A student intelligent mental monitoring and protection system
By optimizing key distribution in real time and dynamically adjusting key tree parameters, secondary encryption protection is applied to easily leaked data, solving the problem of insufficient data privacy protection in the student psychological monitoring system and improving data security and privacy.
Patent Information
- Application Number
- CN202511580154.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2045-10-31
AI Technical Summary
Existing student psychological monitoring systems suffer from insufficient data privacy protection, particularly in the presence of security vulnerabilities and a lack of data integrity verification during data storage and transmission.
Through the psychological monitoring data collection module, key distribution module, key distribution optimization module, key configuration management module, key configuration management optimization module, and secondary encryption module, key distribution is optimized in real time, key tree parameters are dynamically adjusted, and easily leaked data is protected by secondary encryption.
This approach enhances the privacy protection of student psychological monitoring data, ensures data security and privacy, avoids resource waste, and improves the flexibility and accuracy of key management.
Smart Images

Figure CN121037142B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data transmission, and in particular to a student intelligent psychological monitoring and protection system. BACKGROUND
[0002] With the increase of student psychological monitoring data volume and the continuous growth of the number of users, key distribution is a key link to ensure data security, and the management links such as storage, use, update and revocation of keys become increasingly complex, and key configuration management is crucial to ensure the security and stability of student psychological monitoring data storage management.
[0003] The existing student intelligent psychological monitoring and protection system is implemented through key distribution based on public key infrastructure (PKI) and multi-layer key management architecture. The key distribution based on public key infrastructure (PKI) is implemented by a certificate authority (CA) to manage the generation, distribution and update of keys. The multi-layer key management architecture adopts a hierarchical key management method to divide the keys into different levels, and each layer of keys is responsible for different encryption tasks.
[0004] For example, the key management system and key service node disclosed in patent No. CN110120869B include: a plurality of key service nodes and clients running in a secure enclave; each key service node contains a same root key; the client is used to send an identity authentication request to any key service node, verify the enclave identity, and whether it is the latest version, and after verification, a secure session channel is established between them, and encryption and decryption are realized by using the key under envelope encryption protection; any key service node is used to verify the enclave identity of the client when receiving the identity authentication request; and when the client verifies that the key service code is not the latest version, the key service code is updated to the latest version.
[0005] For example, the method for protecting network electronic identity information based on key dispersion operation disclosed in patent No. CN104468096B includes: a network electronic identity server sends an application dispersion identification code of an application and a user network electronic identity code of a client to an encryption machine; the encryption machine randomly generates an application master key, and encrypts the application dispersion identification code to obtain an application encryption key; the encryption machine encrypts the user network electronic identity code to obtain an encrypted file; the network electronic identity server encodes the encrypted file and the application identity code to obtain an application network electronic identity code; and the network electronic identity server takes the application network electronic identity code as a user identifier of the application program.
[0006] However, in the process of implementing the technical scheme of the present application, the above-mentioned technology at least has the following technical problems:
[0007] In the prior art, due to insufficient application of encryption technology, security vulnerabilities in data storage and transmission, lack of data integrity verification and other measures, data is easy to be stolen and tampered with, and there is a problem of insufficient privacy protection of student psychological monitoring data. SUMMARY
[0008] The embodiments of the present application provide a student intelligent psychological monitoring and protection system, which solves the problem of insufficient privacy protection of student psychological monitoring data in the prior art, and achieves the effect of improving the privacy protection of student psychological monitoring data.
[0009] The embodiments of the present application provide a student intelligent psychological monitoring and protection system, which includes a psychological monitoring data collection module, a key distribution module, a key distribution optimization module, a key configuration management module, a key configuration management optimization module and a secondary encryption module, wherein: the psychological monitoring data collection module is used to receive student psychological monitoring data uploaded by an edge channel and prestore the student psychological monitoring data to a key configuration attribution; the key distribution module is used to distribute keys to authorized recipients through a communication channel, collect key distribution related data for analysis, and obtain a key distribution quantitative value; the key distribution optimization module is used to optimize the distribution of the keys in real time according to the key distribution quantitative value, and transmit the distributed keys to a configuration task queue; the key configuration management module is used to configure and process the student psychological monitoring data pre-stored in the key configuration attribution after the keys enter the configuration task queue, collect key configuration management related data for analysis, and obtain a key configuration management quantitative value; the key configuration management optimization module is used to dynamically adjust the relevant parameters of the key tree according to the key configuration management quantitative value, and transmit the student psychological monitoring data to a cloud storage server for storage after the configuration is completed; and the secondary encryption module is used to collect student psychological monitoring data storage related parameters for analysis, screen and obtain student psychological monitoring data prone to leakage for secondary encryption protection.
[0010] Further, the key distribution related data is collected for analysis, and the specific process is as follows: the key distribution related data includes key distribution efficiency, key distribution delay time and key length; the key distribution quantitative value is analyzed based on the key distribution related data; the key distribution quantitative value is the quantitative data of the key distribution evaluated by the key distribution efficiency, the key distribution delay time and the key length, and the specific processing process is as follows: the key distribution efficiency, the delay time of the key distribution and the key length are proportionally checked with the corresponding reference values, the proportionally checked results are coupled with the corresponding importance scores to obtain the key distribution quantitative value.
[0011] Further, the distribution of the key is optimized in real time. The specific process is: obtaining a key distribution evaluation threshold from a database, comparing the key distribution quantization value with the key distribution evaluation threshold, if the key distribution quantization value is greater than or equal to the key distribution evaluation threshold, no real-time optimization of the key distribution is performed, if the key distribution quantization value is less than the key distribution evaluation threshold, the difference between the key distribution quantization value and the key distribution evaluation threshold is extracted as a distribution adjustment control value, and the distribution of the key is optimized in real time according to the distribution adjustment control value, which specifically includes: obtaining a distribution adjustment control threshold from the database, comparing the distribution adjustment control value with the distribution adjustment control threshold, if the distribution adjustment control value is greater than or equal to the distribution adjustment control threshold, automatically triggering the key distribution hash value notarization, if the distribution adjustment control value is less than the distribution adjustment control threshold, mapping the distribution adjustment control value to extract a first key generation rate, at the same time, obtaining the quota of the key distribution, and comparing it with the quota demand calculated in real time by the sliding window algorithm, if the quota of the key distribution is greater than or equal to the quota demand of the key distribution, the first key generation rate is recorded as a second key generation rate, if the quota of the key distribution is less than the quota demand of the key distribution, mapping the key distribution quota difference value to extract a generation rate correction factor, and coupling the first key generation rate to obtain the second key generation rate; if the second key generation rate does not reach the upper limit of the key generation rate, the second key generation rate is recorded as a key generation execution rate, and the key generation execution rate is used for optimization control, if the second key generation rate reaches the upper limit of the key generation rate, the upper limit of the key generation rate is used as the key generation execution rate for optimization control, and the key is extracted from the pre-generated key pool into the configuration task queue.
