Computer information security monitoring and encryption protection system
Through the integration of multiple means of physical, network, software and personnel management modules, computer information security monitoring and encryption protection systems solve the problem of insufficient traditional protection measures, and achieve comprehensive computer information security protection to prevent data leakage and malicious attacks.
Patent Information
- Application Number
- CN202510460091.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-08-01
AI Technical Summary
The existing technology is difficult to effectively deal with computer information security issues, especially in the complex and changeable network environment, traditional security protection measures are difficult to meet the needs, resulting in serious data leakage and malicious attacks.
The computer information security monitoring and encryption protection system is adopted, including physical protection modules, network protection modules, software protection modules, personnel management modules and comprehensive emergency response modules. Through integrated chip encryption transmission, network software monitoring and authentication connections, permission management, real-time monitoring and multi-layer protection measures, all-round security protection is achieved.
Improve the security of computer system and network data, prevent unauthorized access and malicious attacks, ensure the confidentiality, integrity and availability of data, and enhance the protection capabilities of computer information security.
Smart Images

Figure CN120408604A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer information protection, and particularly relates to a computer information security monitoring and encryption protection system. Background Art
[0002] Computer information security, usually simply referred to as information security or network security, refers to protecting the hardware, software, and data in a computer network system from being damaged, altered, or leaked due to accidental or malicious reasons, ensuring that the system runs continuously, reliably, and normally, and that network services are not interrupted. The aim is to maintain the confidentiality, integrity, and availability of information;
[0003] However, with the rapid development of the Internet, computer information security issues have become increasingly severe. Security threats such as cybercrime, data leakage, and virus attacks seriously threaten the property and privacy security of enterprises and individuals. Traditional security protection measures are no longer sufficient to meet the requirements of the increasingly complex and changeable network environment.
[0004] Therefore, this application proposes a computer information security monitoring and encryption protection system to solve the problems raised in the background art. Summary of the Invention
[0005] The purpose of this application is to disclose a computer information security monitoring and encryption protection system to solve the problems of insufficient computer information security in the prior art in order to overcome the problems of the prior art.
[0006] The purpose of this application is achieved through the following technical solutions:
[0007] A computer information security monitoring and encryption protection system, the computer information security monitoring and encryption protection system includes:
[0008] A physical protection module, configured to protect computer information security from the outside;
[0009] A network protection module, configured to implement network security protection when the computer is connected to the network;
[0010] A software protection module, configured to protect the internal software and data of the computer;
[0011] A personnel management module, configured to provide security protection for computer users;
[0012] A comprehensive emergency response module, configured to provide real-time protection and maintenance for the computer.
[0013] According to a preferred embodiment, the network protection module uses the following means to achieve complete network protection:
[0014] Integrated chip for encrypted transmission, with an integrated chip fixedly set on multiple types of interfaces of a computer for encrypted transmission to provide security protection for the transmitted data.
[0015] Network software monitoring and authentication connection, by monitoring and authenticating the networking of the software installed in the computer to provide security protection for the software installed in the computer and prevent the installation of unauthenticated software.
[0016] Network access control, by controlling the network connections of networked computers, granting access permissions to authenticated secure websites and blocking access permissions to unauthenticated network websites.
[0017] Set up a network firewall, deployed between the internal network and the external network, or between network regions with different trust levels, as a security barrier to prevent potential unauthorized access, malware propagation, and data leakage.
[0018] According to a preferred embodiment, the network software monitoring and authentication connection is implemented by the following method:
[0019] Perform encryption settings by using symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms.
[0020] Among them, performing encryption settings by using the hash algorithm includes: dividing the input data in the computer into several message blocks of equal or unequal lengths, and then performing a series of operations on each message block, including: bit operations, shift operations, modulo operations, and exclusive OR operations, and finally obtaining a fixed-length output value for encryption settings.
[0021] Alternatively, through user privilege management, set up separate user accounts for the personnel using the computer, and grant different usage permissions corresponding to different usage accounts to restrict and protect the content viewed and transmitted by the computer.
[0022] According to a preferred embodiment, the software protection module performs security protection in the following manner, including:
[0023] Operating system protection, for protecting the computer operating system, restricting the upgrade and downgrade of the operating version, or the installation of a new operating system.
[0024] Application program and database protection, restricting and protecting the application programs installed in the computer, specifying specific download channels or installation channels, and preventing downloads and usage from arbitrary websites.
[0025] According to a preferred embodiment, the software protection module also performs security protection in the following manner, including:
[0026] Integrated software antivirus. A specific integrated antivirus software is installed in the computer, which has the function of antivirus with network connection restriction and the function of antivirus without network.
