Data security management method and system for intelligent service library

By comprehensively considering the attack situation, physical risks and key usage frequency, dynamically adjusting the key replacement frequency, the problem that traditional static encryption cannot cope with the security threat of intelligent business databases is solved, data security is improved and resource utilization is optimized.

CN120277696AActive Publication Date: 2025-07-08GUANGZHOU HUITONG FINANCE SERVICE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510747826.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-08
Estimated Expiration
2045-06-06

AI Technical Summary

Technical Problem

Traditional encryption at rest and fixed security measures cannot effectively deal with security threats in smart business libraries that change over time and environment, resulting in increased difficulty in key management, easy to be cracked or stolen, and cannot ensure data security.

Method used

By collecting user data and archive data, calculating attack situation evaluation coefficient, physical risk score and key usage frequency, formulating dynamic archive key replacement rules, using Huffman encoding to optimize memory utilization, combining Poisson distribution model to identify abnormal behavior, and dynamically adjusting key replacement frequency to enhance security.

Benefits of technology

It realizes dynamic adjustment of key replacement strategies based on risk conditions, reduces the risk of key cracking or leakage, improves the security of archive data, and avoids waste of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277696A_ABST
    Figure CN120277696A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data processing, in particular to a data security management method and system for an intelligent service library, and the method comprises the steps: collecting user data and archive data of each user in the service library; calculating a data risk assessment factor of each user file; and formulating an archive key replacement rule of the user based on the data risk assessment factor. According to the invention, the file key replacement rule of the user is made based on the quantized data risk assessment factor, and the key replacement strategy can be dynamically adjusted according to the risk condition of the file data of each user, so that the security of the file data is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing. More specifically, the present invention relates to a data security management method and system for an intelligent business library. Background Art

[0002] Intelligent business libraries are applicable to various financial institutions, such as banks, credit unions, etc., and are used to store important items such as cash, cash boxes, important blank vouchers, and negotiable securities. It not only meets the needs of financial institutions for the safe storage of funds, but also improves the efficiency and management level of business operations, and is an indispensable important facility in the operation of financial institutions.

[0003] Intelligent business libraries are not only used to store important items such as cash and cash boxes. Taking a traditional intelligent business library as an example, it also has the function of providing a long-term and stable storage environment for various archive data. The content of these archive data is rich and important, including precious historical records, key legal documents, detailed personal files, etc., and the storage time span may be as long as several years or even decades.

[0004] In traditional encryption practices, static keys are mostly used to encrypt data. The static key remains unchanged during the data encryption process, which means that the life cycle of the key may be exactly the same as the storage time of the archive data. Due to the long storage time of the archive data, the management difficulty of the static key increases, and it is easy to lead to improper key management. For example, a long-term unchanged key is more likely to be cracked or stolen by attackers through various means.

[0005] With the progress of technology and the increasing complexity of network attack means, security threats may come from different directions and will change with time and environment. Using traditional static encryption and fixed security measures cannot ensure the data security of intelligent business libraries. Summary of the Invention

[0006] To solve the above technical problem that using traditional static encryption and fixed security measures cannot ensure the data security of intelligent business libraries, the present invention provides solutions in the following aspects.

[0007] In a first aspect, a data security management method for an intelligent business library includes: Collecting user data and archive data of each user in the business library; Calculating the data risk assessment factor of each user's archive; Formulating an archive key replacement rule for a user based on the data risk assessment factor; Wherein, the data risk assessment factor is: Calculate the attack situation evaluation coefficient of the user, the physical risk score of the business database, and the key usage frequency of the user profile data. Normalize the ratio of the sum of the attack situation evaluation coefficient of the user and the physical risk score of the business database to the key usage frequency of the user profile data to obtain the data risk evaluation factor. The attack situation evaluation coefficient is used to characterize the impact of the correlation between the user's profile data on security. The physical risk score is positively correlated with the real-time power consumption of the business database.

