Information anti-divulging method and system capable of encrypting in real time
By combining eKey authentication, zero trust strategy and cloud-native KMS, an information anti-leakage system that can be encrypted in real time in a dynamic environment is built, which solves the problem of insufficient adaptability and monitoring accuracy of traditional anti-leakage systems, and achieves more efficient data security management.
Patent Information
- Application Number
- CN202510431976.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-22
AI Technical Summary
Traditional proactive leak prevention systems have shortcomings in dynamic environment adaptability, monitoring accuracy and cross-platform support, and are unable to effectively deal with security threats in hybrid office modes and cloud environments.
Combining eKey authentication and zero-trust continuous authentication, user-layer monitoring and EDR behavior analysis engine are adopted, kernel-layer monitoring logs are linked to EDR threat intelligence database, cloud-native KMS is used to replace local key centers, realize multi-factor dynamic authentication and cross-cloud environment key management, and combine server-side encryption of cloud service providers to build a security system of active defense + continuous monitoring + dynamic response.
It improves the system's adaptability and monitoring accuracy in a dynamic environment, reduces intranet leaks, reduces the rate of error blocking, saves manual audit costs, and supports cross-platform data security flow.
Smart Images

Figure BDA0005348468990000051 
Figure FDA0005348468980000021
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information anti-disclosure, and particularly relates to an information anti-disclosure method and system capable of real-time encryption. Background Art
[0002] With the acceleration of the informatization process, data leakage has become the core security threat faced by global enterprises. Early anti-disclosure technologies mainly relied on network boundary protection (such as firewalls, IDS) and static encryption means, but they had little effect in the face of APT attacks and insider leaks. After 2010, proactive anti-disclosure technologies gradually emerged, and their core idea was to build a multi-layer defense system through user identity binding, operation monitoring, and environment-aware encryption. Typical solutions include hardware authentication based on eKey, double-layer monitoring of file operations (API Hook + driver-level interception), and network-bound encrypted storage. These technologies significantly reduced the traditional leakage risk by restricting file usage scenarios (such as only decrypting within the internal network) and blocking high-risk operations (such as illegal copying and printing).
[0003] However, according to research, 31% of enterprises using traditional anti-disclosure technologies still encounter internal leakage incidents, and 48% of them are caused by improper policy configuration leading to defense failure. With the popularization of the hybrid work model (Gartner statistics show that 67% of global enterprises adopted remote / office hybrid work systems in 2023), the traditional solutions have exposed three major defects: (1) Static policies are rigid: Network binding relies on fixed IP / MAC addresses and cannot adapt to scenarios such as mobile device access and cloud environment migration; (2) Detection ability lags behind: The rule-base-driven monitoring mechanism is difficult to identify new leakage methods (such as OCR screenshots and AI voice synthesis for stealing secrets); (3) Key management is vulnerable: The centralized key center has a single-point failure risk and lacks cross-cloud platform collaboration capabilities. Summary of the Invention
[0004] The purpose of the present invention is to provide an information anti-disclosure method and system capable of real-time encryption, which effectively solves the deficiencies of traditional proactive anti-disclosure systems in dynamic environment adaptability, monitoring accuracy, and cross-platform support, and shifts from "passive protection" to "active defense + continuous monitoring + dynamic response".
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] An information anti-disclosure method capable of real-time encryption, comprising the following steps:
[0007] Step 1: Combine eKey authentication with zero-trust continuous authentication to achieve multi-factor dynamic authentication; use a zero-trust policy engine to dynamically adjust file access permissions according to user roles, device status, and network environment;
[0008] Step 2: Combine the user-level monitoring with the behavior analysis engine of EDR to identify abnormal file operations; Link the kernel-level monitoring logs with the EDR threat intelligence library to block the encrypted file stealing behavior of malicious processes; When a high-risk operation is detected, EDR automatically isolates the device and simultaneously triggers the active data leakage prevention system to forcibly encrypt or delete the files.
[0009] Step 3: Use cloud-native KMS to replace the local key center, support key distribution and rotation across cloud environments; Bind the key to the cloud platform metadata to achieve automatic encryption of files in the cloud environment; After the file is encrypted, upload it to cloud storage and combine with the server-side encryption of the cloud service provider to achieve double encryption.
