Key management system for multi-level encryption transmission of bank-enterprise direct connection
By collecting transaction parameters and encryption requirements in real time and combining them with key hierarchical constraints, a configuration vector for multi-dimensional perturbation simulation is generated, and a multi-dimensional key performance response surface is constructed. This solves the problem of delayed risk response in the bank-enterprise direct connection encryption scheme and improves system security and management efficiency.
Patent Information
- Application Number
- CN202510980319.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-07-16
AI Technical Summary
Existing bank-enterprise direct connection encryption solutions cannot collect transaction parameters in real time, resulting in delayed risk response. Key configuration and encryption processes cannot be dynamically adjusted, affecting security and efficiency.
By collecting transaction parameters and encryption requirements in real time, and combining them with key hierarchical constraints, a configuration vector for multi-dimensional perturbation simulation is generated. A multi-dimensional key performance response surface is constructed, sensitive areas of the surface are identified, and the optimal configuration is selected to achieve dynamic security parameter calibration.
It improves the security and management efficiency of the encryption system, reduces redundant operations and computing resource consumption, lowers management costs, and improves optimization efficiency and accuracy.
Smart Images

Figure CN120474850B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of encrypted transmission, in particular to a key management system for multi-level encrypted transmission of bank-enterprise direct connection. BACKGROUND
[0002] Bank-enterprise direct connection refers to an integration mode in which the financial system (such as ERP, fund management system, etc.) of an enterprise and the core business system of a bank are directly connected through a special interface, which is used for fund management, payment, account information query, etc., to realize seamless connection between the enterprise system and the bank system, and has high security requirements; encrypted transmission refers to the encryption processing of data transmitted between the enterprise system and the bank system in the process of bank-enterprise direct connection, to ensure that the data is not stolen, tampered with or forged in the network transmission process.
[0003] The existing bank-enterprise direct connection encryption scheme has the following disadvantages:
[0004] On the one hand, the traditional system cannot collect transaction parameters (such as IP address entropy value, device fingerprint stability) in real time and input the encryption requirement model, resulting in that the risk output lags behind the attack behavior, and the key rotation period and encryption algorithm selection are based on historical experience preset, which cannot dynamically respond to real-time risks (such as sudden DDoS attack, new vulnerability disclosure), greatly increasing the security risk, for example, when a branch bank is subjected to targeted attack, it still needs to wait for the unified adjustment strategy of the head office, and the response delay is up to several hours.
[0005] On the other hand, the mapping relationship between key configuration and encryption process (generation, transmission, verification, destruction) is fixed, and resources cannot be dynamically allocated according to real-time load, which affects the encryption efficiency, causes bank business delay, and reduces management efficiency. SUMMARY
[0006] (I) Technical problems solved
[0007] In view of the deficiencies of the prior art, the present application provides a key management system for multi-level encrypted transmission of bank-enterprise direct connection, which realizes dynamic quantization and intelligent calibration of initial security parameters by collecting transaction parameters and encryption requirements in real time, combining the first condition of key hierarchical constraint and the second condition of key update constraint: through the real-time output of risk amplitude by the encryption requirement model, combined with time complexity, safety collaborative evaluation is carried out, sensitive area is identified, and the best configuration vector is selected, thereby solving the problems proposed in the background art.
[0008] (II) Technical solutions
[0009] To achieve the above purpose, the present application realizes the following technical solutions:
[0010] In a first aspect, the present application provides a key management system for multi-level encrypted transmission of bank-enterprise direct connection, which comprises:
[0011] The first acquisition module is configured to collect transaction parameters and encryption requirements in different service scenarios in real time, and input the transaction parameters and the encryption requirements into a pre-constructed encryption requirement model and output a risk amplitude;
[0012] The second acquisition module is configured to acquire a first condition of key hierarchical constraint and a second condition of key update constraint, quantify initial security parameters based on the first condition and the second condition, and acquire a time complexity; wherein the initial security parameters include an initial authentication security level and an initial key rotation period,
[0013] The configuration generation module is configured to perform multidimensional perturbation simulation on the initial security parameters to generate a plurality of to-be-optimized configuration vectors.
[0014] The evaluation and screening module is configured to map the to-be-optimized configuration vectors to a multi-level encryption process, perform security collaborative evaluation based on the time complexity and the risk amplitude, obtain an evaluation result, construct a multi-dimensional key performance response surface based on the evaluation result and the to-be-optimized configuration vectors, identify a sensitive area of the surface, and screen an optimal configuration vector.
[0015] The driving execution module is configured to drive execution of the optimal configuration vector.
[0016] Further, the transaction parameters include a transaction amount, a transaction IP address, a transaction scenario, and a transaction timestamp, and the encryption requirements at least include a key length and an algorithm combination; and the encryption requirement model at least includes a feature extraction layer, a matrix correlation layer, and a risk evaluation layer.
[0017] Further, the feature extraction layer is configured to extract time-frequency domain features of the transaction parameters based on wavelet transform.
[0018] The matrix correlation layer is configured to construct a risk correlation matrix based on the time-frequency domain features and the encryption requirements.
[0019] The risk evaluation layer is configured to form an evaluation rule set based on the business risk correlation matrix and a transaction topology graph, obtain risk feature points and a risk time sequence, obtain a plurality of risk frequency bands by wavelet decomposition, calculate energy entropy values of the frequency bands and aggregate the energy entropy values according to a preset first weight to obtain second weight values of the plurality of risk frequency bands, and perform weighted fusion on the entropy values of the frequency bands based on the second weight values to obtain a risk amplitude.
