Data analysis method and device, computer equipment and storage medium

By collecting the number of fingerprint verification failures and the bit error rate of quantum IoT devices, and using quantum computing strategies to analyze attack threats and channel vulnerabilities, efficient and accurate attack identification is achieved, solving the problem of low efficiency and accuracy in attack identification of IoT devices.

CN120979701APending Publication Date: 2025-11-18CHINA PING AN LIFE INSURANCE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511045232.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing methods for identifying attacks on IoT devices suffer from low efficiency and insufficient accuracy, making it difficult to respond quickly to complex network attacks and accurately identify attack behaviors.

Method used

By collecting the number of fingerprint verification failures and the bit error rate of quantum technology-based IoT devices, and using preset attack threat coefficient and channel vulnerability coefficient calculation strategies, combined with cracking probability calculation, millisecond-level attack identification is achieved and accurate attack identification results are generated.

Benefits of technology

It improves the efficiency and accuracy of attack identification for IoT devices, enabling fast and accurate attack identification and ensuring the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979701A_ABST
    Figure CN120979701A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of artificial intelligence, and relates to a data analysis method, which comprises the steps of collecting parameter data of target equipment; wherein the parameter data comprises the number of fingerprint verification failures and the error rate; calculating the number of fingerprint verification failures to obtain an attack threat coefficient; calculating the bit error rate to obtain a channel fragility coefficient; calculating the attack threat coefficient and the channel vulnerability coefficient based on a cracking probability calculation strategy to obtain a cracking probability; obtaining a probability threshold value and a time threshold value; carrying out attack identification processing on the cracking probability based on a probability threshold value and a time threshold value to generate an attack identification result; and carrying out output processing on the attack identification result. The invention further provides a data analysis device, computer equipment and a storage medium. In addition, the invention also relates to a block chain technology, and the attack recognition result can be stored in a block chain. The equipment attack identification method and device can be applied to equipment attack identification scenes in the field of financial science and technology, and the identification efficiency and the identification accuracy of equipment attack identification are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology and can be applied to the financial technology field, particularly to data analysis methods, devices, computer equipment and storage media. Background Technology

[0002] With the deep integration of IoT technology into the insurance industry, the construction of an IoT insurance risk control system has become a crucial link in ensuring the security and stable operation of the business. However, existing IoT insurance risk control systems have significant shortcomings, among which the methods for identifying attacks on IoT devices are a prominent issue. Currently, most IoT device attack identification relies mainly on traditional rule matching or simple feature extraction methods. These methods are inadequate in the face of increasingly complex and varied cyberattacks. On the one hand, the identification efficiency is low, making it difficult to respond quickly to real-time attacks, which can lead to attacks lasting for a long time and causing serious damage to the IoT insurance system. On the other hand, the accuracy is poor, easily misjudging normal device behavior as attack behavior or missing actual attack behavior, thereby affecting the normal operation of insurance business and the accuracy of risk assessment.

[0003] Similar problems exist in the financial sector. Taking bank self-service terminals as an example, some banks' attack detection systems, when facing new types of cyberattacks, suffer from low accuracy due to limitations in their algorithms and insufficient precision in extracting attack characteristics. For instance, hackers have used covert malware to launch data theft attacks on self-service terminals, and existing detection systems failed to identify these attacks promptly and accurately, leading to the leakage of large amounts of customer information and causing significant losses to banks and customers. Therefore, improving the efficiency and accuracy of attack detection for IoT devices has become a crucial issue that urgently needs to be addressed in current IoT insurance risk control systems. Summary of the Invention

[0004] The purpose of this application is to provide a data analysis method, apparatus, computer equipment, and storage medium to solve the technical problems of low identification efficiency and low identification accuracy in existing attack identification methods for Internet of Things devices.

[0005] Firstly, a data analysis method is provided, including:

[0006] Collect parameter data corresponding to the target device; wherein, the target device is an Internet of Things (IoT) device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate;

[0007] The number of fingerprint verification failures is calculated based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient.

[0008] The bit error rate is calculated based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient.

[0009] The attack threat coefficient and the channel vulnerability coefficient are calculated based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability.

[0010] Obtain the preset probability threshold and time threshold;

[0011] Based on the probability threshold and the time threshold, the attack identification process is performed on the cracking probability to generate the corresponding attack identification result;

[0012] The attack identification results are then processed for output.

[0013] Secondly, a data analysis device is provided, comprising:

[0014] The acquisition module is used to acquire parameter data corresponding to the target device; wherein, the target device is an Internet of Things (IoT) device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate;

[0015] The first calculation module is used to calculate the number of fingerprint verification failures based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient.

[0016] The second calculation module is used to calculate the bit error rate based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient.

[0017] The third calculation module is used to calculate the attack threat coefficient and the channel vulnerability coefficient based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability.

[0018] The acquisition module is used to acquire preset probability thresholds and time thresholds;

[0019] The identification module is used to perform attack identification processing on the cracking probability based on the probability threshold and the time threshold, and generate the corresponding attack identification result;

[0020] The output module is used to process the attack identification results.

[0021] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described data analysis method.

[0022] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the above-described data analysis method.

