Resource security information data processing method and system, terminal and medium

By analyzing tenant identity and operational behavior characteristics, combined with virtualized resource isolation and multi-factor authentication, real-time data encryption and monitoring of interactive behavior are achieved. Delayed and geographical proximity collaborative confirmation is enabled, which solves the problem of insufficient dynamic monitoring of behavior in existing technologies and realizes highly accurate and reliable resource security management.

CN120995438AActive Publication Date: 2025-11-21ZHEJIANG HUAHE WANRUN INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511509236.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-22
Publication Date
2025-11-21
Estimated Expiration
2045-10-22

AI Technical Summary

Technical Problem

In existing technologies, resource security management systems suffer from a lack of dynamic monitoring of behavior, weak ability to identify abnormal operations, and insufficient collaborative verification mechanisms during the granting of permissions and execution of operations. This makes it difficult to prevent risks such as unauthorized access, account misuse, or covert malicious modifications.

Method used

By analyzing tenant identity information and operational behavior characteristics, combined with virtualization resource isolation mechanisms, multi-factor authentication is adopted, data is encrypted in real time and interactive behavior is monitored, delayed confirmation mechanisms and geographical proximity collaborative confirmation are enabled, and comprehensive decision-making is made by combining permission levels and physical location context. File operations are monitored in real time and collaborative voting and anomaly detection are performed.

Benefits of technology

Significantly improves the precision of access control and the accuracy of security interception, effectively prevents account misuse, unauthorized operations and covert malicious modifications, reduces the risk of false blocking and abuse of permissions, improves the scientific nature and reliability of collaborative approval, and reduces false blocking caused by scattered or delayed feedback.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120995438A_ABST
    Figure CN120995438A_ABST
Patent Text Reader

Abstract

The invention relates to a resource security information data processing method and system, a terminal and a medium, and relates to the field of resource security management technology, and the method comprises the steps: receiving a registration request submitted by a tenant terminal; performing first identity verification on the tenant terminal according to the registration request, and generating an access permission; according to the registration request, allocating an exclusive virtualized resource pool for the tenant terminal in a virtualized environment; in response to an access request submitted by a tenant terminal, obtaining an access permission; performing second identity verification on the tenant terminal according to the access permission to obtain an identity verification result; when the identity verification result shows that verification is passed, in response to the file operation instruction, performing encryption processing on the target data to obtain encrypted data; and performing data transmission operation on the encrypted data. The method and the device have the effect of guaranteeing the isolation of resources and the security of data among different tenants.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of resource security management technology, and particularly relates to a resource security information data processing method and system, a terminal and a medium. BACKGROUND

[0002] In the modern enterprise informatization and cloud computing environment, the resource security information data processing technology is the core support for guaranteeing the isolation of resources and the security of data between different tenants.

[0003] In the related art, the resource security management system is usually based on a static identity authentication mechanism. After a user submits an access or file operation request, the corresponding operation permission is granted by verifying the account credential and the permission policy, and the data is transmitted in a basic encrypted manner.

[0004] In the related art, in the process of permission granting and operation execution, there are problems of lack of behavior dynamic monitoring, weak abnormal operation identification capability and insufficient collaborative verification mechanism, which leads to difficulty for the system to effectively prevent risks such as internal unauthorized access, account impersonation or hidden malicious modification. SUMMARY

[0005] In order to guarantee the isolation of resources and the security of data between different tenants, the present application provides a resource security information data processing method, system, terminal and medium.

[0006] In a first aspect, the present application provides a resource security information data processing method, which adopts the following technical solution: A resource security information data processing method, comprising: receiving a registration request submitted by a tenant terminal; performing first identity verification on the tenant terminal according to the registration request, and generating access permission; allocating a dedicated virtualization resource pool for the tenant terminal in a virtualization environment according to the registration request; obtaining the access permission in response to an access request submitted by the tenant terminal; performing second identity verification on the tenant terminal according to the access permission, and obtaining an identity verification result; when the identity verification result indicates that the verification is passed, performing encryption processing on target data in response to a file operation instruction, and obtaining encrypted data; performing a data transmission operation on the encrypted data, the data transmission operation comprising uploading the encrypted data to the dedicated virtualization resource pool and downloading the encrypted data from the dedicated virtualization resource pool to the tenant terminal.

