White list adaptation system
By generating high-specification strategies through custom selection modules and pre-training modules, the problem that the existing whitelist adaptation system is difficult to adapt to different customer needs is solved, and the security and flexibility of the system are improved.
Patent Information
- Application Number
- CN202510809380.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-05
AI Technical Summary
The existing whitelist adaptation system is difficult to adapt to the needs of different customers and lacks security.
A whitelist adaptation system is provided, which includes a login module, a selection module and a processing module. The first selection module allows users to customize the selection policy requirements, and combines the IP module and the pre-training module to generate high-specification policies to meet the security and policy requirements of different customers.
It realizes the adaptive provision of low-specification or high-specification strategies according to customer needs, improves the security and flexibility of the system, and meets the high-standard requirements of different customers.
Smart Images

Figure CN120602170A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of whitelist authentication, and in particular to a whitelist adaptation system. Background Art
[0002] The emergence of whitelist adaptation systems stems from the need for scenarios with extremely high security, controllability, and compliance requirements. These systems primarily address the inherent flaws of the traditional "blacklist" model (which allows all actions by default and only prohibits known risks), especially when facing unknown threats, zero-day attacks, or insider risks.
[0003] Existing whitelist adaptation systems typically record fixed types and implement a "ban all, allow exceptions" approach. However, some clients require simple whitelisting, while others demand a more stringent approach. Existing whitelist adaptation systems are difficult to adapt to clients with different standards and lack security. Summary of the Invention
[0004] (1) Technical issues to be resolved The problem to be solved by the present invention is to provide a whitelist adaptation system to overcome the defects of the prior art whitelist adaptation system in that it is difficult to adapt to different clients and the security is insufficient.
[0005] (2) Technical solution To solve the above technical problem, the first aspect of the present invention provides a whitelist adaptation system, comprising: A login module, which is used to assist users in securely logging in. The login module includes a login platform, a judgment module, a registration module, a first storage module, and an IP module. The login platform is connected to the judgment module, which is connected to the registration module, which is connected to the first storage module. The first storage module is sequentially connected to the IP module and the judgment module. When a user enters an account and password, the judgment module determines whether it is the user's first login. When the user is logging in for the first time, the judgment module inputs a data stream to the registration module. The registration module provides registration support for the user. The first storage module receives user registration information. The IP module assigns an IP key to each account. When the user enters an incorrect account and password or the password does not match the IP key, the login fails. A first selection module, the first selection module is connected to the login module, and the first selection module is used to provide a selection for the user. When the user enters the first selection module, the user selects between low requirements and high requirements; A processing module, wherein the processing module has a low-specification strategy, a high-specification proprietary strategy, and a high-specification general strategy. The processing module has a pre-training module and a high-specification strategy model. The pre-training module collects data when users use the high-specification strategy and pre-trains the data. The pre-training module is connected to the high-specification strategy model. The pre-training module provides pre-training data to the high-specification strategy model and generates a training model in the high-specification strategy model. The training model outputs the high-specification proprietary strategy externally. The output module is used for external output.
[0006] As described above, in the whitelist adaptation system, optionally, when the user selects a low requirement, the first selection module is connected to the first interface, the first storage module, the processing module, and the output module in sequence.
[0007] As described above, the whitelist adaptation system can optionally select a user with low requirements to call the first interface and input whitelist data into the first storage module. The first storage module is used to store the whitelist data. When the customer with low requirements uses this system, the whitelist data in the first storage module is called into the processing module, and the processing module uses a low-specification strategy to output the results.
[0008] As described above, in the whitelist adaptation system, optionally, when the user selects a high-demand requirement, the first selection module jumps to the second selection module, and the second selection module provides the user with a choice, and the user selects whether to have an authentication interface.
[0009] As described above, the whitelist adaptation system can optionally be connected to the second interface, the processing module and the output module in sequence when the user has an authentication interface; and to the third interface, the processing module and the output module in sequence when the user does not have an authentication interface.
[0010] As described above, in the whitelist adaptation system, optionally, the second interface is used to provide a proprietary authentication interface. When the user has an authentication interface, the user authentication interface is connected to the second interface, and the high-specification proprietary strategy in the processing module is called to output the result.
[0011] As described above, the whitelist adaptation system may optionally include a third interface for providing a public authentication interface Common. When the user does not have an authentication interface, the user connects to the third interface, and the high-specification general policy in the processing module is called to output the result.
[0012] As described above, in the whitelist adaptation system, optionally, a high-specification proprietary policy has multiple high-specification proprietary sub-policies, each high-specification proprietary sub-policy is customized by the customer, and each high-specification proprietary sub-policy corresponds to each customer.
