Password security management system and password management method

By employing technologies such as full-platform asset scanning, dual-encrypted storage, zero-trust dynamic credentials, and context-aware authorization, the system addresses issues such as memory leaks, delayed asset discovery, and coarse-grained permission allocation in enterprise password management. This achieves full lifecycle security coverage and closed-loop auditing, thereby enhancing the enterprise's password security protection capabilities.

CN121967039APending Publication Date: 2026-05-01BEIJING PUHUI RUNZE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610164216.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-05
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing enterprise password management methods suffer from issues such as memory leak risks, delayed asset discovery, coarse-grained permission allocation, and inability to trace abuse through auditing, making it difficult to build a secure and effective management system that covers the entire platform and the entire lifecycle.

Method used

It employs full-platform automatic asset scanning, dual-encrypted storage, zero-trust dynamic credentials, context-aware authorization, fine-grained permission allocation, operation proxy execution, and closed-loop audit tracking, combined with behavioral analysis for proactive defense, generating dynamic access credentials and security warning data.

Benefits of technology

It achieves full-platform password and account coverage, reduces the risk of leakage, provides precise access control, and promptly detects anomalies, forming a closed-loop audit throughout the entire lifecycle, significantly improving the level of password security protection for enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967039A_ABST
    Figure CN121967039A_ABST
Patent Text Reader

Abstract

The invention provides a password security management system and a password management method. The method belongs to the technical field of identity verification and access. The method comprises the following steps: carrying out full-platform asset automatic scanning on an enterprise network environment to generate dynamic asset list data; performing password account identification on various operating systems, databases, network equipment and business middleware according to the dynamic asset list data, and constructing a full-platform password account database; through the password security management method, the comprehensiveness and accuracy of enterprise password management are improved. Through full-platform asset automatic scanning and dynamic asset list construction, full-life-cycle management of various asset passwords of an enterprise is realized, and the management coverage range is expanded.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention proposes a password security management system and password management method, belonging to the field of authentication and access technology. Background Technology

[0002] In today's era of rapid enterprise informatization, various operating system platforms, database systems, network devices, and business system middleware are widely used in the daily operations of enterprises. These systems and devices all rely on passwords for identity authentication and access control, making password security management paramount.

[0003] However, current enterprise password management methods suffer from numerous fundamental flaws. Static password management, even with centralized storage, still faces risks of secondary exposure such as memory leaks and log entries when temporarily decrypting and returning plaintext passwords to users or scripts. Asset discovery mechanisms are severely lagging, relying heavily on manual input or simple port scanning, making it difficult to identify containerized middleware, headless service accounts, and shadow IT systems. Regarding access control, approval processes are based solely on roles, failing to consider real-time context, resulting in coarse-grained permission allocation. Auditing merely passively records password acquisition, unable to correlate with subsequent actual operations, making it difficult to trace abuse.

[0004] In addition, existing public solutions mostly focus on basic functions such as unified password management, automatic password change, and two-factor authentication. They do not deeply integrate elements such as automatic discovery, double encryption, access control, and audit trail with zero-trust dynamic credentials, behavior analysis, and operation agents. They cannot build a proactive and defensive password governance system and cannot meet the needs of enterprises for secure and effective password management that covers the entire platform and the entire lifecycle. Therefore, there is an urgent need for a new password security management method. Summary of the Invention

[0005] This invention provides a password security management system and a password management method to solve the problems mentioned in the background section above:

[0006] This invention proposes a password security management method, the method comprising:

[0007] S1. Perform automatic asset scanning across the entire enterprise network environment to generate dynamic asset inventory data; based on the dynamic asset inventory data, identify passwords and accounts for various operating systems, databases, network devices, and business middleware to build a full-platform password and account database;

[0008] S2. Based on the full-platform password and account database, perform dual encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, generate and replace the encrypted password credential data in real time to generate dynamic access credential data.

[0009] S3. Perform context-aware authorization processing based on dynamic access credential data, and generate dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; allocate permissions based on dynamic access control policies and generate fine-grained access permission data.

