and the control of operations such as mounting and click pressing by illegal personnel, which affect the business security related to enterprise USB tokens.
[0005] And the existing centralized management of USB tokens has security risks in the following scenarios and situations:
[0006] 1. The account password of the enterprise USB token centralized management platform is leaked, affecting the use security of enterprise USB tokens;
[0007] 2. The computer of the enterprise USB token user is controlled, and the relevant operations of the enterprise USB token are remotely controlled;
[0008] 3. Illegal users bypass the black and white list mechanism and account permission control system by forging requests;
[0009] 4. The account password of the enterprise U shield itself is leaked, and the business operations of the U shield are controlled;
[0010] 5. The usage rights of the handling U shield and the review U shield are stolen by the same person or not controlled and isolated, affecting the enterprise data security and business security;
[0011] 6. If others need to take over the shift due to business needs or the fingerprint device is forgotten to be carried, in this case of using an external fingerprint device for identity authentication, the U shield cannot be used remotely at this time, directly affecting the normal operation of the business.
[0012] In the current scenario of centralized management of enterprise U shields, the existing identity authentication and security measures cannot avoid the above problems, resulting in relatively large security risks and also bringing inconvenience to users in terms of use, lacking generality and flexibility. Specifically, there is a relatively high risk of leakage of the account password of the enterprise U shield centralized management platform, and the whitelist mechanism is also easily bypassed. In the actual operation of the enterprise U shield, such as key links like mounting, clicking and pressing, bill of lading review, and stamping, they may all be maliciously controlled. In addition, once the account and password of the enterprise U shield itself are leaked, the usage rights of the handling shield and the review shield may be stolen and abused, which will seriously threaten the security of enterprise data and business. The existing identity authentication methods, such as authentication based on account password, and security protection measures based on user role permissions and whitelist mechanism, or using fingerprint devices for identity authentication, cannot meet the requirements of the enterprise U shield for more efficient, flexible and secure management and control. These measures can neither predict in advance the behavior of illegal or unauthorized access operations, nor block them in a timely manner during the process, and there are also great difficulties in post-event auditing. Summary of the Invention
[0013] Aiming at the deficiencies existing in the prior art, the present invention provides a system and method for enhancing identity authentication and security in the centralized management of U shields. Based on the existing enterprise U shield centralized management software and hardware and identity authentication, through multi-dimensional data collection and parsing, and a security small model formed after DeepSeek training and reasoning, it enhances the user identity authentication and security management and control after the centralized management of enterprise U shields, can dynamically and real-time evaluate the operation risks of U shields, and take different measures according to the risk levels. Finally, even if the account password is stolen, the user's computer is controlled or there is unauthorized access, it can correctly identify the identity of the user and perform necessary rejection actions, effectively protecting the security of enterprise-related businesses and data.
[0014] The first object of the present invention is to provide a system for enhancing identity authentication and security in the centralized management of U shields, including a client, a dynamic multi-dimensional data identifier and instruction library, and a security small model;
[0015] The client is deployed on the user terminal device, and is used to collect multi-dimensional data of the user terminal device using the USBServer software, and transmit the collected information to the dynamic multi-dimensional data identification and instruction library. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data. The user terminal device includes a PC terminal and a mobile terminal;
[0016] The dynamic multi-dimensional data identification and instruction library is used to perform structured parsing on the multi-dimensional data of the user terminal device collected by the client to generate structured multi-dimensional data identification, and transmit the multi-dimensional data after structured parsing to the security small model;
[0017] The security small model is obtained by reasoning and training the DeepSeek R1 model based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems, and multi-dimensional data after structured parsing. It is used to generate the U shield operation risk level and operation instructions corresponding to each risk level, and transmit the generated U shield operation risk level and operation instructions corresponding to each risk level to the dynamic multi-dimensional data identification and instruction library;
[0018] When the user performs a U shield operation, based on the real-time data and historical data of the client, the risk level of the current U shield operation is evaluated in real time, and the U shield operation of the user is allowed / denied according to the operation instructions corresponding to the risk level. The risk level and operation instructions corresponding to each risk level include:
[0019] Low risk, allowing the user to perform a U shield operation; medium risk, triggering two-factor authentication and allowing the user to perform a U shield operation after successful verification; high risk, denying the user to perform a U shield operation.