[0012] Further, the configuration management related data of the key is collected and analyzed. The specific process is: the configuration management related data of the key includes the inter-task key reuse rate, the key usage distribution entropy and the configuration hotspot offset rate; the configuration management quantization value of the key is analyzed based on the configuration management related data of the key; the configuration management quantization value of the key is the quantization data of the key configuration management evaluation by the inter-task key reuse rate, the key usage distribution entropy and the configuration hotspot offset rate, and the specific processing process is: the inter-task key reuse rate, the key usage distribution entropy and the configuration hotspot offset rate are proportionally checked with the corresponding reference value, and the proportionally checked result is coupled with the corresponding importance score to obtain the configuration management quantization value of the key.
[0013] Further, the related parameters of the key tree are dynamically adjusted according to the configuration management quantization value of the key. The specific process is as follows: the configuration management quantization value of the key is compared with the configuration management evaluation threshold of the key. If the configuration management quantization value of the key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the related parameters of the key tree do not need to be dynamically adjusted. If the configuration management quantization value of the key is less than the configuration management evaluation threshold of the key, it is determined that the related parameters of the key tree need to be dynamically adjusted, including adjusting the depth and nodes of the key tree. Specifically, the configuration management evaluation threshold of the key is obtained from the database, the configuration management quantization value of the key is difference processed with the configuration management evaluation threshold of the key, the depth adjustment value of the key tree is obtained according to the difference processing result, and the key tree is dynamically adjusted according to the depth adjustment value of the key tree.
[0014] Further, dynamically adjusting the related parameters of the key tree also includes: after adjusting the depth of the key tree, the configuration management quantization value of the present key is re-evaluated. If the configuration management quantization value of the present key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the key does not need to be adjusted again. If the configuration management quantization value of the present key is less than the configuration management evaluation threshold of the key and greater than the configuration management quantization value of the original key, the difference between the configuration management quantization value of the present key and the configuration management quantization value of the original key is extracted, which is recorded as a key adjustment dynamic reference value. The key adjustment dynamic reference threshold is obtained from the database. If the key adjustment dynamic reference value is greater than the key adjustment dynamic reference threshold, the depth of the key tree is adjusted again. If the key adjustment dynamic reference value is less than or equal to the key adjustment dynamic reference threshold, the control adjustment of the nodes of the key tree is performed with a preset node increase number. If the configuration management quantization value of the present key is less than or equal to the configuration management quantization value of the original key, it is determined that adjusting the depth of the key tree has no effect, the depth of the key tree is adjusted to the depth of the original key tree, and an alarm is issued.
[0015] Further, the student psychological monitoring data storage related parameters are collected for analysis, and the specific process is as follows: the average value of the configuration management quantitative value of the statistical key is obtained, and the storage specified supervision period is obtained by mapping; the student psychological monitoring data storage related parameters are collected within the storage specified supervision period, including the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls; the student psychological monitoring data storage quantitative value is analyzed based on the student psychological monitoring data storage related parameters; the student psychological monitoring data storage quantitative value is the quantitative data of the student psychological monitoring data storage evaluated by the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls, and the specific processing process is as follows: the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls are proportionally checked with the corresponding reference value, the proportionally checked result is coupled with the corresponding importance score to obtain the student psychological monitoring data storage quantitative value; and the student psychological monitoring data is secondarily optimized and managed according to the student psychological monitoring data storage quantitative value.
[0016] Further, the specific process of secondarily optimizing and managing the student psychological monitoring data is as follows: the student psychological monitoring data storage evaluation threshold is obtained from the database, the student psychological monitoring data storage quantitative value is compared with the student psychological monitoring data storage evaluation threshold, if the student psychological monitoring data storage quantitative value is less than the student psychological monitoring data storage evaluation threshold, it is judged that the student psychological monitoring data is ordinary student psychological monitoring data, if the student psychological monitoring data storage quantitative value is greater than or equal to the student psychological monitoring data storage evaluation threshold, it is judged that the student psychological monitoring data is easy-to-leak student psychological monitoring data; if it is judged that the student psychological monitoring data is ordinary student psychological monitoring data, the storage of the ordinary student psychological monitoring data is changed, if it is judged that the student psychological monitoring data is easy-to-leak student psychological monitoring data, the easy-to-leak student psychological monitoring data is partitioned, and the partitioned easy-to-leak student psychological monitoring data is protected by asymmetric secondary encryption.
[0017] Further, the key pre-generation module is further included for pre-generating the student psychological monitoring data of the next period, and the specific process is as follows: after the key distribution and configuration management are ended, the key distribution average quantization value, the configuration management average quantization value and the student psychological monitoring data storage quantization value are collected for analysis to obtain a key pre-generation requirement index, and the student psychological monitoring data of the next period is pre-generated according to the key pre-generation requirement index, specifically: the key pre-generation requirement threshold is obtained from the database, the key pre-generation requirement index is compared with the key pre-generation requirement threshold, if the key pre-generation requirement index is less than or equal to the key pre-generation requirement threshold, it is judged that the student psychological monitoring data of the next period does not need to be pre-generated, and if the key pre-generation requirement index is greater than the key pre-generation requirement threshold, it is judged that the student psychological monitoring data of the next period needs to be pre-generated.
[0018] Further, the key pre-generation module is further included for pre-generating the student psychological monitoring data of the next period, and the specific process is as follows: after the key distribution and configuration management are ended, the key distribution average quantization value, the configuration management average quantization value and the student psychological monitoring data storage quantization value are collected for analysis to obtain a key pre-generation requirement index, and the student psychological monitoring data of the next period is pre-generated according to the key pre-generation requirement index, specifically: the key pre-generation requirement threshold is obtained from the database, the key pre-generation requirement index is compared with the key pre-generation requirement threshold, if the key pre-generation requirement index is less than or equal to the key pre-generation requirement threshold, it is judged that the student psychological monitoring data of the next period does not need to be pre-generated, and if the key pre-generation requirement index is greater than the key pre-generation requirement threshold, it is judged that the student psychological monitoring data of the next period needs to be pre-generated.
[0019] The one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0020] 1. By optimizing the distribution of the key in real time according to the key distribution quantization value, dynamically adjusting the relevant parameters of the key tree according to the key configuration management quantization value, and performing secondary encryption protection on the student psychological monitoring data prone to leakage, the privacy protection effect of the student psychological monitoring data is improved, and the problem of insufficient privacy protection of the student psychological monitoring data in the prior art is effectively solved.
