Key management system for bank-enterprise direct connection multi-level encryption transmission

By collecting transaction parameters and encryption requirements in real time, combining key hierarchical constraints and update constraints, a multi-dimensional key performance response surface is built, sensitive areas are identified and optimal configurations are screened, and the problems of risk response lag and low management efficiency in the bank-enterprise direct-connected encryption solution are solved, and efficient management of dynamic security strategies is achieved.

CN120474850AActive Publication Date: 2025-08-12ZHEJIANG YOUCAI CLOUD CHAIN TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510980319.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-08-12
Estimated Expiration
2045-07-16

AI Technical Summary

Technical Problem

The existing bank-enterprise direct-connected encryption solution cannot collect transaction parameters in real time, resulting in lagging risk response, and the key configuration and encryption process cannot be dynamically adjusted, affecting security and management efficiency.

Method used

By collecting transaction parameters and encryption requirements in real time, combining key hierarchical constraints and update constraints, dynamic quantization and intelligent calibration of initial security parameters are carried out, multi-dimensional key performance response surfaces are built, surface sensitive areas are identified and optimal configuration vectors are filtered, and dynamic security policy adjustment is achieved.

Benefits of technology

It improves the security and management efficiency of the encryption system, reduces ineffective exploration in the optimization process, quickly locates key parameters, reduces computing resource consumption and management costs, and realizes the standardized process of key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474850A_ABST
    Figure CN120474850A_ABST
Patent Text Reader

Abstract

The invention discloses a bank-enterprise direct connection multi-level encryption transmission key management system, which relates to the technical field of encryption transmission, and comprises a first acquisition module, a second acquisition module, a configuration generation module, an evaluation screening module and a driving execution module, the technical key points are as follows: collecting transaction parameters and encryption requirements in different business scenes in real time, inputting the transaction parameters and the encryption requirements to a pre-constructed encryption requirement model, and outputting a risk amplitude; acquiring a first condition of a key grading constraint and a second condition of a key updating constraint to quantify the initial security parameter, and performing multi-dimensional disturbance simulation on the initial security parameter to generate a plurality of to-be-optimized configuration vectors; mapping a to-be-optimized configuration vector to a multi-stage encryption process, performing security collaborative evaluation based on time complexity and risk amplitude to obtain an evaluation result, constructing a multi-dimensional key efficiency response curved surface, identifying a curved surface sensitive area, screening an optimal configuration vector, and performing driving execution; according to the invention, the key security and management efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted transmission, and in particular to a key management system for multi-level encrypted transmission of direct bank-enterprise connections. Background Art

[0002] Direct bank-enterprise connectivity refers to an integration model whereby an enterprise's financial system (such as ERP, treasury management system, etc.) is directly connected to a bank's core business system via a dedicated interface. This allows for operations such as fund management, payments, and account information inquiries, achieving seamless integration between the enterprise and bank systems. This requires very high security. Encrypted transmission encrypts data transmitted between the enterprise and bank systems during direct bank-enterprise connectivity, ensuring that data cannot be stolen, tampered with, or forged during network transmission. The existing bank-enterprise direct connection encryption solution has the following shortcomings: On the one hand, traditional systems are unable to collect transaction parameters (such as IP address entropy and device fingerprint stability) in real time and input them into encryption demand models, resulting in risk output lagging behind attack behavior. Furthermore, key rotation cycles and encryption algorithm selection are preset based on historical experience and cannot dynamically respond to real-time risks (such as sudden DDoS attacks and new vulnerability disclosures). This significantly increases security risks. For example, when a branch encounters a targeted attack, it still needs to wait for the head office to adjust its strategy, resulting in response delays of several hours. On the other hand, the mapping relationship between key configuration and encryption process (generation, transmission, verification, and destruction) is rigid, and resources cannot be dynamically allocated according to real-time load, which affects encryption performance, causes delays in banking services, and reduces management efficiency. Summary of the Invention

[0003] (1) Technical problems solved In response to the shortcomings of the existing technology, the present invention provides a key management system for multi-level encrypted transmission in direct bank-enterprise connections. By real-time collection of transaction parameters and encryption requirements, combined with the first condition of key classification constraints and the second condition of key update constraints, dynamic quantification and intelligent calibration of initial security parameters are achieved: the risk amplitude is output in real time through the encryption requirement model, and security collaborative assessment is performed in combination with time complexity to identify surface sensitive areas. By focusing on sensitive areas and screening the optimal configuration vector, the problems raised in the background technology are solved.