[0027] Malware protection. A protection program is set in the computer to prevent the installation of programs entering through non-specified websites and specified data transmission channels, and alert the integrated antivirus software for processing.
[0028] According to a preferred embodiment, the personnel management module is implemented in the following ways, including:
[0029] Employee background investigation. Conduct an investigation on the job types and work directions of the employees using the computer, and reject the use of the computer by non-professional employees.
[0030] Permission hierarchical management. For employees of different work types, conduct hierarchical management of computer usage permissions, and control and manage the permissions for accessing and transmitting information.
[0031] According to a preferred embodiment, the personnel management module is also implemented in the following ways, including
[0032] Employee security awareness training. Regularly train employees on computer usage rules to enhance their ability to use computers in a standardized manner.
[0033] External access personnel permission restriction. For external access personnel using the computer, equip them with dedicated access personnel permission accounts to prevent the internal information of the computer from being accessed and transmitted.
[0034] According to a preferred embodiment, the comprehensive emergency response module is implemented by the following methods, including:
[0035] Coordinating security information and data. On the computer cloud platform and the background, conduct real-time control over the computer access websites and transmitted information.
[0036] Real-time monitoring and management. Conduct real-time control and management over the indoor and outdoor monitoring of computer usage, and monitor and manage non-users during that time.
[0037] According to a preferred embodiment, the comprehensive emergency response module is also implemented by the following methods, including:
[0038] Abnormal alarm and warning. Alarm and warn against the behavior of obtaining information and data in the computer through abnormal channels, and display the alarm screen in real-time during monitoring.
[0039] Data security maintenance. Regularly maintain and protect the data in the computer to ensure the integrity of the information in the computer and the feasibility of the computer itself.
[0040] According to a preferred embodiment, the physical protection module includes the reinforcement of doors, windows and walls for physically reinforcing the interior where the computer is placed;
[0041] Monitoring by monitoring devices. Monitoring devices are installed both indoors and outdoors where the computer equipment is placed for real-time monitoring. A plurality of monitoring devices are provided to form a non-blind-spot monitoring;
[0042] Fire, water and theft prevention devices. Waterproof and theft-proof walls and doors and windows are provided both indoors and outdoors where the computer is placed. The waterproof layer is provided with multiple layers, and fire prevention devices are provided indoors where the computer is placed;
[0043] Networked alarm devices. Alarm lines are provided on the indoor walls and doors and windows where the computer is placed and are connected to the alarm device in real time through the network for use in case of damage.
[0044] The foregoing main solution of the present application and its various further alternative solutions can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed in the present application. Those skilled in the art can understand that there are various combinations according to the prior art and common general knowledge after understanding the solution of the present application, all of which are the technical solutions to be protected in the present application and will not be enumerated herein.
[0045] Advantages of the present application:
[0046] The computer information security monitoring and encryption protection system of the present application realizes the all-round protection of the computer system and network data through multiple means such as integrating physical security protection, network security protection, software security protection and personnel security protection.
[0047] The computer information security monitoring and encryption protection system provided by the present application can improve the security of the computer system and network data, and can prevent unauthorized access to the computer, resulting in computer data leakage and computer information security being maliciously attacked, thereby improving the information security of computer use. Description of the drawings
[0048] Figure 1 It is the structure diagram of the security monitoring and encryption protection system of the present application;
[0049] Figure 2 It is the structure diagram of the physical protection module of the present application;
[0050] Figure 3 It is the structure diagram of the network protection module of the present application;
[0051] Figure 4 It is the structure diagram of the network software monitoring, authentication and connection protection of the present application;
[0052] Figure 5 It is the structure diagram of the software protection module of the present application;
[0053] Figure 6 This is the structural diagram of the personnel management module of this application;
[0054] Figure 7 This is the structural diagram of the comprehensive emergency response of this application. Specific Embodiments
[0055] The following uses specific specific examples to illustrate the implementation manners of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0056] It should be noted that: Similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0057] In the description of this application, it should also be noted that, unless otherwise clearly defined and limited, the terms "set", "installed", "connected", "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific situations.
[0058] In addition, this application points out that in this application, if the specific structures, connection relationships, position relationships, power source relationships, etc. involved are not specifically written, the structures, connection relationships, position relationships, power source relationships, etc. involved in this application are all known to those skilled in the art on the basis of the prior art without creative labor.
[0059] Refer to Figure 1 As shown, this application discloses a computer information security monitoring and encryption protection system, including: a physical protection module for protecting computer information security from the outside; a network protection module for network security protection when the computer is connected to the network; a software protection module for protecting the internal software and data of the computer; a personnel management module for protecting the security of computer users; a comprehensive emergency response module for real-time protection and maintenance of the computer.
