Public security digital certificate dynamic supervision and management method and system fused with big data analysis

By employing a layered risk scanning mechanism and a behavior-risk mapping model, the shortcomings of traditional monitoring methods in public security business systems have been addressed, enabling accurate identification and hierarchical control of digital certificate operations, thereby improving system security and management efficiency.

CN121509079APending Publication Date: 2026-02-10QINGDAO QIANQING CENTURY INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511900950.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Traditional static authentication and single-dimensional monitoring methods are difficult to effectively address multiple hidden dangers in public security business systems, such as equipment anomalies, sudden operational changes, network risks, and deviations in personnel behavior. In particular, when faced with massive amounts of operation logs and heterogeneous data, they suffer from high false alarm rates, delayed responses, and a lack of adaptive capabilities.

Method used

A hierarchical risk scanning mechanism is adopted to perform two-level parallel scanning, identify trustworthy operation feature points, calculate risk deviation index, and achieve adaptive processing and hierarchical control of mild and severe anomalies through comparison with neighboring reference intervals and behavior-risk mapping model.

Benefits of technology

It enables accurate identification and hierarchical control of public security digital certificate operations, improves security and management efficiency, reduces false alarm rate and response delay, and enhances the stability and security of public security business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509079A_ABST
    Figure CN121509079A_ABST
Patent Text Reader

Abstract

The invention discloses a public security digital certificate dynamic supervision and management method and system fused with big data analysis, and relates to the technical field of digital certificate management. All credible operation feature points and corrected feature points are integrated, a feature set of the operation is output, operation data of the feature set are input into a behavior-risk mapping model, and a behavior-risk mapping model is established; and deducing a corresponding risk quantized value, establishing a risk probability assessment function according to the risk quantized value, fusing prior knowledge provided by the macroscopic baseline scanning layer, performing inversion by utilizing a probabilistic reasoning technology to obtain posterior probability distribution of the operation on each risk dimension, and summarizing the comprehensive risk level of the digital certificate operation according to the posterior probability distribution. And the corresponding hierarchical management and control actions are automatically triggered. According to the management system, through fusion of big data analysis and a multi-level risk perception technology, full-process dynamic accurate supervision of public security digital certificate operation behaviors is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital certificate management technology, specifically to a method and system for dynamic supervision and management of public security digital certificates that integrates big data analysis. Background Technology

[0002] In current practices of supervising and managing public security digital certificates, the widespread application of digital certificates in various public security business systems presents increasingly complex challenges to operational security and the identification of abnormal behavior. Traditional static authentication and single-dimensional monitoring methods are insufficient to effectively address multiple hidden dangers such as equipment anomalies, sudden operational changes, network risks, and deviations in personnel behavior. Especially when faced with massive amounts of operational logs and heterogeneous data, conventional risk detection methods often suffer from high false alarm rates, delayed responses, and a lack of adaptive capabilities. Therefore, there is an urgent need for a new supervisory and management method that can integrate multi-source data, dynamically perceive risks, accurately identify anomalies, and implement hierarchical control to achieve intelligent, precise, and real-time supervision of the entire digital certificate operation process, ensuring the safe and stable operation of public security business systems. Summary of the Invention

[0003] The purpose of this invention is to provide a method and system for dynamic supervision and management of public security digital certificates that integrates big data analysis, so as to solve the problems in the background technology.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a dynamic supervision and management method for public security digital certificates integrating big data analysis, wherein the management method includes the following steps: A layered risk scanning mechanism is used to perform a two-level parallel scan, identify trustworthy operation feature points that are consistent with the normal mode, and calculate the risk deviation index of the trustworthy operation feature points. Based on the preset deviation threshold, the identified trustworthy operation feature points are divided into compliant points, slightly abnormal points and severely abnormal points. In the dimension of mild anomaly point operation occurrence, a neighboring reference interval is constructed. The frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer in the neighboring reference interval is compared. Adaptive processing is performed based on the comparison results. Sudden behavior pattern matching is performed on severe anomaly points to determine whether severe anomaly points meet the known risk operation characteristics. Adaptive processing is performed based on the judgment results. All credible operation feature points are integrated with the corrected feature points to output the feature set of this operation. The operation data of the feature set is input into the behavior-risk mapping model to derive the corresponding risk quantification value. Based on this, a risk probability assessment function is established. The prior knowledge provided by the macro baseline scanning layer is integrated, and the posterior probability distribution of this operation on each risk dimension is derived using probabilistic reasoning technology. The comprehensive risk level of this digital certificate operation is summarized based on the posterior probability distribution, and the corresponding hierarchical control action is automatically triggered.

[0005] Furthermore, a neighboring reference interval is constructed at the dimension of mild anomaly point operation occurrence. The frequency of compliant operations recorded by the macro baseline scan layer and the micro operation scan layer within the neighboring reference interval is compared. Adaptive processing is performed based on the comparison results, including the following steps: If the historical compliance records of the macro baseline scan layer are more than the performance of the current micro operation scan layer, the current mild anomaly is determined to be an occasional interference point, and the features of the mild anomaly are replaced with standardized operation features derived from the macro baseline scan layer; otherwise, they are retained.

[0006] Furthermore, mutation behavior pattern matching is performed on severely anomalies to determine whether they conform to known risky operational characteristics. Based on the determination results, adaptive processing is performed, including the following steps: If a severe anomaly does not belong to a known risk pattern, then the frequency of compliant operations in the adjacent reference interval is compared. If the macro baseline scan layer records of severely anomalies are dominant or are judged to be at risk, the severely anomalies are marked as untrusted operation points and replaced with standardized features provided by the macro baseline scan layer.

[0007] Furthermore, the operational dimensions of the minor anomalies include the time, device, and network in which the operation occurred.

[0008] Furthermore, mutation behavior pattern matching is performed on severely anomalies to determine whether they conform to known risky operational characteristics, including the following steps: Perform mutation behavior pattern matching on severely abnormal points and compare their actual performance with a predefined known risk operation feature library. The risk operation feature library contains pattern features that have been identified as high-risk or malicious behaviors in history. The pattern matching algorithm determines whether the current severe anomaly matches any known risk pattern in the database. If the match is successful, it is determined to be a risky behavior and enters the subsequent untrusted operation point processing flow. If the match fails, the frequency of compliant operations in the adjacent reference interval is compared. By comparing the frequency of compliant operations in the same or similar situations between the macro baseline scanning layer and the micro operation scanning layer, it is determined whether the anomaly still has compliance.