[0023] In the above-described data analysis method, apparatus, computer equipment, and storage medium, parameter data corresponding to the target device is first collected; wherein, the target device is an IoT device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate; then, the number of fingerprint verification failures is calculated based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient; subsequently, the bit error rate is calculated based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient; subsequently, the attack threat coefficient and the channel vulnerability coefficient are calculated based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability; further, preset probability thresholds and time thresholds are obtained; and attack identification processing is performed on the cracking probability based on the probability thresholds and the time thresholds to generate the corresponding attack identification result; finally, the attack identification result is output. Based on the above automated processing flow, this application collects the number of fingerprint verification failures and the bit error rate of the target device. Then, it calculates the attack threat coefficient based on the number of fingerprint verification failures using an attack threat coefficient calculation strategy, and calculates the channel vulnerability coefficient based on the bit error rate using a channel vulnerability coefficient calculation strategy. Subsequently, it calculates the cracking probability based on the attack threat coefficient and the channel vulnerability coefficient using a cracking probability calculation strategy. The cracking probability is then dynamically calculated by combining quantum parameters and device behavior. Finally, the cracking probability is processed for attack identification based on a combination of probability threshold and time threshold, so as to achieve millisecond-level attack identification and automatically and accurately generate the corresponding attack identification results. This effectively improves the identification efficiency and accuracy of attack identification and ensures the accuracy of the generated attack identification results. Attached Figure Description

[0024] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is an exemplary system architecture diagram to which this application can be applied;

[0026] Figure 2 This is a flowchart of an embodiment of the data analysis method according to this application;

[0027] Figure 3This is a schematic diagram of the structure of one embodiment of the data analysis apparatus according to this application;

[0028] Figure 4 This is a schematic diagram of the structure of one embodiment of the computer device according to this application. Detailed Implementation

[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings of this application, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings of this application are used to distinguish different objects, not to describe a particular order.

[0030] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0031] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0032] like Figure 1 As shown, system architecture 100 may include terminal device 101, network 102, and server 103. Terminal device 101 may be a laptop 1011, tablet 1012, or mobile phone 1013. Network 102 is used as a medium to provide a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0033] Users can use terminal device 101 to interact with server 103 via network 102 to receive or send messages, etc. Various communication client applications can be installed on terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social media platform software, etc.

[0034] Terminal device 101 can be various electronic devices with a display screen and support web browsing. In addition to laptops 1011, tablets 1012, or mobile phones 1013, terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer, and a desktop computer, etc.

[0035] Server 103 can be a server that provides various services, such as a backend server that provides support for the pages displayed on terminal device 101.

[0036] It should be noted that the data analysis method provided in the embodiments of this application is generally executed by a server / terminal device, and correspondingly, the data analysis device is generally located in the server / terminal device.

[0037] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0038] Continue to refer to Figure 2 A flowchart illustrating an embodiment of the data analysis method according to this application is shown. The order of steps in the flowchart can be changed, and some steps can be omitted, depending on different needs. The data analysis method provided by this application embodiment can be applied to any scenario requiring device data analysis, and thus can be applied to products in these scenarios, such as device data analysis in the financial insurance field. The data analysis method includes the following steps:

[0039] Step S201: Collect parameter data corresponding to the target device; wherein, the target device is an IoT device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate.

[0040] In this embodiment, the data analysis method runs on an electronic device (e.g., Figure 1The server / terminal device shown can acquire parameter data corresponding to the target device through wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future wireless connection methods. The executing entity of this application is specifically a data analysis system, or a quantum risk control system, which can be simply referred to as the system. The aforementioned fingerprint verification failure count (a) refers to the number of times the Hamming distance (i.e., the number of binary bit differences) between the device and the registered fingerprint exceeds a threshold within 24 hours. Example: If the registered fingerprint is 101010, the currently sampled fingerprint is 100010, and the Hamming distance is 1 (only the 3rd bit is different), then the count a = 1. The aforementioned bit error rate (b) refers to the QKD bit error rate, which is the bit error rate caused by environmental interference or attacks during transmission through the quantum key distribution channel, updated once per second. Example: The normal bit error rate should be below 2%. If an attacker interferes with photon transmission, the bit error rate may rise to 5%.

[0041] Furthermore, the target device mentioned above is an IoT device based on quantum technology. The registration and quantum fingerprint generation process of IoT devices includes: 1. Initialization of the hardware-level quantum entropy source. Implementation process: The IoT device (such as a smart safe) has a built-in indium gallium arsenide semiconductor chip, which drives a laser diode with a 3.3V voltage to excite a single photon to generate a quantum superposition state (|0> represents horizontal polarization, |1> represents vertical polarization) through a beam splitter. The photon polarization state is in an uncertain state before measurement, and its collapse result is guaranteed to be unpredictable by the Heisenberg uncertainty principle, ensuring that each sampling result is random and cannot be copied. Quantum randomness is the physical basis for the uniqueness of device fingerprints, solving the problem that traditional MAC addresses or device serial numbers are easily forged by man-in-the-middle attacks (experiments show that the success rate of cloning commercial device fingerprints reaches 23%).

[0042] 2. Fingerprint Generation and Storage. Implementation Process: Raw Data Acquisition: The chip continuously samples 10 fingerprints at a frequency of 1MHz. 6 A number of quantum states (e.g., |0>, |1>, |0>...) are generated, with a generation length of 10. 6 The original sequence S of bits. Bias elimination: S is divided into adjacent 2-bit groups, discarding

[00] and

[11] (because they cannot reflect quantum randomness), converting

[01] to "0" and

[10] to "1", outputting a sequence F of approximately 250,000 bits. Hash compression: F is processed by SHA-3 (Keccak algorithm) one-way hashing to generate a 128-bit digest as the final device fingerprint, which is stored in the device's TPM security chip. By combining quantum randomness (original data) with hash algorithm (collision prevention), the fingerprint is ensured to be non-cloneable, providing a unique identifier for subsequent risk control.

[0043] 3. Initial Registration Verification. Implementation Process: When the device connects to the network for the first time, it sends its fingerprint H1 to the insurance company's quantum certification center via the QKD secure channel. The certification center records H1 and binds it to the device identifier (such as a serial number), completing the initial registration. By establishing an initial trust chain between the device and the insurance system, all subsequent risk control operations are based on the uniqueness verification of this fingerprint.

[0044] During the device registration phase, a unique, unforgeable fingerprint is generated using quantum physics properties, solving the problem of trustworthy identity for traditional IoT devices. The TPM chip stores the fingerprint to ensure local security, while the quantum certification center registration provides a benchmark for subsequent dynamic monitoring.

