Distributed access control method, system and equipment based on multi-factor authentication
By responding to access requests in a distributed system, determining the first-time and historical records of the access user, combining the decentralized identity system and the access log database for trust risk assessment, and generating a target authentication solution, the problem of insufficient security in the multi-factor authentication method is solved and more efficient access control is achieved.
Patent Information
- Application Number
- CN202510337292.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-04
AI Technical Summary
The existing multi-factor authentication method ignores the context information of access requests in distributed systems, resulting in insufficient security and difficult to effectively prevent unauthorized access.
By responding to access requests, determine whether the access user is the first access, connect to the decentralized identity system and the access log database, conduct trust risk assessment, generate trust risk indicators, and perform minimum permission principle and multi-factor authentication filtering based on the zero-trust architecture to generate a target authentication solution.
Improve the security of access control, effectively prevent unauthorized access, and improve the security protection capabilities of the system.
Smart Images

Figure CN120257250A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to data access control related fields, and in particular to a distributed access control method, system and device based on multi-factor authentication. Background Art
[0002] In distributed systems, ensuring the security of access control is crucial, as it is directly related to the security protection of system data and resources. At present, the main method to solve the security of distributed access control is to adopt multi-factor authentication. Multi-factor authentication improves the security of access control by combining two or more different authentication factors. However, existing multi-factor authentication methods ignore the contextual information of access requests, such as access devices, locations, time, etc., and are based on the principle of "trust but verify", that is, after the user passes the authentication for the first time, it is assumed that his subsequent access requests are credible, which increases potential security risks.
[0003] Among the current related technologies, distributed access control based on multi-factor authentication has technical problems such as insufficient security due to the lack of comprehensive consideration of contextual information and overly loose trust policies, making it difficult to effectively prevent unauthorized access and insufficient system security protection capabilities. Summary of the invention
[0004] The present application provides a distributed access control method, system and device based on multi-factor authentication, which responds to the real-time access request of the access target, determines the first access user who initiates the request, and checks whether it is the first access. For users who are not visiting for the first time, connects to their decentralized identity system, determines the bound multi-factor authentication method, and follows the principle of least privilege under the zero trust architecture. It connects to the access log database of the access target, collects the historical access records of the user, performs trust risk assessment on the real-time access request, generates a trust risk indicator, compares the trust risk indicator with the trust requirements of the zero trust architecture, implements the principle of least privilege and screening of multi-factor authentication methods, generates a suitable target authentication scheme, applies the generated target authentication scheme, authenticates the access rights of the first access user, and other technical means, thereby achieving the technical effect of improving the security of access control, effectively preventing unauthorized access, and enhancing the security protection capability of the system.
[0005] This application provides a distributed access control method based on multi-factor authentication, including: in response to a real-time access request of an access target, determining a first access user and judging whether the first access user is accessing for the first time; if not, connecting to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of minimum privilege under the zero-trust architecture; connecting to the access log database of the access target to collect the historical access records of the first access user, conducting a trust risk assessment on the real-time access request, and generating a trust risk indicator; judging whether the trust risk indicator meets the trust requirements under the zero-trust architecture, performing the screening of the principle of minimum privilege and the multi-factor authentication method, and generating a target authentication scheme; and performing access permission authentication on the first access user with the target authentication scheme.
[0006] In a possible implementation, when judging whether the first access user is accessing for the first time, the following processing is also performed: if the first access user is accessing for the first time, perform identity registration in the first decentralized identity system, generate a unique DID, construct a multi-factor authentication method, execute the highest-level authentication method combination, and generate the highest-level authentication scheme; and perform access permission authentication on the first access user with the highest-level authentication scheme.
[0007] In a possible implementation, when connecting to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of minimum privilege under the zero-trust architecture, the following processing is performed: comprehensively evaluate the security and convenience when each authentication method in the multi-factor authentication method is used alone, and determine the authentication methods with an evaluation value greater than a preset evaluation value; based on the zero-trust architecture, construct the principle of minimum privilege with the authentication methods with an evaluation value greater than the preset evaluation value.
[0008] In a possible implementation, the following processing is performed: the multi-factor authentication method includes an authentication method corresponding to the knowledge factor, an authentication method corresponding to the possession factor, and an authentication method corresponding to the biometric factor.
[0009] In a possible implementation, the access log database of the access target is connected to collect the historical access records of the first access user, and the real-time access request is subjected to a trust risk assessment to generate a trust risk indicator, and the following processing is performed: Extract multiple historical access records of the first access user from the access log database, and the multiple historical access records have a chronological order; Analyze the access device, access location, access time period, and access resource in the multiple historical access records to determine the historical device distribution feature, historical location distribution feature, historical time distribution feature, and historical resource distribution feature; Based on the historical device distribution feature, the historical location distribution feature, the historical time distribution feature, and the historical resource distribution feature, perform risk analysis on the access device, access location, access time, and access resource, and establish a multi-level risk feature set; Determine the real-time access device, real-time access address, real-time access time, and real-time access resource corresponding to the real-time access request, compare them in the multi-level risk feature set, and perform weighted fusion of the risk levels of multiple features to generate the trust risk indicator.
[0010] In a possible implementation, when comparing in the multi-level risk feature set, the following processing is also performed: Compare the real-time access device, real-time access address, real-time access time, and real-time access resource in the multi-level risk feature set. If the comparison result of any real-time access feature in the multi-level risk feature set is empty, assign the trust risk indicator to a preset maximum risk value.
