A deep learning-based security evaluation method for commercial cryptographic application
Patent Information
- Application Number
- CN202611066601.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-17
- Publication Date
- 2026-09-25
AI Technical Summary
采集到的通信交互数据、业务访问数据、身份认证数据和密码设备运行数据来源分散、格式差异明显,现有整理方法往往难以实现异构安全数据的统一组织与连续建模;针对行长度不一致、状态演化复杂的安全记录,传统固定长度特征提取方式容易破坏时序关联和阶段衔接关系,导致阶段转移特征与联合事件特征难以被准确提取;针对多源安全数据中的隐含关联结构,现有浅层评估模型和普通统计分析方法难以同时兼顾切片差异、阶段约束和事件锚定关系,导致安全风险表征能力不足,影响商用密码应用安全性评估结果的准确性和稳定性
与现有主要依赖规则比对、单源日志分析或局部流量检测的商用密码应用安全评估方案相比,本发明通过采集商用密码应用过程中的多源安全数据,先将原始数据集重组为列特征统一且行长度可变的安全数据切片集合,再从安全数据切片集合中提取状态演化片段和交互关联片段,分别形成阶段序列、阶段转移关系和联合事件集合,从而能够在保持异构安全数据结构差异的基础上,对商用密码应用过程中的时序变化关系、阶段衔接关系和事件关联关系进行统一表征,解决了现有方法难以同时兼顾多源异构性、行长度不一致性和过程连续性的问题,提高了安全数据组织和风险建模的完整性。
Smart Images

Figure CN122824463A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method for security assessment of commercial cryptographic applications based on deep learning. Background Technology
[0002] With the increasing prevalence of commercial cryptography applications in government systems, industry information systems, and network service platforms, security assessment technologies for cryptographic resource retrieval, key management, certificate management, and security policy enforcement processes have received widespread attention. Existing commercial cryptography security assessment schemes primarily rely on rule comparison, single-source log analysis, or localized traffic detection for risk identification; however, these schemes commonly suffer from the following problems in practical applications: The collected communication interaction data, business access data, identity authentication data, and cryptographic device operation data are scattered from different sources and have significantly different formats. Existing processing methods often fail to achieve unified organization and continuous modeling of heterogeneous security data. For security records with inconsistent line lengths and complex state evolution, traditional fixed-length feature extraction methods easily disrupt temporal correlations and stage connections, making it difficult to accurately extract stage transition features and joint event features. For the implicit correlation structure in multi-source security data, existing shallow evaluation models and ordinary statistical analysis methods cannot simultaneously take into account slice differences, stage constraints, and event anchoring relationships, resulting in insufficient security risk characterization capabilities and affecting the accuracy and stability of security assessment results for commercial cryptographic applications.
[0003] Therefore, how to provide a deep learning-based method for security assessment of commercial cryptographic applications is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0004] One objective of this invention is to propose a security assessment method for commercial cryptographic applications based on deep learning. This invention fully utilizes the improved PARAFAC2 deep decomposition model to slice and organize multi-source security data in the process of commercial cryptographic applications, perform stage modeling, joint event anchoring, and risk fusion characterization. It can complete the accurate assessment of the security of commercial cryptographic applications and has the advantages of strong adaptability to heterogeneous data, high risk characterization capability, and stable assessment results.
[0005] A method for assessing the security of commercial cryptographic applications based on deep learning, according to an embodiment of the present invention, includes the following steps: Step 1: Collect multi-source security data during commercial cryptography applications to form the raw dataset; Step 2: Perform preprocessing on the original dataset to reorganize it into a set of secure data slices with uniform column features and variable row lengths; Step 3: Extract and arrange state evolution fragments from the security data slice set to form a stage sequence and stage transition relationship; extract and merge interactive related fragments from the security data slice set to form a joint event set. Step 4: Construct an improved PARAFAC2 deep decomposition model, build hierarchical update unit sequences corresponding to slice factor solution, kernel parameter solution and common load solution according to the update order, and establish decomposition residual constraints between adjacent hierarchical update units; Step 5: Using the hierarchical update unit sequence, perform a layer-by-layer decomposition of the safe data slice set under the decomposition residual constraint to form slice factors, kernel parameters, and common loads; Step Six: Introduce stage sequences and stage transition relationships in the kernel parameter solution to impose piecewise correlation constraints on the kernel parameters, forming constrained kernel parameters; Step 7: Introduce a joint event set in the common load solution, apply associated anchoring to the common load, and form an anchored common load; Step 8: Perform fusion characterization on the slice factor, constraint kernel parameters, and anchored common payload to form a security risk characterization vector, and complete the security assessment of commercial cryptographic applications.
[0006] Optionally, step one specifically includes: Collect communication interaction data, business access data, identity authentication data, certificate management data, key management data, cryptographic device operation data, algorithm call data, and policy configuration data during commercial cryptography applications to form multi-source security data; Extract time stamps, object stamps, behavior stamps, status stamps, and source stamps from multi-source security data to form a collected dataset; The collected datasets are sorted according to time stamp, grouped by object, and categorized by source according to source. The collected datasets, after being sorted sequentially, grouped by object, and categorized by source, are compiled into the original dataset.
[0007] Optionally, step two specifically includes: Time base correction is performed on the time stamps in the original dataset, identifier normalization is performed on the object stamps, and value encoding is performed on the behavior stamps, status stamps, and source stamps to form a regular record set; Arrange the time marker, object marker, behavior marker, status marker, and source marker in the regular record set into a record vector according to a unified field order, forming a mapped record set with unified column features; The mapping record set is grouped according to the object label, and the record vector in each group is segmented according to the time label to form a record fragment set; Arrange the record vectors in the record segment set into a slice matrix according to the time stamp order, so that the slice matrix has the same column characteristics and different row lengths; The slice matrices are aggregated into a set of secure data slices.
