Financial data security management system based on AI
By designing an AI-based financial data security management system, combining face image verification and user job information, targeted encryption and identity verification are achieved, and the problems of low security of financial data management and inaccurate leakage risk warning in the existing technology are solved, which significantly improves the security and management security of financial data.
Patent Information
- Application Number
- CN202510341350.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
It is difficult for the prior art to encrypt financial data targeted based on user rights, resulting in low security of financial data management and it is difficult to accurately warn of the risk of financial data leakage.
Design an AI-based financial data security management system, including data acquisition module, data processing module and security early warning module. By collecting and processing original financial data, combining face image verification and user job information, targeted encryption and identity verification are achieved; security risk coefficients are calculated based on access feature information, and real-time warnings are conducted.
It effectively improves the security and access control accuracy of financial data, reduces the risk of financial data leakage, ensures the security of corporate financial data, and improves management security and prevention capabilities.
Smart Images

Figure CN120197214A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of financial data security, and specifically relates to an AI-based financial data security management system. Background Art
[0002] Financial data is the core business data of an enterprise, involving aspects such as the enterprise's capital flow, revenue and cost, and profit analysis, and plays an important role in the enterprise's business decision-making and risk control. However, during the process of financial data collection, storage, transmission, analysis, and application, it may face security risks such as loss, tampering, and leakage, bringing losses or crises to the enterprise. Therefore, how to ensure the security of financial data is an important issue in the process of the enterprise's digital transformation.
[0003] The existing technology encrypts and controls the permissions of the enterprise's financial data through financial management software, thereby ensuring the security of financial data. However, it is difficult for the existing technology to encrypt financial data specifically according to user permissions, resulting in low security in managing financial data; in addition, when the financial management software of the existing technology has a low-privilege user accessing high-privilege financial data, it is difficult to accurately warn of the leakage risk of financial data.
[0004] The present invention proposes an AI-based financial data security management system to solve the above technical problems. Summary of the Invention
[0005] The present invention aims to solve at least one of the technical problems existing in the prior art; for this purpose, the present invention proposes an AI-based financial data security management system, which is used to solve the technical problems that it is difficult for the existing technology to encrypt financial data specifically according to user permissions, resulting in low security in managing financial data; in addition, it is difficult for the existing technology to accurately warn of the leakage risk of financial data.
[0006] To achieve the above object, the first aspect of the present invention provides an AI-based financial data security management system, including: a data processing module, and a data collection module and a security warning module connected thereto;
[0007] The data collection module: is used to collect the original financial data of the enterprise in production and operation; desensitize the original financial data to obtain standard financial data; collect the face images of the target user when accessing the standard financial data;
[0008] The said data processing module: is used to allocate corresponding user permissions based on the job information of the target user; encrypt the standard financial data specifically based on the user permissions and encryption algorithms; authenticate the identity of the target user based on the face image, and obtain the authorization status of the target user according to the result of the identity authentication; wherein, the job information includes management personnel, financial personnel, and ordinary employees;
[0009] The said security warning module: is used to access the standard financial data based on the authorization status and user permissions of the target user and obtain access feature information; calculate the security risk coefficient of the financial system based on the access feature information; and give a warning to the financial system based on the security risk coefficient.
[0010] Preferably, the desensitization processing of the original financial data includes:
[0011] A1: Extract the original financial data from the financial system;
[0012] A2: Convert the original financial data into text format to obtain financial text information;
[0013] A3: Segment the financial text information through a word segmentation algorithm to obtain a number of keywords;
[0014] A4: Input the number of keywords into a preset sensitive word database for matching to obtain a matching result; wherein, the matching result includes successful matching and recognition;
[0015] A5: Mark the keywords with successful matching as words to be desensitized, and replace the words to be desensitized with placeholders;
[0016] A6: Mark the original financial data with the replaced words to be desensitized as standard financial data.
[0017] It should be noted that the sensitive words include customer information, contract amount, budget plan, and employee salary.