[0004] (2) Technical solution To achieve the above objectives, the present invention is implemented through the following technical solutions: In the first aspect, the present application provides a key management system for multi-level encrypted transmission of direct bank-enterprise connections, the system comprising: The first acquisition module is used to collect transaction parameters and encryption requirements in different business scenarios in real time, input them into the pre-built encryption requirement model and output the risk range; The second acquisition module is used to obtain the first condition of the key hierarchical constraint and the second condition of the key update constraint, quantify the initial security parameters based on the first condition and the second condition, and obtain the time complexity; wherein the initial security parameters include: the initial authentication security level and the initial key rotation period, The configuration generation module is used to perform multi-dimensional perturbation simulation on the initial security parameters and generate several configuration vectors to be optimized; An evaluation and screening module is used to map the configuration vector to be optimized to the multi-level encryption process, perform a security collaborative evaluation based on time complexity and risk magnitude, obtain the evaluation results, construct a multidimensional key effectiveness response surface based on the evaluation results and the configuration vector to be optimized, identify the sensitive areas of the surface, and screen the optimal configuration vector; The driving execution module is used to drive the execution of the optimal configuration vector.

[0005] Furthermore, the transaction parameters include transaction amount, transaction IP address, transaction scenario and transaction timestamp, and the encryption requirements include at least key length and algorithm combination; the encryption requirement model includes at least feature extraction layer, matrix association layer and risk assessment layer.

[0006] Furthermore, the feature extraction layer extracts the time-frequency domain features of the transaction parameters based on wavelet transform; Matrix association layer: Based on time-frequency domain characteristics and combined with encryption requirements, a risk association matrix is constructed; Risk assessment layer: Based on the business risk association matrix and combined with the transaction topology map, an assessment rule set is formed to obtain risk feature points and risk time series. Wavelet decomposition is used to obtain several risk frequency bands. The energy entropy value of each frequency band is calculated and aggregated according to the preset first weight to obtain the second weight values of several risk frequency bands. Based on the second weight values of several risk frequency bands, the entropy values of each segment are weighted and fused to obtain the risk amplitude.

[0007] Furthermore, the first condition includes: the frequency of authentication failure and the encryption performance of each encryption level; wherein the encryption level includes the first level, the second level, and the third level; The encryption performance of each encryption layer includes: Obtain performance indicators for each encryption layer and calculate the average performance value for each encryption layer; the performance indicators include encryption and decryption delay rate and resource consumption; analyze the degree of dispersion between the performance indicators and the average performance value for each encryption layer, and dynamically determine the parameter adjustment range based on the degree of dispersion; Based on the risk magnitude and authentication failure frequency, a corresponding sample set is formed, and the loss value between samples is calculated. The security level is filtered in combination with the first condition, and the authentication security level with the smallest deviation from the current one is selected as the initial authentication security level based on the minimum deviation matching from the filtered historical data.

[0008] Furthermore, the second condition includes: attack frequency, attack computing power, and attack form; The key rotation period is the ratio of the key validity period to the comprehensive cracking degree, and the response value is obtained by analyzing the attack frequency distribution, including: The attack frequency and attack form in the preset time period are combined into two tuples and marked as frequency analysis groups; The attack computing power and attack form in the preset time period are combined into a second tuple and marked as a computing power analysis group. The frequency analysis group and computing power analysis group corresponding to the password exposure process are respectively combined into a frequency analysis space and a computing power analysis space; Mark the standard score of the frequency analysis group of the current measurement period in the frequency analysis space as the first cracking degree; The standard score of the computing power analysis group in the computing power analysis space during the current measurement period is marked as the second cracking degree; Set a standard score threshold. If the first or second cracking degree of the current measurement period exceeds the standard score threshold, it means that the current system is at risk of password leakage. At the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain the comprehensive cracking degree. The key rotation period data within the historical preset period is constrained by the second condition, and the initial key rotation period is obtained by averaging.

[0009] Furthermore, several configuration vectors to be optimized are generated, including: Identify a multi-parameter space based on the initial security parameters, where the parameter space includes at least the number of authentication factors, algorithm strength, time period, and trigger threshold; Based on the first and second conditions constraining the parameter space, the Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only within the constrained parameter space, which are combined to form a configuration vector to be optimized, and the configuration vector contains different authentication security levels and key rotation period combinations.

[0010] Furthermore, based on time complexity and risk magnitude, security collaborative assessment includes: Perform nonlinear transformation on time complexity and risk amplitude, establish a two-dimensional curve graph of time complexity-risk amplitude, and draw a corresponding standard curve graph. Overlay the two-dimensional curve graph and the standard curve graph to obtain the intersection area, difference area, non-overlapping total area and overlapping total area. Calculate the first ratio of the intersection area to the difference area, calculate the second ratio of the overlapping total area to the non-overlapping total area, multiply the first ratio and the second ratio, and take weighted difference between the first ratio, the second ratio and the product of the two ratios to obtain the evaluation result.

[0011] Furthermore, the step of constructing a multidimensional key efficiency response surface includes: combining the configuration vector to be optimized and its corresponding evaluation result to form a sample set S1={optimized configuration vector A, evaluation result B}; using a third-order polynomial response surface to construct a multidimensional key efficiency response curve B=f(A).