[0020] Further, the first condition includes an authentication failure frequency and encryption performance of each encryption level; wherein the encryption level includes a first hierarchical level, a second hierarchical level, and a third hierarchical level.
[0021] The encryption performance of each encryption level includes:
[0022] The performance indicators of each encryption level are obtained, and the average performance values of each encryption level are calculated respectively; wherein, the performance indicators include encryption and decryption delay rate and resource consumption; the dispersion degree of the performance indicators and the average performance values of each encryption level is analyzed, and the parameter adjustment range is dynamically determined based on the dispersion degree;
[0023] Based on the risk amplitude and the authentication failure frequency, a corresponding sample set is formed, and the loss value between samples is calculated, and the security level is screened based on the first condition, and the authentication security level with the smallest deviation from the current deviation is selected as the initial authentication security level based on the minimum deviation matching from the screened historical data.
[0024] Further, the second condition includes: attack frequency, attack computing power and attack form;
[0025] The key rotation period is the ratio of the key validity period and the comprehensive cracking degree, and the response value is obtained by analyzing the attack frequency distribution, including:
[0026] The attack frequency and the attack form of the preset time period are formed into a binary tuple and marked as a frequency analysis group;
[0027] The attack computing power and the attack form of the preset time period are formed into a second tuple and marked as a computing power analysis group, and the corresponding frequency analysis group and computing power analysis group in the password exposure process are formed into a frequency analysis space and a computing power analysis space respectively;
[0028] The standard score of the frequency analysis group in the frequency analysis space in the current measurement period is marked as the first cracking degree;
[0029] The standard score of the computing power analysis group in the computing power analysis space in the current measurement period is marked as the second cracking degree;
[0030] A standard score threshold is set, if the first cracking degree or the second cracking degree of the current measurement period exceeds the standard score threshold, it indicates that the current system is subject to the risk of password leakage; at the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain the comprehensive cracking degree;
[0031] The key rotation period data in the historical preset period is constrained by the second condition, and the initial key rotation period is obtained by averaging.
[0032] Further, a plurality of to-be-optimized configuration vectors are generated, including:
[0033] Based on the initial security parameters, a multi-parameter space is identified, and the parameter space at least includes the number of authentication factors, the algorithm strength, the time period and the trigger threshold;
[0034] Based on the first condition and the second condition, the parameter space is constrained, and the Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only in the constrained parameter space, which are combined to form the configuration vector to be optimized, and the configuration vector contains different combinations of authentication security levels and key rotation periods.
[0035] Further, based on the time complexity and risk amplitude security collaborative evaluation, including:
[0036] The time complexity and risk amplitude are nonlinearly transformed, a two-dimensional graph of time complexity-risk amplitude is established, and a standard graph is drawn correspondingly, the two-dimensional graph and the standard graph are superimposed on each other to obtain the intersection area, the difference set area, the non-overlapping total area and the overlapping total area, the first ratio of the intersection area to the difference set area is calculated, the second ratio of the overlapping total area to the non-overlapping total area is calculated, the first ratio and the second ratio are multiplied, and the first ratio, the second ratio and the product of the two ratios are weighted and subtracted to obtain the evaluation result.
[0037] Further, the step of constructing a multi-dimensional key performance response surface includes: combining the configuration vector to be optimized and its corresponding evaluation result to form a sample set S1={optimization configuration vector A, evaluation result B}; and using a third-order polynomial response surface to construct a multi-dimensional key performance response curve B=f(A).
[0038] Further, the step of identifying the sensitive area of the surface and screening the best configuration includes:
[0039] Based on the multi-dimensional key performance response curve, a plurality of peak regions are identified as candidate regions.
[0040] Based on the candidate regions, the corresponding mean and fluctuation value are obtained, the evaluation result is combined to construct a plurality of judgment vectors, the judgment vectors are input into a pre-constructed judgment model, and the judgment result is output, and when the judgment result obtained by any judgment vector is greater than a preset judgment threshold, the candidate region is marked as a sensitive area of the surface.
[0041] Based on the sensitive area of the surface, all configuration vectors to be optimized are extracted to form a candidate configuration pool.
[0042] The NSGA-II algorithm is used to generate a Pareto optimal solution set, and the configuration vector satisfying the optimization target of maximizing the evaluation effect and minimizing the fluctuation value is screened and marked as the best configuration vector.
[0043] In a second aspect, the application provides a key management method for bank-enterprise direct connection multi-level encryption transmission, the method comprising:
[0044] Real-time collection of transaction parameters and encryption requirements in different business scenarios, and input into a pre-constructed encryption requirement model and output of risk amplitude;
[0045] Obtaining a first condition of key hierarchical constraint and a second condition of key update constraint, quantifying initial security parameters based on the first condition and the second condition; wherein the initial security parameters include: initial authentication security level and initial key rotation period;
[0046] Performing multi-dimensional perturbation simulation on the initial security parameters to generate a plurality of to-be-optimized configuration vectors; mapping the to-be-optimized configuration vectors to a multi-level encryption process, obtaining an evaluation result based on time complexity and risk amplitude security collaborative evaluation, constructing a multi-dimensional key performance response surface based on the evaluation result and the to-be-optimized configuration vectors, identifying a sensitive area of the surface and screening an optimal configuration, and driving the optimal configuration vector to be executed.