[0007] By adopting the technical scheme, the tenant identity information and operation behavior characteristics are analyzed, a secure environment is constructed in combination with a virtualization resource isolation mechanism, access is ensured to be trusted by using multi-factor authentication, and data is encrypted in real time and interaction behavior is monitored during file operation. The scheme greatly improves the accuracy of permission control, effectively prevents account impersonation, unauthorized operation and hidden malicious modification.

[0008] Optionally, the interaction behavior data is collected in real time, and the interaction behavior data includes mouse movement trajectory characteristics, mouse click frequency and keyboard input delay interval. The interaction behavior data is compared with historical operation behavior to generate a similarity score. Based on the similarity score, it is determined whether the current operation behavior conforms to the tenant terminal operation behavior. If not, the file operation instruction is interrupted, and the execution of the file operation instruction is refused.

[0009] By adopting the technical scheme, the user's mouse movement trajectory, click frequency and keyboard input delay and other interaction behavior data are collected in real time, comparison is made in combination with the model, a behavior similarity score is generated, and the credibility of the operator's identity is determined accordingly. The scheme greatly improves the continuity and accuracy of identity authentication, effectively identifies abnormal behaviors such as account impersonation and non-personal operation, and realizes the interception of high-risk file operations.

[0010] Optionally, a delay mechanism is enabled, and an operation confirmation request message is pushed to a first authorized user terminal with the highest access permission, the operation confirmation request message being used to inquire whether to continue executing the file operation instruction; Within a preset response waiting time, a post-level feedback result of the first authorized user terminal is received; If the received post-level feedback result is ambiguous, the operation confirmation request message is pushed to a second authorized user terminal located within a preset geographical location range of the tenant terminal to obtain a location feedback result; Based on the post-level feedback result and the location feedback result, it is determined whether to allow the file operation instruction to continue to be executed according to a preset rule; If not, the file operation instruction is interrupted.

[0011] By adopting the technical scheme, when an abnormal operation is detected, a delay confirmation mechanism is enabled, the operation intention is inquired from a high-privilege user first, and when there is a difference in feedback, a collaborative confirmation is further initiated to geographically proximate authorized users, and a comprehensive decision is made in combination with the permission level and the physical location context. The scheme greatly improves the accuracy and reasonableness of security interception, effectively identifies real business scenarios such as legal proxy operation and temporary collaboration, and reduces the risk of false blocking and abuse of authority.

[0012] Optionally, a time-based feedback result axis is established, the feedback result axis is divided into a first time threshold interval and a second time threshold interval, the first time threshold interval is earlier than the second time threshold interval; According to the feedback result axis, the position feedback result is divided into a first position feedback result and a second position feedback result, the first position feedback result includes a first approval feedback result and a first denial feedback result, the second position feedback result includes a second approval feedback result and a second denial feedback result, the first position feedback result is received in the first time threshold interval, and the second position feedback result is received in the second time threshold interval; A first total feedback quantity of the first position feedback result is counted; A first sub-feedback quantity of the first approval feedback result is counted; A proportion value is obtained based on the first total feedback quantity and the first sub-feedback quantity; If the proportion value is higher than a consistency threshold value, and a proportion of the first sub-feedback quantity in a preset total feedback quantity exceeds a first quantity threshold value, the first approval feedback result is taken as the preset rule; If the proportion value is lower than the consistency threshold value, a second majority feedback result is determined from the second approval feedback result and the second denial feedback result; In a case where the second majority feedback result is the second approval feedback result, and a proportion of the second approval feedback result in the preset total feedback quantity is not lower than a second quantity threshold value, the second approval feedback result is taken as the preset rule.

[0013] By adopting the above technical solution, a time-based feedback result axis is established, early and subsequent user confirmation feedback is analyzed in stages, and operation intention is judged in combination with feedback consistency proportion and quantity coverage. This solution greatly improves the scientificity and reliability of collaborative approval, and reduces false interception caused by scattered or delayed feedback.

[0014] Optionally, a modification request of a target file submitted by a tenant terminal is received; An access control policy of the target file is obtained, the access control policy includes a plurality of authorized user identifiers associated with the target file; The modification request is pushed to user terminals corresponding to the plurality of authorized user identifiers, and a voting timer is enabled; During timing of the voting timer, voting intentions of the user terminals are received; It is judged whether a quantity of the voting intentions agreeing to modify the target file satisfies a voting threshold value; If yes, a file modification permission is granted to the tenant terminal.