[0012] Furthermore, surface sensitive areas are identified and the optimal configuration is screened, including: Based on the multi-dimensional key effectiveness response curve, several peak areas are identified and used as candidate areas; Based on the candidate area, the corresponding mean and fluctuation values are obtained. Combined with the evaluation results, several judgment vectors are constructed. The judgment vectors are imported into the pre-built judgment model and the judgment results are output. When the judgment result obtained by any judgment vector is greater than the preset judgment threshold, the candidate area is marked as a surface sensitive area. Based on the surface sensitive area, all configuration vectors to be optimized are extracted to form a candidate configuration pool; The NSGA-II algorithm is used to generate the Pareto optimal solution set, and the configuration vector that meets the optimization objectives of maximizing the evaluation effect and minimizing the fluctuation value is screened and marked as the best configuration vector.

[0013] In a second aspect, the present application provides a key management method for multi-level encrypted transmission of direct bank-enterprise connections, the method comprising: Collect transaction parameters and encryption requirements in different business scenarios in real time, input them into the pre-built encryption requirement model and output the risk range; Obtaining a first condition of the key hierarchical constraint and a second condition of the key update constraint, and quantifying initial security parameters based on the first condition and the second condition; wherein the initial security parameters include: an initial authentication security level and an initial key rotation period; Perform multi-dimensional perturbation simulation on the initial security parameters to generate several configuration vectors to be optimized; map the configuration vectors to be optimized to the multi-level encryption process, obtain evaluation results based on time complexity and risk amplitude security collaborative evaluation, and construct a multi-dimensional key efficiency response surface based on the evaluation results and the configuration vectors to be optimized. Identify the sensitive areas of the surface, screen the optimal configuration, and drive the execution of the optimal configuration vector.

[0014] (3) Beneficial effects The present invention provides a key management system for bank-enterprise direct multi-level encrypted transmission, which has the following beneficial effects: 1. This invention generates several configuration vectors to be optimized by performing multi-dimensional perturbation simulations on initial security parameters. It then constructs a multi-dimensional key performance response surface to systematically analyze the impact of the interaction between various parameters on encryption performance. This method overcomes the limitations of traditional single-dimensional optimization, captures the multi-parameter coupling effect, and screens the optimal configuration from a global perspective, thereby improving the security and management efficiency of the encryption system. 2. This invention achieves dynamic quantification and intelligent calibration of initial security parameters by collecting transaction parameters and encryption requirements in real time, combining the first condition of key classification constraints and the second condition of key update constraints. The encryption requirement model outputs the risk magnitude in real time, and by combining the risk magnitude and time complexity, it conducts a collaborative security assessment and identifies sensitive areas on the surface. By focusing on sensitive areas, it can reduce ineffective exploration during the optimization process, quickly locate key parameters that play a decisive role in system performance, and improve optimization efficiency and accuracy. 3. Automatically execute the optimal configuration by filtering the driver module, further compressing redundant key management operations and reducing computing resource consumption and management costs; 4. Quantify security parameters based on key hierarchical constraints and update mechanisms to standardize key management (such as rotation cycles and authentication levels) and reduce the randomness and error rate of manual configuration. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 The figure is a schematic diagram of modules of a key management system according to an exemplary embodiment. DETAILED DESCRIPTION

