Automatic server security credential management system based on dynamic rules

The automated management system for server security credentials, which uses dynamic rule generation and real-time monitoring, solves the problems of dynamism and security in traditional management methods, achieving high efficiency and security in credential management and ensuring the security and consistency of credentials throughout their entire lifecycle.

WO2026098075A1PCT designated stage Publication Date: 2026-05-15SHANGHAI TIANLONG DIGITAL TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SHANGHAI TIANLONG DIGITAL TECH CO LTD
Filing Date
2025-09-17
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Traditional server credential management methods have shortcomings in terms of dynamism and security. They cannot adapt to rapidly changing use cases and security requirements, and lack dynamic generation, real-time monitoring, and intelligent adjustment, resulting in the inability to effectively guarantee credential security.

Method used

An automated server security credential management system based on dynamic rules is adopted, which includes a rule generation module, a credential generation module, a credential distribution module, a monitoring and detection module, a dynamic adjustment module, and a log recording module. By dynamically generating and adjusting credential management rules, it automatically generates unique identifiers and encryption keys, monitors credential usage in real time, and automatically adjusts in abnormal situations.

Benefits of technology

It achieves high efficiency and security in voucher management, can promptly identify and respond to abnormal voucher usage, ensures the security and consistency of vouchers throughout their lifecycle, and provides comprehensive recording and analysis support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025121944_15052026_PF_FP_ABST
    Figure CN2025121944_15052026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of information security, and specifically relates to an automatic server security credential management system based on dynamic rules. The system comprises a rule generation module, a credential generation module, a credential distribution module, a monitoring and detection module, a dynamic adjustment module and a log recording module, wherein the rule generation module is used for generating a corresponding dynamic management rule, the credential generation module is used for automatically generating a security credential on the basis of the dynamic management rule provided by the rule generation module, the credential distribution module is used for distributing the generated security credential to a specified server, the monitoring and detection module is used for detecting an anomaly of the security credential, and the dynamic adjustment module is used for adjusting the dynamic rule on the basis of monitoring data and an anomaly detection result. In the present invention, by means of dynamic rule generation, real-time monitoring, anomaly detection and an automatic adjustment mechanism, efficient and automatic management of server security credentials is realized, and the security and adaptability of credential management are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Dynamic rule-based automated management system for server security credentials Technical Field

[0001] This invention relates to the field of information security technology, and in particular to an automated management system for server security credentials based on dynamic rules. Background Technology

[0002] In modern information technology environments, server credential management is a crucial aspect of ensuring information system security. Especially with the widespread adoption of cloud computing and distributed architectures, effective credential management and security protection have become paramount. Traditional credential management typically relies on manual configuration or static rule-based methods. These methods suffer from low efficiency and inflexibility in credential generation, distribution, and usage monitoring, making them ill-suited to rapidly changing usage scenarios and security requirements. For instance, when server credentials are leaked due to misconfiguration or improper permission settings, traditional systems may fail to detect and respond promptly. Furthermore, traditional management methods lack automated rule adjustments and log analysis, making them ineffective in addressing abnormal credential usage. This compromises credential security, increasing the risk of information leakage and security attacks.

[0003] Therefore, existing technologies have significant shortcomings in terms of the dynamism and security of credential management, especially in frequently changing server environments. Traditional management methods cannot provide key functions such as dynamic generation, real-time monitoring, intelligent adjustment, and comprehensive recording. To address these issues, it is necessary to propose an automated server security credential management system based on dynamic rules to solve the aforementioned problems. Summary of the Invention

[0004] To achieve the above objectives, the present invention provides an automated management system for server security credentials based on dynamic rules.

[0005] The server security credential automated management system based on dynamic rules includes a rule generation module, a credential generation module, a credential distribution module, a monitoring and detection module, a dynamic adjustment module, and a logging module; among which:

[0006] Rule generation module: Used to generate corresponding dynamic management rules based on the server's usage scenario, connection frequency, and historical operation records. The dynamic management rules include the generation frequency of credentials, expiration time, and restrictions on usage permissions.

[0007] Credential generation module: connected to the rule generation module, used to automatically generate security credentials based on the dynamic management rules provided by the rule generation module, wherein the security credentials contain unique identification information and encryption keys;

[0008] Credential distribution module: Connected to the credential generation module, it is used to distribute the generated security credentials to designated servers and monitor the use of security credentials on the servers;

[0009] Monitoring and Detection Module: Connected to the credential distribution module, it is used to receive the usage of server security credentials and detect abnormal situations of security credentials through rule matching algorithms, including credential abuse, unauthorized access, and frequent requests;

[0010] Dynamic adjustment module: connected to the monitoring and detection module, used to adjust dynamic rules based on monitoring data and abnormal situation detection results to deal with potential security threats;

[0011] Log recording module: Connected to the above modules, it is used to record the operation logs and abnormal events of each module.

[0012] Optionally, the rule generation module includes a scene analysis unit, a connection frequency statistics unit, and a historical record analysis unit; wherein:

[0013] Scenario Analysis Unit: Used to analyze the actual usage scenarios of the server and generate the following dynamic management rules based on the scenarios;

[0014] Rule 1: When the server is located in an open network environment, the expiration time of the credentials shall be set to no more than 4 hours;

[0015] Rule 2: When the server is in a high-frequency task scenario, that is, when the number of operation requests per hour is greater than 100, the voucher generation frequency shall be at least once per hour.

[0016] Rule 3: When a server task involves sensitive data processing, access permissions will be restricted to only the specified data access operations.