[0047] (Three) beneficial effects
[0048] The application provides a key management system for bank-to-bank direct connection multi-level encryption transmission, which has the following beneficial effects:
[0049] 1. The application generates a plurality of to-be-optimized configuration vectors by performing multi-dimensional perturbation simulation on the initial security parameters, and analyzes the influence of the interaction of each parameter on the encryption performance by constructing a multi-dimensional key performance response surface; this method breaks through the limitations of traditional single-dimensional optimization, can capture multi-parameter coupling effects, and selects the optimal configuration from a global perspective, thereby improving the security and management efficiency of the encryption system.
[0050] 2. The application realizes dynamic quantification and intelligent calibration of initial security parameters by real-time collection of transaction parameters and encryption requirements, combination of the first condition of key hierarchical constraint and the second condition of key update constraint, real-time output of risk amplitude through an encryption requirement model, security collaborative evaluation through the combination of risk amplitude and time complexity, identification of the sensitive area of the surface, and reduction of invalid exploration in the optimization process by focusing on the sensitive area, thereby quickly positioning the key parameters that play a decisive role in system performance and improving optimization efficiency and accuracy.
[0051] 3. The application further compresses redundant key management operations and reduces the consumption of computing resources and management costs by screening and driving the optimal configuration through a screening driving module.
[0052] 4. The application quantifies security parameters based on key hierarchical constraint and update mechanism, so that the key management (such as rotation period and authentication level) forms a standardized process, and reduces the randomness and error rate of manual configuration. BRIEF DESCRIPTION OF DRAWINGS
[0053] Figure 1 is a module schematic diagram of a key management system according to an exemplary embodiment. DETAILED DESCRIPTION
[0054] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be clearly and completely described below, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative efforts belong to the protection scope of the present application.
[0055] Embodiment 1:
[0056] The embodiments of the present application provide a key management system for multi-level encryption transmission of bank-enterprise direct connection; Figure 1 It is a module schematic diagram of the key management system shown according to an exemplary embodiment; please refer to Figure 1 The system comprises a first acquisition module, a second acquisition module, a configuration generation module, an evaluation and screening module and a driving execution module, and the first acquisition module, the second acquisition module, the configuration generation module, the evaluation and screening module and the driving execution module are in communication connection;
[0057] The following is an explanation and description of each module:
[0058] The first acquisition module acquires transaction parameters, transaction topology graphs and encryption requirements in different business scenarios in real time within a preset time period, and inputs them into a pre-constructed encryption requirement model and outputs a risk amplitude;
[0059] The transaction parameters include transaction amount, transaction IP address, transaction scenario and transaction timestamp;
[0060] The encryption requirements at least include key length and algorithm combination;
[0061] The business scenarios include data storage scenarios, regular transaction scenarios and risk transaction scenarios;
[0062] The transaction topology graph: taking entities (such as users, service platforms and financial institutions) involved in each business scenario as nodes, business associations (such as fund flow direction) between nodes as edges, connecting nodes through edges to form a transaction topology graph according to business processes and transaction logic, for intuitively displaying the relationship between each entity in the transaction process and the flow path of data, funds, etc.; giving each node a unique identifier, type (such as user node, service node and data node), business role (such as buyer, seller and payment gateway), permission level (such as ordinary permission, administrator permission and high-level business permission) attributes, giving each node a direction (such as one-way fund flow direction), transmission protocol (such as HTTP and HTTPS) and time delay requirement (such as maximum time delay limit for real-time transactions) attributes, and completing the basic element construction of the transaction topology constraint graph;
[0063] The encryption requirement model includes at least a feature extraction layer, a matrix association layer, and a risk assessment layer.
[0064] Feature extraction layer: Extract time-frequency domain features of transaction parameters based on wavelet transform, including: using wavelet transform (e.g., db4 wavelet) to perform multi-resolution decomposition on the time-domain data of transaction amount sequence, transaction IP address sequence, transaction scene sequence and timestamp sequence, and mapping them to the time-frequency domain space to obtain time-frequency domain features;
[0065] Taking a time series of transaction amounts as an example, three-level wavelet decomposition can yield approximate components (low-frequency trends) and detail components (high-frequency fluctuations); among which, the high-frequency components correspond to abnormal features such as sudden large transactions.
[0066] Matrix correlation layer: Constructing a risk correlation matrix based on time-frequency domain features and encryption requirements;
[0067] The risk correlation matrix is represented by R. m*n : In the formula, m represents the number of time-frequency domain feature categories, n represents the number of encryption requirements, and the matrix element r ij This represents the correlation strength between the i-th type of time-frequency domain features and the j-th type of encryption requirements, and the correlation strength is obtained based on the mutual information algorithm: In the formula, x i Representing the time-frequency domain characteristics, y j Indicates encryption requirements, Represents mutual information value;
[0068] Risk assessment layer: Based on the business risk correlation matrix and combined with the transaction topology map, an assessment rule set is formed to obtain risk feature points and risk time series (e.g., arranging risk feature points in chronological order and aggregating them with a fixed window or sliding window). Wavelet decomposition is used to obtain several risk frequency bands. The energy entropy value of each frequency band is calculated and aggregated according to a preset first weight (e.g., higher weight for high frequency bands and lower weight for low frequency bands). Second weight values of several risk frequency bands are obtained. Based on the second weight values of several risk frequency bands, the entropy values of each segment are weighted and fused to obtain the risk magnitude.
