Computer terminal data encryption and security access control method
By constructing a closed-loop system with multi-level authentication and dynamic encryption strategies, the problems of single authentication and fixed encryption strategies in computer terminal data security protection are solved, achieving adaptive security protection and real-time monitoring, and improving data security and compliance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 王振宁
- Filing Date
- 2026-04-07
- Publication Date
- 2026-05-15
AI Technical Summary
Existing technologies for computer terminal data security protection suffer from problems such as single authentication methods, fixed encryption strategies, and a lack of real-time monitoring and adaptive capabilities. This results in rigid security protection capabilities, making it difficult to meet the differentiated protection needs of data with different sensitivity levels and user permissions.
A multi-level authentication mechanism is constructed, employing dynamic encryption strategies and a closed-loop monitoring and feedback system for abnormal behavior. Through multi-level authentication ports, a data encryption processing center, and an anomaly monitoring terminal, identity authentication, dynamic encryption, and real-time monitoring are achieved, and encryption strategies and permission configurations are dynamically adjusted.
It achieves adaptive security protection for computer terminal data, improves the ability to identify and respond to abnormal access, enhances data security and compliance, and supports remote management and intelligent control.
Smart Images

Figure CN122053249A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer terminal data processing technology, specifically to a method for encrypting and securely accessing computer terminal data. Background Technology
[0002] With the deepening of digital transformation, a large amount of core data from enterprises, government agencies, and individuals is stored on computer terminals. Data breaches and unauthorized access are frequent security incidents, posing serious challenges to information security and privacy protection. As the core node for data storage and processing, the data security protection capabilities of computer terminals are directly related to the security of the entire information system.
[0003] Currently, computer terminal data security protection mainly employs static encryption and single identity authentication. Static encryption refers to encrypting stored data using a fixed algorithm. Once the encryption strategy is set, it remains unchanged, making it difficult to adapt to the differentiated protection needs of data with different sensitivity levels, and also unable to dynamically adjust the encryption strength based on user permission levels and terminal operating status. Single identity authentication primarily relies on password verification, which carries the risk of unauthorized access after password leakage, and lacks the ability to continuously monitor user access behavior.
[0004] Chinese Patent Publication No. CN 120455103 A discloses an invention in the field of secure data transmission, specifically disclosing a blockchain-based method and system for secure encrypted transmission and access control. It includes a client-side encryption module, a server-side decryption module, a dynamic access control engine, and a blockchain-based evidence storage unit. The client-side encryption module uses an AES+RSA hybrid encryption algorithm to encrypt and transmit sensitive data such as trade secrets and customer information. The server-side decryption module achieves secure decryption through a key management system; a hardware security chip (HSM) stores RSA key pairs for key decryption, enabling key rotation and lifecycle management. The dynamic access control engine, based on RBAC role-based access control and real-time behavior analysis, dynamically adjusts user permissions to prevent unauthorized access. The blockchain-based evidence storage unit records data operation logs, ensuring data traceability and immutability. This invention solves the risks of data leakage and abuse of permissions during transmission and storage, significantly improving data security and compliance.
[0005] However, the above solution still has the following problems: The authentication method is too simple and cannot defend against security threats such as password leakage and credential stuffing attacks; The encryption strategy is fixed and cannot be dynamically adjusted according to factors such as data sensitivity and user permission level, resulting in insufficient encryption strength or performance redundancy due to a one-size-fits-all approach. The lack of real-time monitoring and anomaly identification capabilities for access behavior makes it impossible to detect and block unauthorized access in a timely manner. The lack of an adaptive security mechanism based on behavioral feedback makes it impossible to dynamically adjust encryption strategies and permission configurations according to abnormal access characteristics, resulting in rigid security protection capabilities and causing many inconveniences.
[0006] Therefore, this invention requires the design of a computer terminal data encryption and secure access control method to solve the above-mentioned problems. Summary of the Invention:
[0007] The purpose of this invention is to provide a computer terminal data encryption and secure access control method to solve the above-mentioned problems. By constructing a multi-level authentication mechanism, dynamic encryption strategy and abnormal behavior monitoring feedback closed loop, it realizes secure protection and adaptive security management of terminal data, thus solving the problems mentioned in the background art.
[0008] To address the above problems, the present invention provides a technical solution: A method for encrypting and securely accessing computer terminal data includes the following specific steps: S1. Construct an encryption and secure access control system, generate a multi-level authentication mechanism, and perform identity authentication and permission granting for users accessing computer terminals. S2. The data to be encrypted in the computer terminal is encrypted using a dynamic encryption strategy to generate an encrypted data packet and a corresponding decryption key. S3. Monitor data access behavior in real time, identify, block and warn of abnormal access, and dynamically adjust encryption policies and permission configurations based on access behavior feedback; when abnormal access is identified, automatically block access requests and record abnormal logs, and send warning information to the system administrator.
