Network data security processing method and platform
By employing technologies such as multidimensional authentication, dynamic risk assessment, and hierarchical encryption, a full-process, dynamic network data security processing system is constructed, which addresses the shortcomings of existing technologies in authentication and risk assessment, and achieves efficient data security protection and self-optimization capabilities.
Patent Information
- Application Number
- CN202511311799.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-15
- Publication Date
- 2025-12-12
AI Technical Summary
Existing network data security technologies are inadequate in terms of authentication, risk assessment, data encryption, and transmission monitoring, and cannot effectively address security challenges in complex network environments. They also lack a dynamic and end-to-end security processing system.
By employing multidimensional identity verification, dynamic risk assessment, hierarchical encryption, anomaly monitoring, and blockchain-based evidence storage, combined with quantum key technology and smart contracts, a full-process, dynamic security processing system is constructed to achieve accurate risk assessment and comprehensive security protection.
It effectively blocks unauthorized access, ensures controlled data access, achieves millisecond-level anomaly identification and response, forms a security protection system covering the entire data transmission process, and has the ability to self-optimize and continuously adapt to new threats.
Smart Images

Figure CN121125243A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network data security, and particularly relates to a network data security processing method and platform. Background Art
[0002] With the continuous deepening of the digitalization process, various types of data are being collected, stored, used, and processed on an unprecedented scale, which poses severe challenges to data security. Data leakage incidents may not only cause significant economic losses but also trigger widespread social problems. There are significant deficiencies in current network data security technologies: in an increasingly complex network environment, authentication means are relatively single, lacking a precise risk prediction mechanism based on access requirements and the ability to perform dynamic evaluation during the access process; it is also unable to perform dynamic data encryption according to the real-time risk level; at the same time, there is a lack of effective monitoring ability for the entire process of data transmission during the access process. Therefore, there is an urgent need for an innovative security processing system that is full-process, dynamic, and traceable. Summary of the Invention
[0003] In view of the above deficiencies in the prior art, the present invention provides a network data security processing method and platform to solve the problems in the above background art. <00,00013>
[0004] To solve the above technical problems, the present invention adopts the following technical solutions: A network data security processing method includes the following specific steps: Step 1: When a data access request is received, trigger multi-dimensional authentication, which includes personal or institutional authentication, permission matching authentication, and credit authentication; Step 2: After passing multi-dimensional authentication, according to the dynamic risk assessment step, extract the data access request, generate network data sensitive parameters, network environment parameters, and network behavior parameters, generate a network risk value based on the parameters, and divide the network risk value R into low risk levels of 0 < R < 30, medium risk levels of 31 < R < 60, and high risk levels of 61 < R < 100; Step 3: According to the risk level, perform hierarchical network data encryption steps. For low risks, use the SM4 algorithm for data encryption; for medium risks, use the SM4 + 256-bit quantum key for data encryption; for high risks, use the SM4 + 512-bit quantum key for data encryption and bind the hardware characteristics of the requesting device; Step 4: During the data access process, perform an anomaly monitoring step, use a sliding window algorithm to monitor the transmission rate, detect the link stability, verify the data integrity, and detect abnormal access and alarm; Step 5: When the data access is completed, perform a blockchain evidence storage step, generate an operation log, including access time, operation type, and risk level information; use the SHA-384 algorithm to generate a hash value and store the hash value in the consortium chain network; Step 6: Strategy adjustment step. Based on the anomaly detection results and historical data, trace the source and dynamically adjust the risk assessment parameter weights and anomaly monitoring model.
[0005] In step 1, personal authentication includes password complexity requirements and two-factor authentication with a facial recognition matching rate of ≥95% with the public security identity database; institutional authentication requires uploading an authorization document with a valid electronic signature, and the system verifies the validity of the electronic signature. Permission matching authentication includes verifying whether the operation permission requested is within the user's permission scope, and whether a single data download does not exceed 20 items; Credit verification includes querying a user's historical credit score; access is denied if the credit score is below 60.
