Method and computer for cryptographic protection of control communication in it system and / or service access to it system
By using asymmetric encryption algorithms to generate session keys in IT systems and combining RBAC and ABAC models for access control, the problems of complex key management and inflexible access control are solved, and efficient and secure IT system communication and service access are achieved.
Patent Information
- Application Number
- CN202510831349.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing IT system communication encryption methods have problems such as complex key management, low efficiency and inflexible access control. Especially when the user environment changes, it is difficult to dynamically adjust permissions, resulting in security risks.
Asymmetric encryption algorithm is used to generate a one-time session key, combine symmetric encryption algorithm to process communication data, and combine RBAC and ABAC hybrid models for access control, dynamically adjust permissions, attach timestamps and verification codes to prevent attacks, set session timeout mechanisms and exception monitoring.
It realizes efficient and secure end-to-end communication encryption, dynamically adjusts access permissions, improves the security and flexibility of the IT system, prevents playback attacks and data tampering, and forms a closed loop of security protection for the entire process.
Smart Images

Figure CN120358087A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of IT system security, and specifically to a method and computer for encrypting and protecting control communication in an IT system and / or accessing IT system services. Background Art
[0002] In today's information age, IT systems are increasingly widely used, covering multiple important fields such as finance, government affairs, and enterprise management. Communication security and system service access security in IT systems are crucial. Once information is stolen, tampered with during transmission, or illegal users obtain access rights to system services, it may lead to serious consequences such as leakage of sensitive data and abuse of system functions, causing huge losses to users and enterprises. Existing IT system communication encryption methods, such as traditional symmetric encryption algorithms DES, AES, and asymmetric encryption algorithm RSA, etc., ensure communication security to a certain extent, but there are still some problems. For example, the key management of symmetric encryption algorithms is complex, and the transmission and storage of keys have security risks; the encryption and decryption speeds of asymmetric encryption algorithms are relatively slow, which will affect system efficiency during large-scale data transmission; in terms of system service access, traditional access control methods are mainly based on user names and passwords, or simple permission divisions. However, user names and passwords are easily stolen or cracked, and the flexibility and dynamics of permission divisions are insufficient to adapt to complex and changeable network environments and user requirements. For example, when the user's access environment changes, such as using different devices and different network addresses, it is difficult for traditional methods to adjust access permissions in real time and dynamically, and there are certain security vulnerabilities. Therefore, there is an urgent need for a more secure, efficient, and flexible encryption protection method for IT system communication and system service access to solve the problems existing in the prior art. Summary of the Invention
[0003] Aiming at the deficiencies of the prior art, the present invention provides a method and computer for encrypting and protecting control communication in an IT system and / or accessing IT system services, and solves the problems of complex traditional encryption key management, low efficiency, and inflexible access control.
[0004] To achieve the above objectives, the present invention is realized through the following technical solutions: A method and computer for encrypting and protecting control communication in an IT system and / or accessing IT system services, including the following steps: S1. System initialization stage: Assign a unique user identifier to each user and generate an asymmetric encryption key pair. Store the public key in the key management center, and the private key is securely stored by the user; Define a service identifier for each system service and set an access policy including user type, access time, device characteristics, and network address range; S2. User Authentication Phase: The user initiates an access request containing the user identifier, service identifier, device characteristics, and network address. The server sequentially verifies the user's legitimacy, device characteristics, and whether the network address complies with the access policy. After passing the verification, a one-time session key is generated and encrypted for transmission using the user's public key. S3. Communication Encryption Phase: The user's client decrypts the received data using the private key to obtain the session key, and encrypts the communication data packets for transmission based on the session key. Each data packet is appended with a timestamp and a checksum, and the server verifies the timestamp and checksum after decryption. S4. Access Control Phase: The server combines the user's role, attributes, environmental attributes, and real-time behavior data to dynamically verify the access permissions based on the hybrid model of RBAC and ABAC. S5. Session Management Phase: Set the session timeout period, monitor the session status in real time, and terminate the session and record the log in case of anomalies.