[0009] Furthermore, the logic for constructing the nearest reference interval is as follows: Centered on the dimension in which anomalies occur in actual operation, a multi-dimensional neighborhood consisting of a time window, equipment usage range, and network environment range is selected to limit the scope of analysis, focusing on historical operation samples related to the actual occurrence context of anomalies.

[0010] Furthermore, the corresponding hierarchical control actions are automatically triggered, including the following steps: Record low-risk cases; Medium-risk situations may trigger enhanced certification or operational alerts. High risk and require mandatory interruption, temporary freezing of certificates, or initiation of security audit measures.

[0011] Furthermore, the stratified risk scanning mechanism includes a dual analysis dimension of macro baseline scanning layer and micro operational scanning layer.

[0012] Furthermore, the macro baseline scanning layer includes scanning the compliance operation patterns, equipment registration lists, network whitelist environment, and personnel behavior baselines within historical periods to establish a benchmark reference for risk assessment. The micro-operation scanning layer includes capturing the behavior sequence of this digital certificate operation, real-time device fingerprint, network connection characteristics, and operation context.

[0013] This application also provides a dynamic supervision and management system for public security digital certificates that integrates big data analysis, including an operation feature anomaly classification module, feature set output module, and control module; Operational feature anomaly classification module: It adopts a hierarchical risk scanning mechanism to perform a two-level parallel scan, identify credible operational feature points that are consistent with the normal mode, and calculate the risk deviation index of credible operational feature points. Based on the preset deviation threshold, the identified credible operational feature points are classified into compliant points, mild anomalies, and severe anomalies. Feature set output module: Construct a neighboring reference interval in the dimension of operation occurrence of mild anomalies, compare the frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer in the neighboring reference interval, perform adaptive processing based on the comparison results, perform mutation behavior pattern matching for severe anomalies, determine whether severe anomalies meet the known risk operation characteristics, perform adaptive processing based on the judgment results, integrate all credible operation feature points with the corrected feature points, and output the feature set of this operation; Control module: Input the operation data of the feature set into the behavior-risk mapping model, derive the corresponding risk quantification value, and establish a risk probability assessment function based on it. Integrate the prior knowledge provided by the macro baseline scanning layer, use probabilistic reasoning technology to inversely derive the posterior probability distribution of this operation on each risk dimension, summarize the comprehensive risk level of this digital certificate operation based on the posterior probability distribution, and automatically trigger the corresponding hierarchical control action.

[0014] The technical effects and advantages provided by the present invention in the above technical solution are as follows: This invention inputs the corrected feature set into a behavior-risk mapping model, combines it with macro-baseline prior knowledge, and uses probabilistic reasoning technology to invert the posterior probability distribution of each risk dimension. This enables deep reasoning from behavioral appearance to the essence of risk, scientifically quantifies the comprehensive risk level of each operation, and automatically triggers graded and differentiated control actions accordingly. This significantly improves the security, controllability, and management efficiency of the public security digital certificate operation process, providing solid technical support for the stable operation and data security of public security business systems.

[0015] This invention employs a hierarchical risk scanning mechanism to perform parallel analysis of macro baselines and micro operations, which can effectively distinguish between compliant operations, minor anomalies, and severe anomalies, accurately identify potential risk points, avoid the problems of missed detections or false alarms under traditional static authentication methods, and enhance the foresight and comprehensiveness of risk discovery.

[0016] This invention constructs a neighboring reference interval around mild anomalies and compares the frequency of compliant operations within different scanning layers to achieve adaptive judgment and rational correction of abnormal behavior. At the same time, it performs mutation pattern matching and feature replacement on severe anomalies to further eliminate interference items, retain true and reliable operation features, and effectively improve the accuracy and representativeness of the operation feature set. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0018] Figure 1 This is a timing diagram of the management method of the present invention.

[0019] Figure 2 This is a framework diagram of the management system of the present invention. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Example 1: This example provides a method for dynamic supervision and management of public security digital certificates that integrates big data analysis. Please refer to [link / reference]. Figure 1 As shown, the management method includes the following steps: A layered risk scanning mechanism is adopted, establishing a dual analytical dimension of macro baseline scanning and micro operational scanning. The macro baseline scanning layer focuses on a broad scan of compliant operation patterns, equipment registration lists, network whitelist environments, and personnel behavior baselines within historical periods to establish a benchmark reference for risk assessment. The micro operational scanning layer focuses on a refined capture of the specific behavioral sequence, real-time device fingerprints, network connection characteristics, and operational context of the current digital certificate operation. Through parallel scanning at both levels, trusted operational feature points consistent with normal patterns are initially identified, and the risk deviation index between trusted operational feature points and the macro baseline scanning layer is calculated. Based on a preset deviation threshold, the identified behavioral points are classified into compliant points (no significant deviation), slightly abnormal points (with explainable minor deviations), and severely abnormal points (with significant or inexplicable deviations), providing categorized input for subsequent in-depth analysis.

[0022] For minor anomalies, a neighboring reference interval is constructed based on the time, device, and network of the operation. The frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer within this interval is compared. If the historical compliance records of the macro baseline scanning layer are significantly more numerous than the performance of the current micro operation scanning layer, the current minor anomaly is determined to be an occasional interference point, and its features are replaced with standardized operation features derived from the macro baseline scanning layer; otherwise, it is retained. For major anomalies, a mutation behavior pattern matching is performed to determine whether it conforms to known risk operation features. If it does not belong to a known risk pattern, the frequency of compliant operations in the neighboring reference interval is compared again; if the macro baseline scanning layer records are significantly dominant or the point is determined to be risky, it is marked as an untrusted operation point and replaced with standardized features provided by the macro baseline scanning layer. Finally, all trustworthy operation feature points are integrated with the corrected feature points to output a purified feature set reflecting the core trustworthy behavior of this operation.

[0023] The operational data of the feature set is input into the behavior-risk mapping model to derive the corresponding risk quantification value. Based on this, a risk probability assessment function is established to characterize the possibility that the current operation is in an abnormal state. Further, prior knowledge (such as historical risk statistics) provided by the macro baseline scanning layer is integrated, and probabilistic reasoning techniques are used to inversely derive the posterior probability distribution of this operation across various risk dimensions (such as behavioral intent), thereby achieving a comprehensive assessment from appearance to underlying risk. Finally, based on the posterior probability distribution, the overall risk level (e.g., low, medium, high, urgent) of this digital certificate operation is determined, and corresponding tiered control actions are automatically triggered: low risk usually only needs to be recorded; medium risk may trigger enhanced authentication or operational alerts; high risk and above will execute strict measures such as forced interruption, temporary certificate freezing, or initiation of security audits.