[0020] As a further improvement of the present invention, the client includes:
[0021] The WatchDog module is used to monitor the hardware information, system environment, network environment, and software service data of the user terminal device, and periodically perform the cumulative calculation of numbers from 1 to 1 million to obtain the RV value;
[0022] The LocalProxy module is used to take over and proxy all TCP / HTTP / HTTPS protocols through delegation;
[0023] The UserHook module is used to capture all operations of the user's keyboard and mouse, page elements of different business systems, platform applications, and client applications, as well as user business operation data through delegation and takeover;
[0024] The ActionChain module is used to execute the delegated action chain for U shield mounting / disconnection and remote pressing operations, and monitor the access addresses, business data, and business operations of the business systems corresponding to U shield operations;
[0025] The AppToken module is used to generate dynamic tokens and interact with the mobile terminal to achieve identity authentication.
[0026] As a further improvement of the present invention, the dynamic multi-dimensional data identification and instruction library includes:
[0027] The environment perception module is used to parse the data transmitted by the WatchDog module and generate corresponding environmental data records;
[0028] The behavior perception module is used to parse the data transmitted by the UserHook module and generate corresponding behavior data records;
[0029] The business perception module is used to parse the data transmitted by the ActionChain module and generate corresponding business data records;
[0030] The feature perception module is used for the protocol transmitted by the LocalProxy module, removes the data without business meaning, text markup language symbols, style markup symbols, and js code in the protocol, and generates corresponding feature data records;
[0031] The Safe Broker Engine (SBE) is used to clean the data of each dimension parsed by the environment perception module, behavior perception module, business perception module, and feature perception module, perform context parsing and business logic analysis and assembly on the cleaned data, and classify, identify, and store the data according to the data dimensions.
[0032] As a further improvement of the present invention, the training of the security small model includes:
[0033] Set validity labels for the data of the four dimensions of environment, behavior, business, and feature, and bind the validity labels corresponding to the variable data to specific operators and user terminal devices to form client structured data records; the variable data includes the business data of users performing business operations, the operation data of users' keyboards and mice;
[0034] Structurally process the enterprise rules, internal control requirements, and business data of each business system, and set validity labels and expressions. The validity labels and expressions are bound to the corresponding departments / organizations, and enterprise structured data records are formed;
[0035] The DeepSeek R1 model conducts self - learning, training, and inference based on client - side structured data records and enterprise structured data records, and optimizes the model parameters through manual annotation and test backtracking to obtain a security mini - model.
[0036] As a further improvement of the present invention, the risk level classification includes:
[0037] When the identity similarity of the environmental label dimension is equal to 100%, the identity similarity of the business label dimension is greater than or equal to 90%, the identity similarity of the action label dimension is greater than or equal to 80%, and the average difference value of the RV is less than or equal to 10%, the risk level is low risk when all the above conditions are met;
[0038] When the identity similarity of the environmental label dimension is equal to 100%, if the identity similarity of the business label dimension is greater than or equal to 60% and less than 90%, the identity similarity of the action label dimension is greater than or equal to 60% and less than 80%, and the average difference value of the RV is less than or equal to 20%, the risk level is medium risk when any two of the above three conditions are met;
[0039] When the identity similarity of the environmental label dimension is not equal to 100%, the identity similarity of the business label dimension is less than 60%, the identity similarity of the action label dimension is less than 60%, and the average difference value of the RV is greater than or equal to 60%, the risk level is high risk when any one of the above four conditions is met.
[0040] As a further improvement of the present invention, the operation instructions corresponding to each risk level include:
[0041] If the risk level is low risk, the identity authentication is passed, and the user is allowed to perform U - shield operations;
[0042] If the risk level is medium risk, secondary identity verification is triggered, and after the secondary identity verification is passed, the user is allowed to perform U - shield operations;
[0043] If the risk level is high risk, the identity authentication fails, the user is refused to perform U - shield operations, the user's desktop, keyboard, and mouse are locked, the user is forced to exit the client, and a risk alert is sent to enterprise managers;
[0044] Among them, the U - shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0045] As a further improvement of the present invention, the secondary identity verification includes:
[0046] The AppToken module uses the MD value of the hardware information of the current terminal device as a random vector to generate a 6 - digit numerical Token. The Token is valid for two minutes and is sent to the mobile terminal;
[0047] When the user performs a U shield operation, a dynamic password input box pops up, and the user enters the Token received by the mobile APP in the input box;
[0048] The SBE compares whether the Token generated by the SBE is the same as the Token entered by the user. If they are the same, the user is allowed to perform the U shield operation. If they are different, it is determined as high risk and the user is refused to perform the U shield operation.