[0006] The formula for calculating the network risk value in step 2 is as follows: Among them, the R network risk value, For network data sensitive parameters, For network environment parameters, For network behavior parameters, , , These are the weighting coefficients, and =1.
[0007] The quantum key in step 3 is generated by the QKD-2000 device and transmitted using the BB84 protocol. When quantum state collapse is detected, it is considered abnormal behavior, and the transmission is immediately terminated and the key is regenerated.
[0008] In step 4, the anomaly monitoring step uses a sliding window algorithm to monitor the transmission rate, with a normal range of 1-10 MB / s. An alarm is triggered if the rate exceeds 30 MB / s or falls below 0.5 MB / s. An LSTM neural network model is used to detect abnormal transmission patterns. The hash value of the data packets during transmission is calculated in real time for integrity verification.
[0009] The blockchain evidence storage step in step 5 includes a consortium blockchain network with four nodes, deployed on the data provider, user, storage provider, and regulator respectively; when the hash value is stored in the consortium blockchain network, at least three nodes need to reach a consensus and use a smart contract to verify the consistency of the hash value.
[0010] In step 6, the anomaly detection model is calculated as follows: Where P is the anomaly detection accuracy, P Y P represents the number of anomalies correctly detected. Z This represents the total number of anomaly detections. When an anomaly is detected, update the training samples used to detect anomalies in the anomaly monitoring step; when the proportion of high-risk operations exceeds 15%, adjust the parameter weights in the dynamic risk assessment step.
[0011] This also includes credit scores that are dynamically updated based on the risk assessment results of each transaction. The credit score calculation formula is: S1 is the new credit score, and S is the original credit score. When the network risk value R of a single operation exceeds 80 points, the credit score will be directly reduced by 20 points.
[0012] The network data sensitivity parameters are determined based on the confidentiality level of the data and the scope of impact of leakage. Core sensitive data corresponds to higher parameter values, while ordinary non-sensitive data corresponds to lower parameter values. Network environment parameters are calculated based on network protocol type, request source geographical location, and request time. Network behavior parameters are calculated based on request frequency and device matching degree. When logging in using an unfamiliar device, the parameter values increase. The parameter values are collected in real time at a frequency of once per second. The initial values of the weighting coefficients are α = 0.4, β = 0.3, and γ = 0.3.
[0013] The platform includes an identity verification module that performs multidimensional identity verification; a risk assessment module that calculates risk values and determines risk levels; an encryption processing module that executes tiered encryption strategies; an anomaly monitoring module that monitors the data access process in real time; a blockchain evidence storage module that manages the storage of operation logs; a policy management module that adjusts system parameters and updates models; and a credit management module that calculates credit scores and stores historical credit data. All modules exchange data through a communication unit and adopt a unified API interface specification.
[0014] Compared with the prior art, the present invention has the following advantages: 1. By integrating personal multi-factor authentication, institutional electronic signature verification, fine-grained access control, and credit history screening, a multi-dimensional identity verification mechanism is established to effectively block unauthorized access attempts and overcome the weak security of traditional single-factor authentication. Combined with continuous awareness of data sensitivity, real-time environmental characteristics, and user behavior patterns, a dynamic weighted algorithm is used to accurately determine risk levels, reliably identifying high-risk access scenarios with high concealment, ensuring that data access is controlled from the entry point. 2. Implement differentiated encryption strategies based on dynamic risk levels. While ensuring the efficiency of low-risk data flow, introduce quantum key enhancement mechanisms and device feature binding for medium- and high-risk data to increase the difficulty of cracking. Combined with transmission rate monitoring, artificial intelligence behavior analysis, and data integrity verification, achieve millisecond-level anomaly identification and response, effectively resisting attacks such as data theft and tampering, and forming a security protection system covering the entire data transmission process; 3. An operation log storage system is built based on a multi-node consortium blockchain and consensus mechanism to ensure log immutability and support rapid traceability and accountability. The system has self-optimization capabilities, automatically updating detection models and adjusting risk weights based on the security situation to continuously improve its adaptability to new threats. A dynamic user credit scoring mechanism is introduced to effectively guide and regulate user behavior, ensuring security while also considering business experience, ultimately forming a continuously evolving and virtuous cycle of security. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of a network data security processing method according to the present invention; Figure 2 This is a schematic diagram of the network data security platform structure. Figure 3 This is a flowchart for dynamic risk assessment. Detailed Implementation To enable those skilled in the art to better understand the present invention, the technical solution of the present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0016] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual images. They should not be construed as limiting the scope of this application. To better illustrate the embodiments of the present invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual dimensions of the product. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.