[0017] Connection frequency statistics unit: Used to count the frequency of server access and, based on the statistical results, to generate voucher generation frequency and expiration time constraints, setting the voucher generation frequency as... The expiration time of the certificate is The limiting conditions include:

[0018] If the server access frequency satisfy times / hour, then times / hour, and Hour;

[0019] If the server access frequency Between 100 and 200 times per hour, Once / 2 hours, and Hour;

[0020] If the server access frequency times / hour, then Once / 4 hours, and Hour;

[0021] Historical record analysis unit: Used to generate usage permission restrictions based on the server's historical operation records. By analyzing the server's past credential usage and permission settings, it formulates corresponding permission priorities to ensure that credential permissions are consistent with the server's historical behavior.

[0022] Optionally, the historical record analysis unit includes:

[0023] Data extraction: Extract historical data for the most recent three months from the server's history. The extracted data includes the operation frequency, access resource categories, and permission levels for each credential.

[0024] Operation frequency statistics: The historical usage frequency of each voucher is statistically analyzed, and the required level of access privileges is determined based on this. Let the statistical value of historical usage frequency be... ;like If the permission is granted once per day, it indicates that the permission is a high-frequency permission, and the generated credentials must include this permission; if If the number of times per day is limited, the generated voucher must restrict the frequency of use of this permission.

[0025] Resource Access Classification: Based on the usage history of the credentials, classify the resource categories involved in each credential; let the access percentage of each resource category be denoted as . If the access percentage of a certain type of resource If the percentage is greater than 40%, it is considered a high-frequency access resource, and the generated credentials must restrict the access permissions of the corresponding resource to the highest priority.

[0026] Permission setting optimization: Based on operation frequency statistics and resource classification results, determine the permission priority for generating credentials; set the permission score as follows: The formula is: ,in The higher the value, the greater the permission requirement; specifically, the permission scope is divided into three levels: when When it is a high-priority permission, set the credential permission to full access; when When the priority is medium, the credential access is set to partial access; when... At that time, the permission is of low priority, and the credential permission is set to restricted access;

[0027] Permission consistency verification: Verify the consistency between the generated permission scope and the server's historical behavior to ensure that the set permission scope matches the actual use of the server and avoid permissions that are too broad or too narrow.

[0028] Optionally, the credential generation module includes a credential generation unit, a unique identifier generation unit, and an encryption key generation unit; wherein:

[0029] Credential generation unit: Used to automatically generate initial information for security credentials based on the dynamic management rules provided by the rule generation module, ensuring that the credential generation frequency, expiration time, and usage permissions comply with the limitations of the dynamic management rules;

[0030] Unique identifier generation unit: used to generate unique identifier information for each security credential. The unique identifier information is generated by a hash algorithm. Specifically, the SHA-256 algorithm is used to perform a hash operation on the initial information of the credential to generate a unique identifier with a length of 256 bits, so as to ensure the uniqueness of each credential in the system.

[0031] Encryption key generation unit: used to generate a corresponding encryption key for each security credential. The encryption key is generated using the Advanced Encryption Standard (AES) algorithm, with a key length of 256 bits, and a high-strength key is generated by a random number generator.

[0032] Optionally, the credential distribution module includes a credential transmission unit, a server designation unit, and a usage monitoring unit; wherein:

[0033] Server designation unit: used to determine the target server address of security credentials according to system configuration or management instructions, wherein the target server address includes the server's IP address, port number and communication protocol type;

[0034] Voucher transmission unit: connected to the designated server unit, used to send the security credential generated by the credential generation module to the designated server through an encrypted communication channel, wherein the encrypted communication channel is encrypted using a transport layer security protocol;

[0035] Usage monitoring unit: Used for real-time monitoring of the usage of distributed security credentials on the server, including usage frequency. Usage time and verification results .

[0036] Optionally, the monitoring and detection module includes a usage record collection unit, a rule matching unit, and an anomaly detection unit; wherein:

[0037] Usage record collection unit: used to collect real-time data on the usage of server security credentials, including the frequency of each use, the time of use, and the verification result;

[0038] Rule matching unit: It compares the usage data obtained by the usage record collection unit with the dynamic management rules provided by the rule generation module. By matching the rules, it identifies whether the usage behavior of the credential meets the preset normal conditions. If the usage behavior exceeds the rule limit, the rule matching unit will mark the behavior as a potential anomaly and submit it to the anomaly detection unit for analysis.

[0039] Anomaly detection unit: Used to determine the anomaly type and identify specific anomalies based on the potential anomalies marked by the rule matching unit.

[0040] Optionally, the rule matching unit includes:

[0041] Data reception: Receives data on credential usage provided by the record collection unit, including usage frequency. Usage time and verification results ;

[0042] Rule Acquisition: Retrieves dynamic management rules from the rule generation module, including the maximum allowed usage frequency. Permissible usage time range and the acceptance criteria for the verification results ;

[0043] Frequency matching: Compare usage frequencies With the maximum allowed frequency of use ,like If it is normal, it indicates that the frequency of use is normal; otherwise, it is marked as abnormal.

[0044] Usage time matching: Determine usage time Is it within the permitted usage time range? inside, if If the time is normal, it indicates that the usage time is normal; otherwise, it is marked as abnormal.

[0045] Verification result matching: Check the verification results Does it meet the qualification standards? ,like If the result is positive, the verification result is normal; otherwise, it is marked as a verification error.