[0045] Step S202: Calculate the number of fingerprint verification failures based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient.

[0046] In this embodiment, the above-mentioned attack threat coefficient calculation strategy includes: Attack Threat Coefficient (T): reflecting the frequency of device fingerprint anomalies, the formula is: T = (a / 10) × α, where a is the number of fingerprint verification failures, and α is a parameter derived from regression based on historical attack data, the value of which can be set to 0.73. The logic is: every 10 fingerprint anomalies increase the threat value by 0.73. Example: If a = 20 within 24 hours, then T = 20 / 10 × 0.73 = 1.46.

[0047] Step S203: The bit error rate is calculated based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient.

[0048] In this embodiment, the channel vulnerability coefficient calculation strategy includes: Channel vulnerability coefficient (V): reflecting the strength of the QKD channel under attack, the formula is: V=e^(20×(b-0.02)), where b is the bit error rate. Logically: when the bit error rate exceeds 2%, it increases exponentially (e.g., when b=3%, V=e^(20×0.01)≈1.22). Example: If the bit error rate b=5%, then V=e^(20×0.03)≈1.82.

[0049] Step S204: Calculate the attack threat coefficient and the channel vulnerability coefficient based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability.

[0050] In this embodiment, the specific implementation process of calculating the attack threat coefficient and the channel vulnerability coefficient based on the preset cracking probability calculation strategy to obtain the corresponding cracking probability will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.

[0051] Step S205: Obtain the preset probability threshold and time threshold.

[0052] In this embodiment, the values ​​of the probability threshold and time threshold are not specifically limited and can be set according to actual business needs. For example, the probability threshold can be set to 10^-6 and the time threshold can be set to 5 seconds.

[0053] Step S206: Based on the probability threshold and the time threshold, perform attack identification processing on the cracking probability to generate the corresponding attack identification result.

[0054] In this embodiment, the specific implementation process of performing attack identification processing on the cracking probability based on the probability threshold and the time threshold to generate the corresponding attack identification result will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.

[0055] Step S207: Output the attack identification result.

[0056] In this embodiment, the generated attack identification results can be sent to relevant personnel, such as users of the target device, or relevant business personnel of the insurance company, thereby completing the output processing of the attack identification results.

[0057] This application first collects parameter data corresponding to the target device; wherein, the target device is an IoT device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate; then, based on a preset attack threat coefficient calculation strategy, the number of fingerprint verification failures is calculated to obtain the corresponding attack threat coefficient; then, based on a preset channel vulnerability coefficient calculation strategy, the bit error rate is calculated to obtain the corresponding channel vulnerability coefficient; subsequently, based on a preset cracking probability calculation strategy, the attack threat coefficient and the channel vulnerability coefficient are calculated to obtain the corresponding cracking probability; further, preset probability thresholds and time thresholds are obtained; and based on the probability thresholds and time thresholds, the cracking probability is subjected to attack identification processing to generate the corresponding attack identification result; finally, the attack identification result is output. Based on the above automated processing flow, this application collects the number of fingerprint verification failures and the bit error rate of the target device. Then, it calculates the attack threat coefficient based on the number of fingerprint verification failures using an attack threat coefficient calculation strategy, and calculates the channel vulnerability coefficient based on the bit error rate using a channel vulnerability coefficient calculation strategy. Subsequently, it calculates the cracking probability based on the attack threat coefficient and the channel vulnerability coefficient using a cracking probability calculation strategy. The cracking probability is then dynamically calculated by combining quantum parameters and device behavior. Finally, the cracking probability is processed for attack identification based on a combination of probability threshold and time threshold, so as to achieve millisecond-level attack identification and automatically and accurately generate the corresponding attack identification results. This effectively improves the identification efficiency and accuracy of attack identification and ensures the accuracy of the generated attack identification results.

[0058] In some alternative implementations, step S204 includes the following steps:

[0059] Obtain the target device parameters corresponding to the target device.

[0060] In this embodiment, based on actual business needs, the above target device parameters are adjusted according to the device type of the target device (e.g., safe γ = 1,000,000, smart lock γ = 100,000).

[0061] Invoke the preset weighting formula.

[0062] In this embodiment, the above weighting formula refers to the formula that weights the attack threat coefficient and the channel vulnerability coefficient. The formula includes: P = (T + V) / γ, where P is the cracking probability, T is the attack threat coefficient, V is the channel vulnerability coefficient, and γ is the target device parameter.

[0063] The attack threat coefficient, the channel vulnerability coefficient, and the target device parameters are calculated based on the weighted formula to obtain the corresponding first calculation result.

[0064] In this embodiment, the attack threat coefficient, channel vulnerability coefficient, and target device parameters are substituted into the corresponding positions in the weighted formula for calculation, and the first calculation result is used as the corresponding cracking probability. For example: For a safe scenario: P = (1.46 + 1.82) / 1,000,000 = 3.28 × 10^-6 (no alarm triggered). If the attacker simultaneously forges a fingerprint (a = 50) and interferes with the channel (b = 8%), then:

[0065] T=1050×a(0.73)=3.65, V=e^(20×0.06)≈3.32.

[0066] P = (3.65 + 3.32) / 1,000,000 = 6.97 × 10^-6 (exceeds the threshold of 10^-6).

[0067] The first calculation result is taken as the cracking probability.

[0068] This application obtains target device parameters corresponding to the target device; then calls a preset weighted formula; subsequently, it calculates the attack threat coefficient, the channel vulnerability coefficient, and the target device parameters based on the weighted formula to obtain a corresponding first calculation result; and then uses the first calculation result as the cracking probability. Based on the above processing flow, this application obtains target device parameters corresponding to the target device, and then calculates the attack threat coefficient, the channel vulnerability coefficient, and the target device parameters based on the use of a weighted formula, thereby efficiently and accurately calculating the corresponding cracking probability, improving the calculation efficiency of the cracking probability, and ensuring the accuracy of the obtained cracking probability data.

