Data search security access system

Through the multi-level key generation and verification mechanism of mobile user terminals and fixed user terminals combined with the server terminal, the problem of data leakage when the user terminal is attacked is solved, a more secure data access system is achieved, and the protection of user data is enhanced.

CN120729615APending Publication Date: 2025-09-30ZHONGHONG RONGCHENG IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511079959.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

When the existing data search security access system is attacked on the user side, the user's search data is easily leaked and lacks effective double-line defense protection.

Method used

A multi-level, multi-endpoint key generation and verification mechanism is adopted that combines the mobile user end and the fixed user end with the first and second server ends. Through dual login and multiple key pair generation, it ensures that users can still provide additional security when any endpoint is attacked, including the generation and verification of primary and secondary key pairs.

Benefits of technology

It improves the security of the system, enhances the difficulty of key pairs, forms multiple lines of defense, ensures the dynamic nature of dynamic ciphertext, reduces the risk of data leakage, and improves the protection level of user data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729615A_ABST
    Figure CN120729615A_ABST
Patent Text Reader

Abstract

The invention discloses a data search security access system, belongs to the technical field of information security, and solves the problem that personal search data of a user flows out once any one of a server or a user side is attacked. Comprising a mobile user side, a fixed user side, a first server side and a second server side, and the mobile user side is in communication connection with the first server side, the first server side is in communication connection with the second server side, and the second server side is in communication connection with the fixed user side; the mobile user side can be logged in by inputting login information by a user so as to send out a first-level access request, and the user can manually input a dynamic ciphertext displayed from the fixed user side. According to the method, a user is required to initiate a first-level access request on a fixed device after logging in the mobile device and then log in to send a second-level request, and even if any end is attacked, the other end can serve as a defense line.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data search security access system. Background Art

[0002] Data search and secure access systems are comprehensive data protection solutions designed to ensure the security of sensitive data during storage, processing, and transmission. These systems typically include transparent encryption and decryption technologies to prevent theft and loss of data assets. They also provide confidentiality protection by controlling document reading, writing, printing, clipboard access, dragging and dropping, screenshots, and memory theft to prevent the leakage of confidential data. Furthermore, the systems implement mandatory access control, applying multiple access rights to confidential documents based on user identity and permissions, as well as document classification. Two-factor authentication enhances user identity security and credibility. Document auditing effectively tracks user operations on encrypted documents. A three-way separation of powers management strategy—approval, execution, and oversight—ensures the separation of responsibilities and enhances management security. Security protocols ensure secure key operations and storage, achieving separation between key storage and hosts. These systems provide comprehensive data security through detailed access control, high-performance national encryption support, ciphertext fuzzy queries, and flexible deployment.

[0003] Generally speaking, when users use this type of data search security access system, in order to ensure the user's privacy, they often need to set an account and password as login information to prevent the loss of their search data content. For convenience, users often set the option to remember the password. However, if either the server or the user end is attacked, it will cause the user's personal search data to leak out.

[0004] Therefore, a data search security access system is proposed to solve or alleviate the above problems. Summary of the Invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a data search and security access system.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions: A data search and security access system includes a mobile user terminal, a fixed user terminal, a first server terminal, and a second server terminal, wherein the mobile user terminal is in communication with the first server terminal, the first server terminal is in communication with the second server terminal, and the second server terminal is in communication with the fixed user terminal. The mobile user terminal can log in by inputting login information to issue a first-level access request, and the user can manually input the dynamic ciphertext displayed by the fixed user terminal; The fixed user terminal can log in by the user inputting login information to issue a secondary access request, and receive the dynamic ciphertext from the second server terminal for display; The first server receives and responds to the primary access request, generates a primary key pair, transmits the primary key pair to the second server, and uses the private key in the secondary key received from the second server to decode the dynamic ciphertext to grant the user access rights; After receiving and responding to the secondary access request, the second server generates a secondary key pair based on the primary key pair, combines the password in the login information with the public key in the secondary key pair to form a dynamic ciphertext and transmits it to the fixed user end, and transmits the private key in the secondary key to the first server.

[0007] Preferably, the IP addresses of the mobile user terminal and the fixed user terminal are set differently, the mobile user terminal is set as a mobile phone terminal, and the fixed user terminal is set as a web page terminal.