[0049] As a further improvement of the present invention, when the U shield is determined to be of low risk in the identity authentication, connection mounting, and service operation stages, in the service submission stage, the current page input data captured by the UserHook module is compared with the pre-stored information of the enterprise approval process in real time. If they are different, the current operation is determined to be of high risk, and the ActionChain module is called to execute the following delegated action chain:
[0050] Forcibly uninstall the U shield and exit the client, lock the keyboard, mouse, and screen of the user terminal device, and send a risk alert to the enterprise management personnel.
[0051] The second object of the present invention is to provide a method for centralized management of identity authentication and security enhancement of the U shield. Based on the above system, it includes:
[0052] Data collection and parsing:
[0053] Collect multi-dimensional data of the user terminal device through the client. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data;
[0054] Perform structured parsing on the multi-dimensional data collected by the client to generate a structured multi-dimensional data identifier;
[0055] Model training and risk classification:
[0056] Based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems, and multi-dimensional data after structured parsing, infer and train the DeepSeek R1 model to obtain a security sub-model, and generate the U shield operation risk level and operation instructions corresponding to each risk level;
[0057] Dynamic assessment of operation risk:
[0058] Based on the real-time data and historical data of the client, the risk level of the current U shield operation is evaluated in real time, and the U shield operation of the user is allowed / denied according to the operation instructions corresponding to the risk level; the risk level and the operation instructions corresponding to each risk level include:
[0059] Low risk: The identity authentication is passed, and the user is allowed to perform the U shield operation;
[0060] Medium risk: Trigger two-factor authentication. After the two-factor authentication is passed, allow the user to perform U shield operations;
[0061] High risk: Authentication fails. Reject the user from performing U shield operations, lock the user's desktop, keyboard, and mouse, force the user to exit the client, and send a risk alert to enterprise administrators;
[0062] Among them, the U shield operation is implemented by invoking the ActionChain module to execute a delegated action chain.
[0063] Compared with the prior art, the beneficial effects of the present invention are:
[0064] The trained security small model integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise systems, internal control requirements, and enterprise approval processes to achieve dynamic risk reasoning. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even if the terminal device is controlled, the account password is leaked, and access is unauthorized, etc., it can still correctly identify the user's identity, and then perform delegated chain blocking and rejection of unsafe operations to effectively protect enterprise data and business security.
[0065] Divide different risk levels, set corresponding operation instructions for each risk level. It neither requires an external fingerprint device nor white list and security control settings. All actions related to using and operating the U shield, as well as actions related to the enterprise U shield business, are dynamically and autonomously decided by the security small model and operation instructions are issued. And by invoking the ActionChain module to execute a delegated action chain to implement the operation instructions corresponding to each risk level. When a high-risk operation is identified, it can quickly reject the user's U shield operation to prevent the spread of the attack chain. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 It is a schematic diagram of the system structure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0068] The following further describes the present invention in detail with reference to the drawings:
[0069] This embodiment provides a system for U shield centralized management identity authentication and security enhancement. The system structure is as Figure 1As shown in the figure, it includes a client, a dynamic multi-dimensional data identifier and an instruction library, and a security mini-model;
[0070] The client is deployed on the user terminal device and includes a PC client and a mobile APP. The PC client is used to collect multi-dimensional data of the user terminal device using the USBServer software, as well as the service proxy and action execution of the terminal device, and transmit the collected information to the dynamic multi-dimensional data identifier and the instruction library. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data.
[0071] Specifically, in this embodiment, the PC client is the Ukey Smart Butler, and the PC client includes:
[0072] The WatchDog module is used to monitor the hardware information, system environment, network environment, and software service data of the user terminal device; the hardware information includes: the ID, model, specification, size, frequency, and current resource utilization rate of the CPU, disk, and memory, and runs once every 30 seconds to calculate the time-consuming (counted as RV) in milliseconds for adding up numbers from 1 to 1 million as an operator (the value is accurate to 5 digits); the system environment includes: the system name and version, host name, environment variables, boot time, user name and number of users, U shield serial number, certificate number, certificate expiration time, U shield account number; the network environment includes: the local IP address, MAC address, network type, network latency in milliseconds, network card name and number, USBServer IP address; the software service data includes: the system service process name, status, and occupied resource data.
[0073] The LocalProxy module is used to take over and proxy all TCP / HTTP / HTTPS protocols through delegation; the LocalProxy module is the proxy gateway for all local services, and any TCP / HTTP / HTTPS protocol passing through the local area is forwarded by the LocalProxy module.
[0074] The UserHook module is used to capture all operations of the user's keyboard and mouse, page elements of different business systems, platform applications, and client applications, as well as user business operation data through delegation and takeover; among them, the user's keyboard and mouse operations specifically include: the action trajectories of the keyboard and mouse, the sequence of actions, and the time-consuming in milliseconds for each action.