[0016] The following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0017] Example 1: The embodiment of the present invention provides a key management system for multi-level encrypted transmission of direct bank-enterprise connections; Figure 1 is a module diagram of a key management system according to an exemplary embodiment; Figure 1 The system includes: a first acquisition module, a second acquisition module, a configuration generation module, an evaluation and screening module, and a driver execution module, and the first acquisition module, the second acquisition module, the configuration generation module, the evaluation and screening module, and the driver execution module are communicatively connected; The following is an explanation of each module: The first acquisition module collects transaction parameters, transaction topologies, and encryption requirements in different business scenarios in real time within a preset time period, inputs them into a pre-built encryption requirement model, and outputs the risk range; Among them, transaction parameters include transaction amount, transaction IP address, transaction scenario, and transaction timestamp; Encryption requirements include at least key length and algorithm combination; Business scenarios include data storage scenarios, regular transaction scenarios, and risky transaction scenarios; Transaction topology: Entities involved in each business scenario (e.g., users, service platforms, financial institutions) are used as nodes, and business relationships between nodes (e.g., capital flows) are used as edges. Based on business processes and transaction logic, nodes are connected through edges to form a transaction topology. This is used to visually display the relationships between entities in the transaction process and the flow paths of data and funds. Each node is assigned a unique identifier, type (e.g., user node, service node, data node), business role (e.g., buyer, seller, payment gateway), and permission level (e.g., general permission, administrator permission, advanced business permission). Each node is also assigned attributes such as edge direction (e.g., one-way capital flows), transmission protocol (e.g., HTTP, HTTPS), and latency requirements (e.g., maximum latency limit for real-time transactions). This completes the construction of the basic elements of the transaction topology constraint diagram. The encryption requirement model includes at least a feature extraction layer, a matrix association layer, and a risk assessment layer; Feature extraction layer: Extracts the time-frequency domain features of transaction parameters based on wavelet transform. This includes: using wavelet transform (e.g., db4 wavelet) to perform multi-resolution decomposition on the time-domain data of transaction amount sequence, transaction IP address sequence, transaction scenario sequence, and timestamp sequence, mapping them to the time-frequency domain space to obtain time-frequency domain features; Taking the transaction amount time series as an example, a three-layer wavelet decomposition can yield approximate components (low-frequency trends) and detailed components (high-frequency fluctuations). The high-frequency components correspond to abnormal features such as sudden large-value transactions. Matrix association layer: Construct risk association matrix based on time-frequency domain characteristics and encryption requirements; Among them, the representation of the risk correlation matrix is R m*n : ; In the formula, m represents the number of categories of time-frequency domain features, n represents the number of encryption requirements, and the matrix element r ij It represents the correlation strength between the i-th type of time-frequency domain features and the j-th type of encryption requirements, and the correlation strength is obtained based on the mutual information algorithm: Where x i Represents the time-frequency domain features, y j Indicates encryption requirements, represents the mutual information value; Risk Assessment Layer: Based on the business risk association matrix and combined with the transaction topology map, an assessment rule set is formed to obtain risk feature points and risk time series (e.g., arranging risk feature points in chronological order and aggregating them using a fixed window or sliding window). Wavelet decomposition is used to obtain several risk frequency bands. The energy entropy value of each frequency band is calculated and aggregated according to a preset first weight (e.g., high frequency bands have a higher weight, low frequency bands have a lower weight). Second weight values are obtained for several risk frequency bands. Based on the second weight values of several risk frequency bands, the entropy values of each segment are weighted and fused to obtain the risk magnitude. Example using python code: # Risk margin calculation def risk_amplitude(signal, weights=None): approx, details = wavelet_decompose(signal) all_coeffs = [approx] + details energy = [np.sum(np.square(c)) for c in all_coeffs] entropy = calculate_entropy(np.array(energy)) if weights is None: weights = np.array([0.2, 0.3, 0.3, 0.2]) # Preset the first weight (low frequency and 3 high frequencies) weights = weights * (entropy / np.sum(entropy)) # Generate the second weight ra = np.sum(weights * entropy) return ra Map the correlation strength in the risk correlation matrix to the nodes and edges of the transaction topology graph, and add risk weight attributes to the nodes and edges; Analyze the path structure of the transaction topology graph, determine mandatory nodes and optional nodes, set different path constraints for nodes of different risk levels based on risk weight attributes, and obtain structural constraint rules, where the structural constraint rules include at least one of a mandatory path constraint, a level restriction constraint, and a node mutual exclusion constraint; Analyze the temporal relationship between nodes and edges in the transaction topology graph to determine the sequence of transaction steps. Based on the risk weight attributes, set different time constraints for transaction steps of different risk levels to obtain timing constraint rules, and the timing constraint rules include at least one of a sequential execution constraint, a delay threshold constraint, and a state machine constraint. Analyze historical traffic data of nodes and edges in the transaction topology graph to determine traffic distribution characteristics, set different traffic restriction conditions for nodes and edges of different risk levels based on risk weight attributes, and obtain traffic constraint rules, where the traffic constraint rules include at least one of frequency limit constraints, capacity threshold constraints, and amount upper limit constraints; Based on the combination of structural constraints, timing constraints, and flow constraints, a set of assessment rules is formed to assess transaction risks. Based on the assessment rule set, a depth-first search (DFS) is performed on the nodes and edges of the transaction topology graph to identify risk feature points that violate the rules. For each risk feature point, a forward and backward time series is extracted to form a risk time series. Beneficial effects: By constructing a time-frequency domain encryption demand model, mapping the transaction characteristics in banking business scenarios from the time domain to the time-frequency domain, extracting implicit dynamic risk characteristics, and constructing a mathematical model directly related to encryption requirements, the limitations of traditional static risk assessment can be broken through, and the coupling characteristics of transaction data in the time and frequency dimensions can be captured, providing a quantitative basis for the dynamic adjustment of multi-level encryption strategies.