[0069] Example using Python code:
[0070] # Risk Range Calculation
[0071] def risk_amplitude(signal, weights=None):
[0072] approx, details = wavelet_decompose(signal)
[0073] all_coeffs = [approx] + details
[0074] energy = [np.sum(np.square(c)) for c in all_coeffs]
[0075] entropy = calculate_entropy(np.array(energy))
[0076] if weights is None:
[0077] weights = np.array([0.2, 0.3, 0.3, 0.2]) # Preset the first weight (low frequency and 3 high frequency)
[0078] weights = weights * (entropy / np.sum(entropy)) # Generate the second weights
[0079] ra = np.sum(weights * entropy)
[0080] return ra
[0081] Map the correlation strength in the risk correlation matrix to the nodes and edges of the transaction topology graph, and add risk weight attributes to the nodes and edges;
[0082] Analyze the path structure of the transaction topology graph, determine the mandatory and optional nodes, and set different path constraints for nodes with different risk levels based on risk weight attributes to obtain structural constraint rules. The structural constraint rules include at least one of the following: mandatory path constraints, hierarchical restriction constraints, and node mutual exclusion constraints.
[0083] Analyze the temporal relationships of nodes and edges in the transaction topology graph to determine the order of transaction steps. Based on the risk weight attribute, set different time constraints for transaction steps with different risk levels to obtain temporal constraint rules. The temporal constraint rules include at least one of sequential execution constraints, time delay threshold constraints, and state machine constraints.
[0084] Analyze the historical flow data of nodes and edges in the transaction topology graph to determine the flow distribution characteristics. Based on the risk weight attribute, set different flow restrictions for nodes and edges with different risk levels to obtain flow constraint rules. The flow constraint rules include at least one of frequency restriction constraints, capacity threshold constraints, and amount limit constraints.
[0085] The evaluation rules set for evaluating transaction risks is formed based on combination of the structural constraint rules, the timing constraint rules and the flow constraint rules, a depth-first search (DFS) is performed on nodes and edges of the transaction topology graph based on the evaluation rules set, risk feature points that violate the rules are identified, for each risk feature point, a time sequence is extracted forward and backward to form a risk time sequence;
[0086] Beneficial effects: By constructing a time-frequency domain encryption demand model, the transaction features in the banking business scenario are mapped from the time domain to the time-frequency domain, the implicit dynamic risk features are extracted, the mathematical model directly related to the encryption demand is constructed, the limitations of traditional static risk assessment are broken through, the coupling features of transaction data in the time and frequency dimensions can be captured, and quantitative basis is provided for dynamic adjustment of multi-level encryption strategies.
[0087] The second acquisition module acquires a first condition of the key hierarchical constraint and a second condition of the key update constraint, and quantifies an initial security parameter based on the first condition and the second condition; wherein the initial security parameter includes an initial authentication security level and an initial key rotation period;
[0088] The first condition includes an authentication failure frequency and encryption performance of each encryption level; wherein the encryption level includes a first hierarchical level, a second hierarchical level and a third hierarchical level;
[0089] The encryption performance of each encryption level includes:
[0090] The performance indicators of each encryption level are acquired, and the average performance values of each encryption level are acquired based on the performance indicators; wherein the performance indicators include encryption and decryption delay rates and resource consumption amounts;
[0091] The dispersion degree of the performance indicators and the average performance values of each encryption level is analyzed, and the parameter adjustment range is dynamically determined based on the dispersion degree; wherein the dispersion degree analysis step includes: selecting a dispersion degree indicator to quantitatively analyze the dispersion degree of the performance indicators and the average performance values of each encryption level, the dispersion degree indicator includes at least one of a standard deviation and a quartile range; a mapping relationship between the dispersion degree and the parameter adjustment is established, and the parameter adjustment range is dynamically determined based on the dispersion degree;
[0092] The dispersion degree level division standard is: setting a first threshold value, a second threshold value,
[0093] When the dispersion degree is less than the first threshold value, it represents low dispersion;
[0094] When the first threshold value is less than or equal to the dispersion degree, which is less than or equal to the second threshold value, it represents medium dispersion;
[0095] When the dispersion degree is greater than the second threshold value, it represents high dispersion;
[0096] According to the determined parameter adjustment range, at least one of the encryption algorithm complexity, the data block fragmentation size, the key length, and the thread scheduling strategy of the encryption level is dynamically adjusted;
[0097] Then, the initial authentication security level is determined based on the first condition, including:
[0098] In the adjustment range, the time complexity corresponding to each encryption level is extracted for evaluating the encryption performance.
[0099] The time complexity is calculated as follows: In the formula, T represents the time complexity, N is the data size, E AES represents the encryption time per unit data, C CPU represents the computing capacity of the CPU, and L is the encryption level, taking a value of 1-3, including the first level, the second level, and the third level, to help understand the allocation of computing resources in the optimized encryption process, adjust the encryption level, and balance the security and efficiency.
