Private data protection method based on computer network

By performing timing division and abnormal analysis of communication data of smart wearable devices, and calculating risk values to update the key, the problem of insufficient key security in the prior art is solved and the security of private data is improved.

CN120474846AActive Publication Date: 2025-08-12BEIJING ZHIYI YANGFAN TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510970929.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-08-12
Estimated Expiration
2045-07-15

AI Technical Summary

Technical Problem

In the prior art, the privacy data protection method of smart wearable devices is difficult to effectively deal with complex network attacks, resulting in insufficient key security and the security of private data cannot be guaranteed.

Method used

By obtaining the communication data of the smart wearable device, dividing it into multiple time period data according to the timing information, analyzing the traffic abnormality characterization degree and monitoring the abnormal performance value, calculating the risk value, and updating the key based on the risk value, so as to change the key in a timely manner.

Benefits of technology

It improves the privacy data security of smart wearable devices, and realizes timely key replacement by accurately calculating risk values, enhancing communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474846A_ABST
    Figure CN120474846A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a privacy data protection method based on a computer network, and the method comprises the steps: obtaining communication data of intelligent wearable equipment; dividing reference data in the communication data according to time sequence information to obtain multiple pieces of time period data; determining traffic anomaly characterization degrees corresponding to the multiple pieces of time period data; based on the monitoring values of the multiple pieces of time period data, determining a total monitoring abnormal performance value of the multiple pieces of time period data; determining a risk value of current data in the multiple pieces of time period data based on the traffic anomaly representation degree corresponding to the multiple pieces of time period data and the total monitoring anomaly representation value; and on the basis of the risk value, updating the key of the current data in the multiple pieces of time period data. According to the method, the risk value of the data can be calculated more accurately, and the key is replaced in time according to the risk value, so that the security of the privacy data of the intelligent wearable device can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a privacy data protection method based on a computer network in the field of data processing technology. Background Art

[0002] With the rapid development of the Internet of Things (IoT), smartwatches and smart wearable devices have become a crucial component of the smart terminal ecosystem. By integrating sensors and advanced algorithms, these devices can monitor users' physiological indicators and provide personalized services. However, the widespread adoption of these devices also presents challenges in protecting privacy. The data collected by these devices is highly sensitive personal information. This data not only impacts the user's privacy but may also involve health information.

[0003] Related technologies for protecting private data encrypt data and ensure key security through regular key rotation. However, regular key rotation is difficult to protect against sophisticated network attacks. Longer key rotation intervals also make it difficult to ensure key security. However, rapidly rotating keys creates a significant burden, making it difficult to effectively ensure the security of private data. Summary of the Invention

[0004] In order to solve the technical problem that the existing technology cannot effectively guarantee the security of private data, the purpose of the present invention is to provide a method for protecting private data based on a computer network. The technical solution adopted is as follows: In a first aspect, an embodiment of the present invention provides a privacy data protection method based on a computer network, the method comprising: Obtain communication data from smart wearable devices; Dividing the reference data in the communication data according to the time sequence information to obtain data for a plurality of time periods; Determine the traffic anomaly characterization degree corresponding to the data of the multiple time periods; Determining a total monitoring abnormal performance value of the data in the multiple time periods based on the monitoring values of the data in the multiple time periods; Determining a risk value of current data in the plurality of time period data based on the flow anomaly characterization degrees corresponding to the plurality of time period data and the total monitored anomaly performance value; Based on the risk value, a key of current data in the plurality of time period data is updated.

[0005] In a second aspect, a privacy data protection device for a smart wearable device is provided, the device comprising: An acquisition module is used to obtain communication data of smart wearable devices; A division module, configured to divide the reference data in the communication data according to the timing information to obtain data for a plurality of time periods; A first determining module is used to determine the traffic anomaly characterization degree corresponding to the data of the multiple time periods; A second determining module is configured to determine a total monitoring abnormal performance value of the data in the plurality of time periods based on the monitoring values of the data in the plurality of time periods; A third determination module is configured to determine a risk value of current data in the plurality of time period data based on the flow anomaly characterization degrees corresponding to the plurality of time period data and the total monitored anomaly performance value; An updating module is configured to update a key of current data in the plurality of time period data based on the risk value.