[0010] S4. Perform proxy execution processing on user operation behavior through refined access permission data to generate operation proxy execution log data; perform behavior analysis processing on operation proxy execution log data to generate operation behavior feature data; perform abnormal behavior detection based on operation behavior feature data to generate abnormal operation early warning data;

[0011] S5. Perform closed-loop audit tracking based on abnormal operation early warning data to generate full lifecycle audit trajectory data; conduct risk assessment based on the full lifecycle audit trajectory data to generate a password security risk index; adjust proactive defense strategies based on the password security risk index to generate enterprise password security early warning data.

[0012] This invention proposes a system for implementing the password security management method described above, the system comprising:

[0013] Platform construction module: Performs automatic scanning of enterprise network environment assets across the entire platform to generate dynamic asset inventory data; Based on the dynamic asset inventory data, identifies passwords and accounts for various operating systems, databases, network devices and business middleware, and builds a platform-wide password and account database;

[0014] Encrypted storage module: Based on the full-platform password and account database, it performs double encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, it generates and replaces encrypted password credential data in real time to generate dynamic access credential data.

[0015] The permission allocation module performs context-aware authorization processing based on dynamic access credential data, and generates dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; it then allocates permissions based on the dynamic access control policies to generate granular access permission data.

[0016] Behavior detection module: Performs proxy execution processing on user operation behavior through refined access permission data, generating operation proxy execution log data; performs behavior analysis processing on operation proxy execution log data, generating operation behavior feature data; and performs abnormal behavior detection based on operation behavior feature data, generating abnormal operation early warning data.

[0017] Security Early Warning Module: Based on abnormal operation early warning data, it performs closed-loop audit tracking and processing to generate full lifecycle audit trajectory data; based on the full lifecycle audit trajectory data, it conducts risk assessment to generate a password security risk index; based on the password security risk index, it adjusts proactive defense strategies and generates enterprise password security early warning data.

[0018] The beneficial effects of this invention are as follows: This password security management method improves the comprehensiveness and accuracy of enterprise password management. Automatic asset scanning and dynamic asset inventory construction across the entire platform enable full lifecycle management of passwords for various enterprise assets, increasing management coverage. Dual encryption storage and a zero-trust dynamic credential mechanism reduce the risk of password leakage during storage and transmission, enhancing password security. Context-aware authorization and fine-grained access permission allocation, combined with real-time login location and terminal security status, reduce the possibility of permission abuse and avoid security vulnerabilities caused by coarse-grained permission allocation. Operation proxy execution and closed-loop audit tracking ensure user operation compliance and promptly detect anomalies through behavioral analysis, reducing the risks of human error and malicious behavior. In complex network environments, this method avoids security incidents caused by delayed asset discovery, lax access control, and passive auditing, significantly improving the overall password security level of the enterprise and providing a solid guarantee for enterprise information security. Attached Figure Description

[0019] Figure 1 This is a diagram illustrating the steps of the method described in this invention;

[0020] Figure 2 This is a system module diagram of the present invention. Detailed Implementation

[0021] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0022] One embodiment of the present invention, such as Figure 1 As shown, a password security management method includes:

[0023] S1. Perform automatic asset scanning across the entire enterprise network environment to generate dynamic asset inventory data; based on the dynamic asset inventory data, identify passwords and accounts for various operating systems, databases, network devices, and business middleware to build a full-platform password and account database;

[0024] S2. Based on the full-platform password and account database, perform dual encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, generate and replace the encrypted password credential data in real time to generate dynamic access credential data.

[0025] S3. Perform context-aware authorization processing based on dynamic access credential data, and generate dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; allocate permissions based on dynamic access control policies and generate fine-grained access permission data.

[0026] S4. Perform proxy execution processing on user operation behavior through refined access permission data to generate operation proxy execution log data; perform behavior analysis processing on operation proxy execution log data to generate operation behavior feature data; perform abnormal behavior detection based on operation behavior feature data to generate abnormal operation early warning data;

[0027] S5. Perform closed-loop audit tracking based on abnormal operation early warning data to generate full lifecycle audit trajectory data; conduct risk assessment based on the full lifecycle audit trajectory data to generate a password security risk index; adjust proactive defense strategies based on the password security risk index to generate enterprise password security early warning data.