[0060] Refer to Figure 2As shown in the figure, the physical protection module includes the reinforcement of doors, windows and walls to physically reinforce the interior where the computer is placed, preventing external personnel from entering the interior where the computer is placed through doors, windows and walls, stealing computer and hardware data such as hard drives, and also preventing external personnel from entering the interior where the computer is placed to damage the computer; monitoring equipment monitoring, installing monitoring equipment in the interior and exterior of the room where the computer equipment is placed for real-time monitoring, and multiple monitoring equipment are set up to form a non-blind spot monitoring, so as to be able to monitor the interior of the computer storage room in real-time and without blind spots in the background monitoring room, thereby improving the security of computer storage; fire, water and theft prevention equipment, waterproof and theft-proof walls and doors and windows are set up in the interior and exterior of the room where the computer is placed, and multiple layers of waterproof layers are set, and fire prevention equipment is set in the interior where the computer is placed. By applying multiple waterproof layers and adding equipment such as carbon dioxide fire extinguishers, the waterproof and fire prevention capabilities of the computer are improved, and the reinforcement of doors, windows and walls can also improve the anti-theft ability of the computer; networked alarm equipment, alarm lines are set on the interior wall side and doors and windows of the room where the computer is placed, and are connected to the alarm device in real-time through the network for use in case of damage. When there is malicious damage to the walls and doors and windows, the alarm lines set in the walls will emit alarm signals due to short circuits, and the alarm signals will be transmitted to the monitoring background in real-time, so as to remind the monitoring background personnel to check the monitoring and handle it, thereby improving the external security of the computer.
[0061] Reference Figure 3As shown in the figure, the network protection module includes: integrated chip encrypted transmission. On various types of interfaces of the computer, an integrated chip is fixedly installed for encrypted transmission to protect the transmitted data, thereby achieving the purpose of protecting the data transmitted by the computer through the interface. Software that is not encrypted and transmitted through the integrated chip cannot be transmitted through the computer interface, effectively preventing unauthorized data theft; network software monitoring and authentication connection, which is used to monitor and authenticate the software installed in the computer for network connection, protect the software installed in the computer, and prevent the installation of unauthenticated software, thereby preventing the arbitrary installation of software in the computer and preventing network vulnerabilities from occurring in the computer due to the installation and use of software, and preventing the leakage of data in the computer from the network vulnerabilities; network access control, which controls the network connection of the networked computer, grants access rights to authenticated secure websites, and blocks access rights to unauthenticated network websites, thereby preventing the computer from accidentally clicking on any link when using the network, causing the computer to connect to a non-secure link and enter a non-secure website, resulting in the leakage of computer data during network transmission; network firewall, which is deployed between the internal network and the external network (such as the Internet), or between network areas with different trust levels, as a security barrier to prevent potential unauthorized access, malware propagation, data leakage and other security threats. The network firewall provides secondary protection for network websites and network transmissions, thereby improving the security of the computer when using the network.
[0062] Reference Figure 4 As shown in the figure, the network software monitoring and authentication connection includes: symmetric encryption algorithm, which is used for the computer to use the same key or two keys that can be simply deduced from each other during the encryption and decryption processes. The symmetric encryption algorithm has the characteristics of fast encryption and decryption speed and is suitable for large-volume data encryption processing; asymmetric encryption algorithm, the computer uses a pair of keys (public key and private key) to perform data encryption and decryption operations. These two keys are mathematically related and cannot be deduced from one another. The asymmetric encryption algorithm has the characteristic of high security. Even if the public key is leaked, the private key cannot be deduced from the public key, thus ensuring the security of the encrypted information; hash algorithm, which divides the input data in the computer into several blocks of equal or unequal length (called message blocks), and then performs a series of complex operations (such as bit operations, shift operations, modulo operations, exclusive OR operations, etc.) on each message block, and finally obtains a fixed-length output value for encryption settings. The hash algorithm has the characteristic that the conversion process is one-way, that is, it is usually impossible to reverse-deduce the original data from the hash value. Through multiple algorithm encryptions, it can ensure that the computer has higher security and has the ability to provide multi-layer encryption protection for confidential data;
[0063] Meanwhile, for user privilege management, separate user accounts are set up for computer users. Different usage accounts are assigned different usage privileges to restrict and protect the content accessed and transmitted on the computer, thereby preventing unauthorized personnel from obtaining confidential information and enhancing the security of the information accessed on the computer.
