Information security protection method based on payment system

By analyzing the data structure of payment instructions, filtering and analyzing the characteristic information of the encrypted data fields, an abnormal change evaluation model is generated, and dynamically divided into three categories: stable, suspicious and abnormal, solving the problem of internal tampering of encrypted data fields in the existing technology, and improving the security protection capability and detection accuracy of the payment system.

CN120524482APending Publication Date: 2025-08-22SHENZHEN DONGCHENG COMMERCIAL MANAGEMENT CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510659386.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing information security protection technology based on payment systems cannot effectively identify abnormal changes in the content of the encrypted data field, making it difficult to detect and block tamper with timely impact on payment security and user assets.

Method used

By analyzing the data structure of the payment instructions, encrypted data fields with abnormal changes in content are filtered out, their characteristic information is obtained and analyzed in real time, entropy discrete coefficients and block offset index are generated, and an abnormal change evaluation model is constructed, which is dynamically divided into three categories: stable, suspicious and abnormal, and corresponding security protection measures are implemented.

Benefits of technology

Real-time screening and precise protection of potential tampering behaviors in payment instructions is realized, the active defense capabilities and detection accuracy of the payment system are improved, the misjudgment rate and misjudgment rate are reduced, and the system security and user transaction experience are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120524482A_ABST
    Figure CN120524482A_ABST
Patent Text Reader

Abstract

The invention discloses an information security protection method based on a payment system, and relates to the technical field of information security protection, and the method specifically comprises the following steps: screening an encrypted data field with abnormal content change from a to-be-detected encrypted field set, and calibrating the encrypted data field as a to-be-analyzed encrypted data field; acquiring encrypted field feature information of each to-be-analyzed encrypted data field in real time, analyzing the acquired encrypted field feature information, evaluating the abnormal change degree of the content of each to-be-analyzed encrypted data field in the payment instruction, and classifying the to-be-analyzed encrypted data field; and respectively executing corresponding safety protection measures according to classification results. According to the method, the problem that a payment system cannot perform dynamic screening according to the abnormal change degree in the encrypted data field is solved, accurate screening and graded protection of the encrypted data field are realized through abnormal change index evaluation and classification, and the tampering detection capability of the payment instruction and the safety protection level of the system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security protection, and in particular to an information security protection method based on a payment system. Background Art

[0002] Information security protection refers to the use of a series of technical means and management measures to safeguard the confidentiality, integrity, and availability of information during its collection, transmission, storage, and processing, preventing unauthorized access, tampering, disclosure, or destruction. In the modern digital economy, payment systems, as core platforms for capital circulation and transaction execution, have become widely used in scenarios such as online shopping, mobile payments, and cross-border settlements. This has led to increasingly serious information security risks, such as payment data interception, account fraud, and transaction content tampering. Therefore, payment system-based information security protection involves integrating encryption algorithms, multi-factor identity authentication, behavior recognition, and anti-replay mechanisms throughout the entire payment process to establish a dynamic, end-to-end information protection mechanism to ensure user identity authenticity, data transmission security, and trustworthy transaction behavior. This type of payment system-based security protection not only improves the overall security of financial transactions and prevents fraud and data leakage risks, but also enhances user trust and promotes the healthy development of the digital payment ecosystem, possessing significant technical and economic significance.

[0003] Existing information security technologies for payment systems typically cover the entire payment process, primarily encompassing four core components: identity authentication, secure communications, transaction verification, and risk control. For identity authentication, systems generally employ multi-factor authentication, combining passwords, biometrics (such as fingerprints and facial recognition), and one-time passwords (OTPs) to verify user identities and prevent unauthorized account access. For secure communications, payment data is encrypted using SSL / TLS or national security algorithms to prevent eavesdropping or tampering. For transaction verification, digital signatures, dynamic verification codes, or hardware security modules (HSMs) are used to verify the uniqueness and integrity of transaction requests, preventing forgery and replay attacks. For risk control, systems incorporate risk control models based on big data and artificial intelligence to analyze transaction behavior in real time, such as determining parameters like the user's device, IP address, and transaction frequency, to identify anomalous operations and trigger timely interception mechanisms. These technologies work together to form a comprehensive security system encompassing "pre-emptive protection, in-process detection, and post-event tracing," effectively safeguarding the operational security of the payment system and the integrity of user funds.

[0004] The existing technology has the following deficiencies: In payment systems, when a user terminal is infected with a Trojan virus or a payment instruction is attacked by a man-in-the-middle attack in a network link, the encrypted data fields in the payment instruction (such as the transaction summary or the sensitive information encryption block) may still comply with the protocol requirements in terms of overall format, but the internal data content may be partially tampered with or reconstructed, resulting in abnormal changes in the content of the encrypted data fields. Since these abnormal changes are usually hidden within the encryption structure, they are difficult to directly identify with the naked eye or traditional surface verification methods, resulting in the key transaction information in the instruction being quietly tampered with. Existing information security protection technologies based on payment systems can only perform static verification based on the existence and format standardization of the encrypted fields, and cannot dynamically screen and grade the encrypted field data based on the degree of abnormal changes in the internal content of the encrypted data fields. As a result, the tampering behavior bypasses the conventional detection process, and the attack cannot be discovered and blocked in time, ultimately causing the payment funds to flow to the wrong target account, resulting in user asset losses, an increase in platform security incidents, and increased difficulty in subsequent tracing, which in turn seriously damages the platform's security reputation and compliance stability.

[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the Invention

[0006] The purpose of the present invention is to provide an information security protection method based on a payment system to solve the problems in the above-mentioned background technology.

[0007] In order to achieve the above-mentioned object, the present invention provides the following technical solution: an information security protection method based on a payment system, specifically comprising the following steps: By parsing the data structure of the payment instruction submitted by the user, all encrypted data fields in the payment instruction are determined to form a set of encrypted data fields to be detected; Filter out encrypted data fields with abnormal content changes from the set of encrypted fields to be detected, and mark them as encrypted data fields to be analyzed; Acquire encrypted field feature information of each encrypted data field to be analyzed in real time, analyze it after acquisition, assess the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction, and classify them; According to the classification results, corresponding safety protection measures are implemented respectively; Collect detection data of payment instructions and the execution results of security protection measures, and continuously optimize the information security protection capabilities of the payment system based on the collected data.

