Intelligent management and control method for secret carrier cabinet based on RFID tag
By analyzing the abnormality of the behavior of identification cards and confidential carriers, calculating the risk level, and adjusting the identity verification security level, the problem of identity card fraud was solved and the security of confidential carriers was improved.
Patent Information
- Application Number
- CN202511293235.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-11
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-09-11
AI Technical Summary
In the management of cabinets containing classified information, the risk of identity cards being fraudulently used threatens security, and existing technologies are unable to effectively provide early warnings and improve security.
By measuring the degree of abnormality in the behavior of identity cards and confidential carriers, the risk level is calculated, and the security level of identity verification is adjusted according to the risk level, including multi-factor authentication to reduce the risk of fraudulent transactions.
It improves the security of classified carriers, reduces the chance of unauthorized use of identification cards, and enhances the security of identity verification.
Smart Images

Figure CN120783428B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data processing technology, specifically relating to a smart management and control method for classified carrier cabinets based on RFID tags. Background Technology
[0002] Radio Frequency Identification (RFID) is a contactless automatic identification technology that utilizes radio frequency signals and their spatial coupling transmission characteristics to automatically identify stationary or moving objects. RFID cards are often referred to as inductive electronic chips, proximity cards, contactless cards, electronic tags, or electronic barcodes. The data storage of RFID tags follows the physical characteristics of integrated circuits; its essence is a binary code. Voltage transitions (rising edge = "1", falling edge = "0") convert binary data into electromagnetic signals. A simple RFID system consists of a reader, a transponder, or an electronic tag. The principle is that the reader emits radio waves of a specific frequency to the transponder, which drives the transponder circuitry to read the ID code inside the transponder. Transponders come in various forms, including cards, buttons, and tags. Electronic tags are battery-free, contactless, and resistant to dirt. Their chip passwords are unique and cannot be copied, offering high security and long lifespan. RFID tags can be affixed or installed on different items, allowing readers located at different geographical locations to read the data stored in the tags and achieve automatic item identification.
[0003] Each compartment of the classified storage cabinet is equipped with an RFID antenna, enabling real-time monitoring of the stored items and their location. The system automatically records when items leave the cabinet and who retrieves them. It also automatically monitors cabinet door status, including the lock status of each compartment, door opening / closing status, and RF antenna operation. An audible and visual alarm is triggered if any abnormal door opening is detected. The system supports network management, allowing administrators to register all personnel's identity information through a unified management platform. The system supports login via IC card, facial recognition, and account information. The cabinet itself retrieves borrowing and return information based on configuration, permissions, and identity information. Administrators can open any compartment, and the operation results are reported to the platform. Administrators can open any compartment in emergency situations, but this action is recorded.
[0004] When managing cabinets containing classified materials, users can open cabinets of different security levels by swiping their IC cards. Since user identity is determined by the access rights of the identification card, the security of the classified materials will be threatened if the identification card is lost or stolen during the security management and maintenance of the classified materials. Summary of the Invention
[0005] To address the aforementioned issues, this application provides a method for intelligent management and control of classified carrier cabinets based on RFID tags.
[0006] This application provides a method for intelligent management and control of classified carrier cabinets based on RFID tags, the method comprising:
[0007] The first step in obtaining the identity card deviates from the anomaly level.
[0008] The second behavior of obtaining classified carriers deviates from anomaly.
[0009] Based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree, the danger level of the current classified operation behavior is obtained;
[0010] Based on the risk level of the current classified operation, determine the security level for identity verification of personnel handling classified operations.
[0011] In one implementation, the first step of obtaining the identity card deviates from the anomaly level, including:
[0012] Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier;
[0013] Obtain the similarity of any two consecutive uses of the classified carrier;
[0014] Based on the weight value and the similarity, the deviation degree of the first behavior of the identity card is obtained.
[0015] In one implementation, obtaining the weight value of the difference in security classification levels between the identification card and the classified carrier includes:
[0016] Obtain the first confidentiality security level of the identification card;
[0017] Obtain the second security level of the classified carrier;
[0018] Based on the first and second security levels, obtain the weight value of the difference in security level between the identity card and the classified carrier.