[0017] In the accompanying drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components. In the description of the present invention, it should be understood that if terms such as "upper," "lower," "left," "right," "inner," and "outer" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting the present application. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.
[0018] In the description of this invention, unless otherwise explicitly specified and limited, the term "connection" or similar designation indicating a connection between components should be interpreted broadly. For example, it can refer to a fixed connection, a detachable connection, or an integral part; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can refer to the internal communication between two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0019] Example 1: As Figure 1-3 shown, a network data security processing method of the present invention includes the following specific steps: Step 1: Upon receiving a data access request, trigger multi-dimensional authentication, which includes personal or institutional authentication, permission matching authentication, and credit authentication; Step 2: After passing multi-dimensional authentication, according to the dynamic risk assessment step, extract the data access request, generate network data sensitive parameters, network environment parameters, and network behavior parameters, generate a network risk value based on the parameters, and divide the risk levels into low (0 < R < 30), medium (31 < R < 60), and high (61 < R < 100) according to the network risk value R; Step 3: According to the risk level, execute the network data hierarchical encryption step. For low risk, use the SM4 algorithm for data encryption; for medium risk, use the SM4 + 256-bit quantum key for data encryption; for high risk, use the SM4 + 512-bit quantum key for data encryption; Specifically, according to the risk level divided in Step 2, execute a differentiated network data encryption strategy. For low-risk data encryption, use the SM4 symmetric encryption algorithm for separate encryption, generate it through SHA-256 hash operation, the key validity period is 24 hours, and it is automatically updated at midnight every day; the encrypted data is transmitted through a conventional secure channel, and the key validity needs to be verified before transmission; For medium-risk data encryption, use double-layer encryption of the SM4 algorithm + 256-bit quantum key. First, use the SM4 algorithm to perform the first encryption on the original data to generate SM4 encrypted data; then use the 256-bit quantum key to perform a second XOR encryption on the SM4 encrypted data to generate the final encrypted data; the quantum key is generated by a QKD-2000 model quantum key distribution device and transmitted using the BB84 protocol; during the transmission process, the system continuously monitors the quantum state, if the quantum state collapse is detected, immediately terminate the current transmission, regenerate the quantum key and then perform encryption and transmission again; the key validity period is 1 hour, and it expires automatically when it exceeds the time limit; For high-risk data encryption, use double-layer encryption of the SM4 algorithm + 512-bit quantum key. The encryption logic is the same as that of medium risk, the difference is that the quantum key length is 512 bits with higher encryption strength, and the key validity period is shortened to 30 minutes; and the encrypted data is bound to the hardware characteristics of the requesting device, and only the requesting device is allowed to decrypt, and other devices cannot parse it; after encryption, generate an encryption identifier containing the encryption algorithm type, key version number, and key validity period, and transmit it together with the encrypted data to enter Step 4.