[0018] A second acquisition module is configured to acquire a first condition of the key hierarchical constraint and a second condition of the key update constraint, and quantify initial security parameters based on the first and second conditions; wherein the initial security parameters include: an initial authentication security level and an initial key rotation period; The first condition includes: the frequency of authentication failures and the encryption performance of each encryption level; wherein the encryption levels include the first level, the second level, and the third level; The encryption performance of each encryption layer includes: Obtaining performance indicators for each encryption layer, and obtaining an average performance value for each encryption layer based on the performance indicators; wherein the performance indicators include encryption and decryption delay rate and resource consumption; Analyzing the degree of dispersion between the performance indicators of each encryption level and the average performance value, and dynamically determining the parameter adjustment range based on the degree of dispersion; wherein the step of analyzing the degree of dispersion includes: selecting a dispersion indicator to quantitatively analyze the degree of dispersion between the performance indicators of each encryption level and the average performance value, the dispersion indicator including at least one of a standard deviation and an interquartile range; establishing a mapping relationship between the degree of dispersion and the parameter adjustment, and dynamically determining the parameter adjustment range based on the degree of dispersion; The discrete degree classification standard is as follows: setting the first threshold and the second threshold of discrete degree, When the dispersion degree is less than the first threshold, it indicates low dispersion; When the first threshold is less than or equal to the dispersion degree is less than or equal to the second threshold, it indicates medium dispersion; When the dispersion degree is greater than the second threshold, it indicates high dispersion; Dynamically adjusting at least one parameter of the encryption layer, including encryption algorithm complexity, data block fragment size, key length, and thread scheduling strategy, according to the determined parameter adjustment range; The initial authentication security level is determined based on the first condition, including: Within the adjustment range, the corresponding time complexity of each encryption level is extracted to evaluate the encryption performance; Among them, the calculation of time complexity is: ; Where T represents the time complexity, N is the data size, E AES Indicates the encryption time per unit data, C CPU Indicates the computing power of the CPU. L represents the encryption level, ranging from 1 to 3, including the first, second, and third levels. It is used to help understand and optimize the allocation of computing resources during the encryption process, adjust the encryption level, and achieve a balance between security and efficiency. It should be noted that the encryption process integrates forward security, search pattern security, and backward security features. Forward security is achieved through ECDHE key exchange and HMAC derivation-free rotation; search pattern security builds a secure index through symmetric / public key searchable encryption; backward security achieves historical data isolation through logical key tree and blockchain version management; the first level is a dynamic searchable encryption scheme that only meets forward security; the second level is an encryption scheme that simultaneously protects forward security and search pattern based on the first level; the third level is an encryption scheme that adds arbitrary strength of backward security to the second level, making it impossible for the server to access deleted ciphertext information; Based on the risk magnitude and authentication failure frequency, a sample set is formed: S0 = {risk magnitude, authentication failure frequency}. The loss value between samples is calculated. The security level is filtered based on the first condition. Based on the minimum deviation matching, the authentication security level with the smallest deviation from the current one is selected from the filtered historical data as the initial authentication security level. The loss value is calculated using Euclidean distance, expressed as the deviation between the current input sample and historical samples. Invalid samples are filtered out (for example, in a certain business scenario, a security level greater than 2 is required). Within the valid sample set, the sample with the smallest deviation from the current input is found, and the authentication security level of that sample is used as the initial authentication security level. Furthermore, if multiple samples have the same minimum distance, the sample with the highest authentication level is selected (for example, if L=2 and L=3 are both matched, L=3 is selected). Determining an initial key rotation period based on the second condition includes: The second condition includes: attack frequency, attack computing power, and attack form; Attack frequency: The frequency of historical attack events is collected through security logs of the target system or similar systems (such as intrusion detection system (IDS) and firewall logs); Attack computing power: Quantify the GPU / ASIC computing power available to attackers (known hacker groups, unknown hacker groups, and individual attacks) (e.g., 10^15 hash operations per second). The higher the computing power, the shorter the rotation cycle. Attack forms: zero-day vulnerabilities, known vulnerabilities, and port scanning; The key rotation period is the ratio of the key validity period to the comprehensive cracking degree, and the response value is obtained by analyzing the attack frequency distribution, including: The attack frequency and attack form in the preset time period are combined into two tuples and marked as frequency analysis groups; The attack computing power and attack form in the preset time period are combined into a second tuple and marked as a computing power analysis group. The frequency analysis group and computing power analysis group corresponding to the password exposure process are respectively combined into a frequency analysis space and a computing power analysis space; Mark the standard score of the frequency analysis group of the current measurement period in the frequency analysis space as the first cracking degree; The standard score of the computing power analysis group in the computing power analysis space during the current measurement period is marked as the second cracking degree; Set a standard score threshold. If the first or second cracking degree of the current measurement period exceeds the standard score threshold, it means that the current system is at risk of password leakage. At the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain the comprehensive cracking degree. The key rotation period data within the historical preset period is constrained by the second condition, and the initial key rotation period is obtained by averaging.