[0021] 2. By collecting and analyzing the key distribution related data to obtain the key distribution quantization value, the distribution of the key is optimized in real time according to the key distribution quantization value, the effect of continuous and stable encryption of communication is achieved, and the resources are reasonably allocated to avoid waste of resources.
[0022] 3. By collecting and analyzing the key configuration management related data to obtain the key configuration management quantization value, the relevant parameters of the key tree are dynamically adjusted according to the key configuration management quantization value, and the key management flexibility of the student psychological monitoring data is effectively improved.
[0023] 4, By collecting student psychological monitoring data storage related parameters for analysis, thereby screening the student psychological monitoring data for secondary encryption protection, thereby effectively improving the privacy protection accuracy of student psychological monitoring data. BRIEF DESCRIPTION OF DRAWINGS
[0024] Figure 1 The structure schematic diagram of the student intelligent psychological monitoring and protection system provided by the embodiment of the present application is shown.
[0025] Figure 2 The part flow schematic diagram of the real-time optimization of the distribution of the key in the student intelligent psychological monitoring and protection system provided by the embodiment of the present application is shown.
[0026] Figure 3 The part flow schematic diagram of the real-time optimization of the distribution of the key in the student intelligent psychological monitoring and protection system provided by the embodiment of the present application is shown.
[0027] Figure 4 The part flow schematic diagram of the dynamic adjustment of the related parameters of the key tree in the student intelligent psychological monitoring and protection system provided by the embodiment of the present application is shown.
[0028] Figure 5 The part flow schematic diagram of the dynamic adjustment of the related parameters of the key tree in the student intelligent psychological monitoring and protection system provided by the embodiment of the present application is shown. DETAILED DESCRIPTION
[0029] The student intelligent psychological monitoring and protection system provided by the embodiment of the present application solves the problem of insufficient privacy protection of student psychological monitoring data in the prior art, and realizes the effect of improving the privacy protection of student psychological monitoring data by real-time optimization of the distribution of the key according to the key distribution quantization value, dynamic adjustment of the related parameters of the key tree by the configuration management quantization value of the key, and secondary encryption protection of the easily-leaked student psychological monitoring data.
[0030] The technical solution in the embodiment of the present application is to solve the problem of insufficient privacy protection of student psychological monitoring data, and the general idea is as follows:
[0031] The student psychological data is obtained by the psychological monitoring data collection module and is pre-stored, the speed of distributing the key is optimized in real time by the key distribution and optimization module, the data is safely stored in the cloud storage server after the key is configured and the parameters are adjusted by the key configuration management and optimization module, and the easily-leaked data is protected by the secondary encryption module, so as to ensure the security and privacy of the data, and achieve the effect of improving the privacy protection of student psychological monitoring data.
[0032] In order to better understand the above technical solution, the above technical solution will be described in detail in combination with the drawings in the specification and the specific embodiments.
[0033] As Figure 1 shown, the structure diagram of the student intelligent psychological monitoring and protection system provided by the embodiment of the application, the student intelligent psychological monitoring and protection system provided by the embodiment of the application comprises a psychological monitoring data collection module, a key distribution module, a key distribution optimization module, a key configuration management module, a key configuration management optimization module and a secondary encryption module, wherein: the psychological monitoring data collection module is used to receive student psychological monitoring data uploaded by an edge channel and prestore the student psychological monitoring data to a key configuration attribution; the key distribution module is used to distribute keys to authorized recipients through a communication channel, collect key distribution related data for analysis, and obtain a key distribution quantitative value; the key distribution optimization module is used to optimize the distribution of the keys in real time according to the key distribution quantitative value, and transmit the distributed keys to a configuration task queue; the key configuration management module is used to perform configuration processing on the student psychological monitoring data pre-stored in the key configuration attribution after the keys enter the configuration task queue, collect key configuration management related data for analysis, and obtain a key configuration management quantitative value; the key configuration management optimization module is used to dynamically adjust the relevant parameters of the key tree according to the key configuration management quantitative value, and transmit the student psychological monitoring data to a cloud storage server for storage after the configuration is completed; and the secondary encryption module is used to collect student psychological monitoring data storage related parameters for analysis, screen and obtain easily leaked student psychological monitoring data for secondary encryption protection.
[0034] In the embodiment, the edge channel refers to an edge device or system for data collection, such as a mental health monitoring device installed in a school, a smart bracelet or a local server for preliminary processing of data.
[0035] The communication channel refers to a medium or path for transmitting data between different entities, such as optical fiber, cable and other physical media, or wireless or wired network connection established through routers, switches and other devices. The communication channel provides a path for the transmission of signals or data, ensuring that data can be transmitted from the sender to the receiver.
[0036] The authorized recipient refers to an entity authorized by the system to receive the key, usually a device or user that needs to access the student psychological monitoring data, such as a school counseling center server, a specific mental health service provider's device, etc.
[0037] The key configuration attribution refers to the local server or system for key configuration management, used to store and manage data during the key configuration process, ensuring the security and privacy of data during the configuration process.
[0038] The cloud storage server refers to a cloud storage service for long-term storage of student psychological monitoring data, with high scalability and availability, ensuring safe storage and timely access to data.
[0039] Further, the key distribution related data is collected for analysis, and the specific process is as follows: the key distribution related data includes key distribution efficiency, key distribution delay time, and key length; the key distribution quantitative value is analyzed based on the key distribution related data; the key distribution quantitative value is the quantitative data of the key distribution evaluated by the key distribution efficiency, the key distribution delay time, and the key length together, and the specific processing process is as follows: the key distribution efficiency, the key distribution delay time, and the key length are proportionally checked with the corresponding reference values, and the proportionally checked results are coupled with the corresponding importance scores to obtain the key distribution quantitative value.
[0040] In the embodiment, the specific method for obtaining the key distribution quantitative value is as follows:
[0041] ;
[0042] ;
[0043] In the formula, the key distribution quantitative value is used to evaluate the distribution effect of the key distribution to the authorized party, the key distribution efficiency, the reference value of the key distribution efficiency, the importance score of the key distribution efficiency, the key distribution delay time, the reference value of the key distribution delay time, the importance score of the key distribution delay time, the key length, the reference value of the key length, the importance score of the key length.
[0044] The reference values of the key distribution efficiency, the key distribution delay time, and the key length refer to the reference values of the key distribution efficiency, the reference values of the key distribution delay time, and the reference values of the key length, which can be obtained from a database.
[0045] The key distribution efficiency refers to the number of successfully distributed keys in a unit of time, which can be counted by a log or a monitoring tool of the key distribution system.
[0046] The key distribution delay time refers to the time required from key generation to successful delivery of the key to the authorized receiver, which can be measured by setting a time stamp in the key distribution system.
[0047] The key length refers to the number of bits contained in the key, which can be obtained by checking the configuration of the key generation algorithm.