[0020] Step 4: During the data access process, execute the abnormal monitoring step, use the sliding window algorithm to monitor the transmission rate, detect the link stability, verify the data integrity, detect abnormal access and alarm; Step 5: After the data access is completed, execute the blockchain notarization step to generate an operation log, which includes access time, operation type, and risk level information; use the SHA-384 algorithm to generate a hash value and store the hash value in the consortium blockchain network; Specifically, the logs include the request subject identifier, the unique code of the request data (data type number + generation timestamp + random sequence), access time, operation type, risk level, encryption identifier (encryption algorithm type, key version number) and anomaly marker (0 = no anomaly, 1 = anomaly), ensuring that the data can be uniquely located and the operation is traceable.
[0021] Logs are processed by standardizing the field order as follows: request subject identifier, unique code of request data, access time, operation type, risk level, encryption identifier, and exception marker. Then, the SHA-384 algorithm is used to generate hash values to avoid inconsistencies in hash values caused by differences in field order.
[0022] The consortium blockchain has four nodes: a data provider, a user, a storage provider, and a regulatory body. When storing hash values, a smart contract is initiated: first, it verifies whether the hash value conforms to the SHA-384 standard (a 128-bit hexadecimal string); then, it sends a consensus request to the four nodes. After at least three nodes confirm its validity, it is written to the ledger, generating a unique block height and transaction ID. The regulatory body queries the system by using the requesting entity's identifier, the unique code of the requested data, or the access time range. The system retrieves the consortium blockchain hash value and, by associating the transaction ID with the complete local logs, achieves end-to-end traceability. Step 6: Strategy adjustment step. Based on the anomaly detection results and historical data, trace the source and dynamically adjust the risk assessment parameter weights and anomaly monitoring model.
[0023] Step 1 includes personal authentication, which requires password complexity and two-factor authentication with a facial recognition matching rate of ≥95% against the public security identity database; institutional authentication requires uploading an authorization document with a valid electronic signature, and the system verifies the validity of the electronic signature; permission matching authentication includes whether the authentication request operation permission is within the user's permission scope, and no more than 20 data downloads at a time; credit authentication includes querying the user's historical credit score, and access is denied if the credit score is below 60.
[0024] Specifically, when the system receives a data access request containing the request subject's identifier, the requested data type, the requested operation type (read, download, or modify), and the requested device hardware information, it immediately triggers a multi-dimensional authentication process. This process requires simultaneous verification through three types of authentication: personal or institutional authentication, permission matching authentication, and credit authentication. If any step fails, the request is rejected. Permission matching authentication involves the system retrieving the request subject's preset permission list to verify whether the requested operation type and data type are within the authorized scope (e.g., ordinary users can only read, not modify highly sensitive data); ordinary users can download ≤ 20 data items per transaction. Credit verification includes querying the requesting entity's historical operation records for the past 90 days and its credit score. The initial credit score is 70 points, ranging from 0 to 100 points. A credit score of ≥60 points is considered passing. If there are abnormal operation records within the past 7 days, such as those that have triggered data integrity alerts, additional manual review and confirmation are required.
[0025] The formula for calculating the network risk value in step 2 is: Among them, the R network risk value, For network data sensitive parameters, For network environment parameters, For network behavior parameters, , , These are the weighting coefficients, and =1.
[0026] Specifically, the network data sensitivity parameters are determined based on the confidentiality level of the requested data and the potential impact of its leakage. Core sensitive data corresponds to high parameter values of 80-100, while ordinary non-sensitive data corresponds to low parameter values of 30-60. For example, an ID card number corresponds to a parameter value of 100, while a regular operation log corresponds to a parameter value of 30. Network environment parameters: Parameter values start at 0 and are added as conditions are met. Public network transmission adds 30 points, private network transmission adds no points. A deviation of more than 100km between the request source's geographical location and the requester's commonly used geographical location adds 20 points; otherwise, no points are added. Request time outside of working hours: 8:00-22:00 for individual users or 9:00-18:00 for institutional users adds 20 points; no points are added during working hours. Network behavior parameters: The parameter value is initially 0, and it will be added if the conditions are met. Request frequency in the past 24 hours: If it exceeds the request subject's historical daily average number of requests by 1, add 30 points; if it does not exceed, no points will be added. Device matching degree: Log in using an unfamiliar device, add 30 points; log in using a commonly used device, no points will be added.