[0075] The ActionChain module is used to execute the delegated action chain for U shield mounting / disconnecting and remote pressing operations, and monitor the access address, business data, and business operations of the business system corresponding to the U shield operation.
[0076] AppToken module, used to generate dynamic tokens and interact with the mobile terminal to achieve identity authentication.
[0077] The dynamic multi-dimensional data identifier and instruction library are used to perform structured analysis on the multi-dimensional data of the user terminal device collected by the client to generate a structured multi-dimensional data identifier, and transmit the structured analyzed multi-dimensional data to the security model.
[0078] Specifically, the dynamic multi-dimensional data identification and instruction library includes:
[0079] The environment perception module is used to parse the data transmitted by the WatchDog module and generate corresponding environmental data records;
[0080] The behavior perception module is used to parse the data transmitted by the UserHook module and generate corresponding behavior data records;
[0081] The business perception module is used to parse the data transmitted by the ActionChain module and generate corresponding business data records;
[0082] The feature perception module is used for the protocol transmitted by the LocalProxy module, removes data, text markup language symbols, style markup symbols and js codes that have no business meaning in the protocol, and generates corresponding feature data records;
[0083] The ID of each data record is composed of the first 20 digits of the MD5 value of the combination of the PC client login address and the account password;
[0084] Safe Broker Engine (SBE) is used to clean the data of various dimensions analyzed by the environment perception module, behavior perception module, business perception module, and feature perception module, perform context analysis and business logic analysis and assembly on the cleaned data, and classify, identify, and store the data according to the data dimensions.
[0085] The security mini-model is obtained by DeepSeek R1 model based on enterprise rules, internal control requirements, approval processes of various businesses, business data of various business systems and multi-dimensional data reasoning training after structured analysis, and is used to generate U-shield operation risk levels and operating instructions corresponding to each risk level, and transmit the generated U-shield operation risk levels and operating instructions corresponding to each risk level to the dynamic multi-dimensional data identification and instruction library.
[0086] Furthermore, the training of the small security model includes:
[0087] Set validity tags for the data in the four dimensions of environment, behavior, business, and features, and bind the validity tags corresponding to the variable data with the specific operator and the user terminal device to form client structured data records; the variable data includes business data for the user to execute business, operation data of the user's keyboard and mouse.
[0088] Structurally process enterprise rules, internal control requirements, approval processes for each business, and business data of each business system, and set validity tags and expressions. The validity tags and expressions are bound to the corresponding department / organization, and enterprise structured data records are formed; among them, the expression is specifically: meet / do not meet certain conditions, and the corresponding results.
[0089] The DeepSeek R1 model performs self-learning, training, and inference based on the client structured data records and enterprise structured data records, and optimizes the model parameters through manual annotation and test backtracking to obtain a security small model.
[0090] The trained security small model integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise systems, internal control requirements, and enterprise approval processes, and can realize dynamic risk inference. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even when the terminal device is controlled, the account password is leaked, and access is unauthorized, etc., it can still correctly identify the user identity, and then perform entrusted chain blocking and rejection on unsafe operations to effectively protect enterprise data and business security.
[0091] Further, the risk level classification includes:
[0092] When the similarity of the environmental label dimension value is equal to 100%, the similarity of the business label dimension value is greater than or equal to 90%, the similarity of the action label dimension value is greater than or equal to 80%, and the average difference value of the RV value is less than or equal to 10%, when all the above conditions are met, the risk level is low risk;
[0093] When the similarity of the environmental label dimension value is equal to 100%, the similarity of the business label dimension value is greater than or equal to 60% and less than 90%, the similarity of the action label dimension value is greater than or equal to 60% and less than 80%, and the average difference value of the RV value is less than or equal to 20%, when any two of the above three conditions are met, the risk level is medium risk;
[0094] When the similarity of the environmental label dimension value is not equal to 100%, the similarity of the business label dimension is less than 60%, the similarity of the action label dimension is less than 60%, and the average difference value of the RV value is greater than or equal to 60%, when any one of the above four conditions is met, the risk level is high risk.
[0095] Further, the operation instructions corresponding to each risk level include:
[0096] If the risk level is low risk, the identity authentication passes, and the user is allowed to perform U shield operations.
[0097] If the risk level is medium risk, secondary identity verification is triggered. After the secondary identity verification passes, the user is allowed to perform U shield operations; the secondary identity verification includes:
[0098] The AppToken module uses the MD value of the hardware information of the current terminal device as a random vector to generate a 6-digit numerical Token. The Token is valid for two minutes and is sent to the mobile terminal.