[0100] It should be noted that in the encryption process, the forward security, search mode security, and backward security features are integrated. The forward security is achieved through ECDHE key exchange and HMAC non-deductive rotation. The search mode security is achieved through symmetric / public key searchable encryption to build a secure index. The backward security is achieved through logical key trees and blockchain version management to isolate historical data. The first level is a dynamic searchable encryption scheme that only meets the forward security. The second level is an encryption scheme that protects the forward security and search mode at the same time based on the first level. The third level is an encryption scheme that increases the backward security of any strength based on the second level, so that the server cannot access the encrypted information of the deleted ciphertext.
[0101] Based on the risk amplitude and the authentication failure frequency, a sample set S0={risk amplitude, authentication failure frequency} is formed, and the loss value between the samples is calculated. Combined with the first condition, the security level is screened, and based on the minimum deviation matching in the screened historical data, the authentication security level with the minimum deviation from the current input is selected as the initial authentication security level.
[0102] The loss value is calculated by the Euclidean distance, which represents the deviation between the current input sample and the historical sample. Combined with the first condition of key level constraint, invalid samples (for example, in a certain business scenario, the security level needs to be greater than 2) are filtered out. In the valid sample set, the sample with the minimum deviation from the current input is found, and the authentication security level of the sample is obtained as the initial authentication security level. In addition, if there are multiple samples with the same minimum distance, the sample with the highest authentication level is selected (for example, L=3 is selected when L=2 and L=3 are matched at the same time).
[0103] The initial key rotation period is determined based on the second condition, including:
[0104] The second condition includes: attack frequency, attack computing power, and attack form;
[0105] Attack frequency: the frequency of historical attack events is counted through the security logs of the target system or similar systems (such as intrusion detection system (IDS), firewall logs);
[0106] Attack computing power: the size of the GPU / ASIC computing power (such as 10^15 hash operations per second) that can be called by the attacker (known hacker organizations, unknown hacker organizations, and individual attacks) is quantified. The stronger the computing power, the shorter the rotation period;
[0107] Attack form: zero-day vulnerability, known vulnerability, and port scanning;
[0108] The key rotation period is the ratio of the key validity period to the comprehensive cracking degree, and the response value is obtained by analyzing the attack frequency distribution, including:
[0109] The attack frequency and attack form of the preset time period are combined into a binary tuple and labeled as a frequency analysis group;
[0110] The attack computing power and attack form of the preset time period are combined into a second tuple and labeled as a computing power analysis group, and the corresponding frequency analysis group and computing power analysis group during the password exposure process are combined into a frequency analysis space and a computing power analysis space, respectively;
[0111] The standard score of the frequency analysis group in the frequency analysis space in the current measurement period is marked as the first cracking degree;
[0112] The standard score of the computing power analysis group in the computing power analysis space in the current measurement period is marked as the second cracking degree;
[0113] A standard score threshold is set. If the first cracking degree or the second cracking degree of the current measurement period exceeds the standard score threshold, it indicates that the current system is at risk of password leakage. At the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain a comprehensive cracking degree;
[0114] The key rotation period data in the historical preset period is constrained by the second condition, and the average is obtained to obtain the initial key rotation period.
[0115] The configuration generation module simulates the initial security parameters in multiple dimensions to obtain a plurality of to-be-optimized configuration vectors;
[0116] The initial security parameters are simulated in multiple dimensions to obtain a plurality of to-be-optimized configuration vectors, including:
[0117] Based on the initial security parameters, a multi-parameter space is identified, and the parameter space at least includes the number of authentication factors, the algorithm strength, the time period, and the trigger threshold;
[0118] For example: authentication security level parameter space: including several levels of authentication factor number (such as: 1-3), several levels of algorithm strength (such as: 1-3), sequential or parallel multi-factor combination mode;
[0119] Key rotation period parameter space: including time period (such as: 1-90 days), transaction trigger threshold (such as: 1000-10000 times), complete rotation or derived rotation strategy;
[0120] Based on the first condition and the second condition constraint parameter space, a Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only in the constrained parameter space, and the configuration vector is combined to form a to-be-optimized configuration vector, and the configuration vector contains different authentication security levels and key rotation period combinations;
[0121] The Latin hypercube sampling algorithm includes:
[0122] The parameter space is divided into N non-overlapping intervals, N≥1; for example, the authentication factor number (1-3 levels) is divided into [1], [2], [3] three intervals, each interval corresponds to single factor, double factor, three factor authentication; By stratification, avoid clustering bias of random sampling, ensure that each parameter level (such as three factor authentication) has at least one sample; In the subsequent nonlinear response surface, stratification can capture the inflection point of parameter change;
[0123] Randomly sample sample points from each interval, and ensure that each interval of each parameter is sampled once, and normalized to map to the [0, 1] value range; wherein, for discrete parameters (authentication factor number, algorithm strength), the mapped continuous value is rounded to the nearest integer; For continuous parameters (time period, trigger threshold), keep the floating point value after mapping or round according to business precision;
[0124] Combine different parameter sample points to generate different to-be-optimized configuration vectors;
[0125] The evaluation and screening module maps the to-be-optimized configuration vector to the multi-level encryption process, and based on the time complexity and risk amplitude security cooperative evaluation, obtains the evaluation result, based on the evaluation result and the to-be-optimized configuration vector, constructs a multi-dimensional key performance response surface, and identifies the sensitive area of the surface and screens the best configuration vector;