[0008] The present invention comprehensively considers multiple factors affecting the security of profile data. Among them, the attack situation evaluation coefficient reflects the impact of the correlation between the user's profile data on security. The physical risk score of the file management system takes into account the physical environment factors of the business database (such as power consumption, etc.). The key usage frequency reflects the security of the key. Therefore, it can more comprehensively and accurately measure the risk level faced by the profile data. By formulating the profile key replacement rule based on the quantified data risk evaluation factor, the key replacement strategy can be dynamically adjusted according to the risk status of each user's profile data. For users with higher risks, the key can be replaced more frequently to reduce the risk of the key being cracked or leaked, thereby enhancing the security of the profile data.

[0009] Preferably, the profile data includes the number of file accesses, the storage duration, and the electronic files. Huffman coding is used to encode each electronic file, and the memory size occupied by each encoded electronic file is recorded.

[0010] Huffman coding is a lossless data compression algorithm. An optimal binary tree is constructed according to the frequency of characters (i.e., a certain data unit of the electronic file). Different lengths of codes are assigned to each character. For characters with high frequencies, shorter codes are assigned, and for characters with low frequencies, longer codes are assigned. In this way, the memory space occupied by the electronic file data during storage can be effectively reduced. Recording the memory size occupied by each encoded electronic file can assist in file data analysis.

[0011] Preferably, the process of obtaining the key usage frequency includes: Count the number of accesses of each file of each user in the business database. Calculate the average time of each file of each user stored in the business database each time. Take the ratio of the number of accesses of each file of each user in the business database to the average time of each file of each user stored in the business database each time as the key usage frequency of each file data of each user.

[0012] By analyzing the key usage frequency, it is possible to identify which files have higher security risks. For example, if the key usage frequency of a certain file is abnormally high, it may mean that the file is being illegally accessed or there is a risk of internal leakage.

[0013] Preferably, the process of obtaining the attack situation evaluation coefficient includes: Calculate the similarity between any two files of the user, sum up the similarities between all pairs of files of the user, and divide by the average memory occupied after encoding all files of the user to obtain the attack situation evaluation coefficient of the user.

[0014] By calculating the similarity between different files of the user, it is possible to measure whether the user's behaviors, characteristics, etc. are consistent in different scenarios or time periods. If the similarity is low, it indicates that there are significant differences in the user's behavior patterns, and there may be risks of being attacked or abnormal operations; summing up the similarities between all files and dividing by the average memory occupied after encoding the files can further standardize the similarity index, making it more comparable, helping to eliminate biases caused by different numbers of files or memory occupations, and making the attack situation evaluation coefficient more accurate.

[0015] Preferably, the process of obtaining the physical risk score includes: Obtain the real-time power consumption of the business library at each moment within a preset time. For each moment, calculate the difference between the real-time power consumption of the business library and the standard power consumption, and perform integration to obtain the total deviation between the real-time power consumption of the business library and the standard power consumption within the preset time. Use the total deviation as the physical risk score.

[0016] When a failure, equipment aging, or other abnormal situations occur in the business library, its real-time power consumption often has a large difference from the standard power consumption. By calculating the total deviation as the physical risk score, these abnormal situations can be quickly detected. For example, if the sealing strip of the business library is damaged, causing the refrigeration or heating system to consume more energy to maintain the temperature inside the cabinet, the real-time power consumption will increase, and the total deviation will also increase accordingly, thus issuing an abnormal warning in a timely manner.

[0017] Preferably, the process of obtaining the physical risk score further includes: Count the number of times of authentication failure of each user before successful authentication within the preset time, find the number of failures that makes the number of users with authentication failure the highest according to the Poisson distribution model, and record this number of failures as the authentication failure factor; Normalize the product of the authentication failure factor and the total deviation to obtain the physical risk score.

[0018] By counting the number of times each user fails authentication before successful authentication within a preset time, it is possible to capture the abnormal behavior patterns of users during the authentication process. For example, a normal user may occasionally fail authentication due to input errors or other reasons, but a malicious attacker or a user attempting to illegally access the system may frequently try different passwords or authentication methods, resulting in multiple authentication failures. According to the Poisson distribution model, finding the number of failures that results in the highest number of users with authentication failures as the authentication failure factor can quantify the degree of this abnormal behavior and more accurately identify potential high-risk users.