[0008] Preferably, the mobile user terminal can issue a first-level access request by the user inputting login information to log in, including the following specific steps: The user enters login information through the mobile user terminal; The mobile user terminal receives the login information, verifies that it is correct, and then sends a first-level access request to the first server terminal.

[0009] Preferably, the first server side generates a first-level key pair after receiving and responding to the first-level access request and transmits the first-level key pair to the second server side, including the following steps: The first server receives a first-level access request; After the first server verifies that the first access request is correct, the first server extracts the real-time data of the first server as a feature to generate a first-level key pair; The first server transmits the primary key pair to the second server.

[0010] Preferably, the step of extracting the real-time data of the first server as a feature to generate a primary key pair comprises the following steps: The first server extracts its own real-time data, wherein the real-time data includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameter and perform wavelet threshold denoising; Normalization processing: subtracting the minimum value from the data and dividing it by the difference between the maximum and minimum values ​​to generate a first set vector, wherein the first set vector includes four components of processed data transmission rate, delay, packet loss rate, and bandwidth utilization; intercepting the current timestamp of the first server, performing a weighted operation on the first set vector by the number of days, hours, minutes, seconds, and milliseconds to generate a preliminary key candidate, multiplying the four components of the first set vector by the corresponding weights, summing the results, and adding the number of milliseconds, and taking the remainder of the calculation result with respect to a prime number to generate a preliminary key candidate value; The preliminary key selection candidates are hashed multiple times using the SHA-256 hash function to generate a primary key pair.

[0011] Preferably, the fixed user terminal can issue a secondary access request by the user inputting login information to log in, including the following steps: The user enters login information through a fixed user terminal; The fixed user terminal receives the login information, verifies that it is correct, and then sends a secondary access request to the second server terminal.

[0012] Preferably, after receiving and responding to the secondary access request, the second server generates a secondary key pair based on the primary key pair, combines the password in the login information with the public key in the secondary key pair to form a dynamic ciphertext and transmits it to the fixed user terminal, and transmits the private key in the secondary key pair to the first server, including the following steps: The second server receives the secondary access request; After the second server verifies that the secondary access request is correct, it extracts the real-time data of the second server and generates a secondary key pair based on the primary key pair; Combine the public key in the secondary key pair with the password in the login information to form a dynamic ciphertext; Deliver the dynamic ciphertext to the fixed user terminal for display; The private key in the secondary key is transferred to the first server for standby use.

[0013] Preferably, the step of extracting the real-time data from the second server and generating the secondary key pair in combination with the primary key pair comprises the following steps: The second server extracts its own real-time data, wherein the real-time data includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameters and perform wavelet threshold denoising to denoise the real-time data; Normalization processing: subtracting the minimum value from the data and dividing it by the difference between the maximum and minimum values ​​to generate a second set vector. The second set vector includes four components: data transmission rate, delay, packet loss rate, and bandwidth utilization. Combine the primary key pair with the hashed second set vector to generate a combined key; Intercepting the current timestamp of the second server, combining the second set vector and the primary key pair with the number of days, hours, minutes, seconds, and milliseconds, and performing a weighted operation to obtain a candidate value, multiplying the four components of the set vector by the corresponding weights, summing the results, and adding the number of milliseconds, and taking the remainder of the calculation result with respect to a prime number to obtain a candidate value for the secondary key; The candidate value is hashed using the SHA-256 hash function and outputs a secondary key pair.

[0014] Preferably, the private key in the secondary key received from the second server is used to decode the dynamic ciphertext to grant the user access rights, including the following steps: The fixed user terminal displays the dynamic ciphertext generated by the second server terminal by combining the password in the login information and the public key in the secondary key pair; The user manually inputs the dynamic ciphertext displayed on the fixed user terminal through the mobile user terminal; After the dynamic ciphertext is transmitted to the first server through the mobile user terminal, the private key is parsed using the secondary key. The parsed dynamic ciphertext is compared with the password in the login information. If they are consistent, the user is granted access rights to the mobile user terminal and the fixed user terminal. If they are inconsistent, no access rights are granted and unauthorized access rights are output.