[0015] By adopting the technical scheme, the permission relationship of the target file is acquired, a modification request is pushed to all relevant authorized users, and voting opinions are collected within a limited time, and whether to authorize is determined by comprehensively considering the majority opinions. The scheme greatly improves the transparency and collaboration of file modification approval, effectively avoids risks caused by individual overstepping of authority or misoperation, and reduces security risks caused by power concentration.

[0016] Optionally, the modification of the target file is monitored to obtain modified content data; The content data is analyzed to obtain an analysis result, the analysis result including at least one of whether a sensitive field is modified, whether there is an overstepping of authority or abnormal data change; It is detected whether the user interface operation behavior of the tenant terminal to the target file meets an abnormal operation mode, the abnormal operation mode including a page switching number in a unit time exceeding a first threshold value or a single page dwell time being less than a second threshold value; If yes, a warning signal is generated.

[0017] By adopting the technical scheme, the modification content of the file is monitored in real time, it is identified whether sensitive information is changed or abnormal data change occurs, and whether there is a suspicious operation mode such as frequent page switching or short dwell time is judged by combining the user operation behavior. The scheme greatly improves the identification of malicious modification behavior, effectively distinguishes normal modification from hidden damage, and reduces data risks caused by misoperation or internal attacks.

[0018] Optionally, a switching page is obtained, the switching page including a first switching page and a second switching page; According to the difference existing in the first switching page and the second switching page, a difference result is obtained; Based on the user interface operation behavior and the difference result, an operation sequence of the switching page is generated, the operation sequence containing a plurality of switching page events recorded in time sequence, the switching page event including switching time, switching-in page identifier, switching-out page identifier, and page dwell time; The operation sequence is matched with the abnormal operation mode; If the matching is successful, the step of judging whether there is malicious modification based on the analysis result is executed.

[0019] ​By adopting the technical scheme, the complete process of user page switching is recorded, the time, source, target and stay duration of each switching are extracted, and an ordered operation behavior sequence is generated in combination with the content difference between pages, and then matched with an abnormal mode. The scheme greatly improves the recognition ability of hidden operation behaviors, effectively discovers suspicious actions such as frequent jumps and short stays, and reduces the risk of missing judgment due to fragmented behaviors.

[0020] In a second aspect, the application provides a resource security information data processing system, which adopts the following technical scheme: A resource security information data processing system comprises: An acquisition module is configured to acquire a registration request, an access request and an access permission. A memory is configured to store a program of the resource security information data processing method. A processor, and the program in the memory can be loaded and executed by the processor and implement the resource security information data processing method.

[0021] By adopting the technical scheme, the acquisition module acquires the registration request, the access request and the permission information of the tenant in real time, the processor calls the pre-stored security processing program in the memory, performs security operations such as identity verification, behavior analysis, collaborative decision and encrypted transmission, realizes the whole-process closed-loop management and control from user access to file operation, and provides an efficient and reliable integrated solution for resource security management in a multi-tenant environment while ensuring data security and operation credibility.

[0022] In a third aspect, the application provides an intelligent terminal, which adopts the following technical scheme: An intelligent terminal comprises a memory and a processor, and the memory stores a computer program capable of being loaded and executed by the processor to implement the method according to any one of the above.

[0023] In a fourth aspect, the application provides a computer storage medium capable of storing a corresponding program, which has the characteristics of facilitating the isolation of resources between different tenants and the security of data, and adopts the following technical scheme: A computer readable storage medium stores a computer program capable of being loaded and executed by a processor to implement any one of the above resource security information data processing methods.

[0024] In summary, the application has at least one of the following beneficial technical effects: 1. Analyzing tenant identity information and operation behavior characteristics, combining a virtualized resource isolation mechanism to implement security environment construction, using multi-factor identity verification to ensure access credibility, and encrypting data and monitoring interaction behavior in real time during file operation. The scheme greatly improves the accuracy of permission control, effectively prevents account impersonation, unauthorized operation and hidden malicious modification; 2. Upon detecting abnormal operations, a delayed confirmation mechanism is activated. Priority is given to soliciting the operational intent from high-privilege users, and if discrepancies exist in the feedback, further collaborative confirmation is initiated with geographically proximate authorized users. A comprehensive decision is made based on a combination of permission levels and physical location context. This solution significantly improves the accuracy and rationality of security interception, effectively identifying legitimate proxy operations, temporary collaborations, and other real-world business scenarios, reducing the risk of false blocking and permission abuse. 3. Establish a time-based feedback result axis to conduct phased analysis of early and subsequent user confirmation feedback, and determine operational intent by combining the feedback consistency ratio and quantity coverage. This solution significantly improves the scientific rigor and reliability of collaborative approval, and reduces false interceptions caused by scattered or delayed feedback. Attached Figure Description

[0025] Figure 1 This is a flowchart illustrating a resource security information data processing method provided in an embodiment of this application.

