U disk encryption communication method, system and device based on terminal identity authentication and medium

By constructing a security risk matrix and a comprehensive security scoring mechanism, the problems of insufficient terminal security status perception and single risk assessment in existing U-shield encrypted communication technologies have been solved. This enables multi-dimensional risk assessment and accurate identification of terminal processes and network behavior, thereby improving the security and adaptability of encrypted communication.

CN121309227BActive Publication Date: 2026-04-21YUNNAN POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YUNNAN POWER GRID CO LTD
Filing Date
2025-12-11
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing U-shield encrypted communication technology suffers from insufficient terminal security status awareness, poor adaptability of encryption strategies, and a single risk assessment dimension in terms of terminal identity authentication. It cannot effectively deal with advanced persistent threats and insider threats, and lacks the ability to analyze the correlation between terminal process behavior and network access behavior.

Method used

By comparing the terminal's running process data with the security process baseline, and combining network access data for anomaly analysis, a security risk matrix is ​​constructed, a comprehensive security score for the terminal is calculated, and differentiated U-shield encrypted communication strategies are formulated based on the score.

Benefits of technology

It enables accurate detection of terminal security status and multi-dimensional risk assessment, timely identification of malicious processes and network attacks, improves the security and protection capabilities of encrypted communication, and avoids the problems of over-protection or under-protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309227B_ABST
    Figure CN121309227B_ABST
Patent Text Reader

Abstract

This invention discloses a U-shield encrypted communication method, system, device, and medium based on terminal identity authentication, belonging to the field of encrypted communication technology. The method includes: acquiring terminal running process data; comparing the running process data with a secure process baseline to obtain a process baseline deviation; acquiring the terminal's network access data based on the process baseline deviation; performing network anomaly analysis on the network access data to obtain a network anomaly metric; constructing a security risk matrix based on the process baseline deviation and the network anomaly metric; and calculating a comprehensive terminal security score based on the security risk matrix; and formulating a U-shield encrypted communication strategy based on the comprehensive terminal security score. The beneficial effect of this invention is that by constructing a security risk matrix to integrate and calculate process security status and network security status, it achieves a comprehensive quantitative assessment of multi-dimensional risks and accurate identification of complex threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of encrypted communication technology, specifically to a U-shield encrypted communication method, system, device, and medium based on terminal identity authentication. Background Technology

[0002] Traditional USB keys, as hardware security tokens, use built-in encryption chips and digital certificates to achieve user authentication and encrypted data transmission. Existing USB key encryption communication technology is primarily based on Public Key Infrastructure (PKI), employing asymmetric encryption algorithms for key negotiation and digital signatures, combined with symmetric encryption algorithms to protect data confidentiality. Simultaneously, terminal access control technology ensures that only compliant terminal devices can access the enterprise network through terminal device authentication, security status detection, and access control management. Current mainstream terminal access control solutions include certificate-based device authentication, agent-based terminal monitoring, and network access control-based access management methods, enhancing network access security.

[0003] However, existing USB key encrypted communication technologies have several shortcomings in terminal authentication. First, traditional USB key authentication mechanisms lack the ability to assess the security of the terminal's operating environment and cannot detect security threats such as abnormal terminal processes and malware intrusions in real time. This means that even if the terminal has been maliciously controlled, the USB key can still be illegally used for encrypted communication. Second, existing USB key encryption communication strategies typically use a static configuration mode, which cannot be adjusted according to the terminal's real-time security status and network behavior characteristics. This results in a lack of effective protection against Advanced Persistent Threat (APT) attacks and insider threats. Furthermore, traditional solutions lack organic integration between terminal access control and USB key encrypted communication, failing to build a unified security strategy framework based on risk assessment. This leads to fragmented security protection measures and an inability to form a defense-in-depth system. Finally, existing network anomaly detection technologies mostly use single-dimensional feature analysis and lack the ability to correlate terminal process behavior with network access behavior, making it difficult to accurately identify security threat patterns. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by this invention is: how to address the shortcomings of existing U-shield encrypted communication technologies, such as insufficient terminal security status perception, poor adaptability of encryption strategies, and single risk assessment dimensions, by using a fusion assessment mechanism of terminal process behavior monitoring and network access pattern analysis to achieve U-shield encrypted communication strategy adjustment based on security risk assessment, improve the accuracy of terminal access control, and provide multi-dimensional security protection, while suppressing the impact of changes in terminal security status on the availability of encrypted communication.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a U-shield encrypted communication method based on terminal identity authentication, comprising,

[0007] The process involves acquiring the terminal's running process data, comparing it with a secure process baseline to obtain the process baseline deviation, acquiring the terminal's network access data based on the process baseline deviation, performing network anomaly analysis on the network access data to obtain a network anomaly metric, constructing a security risk matrix based on the process baseline deviation and the network anomaly metric, and calculating a comprehensive security score for the terminal based on the security risk matrix, and formulating a U-shield encrypted communication strategy based on the comprehensive security score for the terminal.