[0046] Comprehensive matching judgment: The above conditions are comprehensively judged. If all conditions are met, the use of the voucher is considered to meet the preset normal conditions; otherwise, it is marked as a potential anomaly.

[0047] Anomaly Marking: For usage behaviors marked as potentially abnormal, the rule matching unit will record the anomaly type, credential ID, and timestamp, and submit them to the anomaly detection unit for analysis.

[0048] Optionally, the anomaly detection unit includes:

[0049] Abnormal data reception: Receive potential abnormal data marked by the rule matching unit, the data including abnormality type markers, including frequency abnormality, time abnormality, and verification abnormality;

[0050] Frequency anomaly analysis: For potential anomaly data marked as frequency anomalies, the anomaly detection unit calculates the actual usage frequency. With the maximum allowed frequency of use The deviation between the values ​​is used to determine the severity of the frequency anomaly; the deviation calculation formula is: ;like If so, it is marked as a high-frequency abuse anomaly; if If so, it is marked as a mild frequency anomaly;

[0051] Time anomaly analysis: For potentially anomalous data marked as time anomalies, the anomaly detection unit calculates the actual usage time. Relative to the allowed usage time range degree of deviation To determine the specific type of time anomaly; if If it lasts for minutes, it will be marked as an abnormality due to prolonged continuous use; if If the time interval is less than a minute, it is marked as a mild time anomaly;

[0052] Verification anomaly analysis: For potentially abnormal data marked as verification anomalies, the anomaly detection unit calculates the ratio of verification failures to the total number of verification requests, which serves as the basis for determining verification anomalies; verification failure rate. The calculation formula is: ,in, To verify the number of failures, This represents the total number of verification requests; if Then it is marked as a high failure rate exception: if It is then marked as a minor validation anomaly;

[0053] Comprehensive anomaly identification: When multiple anomaly types occur simultaneously, the anomaly detection unit will mark them as composite anomalies and record detailed anomaly data, including credential ID, anomaly type, timestamp, deviation value, deviation time, and verification failure rate.

[0054] Optionally, the dynamic adjustment module includes a credential regeneration unit, an expiration time update unit, and a permission priority adjustment unit; wherein:

[0055] Credential Regeneration Unit: When the anomaly detection unit identifies high-risk anomalies, including high-frequency abuse anomalies, long-term continuous use anomalies, or high failure rate anomalies, it immediately triggers the regeneration of credentials; it will generate new security credentials based on the dynamic management rules provided by the rule generation module and revoke the original credentials.

[0056] Expiration Time Update Unit: Used to dynamically update the expiration time of vouchers based on their actual usage. The unit adjusts the expiration time according to usage frequency, usage time, and verification result data. If the actual usage frequency Exceeding the preset frequency threshold In this case, the failure time is shortened. Update according to the following formula: ,in, This is the shortening factor, set to 0.5; if the actual usage frequency... Less than or equal to the frequency threshold If no abnormal detection results are found, the failure time will be extended. Update according to the following formula: ,in, This is the extension factor, set to 1.5;

[0057] Permission priority adjustment unit: Used to dynamically adjust the permission priority of credentials based on anomaly detection results, ensuring that credential permissions meet current security requirements; permission priority The adjustment is based on the following conditions: if unauthorized access is detected, the permission priority is reduced, and the permission priority adjustment formula is: ,in, This reduces the coefficient, setting it to 0.8; if using frequency... and verification results If all conditions in the rule generation module are met and no abnormal records are found, then the permission priority will be restored or increased. The permission priority adjustment formula is as follows: ,in, This is the boost factor, set to 1.2.

[0058] Optionally, the log recording module includes a log acquisition unit, a log storage unit, and a log analysis unit; wherein:

[0059] Log collection unit: used to collect operation logs and abnormal event information from various modules in the system in real time. The operation logs include the operation time, operation type and operation result of the module, and the abnormal event information includes the time of occurrence of the abnormality and the type of the abnormality.

[0060] Log storage unit: used to store the log information collected by the log collection unit in a predetermined format; the predetermined format includes timestamp, module identifier, operation type, operation result, exception type and description field.

[0061] The beneficial effects of this invention are:

[0062] This invention solves the problems of lag and poor flexibility in traditional voucher management by dynamically generating and adjusting voucher management rules. The system can generate specific dynamic rules based on the actual usage of the server, including the voucher generation frequency, expiration time, and permission scope, making voucher management more targeted. With automatically generated unique identifiers and encryption keys, the system further enhances voucher security and effectively prevents vouchers from being reused or maliciously tampered with. In addition, by encrypting transmission and monitoring voucher usage in real time, the system ensures the security and consistency of vouchers throughout their entire lifecycle.

[0063] This invention, through a real-time anomaly detection and dynamic adjustment mechanism, can promptly identify abnormal credential usage, such as frequent requests, unauthorized access, and abuse. It automatically adjusts management rules based on the anomalies and, combined with a refined logging function, comprehensively records the operations and abnormal events of each module, providing reliable data support for subsequent security analysis and troubleshooting. Attached Figure Description

[0064] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0065] Figure 1 is a schematic diagram of the fully automated voucher management system according to an embodiment of the present invention;

[0066] Figure 2 is a schematic diagram of the monitoring and detection module according to an embodiment of the present invention. Detailed Implementation

[0067] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. It should also be noted that, to make the embodiments more comprehensive, the following embodiments are the best and preferred embodiments, and those skilled in the art can use other alternative methods to implement some well-known technologies; moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.

