Intelligent security method, equipment and medium

By using trusted computing verification and behavior monitoring, the problem of insufficient identity verification in intelligent security systems has been solved, achieving security protection for network equipment and locations, and ensuring the security and trustworthiness of the network.

CN120915529APending Publication Date: 2025-11-07CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511096864.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing intelligent security systems lack identity verification for personnel accessing the network or entering the premises, resulting in threats to the network's hardware and software, and insufficient security and trustworthiness.

Method used

Trusted computing is used to identify users entering the equipment area, monitor their behavior, combine identity and behavior to determine whether there are security threats, and record early warnings to protect the security and trustworthiness of the network.

Benefits of technology

It enables user authentication and behavior monitoring upon entering the equipment area, ensuring the security and trustworthiness of network hardware and software, preventing potential threats, and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915529A_ABST
    Figure CN120915529A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent security method and device and a medium, the method is applied to an intelligent security system, the intelligent security system is arranged in a device place, and the method comprises the following steps: obtaining identity information of a user entering the device place, or obtaining identity information of a user entering a network; determining the identity of the user according to the identity information of the user through trusted computing; monitoring behaviors of the user, and determining whether the intelligent security and protection system is subjected to security threats according to the behaviors and the identity of the user; if yes, early warning and recording are carried out, so that the security function is achieved. According to the method, the user entering the equipment place can be determined in combination with trusted computing, security processing is carried out on visitors, the security and credibility of software and hardware of a network are protected, and the network security is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and in particular to an intelligent security method, device and medium. Background Technology

[0002] Network security encompasses network equipment security, network information security, and network software security. It refers to the protection of the hardware, software, and data within a network system from accidental or malicious damage, alteration, or disclosure, ensuring continuous, reliable, and normal operation of the system and uninterrupted network services. It possesses the characteristics of confidentiality, integrity, availability, controllability, and auditability.

[0003] Intelligent security systems are installed in locations where critical network equipment, such as servers, is placed to protect network security. However, existing intelligent security systems lack identity verification for personnel accessing the network or entering the premises, which leads to threats to the network's hardware and software. The security and reliability during use cannot be guaranteed, and security measures for visitors cannot be implemented, making data easily lost. Summary of the Invention

[0004] This invention aims to at least solve one of the technical problems existing in the prior art. To this end, this invention proposes an intelligent security method that combines trusted computing to determine users entering a device location, performs security measures on visitors, protects the security and trustworthiness of network hardware and software, and safeguards network security.

[0005] The present invention also proposes devices and media having the above-mentioned intelligent security method.

[0006] According to a first aspect of the present invention, an intelligent security method is applied to an intelligent security system, the intelligent security system being installed in an equipment location, comprising:

[0007] Obtain the identity information of users entering the device location, or obtain the identity information of users entering the network;

[0008] The user's identity is determined using trusted computing based on the user's identity information;

[0009] Monitor the user's behavior and determine whether the intelligent security system is under security threat based on the user's behavior and identity;

[0010] If so, an alert will be issued and recorded to achieve the security function.

[0011] According to the intelligent security method, the identity information of a user entering a place where key network equipment is placed or accessing a network is acquired, the identity of the user is confirmed in combination with trusted computing, and the permission of the user who may damage the hardware equipment or the software network is determined; the behavior of the user is monitored in combination with the permission or the identity of the user, and it is determined whether the behavior of the user exceeds the permission corresponding to the identity; if yes, it is easy to understand that the security system is threatened by the user, and a warning record is made. The identity of the user entering the equipment place is determined in combination with trusted computing, the security of the visitor is processed, the security and the credibility of the hardware and the software of the network are protected, and the network security is protected.

[0012] According to some embodiments of the present application, the identity of the user is determined by the trusted computing according to the identity information of the user, and the identity of the user is determined by the trusted computing according to the identity information of the user.

[0013] The identity information of the user is sent to a trusted computing terminal; wherein the intelligent security system comprises the trusted computing terminal;

[0014] The trusted computing terminal determines whether there is a unique hardware identifier corresponding to the identity information of the user in the pre-stored user information; if yes, the identity of the user is determined to be a visitor or an employee according to the corresponding unique hardware identifier;

[0015] If no, the trusted computing terminal verifies according to the identity information of the user; if the verification is illegal user information, a warning is made; if the verification is legal user information, a corresponding unique hardware identifier is generated, and the identity information of the user and the corresponding unique hardware identifier are bound and stored.