[0126] Based on the time complexity and risk amplitude security cooperative evaluation, including:
[0127] Nonlinear transformation is performed on the time complexity and the risk amplitude (for example, logarithm calculation is performed on the time complexity and the risk amplitude), a two-dimensional graph of the time complexity-risk amplitude is established, a standard graph is drawn correspondingly, the two-dimensional graph and the standard graph are superimposed on each other, intersection area, difference set area, non-overlapping total area and overlapping total area are obtained, a first ratio of the intersection area to the difference set area is calculated, a second ratio of the overlapping total area to the non-overlapping total area is calculated, the first ratio and the second ratio are multiplied, and a weighted sum of the first ratio, the second ratio and the product of the two ratios is obtained to obtain an evaluation result;
[0128] The significance of the above analysis is that the time complexity of the encryption performance (such as the operation time consumption of AES and RSA algorithms) directly reflects the resource consumption (CPU, memory) of the system, and the risk amplitude is embodied in the anti-attack ability of the encryption algorithm (such as key space and differential attack resistance); the two-dimensional mapping can be quantitatively compared to avoid the fuzziness of subjective qualitative evaluation; the first ratio reflects the local coincidence degree of the two-dimensional graph and the standard graph, and the higher the ratio, the higher the key security; the second ratio reflects the proportion of the overall security, and the higher the ratio, the more reasonable the overall security structure; the larger the evaluation result value, the more secure the key at this time;
[0129] The weight in the weighting process is defined based on a genetic algorithm, and the specific process is as follows:
[0130] The process of determining based on the genetic algorithm is as follows:
[0131] In a U-dimensional target space, an initial population is randomly generated, the population is composed of m particles, and any particle is marked as k. In the initialization, a certain number of individuals (for example, weight combinations) are randomly generated to ensure that all weight values are within a suitable range and the range is between 0 and 1, and the sum of the weight values is 1;
[0132] Based on the individual fitness, individuals with high fitness are selected as parents, and a roulette selection strategy is used to select particles from the population in turn and put them into a mating pool until the number of particles in the mating pool reaches m. New individuals are obtained by selecting, crossing and mutating the population and added to the population to update the composition of the population;
[0133] In the crossing process:
[0134] A crossover point is selected, the genes (weight vectors) of the parents are divided into two parts from the point, then the two parts are exchanged to generate two offspring. At the same time, the crossing operation is not performed on every pair of parents. Usually, a crossover probability is set, for example, a crossover is performed with a probability of 70%, and the parent is kept unchanged with a probability of 30%;
[0135] For example, the weight vector of parent 1 is [0.2, 0.5, 0.3], the weight vector of parent 2 is [0.4, 0.1, 0.5], the selection crossover point is the second bit, and after crossover, the weight of offspring 1 can be [0.2, 0.1, 0.5], and the weight of offspring 2 can be [0.4, 0.5, 0.3];
[0136] After updating the population, the average value or optimal solution of the population fitness no longer changes significantly, and then the result is output and the training is stopped;
[0137] Constructing a multi-dimensional key performance response surface, comprising:
[0138] Combining the to-be-optimized configuration vector and its corresponding evaluation result to form a sample set S1={optimized configuration vector A, evaluation result B}; a third-order polynomial response surface is used to construct a multi-dimensional key performance response curve of B=f(A);
[0139] For example, the third-order polynomial response surface is a mathematical model for modeling the nonlinear relationship between multivariate input and output response, and its core is to fit sample points through a polynomial function containing the first-order term, the second-order term, the third-order term, and the cross term between variables to describe the complex surface shape. High-order models (such as fourth-order and above) are prone to fitting noise, especially when sample points are sparsely distributed in high-dimensional space (such as some extreme configuration combinations in a key management system that are difficult to obtain through actual measurement). By limiting the highest interaction order, the third-order model balances between fitting accuracy and generalization ability, so the third-order model is selected for the third-order polynomial response surface;
[0140] The feature parameters (such as encryption algorithm parameters, key length, etc.) corresponding to each group of configuration vectors and the evaluation results are taken as sample points (ya, yb), and the third-order polynomial can construct a more accurate configuration-performance mapping model through nonlinear fitting, which is better than the linear or second-order model in describing complex curves;
[0141] Identifying the sensitive area of the surface and screening the best configuration vector, comprising:
[0142] Based on the multi-dimensional key performance response curve, identify several peak regions as candidate regions;
[0143] Based on the candidate region, obtain the corresponding mean jz and fluctuation value bd, and combine the evaluation result B to construct several judgment vectors, including: [jz+bd, B], [jz-bd, B];
[0144] The judgment vector is input into the pre-constructed judgment model, and the judgment result is output. When the judgment result obtained by any judgment vector is greater than the preset judgment threshold, the candidate region is marked as a sensitive area of the surface;
[0145] Based on the curved surface sensitive area, all to-be-optimized configuration vectors are extracted to form a candidate configuration pool;
[0146] The NSGA-II algorithm is adopted to generate a Pareto optimal solution set, filter configuration vectors meeting the optimization target of maximizing the evaluation effect and minimizing the fluctuation value, and mark the configuration vectors as optimal configuration vectors;The judgment model is a support vector machine (SVM) or a random forest model, which is trained by historical configuration data.
[0147] The driving execution module drives the multi-level encryption key management system to execute the optimal configuration vector;The process does not require manual intervention, and can adjust the security policy in real time according to the business scenario change, and is especially suitable for high-concurrency and high-risk transaction scenarios, and improves the response capability and continuous adaptability of the system to dynamic security threats.