[0019] In one implementation, obtaining the similarity between any two adjacent uses of the classified carrier includes:
[0020] Obtain the first time difference between the start times of any two adjacent uses of the classified carrier;
[0021] Obtain the second time difference between the end times of any two consecutive uses of the classified carrier;
[0022] Obtain the dynamic time-normalized distance of the card reader position corresponding to any two adjacent uses of the classified carrier;
[0023] Based on the first time difference, the second time difference, and the dynamic time warping distance, the similarity of any two adjacent uses of the classified carrier is obtained.
[0024] In one implementation, obtaining the first behavioral deviation anomaly degree of the identity card based on the weight value and the similarity includes:
[0025] Obtain the number of classified carriers operated within the current statistical time period;
[0026] Get the number of times any classified carrier is used within the current statistical time period;
[0027] Obtain the maximum similarity between any two consecutive uses of any classified carrier within the current statistical time period;
[0028] Based on the number of classified carriers, the number of times any classified carrier is used within the current statistical time period, and the maximum value, the first behavior deviation anomaly of the identity card is obtained.
[0029] In one implementation, the second behavior of obtaining the classified carrier deviates from the anomaly degree, including:
[0030] Obtain the historical operation record of the classified carrier, the historical operation record including the time when the classified carrier was operated and the location of the corresponding card reader;
[0031] Cluster analysis is performed on the historical operation records of the classified carrier to obtain the local reachability density of any operation of the identity card;
[0032] The number of times the identification card was used on the classified carrier was obtained;
[0033] Based on the local reachability density and the number of times the identification card operates on the classified carrier, the second behavior deviation anomaly degree of the classified carrier is obtained.
[0034] In one implementation, obtaining the danger level of the current classified operation behavior based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree includes:
[0035] Obtain the number of classified carriers operated within the current statistical time period;
[0036] Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier;
[0037] The risk level of the current classified operation behavior is obtained based on the number of classified carriers operated within the current statistical time period, the weight value, the first behavior deviation anomaly degree, and the second behavior deviation anomaly degree.
[0038] In one implementation, determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation includes:
[0039] Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier;
[0040] The safety threshold is determined based on the weight values;
[0041] Based on the risk level of the current classified operation and the security threshold, the security level for identity verification of personnel handling classified operations is determined.
[0042] In one implementation, determining the safety threshold based on the weight value includes:
[0043] Obtain a safety factor, which is a priori value;
[0044] The safety threshold is determined based on the safety factor and the weight value.
[0045] In one implementation, determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation and the security threshold includes:
[0046] If the risk level of the current classified operation is less than or equal to the security threshold, the security level for identity verification of the personnel handling the classified operation is determined to be ordinary.
[0047] If the risk level of the current classified operation is greater than the security threshold, the security level for identity verification of the personnel handling the classified operation is determined to be strict.
[0048] This application offers the following advantages: This application provides a smart management method for classified carrier cabinets based on RFID tags. The method includes: acquiring a first behavioral deviation anomaly degree of an identification card; acquiring a second behavioral deviation anomaly degree of the classified carrier; acquiring the risk level of the current classified operation behavior based on the first behavioral deviation anomaly degree and the second behavioral deviation anomaly degree; and determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior. This application, by determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior, can reduce the probability of unauthorized use of identification cards and improve the security of classified carriers. Attached Figure Description
[0049] To more clearly illustrate the implementation schemes of this application, the accompanying drawings used in the implementation schemes will be briefly introduced below. It should be understood that the accompanying drawings only show some implementation schemes of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained from the accompanying drawings without creative effort.
[0050] Figure 1 This is a flowchart illustrating an intelligent management and control method for a classified carrier cabinet based on RFID tags, according to an exemplary embodiment.
[0051] Figure 2 This is a flowchart illustrating a method for obtaining the degree of deviation of a first behavior from an identity card according to an exemplary embodiment;
[0052] Figure 3 This is a flowchart illustrating a method for obtaining a weighted value of the difference in security level between an identification card and a classified carrier, according to an exemplary embodiment.
[0053] Figure 4 This is a flowchart illustrating a method for obtaining the similarity of any two adjacent uses of a classified carrier, according to an exemplary embodiment.
[0054] Figure 5 This is a flowchart illustrating a method for obtaining the deviation anomaly degree of a first behavior of an identity card based on a weight value and similarity, according to an exemplary embodiment.
[0055] Figure 6 This is a flowchart illustrating a method for obtaining the degree of deviation anomaly of a second behavior of a classified carrier according to an exemplary embodiment;
[0056] Figure 7 This is a flowchart illustrating a method for obtaining the danger level of a current classified operation behavior based on a first behavior deviation anomaly degree and a second behavior deviation anomaly degree, according to an exemplary embodiment.