[0027] The quantum key in step 3 is generated by the QKD-2000 device and transmitted using the BB84 protocol. When quantum state collapse is detected, it is considered abnormal behavior, and the transmission is immediately terminated and the key is regenerated.
[0028] Specifically, the core security guarantee of graded encryption is to clearly define the source of quantum key generation, transmission protocol, and anomaly response mechanism. Quantum keys are generated using the QKD-2000 device, ensuring they are resistant to quantum computing, thus solving the problem of traditional keys being easily cracked by computing power. The BB84 protocol is used for transmission, leveraging the no-cloning principle of quantum states to achieve absolute security in key transmission. Simultaneously, quantum states are monitored in real time. If quantum state collapse is detected, indicating anomalies such as eavesdropping, transmission is immediately terminated and a new key is generated. This effectively prevents eavesdroppers from obtaining the key, avoiding the decryption of encrypted data. This provides underlying security support for medium- to high-risk data encryption, ensuring that the encryption strength and transmission security of data at different risk levels are commensurate.
[0029] In step 4, the anomaly monitoring step uses a sliding window algorithm to monitor the transmission rate, with a normal range of 1-10 MB / s. An alarm is triggered if the rate exceeds 30 MB / s or falls below 0.5 MB / s. An LSTM neural network model is used to detect abnormal transmission patterns. The hash value of the data packets during transmission is calculated in real time for integrity verification.
[0030] Specifically, a sliding window algorithm is used to set the window size to 60 seconds, and the average transmission rate within the window is calculated every 5 seconds. The normal range of data transmission rate is 1-10MB / s. If the average transmission rate is >30MB / s (which may be abnormal behavior such as batch data theft) or <0.5MB / s (which may be transmission link hijacking), an abnormal transmission rate alarm will be triggered immediately. The system counts the number of transmission link switches within 10 minutes. A link stability anomaly alarm is triggered when the number of switches is ≥3. Simultaneously, an LSTM neural network model is used to analyze transmission behavior characteristics. The model training samples include normal transmission patterns and historical abnormal transmission patterns, and the samples are updated weekly. The model identifies unconventional transmission patterns in real time and predicts link security risks in advance. The SM3 hash algorithm is used to calculate the hash value of each data packet during transmission in real time and compare it with the baseline SM3 hash value preset by the data sender. If the difference between the two is greater than 1%, it is determined that the data has been tampered with or lost, and a data integrity abnormality alarm is triggered.
[0031] Step 5, the blockchain evidence storage step, includes a consortium blockchain network comprising four nodes, deployed on the data provider, user, storage provider, and regulator respectively; when the hash value is stored on the consortium blockchain network, at least three nodes must reach a consensus, and a smart contract is used to verify the consistency of the hash value.
[0032] Specifically, the consortium blockchain network comprises four core nodes, deployed at the data provider, data user, data storage provider, and regulatory body, respectively. When storing a hash value on the consortium blockchain, a smart contract must be initiated to perform consensus verification: the smart contract first verifies whether the hash value format conforms to the SHA-384 algorithm's output specification of a 128-bit hexadecimal string, and then sends a consensus request to the four nodes. Only after at least three nodes return a valid confirmation response can the hash value be written to the consortium blockchain ledger. After writing, a unique block height and transaction ID are generated for subsequent traceability and location. In step 6, the anomaly detection model is calculated as follows: Where P is the anomaly detection accuracy, P Y P represents the number of anomalies correctly detected. Z This represents the total number of anomaly detections. When an anomaly is detected, update the training samples used to detect anomalies in the anomaly monitoring step; when the proportion of high-risk operations exceeds 15%, adjust the parameter weights in the dynamic risk assessment step.