[0011] In a possible implementation, determine whether the trust risk indicator meets the trust requirements under the zero trust architecture, perform screening of the least privilege principle and the multi-factor authentication method to generate a target authentication scheme, and perform the following processing: Based on the historical access records, determine a risk feature set in which the historical access feature frequency is greater than a preset threshold and no access security event has occurred, and establish the trust requirements; Determine whether the trust risk indicator meets the trust requirements; If so, generate the target authentication scheme according to the least privilege principle; If not, use the multi-factor authentication method as the configuration space, and perform combined configuration of the multi-factor authentication method based on the trust risk indicator to generate the target authentication scheme.
[0012] In a possible implementation manner, taking the multi-factor authentication method as the configuration space, based on the trust risk indicator, perform combined configuration of the multi-factor authentication method to generate the target authentication scheme, and perform the following processing: Based on the historical access records, combine each method in the multi-factor authentication method and then perform effectiveness analysis in the abnormal access state, construct a trust risk indicator sample and a corresponding authentication method combination sample for effective risk authentication, and construct a risk-effectiveness authentication mapping; Based on the risk-effectiveness authentication mapping, perform authentication method matching on the trust risk indicator to generate the target authentication scheme.
[0013] The present application also provides a distributed access control system based on multi-factor authentication, including: a first access user determination module, configured to determine a first access user in response to a real-time access request of an access target, and determine whether the first access user is accessing for the first time; a multi-factor authentication method determination module, configured to, if not, connect to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of the lowest privilege under the zero-trust architecture; a trust risk assessment module, configured to connect to the access log database of the access target to collect the historical access records of the first access user, perform trust risk assessment on the real-time access request, and generate a trust risk indicator; a target authentication scheme generation module, configured to determine whether the trust risk indicator meets the trust requirements under the zero-trust architecture, perform screening of the principle of the lowest privilege and the multi-factor authentication method, and generate a target authentication scheme; an access permission authentication module, configured to perform access permission authentication on the first access user with the target authentication scheme.
[0014] The present application also provides an electronic device, including: a memory, configured to store executable instructions; a processor, configured to, when executing the executable instructions stored in the memory, implement the distributed access control method based on multi-factor authentication.
[0015] The distributed access control method, system and device based on multi-factor authentication proposed in this application first responds to the real-time access request of the access target, determines the first access user, and judges whether the first access user is accessing for the first time. If not, it connects to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of minimum privilege under the zero-trust architecture. Then it connects to the access log database of the access target to collect the historical access records of the first access user, conducts a trust risk assessment on the real-time access request, generates a trust risk indicator, and then judges whether the trust risk indicator meets the trust requirements under the zero-trust architecture, executes the screening of the minimum privilege principle and the multi-factor authentication method, generates a target authentication scheme, and finally authenticates the access privilege of the first access user with the target authentication scheme. It achieves the technical effects of improving the security of access control, effectively preventing unauthorized access, and enhancing the system security protection ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings of the embodiments of the present invention will be briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the operations in the front or below do not necessarily need to be executed precisely in sequence. On the contrary, according to the need, they can be executed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several operations can be removed from these processes.
[0017] Figure 1 It is a schematic flowchart of the distributed access control method based on multi-factor authentication provided by the embodiment of the present application.
[0018] Figure 2 It is a schematic structural diagram of the distributed access control system based on multi-factor authentication provided by the embodiment of the present application.
[0019] Figure 3 It is a schematic structural diagram of an electronic device provided by the embodiment of the present application.
[0020] Description of the reference numerals: The first access user determination module 10, the multi-factor authentication method determination module 20, the trust risk assessment module 30, the target authentication scheme generation module 40, the access privilege authentication module 50, the input device 301, the processor 302, the memory 303, the output device 304. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0022] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of this application.
[0023] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments, but it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments, and may be combined with each other without conflict, and the terms "first\second" involved are merely to distinguish similar objects and do not represent a specific ordering of objects. The terms "including" and "having" and any variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those generally understood by technicians in the technical field of this application. The terms used herein are for the purpose of describing the embodiments of the present application only.
[0024] The present application embodiment provides a distributed access control method based on multi-factor authentication, such as Figure 1 As shown, the method includes:
[0025] Step S100: In response to a real-time access request of an access target, a first access user is determined, and it is determined whether the first access user is accessing for the first time.
[0026] Specifically, the real-time access request refers to a request issued when a user attempts to access a platform, system or resource, which includes user identity information and resource information requested for access. The system identifies and determines the first access user who initiated the access request, that is, the user entity in this access request, by parsing the identity information (such as user name, IP address, device identification, etc.) in the real-time access request. The system queries the user access record database stored locally or in a distributed manner to check the historical access records of the first access user. If there is no record of this user in the database, it is determined to be the first access; if there is a record, it is determined to be not the first access, and the process goes to step S200.
[0027] In a possible implementation, it is determined whether the first accessing user is accessing for the first time. The method further includes step S600. If the first accessing user is accessing for the first time, identity registration is performed in the first decentralized identity system to generate a unique DID, and a multi-factor authentication method is constructed. The highest-level authentication method combination is executed to generate the highest-level authentication scheme, and the first accessing user is authenticated for access rights with the highest-level authentication scheme.