[0016] According to some embodiments of the present application, the behavior of the user is monitored, and it is determined whether the intelligent security system is threatened according to the behavior, the identity of the user.

[0017] The behavior of the user in network transmission is monitored, and the transmission data of the user is obtained;

[0018] According to the transmission data of the user, it is respectively determined whether the sender of the transmission data is legal, and whether the transmission data is legal; if the sender of the transmission data or the transmission data is illegal, it is determined that the intelligent security system is threatened.

[0019] According to some embodiments of the present application, whether the sender of the transmission data is legal is determined according to the transmission data of the user.

[0020] According to the transmission data of the user, a hash value corresponding to the transmission data is obtained;

[0021] sending the hash value corresponding to the transmission data to the trusted computing terminal, and determining whether the hash value corresponding to the transmission data is consistent with the hash value corresponding to the identity of the user by the trusted computing terminal; if not, determining that the sender of the transmission data is illegal.

[0022] According to some embodiments of the present application, the determining whether the transmission data of the user is legal comprises:

[0023] extracting data features of the transmission data, and determining a security level of the transmission data; wherein the security level comprises a public level, an internal level, and a confidential level;

[0024] determining a risk level of the transmission data according to the security level of the transmission data, a transmission rule of the transmission data, and the identity of the user, and specifically comprising:

[0025] when the identity of the user is a visitor, and the security level of the transmission data is the internal level or the confidential level, determining that the transmission data of the user is high risk;

[0026] when the identity of the user is a visitor or an employee, and the security level of the transmission data is the public level, determining that the transmission data of the user is low risk;

[0027] when the identity of the user is an employee, and the security level of the transmission data is the internal level, and the transmission rule does not conform to the transmission rule corresponding to the internal level, determining that the transmission data of the user is medium risk;

[0028] when the identity of the user is an employee, and the security level of the transmission data is the confidential level, and the transmission rule does not conform to the transmission rule corresponding to the confidential level, determining that the transmission data of the user is high risk; wherein the risk level comprises low risk, medium risk, and high risk.

[0029] if it is determined that the transmission data of the user is medium risk or high risk, determining that the transmission data is illegal.

[0030] According to some embodiments of the present application, the recording comprises:

[0031] comparing the data features of the transmission data with a pre-stored known threat feature library, and marking threats in the transmission data;

[0032] combining the threats in the transmission data, the identity of the user, and constructing a threat data flow direction chain, so as to issue a warning to a flow direction subject of the transmission data.

[0033] According to some embodiments of the present application, further comprising:

[0034] Adjusting a transmission rule of the transmission data, specifically comprising:

[0035] Receiving a new data transmission strategy;

[0036] Mapping the new data transmission strategy to an XACML policy language rule template to obtain a regularized transmission rule;

[0037] Verifying the regularized transmission rule to determine whether the regularized transmission rule conflicts with the original transmission rule and whether the defense of the regularized transmission rule is effective, and if there is no conflict and the defense is effective, updating the transmission rule of the transmission data to the regularized transmission rule.

[0038] According to some embodiments of the present application, the monitoring the behavior of the user, determining whether the intelligent security system is threatened according to the behavior and identity of the user comprises:

[0039] Monitoring the environment of the device site, specifically comprising monitoring the humidity, temperature, gas in the site, and ground water immersion height of the device site; and monitoring the action behavior of the user in the device site through a camera arranged in the device site;

[0040] If any index of the humidity, temperature, gas in the site, and ground water immersion height of the device site exceeds the corresponding index threshold, it is determined that the intelligent security system is threatened;

[0041] According to the action behavior of the user in the device site, it is determined whether the user has dangerous behavior, and if so, it is determined that the intelligent security system is threatened.

[0042] An electronic device according to the second aspect of the embodiments of the present application comprises:

[0043] A memory for storing a program;

[0044] A processor for executing the program stored in the memory, and when the processor executes the program stored in the memory, the processor is configured to execute the method according to any one of the first aspect.

[0045] A storage medium according to the third aspect of the embodiments of the present application, storing computer executable instructions for executing the method according to any one of the first aspect.