[0069] In some optional implementations of this embodiment, step S206 includes the following steps:

[0070] Determine whether the probability of cracking is greater than the probability threshold.

[0071] In this embodiment, the cracking probability is compared numerically with a probability threshold to determine whether the cracking probability is greater than the probability threshold. If the cracking probability is detected to be less than the probability threshold, it is directly determined as an invalid attack, and an attack identification result indicating that no attack event exists is generated.

[0072] If the hacking probability is greater than the probability threshold, then it is determined whether the duration corresponding to the hacking probability is greater than the time threshold.

[0073] In this embodiment, the duration corresponding to the above-mentioned cracking probability is compared with a time threshold to determine whether the duration is greater than the time threshold.

[0074] If the duration is greater than the time threshold, the generated content is the first attack identification result indicating the presence of an attack event.

[0075] In this embodiment, if the duration is detected to be greater than the time threshold, it is determined to be a valid attack, and a first attack identification result containing the content of an attack event is generated.

[0076] If the duration is not greater than the time threshold, the generated content is a second attack identification result indicating that no attack event exists.

[0077] In this embodiment, if the duration is not greater than the time threshold, it is determined to be an invalid attack, and a second attack identification result is generated, which states that no attack event exists.

[0078] This application determines whether the cracking probability is greater than a probability threshold; if the cracking probability is greater than the probability threshold, it determines whether the duration corresponding to the cracking probability is greater than a time threshold; if the duration is greater than the time threshold, a first attack identification result indicating the presence of an attack event is generated; and if the duration is not greater than the time threshold, a second attack identification result indicating the absence of an attack event is generated. Based on the above processing flow, this application automatically and accurately completes the attack identification processing for the cracking probability by comparing the cracking probability with both the probability threshold and the time threshold, thereby ensuring the accuracy of the obtained attack identification result.

[0079] In some optional implementations, the attack identification result indicates the presence of an attack event; after step S206, the aforementioned electronic device may further perform the following steps:

[0080] A verification command is sent to the target device based on a preset secure channel.

[0081] In this embodiment, the aforementioned secure channel is specifically a QKD secure channel. The establishment process of the QKD secure channel includes: Photon emission: The device-side laser emits a 45° linearly polarized photon stream (each pulse contains a single photon). Basis alignment: The security server randomly selects a measurement basis (horizontal / vertical or 45° / 135°). The device informs the transmitted basis via a classical channel; both parties discard measurement results with mismatched basis vectors (approximately 50% of the data is discarded). Key generation: The reserved bits constitute the initial key K1, and the bit error rate threshold is set to 2% (exceeding the threshold is considered channel interference). The QKD secure channel ensures quantum-level security for the transmission of risk control commands, preventing man-in-the-middle attacks or data tampering.

[0082] Determine whether a response message has been received from the target device.

[0083] In this embodiment, by detecting whether a response information corresponding to the above verification command is received from the target device, if a response information is detected, and the response is normal but the fingerprint is still abnormal, it is determined to be a logical attack (such as firmware tampering).

[0084] If no response is received from the target device, the target device will be locked.

[0085] In this embodiment, if no response information is received from the target device, or if the device response times out by 200ms, physical intrusion is confirmed (such as the device being disassembled or its signal being blocked), and the target device will be subject to a function lockout.

[0086] Generate an attack alert corresponding to the target device.

[0087] In this embodiment, the generated attack warning is information carrying an alarm data packet, which may include the following: attack type identifier (such as "fingerprint forgery" or "channel interference"), timestamp (accurate to milliseconds), and device unique ID (a hash value registered on the chain).

[0088] The attack alert was sent to the relevant personnel.

[0089] In this embodiment, the aforementioned relevant personnel may be users of the target device, or may also include relevant business personnel from an insurance company. The generated attack alert can be sent to the corresponding relevant personnel via email, SMS, or other means.

[0090] This application sends a verification command to the target device via a preset secure channel; then determines whether a response is received from the target device; if no response is received, the target device is functionally locked; subsequently, an attack alert corresponding to the target device is generated; and the attack alert is then sent to relevant personnel. Based on the above processing flow, when the attack identification result indicates the existence of an attack event, this application intelligently sends a verification command to the target device using a secure channel, and automatically locks the target device's functions when no response is received, and generates an attack alert corresponding to the target device and sends it to relevant personnel. This enables efficient attack identification and blocking, timely defense, and ensures timely risk control decisions, preventing hackers from penetrating the target device within the window period, thus protecting user assets.

[0091] In some alternative implementations, after the step of generating an attack alert corresponding to the target device, the electronic device may further perform the following steps:

[0092] Invoke the preset blockchain smart contract.

[0093] In this embodiment, after the system detects an attack (e.g., P≥10), -6 When the attack lasts for 5 seconds, the blockchain smart contract will be invoked to receive an attack warning corresponding to the target device. The attack warning is an information carrying an alarm data packet, which may contain the following: attack type identifier (such as "fingerprint forgery" or "channel interference"), timestamp (accurate to milliseconds), and device unique ID (hash value registered on the chain).

[0094] The attack alert is verified based on the blockchain smart contract.

[0095] In this embodiment, the specific implementation process of verifying the attack alert based on the blockchain smart contract will be further described in detail in subsequent specific embodiments of this application, and will not be elaborated on here.

[0096] If the attack alert passes the risk verification, the probability of the attack is calculated based on the preset premium refund calculation strategy to obtain the corresponding target premium refund.

[0097] In this embodiment, the above-mentioned calculation of the cracking probability based on the preset premium return calculation strategy to obtain the specific implementation process of the target premium return is described in more detail in subsequent specific embodiments of this application, and will not be elaborated on here.