[0005] Preferably, in the user authentication phase, the device characteristics include at least one of the device ID, operating system version, and hardware fingerprint, and the network address verification includes at least one of the IP address, MAC address, and geolocation information.
[0006] Preferably, the session key is generated using a symmetric encryption algorithm, the asymmetric encryption algorithm is one of RSA and ECC, and the symmetric encryption algorithm is one of AES and DES.
[0007] Preferably, in the communication encryption phase, the timestamp is used to prevent replay attacks, and the checksum is generated using one of the hash algorithms such as MD5 and SHA-256 for verifying data integrity.
[0008] Preferably, in the access control phase, the user attributes include the user's credit rating, department, and position, the environmental attributes include the access time, geographical location, and network type, and the real-time behavior data includes the access frequency, operation habits, and historical access records.
[0009] Preferably, the verification process of the hybrid model of RBAC and ABAC includes: first determining the basic access permissions based on the user's role, and then refining and dynamically adjusting the permissions in combination with the user attributes, environmental attributes, and real-time behavior data.
[0010] Preferably, in the session management phase, the session timeout period is dynamically configured according to the service sensitivity level. The higher the sensitivity level, the shorter the timeout period.
[0011] Preferably, the abnormal behaviors include abnormal data transmission rate, high-frequency error requests, and unauthorized device access, and the abnormal handling includes session termination, log recording, and security warning.
[0012] Preferably, in the system initialization phase, the user's private key is encrypted and stored through a hardware security module or a trusted execution environment, and the public key is stored in the blockchain distributed key management system.
[0013] Preferably, a computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.
[0014] The present invention provides a method and a computer for encrypting and protecting control communication in an IT system and / or accessing IT system services. It has the following beneficial effects: 1. The present invention transmits a one-time session key through an asymmetric encryption algorithm and processes communication data through a symmetric encryption algorithm, taking into account both security and transmission efficiency, solving the problems of complex key management and low efficiency in traditional encryption methods. The data packets are attached with timestamps and check codes, effectively resisting replay attacks and data tampering, and constructing an end-to-end high-strength communication encryption system, providing a reliable security guarantee for IT system data transmission.
[0015] 2. The present invention adopts an access control model combining RBAC and ABAC, dynamically adjusts permissions based on the user's role, attributes, environment, and real-time behavior, breaks through the limitations of traditional static permission management, and realizes fine-grained and scenario-based access control. With a supporting session timeout mechanism and exception monitoring, risk sessions are terminated in a timely manner and logs are recorded, forming a security protection closed-loop covering the entire process of authentication, transmission, access, and session, significantly improving the security and flexibility of system service access. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0018] Embodiment 1: Please refer to the attached Figure 1 The method and computer for encrypting and protecting control communication in an IT system and / or accessing IT system services provided by the embodiment of the present invention are applied to the access of employees in an enterprise's internal IT system to the financial management service, including the following steps: S1. System initialization phase User Key Distribution: Assign a unique user identifier "EMP0023" to Employee A, and generate a 1024-bit asymmetric encryption key pair through the RSA algorithm. The private key of Employee A is stored in the trusted execution environment (TEE) of their office computer in an encrypted manner, and the public key is uploaded to the blockchain distributed key management system of the system for storage.