[0046] Other features and advantages of the present application will be further described in the following description, and will become apparent from the description, or will be learned through practice of the present application. The objects and other advantages of the present application will be realized and achieved by the structure particularly pointed out in the specification, claims, and drawings. Attached Figure Description

[0047] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.

[0048] Figure 1 This is a flowchart of an intelligent security method provided in an embodiment of the present invention;

[0049] Figure 2 This is a structural block diagram of an intelligent security device provided in an embodiment of the present invention;

[0050] Figure 3 This is a structural block diagram of an intelligent security device provided in an embodiment of the present invention;

[0051] Figure 4 This is a structural block diagram of an intelligent security device provided in an embodiment of the present invention;

[0052] Figure 5 This is a structural block diagram of an intelligent security device provided in an embodiment of the present invention;

[0053] Figure 6 This is a structural block diagram of an intelligent security device provided in an embodiment of the present invention. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0055] It should be understood that in the description of the embodiments of the present invention, "multiple" (or "amounts") means two or more, "greater than," "less than," and "exceeding" are understood to exclude the stated number, while "above," "below," and "within" are understood to include the stated number. If "first," "second," etc., are used in the description, they are only for the purpose of distinguishing technical features and should not be construed as indicating or implying relative importance, or implicitly indicating the number of indicated technical features, or implicitly indicating the order of the indicated technical features.

[0056] like Figure 1 As shown, this embodiment of the invention provides an intelligent security method applied to an intelligent security system. The intelligent security system is installed at the equipment location and includes:

[0057] Step S100: Obtain the identity information of the user who enters the device location, or obtain the identity information of the user who enters the network;

[0058] Step S200, determining the identity of the user according to the identity information of the user through trusted computing;

[0059] Step S300, monitoring the behavior of the user, and determining whether the intelligent security system is threatened according to the behavior and identity of the user;

[0060] If yes, step S400 is executed;

[0061] Step S400, prewarning and recording are performed to realize the security function;

[0062] If no, step S100 is continuously executed.

[0063] For the place where the key network equipment is placed, the identity information of the user entering the place or accessing the network is acquired, the identity of the user is confirmed through trusted computing, the permission of the user who may damage the hardware equipment or the software network is determined, the behavior of the user is monitored in combination with the permission or the identity, and it is determined whether the behavior of the user exceeds the permission corresponding to the identity, if yes, it is easy to understand that the security system is threatened by the user, prewarning and recording are performed. The present application determines the user entering the equipment place in combination with trusted computing, performs security processing on the visiting personnel, and protects the security and credibility of the hardware and software of the network, and protects the network security.

[0064] In an embodiment, in step S200, the identity of the user is determined according to the identity information of the user through trusted computing, which includes:

[0065] The identity information of the user is sent to a trusted computing terminal; wherein the intelligent security system includes the trusted computing terminal;

[0066] The trusted computing terminal determines whether there is a unique hardware identifier corresponding to the identity information of the user in the pre-stored user information, if yes, the identity of the user is determined to be a visitor or an employee according to the corresponding unique hardware identifier;

[0067] If no, the trusted computing terminal verifies according to the identity information of the user, if the verification is illegal user information, prewarning is performed, if the verification is legal user information, the trusted computing terminal generates the corresponding unique hardware identifier, and binds and stores the identity information of the user and the corresponding unique hardware identifier.

[0068] It should be noted that the unique hardware identifier generated by the trusted computing terminal is tamper-proof; the trusted computing terminal is a computing terminal that has passed trusted verification, and it is believed that the unique hardware identifier generated by the computing terminal is accurate.

[0069] In an embodiment, in step S300, the behavior of the user is monitored, and whether the intelligent security system is threatened is determined according to the behavior and identity of the user, which includes:

[0070] monitoring a behavior of a user for network transmission, obtaining transmission data of the user;

[0071] determining whether a sender of the transmission data or the transmission data is illegal according to the transmission data of the user, and determining that the intelligent security system is under security threat if the sender of the transmission data or the transmission data is illegal.