[0068] It should be noted that the use of terms such as "an embodiment," "an embodiment," "an exemplary embodiment," and "some embodiments" in the specification indicates that the described embodiment may include a specific feature, structure, or characteristic, but not every embodiment necessarily includes that specific feature, structure, or characteristic. Furthermore, when a specific feature, structure, or characteristic is described in connection with an embodiment, implementing such a feature, structure, or characteristic in conjunction with other embodiments (whether explicitly described or not) should be within the knowledge of those skilled in the art.

[0069] Generally, terms can be understood at least partly from their use in context. For example, depending at least partly on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in a singular sense, or a combination of features, structures, or characteristics in a plural sense. Additionally, the term "based on" can be understood not necessarily to convey an exclusive set of factors, but rather, alternatively, depending at least partly on the context, to allow for the presence of other factors that are not necessarily explicitly described.

[0070] As shown in Figures 1 and 2, the automated server security credential management system based on dynamic rules includes a rule generation module, a credential generation module, a credential distribution module, a monitoring and detection module, a dynamic adjustment module, and a log recording module; among which:

[0071] Rule generation module: Used to generate corresponding dynamic management rules based on the server's usage scenario, connection frequency, and historical operation records. Dynamic management rules include the frequency of credential generation, expiration time, and restrictions on usage permissions.

[0072] Credential generation module: Connected to the rule generation module, it is used to automatically generate security credentials based on the dynamic management rules provided by the rule generation module. The security credentials contain unique identification information and encryption keys to ensure the uniqueness and confidentiality of the credentials.

[0073] Credential Distribution Module: Connected to the credential generation module, it distributes the generated security credentials to designated servers and monitors the usage of security credentials on the servers;

[0074] Monitoring and Detection Module: Connected to the credential distribution module, it receives information on the use of server security credentials and detects anomalies in security credentials through rule matching algorithms, including credential abuse, unauthorized access, and frequent requests.

[0075] Dynamic adjustment module: Connected to the monitoring and detection module, it is used to adjust dynamic rules based on monitoring data and anomaly detection results to address potential security threats;

[0076] Log recording module: Connected to the above modules, it is used to record the operation logs and abnormal events of each module for subsequent auditing and security analysis.

[0077] The rule generation module includes a scenario analysis unit, a connection frequency statistics unit, and a historical record analysis unit; among which:

[0078] Scenario Analysis Unit: Used to analyze the actual usage scenarios of the server and generate the following dynamic management rules based on the scenarios;

[0079] Rule 1: When the server is located in an open network environment, the expiration time of the credentials is set to no more than 4 hours to reduce the risk of external attacks;

[0080] Rule 2: When the server is in a high-frequency task scenario, that is, when the number of operation requests per hour is greater than 100, the voucher generation frequency is at least once per hour to ensure the timeliness of the voucher.

[0081] Rule 3: When a server task involves sensitive data processing, access permissions will be restricted to specific data access operations only to avoid granting too many permissions.

[0082] Connection frequency statistics unit: Used to count the frequency of server access and, based on the statistical results, to generate voucher generation frequency and expiration time constraints, setting the voucher generation frequency as... The expiration time of the certificate is The limiting conditions include:

[0083] If the server access frequency satisfy times / hour, then times / hour, and Hour;

[0084] If the server access frequency Between 100 and 200 times per hour, Once / 2 hours, and Hour;

[0085] If the server access frequency times / hour, then Once / 4 hours, and Hour;

[0086] Historical Record Analysis Unit: This unit generates usage permission restrictions based on the server's historical operation records. By analyzing the server's past credential usage and permission settings, it establishes corresponding permission priorities to ensure that credential permissions are consistent with the server's historical behavior. This ensures that the generated credential permission settings are reasonable and avoids the risks of overly broad or narrow permissions. Through the synergistic effect of the above units, the rule generation module can comprehensively consider the server's usage scenarios, connection frequency, and historical operation records to generate dynamic management rules adapted to the server's security requirements. This ensures that the frequency of credential generation, expiration time, and usage permissions match the actual usage of the server, achieving both high efficiency and security in credential management.

[0087] The historical record analysis unit includes:

[0088] Data extraction: Extract historical data for the most recent three months from the server's history. The extracted data includes the operation frequency, access resource categories, and permission levels for each credential.

[0089] Operation frequency statistics: The historical usage frequency of each voucher is statistically analyzed, and the required level of access privileges is determined based on this. Let the statistical value of historical usage frequency be... The formula is: ,in, Indicates the first The number of operations, where n represents the total number of operations for this voucher within the statistical range, and T represents the statistical time span in days; if If the permission is granted once per day, it indicates that the permission is a high-frequency permission, and the generated credentials must include this permission; if If the number of times per day is limited, the generated voucher must restrict the frequency of use of this permission.

[0090] Resource Access Classification: Based on the usage history of the credentials, classify the resource categories involved in each credential; let the access percentage of each resource category be denoted as . The formula is: ,in, This represents the number of accesses to resource type j, where m is the number of resource types and M is the total number of accesses; if the access percentage of a certain resource type... If the percentage is greater than 40%, it is considered a high-frequency access resource, and the generated credentials must restrict the access permissions of the corresponding resource to the highest priority.

