Printing encryption method, system and device
Through dynamic hierarchical key generation and risk entropy value model, combined with user behavior analysis, the problem of key reuse and early warning lag in existing printing encryption technology is solved, and efficient printing security management and real-time early warning are achieved.
Patent Information
- Application Number
- CN202510487245.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-08-01
AI Technical Summary
In the existing printing encryption technology, dynamic elements such as user identity, device information and timestamps are not fully utilized, resulting in reuse of keys, which is easy to be stolen or cracked, lacks a layered key system and permission control, and the early warning system lacks correlation analysis between high-frequency non-authorization periods and key combination mode, resulting in high warning noise and lag in emergency response.
The dynamic hierarchical key generation method is adopted, and the master key seed is generated by combining the timestamp, device MAC address and user number, and the content encryption key, permission control key and watermark generation key are derived, and the unauthorized event matrix and risk entropy value model are constructed. High-frequency users are identified through clustering analysis, their key combination preferences are monitored and real-time warnings are warned.
It realizes dynamic encryption and permission binding of document content, improves printing security, reduces the risk of document leakage, improves the scientific nature of risk control and emergency response speed, and reduces the probability of unauthorized events.
Smart Images

Figure CN120408664A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of printing encryption technology, and in particular to a printing encryption method, system and device. Background Art
[0002] As an important port for outputting sensitive data, the security of printing devices directly affects the information security of enterprises or institutions. With the growth of the demand for electronic document encryption, traditional printing encryption technologies have gradually revealed various deficiencies and urgently need more efficient and intelligent solutions.
[0003] Existing solutions mostly use a single static or periodically replaced key, without generating a unique key by combining dynamic elements such as user identity, device information, and timestamp. This results in the repeated use of the key when the same user prints multiple times, which is easily stolen by malicious programs or obtained through brute force cracking. Traditional solutions lack a hierarchical key system and the binding of permission control and content encryption.
[0004] Existing warning systems rely on a single feature to trigger, lacking the correlation analysis of high-frequency unauthorized time periods and key combination patterns. This leads to a large amount of warning noise and little effective information, and it is impossible to predict risks through user behavior patterns before an attack occurs. The emergency response lags behind the attack behavior and it is difficult to block unauthorized printing in real time.
[0005] Therefore, the present invention provides a printing encryption method, system and device. Summary of the Invention
[0006] The purpose of the present invention is to provide a printing encryption method, system and device to solve at least one of the above-mentioned existing technical problems.
[0007] A printing encryption method includes the following steps:
[0008] Generate a dynamic hierarchical key and encrypt and print the document to be printed;
[0009] Identify unauthorized events after encrypted printing, extract the event features of the unauthorized events and construct an unauthorized event matrix;
[0010] Construct a risk entropy value model based on the unauthorized event matrix, obtain the risk entropy index of different dynamic hierarchical keys, and use the dynamic hierarchical key with the highest risk entropy index value as the printing risk key;
[0011] Used to extract the user features corresponding to the printing risk key, perform cluster analysis on the user features to identify high-frequency users, and judge whether the unauthorized events of high-frequency users are limited to the printing risk key;
[0012] If not limited, used to perform a preference analysis on the key combinations of the unauthorized events of high-frequency users, determine the key combinations of high-frequency users, and monitor and warn the printing of high-frequency users.
[0013] As a further technical solution of the present invention:
[0014] The dynamic hierarchical key includes:
[0015] Content encryption key, permission control key, watermark generation key.
[0016] As a further technical solution of the present invention: The method for constructing the unauthorized event matrix is as follows:
[0017] Obtain unauthorized events, extract the probabilities of unauthorized events of the dynamic hierarchical key of unauthorized encrypted printing, the interruption time ratio of interrupted printing services, and the probability events of failed traceability of printing service problems, and construct an unauthorized event matrix based on the event characteristics thus formed.
[0018] As a further technical solution of the present invention: The method for constructing the risk entropy value model is as follows:
[0019] Perform normalization processing on the unauthorized event matrix;
[0020] Calculate the risk entropy and event characteristic weights of the normalized event matrix;
[0021] Calculate the risk entropy index of different dynamic hierarchical keys based on the risk entropy and event characteristic weights.
[0022] As a further technical solution of the present invention: The method for determining whether the unauthorized events of high-frequency users are limited to the printing risk key is as follows:
[0023] Obtain the unauthorized events of the printing risk key, and filter out the unauthorized events of failed traceability of printing service problems to obtain traceable user events;
[0024] Obtain the user characteristics corresponding to each traceable user event and construct a user characteristic group;
[0025] Extract high-frequency users through cluster analysis based on the traceable user events and the corresponding user characteristics;
[0026] Conduct event limitation analysis on the unauthorized events of high-frequency users to determine the event limitation rate of high-frequency users;
[0027] Compare the user limitation rate with a preset user limitation threshold to determine whether the unauthorized events of high-frequency users are limited to the printing risk key.
[0028] As a further technical solution of the present invention: The method for determining the event limitation rate of high-frequency users is as follows:
[0029] Obtain the unauthorized events of high-frequency users, construct a decision classification tree, and extract the event limitation rate of each high-frequency user.