[0057] Figure 8 This is a flowchart illustrating a method for determining the security level of identity verification for personnel handling classified information based on the risk level of the current classified operation, according to an exemplary embodiment.
[0058] Figure 9 This is a flowchart illustrating a method for determining a safety threshold based on weight values according to an exemplary embodiment;
[0059] Figure 10This is a flowchart illustrating a method for determining the security level of authentication for personnel handling classified information based on the risk level of the current classified operation and a security threshold, according to an exemplary embodiment. Detailed Implementation
[0060] To clearly illustrate the technical features of this solution, the following detailed description, in conjunction with specific implementation methods and accompanying drawings, will provide a comprehensive explanation of this application.
[0061] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.
[0062] It should be understood that the steps described in the method embodiments of this application may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this application is not limited in this respect.
[0063] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0064] It should be noted that the concepts of "first" and "second" mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0065] It should be noted that the terms "one" and "multiple" used in this application are illustrative rather than restrictive. Those skilled in the art should understand that, unless explicitly stated in the context, they should be interpreted as "one or more". In the description of this application, unless otherwise stated, "multiple" refers to two or more than two, and other quantifiers are similar; "at least one item", "one item or multiple items", or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one item 'a' can represent any number of 'a's; as another example, one or more of a, b, and c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple; "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural.
[0066] Although operations or steps are described in a specific order in the accompanying drawings in the embodiments of this application, this should not be construed as requiring these operations or steps to be performed in the specific order or serial order shown, or requiring all of the shown operations or steps to be performed to obtain the desired result. In the embodiments of this application, these operations or steps may be performed serially; they may be performed in parallel; or a portion of these operations or steps may be performed.
[0067] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0068] First, the application scenario of this application is explained. The RFID classified carrier monitoring system uses a combination of RFID tags and readers to achieve accurate identification and real-time monitoring of classified carriers. Each classified carrier is equipped with its own RFID tag, which stores the carrier's basic information and circulation records. When the carrier enters the reader's identification range, the reader automatically reads the tag information and uploads the data to the system backend, enabling real-time tracking and status updates of the classified carrier. While intelligent management of classified carrier cabinets only requires identification of an identity card to verify whether the cabinet door can be opened, there is a risk of unauthorized use (e.g., the identity card's permissions are compromised). The aforementioned devices can only verify whether the current identity information has the authority to open or use the classified carrier; they cannot provide risk warnings regarding the use of the classified carrier. This application's embodiment analyzes the use of identity cards and the usage of classified carriers to adjust the security level of identity verification for classified operators. When an anomaly is detected, multiple verifications are performed on the identity of the operator using the identity card, reducing the risk of identity card theft and improving the security of the classified carrier. The present application will now be described in conjunction with specific embodiments.
[0069] Figure 1 This is a flowchart illustrating an intelligent management and control method for classified carrier cabinets based on RFID tags, according to an exemplary embodiment. Figure 1 As shown in the figure, this application provides a smart management and control method for classified carrier cabinets based on RFID tags, which may include the following steps:
[0070] In step S10, the deviation anomaly degree of the first line of the identity card is obtained.
[0071] In this step, the deviation degree of the first behavior of the identification card is obtained. For example, the weight value of the difference in the confidentiality level between the identification card and the confidential carrier can be obtained first, then the similarity of any two adjacent usage behaviors of the confidential carrier can be obtained, and then the deviation degree of the first behavior of the identification card is obtained based on the weight value and the similarity.
[0072] In step S20, the deviation anomaly degree of the second behavior of the classified carrier is obtained.
[0073] In this step, the deviation anomaly of the second behavior of the classified carrier is obtained. For example, the historical operation records of the classified carrier can be obtained first, including the time when the classified carrier was operated and the location of the corresponding card reader. Then, cluster analysis is performed on the historical operation records of the classified carrier to obtain the local reachability density of any operation of the identification card. Then, the number of operations of the identification card on the classified carrier is obtained. Finally, based on the local reachability density and the number of operations of the identification card on the classified carrier, the deviation anomaly of the second behavior of the classified carrier is obtained.
[0074] In step S30, the danger level of the current classified operation behavior is obtained based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree.
