Digital certificate security auditing system and method based on multi-modal analysis cross-cloud architecture
Through the digital certificate security audit system based on multimodal analysis of cross-cloud architecture, the problems of difficult adaptation of heterogeneous environments, low audit efficiency and separation of security strategies of cross-cloud certificate management systems are solved, and efficient integrated audit and risk prediction of cross-cloud environments are achieved, and audit efficiency and risk identification coverage are improved.
Patent Information
- Application Number
- CN202510812568.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-18
AI Technical Summary
The existing cross-cloud certificate management system has problems such as difficulty in adapting heterogeneous environments, low audit efficiency, and fragmentation of security strategies, and it is impossible to achieve integrated audits between dynamic risk identification and cross-cloud environments.
The digital certificate security audit system based on multimodal analysis cross-cloud architecture is adopted, including a cross-cloud certificate acquisition module, a multimodal risk analysis module and a dynamic risk assessment module. The cross-cloud certificate acquisition module realizes distributed storage and cache of digital certificate metadata from different cloud platforms. The multimodal risk analysis module performs certificate chain analysis, permission strategy checking and file type detection, and the dynamic risk assessment module uses the LSTM prediction model to perform risk prediction and repair suggestions.
It realizes adaptation and batch unified audit with different cloud platforms, improves the audit efficiency of cross-cloud certificates, identifies multiple common risks, reduces false positive rates, and can predict future status risk and automatically generate repair suggestions.
Smart Images

Figure CN120342640A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital certificate auditing, and more specifically, to a digital certificate security auditing system and method based on a multi-modal analysis cross-cloud architecture. Background Art
[0002] The current cross-cloud certificate management system has the following technical bottlenecks: 1. It is difficult to adapt to heterogeneous environments. The certificate storage formats of different cloud platforms vary greatly, making it difficult to adapt and requiring customized parsing logic. 2. The auditing efficiency is low. Traditional tools rely on single-point scanning and it is difficult to achieve efficient parallel auditing of cross-cloud clusters. 3. The security policies are fragmented. The certificate permission policies of each cloud platform are independent of each other, lacking global consistency analysis and prone to compliance risks.
[0003] Although the existing JCE architecture supports certificate parsing, it cannot meet the requirements of cross-cloud dynamic expansion and has insufficient compatibility with cloud-native services.
[0004] Therefore, how to achieve dynamic risk identification and integrated auditing of cross-cloud environments is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, the present invention provides a digital certificate security auditing system and method based on a multi-modal analysis cross-cloud architecture, which can achieve dynamic risk identification and integrated auditing of cross-cloud environments, not only with high auditing efficiency, but also capable of realizing risk prediction and repair response.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides a digital certificate security auditing system based on a multi-modal analysis cross-cloud architecture, including: a cross-cloud certificate collection module, a multi-modal risk analysis module, and a dynamic risk assessment module;
[0008] The cross-cloud certificate collection module is used to adapt to different cloud platforms and collect the metadata of digital certificates from different cloud platforms for distributed storage and caching across the cloud;
[0009] The multi-modal risk analysis module is used to retrieve the metadata of the target digital certificate from the cache, perform certificate chain parsing, permission policy verification, and dynamic file type detection on it, and generate a multi-modal analysis result and a comprehensive risk score;
[0010] The dynamic risk assessment module performs risk prediction on the digital certificate based on a pre-trained LSTM prediction model combined with the multi-modal analysis result, and generates a risk heat map and repair suggestions.
[0011] Furthermore, the cross-cloud certificate collection module includes: a cloud platform adaptation layer, a data collection layer, a data standardization engine, and a distributed storage manager;
[0012] The cloud platform adaptation layer is used to uniformly encapsulate the API interfaces of different cloud platforms, shield the underlying differences, and provide a standardized certificate metadata access interface;
[0013] The data collection layer is used to capture various digital certificates of multiple cloud platforms by using a concurrent certificate sniffing method, and automatically deploy lightweight probes to the edge nodes of each cloud platform according to the edge node identifiers of each cloud platform by using containerization technology, and monitor the change events of digital certificates in real time through the lightweight probes;
[0014] The data standardization engine is used to convert the heterogeneous data collected from each cloud platform into a unified JSON structure;
[0015] The distributed storage manager is used to encrypt the digital certificate metadata by using a symmetric encryption algorithm, store the encrypted data in a distributed manner in a persistent database, and write it into the cache at the same time, and eliminate the low-frequency data in the cache according to a preset cache eviction policy.
