Office system and method for digital security

By employing multi-factor authentication, risk fusion assessment, and blockchain-based evidence storage mechanisms, the system addresses the issues of identity verification and risk assessment independence in existing office systems, enabling dynamic access control and continuous monitoring, thereby enhancing the security and flexibility of digital office operations.

CN120833128AInactive Publication Date: 2025-10-24SICHUAN YOUJIA TRACEABILITY TECH CO LTD

Patent Information

Application Number
CN202511341607.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2025-10-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing office systems designed for digital security lack multi-dimensional verification mechanisms for identity authentication, making them vulnerable to identity forgery attacks. Risk assessments are independent and have low accuracy. Access control policies are statically configured and cannot be dynamically adjusted. In cross-organizational collaboration scenarios, it is difficult to balance data sharing efficiency and security protection. Operation traceability and dynamic closed-loop functions are lacking, making it impossible to respond to security threats in a timely manner.

Method used

By employing multi-factor authentication, risk fusion assessment, virtual security sandbox, and zero-trust verification, combined with blockchain evidence storage mechanisms, a perception module, a decision-making module, an execution module, and a closed-loop module are constructed to achieve multi-dimensional identity verification, dynamic risk assessment, differentiated access control, and continuous monitoring.

Benefits of technology

It enhances login security, accurately identifies complex security threats, balances data sharing efficiency with security protection, ensures traceability of operations, avoids outdated protection strategies, and meets the high security and flexibility requirements of modern digital offices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120833128A_ABST
    Figure CN120833128A_ABST
Patent Text Reader

Abstract

The invention discloses a digital security-oriented office system and method, and relates to the technical field of information security and office automation, the digital security-oriented office system comprises a sensing module, a decision module, an execution module, a tracking module and a closed loop module, the sensing module collects login information, performs multi-factor verification, generates security sensing data, and sends the security sensing data to the decision module; the decision-making module compares security perception data with historical login information, divides risk levels and generates an access control decision, the execution module constructs a virtual security sandbox or verifies an access request based on a zero trust principle and generates an authority white list and cooperation timeliness, and the tracking module records an operation behavior and a security log through a block chain. The closed-loop module monitors an office scene in real time and drives data updating and sandbox destroying. According to the method, the whole-process security control of the office scene is realized, the risk is accurately identified, the protection strategy is dynamically adjusted, the high security requirement of cross-organization and internal office is met, and a powerful guarantee is provided for the security of digital office data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security and office automation, and in particular to an office system and method oriented to digital security. BACKGROUND

[0002] In recent years, with the deepening of digital transformation, the office scene gradually shifts from the traditional offline mode to the online collaborative mode, and new office modes such as cross-organization collaboration and remote office are increasingly popular. Under this background, the openness and mobility of office data have been significantly improved, but at the same time, more complex security risks are also faced, such as identity forgery, data leakage, illegal access, and abuse of authority, which directly threaten the core business data security and business interests of the organization.

[0003] In the prior art, the office system oriented to digital security has many limitations in the security protection aspect. In terms of identity verification, most systems only rely on passwords or single biometric features for identity verification, lack multi-dimensional verification mechanisms, and are difficult to resist identity forgery attacks such as password cracking and biometric feature simulation, which can easily lead to illegal users bypassing verification to enter the system. In terms of risk assessment, the risk analysis of user behavior, data access, and network environment is independent of each other, and a unified risk assessment system has not been formed, which cannot fully identify complex security threats, resulting in low risk judgment accuracy and difficulty in avoiding potential security risks in advance. At the same time, the dynamic adjustment capability of access control strategy is insufficient, and the traditional access control strategy is mostly static configuration, which cannot be dynamically adjusted according to the real-time risk level. In the cross-organization collaboration scene, it is difficult to balance data sharing efficiency and security protection, and it is easy to have problems such as excessive grant of authority or collaboration lag, affecting office efficiency and data security. The operation traceability and dynamic closed loop function of the prior art is relatively missing, and there is a lack of tamper-proof operation log recording mechanism, it is difficult to accurately trace the root cause after a security incident occurs, and a continuous monitoring and dynamic updating closed loop of the office scene has not been established, which cannot respond to new security threats in time, resulting in lagging protection strategies and difficulty in meeting the changing security needs in the digital office scene. SUMMARY

[0004] The technical problems solved by the present application are that the existing office system for digital security has many limitations in the security protection aspect, in the identity verification aspect, most systems only rely on passwords or single biometric features for identity verification, lack multi-dimensional verification mechanism, are difficult to resist identity spoofing attacks, and are easy to cause illegal users to bypass verification to enter the system, in the risk assessment, the risk analysis of user behavior, data access, and network environment is independent of each other, and a unified risk assessment system has not been formed, which cannot comprehensively identify complex security threats, resulting in low risk judgment accuracy, and the dynamic adjustment capability of the access control strategy is insufficient, the traditional access control strategy is mostly static configuration, and cannot be dynamically adjusted according to the real-time risk level, in the cross-organization collaboration scene, it is difficult to balance the data sharing efficiency and security protection, the operation traceability and dynamic closed loop function of the prior art are relatively missing, there is a lack of tamper-proof operation log recording mechanism, and a continuous monitoring and dynamic updating closed loop of the office scene has not been established, which cannot respond to new security threats in time, resulting in lagging protection strategy.