[0008] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the following steps are taken: comparing the running process data with the secure process baseline to obtain the process baseline deviation includes: obtaining a process number deviation value by comparing the current total number of processes in the running process data with the baseline number of processes in the secure process baseline; obtaining a process behavior pattern deviation value by comparing the current process behavior characteristics in the running process data with the baseline behavior pattern in the secure process baseline; and calculating the process number deviation value and the process behavior pattern deviation value according to a preset weighting coefficient to obtain the process baseline deviation.

[0009] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the method for obtaining network access data of the terminal based on the process baseline deviation includes: comparing the process baseline deviation with a preset risk threshold; if the process baseline deviation does not exceed the preset risk threshold, then the acquisition of network access data of the terminal is not performed; if the process baseline deviation exceeds the preset risk threshold, then the network access data of the terminal is collected, wherein the network access data includes network connection records, data transmission volume, and access domain name information.

[0010] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the following steps are performed: network anomaly analysis is conducted on the network access data to obtain a network anomaly metric, including: feature extraction of the network access data to obtain connection frequency features, traffic distribution features, and access pattern features; deviation calculation is performed between the connection frequency features, traffic distribution features, and access pattern features and the normal network behavior baseline to obtain the degree of network behavior deviation; and anomaly detection algorithm is used to quantify the degree of network behavior deviation to obtain the network anomaly metric.

[0011] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the following steps are included: constructing a security risk matrix based on the process baseline deviation and the network anomaly metric, comprising: establishing a two-dimensional risk coordinate system with the process baseline deviation as the first dimension and the network anomaly metric as the second dimension; mapping the process baseline deviation and the network anomaly metric as risk coordinate points into the two-dimensional risk coordinate system; and determining the risk level region of the terminal based on the position of the risk coordinate points in the two-dimensional risk coordinate system.

[0012] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the following steps are performed: calculating a comprehensive security score for the terminal based on the security risk matrix, including: determining the basic risk coefficient of the terminal based on the risk level region of the terminal; calculating a risk adjustment value by combining the process baseline deviation and the network anomaly metric; and obtaining the comprehensive security score for the terminal by comprehensively calculating the basic risk coefficient and the risk adjustment value.

[0013] As a preferred embodiment of the U-shield encrypted communication method based on terminal identity authentication described in this invention, the U-shield encrypted communication strategy is formulated based on the terminal's comprehensive security score, including: comparing the terminal's comprehensive security score with a security level threshold to obtain the terminal's security level; determining the terminal's authentication strength parameter and encryption strength parameter based on the terminal's security level; determining the number of verifications and verification method for U-shield identity authentication based on the authentication strength parameter; and determining the encryption algorithm type and key length based on the encryption strength parameter.

[0014] This invention provides a U-shield encrypted communication system based on terminal identity authentication.

[0015] To address the aforementioned technical problems, this invention provides the following technical solution: a U-shield encrypted communication system based on terminal identity authentication, comprising: a terminal access control module, used to acquire the terminal's running process data, compare the running process data with a security process baseline, and obtain the process baseline deviation; a network access control module, used to acquire the terminal's network access data based on the process baseline deviation, perform network anomaly analysis on the network access data, and obtain a network anomaly metric; a security scoring module, used to construct a security risk matrix based on the process baseline deviation and the network anomaly metric, and calculate a comprehensive terminal security score based on the security risk matrix; and an encrypted communication module, used to formulate a U-shield encrypted communication strategy based on the comprehensive terminal security score.

[0016] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the U-shield encrypted communication method based on terminal identity authentication.

[0017] The present invention provides a computer-readable storage medium having a computer program stored thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the U-shield encrypted communication method based on terminal identity authentication.

[0018] The beneficial effects of this invention are as follows: By acquiring terminal running process data and quantitatively comparing it with a security process baseline, this invention achieves accurate detection and numerical evaluation of the security status of the terminal process environment. It can promptly identify malicious processes and abnormal behavior patterns such as keyloggers and screen capture tools, laying a reliable data foundation for subsequent multi-dimensional risk assessment. Through a conditional triggering mechanism based on process baseline deviation, it acquires network access data and performs multi-feature anomaly analysis, achieving intelligent allocation of computing resources and accurate identification of network threats. This avoids the system load caused by continuous full-network monitoring. Furthermore, through comprehensive analysis of connection frequency, traffic distribution, and access patterns, it accurately captures concealed network attack behaviors, improving security. The system improves the efficiency and accuracy of network-level threat detection. By constructing a security risk matrix to integrate process security status and network security status, it achieves comprehensive quantitative assessment of multi-dimensional risks and accurate identification of composite threats. In particular, the risk interaction item effectively detects the synergistic amplification effect of process risks and network risks, solving the problem of missing related risks in single-dimensional assessments. By formulating differentiated U-shield encrypted communication strategies based on the terminal's comprehensive security score, it achieves security protection and intelligent policy adjustment based on real-time risk assessment. It can accurately match authentication strength and encryption level according to the actual security status of the terminal, ensuring security protection in high-risk environments while avoiding over-protection in low-risk environments. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 The above is an overall flowchart of a U-shield encrypted communication method based on terminal identity authentication provided in one embodiment of the present invention.