[0006] In a third aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in the first aspect or any possible implementation of the first aspect.

[0007] In a fourth aspect, a computer-readable storage medium is provided, which stores a computer program code. When the computer program code runs on a computer, the computer executes the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0008] The present invention has the following beneficial effects: after obtaining the communication data of the smart wearable device, the reference data in the communication data is divided according to the time sequence information to obtain multiple time period data, and the flow anomaly characterization degree corresponding to the multiple time period data is determined, so that the flow anomaly characterization degree can be used to reflect whether the communication flow of the historical communication data is abnormal. Afterwards, the total monitoring anomaly performance value of the multiple time period data is determined based on the monitoring values of the multiple time period data. In this way, by analyzing the total monitoring anomaly performance value, it is possible to accurately reflect whether the monitoring value borne by the smart wearable device is abnormal. Finally, based on the flow anomaly characterization degree corresponding to the multiple time period data and the total monitoring anomaly performance value, the risk value of the multiple time period data is determined; and based on the risk value, the key of the current data in the communication data is updated. In this way, the total monitoring anomaly performance value of the time period data is calculated in combination with the monitoring value in the communication data of the smart wearable device, so that the risk value of the current data can be calculated more accurately, and the key can be replaced in time according to the risk value, thereby improving the security of the privacy data of the smart wearable device. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0010] Figure 1 This is a schematic diagram of the implementation process of the privacy data protection method based on a computer network provided by an embodiment of the present invention; Figure 2 This is another implementation flowchart of the computer network-based privacy data protection method provided by an embodiment of the present invention; Figure 3 This is another implementation flowchart of the computer network-based privacy data protection method provided by an embodiment of the present invention; Figure 4 This is another implementation flowchart of the privacy data protection method based on a computer network provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0011] To further illustrate the technical means and effectiveness of the present invention in achieving its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, describes in detail the specific implementation, structure, features, and effectiveness of the computer network-based privacy data protection method proposed by the present invention. In the following description, different references to "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.

[0012] In the description of the embodiments of the present invention, unless otherwise specified, " / " means or, for example, A / B can mean A or B: "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present invention, "multiple" refers to two or more than two.

[0013] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.

[0014] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0015] The following is a detailed description of the specific scheme of the privacy data protection method based on computer network provided by the present invention in conjunction with the accompanying drawings. Figure 1 , which shows a flowchart of a privacy data protection method based on a computer network provided by an embodiment of the present invention, the method comprising: 101. Acquire communication data of the smart wearable device.

[0016] Here, the communication records are obtained from the communication history records of the user end and the server end of the smart wearable device. The present invention uses the historical communication records of the previous 24 hours at the current moment as reference data. The communication between the user end and the server end of the smart wearable device is mainly divided into two communication modes: one is the question-and-answer mode, and the other is the monitoring mode.

[0017] Among them, the question-and-answer mode mainly involves the command interaction between the user side and the server side of the smart wearable device, that is, the server side sends a query or control command, and the user side returns the corresponding receipt data or adjusts the response parameters after receiving the query command to bring the user a more comfortable experience.

[0018] The monitoring mode is to continuously transmit various data to the server at a fixed frequency and interval. For example, the monitoring data of smart wearable devices is continuously transmitted so that the server can judge the user's comfort and adjust the shape and other parameters of the smart wearable device. All commands sent by the server to the user are obtained as query data in the reference data, and all control instructions are selected through the communication protocol content to obtain all control instruction sets A; all commands sent by the user to the server are obtained as transmission data in the reference data to obtain a data set B of all transmission period data. Since the transmission data contains multiple types of data, it is also necessary to divide it according to the communication address to obtain data sets of multiple transmission period data The data sets for each time period are collected data from various sensors on the smart wearable device, primarily monitoring data (monitoring data is typically distributed across multiple monitoring sensors to obtain more accurate data, so monitoring data typically includes data sets from multiple time periods). Additionally, the most recent L length of historical communication data is read as current data. In this embodiment of the present invention, L is 5.