[0099] When the user performs U shield operations, a dynamic password input box pops up, and the user enters the Token received by the mobile APP in the input box.
[0100] The SBE compares whether the Token generated by the SBE is consistent with the Token entered by the user. If they are consistent, the user is allowed to perform U shield operations. If they are inconsistent, it is determined as high risk and the user is refused to perform U shield operations.
[0101] If the risk level is high risk, the identity authentication fails, the user is refused to perform U shield operations, the user's desktop, keyboard, and mouse are locked, the user is forced to exit the client, and a risk alert is sent to enterprise management personnel.
[0102] In the above operation instructions, the U shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0103] Further, when the U shield is determined to be low risk in all stages of identity authentication, connection and mounting, and business operations, in the business submission stage, the input data of the current page captured by the UserHook module is compared with the pre-stored information of the enterprise approval process in real time. If they are inconsistent, the current operation is determined as high risk, and the ActionChain module is called to execute the following delegated action chain:
[0104] Forcibly uninstall the U shield and exit the client, lock the keyboard, mouse, and screen of the user's terminal device, and send a risk alert to enterprise management personnel.
[0105] The security small model divides different risk levels, sets corresponding operation instructions for each risk level, neither requires an external fingerprint device, nor requires a whitelist and security control settings. All actions related to using and operating the U shield, as well as actions related to the enterprise U shield business, are dynamically and autonomously decided by the security small model and operation instructions are issued. The corresponding operation instructions for each risk level are implemented by calling the ActionChain module to execute a delegated action chain. When a high-risk operation is identified, the user's U shield operation can be quickly refused to prevent the spread of the attack chain.
[0106] Using the above system, when a user performs a U shield operation, the risk level of the current U shield operation can be evaluated in real time based on the real-time data and historical data of the client, and the U shield operation of the user can be allowed or rejected according to the operation instructions corresponding to the risk level.
[0107] This embodiment provides a method for centralized management of identity authentication and security enhancement of U shields. Based on the above system, it includes:
[0108] Data collection and parsing:
[0109] Collect multi-dimensional data of the user terminal device through the client. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data;
[0110] Perform structured parsing on the multi-dimensional data collected by the client to generate a structured multi-dimensional data identifier;
[0111] Model training and risk classification:
[0112] Train the DeepSeek R1 model based on enterprise rules, internal control requirements, business data of each business system, and the multi-dimensional data after structured parsing to obtain a security sub-model, and generate the U shield operation risk level and the operation instructions corresponding to each risk level;
[0113] Dynamically evaluate operation risks:
[0114] Based on the real-time data and historical data of the client, evaluate the risk level of the current U shield operation in real time, and allow or reject the U shield operation of the user according to the operation instructions corresponding to the risk level; among them, the risk level and the operation instructions corresponding to each risk level include:
[0115] Low risk: Identity authentication passed, allowing the user to perform U shield operations;
[0116] Medium risk: Trigger secondary identity authentication, and allow the user to perform U shield operations after the secondary identity authentication passes;
[0117] High risk: Identity authentication failed, rejecting the user from performing U shield operations, locking the user's desktop, keyboard, and mouse, forcing the user to exit the client, and sending a risk alert to enterprise management personnel;
[0118] Among them, the U shield operation is implemented by calling the ActionChain module to execute a delegated action chain.
[0119] The specific steps for dynamically evaluating operation risks are as follows:
[0120] After the user logs in to the PC client (Ukey Smart Butler), obtain the hardware information and environment information of the current user terminal device;
[0121] The hardware information and environment information are obtained respectively to obtain the MD5 value of the hardware information and the MD5 value of the environment information. The MD5 value of the hardware information and the MD5 value of the environment information are used as keywords for fast matching and indexing of the small security model.
[0122] Send the hardware information MD5 value and environment information MD5 value, user information, user action information within 10 minutes, and current RV value obtained from the current terminal device to SBE. SBE cleans and structurally analyzes the data sent by the terminal and sends it to the security model. The security model evaluates the risk level of the U shield operation in real time based on historical training data and real-time data.