[0018] Preferably, the allocation of corresponding user permissions based on the job information of the target user includes:
[0019] Extract the job information of the target user, and determine the user permissions according to the job information;
[0020] If the job information of the target user is management personnel, then allocate the user permissions of the target user as first-level permissions; if the job information of the target user is financial personnel, then allocate the user permissions of the target user as second-level permissions; if the job information of the target user is ordinary employees, then allocate the user permissions of the target user as third-level permissions; wherein, the job information includes management personnel, financial personnel, and ordinary employees; the user permissions include first-level permissions, second-level permissions, and third-level permissions, and first-level permissions > second-level permissions > third-level permissions.
[0021] It should be noted that users with higher permission levels can view or operate on the financial data corresponding to lower-level user permissions.
[0022] Preferably, the targeted encryption of the standard financial data based on user permissions and encryption algorithms includes:
[0023] Extract the standard financial data, and sequentially label the numbers of the standard financial data as i; where i = 1, 2,..., n, and n is the total number of standard financial data.
[0024] Deposit the numbers corresponding to the standard financial data that can be accessed by the first-level permission into the first coding sequence; deposit the numbers corresponding to the standard financial data that can be accessed by the second-level permission into the second coding sequence; deposit the numbers corresponding to the standard financial data that can be accessed by the third-level permission into the third coding sequence.
[0025] Generate a permission public key and a permission private key corresponding to the user permissions; where the permission public key includes a first public key, a second public key, and a third public key, and the permission private key includes a first private key, a second private key, and a third private key.
[0026] Generate a data public key and a data private key corresponding to the standard financial data.
[0027] Encrypt the first coding sequence with the first public key to obtain a first encrypted label; encrypt the second coding sequence with the second public key to obtain a second encrypted label; encrypt the third coding sequence with the third public key to obtain a third encrypted label; encrypt the standard financial data with the data public key to obtain a data encrypted label.
[0028] Bind the permission private key and the data private key to the account of the target user to obtain a decryption private key; where the decryption private key includes the permission private key and the data private key.
[0029] It should be noted that the encryption algorithm in the present invention is an asymmetric encryption algorithm, including encryption algorithms such as RSA and ECC.
[0030] Preferably, the binding of the permission private key and the data private key to the account of the target user includes:
[0031] Bind the first private key corresponding to the first public key to the account of the target user with the first-level permission, and mark the first private key as the decryption key; bind the second private key corresponding to the second public key to the account of the target user with the second-level permission; bind the third private key corresponding to the third public key to the account of the target user with the third-level permission; bind the data private key corresponding to the data public key to the account of the target user with each user permission.
[0032] Preferably, the authentication of the target user based on the face image includes:
[0033] Obtain the face image of the target user when logging in to the financial management system, and input the face image of the target user into the authorized face database for matching; determine whether the matching result is successful; if so, mark the identity verification result as verified and mark the authorization status as authorized; if not, mark the identity verification result as verified and mark the authorization status as unauthorized.
[0034] Preferably, the authorized face database is constructed in the following manner:
[0035] When the target user creates an account in the financial data management system, synchronously collect the face image of the target user, and bind the face image to the account of the target user to obtain an account-face mapping relationship; save the face mapping relationship of the target user to the authorized face database.
[0036] Preferably, accessing the standard financial data based on the authorization status and user permissions of the target user and obtaining access feature information includes:
[0037] Extract the authorization status and user permissions of the target user; determine whether the authorization status and user permissions of the target user both meet the permission requirements of the standard financial data; if so, allow the target user to access the financial data and mark this access as a normal access; if not, restrict the target user from accessing the financial data and mark this access as an unauthorized access;
[0038] Count the number of unauthorized accesses of the target user and the number of file downloads during normal access, and integrate the number of unauthorized accesses and file downloads into access feature information.