[0019] 102. Divide the reference data in the communication data according to the time sequence information to obtain data for a plurality of time periods.

[0020] Here, the timing information includes the duration of the communication data and the time points along that duration. In some possible implementations, the duration corresponding to the reference data is divided according to the timing information to obtain multiple time periods; and the data of the reference data within each of the multiple time periods is determined to obtain the multiple time period data. Thus, by dividing the duration corresponding to the reference data in the communication data into multiple time periods, the reference data can be divided into multiple time period data, facilitating subsequent anomaly analysis of the data in each time period.

[0021] In some possible implementations, due to the large number of smart wearable devices in certain scenarios, the large number of devices on these devices, and the large amount of different types of data involved in the interaction between smart wearable devices and users, security vulnerabilities that could lead to key leaks are inevitable. When there is a risk of key leakage, attackers can imitate normal interaction data with the server to steal more private data.

[0022] These generated data can often be well disguised in a single data sensor, but the hidden data connections between multiple sensors are difficult to imitate. Therefore, the greater the change in the correlation among the various transmission data of the smart wearable device, the more abnormal the historical communication data is, the higher the risk of key leakage, and the more necessary the key replacement is.

[0023] In the reference data obtained above, the duration of the reference data is divided into the following time periods in units of 1 minute according to the timestamp: ,in, Indicates the mth period.

[0024] 103 : Determine traffic anomaly characterization levels corresponding to the data in the multiple time periods.

[0025] Here, in the historical communication records of the smart wearable device, abnormal signals are often reflected in the traffic. When the communication traffic data is abnormal, it is considered that the degree of abnormality of the signal is higher. In some possible implementations, the above step 103 can be achieved by Figure 2 The steps shown achieve: 201 : Determine statistical flow values of the data in the multiple time periods to obtain multiple statistical flow values.

[0026] Here, when obtaining data for each period After that, get the statistical traffic value of each time period data Since the data packet sent contains the data size, the statistical flow value can be obtained by accumulating the flow of multiple communications per minute.

[0027] 202 : Determine, based on the multiple statistical flow values, flow anomaly characterization degrees corresponding to the multiple time period data.

[0028] Here, multiple traffic clusters are obtained by clustering the multiple statistical traffic values. For example, K-means clustering is performed on the multiple statistical traffic values to obtain multiple traffic clusters. Then, based on the multiple traffic clusters, the traffic anomaly characterization levels corresponding to the multiple time periods are determined. Here, the difference between the statistical traffic value of any time period and the traffic value at the cluster center is calculated using the multiple traffic clusters. This difference is combined with the traffic variance to accurately calculate the traffic anomaly characterization level for each time period.

[0029] In some possible implementations, for any period of time, the cluster center flow value and flow variance of the cluster to which the data belongs are first determined; then, the difference between the statistical flow value of the data for that period of time and the cluster center flow value is determined; finally, based on the difference and the flow variance, the flow anomaly characterization degree corresponding to the data for that period of time is determined. In this way, by obtaining the statistical flow value of the data for each period of time, the flow anomaly characterization degree of the data for each period of time can be accurately calculated, thereby facilitating analysis of whether the data for each period of time exhibits flow anomalies.

[0030] Here, since the communication data of smart wearable devices is usually divided into two modes, working mode and static mode, the statistical traffic of each time period is set to K=2 for Kmeans clustering, and two traffic clusters W1 and W2 are obtained. Then, the mode of each cluster is obtained as the cluster center, and the traffic of the cluster center is , calculate the variance of flow values within the cluster ; The traffic anomaly characterization degree of each time period data is calculated according to the performance of the cluster to which it belongs, as shown in formula (1): (1); in: Indicates time period The flow value; For the period The cluster center flow value of the cluster to which it belongs; Indicates time period The flow variance of the cluster to which it belongs; Indicates time period The degree of traffic anomaly characterization.

[0031] 104 : Determine a total monitoring abnormal performance value of the data in the multiple time periods based on the monitoring values of the data in the multiple time periods.