[0019] Service Policy Settings: Define the service identifier of the financial management service as "FIN-SVC001", and set the access policy as follows: Allowed User Types: Employees in the finance department, management employees; Access Time: 09:00 - 18:00 on weekdays; Device Characteristics: The device ID needs to be in the list of trusted devices registered in the system (such as containing the prefix "CORP-LAPTOP-"), and the operating system version needs to be Windows 10 or higher or macOS 12 or higher. Network Address Range: Only the internal company IP address segment 192.168.XX.XX / XX is allowed. S2. User Authentication Phase Initiate Access Request: Employee A uses an office computer with device ID "CORP-LAPTOP-098" and IP address 192.168.XX.XX to initiate a request to access the financial management service to the system server at 09:30 on June 10, 2025. The request contains the user identifier "EMP0023", service identifier "FIN-SVC001", device characteristics, and network address information; Legitimacy Verification: The system server first queries the user database to confirm that "EMP0023" is an employee in the finance department and the account status is normal. Further verify the device characteristics: The device ID "CORP-LAPTOP-098" is in the list of trusted devices, and the operating system version Windows 11 meets the requirements; Verify the network address: The IP address 192.168.XX.XX belongs to the allowed internal network segment; Session Key Generation and Transmission: After verification, the system server generates an AES-256 symmetric encryption session key, encrypts the session key using the public key of Employee Zhang San, and sends the encrypted session key to the client. S3. Communication Encryption Phase Key Decryption and Data Encryption: After receiving the encrypted session key, the client uses the private key stored in the TEE to decrypt it to obtain the AES-256 session key. Subsequent communication data such as reimbursement data and financial statements is encrypted in groups using this session key. Each data group is appended with a Unix timestamp and a checksum is generated through the SHA-256 hashing algorithm; Data Verification and Processing: After the server receives the encrypted data, it decrypts it using the same AES-256 session key. First, it checks whether the difference between the timestamp and the current time is within 60 seconds to prevent replay attacks. Then, it calculates the SHA-256 hash value of the decrypted data and compares it with the received checksum to verify data integrity. If both verifications pass, subsequent business processing is performed. S4. Access Control Phase Role Permission Verification: Employee A's role is "Finance Department Employee". According to the RBAC model, this role has the basic permission to access the financial management service. Attribute and Environment Verification: Combining the ABAC model, it further verifies the user attributes, i.e., the affiliated department is the Finance Department, the environmental attribute, i.e., the access time 09:30 is within the permitted range on weekdays, the network type is the company's internal network, and the real-time behavior data, i.e., the recent access frequency is normal and there is no abnormal operation record. After confirming that all conditions meet the access policy, it allows access to the service. S5. Session Management Phase Session Timeout Setting: Since the financial management service is a sensitive service, the session timeout is set to 20 minutes. If Employee A does not perform any operations within 20 minutes, the system automatically terminates the session. Real-time Monitoring and Exception Handling: During the session, the system monitors the data transmission rate and request error rate in real time. If an anomaly is detected, such as a sudden 50% increase in the data transmission rate, the session is immediately terminated, a log containing the time, user identifier, and anomaly type is recorded, and a warning is sent to the security administrator.
[0020] A computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented. Embodiment Two: Please refer to the appendix Figure 1 , The embodiments of the present invention provide a method and computer for encrypting and protecting control communication in an IT system and / or accessing IT system services, which are applied to financial customers accessing account transaction services through mobile devices, including the following steps: S1. System Initialization Phase User Key Distribution: Assign a unique user identifier "CUS0045" to Customer A. Use the ECC algorithm to generate a key pair. The private key is stored in the hardware security module of Customer Li Si's mobile phone, and the public key is stored in the financial institution's distributed key management system. Service Policy Setting: Define the service identifier of the account transaction service as "TRD-SVC002", and the access policy is as follows: Allowed User Types: Authenticated individual customers. Visiting hours: 07:00-23:00 every day; Device characteristics: The device ID must be a mobile device registered by the user, and the operating system must be Android 11 and above or iOS 15 and above; Network address range: Domestic mainstream operator networks are allowed. S2. User authentication phase Initiate access request: Customer A uses a mobile phone with device ID "865432109876543", IP address 114.XXX.XXX.XXX, and location in China to initiate a request to the server to access the account transaction service at 15:45 on June 1, 2025, including user ID, service ID, device characteristics, and network address information; Legitimacy verification: The server verifies that the user ID "CUS0045" has been authenticated and the account is normal. Device feature verification: The device ID is in the registration list, and the operating system iOS16 meets the requirements. Network address verification: The IP address is in China, which is within the permitted range. Session key generation and transmission: Generate a