[0019] Preferably, formulating the user's profile key replacement rule based on the data risk assessment factor includes: When the data risk assessment factor is greater than the first threshold, increase the key rotation frequency of the user profile; Regularly update the key of the user profile according to the determined key rotation frequency, re-encrypt the profile data with the new key, and delete the old key and the profile data encrypted with the old key.

[0020] Preferably, the similarity between any two profiles of the user satisfies the relational expression: ; where is the similarity between the th profile and the th profile of the user, is the data after encoding the th profile of the user, is the data after encoding the th profile of the user, represents the intersection between the data after encoding the th profile and the th profile of the user, represents the union between the data after encoding the th profile and the th profile of the user.

[0021] By comparing the similarities between profiles, abnormal profiles that are significantly different from most profiles can be discovered.

[0022] Preferably, the key usage frequency satisfies the relational expression: ; where is the key usage frequency of the th profile of user , is the number of accesses of the th profile of user within the set time window, is user the average storage duration of the th file,

[0023] In a second aspect, a data security management system for an intelligent service library includes: a processor and a memory, where the memory stores computer program instructions, and when the computer program instructions are executed by the processor, any one of the data security management methods for the intelligent service library is implemented.

[0024] The beneficial effects of the present invention are as follows: By comprehensively considering factors such as the attack situation assessment coefficient, physical risk score, and key usage frequency, the present invention calculates a data risk assessment factor, thereby quantifying the security risk of file data. Dynamically adjusting the key replacement frequency according to the data risk assessment factor can avoid resource waste caused by excessive key replacement while ensuring data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 is a flowchart of the method from step S1 to step S3 in a data security management method for an intelligent service library according to an embodiment of the present invention.

[0026] Figure 2 is a schematic diagram of the constructed frequency of authentication failure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments.

[0028] Referring to Figure 1 , a data security management method for an intelligent service library includes steps S1 to S3, specifically as follows: S1: Collect user data and file data of each user in the service library.

[0029] In one embodiment, the file data in the service library is collected from the file management system, specifically including: recording the number of times each file is accessed and stored, the duration of each storage of each file in the service library, and the digital information content of the file itself (i.e., the electronic file).

[0030] At the same time, relevant information of each user in the system also needs to be collected, including the user's name and user identification. In the example of the present invention, it is determined that the user identification selects the user's fingerprint, but in other embodiments, other methods can be selected according to actual situations, such as face recognition, iris recognition, etc.

[0031] In addition to collecting user data and archive data, it is also necessary to record the number of times the identity verification (such as fingerprint verification) of each user fails when accessing the archives in the business library, and to monitor the power consumption during the operation of the intelligent business library in real time.

[0032] Among them, the encryption algorithm is selected as the symmetric encryption algorithm (AES), and Huffman coding is used for user data and archive data.

[0033] S2: Calculate the data risk assessment factors of each user's archives.

[0034] The storage time and access times of the archives in the business library will affect the usage frequency of their encryption keys. If an archive has been stored in the business library for a long time, it means that the chance of its frequent use is small, the number of encrypted transmissions will also decrease, and thus the number of times the key is used will also be reduced.

[0035] In one embodiment, count the access times of each user's archives in the business library; calculate the average storage time of each user's archives in the business library each time; use the ratio of the access times of each user's archives in the business library to the average storage time of each user's archives in the business library each time as the key usage frequency of each user's archive data. Taking any one archive data of any one user as an example, the key usage frequency of the archive data of this user satisfies the relational expression as:

[0036] In the formula, is the key usage frequency of the user's archive data, is the access times of the user's archive in the business library, is the average storage time of the user's archive in the business library each time.

[0037] By analyzing the access situation (access time and times) of the archives in the business library as described above, calculate the key usage frequency, so as to evaluate the security of the key. For archives with a long storage time and few access times, their key usage frequency is low, and additional security measures may be required to prevent key leakage.