[0016] Furthermore, the change events monitored by the lightweight probes include life cycle events, content change events, and security events; among them, the life cycle events include certificate addition, revocation, and expiration; the content change events include private key replacement, certificate chain update, and permission policy modification; the security event is that the key file is maliciously tampered with.
[0017] Furthermore, the data collection layer is also used to dynamically scale the deployment of lightweight probes according to the changes in the cloud platform edge nodes. When a new cloud platform edge node registration event is monitored, lightweight probes are automatically deployed under the new cloud platform edge node. When it is monitored that a certain cloud platform edge node goes offline, the probes deployed on that edge node are deleted.
[0018] Furthermore, the unified JSON structure includes the following core fields:
[0019] "cert_id", "issuer", "expiration", "key_algorithm", "permissions", "storage_path", "hash_alg", "risk_tags", which respectively represent "unique identifier", "issuing agency", "expiration time", "algorithm type", "policy-related permissions", "key storage path", "certificate digest algorithm", "risk tag".
[0020] Further, the cross-cloud certificate collection module further includes a key vault for centrally managing the API lists used by each cloud platform to obtain digital certificates and the obtained digital certificate key information.
[0021] Further, the multi-modal risk analysis module includes a certificate / key detector, a policy compliance detector, a file type detector, and a multi-modal data fusion engine;
[0022] The certificate / key detector is used to parse the extension fields of the X.509 certificate to verify the integrity of the certificate chain; extract the private key in PKCS#12 format, attempt to parse the PFX or JKS certificate library file through cryptographic library collision, and detect the password strength; calculate the entropy value of the byte sequence of the private key data using the Shannon entropy formula. If the entropy value is less than the custom threshold, the current private key data is stored in plaintext or weakly encrypted, and a risk label is generated;
[0023] The policy compliance detector is used to verify whether the access permissions of the digital certificate are consistent with the pre-defined IAM policy. If not, there is unauthorized access, and a risk label is generated;
[0024] The file type detector is used to parse the file header in real time to determine whether the file extension has been maliciously tampered with, and to detect in real time whether non-certificate files are mixed into the certificate directory, and generate a risk label;
[0025] The multi-modal data fusion engine is used to fuse the multi-modal risk detection results, perform a standardized score based on each risk detection result, and then perform weighted summation to obtain a comprehensive risk score.
[0026] Further, the dynamic risk assessment module includes an LSTM prediction model, a heat map generator, and an automated response engine;
[0027] The LSTM prediction model is trained based on historical certificate time series data, predicts the risk probability of the digital certificate based on the current multi-modal analysis results, determines the risk level, and adjusts the risk level threshold in combination with the business priority;
[0028] The heat map generator is used to display in layers according to the cloud platform, business unit, and risk level, and supports drilling down to view the certificate details;
[0029] The automated response engine is used to adopt different response strategies according to the risk level.
[0030] Further, the dynamic risk assessment module further includes: a work order unit, an alarm unit, and a log unit; for digital certificates with a high risk level, the automated response engine triggers the work order unit to generate a work order and revoke the digital certificate; for digital certificates with a medium risk level, the automated response engine triggers the alarm unit to push an alarm that the digital certificate needs to be updated; for digital certificates with a low risk level, the automated response engine triggers the log unit to record a log and include the digital certificate in the periodic inspection plan.
[0031] In a second aspect, the present invention provides a digital certificate security audit method based on a multi-modal analysis cross-cloud architecture, which is applied to the system as described above, including:
[0032] Collect digital certificate metadata from different cloud platforms across the cloud for distributed storage and caching;
[0033] Retrieve the metadata of the target digital certificate from the cache, perform certificate chain parsing, permission policy verification, and file type dynamic detection on it, and generate multi-modal analysis results and a comprehensive risk score;
[0034] Based on the pre-trained LSTM prediction model and combined with the multi-modal analysis results, perform risk prediction on the digital certificate, and generate a risk heat map and repair suggestions.