[0021] Figure 2 This is a schematic diagram of the risk level area of ​​a terminal provided in one embodiment of the present invention. Detailed Implementation

[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0023] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0024] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0025] Example 1, referring to Figure 1 This is one embodiment of the present invention, which provides a U-shield encrypted communication method based on terminal identity authentication, including:

[0026] S100: Obtain the running process data of the terminal, compare the running process data with the security process baseline, and obtain the process baseline deviation.

[0027] S200: Obtains network access data of the terminal based on process baseline deviation, performs network anomaly analysis on the network access data, and obtains network anomaly measurement values.

[0028] S300: Construct a security risk matrix based on process baseline deviation and network anomaly metrics, and calculate the terminal's comprehensive security score based on the security risk matrix.

[0029] S400: Formulate U-shield encrypted communication strategy based on terminal comprehensive security score.

[0030] It should be noted that enterprise terminal devices face various security threats in the network environment, including malware infection, abnormal process execution, and network attacks. These risks can cause changes in the terminal's security status, affecting the security and reliability of U-shield encrypted communication. Traditional U-shield encrypted communication methods use static security policies and cannot detect changes in the terminal's security status in real time. This means that even if the terminal has been maliciously controlled or has security vulnerabilities, the same encryption strength and authentication method may still be used for communication, posing a risk of exploitation by attackers. At the same time, due to the lack of comprehensive analysis of terminal process behavior and network access patterns, existing methods are unable to accurately identify security threats, and inaccurate risk assessments can lead to security protection failures.

[0031] Therefore, to address the aforementioned issues of terminal security awareness and encryption strategy adaptation, steps S100-S400 are used to conduct a comprehensive security score and risk level assessment of the terminal based on a dual-dimensional security risk assessment of process behavior and network access, thereby achieving an accurate assessment of the terminal's security status. Authentication strength and encryption parameters are configured according to the security score to adjust the U-shield encrypted communication strategy, enhancing protection capabilities. Simultaneously, based on a security risk matrix and multi-dimensional risk quantification, precise identification and early warning of terminal security threats are achieved.

[0032] Example 2, refer to Figure 1 and Figure 2 As an embodiment of the present invention, based on the previous embodiment, a U-shield encrypted communication method based on terminal identity authentication is provided, including:

[0033] In this embodiment of the invention, the running process data of the terminal obtained in step S100 includes the process identifier (PID), process name, CPU utilization, memory usage and process start time of all processes currently running on the terminal.

[0034] Furthermore, in step S100, the running process data is compared with the safety process baseline to obtain the process baseline deviation, including the following steps A1-A3:

[0035] A1: The process number deviation value is obtained by comparing the current total number of processes in the running process data with the baseline number of processes in the safe process baseline. The process number deviation value can be specifically expressed as:

[0036] ;

[0037] in, This represents the deviation value of the number of processes; This represents the total number of processes currently running in the terminal. The number of baseline processes set in the security process baseline.

[0038] It should be noted that when establishing a secure process baseline, process data of the terminal under normal operating conditions for several consecutive days can be collected, and statistical analysis can be performed to obtain the mean and variance of the baseline number of processes. At the same time, the standard CPU utilization and memory usage range of core system processes can be recorded, thereby forming a secure process baseline that includes a whitelist process library and resource usage thresholds.

[0039] A2: By comparing the current process behavior characteristics of the running process data with the baseline behavior pattern in the safe process baseline, the process behavior pattern deviation value is obtained. The process behavior pattern deviation value can be specifically expressed as:

[0040] ;

[0041] in, This represents the deviation value of the process behavior pattern. For the first The current CPU utilization of each process; For the first The baseline CPU utilization of each process in the safe process baseline; For the first The current memory usage of each process; For the first The baseline memory usage of each process in the safe process baseline; The number of processes monitored by the CPU; This represents the number of processes being monitored for memory.

[0042] A3: Based on the preset weighting coefficients, calculate the process quantity deviation value and the process behavior pattern deviation value to obtain the process baseline deviation.

[0043] Furthermore, in step A3, based on preset weighting coefficients, the deviation values ​​of the number of processes and the deviation values ​​of the process behavior patterns are calculated to obtain the process baseline deviation, which can be specifically expressed as:

[0044] ;

[0045] in, The deviation from the process baseline; This represents the deviation value of the number of processes; This represents the deviation value of the process behavior pattern. The weighting coefficient for the deviation value of the number of processes; The weighting coefficients for the deviation values ​​of process behavior patterns. and .

[0046] For example, when calculating the process baseline deviation, the weighting coefficient and The settings can be adjusted according to the terminal type and security level requirements. For example, for high-security financial terminals, the weighting coefficient of the process number deviation value can be adjusted. It can be set to 0.3, the weight of the process behavior pattern deviation value. It can be set to 0.7 to place greater emphasis on detecting abnormal process behavior; for general office terminals, a weighting coefficient can be set. To maintain a balance between process count and behavior pattern monitoring; for server terminals, where process count changes more frequently, weighting coefficients can be set. The focus is on the stability of process behavior; for mobile office terminals, considering the frequent application switching, a weighting coefficient can be set. Appropriately increase the tolerance for changes in the number of processes; the adjustment range of the weight coefficient is usually kept between 0.1 and 0.9 to ensure that both dimensions can play a role and avoid a single indicator dominating the deviation calculation results.