[0009] In a preferred embodiment of the present invention, step S1 further includes the following specific steps: S101. Collect user identity information, which includes at least two of static passwords, dynamic verification codes, and biometric information to form multi-factor authentication. The biometric information includes user facial data, voice data, fingerprint data, and ID account data. S102. Based on the authenticated user's identity information, query the preset permission configuration table and grant the user the corresponding data access permission, which includes at least one of read-only permission, read-write permission, and administrator permission.
[0010] In a preferred embodiment of the present invention, the dynamic encryption strategy in step S2 includes selecting a corresponding encryption algorithm and key length based on at least one parameter among data sensitivity level, user permission level, and terminal operating status.
[0011] In a preferred embodiment of the present invention, the abnormal access in step S3 includes at least one of unauthorized access attempts, high-frequency access requests, access during unusual time periods, and access from different locations. When abnormal access is detected, the access request is automatically blocked and an abnormal log is recorded.
[0012] In a preferred embodiment of the present invention, the multi-level authentication mechanism in step S1 further includes continuous verification of user access behavior. When user behavior is detected to deviate from a preset behavior baseline, secondary authentication is triggered.
[0013] In a preferred embodiment of the present invention, the encryption and secure access control system includes a multi-level authentication port, a data encryption processing center, and an anomaly monitoring terminal. The multi-level authentication port and the data encryption processing center are bidirectionally connected, and the data encryption processing center and the anomaly monitoring terminal are bidirectionally connected. The multi-level authentication port is used to perform identity authentication and permission granting in step S1, the data encryption processing center is used to perform data encryption processing in step S2, and the anomaly monitoring terminal is used to perform anomaly access monitoring and response in step S3.
[0014] In a preferred embodiment of the present invention, the multi-level authentication port includes a multi-level authentication unit, an identity and access control unit, and a synchronization warning unit. The output of the multi-level authentication unit is communicatively connected to the input of the identity and access control unit, and both the multi-level authentication unit and the identity and access control unit are bidirectionally communicatively connected to the synchronization warning unit. The multi-level identity verification unit is used to collect the user's identity information and compare it with a preset identity database to verify the authenticity of the user's identity, including verifying the user's facial data, voice data, fingerprint data, and ID account data. The identity and access control unit is used to grant corresponding data access permissions based on the verified user identity information, and to record the user's operation permission scope; The synchronous early warning unit is used to send early warning information to the system administrator when multiple authentication failures or abnormal permission granting occur, and to lock the user's access request, while locating the location of the access request and querying the personnel who made the access.
[0015] In a preferred embodiment of the present invention, the data encryption processing center includes a data encryption unit, a data processing library, and a key management unit. The output end of the data encryption unit is communicatively connected to the input end of the data processing library, and the data processing library and the key management unit are bidirectionally communicatively connected. The data encryption unit is used to select an encryption algorithm according to a dynamic encryption strategy, encrypt the data to be encrypted, and generate an encrypted data packet. The encryption algorithm can be manually added or deleted according to a preset, and can be a single algorithm or a combination of multiple algorithms. The data processing library is used to store encrypted data packets, encryption algorithm parameters, and encryption history records. It supports the retrieval and retrieval of encrypted data. The data processing library is set with an additional access password for two-factor authentication, and the corresponding permissions can only query the data corresponding to the permissions. The key management unit is used to generate, store, and distribute decryption keys, and to audit the use of keys and manage their lifecycle.
[0016] In a preferred embodiment of the present invention, the anomaly monitoring terminal includes an anomaly monitoring unit, a self-processing learning model, and a network monitoring unit, wherein the outputs of the anomaly monitoring unit and the network monitoring unit are communicatively connected to the input of the self-processing learning model. The anomaly monitoring unit is used to monitor data access behavior in real time, identify abnormal access characteristics, perform blocking or early warning operations, and generate anomaly reports; the anomaly monitoring unit is also used to monitor abnormal data from devices. The self-processing learning model is used to train an anomaly recognition model based on historical anomaly data and normal access behavior data, and dynamically update the model parameters according to new anomaly data. It can self-process problems that have appeared and been resolved in the historical records, and send the corresponding anomaly data and self-resolvement process to the remote system administrator. The network monitoring unit is used to monitor the network communication status of computer terminals, identify abnormal network traffic and external attack behavior, and coordinate with the anomaly monitoring unit to implement protective measures.
[0017] In a preferred embodiment of the present invention, the encryption and secure access control system further includes a mobile control terminal, which is used to receive abnormal warning information, allowing the system administrator to remotely review abnormal access requests, temporarily adjust user permissions, or remotely lock computer terminals.