[0035] It can be seen from the above technical solutions that compared with the prior art, the present invention has the following beneficial effects:
[0036] 1. The present invention can achieve adaptation to different cloud platforms and digital certificate collection, and then batch and uniformly audit digital certificates in different cloud environments and different storage formats, improving the audit efficiency of cross-cloud certificates.
[0037] 2. The present invention combines static parsing (certificate chain parsing, permission policy verification) and dynamic parsing (file type detection) to monitor digital certificates, can identify various common risks such as weak algorithms, permission leakage, and unencrypted keys, expands the risk identification coverage rate, and comprehensively guarantees certificate security. At the same time, through dynamic threshold adjustment and intelligent analysis, the false alarm rate is significantly reduced.
[0038] 3. The present invention is not limited to risk assessment of the current state of the certificate, but can also perform risk prediction on the future state, automatically generate repair suggestions in combination with the prediction results, and improve the automation repair efficiency. Description of the Drawings
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained according to the provided drawings.
[0040] Figure 1 It is a schematic structural diagram of the digital certificate security audit system based on the multi-modal analysis cross-cloud architecture provided by the present invention;
[0041] Figure 2 It is a schematic structural diagram of the cross-cloud certificate collection module provided by the present invention;
[0042] Figure 3 It is a schematic structural diagram of the multi-modal risk analysis module provided by the present invention;
[0043] Figure 4 It is a schematic structural diagram of the dynamic risk assessment module provided by the present invention. Specific embodiments
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0045] As Figure 1 shown, the embodiments of the present invention disclose a digital certificate security audit system based on the multi-modal analysis cross-cloud architecture, including: a cross-cloud certificate collection module, a multi-modal risk analysis module, and a dynamic risk assessment module;
[0046] The cross-cloud certificate collection module is used to adapt to different cloud platforms and collect the metadata of digital certificates from different cloud platforms across the cloud for distributed storage and caching;
[0047] The multi-modal risk analysis module is used to retrieve the metadata of the target digital certificate from the cache, perform certificate chain parsing, permission policy verification, and file type dynamic detection on it, and generate multi-modal analysis results and comprehensive risk scores;
[0048] The dynamic risk assessment module performs risk prediction on the digital certificate based on the pre-trained LSTM prediction model combined with the multi-modal analysis results, and generates a risk heat map and repair suggestions.
[0049] The following further describes the specific structural composition and functions of the above-mentioned each module.
[0050] As shown Figure 2 in the figure, the cross-cloud certificate collection module includes: a cloud platform adaptation layer, a data collection layer, a data standardization engine, a distributed storage manager, and a key vault;
[0051] The cloud platform adaptation layer is used to uniformly encapsulate the API interfaces of different cloud platforms, shield the underlying differences, and provide standardized access interfaces for certificate metadata (such as certificate chains, private key paths, permission policies).
[0052] The data collection layer is used to capture various digital certificates of multiple cloud platforms by using a concurrent certificate sniffing method, and automatically deploy lightweight probes to the edge nodes of each cloud platform according to the edge node identifiers of each cloud platform by using containerization technology, and real-time monitor the change events of digital certificates through the lightweight probes.
[0053] Among them, the concurrent certificate sniffing technology is: using multi-threaded parallel scanning of multiple cloud nodes to avoid the efficiency bottleneck of traditional single-threaded scanning. Specifically, first slice the target cloud platform cluster by nodes or regions and allocate them to different sniffer instances, and then adjust the concurrency according to the node resource usage (such as ≤100 API calls per second), which can achieve audit at the thousand-node level, shortening the time from the hour level to the minute level and adapting to the dynamic expansion of the cloud environment.
[0054] The lightweight probe uses containerization technology (such as Docker) and supports automatic deployment on edge nodes. When deploying, the lightweight probe is packaged as a Docker image, which includes certificate listening logic, cloud platform SDKs, and dependent libraries. Automatically obtain the edge node identifier by using the cloud platform without manual configuration. After obtaining the node identifier, the probe is automatically deployed on the edge node through the identifier.
[0055] The lightweight probe polls the cloud platform API interfaces regularly (polling interval ≤5 seconds) to capture changes by comparing the differences before and after, and supports TLS mutual authentication to ensure the security of API calls and avoid man-in-the-middle attacks. Listen to the certificate storage path (such as / etc / ssl / certs) by using the file system inotify (Linux), and listen for file creation, modification, and deletion.