[0030] As a further technical solution of the present invention, the method for constructing a decision classification tree is as follows:
[0031] Obtain high-frequency user unauthorized events and perform tagging on high-frequency users;
[0032] Construct a decision classification tree based on the tags of all high-frequency users;
[0033] Extract the user limitation rate based on the decision classification tree.
[0034] As a further technical solution of the present invention, the method for determining the key combination of high-frequency users is as follows:
[0035] Obtain the occurrence probabilities of unauthorized events of all high-frequency users during different printing periods, and take the period with the largest occurrence probability value as the high-frequency unauthorized period;
[0036] During the high-frequency unauthorized period, extract unauthorized events of high-frequency users with different dynamic hierarchical keys during the same printing period, perform preference combination on different dynamic keys, and construct a key preference group;
[0037] Perform intersection analysis on the key preference groups of all high-frequency users to extract high-frequency key preferences;
[0038] Real-time monitor the printing behavior of high-frequency users. When a high-frequency user uses a dynamic hierarchical key in the high-frequency key preference, give a warning notice to the user to reduce the probability of unauthorized events of high-frequency users.
[0039] A printing encryption system includes the following modules:
[0040] Document encryption module: used to generate dynamic hierarchical keys and encrypt and print the document to be printed;
[0041] Event analysis module: identify unauthorized events after encrypted printing, extract event features of unauthorized events and construct an unauthorized event matrix;
[0042] Key identification module: construct a risk entropy value model based on the unauthorized event matrix, obtain the risk entropy index of different dynamic hierarchical keys, and take the dynamic hierarchical key with the highest risk entropy index value as the printing risk key;
[0043] Limitation analysis module: used to extract user characteristics corresponding to the printing risk key, perform clustering analysis on user characteristics to identify high-frequency users, and determine whether the unauthorized events of high-frequency users are limited to the printing risk key;
[0044] Monitoring and warning module: if not limited, used to perform preference analysis on the key combination of unauthorized events of high-frequency users, determine the key combination of high-frequency users, and monitor and give early warnings to the printing of high-frequency users.
[0045] A printing encryption device includes the following modules:
[0046] Print task access module: used to receive user print requests, collect basic information, verify the legality of user identities, and reject unauthorized print requests; transfer legitimate tasks and preset print policies to the dynamic hierarchical key generation module;
[0047] Dynamic hierarchical key generation module: construct dynamic hierarchical keys based on the collected basic information;
[0048] Document encryption module: encrypt documents using dynamic hierarchical keys;
[0049] Print policy execution module: parse the encryption keys and control policies in the encrypted document before printing, monitor unauthorized printing behaviors in real time, and monitor and give early warnings for the printing of high-frequency users.
[0050] Advantages of the present invention:
[0051] 1. By collecting the timestamp, device MAC address, and user number in real time to generate the master key seed, and deriving three types of dynamic hierarchical keys (CEK / PCK / WMK) based on HKDF, hierarchical protection for document content encryption, permission policy binding, and dynamic anti-counterfeiting watermark generation is achieved; a three-dimensional security protection system is constructed from three aspects: content encryption, permission control, and post-event traceability, which is beneficial to reducing the risk of document leakage.
[0052] 2. Construct an unauthorized event matrix, generate the risk entropy index of dynamic hierarchical keys through normalization processing and entropy value calculation, locate high-risk keys, be able to quantify the risk level, provide data support for key optimization and policy adjustment, avoid the fuzzy evaluation of traditional security solutions, improve the scientificity and pertinence of printing risk control, screen high-frequency users based on the clustering algorithm, judge whether their unauthorized events are concentrated on printing risk keys, distinguish between the scenarios of single-key high-frequency abuse and multi-key mixed attacks, and avoid misjudgment or missed judgment: for users limited to risk keys, the protection of this key can be strengthened specifically; if not limited, further analyze the key combination preferences of users to implement differentiated security policies and improve resource utilization efficiency;
[0053] 3. For non-limited high-frequency users, through statistical analysis of high-frequency unauthorized time periods and key combination intersection analysis, extract the key preference groups commonly used frequently, and monitor printing behaviors in real time. When it is detected that a user uses a high-frequency key combination during the preference period, an early warning is triggered, which is beneficial to reducing the probability of unauthorized events occurring and improving the emergency response speed. Description of the Drawings
[0054] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0055] Figure 1 is a flowchart of a printing encryption method of the present invention;
[0056] Figure 2 is a flowchart of the construction method of the decision classification tree of the present invention;
[0057] Figure 3 is a module diagram of a printing encryption system provided by the present invention;
[0058] Figure 4 is a module diagram of a printing encryption device of the present invention. Specific Embodiments
[0059] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0060] Embodiment 1
[0061] As Figure 1 shown, a printing encryption method provided by an embodiment of the present invention specifically includes the following steps:
[0062] S1. Generate a dynamic hierarchical key and perform encrypted printing on the document to be printed;
[0063] The generation method of the dynamic hierarchical key is as follows:
[0064] Preferably, the time stamp of the current printing system, the MAC address of the printing device, and the user number of the printing application are collected in real time as basic information, and the basic information is fused through the SHA-3-512 hash algorithm to generate a 256-bit master key seed;
[0065] Obtain the master key seed and use the HKDF key derivation function to generate a dynamic hierarchical key;
[0066] It should be noted that HKDF is a standardized cryptographic tool used to securely derive multiple keys for different purposes from the initial key material; it generates a pseudorandom key from the input material using a salt value and the HMAC function to enhance the randomness of the output; it combines the key usage identifier to generate a derived key of the target length;
[0067] Derive three dynamic hierarchical keys from the master key seed of a fixed length, which can meet the requirements of hierarchical key management;
[0068] Among them, the dynamic hierarchical keys include the content encryption key (CEK), the permission control key (PCK), and the watermark generation key (WMK);
[0069] S101. Content Encryption Key (CEK): Used to encrypt the actual content of the document to be printed, and encrypt the document content in the AES-256-GCM mode;
[0070] Those skilled in the art can understand that each printed document corresponds to a unique set of CEKs. Even if the same user prints the same content at different times, the CEKs will be different due to the change of the timestamp;
[0071] S102. Permission Control Key (PCK): Used to encrypt the printing permission policy of the document, including the time window and the copy limit allowed for printing;
[0072] Those skilled in the art can understand that the printing permission policy is bound to the key. Unauthorized users cannot modify the key or bypass the key restrictions, and the printing permission policy is dynamically generated with the key;
[0073] S103. Watermark Generation Key (WMK): Used to generate a dynamic anti-counterfeiting watermark, which includes the user number, the timestamp, and the MAC address of the printing device;
[0074] Those skilled in the art can understand that the dynamic anti-counterfeiting watermark is hidden in the pixels, colors, or textures of the document. The dynamic anti-counterfeiting watermark is invisible to the naked eye but can be extracted by a dedicated tool for tracing the source of document encryption leakage afterwards;
[0075] Encrypt and print the document to be printed through the dynamic hierarchical key;
[0076] It should be noted that the functions of generating the dynamic hierarchical key and encrypting and printing the document to be printed are as follows:
[0077] Function 1: Enhance data confidentiality. The content encryption key in the dynamic hierarchical key uses an advanced encryption algorithm to encrypt the document content page by page, converting the document data into ciphertext form. This encryption method ensures that even if an attacker obtains the printed data, they cannot decrypt and read the content without the correct key, effectively resisting threats such as network attacks and data interception;
[0078] Function 2: Strengthen permission management. The permission control key (PCK) is responsible for encrypting printing policies, including restrictions such as the number of copies and time window. Before printing, the printing device will parse the PCK and related policies, and perform real-time verification on the current time, device MAC address, user permissions, etc. Only when all conditions meet the preset policies is the printing operation allowed. For example, for important confidential documents, it can be set to only allow a specific number of copies to be printed by a specific user on a specific device within a specific time period, precisely controlling the printing behavior and preventing overprinting, overtime, or unauthorized printing;
[0079] Function 3: Enhance data traceability. The watermark generation key (WMK) is used to generate an invisible anti-counterfeiting watermark containing information such as user ID, timestamp, and device MAC address, and embed it into the pixel layer of the document. These watermarks are invisible to the naked eye but can be extracted and recognized by special tools. Once an unauthorized printing event occurs, by extracting the information in the watermark, it is possible to quickly and accurately trace the user who printed, the device used, and the time of printing, providing strong evidence for event investigation and liability determination.
[0080] S2. Identify unauthorized events after encrypted printing, extract the event characteristics of unauthorized events, and construct an unauthorized event matrix;
[0081] The method for identifying unauthorized events after encrypted printing is as follows:
[0082] It should be further noted that since the core function of the CEK is to encrypt the document content through the AES-256-GCM mode to ensure that only authorized users can decrypt and print, the determination method for unauthorized events of the content encryption key is as follows:
[0083] Method 1: Key theft or cracking. An attacker obtains the CEK through malicious programs, phishing attacks, etc., or forges a legitimate CEK through brute force cracking, side-channel attacks, etc., decrypts the document content, and prints it;
[0084] Method 2: Key abuse. An authorized user illegally shares the CEK (such as extracting the key through screenshots, memory theft tools), resulting in an unauthorized user using the key to decrypt and print the document;
[0085] Since the PCK is used to encrypt printing permission policies (such as time window, copy limit) to ensure that the printing behavior conforms to the preset rules;
[0086] The determination method for unauthorized events based on the PCK is as follows:
[0087] Method 1: Policy bypass: An attacker tampers with or forges the permission policy associated with the PCK (e.g., by reverse engineering the permission control logic) to bypass time restrictions (e.g., printing during prohibited hours) or copy limits (e.g., excessive printing).
[0088] Method 2: Exploiting key expiration: When the PCK becomes invalid due to a permission change (such as user permission expiration), the attacker can bypass permission checks and execute printing by caching the remaining valid PCK or forging the key signature.
[0089] Since WMK is used to generate invisible dynamic anti-counterfeiting watermarks, it can be used to trace the source of the leak afterwards.