[0018] The beneficial effects of this invention are as follows: This invention constructs an encryption and secure access control system by setting up multi-level authentication ports, a data encryption processing center, and an anomaly monitoring terminal. It generates a multi-level authentication mechanism to authenticate and grant permissions to users accessing computer terminals. It encrypts the data to be encrypted within the computer terminal using a dynamic encryption strategy, generating encrypted data packets and corresponding decryption keys. It identifies, blocks, and issues warnings for abnormal access by monitoring data access behavior in real time, and dynamically adjusts encryption strategies and permission configurations based on access behavior feedback. When abnormal access is detected, the system automatically blocks the access request, records the anomaly log, and sends a warning message to the system administrator. The mobile control terminal and the encryption and secure access control system are connected via an encrypted communication channel. When the anomaly monitoring terminal issues a warning message, the system automatically pushes the abnormal event to the system administrator's mobile control terminal. Administrators can remotely review abnormal access requests via a mobile control terminal, view exception details and solution suggestions generated by the self-processing learning model, and perform operations such as temporarily adjusting user permissions, remotely locking computer terminals, and forcibly removing suspicious users. The mobile control terminal supports multiple administrators operating together, and all operation records are uploaded to the data processing database for auditing. It manages, visualizes, and stores encryption and security access control data and corresponding analysis results, which helps to realize encryption and security access control management through Internet cloud management and improve the level of intelligence of encryption and security access control management. Attached image description:
[0019] For ease of explanation, the present invention will be described in detail below with reference to specific embodiments and accompanying drawings.
[0020] Figure 1 This is an overall flowchart of a computer terminal data encryption and secure access control method according to the present invention; Figure 2 This is a flowchart of step S1 in the computer terminal data encryption and secure access control method of the present invention; Figure 3 This is an operational flowchart of a computer terminal data encryption and secure access control method according to the present invention. Detailed implementation method:
[0021] like Figure 1 , Figure 2 and Figure 3 As shown, the specific implementation adopts the following technical solution: A method for encrypting and securely accessing computer terminal data includes the following specific steps: S1. Construct an encryption and secure access control system, generate a multi-level authentication mechanism, and perform identity authentication and permission granting for users accessing computer terminals. S2. The data to be encrypted in the computer terminal is encrypted using a dynamic encryption strategy to generate an encrypted data packet and a corresponding decryption key. S3. Monitor data access behavior in real time, identify, block and warn of abnormal access, and dynamically adjust encryption policies and permission configurations based on access behavior feedback; when abnormal access is identified, automatically block access requests and record abnormal logs, and send warning information to the system administrator.
[0022] Step S1 also includes the following specific steps: S101. Collect user identity information, which includes at least two of static passwords, dynamic verification codes, and biometric information to form multi-factor authentication. The biometric information includes user facial data, voice data, fingerprint data, and ID account data. S102. Based on the authenticated user's identity information, query the preset permission configuration table and grant the user the corresponding data access permission, which includes at least one of read-only permission, read-write permission, and administrator permission.
[0023] The dynamic encryption strategy in step S2 includes selecting the corresponding encryption algorithm and key length based on at least one parameter among data sensitivity level, user permission level, and terminal operating status.
[0024] The abnormal access in step S3 includes at least one of unauthorized access attempts, high-frequency access requests, access during unusual time periods, and access from different locations. When abnormal access is detected, the access request is automatically blocked and an abnormal log is recorded.
[0025] The multi-level authentication mechanism in step S1 also includes continuous verification of user access behavior. When user behavior deviates from the preset behavior baseline, secondary authentication is triggered.
[0026] The encryption and secure access control system includes a multi-level authentication port, a data encryption processing center, and an anomaly monitoring terminal. The multi-level authentication port and the data encryption processing center are bidirectionally connected, and the data encryption processing center and the anomaly monitoring terminal are bidirectionally connected. The multi-level authentication port is used to perform identity authentication and permission granting in step S1. The data encryption processing center is used to perform data encryption processing in step S2. The anomaly monitoring terminal is used to perform anomaly access monitoring and response in step S3.
[0027] The multi-level authentication port includes a multi-level authentication unit, an identity and access control unit, and a synchronization early warning unit. The output of the multi-level authentication unit is communicatively connected to the input of the identity and access control unit, and both the multi-level authentication unit and the identity and access control unit are bidirectionally communicatively connected to the synchronization early warning unit. The multi-level authentication unit is used to collect the user's identity information and compare it with a preset identity database to verify the authenticity of the user's identity, including verifying the user's facial data, voice data, fingerprint data, and ID account data. The identity and access control unit is used to grant corresponding data access permissions based on the verified user's identity information and record the user's operation permission scope. The synchronization early warning unit is used to send early warning information to the system administrator when multiple authentication failures or abnormal permission granting occur, and to lock the user's access request, while locating the location of the access request and querying the personnel who accessed it.