[0008] Preferably, the encrypted data fields with abnormal content changes are screened out from the set of encrypted fields to be detected, and are marked as encrypted data fields to be analyzed, specifically: Extracting content features from each encrypted data field in the set of encrypted data fields to be detected, wherein the content features include data distribution features, encoding features, and structural features; Based on the extracted features, each encrypted data field is checked for content feature anomalies according to the preset content consistency verification rules; The encrypted data field with a verification result showing abnormal content characteristics is marked as the encrypted data field to be analyzed.

[0009] Preferably, the encrypted field feature information of each encrypted data field to be analyzed is obtained in real time, and analyzed after acquisition to evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction and classify them, specifically including the following steps: Acquire encrypted field feature information of each encrypted data field to be analyzed in real time and perform preprocessing after acquisition; Extracting block entropy distribution information and block bit offset information from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, and analyzing the extracted information to generate an entropy dispersion coefficient and a block offset index for each encrypted data field to be analyzed; Constructing an abnormal change assessment model based on the generated entropy discrete coefficient and block offset index of each encrypted data field to be analyzed, and generating an abnormal change index for each encrypted data field to be analyzed by weighted summation; Determine a pre-set abnormal change index threshold range, and after determination, compare it with the generated abnormal change index of each encrypted data field to be analyzed. Evaluate the degree of abnormal change in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results, and divide each encrypted data field to be analyzed into stable encrypted data fields, suspicious encrypted data fields and abnormal encrypted data fields based on the evaluation results.

[0010] Preferably, the logic for obtaining the entropy discrete coefficient of each encrypted data field to be analyzed is as follows: The block entropy distribution information is extracted from the encrypted field feature information of each encrypted data field to be analyzed after preprocessing, specifically including the entropy value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The entropy value of a data block, , , is a positive integer; Calculate the average entropy value of all data blocks in each encrypted data field to be analyzed using the average formula ; The standard deviation formula is used to calculate the standard deviation of the entropy values ​​of all data blocks in each encrypted data field to be analyzed. ; Calculate the entropy dispersion coefficient of each encrypted data field to be analyzed The specific calculation logic is: the standard deviation of the entropy value of all data blocks in each encrypted data field to be analyzed and average Perform a ratio operation to calculate the proportional relationship between the two, add 1 to the proportional relationship and take the natural logarithm to obtain the entropy dispersion coefficient used to reflect the degree of entropy fluctuation within each encrypted data field. .

[0011] Preferably, the logic for obtaining the block offset index of each encrypted data field to be analyzed is as follows: The block bit offset information is extracted from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, specifically including the average bit value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The average bit value of a data block, , , is a positive integer; Calculate the average bit value of all data blocks in each encrypted data field to be analyzed using the average formula ; Calculate the block offset index of each encrypted data field to be analyzed , the specific calculation logic is as follows: encrypted data fields to be analyzed, and calculate the average bit value of each data block and the average The square of the difference between the two data blocks is summed and averaged to get the mean square error. The mean square error result is then squared, and 1 is added to the square result and the natural logarithm is taken to finally get the first Block offset index of the encrypted data field to be analyzed .

[0012] Preferably, the entropy discrete coefficient of each encrypted data field to be analyzed is generated and block offset index Construct an abnormal change assessment model and generate the abnormal change index of each encrypted data field to be analyzed through weighted summation .

[0013] Preferably, a preset abnormal change index threshold interval is determined , and after confirmation, compare it with the abnormal change index of each encrypted data field to be analyzed Perform a comparison and evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results. Based on the evaluation results, each encrypted data field to be analyzed is divided into stable encrypted data fields, suspicious encrypted data fields, and abnormal encrypted data fields. The specific comparison analysis and classification are as follows: like , the degree of abnormal change of the content of the encrypted data field to be analyzed in the payment instruction is low, and the encrypted data field to be analyzed is classified as a stable encrypted data field; like , the degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is medium, and the encrypted data field to be analyzed is classified as a suspicious encrypted data field; like The degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is high, and the encrypted data field to be analyzed is classified as an abnormal encrypted data field.

[0014] Preferably, corresponding safety protection measures are implemented according to the classification results, specifically: For encrypted data fields to be analyzed that are classified as stable encrypted data fields, the security protection measures implemented are: the corresponding payment instructions are forwarded to the payment execution channel for subsequent processing without additional intervention; For encrypted data fields that are classified as suspicious encrypted data fields, the security protection measures implemented are: sending a text message verification code to the user and requiring them to enter the verification code, and performing a hash value comparison and verification on the data content of the payment instruction; For the encrypted data fields to be analyzed that are classified as abnormal encrypted data fields, the security protection measures implemented are: suspending the processing flow of the payment instruction, saving the original data record of the payment instruction, and pushing the abnormal mark to the designated review process.

[0015] In the above technical solution, the technical effects and advantages provided by the present invention are: 1. The present invention introduces a dynamic detection mechanism based on the internal characteristics of the encrypted data field, which can effectively discover internal tampering risks that are difficult to identify by traditional payment instruction verification methods. Specifically, by extracting the block entropy distribution information and block bit offset information in the encrypted data field, the entropy dispersion coefficient and block offset index are generated respectively, and an abnormal change assessment model is constructed to comprehensively evaluate the degree of abnormal changes in the content of the encrypted data field; further, based on the comparison result of the abnormal change index with the preset threshold interval, the encrypted data field is dynamically divided into three categories: stable, suspicious and abnormal, and then corresponding security protection measures are implemented respectively, realizing real-time screening, intelligent classification and precise protection of potential tampering behaviors in payment instructions, and greatly improving the active defense capability and detection accuracy of the payment system when facing complex threats such as man-in-the-middle attacks and Trojan horse implants.