[0090] It does not directly control printing, but is related to the first two;
[0091] The method for determining unauthorized events based on the watermark generation key (WMK) is as follows:
[0092] Method 1: Watermark tampering or forgery: The attacker tampered with the watermark information generated by WMK before printing (such as deleting the user number and timestamp), or forged a false watermark to conceal the true identity of the leaker, indirectly achieving "traceless" illegal printing.
[0093] Method 2: Exploiting a key failure: If the WMK is not correctly embedded in the document (e.g., an abnormal encryption process results in the watermark being missing), an attacker can exploit this vulnerability to print, making it impossible to trace the watermark later, effectively resulting in unauthorized printing.
[0094] The unauthorized event matrix is constructed as follows:
[0095] Obtain unauthorized events, extract the probability of occurrence of unauthorized encrypted printing dynamic layered key unauthorized events, the interruption time ratio of printing business interruptions, and the probability of tracing the source of printing business problem failures, and construct an unauthorized event matrix based on these event features;
[0096] Analyze and extract unauthorized events from the printer's device logs, including the probability of occurrence of unauthorized encrypted printing dynamic layered key unauthorized events, the interruption time ratio of printing business interruptions, and the probability of tracing the failure of printing business problems.
[0097] Based on the probability of occurrence of unauthorized events of dynamic hierarchical keys for unauthorized encrypted printing, the interruption time ratio of printing business interruption, and the probability of tracing the failure of printing business problems, an unauthorized event matrix X is constructed. ij ;
[0098] Where i and j represent the row number and column number of the unauthorized event matrix respectively;
[0099] Exemplary unauthorized event matrix, where P represents the probability of the occurrence of an unauthorized event of the dynamic hierarchical key. For example, P CEK represents the probability of the occurrence of an unauthorized event of the content encryption key CEK;
[0100] I represents the interruption time ratio of the printing service interruption in the unauthorized event of the dynamic hierarchical key. For example, I CEK represents the interruption time ratio of the printing service interruption when the content encryption key CEK appears;
[0101] U represents the probability of failure traceability of the printing service problem in the unauthorized event of the dynamic hierarchical key. For example, U CEK represents the probability of failure traceability of the printing service problem of the content encryption key CEK;
[0102] Those skilled in the art can understand that by obtaining the number of unauthorized events of the dynamic hierarchical key and the total number of events of the dynamic hierarchical key;
[0103] The ratio of the number of unauthorized events of the dynamic hierarchical key to the total number of events of the dynamic hierarchical key is processed to obtain the probability of the occurrence of the unauthorized event;
[0104] The interruption time ratio of the printing service interruption is obtained by obtaining the ratio of the duration of the printing service interruption to the total service duration when the unauthorized event of the dynamic hierarchical key occurs;
[0105] The interruption time ratio of the printing service interruption reflects the impact degree of the unauthorized event on the normal operation of the printing service;
[0106] The probability of failure traceability of the printing service problem refers to the probability that the responsible party or the source of the event cannot be determined after the occurrence of the unauthorized event of the dynamic hierarchical key;
[0107] The number of unauthorized events of the dynamic hierarchical key and the number of times of determining the responsible party or the source of the event are obtained, and the ratio of the number of unauthorized events of the dynamic hierarchical key to the number of times of determining the responsible party or the source of the event is processed to obtain the probability of failure traceability of the printing service problem;
[0108] The probability of failure traceability of the printing service problem reflects the traceability ability of the system;
[0109] It should be noted that the function of constructing the unauthorized event matrix is as follows: integrating the probability of the unauthorized event of the dynamic hierarchical key, the interruption time ratio of the printing service, and the probability of failure traceability, quantifying the unauthorized risk, providing a data basis for the risk entropy value model to locate high-risk keys, and comprehensively reflecting the security status of the printing system, covering aspects such as business continuity and traceability ability, and providing strong data support for decisions such as judging the limitations of high-frequency user events and analyzing key combination preferences.
[0110] S3. Construct a risk entropy value model based on the unauthorized event matrix to obtain the risk entropy indices of different dynamically layered keys, and take the dynamically layered key with the highest risk entropy index value as the printing risk key;
[0111] Among them, the construction method of the risk entropy value model is as follows:
[0112] S301. Normalize the unauthorized event matrix X ij ;
[0113] Normalize each column of the unauthorized event matrix X ij to obtain the normalized event matrix X′ ij ;
[0114] S302. Calculate the risk entropy e ij and the event feature weight w j of the normalized event matrix X′ j ;
[0115] The calculation method of the risk entropy is as follows:
[0116] Through the formula: Obtain the entropy value e j of the j-th event feature; [[ID=·37]]
[0117] Among them, n is the total number of rows of the normalized event matrix;
[0118] Through the formula: Obtain the event feature weight w j ;
[0119] Among them, m is the total number of columns of the normalized event matrix;
[0120] S303. Calculate the risk entropy indices of different dynamically layered keys based on the risk entropy e j and the event feature weight w j ;
[0121] Through the formula: Obtain the risk entropy index H CEK of the content encryption key (CBK);
[0122] Among them, X (CEK,j) represents the row of the normalized event matrix belonging to the content encryption key CBK
[0123] Through the formula: Obtain the risk entropy index H PCK of the permission control key (PCK);
[0124] Through the formula: Obtain the risk entropy index H of the watermark generation key (WMK)WMK ;
[0125] Use the dynamic hierarchical key with the highest risk entropy index value as the printing risk key.