[0015] Preferably, it also includes a reset module, which is communicatively connected to the first server end and the second server end. The reset module is used to eliminate the first-level access request and first-level key pair of the first server end, and the second-level access request and second-level key pair of the second server end after receiving access rights or no access rights.

[0016] The present invention has the following beneficial effects: When a user logs in to access the present invention, not only does the mobile user terminal only need to perform login information once, but the user also needs to issue a first-level access request on the mobile user terminal and then enter the login information on the fixed user terminal to issue a second-level access request. In this way, even if any user terminal is attacked, it can be protected by another user terminal as the first line of defense. Then the first-level key pair generated by the first server terminal will be used as a basis to cooperate with the second server terminal to generate a second-level key pair. The second-level key pair is combined with the password in the login information to generate a dynamic ciphertext. The user needs to read the dynamic ciphertext on the fixed user terminal and input it on the mobile user terminal before obtaining access rights. Such a second-level key pair can ensure that it is difficult to parse and is not easy to be cracked. In addition, the generation of the second-level key pair needs to be performed by the fixed user terminal, the mobile user terminal, and the first server terminal at the same time. The key pair and dynamic ciphertext cannot be obtained by the work of the server end. If any user end or any server end is attacked, the corresponding key pair and dynamic ciphertext cannot be obtained. This operation can constitute a second line of defense with higher difficulty to prevent the system from being breached. Finally, no matter whether it receives access rights or does not have access rights, the reset module will perform the first-level access request and the first-level key pair of the first server end, and the second-level access request and the second-level key pair of the second server end on the first server end. This can constitute the third line of defense of this system, avoiding the retention of the first-level access request and the second-level access request after a single login action, and avoiding the situation where the second-level key pair is not updated for a long time, thereby ensuring that the dynamic ciphertext displayed on the fixed user end each time a user logs in remains inconsistent, ensuring the dynamic state of the dynamic ciphertext, so as to prevent the system from being easily found vulnerabilities when it is attacked. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0018] Figure 1 It is a structural block diagram of the present invention.

[0019] 1. Mobile user terminal; 2. Fixed user terminal; 3. First server terminal; 4. Second server terminal; 5. Reset module. DETAILED DESCRIPTION

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0021] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0022] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0023] In the description of the present invention, it should be understood that the terms "center", "up", "down", "left", "right", "vertical", "horizontal", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, or are the orientation or position relationship in which the product of the invention is usually placed when in use, or are the orientation or position relationship commonly understood by those skilled in the art. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention.

[0024] Furthermore, the terms “first,” “second,” “third,” etc., are merely used for distinguishing descriptions and are not to be understood as indicating or implying relative importance.

[0025] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on the specific circumstances.

[0026] A data search security access system, such as Figure 1As shown, it includes a mobile user terminal 1, a fixed user terminal 2, a first server terminal 3, and a second server terminal 4. The mobile user terminal 1 is connected to the first server terminal 3, the first server terminal 3 is connected to the second server terminal 4, and the second server terminal 4 is connected to the fixed user terminal 2. The mobile user terminal 1 can log in by inputting login information to issue a first-level access request, and the user can manually input the dynamic ciphertext displayed by the fixed user terminal 2; The fixed user terminal 2 can log in by inputting login information to issue a secondary access request, and receive dynamic ciphertext from the second server terminal 4 for display; The first server 3 receives and responds to the primary access request, generates a primary key pair, transmits the primary key pair to the second server 4, and uses the private key in the secondary key received from the second server to decrypt the dynamic ciphertext to grant the user access rights; After receiving and responding to the secondary access request, the second server end 4 generates a secondary key pair based on the primary key pair, combines the password in the login information and the public key in the secondary key pair to form a dynamic ciphertext and transmits it to the fixed user end 2, and transmits the private key in the secondary key to the first server end 3.

[0027] The system provided by the present invention has extremely high security. It requires the user to complete a login operation on the mobile user terminal 1 (mobile phone) to trigger a first-level access request, and also initiate a login operation on the fixed user terminal 2 and enter login information to trigger a second-level access request. This dual operation design ensures that even if any endpoint of the user is attacked, the other endpoint can still provide additional security.