[0028] The working principle and effects of the above technical solution are as follows: By scanning assets across the entire platform and identifying password accounts, the integrity of enterprise password and account coverage is improved, avoiding security risks caused by hidden accounts. Dual encryption storage and a zero-trust dynamic credential mechanism enhance password storage and access security, reducing the risk of static password leakage. Context-aware authorization and fine-grained permission allocation improve the accuracy of permission control and reduce unauthorized access. Operation proxy execution and anomaly detection strengthen operation traceability and the timeliness of anomaly identification, reducing the concealment of security incidents. Closed-loop auditing and proactive defense dynamic adjustments enable rapid response to security risks and continuous optimization of protection mechanisms, preventing the escalation of security threats, reducing losses from password security incidents, and making enterprise password management more efficient and reliable.

[0029] In one embodiment of the present invention, S1 includes:

[0030] S11. Perform automatic asset scanning across the entire enterprise network environment to generate dynamic asset inventory data;

[0031] S12. Based on dynamic asset inventory data, classify and sort the asset attributes of operating systems, databases, network devices and business middleware, and generate asset classification map data;

[0032] S13. Based on asset classification map data, retrieve password account information from various types of assets and extract core fields such as account name, associated asset identifier, and account creation time.

[0033] S14. Integrate the extracted core fields of passwords and accounts, establish an account information association index, and build a password and account database for the entire platform.

[0034] The working principle and effects of the above technical solution are as follows: Automatic scanning of assets across the entire platform improves the comprehensiveness and timeliness of enterprise network asset discovery, avoiding the problem of missed or hidden assets during manual screening. Categorizing and organizing asset attributes to generate classification maps enhances the systematic nature of asset information and reduces the complexity of subsequent password and account retrieval. Targeted retrieval of core fields improves the accuracy of account information extraction and reduces the impact of invalid data on management efficiency. Integrating fields and establishing related indexes makes the password and account database structure across the entire platform more organized, enabling rapid tracing of the correspondence between accounts and assets and providing reliable data support for subsequent encrypted storage and access control. This avoids management gaps caused by scattered and disorganized account information, improving the fundamental reliability of enterprise password and account management from the source.

[0035] In one embodiment of the present invention, S2 includes:

[0036] S21. Based on the full-platform password account database, a dual encryption storage process combining asymmetric encryption and hash salting is used to generate encrypted password credential data.

[0037] S22. Collect user identity baseline information and device trusted identifier, and generate identity trusted baseline data;

[0038] S23. Combining identity trust benchmark data, temporary access credentials are generated in real time through a zero-trust dynamic credential mechanism to replace static password credentials and generate dynamic access credential data.

[0039] S24. Set time constraint parameters for dynamic access credential data, record the credential generation time, validity period and associated user information, and generate a set of dynamic access credentials with time constraints.

[0040] The working principle and effects of the above technical solution are as follows: Through dual processing of asymmetric encryption and hash salting, the security of password storage is enhanced, reducing the risk of passwords being cracked or leaked. Collecting user identity baselines and trusted device identifiers improves the credibility of identity verification and reduces the possibility of impersonation. Dynamic credentials replace static passwords, avoiding the problems of easy leakage and difficulty in management associated with long-term use of static passwords, and enhancing the security and flexibility of access credentials. Setting time-limited parameters gives dynamic credentials a clear validity period, reducing the potential for continued harm after credential theft. The entire process not only strengthens the security defense of password storage but also precisely controls access permissions, making password management more secure from storage to use, and preventing enterprise data leaks or unauthorized access incidents caused by credential security vulnerabilities.

[0041] In one embodiment of the present invention, step S21 includes:

[0042] Read the password and account database across the entire platform, extract the account name, original password information, and associated asset identifiers, and generate a core set of password and account information;

[0043] Based on the core information set of the password account, a random salt value is added to the original password information and mixed operation is performed to generate salted hash data.

[0044] The public key of the asymmetric encryption algorithm is used to encrypt the salted hash data, generating asymmetric encrypted data.

[0045] Associate asymmetric encrypted data with corresponding account identification information, organize the encrypted data structure, and generate encrypted password credential data.

[0046] The working principle and effects of the above technical solution are as follows: By accurately extracting core account information, the targeted nature of encryption processing is ensured, reducing the impact of invalid data on encryption efficiency. Random salt values ​​are mixed with the original password to enhance the password's resistance to cracking, avoiding the vulnerability of simple hashes to rainbow tables. Public key encryption of salted hash data further enhances the encryption layer, reducing the risk of theft and cracking during data transmission or storage. Associating encrypted data with account identifiers and organizing the structure makes encrypted credentials easier to trace and match, ensuring password storage security and providing convenient support for subsequent access verification. This avoids verification obstacles caused by chaotic encrypted data, thus building a strong security barrier for password information from the source.