[0098] The target refund premium will be sent to the user wallet of the target user corresponding to the target device.

[0099] In this embodiment, the funds can be returned by initiating a numerically matched ERC-1155 token transfer to the target user's wallet address based on the generated target return premium. In this way, the quantum risk quantification result is directly transformed into economic incentives, forming a positive "security-return" cycle.

[0100] This application invokes a preset blockchain smart contract; then, based on the blockchain smart contract, it performs risk verification on the attack alert; if the attack alert passes the risk verification, it calculates the probability of successful attack based on a preset premium refund calculation strategy to obtain the corresponding target refund premium; subsequently, it sends the target refund premium to the user wallet of the target user corresponding to the target device. Based on the above processing flow, after generating an attack alert corresponding to the target device, this application intelligently invokes a blockchain smart contract to perform risk verification on the attack alert, and after detecting that the attack alert has passed the risk verification, it automatically calculates the probability of successful attack based on the premium refund calculation strategy to obtain the target refund premium, and sends the target refund premium to the user wallet of the target user corresponding to the target device. This can realize the direct conversion of quantum risk quantification results into economic incentives, forming a positive cycle of security and benefit, which is conducive to improving user experience.

[0101] In some optional implementations of this embodiment, the risk verification of the attack alert based on the blockchain smart contract includes the following steps:

[0102] Based on the blockchain smart contract, verification data corresponding to the target device is obtained from a specified data source according to a preset information type.

[0103] In this embodiment, the aforementioned information types include device fingerprint hash value information and QKD bit error rate curve information. The specified data sources include on-chain distributed storage (such as IPFS) and quantum channel monitoring nodes (operated by a third-party authoritative institution). Specifically, based on blockchain smart contracts, an oracle service can be used to retrieve the hash values ​​of the target device's last 10 fingerprints from on-chain distributed storage, and the raw bit error rate data for the most recent 60 seconds can be obtained from the quantum channel monitoring node.

[0104] The verification data is verified based on a preset service verification strategy.

[0105] In this embodiment, the goal of service verification is to confirm that the received alarm data (fingerprint hash value, bit error rate curve) indeed comes from a real device and has not been tampered with by a man-in-the-middle attack. The service verification strategy includes: comparing whether the uploaded current fingerprint hash is consistent with the on-chain record. Example: If the hash recorded on the chain is 0x123..., while the uploaded data is 0x456..., then the fingerprint is determined to have been tampered with, and the verification data is determined to have failed service verification. It also compares whether the uploaded bit error rate curve is consistent with the node record. Example: If the node record shows a bit error rate of 1.5% between 00:00:00 and 00:00:01, while the uploaded data shows 8%, then it is initially determined that an attack caused the data tampering. Only when both the uploaded current fingerprint hash and the bit error rate curve are detected to be consistent with the node record will the verification data be determined to have passed service verification; otherwise, the verification data is determined to have failed service verification.

[0106] The functions of service verification include: filtering coarse-grained forgery: preventing hackers from directly forging the entire alert data packet (such as fabricating fingerprint hashes or error rates); and establishing trusted data sources: ensuring that subsequent analysis is based on raw data generated by real devices.

[0107] If the verification data passes the service verification, then the verification data is subjected to integrity verification based on the preset integrity verification strategy.

[0108] In this embodiment, the objectives of integrity verification include: detecting whether data verified by the service has been partially tampered with during transmission or storage (e.g., modifying a single bit error rate value or a few bits of the fingerprint hash). The integrity verification strategy includes: Quantum Fourier Transform (QFT) analysis: converting the bit error rate curve or fingerprint hash value into frequency components (similar to Fourier transform, but using quantum superposition to accelerate computation). Detecting whether there are abnormal abrupt changes in the frequency components (e.g., hacker tampering with data introduces unnatural frequency peaks). Shor's algorithm-assisted frequency domain threshold detection: pre-setting the frequency distribution range of normal data (e.g., the fundamental frequency of the bit error rate curve should be between 0.1-1Hz). If a high-frequency component (e.g., a 100Hz spike) or a frequency energy abrupt change exceeds the threshold (e.g., standard deviation ≥ 3 times), it is determined that the data has been tampered with.

[0109] Specifically, the verification data is considered to have passed the integrity verification only if no abnormal changes are detected in the frequency components and no high-frequency components are detected or the frequency energy changes do not exceed the threshold; otherwise, the verification data is considered to have failed the integrity verification.

[0110] If the verification data passes the integrity verification, the attack alert is determined to have passed the risk verification; otherwise, the attack alert is determined to have failed the risk verification.

[0111] In this embodiment, an attack alert is considered to have passed risk verification only if the detected verification data has passed both service verification and integrity verification; otherwise, the attack alert is considered to have failed risk verification.

[0112] The role of dual authentication is crucial: relying solely on service authentication allows hackers to tamper with transmitted data via man-in-the-middle attacks (e.g., intercepting the bit error rate curve and modifying some values). Example: A hacker might change 2% in the curve representing the true bit error rate from 2% to 8% to 1.5%, making the attack appear more "natural" and bypassing simple threshold detection. The advantage of quantum authentication is that integrity verification captures such tampering through frequency domain analysis; even small numerical modifications will reveal problems if the frequency distribution is abnormal.

[0113] In addition, the system provides consortium blockchain collaborative verification functionality: Node roles: Insurance company nodes: store premium pool funds. Regulatory nodes: hold Shor's algorithm verification keys. Laboratory nodes: provide gamma coefficient calibration services. Consensus mechanism: The PBFT algorithm requires confirmation of the authenticity of an attack event by more than 2 / 3 of the nodes. Correlation: Decentralized governance enhances regulatory transparency and prevents single points of failure. The consortium blockchain design ensures that regulatory agencies can audit in real time while protecting user privacy (e.g., storing only fingerprint hash values ​​rather than raw data).