[0033] Specifically, calculate the anomaly detection accuracy P; when P < 95%, update the training samples of the LSTM neural network model in step 4, add the latest anomaly transmission mode, such as fragmented data theft features under normal rate, and optimize the model recognition accuracy. Weekly statistics are compiled on the percentage of high-risk operations (number of high-risk operations / total number of operations within the period). When the percentage exceeds 15%, the risk assessment weight coefficients in step 2 are adjusted to increase the impact of network data sensitivity parameters on the risk value and strengthen the protection of highly sensitive data. If high-risk operations are mainly caused by data-sensitive factors, the α weight is increased; if mainly caused by environmental risk factors, the β weight is increased; if mainly caused by behavioral risk factors, the γ weight is increased. The adjusted parameters and model are synchronized to the risk assessment module and anomaly monitoring module and take effect immediately. Optimized records are stored in the blockchain evidence storage module to form a closed loop for strategy optimization.
[0034] This also includes credit scores that are dynamically updated based on the risk assessment results of each transaction. The credit score calculation formula is: S1 is the new credit score, and S is the original credit score. When the network risk value R of a single operation exceeds 80 points, the credit score will be directly reduced by 20 points.
[0035] Specifically, this section establishes a security operation-credit scoring linkage mechanism, which is a long-term security measure to constrain user behavior. The credit scoring formula combines historical credit with the risk of the current operation, so that the score can reflect the user's security behavior performance; when the network risk value R of a single operation exceeds 80 points, it is directly reduced by 20 points, which forms a strong constraint on high-risk operations.
[0036] Dynamically updated credit scores can be applied to credit authentication in step 1. Users with low scores will have their access restricted, guiding users to operate in a standardized manner and reducing high-risk behaviors. At the same time, the credit scoring system can screen trustworthy users, reduce the authentication complexity of trustworthy users, and improve the access efficiency of compliant users while ensuring security, achieving the dual effect of security constraints and efficiency optimization.
[0037] Network data sensitivity parameters are determined based on the confidentiality level of the data and the scope of impact of leakage. Core sensitive data corresponds to higher parameter values, while ordinary non-sensitive data corresponds to lower parameter values. Network environment parameters are calculated based on network protocol type, request source geographical location, and request time. Network behavior parameters are based on request frequency and device matching degree. When logging in using an unfamiliar device, the parameter values increase. Parameter values are collected in real time at a frequency of once per second. The initial values of the weighting coefficients are α = 0.4, β = 0.3, and γ = 0.3.
[0038] The platform includes an identity verification module that performs multidimensional identity verification; a risk assessment module that calculates risk values and determines risk levels; an encryption processing module that executes tiered encryption strategies; an anomaly monitoring module that monitors the data access process in real time; a blockchain evidence storage module that manages the storage of operation logs; a policy management module that adjusts system parameters and updates models; and a credit management module that calculates credit scores and stores historical credit data. All modules exchange data through a communication unit and adopt a unified API interface specification.
[0039] Specifically, the identity verification module includes a personal authentication unit, an institutional authentication unit, a permission matching unit, and a credit query unit. The personal authentication unit performs password complexity verification, facial recognition comparison, and secondary verification of unfamiliar devices; the institutional authentication unit verifies the validity period and hash value of the electronic signature; the permission matching unit checks the permission list and the number of downloads per transaction; and the credit query unit retrieves historical credit scores and abnormal records. This module outputs the identity verification result and a trustworthiness indicator.
[0040] The risk assessment module includes a parameter acquisition unit, a risk calculation unit, and a risk level determination unit. The parameter acquisition unit collects network data sensitive parameters, network environment parameters, and network behavior parameters at a frequency of once per second; the risk calculation unit executes... The module performs a weighted calculation and classifies risk levels into low, medium, and high risk categories. It outputs a risk assessment report and risk labels.