[0016] 2. The present invention not only breaks through the traditional static security detection method that only relies on format verification and existence verification, but also enables the system to sensitively capture small and hidden data tampering behaviors through real-time quantitative analysis based on the internal change characteristics of data content; at the same time, the classification processing mechanism ensures differentiated responses to payment instructions of different risk levels, avoiding a "one-size-fits-all" security processing approach, which not only improves the success rate of intercepting abnormal instructions, but also maximizes the smoothness of normal payment transactions, taking into account both system security and user transaction experience, significantly reducing the false positive rate and missed positive rate, and improving the accuracy and rationality of overall security protection.

[0017] 3. The present invention realizes the dynamic optimization and adaptive evolution of the information security protection capabilities of the payment system by synchronously collecting detection data and protection results during the payment instruction detection and protection execution process, and continuously adjusting the detection parameters and updating the classification thresholds based on historical data; this data closed-loop optimization mechanism enables the system to timely adjust its own protection strategy according to the ever-changing attack methods in the actual operating environment, and has the ability to continuously evolve and respond to new threats, effectively enhancing the long-term stability and anti-attack resilience of the payment system, and providing technical support for building a sustainable and highly reliable information security protection system. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction to the drawings required for use in the embodiments will be given below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0019] Figure 1 This is a flow chart of an information security protection method based on a payment system according to the present invention; Figure 2This is a method mind map of an information security protection method based on a payment system of the present invention. DETAILED DESCRIPTION

[0020] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these example embodiments are provided so that the description of this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art.

[0021] The present invention provides Figure 1 and Figure 2 The information security protection method based on the payment system shown includes the following steps: By parsing the data structure of the payment instruction submitted by the user, all encrypted data fields in the payment instruction are determined to form a set of encrypted data fields to be detected; By setting up an instruction parsing module in the payment system, the data structure of payment instructions submitted by users can be automatically parsed. In specific implementation, the system first extracts the field level information of the instruction according to the payment protocol standard, including basic metadata such as field name, data type, and field length. Then, the system matches and screens based on the encryption identification bit in the field attributes, the field data format (such as Base64 encoding, hexadecimal format), and field length characteristics (such as fixed length or exceeding the range of ordinary text fields), identifying fields that meet the encryption characteristics one by one and marking them as encrypted data fields. In this way, all fields containing encrypted data can be parsed in real time and accurately after the instruction is received, providing a data foundation for subsequent detection.

[0022] After identifying each encrypted data field in a payment instruction, the system can centrally manage all content marked as encrypted data fields by constructing a dynamic field set. Specifically, this can be achieved by allocating a set storage area in memory and uniformly storing the data according to the structure of the field identifier, field location index, and field original data. At the same time, the system can attach basic attribute tags to each encrypted data field in the set, such as the field source, the instruction number, and the field length, to facilitate subsequent analysis and processing. This collective management approach not only enables efficient and unified scheduling and access to all encrypted data fields to be tested, but also ensures data integrity and relevance during the testing process.

[0023] The reason why it is necessary to parse the data structure of the payment instructions submitted by the user to determine all encrypted data fields and form a set to be detected is that in the payment scenario, encrypted data fields are often distributed in different locations and may appear to be similar to the format of ordinary data fields. If they are not parsed and collected uniformly first, missed detection or misjudgment may occur easily. In addition, the encrypted field structures of different instruction sources may be different. Directly scanning the original instructions as a whole is not only inefficient, but also prone to misjudgment. Therefore, accurate identification must be ensured through data structure analysis. By forming a unified set of encrypted fields to be detected, centralized processing and efficient management of encrypted data can be achieved, providing standardized and normalized data support for subsequent feature collection, anomaly analysis and dynamic screening, thereby improving the accuracy and response speed of the entire security protection process.

[0024] Filter out encrypted data fields with abnormal content changes from the set of encrypted fields to be detected, and mark them as encrypted data fields to be analyzed; In this embodiment, encrypted data fields with abnormal content changes are screened out from the set of encrypted fields to be detected and marked as encrypted data fields to be analyzed. Specifically: Extracting content features from each encrypted data field in the set of encrypted data fields to be detected, wherein the content features include data distribution features, encoding features, and structural features; In actual implementation, a feature extraction module can be established in the payment system to extract content features of each encrypted data field in the set of encrypted data fields to be detected. The specific method is as follows: first, for each encrypted data field, its original binary data is extracted, and the data distribution characteristics are obtained by counting the proportion of different bits (0 and 1) in the overall data block, so as to identify whether the encrypted field conforms to the random distribution law that normal encrypted data should have; second, the encoding format of the encrypted data field is parsed, such as Base64 encoding, hexadecimal encoding or other custom encoding, and its encoding features, including encoding type and encoding integrity features, are extracted to determine whether the data block has abnormal deformation or format tampering at the encoding level; third, according to the encryption protocol or standard, the structural features of the encrypted data field are parsed, such as block length consistency and field grouping mode (such as whether it meets the encryption block length requirements of AES, SM4, etc.), to identify whether the encryption block structure has been tampered with. Through such content feature extraction, potential encrypted data anomalies can be quickly screened out based solely on surface physical and statistical properties without decrypting the data content, laying an efficient and accurate data foundation for subsequent anomaly assessment and dynamic protection, thereby greatly improving the system's perception and screening efficiency of hidden tampering behaviors within encrypted data fields.

[0025] Based on the extracted features, each encrypted data field is checked for content feature anomalies according to the preset content consistency verification rules; In a specific implementation, a content consistency check module can be configured in the payment system to perform anomaly checks on each encrypted data field based on the extracted content features. The specific method is as follows: First, for data distribution features, the system can compare the bit statistics of the current encrypted data field with the preset standard random distribution interval. If it exceeds the interval, it is considered a data distribution anomaly; second, for encoding features, the system can compare the extracted encoding type with the encoding specifications specified in the payment agreement. If the encoding format does not match or there is an abnormal character distribution, it is considered an encoding anomaly; third, for structural features, the system can perform consistency checks with standard encryption structure rules based on field length, grouping mode, etc. If it is found that the field length is abnormal or the grouping structure is damaged, it is considered a structural anomaly. In this way, without relying on the decryption process, the encrypted data field can be quickly verified for consistency based only on the content feature level, potential abnormal changes can be discovered in a timely manner, and detection vulnerabilities caused by internal data being tampered with but the external format is still legal can be effectively avoided, thereby ensuring the data integrity and transaction security of the payment system.