[0032] Here, by using multiple monitoring sensors to collect the initial monitoring values of the data for each time period, multiple initial monitoring values of the data for each time period are obtained; and the average of the multiple initial monitoring values is determined as the monitoring value of the data for each time period. In this way, the initial monitoring values of the data for each time period are collected by monitoring sensors at multiple angles, and the average of the multiple initial monitoring values is used as the monitoring value of the data for each time period, so that the monitoring value of the data for each time period can be made more accurate. In some possible implementations, there are multiple initial monitoring values of multiple monitoring sensor data Bn in each time period, and the average of the initial monitoring values of each monitoring sensor is calculated. As the monitoring value of the time period to which the time period data belongs.

[0033] In some possible implementations, when communicating between the server and user ends of a smart wearable device, a large amount of sensor data is transmitted, including monitoring data collected by sensors at different locations. By analyzing these monitoring data, the user's usage habits and behavior patterns can be obtained.

[0034] When an attacker imitates normal interaction data to interact with the server, random imitation data is often generated. These imitation data can often be well disguised in a single data sensor, but the hidden data connection between multiple sensors is difficult to imitate. Therefore, the abnormality of the data can be judged by the connection between multiple monitoring data. When the user is using the smart wearable device normally, the overall monitoring data of the smart wearable device is relatively stable. Although there are certain changes in the individual monitoring data, the overall monitoring of multiple sensors is usually relatively stable. At the same time, since users may have different usage patterns, the overall performance of the monitoring data can be judged to be abnormal. Based on this, the above step 104 can be completed by Figure 3 The steps shown achieve: 301 : Cluster multiple monitoring values corresponding to the data of each time period to obtain monitoring clusters of the data of each time period.

[0035] Here, the monitoring values of multiple monitoring sensors Bn in each time period are calculated The sum is taken as the total monitoring value of each period , N represents the number of sensors, Represents the total monitoring value of the mth period. Total monitoring value Clustering is performed by mean shift as a clustering parameter. The mean shift sets the radius r = 1 kPa, and v monitoring clusters are obtained. , where each cluster represents a user's usage pattern.

[0036] 302 : Determine the degree of fluctuation of the monitoring value of the data in each time period based on the monitoring cluster corresponding to the data in each time period.

[0037] Here, in each usage pattern cluster Calculate data for each period Total monitoring value The variance is used as the fluctuation degree of the monitoring value .

[0038] 303 : Determine the degree of belonging to the cluster to which the data in each time period belongs based on the degree of fluctuation of the monitoring value of the data in each time period.

[0039] Here, for each period of data in the current data, obtain the cluster to which it belongs , calculate its belonging degree to the cluster to which it belongs, as shown in formula (2): (2); in: Indicates the period in the current data Overall monitoring; Indicates the time periods in the current data Belonging cluster Average total monitoring of Represents a cluster The monitoring volatility variance; Indicates the period in the current data The degree of belonging to the cluster to which it belongs.

[0040] 304. Determine abnormal performance of the total monitoring value of the data in each time period based on the attribution degree.

[0041] Here, the number of attribution changes cow in each period of the current data is obtained; the total monitoring abnormal performance value of the current data in each period of data is calculated, as shown in formula (3): (3); Among them: cow represents the number of changes in the monitoring data attribution of the current data of the smart wearable device. The larger the value, the more chaotic the changes in the sent data and the greater the degree of anomaly. There are multiple different clusters of data in the time period after clustering. Among them, the number of times that different clusters of data alternate in the time sequence of the current data segment is cow. Indicates the period in the current data =The degree of belonging to the cluster to which it belongs; L is the length of the current data; E represents the total monitoring abnormal performance value of the current data. In this way, by calculating the fluctuation degree of the monitoring value of the data in each period and analyzing the degree of belonging to the cluster category of the data in each period, we can accurately analyze the abnormal performance of the total monitoring value of the data in each period.

[0042] 105 : Determine risk values of the data in the multiple time periods based on the flow anomaly characterization degrees corresponding to the data in the multiple time periods and the total monitoring anomaly performance value.