[0091] Permission setting optimization: Based on operation frequency statistics and resource classification results, determine the permission priority for generating credentials; set the permission score as follows: The formula is: ,in The higher the value, the greater the permission requirement; specifically, the permission scope is divided into three levels: when When it is a high-priority permission, set the credential permission to full access; when When the priority is medium, the credential access is set to partial access; when... At that time, the permission is of low priority, and the credential permission is set to restricted access;

[0092] Permission consistency verification: This verifies the consistency between the generated permission scope and the server's historical behavior, ensuring that the set permission scope matches the actual usage of the server and avoiding permissions that are too broad or too narrow. Specifically, this is achieved by analyzing the consistency ratio between the permission scope and historical behavior. To determine this, the formula is: ,like If the consistency is good, it indicates good consistency; if If so, the permission scope needs to be readjusted until consistency meets the set standard. Through the above steps, the historical record analysis unit can automatically generate accurate permission priorities based on the server's historical behavior, ensuring that the permission settings of credentials are consistent with the actual usage needs of the server, avoiding the risk of permissions being too broad or too narrow, and improving the security and adaptability of credential management.

[0093] The credential generation module includes a credential generation unit, a unique identifier generation unit, and an encryption key generation unit; wherein:

[0094] Credential generation unit: Used to automatically generate initial information for security credentials based on the dynamic management rules provided by the rule generation module, ensuring that the credential generation frequency, expiration time, and usage permissions comply with the limitations of the dynamic management rules;

[0095] Unique Identifier Generation Unit: Used to generate unique identifier information for each security credential. The unique identifier information is generated by a hash algorithm. Specifically, the SHA-256 algorithm is used to perform a hash operation on the initial information of the credential to generate a unique identifier with a length of 256 bits, so as to ensure the uniqueness of each credential in the system and prevent credential duplication and conflict.

[0096] Encryption key generation unit: Used to generate a corresponding encryption key for each security credential. The encryption key is generated using the Advanced Encryption Standard (AES) algorithm, with a key length of 256 bits. A high-strength key is generated through a random number generator to ensure the confidentiality and security of the credential. Through the synergistic effect of the above units, the credential generation module can automatically generate security credentials containing unique identification information and encryption keys according to dynamic management rules, ensuring the uniqueness, confidentiality, and compliance with the requirements of dynamic management rules of the credential, thus realizing the secure generation and efficient management of credentials.

[0097] The credential distribution module includes a credential transmission unit, a server designation unit, and a usage monitoring unit; wherein:

[0098] Server designated unit: Used to determine the target server address of security credentials based on system configuration or management instructions. The target server address includes the server's IP address, port number, and communication protocol type, ensuring that security credentials can be accurately sent to the designated server;

[0099] The credential transmission unit is connected to the designated server unit and is used to send the secure credential generated by the credential generation module to the designated server through an encrypted communication channel. The encrypted communication channel is encrypted using the Transport Layer Security Protocol (TLS 1.3) to ensure the confidentiality and integrity of the credential during transmission and to prevent the credential from being intercepted or tampered with.

[0100] Usage Monitoring Unit: Used for real-time monitoring of the usage of distributed security credentials on the server, including usage frequency. Usage time and verification results Among these, usage frequency monitoring involves periodically sending usage query requests to the server to obtain the number of times the credentials have been used. and time interval To calculate usage frequency The formula is: Usage time monitoring involves recording the first time a credential is used. and last time of use Calculate the active period of the voucher. The formula is: The verification result is obtained by collecting the server's success rate in verifying credentials. Calculate the verification failure rate When the verification failure rate exceeds 5%, an abnormal event is recorded, indicating a potential risk of credential tampering. Through the synergistic effect of the above units, the credential distribution module can accurately and securely distribute the generated security credentials to the designated server and monitor the use of security credentials on the server in real time, specifically monitoring the usage frequency, usage time, and verification results. This ensures the validity and security of the credentials, helps to promptly detect and handle abnormal situations in credential use, and improves the system's security management level.

[0101] The monitoring and detection module includes a usage record collection unit, a rule matching unit, and an anomaly detection unit; among which:

[0102] Usage record collection unit: used to collect real-time data on the usage of server security credentials. The collected data includes the frequency of each use of the credentials, the time of use, and the verification result, providing complete data support for subsequent anomaly detection.

[0103] Rule matching unit: It compares the usage data obtained by the usage record collection unit with the dynamic management rules provided by the rule generation module. By matching the rules, it identifies whether the usage behavior of the credential meets the preset normal conditions; to ensure that each credential request is within the scope allowed by the rules; if the usage behavior exceeds the rule limit, the rule matching unit will mark the behavior as a potential anomaly and submit it to the anomaly detection unit for analysis.

[0104] Anomaly detection unit: Used to determine the anomaly type and identify specific anomalies based on the potential anomalies marked by the rule matching unit.

[0105] The rule matching unit includes:

[0106] Data reception: Receives data on voucher usage provided by the record collection unit, including usage frequency. Usage time and verification results ;

[0107] Rule Acquisition: Retrieves dynamic management rules from the rule generation module. The rules include the maximum allowed usage frequency. Permissible usage time range and the acceptance criteria for the verification results ;

[0108] Frequency matching: Compare usage frequencies With the maximum allowed frequency of use ,like If it is normal, it indicates that the frequency of use is normal; otherwise, it is marked as abnormal.

[0109] Usage time matching: Determine usage time Is it within the permitted usage time range? inside, if If the time is normal, it indicates that the usage time is normal; otherwise, it is marked as abnormal.

[0110] Verification result matching: Check the verification results Does it meet the qualification standards? ,like If the result is positive, the verification result is normal; otherwise, it is marked as a verification error.