[0028] Specifically, when the first accessing user is accessing for the first time, the system first presents a registration interface to the first accessing user, asking the user to input basic information (such as username, email, mobile phone number, etc.) and preliminary information for subsequent identity verification (such as password). The system verifies the input preliminary information to ensure the validity and uniqueness of the information (such as checking whether the email has been registered and whether the mobile phone number format is correct, etc.). After the verification passes, the system uses decentralized identity (DID) technology to generate a globally unique and immutable identifier (DID) for the user. This DID is the unique identity identifier of the user in the distributed system. The system saves the generated DID and its associated user information (encrypted storage) in the decentralized identity system to ensure the security and privacy of the user information. Among them, the decentralized identity system means that the user identity information does not rely on a single server for storage but is distributed for storage. Decentralized identity is an identity identification method based on blockchain or other distributed technologies, allowing users to own their identity data and control the way it is used.
[0029] The system presents multiple optional multi-factor authentication methods to the user (an identity verification method that improves security by combining multiple authentication factors, such as knowledge factors: password, PIN code; possession factors: smart card, OTP; biometric factors: fingerprint, face, iris, etc.), and asks the user to select at least one as the authentication means for subsequent access. According to the user's selection, the system guides the user to input or configure the corresponding authentication information (such as setting a PIN code, binding a smart card, entering biometric data, etc.). The system verifies the authentication information input by the user to ensure the accuracy and validity of the information, and associates the verified authentication information (encrypted storage) with the user's DID and saves it in the decentralized identity system.
[0030] For first-time visiting users, the system by default adopts the highest-level combination of authentication methods to ensure the security of the system, including combinations of multiple authentication factors, such as password + OTP + biometric authentication, etc. The system automatically generates a highest-level authentication scheme that includes all selected authentication factors based on the multi-factor authentication methods configured by the user. After receiving the real-time access request from the first-time visiting user, the system displays the corresponding authentication interface or prompt to the user according to the generated highest-level authentication scheme (such as requesting password input, scanning the OTP QR code, verifying biometrics, etc.). The system receives the authentication information input by the user and verifies the information one by one according to the requirements of the highest-level authentication scheme. If all authentication factors pass the verification, the system considers the user's identity legal and grants them the permission to access the target resources; otherwise, it rejects the access request and displays an error prompt message to the user. For first-time visiting users, since the system has not yet established their trust records and behavior patterns, a more stringent identity verification process is required to ensure the legality and authenticity of their identities. The highest-level combination of authentication methods can ensure that even if some authentication information is leaked, attackers cannot easily obtain access rights. At the same time, the strict identity verification during the first visit provides a reliable trust basis for subsequent access control. The system can dynamically adjust the authentication method according to the user's trust records and behavior patterns to achieve more intelligent access control.
[0031] Step S200, if not, connect to the first decentralized identity system of the first visiting user to determine the bound multi-factor authentication method and the lowest privilege principle under the zero-trust architecture.
[0032] Specifically, if the first visiting user is not a first-time visitor, the system uses distributed identity management technology to access the user identity information stored on the local device through the client application or browser extension on the user device. Read the multi-factor authentication method configuration pre-bound by the user from the user's decentralized identity system, such as password, OTP, fingerprint, etc., and a simple and effective authentication method suitable for application in the current security scenario (such as password only or password + fingerprint). Among them, the zero-trust architecture is a security framework that assumes that all users and devices in the network are potential threat sources and conducts strict identity verification and authorization checks on each access request, that is, identity verification is required for each access, and no user or device is trusted by default.
[0033] In a possible implementation, the first decentralized identity system connecting the first accessing user determines the bound multi-factor authentication method and the principle of least privilege under the zero-trust architecture. Step S200 further includes step S210, which comprehensively evaluates the security and convenience when each authentication method in the multi-factor authentication method is used alone, and determines the authentication methods whose evaluation values are greater than the preset evaluation value. Specifically, evaluate the ability of each authentication method to prevent unauthorized access, including the strength of its resistance to attacks (such as man-in-the-middle attacks, etc.) and the accuracy of user authentication. Evaluate the impact of each authentication method on the user-friendliness, including ease of use (such as whether additional devices are required, operation complexity, etc.) and user experience (such as the fluency of the authentication process, waiting time, etc.). Collect historical data on the security and convenience of each authentication method from existing system logs, user feedback, and third-party security reports. Collect real-time data on the security and convenience of each authentication method in the actual environment through means such as simulated attacks and user tests. Assign different weights to the security and convenience criteria according to the organization's security policies and user requirements. Based on the collected data and the assigned weights, calculate the comprehensive evaluation value of the security and convenience of each authentication method. Compare the evaluation value of each authentication method with the preset evaluation value threshold (used to determine whether the evaluation value of a certain authentication method is high enough to meet the organization's security requirements) to determine which authentication methods have evaluation values greater than the preset evaluation value.
[0034] Step S220, based on the zero-trust architecture, constructs the principle of least privilege with the authentication methods whose evaluation values are greater than the preset evaluation value. Specifically, the principle of least privilege is to clarify that each access requires authentication, but one of the authentication methods whose evaluation values are greater than the preset evaluation value can be selected for verification. Set the principle of least privilege in the system configuration to ensure that each access follows this principle for authentication. During the authentication process, display a list of authentication methods whose evaluation values are greater than the preset evaluation value to the user, and allow the user to select one authentication method for verification according to their own needs and preferences. According to the authentication method selected by the user, execute the corresponding authentication process and verify the user's identity. If the authentication is successful, grant the user the corresponding access rights according to the user's permissions and the security policy of the access target. This implementation method enhances the security of the system by selecting authentication methods with high evaluation values and reduces the risk of unauthorized access. At the same time, allowing the user to select the most suitable authentication method among the authentication methods whose evaluation values are greater than the preset evaluation value improves the convenience of authentication and the user experience.