[0005] To solve the above technical problems, the present application provides the following technical scheme: an office system for digital security, comprising a perception module, a decision module and an execution module; The perception module is used for collecting login information, performing feature extraction and data analysis on the login information, and obtaining security perception data; The decision module is used for comparing the security perception data with historical login information, obtaining a comparison result, dividing the risk level of user behavior mode, data access mode and network environment abnormality, establishing a one-to-one correspondence between the comparison result and the risk level, generating an access control decision result, triggering corresponding security measures according to the access control decision result, and the risk level includes a first risk level, a second risk level and a third risk level; The execution module is used for encrypting and loading target data requested by the user to access, and generating a permission white list of the user account and a collaboration time limit based on the access control decision result.

[0006] As a preferred scheme of the office system for digital security, wherein the perception module comprises an identity verification unit and a data acquisition unit; The identity verification unit is used for multi-factor identity verification of login information, and the multi-factor identity verification includes password authentication, biometric recognition and device fingerprint recognition, and first verification data, second verification data and third verification data are obtained respectively; The security perception data includes user identity feature data, environment state data, network behavior data and biometric matching data; The data collection unit is used to collect user information, environmental information and network addresses, and generate first security perception data, second security perception data and third security perception data from the collected information, and obtain verification result deviation values ​​of the first verification data, the second verification data and the third verification data. The verification result deviation values ​​are respectively calculated as the deviation values ​​of the first verification data, the second verification data and the third verification data from the historical login information benchmark data, and the verification result deviation values ​​are compared with a preset deviation threshold value. When any verification result deviation value is greater than the preset deviation threshold value, it is determined that there is an abnormality in the perception module, an alarm mechanism is triggered, and the login information corresponding to the abnormal data is determined and recorded in the tracking module; The login information includes user information, environment information, network address and user biometrics; The user information includes user name, account ID, job function and department; The environmental information includes the device operating system version, the terminal's geographical location, and the network access method, which includes wired access, wireless access, and VPN access; The network address includes a MAC address, a port number, and a corresponding subnet mask; The user biometric features include facial features, fingerprint features and iris features.

[0007] As a preferred solution of the digital security-oriented office system described in the present invention, the system further includes a tracking module, which is used to use blockchain distributed ledger technology to record all user operations, permission changes, and security event logs, and generate a hash sequence; The user operation behavior includes user login and identity authentication operations, data access behavior, application and system operation behavior and collaboration behavior; The permission change records include user role adjustments, access rights addition or revocation, sharing permission modifications, data access scope adjustments, and permission expiration changes; The security event log includes access exception records, interception records, permission change records and system alarm information; The triggering of the alarm mechanism, determining the login information corresponding to the abnormal data and recording it in the tracking module includes: Analyze the verification status of the first verification data, the second verification data, and the third verification data, which include a normal state and an abnormal state, and determine whether the first verification data, the second verification data, and the third verification data are in an abnormal state, wherein the abnormal state includes password verification failure, biometric abnormality, and device fingerprint mismatch. If the login information corresponding to any one of the first verification data, the second verification data, or the third verification data is abnormal, trigger an alarm mechanism and record the abnormal data to the tracking module.

[0008] As a preferred scheme of the office system for digital security, wherein: the judging whether the first verification data, the second verification data and the third verification data are in abnormal state comprises: Password verification anomaly: comparing the first verification data, the second verification data and the third verification data with preset password verification standards respectively, recording the verification data that does not pass the preset standard, and judging the login information corresponding to the verification data that does not pass the verification standard as password verification anomaly; Biological feature anomaly: calculating the similarity changes of the first verification data, the second verification data and the third verification data at adjacent verification time nodes respectively to obtain the first similarity change, the second similarity change and the third similarity change, and if the similarity change of any verification data is lower than a preset similarity threshold, judging the login information corresponding to the verification data lower than the preset similarity threshold as biological feature anomaly; Device fingerprint anomaly: obtaining the device fingerprint update records of the first verification data, the second verification data and the third verification data respectively, counting the update frequencies of the first verification data, the second verification data and the third verification data within a preset time according to the update records to obtain the first update frequency, the second update frequency and the second update frequency, and if the update frequency of any verification data decreases to zero within a preset period and the fingerprint does not change, judging the corresponding verification data as device fingerprint anomaly.

[0009] As a preferred scheme of the office system for digital security, wherein: the decision module comprises a comparison unit and a risk assessment unit; The comparison unit is used for performing first comparison on the user information, the environment information, the network address, the user biological feature and the historical login information, calculating the corresponding matching rates respectively, accumulating the matching rates to generate an accumulated score, performing normalization processing on the matching rates, and generating a first comparison result through the accumulated score calculation, wherein the accumulated score is compared with a preset threshold after the matching rates are accumulated, when the accumulated score is higher than the preset threshold, it is determined as high consistency, when the accumulated score is in a preset threshold interval, it is determined as medium consistency, and when the accumulated score is lower than the preset threshold, it is determined as low consistency. The risk assessment unit is used for analyzing the user behavior mode, calculating a first risk score by using a cumulative scoring algorithm to generate a first risk level, analyzing the data access mode, calculating a second risk score by using the cumulative scoring algorithm to generate a second risk level, and analyzing the network environment anomaly, calculating a third risk score by using the cumulative scoring algorithm to generate a third risk level. The user behavior mode comprises login frequency, common operation path and common file access type. The data access mode comprises access frequency, access data type and access duration. The network environment abnormal situation includes an abnormal traffic peak, a malicious port scan and an illegal IP connection. The access control policy adjustment includes: normalizing the first comparison result with the first risk level, the second risk level and the third risk level to obtain a normalized score, accumulating the normalized score to generate an accumulated score, comparing the accumulated score with a preset threshold to obtain a fusion result, determining that the access control policy adjustment condition is established when the fusion result shows that the risk level is higher than the preset threshold, triggering an access control policy adjustment mechanism, and recording a policy adjustment log, the policy adjustment log including adjustment time, adjustment content and trigger condition.