[0048] The longer the length of the key, the higher the security, but at the same time, it will increase the delay time of key distribution, because longer key needs more data transmission and processing time, which will reduce the efficiency of key distribution. On the contrary, shorter key length can improve the distribution efficiency and reduce the delay, but may reduce the security.
[0049] Obtain the preset key length security threshold from the database. When the key length is greater than the key length security threshold, the longer the key length, the smaller the key distribution efficiency. When the key length is less than or equal to the key length security threshold, the system issues an alarm to remind the relevant personnel that the key security is too low.
[0050] When the system is running, the mapping table of importance score is obtained from the database, for example, the corresponding importance score is extracted according to the current key distribution efficiency, key distribution delay time and key length, such as the importance score of key distribution efficiency, the importance score of key distribution delay time and the importance score of key length. This mapping table defines a clear set of association rules, which converts the specific values of key distribution efficiency, key distribution delay time and key length into their corresponding importance scores. Under this mechanism, whether it is to realize one-to-one accurate matching, or multiple parameters converge into a single weight of many-to-one relationship, the dynamic acquisition of importance score can be effectively realized.
[0051] Further, the distribution of the key is optimized in real time, and the specific process is: obtaining a key distribution evaluation threshold from a database, comparing the key distribution quantization value with the key distribution evaluation threshold, if the key distribution quantization value is greater than or equal to the key distribution evaluation threshold, the real-time optimization of the key distribution is not performed, if the key distribution quantization value is less than the key distribution evaluation threshold, a difference value between the key distribution quantization value and the key distribution evaluation threshold is extracted as a distribution adjustment control value, the distribution of the key is optimized in real time according to the distribution adjustment control value, and the specific process includes: obtaining a distribution adjustment control threshold from the database, comparing the distribution adjustment control value with the distribution adjustment control threshold, if the distribution adjustment control value is greater than or equal to the distribution adjustment control threshold, the hash value storage of the key distribution is automatically triggered, if the distribution adjustment control value is less than the distribution adjustment control threshold, a first generation rate of the key is extracted based on the mapping of the distribution adjustment control value, the quota of the key distribution is obtained, and the quota is compared with the quota demand calculated in real time by using a sliding window algorithm, if the quota of the key distribution is greater than or equal to the quota demand of the key distribution, the first generation rate of the key is recorded as a second generation rate of the key, if the quota of the key distribution is less than the quota demand of the key distribution, a generation rate correction factor is extracted based on the mapping of the difference value of the key distribution quota, and the first generation rate of the key is coupled to obtain the second generation rate of the key, if the second generation rate of the key does not reach an upper limit of the key generation rate, the second generation rate of the key is recorded as a key generation execution rate, and the key generation execution rate is used for optimization control, if the second generation rate of the key reaches the upper limit of the key generation rate, the upper limit of the key generation rate is used as the key generation execution rate for optimization control, and the key is extracted from a pre-generated key pool into a configuration task queue.
[0052] In the embodiment, Figure 2 and Figure 3 The process diagram for optimizing the distribution of the key in the student intelligent psychological monitoring and protection system provided by the embodiment of the application is shown in the figure. After obtaining the key distribution evaluation threshold from the database, the key distribution quantization value is compared with the threshold. If the evaluation coefficient is greater than or equal to the threshold, real-time optimization is not performed; if it is less than the threshold, the distribution adjustment control value is extracted. Then compare with the distribution adjustment control threshold, if greater, trigger the hash value storage, if less, extract the first generation rate of the key and compare with the quota and quota demand. According to the comparison result, determine the second generation rate of the key, if not reach the upper limit, then optimize control with this rate, if reach the upper limit, optimize with the rate upper limit and extract the key from the pre-generated key pool.
[0053] The first generation rate of the key is extracted based on the mapping of the distribution adjustment control value, which is: obtaining a mapping set of the distribution adjustment control value and the first generation rate of the key from the database, inputting the existing distribution adjustment control value, and obtaining the existing first generation rate of the key.
[0054] The quota requirement calculated by the sliding window algorithm in real time is specifically: a fixed-size window is defined to store data samples in the last n time units, and real-time quota requirement data such as access frequency of student psychological monitoring data and storage capacity requirement are collected, and each time a new data sample arrives, it is added to the window. If the window is full (i.e., contains n data samples), the oldest data sample entering the window is removed to maintain the window size, and a weighted average method is used to assign different weights to the data samples in the window to calculate the quota requirement.
[0055] The key distribution quota difference value mapping extraction generates a generation rate correction factor, which is specifically: obtaining a mapping set of key distribution quota difference values and generation rate correction factors from the database, inputting the existing key distribution quota difference value, and obtaining the existing generation rate correction factor.
[0056] The generation rate of the key is controlled by dynamically adjusting the length of the time slot, and when the key generation demand is high, the length of the key generation time slot is increased.
[0057] The existing generation rate correction factor is coupled with the first generation rate of the key to obtain the second generation rate of the key, and the coupling processing is to multiply the existing generation rate correction factor and the first generation rate of the key.
[0058] Further, the configuration management related data of the key is collected for analysis, and the specific process is: the configuration management related data of the key includes inter-task key reuse rate, key usage distribution entropy and configuration hotspot offset rate; based on the configuration management related data of the key, the configuration management quantitative value of the key is analyzed; the configuration management quantitative value of the key is the quantitative data of the key configuration management evaluation by the inter-task key reuse rate, the key usage distribution entropy and the configuration hotspot offset rate, and the specific processing process is: the inter-task key reuse rate, the key usage distribution entropy and the configuration hotspot offset rate are proportionally checked with the corresponding reference value, and the proportionally checked result is coupled with the corresponding importance score to obtain the configuration management quantitative value of the key.
[0059] In this embodiment, the specific method for obtaining the configuration management quantitative value of the key is:
[0060] ;
[0061] ;
[0062] In the formula, The configuration management quantitative value of the key is used to evaluate the configuration effectiveness of the key when the configuration management of the key is evaluated, The inter-task key reuse rate is represented by R, The reference value of the inter-task key reuse rate is represented by R ref, The importance score of the inter-task key reuse rate is represented by R imp. represents the key usage distribution entropy, represents the reference value of the key usage distribution entropy, represents the importance score of the key usage distribution entropy, represents the configuration hotspot offset rate, represents the reference value of the configuration hotspot offset rate, represents the importance score of the configuration hotspot offset rate.
[0063] The reference values of the inter-task key reuse rate, the key usage distribution entropy, and the configuration hotspot offset rate refer to the reference values of the inter-task key reuse rate, the key usage distribution entropy, and the configuration hotspot offset rate, which can be obtained from a database.