[0148] Embodiment 2
[0149] The embodiment of the application provides a key management method for multi-level encryption transmission of bank-enterprise direct connection, and the method comprises the following steps:
[0150] Real-time acquisition of transaction parameters and encryption requirements in different business scenarios, and input into a pre-constructed encryption requirement model and output of risk amplitude;
[0151] Obtaining a first condition of key hierarchical constraint and a second condition of key update constraint, and quantifying initial security parameters based on the first condition and the second condition;The initial security parameters include: initial authentication security level and initial key rotation period;
[0152] Multi-dimensional disturbance simulation is performed on the initial security parameters to generate a plurality of to-be-optimized configuration vectors;The to-be-optimized configuration vectors are mapped to the multi-level encryption process, and the evaluation results are obtained based on the time complexity and the risk amplitude security cooperative evaluation, and the multi-dimensional key performance response surface is constructed based on the evaluation results and the to-be-optimized configuration vectors, and the curved surface sensitive area is identified and the best configuration is screened, and the optimal configuration vector is driven to execute.
[0153] In the application, the several formulas involved are dimensionless values, and the formula is a formula obtained by software simulation of a large amount of data to obtain the latest real situation, and the formula is set by a person skilled in the art according to the actual situation.
[0154] The above-described embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented by software, the above-described embodiments can be implemented in whole or in part in the form of a computer program product. A person of ordinary skill in the art can be aware that units and algorithm steps of the examples described in connection with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are performed by hardware or software depends on the specific application and design constraints of the technical solutions.
[0155] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, and can be located in one place or distributed on multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiments according to actual needs.
[0156] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application.
Claims
1. A key management system for bank-enterprise direct connection multi-level encryption transmission, characterized in that, The system comprises: A first acquisition module is configured to collect transaction parameters and encryption requirements in different business scenarios in real time, and input the transaction parameters and encryption requirements into a pre-constructed encryption requirement model to output a risk amplitude; A second acquisition module is configured to acquire a first condition of key hierarchical constraint and a second condition of key update constraint, quantify initial security parameters based on the first condition and the second condition, and acquire a time complexity, wherein the first condition comprises an authentication failure frequency and an encryption performance of each encryption level, the second condition comprises an attack frequency, an attack computing power, and an attack form, and the initial security parameters comprise an initial authentication security level and an initial key rotation period; the encryption level comprises a first hierarchical level, a second hierarchical level, and a third hierarchical level; the key rotation period is a ratio of a key validity period to a comprehensive cracking degree, and a response value is obtained by analyzing an attack frequency distribution; A configuration generation module is configured to simulate a multi-dimensional perturbation of the initial security parameters to generate a plurality of to-be-optimized configuration vectors, wherein the configuration vectors comprise different combinations of authentication security levels and key rotation periods; An evaluation and screening module is configured to map the to-be-optimized configuration vectors to a multi-level encryption process, perform a security collaborative evaluation based on the time complexity and the risk amplitude to obtain an evaluation result, construct a multi-dimensional key performance response surface based on the evaluation result and the to-be-optimized configuration vectors, identify a sensitive area of the surface, and screen an optimal configuration vector, wherein the security collaborative evaluation based on the time complexity and the risk amplitude comprises: performing a nonlinear transformation on the time complexity and the risk amplitude, establishing a two-dimensional curve graph of the time complexity and the risk amplitude, and correspondingly drawing a standard curve graph, superimposing the two-dimensional curve graph and the standard curve graph on each other to obtain an intersection area, a difference set area, a non-overlapping total area, and an overlapping total area, calculating a first ratio of the intersection area to the difference set area, calculating a second ratio of the overlapping total area to the non-overlapping total area, multiplying the first ratio and the second ratio, and performing a weighted difference operation on the first ratio, the second ratio, and the product of the two ratios to obtain the evaluation result; A driving execution module is configured to drive execution of the optimal configuration vector.
2. The key management system for silver link direct multi-level encryption transmission according to claim 1, characterized in that, The transaction parameters comprise a transaction amount, a transaction IP address, a transaction scenario, and a transaction timestamp, and the encryption requirements comprise at least a key length and an algorithm combination; the encryption requirement model comprises at least a feature extraction layer, a matrix correlation layer, and a risk evaluation layer.
3. The key management system for bank-enterprise direct connection multi-level encryption transmission according to claim 2, wherein: The feature extraction layer is configured to extract time-frequency domain features of the transaction parameters based on wavelet transformation; The matrix correlation layer is configured to construct a risk correlation matrix based on the time-frequency domain features and the encryption requirements; The risk evaluation layer is configured to form an evaluation rule set based on a business risk correlation matrix and a transaction topology graph, obtain a risk feature point and a risk time sequence, obtain a plurality of risk frequency bands by wavelet decomposition, calculate energy entropy values of the frequency bands and aggregate the energy entropy values according to a preset first weight to obtain second weight values of the risk frequency bands, and perform a weighted fusion on the entropy values of the frequency bands based on the second weight values to obtain the risk amplitude.