[0010] As a preferred scheme of the office system for digital security, the execution module comprises a sandbox management unit and an access control unit. The sandbox management unit is configured to build a virtual security sandbox in a cross-organization collaboration scenario, load and encrypt target data as first data, and set a first permission whitelist and a collaboration time limit. The cross-organization collaboration scenario refers to a data sharing and business collaboration scenario between the organization to which the user belongs and an external third-party organization, wherein the external third-party organization includes partners, suppliers, customers and regulatory agencies. The target data includes business data, file data, communication data and operation data. The permission whitelist includes data paths to be accessed, operation types to be executed and valid time ranges. The collaboration time limit refers to the duration during which the virtual security sandbox and the permission whitelist are valid, and the destruction mechanism is triggered automatically after the preset period of time. The access control unit is configured to continuously verify access requests based on the zero trust principle in a non-cross-organization scenario, generate first access request data from the access requests, and generate second comparison results from the access control decision results. The first access request data includes request time, request account and request data identifier. The non-cross-organization collaboration scenario refers to a data access and business operation scenario within the organization. The access control unit includes: analyzing the matching state of the second comparison result and the access control policy, the matching state including an allowed state and a denied state, determining whether the second comparison result is in the denied state, and if the second comparison result is in the denied state, determining that the access request is an out-of-permission operation, triggering an interception operation, and encrypting the intercepted data, the target data and the permission whitelist.

[0011] As a preferred scheme of the office system for digital security, wherein: the system further comprises a closed loop module, the closed loop module is used for monitoring an office scene in real time, performing feature extraction and data analysis on the office scene to obtain office scene data, comparing the office scene data with security perception data to obtain a comparison result of the office scene, triggering an update mechanism through the comparison result to drive updated login information and security perception data, and destroying a sandbox, clearing data and operation traces after collaboration time limit ends; The feature extraction comprises extracting user behavior features, data access features, collaboration features and environment features, and the data analysis comprises screening, counting and processing of collected login information; The office scene data comprises user behavior information, data access information and collaboration time limit information; The closed loop module comprises a monitoring unit and an update unit; The monitoring unit is used for obtaining first office scene data, second office scene data and third office scene data corresponding to user behavior, data access situation and collaboration time limit respectively; The update unit is used for performing data analysis and comparison calculation on the first office scene data, the second office scene data, the third office scene data, the first security perception data, the second security perception data, the third security perception data and the access control decision result to obtain a comparison result; The data analysis matches and calculates the first office scene data, the second office scene data, the third office scene data, the first security perception data, the second security perception data, the third security perception data and a preset standard respectively to calculate similarity or difference value, compares with the preset standard to judge whether the data deviates from the standard, and triggers a corresponding update mechanism; The triggering update mechanism comprises: comparing the comparison result after the data analysis and comparison calculation with the preset standard, determining that an update condition is established when the comparison result shows that the login information or the access control strategy deviates from the preset standard, triggering the update mechanism to generate updated login information and access control strategy, and sending the updated login information and the access control strategy to an execution module, and determining that a destruction condition is established when the collaboration time limit ends, triggering the sandbox to be destroyed and data traces to be cleared.

[0012] As a preferred scheme of the office system for digital security, wherein: the tracking module comprises a recording unit and a storage unit; The recording unit is used for generating first record data from user operation behavior, generating second record data from permission change record, and generating third record data from security event log; The user operation behavior comprises user login and identity verification operation, data access behavior, application and system operation behavior and collaboration behavior; The permission change record includes user role adjustment, access permission addition or revocation, shared permission modification, data access range adjustment and permission time limit change; The security event log includes access exception record, interception record, permission change record and system alarm information; The evidence storage unit is used for performing hash operation on the first record data, the second record data and the third record data to obtain corresponding first hash value, second hash value and third hash value, sequentially connecting the first hash value, the second hash value and the third hash value in time sequence to form a hash sequence, and storing the obtained hash sequence in the block chain; The alarm includes: comparing the first record data, the second record data and the third record data with the preset normal operation standard, when the data is abnormal or there is tampering evidence, determining that the alarm condition is established, triggering the alarm and recording the abnormal information.

[0013] As a preferred scheme of the office system for digital security, wherein: the triggering of corresponding security measures according to the access control decision result comprises: When it is determined that the first risk level access request, the access interception mechanism is triggered, the current session is suspended and the emergency notification is sent, the real-time monitoring is started and the access data is encrypted to prevent data leakage and record the access log and operation behavior; When it is determined that the second risk level access request, the access permission is limited to the minimum permission, and the user information, the environment information, the network address and the user biological characteristics are continuously verified, the second risk level corresponding alarm is issued, the detailed information of the access request is recorded and archived, and additional audit is triggered; When it is determined that the third risk level access request, the user is allowed to continue to access and perform the regular access behavior monitoring, the access record is audited regularly, and the access report is generated, and the regular report is sent to the management personnel.