[0026] Figure 2 This is a flowchart illustrating a behavioral feature-based authentication method provided in an embodiment of this application.

[0027] Figure 3 This is a flowchart illustrating a collaborative confirmation method based on permissions and location provided in an embodiment of this application.

[0028] Figure 4 This is a flowchart illustrating a time-segmented feedback decision-making method provided in an embodiment of this application.

[0029] Figure 5 This is a flowchart illustrating a document authorization method based on collaborative voting, as provided in an embodiment of this application.

[0030] Figure 6 This is a flowchart illustrating a content- and behavior-based file modification method provided in an embodiment of this application.

[0031] Figure 7 This is a flowchart illustrating an anomaly detection method based on page switching behavior provided in an embodiment of this application.

[0032] Figure 8 This is a schematic diagram of the structure of a resource security information data processing system provided in an embodiment of this application. Detailed Implementation

[0033] To make the purpose, technical solution, and advantages of this application clearer, the following description is provided in conjunction with the appendix. Figures 1 to 8 The present application will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application.

[0034] The embodiment of the application discloses a resource security information data processing method. Referring to Figure 1 The method comprises the following steps: Step S101: receiving a registration request submitted by a tenant terminal.

[0035] Before receiving the registration request, a virtualization environment is initialized, and basic parameters of the virtualization environment are configured, wherein the virtualization environment comprises at least one of a virtualized server, a storage space and a network configuration.

[0036] The registration request refers to a data packet containing identity information sent by a tenant terminal to a background server when the tenant terminal accesses the system for the first time.

[0037] For example, an employee in company A uses a personal office computer to access the system, fills in basic information such as name, employee number and department, and submits a registration request, and the system background receives the registration request of the employee.

[0038] Step S102: performing first identity verification on the tenant terminal according to the registration request, and generating access authority.

[0039] The first identity verification refers to initial identity verification performed by the user in the registration stage.

[0040] The access authority refers to an operation range granted according to the user identity or post role, including accessible data resources, executable operation types and usable function modules, and the operation types are, for example, viewing, editing and deleting.

[0041] According to the user identity information in the registration request, the corresponding resource access range and operation authority are allocated in combination with the department and post level, and the access authority of the tenant terminal is generated.

[0042] Step S103: allocating a dedicated virtualization resource pool for the tenant terminal in the virtualization environment according to the registration request.

[0043] The virtualization environment refers to a logically isolated running environment constructed by using a virtualization technology.

[0044] The dedicated virtualization resource pool refers to a virtual resource set separately allocated for a specific tenant.

[0045] According to the department and business type of the tenant in the registration request, independent computing, storage and network resources are allocated according to a preset resource configuration, a logically isolated dedicated virtualization resource pool is formed, and the tenant terminal is bound.

[0046] For example, when the tenant registers, the department of the tenant is the finance department, and the information is allocated with independent storage space and network channels, and is configured with 2-core CPU and 4GB memory.

[0047] Step S104: In response to the access request submitted by the tenant terminal, the access permission is obtained.

[0048] The access request refers to the data access or operation request initiated by the tenant to the system after completing the registration and obtaining the permission.

[0049] The access permission refers to the operable resource range pre-allocated according to the tenant identity.

[0050] Step S105: According to the access permission, the second identity verification is performed on the tenant terminal, and the identity verification result is obtained.

[0051] The second identity verification refers to the identity verification performed again when the tenant logs in the system.

[0052] The identity verification result refers to the judgment output of the second identity verification process, including pass and fail states.

[0053] According to the access permission, the verification mode is triggered, the user completes the SMS verification code input or fingerprint recognition, the verification information is compared, and the identity verification pass result is generated after confirming that there is no error.

[0054] Step S106: When the identity verification result indicates that the verification is passed, in response to the file operation instruction, the target data is encrypted to obtain the encrypted data.

[0055] The file operation instruction refers to the specific data processing command initiated by the tenant, including editing, saving, deleting, uploading, downloading, etc.

[0056] The target data refers to the specific data object involved in the current operation of the tenant, such as a certain document, database record, and configuration file, etc.

[0057] The encryption processing refers to the encryption of the target data using encryption algorithm, so that the target data cannot be read in unauthorized circumstances. Here, the AES-256 encryption algorithm is used to block encrypt the target data, and a unique session key is used for encryption transformation to generate unreadable ciphertext data, completing the encryption processing.