[0039] Preferably, calculating the security risk coefficient of the financial system based on the access feature information includes:
[0040] Extract the access feature information of the target user; calculate the security risk coefficient AFX through the formula AFX = a×ln(1 + YFC)+b×arctan(XZS); where, YFC is the number of unauthorized accesses, XZS is the number of file downloads; a and b are both proportionality coefficients greater than 0; ln() is the natural logarithm function with the natural constant as the base, and arctan() is the arctangent function.
[0041] Preferably, warning the financial system based on the security risk coefficient includes:
[0042] Extract the security risk coefficient; determine whether the security risk coefficient is greater than a preset risk threshold; if so, generate a warning message and send the warning message to the smart terminal of the management personnel; if not, continue to obtain the security risk of the financial system for monitoring; where, the smart terminal includes mobile phones, tablets and computers.
[0043] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0044] 1. By collecting and processing the original financial data of enterprises, the present invention realizes the standardization and desensitization of data. At the same time, combined with face image verification and permission allocation of target user position information, it effectively improves the security of financial data and the accuracy of access control. Targeted encryption of standard financial data based on user permissions and encryption algorithms further ensures the secure transmission and access of financial data, thereby reducing the risk of financial data leakage. Calculating the security risk coefficient by combining access feature information realizes real-time warning of the financial system, which is conducive to timely discovering and preventing potential security hazards, thus ensuring the security of enterprise financial data.
[0045] 2. By double-verifying the authorization status and user permissions of target users, the present invention ensures that target users can only access the financial data within their permissions, effectively preventing the loss and leakage of financial data caused by account theft, and significantly improving management security. At the same time, real-time statistics of unauthorized access and file download times provide a basis for calculating the security risk coefficient based on access features subsequently, which is conducive to accurately evaluating and strengthening the security protection ability of the financial system.
[0046] 3. By capturing the access feature information of target users, especially the number of unauthorized accesses and file download times, the number of unauthorized accesses can reflect the risk of low-level permission personnel illegally accessing high-level permission financial data, and the number of file downloads to a certain extent maps the possibility of financial data leakage. Substituting these two indicators into a special formula to calculate the security risk coefficient can accurately evaluate the security situation of financial data in the financial system, providing a strong basis for managers to take targeted protection measures, thereby effectively improving the security and prevention ability of financial data management. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0048] Figure 1 It is the overall flowchart of the AI-based financial data security management system of the present invention;
[0049] Figure 2 It is the schematic diagram of the principle of the AI-based financial data security management system of the present invention;
[0050] Figure 3 It is the flowchart of accessing standard financial data and obtaining access feature information in the present invention. Specific implementation mode
[0051] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative work belong to the scope of protection of the present invention.
[0052] Please refer to Figures 1 - 3 , an embodiment of the first aspect of the present invention provides a financial data security management system based on AI, including: a data processing module, and a data acquisition module and a security warning module connected thereto;
[0053] Data acquisition module: used to collect the original financial data of the enterprise in production and operation; desensitize the original financial data to obtain standard financial data; collect the face images of the target user when accessing the standard financial data;
[0054] Data processing module: used to allocate corresponding user permissions based on the job information of the target user; encrypt the standard financial data specifically based on the user permissions and encryption algorithms; authenticate the identity of the target user based on the face image, and obtain the authorization status of the target user according to the result of the identity authentication; among them, the job information includes management personnel, financial personnel and ordinary employees;
[0055] Security warning module: used to access the standard financial data based on the authorization status and user permissions of the target user and obtain access feature information; calculate the security risk coefficient of the financial system based on the access feature information; give a warning to the financial system based on the security risk coefficient.
[0056] In this embodiment, the desensitization processing of the original financial data includes:
[0057] A1: Extract the original financial data from the financial system;
[0058] A2: Convert the original financial data into a text format to obtain financial text information;
[0059] A3: Segment the financial text information through a word segmentation algorithm to obtain a number of keywords;
[0060] A4: Input the number of keywords into a preset sensitive word database for matching to obtain a matching result; among them, the matching result includes successful matching and recognition;
[0061] A5: Mark the keywords with successful matching as words to be desensitized, and replace the words to be desensitized with placeholders;
[0062] A6: Mark the original financial data with the replaced words to be desensitized as standard financial data.