[0028] In addition, the first server end 3 will generate a first-level key pair, and the second server end 4 will generate a second-level key pair based on this. These two key pairs work together to enhance the difficulty of the final key pair, so that the public key in the second-level key pair is combined with the password in the user login information to generate a dynamic ciphertext. The user must read this dynamic ciphertext on the fixed user end 2 and enter it on the mobile user end 1 to obtain access rights to the system.

[0029] The design of this secondary key pair significantly increases the difficulty of key cracking, because they require the collaborative work of the fixed user terminal 2, the mobile user terminal 1 and the first server terminal 3 to generate. Even if the attacker controls any endpoint, he cannot obtain the key pair and dynamic ciphertext independently. This mechanism constitutes the second line of defense of the system and greatly enhances the security of the system.

[0030] Finally, regardless of whether the user obtains access rights, the system is equipped with a reset module 5, which will clear the first-level access request and first-level key pair of the first server side 3, as well as the second-level access request and second-level key pair of the second server side 4 after each login. This measure constitutes the third line of defense of the system, ensuring that after each login, the first-level and second-level access requests will not be retained, while avoiding the risk of the key pair not being updated for a long time. This ensures that each time a user logs in, the dynamic ciphertext displayed on the fixed user side 2 is different, maintaining the dynamic nature of the ciphertext, so that when the system is attacked, it is not easy to find vulnerabilities.

[0031] In general, the present invention provides users with a more secure and difficult-to-crack login system through this multi-level, multi-endpoint key generation and verification mechanism. The design of this system not only improves the security of individual users, but also provides strong protection for the security of the entire network environment. In this way, the present invention effectively improves the protection level of user data and reduces the risk of data leakage and unauthorized access.

[0032] Preferably, the IP addresses of the mobile user terminal 1 and the fixed user terminal 2 are set differently, the mobile user terminal 1 is set as a mobile phone terminal, and the fixed user terminal 2 is set as a web page terminal.

[0033] Since the mobile user terminal 1 is set as a mobile phone terminal and the fixed user terminal 2 is set as a web page terminal, and the IP addresses of the mobile user terminal 1 and the fixed user terminal 2 are required to be set differently, it can ensure that when the user logs in, the fixed user terminal 2 and the mobile user terminal 1 are not the same user terminal, and when the mobile user terminal 1 is attacked, the fixed user terminal 2 will not be attacked as well, thereby building the first line of defense, increasing the difficulty of breaking the system, and preventing the privacy of search data in the system from leaking.

[0034] Preferably, the mobile user terminal 1 can issue a first-level access request by the user inputting login information to log in, including the following specific steps: The user enters login information through the mobile user terminal 1; The mobile user terminal 1 receives the login information, verifies that it is correct, and then sends a first-level access request to the first server terminal 3.

[0035] When the mobile user terminal 1 needs to log in, the user login information including the account and password set by itself serves as a line of defense to prevent outsiders from snooping. In addition, when the login information is difficult, as long as the user terminal does not remember the login information, even if the user terminal is attacked, it can provide a certain degree of protection to prevent the mobile user terminal 1 and the fixed user terminal 2 from being completely hacked.

[0036] Preferably, the first server 3 generates a first-level key pair after receiving and responding to the first-level access request and transmits the first-level key pair to the second server 4, including the following steps: The first server 3 receives the first-level access request; After the first server 3 verifies that the first-level access request is correct, it extracts the real-time data of the first server 3 as a feature to generate a first-level key pair; The first server 3 transmits the primary key pair to the second server 4 .

[0037] The first server end 3 can only start extracting features to generate a first-level key pair after the first-level access request is sent, and the generated first-level key pair will not be used directly for parsing the ciphertext, but will assist in generating a second-level key pair, thereby increasing the difficulty of ciphertext encryption. On the one hand, it can provide the attacker with a wrong parsing direction when the system is attacked, and on the other hand, it can also improve the security performance of the system.

