Data trusted security space construction method based on production and fusion combination

Through the pre-processing and label construction of industrial and financial data, combined with multi-factor identity authentication and real-time monitoring, the problems of data leakage and illegal user impersonation in the integration of industry and finance have been solved, the accuracy, traceability and security of data are achieved, and the intelligence level of data protection has been improved.

CN120337307APending Publication Date: 2025-07-18QINGDAO MENGDOU NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510422380.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the integration of industry and finance, sensitive data in the industry and financial fields have risks of leakage during the interaction process, resulting in economic losses and reputation damage. It is difficult for existing technology to effectively prevent illegal users from impersonating and data leakage.

Method used

By preprocessing and labeling the industrial and financial side data, a multi-factor identity authentication mechanism is adopted, combining biometrics and typed rhythm behavior characteristics, a multi-level identity protection barrier is established, and real-time hash calculation and clustered exception access monitoring are ensured to the accuracy, traceability and security of the data.

Benefits of technology

Effectively prevent illegal users from impersonating and data leakage, ensure data security, enhance all parties' trust in data security, promptly detect data tampering, dynamically identify abnormal access, and protect industrial and financial data assets.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to a data trusted security space construction method based on production and fusion combination. Comprising the following steps: collecting data information of an industrial end and a financial end, preprocessing the collected data information, and constructing a corresponding label; establishing a multi-factor identity authentication mechanism, and respectively endowing corresponding permission levels according to user roles; storing the data information, and monitoring the integrity and security of the data information; according to the method, data information of an industrial end and a financial end is subjected to preprocessing and label construction, the accuracy and traceability of data are ensured, meanwhile, a multi-factor identity authentication mechanism is adopted, the masquerading and data leakage risks of illegal users can be effectively prevented, the data security is ensured, and in addition, the data security is improved. And data integrity monitoring and security monitoring improve the credibility of each party on data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and specifically provides a method for constructing a data trusted security space based on the integration of industry and finance. Background Art

[0002] The integration of industry and finance is an important economic development model, in which industrial capital and financial capital penetrate and merge with each other, aiming to enhance enterprise competitiveness, optimize resource allocation, and expand business territory through synergy. In this process, a large amount of data is frequently exchanged between the industrial side and the financial side, and the types and scales of data have grown explosively, covering industrial production operation data, financial data, as well as financial-side capital flow data, credit rating data, transaction data, etc.

[0003] Both the industrial and financial fields contain a large amount of sensitive information. Once this sensitive data is leaked, it will cause huge economic losses and reputation damage to the enterprise itself.

[0004] Based on this, the present invention provides a method for constructing a data trusted security space based on the integration of industry and finance to solve the above-mentioned technical problems. Summary of the Invention

[0005] The purpose of the present invention is to provide a method for constructing a data trusted security space based on the integration of industry and finance. By preprocessing and constructing labels for the data information of the industrial side and the financial side, the present invention ensures the accuracy and traceability of the data. At the same time, by adopting a multi-factor identity authentication mechanism, it can effectively prevent the impersonation of illegal users and the risk of data leakage, ensuring data security. In addition, data integrity monitoring and security monitoring enhance the trust of all parties in data security.

[0006] To achieve the above purpose, the present invention provides the following technical solutions:

[0007] The present invention provides a method for constructing a data trusted security space based on the integration of industry and finance, including the following steps:

[0008] Collect the data information of the industrial side and the financial side, preprocess the collected data information, and construct corresponding labels;

[0009] Establish a multi-factor identity authentication mechanism and assign corresponding permission levels according to user roles;

[0010] Store the data information and monitor the integrity and security of the data information.

[0011] The present invention is further configured as follows: The process of the preprocessing is as follows:

[0012] Select identification fields from the data information and calculate the hash value of the identification fields;

[0013] Store the calculated hash value in the database table. When collecting new data subsequently, calculate its hash value and compare it with the stored hash value.

[0014] If the hash value already exists, discard the newly collected data.

[0015] The present invention is further configured such that: the tag includes the source of the data, the collection time, and the data owner.

[0016] The present invention is further configured such that: the process of establishing the multi-factor authentication mechanism is as follows:

[0017] Obtain the biometric information of the user and construct a first authentication mechanism based on the biometric information.

[0018] Adopt the timestamp of each key pressed during the user input process, count the key press time interval data within the set time, calculate its mean μ and standard deviation σ, and use the mean μ and standard deviation σ as the eigenvalue of the typing rhythm to construct a second authentication mechanism based on the eigenvalue.

[0019] The present invention is further configured such that: the process of monitoring the integrity is as follows:

[0020] Perform a hash calculation on the data information using a hash function to generate the hash value of the corresponding data.

[0021] Before data operation, temporarily generate buffer data. After data operation, calculate the hash value of the buffer data and compare it with the original hash value. If they are the same, the data is complete. If they are different, mark and give a warning to the user according to the information of the operating user.