[0024] Example 2: This example provides a dynamic supervision and management system for public security digital certificates that integrates big data analytics. Please refer to [link / reference]. Figure 2 As shown, it includes an operation feature anomaly classification module, a feature set output module, and a control module; Operation feature anomaly classification module: adopts a hierarchical risk scanning mechanism to perform dual-level parallel scanning, identify credible operation feature points that are consistent with the normal mode, and calculate the risk deviation index of credible operation feature points. Based on the preset deviation threshold, the identified credible operation feature points are classified into compliant points, mild anomalies, and severe anomalies. The credible operation feature point classification results are sent to the feature set output module. Feature set output module: Constructs a neighboring reference interval at the dimension of operation occurrence of minor anomalies, compares the frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer in the neighboring reference interval, performs adaptive processing based on the comparison results, performs mutation behavior pattern matching for severe anomalies, determines whether severe anomalies meet the known risk operation characteristics, performs adaptive processing based on the determination results, integrates all credible operation feature points with the corrected feature points, outputs the feature set of this operation, and sends the feature set to the control module; Control module: Input the operation data of the feature set into the behavior-risk mapping model, derive the corresponding risk quantification value, and establish a risk probability assessment function based on it. Integrate the prior knowledge provided by the macro baseline scanning layer, use probabilistic reasoning technology to inversely derive the posterior probability distribution of this operation on each risk dimension, summarize the comprehensive risk level of this digital certificate operation based on the posterior probability distribution, and automatically trigger the corresponding hierarchical control action.

[0025] Example 3: In this example, the various process steps of the dynamic supervision and management method for public security digital certificates integrating big data analysis are described in detail below: In one embodiment disclosed in this application, the macro baseline scanning layer focuses on extensive scanning and modeling of a large amount of operational data accumulated within historical periods (such as the past 30 days or a custom period), the objects of which include, but are not limited to: (1) Compliance operation mode, that is, the typical behavior sequence, time distribution, operation frequency and operation path exhibited by normal users when using digital certificates to perform identity authentication, permission call, data access and other operations in normal business scenarios; (2) Equipment filing list, which is the information of legal terminal equipment that has passed security audit and registered, covering basic characteristics such as device ID, hardware fingerprint, operation type, and common network environment; (3) Network whitelist environment, which is a network access environment that is recognized as safe and trustworthy, such as public security intranet IP segment, authorized VPN node, fixed office network exit, etc. (4) Personnel behavior baseline, which refers to the personalized behavioral characteristics formed by a specific operator (or user identity) in historical operations, such as commonly used operation time periods, preferred equipment, commonly used functional modules, operation rhythm and interaction logic, etc.

[0026] In one embodiment disclosed in this application, the micro-operation scanning layer focuses on the fine-grained feature extraction and real-time capture of digital certificate operation behaviors that are currently occurring or have just occurred. Its main focus includes: (1) Specific action sequence, namely, the operation process details such as the order of function calls, page jump logic, permission request steps, etc. involved in this operation; (2) Real-time device fingerprint, which is the dynamic fingerprint information of the terminal device used in the current operation in the current session, such as hardware identification, version, browser characteristics, network adaptation information, etc. (3) Network connection characteristics, including current network IP address, network type (such as Wi-Fi / 4G / 5G), proxy settings, DNS resolution path, connection latency and packet loss rate and other network environment parameters; (4) Operation context, such as the specific time of the operation (whether it is outside working hours), geographical location (whether it is a frequently used location), the matching degree between the operation terminal and historically frequently used devices, and the binding relationship between the current user identity and historical operation accounts, etc.

[0027] The micro-operation scanning layer constructs a micro-profile describing the unique characteristics of this operation by real-time acquisition of these fine-grained features, which is then used for comparative analysis with the macro-baseline.

[0028] In one embodiment disclosed in this application, based on the aforementioned two-level scanning mechanism, a parallel scanning strategy is adopted. That is, the macroscopic baseline scanning layer and the microscopic operation scanning layer are analyzed synchronously within the same time window, independent of each other but interconnected. By jointly processing the feature sets output by the two layers, it is possible to initially identify those reliable operation feature points that not only conform to the normal patterns defined by the macroscopic baseline, but also exhibit consistency with the current operation context at the microscopic level.

[0029] Furthermore, for each identified credible operational feature point, a risk deviation index is calculated between it and the benchmark reference model established by the macroscopic baseline scanning layer. The calculation logic of this index is described as follows: Multiple baseline features related to the current feature point are extracted from the macro baseline model (such as the average occurrence time of this type of operation in history, the proportion of commonly used device types, and the distribution ratio of network environments). Then, for the actual value of the current feature point (such as the actual occurrence time of this operation, the type of device used, and the actual network environment), the degree of difference between each feature and the corresponding baseline feature is calculated (such as time offset, device matching degree, and network environment deviation ratio). Finally, by summarizing the differences (which can be weighted or unweighted, depending on the importance of the feature), a comprehensive numerical index, namely the risk deviation index, is formed, which is used to quantitatively characterize the degree of deviation between the current operation point and the normal mode.

[0030] Based on a pre-defined deviation threshold system (which can be configured according to actual business scenarios, historical risk distribution, or expert experience, and typically includes three levels—high, medium, and low—or specific numerical boundary points), all identified trustworthy operational feature points are classified and judged: If the risk deviation index of a certain feature point is less than or equal to the low threshold, it is determined to be a compliant point. That is, the operation point does not show significant deviation in terms of behavior pattern, equipment environment, network conditions, etc., and is within the normal operation range, requiring no extra attention. If the risk deviation index of a certain feature point is between the low threshold and the medium threshold, it is determined to be a mild anomaly. That is, the operation point has a certain degree of deviation in some dimensions (such as the operation time slightly deviating from the normal time period, the equipment used is not commonly used but has been registered, the network environment is not preferred but is within the whitelist, etc.). Such deviations are usually interpretable and may be caused by normal business changes or temporary environmental adjustments, but still need to be further observed or handled lightly. If the risk deviation index of a certain feature point exceeds the medium threshold (or reaches the high threshold), it is determined to be a severe anomaly point. That is, the operation point shows significant or inexplicable deviations in multiple dimensions (such as using unregistered equipment, connecting to non-whitelisted networks, abnormal jumps in the operation sequence, occurring outside of working hours and with abnormal geographical location, etc.). Such deviations often indicate potential security risks and require close attention to trigger subsequent in-depth analysis and adaptive processing.