[0038] In another embodiment, the key usage frequency satisfies the relational expression as:

[0039] In the formula, is the user 's th key usage frequency of the archive, is the user 's th archive's access times within the set time window, is the user The average storage duration of the nth file, , are all weighting factors (set according to actual conditions or historical data).

[0040] It should be noted that when the number of files stored by the user in the business library is large and there is a large correlation between the files (this is because there may be overlap or sharing in the content of the files, etc.), once the data of one of the electronic files is attacked or the key is leaked, then other files are also likely to be leaked. This is because the correlation between the files enables the attacker to infer the content of other files through the information of one file.

[0041] In order to quantify this risk, in one embodiment, the similarity between any two files of the user is calculated, the similarities between all the said any two files of the user are summed, and then divided by the average value of the memory occupied by the encoded data of all the files of the user, to obtain the attack situation evaluation coefficient of the user.

[0042] Then the attack situation evaluation coefficient of the above user satisfies the relational expression as:

[0043]

[0044] In the formula, is the attack situation evaluation coefficient of the user, is the total number of all files stored by the user in the business library, is the nth file and the mth file of the user, is the average value of the memory occupied by the encoded data of all the electronic file data of the user, is the data of the nth file of the user after encoding, is the data of the mth file of the user after encoding, represents the intersection between the data of the nth file and the mth file of the user after encoding, represents the union between the data of the nth file and the mth file of the user after encoding. Among them, is to eliminate the repeated combination calculation and avoid the meaningless situation of self-intersection.

[0045] When the similarities of all the files stored by the user in the business library are relatively high, the similarities between the encodings of the electronic file data are also relatively high. At this time, has a larger value; the higher the similarity among all the user's electronic file data, when the encrypted data of one electronic file data is attacked, the higher the possibility that other electronic data files of the user in the business library will be attacked and leaked, and the attack situation evaluation coefficient has a larger value, and the attack situation evaluation coefficient has a larger value.

[0046] The attack situation evaluation coefficient has a larger value, which means that the encryption key of the user's electronic file data needs to be rotated more frequently to prevent the electronic file data from being attacked and leaked.

[0047] It should be noted that in the business library, the electronic file data may be subject to side-channel attacks (i.e., attackers obtain encrypted information by analyzing physical characteristics such as the power consumption and electromagnetic radiation of the device) during the encrypted transmission process, resulting in data leakage.

[0048] In one embodiment, the real-time power consumption of the business library at each moment within a preset time (such as one year) is obtained. For each moment, the difference between the real-time power consumption of the business library and the standard power consumption is calculated, and the integral is performed to obtain the total deviation between the real-time power consumption and the standard power consumption of the business library within the preset time. The total deviation is used as the physical risk score of the business library. Then the physical risk score of the business library satisfies the relationship:

[0049] In the formula, is the physical risk score of the business library, is the real-time power consumption of the business library at moment , is the standard power consumption of the business library at moment , is the preset time.

[0050] The above physical risk score represents the sum of all instantaneous differences between the real-time power consumption and the standard power consumption of the business library within this time interval. If this sum is large, it indicates that the power consumption of the business library fluctuates greatly, which may mean there are relatively large security risks or efficiency problems; conversely, if the sum is small, it indicates that the power consumption of the business library is relatively stable, and the security and efficiency may be higher.

[0051] In another embodiment, in addition to considering the security of electronic file data transmission and the physical security of the business library, user authentication security is also a crucial link.

[0052] When a user needs to obtain files from the business library, the system verifies the user's personal information. To estimate the probability of such verification failure, the system uses a Poisson distribution model. By counting the number of times each user fails the identity verification before successful verification within a preset time period (such as one year), as Figure 2 shown, construct a frequency diagram of authentication failures (the abscissa represents the frequency of user authentication failures, and the ordinate represents the number of users with authentication failures), and calculate the parameters of the Poisson distribution based on this (usually using methods such as sample mean), and then estimate the probability of the occurrence of the authentication failure frequency for each user.