[0075] In this step, the risk level of the current classified operation is obtained based on the deviation anomaly degree of the first line and the deviation anomaly degree of the second line. For example, the number of classified carriers operated within the current statistical time period can be obtained first, then the weight value of the difference in the classification level between the identification card and the classified carrier can be obtained, and then the risk level of the current classified operation is obtained based on the number of classified carriers operated within the current statistical time period, the weight value, the deviation anomaly degree of the first line, and the deviation anomaly degree of the second line.
[0076] In step S40, the security level for identity verification of personnel handling classified information is determined based on the risk level of the current classified operation.
[0077] In this step, the security level for identity verification of personnel handling classified information is determined based on the risk level of the current classified operation. For example, the weighted value of the difference in classification level between the identification card and the classified carrier can be obtained first. Then, a security threshold can be determined based on the weighted value. Finally, the security level for identity verification of personnel handling classified information is determined based on the risk level of the current classified operation and the security threshold.
[0078] In summary, this application provides a smart management method for classified carrier cabinets based on RFID tags. The method includes: acquiring a first behavioral deviation anomaly degree of an identification card; acquiring a second behavioral deviation anomaly degree of the classified carrier; acquiring the risk level of the current classified operation behavior based on the first and second behavioral deviation anomalies; and determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior. This application, by determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior, can reduce the probability of unauthorized use of identification cards and improve the security of classified carriers.
[0079] Figure 2This is a flowchart illustrating a method for obtaining the degree of a first behavioral deviation from an anomaly of an identity card, according to an exemplary embodiment. Figure 2 As shown, obtaining the first deviation anomaly degree of the identity card may include the following steps:
[0080] In step S101, the weight value of the difference in confidentiality level between the identity card and the confidential carrier is obtained.
[0081] In this step, the weight value of the difference in security level between the identification card and the classified carrier is obtained. For example, the first security level of the identification card can be obtained first, then the second security level of the classified carrier can be obtained, and then the weight value of the difference in security level between the identification card and the classified carrier can be obtained based on the first security level and the second security level.
[0082] In step S102, the similarity of any two adjacent uses of the classified carrier is obtained.
[0083] In this step, the similarity between any two adjacent uses of the classified carrier is obtained. For example, the first time difference between the start times of any two adjacent uses of the classified carrier can be obtained first, then the second time difference between the end times of any two adjacent uses of the classified carrier can be obtained, then the dynamic time-normalized distance of the card reader positions corresponding to any two adjacent uses of the classified carrier can be obtained, and finally the similarity between any two adjacent uses of the classified carrier can be obtained based on the first time difference, the second time difference, and the dynamic time-normalized distance.
[0084] In step S103, the first behavior deviation anomaly degree of the identity card is obtained based on the weight value and the similarity.
[0085] In this step, the first behavior deviation anomaly of the identity card is obtained based on the weight value and similarity. For example, the number of classified carriers operated within the current statistical time period can be obtained first, then the number of times any classified carrier was used within the current statistical time period can be obtained, then the maximum similarity of any two adjacent usage behaviors of any classified carrier within the current statistical time period can be obtained, and finally, the first behavior deviation anomaly of the identity card is obtained based on the number of classified carriers, the number of times any classified carrier was used within the current statistical time period, and the maximum similarity.
[0086] Figure 3 This is a flowchart illustrating a method for obtaining a weighted value of the difference in security level between an identification card and a classified carrier, according to an exemplary embodiment. Figure 3 As shown, obtaining the weight value of the difference in confidentiality level between the identification card and the confidential carrier may include the following steps:
[0087] In step S1011, the first confidentiality security level of the identity card is obtained.
[0088] In this step, the first level of security confidentiality for the identification card i is obtained. The security levels of an identification card can include: Secret, Confidential, and Top Secret. For example, these can be quantified: Secret corresponds to a security level of 1, Confidential to a security level of 2, and Top Secret to a security level of 3.
[0089] In step S1012, the second security level of the classified carrier is obtained.
[0090] In this step, the second security level of classified carrier a is obtained. The security levels of classified media can include: Secret, Confidential, and Top Secret. For example, these can be quantified: Secret corresponds to a security level of 1, Confidential to a security level of 2, and Top Secret to a security level of 3.
[0091] Generally speaking, the first security level of an identification card should correspond to the second security level of the classified carrier. That is, only identification cards with the corresponding security level can operate on classified carriers of the corresponding security level. The first security level of the identification card should not be lower than the second security level of the classified carrier.