[0123] If the risk level is low, the identity authentication is passed, and ActionChain is called to execute the delegated action chain that allows the U-Shield operation;
[0124] If the risk level is medium, secondary identity authentication is triggered: AppToken uses the current hardware information MD value as a random vector to generate a 6-digit numeric Token, which is valid for two minutes, and sends the Token to the mobile APP; when the user clicks on the Ukey smart housekeeper to connect or press, a dynamic password input box will pop up, and the Token value obtained by the mobile APP will be entered; SBE generates a Token based on the same algorithm, and when the user clicks OK, the input Token value is compared with the Token value generated by SBE to see if they are consistent. If they are consistent, ActionChain is called to remove the operation restrictions of the buttons such as connection, mounting, submission, and confirmation;
[0125] If the risk level is high, the identity authentication and security control will fail, any operation will be rejected, ActionChain will be called to execute the delegated action chain to reject the U-Shield operation, and Ukey Smart Butler will be exited. UserHook will be called to lock the desktop, keyboard and mouse, and a warning will be sent to the designated enterprise manager through the Ukey Smart Butler mobile APP;
[0126] If the risk of the enterprise U shield is low during the operation stages such as identity authentication and connection and mounting, and it is also low when operating the corresponding business system, but when submitting business information, according to the business approval flow information, it is determined that the currently submitted document data is inconsistent with the real-time data input by the user dynamically obtained by UserHook, then the current page operation is determined to be a high risk. UserHook obtains and intercepts the submit or confirm button on the current business system page, triggers the ActionChain delegated action chain, automatically prohibits the operation of the submit and confirm buttons on this page, exits the Ukey intelligent steward, calls UserHook to lock the current desktop, keyboard and mouse, and sends a warning to the designated enterprise management personnel through the Ukey intelligent steward mobile APP.
[0127] The following describes the effects of the present invention in actual applications through specific scenarios:
[0128] After the fund settlement staff member Li remotely connected and mounted the handling shield of the bank through the USBServer client on his own computer and went out to handle business without logging out, the login account and password of this online banking U shield, as well as the payment password, were leaked to illegal users, and the computer had also been remotely controlled by this illegal user. The main steps for the security small model to enhance identity authentication and security control in this scenario include:
[0129] 1. The Ukey intelligent steward sends the hardware information, environment information, etc. of the user's terminal computer device to the SBE service module;
[0130] 2. The Ukey intelligent steward UserHook obtains all the operations of the current illegal user, including the operation behavior track, the order of operations, the duration of each operation, and the time interval between each operation, and matches them with the security risk level of the backend security small model;
[0131] 3. After detecting that the device information and environment information are consistent, it is determined to be a low risk here;
[0132] 4. Compare the obtained operation behavior track, the order of operations, the duration of each operation, and the time interval between each operation of the current user with the data in the model. After comparison, the similarity of the dimension information of the business label (normally, it is necessary to log in to the financial system to view the payment approval form under one's own responsibility and copy the payment information to the text editing box for payment filling backup) and the action label (actions such as opening the financial system and entering the username and password) is less than 60%. The security small model determines that the current operation is a medium-high risk;
[0133] 5. Issue secondary identity authentication through the SBE module, call the AppToken service of the Ukey intelligent steward to generate a Token and issue it to Li's mobile phone APP (Ukey intelligent steward mobile phone);
[0134] 6. An illegal remote user inputs the login account and password of this shield and clicks the login button to log in.
[0135] 7. The Ukey Smart Butler pops up a Token input box for two-factor authentication and calls the UserHook service to lock the computer screen and keyboard and mouse (the part outside the Token input box).
[0136] 8. If the illegal remote user cannot input the corresponding Token this time or tries to input the Token value multiple times, and the security small model determines it as a high risk, it will automatically uninstall the shield, exit the Ukey Smart Butler, and completely lock the computer screen and keyboard and mouse, and remind the user and enterprise management personnel through the Ukey Smart Butler mobile APP that the account password of the current shield may have been leaked and the computer may have been remotely controlled.
[0137] 9. When the Ukey Smart Butler APP on Xiao Li's mobile phone receives the Token, it also receives a risk warning prompt message. And Xiao Li knows that he has not operated the computer at this time, that is, he knows that there is an illegal user remotely operating. After Xiao Li goes back, he restarts the computer, performs a Trojan virus scan, and modifies the account password of the shield.
[0138] 10. If the illegal user disguises very professionally and the business behavior and action trajectory are basically consistent with the historical data, and it cannot be determined as medium or high risk at this time. The illegal user successfully logs in to the bank with the account and password information of the illegally obtained bank online banking shield and fills in an illegal transfer form. At this time, the real-time filling data obtained by UserHook does not match the enterprise business approval flow data. Then, UserHook obtains the current page elements and calls the ActionChain delegated action chain to lock the confirmation or submission button, and automatically uninstalls the shield, exits the Ukey Smart Butler, completely locks the computer screen and keyboard and mouse, and reminds the user and enterprise management personnel through the Ukey Smart Butler mobile APP that the account password of the current shield may have been leaked and the computer may have been remotely controlled.