4. The key management system for silver link direct multi-level encryption transmission according to claim 1, characterized in that, The process of acquiring the initial authentication security level comprises: The encryption performance of each encryption level includes: Obtain the performance indicators of each encryption level and calculate the average performance value of each encryption level; wherein the performance indicators include encryption and decryption delay rate and resource consumption; analyze the dispersion degree of the performance indicators and the average performance value of each encryption level, and dynamically determine the parameter adjustment range based on the dispersion degree; Based on the risk amplitude and the authentication failure frequency, a corresponding sample set is formed, and the loss value between the samples is calculated. Combined with the first condition, the security level is filtered, and based on the minimum deviation matching from the filtered historical data, the authentication security level with the minimum current deviation is selected as the initial authentication security level.
5. The key management system for silver link direct multi-level encryption transmission according to claim 1, characterized in that, The acquisition process of the initial key rotation period includes: Form a binary tuple of the attack frequency and attack form in the preset time period and mark it as a frequency analysis group; Form a second tuple of the attack computing power and attack form in the preset time period and mark it as a computing power analysis group. The corresponding frequency analysis group and computing power analysis group in the password exposure process form a frequency analysis space and a computing power analysis space, respectively; Mark the standard score of the frequency analysis group in the frequency analysis space in the current measurement period as the first cracking degree; Mark the standard score of the computing power analysis group in the computing power analysis space in the current measurement period as the second cracking degree; Set a standard score threshold. If the first cracking degree or the second cracking degree of the current measurement period exceeds the standard score threshold, it indicates that the current system is at risk of password leakage. At the same time, the first cracking degree and the second cracking degree are weighted and summed to obtain a comprehensive cracking degree; The initial key rotation period is obtained by constraining the key rotation period data in the historical preset period through the second condition and averaging.
6. The key management system for silver link direct multi-level encryption transmission according to claim 1, characterized in that, The method includes: Identify a multi-parameter space based on the initial security parameters, and the parameter space at least includes the number of authentication factors, algorithm strength, time period, and trigger threshold; Based on the first condition and the second condition, the Latin hypercube sampling algorithm is used to generate uniformly distributed sample points only in the constrained parameter space to form the to-be-optimized configuration vector.
7. The key management system for silver link direct multi-level encryption transmission according to claim 1, characterized in that, The step of constructing the multi-dimensional key performance response surface includes: combining the to-be-optimized configuration vector and its corresponding evaluation result to form a sample set S1={optimized configuration vector A, evaluation result B}; and using a third-order polynomial response surface to construct a multi-dimensional key performance response curve of B=f(A).
8. The key management system of silver enterprise direct connection multi-level encryption transmission according to claim 1, characterized in that, The method includes: Based on the multi-dimensional key performance response curve, identify several peak regions as candidate regions; Based on the candidate regions, obtain the corresponding mean and fluctuation value, and construct several judgment vectors based on the evaluation results. The judgment vectors are input into a pre-constructed judgment model to output a judgment result. When the judgment result obtained by any judgment vector is greater than a preset judgment threshold, the candidate region is marked as a surface sensitive region; Based on the surface sensitive region, extract all to-be-optimized configuration vectors to form a candidate configuration pool; Generate a Pareto optimal solution set using the NSGA-II algorithm, filter the configuration vector that meets the optimization target of maximizing the evaluation effect and minimizing the fluctuation value, and mark it as the best configuration vector.
9. The key management method of the multi-level encryption transmission of bank-enterprise direct connection, characterized in that, The method includes: Real-time collection of transaction parameters and encryption requirements in different business scenarios, and input to the pre-constructed encryption requirement model, output risk amplitude; Obtain a first condition of key hierarchical constraint and a second condition of key update constraint, quantify initial security parameters based on the first condition and the second condition, and obtain time complexity, the first condition includes authentication failure frequency and encryption performance of each encryption level, the second condition includes attack frequency, attack computing power and attack form, the initial security parameters include initial authentication security level and initial key rotation period; wherein the encryption level includes first hierarchical, second hierarchical and third hierarchical; the key rotation period is the ratio of key validity period and comprehensive cracking degree, and the response value is obtained by analyzing attack frequency distribution; Multi-dimensional perturbation simulation is performed on the initial security parameters to generate a plurality of to-be-optimized configuration vectors, wherein the configuration vectors contain different combinations of authentication security levels and key rotation periods; Map the to-be-optimized configuration vectors to the multi-level encryption process, perform security collaborative evaluation based on the time complexity and the risk amplitude, obtain the evaluation results, construct a multi-dimensional key performance response surface based on the evaluation results and the to-be-optimized configuration vectors, identify the sensitive area of the surface and select the best configuration vector, wherein the security collaborative evaluation based on the time complexity and the risk amplitude includes: performing nonlinear transformation on the time complexity and the risk amplitude, establishing a two-dimensional curve graph of the time complexity-risk amplitude, and corresponding drawing a standard curve graph, superimposing the two-dimensional curve graph and the standard curve graph, obtaining the intersection area, the difference set area, the non-overlapping total area and the overlapping total area, calculating the first ratio of the intersection area and the difference set area, calculating the second ratio of the overlapping total area and the non-overlapping total area, multiplying the first ratio and the second ratio, and weightedly subtracting the first ratio, the second ratio and the result of multiplying the two ratios to obtain the evaluation results; Drive to execute the best configuration vector.
Citation Information
Patent Citations
Digital function management method and system based on data mining
CN119691781A
Smart power grid multi-time scale resource scheduling optimization method and system
CN119990716A