[0014] An office method for digital security, which is applied to an office system for digital security, comprising the following steps: Step S1: collecting login information, including user information, environment information, network address and user biological characteristics, and generating security perception data; Step S2: analyzing the state of the data and determining whether it is abnormal, if there is an abnormality, triggering an alarm and recording the login information corresponding to the abnormal data; Step S3: comparing the user information, the environment information, the network address and the user biological characteristics with the historical login information, and generating an access control decision according to the risk assessment result, and triggering corresponding security measures according to different access control decision results; Step S4: Constructing a virtual security sandbox and encrypting the target data in a cross-organizational collaboration scenario, generating a permission whitelist for the user account and a collaboration time limit, continuously verifying access requests based on the zero-trust principle in a non-cross-organizational scenario, and triggering interception operations; Step S5: Obtaining office scenario data and comparing it with security perception data and access control decision results, triggering an update mechanism when the standard is deviated, generating updated login information and access control policies, and destroying the sandbox and clearing data traces when the collaboration time limit ends; Step S6: Recording user operation behavior, permission change records, and security event logs, generating a hash sequence and storing it in a blockchain, triggering an alarm and recording abnormal information when there are abnormal records or signs of tampering.

[0015] The present application has the following advantages: The multi-factor identity verification of the perception module breaks through the limitations of single identity verification, effectively resists identity forgery attacks, and improves login security. The risk fusion evaluation of the decision module solves the fragmentation problem of risk assessment, accurately identifies complex security threats, and the execution module uses virtual security sandboxes and zero-trust verification for different office scenarios, balancing the data sharing efficiency and security protection of cross-organizational collaboration. The blockchain storage mechanism of the tracking module makes the operation log tamper-proof, ensuring that security events can be traced back. The continuous monitoring and dynamic updating of the closed-loop module form a security protection closed loop, avoiding lagging protection strategies. The overall solution realizes full-process security management in digital office scenarios, meets the needs of modern digital office for high security, high flexibility, and traceability, and provides strong technical support for enterprise digital office data security. BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 A basic flowchart of an office system for digital security is provided for an embodiment of the present application.

[0017] Figure 2 A step flowchart of an office method for digital security is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0018] To make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, not all embodiments.

[0019] Embodiment 1, refer to Figure 1 For an embodiment of the present application, an office system for digital security is provided, which includes a perception module, a decision module, an execution module, a closed-loop module, and a tracking module: The perception module is used for collecting login information and performing multi-factor identity verification, performing feature extraction and data analysis on the login information to generate security perception data, triggering an alarm mechanism if an anomaly is detected, and recording the abnormal data to the tracking module.

[0020] The perception module includes an identity verification unit and a data collection unit.

[0021] The identity verification unit deploys three types of verification methods, namely password authentication, biometric identification (including face, fingerprint, and iris feature recognition), and device fingerprint identification, to obtain first verification data (password-related data), second verification data (biometric matching data), and third verification data (device fingerprint data). Through multi-dimensional verification, the authenticity of the user's identity is ensured, and the problem of single verification method being easily cracked is avoided. For example, if password verification is solely relied upon, once the password is leaked, illegal login may occur. However, by adding biometric and device fingerprint verification, the security of identity verification can be significantly improved.

[0022] The data acquisition unit collects user information, environment information and network address, wherein the user information includes username, account ID, post function and department, the environment information includes device operating system version, terminal geographic location, network access mode (wired access, wireless access, VPN access), and the network address covers MAC address, port number and corresponding subnet mask. After collection, first security perception data, second security perception data and third security perception data are generated respectively. At the same time, the verification result deviation values of the first verification data, the second verification data and the third verification data and the historical login information reference data are calculated respectively, and the differentiated preset deviation threshold values are set for different types of data: wherein the terminal geographic location deviation threshold value is set to 50 kilometers (i.e. the straight-line distance between the current login geographic location and the historical commonly used geographic location exceeds 50 kilometers to determine the deviation out of limit), the network access mode deviation threshold value is set to "non-historical commonly used access mode type cumulative occurrence 2 times" (i.e. two times or single login using an access mode that has never appeared in the historical record is determined as deviation out of limit), the network address class data deviation threshold value such as MAC address and port number is set to "core parameter mismatch item ≥ 1 item" (i.e. the current network address and the historical reference data MAC address, subnet mask and other core parameters have 1 or more mismatches to determine the deviation out of limit), and the biological feature matching degree deviation threshold value is set to 90% (i.e. the matching degree of the current biological feature and the historical reference feature is less than 90% to determine the deviation out of limit). The verification result deviation values of various types are compared with the corresponding preset deviation threshold values respectively, and if any deviation value exceeds the threshold value, it is determined that the perception module is abnormal, the alarm is triggered, and the abnormal login information is recorded to the tracking module. Such design can comprehensively capture various information at the login link and timely discover abnormal conditions, for example, when the terminal geographic location suddenly changes from the commonly used "Beijing" to "Guangzhou" (the straight-line distance between the two places far exceeds the 50-kilometer threshold value), and the network access mode changes from the historically commonly used "wired access" to the unrecorded "VPN access" (triggering the access mode deviation threshold value), the system can detect such abnormality through the deviation value and prevent security risks in advance.

[0023] The decision module is used to compare the security perception data with the historical login information, analyze the user behavior mode, data access mode and network environment abnormality, divide the risk level, build the corresponding relationship between the comparison result and the risk level, generate the access control decision result, and trigger the corresponding security measures according to the result.

[0024] The decision module includes a comparison unit and a risk assessment unit. The comparison unit performs a first comparison between user information, environment information, network addresses, user biometric features, and historical login information, calculates matching rates in each dimension, and accumulates to generate an accumulated score. After normalization processing of the matching rates, high, medium, and low consistency is determined according to the accumulated score. For example, if the accumulated score is higher than 80 points, it is determined as high consistency, between 50 and 80 points as medium consistency, and lower than 50 points as low consistency. This multi-dimensional comparison can more accurately determine the difference between the current login and the historical normal login, and provide a basis for subsequent risk assessment.