[0111] Comprehensive matching judgment: The above conditions are comprehensively judged. If all conditions are met, the use of the voucher is considered to meet the preset normal conditions; otherwise, it is marked as a potential anomaly.

[0112] Anomaly Marking: For usage behaviors marked as potentially abnormal, the rule matching unit will record the anomaly type (frequency anomaly, time anomaly, verification anomaly), credential ID, and timestamp, and submit them to the anomaly detection unit for analysis. Through the above steps, the rule matching unit can accurately match credential usage with dynamic management rules, and promptly mark behaviors that exceed the rule restrictions as potential anomalies, providing effective technical support for system security protection.

[0113] The anomaly detection unit includes:

[0114] Abnormal data reception: Receives potential abnormal data marked by rule matching units. The data includes anomaly type markers, including frequency anomalies, time anomalies, and verification anomalies.

[0115] Frequency anomaly analysis: For potential anomaly data marked as frequency anomalies, the anomaly detection unit calculates the actual usage frequency. With the maximum allowed frequency of use The deviation between the values ​​is used to determine the severity of the frequency anomaly; the deviation calculation formula is: ;like If so, it is marked as a high-frequency abuse anomaly; if If so, it is marked as a mild frequency anomaly;

[0116] Time anomaly analysis: For potentially anomalous data marked as time anomalies, the anomaly detection unit calculates the actual usage time. Relative to the allowed usage time range degree of deviation To determine the specific type of time anomaly; if If it lasts for minutes, it will be marked as an abnormality due to prolonged continuous use; if If the time interval is less than a minute, it is marked as a mild time anomaly;

[0117] Verification anomaly analysis: For potentially abnormal data marked as verification anomalies, the anomaly detection unit calculates the ratio of verification failures to the total number of verification requests, which serves as the basis for determining verification anomalies; verification failure rate. The calculation formula is: ,in, To verify the number of failures, This represents the total number of verification requests; if Then it is marked as a high failure rate exception: if It is then marked as a minor validation anomaly;

[0118] Comprehensive Anomaly Identification: When multiple anomaly types occur simultaneously, the anomaly detection unit will mark them as composite anomalies and record detailed anomaly data, including credential ID, anomaly type, timestamp, deviation value, deviation time, and verification failure rate. Through the above steps, the anomaly detection unit can accurately determine the anomaly type and identify specific anomalies based on potential anomaly data, providing more refined protection measures for the system's security management.

[0119] The dynamic adjustment module includes a voucher regeneration unit, an expiration time update unit, and a permission priority adjustment unit; among which:

[0120] Credential Regeneration Unit: When the anomaly detection unit identifies high-risk anomalies, including high-frequency abuse anomalies, long-term continuous use anomalies, or high failure rate anomalies, it immediately triggers credential regeneration; it generates new security credentials based on the dynamic management rules provided by the rule generation module and revokes the original credentials; the newly generated credentials contain a unique identifier and encryption key to ensure the uniqueness and confidentiality of the credentials;

[0121] Expiration Time Update Unit: Used to dynamically update the expiration time of vouchers based on their actual usage. The unit adjusts the expiration time according to usage frequency, usage time, and verification result data. If the actual usage frequency Exceeding the preset frequency threshold In this case, the failure time is shortened. Update according to the following formula: ,in, This is the shortening factor, set to 0.5; if the actual usage frequency... Less than or equal to the frequency threshold If no abnormal detection results are found, the failure time will be extended. Update according to the following formula: ,in, This is the extension factor, set to 1.5;

[0122] Permission priority adjustment unit: Used to dynamically adjust the permission priority of credentials based on anomaly detection results, ensuring that credential permissions meet current security requirements; permission priority The adjustment is based on the following conditions: if unauthorized access is detected, the permission priority is reduced, and the permission priority adjustment formula is: ,in, This reduces the coefficient, setting it to 0.8; if using frequency... and verification results If all conditions in the rule generation module are met and no abnormal records are found, then the permission priority will be restored or increased. The permission priority adjustment formula is as follows: ,in, The boost factor is set to 1.2. Through the synergistic effect of the above units, the dynamic adjustment module can dynamically adjust the management rules in real time based on monitoring data and anomaly detection results, including regenerating credentials, updating expiration times, and adjusting permission priorities, in order to deal with potential security threats and ensure the effective management and security of server credentials.

[0123] The log recording module includes a log collection unit, a log storage unit, and a log analysis unit; among which:

[0124] Log collection unit: Used to collect operation logs and abnormal event information from various modules in the system in real time. Operation logs include the operation time, operation type and operation result of the module, and abnormal event information includes the time of occurrence and the type of abnormality. The log collection unit ensures the integrity and accuracy of all log information, providing a reliable foundation for subsequent data storage and analysis.

[0125] Log storage unit: Used to store the log information collected by the log collection unit in a predetermined format; the predetermined format includes timestamp, module identifier, operation type, operation result, exception type and description field; through the synergistic effect of the above units, the log recording module can comprehensively and accurately record the operation logs and abnormal events of each module, providing important technical support for system security management, performance optimization and fault diagnosis.

[0126] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.