[0038] Preferably, extracting the real-time data of the first server 3 as a feature to generate a primary key pair includes the following steps: The first server 3 extracts its own real-time data, which includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameter and perform wavelet threshold denoising; Normalization processing: subtract the minimum value from the data and divide it by the difference between the maximum and minimum values ​​to generate a set vector. The set vector includes the processed data transmission rate, delay, packet loss rate and bandwidth utilization. Intercepting the current timestamp of the first server, performing a weighted operation on the set vector by the number of days, hours, minutes, seconds, and milliseconds to generate a preliminary key candidate, multiplying the four components of the set vector by the corresponding weights, summing the results, and adding the number of milliseconds, and taking the remainder of the calculation result with respect to a prime number to generate a preliminary key candidate value; The preliminary key selection candidates are hashed multiple times using the SHA-256 hash function to generate a primary key pair.

[0039] Through the above steps, the first server end 3 can generate a first-level key pair. By intercepting the current timestamp of the first server end 3 and extracting its own real-time data, the real-time data includes data transmission rate, delay, packet loss rate, and bandwidth utilization rate, which are real-time changing data, to generate a first-level key pair as a feature, so that the key pair has no regularity, thereby greatly increasing the difficulty for attackers to crack it.

[0040] Preferably, the fixed user terminal 2 can issue a secondary access request by the user inputting login information to log in, including the following steps: The user enters login information through the fixed user terminal 2; The fixed user terminal 2 receives the login information, verifies that it is correct, and then sends a secondary access request to the second server terminal 4.

[0041] By having the fixed user terminal 2 re-enter the login information, it is ensured that the fixed user terminal 2 can be triggered and then send a secondary access request to the second server terminal 4, thereby preventing the fixed user terminal 2 from directly sending a secondary access request when the fixed user terminal 2 is attacked.

[0042] Preferably, after receiving and responding to the secondary access request, the second server 4 generates a secondary key pair based on the primary key pair, combines the password in the login information with the public key in the secondary key pair to form a dynamic ciphertext and transmits it to the fixed user 2, and transmits the private key in the secondary key pair to the first server 3, including the following steps: The second server 4 receives the secondary access request; After the second server 4 verifies that the secondary access request is correct, it extracts the real-time data of the second server 4 and generates a secondary key pair in combination with the primary key pair; Combine the public key in the secondary key pair with the password in the login information to form a dynamic ciphertext; The dynamic ciphertext is transmitted to the fixed user terminal 2 for display; The private key in the secondary key is transferred to the first server 3 for standby use.

[0043] The prerequisite for the second server end 4 to generate a secondary key pair is not only to receive the primary key pair from the first server end 3, but also to fix the secondary access request triggered by the user end 2. Multiple and multi-condition triggering requires that the secondary key needs to meet multiple conditions before it can be generated. In addition, it extracts the real-time data of the second server end 4 and combines it with the primary key pair to generate a secondary key pair, so that the secondary key pair has a higher parsing difficulty and strong randomness, which makes the dynamic ciphertext have a better confidentiality effect.

[0044] Preferably, extracting the real-time data of the second server 4 and generating the secondary key pair in combination with the primary key pair comprises the following steps: The second server 4 extracts its own real-time data, which includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameters and perform wavelet threshold denoising to denoise the real-time data; Normalization processing: subtracting the minimum value from the data and dividing it by the difference between the maximum and minimum values ​​to generate a second set vector. The second set vector includes four components: data transmission rate, delay, packet loss rate, and bandwidth utilization. Combine the primary key pair with the hashed second set vector to generate a combined key; Intercepting the current timestamp of the second server end 4, combining the second set vector and the primary key pair with the number of days, hours, minutes, seconds, and milliseconds, and performing a weighted operation to obtain a candidate value, multiplying the four components of the set vector by the corresponding weights, summing the results, and adding the number of milliseconds, and taking the remainder of the calculation result with respect to a prime number to obtain a candidate value for the secondary key; The candidate value is hashed using the SHA-256 hash function and outputs a secondary key pair.

[0045] Through the above steps, the first-level key pair and the second server end 4 can extract its own real-time data to generate a second-level key pair. The second-level key pair not only increases the difficulty based on the first-level key pair, but also can increase the real-time data of the second server end 4, further enhancing its randomness, so that the regularity of the second-level key pair is further weakened, increasing the difficulty of its parsing.