[0026] The encrypted data field with a verification result showing abnormal content characteristics is marked as the encrypted data field to be analyzed.

[0027] In practical implementation, an anomaly detection module can be established within the payment system to identify encrypted data fields identified as having abnormal content characteristics after content consistency verification, placing them in a pending analysis state. Specifically, upon detecting any of the following: data distribution anomalies, encoding anomalies, or structural anomalies in an encrypted data field, the system automatically assigns the field a pending analysis status flag and registers the encrypted data field's unique identification information (such as field index, field location, and instruction number) in a pending analysis field management list for subsequent feature analysis and anomaly assessment modules. Furthermore, anomaly type information is appended to each pending encrypted data field to support subsequent tiered processing based on the type of abnormal characteristics. This approach allows for efficient and automatic isolation of potentially high-risk data fields within the overall detection process, ensuring that subsequent anomaly assessments are conducted only on fields that demonstrate signs of anomalies. This effectively improves the utilization of system detection resources, reduces false positives and missed detections, and further enhances the accuracy and timeliness of payment instruction data security protection.

[0028] Acquire encrypted field feature information of each encrypted data field to be analyzed in real time, analyze it after acquisition, assess the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction, and classify them; In this embodiment, encrypted field feature information of each encrypted data field to be analyzed is obtained in real time, and analyzed after acquisition to evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction and classify them. Specifically, the following steps are included: Acquire encrypted field feature information of each encrypted data field to be analyzed in real time and perform preprocessing after acquisition; In actual applications, by deploying a data monitoring and processing module, the raw data content of each encrypted data field to be analyzed can be intercepted in real time before the payment instruction flows to the transaction verification stage. The specific implementation method is as follows: After the payment instruction reaches the parsing module, the system automatically parses the instruction's data structure, identifies and extracts the encrypted data fields marked for analysis; then, for each encrypted data field, it calls the built-in data feature extraction engine to read the field's raw bit data in real time, completing the capture and caching of basic data units (such as bytes and bits); during the capture process, the system also extracts metadata associated with the field, such as field length, encoding method prompts, and grouping mode information, to ensure that subsequent analysis steps have complete data context. Through this method, the encrypted field feature information of each encrypted data field to be analyzed can be obtained in real time and without interruption during the instruction flow, providing continuous data support for subsequent abnormal change analysis.

[0029] Preprocessing encrypted field feature information acquired in real time is essential. This is primarily because raw feature data directly acquired may contain various noise factors, encoding anomalies, or format misalignments. Without standardized preprocessing, this can lead to deviations in subsequent feature extraction and parameter calculation, impacting the accuracy and reliability of anomaly change assessment. Specific preprocessing steps include data normalization, encoding format standardization verification and correction, and field structure boundary verification. First, the system normalizes field data based on the original length and bit distribution of the field to ensure that feature collection is based on a uniform scale. Second, the field encoding format is verified to ensure compliance with pre-set standard encodings (such as Base64 and Hex). Any non-compliant encodings are automatically transcoded or corrected. Finally, the logical grouping boundaries of the field are verified to correct potential grouping misalignments or block truncation. These multiple preprocessing steps ensure that the subsequently extracted block entropy distribution and block bit offset information are highly consistent and comparable, thereby improving the overall stability and accuracy of the anomaly detection model.

[0030] Extracting block entropy distribution information and block bit offset information from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, and analyzing the extracted information to generate an entropy dispersion coefficient and a block offset index for each encrypted data field to be analyzed; In practical implementation, the feature information extraction module can be used to partition the pre-processed encrypted field feature information of each encrypted data field to be analyzed into blocks. Based on the block partitioning results, block entropy distribution information and block bit offset information are extracted. Specifically, the system first divides the bit stream of each encrypted data field into several data blocks according to a set fixed length standard (e.g., every 128 bits or 256 bits). Then, for each data block, the system performs two-dimensional feature extraction: first, the distribution frequency of each bit value (0 and 1) within each block is calculated, and the information entropy value of the single block is calculated based on the bit distribution frequency, thereby forming the corresponding block entropy distribution information. Second, the system calculates the mean proportion of bits 1 within each block and the global mean of bits 1 across the entire field. By comparing the local mean with the global mean, the offset data for each block is generated, thereby generating block bit offset information. This software processing method based on block entropy calculation and bit mean offset calculation can systematically extract key feature information for each encrypted data field at the local and global levels, providing an accurate and quantitative data foundation for subsequent parameter generation and abnormal change assessment.

[0031] Constructing an abnormal change assessment model based on the generated entropy discrete coefficient and block offset index of each encrypted data field to be analyzed, and generating an abnormal change index for each encrypted data field to be analyzed by weighted summation; Determine a pre-set abnormal change index threshold range, and after determination, compare it with the generated abnormal change index of each encrypted data field to be analyzed. Evaluate the degree of abnormal change in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results, and divide each encrypted data field to be analyzed into stable encrypted data fields, suspicious encrypted data fields and abnormal encrypted data fields based on the evaluation results.

[0032] In actual implementation, the abnormality threshold configuration module can be used to determine the pre-set threshold range for the abnormal change index. Specifically, the system initially collects a large number of encrypted data field samples labeled as normal, suspicious, and abnormal based on historical payment instruction data samples. For each sample, the system calculates the corresponding abnormal change index and establishes a distribution model for the abnormal change index. Subsequently, using statistical analysis methods such as percentiles or cluster analysis, the system automatically analyzes the distribution characteristics of the abnormal change index across samples of different categories and determines the critical thresholds between different categories. Based on these critical values, the system sets the first and second threshold ranges, ensuring clear and stable demarcations between the normal, suspicious, and abnormal categories of encrypted data fields based on the abnormal change index. During subsequent operation, the system can continuously revise and fine-tune the threshold ranges based on real-time detection data to adapt to changes in the payment environment and evolving attack methods. This historical data-based modeling and dynamic maintenance approach allows for the rational, scientific, and sustainable determination of the abnormal change index threshold ranges, ensuring that the payment system can accurately distinguish encrypted data fields with varying degrees of abnormality.