[0056] The change events monitored by the lightweight probe include lifecycle events, content change events, and security events; among them, lifecycle events include certificate addition (such as uploading to cloud storage), revocation (actively revoked by the CA), and expiration (reaching the validity period); content change events include private key replacement, certificate chain update (such as intermediate CA replacement), and permission policy modification (such as IAM policy binding adjustment); the security event is that the key file is maliciously tampered with. When a high-risk event (such as private key modification) is monitored, real-time analysis is preferentially triggered.
[0057] More preferably, the data acquisition layer is further configured to dynamically scale the deployment of lightweight probes according to the changes of the edge nodes of the cloud platform. When a new edge node registration event of the cloud platform is monitored, lightweight probes are automatically deployed under the new edge node of the cloud platform. When it is monitored that a certain edge node of the cloud platform goes offline, the probes deployed on the edge node are deleted.
[0058] The data standardization engine is used to convert the heterogeneous data collected from each cloud platform into a unified JSON structure; the unified JSON structure includes the following core fields:
[0059] "cert_id", "issuer", "expiration", "key_algorithm", "permissions", "storage_path", "hash_alg", "risk_tags", which respectively represent "unique identifier", "issuing agency", "expiration time", "algorithm type", "policy associated permissions", "private key storage path", "certificate digest algorithm", "risk tags" (such as weak algorithm, overly broad permissions).
[0060] The distributed storage manager is used to encrypt the digital certificate metadata using a symmetric encryption algorithm (such as AES / SM4, etc.), store the encrypted data in a distributed manner in a persistent database, write it into the cache at the same time, and eliminate the low-frequency data in the cache according to the preset cache eviction policy. At the same time, the API lists used by each cloud platform to obtain digital certificates and the obtained digital certificate key information are centrally stored in a key vault for management.
[0061] Specifically, the distributed storage manager can also dynamically manage keys in combination with a key management service to ensure data static and transmission security. Through the key management service, operations such as adding, deleting, importing, and destroying user private keys can be performed to dynamically manage user private keys. The keys generated by the key management service are used to encrypt the collected metadata, avoid plaintext transmission during the transmission process, ensure the security of data transmission, and store the encrypted metadata in the database to ensure data storage security.
[0062] In addition, by building a distributed cache (such as based on the Redis Cluster framework), millisecond-level response is supported, and low-frequency data is eliminated through the preset cache eviction policy to improve query efficiency. The cache eviction policy can adopt the LFU algorithm, and its core logic is to preferentially eliminate the data with the lowest access frequency. Low-frequency data refers to the data with few access times or low access frequency in the cache. For example:
[0063] 1. Certificate metadata that has not been queried for a long time (such as historical audit records, expired certificate information).
[0064] 2. Certificates with low relevance to the current business (such as certificates for non-core systems).
[0065] 3. Certificate policies rarely referenced in static configurations.
[0066] The long-term occupation of cache space by such data will lead to a decrease in the cache hit rate of high-frequency data (such as recently active certificates and certificate information for core systems), affecting query efficiency. By eliminating low-frequency data, cache resource allocation can be optimized to ensure fast access to high-frequency data (millisecond-level response).
[0067] The specific operation process of the cross-cloud certificate collection module includes:
[0068] 1. User initiates a request: The user sends a certificate collection instruction to the cloud platform adaptation layer.
[0069] 2. Call the cloud interface: The cloud platform adaptation layer calls the interface of the Azure Key Vault (such as the Get Certificate List API) to pull the original certificate data from the cloud platform.
[0070] 3. Listen for change events: The cloud platform adaptation layer subscribes to certificate change events (such as certificate expiration, update, etc.) from the lightweight probe; the probe listens for Azure event pushes in real time through the publish / subscribe mode (similar to a message queue).
[0071] 4. Actively push changes: The probe sends the monitored certificate change data (such as newly issued certificates) back to the cloud platform adaptation layer in real time.
[0072] 5. Standardize data format: The cloud platform adaptation layer sends the original certificate metadata to the data standardization engine, and the engine converts the data according to the predefined JSON format specifications (such as unifying the date format, field naming, etc.).
[0073] 6. Encrypted storage and caching: The standardized data is transferred to the distributed storage manager, and the following operations are performed:
[0074] (1) Protect the data using the AES-256 encryption algorithm.