[0028] The data encryption processing center includes a data encryption unit, a data processing library, and a key management unit. The output of the data encryption unit is communicatively connected to the input of the data processing library, and the data processing library and the key management unit are bidirectionally connected. The data encryption unit is used to select an encryption algorithm according to a dynamic encryption strategy, encrypt the data to be encrypted, and generate encrypted data packets. The encryption algorithms can be manually added or removed according to presets, and can be a single algorithm or a combination of multiple algorithms. The data processing library is used to store encrypted data packets, encryption algorithm parameters, and encryption history records, and supports the retrieval and retrieval of encrypted data. The data processing library is equipped with an additional access password for two-factor authentication, and corresponding permissions can only query data corresponding to their permissions. The key management unit is used to generate, store, and distribute decryption keys, and to audit the use of keys and manage their lifecycle.
[0029] The anomaly monitoring terminal includes an anomaly monitoring unit, a self-processing learning model, and a network monitoring unit. The outputs of both the anomaly monitoring unit and the network monitoring unit are communicatively connected to the input of the self-processing learning model. The anomaly monitoring unit is used to monitor data access behavior in real time, identify abnormal access characteristics, perform blocking or early warning operations, and generate anomaly reports. The anomaly monitoring unit is also used to monitor abnormal data from devices. The self-processing learning model is used to train anomaly identification models based on historical anomaly data and normal access behavior data, and dynamically update model parameters according to new anomaly data. It self-processes problems that have occurred and been resolved in historical records, and simultaneously sends corresponding anomaly data and self-resolvement procedures to the remote system administrator. The network monitoring unit is used to monitor the network communication status of computer terminals, identify abnormal network traffic and external attack behaviors, and coordinate with the anomaly monitoring unit to implement protective measures.
[0030] The encryption and secure access control system also includes a mobile control terminal, which is used to receive abnormal warning information, allowing system administrators to remotely review abnormal access requests, temporarily adjust user permissions, or remotely lock computer terminals.
[0031] System Construction and Identity Authentication S1. Construct an encryption and secure access control system, generate a multi-level authentication mechanism, and perform identity authentication and permission granting for users accessing computer terminals. S101. The encryption and secure access control system includes a multi-level authentication port, a data encryption processing center, and an anomaly monitoring terminal. The multi-level authentication port is used to perform identity authentication and permission granting. The data encryption processing center is used to perform data encryption processing. The anomaly monitoring terminal is used to perform anomaly access monitoring and response. S102. The multi-level authentication port includes a multi-level authentication unit, an identity and access control unit, and a synchronization warning unit. The output of the multi-level authentication unit is kept in communication with the input of the identity and access control unit, and both the multi-level authentication unit and the identity and access control unit are kept in bidirectional communication with the synchronization warning unit. S103. The encryption and secure access control system controls the multi-level authentication unit to collect the user's identity information, which includes at least two of the following: static password, dynamic verification code, and biometric information, to form multi-factor authentication. The biometric information includes one or more combinations of the user's facial data, voice data, fingerprint data, and ID account data. S104. The multi-level authentication unit compares the collected identity information with the preset identity database to verify the authenticity of the user's identity. When authentication is successful, the authentication result is sent to the identity and access control unit; when multiple authentication attempts fail, the synchronous early warning unit sends an early warning message to the system administrator, locks the user's access request, and simultaneously locates the location of this access request and queries the information of the person accessing the request. S105. The encryption and secure access control system's identity and permission control unit, based on the verified user identity information, queries a preset permission configuration table and grants the user the corresponding data access permissions. The data access permissions include at least one of read-only permissions, read-write permissions, and administrator permissions, and the user's operation permission scope is recorded. S106. The encryption and secure access control system's multi-level authentication mechanism also includes continuous verification of user access behavior. When user behavior deviates from the preset behavior baseline, secondary authentication is triggered, requiring the user to resubmit identity information for confirmation.
[0032] Dynamic encryption processing S201. The encryption and secure access control system's data encryption processing center uses a dynamic encryption strategy to encrypt the data to be encrypted in the computer terminal, generating encrypted data packets and corresponding decryption keys. S202. The data encryption processing center includes a data encryption unit, a data processing library, and a key management unit. The output end of the data encryption unit is kept in communication with the input end of the data processing library, and the data processing library and the key management unit are kept in bidirectional communication. S203. The encryption and secure access control system control data encryption unit selects an encryption algorithm according to a dynamic encryption strategy and performs encryption processing on the data to be encrypted. The dynamic encryption strategy includes selecting the corresponding encryption algorithm and key length according to at least one parameter among data sensitivity level, user permission level, and terminal operating status. The encryption algorithm can be added or deleted according to a preset and can be a single algorithm or a combination of multiple algorithms. S204. The encryption and secure access control system controls the data encryption unit to send the encrypted data packets generated by the encryption process to the data processing library for storage, and sends the corresponding decryption keys to the key management unit for unified management. S205. The encryption and secure access control system's control data processing library stores encrypted data packets, encryption algorithm parameters, and encryption history records, supporting the retrieval and retrieval of encrypted data. The data processing library uses an additional access password for two-factor authentication, and users with corresponding permissions can only query data within their authorized scope. S206. The encryption and secure access control system control key management unit generates, stores, and distributes decryption keys, and audits and manages the use of keys throughout their lifecycle, recording the key's generation time, number of uses, user, and expiration time.