[0043] When users use smart wearable devices, monitoring data fluctuates and changes. These changes are often caused by user habits. Due to these habits, there are certain connections between the monitoring data read by different sensors on smart wearable devices. That is, changes in monitoring data from sensors at different locations will cause corresponding changes in monitoring data at other locations. This connection is personalized and difficult to imitate. Therefore, the more dissimilar and unreasonable the monitoring performance of multiple monitoring sensors is from historical connections, the greater the degree of communication signal anomaly.

[0044] In some possible implementations, the total monitoring data collected by the user during normal use is relatively fixed, and the correlation between monitoring data at different locations is also strong. The more abnormal the total monitoring data in the current data is, and the more abnormal the correlation between monitoring data sets of different time periods is, the greater the degree of signal abnormality in the current data is, and the higher the risk of data transmission. Based on this, the above step 105 can be achieved by Figure 4 The steps shown achieve: 401 : Determine, based on the monitoring values of the data in the multiple time periods, the correlation of the overall monitoring data of the data in the multiple time periods.

[0045] Here, the monitoring correlation between the data in each time period and the monitoring correlation between the overall data are analyzed through the monitoring values of the data in each time period, and the risk value of the current data is calculated through the monitoring correlation.

[0046] In some possible implementations, the above step 401 may be implemented by the following steps 411 to 413 (not shown): 411 : Based on the monitoring values of the data in the multiple time periods, determine the data change correlation between the data in the multiple time periods and the difference in the monitoring data change amount.

[0047] 412. Based on the data change correlation and the difference in the monitoring data change amount, determine the monitoring correlation between the data in the multiple time periods to obtain multiple monitoring correlations.

[0048] 413. Determine the correlation of the overall monitoring data based on the multiple monitoring correlations.

[0049] In the above steps 411 to 413, since the change of monitoring data is often due to the change of the distribution of monitoring, and the change of the total monitoring value is small, the monitoring value set PN of the data set of each period of data is obtained as a first-order difference sequence ; Afterwards, calculate the average monitoring change within the data set for each period of time , where M represents the total number of elements in the monitoring value set PN. Calculate the variance in the difference sequence ; Then calculate the data change correlation between the data sets of each period, as shown in formula (4): (4); in: for Each element in represents the monitoring changes of the data set Bn of the period data in period m; The average monitored change of the data set Bn representing the period data; Represents the monitored changes of the dataset Bu in period m; The average monitored change of the data set Bu representing the period data; and They represent the monitoring difference variance of the data set Bn of the period data and the data set Bu of the period data respectively; Indicates the correlation between the pressure data changes of the dataset Bn and the dataset Bu of the period data. The closer the value of is to 1, the stronger the correlation between the two time periods. The closer it is to (-1), the stronger the reverse correlation. The closer it is to 0, the weaker the correlation. The correlation between the above data sets only reflects the synergistic relationship between data changes, and cannot express the relationship between the amount of change in data changes. Therefore, it is also necessary to calculate the relationship between the amount of change of each data set, that is, to monitor the difference in the amount of change of data, as shown in formula (5): (5); in: The average monitored change of the data set Bn representing the period data; The average monitored change of the data set Bu representing the period data; The difference in the amount of change in the monitoring data between the dataset Bn and the dataset Bu for the time period. The larger the value, the smaller the mutual influence of the monitoring changes between the two datasets. The monitoring correlation between the data in each time period is shown in formula (6): (6); in: Indicates the correlation between the monitoring data changes of dataset Bn and dataset Bu; Indicates the difference in the amount of change in monitoring data between dataset Bn and dataset Bu; Indicates the monitoring correlation when monitoring changes between datasets Bn and Bu for period data.