DES symmetric encryption session key, encrypt it with client A's public key, and send it to the client. S3. Communication encryption stage Key decryption and data encryption: The client obtains the DES session key by decrypting the private key in the mobile phone HSM, encrypts the transaction data in groups, adds an ISO8601 format timestamp to each group, and calculates the MD5 checksum. Data verification and processing: After decryption, the server checks that the time stamp is less than 120 seconds away from the current time and that the MD5 checksum is consistent. After confirming that the data is valid, the transaction is processed. S4. Access control stage Role authority verification: Customer A's role is "individual customer" and according to the RBAC model, he has basic transaction authority; Attribute and environment verification: Combined with the ABAC model, verify the user attributes: credit rating B, normal account balance, environmental attributes: access time 15:45 is within the permitted range, the device is a registered device, and real-time behavior data: recent transaction frequency is normal, there is no cross-time zone login record, and the transfer transaction is allowed within the limit. S5. Session management phase Session timeout setting: The account transaction service sets the session timeout to 15 minutes to ensure the security of sensitive operations; Real-time monitoring and exception handling: If it is detected that the same device initiates 15 transaction requests within 10 minutes, which exceeds the normal threshold of 10 times, it is judged as an abnormality, the session is terminated immediately, the log is recorded, and the customer is required to re-perform the SMS verification code + fingerprint recognition two-factor authentication. Embodiment three: Please refer to the appendix Figure 1 The embodiments of the present invention provide a method and a computer for encrypting and protecting control communication in an IT system and / or accessing IT system services, which are applied to government platform staff accessing classified file services, and include the following steps: S1. System initialization phase User key distribution: Assign a unique user identifier "GOV0067" to staff member B, generate an RSA-2048 key pair, encrypt the private key and store it in the TEE of a dedicated security terminal, and upload the public key to the blockchain key management system of the government cloud; Service policy setting: Define the service identifier of the classified file service as "SEC-SVC003", and the access policy is as follows: Allowed user types: Government personnel with a security level of level 3 or above; Access time: 08:30-17:30 on weekdays; Device characteristics: Designate the security terminal as device ID: GOV-TERM-009, and pre-install a dedicated security operating system; Network address range: Government private network IP address segment 10.10.XX.XX / XX. S2. User authentication phase Initiate an access request: Staff member B uses a security terminal with device ID "GOV-TERM-009" and IP address 10.10.XX.XX to initiate an access request at 10:20 on June 2, 2025, including user identification, service identification, device characteristics, and network address information; Legitimacy verification: The server verifies that the security level of the user identifier "GOV0067" is level 3 and the account is normal; Device characteristics verification: The device ID is consistent with the designated security terminal, and the operating system is a dedicated security version; Network address verification: The IP address 10.10.XX.XX belongs to the government private network segment; Session key generation and transmission: Generate an AES-256 session key, encrypt it with the user's public key, and send it to the client. S3. Communication encryption phase Key decryption and data encryption: The client decrypts through the private key in the TEE to obtain the session key, encrypts the classified file data in groups, adds a UTC timestamp to each group, and generates a SHA-512 checksum; Data verification and processing: After the server decrypts, check that the timestamp difference < 30 seconds and the SHA-512 checksum is consistent, and allow the file reading operation. S4. Access control phase Role permission verification: The role of B is "level 3 security personnel", and according to the RBAC model, has the basic permission to access classified files; Attribute and Environment Verification: Combining with the ABAC model, verify user attributes: the department is a certain confidential unit, the length of service is 5 years, environmental attributes: the access time 10:20 is within the permitted range, the network is a government dedicated network, and real-time behavior data: recent access records are normal, there is no abnormal file download behavior. After confirming that the permissions are compliant, open the file viewing permission. S5. Session Management Phase Session Timeout Setting: The sensitive level of the classified file service is the highest. Set the session timeout time to 10 minutes and automatically log out when there is no operation. Real-time Monitoring and Exception Handling: If it is detected that the file download request exceeds the user's permission range, immediately terminate the session, record the log containing the user identification, operation time, and exception type, and trigger the security audit process, requiring the user to perform secondary authentication of iris + fingerprint of biometrics. Policy Update Process When it is necessary to adjust the access time of the classified file service, such as extending it to 18:00, the administrator modifies it through the visual policy configuration interface of the government platform. The system automatically triggers the incremental synchronization mechanism, only transmits the updated part of the policy to the relevant service nodes, and completes the policy synchronization of the entire platform within 5 seconds to ensure that the policies of all nodes are consistent.