[0072] In an embodiment, determining whether the sender of the transmission data is legal according to the transmission data of the user comprises:

[0073] obtaining a hash value corresponding to the transmission data according to the transmission data of the user;

[0074] sending the hash value corresponding to the transmission data to a trusted computing terminal, and determining whether the hash value corresponding to the transmission data is consistent with a hash value corresponding to the identity of the user by the trusted computing terminal, and determining that the sender of the transmission data is illegal if not.

[0075] In an embodiment, determining whether the transmission data is legal according to the transmission data of the user comprises:

[0076] extracting a data feature of the transmission data, and determining a security level of the transmission data; wherein the security level comprises a public level, an internal level, and a confidential level; and the extracting the data feature of the transmission data specifically comprises extracting a keyword of the transmission data, and the keyword is, for example, a password or financial data;

[0077] determining a risk level of the transmission data according to the security level of the transmission data, a transmission rule of the transmission data, and the identity of the user, and the determining the risk level of the transmission data specifically comprises:

[0078] determining that the transmission data of the user is high risk when the identity of the user is a visitor, and the security level of the transmission data is the internal level or the confidential level;

[0079] determining that the transmission data of the user is low risk when the identity of the user is a visitor or an employee, and the security level of the transmission data is the public level;

[0080] determining that the transmission data of the user is medium risk when the identity of the user is an employee, the security level of the transmission data is the internal level, and the transmission rule does not conform to a transmission rule corresponding to the internal level;

[0081] determining that the transmission data of the user is high risk when the identity of the user is an employee, the security level of the transmission data is the confidential level, and the transmission rule does not conform to a transmission rule corresponding to the confidential level; wherein the risk level comprises low risk, medium risk, and high risk.

[0082] determining that the transmission data is illegal if the transmission data of the user is determined to be medium risk or high risk.

[0083] In an embodiment, in step S400, the recording comprises:

[0084] comparing the data features of the transmission data with the pre-stored known threat feature library, marking the threats in the transmission data;

[0085] combining the threats in the transmission data, the identity of the user, constructing a threat data flow chain, and issuing a warning to the subject of the flow of the transmission data.

[0086] It is easy to understand that the threat data flow chain is represented as threats in the transmission data→the identity of the user→the unique hardware identifier→the operation log; in an embodiment, the unique hardware identifier includes the fingerprint corresponding to the user and the face corresponding to the user.

[0087] In an embodiment, it further comprises:

[0088] adjusting the transmission rules of the transmission data regularly, so as to update the adjustment of determining whether the system is threatened; adjusting the transmission rules of the transmission data specifically comprises:

[0089] receiving a new data transmission strategy;

[0090] mapping the new data transmission strategy to the XACML policy language rule template to obtain a regularized transmission rule;

[0091] verifying the regularized transmission rule, determining whether the regularized transmission rule conflicts with the original transmission rule, and determining whether the defense of the regularized transmission rule is effective, if there is no conflict and effective, updating the transmission rules of the transmission data to the regularized transmission rule. The automatic updating of the transmission rule facilitates the subsequent improvement of the speed and efficiency of the user verification, and can analyze and locate the processed information data.

[0092] In an embodiment, verifying the regularized transmission rule, determining whether the regularized transmission rule conflicts with the original transmission rule, and determining whether the defense of the regularized transmission rule is effective specifically comprises:

[0093] firstly determining whether the port rule in the regularized transmission rule conflicts with the port rule in the original transmission rule in a sandbox environment, and then performing penetration testing to determine the defense of the regularized transmission rule.

[0094] In an embodiment, in step S300, monitoring the behavior of the user, and determining whether the intelligent security system is threatened according to the behavior and identity of the user comprises:

[0095] The environment of the equipment site is monitored, specifically including monitoring the humidity, temperature, gas in the site, and ground water immersion height of the equipment site; the action behavior of the user in the equipment site is monitored through the camera arranged in the equipment site;

[0096] If any index of the humidity, temperature, gas in the site, and ground water immersion height of the equipment site exceeds the corresponding index threshold value, it is determined that the intelligent security system is threatened;

[0097] According to the action behavior of the user in the equipment site, it is determined whether the user has dangerous behavior, if so, it is determined that the intelligent security system is threatened; wherein the dangerous behavior includes: entering the designated dangerous area, abnormal behavior such as fighting and brawling that disturbs public order.