[0139] The security small model trained by the present invention integrates multi-dimensional data such as device environment, user behavior, business execution data, enterprise systems, internal control requirements, and enterprise approval processes, and can realize dynamic risk reasoning. Compared with traditional static rules (such as black and white lists, fixed permissions), it can identify complex attack scenarios. Even if the terminal device is controlled, the account password is leaked, and access is unauthorized, etc., it can still normally identify the user identity, and then perform delegated chain blocking and rejection on unsafe operations to effectively protect enterprise data and business security.
[0140] By dividing different risk levels and setting corresponding instructions for each risk level, there is no need for an external fingerprint device, nor for white list and security control settings. All actions related to using and operating the USB key, as well as actions related to the enterprise USB key business, are dynamically and autonomously decided by the security mini-model and instructions are issued. And by calling the ActionChain module to execute the delegated action chain, the instructions corresponding to each risk level are realized. When a high-risk operation is recognized, the USB key operation of the user can be quickly rejected to prevent the spread of the attack chain.
[0141] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A system for centralized management of identity authentication and security enhancement of USB tokens, characterized in that, It includes a client, a dynamic multi-dimensional data identifier and instruction library, and a security mini-model; The client is deployed on the user terminal device, and is used to collect multi-dimensional data of the user terminal device using the USBServer software, and transmit the collected information to the dynamic multi-dimensional data identifier and instruction library. The multi-dimensional data includes user terminal device environment data, user behavior data, business data executed by the user, and protocol feature data. The user terminal device includes a PC terminal and a mobile terminal; The dynamic multi-dimensional data identifier and instruction library is used to perform structured parsing on the multi-dimensional data of the user terminal device collected by the client to generate a structured multi-dimensional data identifier, and transmit the multi-dimensional data after structured parsing to the security mini-model; among them, the dynamic multi-dimensional data identifier and instruction library includes: an environment perception module, which is used to parse the data transmitted by the WatchDog module and generate corresponding environment data records; a behavior perception module, which is used to parse the data transmitted by the UserHook module and generate corresponding behavior data records; a business perception module, which is used to parse the data transmitted by the ActionChain module and generate corresponding business data records; a feature perception module, which is used for the protocol transmitted by the LocalProxy module, removes data without business meaning, text markup language symbols, style markup symbols, and js code in the protocol, and generates corresponding feature data records; a Safe Broker Engine (SBE), which is used to clean the data of each dimension parsed by the environment perception module, the behavior perception module, the business perception module, and the feature perception module, perform context parsing and business logic analysis and assembly on the cleaned data, and classify, identify, and store the data according to the data dimension; The security mini-model is obtained by reasoning and training the DeepSeek R1 model based on enterprise rules, internal control requirements, approval processes of each business, business data of each business system, and multi-dimensional data after structured parsing, and is used to generate the U shield operation risk level and operation instructions corresponding to each risk level, and transmit the generated U shield operation risk level and operation instructions corresponding to each risk level to the dynamic multi-dimensional data identifier and instruction library; When the user performs a U shield operation, based on the real-time data and historical data of the client, the risk level of the current U shield operation is evaluated in real time, and the U shield operation of the user is allowed / denied according to the operation instructions corresponding to the risk level; the risk level and the operation instructions corresponding to each risk level include: Low risk, allowing the user to perform a U shield operation; medium risk, triggering two-factor authentication, and allowing the user to perform a U shield operation after the verification is passed; high risk, denying the user to perform a U shield operation.
2. The system according to claim 1, characterized in that, The client includes: The WatchDog module is used to monitor the hardware information, system environment, network environment, and software service data of the user terminal device, and periodically perform the cumulative calculation of numbers from 1 to 1 million to obtain the RV value; The LocalProxy module is used to take over and proxy all TCP / HTTP / HTTPS protocols through delegation; The UserHook module is used to capture all operations of the user's keyboard and mouse, page elements of different business systems, platform applications, and client applications, as well as user business operation data through delegated takeover agents. The ActionChain module is used to execute the delegated action chain for U shield mounting / disconnection and remote pressing operations, and monitor the access addresses, business data, and business operations of the business systems corresponding to U shield operations. The AppToken module is used to generate dynamic tokens and interact with the mobile terminal to achieve identity authentication.
3. The system according to claim 2, characterized in that, The training of the security small model includes: Setting validity tags for the data in the four dimensions of environment, behavior, business, and feature, and binding the validity tags corresponding to the variable data with specific operators and user terminal devices to form client structured data records; the variable data includes the business data of the user performing business operations and the operation data of the user's keyboard and mouse. Structuring the enterprise rules, internal control requirements, and business data of each business system, and setting validity tags and expressions, which are bound to the corresponding departments / organizations to form enterprise structured data records. The DeepSeek R1 model performs self-learning, training, and inference based on the client structured data records and enterprise structured data records, and optimizes the model parameters through manual annotation and test backtracking to obtain the security small model.