[0035] In a possible implementation, step S210 further includes step S211. The multi-factor authentication method includes the authentication method corresponding to the knowledge factor, the authentication method corresponding to the possession factor, and the authentication method corresponding to the biometric factor. Specifically, the knowledge factor refers to information known to the user, such as passwords, PINs, security secret questions, etc. The possession factor refers to items owned by the user, such as mobile phones (for receiving SMS verification codes), hardware tokens, IC cards, etc. The biometric factor refers to factors related to the user's physical characteristics, such as fingerprints, faces, irises, etc. The system identifies and configures the authentication method based on the knowledge factor, such as setting parameters and rules of the authentication method, identifies and configures the authentication method based on the possession factor, such as the sending rules of SMS verification codes, the identification rules of hardware tokens, etc., and identifies and configures the authentication method based on the biometric factor, such as the sensitivity of fingerprint recognition, the algorithm of face recognition, etc. In this implementation, by subdividing the multi-factor authentication method, the system can comprehensively cover multiple dimensions of user identity verification, thereby improving the security of access control. The complementarity between different authentication methods makes it difficult for attackers to crack other methods simultaneously even if they crack one method, thus reducing the risk of unauthorized access.
[0036] Step S300: Connect to the access log database of the access target to collect the historical access records of the first access user, and conduct a trust risk assessment on the real-time access request to generate a trust risk indicator.
[0037] Specifically, extract the historical access data of the first access user from the access log database of the access target, including access time, access frequency, access success / failure records, etc. Apply machine learning algorithms or rule engines to analyze the historical access data and generate a trust risk indicator representing the user's trust level. The evaluation factors may include the consistency of the user's behavior pattern, the frequency of abnormal access attempts, etc. Among them, the access log database is a system component that stores user access records. Trust risk assessment is a process of evaluating the potential threat level of a user to the system based on the user's historical behavior.
[0038] In a possible implementation, when connecting to the access log database of the access target to collect the historical access records of the first access user and conduct a trust risk assessment on the real-time access request to generate a trust risk indicator, step S300 further includes step S310: Extract multiple historical access records of the first access user from the access log database, and the multiple historical access records have a chronological order. Specifically, the system retrieves all historical access records related to the first access user from the access log database through SQL queries or NoSQL query statements. According to the timestamp field, filter out the historical access records arranged in chronological order to ensure the chronological nature of the data.
[0039] Step S320: Analyze the access devices, access locations, access time periods, and access resources in the multiple historical access records to determine the historical device distribution characteristics, historical location distribution characteristics, historical time distribution characteristics, and historical resource distribution characteristics. Specifically, parse each historical access record to extract key information such as the access device, access location, access time period, and access resource. Among them, the access device refers to the type of device used by the user for access, such as a mobile phone, computer, etc. The access location refers to the geographical location information when the user accesses. The access time period refers to the time range or period when the user accesses. The access resource refers to the specific content or target accessed by the user, such as a web page, file, database, etc. Use statistical analysis or data mining techniques to extract the device distribution characteristics, location distribution characteristics, time distribution characteristics, and resource distribution characteristics from the historical access records.
[0040] Step S330: Based on the historical device distribution characteristics, historical location distribution characteristics, historical time distribution characteristics, and historical resource distribution characteristics, conduct risk analysis of the access device, access location, access time, and access resource, and establish a multi-level risk feature set. Specifically, use machine learning algorithms or statistical models to perform risk scoring on each key piece of information (device, location, time, resource). According to the risk scores, divide the key information into different risk levels to construct a multi-level risk feature set for evaluating the user's access risk.
[0041] Step S340: Determine the real-time access device, real-time access address, real-time access time, and real-time access resource corresponding to the real-time access request, compare them in the multi-level risk feature set, and perform weighted fusion of the risk levels of multiple features to generate the trust risk indicator. Specifically, compare the real-time access device, real-time access address, real-time access time, and real-time access resource in the real-time access request with the information in the risk feature set. According to the risk level of each feature, assign different weights to it, perform weighted summation, and generate the final trust risk indicator. This implementation method deeply analyzes the historical access records of the first access user, extracts key information, establishes a risk feature set, and finally generates a trust risk indicator. The system can identify the user's access behavior pattern, discover potential abnormal access behaviors, and thus provide a strong basis for the authentication of the user's access rights.
[0042] The following is a specific example: Historical access records arranged in chronological order as shown in Table 1 are extracted from the access log database.
[0043] Table 1: Historical Access Records
[0044]
[0045]
[0046] Extract features from historical access records as follows: Historical device distribution features: mobile phone (3 times), computer (2 times); Historical location distribution features: City A (4 times), City B (1 time); Historical time distribution features: 08:00 - 09:00 (2 times), 14:00 - 15:00 (2 times), 20:00 - 21:00 (1 time); Historical resource distribution features: File A (2 times), File B (2 times), File C (1 time).