[0010] Further, in Step 1, the user's permissions are periodically verified after login.
[0011] Further, in Step 1, the identity authentication includes but is not limited to fingerprint recognition, face recognition, or ID card recognition.
[0012] Further, use risk-based access control to verify the user's permissions, which includes collecting multi-dimensional data such as user behavior, device status, and network environment; Real-time calculate the risk score of the user-resource access request, dynamically generate access control rules according to the risk score, and implement real-time blocking or release at positions such as the API gateway and file system driver.
[0013] Further, the risk score W i The weight of the i-th dimension, V i Is the standardized value (0-1) of the i-th dimension; α is the anomaly detection coefficient (default 0.2); LSTM(x) is the anomaly probability output based on the machine learning model LSTM.
[0014] The present invention also provides an information leakage prevention system capable of real-time encryption, including:
[0015] A control layer, in which a zero-trust policy engine, a key management service, and a risk scoring module are embedded;
[0016] A data layer, which includes a terminal protection agent, a cloud storage gateway, and an API security gateway;
[0017] A support layer, which includes a blockchain audit and traceability module and a trusted computing base TCB.
[0018] Further, the blockchain audit and traceability module calculates the log hash according to the terminal agent / API gateway to generate a standardized log, writes it into the blockchain transaction; The original log is encrypted and stored in IPFS, and the content identifier is returned and recorded on the chain.
[0019] Furthermore, the Trusted Computing Base (TCB) builds a trusted boot chain based on TPM 2.0 / HSM to ensure that system components have not been tampered with.
[0020] By deeply integrating the active anti-disclosure system with zero trust, EDR, and cloud-native security technologies, the present invention can construct a new generation of information security protection system that combines "active defense - continuous monitoring - dynamic control". This combined solution not only makes up for the deficiencies of the original system in mobile office, cloud environment, and automated response, but also reduces the upgrade cost through modular design, making it an ideal choice for dealing with complex internal and external threats. During implementation, it is necessary to verify the compatibility of key components first and promote it in phases (such as integrating zero-trust authentication first and then expanding to cloud KMS). Detailed implementation manners
[0021] An information anti-disclosure method capable of real-time encryption provided in this embodiment includes the following steps:
[0022] Step 1: Combine eKey authentication with the continuous authentication of zero trust to achieve multi-factor dynamic authentication; use the zero-trust policy engine to dynamically adjust file access permissions according to user roles, device status, and network environment; replace the traditional network binding with the zero-trust SDP, associate the file encryption key with the dynamic network label, support the remote office scenario, decrypt the file under the zero-trust network label, and upgrade the "user binding" to "dynamic binding". For example, decrypting the file is only allowed at specific times or locations.
[0023] This embodiment also requires verifying the user's permissions regularly after login, and minimizing the principle of permissions reduces the risk of internal active disclosure.
[0024] The authentication includes, but is not limited to, using fingerprint recognition, face recognition, or ID card recognition.
[0025] Risk-based access control verifies the user's permissions, including collecting multi-dimensional data such as user behavior, device status, and network environment; calculating the risk score of the user-resource access request in real time, dynamically generating access control rules according to the risk score, and implementing real-time blocking or release at positions such as the API gateway and file system driver.
[0026] The risk score W i The weight of the i-th dimension, V i Is the normalized value (0-1) of the i-th dimension; α is the anomaly detection coefficient (default 0.2); LSTM(x) is the anomaly probability output based on the machine learning model LSTM.
[0027] Table 1 Examples of dimensions and weights
[0028]
[0029] When the risk score > 70, the financial report only allows PDF preview with dynamic watermarking; the false block rate drops from 12.3% to 1.8%, and the internal network leakage incidents are reduced by 92%. Implement request frequency fusing for high-risk APIs (such as user data export): throttling is triggered when R > 60; automatically block API abuse attacks, saving 75% of the manual audit cost.