[0127] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

The server security credential automated management system based on dynamic rules is characterized by, It includes a rule generation module, a voucher generation module, a voucher distribution module, a monitoring and detection module, a dynamic adjustment module, and a log recording module; among which: Rule generation module: Used to generate corresponding dynamic management rules based on the server's usage scenario, connection frequency, and historical operation records. The dynamic management rules include the generation frequency of credentials, expiration time, and restrictions on usage permissions. Credential generation module: connected to the rule generation module, used to automatically generate security credentials based on the dynamic management rules provided by the rule generation module, wherein the security credentials contain unique identification information and encryption keys; Credential distribution module: Connected to the credential generation module, it is used to distribute the generated security credentials to designated servers and monitor the use of security credentials on the servers; Monitoring and Detection Module: Connected to the credential distribution module, it is used to receive the usage of server security credentials and detect abnormalities in security credentials through rule matching algorithms, including credential abuse, unauthorized access, and frequent requests; Dynamic adjustment module: connected to the monitoring and detection module, used to adjust dynamic rules based on monitoring data and abnormal situation detection results to deal with potential security threats; Log recording module: Connected to the above modules, it is used to record the operation logs and abnormal events of each module. The automated server security credential management system based on dynamic rules according to claim 1 is characterized in that, The rule generation module includes a scenario analysis unit, a connection frequency statistics unit, and a historical record analysis unit; wherein: Scenario Analysis Unit: Used to analyze the actual usage scenarios of the server and generate the following dynamic management rules based on the scenarios; Rule 1: When the server is located in an open network environment, the expiration time of the credentials shall be set to no more than 4 hours; Rule 2: When the server is in a high-frequency task scenario, that is, when the number of operation requests per hour is greater than 100, the voucher generation frequency shall be at least once per hour. Rule 3: When a server task involves sensitive data processing, access permissions will be restricted to only the specified data access operations. Connection frequency statistics unit: Used to count the frequency of server access and, based on the statistical results, to generate voucher generation frequency and expiration time constraints, setting the voucher generation frequency as... The expiration time of the certificate is The limiting conditions include: If the server access frequency satisfy times / hour, then times / hour, and Hour; If the server access frequency Between 100 and 200 times per hour, Once / 2 hours, and Hour; If the server access frequency times / hour, then Once / 4 hours, and Hour; Historical record analysis unit: Used to generate usage permission restrictions based on the server's historical operation records. By analyzing the server's past credential usage and permission settings, it formulates corresponding permission priorities to ensure that credential permissions are consistent with the server's historical behavior. The automated server security credential management system based on dynamic rules according to claim 2 is characterized in that, The historical record analysis unit includes: Data extraction: Extract historical data for the most recent three months from the server's history. The extracted data includes the operation frequency, access resource categories, and permission levels for each credential. Operation frequency statistics: The historical usage frequency of each voucher is statistically analyzed, and the required level of access privileges is determined based on this. Let the statistical value of historical usage frequency be... ;like If the permission is granted once per day, it indicates that the permission is a high-frequency permission, and the generated credentials must include this permission; if If the number of times per day is limited, the generated voucher must restrict the frequency of use of this permission. Resource Access Classification: Based on the usage history of the credentials, classify the resource categories involved in each credential; let the access percentage of each resource category be denoted as . If the access percentage of a certain type of resource If the percentage is greater than 40%, it is considered a high-frequency access resource, and the generated credentials must restrict the access permissions of the corresponding resource to the highest priority. Permission setting optimization: Based on operation frequency statistics and resource classification results, determine the permission priority for generating credentials; set the permission score as follows: The formula is: ,in The higher the value, the greater the permission requirement; specifically, the permission scope is divided into three levels: when When it is a high-priority permission, set the credential permission to full access; when When the priority is medium, the credential access is set to partial access; when... At that time, the permission is of low priority, and the credential permission is set to restricted access; Permission consistency verification: Verify the consistency between the generated permission scope and the server's historical behavior to ensure that the set permission scope matches the actual use of the server and avoid permissions that are too broad or too narrow. The automated server security credential management system based on dynamic rules according to claim 1 is characterized in that, The credential generation module includes a credential generation unit, a unique identifier generation unit, and an encryption key generation unit; wherein: Credential generation unit: Used to automatically generate initial information for security credentials based on the dynamic management rules provided by the rule generation module, ensuring that the credential generation frequency, expiration time, and usage permissions comply with the limitations of the dynamic management rules; Unique identifier generation unit: used to generate unique identifier information for each security credential. The unique identifier information is generated by a hash algorithm. Specifically, the SHA-256 algorithm is used to perform a hash operation on the initial information of the credential to generate a unique identifier with a length of 256 bits, so as to ensure the uniqueness of each credential in the system. Encryption key generation unit: used to generate a corresponding encryption key for each security credential. The encryption key is generated using the Advanced Encryption Standard (AES) algorithm, with a key length of 256 bits, and a high-strength key is generated by a random number generator. The automated server security credential management system based on dynamic rules according to claim 1 is characterized in that, The credential distribution module includes a credential transmission unit, a server designation unit, and a usage monitoring unit; wherein: Server designation unit: used to determine the target server address of security credentials according to system configuration or management instructions, wherein the target server address includes the server's IP address, port number and communication protocol type; Voucher transmission unit: connected to the designated server unit, used to send the security credential generated by the credential generation module to the designated server through an encrypted communication channel, wherein the encrypted communication channel is encrypted using a transport layer security protocol; Usage monitoring unit: Used for real-time monitoring of the usage of distributed security credentials on the server, including usage frequency. Usage time and verification results 。 