[0019] The configuration generation module performs multi-dimensional perturbation simulation on the initial security parameters to obtain several configuration vectors to be optimized; Perform multi-dimensional perturbation simulation on the initial security parameters to obtain several configuration vectors to be optimized, including: Identify a multi-parameter space based on the initial security parameters, where the parameter space includes at least the number of authentication factors, algorithm strength, time period, and trigger threshold; For example: authentication security level parameter space: including the number of authentication factors at several levels (e.g., 1-3), the strength of the algorithm at several levels (e.g., 1-3), and the sequential or parallel combination of multiple factors; Key rotation cycle parameter space: including time period (e.g., 1-90 days), transaction trigger threshold (e.g., 1,000-10,000 times), full rotation or derived rotation strategy; Based on the first and second conditions constraining the parameter space, a Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only within the constrained parameter space, which are combined to form a configuration vector to be optimized. The configuration vector contains different combinations of authentication security levels and key rotation periods. Latin hypercube sampling algorithm, including: Divide the parameter space into N non-overlapping intervals, N ≥ 1; for example, divide the number of authentication factors (levels 1-3) into three intervals [1], [2], and [3], each corresponding to single-factor, two-factor, and three-factor authentication; through stratification, avoid clustering bias in random sampling and ensure that each parameter level (such as three-factor authentication) has at least one sample; in the subsequent nonlinear response surface, stratification can capture the inflection point of parameter change; Randomly extract sample points from each interval, ensuring that each interval of each parameter is sampled once, and then normalize and map them to the range of [0, 1]. For discrete parameters (number of authentication factors, algorithm strength), round the mapped continuous values to the nearest integer. For continuous parameters (time period, trigger threshold), retain the mapped floating-point values or round them to the nearest integer based on the business precision. Combining different parameter sample points to generate different configuration vectors to be optimized; The evaluation and screening module maps the configuration vector to be optimized to the multi-level encryption process, performs a secure collaborative evaluation based on time complexity and risk magnitude, obtains the evaluation results, and constructs a multidimensional key effectiveness response surface based on the evaluation results and the configuration vector to be optimized. It then identifies sensitive areas on the surface and selects the optimal configuration vector. Safety collaborative assessment based on time complexity and risk magnitude, including: Perform a nonlinear transformation on the time complexity and the risk amplitude (for example, calculate the logarithm of the time complexity and the risk amplitude), establish a two-dimensional curve graph of the time complexity-risk amplitude, and draw a corresponding standard curve graph. Overlay the two-dimensional curve graph and the standard curve graph to obtain the intersection area, the difference area, the non-overlapping total area, and the overlapping total area. Calculate a first ratio of the intersection area to the difference area, calculate a second ratio of the overlapping total area to the non-overlapping total area, multiply the first ratio and the second ratio, and perform a weighted sum of the first ratio, the second ratio, and the product of the two ratios to obtain an assessment result. The significance of the above analysis lies in the following: the time complexity of encryption performance (such as the computational time of the AES and RSA algorithms) directly reflects the system's resource consumption (CPU, memory), while the risk magnitude is reflected in the encryption algorithm's anti-attack capabilities (such as the key space and resistance to differential attacks); the two-dimensional mapping of the two allows for quantitative comparison, avoiding the ambiguity of subjective qualitative evaluations; the first ratio reflects the local conformity of the two-dimensional curve graph with the standard curve; a higher ratio indicates a higher key security; the second ratio reflects the overall security ratio; a higher ratio indicates a more reasonable overall security structure; the larger the numerical value of the evaluation result, the more secure the key is at that time; The weights in the weighting process are defined based on the genetic algorithm. The specific process is as follows: The process of determination based on the genetic algorithm is as follows: In a U-dimensional target space, an initial population is randomly generated, consisting of m particles, and any particle is marked as k. During initialization, a certain number of individuals (e.g., weight combinations) are randomly generated to ensure that all weight values are within the appropriate range, between [0, 1], and the sum of the weight values is 1; Based on individual fitness, individuals with high fitness are selected as parents. Roulette wheel selection strategy is used to select particles from the population and put them into the mating pool in turn until the number of particles in the mating pool reaches m. New individuals are obtained by performing selection, crossover and mutation operations on the population and added to the population to update the composition of the population. During the crossover process: A crossover point is selected, and the parent's genes (weight vectors) are split into two parts at this point. The two parts are then exchanged to generate two offspring. At the same time, the crossover operation is not performed on every pair of parents. Usually a crossover probability is set, for example: a crossover is performed at a 70% probability, and the parent remains unchanged at a 30% probability. For example: the weight vector of parent 1 is [0.2, 0.5, 0.3], the weight vector of parent 2 is [0.4, 0.1, 0.5], and the crossover point is selected as the second position. After crossover, the weight of offspring 1 can be [0.2, 0.1, 0.5], and the weight of offspring 2 can be [0.4, 0.5, 0.3]; After updating the population, if the average value of the population fitness or the optimal solution no longer changes significantly, the result is output and training stops; Construct a multidimensional key effectiveness response surface, including: The configuration vector to be optimized is combined with its corresponding evaluation result to form a sample set S1 = {optimized configuration vector A, evaluation result B}; a third-order polynomial response surface is used to construct a multi-dimensional key efficiency response curve B = f (A); For example: The third-order polynomial response surface is a mathematical model used to model the nonlinear relationship between multivariable input and output responses. Its core is to fit sample points through polynomial functions that contain linear, quadratic, cubic terms of the input variables and cross terms between variables to characterize the complex surface shape. High-order models (such as fourth-order and above) are easy to fit noise, especially when the sample points are sparsely distributed in high-dimensional space (such as some extreme configuration combinations in key management systems that are difficult to obtain through actual measurements). The third-order model strikes a balance between fitting accuracy and generalization ability by limiting the highest interaction order, so the third-order model is selected for the third-order polynomial response surface; The characteristic parameters corresponding to each configuration vector (such as encryption algorithm parameters, key length, etc.) and the evaluation results are used as sample points (ya, yb). A third-order polynomial can construct a more accurate configuration-performance mapping model through nonlinear fitting, which is superior to linear or second-order models in characterizing complex surfaces. Identify surface sensitive areas and select the best configuration vector, including: Based on the multi-dimensional key effectiveness response curve, several peak areas are identified and used as candidate areas; Based on the candidate region, obtain the corresponding mean jz and fluctuation value bd, and combine the evaluation result B to construct several judgment vectors, including: [jz+bd, B], [jz-bd, B]; Import the judgment vector into the pre-built judgment model and output the judgment result. When the judgment result obtained by any judgment vector is greater than the preset judgment threshold, the candidate area is marked as a surface sensitive area; Based on the surface sensitive area, all configuration vectors to be optimized are extracted to form a candidate configuration pool; The NSGA-II algorithm is used to generate the Pareto optimal solution set, and the configuration vector that meets the optimization goals of maximizing the evaluation effect and minimizing the fluctuation value is screened and marked as the best configuration vector; among them, the judgment model is a support vector machine (SVM) or a random forest model, which is trained with historical configuration data.