[0031] Multiple benchmark features closely related to current trustworthy operational characteristics are extracted from the macro baseline model. These benchmark features are typically typical values ​​or distribution parameters obtained through statistical analysis of a large number of compliant operational behaviors over historical periods (such as the past 30 days or longer). For example: (1) Baseline characteristics of operation occurrence time, such as the average occurrence time of a certain type of operation (such as night query permission) in history (for example, only 5% occurs between 1 am and 5 am, while as much as 85% occurs between 9 am and 5 pm). (2) Baseline characteristics of equipment type, such as the proportion of commonly used equipment types (such as specific models of public security dedicated terminals) in historical operations (for example, the proportion of this model of equipment is 70%, other registered equipment accounts for 20%, and non-registered equipment accounts for 10%). (3) The baseline characteristics of the network environment, such as the historical distribution of the network type used in the operation (e.g., public security intranet, authorized VPN) (e.g., intranet IP accounts for 90%, whitelisted proxies account for 8%, and non-whitelisted networks account for 2%). These baseline characteristics together constitute a reference system for measuring whether the current operation is compliant or deviates from the norm.

[0032] For each actual value of a trusted operation feature point (i.e., the performance of this operation in a specific scenario), calculate the degree of difference between it and the corresponding baseline feature. For example: (1) For operation time, if the current operation occurs at 3:00 AM (the historical average occurrence time is concentrated during the daytime), calculate its time offset relative to the normal time period (such as the number of minutes deviating from the normal time period or the time period difference score). (2) For device type, if the current operation uses a device that is not commonly used but has been registered (such as a non-mainstream terminal of a certain model), then calculate its device matching degree relative to the commonly used device type (for example, the usage rate of this device in history is only 5%, which is far lower than the 70% of commonly used devices). (3) For the network environment, if the current operation connects to a network that is not the preferred choice but is within the whitelist (such as a fixed office Wi-Fi), the deviation ratio of the network environment relative to the standard network environment is calculated (for example, the current network accounts for only 5% of historical compliant operations, while the intranet accounts for 90%). Each difference is transformed into a quantifiable value through specific logical processing (such as directly taking the difference, calculating the ratio deviation, or using preset scoring rules) to reflect the deviation intensity on that dimension.

[0033] Based on the risk deviation index calculated above, all trustworthy operation feature points are further classified and judged according to a pre-set deviation threshold system (this threshold is usually configured according to actual business scenarios, historical risk distribution data or expert experience, and is generally divided into three levels: high, medium and low. Specific numerical boundary points can also be used, such as setting the low threshold to 20, the medium threshold to 50, and the high threshold to 80). The specific logic is as follows: Compliance Point: If the risk deviation index of a certain trusted operation feature point is less than or equal to a low threshold (e.g., ≤20), then the operation point is determined to be a compliance point. This means that the operation point does not show significant deviations in terms of behavioral patterns (e.g., operation time is during normal periods), equipment environment (e.g., using common or registered equipment), network conditions (e.g., connecting to an intranet or whitelisted network), etc. Its performance is highly consistent with the historical baseline, falls within the scope of normal operation, and does not require additional attention or processing. It can be directly regarded as part of trusted operation.

[0034] Mild Anomalies: If the risk deviation index of a trusted operation feature point is between the low and medium thresholds (e.g., 20 < index ≤ 50), then the operation point is determined to be a mild anomaly. These operation points typically exhibit some deviation in certain dimensions, but the degree of deviation is still within an interpretable range. Examples include: the operation time slightly deviating from the usual time period (e.g., 7 PM instead of peak daytime hours); the device used being a non-frequently used but registered terminal (e.g., a temporary backup device); and the network environment being a non-preferred but whitelisted network (e.g., a fixed office Wi-Fi network). These deviations are often caused by normal business changes (e.g., overtime operations, temporary equipment replacement), environmental adjustments (e.g., network switching), or individual habit differences. While not ideal, they usually do not possess obvious malicious intent. Therefore, they are marked as anomalies requiring further observation or lightweight handling, such as logging or increasing subsequent monitoring frequency.

[0035] Severe Anomalies: If the risk deviation index of a trusted operation feature exceeds the medium threshold (or reaches the high threshold, such as >50, or the high threshold is directly set to 80), then the operation is determined to be a severe anomaly. Such operation points exhibit significant or inexplicable deviations across multiple dimensions, such as: using unregistered devices (e.g., personal mobile phones or terminals from unknown sources), connecting to non-whitelisted networks (e.g., public Wi-Fi or overseas IPs), abnormally jumping operation sequences (e.g., switching functional modules multiple times within a short period), or operations occurring outside of working hours and in unusual geographical locations (e.g., operating late at night in uncommon locations). These deviations often indicate potential security risks, such as device spoofing, unauthorized access, internal threats, or external attack attempts. Therefore, they are marked as anomalies requiring close attention and triggering subsequent in-depth analysis and adaptive processing, such as performing mutation behavior pattern matching, device anomaly detection, or initiating multi-dimensional risk verification.

[0036] Example: Let the actual characteristics of a certain digital certificate operation be: The operation took place at 3 a.m. (the historical average time of occurrence is between 9 a.m. and 5 p.m., which accounts for only 5% of historical occurrences). The equipment used was a model that was not frequently used but had been registered (historically, this model accounted for 5% of historical occurrences, while commonly used equipment accounted for 70%). The network environment was an office Wi-Fi network that was not the preferred choice but was on the whitelist (historically, this model accounted for 8% of compliant operations and 90% of intranet operations).

[0037] After extracting the corresponding baseline features from the macro baseline model, the differences for each item are calculated: the operation time deviation score is 30 (due to a significant deviation from the normal time period), the equipment matching score is 20 (due to the use of uncommon equipment), and the network environment deviation score is 10 (due to a non-preferred network). If a weighted calculation is used (with weights of 0.5, 0.3, and 0.2 respectively), the risk deviation index = 30 × 0.5 + 20 × 0.3 + 10 × 0.2 = 15 + 6 + 2 = 23. Since 23 is between the low threshold of 20 and the medium threshold of 50, this operation point is judged as a minor anomaly. The operation will be recorded and may be subject to additional monitoring, but strict control will not be triggered at this time. If the operation time is changed to 2:00 AM and the equipment is an unregistered device, and the network is a non-whitelisted IP, causing a significant increase in the scores for each difference (e.g., time 35, equipment 40, network 30, with a total deviation of 50+ after weighting), and the total index exceeds 50, it will be directly judged as a severe anomaly, thereby triggering in-depth analysis and strict handling procedures.