[0047] In one embodiment of the present invention, S3 includes:

[0048] S31. Obtain dynamic access credential data and synchronously collect data related to the user's real-time login location, terminal security status, and historical user behavior patterns.

[0049] S32. Perform fusion analysis on the collected multi-dimensional environmental data, extract login scenario features and user behavior baselines, and generate contextual environment feature data;

[0050] S33. Perform context-aware authorization processing based on contextual environment feature data, formulate access control rules adapted to different scenarios, and generate dynamic access control policies.

[0051] S34. Based on dynamic access control policies, permission scopes are divided according to business roles, operation scenarios, and data sensitivity to generate refined access permission data.

[0052] The working principle and effects of the above technical solution are as follows: By synchronously collecting multi-dimensional environmental data, authorization judgment is more comprehensive, avoiding authorization bias caused by a single information dimension. By integrating and analyzing scenario features and behavioral baselines, the accuracy of context recognition is improved, reducing control vulnerabilities caused by scenario misjudgments. Access rules adapted to different scenarios are formulated to enhance the flexibility of access control and avoid the problem of a unified management model being difficult to adapt to complex scenarios. Permissions are divided into hierarchical levels according to multiple dimensions, improving the granularity of permission allocation and reducing the risk of unauthorized access. The entire process can accurately prevent and control security threats while adapting to the access needs of different business scenarios, avoiding excessive control that affects work efficiency, and making permission management more secure and practical.

[0053] In one embodiment of the present invention, S32 includes:

[0054] Receive and collect multi-dimensional environmental data, classify and organize it according to login location, terminal security status, and historical user behavior patterns, and generate categorized environmental data subsets.

[0055] The subset of classified environmental data is deduplicated and filtered for noise to remove invalid data and abnormal interference information, thereby generating clean environment data.

[0056] Geographic features, terminal configuration features, and network environment features of the login scenario are extracted from the cleanup environment data to generate scenario feature factors;

[0057] Analyze historical user behavior pattern data to identify statistical patterns, including operation frequency, operation time period, and operation object, and generate user behavior baseline data; integrate scenario feature factors with user behavior baseline data to establish feature association mapping and generate context environment feature data.

[0058] The working principle and effects of the above technical solution are as follows: By organizing multi-dimensional environmental data by category, the data structure becomes clearer, improving the efficiency of subsequent analysis and avoiding processing chaos caused by mixed data. Deduplication and noise filtering remove invalid interference information, enhancing data purity and reducing the impact of impurity data on feature extraction. Multi-dimensional scene features are extracted, making scene characterization more accurate and avoiding one-sided scene recognition caused by single features. Baselines are generated by statistically analyzing user behavior patterns, clearly defining the boundaries of normal behavior and reducing the probability of misjudging abnormal behavior. Scene features and behavioral baselines are integrated and correlated, making the contextual environmental feature data more comprehensive and three-dimensional. This provides a reliable basis for subsequent perception and authorization, avoids authorization decision bias caused by incomplete information, and makes the pre-judgment of permission control more accurate.

[0059] In one embodiment of the present invention, S33 includes:

[0060] Receive context environment feature data, split it into corresponding categories according to login scenario type, the corresponding categories include office scenario, remote scenario, public network scenario, and generate scenario classification feature set;

[0061] For different scenario-based feature sets, analyze the differences in security risk levels and access requirements under various scenarios, and generate a list of scenario security requirements;

[0062] Based on the security requirements list for each scenario, formulate rules for enabling authorization, restricting access operations, and defining the scope of data viewing for each scenario, and generate a scenario-based authorization rule set;

[0063] Integrate scenario-based authorization rule sets, unify rule expression formats, associate scenario classification identifiers with rule execution priorities, and generate dynamic access control policies.