[0008] Optionally, step three specifically includes: Extract time markers, object markers, and state markers from the slice matrix in the secure data slice set. Arrange the state markers according to the time marker order and divide the continuous state intervals according to the position of state marker changes to form a set of state evolution fragments. The state evolution fragment set is arranged according to the time stamp order, and stage identifiers are assigned to the state evolution fragments in the state evolution fragment set along the arrangement order to form a stage sequence; Perform a connection analysis on adjacent stage identifiers in the stage sequence, record the transfer relationship from the previous stage identifier to the next stage identifier, and form a stage transfer relationship; Extract time stamps, object stamps, and behavior stamps from the slice matrix in the secure data slice set; group record vectors according to object stamps; divide continuous interaction intervals according to time stamps; and form a set of interactive related fragments. The sets of interactive related fragments are merged according to object tags and time intervals to form a joint event set.
[0009] Optionally, step four specifically involves: The row length and column features of each slice matrix are extracted from the set of secure data slices. The slice factor dimension, kernel parameter dimension and common load dimension are determined by the number of column features and the distribution of row length, forming a decomposed configuration set. Establish the decomposition relationship between the slice matrix, slice factor, kernel parameter, and common load by configuring a slice matrix, a slice factor, and a kernel parameter, and configuring a common load according to a set of secure data slices; The slice factor solution is set as a representation update process based on the row records of the slice matrix, the kernel parameter solution is set as an intensity update process based on the component distribution inside the slice matrix, and the common load solution is set as a shared representation update process based on the common column features of the security data slice set. A hierarchical update unit is formed by solving for slice factors, kernel parameters, and common loads in that order, and all hierarchical update units are connected in the same order to form a hierarchical update unit sequence. Establish parameter inheritance relationships in the hierarchical update unit sequence so that the slice factor, kernel parameter and common load formed by the previous level update unit can participate in the solution of the next level update unit. The slice matrix is decomposed and reconstructed using the slice factor, kernel parameter and common load formed by the update unit at each level, and the decomposition residual constraint is formed based on the difference between the decomposition and reconstruction result and each slice matrix. The decomposition configuration set, hierarchical update unit sequence, and decomposition residual constraints are combined to form an improved PARAFAC2 deep decomposition model.
[0010] Optionally, step five specifically includes: The first-level update unit is determined according to the order of the hierarchical update unit sequence, and the slice matrix in the safe data slice set is mapped to the slice factor solution, kernel parameter solution and common load solution corresponding to the first-level update unit. In the first-level update unit, slice factor updates are performed using the slice matrix and decomposed configuration set to form the first round of slice factors. Kernel parameter updates are performed using the first round of slice factors and slice matrix to form the first round of kernel parameters. Common payload updates are performed using the first round of slice factors, first round of kernel parameters and security data slice set to form the first round of common payload. The slice matrix is decomposed and reconstructed using the first-round slice factor, the first-round kernel parameter, and the first-round common load, and the decomposition residual constraint is verified based on the difference between the decomposition and reconstruction result and the slice matrix. The first-round slice factor, first-round kernel parameter, and first-round common load that satisfy the decomposition residual constraints are passed to the next-level update unit, and the slice factor update, kernel parameter update, common load update, and decomposition residual constraint verification are repeatedly performed in the next-level update unit. At the end of the hierarchical update unit sequence, the slice factor, kernel parameters, and common payload formed by the final update are aggregated to form the slice factor, kernel parameters, and common payload.
[0011] Optionally, step six specifically includes: Extract stage identifiers arranged in the order of arrangement from the stage sequence, and extract the transition start and transition end points corresponding to the stage identifiers from the stage transition relationship to form a stage constraint record set; According to the stage constraint record set, locate the parameter position corresponding to the stage identifier in the kernel parameter, and divide the kernel parameter into intervals according to the arrangement order of the stage identifier to form the stage parameter interval; Within each stage parameter interval, the kernel parameters are subjected to interval correlation calculation according to the parameter position order, so that the kernel parameters within the same stage parameter interval remain continuously correlated. According to the stage transition relationship, the transition association restriction is applied to the parameter intervals of adjacent stages, so that the kernel parameter corresponding to the transition start point only forms a transition association with the kernel parameter corresponding to the transition end point. Kernel parameters that have completed interval correlation calculations and transfer correlation constraints are aggregated into constraint kernel parameters.
[0012] Optionally, step seven specifically includes: Extract object tags, time intervals, and interaction-related fragments from the joint event set, and combine the object tags, time intervals, and interaction-related fragments into an event-related record set; Based on object labels and time intervals, locate the slice matrix and column feature positions that participate in the joint event set representation in the security data slice set to form an anchor position set; During the common load solution process, event association aggregation calculations are performed on the common load according to the anchor location set to form the association strength of the joint event set in the anchor location set; The common load values in the anchoring location set are adjusted according to the correlation strength to ensure that the common loads corresponding to the same set of joint events remain consistent within the anchoring location set. The common loads that have completed weight adjustments are aggregated according to column characteristic order to form anchored common loads.
[0013] Optionally, step eight specifically includes: Extract the factor components from the slice factors, the parameter components from the constraint kernel parameters, and the load components from the anchored common loads according to the arrangement position of the slice matrix to form a fusion record set; The fused record set is registered according to the arrangement of the slice matrix, and the factor components, parameter components and load components are spliced and arranged according to the column feature order to form the characterization record set. Joint mapping calculations are performed on the factor components, parameter components, and loading components in the characterization record set to form risk response values; The risk response values are merged and aggregated according to the arrangement of the slice matrix to form a safety risk representation vector; An evaluation mapping is performed on the security risk representation vector to generate a security evaluation result for commercial cryptographic applications.