[0033] Anomaly monitoring and adaptive response S301, The encryption and secure access control system controls the abnormal monitoring terminal to monitor data access behavior in real time, identify, block and warn of abnormal access, and dynamically adjust encryption strategies and permission configurations based on access behavior feedback; S302, The anomaly monitoring terminal includes an anomaly monitoring unit, a self-processing learning model, and a network monitoring unit, and the outputs of the anomaly monitoring unit and the network monitoring unit are kept in communication connection with the input of the self-processing learning model; S303, the encryption and secure access control system's anomaly monitoring unit monitors data access behavior in real time and identifies abnormal access characteristics. These abnormal accesses include at least one of unauthorized access attempts, high-frequency access requests, access during unusual time periods, and access from different locations. When an abnormal access is detected, the system automatically blocks the access request, records the anomaly log, and sends a warning message to the system administrator. The anomaly monitoring unit is also used to monitor abnormal data originating from devices. S304. The encryption and secure access control system controls the network monitoring unit to monitor the network communication status of computer terminals, identify abnormal network traffic and external attack behavior, and coordinate with the anomaly monitoring unit to implement protective measures. S305. The encryption and secure access control system's self-processing learning model is based on historical abnormal data and normal access behavior data. It trains an anomaly recognition model and dynamically updates the model parameters according to new abnormal data. It self-processes problems that have occurred and been resolved in the historical records and sends the corresponding abnormal data and self-resolvement process to the remote system administrator. S306. The encryption and secure access control system dynamically adjusts encryption policy parameters and permission configuration rules based on the identification results of abnormal access behavior. When high-frequency access requests are identified, the encryption strength is temporarily increased or the key update cycle is shortened. When access from other locations is identified, the access permission level is automatically reduced or two-factor authentication is triggered. S307. The encryption and secure access control system controls the mobile control terminal to receive abnormal warning information, allowing the system administrator to remotely review abnormal access requests, temporarily adjust user permissions, or remotely lock computer terminals.
[0034] The multi-level authentication port, data encryption processing center, and anomaly monitoring terminal are sequentially connected to form a complete security protection link from identity authentication and data encryption to anomaly monitoring. When a user accesses a computer terminal, the access request first enters the multi-level authentication port for identity authentication. After successful authentication, the user can operate on the terminal data. The data encryption processing center dynamically encrypts the stored and transmitted data. The anomaly monitoring terminal monitors user access behavior in real time. When an anomaly is detected, it blocks access and feeds back to the multi-level authentication port and data encryption processing center, dynamically adjusting permission configurations and encryption policies to form a closed-loop adaptive protection. The multi-level authentication unit collects at least two of the user's static password, dynamic verification code, and biometric information to form a multi-factor authentication combination. The multi-level authentication unit compares the collected information with a preset identity database. Authentication is successful only when all collected factors pass verification. After successful authentication, the identity and access control unit queries a preset access control table and matches the corresponding data access permissions based on the user's identity information. The synchronous early warning unit continuously monitors the authentication process. When multiple authentication failures are detected, it is determined to be a brute-force attack. The user's access request is immediately locked, and an early warning message is sent to the system administrator via the network. At the same time, the network location information of the attack source is recorded. The continuous verification mechanism runs continuously after a user logs in. The anomaly monitoring terminal collects user behavior data in real time, including access time, access frequency, and access data range. The self-processing learning model establishes a user behavior baseline based on historical behavior data. When user behavior deviates from the baseline by more than a preset threshold, it is judged as abnormal behavior, triggering secondary authentication and requiring the user to resubmit identity information for confirmation. The data encryption unit receives user permission information from the multi-level authentication port and simultaneously obtains the data sensitivity level label of the data to be encrypted. The data sensitivity level is preset by the system administrator and is divided into three levels: high sensitivity, medium sensitivity, and low sensitivity. The dynamic encryption strategy makes a comprehensive decision based on three parameters: data sensitivity level, user permission level, and terminal operating status. For high-sensitivity data, a high-strength encryption algorithm such as AES-256 or SM4 is selected, with a key length of no less than 256 bits. For low-sensitivity data, a lightweight encryption algorithm is selected to reduce encryption overhead. When the terminal is under high load, an encryption algorithm with lower computational overhead is prioritized to balance security and system performance. After encryption, the encrypted data packet is stored in the data processing library. The decryption key is sent to the key management unit for unified management. The data processing library is set with an independent access password. Users need to perform two-factor authentication when querying data, and users can only query data that matches their permission level. The key management unit manages the keys throughout their entire lifecycle, recording the applicant, user, and expiration time of each key generation, and rotates the keys periodically. The anomaly monitoring unit collects data access logs in real time, including information such as accessing user, access time, access data type, access frequency, and access source network