[0064] The working principle and effects of the above technical solution are as follows: By splitting feature sets according to scenario type, the access characteristics of different scenarios become clearer, improving the targeting of rule formulation and avoiding the problem of uniform rules being difficult to adapt to diverse scenarios. Analyzing the differences in security risks and access requirements across various scenarios allows for precise grasp of the control priorities for different scenarios, reducing over-control or under-control. Developing scenario-based authorization rules clarifies authorization conditions, operational restrictions, and viewing scope, enhancing the accuracy of access control and reducing the risk of unauthorized access or illegal operations. Integrating rules and unifying their format and priorities makes dynamic access control policies more standardized and orderly, avoiding rule conflicts or chaotic execution. The entire process can accurately prevent and control security threats in different scenarios while adapting to the normal access needs of various scenarios, avoiding the impact of rigid control on work efficiency, and making access control more flexible and secure.

[0065] In one embodiment of the present invention, step S4 includes:

[0066] S41. Call the refined access permission data to perform proxy execution processing on various operation requests initiated by the user, record the proxy execution information, including the operation initiation time, operation content and permission verification result, and generate operation proxy execution log data;

[0067] S42. Extract key behavioral features from the operation agent execution log data. The key behavioral features include operation frequency, concentration of operation objects, and distribution of operation time periods, and generate log feature extraction data.

[0068] S43. Perform in-depth behavioral analysis on log feature extraction data, summarize user routine operation patterns and behavioral preferences, and generate operation behavior feature data;

[0069] S44. Compare and verify the operational behavior characteristic data with the regular operational patterns, identify operational behaviors that deviate from the baseline, and generate abnormal operation warning data.

[0070] The working principle and effects of the above technical solution are as follows: By proxying user operations and fully recording key information, the traceability of operational behavior is improved, reducing situations where operations are untraceable. Key features such as operation frequency and object concentration are extracted, making behavioral analysis more targeted and enhancing the accuracy of understanding user operation patterns. In-depth analysis and summarization of routine operation patterns and preferences clearly define the boundaries of normal behavior, reducing the probability of misjudging abnormal behavior. Comparison and verification between actual behavior and baseline quickly identifies deviations, improving the timeliness of abnormal behavior detection and preventing the continued spread of potential security threats. The entire process can strictly control user operation compliance while adapting to normal business operation needs, reducing the impact of excessive intervention on work efficiency, making security monitoring more practical, and effectively preventing enterprise data security risks caused by violations or abnormal operations.

[0071] In one embodiment of the present invention, step S5 includes:

[0072] S51. Receive abnormal operation warning data, link operation agent execution log data, dynamic access control policies and full life cycle account operation records, perform closed-loop audit tracking processing, and generate full life cycle audit trajectory data.

[0073] S52. Extract key indicators from the full lifecycle audit trajectory data, including the frequency of risk events, the level of assets affected, and the degree of operational violations, and generate basic data for risk assessment.

[0074] S53. Quantify the basic data of risk assessment and generate a password security risk index by combining the asset importance weight and security threat level.

[0075] S54. Based on the password security risk index, adjust the rule thresholds, response speed, and protection scope of proactive defense, optimize the defense mechanism, and generate enterprise password security early warning data.

[0076] The working principle and effects of the above technical solution are as follows: By linking multiple types of data for closed-loop audit tracking, risk event tracing is more complete, improving the comprehensiveness and accuracy of audits and avoiding audit loopholes caused by single data sources. Core risk indicators are extracted to generate basic assessment data, providing a clear basis for risk judgment and reducing biases caused by subjective judgment. Quantitative calculations combined with asset weights and threat levels make the risk index more closely reflect the actual situation, improving the accuracy of risk identification. Defense mechanisms are dynamically adjusted based on the risk index, optimizing rule thresholds, response speed, and protection scope, enhancing the adaptability of defenses and preventing rigid defenses from being unable to cope with new risks. The entire process can quickly locate the root cause of risks and continuously iterate protection strategies, reducing losses caused by password security incidents and forming a complete closed loop for enterprise password security management, making it more reliable and sustainable.

[0077] In one embodiment of the present invention, S53 includes:

[0078] Receive basic risk assessment data, simultaneously collect data related to asset importance weights and security threat levels, and classify and organize them to form a set of basic data and weight levels;

[0079] The frequency of risk events, the level of assets affected, and the degree of operational violations in the basic data of risk assessment are quantified and assigned values ​​to generate quantitative data for individual indicators.