[0114] This application, based on a blockchain smart contract, retrieves verification data corresponding to the target device from a specified data source according to a preset information type. Then, it performs service verification on the verification data based on a preset service verification strategy. If the verification data passes service verification, it performs integrity verification on the verification data based on a preset integrity verification strategy. If the verification data passes integrity verification, the attack alert is determined to have passed risk verification; otherwise, the attack alert is determined to have failed risk verification. This application, through the use of a blockchain smart contract, retrieves verification data corresponding to the target device from a specified data source according to the information type, and then performs service and integrity verification on the verification data to achieve efficient and accurate risk verification processing for attack alerts. Furthermore, only when the verification data is detected to have passed both service and integrity verification is the attack alert determined to have passed risk verification, effectively ensuring the accuracy of the generated risk verification results.

[0115] In some optional implementations of this embodiment, the step of calculating the hacking probability based on a preset premium refund calculation strategy to obtain the corresponding target refund premium includes the following steps:

[0116] Obtain the equipment risk coefficient corresponding to the target equipment.

[0117] In this embodiment, the device risk coefficient of the target device can be obtained by querying data on the target device. The device risk coefficient for different devices can be preset according to actual business needs; for example, a safe is set to 0.9, and a smart lock to 0.7.

[0118] Invoke the preset return calculation formula.

[0119] In this embodiment, the above-mentioned return calculation formula is as follows: Return amount = annual premium × (1-P×z) × equipment risk coefficient (γ), where P is the probability of cracking and z is the penalty factor, which is used to amplify the economic impact of the attack risk, for example, it can be set to 10,000.

[0120] The probability of hacking and the risk coefficient of the device are calculated based on the return calculation formula to obtain the corresponding second calculation result.

[0121] In this embodiment, the above-mentioned hacking probability and device risk coefficient are input into the corresponding positions in the above-mentioned return calculation formula for calculation, and the generated second calculation result is used as the corresponding target return premium. Example calculation: User A's safe deposit box: Annual premium = US$500, P = 3.98 × 10 -5 γ = 0.9. Returned amount = 500 × (1 - 3.98 × 10) -5 ×10,000)×0.9≈500×0.602×0.9≈$270.9 (approximately 54% refund). User B's smart lock (γ=0.7): Under the same conditions, the refund amount ≈500×0.602×0.7≈$210.7 (approximately 42% refund).

[0122] The second calculation result will be used as the target premium refund.

[0123] This application obtains the device risk coefficient corresponding to the target device; then calls a preset return calculation formula; subsequently, it calculates the hacking probability and the device risk coefficient based on the return calculation formula to obtain a corresponding second calculation result; and finally, it uses the second calculation result as the target return premium. Based on the above processing flow, this application obtains the device risk coefficient corresponding to the target device, and then calculates the hacking probability and the device risk coefficient based on the return calculation formula, thereby automatically and accurately calculating the corresponding target return premium, improving the calculation efficiency of the target return premium, and ensuring the accuracy of the obtained target return premium data.

[0124] In some alternative implementations, the user information obtained is subject to user consent and complies with relevant laws and policies.

[0125] Furthermore, any software tools or components not belonging to our company that appear in the embodiments of this application are merely illustrative examples and do not represent actual use.

[0126] Furthermore, this application achieves functional support based on the following core technologies:

[0127] 1. Quantum-Classical System Interface. Time Synchronization Mechanism: The device-side GPS module provides a nanosecond-level clock, with a synchronization error of <1ns with the QKD photon transmitter. Data Encapsulation Protocol: Defines a dedicated Q-Insurance message format: | Quantum Fingerprint (128 bits) | Timestamp (64 bits) | Bit Error Rate (16 bits) | Digital Signature (256 bits) |.

[0128] 2. Environmental Interference Resistance Design. Temperature Compensation: The quantum chip has a built-in temperature sensor that automatically corrects the laser wavelength when the temperature deviation exceeds 2℃: wavelength λ = 1550nm + 0.08 × (T - 25)nm / ℃. Adaptive Light Intensity: The laser power is dynamically adjusted according to the photon detector count rate to maintain a single-photon state probability >99.9%.

[0129] The benefits of this application include: 1. Absolutely trustworthy identity: Quantum fingerprint forgery requires overcoming the Heisenberg uncertainty principle, theoretically requiring simultaneous measurement of conjugate physical quantities (such as position / momentum), with a success probability of <10^-30 under current technology. 2. 1000-fold improvement in risk control response speed: Quantum parameter sampling frequency reaches 1MHz, compared to traditional daily statistical models, attack behavior can be identified within 50ms. 3. Structural optimization of insurance costs: Insurance companies can reduce security equipment premiums by 30-50%. Users receive an average annual premium return rate of approximately 12% (based on simulation data from 100,000 devices). 4. Building a new security ecosystem: Equipment manufacturers need to pass quantum security certification to access the insurance network. Insurance companies transform from risk bearers to security capability providers. 5. Enhanced regulatory transparency: Quantum parameters + blockchain notarization enable regulatory agencies to audit the effectiveness of risk control in real time.

[0130] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0131] It should be emphasized that, to further ensure the privacy and security of the above attack identification results, the above attack identification results can also be stored in a blockchain node.

[0132] The blockchain referred to in this application is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying blockchain platform, a platform product service layer, and an application service layer.

[0133] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0134] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.

[0135] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware with computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When executed, the program can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).

[0136] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0137] Further reference Figure 3 As a response to the above Figure 2 To implement the method shown, this application provides an embodiment of a data analysis device, which is similar to... Figure 2 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.