[0047] Based on the above features, use statistical methods to perform risk scoring for each feature. The scoring rules are as follows: For device risk scoring, evaluate according to the commonness of device types. Mobile phones and computers have lower risks (2 points), and tablets (less frequently used) have higher risks (6 points); For location risk scoring, evaluate according to the commonness of geographical locations. City A (2 points), City B (4 points), and other unknown or uncommon locations (8 points); For time period risk scoring, evaluate according to the commonness of time periods. Working hours (08:00 - 17:00) have low risks (2 points), and nighttime (22:00 - 06:00) has high risks (6 points); For resource risk scoring, evaluate according to the sensitivity of resources. File A and File B have low risks (2 points), File C has medium risks (4 points), and unknown resources have high risks (8 points). The established risk feature set is shown in Table 2.
[0048] Table 2: Risk Feature Set
[0049]
[0050]
[0051] The features of the currently received real-time access request are as follows: Real-time access device: tablet; Real-time access location: City A; Real-time access time period: 22:00 - 23:00; Real-time access resource: File A. Compare these real-time features with the risk feature set, and the results are shown in Table 3.
[0052] Table 3: Comparison Results
[0053] Feature type Real-time feature value Matching result in the risk feature set Risk score Weight Weighted score Device Tablet Tablet (medium risk) 6 0.3 1.8 Location City A City A (low risk) 2 0.3 0.6 Time period 22:00-23:00 22:00 - 23:00 (high risk) 6 0.2 1.2 Resource File A File A (low risk) 2 0.2 0.4
[0054] Among them, the weights are set according to the organization's security policy. The device type has a greater impact on risk, and the device weight is set to 0.3. The geographical location has a greater impact on risk, and the location weight is set to 0.3. The access time period has a certain impact on risk, and the time period weight is set to 0.2. The sensitivity of access resources has a certain impact on risk, and the resource weight is set to 0.2. According to the above weighted scores, calculate the trust risk indicator: Trust risk indicator = 1.8 (device) + 0.6 (location) + 1.2 (time period) + 0.4 (resource) = 4.0.
[0055] In a possible implementation, comparison is performed in the multi-level risk feature set. Step S300 further includes step S350 of comparing the real-time access device, real-time access address, real-time access time, and real-time access resource in the multi-level risk feature set. If the comparison result of any real-time access feature in the multi-level risk feature set is empty, the trust risk indicator is assigned a preset maximum risk value.
[0056] Specifically, database queries or in-memory data structures (such as hash tables, red-black trees, etc.) are used to quickly retrieve records in the multi-level risk feature set. For each feature (device, address, time, resource) in the real-time access request, the system uses algorithms such as string matching, geographical location matching, time range matching, and resource identifier matching to find whether there are similar or matching records in the risk feature set. The system checks the comparison results of each real-time access feature. If any feature does not find a matching item in the risk feature set (i.e., the comparison result is empty), the system assigns the trust risk indicator variable a preset maximum risk value. The preset maximum risk value is a constant representing an extremely high security risk level, used to indicate abnormal situations in trust risk assessment. If any real-time access feature has no matching item in the risk feature set, it means that the user's access behavior does not conform to the historical behavior pattern and there is a security risk. At this time, assigning the trust risk indicator a maximum risk value can trigger a more rigorous authentication process or security review, thereby enhancing the security of the system.
[0057] Step S400: Determine whether the trust risk indicator meets the trust requirements under the zero-trust architecture, perform screening of the least privilege principle and the multi-factor authentication method, and generate a target authentication scheme.
[0058] Specifically, the generated trust risk indicator is compared with a preset trust threshold to determine whether the user meets the trust requirements under the zero-trust architecture. According to the trust risk assessment result, determine whether to execute the least privilege principle or a combination of multi-factor authentication methods that can effectively cope with the current trust risk level, determine the authentication method finally applied to this access request, and form a target authentication scheme.
[0059] In a possible implementation, it is determined whether the trust risk indicator meets the trust requirements under the zero-trust architecture, and the screening of the least privilege principle and the multi-factor authentication method is performed to generate a target authentication scheme. Step S400 further includes step S410 of determining a set of risk characteristics with a historical access feature frequency greater than a preset threshold and without access security incidents based on historical access records, and establishing the trust requirements. Specifically, key access features in the historical access records are extracted, including the access device, access location, access time period, and access resources, etc. The occurrence frequency of each access feature is statistically calculated (the ratio of the number of times a certain access feature appears in the historical access records to the total number of accesses), and a preset threshold is set (this threshold is obtained based on system security requirements and historical data analysis and is used to determine whether the access feature is common and secure enough). The access features with a frequency greater than the preset threshold and not associated with any known security incidents are screened out to form a set of risk characteristics, that is, a set composed of a series of access features considered to be secure and common. Based on this set of risk characteristics, the trust requirements of the system are established, that is, the system considers these characteristics to represent secure access behaviors.
[0060] Step S420 of determining whether the trust risk indicator meets the trust requirements. Specifically, each feature in the set of risk characteristics without access security incidents is quantized into a quantization standard that can be compared with the trust risk indicator. The scores of the trust risk indicator in each feature dimension are compared with the corresponding quantization standards in the set of risk characteristics. If the scores of the trust risk indicator in each comparison dimension are lower than the corresponding quantization standards in the set of risk characteristics, it is considered that the trust risk indicator meets the trust requirements.
[0061] Step S430, if so, generating the target authentication scheme according to the least privilege principle. Specifically, if the trust risk indicator meets the trust requirements, an appropriate authentication method is selected according to the least privilege principle. According to this principle, the authentication method combinations that meet the requirements are screened out from the multi-factor authentication methods to form a target authentication scheme.