[0021] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for controlling communication and / or access to IT system services in an IT system, characterized in that, It includes the following steps: S1. System initialization phase: Assign a unique user identifier to each user and generate an asymmetric encryption key pair. Store the public key in the key management center, and the private key is securely stored by the user. Define a service identifier for each system service and set an access policy that includes user type, access time, device characteristics, and network address range. S2. User authentication phase: The user initiates an access request that includes the user identifier, service identifier, device characteristics, and network address. The server sequentially verifies the user's legitimacy, whether the device characteristics and network address conform to the access policy. After passing the verification, a one-time session key is generated and encrypted for transmission using the user's public key. S3. Communication encryption phase: The user client decrypts the session key using the private key and encrypts the communication data packets for transmission based on the session key. Each data packet is attached with a timestamp and a checksum, and the server verifies the timestamp and checksum after decryption. S4. Access control phase: The server combines the user's role, attributes, environmental attributes, and real-time behavior data to dynamically verify the access rights based on a hybrid model of RBAC and ABAC. S5. Session management phase: Set the session timeout period, monitor the session status in real time, terminate the session and record the log when an anomaly occurs.
2. The method for controlling communication and / or access to IT system services with encryption protection according to claim 1, characterized in that, In the user authentication phase, the device characteristics include at least one of the device ID, operating system version, and hardware fingerprint. The network address verification includes at least one of the IP address, MAC address, and geolocation information.
3. The method for controlling communication and / or access to IT system services by encryption protection according to claim 1, characterized in that, The session key is generated using a symmetric encryption algorithm. The asymmetric encryption algorithm is one of RSA and ECC, and the symmetric encryption algorithm is one of AES and DES.
4. The method for controlling communication and / or accessing IT system services with encryption protection according to claim 1, characterized in that, In the communication encryption phase, the timestamp is used to prevent replay attacks, and the checksum is generated using one of the hash algorithms of MD5 and SHA-256 to verify the data integrity.
5. The method for controlling communication and / or access to IT system services with encryption protection according to claim 1, characterized in that, In the access control phase, the user attributes include the user's credit rating, department, and position. The environmental attributes include the access time, geographical location, and network type. The real-time behavior data includes the access frequency, operation habits, and historical access records.
6. The method for controlling communication and / or access to IT system services with encryption protection according to claim 1, characterized in that, The verification process of the hybrid model of RBAC and ABAC includes: First, determine the basic access rights based on the user's role, and then refine and dynamically adjust the rights in combination with the user's attributes, environmental attributes, and real-time behavior data.
7. The method for controlling communication and / or access to IT system services in an IT system with encryption protection according to claim 1, characterized in that, In the session management phase, the session timeout period is dynamically configured according to the service sensitivity level. The higher the sensitivity level, the shorter the timeout period.
8. A method for controlling communication and / or access to IT system services with encryption protection according to claim 1, characterized in that, The abnormal behaviors include abnormal data transmission rate, high-frequency error requests, and unauthorized device access. The abnormal handling includes session termination, log recording, and security warning.
9. The method for controlling communication and / or access to IT system services in an IT system with encryption protection according to claim 1, characterized in that, In the system initialization phase, the user's private key is encrypted and stored through a hardware security module or a trusted execution environment, and the public key is stored in a blockchain distributed key management system.
10. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Access control method based on ABAC (Attribute Based Access Control) and RBAC (Role Based Access Control)
CN104217146A
Session key transmission method and device and computer readable storage medium
CN110213045A
Secure data exchange network
CN114641965A
End-to-end encrypted data key distribution method, electronic device and program product
CN119995879A
Secure process for device registration with a service
US20240306111A1