[0063] Exemplarily, in this embodiment, the jieba word segmentation algorithm is used to segment the financial text information to obtain several keywords; the sensitive word database is {address, mobile phone number, customer name, contract amount, employee salary}; assuming that the contract amount of the word to be desensitized is "10460.20" yuan, the contract amount is replaced with "1046***" yuan through the placeholder "***".
[0064] It should be noted that the sensitive words include customer information, contract amount, budget plan, and employee salary.
[0065] In this embodiment, the corresponding user permissions are assigned based on the job information of the target user, including:
[0066] Extract the job information of the target user and determine the user permissions according to the job information;
[0067] If the job information of the target user is a manager, the user permission of the target user is assigned as the first-level permission; if the job information of the target user is a financial staff, the user permission of the target user is assigned as the second-level permission; if the job information of the target user is an ordinary employee, the user permission of the target user is assigned as the third-level permission; among them, the job information includes managers, financial staff, and ordinary employees; the user permissions include the first-level permission, the second-level permission, and the third-level permission, and the first-level permission > the second-level permission > the third-level permission.
[0068] It should be noted that users with higher permission levels can view or operate the financial data corresponding to lower-level user permissions.
[0069] In the present invention, by setting corresponding user permissions for target users with different job information, the higher the position, the higher the set user permissions, which is convenient for subsequently setting the corresponding financial data access scope according to the user permissions of the target user, thereby facilitating the control of access permissions for financial data, improving the security of financial data during the access process, and reducing the risk of financial data leakage.
[0070] In this embodiment, targeted encryption is performed on the standard financial data based on user permissions and encryption algorithms, including:
[0071] Extract the standard financial data, and sequentially mark the numbers of the standard financial data as i; where i = 1, 2,..., n, and n is the total number of standard financial data;
[0072] Store the numbers corresponding to the standard financial data accessible with first-level permissions into the first coding sequence; store the numbers corresponding to the standard financial data accessible with second-level permissions into the second coding sequence; store the numbers corresponding to the standard financial data accessible with third-level permissions into the third coding sequence;
[0073] Generate a permission public key and a permission private key corresponding to the user permissions; among them, the permission public key includes a first public key, a second public key, and a third public key, and the permission private key includes a first private key, a second private key, and a third private key;
[0074] Generate a data public key and a data private key corresponding to the standard financial data;
[0075] Encrypt the first coding sequence with the first public key to obtain a first encrypted tag; encrypt the second coding sequence with the second public key to obtain a second encrypted tag; encrypt the third coding sequence with the third public key to obtain a third encrypted tag; encrypt the standard financial data with the data public key to obtain a data encrypted tag;
[0076] Bind the permission private key, the data private key to the account of the target user to obtain a decryption private key; among them, the decryption private key includes the permission private key and the data private key.
[0077] It should be noted that the encryption algorithm in the present invention is an asymmetric encryption algorithm, including encryption algorithms such as RSA and ECC.
[0078] The present invention sets corresponding coding sequences according to user permissions, and the coding sequences store the numbers of the standard financial data that can be accessed by the target users with the corresponding user permissions; encrypt the corresponding coding sequences with different permission public keys to obtain a number of encrypted tags; encrypt the standard financial data with the data public key to obtain a data encrypted tag; so that when the target user decrypts the standard financial data, only the financial data matching the permissions of the target user can be decrypted, which is beneficial to improving the security of financial data management.
[0079] In this embodiment, binding the permission private key, the data private key to the account of the target user includes:
[0080] Bind the first private key corresponding to the first public key to the account of the target user with first-level permissions, and mark the first private key as the decryption key; bind the second private key corresponding to the second public key to the account of the target user with second-level permissions; bind the third private key corresponding to the third public key to the account of the target user with third-level permissions; bind the data private key corresponding to the data public key to the account of the target user with each user permission.