[0046] Preferably, receiving the private key in the secondary key from the second server to decode the dynamic ciphertext to grant the user access rights includes the following steps: The fixed user terminal 2 displays the dynamic ciphertext generated by the second server terminal 4 by combining the password in the login information and the public key in the secondary key pair; The user manually inputs the dynamic ciphertext displayed by the fixed user terminal 2 through the mobile user terminal 1; After the dynamic ciphertext is transmitted to the first server end 3 through the mobile user end 1, the private key is parsed with the secondary key. The parsed dynamic ciphertext is compared with the password in the login information. If they are consistent, the user is granted access rights to the mobile user end 1 and the fixed user end 2. If they are inconsistent, no access rights are granted and unauthorized access rights are output.

[0047] After finally obtaining the dynamic ciphertext, the dynamic ciphertext needs to be displayed through the fixed user terminal 2 so that the user can obtain it. However, since the IP addresses of the fixed user terminal 2 and the mobile user terminal 1 are set differently, if any user terminal is attacked, the user will not be able to actively view the dynamic ciphertext with the naked eye, thus avoiding the dynamic ciphertext from appearing on the same user terminal, thereby increasing access difficulty and security performance.

[0048] Preferably, if Figure 1 As shown, it also includes a reset module 5, which is communicated with the first server end 3 and the second server end 4. The reset module 5 is used to eliminate the first-level access request and the first-level key pair of the first server end 3, and the second-level access request and the second-level key pair of the second server end 4 after receiving access rights or no access rights.

[0049] The setting of the reset module 5 allows the previous first-level access request and first-level key pair of the first server end 3, as well as the second-level access request and second-level key pair of the second server end 4 to be eliminated after the user completes a login action, so as to prevent the above-mentioned contents from being retained for a long time to be parsed by attackers. The next first-level key pair and second-level key pair have strong randomness due to the real-time data, making it difficult to find the pattern of dynamic ciphertext each time the user logs in, thereby ensuring the security of the system and preventing the outflow of user search data.

[0050] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A data search and security access system, characterized in that: The system comprises a mobile user terminal (1), a fixed user terminal (2), a first server terminal (3), and a second server terminal (4), wherein the mobile user terminal (1) is in communication connection with the first server terminal (3), the first server terminal (3) is in communication connection with the second server terminal (4), and the second server terminal (4) is in communication connection with the fixed user terminal (2); The mobile user terminal (1) can be logged in by the user inputting login information to issue a first-level access request, and the user can manually input the dynamic ciphertext displayed by the fixed user terminal (2); The fixed user terminal (2) can be logged in by the user inputting login information to issue a secondary access request, and receive dynamic ciphertext from the second server terminal (4) for display; The first server (3) generates a first-level key pair after receiving and responding to the first-level access request, transmits the first-level key pair to the second server (4), and uses the private key in the second-level key received from the second server to decode the dynamic ciphertext to grant the user access rights; The second server (4) receives and responds to the secondary access request, generates a secondary key pair based on the primary key pair, combines the password in the login information with the public key in the secondary key pair to form a dynamic ciphertext, and transmits it to the fixed user (2), and transmits the private key in the secondary key pair to the first server (3).

2. A data search and security access system according to claim 1, characterized in that: The IP addresses of the mobile user terminal (1) and the fixed user terminal (2) are set differently. The mobile user terminal (1) is set as a mobile phone terminal, and the fixed user terminal (2) is set as a web page terminal.

3. A data search and security access system according to claim 1, characterized in that: The mobile user terminal (1) can issue a first-level access request by the user inputting login information to log in, including the following specific steps: The user enters login information through the mobile user terminal (1); The mobile user terminal (1) receives the login information, verifies that it is correct, and then sends a first-level access request to the first server terminal (3).

4. A data search and security access system according to claim 3, characterized in that: The first server (3) generates a first-level key pair after receiving and responding to the first-level access request, and transmits the first-level key pair to the second server (4), including the following steps: The first server (3) receives a first-level access request; After the first server side (3) verifies that the first level access request is correct, the first server side (3) extracts the real-time data of the first server side (3) as a feature to generate a first level key pair; The first server (3) transmits the primary key pair to the second server (4).