[0033] In this embodiment, the logic for obtaining the entropy discrete coefficient of each encrypted data field to be analyzed is as follows: The block entropy distribution information is extracted from the encrypted field feature information of each encrypted data field to be analyzed after preprocessing, specifically including the entropy value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The entropy value of a data block, , , is a positive integer; In actual implementation, a data block entropy calculation module can be set up to divide the bit stream of the encrypted data field to be analyzed into multiple continuous data blocks of fixed length during the real-time flow and parsing of the encrypted data field. The information entropy value of each data block is calculated in real time. The specific method is as follows: First, according to the preset block division rule (such as each 128-bit or 256-bit bit is a block), the bit stream of the encrypted data field is sequentially intercepted to form several independent data block units. Then, for each data block, the system calculates the frequency distribution of different bit states (usually 0 and 1) in the block and calculates the entropy value of the current data block based on the Shannon entropy formula. The entropy value is a single, specific real value that reflects the randomness and information richness of the bit distribution within the data block. The closer the entropy value is to the theoretical maximum value, the more uniform the bit distribution is and the higher the randomness is. The lower the entropy value is, the more biased or patterned the bit distribution is, and the lower the randomness is. Through the above software method, during the payment instruction parsing and detection process, the entropy value set of each data block in each encrypted data field to be analyzed can be obtained in real time and dynamically, laying the foundation for subsequent abnormality analysis, abnormal change index calculation and encrypted data field classification, ensuring that the system can accurately grasp the internal change trend of the data without destroying the privacy of the encrypted data, thereby improving the real-time and accuracy of the overall security protection.

[0034] Calculate the average entropy value of all data blocks in each encrypted data field to be analyzed using the average formula , according to the formula: ; The standard deviation formula is used to calculate the standard deviation of the entropy values ​​of all data blocks in each encrypted data field to be analyzed. , according to the formula: ; Calculate the entropy dispersion coefficient of each encrypted data field to be analyzed The specific calculation logic is: the standard deviation of the entropy value of all data blocks in each encrypted data field to be analyzed and average Perform a ratio operation to calculate the proportional relationship between the two, add 1 to the proportional relationship and take the natural logarithm to obtain the entropy dispersion coefficient used to reflect the degree of entropy fluctuation within each encrypted data field. The specific calculation formula is as follows: Where, For the The entropy dispersion coefficient of the encrypted data field to be analyzed.

[0035] When evaluating abnormal changes in each encrypted data field to be analyzed, the ratio of the standard deviation of the entropy value of the data block to the average value can be calculated to reflect the degree of dispersion of local entropy fluctuations relative to the overall entropy level. Therefore, the ratio of the standard deviation to the average value is first used as the basic abnormality indicator; because in actual data, there are cases where the entropy standard deviation is close to zero or the average value is extremely small, a direct ratio may cause extreme numerical amplification or instability. Therefore, 1 is added to the ratio to ensure that the ratio is always greater than zero to avoid mathematical errors in logarithmic calculations; further, the natural logarithm of the result after adding 1 is taken, which can compress the abnormal numerical range while ensuring the ability to perceive the abnormal amplitude, reduce the interference of extreme abnormal values ​​on subsequent processing, and make the entropy dispersion coefficient show a more stable, continuous and distinguishable change trend as a whole, thereby more accurately quantifying the degree of random abnormality in the content of the encrypted data field, and providing a reliable basis for subsequent classification evaluation.

[0036] No. The entropy dispersion coefficient of the encrypted data field to be analyzed It reflects the degree of dispersion of the entropy fluctuation amplitude of each data block within the encrypted data field relative to the overall entropy level. Therefore, the larger the entropy dispersion coefficient value, the more significant the randomness difference between the data blocks, and the higher the degree of abnormal change of the local content, which means that there may be more serious data tampering, insertion or destruction behavior within the encrypted data field; on the contrary, the smaller the entropy dispersion coefficient value, the more uniform the change of the data block entropy value, the stable overall structure, and the lower the degree of change of the data content, so the possibility of content tampering or abnormal modification is smaller; therefore, by comparing the size of the entropy dispersion coefficient of each encrypted data field to be analyzed, the degree of abnormal change of the content of the encrypted data field in the payment instruction can be effectively quantified and evaluated, providing an accurate basis for subsequent classification processing and security protection decision-making.

[0037] In this embodiment, the logic for obtaining the block offset index of each encrypted data field to be analyzed is as follows: The block bit offset information is extracted from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, specifically including the average bit value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The average bit value of a data block, , , is a positive integer; In actual implementation, a bit statistics module can be deployed to monitor and process the encrypted data field to be analyzed in real time during the payment instruction parsing process. The specific method is as follows: First, the system sequentially divides the bit stream of the encrypted data field into several data blocks according to a preset block segmentation rule (for example, each 128 or 256 bits is a block). Then, for each data block, the system uses a bit scanning method to count the number of bits with a value of 1 among all bits in the block and divide this number by the total number of bits in the data block to obtain the average bit value of the data block. The average bit value is a specific value between 0 and 1, indicating the density of bits 1 in the block, thereby quantifying the local characteristics of the data block. An average bit value close to 0.5 generally indicates a relatively uniform bit distribution within the data block and high randomness, while deviations from 0.5 may indicate an abnormal data pattern or local data tampering. Through this software method, the average bit value of each data block in each encrypted data field to be analyzed can be extracted dynamically and in real time. This not only captures internal characteristics without destroying the encrypted data structure, but also provides accurate and quantifiable basic information for subsequent deviation assessment and anomaly screening.