[0081] In the present invention, by binding the corresponding decryption key to the account of the target user according to the size of the user permissions of the target user, it is ensured that the target user can only access the financial data within the scope of the permissions possessed by the user himself, avoiding the situation where low-level permission users accidentally operate high-level permission financial data, thus being conducive to improving the security of financial data management.
[0082] In this embodiment, authenticating the target user based on the face image includes:
[0083] Obtaining the face image of the target user when logging in to the financial management system, and inputting the face image of the target user into the authorized face database for matching; judging whether the matching result is successful; if so, marking the authentication result as verified and marking the authorization status as authorized; if not, marking the authentication result as verified and marking the authorization status as unauthorized.
[0084] Exemplarily, it is set that the face image of the target user has been saved in the authorized face database. Then, when the face image of the target user is input into the authorized face database for matching, the matching result is successful; the authentication result is marked as verified and the authorization status is marked as authorized.
[0085] In this embodiment, the authorized face database is constructed in the following manner:
[0086] When the target user creates an account in the financial data management system, the face image of the target user is synchronously collected and bound to the account of the target user to obtain an account-face mapping relationship; the face mapping relationship of the target user is saved to the authorized face database.
[0087] In this embodiment, accessing the standard financial data based on the authorization status and user permissions of the target user and obtaining access feature information includes:
[0088] Extracting the authorization status and user permissions of the target user; judging whether both the authorization status and user permissions of the target user meet the permission requirements of the standard financial data; if so, allowing the target user to access the financial data and marking this access as a normal access; if not, restricting the target user from accessing the financial data and marking this access as an unauthorized access;
[0089] Counting the number of unauthorized accesses of the target user and the number of file downloads during normal access, and integrating the number of unauthorized accesses and the number of file downloads into access feature information.
[0090] Exemplarily, set the authorization status of the target user as authorized and the user permission as secondary permission; the permission requirement for the standard financial data accessed by the current target user is tertiary permission; since both the authorization status and user permission of the target user meet the permission requirements for the standard financial data, the target user is allowed to access the financial data, and this access is marked as normal access; count the number of unauthorized accesses of the target user and the number of file downloads during normal access, and integrate the number of unauthorized accesses and file downloads into access feature information.
[0091] It should be noted that when the target user accesses the financial data, the present invention verifies both the authorization status and user permission of the target user; so that the target user can only access the financial data within the scope of the permissions owned by the target user, avoiding the risk of the target user's account being stolen by others and causing the loss and leakage of financial data, thereby facilitating improving the security of the management of financial data; in addition, the present invention counts the number of unauthorized accesses and file downloads while the target user is accessing, which is convenient for calculating the security risk coefficient of the financial system according to the access feature information subsequently.
[0092] In this embodiment, calculating the security risk coefficient of the financial system based on the access feature information includes:
[0093] Extract the access feature information of the target user; calculate the security risk coefficient AFX through the formula AFX = a × ln(1 + YFC) + b × arctan(XZS); where, YFC is the number of unauthorized accesses, XZS is the number of file downloads; a and b are both proportionality coefficients greater than 0, and the specific values of a and b are set by experts in relevant fields according to experience; ln() is the logarithmic function with the natural constant as the base, and arctan() is the arctangent function.
[0094] Exemplarily, set the proportionality coefficient a = 5, b = 0.2; the number of unauthorized accesses YFC = 16, the number of file downloads XZS = 13; calculate the security risk coefficient AFX ≈ 31.29 through the formula.
[0095] It should be noted that the more the number of unauthorized accesses and file downloads, the greater the calculated security risk coefficient, indicating that the security risk of the financial data in the financial system is higher.