[0092] In step S1013, the weight value of the difference in confidentiality level between the identity card and the confidential carrier is obtained based on the first confidentiality security level and the second confidentiality security level.
[0093] In this step, according to the first level of classified security and the second level of classified security Obtain the weight value of the difference in confidentiality level between the identification card i and the confidential carrier a. For example, the weight value of the difference in the security level between the identification card i and the classified carrier a. It can be obtained from the following formula:
[0094] ;
[0095] in, This is for normalization purposes.
[0096] Based on the historical usage of classified media, a usage record sequence of classified media can be obtained, which can be represented as ((t1, x1), (t2, x2), (t3, x3)...). Here, t1 represents the time when the classified media is read by the first reader (the time when the classified media is first used), and x1 represents the location of the first reader (the location where the classified media is first used).
[0097] Figure 4 This is a flowchart illustrating a method for obtaining the similarity of arbitrary two adjacent uses of a classified carrier, according to an exemplary embodiment. Figure 4 As shown, obtaining the similarity between any two adjacent uses of the classified carrier may include the following steps:
[0098] In step S1021, the first time difference between the start times of any two adjacent uses of the classified carrier is obtained.
[0099] In this step, the first time difference between the start times of any two adjacent uses of the classified carrier is obtained. .
[0100] In step S1022, the second time difference between the end times of any two adjacent uses of the classified carrier is obtained.
[0101] In this step, the second time difference between the end times of any two consecutive uses of the classified carrier is obtained. .
[0102] In step S1023, the dynamic time-normalized distance of the card reader position corresponding to any two adjacent uses of the classified carrier is obtained.
[0103] In this step, the dynamic time-normalized distance of the reader position corresponding to any two adjacent uses of the classified carrier is obtained. .
[0104] In step S1024, the similarity of any two adjacent uses of the classified carrier is obtained based on the first time difference, the second time difference, and the dynamic time warping distance.
[0105] In this step, based on the first time difference Second time difference and dynamic time warping distance Obtain the usage behavior of any two consecutive times of classified carrier a. and similarity For example, any two consecutive uses of classified carrier a. and similarity It can be obtained from the following formula:
[0106] ;
[0107] in, This indicates the j-th use of the classified carrier a. This represents the (j+1)th use of the classified carrier a. It is an exponential function with the natural number e as its base.
[0108] When judging abnormal behavior in the use of identity cards, it is not determined by a single behavior, but by analyzing and judging the cumulative abnormal behavior over a period of time. It is similar to how suspicion does not arise in a day, but is generated by the accumulation of events.
[0109] Figure 5 This is a flowchart illustrating a method for obtaining the degree of deviation of a first behavior of an identity card from an abnormality based on a weight value and similarity, according to an exemplary embodiment. Figure 5 As shown, obtaining the first behavior deviation anomaly degree of the identity card based on the weight value and the similarity may include the following steps:
[0110] In step S1031, the number of classified carriers operated within the current statistical time period is obtained.
[0111] In this step, the number of classified carriers operated within the current statistical time period is obtained. For example, the current statistical time period could be the most recent week.
[0112] In step S1032, the number of times any classified carrier is used within the current statistical time period is obtained.
[0113] In this step, the number of times any classified carrier 'a' is used within the current statistical time period is obtained. For example, the current statistical time period could be the most recent week.
[0114] In step S1033, the maximum value of the similarity between any two adjacent uses of any classified carrier within the current statistical time period is obtained.
[0115] In this step, the maximum similarity between any two consecutive uses of any classified carrier 'a' within the current statistical time period is obtained. .
[0116] In step S1034, the first behavior deviation anomaly degree of the identity card is obtained based on the number of classified carriers, the number of times any classified carrier is used within the current statistical time period, and the maximum value.
[0117] In this step, based on the number of classified carriers The number of times any classified carrier 'a' is used within the current statistical time period. and the maximum value Obtain the first deviation anomaly of the identity card i. For example, the first behavior of ID card i deviates from the anomaly level. It can be obtained from the following formula:
[0118] ;
[0119] Where 'a' represents the 'a'th classified carrier, and 'j' represents the 'j'th use of the classified carrier. It is an exponential function with the natural number e as its base.