[0041] The encryption processing module includes an SM4 encryption unit, a quantum key management unit, a key transmission unit, and an encryption strategy adaptation unit. The SM4 encryption unit performs SM4 symmetric encryption; the quantum key management unit interacts with the QKD-2000 device to generate, update, and destroy quantum keys; the key transmission unit transmits quantum keys via the BB84 protocol; and the encryption strategy adaptation unit selects the encryption method based on the risk level. This module outputs encrypted data and an encryption identifier.
[0042] The anomaly monitoring module comprises a rate monitoring unit, a link detection unit, an integrity verification unit, and an anomaly response unit. The rate monitoring unit runs a sliding window algorithm; the link detection unit counts link switching counts and runs an LSTM model; the integrity verification unit calculates and compares SM3 hash values; and the anomaly response unit performs interruption transmission, locks the key, and sends alarms. This module outputs anomaly logs and monitoring results.
[0043] The blockchain evidence storage module includes a log generation unit, a hash calculation unit, a consortium blockchain interaction unit, and a traceability query unit. The log generation unit creates a complete operation log; the hash calculation unit generates SHA-384 hash values; the consortium blockchain interaction unit communicates with the four nodes and performs consensus verification; and the traceability query unit supports log querying and export. This module outputs evidence storage results and anomaly tracing reports.
[0044] The strategy management module includes a data statistics unit, a parameter tuning unit, a model optimization unit, and a strategy synchronization unit. The data statistics unit calculates the anomaly detection accuracy and the proportion of high-risk operations; the parameter tuning unit updates the risk assessment weights; the model optimization unit updates the LSTM training samples; and the strategy synchronization unit pushes the optimization results to each module. This module outputs the optimized strategy and execution list.
[0045] The credit management module includes a credit scoring calculation unit and a credit database. The credit scoring calculation unit executes... The module calculates credit scores using formulas and handles the logic for downgrading credit scores when R > 80; the credit database stores historical credit scores and update records. This module provides credit data support for the identity verification module.
[0046] The above are merely embodiments of the present invention. The circuits, electronic components, and modules involved are all prior art, fully achievable by those skilled in the art, and require no further explanation. The scope of protection in this application does not involve improvements to the software and methods. Commonly known structures and characteristics in the solutions are not described in detail here. Those skilled in the art are aware of all common technical knowledge in the field prior to the application date or priority date, are aware of all prior art in that field, and have the ability to apply conventional experimental methods prior to that date. Those skilled in the art can, under the guidance of this application, improve and implement this solution in combination with their own capabilities. Some typical known structures or methods should not be obstacles for those skilled in the art to implement this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the structure of the present invention. These should also be considered within the scope of protection of the present invention, and will not affect the effectiveness of the implementation of the present invention or the practicality of the patent.
Claims
1. A method for secure network data processing, characterized in that: It includes the following specific steps: Step 1: Upon receiving a data access request, trigger multi-dimensional authentication, which includes personal or institutional authentication, permission matching authentication, and credit authentication; Step 2: After passing multi-dimensional authentication, according to the dynamic risk assessment step, extract the data access request, generate network data sensitive parameters, network environment parameters, and network behavior parameters, generate a network risk value based on the parameters, and divide the risk levels into low (0<R<30), medium (31<R<60), and high (61<R<100) according to the network risk value R; Step 3: According to the risk level, perform network data hierarchical encryption steps. For low risks, use the SM4 algorithm for data encryption; for medium risks, use the SM4+256-bit quantum key for data encryption; for high risks, use the SM4+512-bit quantum key for data encryption and bind the hardware characteristics of the requesting device; Step 4: During the data access process, perform an abnormal monitoring step, use a sliding window algorithm to monitor the transmission rate, detect the link stability, verify the data integrity, and detect abnormal access and alarm; Step 5: When the data access is completed, perform the blockchain evidence storage step, generate an operation log, including access time, operation type, and risk level information; use the SHA-384 algorithm to generate a hash value and store the hash value in the consortium chain network; Step 6: Policy adjustment step, trace back according to the abnormal detection results and historical data, and dynamically adjust the weight of risk assessment parameters and the abnormal detection model.