[0126] It should be noted that the role of identifying the printing risk key is as follows:
[0127] Function 1. Locate security risks. By constructing a risk entropy value model to analyze the unauthorized event matrix, identifying the dynamic hierarchical key with the highest risk entropy index value as the printing risk key can accurately locate the link where security problems are most likely to occur during printing;
[0128] Function 2. Focus on high-frequency user risk control. Identifying the printing risk key provides a basis for the subsequent analysis and management of high-frequency users; by analyzing the user characteristics corresponding to the unauthorized events related to the printing risk key, high-frequency users can be accurately identified, and whether their unauthorized events are limited to the printing risk key can be judged.
[0129] The technical solution of this embodiment is: generate a dynamic hierarchical key and perform encrypted printing on the document to be printed; identify unauthorized events after encrypted printing, extract the event characteristics of unauthorized events and construct an unauthorized event matrix; construct a risk entropy value model based on the unauthorized event matrix to obtain the risk entropy index of different dynamic hierarchical keys, and use the dynamic hierarchical key with the highest risk entropy index value as the printing risk key; locate high-risk keys, which can quantify the risk level and provide data support for key optimization and policy adjustment.
[0130] Embodiment 2
[0131] As Figure 1 shown, a printing encryption method further includes the following steps:
[0132] S4. Extract the user characteristics corresponding to the unauthorized events of the printing risk key, perform clustering analysis on the user characteristics to identify high-frequency users, and judge whether the unauthorized events of high-frequency users are limited to the printing risk key;
[0133] Obtain the unauthorized events of the printing risk key, and filter out the unauthorized events that fail to trace the source of printing service problems to obtain traceable user events;
[0134] Obtain the user characteristics corresponding to each traceable user event and construct a user characteristic group;
[0135] Among them, the user characteristic group includes: user number, occurrence probability of unauthorized events;
[0136] Based on the traceable user events and the corresponding user characteristics, perform frequency clustering analysis through a clustering algorithm to identify high-frequency user clustering groups;
[0137] Those skilled in the art can understand that the high-frequency user clustering groups are obtained by using clustering algorithms. Based on tracing user events and their corresponding user characteristics, frequency clustering analysis is carried out using clustering algorithms. Clustering algorithms such as K-means and DBSCAN are selected, and the probability of unauthorized events occurring is used as the core feature. The similarity of this feature between users is calculated, for example, the Euclidean distance is used to measure it. According to the preset parameters and rules of the algorithm, users with similar probabilities of unauthorized events occurring are divided into the same clustering group. By comparing the probability means of each clustering group, the clustering group with a significantly higher probability of unauthorized events occurring is identified, that is, the high-frequency user clustering group;
[0138] Extract the users in the high-frequency user clustering group as high-frequency users;
[0139] Those skilled in the art can understand that there are multiple users in the high-frequency user clustering group;
[0140] Among them, whether the unauthorized events of high-frequency users are limited to the way of printing risk keys is as follows:
[0141] Obtain the unauthorized events of high-frequency users, construct a decision classification tree, and extract the event limitation rate of each high-frequency user;
[0142] As Figure 2 shown, the construction method of the decision classification tree is as follows:
[0143] S401. Obtain the unauthorized events of high-frequency users and perform labeling processing on high-frequency users;
[0144] Obtain the total number of unauthorized events of a single high-frequency user and the number of events of a single high-frequency user belonging to printing risk keys;
[0145] Calculate the ratio of the number of events of a single high-frequency user belonging to printing risk keys to the total number of unauthorized events of a single high-frequency user to obtain the proportion of improved events, marked as Key_Ratio;
[0146] Label high-frequency users based on the proportion of improved events Key_Ratio;
[0147] Exemplarily, if Key_Ratio≥80%, the high-frequency user label Flag = 1, indicating that the high-frequency user is limited to printing risk keys. If Key_Ratio<80%, the high-frequency user Flag = 0, indicating that the high-frequency user is not limited to printing risk keys;
[0148] S402. Construct a decision classification tree based on the labels of all high-frequency users;
[0149] Obtain the tags of all high-frequency users, take the improved event ratio Key_Ratio as the splitting feature, and determine the splitting point of the decision classification tree through the dichotomy method;
[0150] S403. Based on the decision classification tree, extract the user confinement rate;
[0151] Each high-frequency user falls into a unique leaf node along the decision tree path, and the ratio of the confined samples in the node is the event confinement rate of the user;
[0152] It can be understood that using the decision classification tree to calculate the user confinement rate can integrate the multi-dimensional printing behavior data of high-frequency users, such as the total number of unauthorized events, the number of events belonging to the printing risk key, etc. for classification; the dichotomy method is used to improve the event ratio (Key_Ratio) splitting node to display the decision-making process; it is beneficial to handle the complex relationships and uncertainties in the printing security scenario;