[0047] It should be noted that this invention acquires complete process information of the terminal in real time and quantitatively compares it with a preset security baseline. It quantifies abnormal process quantity and abnormal behavior patterns into numerical indicators and comprehensively evaluates the security status of the terminal process environment through a weighted fusion mechanism. Compared with the existing technology that relies solely on simple process blacklist and whitelist checks, this invention solves the problem that traditional methods are difficult to identify abnormal process behavior and abnormal resource usage by establishing a multi-dimensional process baseline comparison mechanism. In particular, by monitoring CPU utilization and memory usage, it can discover hidden malicious processes and resource abuse behaviors, ensuring the accuracy and reliability of subsequent network monitoring trigger conditions. This not only improves the comprehensiveness of terminal environment security detection but also provides accurate risk assessment basis for network analysis based on process deviation, effectively preventing U-shield authentication operations under insecure process environments.

[0048] In this embodiment of the invention, step S200, which involves obtaining network access data of the terminal based on process baseline deviation, includes the following steps B1-B2:

[0049] B1: Compare the process baseline deviation with the preset risk threshold. If the process baseline deviation does not exceed the preset risk threshold, then the terminal's network access data will not be acquired.

[0050] B2: If the process baseline deviation exceeds the preset risk threshold, the terminal's network access data will be collected. The network access data includes network connection records, data transmission volume, and access domain name information.

[0051] For example, when obtaining network access data of a terminal based on process baseline deviation, a preset risk threshold is used. The settings can be configured hierarchically according to the terminal application scenario and security level. For example, for financial trading terminals, risk thresholds can be set. This enables low-threshold, high-sensitivity monitoring; for general office terminals, risk thresholds can be set. To maintain a balance between security and performance; for development and testing terminals, risk thresholds can be set. This allows for a wider range of process variations.

[0052] In this embodiment of the invention, step S200 involves performing network anomaly analysis on network access data to obtain network anomaly metrics, including the following steps B3-B5:

[0053] B3: Perform feature extraction on network access data to obtain connection frequency features, traffic distribution features, and access pattern features. Specifically, the extracted connection frequency feature can be represented as follows:

[0054] ;

[0055] in, For connection frequency characteristic values; This represents the total number of network connections within the data acquisition time window. This is the length of the data acquisition time window, in seconds, and is typically set between 60 and 300 seconds to ensure that complete network behavior patterns can be captured.

[0056] The extracted flow distribution characteristics can be specifically represented as:

[0057] ;

[0058] in, These are characteristic values ​​of the flow distribution. For the first The amount of data transmitted per network connection, in bytes; This is the length of the data acquisition time window, in seconds. This represents the total number of network connections.

[0059] The extraction of access pattern features can be specifically represented as follows:

[0060] ;

[0061] in, Access pattern feature value; For the first Information entropy of a visited domain name , For domain name The The probability of a certain type of access behavior; The number of different domains accessed.

[0062] B4: Based on the characteristics of connection frequency, traffic distribution, and access patterns, the deviation from the normal network behavior baseline is calculated to obtain the degree of network behavior deviation. The degree of network behavior deviation can be specifically expressed as follows:

[0063] ;

[0064] in, The degree of deviation from online behavior; , and These are the baseline values ​​for connection frequency, traffic distribution, and access patterns in the normal network behavior baseline.

[0065] It should be noted that the establishment of a normal network behavior baseline can be achieved by collecting network access data of terminals under normal working conditions for several consecutive days, statistically analyzing network behavior patterns during working and non-working hours, calculating the mean, variance, and quantile distribution of connection frequency, traffic distribution, and access patterns, and recording commonly used domain name whitelists, standard data transmission volume ranges, and typical access timing patterns. This forms a normal network behavior baseline that includes a normal access domain name database, traffic threshold ranges, and timing behavior patterns. The baseline value is calculated using the median method to reduce the impact of outliers on the accuracy of the baseline.

[0066] B5: Use anomaly detection algorithms to quantify the degree of deviation of network behavior and obtain network anomaly measurement values.

[0067] Furthermore, in step B5, the anomaly detection algorithm is used to quantify the degree of deviation of network behavior, resulting in a network anomaly metric. This metric is obtained by using the Z-score standardization method based on statistical analysis. The degree of anomaly is quantified by calculating the standardized deviation of the network behavior deviation relative to the normal baseline distribution. Specifically, the network anomaly metric can be expressed as follows:

[0068] ;

[0069] in, This is a measure of network anomalies. The degree of deviation from online behavior; This represents the average degree of deviation from normal network behavior. This represents the standard deviation of the degree of deviation from normal network behavior.

[0070] It should be noted that this invention achieves optimized allocation of computing resources and accurate anomaly detection by establishing a process deviation-driven network monitoring trigger mechanism. Through multi-dimensional network feature extraction and standardized deviation calculation, network behavior patterns are transformed into quantifiable anomaly metrics. Compared with the existing technology of continuously monitoring all network traffic, this invention solves the problems of excessive system resource consumption and high false alarm rate in traditional methods through a conditional trigger mechanism. In particular, the comprehensive analysis of three dimensions—connection frequency, traffic distribution, and access patterns—can accurately identify covert network attack behaviors and abnormal access patterns, ensuring that deep network analysis is only initiated when there is a risk in the process environment. This not only improves detection efficiency and accuracy but also provides high-quality network risk assessment data for subsequent security risk matrix construction, effectively avoiding resource waste and improving overall response speed.