2. The network data security processing method as described in claim 1, characterized in that: In Step 1, personal authentication includes password complexity requirements and two-factor authentication with a face recognition and comparison match degree of ≥95% with the public security identity database; institutional authentication requires uploading an authorized document with a valid electronic signature, and the system verifies the validity of the electronic signature; Permission matching authentication includes verifying whether the authentication request operation permission is within the user's permission range and that the single data download does not exceed 20 items; Credit authentication includes querying the user's historical credit score, and rejecting access when the credit score is lower than 60; 3. The network data security processing method as described in claim 1, characterized in that: The calculation formula for the network risk value in Step 2 is: Among them, the R network risk value, For network data sensitive parameters, For network environment parameters, For network behavior parameters, , , These are the weighting coefficients, and =1.
4. The network data security processing method as described in claim 1, characterized in that: The quantum key in Step 3 is generated by a QKD-2000 device, transmitted using the BB84 protocol, and when a quantum state collapse is detected, which is an abnormal behavior, the transmission is immediately terminated and a new key is generated.
5. The network data security processing method as described in claim 1, characterized in that: In Step 4, the abnormal monitoring step uses a sliding window algorithm to monitor the transmission rate, with the normal range being 1-10MB / s, triggering an alarm when it exceeds 30MB / s or is lower than 0.5MB / s; uses an LSTM neural network model to detect abnormal transmission patterns; and calculates the hash value of the data packet in real time during the transmission for integrity verification.
6. The network data security processing method as described in claim 1, characterized in that: The blockchain evidence storage step in Step 5 includes that the consortium chain network contains 4 nodes, which are respectively deployed at the data provider, user, storage party, and regulatory party; when the hash value is stored in the consortium chain network, at least 3 nodes need to reach a consensus, and a smart contract is used to verify the consistency of the hash value.
7. A network data security processing method as described in claim 1, characterized in that: The calculation of the abnormal detection model in Step 6 is Where P is the anomaly detection accuracy, P Y P represents the number of anomalies correctly detected. Z This represents the total number of anomaly detections. When an anomaly is detected, update the training samples used to detect anomalies in the anomaly monitoring step; when the proportion of high-risk operations exceeds 15%, adjust the parameter weights in the dynamic risk assessment step.
8. A network data security processing method as described in claim 2, characterized in that: It also includes that the credit score is dynamically updated according to the risk assessment results of each operation, and the calculation formula for the credit score is: S1 is the new credit score, and S is the original credit score. When the network risk value R of a single operation exceeds 80 points, the credit score will be directly reduced by 20 points.
9. A network data security processing method as described in claim 3, characterized in that: The network data sensitivity parameters are determined based on the confidentiality level of the data and the scope of impact of leakage. Core sensitive data corresponds to higher parameter values, while ordinary non-sensitive data corresponds to lower parameter values. Network environment parameters are calculated based on network protocol type, request source geographical location, and request time. Network behavior parameters are calculated based on request frequency and device matching degree. When logging in using an unfamiliar device, the parameter values increase. The parameter values are collected in real time at a frequency of once per second. The initial values of the weighting coefficients are α = 0.4, β = 0.3, and γ = 0.
3.
10. A network data security processing platform, applicable to the network data security processing method as described in claims 1-9, characterized in that: The platform includes an authentication module that performs multidimensional authentication. The risk assessment module calculates risk values and determines risk levels. The encryption processing module executes a hierarchical encryption strategy. The anomaly monitoring module monitors the data access process in real time. The blockchain-based evidence storage module manages the storage of operation logs; the strategy management module adjusts system parameters and updates models; and the credit management module calculates credit scores and stores historical credit data. Each module exchanges data through a communication unit, using a unified API interface specification.
Citation Information
Cited By
Multi-tenant data isolation and sharing method and system in SaaS mode
CN121690804A
ESIM card security encryption data transmission system
CN121728451A