[0050] The above analysis shows that the total monitoring data collected during normal user use is relatively fixed, and the correlation between monitoring data at different locations is also strong. The more abnormal the total monitoring data in the current data is, and the more abnormal the relationship between monitoring data sets is, the greater the degree of signal abnormality in the current data is, and the higher the risk of data transmission. Obtain the correlation between the monitoring data sets mentioned above. , take the dataset Bu with the maximum correlation with the dataset Bn, and record the dataset Bu as the related dataset of the dataset Bn; the correlation of the overall monitoring data is shown in formula (7): (7); in: is the monitoring correlation between the dataset Bn of the time period data and its related dataset Bu; S represents the correlation of the overall monitoring data. In this way, by calculating the monitoring correlation of the data scaffolds of each time period, the correlation of the overall monitoring data can be accurately obtained.

[0051] 402 , the total monitoring abnormality performance value and the traffic abnormality representation degree are fused to obtain a fusion result.

[0052] Here, the total monitoring abnormality performance value and the flow abnormality representation degree are multiplied and averaged to obtain the fusion result.

[0053] 403. Determine the risk value of the current data based on the correlation and fusion result of the overall monitoring data.

[0054] Here, the risk value of the current data is obtained by dividing the correlation of the overall monitoring data by the fusion result. In some possible implementations, in the current data, the monitoring correlation SR of the current data is calculated based on the monitoring correlation between the data sets of the time period data to obtain the risk value of the current data, as shown in formula (8): (8); Among them: sigmoid() represents the activation function, which is used to map variables to between (0, 1). Indicates time period The degree of traffic anomaly characterization; It is the traffic anomaly characterization of the current data as a whole; E represents the abnormal performance value of the total monitoring value of the current data; S represents the correlation of the overall monitoring data; SR represents the correlation between the current monitoring data and the overall monitoring data. For example, by calculating the covariance between the current monitoring data and the overall monitoring data, the correlation between the current monitoring data and the overall monitoring data is obtained. c is a constant. In case the denominator is 0, the value is 1; DC represents the risk value of the current data, that is, the risk level of the current signal transmission. In this way, by combining the correlation of the overall monitoring data of each time period with the total monitoring abnormal performance value and the traffic anomaly characterization, the risk value of the current data can be accurately analyzed.

[0055] 106. Update the key of the current data in the plurality of time period data based on the risk value.

[0056] Here, the risk value is compared with a preset risk threshold. If the risk value exceeds the preset risk threshold, the key of the current data is replaced to obtain an updated key. Key verification is then performed on the updated key. If the updated key verification fails, the current data is marked and a prompt message is output. The prompt message can be a voice prompt, a text prompt, or other form of prompt. The preset risk threshold can be custom-set, for example, 0.5. Thus, by setting the risk threshold Y = 0.5, when the risk level exceeds the preset risk threshold, the communication risk is considered high, no longer secure, and there is a high risk of key leakage, requiring a key replacement. The key replacement is performed according to a preset key table or other methods. Key verification is then performed using the replaced key. If verification passes, the new key is considered to ensure communication security. If verification fails, the current data is marked as abnormal, and a prompt message is output to the system for subsequent processing by personnel. In this way, performing an emergency key replacement when communication risk is high can improve communication security, thereby enhancing the security of private data on smart wearable devices.

[0057] In an embodiment of the present invention, after obtaining the communication data of the smart wearable device, the reference data in the communication data is divided according to the timing information to obtain multiple time period data, and the flow anomaly characterization degree corresponding to the multiple time period data is determined, so that the flow anomaly characterization degree can be used to reflect whether the communication flow of the communication data is abnormal. Afterwards, the total monitoring anomaly performance value of the multiple time period data is determined through the monitoring values of the multiple time period data. In this way, by analyzing the total monitoring anomaly performance value, it can be accurately reflected whether the monitoring value borne by the smart wearable device is abnormal. Finally, based on the flow anomaly characterization degree corresponding to the multiple time period data and the total monitoring anomaly performance value, the risk value of the multiple time period data is determined; and based on the risk value, the key of the current data is updated. In this way, the total monitoring anomaly performance value of the time period data is calculated in combination with the monitoring values in the historical communication data of the smart wearable device, so that the risk value of the data can be calculated more accurately, and the key can be replaced in time according to the risk value, which can improve the security of the privacy data of the smart wearable device.