[0080] Based on the asset importance weight, the quantitative data of individual indicators are weighted and calculated to generate weighted composite indicator data;

[0081] By combining the security threat level, the weighted comprehensive indicator data is corrected with a level coefficient to balance the indicator weight ratio under different threat levels;

[0082] The revised weighted composite index data is aggregated, a comprehensive quantitative score is calculated, and a password security risk index is generated.

[0083] The working principle and effects of the above technical solution are as follows: By synchronously collecting and classifying basic data and weight level sets, the data source for risk assessment becomes more standardized, avoiding calculation biases caused by data clutter. Each risk indicator is quantified and assigned a value, transforming vague risk elements into concrete data, improving the objectivity of the assessment, and reducing errors caused by subjective judgment. Weighted calculations are performed according to the importance of assets, highlighting the risk impact of core assets and avoiding confusion in risk priority caused by considering all assets equally. The weights of indicators are adjusted in conjunction with security threat levels to balance the risk proportion under different threat scenarios, enhancing the scenario adaptability of risk assessment and avoiding the problem that a single calculation model cannot cope with diverse threats. Finally, a comprehensive quantitative score is obtained, making the password security risk index more accurate and comprehensive. This provides a reliable basis for subsequent adjustments to defense mechanisms and avoids over- or under-defense due to inaccurate risk assessment, effectively improving the scientific nature of password security risk judgment.

[0084] In one embodiment of the present invention, S54 includes:

[0085] The security risk index for receiving passwords is divided into three levels: high risk, medium risk, and low risk, based on the risk value range, and a risk level classification result is generated.

[0086] Based on the risk level classification results, the trigger thresholds for proactive defense rules are adjusted accordingly: the thresholds are lowered for high-risk levels, maintained at the baseline thresholds for medium-risk levels, and raised for low-risk levels, generating the adjusted threshold parameters.

[0087] Based on the differences in risk levels, optimize the response speed of proactive defense: improve real-time response efficiency for high-risk levels, maintain a normal response rate for medium-risk levels, and adopt an on-demand response mode for low-risk levels, generating response speed configuration data.

[0088] Based on the risk level and the distribution of enterprise assets, the scope of protection is adjusted: high-risk level is expanded to full asset protection, medium-risk level focuses on core asset protection, and low-risk level targets key area protection, generating protection scope definition data.

[0089] Integrate and adjust threshold parameters, response speed configuration data, and protection range definition data, optimize the collaborative operation logic of the active defense mechanism, and generate optimized defense mechanism parameters;

[0090] Based on the optimized defense mechanism parameters, the warning trigger conditions, notification targets, and handling suggestions are clarified to generate enterprise password security warning data.

[0091] The working principle and effects of the above technical solution are as follows: By classifying risks into levels based on risk values, defense adjustments become more targeted, avoiding a one-size-fits-all approach that could lead to defense imbalances. Dynamically adjusting rule trigger thresholds—lowering thresholds for high-risk threats and raising thresholds for low-risk threats—improves early warning accuracy and reduces false alarms or missed alarms. Optimizing response speed based on risk levels—real-time response for high-risk threats and on-demand response for low-risk threats—enhances defense flexibility and prevents excessive resource consumption or delayed risk response. Adjusting the protection scope based on asset distribution, focusing on core and key areas, improves the utilization rate of protection resources and reduces ineffective protection waste. Integrating parameters to optimize defense collaboration logic makes the mechanism run more smoothly and avoids poor coordination between links affecting protection effectiveness. Clearly defining early warning conditions and handling suggestions improves emergency response efficiency and prevents the risk from escalating. The entire process can accurately respond to different levels of security threats and rationally allocate protection resources, making proactive defense more practical and efficient, effectively strengthening the enterprise's password security defense line.

[0092] One embodiment of the present invention, such as Figure 2 As shown, a system for implementing the password security management method as described above is characterized in that the system comprises:

[0093] Platform construction module: Performs automatic scanning of enterprise network environment assets across the entire platform to generate dynamic asset inventory data; Based on the dynamic asset inventory data, identifies passwords and accounts for various operating systems, databases, network devices and business middleware, and builds a platform-wide password and account database;

[0094] Encrypted storage module: Based on the full-platform password and account database, it performs double encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, it generates and replaces encrypted password credential data in real time to generate dynamic access credential data.

[0095] The permission allocation module performs context-aware authorization processing based on dynamic access credential data, and generates dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; it then allocates permissions based on the dynamic access control policies to generate granular access permission data.