[0013] (3) Beneficial effects The present invention provides a whitelist adaptation system, which has the following beneficial effects: The present invention allows customers to customize whether they need a high-requirement whitelist strategy through the first selection module. When the user chooses a low-requirement whitelist strategy, the user can use the first interface and cooperate with the first storage module, and the processing module adopts a low-specification strategy to output the whitelist; when the user chooses a high-requirement whitelist strategy, the user can make a choice according to their own conditions in the second selection module. When the user has an authentication interface, the user connects to the second interface, and the processing module adopts a high-specification proprietary strategy to output the result. The high-specification proprietary strategy is pre-trained by the pre-training module and the high-specification strategy model, thereby improving the effect; when the user does not have an authentication interface, the user connects to the third interface, which is a universal interface, and the high-specification universal strategy can output the result. This design can effectively match the different needs of different customers, thereby achieving better results.
[0014] The present invention further improves the security of user login through the login module, the judgment module and the IP module. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0016] Figure 1 The present invention is a flowchart of a whitelist adaptation system.
[0017] The corresponding component names of the various figure marks in the figure are: 1. Login module; 2. Login platform; 3. Judgment module; 4. Registration module; 5. First storage module; 6. IP module; 7. First selection module; 8. Processing module; 9. Pre-training module; 10. High-specification strategy model; 11. Output module; 12. First interface; 13. Second selection module; 14. Second interface; 15. Third interface. DETAILED DESCRIPTION
[0018] The present application is described in detail below with reference to the accompanying drawings and specific embodiments.
[0019] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the features in the following embodiments and embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.
[0020] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this application, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number and aspect described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.
[0021] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. The illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0022] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples, however, one skilled in the art will appreciate that the examples can be practiced without these specific details.
[0023] The following describes the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.
[0024] See Figure 1 The present invention provides a whitelist adaptation system, comprising: a login module 1, a first selection module 7, a processing module 8, and a second selection module 13. When the login module 1 is used to assist a user in logging into a security system, the first selection module 7 can selectively provide options based on the user's needs, the second selection module 13 can selectively provide options based on the user's conditions, and the processing module 8 processes, matches, and outputs the user's needs.
[0025] Furthermore, the login module 1 is used to assist the user in logging in safely. The login module 1 includes a login platform 2, a judgment module 3, a registration module 4, a first storage module 5 and an IP module 6.
[0026] Among them, the login platform 2 is connected to the judgment module 3, the judgment module 3 is connected to the registration module 4, the registration module 4 is connected to the first storage module 5, and the first storage module 5 is connected to the IP module 6 and the judgment module 3 in sequence.
[0027] It should be noted that the login platform 2 provides the user with an input interface for the account and password. When the user enters the account and password, he can choose to log in. The account and password data are transmitted to the judgment module 3. The judgment module 3 judges whether the user's account and password are the first login or whether they are incorrect. When the user logs in for the first time, the judgment module 3 inputs the data stream to the registration module 4, thereby starting the registration process for the first login. The registration module 4 provides registration support for the user.
[0028] Furthermore, the registration module 4 jumps to the first storage module 5, which receives the user registration information. At the same time, the IP module 6 assigns an IP key to each account. Each IP key corresponds to each account. If the user enters an incorrect account or password or it does not match the IP key, the login fails. If the user enters an incorrect account or password, the login fails. If the user enters the correct account and password for this login and it is not the first login, the login succeeds.
[0029] Among them, IP keys can better provide security guarantees for users.
[0030] exist Figure 1 In an optional embodiment, the first selection module 7 is connected to the login module 1. The first selection module 7 is used to provide selections for the user. When the user enters the first selection module 7, the user selects between low requirements and high requirements.
[0031] Furthermore, the processing module 8 has low-specification strategies, high-specification proprietary strategies and high-specification general strategies. The processing module 8 has a pre-training module 9 and a high-specification strategy model 10. The pre-training module 9 collects data when users use high-specification strategies and pre-trains the data. The pre-training module 9 is connected to the high-specification strategy model 10. The pre-training module 9 provides pre-training data to the high-specification strategy model 10 and generates a training model in the high-specification strategy model 10. The training model outputs high-specification proprietary strategies to the outside.
[0032] The pre-trained model can analyze and train the user's strategy and form a high-specification proprietary strategy in the high-specification strategy model 10. The high-specification proprietary strategy has multiple high-specification proprietary sub-strategies, each of which is customized by the customer and corresponds to each customer.
[0033] As described above, when the user selects a low requirement, the first selection module 7 is connected to the first interface 12 , the first storage module 5 , the processing module 8 , and the output module 11 in sequence.
[0034] Furthermore, users with low requirements are selected to call the first interface 12 and input whitelist data into the first storage module 5. The first storage module 5 is used to store whitelist data. When customers with low requirements use this system, the whitelist data in the first storage module 5 is called to the processing module 8, and the processing module 8 uses a low-specification strategy to output the results.