[0058] In some possible implementations, the division module is further used to divide the duration corresponding to the reference data according to the timing information to obtain multiple time periods; determine the data of the reference data in each of the multiple time periods to obtain the multiple time period data.

[0059] In some possible implementations, the first determination module is further configured to determine statistical flow values of the data in the multiple time periods to obtain multiple statistical flow values; and determine flow anomaly characterization degrees corresponding to the data in the multiple time periods based on the multiple statistical flow values.

[0060] In some possible implementations, the first determining module is further configured to cluster the multiple statistical traffic values to obtain multiple traffic clusters; and determine traffic anomaly characterization degrees corresponding to the multiple time period data based on the multiple traffic clusters.

[0061] In some possible implementations, the first determination module is also used to determine, for any time period data, the cluster center flow value and flow variance of the cluster to which the data of any time period belongs; determine the difference between the statistical flow value of the data of any time period and the cluster center flow value; and determine the flow anomaly characterization degree corresponding to the data of any time period based on the difference and the flow variance.

[0062] In some possible implementations, the second determination module is further used to use multiple monitoring sensors to collect initial monitoring values of the data for each time period, to obtain multiple initial monitoring values of the data for each time period; and to determine the average of the multiple initial monitoring values as the monitoring value of the data for each time period.

[0063] In some possible implementations, the second determination module is further used to cluster the multiple monitoring values corresponding to the data of each time period to obtain the monitoring cluster clusters of the data of each time period; based on the monitoring cluster clusters corresponding to the data of each time period, determine the degree of fluctuation of the monitoring values of the data of each time period; based on the degree of fluctuation of the monitoring values of the data of each time period, determine the degree of belonging to the cluster to which the data of each time period belongs; based on the degree of belonging, determine the abnormal performance of the total monitoring value of the data of each time period.

[0064] In some possible implementations, the third determination module is also used to determine the correlation of the overall monitoring data of the multiple time period data based on the monitoring values of the multiple time period data; fuse the total monitoring abnormality performance value and the flow abnormality characterization degree to obtain a fusion result; and determine the risk value of the current data based on the correlation of the overall monitoring data and the fusion result.

[0065] In some possible implementations, the third determination module is also used to determine the data change correlation and the difference in monitoring data change amounts between the multiple time period data based on the monitoring values of the multiple time period data; determine the monitoring correlation between the multiple time period data based on the data change correlation and the difference in monitoring data change amounts to obtain multiple monitoring correlations; and determine the correlation of the overall monitoring data based on the multiple monitoring correlations.

[0066] In some possible implementations, the update module is also used to replace the key of the current data to obtain an updated key if the risk value is greater than a preset risk threshold; perform key verification on the updated key; if the updated key verification fails, mark the current data and output a prompt message.

[0067] It should be noted that the above-mentioned order of the embodiments of the present invention is for description only and does not represent the advantages and disadvantages of the embodiments. The processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-tasking and parallel processing are also possible or may be advantageous. The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other. Each embodiment focuses on the differences from other embodiments. The above content is only a specific embodiment of the present invention, but the scope of protection of the present invention is not limited to this. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed by the present invention, which should be covered within the scope of protection of the present invention.

Claims

1. A privacy data protection method based on a computer network, characterized in that: The method comprises: Obtain communication data from smart wearable devices; Dividing the reference data in the communication data according to the time sequence information to obtain data for a plurality of time periods; Determine the traffic anomaly characterization degree corresponding to the data of the multiple time periods; Determining a total monitoring abnormal performance value of the data in the multiple time periods based on the monitoring values of the data in the multiple time periods; Determining a risk value of current data in the plurality of time period data based on the flow anomaly characterization degrees corresponding to the plurality of time period data and the total monitored anomaly performance value; Based on the risk value, a key of current data in the plurality of time period data is updated.

2. The privacy data protection method based on computer network according to claim 1, characterized in that: The reference data in the communication data is divided according to the time sequence information to obtain multiple time period data, including: Divide the duration corresponding to the reference data according to the time series information to obtain multiple time periods; The data of the reference data in each of the multiple time periods is determined to obtain the multiple time period data.