[0025] The risk assessment unit analyzes user behavior patterns (login frequency, commonly used operation paths, commonly used file access types), data access patterns (access frequency, access data types, access duration), network environment abnormal conditions (abnormal traffic peak, malicious port scanning, illegal IP connection), and uses a cumulative scoring algorithm to calculate a first risk score, a second risk score, and a third risk score, respectively, to generate a first risk level, a second risk level, and a third risk level. The first comparison result, the first risk level, the second risk level, and the third risk level are normalized, the normalized scores are accumulated to obtain a fusion result, and if the fusion result shows that the risk level is higher than a preset threshold, an access control strategy adjustment mechanism is triggered, and a strategy adjustment log containing the adjustment time, content, and trigger condition is recorded. For example, when a user suddenly accesses core data unrelated to his / her job at a high frequency, and abnormal traffic peak occurs in the network environment, the risk assessment unit will calculate a high risk score, and then trigger the strategy adjustment to limit the user's access rights to prevent data leakage.

[0026] The execution module is used to encrypt and load target data requested by the user for access, generate a permission whitelist and a collaboration time limit for the user account based on the access control decision result, and take differentiated access control measures for different office scenarios.

[0027] The execution module includes a sandbox management unit and an access control unit.

[0028] The sandbox management unit builds a virtual secure sandbox in a cross-organization collaboration scenario (business collaboration of a user's organization and an external third-party organization such as a partner, a supplier, a customer, and a regulatory agency), loads target data such as business data, file data, communication data, and operation data into the virtual secure sandbox, sets a permission whitelist containing an access data path, an operation type, and a valid time range, and sets a collaboration time limit for the virtual secure sandbox and the permission whitelist. When the time limit expires, a destruction mechanism is automatically triggered. In a cross-organization collaboration scenario, data sharing is in high demand but also has high security risks. The virtual secure sandbox can isolate shared data from internal core data. For example, when sharing project progress data with a supplier, the supplier can only access the specified data in the sandbox and cannot access sensitive data such as financial and personnel data within the organization. Moreover, when the time limit expires, the data is automatically destroyed, further ensuring security.

[0029] The access control unit continuously verifies access requests based on the zero trust principle in a non-cross-organization scenario (a user performs business operations within the organization), generates first access request data containing a request time, a request account, and a request data identifier from the access request, and generates second comparison results from access control decision results. If the second comparison result is a rejection state, it is determined that the access request is an out-of-permission operation, an interception operation is triggered, and the interception data, the target data, and the permission whitelist are encrypted.

[0030] The tracking module is used to record all user operation behaviors, permission change records, and security event logs using a blockchain distributed ledger technology, generate a hash sequence, and ensure that operations are traceable and data is tamper-proof.

[0031] The tracking module includes a recording unit and a notarization unit.

[0032] The recording unit generates first record data from user operation behaviors (login and identity verification operations, data access behaviors, application and system operation behaviors, and collaboration behaviors), second record data from permission change records (user role adjustment, access permission addition or revocation, shared permission modification, data access range adjustment, and permission time limit change), and third record data from security event logs (access exception records, interception records, permission change records, and system alarm information). Comprehensive records can cover key operations and events in the office process and provide complete data for subsequent tracing.

[0033] The storage unit performs SHA-256 hash operation on the first record data (user operation behavior data), the second record data (permission change record data) and the third record data (security event log data), obtains the first hash value, the second hash value and the third hash value, sequentially connects the first hash value, the second hash value and the third hash value in time sequence, forms a hash sequence, and stores the obtained hash sequence in the block chain. At the same time, the record data is compared with the preset normal operation standard, wherein the preset normal operation standard is clearly defined for different record data types: for user operation behavior data, the preset normal operation standard is "login frequency ≤ 5 times / hour, single data access time ≤ 2 hours, and no cross-department core data access record"; for permission change record data, the preset normal operation standard is "single permission change involves only 1-2 operation permission adjustments, permission change requires confirmation of 2-level and above approvers, and permission time limit is set to ≤ 90 days"; for security event log data, the preset normal operation standard is "single-day access exception record ≤ 3 times, no repeated interception record within 30 minutes, and system alarm information triggering frequency ≤ 5 times per day", if the record data exceeds the range of any of the above preset normal operation standards, or the hash sequence is inconsistent with the historical hash sequence stored in the block chain (determined to have tampering signs), it is determined that the alarm condition is established, the audible and light alarms (alarm frequency 1 Hz, red warning light always on) are triggered, and the abnormal information (including abnormal data content, abnormal occurrence time and associated account) is recorded. The tamper-proof nature of the block chain ensures the authenticity of the record data, even if someone tries to modify the operation log, it will be discovered due to the mismatch of the hash value, for example, when someone tampers the user's permission change record and illegally modifies "only view data permission" to "modify + download data permission" (which exceeds the preset standard of "single permission change involves only 1-2 operation permission adjustments"), or directly tampers the stored permission change record data to cause the hash value to change, the storage unit can detect data anomalies and trigger alarms to prevent illegal operations in a timely manner.

[0034] The closed loop module is used for real-time monitoring of an office scene, extracting and analyzing office scene data to obtain office scene data, comparing the office scene data with security perception data, triggering an update mechanism through a comparison result, driving login information and security perception data to be updated, and destroying a sandbox, clearing data and operation traces after a collaboration time limit ends.