[0030] Step 2: Combine user-level monitoring (API Hook) with the behavior analysis engine of EDR to identify abnormal file operations (such as batch copying, printing during non-office hours); link the kernel-level monitoring (file filtering driver) logs with the EDR threat intelligence library to block the encrypted file stealing behavior of malicious processes. When a high-risk operation is detected, EDR automatically isolates the device and simultaneously triggers the active anti-disclosure system to forcibly encrypt or delete the file. Analyze the file operation logs in association with the threat events of EDR to generate a more accurate leakage traceability report. Improve the defense ability against APT attacks and internal personnel's collaborative crimes; achieve a closed-loop of "monitoring - detection - response".
[0031] Step 3: Use cloud-native KMS (Key Management Service) to replace the local key center, support key distribution and rotation across cloud environments; bind the system key (SK) with cloud platform metadata (such as tenant ID, bucket label) to achieve automatic encryption of files in the cloud environment. After the file is encrypted, upload it to cloud storage, and combine with the server-side encryption (SSE) of the cloud service provider to achieve double encryption. Link the IAM policy of the cloud platform with the user binding mechanism of the active anti-disclosure system. For example, only users authenticated by eKey are allowed to access the encrypted files. Support the hybrid cloud scenario to solve the security problem of cross-platform data flow. Use cloud-native services to improve the high availability of key management.
[0032] Example 2
[0033] An information anti-disclosure system capable of real-time encryption provided in this example includes: a control layer, and the control layer includes a zero-trust policy engine, a key management service, and a risk scoring module embedded therein; the zero-trust policy engine combines eKey authentication with continuous authentication of zero trust to achieve multi-factor dynamic authentication; use the zero-trust policy engine to dynamically adjust file access permissions according to user roles, device status, and network environment; the zero-trust SDP replaces the traditional network binding, and the file encryption key is associated with the dynamic network label, supporting the remote work scenario, and the file is decrypted under the zero-trust network label, upgrading "user binding" to "dynamic binding". For example, the file is only allowed to be decrypted at specific times or locations.
[0034] The key management service is risk-based access control to verify user permissions; the authentication includes but is not limited to fingerprint recognition, face recognition, or ID card recognition.
[0035] Risk-based access control verifies user permissions, including collecting multi-dimensional data such as user behavior, device status, and network environment; calculates the risk score of the user-resource access request in real time, dynamically generates access control rules according to the risk score, and implements real-time blocking or release at positions such as API gateways and file system drivers.
[0036] The risk score W i The weight of the i-th dimension, V i Is the normalized value (0-1) of the i-th dimension; α is the anomaly detection coefficient (default 0.2); LSTM(x) is the anomaly probability output based on the machine learning model LSTM.
[0037] When the risk score > 70, only PDF previews with dynamic watermarks are allowed for financial reports; the false blocking rate is reduced from 12.3% to 1.8%, and the internal network leakage incidents are reduced by 92%. Implement request frequency fusing for high-risk APIs (such as user data export): trigger traffic limiting when R > 60; automatically block API abuse attacks, saving 75% of the manual audit cost.
[0038] Data layer, the data layer includes terminal protection agents, cloud storage gateways, and API security gateways; uses a combination of user layer monitoring (API Hook) and the behavior analysis engine of EDR to identify abnormal file operations (such as batch copying, printing outside office hours); the kernel layer monitoring (file filter driver) logs are linked with the EDR threat intelligence library to block the encrypted file stealing behavior of malicious processes. When a high-risk operation is detected, EDR automatically isolates the device, and at the same time triggers the active anti-leakage system to forcibly encrypt or delete files. The file operation logs are associated and analyzed with the threat events of EDR to generate a more accurate leakage traceability report. Improve the defense ability against APT attacks and internal personnel's collaborative crimes; achieve a closed-loop of "monitoring - detection - response".
[0039] Use cloud-native KMS (Key Management Service) to replace the local key center, support key distribution and rotation across cloud environments; the system key (SK) is bound to cloud platform metadata (such as tenant ID, storage bucket label) to achieve automatic encryption of files in the cloud environment. After the file is encrypted, it is uploaded to cloud storage, and combined with the server-side encryption (SSE) of the cloud service provider to achieve double encryption. The IAM policy of the cloud platform is linked with the user binding mechanism of the active anti-leakage system. For example: only users authenticated through eKey are allowed to access encrypted files. Support hybrid cloud scenarios to solve the security problem of cross-platform data flow. Use cloud-native services to improve the high availability of key management.