[0038] Calculate the average bit value of all data blocks in each encrypted data field to be analyzed using the average formula , according to the formula: ; Calculate the block offset index of each encrypted data field to be analyzed , the specific calculation logic is as follows: encrypted data fields to be analyzed, and calculate the average bit value of each data block and the average The square of the difference between the two data blocks is summed and averaged to get the mean square error. The mean square error result is then squared, and 1 is added to the square result and the natural logarithm is taken to finally get the first Block offset index of the encrypted data field to be analyzed The specific calculation formula is as follows: Where, For the The block offset index of the encrypted data field to be analyzed.

[0039] When evaluating the degree of abnormal variation in each encrypted data field to be analyzed, the square of the difference between the average bit value of each data block and the overall average bit value is first calculated, and the average of the squared differences of all data blocks is taken. This can quantify the overall degree of deviation between the local bit distribution and the overall distribution, reflecting the basic trend of local anomalies within the field. Furthermore, squaring the mean square error result can enhance the sensitivity to changes in the amplitude of local deviations, so that even small local anomalies can be clearly reflected in the numerical value. To ensure the mathematical stability of subsequent calculations, avoid logarithmic operation anomalies caused by zero mean square error, and reasonably compress the extreme values ​​caused by large abnormal deviations, the design adds 1 to the squared result and finally takes the natural logarithm. The output range is smoothed by the logarithmic function, making the deviation degree variation more continuous, stable, and controllable. Therefore, the entire block deviation index calculation process can both sensitively amplify local anomalies and effectively suppress the system instability caused by abnormal amplification, thereby accurately quantifying the local deviation characteristics of encrypted data fields and providing a solid data foundation for the scientific assessment of the degree of abnormal variation.

[0040] No. Block offset index of the encrypted data field to be analyzed It reflects the degree of deviation between the bit distribution characteristics of each local data block within the field and the overall average distribution characteristics. The larger the value of the block offset index, the more significant the difference between the bit distribution of the local data block and the overall structure, and the higher the amplitude of local abnormal changes, indicating that the internal content of the encrypted data field may have local tampering, insertion, deletion or other forms of abnormal changes, thereby causing overall consistency to be destroyed; on the contrary, the smaller the value of the block offset index, the more consistent the bit distribution characteristics of the local data block and the overall structure, the smaller the degree of change in the data content, and the lower the risk of tampering. Therefore, by comparing the block offset index sizes of each encrypted data field to be analyzed, the degree of abnormal change in the content of the encrypted data field in the payment instruction can be effectively quantitatively evaluated, which serves as an important basis for subsequent classification screening and security protection decision-making.

[0041] In this embodiment, the entropy discrete coefficient of each encrypted data field to be analyzed is generated. and block offset index Construct an abnormal change assessment model and generate the abnormal change index of each encrypted data field to be analyzed through weighted summation , the specific calculation formula is as follows: Where, For the The abnormal change index of the encrypted data field to be analyzed, and The entropy discrete coefficients of each encrypted data field to be analyzed and block offset index The non-zero weight coefficient of .

[0042] In actual implementation, the system completes the entropy discrete coefficient of each encrypted data field to be analyzed. and block offset index After the calculation, the abnormal change evaluation module is called to generate the abnormal change index according to the set weighted summation formula. , specifically: the system is and Configure non-zero weight coefficients separately and ,in and It is a coefficient predetermined based on the system security strategy and historical detection performance evaluation results, and the sum of the two is 1 to ensure the normalization of the contribution of each feature; weight coefficient It is used to adjust the proportion of entropy discrete features in the abnormal change index, usually used to highlight the importance of overall random fluctuations, and the weight coefficient Used to adjust the proportion of local block offset features, suitable for highlighting the detection sensitivity of local abnormal changes; during the calculation process, the system calls and The current value of is multiplied by the corresponding weight coefficient and then summed to form ,In this way, the contribution of different features to the abnormal changes in ,encrypted data fields can be comprehensively considered, ensuring that the evaluation results ,can reflect the overall abnormal fluctuations and sensitively capture ,local abnormal changes, thereby improving the payment system’s detection ,accuracy and response capabilities to potential tampering risks.

[0043] In this embodiment, the preset abnormal change index threshold interval is determined , and after confirmation, compare it with the abnormal change index of each encrypted data field to be analyzed Perform a comparison and evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results. Based on the evaluation results, each encrypted data field to be analyzed is divided into stable encrypted data fields, suspicious encrypted data fields, and abnormal encrypted data fields. The specific comparison analysis and classification are as follows: like , the degree of abnormal change of the content of the encrypted data field to be analyzed in the payment instruction is low, and the encrypted data field to be analyzed is classified as a stable encrypted data field; This situation shows that the random distribution characteristics of each local data block within the encrypted data field are highly consistent with the overall average level, the local fluctuations are extremely small, the data content has not shown obvious tampering, forgery or other abnormal changes, and the overall structure shows good stability and continuity. In this case, it can be determined that the content of the encrypted data field is in a safe and normal state and does not require additional protection processing, thereby reducing the resource consumption of the payment system, improving transaction efficiency, and helping to maintain the smoothness and reliability of the overall system processing flow.

[0044] like , the degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is medium, and the encrypted data field to be analyzed is classified as a suspicious encrypted data field; This situation indicates that there is a certain degree of deviation in the random distribution or bit density characteristics of the local data blocks within the encrypted data field. The amplitude of local abnormal fluctuations is obvious but not extremely serious. It may be caused by multiple factors such as equipment abnormalities, minor interference in the communication link, non-standard operations or minor tampering. In this case, the payment system needs to perform enhanced verification or composite testing on the encrypted data field to further confirm its data integrity and legitimacy, thereby improving the ability to actively identify potential security risks without affecting the normal transaction experience and effectively suppressing the spread of risks.

[0045] like The degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is high, and the encrypted data field to be analyzed is classified as an abnormal encrypted data field.