[0062] Step S440, if not, using the multi-factor authentication method as the configuration space, performing the combined configuration of the multi-factor authentication method based on the trust risk indicator, and generating the target authentication scheme. Specifically, if the trust risk indicator does not meet the trust requirements, according to the specific value of the trust risk indicator, the authentication method combination that can provide a higher level of security is selected. This implementation method can effectively reduce the security risks caused by password leakage or cracking through the combined use of multi-factor authentication and the least privilege principle. At the same time, the authentication method is dynamically adjusted according to the trust risk indicator of the real-time access request, further improving the security of the system.
[0063] In a possible implementation, taking the multi-factor authentication method as the configuration space, based on the trust risk indicator, perform combined configuration of the multi-factor authentication method to generate the target authentication scheme. Step S440 further includes step S441, which is to perform combination of each method in the multi-factor authentication method based on the historical access record and then perform effectiveness analysis under the abnormal access state, construct a trust risk indicator sample and a corresponding authentication method combination sample for effective risk authentication, and construct a risk-effectiveness authentication mapping. Specifically, extract the historical access record of the first access user from the access log database, including successful and failed access attempts. Extract key features from the historical access record, such as access time, access device, access location, access resource, and the authentication method used, etc. According to the extracted features, combine each method in the multi-factor authentication method to form different authentication schemes. Simulate abnormal access states, such as device abnormality, location abnormality, time abnormality, etc. Perform effectiveness testing on each authentication scheme under the simulated abnormal state, and record whether it can successfully identify abnormal access and prevent unsafe behaviors. According to the test results, construct the mapping relationship between the risk indicator and the effective authentication method combination.
[0064] Step S442, based on the risk-effectiveness authentication mapping, perform authentication method matching on the trust risk indicator to generate the target authentication scheme. Specifically, search for the authentication method combination that matches the current trust risk indicator in the risk-effectiveness authentication mapping. According to the matching result, determine the target authentication scheme. This implementation method can identify which authentication method combinations are the most effective in abnormal situations by simulating abnormal states and performing effectiveness analysis. Select the most suitable authentication method combination according to the risk indicator of the real-time access request, thereby improving the security and accuracy of access control.
[0065] Step S500, perform access permission authentication on the first access user with the target authentication scheme.
[0066] Specifically, according to the target authentication scheme, the corresponding authentication interface or prompt (such as entering a password, scanning a QR code, verifying a fingerprint, etc.) is displayed to the first access user, and the user is required to complete the authentication operation. The system receives and verifies the user's authentication response. If all authentication factors are verified, the user is granted access rights; otherwise, access is denied and additional security response measures are triggered. The embodiment of the present application adopts a real-time access request that responds to the access target, determines the first access user who initiates the request, and checks whether it is the first access. For users who are not visiting for the first time, connects to its decentralized identity system, determines the bound multi-factor authentication method, and follows the principle of minimum authority under the zero-trust architecture, connects to the access log database of the access target, collects the user's historical access records, and conducts trust risk assessment on the real-time access request, generates a trust risk indicator, compares the trust risk indicator with the trust requirements of the zero-trust architecture, performs the screening of the minimum authority principle and the multi-factor authentication method, generates a suitable target authentication scheme, applies the generated target authentication scheme, and authenticates the access rights of the first access user. Technical means such as the technical effect of improving the security of access control, effectively preventing unauthorized access, and enhancing the security protection capability of the system.
[0067] In the above, refer to Figure 1 The distributed access control method based on multi-factor authentication according to an embodiment of the present invention is described in detail. Figure 2 A distributed access control system based on multi-factor authentication according to an embodiment of the present invention is described.
[0068] The distributed access control system based on multi-factor authentication according to the embodiment of the present invention is used to solve the technical problems of insufficient security, difficulty in effectively preventing unauthorized access, and insufficient system security protection capabilities due to the lack of comprehensive consideration of context information and overly loose trust policies in the prior art, so as to achieve the technical effect of improving the security of access control, effectively preventing unauthorized access, and improving the system security protection capabilities. The distributed access control system based on multi-factor authentication includes: a first access user determination module 10, a multi-factor authentication method determination module 20, a trust risk assessment module 30, a target authentication scheme generation module 40, and an access rights authentication module 50.
[0069] The first access user determination module 10 is configured to determine the first access user in response to a real-time access request for an access target, and determine whether the first access user is accessing for the first time; the multi-factor authentication method determination module 20 is configured to, if the first access user is not accessing for the first time, connect to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method, and the principle of minimum privilege under the zero-trust architecture; the trust risk assessment module 30 is configured to connect to the access log database of the access target to collect the historical access records of the first access user, perform a trust risk assessment on the real-time access request, and generate a trust risk indicator; the target authentication scheme generation module 40 is configured to determine whether the trust risk indicator meets the trust requirements under the zero-trust architecture, perform screening of the principle of minimum privilege and the multi-factor authentication method, and generate a target authentication scheme; the access permission authentication module 50 is configured to perform an access permission authentication on the first access user with the target authentication scheme.
[0070] Among them, to determine whether the first access user is accessing for the first time, the system may further include: a highest-level authentication scheme generation module configured to, if the first access user is accessing for the first time, perform identity registration in the first decentralized identity system, generate a unique DID, construct a multi-factor authentication method, execute the highest-level authentication method combination, generate a highest-level authentication scheme, and perform an access permission authentication on the first access user with the highest-level authentication scheme.