[0096] The present invention obtains the unauthorized access times and file download times in the target user's access feature information. The unauthorized access times can reflect the risk that financial data with high-level permissions in the financial system is accessed by personnel with low-level permissions, and the file download times can, to a certain extent, reflect the risk of leakage of financial data. The unauthorized access times and file download times are substituted into a specific formula to calculate the security risk coefficient, so that the calculated security risk coefficient can accurately evaluate the security risk situation of the financial data in the financial system, facilitating managers to take other protection measures for the financial data according to the security risk coefficient, thereby being beneficial to improving the security of managing financial data.
[0097] In this embodiment, warning the financial system based on the security risk coefficient includes:
[0098] Extracting the security risk coefficient; determining whether the security risk coefficient is greater than a preset risk threshold; if yes, generating a warning message and sending the warning message to the intelligent terminal of the manager; if no, continuing to obtain the security risk of the financial system for monitoring; where the intelligent terminal includes mobile phones, tablets, and computers.
[0099] Exemplarily, set the security risk coefficient AFX = 31.29, and the preset risk threshold is 26; since the security risk coefficient is greater than the preset risk threshold, a warning message is generated and sent to the intelligent terminal of the manager.
[0100] Some of the data in the above formula is calculated by removing the dimension and taking its numerical value. The formula is obtained by software simulation of a large amount of collected data to get a formula closest to the actual situation; the preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.
[0101] The working principle of the present invention:
[0102] The present invention collects the original financial data of an enterprise in production and operation; performs desensitization processing on the original financial data to obtain standard financial data; collects the face images of target users when accessing the standard financial data; assigns corresponding user permissions based on the job information of the target users; performs targeted encryption on the standard financial data based on the user permissions and encryption algorithms; performs identity verification on the target users based on the face images, and obtains the authorization status of the target users according to the results of the identity verification; accesses the standard financial data based on the authorization status and user permissions of the target users and obtains access feature information; calculates the security risk coefficient of the financial system based on the access feature information; warns the financial system based on the security risk coefficient.
[0103] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. An AI-based financial data security management system, comprising: The data processing module, and the data acquisition module and safety warning module connected thereto are characterized in that: The data collection module is used to collect the original financial data of the enterprise in production and operation; perform desensitization processing on the original financial data to obtain standard financial data; collect the face image of the target user when accessing the standard financial data; The data processing module is used to assign corresponding user rights based on the job information of the target user; to perform targeted encryption on the standard financial data based on the user rights and encryption algorithm; to perform identity authentication on the target user based on the face image, and to obtain the authorization status of the target user according to the result of the identity authentication; The security warning module is used to access standard financial data and obtain access feature information based on the authorization status and user rights of the target user; calculate the security risk coefficient of the financial system based on the access feature information; and issue a warning to the financial system based on the security risk coefficient.
2. According to claim 1, the AI-based financial data security management system is characterized in that: The desensitizing of the original financial data includes: A1: Extract original financial data from the financial system; A2: Convert the original financial data into text format to obtain financial text information; A3: Use the word segmentation algorithm to segment the financial text information and obtain several keywords; A4: Input several keywords into the preset sensitive word database for matching and obtain matching results; wherein the matching results include matching success and matching identification; A5: Mark the successfully matched keywords as words to be desensitized and use placeholders to replace them. A6: Mark the original financial data after the desensitized words are replaced as standard financial data.
3. According to claim 1, the AI-based financial data security management system is characterized in that: The assigning of corresponding user rights based on the job information of the target user includes: Extract the target user's job information and determine the user's permissions based on the job information; If the target user's job information is a manager, the target user's user rights are assigned to the first-level rights; if the target user's job information is a financial staff, the target user's user rights are assigned to the second-level rights; if the target user's job information is an ordinary employee, the target user's user rights are assigned to the third-level rights; wherein, the job information includes managers, financial staff and ordinary employees; user rights include first-level rights, second-level rights and third-level rights, and first-level rights > second-level rights > third-level rights.