[0153] Exemplarily, if a leaf node contains 50 high-frequency users, and 45 of them have Key_Ratio≥80%, then the user confinement rate of this node = 45 / 50 = 90%;
[0154] Compare the user confinement rate with the preset user confinement threshold. If the user confinement rate is higher than or equal to the preset user confinement threshold, it is considered that the unauthorized events of high-frequency users are confined to the printing risk key;
[0155] If the user confinement rate is lower than the preset user confinement threshold, it is considered that the unauthorized events of high-frequency users are not confined to the printing risk key;
[0156] It should be noted that the function of judging that the unauthorized events of high-frequency users are not confined to the printing risk key is as follows:
[0157] Function 1. Identify complex risks. In printing security management, if only the printing risk key is concerned, potential risks in other aspects of high-frequency users may be ignored. Judging that the unauthorized events of high-frequency users are not confined to the printing risk key can help security managers discover the complex situation where high-frequency users use multiple keys for unauthorized printing;
[0158] Function 2. Optimize the risk prevention and control strategy. When it is determined that high-frequency users have unauthorized printing behaviors that are not confined to the printing risk key, the security team can adjust the original prevention and control strategy centered on a single risk key. Instead of only focusing on strengthening the protection of the printing risk key, it comprehensively analyzes all unauthorized behaviors of high-frequency users, formulates more comprehensive and detailed prevention and control measures for the multiple key combinations they use, and improves the pertinence and effectiveness of security protection;
[0159] Function 3: Improve the early warning mechanism, which helps to improve the early warning mechanism for printing security. If the unauthorized events of high-frequency users are not limited to printing risk keys, it is necessary to expand the scope of early warning monitoring. Not only the usage of printing risk keys should be monitored, but also the usage patterns of other types of keys by high-frequency users at different times should be concerned. Once it is found that a high-frequency user uses a specific key combination during the high-frequency unauthorized period, and this combination matches the high-frequency key preference obtained from the previous analysis, the system can issue an early warning in a timely manner, enabling security managers to take measures in advance to prevent unauthorized printing events and reduce security risks.
[0160] S5. If not limited, conduct a preference analysis on the key combinations of the unauthorized events of high-frequency users, determine the key combinations of high-frequency users, and monitor and give early warnings to the printing of high-frequency users;
[0161] The method for conducting a preference analysis on the key combinations of the unauthorized events of high-frequency users is as follows:
[0162] Obtain the occurrence probabilities of the unauthorized events of all high-frequency users during different printing periods, and take the period with the largest occurrence probability value as the high-frequency unauthorized period;
[0163] During the high-frequency unauthorized period, extract the unauthorized events of high-frequency users with different dynamic hierarchical keys during the same printing period, combine different dynamic keys for preference, and construct a key preference group;
[0164] Obtain the key preference groups of all high-frequency users for intersection analysis, and extract high-frequency key preferences;
[0165] It should be noted that the method of combining set intersection operation and frequency statistics is used to extract high-frequency key preferences: First, regard the key preference group of each high-frequency user as an independent set, calculate the intersection of all sets or the key combinations that frequently appear together, count the occurrence frequencies of each key combination in the preference group, set a frequency threshold (such as the key combination commonly included by more than 50% of high-frequency users), and extract the key combinations that meet the conditions as high-frequency key preferences, so as to reflect the key combination patterns commonly preferred by the high-frequency user group in unauthorized events;
[0166] Monitor the printing behavior of high-frequency users in real time. When a high-frequency user uses the dynamic hierarchical key in the high-frequency key preference, give an early warning notice to the user to reduce the probability of unauthorized events of high-frequency users.
[0167] The technical solution of this embodiment is as follows: extract the user characteristics corresponding to the unauthorized events of the printing risk key, perform clustering analysis on the user characteristics to identify high-frequency users, and determine whether the unauthorized events of the high-frequency users are limited to the printing risk key; if not, perform preference analysis on the key combinations of the unauthorized events of the high-frequency users to determine the key combinations of the high-frequency users, and monitor and warn the printing of the high-frequency users; when it is detected that the user uses the high-frequency key combination during the preference period, an alarm is triggered, which is beneficial to reducing the probability of unauthorized events and improving the emergency response speed.
[0168] Embodiment III
[0169] As Figure 3 shown, a printing encryption system includes the following modules:
[0170] Document encryption module: used to generate a dynamic hierarchical key and encrypt and print the document to be printed;
[0171] The generation method of the dynamic hierarchical key is:
[0172] Obtain the master key seed and use the HKDF key derivation function to generate the dynamic hierarchical key;
[0173] Among them, the dynamic hierarchical key includes a content encryption key (CEK), a permission control key (PCK), and a watermark generation key (WMK).