[0096] Behavior detection module: Performs proxy execution processing on user operation behavior through refined access permission data, generating operation proxy execution log data; performs behavior analysis processing on operation proxy execution log data, generating operation behavior feature data; and performs abnormal behavior detection based on operation behavior feature data, generating abnormal operation early warning data.

[0097] Security Early Warning Module: Based on abnormal operation early warning data, it performs closed-loop audit tracking and processing to generate full lifecycle audit trajectory data; based on the full lifecycle audit trajectory data, it conducts risk assessment to generate a password security risk index; based on the password security risk index, it adjusts proactive defense strategies and generates enterprise password security early warning data.

[0098] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A password security management method, characterized in that, The method includes: S1. Perform automatic asset scanning across the entire enterprise network environment to generate dynamic asset inventory data; based on the dynamic asset inventory data, identify passwords and accounts for various operating systems, databases, network devices, and business middleware to build a full-platform password and account database; S2. Based on the full-platform password and account database, perform dual encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, generate and replace the encrypted password credential data in real time to generate dynamic access credential data. S3. Perform context-aware authorization processing based on dynamic access credential data, and generate dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; allocate permissions based on dynamic access control policies and generate fine-grained access permission data. S4. Perform proxy execution processing on user operation behavior through refined access permission data to generate operation proxy execution log data; perform behavior analysis processing on operation proxy execution log data to generate operation behavior feature data; perform abnormal behavior detection based on operation behavior feature data to generate abnormal operation early warning data; S5. Perform closed-loop audit tracking based on abnormal operation early warning data to generate full lifecycle audit trajectory data; conduct risk assessment based on the full lifecycle audit trajectory data to generate a password security risk index; adjust proactive defense strategies based on the password security risk index to generate enterprise password security early warning data.

2. The password security management method according to claim 1, characterized in that, S1 includes: S11. Perform automatic asset scanning across the entire enterprise network environment to generate dynamic asset inventory data; S12. Based on dynamic asset inventory data, classify and sort the asset attributes of operating systems, databases, network devices and business middleware, and generate asset classification map data; S13. Based on asset classification map data, retrieve password account information from various types of assets and extract core fields such as account name, associated asset identifier, and account creation time. S14. Integrate the extracted core fields of passwords and accounts, establish an account information association index, and build a password and account database for the entire platform.

3. The password security management method according to claim 1, characterized in that, The S2 includes: S21. Based on the full-platform password account database, a dual encryption storage process combining asymmetric encryption and hash salting is used to generate encrypted password credential data. S22. Collect user identity baseline information and device trusted identifier, and generate identity trusted baseline data; S23. Combining identity trust benchmark data, temporary access credentials are generated in real time through a zero-trust dynamic credential mechanism to replace static password credentials and generate dynamic access credential data. S24. Set time constraint parameters for dynamic access credential data, record the credential generation time, validity period and associated user information, and generate a set of dynamic access credentials with time constraints.

4. The password security management method according to claim 3, characterized in that, S21 includes: Read the password and account database across the entire platform, extract the account name, original password information, and associated asset identifiers, and generate a core set of password and account information; Based on the core information set of the password account, a random salt value is added to the original password information and mixed operation is performed to generate salted hash data. The public key of the asymmetric encryption algorithm is used to encrypt the salted hash data, generating asymmetric encrypted data. Associate asymmetric encrypted data with corresponding account identification information, organize the encrypted data structure, and generate encrypted password credential data.

5. The password security management method according to claim 1, characterized in that, The S3 includes: S31. Obtain dynamic access credential data and synchronously collect data related to the user's real-time login location, terminal security status, and historical user behavior patterns. S32. Perform fusion analysis on the collected multi-dimensional environmental data, extract login scenario features and user behavior baselines, and generate contextual environment feature data; S33. Perform context-aware authorization processing based on contextual environment feature data, formulate access control rules adapted to different scenarios, and generate dynamic access control policies. S34. Based on dynamic access control policies, permission scopes are divided according to business roles, operation scenarios, and data sensitivity to generate refined access permission data.