[0138] like Figure 3 As shown, the data analysis device 300 described in this embodiment includes: a data acquisition module 301, a first calculation module 302, a second calculation module 303, a third calculation module 304, an acquisition module 305, an identification module 306, and an output module 307. Wherein:

[0139] The acquisition module 301 is used to acquire parameter data corresponding to the target device; wherein, the target device is an Internet of Things device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate;

[0140] The first calculation module 302 is used to calculate the number of fingerprint verification failures based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient.

[0141] The second calculation module 303 is used to calculate the bit error rate based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient.

[0142] The third calculation module 304 is used to calculate the attack threat coefficient and the channel vulnerability coefficient based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability.

[0143] The acquisition module 305 is used to acquire preset probability thresholds and time thresholds;

[0144] The identification module 306 is used to perform attack identification processing on the cracking probability based on the probability threshold and the time threshold, and generate a corresponding attack identification result;

[0145] The output module 307 is used to output the attack identification result.

[0146] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0147] In some optional implementations of this embodiment, the third calculation module 304 includes:

[0148] The first acquisition submodule is used to acquire target device parameters corresponding to the target device;

[0149] The first calling submodule is used to call the preset weighting formula;

[0150] The first calculation submodule is used to calculate and process the attack threat coefficient, the channel vulnerability coefficient and the target device parameters based on the weighting formula to obtain the corresponding first calculation result;

[0151] The first determining submodule is used to take the first calculation result as the cracking probability.

[0152] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0153] In some optional implementations of this embodiment, the identification module 306 includes:

[0154] The first judgment submodule is used to determine whether the cracking probability is greater than the probability threshold.

[0155] The second judgment submodule is used to determine whether the duration corresponding to the cracking probability is greater than the time threshold if the cracking probability is greater than the probability threshold.

[0156] The first generation submodule is used to generate a first attack identification result indicating the presence of an attack event if the duration is greater than the time threshold.

[0157] The second generation submodule is used to generate a second attack identification result that indicates the absence of an attack event if the duration is not greater than the time threshold.

[0158] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0159] In some optional implementations of this embodiment, the attack identification result is that an attack event exists; the data analysis device further includes:

[0160] The sending module is used to send a verification command to the target device based on a preset secure channel;

[0161] The judgment module is used to determine whether the response information returned by the target device has been received;

[0162] The processing module is used to perform a function lockout process on the target device if no response information is received from the target device.

[0163] The generation module is used to generate an attack alert corresponding to the target device;

[0164] The first sending module is used to send the attack alert to relevant personnel.

[0165] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0166] In some optional implementations of this embodiment, the data analysis device further includes:

[0167] The calling module is used to invoke pre-defined blockchain smart contracts;

[0168] The verification module is used to perform risk verification on the attack alert based on the blockchain smart contract;

[0169] The calculation module is used to calculate the probability of the attack based on a preset premium return calculation strategy if the attack alarm passes the risk verification, and obtain the corresponding target premium return.

[0170] The second sending module is used to send the target refund premium to the user wallet of the target user corresponding to the target device.

[0171] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0172] In some optional implementations of this embodiment, the verification module includes:

[0173] The second acquisition submodule is used to acquire verification data corresponding to the target device from a specified data source based on the blockchain smart contract and according to a preset information type.

[0174] The first verification submodule is used to perform service verification on the verification data based on a preset service verification strategy.

[0175] The second verification submodule is used to perform integrity verification on the verification data based on a preset integrity verification strategy if the verification data passes the service verification.

[0176] The determination submodule is used to determine that the attack alert passes the risk verification if the verification data passes the integrity verification, and otherwise determine that the attack alert fails the risk verification.

[0177] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0178] In some optional implementations of this embodiment, the calculation module includes:

[0179] The third acquisition module is used to acquire the equipment risk coefficient corresponding to the target equipment;

[0180] The second calling module is used to call the preset return calculation formula;

[0181] The second calculation module is used to calculate the hacking probability and the device risk coefficient based on the return calculation formula to obtain the corresponding second calculation result;

[0182] The second determining module is used to use the second calculation result as the target return premium.

[0183] In this embodiment, the operations performed by the above modules or units correspond one-to-one with the steps of the data analysis method in the aforementioned embodiments, and will not be repeated here.

[0184] To address the aforementioned technical problems, embodiments of this application also provide a computer device. Please refer to [link / reference needed]. Figure 4 , Figure 4 This is a basic structural block diagram of the computer device in this embodiment.

[0185] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are interconnected via a system bus. It should be noted that only the computer device 4 with components 41-43 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0186] The computer device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device can interact with the user via a keyboard, mouse, remote control, touchpad, or voice control.

[0187] The memory 41 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 41 may be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 may also be an external storage device of the computer device 4, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 4. Of course, the memory 41 may also include both the internal storage unit and its external storage device of the computer device 4. In this embodiment, the memory 41 is typically used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions for data analysis methods. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or will be output.

[0188] In some embodiments, the processor 42 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 42 is typically used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to execute computer-readable instructions stored in the memory 41 or to process data, such as executing computer-readable instructions for the data analysis method.

[0189] The network interface 43 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the computer device 4 and other electronic devices.

[0190] Compared with the prior art, the embodiments of this application have the following beneficial effects:

[0191] In this embodiment, the number of fingerprint verification failures and the bit error rate of the target device are collected. Then, the attack threat coefficient is obtained by calculating the number of fingerprint verification failures based on the attack threat coefficient calculation strategy, and the channel vulnerability coefficient is obtained by calculating the bit error rate based on the channel vulnerability coefficient calculation strategy. Then, the cracking probability is obtained by calculating the attack threat coefficient and the channel vulnerability coefficient based on the cracking probability calculation strategy. The cracking probability is dynamically calculated by combining quantum parameters and device behavior. Subsequently, the cracking probability is processed for attack identification based on the combination of probability threshold and time threshold, so as to achieve millisecond-level attack identification and automatically and accurately generate the corresponding attack identification results. This effectively improves the identification efficiency and accuracy of attack identification and ensures the accuracy of the generated attack identification results.