[0038] In one embodiment disclosed in this application, for minor anomalies, since their risk deviation is within an acceptable range (i.e., the deviation has not yet reached the significant anomaly threshold, typically manifested as slight deviations from the historical baseline in individual dimensions such as operation time, equipment usage, or network environment, but still possessing a certain degree of rationality overall), a neighboring reference interval is constructed around the specific dimensions in which the anomaly occurred during actual operation (such as operation time, equipment identification, network connection characteristics, etc.). The construction logic of this neighboring reference interval is as follows: Centered on the key dimensions of the anomaly in actual operation (such as operation timestamp), a multi-dimensional neighborhood is selected, consisting of a time window (such as several minutes before and after or a specific period of time), the scope of equipment use (such as the same type of equipment model or the same registered equipment group), and the scope of network environment (such as the same IP segment or the same network type). This neighborhood is used to limit the scope of analysis and focus on historical operation samples related to the actual occurrence of the anomaly.

[0039] In one embodiment disclosed in this application, after the adjacent reference interval is constructed, the compliant operation frequency data recorded by the macro baseline scanning layer and the micro operation scanning layer in the interval are retrieved respectively.

[0040] The macro baseline scanning layer provides the number of normal and compliant operations accumulated over a long historical period (such as the past 30 days or longer) under the same or similar dimensional conditions (such as the same time period, the same type of equipment, and the same network environment), reflecting the density of typical compliant behaviors in this type of scenario. The micro operation scanning layer records the number of compliant operations that actually occurred in the current operation event within the same adjacent reference interval, representing the actual compliance performance of this operation under similar scenarios.

[0041] In one embodiment disclosed in this application, the following processing logic is executed by comparing the frequency of compliant operations from these two sources: If the frequency of compliant operations recorded by the macro baseline scanning layer within the adjacent reference interval is significantly higher than that of the micro operation scanning layer (for example, the macro baseline shows that more than 90% of operations in this scenario are compliant, while only a few or no compliant records are found in this operation), it indicates that the current minor anomaly is likely an occasional interference point caused by sporadic factors (such as temporary network switching, brief equipment malfunctions, temporary changes in user operating habits, etc.). Its deviation does not represent a real risk, so it is identified as an occasional interference point, and a feature replacement operation is performed. That is, the original features of the anomaly point (which may contain some noise or deviation) are replaced with standardized operation features derived from the macro baseline scanning layer (such as the most common operation time points, the most commonly used compliant equipment types, the most typical network environment parameters, etc. within this time period). This replacement operation is essentially a credibility correction of the current anomaly point, making it closer to the average level of historical compliant behavior, thereby reducing its interference with subsequent risk analysis. Conversely, if the difference in the frequency of compliant operations between the macro baseline and the micro-operational scanning layer within the adjacent reference interval is not significant (e.g., both show a high compliance rate or the current operation performance is basically consistent with the historical baseline), then it is considered that although the slight anomaly has a minor deviation, it belongs to a reasonable range of individual differences or normal business fluctuations, and therefore it is retained without further replacement to ensure that potential normal operation characteristics are not mistakenly deleted. An example is as follows: Suppose a minor anomaly occurs between 2 AM and 3 AM, using a non-preferred but registered mobile device, and connecting to a whitelisted office Wi-Fi network. Historical data from the macro baseline scanning layer shows that within this adjacent reference interval (i.e., 2 AM to 3 AM, using a similar non-preferred device, and connecting to a whitelisted Wi-Fi network), 90% of historical operations (e.g., 90 out of 100) are compliant operations (i.e., no significant deviations are triggered, and they conform to normal behavior patterns), representing a compliant operation frequency of 90%. However, the analysis results from the micro operation scanning layer for this specific operation show that within the same adjacent reference interval, only 10% of the operations (e.g., 1 out of 10) are judged to be compliant, representing a compliant operation frequency of 10%. At this point, the macro baseline compliance frequency (90%) is significantly higher than the micro operational compliance frequency (10%). It is determined that this minor anomaly is likely caused by sporadic factors (such as a user temporarily performing an operation in the early morning or a device temporarily connecting to a non-preferred but secure Wi-Fi network). Therefore, a feature replacement operation is performed, replacing the original features of the anomaly (such as the early morning operation time, uncommon mobile devices, and non-preferred Wi-Fi) with standardized operational features derived from the macro baseline (such as the most common operation time during this period, e.g., 2:30 AM; the most commonly used compliant device type, e.g., a specific type of public security terminal; and the most typical network environment parameters, e.g., an intranet IP address range). This replacement makes the anomaly closer to the average level of historical compliance behavior, reducing interference with subsequent risk analysis.

[0042] In one embodiment of this application, a more stringent analysis strategy is adopted for operational feature points classified as severe anomalies (i.e., risk deviations exceeding medium or high thresholds, typically manifested as using unregistered devices, connecting to non-whitelisted networks, abnormally jumping operational sequences, or significantly deviating from normal patterns during off-peak hours and at abnormal geographical locations). A mutation behavior pattern matching is performed on the severe anomaly, comparing its actual behavior (such as operational sequences, device switching trajectories, network connection change patterns, etc.) with a predefined database of known risk operational features. This feature database typically contains a series of pattern features shared by historically identified high-risk or malicious behaviors (e.g., multiple attempts to log in from different devices within a short period, frequent switching to non-registered networks, abnormally circuitous operational paths, etc.). A pattern matching algorithm (e.g., rule-based matching) is used to determine whether the current severe anomaly matches any known risk pattern in the database. If a match is successful, the point is directly identified as a high-risk behavior and proceeds to the subsequent untrusted operation point handling process. If a match fails (i.e., the behavior pattern of the current anomaly point has no direct correspondence in the known risk database), a comparison of the compliant operation frequency within the adjacent reference interval is performed. The logic is similar to that for handling minor anomalies. By comparing the compliant operation frequency differences between the macro baseline scanning layer and the micro operation scanning layer under the same or similar circumstances (within the adjacent reference interval), it is determined whether the anomaly point still has a certain possibility of compliance. An example is as follows: Suppose a highly abnormal event exhibits the following characteristics: the operation occurred at 2 AM (outside of working hours); the device used was an unregistered mobile device (not on the device registration list); the network environment involved connecting to a non-whitelisted public Wi-Fi network; and the operation sequence consisted of consecutive access control, data export, and configuration operations within 5 minutes (the operation path was abnormally circuitous and inconsistent with normal business processes). First, the behavioral details of this abnormal event (early morning operation, unregistered device, non-whitelisted network, abnormal operation path) were compared with a predefined database of known risk operation features. It was found that although unregistered devices and non-whitelisted networks inherently carry high risk, the operation sequence did not directly match predefined risk patterns such as repeatedly attempting to log in from different devices within a short period or frequently switching between non-registered networks (e.g., not switching between multiple devices within 5 minutes, using only one unregistered device). Therefore, the abnormal behavior pattern matching result was no match for a known risk pattern.