6. The password security management method according to claim 5, characterized in that, S32 includes: Receive and collect multi-dimensional environmental data, classify and organize it according to login location, terminal security status, and historical user behavior patterns, and generate categorized environmental data subsets. The subset of classified environmental data is deduplicated and filtered for noise to remove invalid data and abnormal interference information, thereby generating clean environment data. Geographic features, terminal configuration features, and network environment features of the login scenario are extracted from the cleanup environment data to generate scenario feature factors; Analyze historical user behavior pattern data, statistically identify patterns, and generate user behavior baseline data; integrate scenario feature factors with user behavior baseline data, establish feature association mapping, and generate contextual environment feature data.

7. The password security management method according to claim 1, characterized in that, The S4 includes: S41. Call the refined access permission data to perform proxy execution processing on various operation requests initiated by users, record proxy execution information, and generate operation proxy execution log data; S42. Extract key behavioral features from the operation agent execution log data and generate log feature extraction data; S43. Perform in-depth behavioral analysis on log feature extraction data, summarize user routine operation patterns and behavioral preferences, and generate operation behavior feature data; S44. Compare and verify the operational behavior characteristic data with the regular operational patterns, identify operational behaviors that deviate from the baseline, and generate abnormal operation warning data.

8. The password security management method according to claim 1, characterized in that, The S5 includes: S51. Receive abnormal operation warning data, link operation agent execution log data, dynamic access control policies and full life cycle account operation records, perform closed-loop audit tracking processing, and generate full life cycle audit trajectory data. S52. Extract key indicators from the full lifecycle audit trajectory data to generate basic data for risk assessment; S53. Quantify the basic data of risk assessment and generate a password security risk index by combining the asset importance weight and security threat level. S54. Based on the password security risk index, adjust the rule thresholds, response speed, and protection scope of proactive defense, optimize the defense mechanism, and generate enterprise password security early warning data.

9. The password security management method according to claim 8, characterized in that, S54 includes: The security risk index for receiving passwords is divided into three levels: high risk, medium risk, and low risk, based on the risk value range, and a risk level classification result is generated. Based on the risk level classification results, the trigger thresholds for proactive defense rules are adjusted accordingly: the thresholds are lowered for high-risk levels, maintained at the baseline thresholds for medium-risk levels, and raised for low-risk levels, generating the adjusted threshold parameters. Based on the differences in risk levels, optimize the response speed of proactive defense: improve real-time response efficiency for high-risk levels, maintain a normal response rate for medium-risk levels, and adopt an on-demand response mode for low-risk levels, generating response speed configuration data. Based on the risk level and the distribution of enterprise assets, the scope of protection is adjusted: high-risk level is expanded to full asset protection, medium-risk level focuses on core asset protection, and low-risk level targets key area protection, generating protection scope definition data. Integrate and adjust threshold parameters, response speed configuration data, and protection range definition data, optimize the collaborative operation logic of the active defense mechanism, and generate optimized defense mechanism parameters; Based on the optimized defense mechanism parameters, the warning trigger conditions, notification targets, and handling suggestions are clarified to generate enterprise password security warning data.

10. A system for implementing the password security management method as described in claim 1, characterized in that, The system includes: Platform construction module: Performs automatic scanning of enterprise network environment assets across the entire platform to generate dynamic asset inventory data; Based on the dynamic asset inventory data, identifies passwords and accounts for various operating systems, databases, network devices and business middleware, and builds a platform-wide password and account database; Encrypted storage module: Based on the full-platform password and account database, it performs double encryption storage processing to generate encrypted password credential data; through a zero-trust dynamic credential mechanism, it generates and replaces encrypted password credential data in real time to generate dynamic access credential data. The permission allocation module performs context-aware authorization processing based on dynamic access credential data, and generates dynamic access control policies by combining real-time login location, terminal security status, and user behavior patterns; it then allocates permissions based on the dynamic access control policies to generate granular access permission data. Behavior detection module: Performs proxy execution processing on user operation behavior through refined access permission data, generating operation proxy execution log data; performs behavior analysis processing on operation proxy execution log data, generating operation behavior feature data; and performs abnormal behavior detection based on operation behavior feature data, generating abnormal operation early warning data. Security Early Warning Module: Based on abnormal operation early warning data, it performs closed-loop audit tracking and processing to generate full lifecycle audit trajectory data; based on the full lifecycle audit trajectory data, it conducts risk assessment to generate a password security risk index; based on the password security risk index, it adjusts proactive defense strategies and generates enterprise password security early warning data.