[0064] The inter-task key reuse rate refers to the ratio of repeatedly using the same key in different tasks, which is directly obtained by a security audit log analysis tool (such as Splunk), and the value range of the inter-task key reuse rate is 0-100%, indicating complete non-reuse to complete reuse, but only the premise of existing reuse is considered for calculation, so the value range is (0, 1].
[0065] The key usage distribution entropy refers to the uniformity of the key usage distribution, and the higher the uniformity, the greater the entropy value, representing more dispersed key usage and higher security, which is directly obtained by calling the entropy calculation function in the Python scientific computing library (such as NumPy and SciPy), and the value range of the key usage distribution entropy is 0-log(n), n is the number of keys, and when the number of keys is 1, the key usage distribution entropy is 0, but generally the number of keys is not considered to be 1.
[0066] The configuration hotspot offset rate refers to the degree of change of the key configuration hotspot over time, i.e., the offset of the highest frequency point of key usage, and the position change of the hotspot key is determined by directly obtaining it through a network analysis tool (such as Wireshark), and the value range of the configuration hotspot offset rate is 0-100%, indicating complete non-offset of the configuration hotspot to complete offset of the configuration hotspot, but complete non-offset of the configuration hotspot only exists in theoretical cases, so the value range is generally (0, 1].
[0067] High reuse rate makes key usage more concentrated, reduces key distribution entropy, and also forms a stable configuration hotspot, reducing hotspot offset rate, making key configuration management more flexible and variable. Low reuse rate makes key usage dispersed, increases distribution entropy, and increases hotspot offset rate.
[0068] When the system is running, a mapping table of importance scores is obtained from the database, for example, the corresponding importance scores of inter-task key reuse rate, key usage distribution entropy and configuration hotspot offset rate are extracted quickly according to the current inter-task key reuse rate, key usage distribution entropy and configuration hotspot offset rate. This mapping table defines a clear set of association rules, which converts the specific values of inter-task key reuse rate, key usage distribution entropy and configuration hotspot offset rate into their corresponding importance scores. Under this mechanism, whether it is to achieve one-to-one accurate matching or multiple parameters to converge into a single weight many-to-one relationship, the dynamic acquisition of importance scores can be effectively realized.
[0069] Further, the related parameters of the key tree are dynamically adjusted according to the configuration management quantization value of the key. The specific process is as follows: the configuration management quantization value of the key is compared with the configuration management evaluation threshold of the key. If the configuration management quantization value of the key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the related parameters of the key tree do not need to be dynamically adjusted. If the configuration management quantization value of the key is less than the configuration management evaluation threshold of the key, it is determined that the related parameters of the key tree need to be dynamically adjusted, including adjusting the depth and nodes of the key tree. Specifically: the configuration management evaluation threshold of the key is obtained from the database, the configuration management quantization value of the key is difference processed with the configuration management evaluation threshold of the key, the depth adjustment value of the key tree is obtained according to the difference processing result, and the key tree is dynamically adjusted according to the depth adjustment value of the key tree.
[0070] In this embodiment, the mapping set of the difference between the configuration management quantization value of the key and the configuration management evaluation threshold of the key and the depth adjustment value of the key tree is obtained from the database, the difference between the existing configuration management quantization value of the key and the configuration management evaluation threshold of the key is input into the mapping set, the depth adjustment value of the key tree is obtained, and the depth of the key tree is increased according to the depth adjustment value of the key tree through dynamic updating of the key security communication device.
[0071] Further, the method for dynamically adjusting the parameters of the key tree further comprises: after adjusting the depth of the key tree, re-evaluating the configuration management quantization value of the current key; if the configuration management quantization value of the current key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the key does not need to be adjusted again; if the configuration management quantization value of the current key is less than the configuration management evaluation threshold of the key and greater than the configuration management quantization value of the original key, a difference value between the configuration management quantization value of the current key and the configuration management quantization value of the original key is extracted, and is recorded as a key adjustment dynamic reference value; a key adjustment dynamic reference threshold is obtained from a database; if the key adjustment dynamic reference value is greater than the key adjustment dynamic reference threshold, the depth of the key tree is readjusted; if the key adjustment dynamic reference value is less than or equal to the key adjustment dynamic reference threshold, the control adjustment of the key tree nodes is performed by a preset number of nodes; and if the configuration management quantization value of the current key is less than or equal to the configuration management quantization value of the original key, it is determined that the adjustment of the depth of the key tree is ineffective, the depth of the key tree is adjusted to the depth of the original key tree, and an alarm is issued.
[0072] In the embodiment, Figure 4 and Figure 5 The flowchart of the method for dynamically adjusting the parameters of the key tree in the student intelligent psychological monitoring and protection system provided by the embodiment is shown in the figure. After adjusting the depth of the key tree, the configuration management quantization value of the key is re-evaluated. If the configuration management quantization value of the current key is greater than or equal to the configuration management quantization value threshold of the key, it is not necessary to adjust again; if the configuration management quantization value of the current key is less than the configuration management quantization value threshold of the key but greater than the original configuration management quantization value, a difference value is extracted to obtain a key adjustment dynamic reference value, which is compared with a reference threshold in the database. If the reference value is greater than the threshold, the depth of the key tree is readjusted; otherwise, the key tree nodes are adjusted by a preset number of nodes; and if the configuration management quantization value of the current key is less than or equal to the original configuration management quantization value, it is determined that the adjustment is ineffective, the depth of the original key tree is restored, and an alarm is issued.
[0073] The readjustment of the depth of the key tree specifically comprises: extracting a difference value between the key adjustment dynamic reference value and the key adjustment dynamic reference threshold, recording the difference value as a key adjustment dynamic reference difference value, obtaining a mapping set between the key adjustment dynamic reference difference value and a key tree depth readjustment amount from a database, inputting the current key adjustment dynamic reference difference value into the mapping set to obtain the key tree depth readjustment amount, and increasing the depth of the key tree again according to the key tree depth readjustment amount.
[0074] Further, the student psychological monitoring data storage related parameters are collected for analysis, and the specific process is: the average value of the configuration management quantitative value of the statistical key is mapped to obtain the storage specified supervision period; the student psychological monitoring data storage related parameters are collected in the storage specified supervision period, including the calling frequency of the student psychological monitoring data and the average data transmission amount of the student mental health data under multiple calls; the student psychological monitoring data storage quantitative value is analyzed based on the student psychological monitoring data storage related parameters; the student psychological monitoring data storage quantitative value is the quantitative data of the student psychological monitoring data storage evaluation of the calling frequency of the student psychological monitoring data and the average data transmission amount of the student mental health data under multiple calls, and the specific processing process is: the calling frequency of the student psychological monitoring data and the average data transmission amount of the student mental health data under multiple calls are proportionally checked with the corresponding reference value, the proportionally checked result is coupled with the corresponding importance score to obtain the student psychological monitoring data storage quantitative value; the student psychological monitoring data is secondarily optimized and managed according to the student psychological monitoring data storage quantitative value.