[0053] After obtaining , the probability density function of the Poisson distribution can be used to estimate the probability of different authentication failure frequencies. The probability density function of the Poisson distribution is:

[0054] where is the parameter of the Poisson distribution, representing the average occurrence rate (i.e., the average number of failures), is the frequency of authentication failure, is the probability of the occurrence of this frequency.

[0055] Through the probability density function of the Poisson distribution, the number of users corresponding to different authentication failure frequencies can be estimated. Compare these estimated values to find the authentication failure frequency corresponding to the highest estimated number of users with authentication failures. This frequency is recorded as the "verification failure factor". Simply put, the verification failure factor is the most likely authentication failure frequency, which reflects a typical situation of authentication failure in the system.

[0056] Furthermore, the product of the verification failure factor and the total deviation is normalized to obtain the physical risk score, that is, the relational expression is satisfied as:

[0057] In the formula, is the physical risk score of the business library, is a constant, is the verification failure factor, is the real-time power consumption of the business library at time , is the standard power consumption of the business library at time , is the preset time.

[0058] When the number of authentication failures of a user in the file is relatively large, the value of the authentication failure factor is large, indicating a low physical security level of the business database. When the business database is subject to a side-channel attack, the gap between the real-time power consumption and the standard power consumption is large, resulting in a small value of the physical risk score, which also indicates a low physical security level. On the contrary, if the number of authentication failures is small and the power consumption of the business database is stable, the value of the physical risk score is large, indicating a high physical security level.

[0059] When the file is stored in the business database for a longer time, the frequency of key usage will decrease. At the same time, the attack situation assessment coefficient and the physical risk score may increase. Therefore, considering the three influencing factors of the attack situation assessment coefficient, the physical risk score, and the key usage frequency, calculate the data risk assessment factor of the user file, that is, the relational expression is satisfied as:

[0060] In the formula, is the data risk assessment factor, is the attack situation assessment coefficient of the user, is the physical risk score of the business database, is the key usage frequency of the user file data, represents normalization processing.

[0061] When each file is stored in the business database for a longer time, it usually means that the number of encrypted transmissions of the electronic file data is relatively small; the larger the attack situation assessment coefficient, the more serious the attack threat faced by the file; the larger the physical risk score, the lower the physical security level of the business database.

[0062] According to the above The data risk assessment factors of all files of all users collected can be obtained in the same way for the calculation operation.

[0063] S3: Formulate a file key replacement rule for the user based on the data risk assessment factor.

[0064] In one embodiment, when it is found that the file data risk of a certain user is relatively high, in order to improve the security of the electronic file data, the rotation frequency of the key during the encryption of the electronic file data of the user should be increased. By regularly changing the key, the risk of the key being leaked due to long-term use can be reduced, thereby ensuring the security of the file data to a certain extent.

[0065] Specifically, formulate a file key replacement rule for the user based on the data risk assessment factor, and the rule is as follows: When is greater than the first threshold (in the embodiment of the present invention, the first threshold value is 0.8), the key of the file corresponding to the user is rotated every eight hours; when When it is less than or equal to the first threshold and greater than the second threshold (in the embodiments of the present invention, the value of the second threshold is 0.9), the key of the user's corresponding file is rotated every 24 hours; when When it is less than or equal to the second threshold (in the embodiments of the present invention, the value of the second threshold is 0.9), the key of the user's corresponding file is rotated every 48 hours.

[0066] Then, the key of the user file is updated regularly according to the determined key rotation frequency, the file data is re-encrypted with the new key, and the old key and the file data encrypted with the old key are deleted.

[0067] The system includes a processor and a memory. The memory stores computer program instructions. When the computer program instructions are executed by the processor, a data security management method for an intelligent service library according to the first aspect of the present invention is implemented.

[0068] The system further includes other components well known to those skilled in the art such as a communication bus and a communication interface. Their settings and functions are known in the art, so they will not be described herein again.

[0069] It should be noted that for those of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present invention, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.