[0098] In an embodiment, according to the action behavior of the user in the equipment site, it is determined whether the user has dangerous behavior, including:

[0099] The face of the user is recognized frame by frame through the monitoring video in the equipment site, and the face of the user is tracked;

[0100] The pose of the user is recognized by joint tracking of several video frames of the user, it is determined whether the user has abnormal behavior that disturbs public order, or the position where the user is located is recognized by recognizing the video frame of the user, if any video frame recognizes that the user enters the designated dangerous area, it is determined that the intelligent security system is threatened.

[0101] As shown in Figure 2 The embodiment of the present application also provides an intelligent security device, which comprises:

[0102] A main control unit is used for executing the above-mentioned intelligent security method, which comprises: an identity verification unit, an information risk control unit, the output ends of the identity verification unit and the information risk control unit are electrically connected with a data monitoring module, the input end of the data monitoring module is electrically connected with the output ends of an intelligent monitoring unit and a data limiting unit, the output end of the data monitoring module is electrically connected with the input ends of a warning module and an alarm module, the identity verification unit is used for verifying the identity of the user accessing the network, the information risk control unit is used for controlling the risk of the information received by the network, the intelligent monitoring unit is used for monitoring the environment of the network equipment site, the data monitoring module is used for monitoring the overall data accessing the network, the data limiting unit is used for setting and limiting the overall data, the warning module is used for warning the data close to the limiting range, and the alarm module is used for warning the data exceeding the limiting range;

[0103] The intelligent gateway comprises an Ethernet interface, an ARM processor, a coordinator and a communication module, an input end of a trusted computing terminal is electrically connected to an output end of the intelligent gateway, an output end and an input end of a network port are electrically connected to an output end and an input end of the trusted computing terminal, a server comprises a CPU and a network security chip, an output end of the network security chip is electrically connected to an input end of a password protection module, an input end of a power supply monitoring module is electrically connected to an output end of the server and the network port, the power supply monitoring module is used for monitoring the power supply condition of the whole network equipment, and the password protection module is used for protecting the password of the server, so that the security is improved.

[0104] As shown in Figure 3 In an embodiment, the identity authentication unit comprises an identity information import module, an output end of the identity information import module is electrically connected to an input end of an analysis and acquisition module, an output end of the analysis and acquisition module is electrically connected to an input end of an identity confirmation module, an output end of the identity confirmation module is electrically connected to an input end of an interface configuration module, an output end of the interface configuration module is electrically connected to input ends of the interface configuration module and a state monitoring module, the identity information import module is used for inputting the identity information of a user who can enter the network, the analysis and acquisition module is used for subsequent analysis and acquisition of the identity information of the user after login, the identity confirmation module is used for confirming the identity of the user through the analysis and acquisition module, the identity confirmation comprises a visitor and an employee, the interface configuration module configures a visitor interface and an employee interface based on the identity confirmation, the state monitoring module is used for monitoring the operation state of the user in the current network, and the operation record module is used for recording the operation of the user in the network.

[0105] As shown in Figure 4 In an embodiment, the information risk management and control unit comprises a constraint condition binding module, an output end of the constraint condition binding module is electrically connected to an input end of an information feature extraction module, an output end of the information feature extraction module is electrically connected to an input end of an information screening module, an output end of the information screening module is electrically connected to an input end of an interactive information updating module, an output end of the interactive information updating module is electrically connected to an input end of a network verification module, an output end of the network verification module is electrically connected to input ends of a network protection analysis module and a threat information distribution module, the constraint condition binding module is used for binding the input security information as a constraint condition, the information feature extraction module extracts the features of the information based on the information bound by the constraint condition binding module, the information screening module screens different information after the extraction, the interactive information updating module updates the constraint condition binding module based on the information screened by the information screening module, the network verification module performs a security verification process on the information based on the network, and the network protection analysis module and the threat information distribution module are used for analyzing the network and distributing the threat information in the verified information.

[0106] As shown in Figure 5 In an embodiment, the intelligent monitoring unit includes a cloud storage unit, the output end of the cloud storage unit is electrically connected with the input end of the sensor unit and the video monitoring unit, the output end of the video monitoring unit is electrically connected with the input end of the face recognition module, the sensor unit detects the temperature and humidity, flame radiation, smoke content and flammable gas content of the current environment based on the temperature and humidity sensor, flame sensor, flammable gas sensor, smoke sensor and water immersion sensor, for safety monitoring of the current environment, the video monitoring unit monitors the audio and video situation of the current environment based on the monitor, the face recognition module identifies the identity information of the user entering the environment based on the video monitoring unit, and the cloud storage unit is used for storing the data monitored by the sensor unit and the video monitoring unit.