[0174] Event analysis module: identify unauthorized events after encrypted printing, extract the event characteristics of unauthorized events and construct an unauthorized event matrix;
[0175] The construction method of the unauthorized event matrix is:
[0176] Obtain unauthorized events, extract the event characteristics composed of the probability of unauthorized events of the dynamic hierarchical key of unauthorized encrypted printing, the interruption time ratio of the printing service interruption, and the probability event of tracing the source of the failure of the printing service problem, and construct an unauthorized event matrix;
[0177] Analyze and extract unauthorized events from the device logs of the printer, and extract the probability of unauthorized events of the dynamic hierarchical key of unauthorized encrypted printing, the interruption time ratio of the printing service interruption, and the probability of tracing the source of the failure of the printing service problem;
[0178] Based on the probability of unauthorized events of the dynamic hierarchical key of unauthorized encrypted printing, the interruption time ratio of the printing service interruption, and the probability of tracing the source of the failure of the printing service problem, construct an unauthorized event matrix X ij ;
[0179] Where i and j respectively represent the row number and column number of the unauthorized event matrix.
[0180] Key identification module: Based on the unauthorized event matrix, construct a risk entropy value model to obtain the risk entropy index of different dynamically stratified keys, and use the dynamically stratified key with the highest risk entropy index value as the printing risk key;
[0181] Among them, the construction method of the risk entropy value model is as follows:
[0182] S301. Normalize the unauthorized event matrix X ij ;
[0183] S302. Calculate the risk entropy e ij and the event feature weight w j of the normalized event matrix X′ j ;
[0184] S303. Based on the risk entropy e j and the event feature weight w j calculate the risk entropy index of different dynamically stratified keys;
[0185] Use the dynamically stratified key with the highest risk entropy index value as the printing risk key.
[0186] Limitation analysis module: Used to extract the user characteristics corresponding to the unauthorized events of the printing risk key, perform clustering analysis on the user characteristics to identify high-frequency users, and judge whether the unauthorized events of high-frequency users are limited to the printing risk key;
[0187] Obtain the unauthorized events of the printing risk key, and filter out the unauthorized events that fail to trace the source of printing business problems to obtain the traced user events;
[0188] Obtain the user characteristics corresponding to each traced user event and construct a user characteristic group;
[0189] Among them, the user characteristic group includes: user number, occurrence probability of unauthorized events;
[0190] Based on the traced user events and the corresponding user characteristics, perform frequency clustering analysis through a clustering algorithm to identify high-frequency user clustering groups;
[0191] Extract the users in the high-frequency user clustering group as high-frequency users;
[0192] Among them, the method for judging whether the unauthorized events of high-frequency users are limited to the printing risk key is as follows:
[0193] Obtain the unauthorized events of high-frequency users, construct a decision classification tree and extract the event limitation rate of each high-frequency user;
[0194] Among them, the construction method of the decision classification tree is as follows:
[0195] S401. Obtain unauthorized events of high-frequency users and perform tagging on high-frequency users;
[0196] S402. Based on the tags of all high-frequency users, construct a decision classification tree;
[0197] S403. Based on the decision classification tree, extract the user limitation rate;
[0198] Compare the user limitation rate with a preset user limitation threshold. If the user limitation rate is higher than or equal to the preset user limitation threshold, it is considered that the unauthorized events of high-frequency users are limited to printing risk keys;
[0199] If the user limitation rate is lower than the preset user limitation threshold, it is considered that the unauthorized events of high-frequency users are not limited to printing risk keys.
[0200] Monitoring and warning module: If not limited, it is used to perform preference analysis on the key combinations of unauthorized events of high-frequency users, determine the key combinations of high-frequency users, and monitor and warn the printing of high-frequency users;
[0201] The method for performing preference analysis on the key combinations of unauthorized events of high-frequency users is as follows:
[0202] Obtain the occurrence probabilities of unauthorized events of all high-frequency users during different printing time periods, and take the time period with the largest occurrence probability value as the high-frequency unauthorized time period;
[0203] During the high-frequency unauthorized time period, extract the unauthorized events of high-frequency users with different dynamic hierarchical keys during the same printing time period, perform preference combination on different dynamic keys, and construct a key preference group;
[0204] Obtain the intersection analysis of the key preference groups of all high-frequency users and extract the high-frequency key preferences;
[0205] Real-time monitor the printing behavior of high-frequency users. When high-frequency users use the dynamic hierarchical keys in the high-frequency key preferences, give a warning notice to the users to reduce the probability of unauthorized events of high-frequency users.
[0206] Embodiment 4
[0207] As Figure 4 shown, a printing encryption device includes the following modules:
[0208] Printing task access module: Used to receive user printing requests and collect basic information, verify the legitimacy of user identities, and reject unauthorized printing requests; Transfer legitimate tasks and preset printing policies to the dynamic hierarchical key generation module;
[0209] Dynamic hierarchical key generation module: Based on the collected basic information, construct dynamic hierarchical keys;
[0210] Document Encryption Module: Encrypts documents using dynamic hierarchical keys;
[0211] Print Policy Execution Module: Parses the encryption keys and control policies in the encrypted document before printing, monitors unauthorized printing behaviors in real time, and monitors and gives early warnings for the printing of high-frequency users.
[0212] The above has described an embodiment of the present invention in detail, but the content described is only the preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.