[0058] The encrypted data refers to the data after encryption processing, and the original content has been converted into ciphertext, which needs to be restored through the corresponding decryption key.

[0059] Step S107: The encrypted data is subjected to data transmission operation, which includes uploading the encrypted data to the exclusive virtualization resource pool and downloading the encrypted data from the exclusive virtualization resource pool to the tenant terminal.

[0060] Data transmission refers to the transmission process of the encrypted data between the tenant terminal and the exclusive virtualization resource pool.

[0061] The background continuously runs a security check script, periodically checks the system health status and sends a report to the system related personnel; if an anomaly is found, measures are taken to isolate the affected area and notify the tenant related personnel.

[0062] By adopting the technical scheme, the tenant identity information and operation behavior characteristics are analyzed, the security environment construction is realized in combination with the virtualization resource isolation mechanism, the access is ensured to be credible by using the multi-factor identity authentication, and the data is encrypted in real time in the file operation process and the interaction behavior is monitored. The scheme greatly improves the accuracy of permission control, and effectively prevents account impersonation, unauthorized operation and hidden malicious modification.

[0063] The embodiment of the application discloses an identity authentication method based on behavior characteristics. Referring to Figure 2 , the method comprises: Step S201: collecting interaction behavior data in real time, the interaction behavior data comprising mouse movement trajectory characteristics, mouse click frequency and keyboard input delay interval.

[0064] The interaction behavior data refers to the behavior information generated by the user in the operation process on the system interface of the tenant terminal. The interaction behavior data involved in the application is collected after the consent of the tenant, and the collection behavior conforms to the relevant laws and regulations.

[0065] For example, in the process of editing a document, the user's trajectory arc from the title bar to the toolbar, the frequency of clicking the save button, and the interval time of inputting adjacent characters on the keyboard are recorded in real time.

[0066] Step S202: comparing the interaction behavior data with the historical operation behavior to generate a similarity score.

[0067] The historical operation behavior refers to the collection of interaction behavior data accumulated by the same user in the past normal use of the system.

[0068] The similarity score refers to the quantitative value obtained by matching and calculating the interaction behavior data and the historical operation behavior, indicating the consistency degree of the current operator's behavior mode and the current operator's historical behavior.

[0069] The average speed of the current mouse movement is calculated with the data of the user's past thirty normal logins to obtain a trajectory similarity score; the current click frequency is compared with the historical click frequency to obtain a click behavior score; the delay interval sequence of inputting adjacent characters on the keyboard is compared with the historical record to obtain a keystroke score; finally, the trajectory accounts for 40%, the click accounts for 20%, and the keystroke accounts for 40% of the weight, and the weighted sum is generated to generate a similarity score between 0 and 100.

[0070] For example, in the current operation of the user, the average speed of the mouse movement is 320 pixels per second, the click frequency is 48 times per minute, and the interval sequence between adjacent characters of the keyboard input is 180 milliseconds, 210 milliseconds and 190 milliseconds. By comparing the above data with the historical operation behavior of the user and calculating the deviation of each item after weighting, a similarity score of 88 points is obtained.

[0071] Step S203: Based on the similarity score, it is judged whether the current operation behavior conforms to the operation behavior of the tenant terminal.

[0072] According to the comparison between the similarity score and the preset threshold, it is judged whether the current operator is a legal user of the tenant terminal. If the score is higher than the threshold, it is considered that the current operation behavior conforms to the operation behavior of the tenant terminal; if the score is lower than the threshold, it is considered that the current operation behavior does not conform to the operation behavior of the tenant terminal, and there may be a risk of account impersonation or non-personal operation.

[0073] For example, the preset threshold is set to 85 points. The similarity score of this time is 92 points, which is higher than the threshold, and it is determined that the current operation behavior conforms to the operation habit of Xiao Li, and the subsequent operation is allowed to continue. If the score is 76 points, it is determined that it does not conform.

[0074] Step S204: If not, interrupt the file operation instruction and refuse to execute the file operation instruction.

[0075] After judging that the current operation behavior does not conform to the operation behavior of the tenant terminal, the file operation request initiated by the user is interrupted, such as saving, modifying, deleting or uploading.

[0076] Specifically, the file operation instruction is not sent, the file content is not modified or transmitted, and a prompt that the operation is refused is returned to the user terminal, so as to ensure that the data is not accessed and modified by non-person or abnormal behavior.