[0035] The closed loop module includes a monitoring unit and an update unit.

[0036] The monitoring unit obtains first, second and third office scene data corresponding to user behavior, data access and collaboration time limit respectively, and masters office scene dynamics in real time, such as whether a new abnormal pattern of user behavior appears, whether data access is within a reasonable range and whether the collaboration time limit is about to expire.

[0037] The updating unit performs data analysis and comparison calculation on the first office scene data, the second office scene data, and the third office scene data and the first security perception data, the second security perception data, the third security perception data, and the access control decision result, respectively matches the data with a preset standard to calculate a similarity or a difference value, and judges whether the data deviates from the standard. If the comparison result shows that the login information or the access control policy deviates from the preset standard, it is determined that the updating condition is established, the updating mechanism is triggered to generate the updated login information and the access control policy, and the updated login information and the access control policy are sent to the execution module; when the collaboration time limit ends, it is determined that the destruction condition is established, the sandbox is destroyed, and the data traces are cleared. For example, as the office scene changes, the user's common operation path may change, the updating unit can detect the change, update the historical reference data in the login information, make the subsequent risk assessment and policy adjustment more in line with the actual situation, and timely destroy the sandbox and the data traces after the collaboration time limit ends, to avoid the security risks caused by long-term data retention.

[0038] Embodiment 2, refer to Figure 2 The office method for digital security provided by the application comprises the following steps: Step S1: Collect login information including user information, environment information, network address, and user biological characteristics, extract features from the login information, and perform data analysis to generate security perception data; Step S2: Analyze the state of the first, second, and third verification data obtained by the identity verification unit, determine whether it is abnormal, and if there is an abnormality, trigger the alarm mechanism and record the login information corresponding to the abnormal data to the tracking module; Step S3: Compare the user information, environment information, network address, and user biological characteristics with the historical login information, combine the risk assessment results of the user behavior mode, data access mode, and network environment abnormality, generate an access control decision, and trigger corresponding security measures (intercept access, suspend session, and encrypt data at the first risk level, limit the minimum permission and continuously verify at the second risk level, and perform regular monitoring and periodic audit at the third risk level) according to different access control decision results; Step S4: In a cross-organization collaboration scenario, a virtual security sandbox is constructed, target data is encrypted and loaded, a permission whitelist of the user account is generated, and a collaboration time limit is generated; in a non-cross-organization scenario, continuously verify the access request based on the zero trust principle, and if the access request is a permission outside operation, trigger the interception operation; Step S5: Obtain office scene data, compare it with security perception data and access control decision results, and when the login information or the access control policy deviates from the preset standard, trigger the updating mechanism to generate the updated login information and the access control policy and send them to the execution module; when the collaboration time limit ends, destroy the sandbox, clear the data and operation traces; Step S6: record the user operation behavior, permission change record and security event log, hash the record data to generate a hash sequence stored in the blockchain, and when the record data is abnormal or there is tampering evidence, trigger an alarm and record the abnormal information.

[0039] The present application breaks through the limitation of single identity verification by multi-factor identity verification and multi-dimensional data collection of the perception module, effectively resists identity forgery attacks, the decision module fuses multi-dimensional risk assessment, solves the fragmentation problem of risk assessment, accurately identifies complex security threats, the execution module adopts differentiated protection measures for different scenarios, balances data sharing efficiency and security protection, the tracking module realizes operation traceability by using blockchain storage, ensures that security events can accurately locate the root cause, the closed loop module continuously monitors and dynamically updates, forms a security protection closed loop, and avoids lagging protection strategies. The overall scheme realizes the whole process security management of digital office scene, meets the needs of modern digital office for high security, high flexibility and traceability, and provides strong technical support for enterprise digital office data security.

[0040] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media containing computer usable program code. The storage medium can be realized by any type of volatile or non-volatile storage device or their combination, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. These computer program instructions can also be stored in a computer readable storage medium which can guide the computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer readable storage medium produce the product including instruction device, which realizes the flow Figure 1 one or more flows and / or blocks Figure 1 the function specified in one or more blocks.

[0041] It should be noted that the above examples are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalently replaced, without departing from the spirit and scope of the technical solutions of the present application, which should be covered in the scope of the claims of the present application.

Claims

1. A digital security oriented office system, characterized in that, The system comprises a perception module, a decision module and an execution module. The perception module is configured to collect login information, perform feature extraction and data analysis on the login information, and obtain security perception data. The decision module is configured to compare the security perception data with historical login information, obtain a comparison result, divide user behavior patterns, data access patterns and network environment abnormal conditions into risk levels, build a one-to-one correspondence between the comparison result and the risk levels, generate an access control decision result, trigger corresponding security measures according to the access control decision result, and the risk levels include a first risk level, a second risk level and a third risk level. The execution module is configured to encrypt and load target data requested by a user for access, and generate a permission whitelist and a collaboration time limit for a user account based on the access control decision result.