[0064] Reference Figure 5 As shown in the reference, the software protection module includes: operating system protection, which is used to protect the computer operating system, restrict the upgrade and downgrade of the operating version or the installation of a new operating system, thereby limiting the replacement of the computer system and preventing vulnerabilities from existing during the replacement of the computer system, which could otherwise allow unauthorized personnel to access computer information; application program and database protection, which restricts and protects the application programs installed on the computer, specifies specific download or installation channels, blocks downloads from arbitrary websites, and restricts the arbitrary download and installation of programs on the computer, thereby preventing the intrusion of programs such as Trojan viruses during program installation and causing the leakage of information on the computer; the software protection module also includes integrated software anti-virus. A specific integrated anti-virus software is installed on the computer, which has the function of anti-virus with network restrictions and anti-virus in the absence of a network, thereby enhancing the anti-virus ability of the computer, enabling anti-virus both when connected to the network and in the absence of a network, and the anti-virus software is integrated and can have multiple anti-virus methods, thereby enhancing the protection ability of the computer; malicious software protection function. A protection program is set up on the computer to prevent the installation of programs entering through non-specified websites and non-specified data transmission channels and alert the integrated anti-virus software for processing.
[0065] Reference Figure 6 As shown in the reference, the personnel management module includes: employee background investigation, which investigates the job types and work directions of computer-using employees, and refuses computer access to non-professional employees, thereby avoiding damage to computer programs caused by non-professional employees using the computer and also avoiding the transmission of unknown files by professional personnel; privilege classification management, which classifies the computer usage privileges of employees corresponding to different job types and restricts and controls the privileges for accessing and transmitting information, thereby preventing the arbitrary transmission and use of confidential files; the personnel management module also includes employee security awareness training, which regularly trains employees on computer usage rules to enhance their ability to use the computer in a standardized manner and improve the security of computer use at the subjective level of employees; external access personnel privilege restriction, which provides dedicated access personnel privilege accounts for external access personnel using the computer to prevent the access and transmission of internal computer information.
[0066] Reference Figure 7As shown in the figure, the comprehensive emergency response module includes: integrating safety information and data, and on the computer cloud platform and the background, real-time controlling the computer access website and the transmitted materials. When the materials in the computer are viewed and transmitted, it can monitor the viewers and transmitters, and can also monitor the viewed and transmitted materials in the background to prevent unauthorized personnel from viewing and transmitting materials, resulting in data leakage; real-time monitoring and management, real-time controlling and managing the indoor and outdoor monitoring of computer use, monitoring and managing non-users at this time, and preventing unauthorized users from privately using the computer to view and transmit materials; the comprehensive emergency response module also includes abnormal alarm and warning, alarming and warning the behavior of obtaining information and materials in the computer through abnormal channels, and displaying the alarm screen in real time during monitoring, facilitating the background to manage the users in real time; data security maintenance, regularly maintaining and protecting the data in the computer, ensuring the integrity of the materials in the computer and the feasibility of the computer itself, and avoiding the loss of materials caused by the damage of the internal materials of the computer.
[0067] Working principle: Through the encrypted transmission of the integrated chip, on multiple types of interfaces of the computer, an integrated chip is fixedly set for encrypted transmission to protect the transmitted materials, so as to achieve the purpose of protecting the materials transmitted through the interface of the computer. Software that is not encrypted and transmitted through the integrated chip cannot be transmitted through the computer interface, effectively preventing the unauthorized use of materials. Network software monitoring and authentication connection is used to monitor and authenticate the networking of the software installed in the computer, protect the software installed in the computer, and prevent the installation of non-authenticated software, thereby preventing the arbitrary installation of software in the computer, and thus preventing the leakage of computer data from the networking loopholes caused by the installation and use of software in the computer. Network access control controls the network connection of the networked computer, grants access rights to the authenticated secure website, and blocks access rights to the unauthenticated network website, thereby preventing the computer from accidentally clicking on any link when using the network, resulting in the computer accessing a non-safe link and entering a non-safe website, causing the leakage of computer data through network transmission. The network firewall is deployed between the internal network and the external network (such as the Internet), or between network regions with different trust levels, as a security barrier to prevent potential unauthorized access, malware propagation, data leakage and other security threats. Through the network firewall, the network website and network transmission are protected again to improve the security of the computer when using the network.
[0068] The above are only the preferred embodiments of the present application, and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A computer information security monitoring and encryption protection system, characterized in that The computer information security monitoring and encryption protection system includes: A physical protection module, configured to protect computer information security from the outside; A network protection module, configured to achieve network security protection when the computer is connected to the network; A software protection module, configured to protect the internal software and data of the computer; A personnel management module, configured to protect the security of computer users; A comprehensive emergency response module, configured to protect and maintain the real-time use of the computer.