[0014] The beneficial effects of this invention are: Compared with existing commercial cryptographic application security assessment schemes that mainly rely on rule comparison, single-source log analysis, or local traffic detection, this invention collects multi-source security data during the commercial cryptographic application process. It first reorganizes the original dataset into a set of security data slices with unified column features and variable row lengths. Then, it extracts state evolution fragments and interaction correlation fragments from the security data slice set to form stage sequences, stage transition relationships, and joint event sets, respectively. This allows for a unified representation of temporal changes, stage connections, and event correlations in the commercial cryptographic application process while maintaining the differences in heterogeneous security data structures. This solves the problem that existing methods struggle to simultaneously address multi-source heterogeneity, inconsistent row lengths, and process continuity, improving the completeness of security data organization and risk modeling.
[0015] Furthermore, this invention constructs an improved PARAFAC2 deep decomposition model, expanding the slice factor solution, kernel parameter solution, and common payload solution along the hierarchical update unit sequence. In the kernel parameter solution, stage sequences and stage transition relationships are introduced to form constraint kernel parameters, and in the common payload solution, a set of joint events is introduced to form anchored common payloads. Finally, a security risk representation vector is formed through the fusion representation of slice factors, constraint kernel parameters, and anchored common payloads, and a security assessment is completed. Therefore, this invention not only enhances the ability to characterize implicit risk relationships in complex commercial cryptographic application scenarios but also strengthens the ability to identify abnormal state transitions, joint event coupling risks, and overall security posture, resulting in assessment results with higher accuracy, stability, and adaptability. Attached Figure Description
[0016] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a deep learning-based security assessment method for commercial cryptographic applications proposed in this invention. Figure 2 This is a structural diagram of the improved PARAFAC2 deep decomposition model, which is an improved security assessment method for commercial cryptographic applications based on deep learning proposed in this invention. Detailed Implementation
[0017] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0018] refer to Figures 1-2 A security assessment method for commercial cryptographic applications based on deep learning includes the following steps: Step 1: Collect multi-source security data during commercial cryptography applications to form the raw dataset; Step 2: Perform preprocessing on the original dataset to reorganize it into a set of secure data slices with uniform column features and variable row lengths; Step 3: Extract and arrange state evolution fragments from the security data slice set to form a stage sequence and stage transition relationship; extract and merge interactive related fragments from the security data slice set to form a joint event set. Step 4: Construct an improved PARAFAC2 deep decomposition model, build hierarchical update unit sequences corresponding to slice factor solution, kernel parameter solution and common load solution according to the update order, and establish decomposition residual constraints between adjacent hierarchical update units; Step 5: Using the hierarchical update unit sequence, perform a layer-by-layer decomposition of the safe data slice set under the decomposition residual constraint to form slice factors, kernel parameters, and common loads; Step Six: Introduce stage sequences and stage transition relationships in the kernel parameter solution to impose piecewise correlation constraints on the kernel parameters, forming constrained kernel parameters; Step 7: Introduce a joint event set in the common load solution, apply associated anchoring to the common load, and form an anchored common load; Step 8: Perform fusion characterization on the slice factor, constraint kernel parameters, and anchored common payload to form a security risk characterization vector, and complete the security assessment of commercial cryptographic applications.
[0019] In this embodiment, step one specifically includes: Collect communication interaction data, business access data, identity authentication data, certificate management data, key management data, cryptographic device operation data, algorithm call data, and policy configuration data during commercial cryptography applications. During collection, retain business occurrence records, management operation records, and operation status records respectively, and write them into a unified collection format according to the data source to form multi-source security data. Extract time stamps, object stamps, behavior stamps, status stamps, and source stamps from multi-source security data. During extraction, information representing the time of occurrence is written into the time stamp, information representing the associated subject is written into the object stamp, information representing the operation type and interaction type is written into the behavior stamp, information representing the running status and management status is written into the status stamp, and information representing the source of collection is written into the source stamp, forming a collection dataset. The collected dataset is sorted according to time stamps to form a time series of data in the dataset. The collected dataset is also grouped according to object stamps to group data with the same object stamps into the same object set. Finally, the collected dataset is categorized according to source stamps to group data with the same source stamps into the same source category. The collected datasets, after being sorted sequentially, grouped by object, and categorized by source, are combined into the original dataset, so that the original dataset simultaneously maintains the time order, object correspondence, and source classification relationship.
[0020] In this embodiment, step two specifically involves: Time base correction is performed on the time stamps in the original dataset, identifier normalization is performed on the object markers, and value encoding is performed on the behavior markers, status markers, and source markers. Time base correction converts the time stamps corresponding to different collection times to a unified time scale, identifier normalization transforms different identifier forms pointing to the same object into a unified identifier value, and value encoding transforms the behavior markers, status markers, and source markers into fixed coded values, forming a regular record set. The time marker, object marker, behavior marker, status marker, and source marker in the regular record set are arranged into record vectors according to a unified field order. During the arrangement, the corresponding marker value is written in the same field position for each record, so that all record vectors maintain the same field order and the same column position meaning, forming a mapping record set with unified column characteristics. The mapping record set is grouped according to the object label, and the record vector in each group is segmented according to the time label. The grouping process puts the record vectors with the same object label into the same group. The segmentation process divides the continuous time range according to the order of the time label, so that the record vectors in the same time range form a record segment, forming a record segment set. The record vectors in the record segment set are arranged into a slice matrix according to the time stamp order. When arranging, the record vectors are used as the matrix rows and the fields corresponding to the unified field order are used as the matrix columns. This ensures that all rows in the same slice matrix maintain the same column structure and that different slice matrices maintain the same column characteristics but have different row lengths. The slice matrices are aggregated into a secure data slice set. During the aggregation, the correspondence between the slice matrices and object labels and time intervals is preserved, so that the secure data slice set can maintain a uniform column feature and a variable row length organization.