[0071] In this embodiment of the invention, step S300, which constructs a security risk matrix based on process baseline deviation and network anomaly metrics, includes the following steps C1-C3:

[0072] C1: Establish a two-dimensional risk coordinate system with process baseline deviation as the first dimension and network anomaly metric as the second dimension.

[0073] Specifically, a two-dimensional risk coordinate system is established, with the process baseline deviation as the first dimension and the network anomaly metric as the second dimension, including:

[0074] A Cartesian coordinate system is established by setting the process baseline deviation as the X-axis and the network anomaly metric as the Y-axis. The coordinate system is divided into different risk level zones according to the degree of risk.

[0075] C2: The process baseline deviation and network anomaly metric are used as risk coordinate points and mapped to a two-dimensional risk coordinate system.

[0076] C3: Determine the risk level zone of the terminal based on the position of the risk coordinate point in the two-dimensional risk coordinate system.

[0077] Specifically, such as Figure 2 The diagram shows the risk level zones of a terminal. The risk level zones of a terminal are determined based on the position of the risk coordinate points in a two-dimensional risk coordinate system, including:

[0078] When the process baseline deviation Less than or equal to the first process threshold and network anomaly metric When the risk level is less than or equal to the first network threshold, it is classified as a low-risk area.

[0079] When the process baseline deviation The value is greater than the first process threshold, less than the second process threshold, and is a network anomaly metric. If the risk level is greater than the first network threshold but less than the second network threshold, it is classified as a medium-risk area.

[0080] When the process baseline deviation Greater than or equal to the second process threshold or network anomaly metric When the value is greater than or equal to the second network threshold, it is classified as a high-risk area.

[0081] Conversely, areas with low risk are classified as medium to high risk.

[0082] It should be noted that the first and second process thresholds mentioned above can be obtained by analyzing the statistical distribution of historical normal operation data and selecting the upper quartile of the normal data distribution as the dividing point between low risk and medium risk; the second process threshold and the second network threshold can be obtained by analyzing abnormal process and network data in known security events and selecting the lower quartile of the abnormal data distribution as the dividing point between medium risk and high risk. The threshold setting also needs to take into account the differences in terminal types. By classifying and statistically analyzing security event samples of terminals in different industries and for different purposes, the threshold parameters can be adjusted to adapt to the security requirements of specific application scenarios, ensuring the accuracy and applicability of risk area division.

[0083] For example, the division of risk level zones can be set in the following manner, where the deviation of the process baseline is... Less than or equal to 0.3 and network anomaly metric When the baseline deviation is less than or equal to 1.0, it is classified as a low-risk area; when the baseline deviation is greater than 0.3 and less than 0.6, and the network anomaly metric is greater than 1.0 and less than 2.0, it is classified as a medium-risk area; when the baseline deviation is greater than or equal to 0.6 or the network anomaly metric is greater than or equal to 2.0, it is classified as a high-risk area; in addition, transitional areas are set, such as when the baseline deviation is low but the network anomaly metric is high, or when the baseline deviation is high but the network anomaly metric is low, it is classified as a medium-to-high-risk area.

[0084] In this embodiment of the invention, step S300 involves calculating a comprehensive security score for the terminal based on a security risk matrix, including the following steps C4-C6:

[0085] C4: Determine the basic risk coefficient of the terminal based on the risk level area of ​​the terminal.

[0086] Specifically, the basic risk coefficient of a terminal is determined based on its risk level region, including:

[0087] When the terminal's risk level zone is low risk, set the terminal's base risk coefficient. for .

[0088] When the terminal's risk level zone is medium risk, set the terminal's base risk coefficient. for .

[0089] When the terminal's risk level is in the medium-to-high risk zone, set the terminal's base risk coefficient. for .

[0090] When the terminal's risk level zone is a high-risk zone, set the terminal's base risk coefficient. for .

[0091] It should be noted that the aforementioned basic risk coefficients can be determined through a combination of statistical analysis of a large number of actual security incidents and expert evaluation. Specifically, the coefficients for low-risk areas are set based on the probability and impact of security incidents in that area according to historical data; the coefficients for medium-risk areas are quantitatively assessed based on the frequency of security incidents and the potential for loss within that area; the coefficients for high-risk areas are calculated based on historical statistical data of serious security incidents and risk assessment models; and the coefficients for moderately high-risk areas are determined through analysis of security incidents under single-dimensional high-risk conditions. Furthermore, considering the risk propagation mechanism and scope of impact, the coefficient settings also need to be calibrated in conjunction with industry safety standards and regulatory requirements to ensure the scientific rigor and practicality of risk quantification.

[0092] For example, when determining the basic risk coefficient of a terminal based on its risk level zone, it can be set as follows: the basic risk coefficient for a low-risk zone is 0.1, indicating that the terminal is in a relatively safe state; the basic risk coefficient for a medium-risk zone is 0.5, indicating that the terminal has certain security risks; the basic risk coefficient for a high-risk zone is 0.9, indicating that the terminal is in a high-risk state; and the basic risk coefficient for a medium-to-high-risk zone is 0.7, used to handle situations where a single dimension of risk is prominent.