[0077] By using the above technical scheme, the interactive behavior data such as mouse movement trajectory, click frequency and keyboard input delay of the user are collected in real time, compared with the model, the behavior similarity score is generated, and the credibility of the operator identity is judged accordingly. The scheme greatly improves the persistence and accuracy of identity verification, effectively identifies abnormal behaviors such as account impersonation and non-personal operation, and realizes the interception of high-risk file operations.

[0078] The embodiment of the application discloses a method for cooperative confirmation based on permissions and positions. Referring to Figure 3 The method comprises the following steps. Step S301: Enable the delay mechanism, and push an operation confirmation request message to a first authorized user terminal with the highest access permission, the operation confirmation request message being used to inquire whether to continue executing a file operation instruction.

[0079] The delay mechanism refers to not immediately interrupting the file operation instruction when the tenant terminal operation behavior does not meet the requirements, but suspending the execution and reserving a period of time for confirming the tenant terminal operation behavior.

[0080] The highest access permission refers to the permission of a user with the highest level of operation control, who can approve or veto critical operations, usually corresponding to roles such as department head, system administrator, or project manager.

[0081] The first authorized user terminal refers to the device used by the user with the highest permission pre-set by the tenant, which is used to receive operation confirmation request messages and make approval decisions.

[0082] The operation confirmation request message refers to a prompt message sent to the first authorized user terminal, usually containing operation type, target file, initiator, time, and other context information, with agree or refuse options.

[0083] For example, after the user submits an instruction to delete the core database, the execution is suspended and delayed for 30 seconds, and a confirmation pop-up window is sent to the department head's office computer, asking whether to continue executing the file operation instruction, waiting for approval or refusal.

[0084] Step S302: Receive the post-level feedback result from the first authorized user terminal within the pre-set response waiting time.

[0085] The response waiting time refers to the time window set for operation confirmation, usually 30 seconds to 5 minutes, and the specific duration can be adjusted.

[0086] The post-level feedback result refers to the decision response made by the first authorized user terminal based on its management responsibilities and permission level, including explicit instructions such as agree, refuse, or transfer to others for handling.

[0087] For example, after sending a confirmation request to the department head terminal, a 2-minute waiting window is started, and the supervisor clicks the agree or refuse button before the countdown ends, receiving the response as the post-level feedback result.

[0088] Step S303: If the received post-level feedback result is ambiguous, push the operation confirmation request message to the second authorized user terminal located within the pre-set geographical location range of the tenant terminal, and obtain the location feedback result.

[0089] Ambiguity refers to the inconsistency between two or more received post-level feedback results.

[0090] The pre-set geographical location range refers to the pre-configured physical area range, such as a ten-meter range centered on the tenant terminal.

[0091] The second authorized user terminal refers to the user terminal within the pre-set geographical location range.

[0092] The position feedback result refers to the opinion of the second authorized user terminal located within the preset geographical position range on the operation confirmation request message.

[0093] For example, if the post-level feedback result is determined to be ambiguous, the operation confirmation request message is sent to the second authorized user terminal within a 100-meter range centered on the tenant terminal, and the response is received as the position feedback result.

[0094] Step S304: Based on the post-level feedback result and the position feedback result, determine whether to allow the file operation instruction to continue to be executed according to a preset rule.

[0095] The preset rule refers to a preconfigured decision logic for comprehensively determining whether to allow the file operation instruction to continue to be executed.

[0096] Step S305: If not, interrupt the file operation instruction.

[0097] For example, if neither the post-level feedback result nor the position feedback result passes the confirmation condition, the file deletion operation is interrupted, and no data modification is performed.

[0098] By using the above technical solution, when an abnormal operation is detected, a delay confirmation mechanism is enabled, the operation intention is preferentially inquired from a high-privilege user, and when there is a difference in feedback, a collaborative confirmation is further initiated from authorized users in geographical proximity, and a comprehensive decision is made in combination with the privilege level and the physical location context. This solution greatly improves the accuracy and reasonableness of security interception, effectively identifies real business scenarios such as legal proxy operation and temporary collaboration, and reduces the risk of false interruption and privilege abuse.

[0099] Embodiments of the present application disclose a feedback decision method based on time segmentation. Referring to Figure 4 , the method comprises: Step S401: Establish a feedback result axis based on time, and divide the feedback result axis into a first time threshold interval and a second time threshold interval, the first time threshold interval being earlier than the second time threshold interval.