location. The self-processing learning model trains an anomaly recognition model based on historical normal access data. When a new access behavior deviates from the normal model by more than a threshold, it is judged as an abnormal access. Abnormal access types include unauthorized access attempts, high-frequency access with an access frequency more than three times the normal value per unit time, access during unconventional time periods that occur outside of working hours, and access from uncommon network locations. When the anomaly monitoring unit detects abnormal access, it immediately performs a blocking operation, terminating the current access request, recording the anomaly log, and sending an alert message containing the anomaly type, attack source, and target data to the system administrator. Simultaneously, the self-processing learning model inputs the abnormal access features into its training model, dynamically updating the anomaly identification parameters to improve its ability to identify similar attacks. The network monitoring unit monitors network traffic on computer terminals, identifies abnormal network behaviors such as DDoS attacks, port scanning, and malware communication, and coordinates with the anomaly monitoring unit to execute network isolation or update firewall rules. The identification results from the anomaly monitoring terminal are fed back to the multi-level authentication port and the data encryption processing center in real time. When an anomaly is detected in a user's access behavior, the identity and access control unit temporarily lowers the user's access level, such as downgrading read and write permissions to read-only permissions, or restricting access to only low-sensitivity data. The data encryption unit dynamically adjusts the encryption strategy according to the anomaly type. When high-frequency access anomalies are detected, the encryption strength is temporarily increased, the number of encryption rounds is increased, or the key update cycle is shortened. The self-processing learning model records and learns from successfully processed anomaly events, forming a self-resolving process library. When the same type of anomaly occurs again, the system can automatically execute the preset processing strategy without manual intervention. The mobile control terminal is connected to the encryption and secure access control system via an encrypted communication channel. When the abnormal monitoring terminal issues an alert, the system automatically pushes the abnormal event to the system administrator's mobile control terminal. Administrators can remotely review abnormal access requests through the mobile control terminal, view anomaly details and solution suggestions generated by the self-processing learning model, and perform operations such as temporarily adjusting user permissions, remotely locking computer terminals, and forcibly removing suspicious users. The mobile control terminal supports multiple administrators operating simultaneously, and all operation records are uploaded to a data processing database for auditing.
[0035] Example 1 (Data Security Protection Based on Large Enterprise Intranet) System Configuration Multi-factor authentication combination: static password, fingerprint recognition, dynamic verification code; Identity authentication failure lockout threshold: 3 consecutive failures will lock the account for 30 minutes; Data sensitivity levels are classified as follows: High sensitivity (financial data, core technical documents), Medium sensitivity (internal management documents), Low sensitivity (public information). Dynamic encryption strategy: High-sensitivity data: AES-256; Medium-sensitivity data: SM4; Low-sensitivity data: Lightweight algorithm; Key update cycle: Highly sensitive data: 7 days; Mediumly sensitive data: 30 days; Lowly sensitive data: 90 days; Abnormal access judgment thresholds: Unauthorized access attempts ≥ 1 time; High-frequency access ≥ 3 times the normal value; Unusual time period: 22:00-06:00; Remote access: Distance ≥ 500 kilometers; Behavioral baseline learning period: 7 days; Mobile control terminal: Supports iOS / Android, with remote locking and permission adjustment functions; Implementation data: This system was deployed in a large manufacturing enterprise, covering four core departments: R&D center, finance department, production management department, and administration department. There were approximately 1,200 terminals, with an average of about 50,000 data access requests per day.
[0036] Table 1: System Performance Test Data for Example 1
[0037] Specific Implementation Cases On November 15, 2025, a large manufacturing company conducted a quarterly information security drill, simulating an external attacker launching a data theft attack on the R&D center's terminal.
[0038] Work process: 09:00:00: The attacker attempted to log in to terminal A in the R&D center using the stolen employee account password; 09:00:05: The multi-level authentication unit detected a login request, requiring the input of a dynamic verification code and fingerprint verification, which the attacker could not provide; 09:00:30: After three consecutive failed identity verification attempts, the synchronous early warning unit determined it to be a brute-force attack, locked the account for 30 minutes, and sent an early warning message to the security administrator's mobile control terminal; 09:01:00: The anomaly monitoring unit detected that the account continued to attempt to log in during the lockout period, determined it to be an automated attack, and added the IP address to the temporary blacklist; 09:05:00: The self-processing learning model analyzes the attack characteristics, identifies that the IP address is simultaneously attempting to connect to multiple terminals, and updates the parameters of the anomaly identification model; 09:10:00: The security administrator remotely reviews the alert information via a mobile control terminal. After confirming the attack behavior, the administrator remotely locks the attacked terminal. 09:15:00: The self-processing learning model records the characteristics of this attack into the anomaly database and generates self-resolvement strategies for similar attacks; Results: During the exercise, a total of 47 attack attempts were identified and blocked. The accuracy rate for identifying the first attack was 92.8%, and the accuracy rate for identifying subsequent similar attacks improved to 98.5%. The adaptive strategy adjustment reduced the attack response time from 30 seconds for the first attack to less than 3 seconds for subsequent attacks. After the administrator remotely locked the 12 attacked terminals, no data was leaked. The attack report and self-resolvement strategy generated by the system provided a reference for the company's subsequent security protection.