Claims
1. A printing encryption method, characterized in that, Including the following steps: Generate a dynamic hierarchical key and perform encrypted printing on the document to be printed; Identify unauthorized events after encrypted printing, extract the event features of unauthorized events, and construct an unauthorized event matrix; Construct a risk entropy value model based on the unauthorized event matrix, obtain the risk entropy index of different dynamic hierarchical keys, and use the dynamic hierarchical key with the highest risk entropy index value as the printing risk key; Used to extract the user features corresponding to the printing risk key, perform clustering analysis on the user features to identify high-frequency users, and determine whether the unauthorized events of high-frequency users are limited to the printing risk key; If not limited, used to perform preference analysis on the key combinations of unauthorized events of high-frequency users, determine the key combinations of high-frequency users, and monitor and warn the printing of high-frequency users.
2. The printing encryption method according to claim 1, wherein The dynamic hierarchical key includes: Content encryption key, permission control key, watermark generation key.
3. A printing encryption method according to claim 1, characterized in that, The method for constructing the unauthorized event matrix is: Obtain unauthorized events, extract the probability of occurrence of unauthorized events of the dynamic hierarchical key of unauthorized encrypted printing, the interruption time ratio of printing service interruption, and the probability of failure traceability of printing service problems, and construct an unauthorized event matrix.
4. A printing encryption method according to claim 1, wherein The method for constructing the risk entropy value model is: Perform normalization processing on the unauthorized event matrix; Calculate the risk entropy and event feature weights of the normalized event matrix; Calculate the risk entropy index of different dynamic hierarchical keys based on the risk entropy and event feature weights.
5. A printing encryption method according to claim 1, characterized in that, The method for determining whether the unauthorized events of high-frequency users are limited to the printing risk key is: Obtain the unauthorized events of the printing risk key, and filter out the unauthorized events of printing service problem failure traceability to obtain the traced user events; Obtain the user features corresponding to each traced user event and construct a user feature group; Extract high-frequency users through clustering analysis based on the traced user events and the corresponding user features; Perform event limitation analysis on the unauthorized events of high-frequency users to determine the event limitation rate of high-frequency users; Compare the user limitation rate with a preset user limitation threshold to determine whether the unauthorized events of high-frequency users are limited to the printing risk key.
6. A printing encryption method according to claim 5, characterized in that, The method for determining the event limitation rate of high-frequency users is: Obtain the unauthorized events of high-frequency users, construct a decision classification tree, and extract the event limitation rate of each high-frequency user.
7. A printing encryption method according to claim 6, characterized in that, The method for constructing the decision classification tree is: Obtain the unauthorized events of high-frequency users and perform tagging on high-frequency users; Construct a decision classification tree based on the tags of all high-frequency users; Based on the decision classification tree, extract the user limitation rate.
8. A printing encryption method according to claim 1, characterized in that The method for determining the key combination of high-frequency users is: Obtain the probability of occurrence of unauthorized events of all high-frequency users in different printing time periods, and use the time period with the largest probability value as the high-frequency unauthorized time period; In the high-frequency unauthorized time period, extract the unauthorized events of different dynamic hierarchical keys that high-frequency users appear in the same printing time period, perform preference combination on different dynamic keys, and construct a key preference group; Obtain the key preference groups of all high-frequency users for intersection analysis and extract high-frequency key preferences; Real-time monitor the printing behavior of high-frequency users, and when high-frequency users use the dynamic hierarchical key in the high-frequency key preference, give a warning notice to the user.
9. A printing encryption system for implementing a printing encryption method according to any one of claims 1-8, characterized in that, Including the following modules: Document Encryption Module: used to generate dynamic hierarchical keys and encrypt the document to be printed; Event Analysis Module: identify unauthorized events after encrypted printing, extract the event features of unauthorized events and construct an unauthorized event matrix; Key Identification Module: build a risk entropy value model based on the unauthorized event matrix, obtain the risk entropy index of different dynamic hierarchical keys, and take the dynamic hierarchical key with the highest risk entropy index value as the printing risk key; Limitation Analysis Module: used to extract the user characteristics corresponding to the printing risk key, perform cluster analysis on the user characteristics to identify high-frequency users, and judge whether the unauthorized events of high-frequency users are limited to the printing risk key; Monitoring and Early Warning Module: if not limited, used to perform preference analysis on the key combinations of unauthorized events of high-frequency users, determine the key combinations of high-frequency users, and monitor and give early warnings for the printing of high-frequency users.
10. A printing encryption device, characterized in that, It includes the following modules: Print Task Access Module: used to receive user printing requests and collect basic information, verify the legitimacy of user identities, and reject unauthorized printing requests; transfer legitimate tasks and preset printing policies to the dynamic hierarchical key generation module; Dynamic Hierarchical Key Generation Module: construct dynamic hierarchical keys based on the collected basic information; Document Encryption Module: encrypt the document using dynamic hierarchical keys; Print Policy Execution Module: parse the encryption keys and control policies in the encrypted document before printing, monitor unauthorized printing behaviors in real time, and monitor and give early warnings for the printing of high-frequency users.