[0075] In the embodiment, the specific method of obtaining the student psychological monitoring data storage quantitative value is:
[0076] ;
[0077] ;
[0078] In the formula, represents the student psychological monitoring data storage quantitative value, which is used to evaluate the encryption demand of the student mental health data in the cloud storage server, represents the calling frequency of the student mental health data, represents the reference value of the calling frequency of the student mental health data, represents the importance score of the calling frequency of the student mental health data, represents the average data transmission amount of the student mental health data under multiple calls, represents the reference value of the average data transmission amount of the student mental health data under multiple calls, represents the importance score of the average data transmission amount of the student mental health data under multiple calls.
[0079] The reference values of the calling frequency of the student mental health data and the average data transmission amount of the student mental health data under multiple calls refer to the reference values of the calling frequency of the student mental health data and the average data transmission amount of the student mental health data under multiple calls, which can be obtained from the database.
[0080] The calling frequency of the student mental health data refers to the number of times the data is requested to be accessed within a certain time, which can be obtained by analyzing system logs.
[0081] The average data transmission amount of the student mental health data under multiple calls refers to the average data transmission amount of each call under multiple calls, which can be measured by network monitoring tools (such as Wireshark).
[0082] The increase in calling frequency will lead to an increase in data transmission demand, thus requiring higher data transmission capacity. If the data transmission capacity is insufficient, it will cause data transmission delay, reducing system response speed and performance; on the contrary, if the system has higher data transmission capacity, it can better meet the high-frequency calling demand and ensure fast and stable data transmission.
[0083] When the system is running, the mapping table of importance scores is obtained from the database, for example, the importance scores of the current calling frequency of the student mental health data and the average data transmission amount of the student mental health data under multiple calls are extracted, such as the importance score of the calling frequency of the student mental health data and the importance score of the average data transmission amount of the student mental health data under multiple calls. This mapping table defines a clear set of association rules, which converts the specific values of the calling frequency of the student mental health data and the average data transmission amount of the student mental health data under multiple calls into their corresponding importance scores. Under this mechanism, whether it is to realize one-to-one accurate matching or multiple parameters to gather into a single weight many-to-one relationship, the dynamic acquisition of importance scores can be effectively realized.
[0084] The mapping set between the average value of the average value of the key configuration management quantitative value and the storage specified supervision period is obtained from the database, the existing average value of the key configuration management quantitative value is input into the mapping set, and the existing storage specified supervision period is obtained.
[0085] Further, the specific process of secondary optimization management of student psychological monitoring data is as follows: obtaining the student psychological monitoring data storage evaluation threshold from the database, comparing the student psychological monitoring data storage quantitative value with the student psychological monitoring data storage evaluation threshold, if the student psychological monitoring data storage quantitative value is less than the student psychological monitoring data storage evaluation threshold, judging that the student psychological monitoring data is ordinary student psychological monitoring data, if the student psychological monitoring data storage quantitative value is greater than or equal to the student psychological monitoring data storage evaluation threshold, judging that the student psychological monitoring data is easy-to-leak student psychological monitoring data; if the student psychological monitoring data is judged to be ordinary student psychological monitoring data, the storage of the ordinary student psychological monitoring data is changed, if the student psychological monitoring data is judged to be easy-to-leak student psychological monitoring data, the easy-to-leak student psychological monitoring data is partitioned, and the partitioned easy-to-leak student psychological monitoring data is protected by asymmetric secondary encryption.
[0086] In the present embodiment, the storage of ordinary student psychological monitoring data is changed, specifically: using a data migration tool to migrate the ordinary student psychological monitoring data from the cloud storage server to the local server, updating the data management record, and reflecting the new storage location and related storage information.
[0087] The easy-to-leak student psychological monitoring data is partitioned, specifically: using a data partition tool or a data processing library in a programming language (such as Python) to realize the partitioning operation of the data.
[0088] The partitioned easy-to-leak student psychological monitoring data is protected by asymmetric secondary encryption, specifically: generating a pair of asymmetric keys, including a public key and a private key, wherein the private key is securely kept by the data owner, and the public key is used to encrypt the data. Then, using the public key to encrypt each partitioned data block to generate ciphertext. In the encryption process, each data block is processed by an asymmetric encryption algorithm (RSA-4096 encryption algorithm), and the encrypted data block is stored or transmitted to the target location, while recording the encryption-related information, when accessing the data, using the private key to decrypt the ciphertext to restore the original data, ensuring that only the authorized party with the private key can read the data content, partitioning the easy-to-leak student psychological monitoring data, improving the accuracy and security of secondary encryption.
[0089] Further, the key pre-generation module is further included for pre-generating the student psychological monitoring data in the next period, and the specific process is as follows: after the key distribution and configuration management are ended, the key distribution average quantization value, the configuration management average quantization value and the student psychological monitoring data storage quantization value are collected for analysis to obtain a key pre-generation demand index, and the student psychological monitoring data in the next period is pre-generated according to the key pre-generation demand index, and the specific process is as follows: the key pre-generation demand threshold is obtained from the database, the key pre-generation demand index is compared with the key pre-generation demand threshold, if the key pre-generation demand index is less than or equal to the key pre-generation demand threshold, it is judged that the student psychological monitoring data in the next period does not need to be pre-generated, and if the key pre-generation demand index is greater than the key pre-generation demand threshold, it is judged that the student psychological monitoring data in the next period needs to be pre-generated.
[0090] In the embodiment, the specific method for obtaining the key pre-generation demand index is as follows:
[0091] ;
[0092] ;
[0093] In the formula, the key pre-generation demand index is used to evaluate the demand situation of the key pre-generation,
[0094] The average value of the key distribution quantization value in the last key generation period refers to that all the key distribution quantization values in the last key generation period are summarized and averaged.
[0095] The average value of the key configuration management quantization value in the last key generation period refers to the result of summarizing and averaging all the key configuration management quantization values in the last key generation period.
[0096] The average value of the student psychological monitoring data storage quantization value in the last key generation cycle is the result of aggregating and averaging all student psychological monitoring data storage quantization values in the last key generation cycle.
[0097] If the average quantization value of key distribution is low, i.e. there is a delay or error in the key distribution process, the configuration management module will not be able to obtain the correct key in time, resulting in errors and delays in the configuration management process, which directly determines the security and reliability of data storage. If the average quantization value of configuration management is low, it indicates that there may be improper use of keys, configuration errors of storage locations, etc. in the configuration process, resulting in a decrease in the security of data storage and a decrease in the quantization value of data storage.