2. A digital security oriented office system as claimed in claim 1, characterized in that: The perception module comprises an identity verification unit and a data collection unit. The identity verification unit is configured to perform multi-factor identity verification on the login information, and the multi-factor identity verification comprises password authentication, biometric identification and device fingerprint identification, and first verification data, second verification data and third verification data are obtained respectively. The security perception data comprises user identity feature data, environment state data, network behavior data and biometric matching data. The data collection unit is configured to collect user information, environment information and network addresses, generate first security perception data, second security perception data and third security perception data from the collected information, obtain verification result deviation values of the first verification data, the second verification data and the third verification data, calculate deviation values of the first verification data, the second verification data and the third verification data from historical login information reference data respectively, compare the verification result deviation values with a preset deviation threshold, and when any verification result deviation value is greater than the preset deviation threshold, determine that the perception module is abnormal, trigger an alarm mechanism, and determine abnormal data corresponding to the login information and record it to a tracking module. The login information comprises user information, environment information, network addresses and user biometrics. The user information comprises a user name, an account ID, a job function and a department. The environment information comprises a device operating system version, a terminal geographic location and a network access method, and the network access method comprises wired access, wireless access and VPN access. The network address comprises a MAC address, a port number and a corresponding subnet mask. The user biometrics comprise facial features, fingerprint features and iris features.

3. A digitally secure office oriented system as claimed in claim 2, wherein: The system further comprises a tracking module configured to record all user operation behaviors, permission change records and security event logs using a blockchain distributed ledger technology, and generate a hash sequence. The user operation behaviors comprise user login and identity verification operations, data access behaviors, application and system operation behaviors and collaboration behaviors. The permission change records comprise user role adjustment, access permission addition or revocation, shared permission modification, data access range adjustment and permission time limit change. The security event logs comprise access anomaly records, interception records, permission change records and system alarm information. The trigger alarm mechanism judges the login information corresponding to the abnormal data and records to the tracking module, comprising: The verification state of the first verification data, the second verification data and the third verification data is analyzed, the verification state includes normal state and abnormal state, it is determined whether the first verification data, the second verification data and the third verification data are abnormal state, the abnormal state includes password verification failure, biological characteristics exception and device fingerprint mismatch, if the login information corresponding to any one of the first verification data, the second verification data or the third verification data is abnormal, the alarm mechanism is triggered, and the abnormal data is recorded to the tracking module.

4. A digitally secure office system as claimed in claim 3, characterized in that: The determination of whether the first verification data, the second verification data and the third verification data are abnormal state includes: Password verification exception: comparing the first verification data, the second verification data and the third verification data with the preset password verification standard respectively, recording the verification data that does not pass the preset standard, and determining the login information corresponding to the verification data that does not pass the verification standard as password verification exception; Biological characteristics exception: the similarity change of the first verification data, the second verification data and the third verification data at adjacent verification time nodes is calculated respectively to obtain the first similarity change, the second similarity change and the third similarity change, if the similarity change of any one of the verification data is lower than the preset similarity threshold, the login information corresponding to the verification data lower than the preset similarity threshold is determined as biological characteristics exception; Device fingerprint exception: the device fingerprint update record of the first verification data, the second verification data and the third verification data is obtained respectively, the update frequency of the first verification data, the second verification data and the third verification data within a preset time is counted according to the update record, the first update frequency, the second update frequency and the second update frequency are obtained, if the update frequency of any one of the verification data decreases to zero within a preset period and the fingerprint does not change, it is determined that the corresponding verification data is device fingerprint exception.

5. A digital security oriented office system as claimed in claim 1, characterized in that: The decision module includes a comparison unit and a risk assessment unit; The comparison unit is used for first comparison of user information, environment information, network address, user biological characteristics and historical login information, respectively calculating the matching rate, accumulating the matching rate to generate cumulative score, normalizing the matching rate, and generating a first comparison result through cumulative score calculation, the cumulative score is compared with the preset threshold after accumulating the matching rate, when the cumulative score is higher than the preset threshold, it is determined as high consistency, when the cumulative score is in the preset threshold interval, it is determined as medium consistency, and when the cumulative score is lower than the preset threshold, it is determined as low consistency; The risk assessment unit is used for analyzing user behavior mode, calculating the first risk score by using cumulative score algorithm, generating the first risk level, analyzing data access mode, calculating the second risk score by using cumulative score algorithm, generating the second risk level, analyzing network environment exception, calculating the third risk score by using cumulative score algorithm, and generating the third risk level; The user behavior mode includes login frequency, common operation path and common file access type; The data access mode includes access frequency, access data type and access time length; The network environment abnormal situation includes an abnormal traffic peak, a malicious port scan, and an illegal IP connection. The access control policy adjustment includes: normalizing the first comparison result with the first risk level, the second risk level, and the third risk level to obtain a normalized score, accumulating the normalized score to generate an accumulated score, comparing the accumulated score with a preset threshold to obtain a fusion result, determining that the access control policy adjustment condition is established when the fusion result shows that the risk level is higher than the preset threshold, triggering an access control policy adjustment mechanism, and recording a policy adjustment log, the policy adjustment log including an adjustment time, adjustment content, and a trigger condition.

6. A digitally secure office system as in claim 1, wherein: The execution module includes a sandbox management unit and an access control unit. The sandbox management unit is configured to build a virtual security sandbox in a cross-organization collaboration scenario, load and encrypt target data as first data, and set a first permission whitelist and a collaboration time limit. The cross-organization collaboration scenario refers to a data sharing and business collaboration scenario between a user's organization and an external third-party organization, where the external third-party organization includes partners, suppliers, customers, and regulatory agencies. The target data includes business data, file data, communication data, and operation data. The permission whitelist includes data paths to be accessed, operation types to be performed, and valid time ranges. The collaboration time limit refers to the duration for which the virtual security sandbox and the permission whitelist are valid, and after the preset period of time is reached, a destruction mechanism is automatically triggered. The access control unit is configured to continuously verify access requests based on the zero trust principle in a non-cross-organization scenario, generate first access request data from the access requests, and generate a second comparison result from the access control decision result. The first access request data includes request time, request account, and request data identifier. The non-cross-organization collaboration scenario refers to a data access and business operation scenario within a user's organization. The access control unit includes: analyzing the matching state of the second comparison result and the access control policy, the matching state including an allowed state and a denied state, determining whether the second comparison result is in the denied state, if the second comparison result is in the denied state, determining that the access request is an out-of-permission operation, triggering an interception operation, and encrypting the interception data, target data, and permission whitelist.