[0093] C5: The risk adjustment value is calculated by combining the process baseline deviation and the network anomaly metric.

[0094] Specifically, the risk adjustment value is calculated by combining the process baseline deviation and network anomaly metric. This involves using a nonlinear risk assessment method to quantify the combined risk effect by weighting the squared terms and interaction terms of process risk and network risk. The squared term reflects the nonlinear amplification characteristics of a single risk source, while the interaction term reflects the synergistic amplification effect of the two risk sources. The risk adjustment value can be expressed as follows:

[0095] ;

[0096] in, Risk-adjusted value; , , This is a risk adjustment factor; The deviation from the process baseline; This is a measure of network anomalies.

[0097] For example, when calculating the risk-adjusted value, the risk adjustment factor... , , The settings can be adjusted according to the terminal type and security policy. For example, for financial terminals with high security requirements, the settings can be adjusted accordingly. , and It emphasizes the weight of network risks; for general office terminals, settings can be configured. , and Balancing process and network risks; for development and testing terminals, settings can be configured. , and More attention is paid to process stability; among which, the risk adjustment coefficient It is usually set between 0.05 and 0.3 to adjust the degree of synergistic amplification of process risk and network risk, and to avoid a single risk source dominating the scoring results.

[0098] C6: The overall security score of the terminal is obtained by comprehensively calculating the basic risk coefficient and the risk adjustment value.

[0099] Specifically, the comprehensive calculation using the basic risk coefficient and risk adjustment value refers to employing a linear superposition method to combine the basic risk coefficient determined based on the risk level region with the risk adjustment value calculated numerically, forming a comprehensive assessment result that reflects both the risk level and the precise numerical value. The terminal comprehensive safety score can be specifically expressed as:

[0100] ;

[0101] in, Assess the overall security score of the terminal; Basic risk coefficient; This is a risk-adjusted value.

[0102] It should be noted that this invention, by establishing a two-dimensional risk coordinate system, transforms the independent assessment of process security status and network security status into a comprehensive risk situation awareness. It achieves precise risk quantification by combining partitioned rating and numerical calculation. In particular, by introducing risk interaction terms, it can identify the synergistic amplification effect of process risk and network risk. Compared with the simple addition or independent assessment methods in existing technologies, this invention solves the problems of traditional methods failing to reflect multidimensional risk correlations and accurately assessing composite threats by constructing a security risk matrix. Specifically, the regional division method of the two-dimensional coordinate system can intuitively reflect the security situation under different risk combinations, and the nonlinear calculation of risk adjustment values ​​can accurately capture risk amplification and suppression effects. This not only improves the accuracy and comprehensiveness of security assessment but also provides a scientific quantitative basis for the subsequent formulation of U-shield encrypted communication strategies, ensuring that authentication strategies accurately match actual risk levels and effectively preventing efficiency losses due to over-protection and security risks due to insufficient protection.

[0103] In this embodiment of the invention, step S400, which involves formulating a U-shield encrypted communication strategy based on the terminal's comprehensive security score, includes the following steps D1-D3:

[0104] D1: The terminal's overall security score is compared with the security level threshold to obtain the terminal's security level.

[0105] Specifically, the terminal's overall security score is compared with the security level threshold to obtain the terminal's security level, including:

[0106] When the terminal's overall security score is less than the first security level threshold, the terminal's security level is determined to be secure, indicating that the terminal environment is trustworthy.

[0107] When the terminal's overall security score is greater than or equal to the first security level threshold but less than the second security level threshold, the terminal's security level is determined to be warning level, indicating that the terminal has potential risks.

[0108] When the terminal's overall security score is greater than or equal to the second security level threshold but less than the third security level threshold, the terminal's security level is determined to be dangerous, indicating that the terminal poses a significant threat.

[0109] When the terminal's overall security score is greater than or equal to the threshold of the third security level, the terminal's security level is determined to be emergency, indicating that the terminal is in a high-risk state.

[0110] It should be noted that the safety level thresholds can be determined in the following ways: for example, the first safety level threshold is determined by analyzing the statistical distribution of the terminal's comprehensive safety score under normal operating conditions, and selecting the upper boundary value of the normal distribution as the dividing point between safety and warning; the second safety level threshold is based on the score range corresponding to known minor safety incidents, and selecting the median of this range as the dividing point between warning and danger; the third safety level threshold is determined based on historical data of serious safety incidents and expert experience, serving as the dividing point between danger and emergency; in addition, the threshold setting also needs to be calibrated in conjunction with regulatory requirements and industry safety standards, and adjusted according to actual operating conditions and safety incident feedback to ensure the accuracy and practicality of the level classification.

[0111] D2: Determine the authentication strength parameters and encryption strength parameters of the terminal based on the terminal's security level.

[0112] Specifically, determining the authentication strength parameters of a terminal based on its security level means configuring corresponding identity verification strength requirements for different terminal security levels based on the risk level matching principle, including the number of verification factors, verification accuracy requirements, and verification timeout settings.