[0192] This application also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the data analysis method described above.

[0193] Compared with the prior art, the embodiments of this application have the following main advantages:

[0194] In this embodiment, the number of fingerprint verification failures and the bit error rate of the target device are collected. Then, the attack threat coefficient is obtained by calculating the number of fingerprint verification failures based on the attack threat coefficient calculation strategy, and the channel vulnerability coefficient is obtained by calculating the bit error rate based on the channel vulnerability coefficient calculation strategy. Then, the cracking probability is obtained by calculating the attack threat coefficient and the channel vulnerability coefficient based on the cracking probability calculation strategy. The cracking probability is dynamically calculated by combining quantum parameters and device behavior. Subsequently, the cracking probability is processed for attack identification based on the combination of probability threshold and time threshold, so as to achieve millisecond-level attack identification and automatically and accurately generate the corresponding attack identification results. This effectively improves the identification efficiency and accuracy of attack identification and ensures the accuracy of the generated attack identification results.

[0195] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0196] Obviously, the embodiments described above are only some embodiments of this application, not all embodiments. The accompanying drawings show preferred embodiments of this application, but do not limit the patent scope of this application. This application can be implemented in many different forms; rather, the purpose of providing these embodiments is to provide a more thorough and comprehensive understanding of the disclosure of this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this application's specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the scope of patent protection of this application.

Claims

1. A data analysis method, characterized in that, Includes the following steps: Collect parameter data corresponding to the target device; wherein, the target device is an Internet of Things (IoT) device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate; The number of fingerprint verification failures is calculated based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient. The bit error rate is calculated based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient. The attack threat coefficient and the channel vulnerability coefficient are calculated based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability. Obtain the preset probability threshold and time threshold; Based on the probability threshold and the time threshold, the attack identification process is performed on the cracking probability to generate the corresponding attack identification result; The attack identification results are then processed for output.

2. The data analysis method according to claim 1, characterized in that, The step of calculating the attack threat coefficient and the channel vulnerability coefficient based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability specifically includes: Obtain the target device parameters corresponding to the target device; Invoke the preset weighting formula; The attack threat coefficient, the channel vulnerability coefficient, and the target device parameters are calculated based on the weighted formula to obtain the corresponding first calculation result. The first calculation result is taken as the cracking probability.

3. The data analysis method according to claim 1, characterized in that, The step of performing attack identification processing on the cracking probability based on the probability threshold and the time threshold, and generating a corresponding attack identification result, specifically includes: Determine whether the probability of cracking is greater than the probability threshold; If the hacking probability is greater than the probability threshold, then determine whether the duration corresponding to the hacking probability is greater than the time threshold; If the duration is greater than the time threshold, the generated content is the first attack identification result indicating the presence of an attack event; If the duration is not greater than the time threshold, the generated content is a second attack identification result indicating that no attack event exists.

4. The data analysis method according to claim 1, characterized in that, The attack identification result indicates the existence of an attack event; after the step of performing attack identification processing on the cracking probability based on the probability threshold and the time threshold to generate the corresponding attack identification result, the method further includes: A verification command is sent to the target device based on a preset secure channel; Determine whether a response message has been received from the target device; If no response is received from the target device, the target device will be locked. Generate an attack alert corresponding to the target device; The attack alert was sent to the relevant personnel.

5. The data analysis method according to claim 4, characterized in that, Following the step of generating an attack alert corresponding to the target device, the method further includes: Invoke the preset blockchain smart contract; The attack alert is verified based on the blockchain smart contract. If the attack alert passes the risk verification, the probability of the attack is calculated based on the preset premium refund calculation strategy to obtain the corresponding target premium refund. The target refund premium will be sent to the user wallet of the target user corresponding to the target device.

6. The data analysis method according to claim 5, characterized in that, The step of verifying the attack alert based on the blockchain smart contract specifically includes: Based on the blockchain smart contract, verification data corresponding to the target device is obtained from a specified data source according to a preset information type; The verification data is verified based on a preset service verification strategy. If the verification data passes the service verification, then the verification data is subjected to integrity verification based on the preset integrity verification strategy; If the verification data passes the integrity verification, the attack alert is determined to have passed the risk verification; otherwise, the attack alert is determined to have failed the risk verification.

7. The data analysis method according to claim 5, characterized in that, The step of calculating the probability of cracking based on a preset premium refund calculation strategy to obtain the corresponding target premium refund specifically includes: Obtain the equipment risk coefficient corresponding to the target equipment; Invoke the preset return calculation formula; The probability of hacking and the risk coefficient of the device are calculated based on the return calculation formula to obtain the corresponding second calculation result; The second calculation result will be used as the target premium to be returned.

8. A data analysis device, characterized in that, include: The acquisition module is used to acquire parameter data corresponding to the target device; wherein, the target device is an Internet of Things (IoT) device based on quantum technology; the parameter data includes the number of fingerprint verification failures and the bit error rate; The first calculation module is used to calculate the number of fingerprint verification failures based on a preset attack threat coefficient calculation strategy to obtain the corresponding attack threat coefficient. The second calculation module is used to calculate the bit error rate based on a preset channel vulnerability coefficient calculation strategy to obtain the corresponding channel vulnerability coefficient. The third calculation module is used to calculate the attack threat coefficient and the channel vulnerability coefficient based on a preset cracking probability calculation strategy to obtain the corresponding cracking probability. The acquisition module is used to acquire preset probability thresholds and time thresholds; The identification module is used to perform attack identification processing on the cracking probability based on the probability threshold and the time threshold, and generate the corresponding attack identification result; The output module is used to process the attack identification results.

9. A computer device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the data analysis method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the data analysis method as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Quantum key distribution (QKD) based secure communication system using artificial intelligence

    US20240396719A1