The automated server security credential management system based on dynamic rules according to claim 5 is characterized in that, The monitoring and detection module includes a usage record collection unit, a rule matching unit, and an anomaly detection unit; wherein: Usage record collection unit: used to collect real-time data on the usage of server security credentials, including the frequency of each use, the time of use, and the verification result; Rule matching unit: It compares the usage data obtained by the usage record collection unit with the dynamic management rules provided by the rule generation module. By matching the rules, it identifies whether the usage behavior of the credential meets the preset normal conditions. If the usage behavior exceeds the rule limit, the rule matching unit will mark the behavior as a potential anomaly and submit it to the anomaly detection unit for analysis. Anomaly detection unit: Used to determine the anomaly type and identify specific anomalies based on the potential anomalies marked by the rule matching unit. The automated server security credential management system based on dynamic rules according to claim 6 is characterized in that, The rule matching unit includes: Data reception: Receives data on credential usage provided by the record collection unit, including usage frequency. Usage time and verification results ; Rule Acquisition: Retrieves dynamic management rules from the rule generation module, including the maximum allowed usage frequency. Permissible usage time range and the acceptance criteria for the verification results ; Frequency matching: Compare usage frequencies With the maximum allowed frequency of use ,like If it is normal, it indicates that the frequency of use is normal; otherwise, it is marked as abnormal. Usage time matching: Determine usage time Is it within the permitted usage time range? Inside, young If the time is normal, it indicates that the usage time is normal; otherwise, it is marked as abnormal. Verification result matching: Check the verification results Does it meet the qualification standards? ,like If the result is positive, the verification result is normal; otherwise, it is marked as a verification error. Comprehensive matching judgment: The above conditions are comprehensively judged. If all conditions are met, the use of the voucher is considered to meet the preset normal conditions; otherwise, it is marked as a potential anomaly. Anomaly Marking: For usage behaviors marked as potentially abnormal, the rule matching unit will record the anomaly type, credential ID, and timestamp, and submit them to the anomaly detection unit for analysis. The automated server security credential management system based on dynamic rules according to claim 7 is characterized in that, The anomaly detection unit includes: Abnormal data reception: Receive potential abnormal data marked by the rule matching unit, the data including abnormality type markers, including frequency abnormality, time abnormality, and verification abnormality; Frequency anomaly analysis: For potential anomaly data marked as frequency anomalies, the anomaly detection unit calculates the actual usage frequency. With the maximum allowed frequency of use The deviation between the values ​​is used to determine the severity of the frequency anomaly; the deviation calculation formula is: ;like If so, it is marked as a high-frequency abuse anomaly; if If so, it is marked as a mild frequency anomaly; Time anomaly analysis: For potentially anomalous data marked as time anomalies, the anomaly detection unit calculates the actual usage time. Relative to the allowed usage time range degree of deviation To determine the specific type of time anomaly; if If it lasts for minutes, it will be marked as an abnormality due to prolonged continuous use; if If the time interval is less than a minute, it is marked as a mild time anomaly; Verification anomaly analysis: For potentially abnormal data marked as verification anomalies, the anomaly detection unit calculates the ratio of verification failures to the total number of verification requests, which serves as the basis for determining verification anomalies; verification failure rate. The calculation formula is: ,in, To verify the number of failures, This represents the total number of verification requests; if Then it is marked as a high failure rate exception: if It is then marked as a minor validation anomaly; Comprehensive anomaly identification: When multiple anomaly types occur simultaneously, the anomaly detection unit will mark them as composite anomalies and record detailed anomaly data, including credential ID, anomaly type, timestamp, deviation value, deviation time, and verification failure rate. The automated server security credential management system based on dynamic rules according to claim 1 is characterized in that, The dynamic adjustment module includes a credential regeneration unit, an expiration time update unit, and a permission priority adjustment unit; wherein: Credential Regeneration Unit: When the anomaly detection unit identifies high-risk anomalies, including high-frequency abuse anomalies, long-term continuous use anomalies, or high failure rate anomalies, it immediately triggers the regeneration of credentials; it generates new security credentials based on the dynamic management rules provided by the rule generation module and revokes the original credentials. Expiration Time Update Unit: Used to dynamically update the expiration time of vouchers based on their actual usage. The unit adjusts the expiration time according to usage frequency, usage time, and verification result data. If the actual usage frequency Exceeding the preset frequency threshold In this case, the failure time is shortened. Update according to the following formula: ,in, This is the shortening factor, set to 0.5; if the actual usage frequency... Less than or equal to the frequency threshold If no abnormal detection results are found, the failure time will be extended. Update according to the following formula: ,in, This is the extension factor, set to 1.5; Permission priority adjustment unit: Used to dynamically adjust the permission priority of credentials based on anomaly detection results, ensuring that credential permissions meet current security requirements; permission priority The adjustment is based on the following conditions: if unauthorized access is detected, the permission priority is reduced, and the permission priority adjustment formula is: ,in, This reduces the coefficient, setting it to 0.8; if using frequency... and verification results If all conditions in the rule generation module are met and no abnormal records are found, then the permission priority will be restored or increased. The permission priority adjustment formula is as follows: ,in, This is the boost factor, set to 1.

2. The automated server security credential management system based on dynamic rules according to claim 1 is characterized in that, The log recording module includes a log acquisition unit, a log storage unit, and a log analysis unit; wherein: Log collection unit: used to collect operation logs and abnormal event information from various modules in the system in real time. The operation logs include the operation time, operation type and operation result of the module, and the abnormal event information includes the time of occurrence of the abnormality and the type of the abnormality. Log storage unit: used to store the log information collected by the log collection unit in a predetermined format; the predetermined format includes timestamp, module identifier, operation type, operation result, exception type and description field.