3. The privacy data protection method based on computer network according to claim 1, characterized in that: Determining the traffic anomaly characterization degree corresponding to the data in the multiple time periods includes: Determine statistical flow values of the data in the multiple time periods to obtain multiple statistical flow values; Based on the multiple statistical flow values, flow anomaly characterization degrees corresponding to the multiple time period data are determined.

4. The privacy data protection method based on computer network according to claim 3, characterized in that: The determining, based on the multiple statistical flow values, flow anomaly characterization degrees corresponding to the multiple time period data includes: Clustering the multiple statistical flow values to obtain multiple flow clusters; Based on the multiple traffic clusters, traffic anomaly characterization degrees corresponding to the multiple time period data are determined.

5. The privacy data protection method based on computer network according to claim 4, characterized in that: The determining, based on the multiple traffic clusters, traffic anomaly characterization degrees corresponding to the multiple time period data includes: For data in any period of time, determine the cluster center flow value and flow variance of the cluster to which the data in any period of time belongs; Determine the difference between the statistical flow value of the data in any period and the cluster center flow value; Based on the difference and the flow variance, a flow anomaly characterization degree corresponding to the data in any time period is determined.

6. The privacy data protection method based on computer network according to claim 1, characterized in that: Before determining the total monitoring abnormal performance value of the data in the multiple time periods based on the monitoring values of the data in the multiple time periods, the method further includes: Using multiple monitoring sensors to collect initial monitoring values of data for each time period to obtain multiple initial monitoring values of the data for each time period; The average of the multiple initial monitoring values is determined as the monitoring value of the data in each time period.

7. The privacy data protection method based on computer network according to claim 1, characterized in that: The determining, based on the monitoring values of the data in the multiple time periods, a total monitoring abnormal performance value of the data in the multiple time periods includes: Clustering the multiple monitoring values corresponding to the data in each time period to obtain monitoring clusters of the data in each time period; Determining the degree of fluctuation of the monitoring values of the data in each time period based on the monitoring clusters corresponding to the data in each time period; Determining the degree of belonging to the cluster to which the data in each time period belongs based on the degree of fluctuation of the monitoring value of the data in each time period; Based on the degree of attribution, the abnormal performance of the total monitoring value of the data in each time period is determined.

8. The privacy data protection method based on computer network according to claim 1, characterized in that: The determining, based on the flow anomaly characterization degrees corresponding to the data in the multiple time periods and the total monitored anomaly performance value, the risk value of the current data in the data in the multiple time periods includes: Determining, based on the monitoring values of the data in the multiple time periods, the correlation of the overall monitoring data of the data in the multiple time periods; Fusing the total monitoring abnormality performance value and the flow abnormality representation degree to obtain a fusion; Based on the correlation and fusion results of the overall monitoring data, the risk value of the current data is determined.

9. The computer network-based privacy data protection method according to claim 8, characterized in that: The determining, based on the monitoring values of the data in the multiple time periods, the correlation of the overall monitoring data of the data in the multiple time periods includes: Based on the monitoring values of the data in the multiple time periods, determining the data change correlation between the data in the multiple time periods and the difference in the monitoring data change amount; Determining monitoring correlations between the data in the multiple time periods based on the data change correlations and the difference in the monitoring data change amounts to obtain multiple monitoring correlations; Based on the multiple monitoring correlations, the correlation of the overall monitoring data is determined.

10. The privacy data protection method based on computer network according to claim 1, characterized in that: The updating, based on the risk value, of the key of the current data in the plurality of time period data includes: If the risk value is greater than a preset risk threshold, replacing the key of the current data to obtain an updated key; performing key verification on the updated key; If the updated key verification fails, the current data is marked and a prompt message is output.

Citation Information

Patent Citations

  • Industrial network security protection method and system, terminal and storage medium

    CN118827247A

  • End-to-end data processing method and device

    CN119051998A

  • Industrial Internet of Things safety monitoring method and system

    CN119449368A

  • Computer data security protection system based on computer network

    CN119652648A

  • Industrial data secure storage method and system based on block chain

    CN120012134A