[0035] It should be noted that, when the user selects a high requirement, the first selection module 7 jumps to the second selection module 13. The second selection module 13 provides the user with a choice, and the user selects whether to have an authentication interface.
[0036] Furthermore, when the user has an authentication interface, the second selection module 13 is connected to the second interface 14, the processing module 8 and the output module 11 in sequence; when the user does not have an authentication interface, the second selection module 13 is connected to the third interface 15, the processing module 8 and the output module 11 in sequence.
[0037] Furthermore, the second interface 14 is used to provide a proprietary authentication interface. When the user has an authentication interface, the user authentication interface is connected to the second interface 14, and the high-specification proprietary strategy in the processing module 8 is called and the result is output.
[0038] The third interface 15 is used to provide a public authentication interface Common. When the user does not have an authentication interface, the user connects to the third interface 15, and the high-specification common policy call in the processing module 8 is output.
[0039] The user can obtain results based on the data output by the output module 11 .
[0040] The same or similar parts between the various embodiments in this specification can be referred to each other, and each embodiment focuses on the differences from other embodiments.
[0041] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A whitelist adaptation system, characterized in that: include: A login module (1), the login module (1) is used to assist users in logging in safely, the login module (1) includes a login platform (2), a judgment module (3), a registration module (4), a first storage module (5) and an IP module (6), the login platform (2) is connected to the judgment module (3), the judgment module (3) is connected to the registration module (4), the registration module (4) is connected to the first storage module (5), the first storage module (5) is sequentially connected to the IP module (6) and the judgment module (3), when the user enters an account number and password, the judgment module (3) determines whether the user is logging in for the first time, when the user is logging in for the first time, the judgment module (3) inputs a data stream to the registration module (4), the registration module (4) provides registration support for the user, the first storage module (5) receives user registration information, the IP module (6) assigns an IP key to each account, when the user enters an incorrect account number and password or the password does not match the IP key, the login fails; A first selection module (7), the first selection module (7) is connected to the login module (1), and the first selection module (7) is used to provide a selection for the user. When the user enters the first selection module (7), the user selects between low requirements and high requirements; A processing module (8), wherein the processing module (8) has a low-specification strategy, a high-specification proprietary strategy, and a high-specification general strategy. The processing module (8) has a pre-training module (9) and a high-specification strategy model (10). The pre-training module (9) collects data when a user uses the high-specification strategy and pre-trains the data. The pre-training module (9) is connected to the high-specification strategy model (10). The pre-training module (9) provides pre-training data to the high-specification strategy model (10) and generates a training model in the high-specification strategy model (10). The training model outputs the high-specification proprietary strategy externally. An output module (11), wherein the output module (11) is used for external output.
2. The whitelist adaptation system according to claim 1, wherein: When the user selects a low requirement, the first selection module (7) is connected to the first interface (12), the first storage module (5), the processing module (8), and the output module (11) in sequence.
3. The whitelist adaptation system according to claim 2, wherein: A user who selects a low-requirement requirement calls the first interface (12) and inputs whitelist data into the first storage module (5). The first storage module (5) is used to store the whitelist data. When the customer with the low-requirement requirement uses the system, the whitelist data in the first storage module (5) is called into the processing module (8). The processing module (8) outputs the result using a low-specification strategy.
4. The whitelist adaptation system according to claim 1, wherein: When the user selects a high-demand requirement, the first selection module (7) jumps to the second selection module (13), and the second selection module (13) provides a choice for the user, and the user selects whether to have an authentication interface.
5. The whitelist adaptation system according to claim 4, characterized in that: When the user has an authentication interface, the second selection module (13) is connected to the second interface (14), the processing module (8) and the output module (11) in sequence; when the user does not have an authentication interface, the second selection module (13) is connected to the third interface (15), the processing module (8) and the output module (11) in sequence.
6. The whitelist adaptation system according to claim 5, characterized in that: The second interface (14) is used to provide a proprietary authentication interface. When the user has an authentication interface, the user authentication interface is connected to the second interface (14), and the high-specification proprietary strategy in the processing module (8) is called to output the result.
7. The whitelist adaptation system according to claim 5, characterized in that: The third interface (15) is used to provide a common authentication interface Common. When the user does not have an authentication interface, the user connects to the third interface (15), and the high-specification common strategy in the processing module (8) is called and the result is output.
8. The whitelist adaptation system according to claim 1, wherein: A high-specification proprietary strategy contains multiple high-specification proprietary sub-strategies. Each high-specification proprietary sub-strategy is customized by the customer, and each high-specification proprietary sub-strategy corresponds to each customer.