[0043] Perform a comparison of the frequency of compliant operations in the adjacent reference interval for this anomaly point: The constructed proximity reference interval is defined as 2 AM, using an unregistered mobile device, and connecting to a non-whitelisted public Wi-Fi network. Historical data from the macro baseline scanning layer shows that within this proximity reference interval, 90% of historical operations (e.g., 90 out of 100) are compliant operations (i.e., no significant deviations are triggered, and they conform to normal behavior patterns), with a compliance operation frequency ratio of 90%. However, the analysis results from the micro operation scanning layer for this operation show that within the same proximity reference interval, only 10% of operations (e.g., 1 out of 10) are judged to be compliant, with a compliance operation frequency ratio of 10%. At this point, the macro baseline compliance frequency (90%) is significantly higher than the micro operation compliance frequency (10%). It is determined that even if the behavior pattern of this anomaly does not directly match the known risk database, it still shows a significant deviation in the current context, and this deviation is extremely rare in the historical baseline. Therefore, this severely anomaly is marked as an untrusted operation point, and subsequent feature substitution operations are performed.

[0044] In one embodiment disclosed in this application, after the above comparison is completed, the following processing logic is executed: If the frequency of compliant operations recorded by the macro baseline scanning layer within the adjacent reference interval is significantly higher than that of the micro operation scanning layer (indicating that historical compliant behavior dominates in the current context, while the current operation is abnormal), or if the severe anomaly does not match a known risk pattern but is still considered to have potential risk after comprehensive judgment (e.g., although there is no direct match, the behavioral deviation is too significant), then the severe anomaly is marked as an untrusted operation point, and a feature substitution operation is performed. That is, the original features of the anomaly point are replaced with standardized operation features provided by the macro baseline scanning layer (e.g., the most commonly used device type, network environment parameters, operation time point, etc. in normal circumstances for this type of operation), thereby transforming it from a potentially high-risk feature into a trustworthy standardized feature, ensuring that subsequent risk analysis will not lead to misjudgment due to the retention of abnormal features.

[0045] Conversely, if the difference in the frequency of compliant operations between the macro baseline scanning layer and the micro operation scanning layer is not significant, and the point is judged to have no obvious risk (although it is a severe deviation), it may be possible to retain the original features of the point or perform other lightweight processing. However, under normal circumstances, severe outliers that fail to pass any of the above verification steps tend to be classified as untrusted operation points and undergo feature correction.

[0046] If a severely anomaly occurs within a nearby reference period of 3 AM, involves the use of a new, unregistered device, and a connection to a VPN belonging to a company not on the whitelist, the macro baseline scan layer shows that 95% of historical operations within this nearby reference period are compliant, representing a 95% frequency of compliant operations. However, the micro operation scan layer shows that only 5% of the operations in this instance were deemed compliant, representing a 5% frequency of compliant operations. Since the macro baseline compliance frequency is significantly higher than the micro operation compliance frequency, it indicates that historical compliant behavior dominates in the current context, while this operation is abnormal. Therefore, this severely anomaly is marked as an untrusted operation point, and a feature substitution operation is performed, replacing the original features with standardized operational features provided by the macro baseline (such as commonly used device types, standard network environment parameters, and typical operation times for this period). Conversely, if the difference in the frequency of compliant operations between the macro baseline and the micro operation scanning layer is not significant (e.g., both are 80%), and the point is judged to have no obvious risk (although the operation deviation is significant), the original features may be retained or lightweight processing may be performed. However, in general, severe anomalies that fail to pass any verification step will be classified as untrusted operation points and feature correction will be performed.

[0047] All the trusted operational feature points after the above processing (i.e., the original points that were not judged as abnormal, the retained slightly abnormal points, and the reasonable abnormal points that were not replaced) and the corrected feature points (i.e. the operational points that were originally slightly or severely abnormal, but were replaced with standardized features after comparison with the nearest reference interval and pattern matching) are integrated into a unified feature set.

[0048] In one embodiment disclosed in this application, operational data (including key features such as operational behavior sequences, device fingerprints, network environment, and temporal context) from a purified and integrated feature set are used as input and passed to a pre-trained or configured behavior-risk mapping model. The core function of this model is to establish a mapping relationship between operational features and risk quantification values, described as follows: The model internally maintains a set of feature-risk association rules or parameters built based on a historical risk event database, typical risk behavior patterns, and statistical learning methods (such as classification rules). When it receives feature input for the current operation, the model analyzes the degree of matching or deviation between each feature dimension (such as whether the operation time is outside working hours, whether the device is unregistered, whether the network environment is not whitelisted, etc.) and known risk features. Based on a preset weighting mechanism (for example, certain key features such as unregistered devices may be given higher weights), the model comprehensively calculates the contribution value of each feature and finally outputs a risk quantification value. This value is used to intuitively represent the degree to which the current operation deviates from the normal behavior pattern; the higher the value, the greater the potential risk. This risk quantification value is essentially a comprehensive measure of the abnormality of the current operation, providing a basic input for subsequent probabilistic inference.

[0049] In one embodiment disclosed in this application, a risk probability assessment function is constructed based on a risk quantification value to characterize the probability that the current operation is in an abnormal state (i.e., there is a security risk). The logic of this function is as follows: Using quantified risk values ​​as input variables, combined with predefined risk level ranges (e.g., low risk corresponds to a quantified value range of 0-30, medium risk 30-60, high risk 60-80, and emergency risk above 80; specific thresholds can be adjusted according to actual business scenarios), a series of logical judgment conditions or piecewise function rules are set (e.g., when the quantified value is less than or equal to 30, the probability of anomaly is defined as low; greater than 30 and less than or equal to 60, it is defined as medium; and so on), continuous quantified risk values ​​are mapped to discrete probability descriptions of abnormal states, thus intuitively reflecting the overall probability level that the current operation may be abnormal. This function not only provides a quantitative basis for the final determination of risk level but also provides clear risk measurement indicators for subsequent visualization and decision interpretation.

[0050] When the model receives the feature input for the current operation, it performs a risk quantification assessment according to the following processing logic: The model analyzes each characteristic dimension (such as whether the operation occurred outside of working hours, whether the device is unregistered, whether the network environment is not on the whitelist, whether the sequence of operational behaviors conforms to normal procedures, and whether the device's geographical location is abnormal) to assess the degree of match or deviation with known risk characteristics. For example, if the operation occurs at 2:00 AM (outside of working hours), the model will assess the degree of deviation of that time point from normal working hours; if the device used is unregistered, the model will identify the fact that the device is not on the registration list and assess its potential risk weight.