[0107] As shown in Figure 6 In an embodiment, the data limiting unit includes a monitoring data setting module and an access permission setting module, the monitoring data setting module includes a face information input module, a temperature and humidity threshold setting module, a flame radiation threshold setting module, a smoke threshold setting module and a flammable gas threshold setting module, the output end of the monitoring data setting module is electrically connected with the input end of the standard range setting module, the face information input module is used for inputting the face information of the employee, the temperature and humidity threshold setting module is used for setting the temperature and humidity threshold of the environment, the smoke threshold setting module is used for setting the threshold of the flame radiation intensity, the smoke threshold setting module is used for setting the threshold of the smoke content, and the flammable gas threshold setting module is used for setting the threshold of the flammable gas concentration, the standard range setting module sets the standard range based on the above threshold, and the access permission setting module divides the access permission into visitors and employees.

[0108] The embodiment of the present application also provides an electronic device, which includes but is not limited to:

[0109] a memory for storing a program;

[0110] a processor for executing the program stored in the memory, when the processor executes the program stored in the memory, the processor is used for executing the above-mentioned intelligent security method.

[0111] The processor and the memory can be connected through a bus or other means.

[0112] The memory as a kind of non-transient computer readable storage medium can be used to store non-transient software programs and non-transient computer executable programs, such as the method described in the embodiment of the present application. The processor realizes the above-mentioned method by running the non-transient software program and instruction stored in the memory.

[0113] The memory can include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by the at least one function; and the data storage area can store the execution of the above method. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory disposed remotely relative to the processor, which can be connected to the processor through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0114] The non-transitory software programs and instructions required to implement the above terminal selection method are stored in the memory, and when executed by one or more processors, the above method is executed.

[0115] The embodiments of the present application also provide a storage medium storing computer executable instructions for executing the above method.

[0116] In an embodiment, the storage medium stores computer executable instructions, which are executed by one or more control processors.

[0117] The above described embodiments are merely illustrative, wherein the units described as separate components can or can not be physically separate, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment.

[0118] As will be appreciated by one of ordinary skill in the art, all or some steps, systems of the above-disclosed methods can be implemented as software, firmware, hardware, or any suitable combination thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application- specific integrated circuit. Such software can be distributed on computer readable media, which can comprise computer storage media (or non-transitory media), and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes both volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media include, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. Further, as is well known to those of ordinary skill in the art, communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal, such as carrier waves or other transport mechanisms, and includes any information delivery media.

[0119] Embodiments of the present application are described herein with reference to the drawings, which are as follows: Embodiments of the present application are described herein with reference to the accompanying drawings, which are as follows: FIG. 1 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 2 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 3 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 4 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 5 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 6 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 7 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 8 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 9 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 10 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 11 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 12 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 13 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 14 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 15 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 16 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 17 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 18 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 19 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 20 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 21 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 22 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 23 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 24 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 25 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 26 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 27 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 28 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 29 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 30 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 31 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 32 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 33 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 34 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 35 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 36 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 37 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 38 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 39 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 40 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 41 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 42 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 43 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 44 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 45 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 46 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 47 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 48 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 49 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 50 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 51 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 52 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 53 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 54 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 55 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 56 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 57 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of the present application. FIG. 58 is a schematic diagram of a system for providing a user with a virtual environment in accordance with an embodiment of

Claims

1. A smart security method applied to a smart security system, the smart security system being arranged at a device site, characterized in that, The method comprises: acquiring identity information of a user entering a device site or a network; determining the identity of the user according to the identity information of the user through trusted computing; monitoring the behavior of the user, and determining whether the smart security system is threatened according to the behavior and identity of the user; if so, giving a warning and recording to realize the security function.