[0022] The present invention is further configured such that: the process of monitoring the security is as follows:

[0023] Obtain the IP address, access time, and access data characteristics of the historical access users.

[0024] Construct a feature vector of the IP address, access time, and access data characteristics.

[0025] Perform clustering on the feature vector to obtain the historical clustering centers.

[0026] Obtain the feature vector of the new historical access user, calculate the distance between the new access feature vector and each clustering center, and compare this distance with the preset determination threshold to determine whether the access is abnormal.

[0027] The present invention is further configured such that: the process of performing clustering on the feature vector is as follows:

[0028] Randomly initialize K clustering centers.

[0029] For each user access feature vector, calculate its distances from K cluster centers, and assign the user access feature vector to the cluster where the nearest cluster center is located;

[0030] Recalculate the cluster center of each cluster;

[0031] Repeat the above steps until the sum of the distances between the cluster centers before and after is less than the preset clustering threshold.

[0032] A further setting of the present invention is: if the distance is less than the preset determination threshold, there is no abnormality; otherwise, terminate the access and issue a warning.

[0033] Compared with the prior art, the beneficial effects of the present invention are:

[0034] By preprocessing and label construction of the data information of the industrial end and the financial end, the present invention ensures the accuracy and traceability of the data. At the same time, a multi-factor identity authentication mechanism is adopted, that is, combining biometric features with typing rhythm behavior features to construct a multi-level identity protection barrier. In the industrial and financial business, it can effectively prevent the impersonation of illegal users and the risk of data leakage, ensuring data security. In addition, the real-time hash calculation and comparison mechanism for data integrity monitoring can promptly detect any tampering behavior of the data during storage and operation, ensuring data integrity. The clustering-based abnormal access security monitoring can also intelligently and dynamically identify abnormal access behaviors, effectively protecting the industrial and financial data assets from infringement, and enhancing the trust of all parties in data security. Specific embodiments

[0035] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0036] Embodiment:

[0037] This embodiment provides a method for constructing a data-trusted security space based on the integration of industry and finance, including the following steps:

[0038] S1. Collect the data information of the industrial end and the financial end, preprocess the collected data information, and construct corresponding labels.

[0039] Among them, the preprocessing process is as follows:

[0040] Select the identification field from the data information and calculate the hash value of the identification field;

[0041] Store the calculated hash value in the database table. When collecting new data subsequently, calculate its hash value and compare it with the stored hash value.

[0042] If the hash value already exists, discard the newly collected data.

[0043] The tags include the source of the data, the collection time, and the data owner.

[0044] In this embodiment, it should be noted that by calculating the hash value of the identification field and storing and comparing it, duplicate data can be quickly and accurately identified, greatly improving the data cleaning efficiency. Especially when dealing with large-scale data, it can significantly reduce the data storage space and processing time, ensure the uniqueness and accuracy of the data, and provide a high-quality data foundation for subsequent processing. In addition, adding tags such as the source, collection time, and data owner to the data not only facilitates data traceability but also helps to clarify the data responsible entity in the scenario of the integration of industry and finance.

[0045] S2. Establish a multi-factor identity authentication mechanism and assign corresponding permission levels according to user roles.

[0046] Among them, the process of establishing a multi-factor identity authentication mechanism is as follows:

[0047] Obtain the user's biometric information and construct a first identity authentication mechanism based on the biometric information.

[0048] Adopt the timestamp of each key pressed during the user input process, count the key press time interval data within the set time, calculate its mean value μ and standard deviation σ, and use the mean value μ and standard deviation σ as the characteristic values of the typing rhythm to construct a second identity authentication mechanism based on the characteristic values.

[0049] In this embodiment, it should be noted that using biometric information for the first identity authentication mechanism provides a basis for highly reliable user identity recognition, taking advantage of the uniqueness and difficulty of forgery of biometric features. The second identity authentication mechanism based on typing rhythm verifies the identity from the user behavior level and can effectively supplement the deficiencies of biometric authentication. Using a dual verification method greatly improves the security of identity authentication and prevents illegal users from invading the system to obtain industry-finance data.

[0050] S3. Store the data information and monitor the integrity and security of the data information.

[0051] Among them, the monitoring process of integrity is as follows:

[0052] Use a hash function to perform a hash calculation on the data information to generate the hash value of the corresponding data.

[0053] Before data operation, buffer data is generated temporarily. After data operation, the hash value of the buffer data is calculated and compared with the original hash value. If they are the same, the data is complete. If not, the user is marked and warned according to the information of the operating user.

[0054] In addition, the security monitoring process is as follows:

[0055] Obtain the IP address, access time, and access data characteristics of historical access users;

[0056] Construct a feature vector of the IP address, access time, and access data characteristics;

[0057] Cluster the feature vectors to obtain historical cluster centers;

[0058] Obtain the feature vector of a new historical access user, calculate the distance between the new access feature vector and each cluster center, and compare this distance with a preset determination threshold to determine whether the access is abnormal.