[0113] Specifically, determining the encryption strength parameters of a terminal based on its security level means configuring corresponding data protection strength requirements for different terminal security levels based on the principle of matching security levels, including encryption algorithm strength, key management strategy, and communication protocol security level.

[0114] D3: Based on the authentication strength parameter, specify the number of verifications and the verification method for U-shield authentication; based on the encryption strength parameter, specify the encryption algorithm type and key length.

[0115] Specifically, the number of verification attempts and verification methods for U-shield authentication are determined based on the authentication strength parameter. The specific steps can be as follows:

[0116] For security-grade terminals, a standard single-factor authentication method is used, including password verification or biometric verification. The number of verification attempts is set to one, and the verification timeout is set to the standard duration.

[0117] For warning-level terminals, a two-factor authentication method is adopted, which includes password verification combined with biometric verification. The number of verifications is set to two, and the verification timeout is shortened to a certain percentage of the standard timeout.

[0118] For high-risk terminals, a multi-factor authentication method is adopted, including a combination of password verification, biometric verification and hardware token verification. The number of verification attempts is set to multiple, and the verification timeout is set to a short duration.

[0119] For emergency-level terminals, an enhanced multi-factor authentication method is adopted, which includes a combination of all available authentication methods. The number of authentication attempts is set to the maximum, and the authentication timeout is set to the minimum duration.

[0120] Specifically, the encryption algorithm type and key length are determined based on the encryption strength parameter. The specific steps can be as follows:

[0121] For security-grade terminals, standard encryption algorithms are used, such as Advanced Encryption Standard (AES) 128-bit, with the key length set to standard length and the key update cycle set to regular cycle.

[0122] For warning-level terminals, an enhanced encryption algorithm, such as AES 192-bit, is used, the key length is set to an enhanced length, and the key update cycle is shortened to a certain proportion of the regular cycle.

[0123] For high-risk terminals, use high-strength encryption algorithms, such as AES 256-bit or the commercial cryptographic SM4 algorithm, with the key length set to the maximum length and the key update cycle set to a shorter cycle.

[0124] For emergency-level terminals, the highest strength encryption algorithm combination is used, including multiple encryption and digital signature verification, the key length is set to the maximum available length, and the key update cycle is set to the shortest cycle.

[0125] For example, the number of verifications and verification methods for U-shield authentication can be defined. The specific parameters of the number of verifications and verification methods can be finely adjusted according to user type and operation sensitivity: for ordinary users, the verification complexity can be appropriately reduced at each security level; for administrator users, the verification strength can be increased at each security level; for high-value transactions, the highest level of verification method is required regardless of the terminal security level; in addition, the verification timeout is set based on user operation habit analysis and security response time requirements, balancing the needs of user experience and security protection; the selection of encryption algorithm type and key length also needs to consider the terminal computing power and network bandwidth limitations to ensure the executability and real-time performance of the encryption strategy.

[0126] It should be noted that this invention achieves security protection based on real-time risk assessment by establishing an intelligent mapping mechanism between terminal comprehensive security scoring and U-shield encrypted communication strategy. It precisely adjusts authentication and encryption strength according to the actual security status of the terminal, avoiding the limitations of fixed security strategies. Compared with existing technologies that use unified security strategies or simple hierarchical protection, this invention solves the problem of balancing security protection and system efficiency in traditional methods by constructing a multi-dimensional security level system and refined strategy configuration. In particular, the four-level security level division and corresponding differentiated authentication and encryption strategies maximize availability while ensuring security. The combined use of key management and multi-factor authentication effectively addresses security challenges at different threat levels, not only improving the overall security level of U-shield encrypted communication but also optimizing the user experience.

[0127] In summary, this invention achieves accurate detection and numerical assessment of the security status of the terminal process environment by acquiring terminal running process data and quantitatively comparing it with a security process baseline. It can promptly identify malicious processes and abnormal behavior patterns such as keyloggers and screen capture tools, laying a reliable data foundation for subsequent multi-dimensional risk assessment. By acquiring network access data through a conditional triggering mechanism based on process baseline deviation and performing multi-feature anomaly analysis, it achieves intelligent allocation of computing resources and accurate identification of network threats, avoiding the system load caused by continuous full-network monitoring. Furthermore, through comprehensive analysis of connection frequency, traffic distribution, and access patterns, it accurately captures concealed network attack behaviors, improving network layer security. The system improves the efficiency and accuracy of threat detection; by constructing a security risk matrix to integrate process security status and network security status, it achieves comprehensive quantitative assessment of multi-dimensional risks and accurate identification of composite threats. In particular, through risk interaction items, it can effectively detect the synergistic amplification effect of process risks and network risks, solving the problem that single-dimensional assessments are prone to overlooking related risks; by formulating differentiated U-shield encrypted communication strategies based on the terminal's comprehensive security score, it achieves security protection and intelligent policy adjustment based on real-time risk assessment. It can accurately match authentication strength and encryption level according to the actual security status of the terminal, ensuring security protection in high-risk environments while avoiding over-protection in low-risk environments.