[0075] (2) Store the encrypted data in a persistent database (such as MySQL).
[0076] (3) Write to the Redis cache at the same time to improve subsequent access speed.
[0077] 7. Result feedback: The storage results are passed back layer by layer (storage manager → standardization engine → cloud platform adaptation layer → user), and finally the user is notified that the collection is complete.
[0078] Such as Figure 3As shown in the figure, the multimodal risk analysis module includes a certificate / key detector, a policy compliance detector, a file type detector, and a multimodal data fusion engine.
[0079] The certificate / key detector performs the following validations:
[0080] 1) Parse the extension fields of the X.509 certificate (such as Subject Alternative Name, CRL distribution point), verify the integrity of the certificate chain, and identify potential risks of intermediate CA institutions.
[0081] 2) Extract the private key in PKCS#12 format, try to parse the PFX or JKS certificate library file through password library collision, and detect the password strength.
[0082] Password library collision refers to trying to brute-force crack or intelligently guess the encryption password of the PFX (PKCS#12) or JKS (Java KeyStore) certificate library file through a predefined common password dictionary or rule library (such as the top 100,000 weak passwords, enterprise common password patterns).
[0083] The steps for password library collision detection are as follows:
[0084] Password library preparation: Build in common password combinations (such as 123456, password@2023), industry default passwords (such as changeit), and enterprise historical leaked passwords.
[0085] Tool invocation: Use JCE (JCE is Java's encryption toolkit for certificate parsing, key management, encryption and decryption, etc.) to provide the KeyStore class to try to decrypt the PFX / JKS file with the passwords in the password library.
[0086] Multithreaded acceleration: Try multiple passwords in parallel (such as 1000 times per second), and exclude incorrect passwords through failure responses.
[0087] Password strength determination: If a certain password in the password library decrypts successfully, mark it as a "weak password" and force a replacement.
[0088] 3) Use the Shannon entropy formula to calculate the entropy value of the byte sequence of the private key data. If the entropy value is less than the custom threshold, the current private key data is stored in plaintext or weakly encrypted, and a risk label is generated.
[0089] The policy compliance detector is used to verify whether the access rights of the digital certificate are consistent with the predefined IAM policy. If not, there is unauthorized access, and a risk label is generated. For example, simulate the actual usage scenario of the certificate permissions through a policy simulator to detect whether the IAM policy is consistent with the certificate permissions. If an unauthorized behavior is output, mark it as a compliance risk.
[0090] The file type detector is used to parse the file header in real time, distinguish certificate files (.pem / .crt, etc.), key files (.key / .pri, etc.) from obfuscation attack files (such as malicious pictures disguised as certificates), determine whether the file extension has been maliciously tampered with (such as disguising.exe as.crt), and detect in real time whether non-certificate files (such as pictures, executable files, etc.) are mixed into the certificate directory, generating risk tags.
[0091] The multi-modal data fusion engine is used to fuse the risk detection results of multiple modalities, and perform a standardized scoring based on the risk detection results of each modality, assign corresponding weights to different risk categories (such as a weak algorithm weight of 0.3 and an over-permissive weight of 0.5), and then perform a weighted sum to obtain a comprehensive risk score.
[0092] The specific operation process of the multi-modal risk analysis module is as follows:
[0093] 1. User initiates a request: The user submits a risk analysis request to the distributed storage manager, asking for a security assessment of the target certificate or key.
[0094] 2. Query metadata: The distributed storage manager quickly retrieves the metadata of the target certificate (such as certificate chain, validity period, issuer, etc.) from the Redis cache.
[0095] 3. Parse the certificate chain: The distributed storage manager sends the certificate data to the certificate / key parser, and the parser recursively parses the certificate chain (including the root certificate, intermediate certificates, etc.), and extracts key information (such as public key, signature algorithm).
[0096] 4. Verify the permission policy: The certificate / key parser passes the parsing result to the policy compliance checker, and the checker calls the IAM policy to check whether the access permission of the certificate complies with the security specifications (such as the principle of least privilege).
[0097] 5. Detect the file type: The compliance checker sends the file path of the certificate or key to the file type detector, and the file type detector determines the actual file type by parsing the file header to prevent file disguise attacks.