[0021] In this embodiment, step three specifically includes: Extract time stamps, object stamps, and state stamps from the slice matrix in the secure data slice set. During extraction, read the time stamps, object stamps, and state stamps corresponding to each record vector along the row direction of the slice matrix, and arrange the state stamps from front to back according to the time stamps. Compare the state stamps in adjacent record vectors one by one, and divide the continuous state intervals at the positions where the state stamps change, so that the state stamps in the same continuous state interval are consistent, forming a set of state evolution fragments. The state evolution fragment set is arranged according to the time stamp order, and stage identifiers are assigned to the state evolution fragments in the state evolution fragment set according to the arrangement order. When arranging, the state evolution fragments with earlier time stamps are placed at the beginning and the state evolution fragments with later time stamps are placed at the end. When assigning stage identifiers, the stage identifier values are written in the order of arrangement to form a stage sequence. A connection analysis is performed on adjacent stage identifiers in the stage sequence to record the transition relationship from the previous stage identifier to the next stage identifier. During the connection analysis, the end time of the previous state evolution segment and the start time of the next state evolution segment corresponding to the adjacent stage identifier are read, and the state markers in the previous state evolution segment and the state markers in the next state evolution segment are read. The corresponding change relationship between the previous stage identifier and the next stage identifier is recorded as a stage transition relationship, thus forming a stage transition relationship. Extract time stamps, object stamps, and behavior stamps from the slice matrix in the secure data slice set. Group record vectors according to object stamps and divide continuous interaction intervals according to time stamps. During extraction, read the time stamps, object stamps, and behavior stamps corresponding to each record vector along the row direction of the slice matrix. During grouping, record vectors with the same object stamps are grouped into the same grouping result. During division, arrange the record vectors in the grouping result from front to back according to the time stamps, and divide the continuous interaction intervals at the positions where the time interval is interrupted to form a set of interactive related fragments. The interaction-related fragment set is merged according to object tag and time interval. During the merging process, interaction-related fragments with the same object tag and adjacent or overlapping time intervals are merged into the same event unit, and the merged event units are aggregated into a joint event set.
[0022] In this embodiment, step four specifically includes: The row length and column features of each slice matrix are extracted from the security data slice set. During extraction, the number of record vectors along the row direction of each slice matrix is counted as the row length, and the field arrangement position and field meaning are read along the column direction as the column features. The slice factor dimension, kernel parameter dimension and common load dimension are determined by the number of column features and the distribution of row length, forming a decomposed configuration set. The decomposition relationship between the slice matrix, slice factor, kernel parameter and common load is established by configuring a slice matrix with a slice factor and a kernel parameter, and configuring a common load according to the set of secure data slices. When establishing, the arrangement position of the slice matrix in the set of secure data slices is used as the corresponding index, so that each slice matrix corresponds to a set of slice factors and a set of kernel parameters, and all slice matrices correspond to a common load. The slice factor solution is set as a representation update process based on the row records of the slice matrix. When setting it up, the row information is extracted according to the arrangement order of the record vectors in each row of the slice matrix and the slice factor update amount is generated. The kernel parameter solution is set as an intensity update process based on the component distribution inside the slice matrix. When setting it up, the kernel parameter update amount is formed according to the component contribution corresponding to each column feature of the slice matrix. The common load solution is set as a shared representation update process based on the common column features of the security data slice set. When setting it up, the convergence calculation is performed on the column features with consistent positions in all slice matrices and the common load update amount is generated. A hierarchical update unit is constructed in the order of solving the slice factor, kernel parameter, and common load. All hierarchical update units are then connected in the same order to form a hierarchical update unit sequence. When constructing the sequence, the slice factor update process, kernel parameter update process, and common load update process are written into the same hierarchical update unit in sequence. Then, the hierarchical update units are arranged in a sequential manner to form a hierarchical update unit sequence. In the hierarchical update unit sequence, parameter succession relationship is established so that the slice factor, kernel parameter and common load formed by the previous level update unit participate in the solution of the next level update unit. When establishing, the slice factor, kernel parameter and common load output by the previous level update unit are written into the initial position of the corresponding solution process of the next level update unit, so that the next level update unit continues to perform update based on the results of the previous level update unit. The slice matrix is decomposed and reconstructed using the slice factor, kernel parameter and common load formed by each level update unit. The decomposition residual constraint is formed according to the difference between the decomposition and reconstruction result and each slice matrix. During execution, the slice factor, kernel parameter and common load are combined into the decomposition and reconstruction result according to the decomposition relationship. The numerical difference between the decomposition and reconstruction result and each slice matrix at the corresponding row position and column position is calculated. The change relationship of the corresponding difference between adjacent level update units is organized into the decomposition residual constraint. The decomposition configuration set, hierarchical update unit sequence, and decomposition residual constraints are combined to form an improved PARAFAC2 deep decomposition model. During the combination, the decomposition configuration set is used to limit the solution dimension, the hierarchical update unit sequence is used to limit the update order, and the decomposition residual constraints are used to limit the relationship of decomposition residual changes between hierarchical update units, thus forming an improved PARAFAC2 deep decomposition model.