[0128] Example 3 is an embodiment of the present invention, which provides a U-shield encrypted communication system based on terminal identity authentication, including: a terminal access control module, used to acquire the terminal's running process data, compare the running process data with a security process baseline, and obtain the process baseline deviation; a network access control module, used to acquire the terminal's network access data based on the process baseline deviation, perform network anomaly analysis on the network access data, and obtain a network anomaly metric; a security scoring module, used to construct a security risk matrix based on the process baseline deviation and the network anomaly metric, and calculate a comprehensive terminal security score based on the security risk matrix; and an encrypted communication module, used to formulate a U-shield encrypted communication strategy based on the comprehensive terminal security score.

[0129] This embodiment also provides an electronic device applicable to the U-shield encrypted communication method based on terminal identity authentication, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the U-shield encrypted communication method based on terminal identity authentication as proposed in the above embodiment.

[0130] This embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements the U-shield encrypted communication method based on terminal identity authentication as proposed in the above embodiments.

[0131] The storage medium proposed in this embodiment and the U-shield encrypted communication method based on terminal identity authentication proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0132] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0133] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A U-shield encrypted communication method based on terminal identity authentication, characterized in that: include, Obtain the running process data of the terminal, compare the running process data with the security process baseline, and obtain the process baseline deviation. Based on the process baseline deviation, the terminal's network access data is obtained, and network anomaly analysis is performed on the network access data to obtain a network anomaly metric. A security risk matrix is ​​constructed based on the process baseline deviation and the network anomaly metric, and a comprehensive terminal security score is obtained by calculating based on the security risk matrix. A U-Shield encrypted communication strategy is formulated based on the terminal's comprehensive security score. The running process data is compared with the security process baseline to obtain the process baseline deviation, including: The process number deviation value is obtained by comparing the current total number of processes in the running process data with the baseline number of processes in the safe process baseline; The process behavior pattern deviation value is obtained by comparing the current process behavior characteristics of the running process data with the baseline behavior pattern in the safe process baseline. Based on preset weighting coefficients, the deviation values ​​of the number of processes and the deviation values ​​of the process behavior patterns are calculated to obtain the process baseline deviation. Based on the process baseline deviation, the terminal's network access data is obtained, including: The process baseline deviation is compared with a preset risk threshold. If the process baseline deviation does not exceed the preset risk threshold, the network access data of the terminal will not be acquired. If the deviation of the process baseline exceeds a preset risk threshold, the network access data of the terminal is collected. The network access data includes network connection records, data transmission volume, and access domain name information. Perform network anomaly analysis on the network access data to obtain network anomaly metrics, including: Feature extraction is performed on the network access data to obtain connection frequency features, traffic distribution features, and access pattern features; The degree of deviation from the normal network behavior baseline is calculated based on the connection frequency characteristics, traffic distribution characteristics, and access pattern characteristics. The degree of deviation of the network behavior is quantified using an anomaly detection algorithm to obtain a network anomaly metric.

2. The U-shield encrypted communication method based on terminal identity authentication as described in claim 1, characterized in that: A security risk matrix is ​​constructed based on the process baseline deviation and the network anomaly metric, including: Establish a two-dimensional risk coordinate system with the process baseline deviation as the first dimension and the network anomaly metric as the second dimension; The process baseline deviation and the network anomaly metric are used as risk coordinate points and mapped onto the two-dimensional risk coordinate system; The risk level zone of the terminal is determined based on the position of the risk coordinate point in the two-dimensional risk coordinate system.

3. The U-shield encrypted communication method based on terminal identity authentication as described in claim 2, characterized in that: The comprehensive security score of the terminal is calculated based on the security risk matrix, including: The basic risk coefficient of the terminal is determined based on the risk level zone of the terminal. The risk adjustment value is calculated by combining the process baseline deviation and the network anomaly metric. The terminal's overall security score is obtained by comprehensively calculating the basic risk coefficient and the risk adjustment value.

4. The U-shield encrypted communication method based on terminal identity authentication as described in claim 3, characterized in that: Based on the comprehensive security score of the terminal, a U-shield encrypted communication strategy is formulated, including: The terminal's overall security score is compared with the security level threshold to obtain the terminal's security level; The authentication strength parameters and encryption strength parameters of the terminal are determined based on the terminal security level. The authentication strength parameter determines the number of authentication attempts and the authentication method for U-shield authentication, and the encryption strength parameter determines the encryption algorithm type and key length.

5. A U-shield encrypted communication system based on terminal identity authentication, employing the U-shield encrypted communication method based on terminal identity authentication as described in any one of claims 1 to 4, characterized in that, include: The terminal access control module is used to acquire the terminal's running process data, compare the running process data with the security process baseline, and obtain the process baseline deviation. The network access control module is used to obtain the terminal's network access data based on the process baseline deviation, perform network anomaly analysis on the network access data, and obtain network anomaly measurement values. The security scoring module is used to construct a security risk matrix based on process baseline deviation and network anomaly metrics, and to calculate the overall security score of the terminal based on the security risk matrix. The encrypted communication module is used to formulate the encrypted communication strategy for the U-shield based on the terminal's comprehensive security score.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the U-shield encrypted communication method based on terminal identity authentication as described in any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the U-shield encrypted communication method based on terminal identity authentication as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • USB key safety control management system

    CN112511484A

  • Network security intelligent monitoring method and system for bank shield key press

    CN119232441A