Claims

1. A data security management method for an intelligent service library, characterized in that, Including: Collecting user data and profile data of each user in the business database; Calculating the data risk assessment factors of each user's profile; Formulating a rule for replacing the profile key of the user based on the data risk assessment factor; Wherein, the data risk assessment factor is: Calculating the attack situation assessment coefficient of the user, the physical risk score of the business database, and the key usage frequency of the user's profile data, and normalizing the ratio of the sum of the attack situation assessment coefficient of the user and the physical risk score of the business database to the key usage frequency of the user's profile data to obtain the data risk assessment factor; the attack situation assessment coefficient is used to characterize the impact of the correlation between the user's profile data on security; the physical risk score is positively correlated with the real-time power consumption of the business database.

2. The data security management method for an intelligent service library according to claim 1, characterized in that The profile data includes the number of profile accesses, the storage duration, and electronic profiles; Huffman coding is used to encode each electronic profile, and the memory size occupied by each encoded electronic profile is recorded.

3. The data security management method for an intelligent service library according to claim 2, characterized in that The process of obtaining the key usage frequency includes: Counting the number of accesses of each user's each profile in the business database; calculating the average time of each user's each profile stored in the business database each time; Taking the ratio of the number of accesses of each user's each profile in the business database to the average time of each user's each profile stored in the business database each time as the key usage frequency of each user's each profile data.

4. A data security management method for an intelligent service library according to claim 3, characterized in that, The process of obtaining the attack situation assessment coefficient includes: Calculating the similarity between any two profiles of the user, summing up the similarities between all the any two profiles of the user, and dividing by the average value of the memory occupied by all the encoded profiles of the user to obtain the attack situation assessment coefficient of the user.

5. A data security management method for an intelligent service library according to claim 4, characterized in that The process of obtaining the physical risk score includes: Obtaining the real-time power consumption of each moment of the business database within a preset time, for each moment, calculating the difference between the real-time power consumption of the business database and the standard power consumption, and integrating to obtain the total deviation between the real-time power consumption of the business database and the standard power consumption within the preset time, and taking the total deviation as the physical risk score.

6. The data security management method for an intelligent service library according to claim 5, characterized in that, The process of obtaining the physical risk score further includes: Counting the number of times of authentication failure of each user before successful authentication within the preset time, finding the number of failure times that makes the number of users with authentication failure the highest according to the Poisson distribution model, and recording the number of failure times as the verification failure factor; Normalizing the product of the verification failure factor and the total deviation to obtain the physical risk score.

7. A data security management method for an intelligent service library according to claim 6, characterized in that The formulating a rule for replacing the profile key of the user based on the data risk assessment factor includes: When the data risk assessment factor is greater than the first threshold, increasing the key rotation frequency of the user's profile; Regularly updating the key of the user's profile according to the determined key rotation frequency, re-encrypting the profile data with the new key, and deleting the old key and the profile data encrypted with the old key.

8. The data security management method for an intelligent service library according to claim 3, wherein The similarity between any two profiles of the user satisfies the relational expression: ; where, is the similarity between the th file and the th file of the user, is the data after encoding the th file of the user, is the data after encoding the th file of the user, represents the intersection between the data after encoding the th file and the data after encoding the th file of the user, represents the union between the data after encoding the th file and the data after encoding the th file of the user.

9. The data security management method for an intelligent service library according to claim 2, characterized in that The key usage frequency satisfies the relational expression: ; wherein, is the frequency of key usage for the th file of the user, is the number of accesses for the th file of the user within the set time window, is the average storage duration for the th file of the user, , are both weighting factors.

10. A data security management system for an intelligent service library, characterized in that, Including: A processor and a memory, the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the data security management method for an intelligent business database according to any one of claims 1-9 is implemented.

Citation Information

Patent Citations

  • Intelligent archive storage method and system based on block chain

    CN118394991A

  • Key management method and system based on Vault

    CN118523908A

  • Security risk assessment system and method based on Internet of Things

    CN119232483A

  • Electronic file intelligent classification method and system, electronic equipment and storage medium

    CN119312173A