[0098] 6. Calculate the risk score: The detection results of the certificate chain, file type, and permission policy data are sent to the multi-modal data fusion engine, and the engine combines factors such as algorithm vulnerability weights (such as weak signature algorithms) and permission risks (such as over-authorization) to calculate the comprehensive risk score.
[0099] 7. Return the analysis result: The final risk score is returned by the fusion engine to the storage manager and displayed to the user, and the user can take corresponding security measures based on the score.
[0100] Such as Figure 4As shown in the figure, the dynamic risk assessment module includes an LSTM prediction model, a heat map generator, an automated response engine, a work order unit, an alarm unit, and a log unit.
[0101] The LSTM prediction model is trained based on historical certificate time series data, predicts the risk probability of digital certificates based on the current multi-modal analysis results, determines the risk score and risk level, and adjusts the risk level threshold in combination with business priorities (for example, the priority of the financial system is higher).
[0102] The heat map generator is used for hierarchical display according to the cloud platform, business unit, and risk level, and supports drilling down to view certificate details, that is, allows users to gradually drill down from the summary view to view more detailed subset data.
[0103] The automated response engine is used to adopt different response strategies according to the risk level.
[0104] For digital certificates with a high risk level (score ≥ 80), the automated response engine triggers the work order unit to generate a work order and revokes the digital certificate;
[0105] For digital certificates with a medium risk level (40 ≤ score < 80), the automated response engine triggers the alarm unit to push an alarm that the digital certificate needs to be updated;
[0106] For digital certificates with a low risk level (score < 40), the automated response engine triggers the log unit to record the log and includes the digital certificate in the periodic inspection plan.
[0107] In other embodiments, the present invention also provides a digital certificate security audit method based on a multi-modal analysis cross-cloud architecture, which is applied in the above system and includes:
[0108] Collect digital certificate metadata from different cloud platforms across the cloud for distributed storage and caching;
[0109] Retrieve the metadata of the target digital certificate from the cache, perform certificate chain parsing, permission policy verification, and file type dynamic detection on it, and generate multi-modal analysis results and a comprehensive risk score;
[0110] Predict the risk probability of digital certificates based on the pre-trained LSTM prediction model combined with the multi-modal analysis results, and generate a risk heat map and repair suggestions.
[0111] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0112] The foregoing description of the disclosed embodiments enables those skilled in the art to practice or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Thus, the present invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A digital certificate security audit system based on a multi-modal analysis cross-cloud architecture, characterized in that, It includes: A cross-cloud certificate collection module, a multi-modal risk analysis module, and a dynamic risk assessment module; The cross-cloud certificate collection module is used to adapt to different cloud platforms, and collect metadata of digital certificates from different cloud platforms across the cloud for distributed storage and caching; The multi-modal risk analysis module is used to retrieve metadata of the target digital certificate from the cache, perform certificate chain parsing, permission policy verification, and file type dynamic detection on it, and generate multi-modal analysis results and a comprehensive risk score; The dynamic risk assessment module is used to perform risk prediction on the digital certificate based on the pre-trained LSTM prediction model combined with the multi-modal analysis results, and generate a risk heat map and repair suggestions.
2. The digital certificate security audit system based on the cross-cloud architecture with multimodal analysis according to claim 1, characterized in that, The cross-cloud certificate collection module includes: a cloud platform adaptation layer, a data collection layer, a data standardization engine, and a distributed storage manager; The cloud platform adaptation layer is used to uniformly encapsulate API interfaces of different cloud platforms, shield underlying differences, and provide a standardized certificate metadata access interface; The data collection layer is used to capture various digital certificates of multiple cloud platforms in a concurrent certificate sniffing manner, and automatically deploy lightweight probes to edge nodes of each cloud platform using containerization technology according to the edge node identifiers of each cloud platform, and listen for change events of digital certificates in real time through the lightweight probes; The data standardization engine is used to convert heterogeneous data collected from each cloud platform into a unified JSON structure; The distributed storage manager is used to encrypt digital certificate metadata using a symmetric encryption algorithm, distribute and store the encrypted data in a persistent database, write it into the cache at the same time, and eliminate low-frequency data in the cache according to a preset cache eviction policy.
3. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 2, wherein The change events listened for by the lightweight probes include lifecycle events, content change events, and security events; among them, the lifecycle events include certificate addition, revocation, and expiration; the content change events include private key replacement, certificate chain update, and permission policy modification; the security event is that the key file is maliciously tampered with.
4. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 2, wherein The data collection layer is also used to dynamically scale the deployment of lightweight probes according to changes in cloud platform edge nodes. When a new cloud platform edge node registration event is listened for, lightweight probes are automatically deployed under the new cloud platform edge node. When it is listened for that a certain cloud platform edge node goes offline, the probes deployed on that edge node are deleted.
5. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 2, wherein The unified JSON structure contains the following core fields: "cert_id", "issuer", "expiration", "key_algorithm", "permissions", "storage_path", "hash_alg", "risk_tags", which respectively represent "unique identifier", "issuing agency", "expiration date", "algorithm type", "policy-related permissions", "key storage path", "certificate digest algorithm", "risk tag".
6. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 2, wherein The cross-cloud certificate collection module also includes a key vault for centrally managing the API list used by each cloud platform to obtain digital certificates and the obtained digital certificate key information.
7. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 1, characterized in that, The multimodal risk analysis module includes a certificate / key detector, a policy compliance detector, a file type detector, and a multimodal data fusion engine; The certificate / key detector is used to parse the extension fields of the X.509 certificate, verify the integrity of the certificate chain; extract the private key in PKCS#12 format, attempt to parse the PFX or JKS certificate library file by cryptographic library collision, and detect the password strength; calculate the entropy value of the byte sequence of the private key data using the Shannon entropy formula. If the entropy value is less than the custom threshold, the current private key data is stored in plaintext or weakly encrypted, and a risk label is generated; The policy compliance detector is used to verify whether the access rights of the digital certificate are consistent with the predefined IAM policy. If not, there is unauthorized access, and a risk label is generated; The file type detector is used to parse the file header in real time, determine whether the file extension has been maliciously tampered with, and detect in real time whether non-certificate files are mixed into the certificate directory, generating a risk label; The multimodal data fusion engine is used to fuse the multimodal risk detection results, perform standardized scoring based on each risk detection result, and then perform weighted summation to obtain a comprehensive risk score.
8. The digital certificate security auditing system based on a multi-modal analysis cross-cloud architecture according to claim 1, wherein The dynamic risk assessment module includes an LSTM prediction model, a heat map generator, and an automated response engine; The LSTM prediction model is trained based on historical certificate time series data, predicts the risk probability of digital certificates based on the current multimodal analysis results, determines the risk level, and adjusts the risk level threshold in combination with the business priority; The heat map generator is used to display in layers according to the cloud platform, business unit, and risk level, and supports drilling down to view the certificate details; The automated response engine is used to adopt different response strategies according to the risk level.
9. The digital certificate security audit system based on a multi-modal analysis cross-cloud architecture according to claim 8, characterized in that The dynamic risk assessment module further includes: a work order unit, an alarm unit, and a log unit; for digital certificates with a high risk level, the automated response engine triggers the work order unit to generate a work order and revoke the digital certificate; for digital certificates with a medium risk level, the automated response engine triggers the alarm unit to push an alarm that the digital certificate needs to be updated; for digital certificates with a low risk level, the automated response engine triggers the log unit to record a log and include the digital certificate in the periodic inspection plan.
10. A digital certificate security audit method based on a multi-modal analysis cross-cloud architecture, characterized in that, Its application in the system as described in any one of claims 1-9 includes: Collecting digital certificate metadata from different cloud platforms across the cloud for distributed storage and caching; Retrieving the metadata of the target digital certificate from the cache, performing certificate chain parsing, permission policy verification, and file type dynamic detection on it, generating multimodal analysis results and a comprehensive risk score; Performing risk prediction on digital certificates based on the pre-trained LSTM prediction model combined with multimodal analysis results, generating a risk heat map and repair suggestions.
Citation Information
Patent Citations
Digital certificate credibility determination method and related device
CN116996225A
Certificate management method and system based on pre-trained large language model, and readable medium
CN119025760A
Transfer station system and method for auditing file security sharing
CN119155012A
SSL certificate management method, system, medium, and electronic device based on heterogeneous CA environment
CN119788379A
Big data mining method and system applied to supply chain financial business
CN120088071A
Cited By
Digital certificate expiration risk monitoring and evaluating method, system and device based on large model
CN120896691A