2. The computer information security monitoring and encryption protection system according to claim 1, characterized in that: The network protection module achieves network full protection by the following means: Integrated chip encryption transmission, by fixedly setting an integrated chip on multiple types of interfaces of the computer to perform encryption transmission and protect the security of the transmitted data; Network software monitoring and authentication connection, by monitoring and authenticating the software installed in the computer for network connection to protect the security of the software installed in the computer and prevent the installation of unauthenticated software; Network access control, by controlling the network connection of the networked computer, opening access permissions for the authenticated secure website addresses and blocking access permissions for the unauthenticated network website addresses; Setting up a network firewall, deployed between the internal network and the external network, or between network regions with different trust levels, as a security barrier to prevent potential unauthorized access, malicious software propagation, and data leakage.
3. The computer information security monitoring and encryption protection system according to claim 2, characterized in that: The network software monitoring and authentication connection is achieved by the following method: Encryption settings are performed by using symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms; Among them, the encryption setting by using the hash algorithm includes: dividing the input data in the computer into several message blocks of equal or unequal lengths, and then performing a series of operations on each message block, including: bit operation, shift operation, modulo operation, exclusive OR operation, and finally obtaining a fixed-length output value for encryption setting; Alternatively, through user privilege management, separate user accounts are set for computer users, and different usage privileges are given corresponding to different usage accounts to restrict and protect the content viewed and transmitted by the computer.
4. The computer information security monitoring and encryption protection system according to claim 1, wherein: The software protection module performs security protection in the following ways, including: Operating system protection, used for protecting the computer operating system, restricting the upgrade and downgrade of the operating version, or installing a new operating system; Application program and database protection, restricting and protecting the application programs installed in the computer, specifying a specific download channel or installation channel, and preventing downloading and using from any website address.
5. The computer information security monitoring and encryption protection system according to claim 4, wherein: The software protection module also performs security protection in the following ways, including: Integrated software anti-virus, installing specific integrated anti-virus software in the computer, which has the function of anti-virus with network restrictions and the function of anti-virus without network; Malicious software protection, setting up a protection program in the computer to prevent the installation of programs entering through non-specified website addresses and specified data transmission paths, and alerting the integrated anti-virus software for processing.
6. The computer information security monitoring and encryption protection system according to claim 1, characterized in that: The personnel management module is achieved by the following ways, including: Employee background investigation, investigating the job types and work directions of the computer employees used, and refusing non-professional employees to use the computer; Hierarchical permission management is carried out for employees corresponding to different types of work. The computer usage permissions are hierarchically classified, and the permissions for accessing and transmitting information are restricted and controlled.
7. The computer information security monitoring and encryption protection system according to claim 6, characterized in that: The personnel management module is also implemented in the following ways, including Employee safety awareness training, regularly training employees on computer usage rules to enhance their ability to use computers in a standardized manner; External access personnel permission restriction. For external access personnel using computers, dedicated access accounts are provided to prevent the internal information of the computer from being accessed and transmitted.
8. The computer information security monitoring and encryption protection system according to claim 1, wherein: The comprehensive emergency response module is implemented by the following methods, including: Coordinating security information and data, and conducting real-time control over computer access URLs and transmitted information on the computer cloud platform and the background; Real-time monitoring and management, conducting real-time monitoring and management of indoor and outdoor monitoring of computer usage, and monitoring and managing non-users during that time.
9. The computer information security monitoring and encryption protection system according to claim 8, characterized in that: The comprehensive emergency response module is also implemented by the following methods, including: Abnormal alarm and warning, alarming and warning against behaviors of obtaining information and data in the computer through abnormal channels, and displaying the alarm screen in real time during monitoring; Data security maintenance, regularly maintaining and protecting the data in the computer to ensure the integrity of the information in the computer and the feasibility of the computer itself.
10. The computer information security monitoring and encryption protection system according to claim 1, characterized in that: The physical protection module includes strengthening the doors, windows, and walls to physically reinforce the room where the computer is placed; Monitoring device monitoring, installing monitoring devices indoors and outdoors where the computer equipment is placed for real-time monitoring, and multiple monitoring devices are set up to form a non-blind spot monitoring; Fire, water, and theft prevention equipment, waterproof and theft-proof walls and doors and windows are set up indoors and outdoors where the computer is placed, and multiple layers of waterproof layers are set, and fire prevention equipment is set up indoors where the computer is placed; Networked alarm equipment, alarm lines are set up on the indoor walls and doors and windows where the computer is placed, and are connected to the alarm device in real time through the network for use in case of damage.