[0040] Support layer, the support layer includes a blockchain audit and traceability module and a Trusted Computing Base (TCB); the blockchain audit and traceability module standardizes the logs (CEF format) generated by the terminal agent / API gateway; calculates the log hash and writes it into the blockchain transaction; encrypts the original logs and stores them in IPFS, and returns the CID (Content Identifier) to be recorded on the chain. The Trusted Computing Base (TCB) establishes a trusted boot chain based on TPM 2.0 / HSM to ensure that system components have not been tampered with. The deep integration of the blockchain audit and traceability module and the Trusted Computing Base constructs a three-in-one security system of "operational trust - record immutability - verification automation". By ensuring the trustworthiness of the data generation process through a hardware-level trust root and combining the distributed characteristics of the blockchain to achieve audit transparency, it can effectively address internal tampering, external attacks, and compliance review requirements. Future directions include the migration of quantum security algorithms and the adaptation of lightweight TEEs for edge devices, etc.
[0041] The above are only the preferred embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any modification and replacement based on the technical solutions and inventive concepts provided by the present invention should be covered within the protection scope of the present invention.
Claims
1. An information anti-disclosure method capable of real-time encryption, characterized in that, It includes the following steps: Step 1: Combine eKey authentication with zero-trust continuous authentication to achieve multi-factor dynamic authentication; use the zero-trust policy engine to dynamically adjust file access permissions according to user roles, device status, and network environment; Step 2: Combine user-layer monitoring with the behavior analysis engine of EDR to identify abnormal file operations; link the kernel-layer monitoring logs with the EDR threat intelligence library to block the encrypted file stealing behavior of malicious processes; when high-risk operations are detected, EDR automatically isolates the device and at the same time triggers the active anti-disclosure system to forcibly encrypt or delete files; Step 3: Use cloud-native KMS to replace the local key center to support key distribution and rotation across cloud environments; bind the key to the cloud platform metadata to achieve automatic encryption of files in the cloud environment; upload the encrypted files to cloud storage and combine with the server-side encryption of the cloud service provider to achieve double encryption.
2. The information anti-disclosure method capable of real-time encryption according to claim 1, characterized in that In Step 1, the user's permissions are periodically verified after login.
3. A method for preventing information leakage that can be encrypted in real time according to claim 1, characterized in that, In Step 1, the authentication includes fingerprint recognition, face recognition, or ID card recognition.
4. A method for preventing information leakage that can be encrypted in real time according to claim 2, characterized in that, Use risk-based access control to verify user permissions, which includes collecting multi-dimensional data such as user behavior, device status, and network environment; calculating the risk score of the user-resource access request in real time, dynamically generating access control rules according to the risk score, and implementing real-time blocking or release at positions such as the API gateway and file system driver.
5. A method for preventing information leakage that can be encrypted in real time according to claim 4, characterized in that, The risk score W i The weight of the i-th dimension, V i is the standardized value (0-1) of the i-th dimension; α is the anomaly detection coefficient (default 0.2); LSTM(x) is the anomaly probability output based on the machine learning model LSTM.
6. An information anti-disclosure system capable of real-time encryption, characterized in that, It includes: A control layer, in which a zero-trust policy engine, a key management service, and a risk scoring module are embedded; A data layer, which includes a terminal protection agent, a cloud storage gateway, and an API security gateway; A support layer, which includes a blockchain audit and traceability module and a trusted computing base TCB.
7. An information anti-disclosure system capable of real-time encryption according to claim 6, characterized in that, The blockchain audit and traceability module calculates the log hash according to the standardized logs generated by the terminal agent / API gateway and writes it into the blockchain transaction; the original logs are encrypted and stored in IPFS, and the content identifier is returned and recorded on the chain.
8. The information anti-disclosure system capable of real-time encryption according to claim 6, wherein, The trusted computing base TCB establishes a trusted boot chain based on TPM 2.0 / HSM to ensure that system components have not been tampered with.