[0051] According to a pre-defined weighting mechanism, the model assigns a corresponding weight coefficient to each feature dimension. These weights reflect the relative importance of each feature in the overall risk assessment and are typically set based on historical data analysis, expert experience, or business needs. For example, whether the equipment is unregistered may be assigned a higher weight (e.g., 0.4), because using unregistered equipment is often a significant indicator of high-risk behavior; while whether the operation takes place outside of working hours may be assigned a lower weight (e.g., 0.1), unless operating outside of working hours carries special risks in a specific business scenario. The model multiplies the deviation of each feature dimension by its corresponding weight to calculate the feature's contribution to the overall risk.

[0052] The contribution values ​​of all feature dimensions are weighted and summed (or calculated using other specified comprehensive methods, such as weighted average, product, etc., depending on the model design) to obtain a comprehensive risk quantification value. This value is used to intuitively represent the degree to which the current operation deviates from the normal behavior pattern; the higher the value, the greater the potential risk. For example, if the weight of operation time deviation is 0.1 and the deviation score is 0.3; the weight of unregistered equipment is 0.4 and the deviation score is 1.0; the weight of network environment deviation is 0.3 and the deviation score is 0.5; and the weight of operation behavior sequence deviation is 0.2 and the deviation score is 0.2, then the comprehensive risk quantification value = 0.1×0.3 + 0.4×1.0 + 0.3×0.5 + 0.2×0.2 = 0.03 + 0.4 + 0.15 + 0.04 = 0.62.

[0053] In one embodiment disclosed in this application, prior knowledge provided by the macro baseline scanning layer is integrated, including historical risk statistics (such as the frequency of various risk events, the distribution of common risky device types, and statistics on high-risk time periods), personnel behavior baselines (such as the normal operating habits and historical compliance records of specific users), device registration and trust profiles (such as the long-term stability of devices and historical violation records), and network environment risk assessment data (such as the security reputation of IP address ranges and statistics on proxy / VPN usage). This prior knowledge serves as background information for risk reasoning, providing a global perspective beyond the data of a single operation, enabling risk analysis to go beyond the superficial characteristics of the current operation and to make a comprehensive judgment by combining historical patterns and the overall environmental background.

[0054] When constructing a comprehensive risk assessment system, the system integrates prior knowledge provided by the macro baseline scanning layer, including historical risk statistics (e.g., in the past year, the frequency of unauthorized device login events was 5%, the violation rate of common risky device types such as a certain model of old mobile phone was 8%, and the risk event rate of high-risk time periods such as midnight to 4 am was 12%), personnel behavior baselines (e.g., in the past 90 days, 98% of user A's operations were performed during normal working hours and never logged in on non-registered devices), device registration and trust profiles (e.g., device X has been used stably and has no violation records in the past two years, with a trust score of 95), and network environment risk assessment data (e.g., the security reputation score of IP address range Y is 80, and the proxy / VPN usage rate is 3%).

[0055] This prior knowledge provides a global perspective for risk reasoning that goes beyond the data from a single operation. For example, when user A initiates an operation at midnight using device X (trust score 95) from IP address range Y (security reputation score 80), the overall risk score for this operation is calculated by combining not only the apparent characteristics of the operation, but also historical risk statistics (high-risk events at night account for 12%), baseline personnel behavior (user A's operation at night is abnormal), device registration information (device X has no violations), and network environment assessment (IP range Y has good reputation).

[0056] In one embodiment disclosed in this application, probabilistic inference techniques (such as Bayesian inference methods) are used to inversely calculate the posterior probability distribution of the current operation across various risk dimensions. This processing logic can be described as follows: Based on the prior knowledge provided by the macro baseline scanning layer, an initial prior probability distribution is set for each risk dimension (such as the credibility of behavioral intent, device credibility, network environment security, etc.). For example, according to historical statistics, the initial probability of a certain type of device being marked as untrustworthy is relatively high. The characteristic data of the current operation (including the risk quantification value and the specific values ​​of each characteristic dimension) is used as observation evidence input into the inference model. By calculating the conditional probability relationship between the observation evidence and the assumptions of each risk dimension (such as the operation is normal behavior, the device is a trustworthy device, etc.), the posterior probability distribution of each risk dimension in the current operation context is updated and deduced, that is, the actual probability that the current operation is in a risky or abnormal state in each dimension.

[0057] Based on the prior knowledge provided by the macro baseline scanning layer, an initial prior probability distribution is set for each risk dimension (such as the credibility of behavioral intent, device credibility, and network environment security). For example, based on historical statistical data, the initial probability of a certain type of device (such as an older model of mobile terminal) being marked as untrustworthy is set to 30%, while the initial probability of credibility for normal devices is 70%.

[0058] The characteristic data of the current operation (including the risk quantification value and the specific values ​​of each characteristic dimension) is used as observational evidence input into the inference model. Assume the risk quantification value of the current operation is 0.65, the device fingerprint indicates it is an older model mobile terminal, and the network environment is a non-whitelisted public Wi-Fi. By calculating the conditional probability relationship between the observational evidence and the assumptions of each risk dimension (such as the operation being normal behavior, the device being a trusted device, etc.), the model is updated and the posterior probability distribution of each risk dimension in the current operation context is derived. The specific calculation is as follows: For the device trustworthiness dimension, based on Bayes' theorem, and combining the prior probability of 30%, the conditional probabilities of the observed device type (older mobile terminal model) and the abnormal device type, as well as the impact of the risk quantification value of 0.65 on device trustworthiness, the posterior probability is calculated to be 70% (i.e., in the current operating context, the probability that the device is a trustworthy device is 70%). Similarly, for the network environment security dimension, considering the combined impact of the historical risk proportion of non-whitelisted public Wi-Fi and the current risk quantification value, the posterior probability is calculated to be 40% (i.e., the probability that the current network environment is secure is 40%).