[0023] This invention addresses the shortcomings of traditional PARAFAC2 in commercial cryptographic applications' secure data processing. It can only perform conventional decomposition of variable-row-length slice matrices, struggles to balance local difference representation with global shared representation, lacks sufficient hierarchical structure in the decomposition process, and has weak error propagation control. The invention focuses on targeted improvements to the decomposition structure and update path. Specifically, it first constructs a decomposition configuration set based on the row length and column characteristics of each slice matrix in the secure data slice set, ensuring that the slice factor dimension, kernel parameter dimension, and common payload dimension match the actual structure of the secure data slice set. Furthermore, it refines the relatively simple decomposition process in traditional PARAFAC2 into three update processes: slice factor solution, kernel parameter solution, and common payload solution. This allows for more targeted modeling of row direction record information, internal component distribution information, and common column feature information in the slice matrix. Based on this, the three update processes are organized into a hierarchical update unit sequence according to the update order. Parameter inheritance relationships and decomposition residual constraints are established between adjacent hierarchical update units, ensuring that the update results of the previous level continuously participate in the update of the next level. Simultaneously, the decomposition residual variation relationship is used to suppress decomposition offset and error accumulation. Through the above improvements, the improved PARAFAC2 not only retains the technical foundation of the traditional PARAFAC2 for variable row length slice matrices, but also significantly enhances its ability to jointly express heterogeneous structures, component differences, and shared features of multi-source security data. This makes the decomposition results more stable, the potential representation clearer, and the adaptability to complex state evolution and interaction correlations stronger. As a result, it provides a more reliable decomposition basis for constructing constraint kernel parameters, forming anchor common payloads, and generating security risk characterization vectors. Ultimately, this is conducive to improving the accuracy, stability, and overall robustness of security assessment for commercial cryptographic applications.
[0024] In this embodiment, step five specifically includes: The first-level update unit is determined according to the order of the hierarchical update unit sequence. The slice matrix in the secure data slice set is mapped to the slice factor solution, kernel parameter solution, and common load solution corresponding to the first-level update unit. During the mapping, the correspondence between the slice matrix and the solution position inside the first-level update unit is established according to the arrangement position of the slice matrix in the secure data slice set. This ensures that each slice matrix enters the corresponding slice factor solution position and kernel parameter solution position inside the first-level update unit, and that the entire secure data slice set enters the corresponding common load solution position inside the first-level update unit. In the first-level update unit, slice factor updates are performed using the slice matrix and decomposition configuration set to form the first-round slice factor. During execution, the record vectors of each row of the slice matrix are represented and calculated according to the slice factor dimensions defined in the decomposition configuration set to obtain the first-round slice factor corresponding to the slice matrix. Kernel parameter updates are performed using the first-round slice factor and the slice matrix to form the first-round kernel parameter. During execution, the distribution intensity of each component in the slice matrix in the column direction is calculated based on the first-round slice factor to obtain the first-round kernel parameter corresponding to the slice matrix. Common load updates are performed using the first-round slice factor, the first-round kernel parameter, and the set of secure data slices to form the first-round common load. During execution, the first-round slice factor and the first-round kernel parameter are mapped to the column feature positions common to all slice matrices in the set of secure data slices, and the common column features are aggregated and calculated to obtain the first-round common load. The slice matrix is decomposed and reconstructed using the first-round slice factor, first-round kernel parameters, and first-round common load. The decomposition residual constraints are verified based on the difference between the decomposition and reconstruction results and the slice matrix. During execution, the decomposition and reconstruction results are first formed according to the decomposition relationship between the slice matrix and the first-round slice factor, first-round kernel parameters, and first-round common load. Then, the numerical differences between the decomposition and reconstruction results and the slice matrix at the corresponding row and column positions are calculated to obtain the decomposition residual corresponding to the current level update unit. The decomposition residual corresponding to the current level update unit is compared with the decomposition residual constraints to determine whether the first-round slice factor, first-round kernel parameters, and first-round common load formed by the current level update unit meet the decomposition residual constraints. The first-round slice factor, first-round kernel parameter, and first-round common load that satisfy the decomposition residual constraints are passed to the next-level update unit. In the next-level update unit, the slice factor update, kernel parameter update, common load update, and decomposition residual constraint verification are repeatedly executed. During the transfer, the first-round slice factor, first-round kernel parameter, and first-round common load are written into the initial position of the corresponding solution process of the next-level update unit, so that the next-level update unit continues to perform updates based on the results formed by the first-level update unit. In the repeated execution process, the updated slice factor, updated kernel parameter, and updated common load corresponding to the next-level update unit are formed. At the end of the hierarchical update unit sequence, the slice factor, kernel parameter, and common payload formed by the final update are aggregated to form the slice factor, kernel parameter, and common payload. During aggregation, the update slice factor corresponding to the end of the hierarchical update unit sequence is used as the slice factor, the update kernel parameter corresponding to the end of the hierarchical update unit sequence is used as the kernel parameter, and the update common payload corresponding to the end of the hierarchical update unit sequence is used as the common payload, thereby completing the layer-by-layer decomposition of the secure data slice set in the hierarchical update unit sequence.
[0025] In this embodiment, step six specifically includes: Extract the stage identifiers arranged in the order of the stage sequence from the stage sequence, and extract the transition start and transition end points corresponding to the stage identifiers from the stage transition relationship to form a stage constraint record set. During extraction, read each stage identifier in sequence along the arrangement direction of the stage sequence, and read the preceding and following stage identifiers corresponding to each transition relationship in sequence along the stage transition relationship. Write the stage identifier, transition start and transition end point into the same constraint record to form a stage constraint record set. According to the stage constraint record set, locate the parameter position corresponding to the stage identifier in the kernel parameter, and divide the kernel parameter into intervals according to the order of the stage identifiers to form stage parameter intervals. During the location, match the stage identifier in the stage constraint record set with the parameter position in the kernel parameter item by item, so that each stage identifier corresponds to a set of parameter positions in the kernel parameter. Then, divide the continuous parameter positions into different stage parameter intervals according to the order of the stage identifiers in the stage sequence. Within each stage parameter interval, the kernel parameters are subjected to interval correlation calculation according to the parameter position order, so that the kernel parameters within the same stage parameter interval remain continuously correlated. During the interval correlation calculation, the kernel parameter values corresponding to each parameter position in the same stage parameter interval are read sequentially, the numerical change relationship between adjacent parameter positions is calculated, and the numerical change relationship is restricted to a continuous change range, so that the kernel parameters within the same stage parameter interval remain continuously correlated in the parameter position direction. According to the stage transition relationship, the transition association restriction is applied to the parameter intervals of adjacent stages, so that the kernel parameter corresponding to the transition start point only forms a transition association with the kernel parameter corresponding to the transition end point. During execution, the transition start point and transition end point in the stage constraint record set are read, and a correspondence between the start point parameter position and the end point parameter position is established between adjacent stage parameter intervals. The parameter connection that does not belong to the correspondence between the transition start point and the transition end point is constrained, thereby preserving the transition association that conforms to the stage transition relationship. Kernel parameters that have completed interval association calculation and transfer association constraints are aggregated to form constraint kernel parameters. During aggregation, the kernel parameters in each stage parameter interval are rearranged according to the stage identifier, and the connection relationship of kernel parameters that satisfy the transfer association constraints between adjacent stage parameter intervals is also retained, thus forming constraint kernel parameters.