[0039] Example 2 (Data Security Protection Based on Financial Institution Terminals) System Configuration Multi-factor authentication combination: dynamic token, facial recognition, and ID account data; Identity authentication failure lockout threshold: 15 minutes lockout after 2 consecutive failures; Data sensitivity levels are categorized as follows: High sensitivity (customer account information, transaction records), Medium sensitivity (internal risk control models), and Low sensitivity (business promotional materials). Dynamic encryption strategy: High-sensitivity data: SM4 + Chinese national cryptographic algorithm; Medium-sensitivity data: AES-192; Low-sensitivity data: AES-128; Key update cycle: Highly sensitive data: 24 hours; Mediumly sensitive data: 7 days; Lowly sensitive data: 30 days; Abnormal access judgment thresholds: Unauthorized access attempts ≥ 1 time; High-frequency access ≥ 2 times the normal value; Unusual time period: 20:00-08:00; Remote access: Distance ≥ 100 kilometers; Behavioral baseline learning period: 3 days; Mobile control terminal: Supports regulatory compliance auditing and remote permission revocation functions; Implementation data: This system was deployed in a joint-stock commercial bank, covering the head office's information technology department, risk management department, personal finance department, and corporate business department, with approximately 800 terminals and an average of approximately 80,000 data access requests per day.
[0040] Table 2: System Performance Test Data for Example 2
[0041] Specific Implementation Cases On January 20, 2026, a joint-stock commercial bank conducted its annual regulatory compliance self-inspection, focusing on the access control and encryption protection of sensitive customer information.
[0042] Work process: 14:00:00: Zhang, an employee of the Personal Finance Department, requested access to the customer account information database (highly sensitive data); 14:00:03: The multi-level identity verification unit collects Zhang's ID account, dynamic token code, and facial recognition information, and the comparison with the preset identity database is successful; 14:00:05: The identity and access control unit queries the access configuration table, confirms that Zhang is a senior account manager in the personal finance department, and grants the customer's account information read and write permissions; 14:00:08: The data encryption unit uses the SM4 national cryptographic algorithm to encrypt the query results based on the high sensitivity level of the data and Zhang's access level. The key is valid for 24 hours. 14:00:10: The anomaly monitoring unit records the access log for this access, including the access time, access data type, and access result; 14:30:00: Zhang attempted to log in to the system outside of working hours (20:15). The self-processing learning model detected that the access time deviated from his historical behavior baseline, triggering two-factor authentication. 14:30:05: The system requires Zhang to resubmit his facial recognition and dynamic token code for confirmation. Access will be granted after the verification is successful. 15:00:00: Regulatory compliance auditors log in to the system and query all highly sensitive data access records for the past 90 days through the data processing database. The key management unit provides a complete audit log of key usage. Results: During the compliance self-inspection, a total of 23,000 highly sensitive data access records were reviewed, including 12 instances of abnormal access behavior. The system automatically triggered two-factor authentication or blocked all such instances. The key management unit provided 24,000 key usage audit logs, demonstrating complete and traceable key lifecycle management. The compliance audit report generated by the system showed that all highly sensitive data access was protected by multi-factor authentication and dynamic encryption, key management complied with regulatory requirements, and the audit pass rate was 100%. The self-processing learning model identified three new types of abnormal access patterns, which have been updated to the anomaly identification model.
[0043] Those skilled in the art will recognize that the modules and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0044] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, equipment, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0045] In the embodiments provided in this application, it should be understood that the disclosed devices, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or units may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or equipment, and may be electrical, mechanical, or other forms.
[0046] The modules serving as multi-level authentication ports, data encryption processing centers, and anomaly monitoring terminals may or may not be physically separate. The components displayed as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of these units can be selected to achieve the purpose of this embodiment based on actual needs.
[0047] The above are merely preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for encrypting and securely accessing computer terminal data, characterized in that, The specific steps include the following: S1. Construct an encryption and secure access control system, generate a multi-level authentication mechanism, and perform identity authentication and permission granting for users accessing computer terminals. S2. The data to be encrypted in the computer terminal is encrypted using a dynamic encryption strategy to generate an encrypted data packet and a corresponding decryption key. S3. Monitor data access behavior in real time, identify, block and warn of abnormal access, and dynamically adjust encryption policies and permission configurations based on access behavior feedback; when abnormal access is identified, automatically block access requests and record abnormal logs, and send warning information to the system administrator.