[0059] In one embodiment disclosed in this application, based on the posterior probability distribution of each risk dimension obtained by inversion, the comprehensive risk level of this digital certificate operation is obtained by aggregation logic (e.g., weighted summation or taking the maximum value of the posterior probabilities of each dimension, the weights can be set according to business needs, such as higher weight for device trustworthiness), and it is divided into standardized level categories, such as low risk (low overall probability of anomaly, all risk dimensions are within the normal range), medium risk (some dimensions deviate but the overall situation is controllable), high risk (significant deviation of multiple key dimensions, high probability of anomaly), and emergency risk (extremely high risk, there may be malicious operation or security incident). For different risk levels, corresponding strict hierarchical control actions are automatically triggered: for low-risk operations, only operation logs are usually recorded, and no additional intervention is required; for medium-risk operations, enhanced authentication processes (such as two-factor authentication), operation reminders (such as pop-up risk warning boxes), or increased operation monitoring frequency may be triggered; and for high-risk and above operations, strict control measures will be implemented, including but not limited to forcibly interrupting the current operation process, temporarily freezing the use of digital certificates, and initiating security audit processes (such as recording detailed operation logs and notifying security administrators to intervene in the investigation), to ensure the security of the use of public security digital certificates and prevent potential internal threats and external attacks.

[0060] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0061] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A dynamic supervision and management method for public security digital certificates integrating big data analysis, characterized by: The management method includes the following steps: A layered risk scanning mechanism is used to perform a two-level parallel scan, identify trustworthy operation feature points that are consistent with the normal mode, and calculate the risk deviation index of the trustworthy operation feature points. Based on the preset deviation threshold, the identified trustworthy operation feature points are divided into compliant points, slightly abnormal points and severely abnormal points. In the dimension of mild anomaly point operation occurrence, a neighboring reference interval is constructed. The frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer in the neighboring reference interval is compared. Adaptive processing is performed based on the comparison results. Sudden behavior pattern matching is performed on severe anomaly points to determine whether severe anomaly points meet the known risk operation characteristics. Adaptive processing is performed based on the judgment results. All credible operation feature points are integrated with the corrected feature points to output the feature set of this operation. The operation data of the feature set is input into the behavior-risk mapping model to derive the corresponding risk quantification value. Based on this, a risk probability assessment function is established. The prior knowledge provided by the macro baseline scanning layer is integrated, and the posterior probability distribution of this operation on each risk dimension is derived using probabilistic reasoning technology. The comprehensive risk level of this digital certificate operation is summarized based on the posterior probability distribution, and the corresponding hierarchical control action is automatically triggered.

2. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 1, characterized in that: A neighboring reference interval is constructed at the dimension of operation occurrence at minor anomalies. The frequency of compliant operations recorded by the macro baseline scan layer and the micro operation scan layer within the neighboring reference interval is compared. Adaptive processing is performed based on the comparison results, including the following steps: If the historical compliance records of the macro baseline scan layer are more than the performance of the current micro operation scan layer, the current mild anomaly is determined to be an occasional interference point, and the features of the mild anomaly are replaced with standardized operation features derived from the macro baseline scan layer; otherwise, they are retained.

3. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 2, characterized in that: Severe outliers are subjected to mutation behavior pattern matching to determine whether they conform to known risky operational characteristics. Based on the determination results, adaptive processing is performed, including the following steps: If a severe anomaly does not belong to a known risk pattern, then the frequency of compliant operations in the adjacent reference interval is compared. If the macro baseline scan layer records of severely anomalies are dominant or are judged to be at risk, the severely anomalies are marked as untrusted operation points and replaced with standardized features provided by the macro baseline scan layer.

4. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 2, characterized in that: The operational dimensions of the minor anomalies include the time, device, and network in which the operation occurred.

5. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 2, characterized in that: Perform mutation behavior pattern matching on severe outliers to determine whether they conform to known risky operational characteristics, including the following steps: Perform mutation behavior pattern matching on severely abnormal points and compare their actual performance with a predefined known risk operation feature library. The risk operation feature library contains pattern features that have been identified as high-risk or malicious behaviors in history. The pattern matching algorithm determines whether the current severe anomaly matches any known risk pattern in the database. If the match is successful, it is determined to be a risky behavior and enters the subsequent untrusted operation point processing flow. If the match fails, the frequency of compliant operations in the adjacent reference interval is compared. By comparing the frequency of compliant operations in the same or similar situations between the macro baseline scanning layer and the micro operation scanning layer, it is determined whether the anomaly still has compliance.

6. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 5, characterized in that: The logic for constructing the adjacent reference interval is as follows: Centered on the dimension in which anomalies occur in actual operation, a multi-dimensional neighborhood consisting of a time window, equipment usage range, and network environment range is selected to limit the scope of analysis, focusing on historical operation samples related to the actual occurrence context of anomalies.

7. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 1, characterized in that: Automatically trigger the corresponding hierarchical control actions, including the following steps: Record low-risk cases; Medium-risk situations may trigger enhanced certification or operational alerts. High risk and require mandatory interruption, temporary freezing of certificates, or initiation of security audit measures.

8. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 1, characterized in that: The stratified risk scanning mechanism includes a dual analytical dimension: a macro baseline scanning layer and a micro operational scanning layer.

9. The method for dynamic supervision and management of public security digital certificates integrating big data analysis according to claim 8, characterized in that: The macro baseline scanning layer includes scanning the compliance operation mode, equipment registration list, network whitelist environment and personnel behavior baseline in the historical period to establish a benchmark reference for risk assessment. The micro-operation scanning layer includes capturing the behavior sequence of this digital certificate operation, real-time device fingerprint, network connection characteristics, and operation context.

10. A dynamic supervision and management system for public security digital certificates integrating big data analysis, used to implement the management method described in any one of claims 1-9, characterized in that: It includes an operation feature anomaly classification module, a feature set output module, and a control module; Operational feature anomaly classification module: It adopts a hierarchical risk scanning mechanism to perform a two-level parallel scan, identify credible operational feature points that are consistent with the normal mode, and calculate the risk deviation index of credible operational feature points. Based on the preset deviation threshold, the identified credible operational feature points are classified into compliant points, mild anomalies, and severe anomalies. Feature set output module: Construct a neighboring reference interval in the dimension of operation occurrence of mild anomalies, compare the frequency of compliant operations recorded by the macro baseline scanning layer and the micro operation scanning layer in the neighboring reference interval, perform adaptive processing based on the comparison results, perform mutation behavior pattern matching for severe anomalies, determine whether severe anomalies meet the known risk operation characteristics, perform adaptive processing based on the judgment results, integrate all credible operation feature points with the corrected feature points, and output the feature set of this operation; Control module: Input the operation data of the feature set into the behavior-risk mapping model, derive the corresponding risk quantification value, and establish a risk probability assessment function based on it. Integrate the prior knowledge provided by the macro baseline scanning layer, use probabilistic reasoning technology to inversely derive the posterior probability distribution of this operation on each risk dimension, summarize the comprehensive risk level of this digital certificate operation based on the posterior probability distribution, and automatically trigger the corresponding hierarchical control action.