[0120] Based on the similarity of any two adjacent uses of any classified carrier 'a' within the current statistical time period, the classified operation behavior within the current statistical time period and the historical statistical time period are analyzed to determine whether the classified operation behavior in the current statistical time period deviates from that in the historical statistical time period. Each classified operation behavior in the current statistical time period exists in the historical statistical time period or is similar to the historical behavior. The more similar behaviors exist or the greater the similarity, the smaller the deviation abnormality of the first behavior.
[0121] Figure 6 This is a flowchart illustrating a method for obtaining the degree of deviation anomaly of a second behavior of a classified carrier, according to an exemplary embodiment. Figure 6 As shown, obtaining the deviation anomaly degree of the second behavior of the classified carrier may include the following steps:
[0122] In step S201, the historical operation record of the classified carrier is obtained. The historical operation record includes the time when the classified carrier was operated and the location of the corresponding card reader.
[0123] In this step, the historical operation records of the classified carrier are obtained. These records include the time when the classified carrier was operated and the location of the corresponding card reader. For example, based on the historical usage of the classified carrier, a usage record sequence can be obtained, represented as ((t1, x1), (t2, x2), (t3, x3)...). Here, t1 represents the time when the classified carrier was read by the first card reader (the time when the classified carrier was first used), and x1 represents the location of the first card reader (the location where the classified carrier was first used).
[0124] In step S202, cluster analysis is performed on the historical operation records of the classified carrier to obtain the local reachability density of any operation of the identity card.
[0125] In this step, cluster analysis is performed on the historical operation records of classified carriers to obtain the local reachability density of any operation k of the identification card. For example, the local reachability density of any operation k of an identity card can be obtained using existing LOF algorithms. The local achievable density It can characterize the anomaly degree of classified operational behavior, i.e., the local reachability density. The larger the value, the smaller the degree of abnormality in classified operations, and the higher the local density. The smaller the value, the greater the degree of abnormality in classified operations.
[0126] In step S203, the number of times the identification card operates on the classified carrier is obtained.
[0127] In this step, the number of operations performed by identification card i on classified carrier a is obtained. .
[0128] In step S204, the second behavior deviation anomaly degree of the classified carrier is obtained based on the local reachability density and the number of operations performed by the identification card on the classified carrier.
[0129] In this step, based on the locally reachable density And the number of times the identification card i operates on the classified carrier a. Obtain the deviation anomaly degree of the second behavior of the classified carrier a. For example, the second behavior of classified carrier a deviates from the anomaly degree. It can be obtained from the following formula:
[0130] ;
[0131] in, Let e be an exponential function with the natural number e as its base. From this formula, we can see the locally reachable density. The larger the value, the greater the deviation of the second line from the abnormality. The smaller the density, the higher the local density. The smaller the value, the higher the deviation from the anomaly level in the second row. The larger.
[0132] Figure 7 This is a flowchart illustrating a method for obtaining the danger level of a current classified operation behavior based on a first behavior deviation anomaly degree and a second behavior deviation anomaly degree, according to an exemplary embodiment. Figure 7 As shown, obtaining the danger level of the current classified operation behavior based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree may include the following steps:
[0133] In step S301, the number of classified carriers operated within the current statistical time period is obtained.
[0134] In this step, the number N of classified carriers operated within the current statistical time period is obtained. For example, the current statistical time period can be the most recent week.
[0135] In step S302, the weight value of the difference in confidentiality level between the identity card and the confidential carrier is obtained.
[0136] In this step, the weighted value of the difference in the security classification level between the identification card i and the classified carrier a is obtained. For example, the weight value of the difference in the security level between the identification card i and the classified carrier a. The method for obtaining the data can be referred to in the aforementioned step S1013 embodiment, and will not be repeated here.
[0137] In step S303, the danger level of the current classified operation behavior is obtained based on the number of classified carriers operated within the current statistical time period, the weight value, the first behavior deviation anomaly degree, and the second behavior deviation anomaly degree.
[0138] In this step, the number N of classified carriers operated within the current statistical time period and the weight value are used as the basis for the calculation. The first line deviates from the abnormality level. And the degree of deviation from the second behavior. Obtain the risk level of the current classified operation of the identity card i. For example, the risk level of the current classified operation of ID card i. It can be obtained from the following formula:
[0139] ;
[0140] Where 'a' represents the a-th classified carrier. From this formula, it can be seen that the first row represents the deviation anomaly degree. The larger the value, the greater the deviation of the second line from the abnormality. The larger the value, or the greater the weight of the difference in the security classification level between the identification card i and the classified carrier a. The larger the value, the higher the risk level of the current classified operation behavior of ID card i. The larger.