[0020] The driver execution module drives the multi-level encryption key management system to execute the optimal configuration vector. This process does not require human intervention and can adjust security policies in real time according to changes in business scenarios. It is particularly suitable for high-concurrency and high-risk transaction scenarios, improving the system's responsiveness and continuous adaptability to dynamic security threats.

[0021] Example 2: An embodiment of the present invention provides a key management method for multi-level encrypted transmission of bank-enterprise direct connection, the method comprising the following steps: Collect transaction parameters and encryption requirements in different business scenarios in real time, input them into the pre-built encryption requirement model and output the risk range; Obtaining a first condition of the key hierarchical constraint and a second condition of the key update constraint, and quantifying initial security parameters based on the first condition and the second condition; wherein the initial security parameters include: an initial authentication security level and an initial key rotation period; Perform multi-dimensional perturbation simulation on the initial security parameters to generate several configuration vectors to be optimized; map the configuration vectors to be optimized to the multi-level encryption process, obtain evaluation results based on time complexity and risk amplitude security collaborative evaluation, and construct a multi-dimensional key efficiency response surface based on the evaluation results and the configuration vectors to be optimized. Identify the sensitive areas of the surface, screen the optimal configuration, and drive the execution of the optimal configuration vector.

[0022] In the application, the several formulas involved are all calculated by taking their numerical values after removing the dimensions, and the formula is a formula of the most recent real situation obtained by collecting a large amount of data and performing software simulation. The formula is set by technical personnel in this field according to actual conditions.

[0023] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art will appreciate that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution.

[0024] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment as needed.

[0025] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. A key management system for multi-level encrypted transmission in direct bank-enterprise connection, characterized by: The system comprises: The first acquisition module is used to collect transaction parameters and encryption requirements in different business scenarios in real time, input them into the pre-built encryption requirement model and output the risk range; The second acquisition module is used to obtain the first condition of the key hierarchical constraint and the second condition of the key update constraint, quantify the initial security parameters based on the first condition and the second condition, and obtain the time complexity; wherein the initial security parameters include: the initial authentication security level and the initial key rotation period, The configuration generation module is used to perform multi-dimensional perturbation simulation on the initial security parameters and generate several configuration vectors to be optimized; An evaluation and screening module is used to map the configuration vector to be optimized to the multi-level encryption process, perform a security collaborative evaluation based on time complexity and risk magnitude, obtain the evaluation results, construct a multidimensional key effectiveness response surface based on the evaluation results and the configuration vector to be optimized, identify the sensitive areas of the surface, and screen the optimal configuration vector; The driving execution module is used to drive the execution of the optimal configuration vector.

2. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The transaction parameters include transaction amount, transaction IP address, transaction scenario and transaction timestamp; the encryption requirements include at least key length and algorithm combination; the encryption requirement model includes at least feature extraction layer, matrix association layer and risk assessment layer.

3. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The feature extraction layer extracts the time-frequency domain features of the transaction parameters based on wavelet transform; The matrix association layer: constructs a risk association matrix based on time-frequency domain characteristics and encryption requirements; The risk assessment layer: based on the business risk association matrix, combined with the transaction topology map to form an assessment rule set, obtain risk feature points and risk time series, use wavelet decomposition to obtain several risk frequency bands, calculate the energy entropy value of each frequency band and aggregate it according to a preset first weight to obtain the second weight values of the several risk frequency bands, based on the second weight values of the several risk frequency bands, weighted fusion of the entropy values of each segment to obtain the risk amplitude.

4. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The first condition includes: the frequency of authentication failures and the encryption performance of each encryption level; wherein the encryption levels include the first level, the second level, and the third level; The encryption performance of each encryption layer includes: Obtain performance indicators for each encryption layer and calculate the average performance value for each encryption layer; the performance indicators include encryption and decryption delay rate and resource consumption; analyze the degree of dispersion between the performance indicators and the average performance value for each encryption layer, and dynamically determine the parameter adjustment range based on the degree of dispersion; Based on the risk magnitude and authentication failure frequency, a corresponding sample set is formed, and the loss value between samples is calculated. The security level is filtered in combination with the first condition, and the authentication security level with the smallest deviation from the current one is selected as the initial authentication security level based on the minimum deviation matching from the filtered historical data.

5. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The second condition includes: attack frequency, attack computing power, and attack form: the key rotation period is the ratio of the key validity period to the comprehensive cracking degree, and the response value is obtained by analyzing the attack frequency distribution quantification, including: The attack frequency and attack form in the preset time period are combined into two tuples and marked as frequency analysis groups; The attack computing power and attack form in the preset time period are combined into a second tuple and marked as a computing power analysis group. The frequency analysis group and computing power analysis group corresponding to the password exposure process are respectively combined into a frequency analysis space and a computing power analysis space; Mark the standard score of the frequency analysis group of the current measurement period in the frequency analysis space as the first cracking degree; The standard score of the computing power analysis group in the computing power analysis space during the current measurement period is marked as the second cracking degree; Set a standard score threshold. If the first or second cracking degree of the current measurement period exceeds the standard score threshold, it means that the current system is at risk of password leakage. At the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain the comprehensive cracking degree. The key rotation period data within the historical preset period is constrained by the second condition, and the initial key rotation period is obtained by averaging.

6. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The generating of a plurality of configuration vectors to be optimized includes: Identify a multi-parameter space based on the initial security parameters, where the parameter space includes at least the number of authentication factors, algorithm strength, time period, and trigger threshold; Based on the first and second conditions constraining the parameter space, the Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only within the constrained parameter space, which are combined to form a configuration vector to be optimized, and the configuration vector contains different authentication security levels and key rotation period combinations.

7. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The security collaborative assessment based on time complexity and risk magnitude includes: Perform nonlinear transformation on time complexity and risk amplitude, establish a two-dimensional curve graph of time complexity-risk amplitude, and draw a corresponding standard curve graph. Overlay the two-dimensional curve graph and the standard curve graph to obtain the intersection area, difference area, non-overlapping total area and overlapping total area. Calculate the first ratio of the intersection area to the difference area, calculate the second ratio of the overlapping total area to the non-overlapping total area, multiply the first ratio and the second ratio, and take weighted difference between the first ratio, the second ratio and the product of the two ratios to obtain the evaluation result.

8. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The step of constructing a multidimensional key efficiency response surface includes: combining the configuration vector to be optimized and its corresponding evaluation result to form a sample set S1={optimized configuration vector A, evaluation result B}; using a third-order polynomial response surface to construct a multidimensional key efficiency response curve B=f(A).

9. The key management system for bank-enterprise direct multi-level encrypted transmission according to claim 1 is characterized in that: The method of identifying the surface sensitive area and selecting the optimal configuration includes: Based on the multi-dimensional key effectiveness response curve, several peak areas are identified and used as candidate areas; Based on the candidate area, the corresponding mean and fluctuation values are obtained. Combined with the evaluation results, several judgment vectors are constructed. The judgment vectors are imported into the pre-built judgment model and the judgment results are output. When the judgment result obtained by any judgment vector is greater than the preset judgment threshold, the candidate area is marked as a surface sensitive area. Based on the surface sensitive area, all configuration vectors to be optimized are extracted to form a candidate configuration pool; The NSGA-II algorithm is used to generate the Pareto optimal solution set, and the configuration vector that meets the optimization objectives of maximizing the evaluation effect and minimizing the fluctuation value is screened and marked as the best configuration vector.

10. A key management method for multi-level encrypted transmission in direct bank-enterprise connection, characterized in that: The method comprises: Collect transaction parameters and encryption requirements in different business scenarios in real time, input them into the pre-built encryption requirement model and output the risk range; Obtaining a first condition of the key hierarchical constraint and a second condition of the key update constraint, and quantifying initial security parameters based on the first condition and the second condition; wherein the initial security parameters include: an initial authentication security level and an initial key rotation period; Perform multi-dimensional perturbation simulation on the initial security parameters to generate several configuration vectors to be optimized; map the configuration vectors to be optimized to the multi-level encryption process, obtain evaluation results based on time complexity and risk amplitude security collaborative evaluation, and construct a multi-dimensional key efficiency response surface based on the evaluation results and the configuration vectors to be optimized. Identify the sensitive areas of the surface, screen the optimal configuration, and drive the execution of the optimal configuration vector.

Citation Information

Patent Citations

  • Processing method and system for dynamic encryption of enterprise sensitive data

    CN119449369A

  • Digital function management method and system based on data mining

    CN119691781A

  • Data encryption and dynamic key management method based on quantum security protocol

    CN119921951A

  • Smart power grid multi-time scale resource scheduling optimization method and system

    CN119990716A

  • Encrypted enterprise network data security access method and system

    CN120017424A