[0100] The feedback result axis refers to a time sequence coordinate established for collecting responses of the second authorized user terminal to the operation confirmation request message, for recording the types and quantities of feedback received in different time periods.

[0101] The first time threshold interval refers to an early time period close to the operation initiation time on the feedback result axis, for example, within 0 to 2 minutes after the operation. The feedback in this interval usually reflects the user's immediate judgment on the operation, and the faster the response, the higher the credibility.

[0102] The second threshold interval refers to a time period after the first time threshold interval, for example, within 2-5 minutes after the operation. This interval is used to receive delayed responses as a supplement to the first time threshold interval.

[0103] For example, a timeline is established after the operation confirmation request message is initiated, 0-2 minutes is set as the first time threshold interval, and 2-5 minutes is set as the second time threshold interval, which is used to collect feedback from the second authorized user terminal in segments.

[0104] Step S402: According to the feedback result axis, the position feedback result is divided into a first position feedback result and a second position feedback result, the first position feedback result includes a first approval feedback result and a first denial feedback result, and the second position feedback result includes a second approval feedback result and a second denial feedback result. The first position feedback result is received within the first time threshold interval, and the second position feedback result is received within the second time threshold interval.

[0105] The first position feedback result refers to the feedback result received within the first time threshold interval.

[0106] The second position feedback result refers to the feedback result received within the second time threshold interval.

[0107] The first approval feedback result refers to the confirmation response of approving the operation sent by the authorized user within the preset geographical range within the first time threshold interval.

[0108] The first denial feedback result refers to the confirmation response of refusing to perform the operation sent by the authorized user within the preset geographical range within the first time threshold interval.

[0109] The second approval feedback result refers to the confirmation response of approving the operation sent by the authorized user within the preset geographical range within the second time threshold interval.

[0110] The second denial feedback result refers to the confirmation response of refusing to perform the operation sent by the authorized user within the preset geographical range within the second time threshold interval.

[0111] Step S403: Count the first total feedback quantity of the first position feedback result.

[0112] The first total feedback quantity refers to the total number of all first position feedback results received within the first time threshold interval.

[0113] For example, within 0-2 minutes, a total of 5 feedbacks from on-site authorized personnel are received, of which 3 people agree and 2 people refuse, so the first total feedback quantity is 5.

[0114] Step S404: Count the first sub-feedback quantity of the first approval feedback result.

[0115] The first sub-feedback quantity refers to the quantity of the approval feedback received within the first time threshold interval, i.e., the quantity of the first approval feedback result.

[0116] For example, in the last example, 3 out of 5 people choose "agree", and the first sub-feedback quantity is 3.

[0117] Step S405: Obtain a proportion value based on the first total feedback quantity and the first sub-feedback quantity.

[0118] The proportion value refers to the ratio of the first sub-feedback quantity to the first total feedback quantity, which is used to measure the degree of the approval feedback result in the first position feedback result.

[0119] For example, the first total feedback quantity is 5, the first sub-feedback quantity is 3, and the proportion value is calculated as 60%.

[0120] Step S406: If the proportion value is higher than the consistency threshold value, and the proportion of the first sub-feedback quantity to the preset total feedback quantity exceeds the first quantity threshold value, the first approval feedback result is taken as the preset rule.

[0121] The preset total feedback quantity refers to the total feedback quantity collected within the time range covered by the feedback result axis, which is used to determine whether the current feedback reaches the required minimum sample size.

[0122] The preset rule refers to the basis determined according to the statistical analysis of the feedback result, which is used to determine whether to allow the operation instruction to continue to be executed.

[0123] The first quantity threshold value refers to the minimum proportion of the first sub-feedback quantity to the preset total feedback quantity.

[0124] For example, if the consistency threshold value is set to 70%, the first quantity threshold value is 30%, and the preset total feedback quantity is 10. The current proportion value 80% is higher than 70%, which does not meet the condition, so the first approval feedback result is adopted as the preset rule.

[0125] Step S407: If the proportion value is lower than the consistency threshold value, determine the second majority feedback result from the second approval feedback result and the second denial feedback result.

[0126] The second majority feedback result refers to the party with more quantity in the second approval feedback result and the second denial feedback result within the second time threshold interval.

[0127] For example, within 2 to 5 minutes, 6 feedbacks are received, including 4 approvals and 2 refusals, and the second majority feedback result is the second approval feedback result.