[0141] Figure 8 This is a flowchart illustrating a method for determining the security level of authentication for personnel handling classified information based on the risk level of the current classified operational activity, according to an exemplary embodiment. Figure 8As shown, determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation may include the following steps:
[0142] In step S401, the weight value of the difference in confidentiality level between the identity card and the confidential carrier is obtained.
[0143] In this step, the weighted value of the difference in the security classification level between the identification card i and the classified carrier a is obtained. For example, the weight value of the difference in the security level between the identification card i and the classified carrier a. The method for obtaining the data can be referred to in the aforementioned step S1013 embodiment, and will not be repeated here.
[0144] In step S402, a safety threshold is determined based on the weight value.
[0145] In this step, a safety threshold is determined based on the weight values. For example, a safety coefficient can be obtained first, which is a priori value, and then the safety threshold can be determined based on the safety coefficient and the weight values.
[0146] In step S403, the security level for identity verification of personnel handling classified information is determined based on the risk level of the current classified operation and the security threshold.
[0147] In this step, the security level for authenticating personnel handling classified information is determined based on the risk level of the current classified operation and the security threshold. For example, if the risk level of the current classified operation is less than or equal to the security threshold, the security level for authenticating personnel handling classified information can be determined as "normal"; if the risk level of the current classified operation is greater than the security threshold, the security level for authenticating personnel handling classified information can be determined as "strict".
[0148] Figure 9 This is a flowchart illustrating a method for determining a safety threshold based on weight values, according to an exemplary embodiment. Figure 9 As shown, determining the safety threshold based on the weight value may include the following steps:
[0149] In step S4021, a safety factor is obtained, which is a priori value.
[0150] In this step, a safety factor β is obtained, which is a priori value. For example, the safety factor β can be 0.75.
[0151] In step S4022, a safety threshold is determined based on the safety factor and the weight value.
[0152] In this step, based on the safety factor β and the weight value... Determine the safety threshold α. For example, the safety threshold α can be obtained by the following formula:
[0153] α = (1- )*β;
[0154] This formula shows the weighting value of the difference in security level between the identification card i and the classified carrier a. The smaller the value, the larger the security threshold α, which is the weighted value of the difference in the security level between the identification card i and the classified carrier a. The larger the value, the smaller the security threshold α, which can further reduce the probability of the identification card being used without authorization and improve the security of classified carriers.
[0155] Figure 10 This is a flowchart illustrating a method for determining the security level of authentication for personnel handling classified information based on the risk level of the current classified operational activity and a security threshold, according to an exemplary embodiment. Figure 10 As shown, determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation and the security threshold may include the following steps:
[0156] In step S4031, if the danger level of the current classified operation is less than or equal to the security threshold, the security level for identity verification of the classified operator is determined to be ordinary.
[0157] In this step, the risk level of the current classified operation of ID card i is determined. If the security level is less than or equal to the security threshold α, the security level for authenticating personnel handling classified information is determined to be "normal". For example, if the security level for authenticating personnel handling classified information is "normal", then multi-factor authentication is not required; the normal authentication process can be followed.
[0158] In step S4032, if the danger level of the current classified operation is greater than the security threshold, the security level for identity verification of the classified operator is determined to be strict.
[0159] In this step, the risk level of the current classified operation of ID card i is determined. If the security threshold α is exceeded, the security level for identity verification of personnel handling classified information is determined to be strict. For example, a strict security level for identity verification of personnel handling classified information means that multiple identity verifications are required, such as facial recognition verification in addition to password and account verification. Only after all multiple identity verifications are passed can the classified information be operated.
[0160] In summary, this application provides a smart management method for classified carrier cabinets based on RFID tags. The method includes: acquiring a first behavioral deviation anomaly degree of an identification card; acquiring a second behavioral deviation anomaly degree of the classified carrier; acquiring the risk level of the current classified operation behavior based on the first and second behavioral deviation anomalies; and determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior. This application, by determining the security level for identity verification of the classified operator based on the risk level of the current classified operation behavior, can reduce the probability of unauthorized use of identification cards and improve the security of classified carriers.
[0161] This application also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement the steps of the intelligent management and control method for classified carrier cabinets based on RFID tags provided in this application.