7. A digitally secure office system as in claim 1, wherein: The system further includes a closed-loop module configured to monitor an office scenario in real time, extract features and analyze data of the office scenario to obtain office scenario data, compare the office scenario data with security perception data to obtain a comparison result of the office scenario, trigger an update mechanism through the comparison result, drive updated login information and security perception data, and destroy the sandbox, clear data, and operation traces after the collaboration time limit ends. The feature extraction includes extracting user behavior features, data access features, collaboration features, and environment features, and the data analysis includes screening, counting, and processing collected login information. The office scenario data includes user behavior information, data access information, and collaboration time limit information. The closed-loop module includes a monitoring unit and an update unit. The monitoring unit is configured to obtain first office scene data, second office scene data and third office scene data corresponding to user behavior, data access and collaboration timeliness respectively; The updating unit is configured to obtain comparison results by performing data analysis and comparison calculation on the first office scene data, the second office scene data, the third office scene data, the first security perception data, the second security perception data, the third security perception data and the access control decision result; The data analysis is configured to perform matching calculation on the first office scene data, the second office scene data, the third office scene data, the first security perception data, the second security perception data, the third security perception data and a preset standard, calculate a similarity or a difference value, and determine whether the data deviates from the standard by comparison with the preset standard, to trigger a corresponding update mechanism; The trigger update mechanism includes: comparing the comparison results after the data analysis and comparison calculation with the preset standard, determining that the update condition is established when the login information or the access control strategy deviates from the preset standard, triggering the update mechanism to generate updated login information and access control strategy, and sending the updated login information and access control strategy to the execution module, and determining that the destruction condition is established when the collaboration timeliness ends, triggering the sandbox destruction and data trace cleaning.

8. A digitally secure office oriented system as claimed in claim 3, wherein: The tracking module includes a recording unit and a storage unit; The recording unit is configured to generate first record data from user operation behavior, generate second record data from permission change records, and generate third record data from security event logs; The user operation behavior includes user login and identity verification operation, data access behavior, application and system operation behavior and collaboration behavior; The permission change record includes user role adjustment, access permission addition or revocation, shared permission modification, data access range adjustment and permission time limit change; The security event log includes access exception record, interception record, permission change record and system alarm information; The storage unit is configured to perform hash operation on the first record data, the second record data and the third record data to obtain corresponding first hash value, second hash value and third hash value, sequentially connect the first hash value, the second hash value and the third hash value in time sequence to form a hash sequence, and store the obtained hash sequence in a blockchain; The alarm includes: comparing the first record data, the second record data and the third record data with a preset normal operation standard, determining that the alarm condition is established when the data is abnormal or there is tampering evidence, triggering the alarm and recording the abnormal information.

9. A digitally secure office system as in claim 1, wherein: Triggering corresponding security measures according to the access control decision result includes: When determining that the access request is of the first risk level, triggering the access interception mechanism, suspending the current session and sending an emergency notification, starting real-time monitoring and encrypting the access data to prevent data leakage and record access logs and operation behavior; When determining that the access request is of the second risk level, limiting the access permission to the minimum permission, continuously verifying user information, environment information, network address and user biological characteristics, issuing a second risk level corresponding alarm, recording and archiving detailed information of the access request, and triggering additional audit; When the third risk level access request is determined, the user is allowed to continue accessing and performing regular access behavior monitoring, access records are audited regularly, and access reports are generated and sent to management personnel on a regular basis.

10. A digital security oriented office method, applied in a digital security oriented office system according to any one of claims 1-9, characterized in that, The method comprises the following steps: Step S1: Collect login information, including user information, environment information, network address, and user biometric characteristics, and generate security perception data; Step S2: Analyze the state of the verification data, determine whether it is abnormal, and if there is an abnormality, trigger an alarm and record the login information corresponding to the abnormal data; Step S3: Compare the user information, environment information, network address, and user biometric characteristics with historical login information, and generate an access control decision based on the risk assessment results, and trigger corresponding security measures according to different access control decision results; Step S4: In the cross-organization collaboration scenario, a virtual security sandbox is constructed and the target data is encrypted and loaded, a permission whitelist of the user account and a collaboration time limit are generated, and in the non-cross-organization scenario, the access request is continuously verified based on the zero trust principle, and an interception operation is triggered; Step S5: Obtain office scene data and compare it with security perception data and access control decision results, trigger an update mechanism when it deviates from the standard, generate updated login information and access control policies, and destroy the sandbox and clear data traces when the collaboration time limit ends; Step S6: Record user operation behavior, permission change records, and security event logs, generate a hash sequence and store it in a blockchain, and when there is an abnormal record or tampering evidence, trigger an alarm and record the abnormal information.

Citation Information

Patent Citations

  • Enhanced identity authentication and resource access control system

    CN116633638A

  • Terminal zero-trust security capability system based on trusted environment perception

    CN119155116A

  • Cloud office access control system based on zero-trust architecture

    CN119854021A

Cited By

  • Access authority management and control system for security isolation

    CN121441654A

  • Data management system based on multi-service handling information security

    CN121690640A