[0026] In this embodiment, step seven specifically includes: Extract object tags, time intervals, and interaction-related fragments from the set of joint events, and combine them into an event association record set. During extraction, read the object tags, time intervals, and interaction-related fragments corresponding to each joint event in the order of the set of joint events, and then write the object tags, time intervals, and interaction-related fragments into the same event association record, so that each event association record corresponds to a joint event, thus forming an event association record set. Based on object labels and time intervals, the slice matrix and column feature positions participating in the representation of the joint event set are located in the secure data slice set to form an anchor position set. During the location process, the slice matrix with consistent object labels is first retrieved in the secure data slice set. Then, the record vectors falling into the time interval are filtered in the retrieved slice matrix according to the time label. The column feature positions are determined according to the behavior label and status label corresponding to the interactive associated fragments. The slice matrix identifier and column feature positions are combined and recorded to form an anchor position set. During the common load solution process, event association aggregation calculation is performed on the common load according to the anchor position set to form the association strength of the joint event set in the anchor position set. During the calculation, the slice matrix position and column feature position corresponding to the anchor position set are read, and the values of the common load at the corresponding column feature positions are extracted. The cumulative calculation, mean calculation or weighted aggregation calculation is performed on all anchor positions corresponding to the same joint event to obtain the association strength of the joint event set in the anchor position set. Based on the correlation strength, the common load values in the anchoring location set are weighted and adjusted so that the common loads corresponding to the same set of joint events remain consistent within the anchoring location set. During execution, the correlation strength is mapped to the location weight, and then the location weight is applied to the common load values corresponding to the anchoring location set. For locations with large deviations in values, convergence adjustment is performed, and for locations with similar values, consistent changes are maintained, so that the common loads corresponding to the same set of joint events form a consistent aggregate representation within the anchoring location set. The common loads that have completed weight adjustments are aggregated according to the column feature order to form anchor common loads. During aggregation, all common load values are rearranged according to the column feature arrangement order in the safe data slice set, and the adjustment results corresponding to the anchor position set are written into the corresponding column feature position to form anchor common loads.
[0027] In this embodiment, step eight specifically includes: According to the arrangement position of the slice matrix, the factor components in the slice factor, the parameter components in the constraint kernel parameter, and the load components in the anchor common load are extracted to form a fusion record set. During extraction, the arrangement position of each slice matrix in the security data slice set is read first, and then the corresponding factor components are read from the slice factor, the corresponding parameter components are read from the constraint kernel parameter, and the corresponding load components are read from the anchor common load according to the arrangement position. The factor components, parameter components, and load components are written into the same fusion record to form a fusion record set. The fusion record set is registered according to the arrangement of the slice matrix, and the factor components, parameter components and load components are spliced and arranged according to the column feature order to form a characterization record set. During the registration, the arrangement of the slice matrix is used as the index to ensure that the factor components, parameter components and load components corresponding to the same arrangement position are in one-to-one correspondence. During the splicing and arrangement, the values of the factor components, parameter components and load components are arranged in the order of column features to form a characterization record set. Joint mapping calculations are performed on the factor components, parameter components, and load components in the characterization record set to form risk response values. During the joint mapping calculation, the factor components, parameter components, and load components in the characterization record set are used as input components in the same calculation unit. Weighted combination, linear transformation, and response calculation are performed on each input component so that each characterization record corresponds to a risk response value. According to the arrangement position of the slice matrix, the risk response values are merged and aggregated to form a safety risk characterization vector. During merging, risk response values with the same arrangement position are grouped into the same position unit. During aggregation, the risk response values in each position unit are arranged in order and numerically aggregated so that the risk response values corresponding to all position units are combined into a safety risk characterization vector. An evaluation mapping is performed on the security risk representation vector to form a security evaluation result for commercial cryptography applications. During the evaluation mapping, each component in the security risk representation vector is sequentially mapped to the evaluation output space, and the security evaluation result for commercial cryptography applications is determined based on the mapping result.
[0028] Example 1: To verify the feasibility of this invention in practice, it was applied to a commercial cryptographic application security assessment scenario of a large-scale integrated information platform. This platform simultaneously supports identity authentication, certificate management, key management, cryptographic device invocation, business access control, and interface encryption / decryption services. During platform operation, it continuously generates communication interaction data, business access data, identity authentication data, certificate management data, key management data, cryptographic device operation data, algorithm invocation data, and policy configuration data. In actual operation, the platform has long used rule comparison and single-source log analysis for security assessment. However, when business access volume increases, certificate status changes frequently, and cryptographic device load fluctuations intertwine, the same risky behavior is often scattered across different data sources, and the line length of individual records is inconsistent. This makes it difficult to identify the combined risks of key invocation continuing after certificate freezing, algorithm invocation triggering after authentication failure, and policy switching and device anomalies occurring simultaneously, resulting in significant false positives and false negatives.