[0098] When the system is running, the mapping table of importance scores is obtained from the database, for example, the corresponding importance scores are extracted according to the current average quantization value of key distribution, the average quantization value of configuration management, and the student psychological monitoring data storage quantization value, such as the importance score of the average quantization value of key distribution, the importance score of the average quantization value of configuration management, and the importance score of the student psychological monitoring data storage quantization value. This mapping table defines a clear set of association rules, which converts the specific values of the average quantization value of key distribution, the average quantization value of configuration management, and the student psychological monitoring data storage quantization value into their corresponding importance scores. Under this mechanism, whether it is a one-to-one precise match or a many-to-one relationship where multiple parameters converge into a single weight, the dynamic acquisition of importance scores can be effectively achieved.
[0099] Further, the key pre-generation of the student psychological monitoring data in the next cycle is performed, and the specific process is as follows: the difference between the key pre-generation demand index and the key pre-generation demand threshold is extracted, denoted as the pre-generation demand difference, the key generation time window pre-adjustment and the proportion of pre-generated backup keys are obtained by mapping the pre-generation demand difference, and the key pre-generation of the student psychological monitoring data in the next cycle is optimized and controlled according to the key generation time window pre-adjustment and the proportion of pre-generated backup keys.
[0100] In this embodiment, the mapping set of the pre-generation demand difference and the key generation time window pre-adjustment is obtained from the database, the existing pre-generation demand difference is input into the mapping set, the key generation time window pre-adjustment in the next cycle is obtained, and the key pre-generation of the student psychological monitoring data in the next cycle is optimized and controlled according to the key generation time window pre-adjustment in the next cycle, i.e. the key pre-generation is performed in advance at the default upload time of the student psychological monitoring data in the next cycle, and the time in advance is the key generation time window pre-adjustment.
[0101] The mapping set of the pre-generated demand difference and the proportion of the pre-generated spare key is obtained from the database, the existing pre-generated demand difference is input into the mapping set, the proportion of the pre-generated spare key of the next period is obtained, the key pre-generation of the student psychological monitoring data of the next period is controlled and optimized according to the proportion of the pre-generated spare key of the next period, that is, in the pre-generation stage of the key, the key is generated in the proportion of the pre-generated spare key, and the pre-generated key is stored as a spare in the pre-generated key pool, wherein the proportion of the pre-generated spare key refers to the proportion between the number of the pre-generated spare key and the number of the full load key of the pre-generated key pool.
[0102] Those skilled in the art will appreciate that embodiments of the application can be provided as methods, systems, or computer program products. Accordingly, the application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the application can be embodied in the form of a computer program product on one or more computer readable storage media (including, but not limited to, disk memory, CD-ROMs, optical storage media, etc.) having computer usable program code embodied thereon.
[0103] The present application is described in reference to flowcharts and / or block diagrams of systems, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions, which are executed via the processor of the computer or other programmable data processing apparatus, generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks
[0104] These computer program instructions can also be stored in a computer readable storage medium that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer readable storage medium produce a manufactured product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks
[0105] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to generate a computer implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocksFigure 1 the steps of the functions specified in the one or more blocks.
[0106] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the preferred embodiments by those of skill in the art once they have the benefit of the present disclosure. Therefore, the appended claims are intended to encompass within their scope all possible variations and modifications of the preferred embodiments. 1
[0107] It is apparent that those skilled in the art can, without departing from the spirit and scope of the application, make various changes and modifications of the application. Thus, the present application is intended to encompass all such changes and modifications insofar as they come within the scope of the claims and their equivalents.
Claims
1. A student intelligent mental monitoring and protection system, characterized in that, The system comprises a psychological monitoring data collection module, a key distribution module, a key distribution optimization module, a key configuration management module, a key configuration management optimization module, and a secondary encryption module, wherein: The psychological monitoring data collection module is used to receive the student psychological monitoring data uploaded on the edge channel and pre-store the data to the key configuration attribution; The key distribution module is used to distribute the keys to the authorized recipients through the communication channel, collect the key distribution related data for analysis, and obtain the key distribution quantitative value; The specific process of collecting the key distribution related data for analysis is as follows: The key distribution related data includes key distribution efficiency, key distribution delay time, and key length; The key distribution quantitative value is analyzed based on the key distribution related data; The key distribution quantitative value is the quantitative data of the key distribution evaluated by the key distribution efficiency, the key distribution delay time, and the key length, and the specific processing process is as follows: the key distribution efficiency, the key distribution delay time, and the key length are proportionally checked with the corresponding reference values, the proportionally checked results are coupled with the corresponding importance scores to obtain the key distribution quantitative value; The key distribution optimization module is used to optimize the distribution of the keys in real time according to the key distribution quantitative value, and transmit the distributed keys to the configuration task queue; The specific process of optimizing the distribution of the keys in real time is as follows: The key distribution evaluation threshold value is obtained from the database, the key distribution quantitative value is compared with the key distribution evaluation threshold value, if the key distribution quantitative value is greater than or equal to the key distribution evaluation threshold value, the real-time optimization of the key distribution is not performed, if the key distribution quantitative value is less than the key distribution evaluation threshold value, the difference value between the key distribution quantitative value and the key distribution evaluation threshold value is extracted and recorded as the distribution adjustment control value, the distribution of the keys is optimized in real time according to the distribution adjustment control value, which specifically includes: The distribution adjustment control threshold value is obtained from the database, the distribution adjustment control value is compared with the distribution adjustment control threshold value, if the distribution adjustment control value is greater than or equal to the distribution adjustment control threshold value, the hash value of the key distribution is automatically triggered to be stored, if the distribution adjustment control value is less than the distribution adjustment control threshold value, the first generation rate of the key is extracted based on the mapping of the distribution adjustment control value, the quota of the key distribution is obtained, and is compared with the quota demand calculated in real time by the sliding window algorithm, if the quota of the key distribution is greater than or equal to the quota demand of the key distribution, the first generation rate of the key is recorded as the second generation rate of the key, if the quota of the key distribution is less than the quota demand of the key distribution, the generation rate correction factor is extracted based on the mapping of the key distribution quota difference value, and is coupled with the first generation rate of the key to obtain the second generation rate of the key; If the second generation rate of the key does not reach the upper limit of the key generation rate, the second generation rate of the key is recorded as the key generation execution rate, and the optimization control is performed at the key generation execution rate, if the second generation rate of the key reaches the upper limit of the key generation rate, the upper limit of the key generation rate is taken as the key generation execution rate for optimization control, and the key is extracted from the pre-generated key pool to enter the configuration task queue; The key configuration management module is configured to perform configuration processing on the student psychological monitoring data pre-stored in the key configuration home after the key enters the configuration task queue, collect configuration management related data of the key for analysis, and obtain a configuration management quantitative value of the key. The key configuration management optimization module is configured to dynamically adjust relevant parameters of the key tree according to the configuration management quantitative value of the key, and transmit the student psychological monitoring data to the cloud storage server for storage after the configuration is completed. The secondary encryption module is configured to collect student psychological monitoring data storage related parameters for analysis, screening to obtain easily leaked student psychological monitoring data for secondary encryption protection.