[0162] In another exemplary embodiment, a computer program product is also provided, which includes a computer program executable by a programmable electronic device, the computer program having a code portion for executing the above-described intelligent management and control method for classified carrier cabinets based on RFID tags when executed by the programmable electronic device.
[0163] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these modifications and improvements all fall within the protection scope of this application.
Claims
1. A method for intelligent management and control of classified carrier cabinets based on RFID tags, characterized in that, The method includes: The first step in obtaining the identity card deviates from the anomaly level. The second behavior of obtaining classified carriers deviates from anomaly. Based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree, the danger level of the current classified operation behavior is obtained; Based on the risk level of the current classified operation, determine the security level for identity verification of the personnel involved in the classified operation; The first line of obtaining the identity card deviates from the anomaly level, including: Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier; Obtain the similarity of any two consecutive uses of the classified carrier; Based on the weight value and the similarity, the deviation degree of the first behavior of the identity card is obtained; The step of obtaining the weighted value of the difference in security classification levels between the identification card and the classified carrier includes: Obtain the first confidentiality security level of the identification card; Obtain the second security level of the classified carrier; Based on the first security level and the second security level, obtain the weight value of the difference in security level between the identity card and the classified carrier; The process of obtaining the similarity between any two consecutive uses of the classified carrier includes: Obtain the first time difference between the start times of any two adjacent uses of the classified carrier; Obtain the second time difference between the end times of any two consecutive uses of the classified carrier; Obtain the dynamic time-normalized distance of the card reader position corresponding to any two adjacent uses of the classified carrier; Based on the first time difference, the second time difference, and the dynamic time warping distance, the similarity of any two adjacent uses of the classified carrier is obtained; The step of obtaining the deviation anomaly degree of the first line of the identity card based on the weight value and the similarity includes: Obtain the number of classified carriers operated within the current statistical time period; Get the number of times any classified carrier is used within the current statistical time period; Obtain the maximum similarity between any two consecutive uses of any classified carrier within the current statistical time period; Based on the number of classified carriers, the number of times any classified carrier is used within the current statistical time period, and the maximum value, the first behavior deviation anomaly of the identity card is obtained; The second step in obtaining classified carriers is the deviation anomaly, including: Obtain the historical operation record of the classified carrier, the historical operation record including the time when the classified carrier was operated and the location of the corresponding card reader; Cluster analysis is performed on the historical operation records of the classified carrier to obtain the local reachability density of any operation of the identity card; The number of times the identification card was used on the classified carrier was obtained; Based on the local reachability density and the number of times the identification card operates on the classified carrier, the second behavior deviation anomaly degree of the classified carrier is obtained; The step of obtaining the danger level of the current classified operation behavior based on the first behavior deviation anomaly degree and the second behavior deviation anomaly degree includes: Obtain the number of classified carriers operated within the current statistical time period; Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier; The risk level of the current classified operation behavior is obtained based on the number of classified carriers operated within the current statistical time period, the weight value, the first behavior deviation anomaly degree, and the second behavior deviation anomaly degree.
2. The intelligent management and control method for classified carrier cabinets based on RFID tags according to claim 1, characterized in that, The step of determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation includes: Obtain the weighted value of the difference in confidentiality level between the identification card and the confidential carrier; The safety threshold is determined based on the weight values; Based on the risk level of the current classified operation and the security threshold, the security level for identity verification of personnel handling classified operations is determined.
3. The intelligent management and control method for classified carrier cabinets based on RFID tags according to claim 2, characterized in that, Determining the safety threshold based on the weight value includes: Obtain a safety factor, which is a priori value; The safety threshold is determined based on the safety factor and the weight value.
4. The intelligent management and control method for classified carrier cabinets based on RFID tags according to claim 2, characterized in that, The step of determining the security level for identity verification of personnel handling classified information based on the risk level of the current classified operation and the security threshold includes: If the risk level of the current classified operation is less than or equal to the security threshold, the security level for identity verification of the personnel handling the classified operation is determined to be ordinary. If the risk level of the current classified operation is greater than the security threshold, the security level for identity verification of the personnel handling the classified operation is determined to be strict.
Citation Information
Patent Citations
IC card, portable electronic device, and information processing method
CN109154960A
Threshold determining and identity verification method, apparatus, electronic device, and storage medium
US20210049259A1