4. According to claim 1, the AI-based financial data security management system is characterized in that: The targeted encryption of standard financial data based on user permissions and encryption algorithms includes: Extract standard financial data, and mark the numbers of the standard financial data as i in sequence; wherein i=1, 2, ..., n, and n is the total number of standard financial data; The numbers corresponding to the standard financial data accessible by the first-level authority are stored in the first coding sequence; the numbers corresponding to the standard financial data accessible by the second-level authority are stored in the second coding sequence; the numbers corresponding to the standard financial data accessible by the third-level authority are stored in the third coding sequence; Generate a permission public key and a permission private key corresponding to the user's permission; wherein the permission public key includes a first public key, a second public key, and a third public key, and the permission private key includes a first private key, a second private key, and a third private key; Generate data public key and data private key corresponding to standard financial data; The first coding sequence is encrypted by the first public key to obtain a first encryption tag; the second coding sequence is encrypted by the second public key to obtain a second encryption tag; the third coding sequence is encrypted by the third public key to obtain a third encryption tag; the standard financial data is encrypted by the data public key to obtain a data encryption tag; Bind the permission private key, data private key and the target user's account to obtain a decryption private key; wherein the decryption private key includes the permission private key and the data private key.
5. According to claim 4, the AI-based financial data security management system is characterized in that: The step of binding the permission private key, the data private key and the target user's account includes: Bind the first private key corresponding to the first public key to the account of the target user with the first-level authority, and mark the first private key as the decryption key; bind the second private key corresponding to the second public key to the account of the target user with the second-level authority; bind the third private key corresponding to the third public key to the account of the target user with the third-level authority; bind the data private key corresponding to the data public key to the account of the target user of each user authority.
6. The AI-based financial data security management system according to claim 1, characterized in that: The identity verification of the target user based on the face image includes: Obtain the facial image of the target user when he logs into the financial management system, and input the facial image of the target user into the authorized face database for matching; determine whether the matching result is successful; if yes, mark the identity authentication result as verified, and mark the authorization status as authorized; if not, mark the identity authentication result as verified, and mark the authorization status as unauthorized.
7. The AI-based financial data security management system according to claim 6 is characterized in that: The authorized face database is constructed in the following way: When the target user creates an account in the financial data management system, the target user's facial image is collected simultaneously, and the facial image is bound to the target user's account to obtain an account-face mapping relationship; the target user's facial mapping relationship is saved in the authorized face database.
8. The AI-based financial data security management system according to claim 1, characterized in that: The accessing of standard financial data and obtaining access feature information based on the authorization status and user rights of the target user includes: Extract the authorization status and user permissions of the target user; determine whether the authorization status and user permissions of the target user meet the permission requirements of standard financial data; if yes, allow the target user to access the financial data and mark this access as normal access; if no, restrict the target user from accessing the financial data and mark this access as unauthorized access; Count the number of unauthorized accesses and file downloads during normal access by the target user, and integrate the number of unauthorized accesses and file downloads into access feature information.
9. The AI-based financial data security management system according to claim 1, characterized in that: The security risk factor of the financial system based on access feature information and calculation includes: Extract the target user's access feature information; calculate the security risk factor AFX through the formula AFX=a×ln(1+YFC)+b×arctan(XZS); where YFC is the number of unauthorized accesses, and XZS is the number of file downloads; a and b are both proportional coefficients greater than 0; ln() is a logarithmic function with a natural constant as the base, and arctan() is an inverse tangent function.
10. The AI-based financial data security management system according to claim 2, characterized in that: The early warning of the financial system based on the security risk factor includes: Extract the security risk factor; determine whether the security risk factor is greater than the preset risk threshold; if yes, generate warning information and send it to the manager's smart terminal; if no, continue to obtain the security risk of the financial system for monitoring; among them, smart terminals include mobile phones, tablets and computers.
Citation Information
Cited By
Safety management method and system for data management and storage medium
CN120896742A
Financial data security management system based on multi-factor identity authentication
CN122491896A