2. The computer terminal data encryption and secure access control method according to claim 1, characterized in that: Step S1 also includes the following specific steps: S101. Collect user identity information, which includes at least two of static passwords, dynamic verification codes, and biometric information to form multi-factor authentication. The biometric information includes user facial data, voice data, fingerprint data, and ID account data. S102. Based on the authenticated user's identity information, query the preset permission configuration table and grant the user the corresponding data access permission, which includes at least one of read-only permission, read-write permission, and administrator permission.
3. The computer terminal data encryption and secure access control method according to claim 1, characterized in that: The dynamic encryption strategy in step S2 includes selecting the corresponding encryption algorithm and key length based on at least one parameter among data sensitivity level, user permission level, and terminal operating status.
4. The computer terminal data encryption and secure access control method according to claim 3, characterized in that: The abnormal access in step S3 includes at least one of unauthorized access attempts, high-frequency access requests, access during unusual time periods, and access from different locations. When abnormal access is detected, the access request is automatically blocked and an abnormal log is recorded.
5. The computer terminal data encryption and secure access control method according to claim 1, characterized in that: The multi-level authentication mechanism in step S1 also includes continuous verification of user access behavior. When user behavior deviates from the preset behavior baseline, secondary authentication is triggered.
6. The computer terminal data encryption and secure access control method according to claim 5, characterized in that: The encryption and secure access control system includes a multi-level authentication port, a data encryption processing center, and an anomaly monitoring terminal. The multi-level authentication port and the data encryption processing center are bidirectionally connected, and the data encryption processing center and the anomaly monitoring terminal are bidirectionally connected. The multi-level authentication port is used to perform identity authentication and permission granting in step S1. The data encryption processing center is used to perform data encryption processing in step S2. The anomaly monitoring terminal is used to perform anomaly access monitoring and response in step S3.
7. The computer terminal data encryption and secure access control method according to claim 6, characterized in that: The multi-level authentication port includes a multi-level authentication unit, an identity and access control unit, and a synchronization warning unit. The output of the multi-level authentication unit is communicatively connected to the input of the identity and access control unit, and both the multi-level authentication unit and the identity and access control unit are bidirectionally communicatively connected to the synchronization warning unit. The multi-level identity verification unit is used to collect the user's identity information and compare it with a preset identity database to verify the authenticity of the user's identity; The identity and access control unit is used to grant corresponding data access permissions based on the verified user identity information, and to record the user's operation permission scope; The synchronous early warning unit is used to send early warning information to the system administrator when multiple authentication failures or abnormal permission granting occur, and to lock the user's access request, while locating the location of the access request and querying the personnel who made the access.
8. The computer terminal data encryption and secure access control method according to claim 6, characterized in that: The data encryption processing center includes a data encryption unit, a data processing library, and a key management unit. The output of the data encryption unit is communicatively connected to the input of the data processing library, and the data processing library and the key management unit are bidirectionally communicatively connected. The data encryption unit is used to select an encryption algorithm according to a dynamic encryption strategy, encrypt the data to be encrypted, and generate an encrypted data packet. The encryption algorithm can be manually added or deleted according to a preset, and can be a single algorithm or a combination of multiple algorithms. The data processing library is used to store encrypted data packets, encryption algorithm parameters, and encryption history records. It supports the retrieval and retrieval of encrypted data. The data processing library is set with an additional access password for two-factor authentication, and the corresponding permissions can only query the data corresponding to the permissions. The key management unit is used to generate, store, and distribute decryption keys, and to audit the use of keys and manage their lifecycle.
9. The computer terminal data encryption and secure access control method according to claim 6, characterized in that: The anomaly monitoring terminal includes an anomaly monitoring unit, a self-processing learning model, and a network monitoring unit. The outputs of the anomaly monitoring unit and the network monitoring unit are both communicatively connected to the input of the self-processing learning model. The anomaly monitoring unit is used to monitor data access behavior in real time, identify abnormal access characteristics, perform blocking or early warning operations, and generate anomaly reports; the anomaly monitoring unit is also used to monitor abnormal data from devices. The self-processing learning model is used to train an anomaly recognition model based on historical anomaly data and normal access behavior data, and dynamically update the model parameters according to new anomaly data. It can self-process problems that have appeared and been resolved in the historical records, and send the corresponding anomaly data and self-resolvement process to the remote system administrator. The network monitoring unit is used to monitor the network communication status of computer terminals, identify abnormal network traffic and external attack behavior, and coordinate with the anomaly monitoring unit to implement protective measures.
10. The computer terminal data encryption and secure access control method according to claim 9, characterized in that: The encryption and secure access control system also includes a mobile control terminal, which is used to receive abnormal warning information, allowing system administrators to remotely review abnormal access requests, temporarily adjust user permissions, or remotely lock computer terminals.