[0046] This situation shows that the bit distribution characteristics of the local data block within the encrypted data field deviate significantly from the overall average level, and the local entropy value fluctuates violently and is systematically abnormal, which strongly indicates that the field may have been subjected to malicious operations such as tampering, forgery, insertion, and truncation. In this case, advanced security protection measures such as interception, isolation or termination of transactions must be immediately implemented on the encrypted data field to prevent potential abnormal fund flows, asset losses and systemic security incidents. At the same time, abnormal evidence support should be provided in the subsequent audit and evidence collection process to comprehensively strengthen the security prevention and control capabilities and compliance audit system of the payment platform.

[0047] According to the classification results, corresponding safety protection measures are implemented respectively; In this embodiment, corresponding security protection measures are executed according to the classification results, specifically: For encrypted data fields to be analyzed that are classified as stable encrypted data fields, the security protection measures implemented are: the corresponding payment instructions are forwarded to the payment execution channel for subsequent processing without additional intervention; For encrypted data fields to be analyzed that are classified as stable encrypted data fields, protection can be achieved through instruction status determination and instruction routing control. Specifically, after the payment instruction passes the abnormal change assessment, the system identifies the stable encrypted data field based on the classification label. For this field, the software process directly marks the instruction as "normal" and forwards the payment instruction to the subsequent transaction processing channel according to the standard transaction process through the internal instruction routing table, without the need for additional verification or interception processing. The reason for adopting this method is that the stable encrypted data field has been confirmed to have no abnormal changes in its internal data structure through feature analysis. Continuing to execute the standard transaction path can avoid waste of resources, improve instruction processing efficiency, and reduce interference with normal user transaction experience. It meets the payment system's requirements for efficient and secure processing processes.

[0048] For encrypted data fields that are classified as suspicious encrypted data fields, the security protection measures implemented are: sending a text message verification code to the user and requiring them to enter the verification code, and performing a hash value comparison and verification on the data content of the payment instruction; For encrypted data fields classified as suspicious and awaiting analysis, protection can be achieved by triggering a verification action chain through instruction tags. Specifically, after evaluating and classifying the payment instruction, the software process adds a "Second Verification Pending" status tag to the instruction marked as a suspicious encrypted data field. The processing flow then calls the SMS verification code generation module, sends a random verification code to the user terminal bound to the payment instruction, and initiates an input verification request on the user interface. Simultaneously, a data consistency verification tool calculates a hash value based on the original instruction data and compares it with a reserved hash value. Only when the user verification code is verified and the hash value is consistent is the instruction allowed to continue. This approach is adopted because suspicious encrypted data fields have a certain degree of data deviation, and the risk cannot be ignored. The double verification mechanism can effectively confirm the integrity of the instruction data and the authenticity of the user operation, taking into account both security and user experience, and preventing the expansion of potential risks.

[0049] For the encrypted data fields to be analyzed that are classified as abnormal encrypted data fields, the security protection measures implemented are: suspending the processing flow of the payment instruction, saving the original data record of the payment instruction, and pushing the abnormal mark to the designated review process.

[0050] For encrypted data fields to be analyzed that are classified as abnormal encrypted data fields, protection can be achieved through instruction interception and exception record distribution. Specifically, after a payment instruction completes the abnormal change assessment and is identified as an abnormal encrypted data field, the software process immediately performs forced interception processing on the instruction, setting the instruction processing status to "terminated" and writing all the original data of the instruction (including the instruction number, field data, timestamp, etc.) to the abnormal data storage area. The process control logic then reports the abnormality mark to the predefined review path and pushes the abnormality number to the manual review queue through a preset interface for further investigation. This approach is adopted because abnormal encrypted data fields have an extremely high risk of tampering, and the spread of their impact must be promptly blocked at the source. At the same time, by fully recording the abnormal instruction data, reliable evidence is provided for subsequent security audits and accountability, ensuring the stability and traceability of the overall operation of the payment system.

[0051] Collect detection data of payment instructions and the execution results of security protection measures, and continuously optimize the information security protection capabilities of the payment system based on the collected data.

[0052] In actual applications, by setting up a payment instruction detection data recording module and a security protection measure execution recording module, all intermediate data generated by each payment instruction in the detection process can be collected in real time, including the payment instruction's preliminary detection results, classification labels, abnormal change index values, the instruction's final processing status (such as release, secondary verification, and termination), and the corresponding security protection action execution log. The specific implementation method is as follows: when the instruction flows to each detection node or protection node, the internal event monitoring mechanism automatically captures the input features, judgment results, and action decision information during the detection process, and stores this data in a structured manner in a specific data collection buffer. After the instruction processing process is completed, it is uniformly packaged and written into the continuous optimization database. At the same time, after each security protection measure is executed, the system also synchronously records the protection results, such as whether the verification code verification is successful, whether the hash check passes, and whether the instruction is intercepted, to ensure the formation of a complete instruction processing trajectory chain. In this way, full, real-time, and structured collection of instruction detection and protection execution status can be achieved without interrupting the normal payment instruction processing flow.

[0053] The reason why it is necessary to systematically collect and continuously record the detection data of payment instructions and the execution results of security protection measures is that it is difficult to comprehensively evaluate the overall information security protection effect of the payment system by relying solely on single detection results or single-point protection actions; through long-term and continuous collection and accumulation of instruction detection and protection execution data, potential new attack patterns can be dynamically discovered based on the actual operating environment, protection blind spots can be identified, and the rationality of existing detection classification threshold settings can be evaluated; in addition, the collected data can also be used as a basis for optimization, supporting automatic adjustment of the threshold range of the abnormal change index, updating weight coefficients, optimizing classification rules, and even used to train more efficient detection models, so that the information security protection capabilities of the payment system have the ability to continuously adapt, evolve and enhance in the face of ever-changing attack methods, thereby improving the overall security level and system stability.

[0054] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.

[0055] The above embodiments can be implemented in whole or in part via software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. A computer program product comprises one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the processes or functions according to the embodiments of the present application are fully or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means (e.g., infrared, wireless, microwave, etc.). A computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.