[0029] In this scenario, multi-source security data generated by the platform operation is first aggregated to form a raw dataset. Then, time base correction, identifier normalization, and value encoding are performed on the raw dataset, reorganizing it into a set of security data slices with unified column features and variable row lengths. Subsequently, state evolution fragments are extracted from the security data slice set and arranged to form stage sequences and stage transition relationships. Simultaneously, interaction-related fragments are extracted and merged to form a joint event set. An improved PARAFAC2 deep decomposition model is constructed based on the security data slice set. Layer-by-layer decomposition of slice factors, kernel parameters, and common loads is completed in the hierarchical update unit sequence. The stage sequences and stage transition relationships are then introduced into the kernel parameter solution process to form constraint kernel parameters, and the joint event set is introduced into the common load solution process to form anchored common loads. Finally, a fusion representation is performed on the slice factors, constraint kernel parameters, and anchored common loads to obtain a security risk representation vector and complete the security assessment. After this processing, risk behaviors originally scattered across different data sources can be correlated in the same risk representation space, and continuous state changes that cannot be reflected by a single log can be fully expressed through stage sequences, thereby more accurately identifying cross-source joint anomalies.
[0030] During a complete evaluation cycle, the platform collected 1.324 million communication interaction data entries, 978,000 business access data entries, 816,000 identity authentication data entries, 193,000 certificate management data entries, 135,000 key management data entries, 461,000 cryptographic device operation data entries, 1.637 million algorithm call data entries, and 64,000 policy configuration data entries, totaling 5.608 million multi-source security data entries. After preprocessing, 35,700 security data slice samples were formed, with an average row length of 164 in the slice matrix, a minimum row length of 31, and a maximum row length of 252. Security operations personnel manually reviewed the high-risk samples and formed benchmark results. Under the same dataset and the same annotation standards, the method of this invention was compared with traditional rule evaluation methods, ordinary deep classification models, and the unconstrained PARAFAC2 evaluation method. The results are shown in Table 1. Table 1. Comparison of Safety Assessment Effects of Different Assessment Methods
[0031] As shown in Table 1, the method of this invention outperforms the comparative methods in all key indicators. Specifically, the recall rate for high-risk samples is 19.2 percentage points higher than the traditional rule-based evaluation method, 10.5 percentage points higher than the ordinary deep classification model, and 6.3 percentage points higher than the unconstrained PARAFAC2 evaluation method, indicating that this invention can capture real risk events more completely. The false positive rate is reduced to 4.8%, indicating that the introduction of stage transition relationships and joint event sets into the model effectively suppresses misjudgments caused by local fluctuations. The stage transition identification accuracy reaches 91.4%, and the joint event identification accuracy reaches 89.3%, demonstrating that this invention can not only identify single-point anomalies but also accurately reconstruct the state evolution chain and joint risk relationships across data sources. The average evaluation time per batch is reduced to 1.98 seconds, indicating that the improved PARAFAC2 deep decomposition model improves evaluation accuracy without increasing processing burden, and instead has better practical deployment efficiency. Therefore, this invention can effectively solve the problems of difficulty in unifying the organization of heterogeneous data, difficulty in continuously depicting state chains, and difficulty in stably identifying joint risks in the security assessment of commercial cryptographic applications. It has the beneficial effects of complete risk characterization, high assessment accuracy, low false alarm rate, and high operating efficiency.
[0032] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for security assessment of commercial cryptographic applications based on deep learning, characterized in that, Includes the following steps: Step 1: Collect multi-source security data during commercial cryptography applications to form the raw dataset; Step 2: Perform preprocessing on the original dataset to reorganize it into a set of secure data slices with uniform column features and variable row lengths; Step 3: Extract and arrange state evolution fragments from the security data slice set to form a stage sequence and stage transition relationship; extract and merge interactive related fragments from the security data slice set to form a joint event set. Step 4: Construct an improved PARAFAC2 deep decomposition model, build hierarchical update unit sequences corresponding to slice factor solution, kernel parameter solution and common load solution according to the update order, and establish decomposition residual constraints between adjacent hierarchical update units; Step 5: Using the hierarchical update unit sequence, perform a layer-by-layer decomposition of the safe data slice set under the decomposition residual constraint to form slice factors, kernel parameters, and common loads; Step Six: Introduce stage sequences and stage transition relationships in the kernel parameter solution to impose piecewise correlation constraints on the kernel parameters, forming constrained kernel parameters; Step 7: Introduce a joint event set in the common load solution, apply associated anchoring to the common load, and form an anchored common load; Step 8: Perform fusion characterization on the slice factor, constraint kernel parameters, and anchored common payload to form a security risk characterization vector, and complete the security assessment of commercial cryptographic applications.
2. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step one specifically involves: Collect communication interaction data, business access data, identity authentication data, certificate management data, key management data, cryptographic device operation data, algorithm call data, and policy configuration data during commercial cryptography applications to form multi-source security data; Extract time stamps, object stamps, behavior stamps, status stamps, and source stamps from multi-source security data to form a collected dataset; The collected datasets are sorted according to time stamp, grouped by object, and categorized by source according to source. The collected datasets, after being sorted sequentially, grouped by object, and categorized by source, are compiled into the original dataset.
3. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step two specifically involves: Time base correction is performed on the time stamps in the original dataset, identifier normalization is performed on the object stamps, and value encoding is performed on the behavior stamps, status stamps, and source stamps to form a regular record set; Arrange the time marker, object marker, behavior marker, status marker, and source marker in the regular record set into a record vector according to a unified field order, forming a mapped record set with unified column features; The mapping record set is grouped according to the object label, and the record vector in each group is segmented according to the time label to form a record fragment set; Arrange the record vectors in the record fragment set into a slice matrix according to the time stamp order, so that the slice matrix has the same column characteristics and different row lengths; The slice matrices are aggregated into a set of secure data slices.
4. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step three specifically involves: Extract time markers, object markers, and state markers from the slice matrix in the secure data slice set. Arrange the state markers according to the time marker order and divide the continuous state intervals according to the position of state marker changes to form a set of state evolution fragments. The state evolution fragment set is arranged according to the time stamp order, and stage identifiers are assigned to the state evolution fragments in the state evolution fragment set along the arrangement order to form a stage sequence; Perform a connection analysis on adjacent stage identifiers in the stage sequence, record the transfer relationship from the previous stage identifier to the next stage identifier, and form a stage transfer relationship; Extract time stamps, object stamps, and behavior stamps from the slice matrix in the secure data slice set; group record vectors according to object stamps; divide continuous interaction intervals according to time stamps; and form a set of interactive related fragments. The sets of interactive related fragments are merged according to object tags and time intervals to form a joint event set.
5. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step four specifically involves: The row length and column features of each slice matrix are extracted from the set of secure data slices. The slice factor dimension, kernel parameter dimension and common load dimension are determined by the number of column features and the distribution of row length, forming a decomposed configuration set. Establish the decomposition relationship between the slice matrix, slice factor, kernel parameter, and common load by configuring a slice matrix, a slice factor, and a kernel parameter, and configuring a common load according to a set of secure data slices; The slice factor solution is set as a representation update process based on the row records of the slice matrix, the kernel parameter solution is set as an intensity update process based on the component distribution inside the slice matrix, and the common load solution is set as a shared representation update process based on the common column features of the security data slice set. A hierarchical update unit is formed by solving for slice factors, kernel parameters, and common loads in that order, and all hierarchical update units are connected in the same order to form a hierarchical update unit sequence. Establish parameter inheritance relationships in the hierarchical update unit sequence so that the slice factor, kernel parameter and common load formed by the previous level update unit can participate in the solution of the next level update unit. The slice matrix is decomposed and reconstructed using the slice factor, kernel parameter and common load formed by the update unit at each level, and the decomposition residual constraint is formed based on the difference between the decomposition and reconstruction result and each slice matrix. The decomposition configuration set, hierarchical update unit sequence, and decomposition residual constraints are combined to form an improved PARAFAC2 deep decomposition model.
6. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step five specifically involves: The first-level update unit is determined according to the order of the hierarchical update unit sequence, and the slice matrix in the safe data slice set is mapped to the slice factor solution, kernel parameter solution and common load solution corresponding to the first-level update unit. In the first-level update unit, slice factor updates are performed using the slice matrix and decomposed configuration set to form the first round of slice factors. Kernel parameter updates are performed using the first round of slice factors and slice matrix to form the first round of kernel parameters. Common payload updates are performed using the first round of slice factors, first round of kernel parameters and security data slice set to form the first round of common payload. The slice matrix is decomposed and reconstructed using the first-round slice factor, the first-round kernel parameter, and the first-round common load, and the decomposition residual constraint is verified based on the difference between the decomposition and reconstruction result and the slice matrix. The first-round slice factor, first-round kernel parameter, and first-round common load that satisfy the decomposition residual constraints are passed to the next-level update unit, and the slice factor update, kernel parameter update, common load update, and decomposition residual constraint verification are repeatedly performed in the next-level update unit. At the end of the hierarchical update unit sequence, the slice factor, kernel parameters, and common payload formed by the final update are aggregated to form the slice factor, kernel parameters, and common payload.
7. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step six specifically involves: Extract stage identifiers arranged in the order of arrangement from the stage sequence, and extract the transition start and transition end points corresponding to the stage identifiers from the stage transition relationship to form a stage constraint record set; According to the stage constraint record set, locate the parameter position corresponding to the stage identifier in the kernel parameter, and divide the kernel parameter into intervals according to the arrangement order of the stage identifier to form the stage parameter interval; Within each stage parameter interval, the kernel parameters are subjected to interval correlation calculation according to the parameter position order, so that the kernel parameters within the same stage parameter interval remain continuously correlated. According to the stage transition relationship, the transition association restriction is applied to the parameter intervals of adjacent stages, so that the kernel parameter corresponding to the transition start point only forms a transition association with the kernel parameter corresponding to the transition end point. Kernel parameters that have completed interval correlation calculations and transition correlation constraints are aggregated into constraint kernel parameters.
8. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step seven specifically involves: Extract object tags, time intervals, and interaction-related fragments from the joint event set, and combine the object tags, time intervals, and interaction-related fragments into an event-related record set; Based on object labels and time intervals, locate the slice matrix and column feature positions that participate in the joint event set representation in the security data slice set to form an anchor position set; During the common load solution process, event association aggregation calculations are performed on the common load according to the anchor location set to form the association strength of the joint event set in the anchor location set; The common load values in the anchoring location set are adjusted according to the correlation strength to ensure that the common loads corresponding to the same set of joint events remain consistent within the anchoring location set. The common loads that have completed weight adjustments are aggregated according to column characteristic order to form anchored common loads.
9. The method for security assessment of commercial cryptographic applications based on deep learning according to claim 1, characterized in that, Step eight specifically involves: Extract the factor components from the slice factors, the parameter components from the constraint kernel parameters, and the load components from the anchored common loads according to the arrangement position of the slice matrix to form a fusion record set; The fused record set is registered according to the arrangement of the slice matrix, and the factor components, parameter components and load components are spliced and arranged according to the column feature order to form the characterization record set. Joint mapping calculations are performed on the factor components, parameter components, and loading components in the characterization record set to form risk response values; The risk response values are merged and aggregated according to the arrangement of the slice matrix to form a safety risk representation vector; An evaluation mapping is performed on the security risk representation vector to generate a security evaluation result for commercial cryptographic applications.