[0071] Next, the specific configuration of the multi-factor authentication method determination module 20 will be described in detail. As described above, connect to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method, and the principle of minimum privilege under the zero-trust architecture. The multi-factor authentication method determination module 20 may further include: a comprehensive evaluation unit configured to comprehensively evaluate the security and convenience when each authentication method in the multi-factor authentication method is used alone, and determine the authentication methods with an evaluation value greater than a preset evaluation value; a minimum privilege principle construction unit configured to construct the principle of minimum privilege based on the zero-trust architecture with the authentication methods having an evaluation value greater than the preset evaluation value.
[0072] Among them, the comprehensive evaluation unit may further include: a multi-factor authentication method construction subunit configured to construct a multi-factor authentication method, where the multi-factor authentication method includes an authentication method corresponding to a knowledge factor, an authentication method corresponding to an ownership factor, and an authentication method corresponding to a biometric factor.
[0073] Next, the specific configuration of the trust risk assessment module 30 will be described in detail. As described above, the access log database connecting the access target collects the historical access records of the first access user, performs a trust risk assessment on the real-time access request, and generates a trust risk indicator. The trust risk assessment module 30 may further include: a historical access record extraction unit for extracting multiple historical access records of the first access user from the access log database, and the multiple historical access records have a chronological order; a feature determination unit for analyzing the access device, access location, access time period, and access resource in the multiple historical access records to determine the historical device distribution feature, historical location distribution feature, historical time distribution feature, and historical resource distribution feature; a risk analysis unit for performing risk analysis on the access device, access location, access time, and access resource based on the historical device distribution feature, historical location distribution feature, historical time distribution feature, and historical resource distribution feature, and establishing a multi-level risk feature set; a trust risk indicator generation unit for determining the real-time access device, real-time access address, real-time access time, and real-time access resource corresponding to the real-time access request, comparing them in the multi-level risk feature set, and performing weighted fusion of the risk levels of multiple features to generate the trust risk indicator.
[0074] Among them, when comparing in the multi-level risk feature set, the trust risk assessment module 30 may further include: a preset maximum risk assignment unit for comparing the real-time access device, real-time access address, real-time access time, and real-time access resource in the multi-level risk feature set. If the comparison result of any real-time access feature in the multi-level risk feature set is empty, the trust risk indicator is assigned a preset maximum risk value.
[0075] Next, the specific configuration of the target authentication scheme generation module 40 will be described in detail. As described above, it is judged whether the trust risk indicator meets the trust requirements under the zero-trust architecture, and the screening of the least privilege principle and the multi-factor authentication method is performed to generate a target authentication scheme. The target authentication scheme generation module 40 may further include: a trust requirement establishment unit for determining a set of risk features with a historical access feature frequency greater than a preset threshold and no access security events based on historical access records, and establishing the trust requirements; a judgment unit for judging whether the trust risk indicator meets the trust requirements; a target authentication scheme generation unit for, if so, generating the target authentication scheme based on the least privilege principle, and if not, taking the multi-factor authentication method as the configuration space and performing a combined configuration of the multi-factor authentication method based on the trust risk indicator to generate the target authentication scheme.
[0076] Among them, taking the multi-factor authentication method as the configuration space, based on the trust risk index, a combined configuration of the multi-factor authentication method is performed to generate the target authentication scheme. The target authentication scheme generation unit may further include: a risk-validity authentication mapping construction subunit for combining each method in the multi-factor authentication method based on historical access records and then performing validity analysis in the case of abnormal access states, constructing a trust risk index sample and a corresponding authentication method combination sample for effective risk authentication, and constructing a risk-validity authentication mapping; an authentication method matching subunit for performing authentication method matching on the trust risk index based on the risk-validity authentication mapping to generate the target authentication scheme.
[0077] The distributed access control system based on multi-factor authentication provided by the embodiments of the present invention can execute the distributed access control method based on multi-factor authentication provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0078] Although this application makes various references to certain modules in the system according to the embodiments of this application, however, any number of different modules can be used and run on the user terminal and / or the server. The included various units and modules are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present invention.
[0079] Based on the foregoing embodiments, an embodiment of this application further provides an electronic device. Figure 3 It is a schematic structural diagram of the electronic device provided by the embodiment of the present invention, showing a block diagram of an exemplary electronic device suitable for implementing the embodiment of the present invention. Figure 3 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present invention. The electronic device is presented in the form of a general computing device, and its components may include, but are not limited to, an input device 301, a processor 302, a memory 303, and an output device 304. Among them, the processor 302 may be one or more; the memory 303 may include a computer-readable medium and at least one program product, and this program product has a set (at least one) of program modules, and these program modules are configured to execute the functions of the embodiments of this application.
[0080] The memory 303 shown in the embodiments of the present invention may adopt any combination of one or more computer-readable media; the computer-readable storage medium may be, but is not limited to, infrared rays, semiconductor systems, devices or components, or any combination of the above, for storing software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the multi-factor authentication-based distributed access control method in the embodiments of the present invention. The processor 302 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 303, that is, implements the above-mentioned multi-factor authentication-based distributed access control method.