2. The intelligent security method of claim 1, wherein, The method of determining the identity of the user according to the identity information of the user through trusted computing comprises: sending the identity information of the user to a trusted computing terminal; wherein the smart security system comprises the trusted computing terminal; the trusted computing terminal determines whether there is a unique hardware identifier corresponding to the identity information of the user in the pre-stored user information, and if so, determines the identity of the user to be a visitor or an employee according to the corresponding unique hardware identifier; if not, the trusted computing terminal verifies the identity information of the user, and if the verification is illegal user information, gives a warning; if the verification is legal user information, generates a corresponding unique hardware identifier, and binds and stores the identity information of the user and the corresponding unique hardware identifier.

3. The intelligent security method of claim 2, wherein, The method of monitoring the behavior of the user, and determining whether the smart security system is threatened according to the behavior and identity of the user comprises: monitoring the behavior of the user in network transmission to obtain transmission data of the user; determining whether the sender of the transmission data is legal and whether the transmission data is legal according to the transmission data of the user, and if the sender of the transmission data or the transmission data is illegal, determining that the smart security system is threatened.

4. The intelligent security method of claim 3, wherein, The method of determining whether the sender of the transmission data is legal according to the transmission data of the user comprises: obtaining a hash value corresponding to the transmission data according to the transmission data of the user; sending the hash value corresponding to the transmission data to the trusted computing terminal, and the trusted computing terminal determines whether the hash value corresponding to the transmission data is consistent with the hash value corresponding to the identity of the user; if not, determining that the sender of the transmission data is illegal.

5. The intelligent security method of claim 3, wherein, The method of determining whether the transmission data is legal according to the transmission data of the user comprises: extracting data features of the transmission data to determine the security level of the transmission data; wherein the security level comprises public level, internal level and confidential level; determining the risk level of the transmission data according to the security level of the transmission data, the transmission rule of the transmission data and the identity of the user, specifically comprising: when the identity of the user is a visitor and the security level of the transmission data is internal level or confidential level, determining that the transmission data of the user is high risk; when the identity of the user is a visitor or an employee and the security level of the transmission data is public level, determining that the transmission data of the user is low risk; when the identity of the user is an employee and the security level of the transmission data is internal level, and the transmission rule does not conform to the transmission rule corresponding to the internal level, determining that the transmission data of the user is medium risk; When the user's identity is an employee, the security level of the transmission data is confidential, and the transmission rule does not conform to the transmission rule corresponding to the confidential level, it is determined that the transmission data of the user is high risk; wherein the risk level includes: low risk, medium risk, high risk; If it is determined that the transmission data of the user is medium risk or high risk, it is determined that the transmission data is illegal.

6. The intelligent security method of claim 5, wherein, The recording includes: Comparing the data characteristics of the transmission data with the pre-stored known threat feature library, and marking the threats in the transmission data; Combine the threats in the transmission data, the identity of the user, and construct a threat data flow chain to issue a warning to the flow subject of the transmission data.

7. The intelligent security method of claim 1, wherein, Also includes: Adjusting the transmission rule of the transmission data, specifically including: Receiving a new data transmission strategy; Map the new data transmission strategy to the XACML policy language rule template to get the regularized transmission rule; Verify the regularized transmission rule to determine whether the regularized transmission rule conflicts with the original transmission rule, and determine whether the defense of the regularized transmission rule is effective, if there is no conflict and effective, update the transmission rule of the transmission data to the regularized transmission rule.

8. The intelligent security method of claim 2, wherein, The monitoring of the behavior of the user, according to the behavior and identity of the user, to determine whether the intelligent security system is threatened includes: Monitoring the environment of the device site, specifically including monitoring the humidity, temperature, gas in the site, and ground water immersion height of the device site; monitoring the action behavior of the user in the device site through the camera arranged in the device site; If any of the humidity, temperature, gas in the site, and ground water immersion height of the device site exceeds the corresponding index threshold, it is determined that the intelligent security system is threatened; According to the action behavior of the user in the device site, it is determined whether the user has dangerous behavior, if so, it is determined that the intelligent security system is threatened.

9. An electronic device, comprising: Including: Memory for storing programs; The processor is configured to execute the program stored in the memory, and when the processor executes the program stored in the memory, the processor is configured to execute the method of any one of claims 1-8.

10. A storage medium, characterized by Computer executable instructions are stored, and the computer executable instructions are used to execute the method of any one of claims 1-8.