2. The student intelligent mental monitoring and protection system as claimed in claim 1, wherein, The configuration management related data of the key includes inter-task key reuse rate, key usage distribution entropy, and configuration hotspot offset rate. The configuration management quantitative value of the key is obtained based on the configuration management related data of the key. The configuration management quantitative value of the key is a quantitative data of the key configuration management evaluated by the inter-task key reuse rate, the key usage distribution entropy, and the configuration hotspot offset rate. The specific processing procedure is as follows: the inter-task key reuse rate, the key usage distribution entropy, and the configuration hotspot offset rate are proportionally checked with the corresponding reference values, the proportionally checked results are coupled with the corresponding importance scores to obtain the configuration management quantitative value of the key. The relevant parameters of the key tree are dynamically adjusted according to the configuration management quantitative value of the key.
3. The intelligent mental monitoring and protection system for students as claimed in claim 1 wherein, The configuration management quantitative value of the key is compared with the configuration management evaluation threshold of the key. If the configuration management quantitative value of the key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the relevant parameters of the key tree do not need to be dynamically adjusted. If the configuration management quantitative value of the key is less than the configuration management evaluation threshold of the key, it is determined that the relevant parameters of the key tree need to be dynamically adjusted, including adjusting the depth and nodes of the key tree. The configuration management evaluation threshold of the key is obtained from the database, the configuration management quantitative value of the key is difference processed with the configuration management evaluation threshold of the key, the depth adjustment value of the key tree is mapped according to the difference processing result, and the key tree is dynamically adjusted according to the depth adjustment value of the key tree. The relevant parameters of the key tree are dynamically adjusted, which also includes:
4. The student intelligent mental monitoring and protection system as claimed in claim 3, wherein, After adjusting the depth of the key tree, the configuration management quantitative value of the present key is re-evaluated. If the configuration management quantitative value of the present key is greater than or equal to the configuration management evaluation threshold of the key, it is determined that the key does not need to be adjusted again. If the configuration management quantitative value of the present key is less than the configuration management evaluation threshold of the key and greater than the configuration management quantitative value of the original key, the difference between the configuration management quantitative value of the present key and the configuration management quantitative value of the original key is extracted, which is recorded as a key adjustment dynamic reference value. The key adjustment dynamic reference threshold is obtained from the database. If the key adjustment dynamic reference value is greater than the key adjustment dynamic reference threshold, the depth of the key tree is adjusted again. If the key adjustment dynamic reference value is less than or equal to the key adjustment dynamic reference threshold, the control adjustment of the nodes of the key tree is performed with a preset number of node increases. If the configuration management quantization value of the current key is less than or equal to the configuration management quantization value of the original key, it is determined that adjusting the key tree depth has no effect, the key tree depth is adjusted to the original key tree depth, and an alarm is issued.
5. The intelligent mental monitoring and protection system for students as claimed in claim 1 wherein, The student psychological monitoring data storage related parameters are analyzed, and the specific process is as follows: The average value of the configuration management quantization value of the statistical key is obtained, and the storage specified supervision period is mapped; Student psychological monitoring data storage related parameters are collected within the storage specified supervision period, including the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls; Based on the student psychological monitoring data storage related parameters, the student psychological monitoring data storage quantization value is analyzed; The student psychological monitoring data storage quantization value is the quantization data of the student psychological monitoring data storage evaluation of the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls, and the specific processing process is as follows: the calling frequency of the student psychological monitoring data and the average data transmission amount of the student psychological health data under multiple calls are proportionally checked with the corresponding reference value, and the proportionally checked result is coupled with the corresponding importance score to obtain the student psychological monitoring data storage quantization value; According to the student psychological monitoring data storage quantization value, the student psychological monitoring data is secondarily optimized and managed.
6. The intelligent mental monitoring and protection system for students as claimed in claim 5 wherein, The specific process of the secondary optimization and management of the student psychological monitoring data is as follows: The student psychological monitoring data storage evaluation threshold is obtained from the database, and the student psychological monitoring data storage quantization value is compared with the student psychological monitoring data storage evaluation threshold. If the student psychological monitoring data storage quantization value is less than the student psychological monitoring data storage evaluation threshold, it is determined that the student psychological monitoring data is ordinary student psychological monitoring data. If the student psychological monitoring data storage quantization value is greater than or equal to the student psychological monitoring data storage evaluation threshold, it is determined that the student psychological monitoring data is easy-to-leak student psychological monitoring data. If it is determined that the student psychological monitoring data is ordinary student psychological monitoring data, the storage of the ordinary student psychological monitoring data is changed. If it is determined that the student psychological monitoring data is easy-to-leak student psychological monitoring data, the easy-to-leak student psychological monitoring data is partitioned, and the partitioned easy-to-leak student psychological monitoring data is asymmetrically secondarily encrypted and protected.
7. The intelligent mental monitoring and protection system for students as claimed in claim 1 wherein, It also includes a key pre-generation module for pre-generating keys for student psychological monitoring data of the next period, and the specific process is as follows: After the key distribution and configuration management are completed, the key distribution average quantization value, the configuration management average quantization value, and the student psychological monitoring data storage quantization value are collected and analyzed to obtain a key pre-generation requirement index, and the student psychological monitoring data of the next period is pre-generated based on the key pre-generation requirement index, and the specific process is as follows: The key pre-generation demand threshold is obtained from the database, the key pre-generation demand index is compared with the key pre-generation demand threshold, if the key pre-generation demand index is less than or equal to the key pre-generation demand threshold, it is judged that the key pre-generation of the student psychological monitoring data of the next period is not needed, and if the key pre-generation demand index is greater than the key pre-generation demand threshold, it is judged that the key pre-generation of the student psychological monitoring data of the next period is needed.
8. The intelligent mental monitoring and protection system for students as claimed in claim 7 wherein, The key pre-generation of the student psychological monitoring data of the next period is specifically as follows: The difference between the key pre-generation demand index and the key pre-generation demand threshold is extracted, denoted as a pre-generation demand difference, a key generation time window pre-adjustment amount and a pre-generation spare key proportion are obtained according to the pre-generation demand difference, and the key pre-generation of the student psychological monitoring data of the next period is optimized and controlled according to the key generation time window pre-adjustment amount and the pre-generation spare key proportion.
Citation Information
Patent Citations
A method for protecting network electronic identity information based on key distribution computation
CN104468096B
Key management system and key service nodes
CN110120869B
Quantum security key management method and system based on homomorphic encryption
CN119652492A
Quantum key distribution secure communication system based on quantum mechanics principle
CN120675711A