[0056] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0057] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0058] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the embodiments described above are merely illustrative. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0059] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0060] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0061] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. An information security protection method based on a payment system, characterized in that: The specific steps include: By parsing the data structure of the payment instruction submitted by the user, all encrypted data fields in the payment instruction are determined to form a set of encrypted data fields to be detected; Filter out encrypted data fields with abnormal content changes from the set of encrypted fields to be detected, and mark them as encrypted data fields to be analyzed; Acquire encrypted field feature information of each encrypted data field to be analyzed in real time, analyze it after acquisition, assess the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction, and classify them; According to the classification results, corresponding safety protection measures are implemented respectively; Collect detection data of payment instructions and the execution results of security protection measures, and continuously optimize the information security protection capabilities of the payment system based on the collected data.

2. The information security protection method based on the payment system according to claim 1 is characterized in that: Filter out the encrypted data fields with abnormal content changes from the set of encrypted fields to be detected and mark them as encrypted data fields to be analyzed. Specifically: Extracting content features from each encrypted data field in the set of encrypted data fields to be detected, wherein the content features include data distribution features, encoding features, and structural features; Based on the extracted features, each encrypted data field is checked for content feature anomalies according to the preset content consistency verification rules; The encrypted data field with a verification result showing abnormal content characteristics is marked as the encrypted data field to be analyzed.

3. The information security protection method based on the payment system according to claim 2, characterized in that: Acquire encrypted field feature information of each encrypted data field to be analyzed in real time, analyze it after acquisition, evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction, and classify it, specifically including the following steps: Acquire encrypted field feature information of each encrypted data field to be analyzed in real time and perform preprocessing after acquisition; Extracting block entropy distribution information and block bit offset information from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, and analyzing the extracted information to generate an entropy dispersion coefficient and a block offset index for each encrypted data field to be analyzed; Constructing an abnormal change assessment model based on the generated entropy discrete coefficient and block offset index of each encrypted data field to be analyzed, and generating an abnormal change index for each encrypted data field to be analyzed by weighted summation; Determine a pre-set abnormal change index threshold range, and after determination, compare it with the generated abnormal change index of each encrypted data field to be analyzed. Evaluate the degree of abnormal change in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results, and divide each encrypted data field to be analyzed into stable encrypted data fields, suspicious encrypted data fields and abnormal encrypted data fields based on the evaluation results.

4. The information security protection method based on the payment system according to claim 3 is characterized in that: The logic for obtaining the entropy discrete coefficient of each encrypted data field to be analyzed is as follows: The block entropy distribution information is extracted from the encrypted field feature information of each encrypted data field to be analyzed after preprocessing, specifically including the entropy value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The entropy value of a data block, , , is a positive integer; Calculate the average entropy value of all data blocks in each encrypted data field to be analyzed using the average formula ; The standard deviation formula is used to calculate the standard deviation of the entropy values ​​of all data blocks in each encrypted data field to be analyzed. ; Calculate the entropy dispersion coefficient of each encrypted data field to be analyzed The specific calculation logic is: the standard deviation of the entropy value of all data blocks in each encrypted data field to be analyzed and average Perform a ratio operation to calculate the proportional relationship between the two, add 1 to the proportional relationship and take the natural logarithm to obtain the entropy dispersion coefficient used to reflect the degree of entropy fluctuation within each encrypted data field. .

5. The information security protection method based on the payment system according to claim 4 is characterized in that: The logic for obtaining the block offset index of each encrypted data field to be analyzed is as follows: The block bit offset information is extracted from the pre-processed encrypted field feature information of each encrypted data field to be analyzed, specifically including the average bit value of each data block in each encrypted data field to be analyzed, and marked as , Indicates the The encrypted data field to be analyzed The average bit value of a data block, , , is a positive integer; Calculate the average bit value of all data blocks in each encrypted data field to be analyzed using the average formula ; Calculate the block offset index of each encrypted data field to be analyzed , the specific calculation logic is as follows: encrypted data fields to be analyzed, and calculate the average bit value of each data block and the average The square of the difference between the two data blocks is summed and averaged to get the mean square error. The mean square error result is then squared, and 1 is added to the square result and the natural logarithm is taken to finally get the first Block offset index of the encrypted data field to be analyzed .

6. The information security protection method based on the payment system according to claim 5, characterized in that: The entropy discrete coefficient of each encrypted data field to be analyzed and block offset index Construct an abnormal change assessment model and generate the abnormal change index of each encrypted data field to be analyzed through weighted summation .

7. The information security protection method based on the payment system according to claim 6, characterized in that: Determine the pre-set abnormal change index threshold range , and after confirmation, compare it with the abnormal change index of each encrypted data field to be analyzed Perform a comparison and evaluate the degree of abnormal changes in the content of each encrypted data field to be analyzed in the payment instruction based on the comparison results. Based on the evaluation results, each encrypted data field to be analyzed is divided into stable encrypted data fields, suspicious encrypted data fields, and abnormal encrypted data fields. The specific comparison analysis and classification are as follows: like , the degree of abnormal change of the content of the encrypted data field to be analyzed in the payment instruction is low, and the encrypted data field to be analyzed is classified as a stable encrypted data field; like , the degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is medium, and the encrypted data field to be analyzed is classified as a suspicious encrypted data field; like The degree of abnormal change in the content of the encrypted data field to be analyzed in the payment instruction is high, and the encrypted data field to be analyzed is classified as an abnormal encrypted data field.

8. The information security protection method based on the payment system according to claim 7, characterized in that: According to the classification results, corresponding safety protection measures are implemented respectively, specifically: For encrypted data fields to be analyzed that are classified as stable encrypted data fields, the security protection measures implemented are: the corresponding payment instructions are forwarded to the payment execution channel for subsequent processing without additional intervention; For encrypted data fields that are classified as suspicious encrypted data fields, the security protection measures implemented are: sending a text message verification code to the user and requiring them to enter the verification code, and performing a hash value comparison and verification on the data content of the payment instruction; For the encrypted data fields to be analyzed that are classified as abnormal encrypted data fields, the security protection measures implemented are: suspending the processing flow of the payment instruction, saving the original data record of the payment instruction, and pushing the abnormal mark to the designated review process.

Citation Information

Cited By

  • Firmware backdoor detection and one-key security restoration method and system

    CN121786844A