[0081] The above specific embodiments do not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application. In some cases, the actions or steps recited in the present application may be executed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A distributed access control method based on multi-factor authentication, characterized in that Including: In response to a real-time access request for a target, determine the first access user and determine whether the first access user is accessing for the first time; If not, connect to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of minimum privilege under the zero-trust architecture; Connect to the access log database of the access target to collect the historical access records of the first access user, perform a trust risk assessment on the real-time access request, and generate a trust risk indicator; Determine whether the trust risk indicator meets the trust requirements under the zero-trust architecture, perform screening of the minimum privilege principle and the multi-factor authentication method, and generate a target authentication scheme; Authenticate the access privilege of the first access user with the target authentication scheme.
2. The distributed access control method based on multi-factor authentication according to claim 1, wherein Determining whether the first access user is accessing for the first time further includes: If the first access user is accessing for the first time, perform identity registration in the first decentralized identity system to generate a unique DID, construct a multi-factor authentication method, execute the highest-level authentication method combination, and generate a highest-level authentication scheme; Authenticate the access privilege of the first access user with the highest-level authentication scheme.
3. The distributed access control method based on multi-factor authentication according to claim 1, wherein Connecting to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the principle of minimum privilege under the zero-trust architecture includes: Comprehensively evaluate the security and convenience when each authentication method in the multi-factor authentication method is used alone, and determine the authentication methods with an evaluation value greater than a preset evaluation value; Based on the zero-trust architecture, construct the principle of minimum privilege with the authentication methods whose evaluation value is greater than the preset evaluation value.
4. The distributed access control method based on multi-factor authentication according to claim 3, wherein The multi-factor authentication method includes an authentication method corresponding to a knowledge factor, an authentication method corresponding to an ownership factor, and an authentication method corresponding to a biometric factor.
5. The distributed access control method based on multi-factor authentication according to claim 1, characterized in that Connecting to the access log database of the access target to collect the historical access records of the first access user, perform a trust risk assessment on the real-time access request, and generate a trust risk indicator includes: Extract multiple historical access records of the first access user from the access log database, and the multiple historical access records have a chronological order; Analyze the access device, access location, access time period, and access resource in the multiple historical access records to determine the historical device distribution feature, historical location distribution feature, historical time distribution feature, and historical resource distribution feature; Based on the historical device distribution feature, the historical location distribution feature, the historical time distribution feature, and the historical resource distribution feature, perform risk analysis on the access device, access location, access time, and access resource, and establish a multi-level risk feature set; Determine the real-time access device, real-time access address, real-time access time, and real-time access resource corresponding to the real-time access request, perform comparison in the multi-level risk feature set, and perform weighted fusion of risk levels of multiple features to generate the trust risk indicator.
6. The distributed access control method based on multi-factor authentication according to claim 5, wherein Performing comparison in the multi-level risk feature set further includes: Compare the real-time access device, real-time access address, real-time access time, and real-time access resource in the multi-level risk feature set. If the comparison result of any real-time access feature in the multi-level risk feature set is empty, assign the trust risk indicator to a preset maximum risk value.
7. The distributed access control method based on multi-factor authentication according to claim 1, wherein Judge whether the trust risk indicator meets the trust requirements under the zero-trust architecture, and perform the screening of the least privilege principle and the multi-factor authentication method to generate a target authentication scheme, including: Based on the historical access records, determine the risk feature set where the historical access feature frequency is greater than the preset threshold and no access security event has occurred, and establish the trust requirements. Judge whether the trust risk indicator meets the trust requirements. If so, generate the target authentication scheme according to the least privilege principle. If not, take the multi-factor authentication method as the configuration space, and perform the combined configuration of the multi-factor authentication method based on the trust risk indicator to generate the target authentication scheme.
8. The distributed access control method based on multi-factor authentication according to claim 7, characterized in that Take the multi-factor authentication method as the configuration space, and perform the combined configuration of the multi-factor authentication method based on the trust risk indicator to generate the target authentication scheme, including: Based on the historical access records, combine each method in the multi-factor authentication method and then perform the effectiveness analysis under the abnormal access state, construct the trust risk indicator sample and the corresponding authentication method combination sample for effective risk authentication, and construct the risk-effectiveness authentication mapping. Based on the risk-effectiveness authentication mapping, perform the authentication method matching for the trust risk indicator to generate the target authentication scheme.
9. A distributed access control system based on multi-factor authentication, characterized in that, The system is used to implement the distributed access control method based on multi-factor authentication according to any one of claims 1-8. The system includes: The first access user determination module is used to respond to the real-time access request of the access target, determine the first access user, and judge whether the first access user is accessing for the first time. The multi-factor authentication method determination module is used, if not, to connect to the first decentralized identity system of the first access user to determine the bound multi-factor authentication method and the least privilege principle under the zero-trust architecture. The trust risk assessment module is used to connect to the access log database of the access target to collect the historical access records of the first access user, perform a trust risk assessment on the real-time access request, and generate a trust risk indicator. The target authentication scheme generation module is used to judge whether the trust risk indicator meets the trust requirements under the zero-trust architecture, perform the screening of the least privilege principle and the multi-factor authentication method, and generate a target authentication scheme. The access permission authentication module is used to perform access permission authentication on the first access user with the target authentication scheme.
10. An electronic device, characterized in that, The electronic device includes: A memory for storing executable instructions. A processor, when executing the executable instructions stored in the memory, implements the distributed access control method based on multi-factor authentication according to any one of claims 1 to 8.
Citation Information
Cited By
Transaction platform user access method and system based on SSLVPN gateway
CN120450867A
Multi-level dynamic data access control method and device based on credential environment
CN120729631A