[0059] Furthermore, if the distance is less than the preset determination threshold, there is no abnormality. Otherwise, the access is terminated and a warning is issued.

[0060] The process of clustering the feature vectors is as follows:

[0061] Randomly initialize K cluster centers;

[0062] For each user access feature vector, calculate its distance from the K cluster centers, and assign the user access feature vector to the cluster where the nearest cluster center is located;

[0063] Recalculate the cluster center of each cluster;

[0064] Repeat the above steps until the sum of the distances between the previous and current cluster centers is less than the preset clustering threshold.

[0065] In this embodiment, it should be noted that calculating and comparing the hashes before and after data operation can detect in real time whether the data has been tampered with during the operation, can discover problems and take measures more promptly. Once it is found that the data integrity is damaged, the transaction can be terminated immediately and the reason can be traced, effectively avoiding financial risks and losses caused by data errors. In addition, by clustering the historical access feature vectors and using the cluster centers to determine whether new access is abnormal, it can adaptively learn the normal access pattern and discover abnormal access that deviates from the normal pattern, and can effectively cope with new types of network attacks and data theft means, improving the intelligent level and accuracy of data security monitoring.

[0066] By preprocessing and constructing tags for the data information of the industrial end and the financial end, the present invention ensures the accuracy and traceability of the data. At the same time, a multi-factor identity authentication mechanism is adopted, that is, by combining biometric features with typing rhythm behavior features, a multi-level identity protection barrier is constructed. In the industrial-financial business, it can effectively prevent the impersonation of illegal users and the risk of data leakage, ensuring data security. In addition, the real-time hash calculation and comparison mechanism for data integrity monitoring can promptly detect any tampering behavior of the data during storage and operation, ensuring the integrity of the data. The security monitoring of abnormal access based on clustering can also intelligently and dynamically identify abnormal access behaviors, effectively protecting the industrial-financial data assets from infringement and enhancing the trust of all parties in data security.

[0067] In the description of this specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0068] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not elaborate on all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the relevant technical fields can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A method for constructing a data trusted security space based on the integration of industry and finance, characterized in that, It includes the following steps: Collect data information from the industrial side and the financial side, preprocess the collected data information, and construct corresponding tags; Establish a multi-factor identity authentication mechanism and assign corresponding permission levels according to user roles; Store data information and monitor the integrity and security of data information.

2. The method for constructing a data trusted security space based on the integration of industry and finance according to claim 1, wherein The process of the preprocessing is as follows: Select identification fields from the data information and calculate the hash value of the identification fields; Store the calculated hash value in the database table. When collecting new data subsequently, calculate its hash value and compare it with the stored hash value; If the hash value already exists, discard the newly collected data.

3. A method for constructing a data trusted security space based on the integration of industry and finance according to claim 1, characterized in that, The tags include the source of the data, the collection time, and the data owner.

4. A method for constructing a data trusted security space based on the integration of industry and finance according to claim 1, characterized in that, The process of establishing the multi-factor identity authentication mechanism is as follows: Obtain the biometric information of the user and construct a first identity authentication mechanism based on the biometric information; Adopt the timestamp of each key pressed during the user input process, count the key press time interval data within the set time, calculate its mean μ and standard deviation σ, and use the mean μ and standard deviation σ as the characteristic values of the typing rhythm to construct a second identity authentication mechanism based on the characteristic values.

5. A method for constructing a data trusted security space based on the integration of industry and finance according to claim 1, characterized in that, The process of monitoring the integrity is as follows: Use a hash function to perform a hash calculation on the data information to generate the hash value of the corresponding data; Before data operation, temporarily generate buffer data. After data operation, calculate the hash value of the buffer data and compare it with the original hash value. If they are the same, the data is complete. If they are different, mark and give a warning to the user according to the information of the operating user.

6. A method for constructing a data trusted security space based on the integration of industry and finance according to claim 1, characterized in that, The process of monitoring the security is as follows: Obtain the IP address, access time, and access data characteristics of historical access users; Construct a feature vector of the IP address, access time, and access data characteristics; Cluster the feature vector to obtain historical cluster centers; Obtain the feature vector of a new historical access user, calculate the distance between the new access feature vector and each cluster center, and compare this distance with a preset determination threshold to determine whether the access is abnormal.

7. A method for constructing a data-trustworthy and secure space based on the integration of industry and finance according to claim 6, characterized in that, The process of clustering the feature vector is as follows: Randomly initialize K cluster centers; For each user access feature vector, calculate its distance from the K cluster centers, and assign the user access feature vector to the cluster where the nearest cluster center is located; Recalculate the cluster center of each cluster; Repeat the above steps until the sum of the distances between the previous and current cluster centers is less than a preset clustering threshold.

8. A method for constructing a data trusted security space based on the integration of industry and finance according to claim 6, characterized in that, If the distance is less than the preset determination threshold, there is no abnormality. Otherwise, terminate the access and issue a warning.