4. The system according to claim 3, characterized in that, The risk level classification includes: When the identity similarity of the environment label dimension value is equal to 100%, the identity similarity of the business label dimension value is greater than or equal to 90%, the identity similarity of the action label dimension value is greater than or equal to 80%, and the average difference value of the RV value is less than or equal to 10%, the risk level is low risk when all the above conditions are met. When the identity similarity of the environment label dimension value is equal to 100%, the identity similarity of the business label dimension value is greater than or equal to 60% and less than 90%, the identity similarity of the action label dimension value is greater than or equal to 60% and less than 80%, and the average difference value of the RV value is less than or equal to 20%, the risk level is medium risk when any two of the above three conditions are met. When the identity similarity of the environment label dimension value is not equal to 100%, the identity similarity of the business label dimension is less than 60%, the identity similarity of the action label dimension is less than 60%, and the average difference value of the RV value is greater than or equal to 60%, the risk level is high risk when any one of the above four conditions is met.
5. The system according to claim 4, characterized in that, The operation instructions corresponding to each risk level include: If the risk level is low risk, the identity authentication passes, and the user is allowed to perform U shield operations. If the risk level is medium risk, secondary identity verification is triggered, and the user is allowed to perform U shield operations after the secondary identity verification passes. If the risk level is high risk, the identity authentication fails, the user is refused to perform U shield operations, the user's desktop, keyboard, and mouse are locked, the user is forced to exit the client, and a risk alert is sent to the enterprise management personnel. Among them, the U shield operation is implemented by calling the ActionChain module to execute the delegated action chain.
6. The system according to claim 5, wherein The secondary identity verification includes: The AppToken module uses the MD value of the hardware information of the current terminal device as a random vector to generate a 6-digit numerical Token. The Token is valid for two minutes and is sent to the mobile terminal; When the user performs a U shield operation, a dynamic password input box pops up, and the Token received by the mobile APP is entered in the input box; The SBE compares whether the Token generated by the SBE is the same as the Token entered by the user. If they are the same, the user is allowed to perform the U shield operation. If they are different, it is determined as a high risk and the user is refused to perform the U shield operation.
7. The system according to claim 5, wherein When the U shield is determined to be of low risk in the identity authentication, connection mounting, and business operation phases, in the business submission phase, the input data of the current page captured by the UserHook module is compared in real time with the pre-stored information of the enterprise approval process. If they are different, the current operation is determined to be of high risk, and the ActionChain module is called to execute the following delegated action chain: Forcibly uninstall the U shield and exit the client, lock the keyboard, mouse, and screen of the user's terminal device, and send a risk alert to the enterprise management personnel.
8. A method for centralized management of identity authentication and security enhancement of USB tokens, based on the system according to any one of claims 1 to 7, characterized in that, Including: Data collection and parsing: Collect multi-dimensional data of the user's terminal device through the client. The multi-dimensional data includes the user's terminal device environment data, user behavior data, business data executed by the user, and protocol feature data; Structurally parse the multi-dimensional data collected by the client to generate a structured multi-dimensional data identifier; Model training and risk classification: Based on enterprise rules, internal control requirements, the approval processes of various businesses, the business data of various business systems, and the multi-dimensional data after structured parsing, infer and train the DeepSeek R1 model to obtain a security sub-model, and generate the U shield operation risk level and the operation instructions corresponding to each risk level; Dynamically evaluate the operation risk: Based on the real-time data and historical data of the client, real-time evaluate the risk level of the current U shield operation, and allow / deny the user's U shield operation according to the operation instructions corresponding to the risk level; The risk level and the operation instructions corresponding to each risk level include: Low risk: The identity authentication is passed, and the user is allowed to perform the U shield operation; Medium risk: Trigger secondary identity authentication, and the user is allowed to perform the U shield operation after the secondary identity authentication is passed; High risk: The identity authentication fails, the user is refused to perform the U shield operation, the user's desktop, keyboard, and mouse are locked, the user is forced to exit the client, and a risk alert is sent to the enterprise management personnel; Among them, the U shield operation is realized by calling the ActionChain module to execute the delegated action chain.
Citation Information
Patent Citations
USB key centralized management identity authentication and security enhancement system and implementation method
CN118094510A
Enterprise evaluation method and device, storage medium and computer equipment
CN118396448A