5. A data search and security access system according to claim 4, characterized in that: The method of extracting the real-time data of the first server end (3) as a feature to generate a primary key pair includes the following steps: The first server (3) extracts its own real-time data, wherein the real-time data includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameter and perform wavelet threshold denoising; Normalization processing: subtracting the minimum value from the data and dividing it by the difference between the maximum and minimum values ​​to generate a first set vector, wherein the first set vector includes four components of processed data transmission rate, delay, packet loss rate, and bandwidth utilization; intercepting the current timestamp of the first server, performing a weighted operation on the first set vector by the number of days, hours, minutes, seconds, and milliseconds to generate a preliminary key candidate, multiplying the four components of the first set vector by the corresponding weights, summing the results, and adding the number of milliseconds, and taking the remainder of the calculation result with respect to a prime number to generate a preliminary key candidate value; The preliminary key selection candidates are hashed multiple times using the SHA-256 hash function to generate a primary key pair.

6. A data search and security access system according to claim 5, characterized in that: The fixed user terminal (2) can issue a secondary access request by the user inputting login information to log in, including the following steps: The user enters login information through the fixed user terminal (2); The fixed user terminal (2) receives the login information, verifies that it is correct, and then sends a secondary access request to the second server terminal (4).

7. A data search and security access system according to claim 6, characterized in that: The second server (4) receives and responds to the secondary access request, generates a secondary key pair based on the primary key pair, combines the password in the login information with the public key in the secondary key pair to form a dynamic ciphertext, transmits it to the fixed user (2), and transmits the private key in the secondary key pair to the first server (3), including the following steps: The second server (4) receives the secondary access request; After the second server end (4) verifies that the secondary access request is correct, it extracts the real-time data of the second server end (4) and generates a secondary key pair in combination with the primary key pair; Combine the public key in the secondary key pair with the password in the login information to form a dynamic ciphertext; The dynamic ciphertext is transmitted to the fixed user terminal (2) for display; The private key in the secondary key is transferred to the first server (3) for standby use.

8. A data search and security access system according to claim 7, characterized in that: The method of extracting the real-time data of the second server (4) and generating the secondary key pair by combining the primary key pair comprises the following steps: The second server (4) extracts its own real-time data, wherein the real-time data includes data transmission rate, delay, packet loss rate, and bandwidth utilization; Use WaveletThreshold function to set the threshold parameters and perform wavelet threshold denoising to denoise the real-time data; Normalization processing: subtracting the minimum value from the data and dividing it by the difference between the maximum and minimum values ​​to generate a second set vector. The second set vector includes four components: data transmission rate, delay, packet loss rate, and bandwidth utilization. Combine the primary key pair with the hashed second set vector to generate a combined key; Intercept the current timestamp of the second server (4), combine the second set vector and the primary key pair with the number of days, hours, minutes, seconds, and milliseconds, and perform a weighted operation to obtain a candidate value, multiply the four components of the set vector by the corresponding weights, and then sum them up, and add the number of milliseconds, and take the remainder of the calculation result to the prime number to obtain the candidate value of the secondary key; The candidate value is hashed using the SHA-256 hash function and outputs a secondary key pair.

9. A data search and secure access system according to claim 1, characterized in that: The private key in the secondary key received from the second server (4) is used to decode the dynamic ciphertext to grant the user access rights, including the following steps: The fixed user terminal (2) displays the dynamic ciphertext generated by the second server terminal (4) by combining the password in the login information and the public key in the secondary key pair; The user manually inputs the dynamic ciphertext displayed by the fixed user terminal (2) through the mobile user terminal (1); The dynamic ciphertext is transmitted to the first server (3) through the mobile user terminal (1), and then the private key is parsed with the secondary key. The parsed dynamic ciphertext is compared with the password in the login information. If they are consistent, the user is granted access rights to the mobile user terminal (1) and the fixed user terminal (2). If they are inconsistent, no access rights are granted, and unauthorized access rights are output.

10. A data search and security access system according to claim 9, characterized in that: The system further comprises a reset module (5), the reset module (5) being in communication with the first server end (3) and the second server end (4), and the reset module (5) being configured to eliminate the primary access request and the primary key pair of the first server end (3), and the secondary access request and the secondary key pair of the second server end (4) after receiving access rights or unauthorized access rights.