[0128] Step S408: In the case that the second majority feedback result is the second approval feedback result, and the proportion of the second approval feedback result in the preset total feedback quantity is not less than the second quantity threshold, the second approval feedback result is taken as the preset rule.

[0129] The second quantity threshold refers to that the second approval feedback result needs to reach the minimum proportion of the preset total feedback quantity.

[0130] For example, the second approval feedback result is 4, the preset total feedback quantity is 10, the proportion is 40%, and the second quantity threshold is satisfied, and then the file operation instruction is continuously executed.

[0131] By using the above technical scheme, a feedback result axis based on time is established, early and subsequent user confirmation feedbacks are analyzed in stages, and the operation intention is judged in combination with the feedback consistency proportion and the quantity coverage rate. The scheme greatly improves the scientificity and reliability of collaborative approval, and reduces the misinterception caused by scattered or delayed feedback.

[0132] Embodiments of the present application disclose a file authorization method based on collaborative voting. Referring to Figure 5 , the method comprises: Step S501: receiving a modification request of a target file submitted by a tenant terminal.

[0133] The target file refers to a specific data object currently operated by the user, such as a document, a table, a configuration file, etc.

[0134] The modification request refers to an instruction initiated by the user to edit, update or adjust the target file, usually including operation type and request time, etc.

[0135] Step S502: obtaining an access control policy of the target file, the access control policy comprising a plurality of authorized user identifiers associated with the target file.

[0136] The access control policy refers to a permission management rule set for a specific file, which is used to define which user has the permission to view, edit or approve the file.

[0137] The plurality of authorized user identifiers refers to the user identity identifiers of the users who have the approval or management permission of the target file and are explicitly listed in the access control policy, and these users have the voting right in the file modification process.

[0138] Step S503: pushing the modification request to the user terminals corresponding to the plurality of authorized user identifiers, and starting a voting timer.

[0139] The voting timer refers to the time limit set for this voting, which starts counting from the time of request pushing and lasts for a certain duration, and is used to control the decision cycle and avoid indefinite waiting.

[0140] Exemplarily, the modification request is sent to the office computers of the financial supervisor, the department manager and the audit officer respectively, and a 10-minute countdown voting timer is started.

[0141] Step S504: During the counting of the voting timer, the voting intention of the user terminal is received.

[0142] The voting intention refers to the explicit response of the authorized users to whether they agree to modify the target file, usually including the options of agreement, rejection or abstention, and only valid responses are counted.

[0143] Exemplarily, during the 8-minute counting period, user 1 clicks on agreement, user 2 clicks on rejection, and user 3 does not respond, and then two valid voting intentions are recorded: one agreement and one rejection.

[0144] Step S505: Determine whether the number of agreements to modify the target file in the received voting intention meets the voting threshold.

[0145] The voting threshold refers to the minimum number of agreements preset to determine whether to agree to the modification operation.

[0146] Exemplarily, the voting threshold is set to at least 2 agreements, and actually only 1 agreement is obtained, so the voting threshold is not met, and it is determined that the modification is not passed.

[0147] Step S506: If yes, the file modification permission is granted to the tenant terminal.

[0148] The file modification permission refers to temporarily opening the editing permission of the target file to the tenant terminal after the voting is passed, allowing it to perform the modification operation. The file modification permission usually has a time limit and is automatically recovered after the modification is completed.

[0149] If the number of agreements to modify the target file in the voting intention does not meet the voting threshold, the tenant terminal is not allowed to modify the target file.

[0150] Exemplarily, if two of the three authorized users agree to modify, the editing permission of the file is opened to the tenant terminal, allowing it to perform the modification operation. If only one of the three authorized users agrees to modify, the tenant terminal is not allowed to perform the modification operation.

[0151] By using the above technical solution, the permission relationship of the target file is obtained, the modification request is pushed to all related authorized users, and the voting opinions are collected within a limited time, and the majority opinions are comprehensively considered to determine whether to authorize. This scheme greatly improves the transparency and collaboration of file modification approval, effectively avoids the risks caused by individual overreach or misoperation, and reduces the security risks caused by power concentration.

[0152] The embodiment of the application discloses a file modification method based on content and behavior.Figure 6 The method comprises: Step S601: Monitoring the modification of the target file to obtain the modified content data.

[0153] The content data refers to the information contained in the target file after the completion of the current modification operation, including the modified text, numerical value or format, etc.

[0154] When the user clicks save, read the current content of the file, record the text, numerical value and format information, and compare it with the stored content of the previous version of the file to determine the modified part as the content data.

[0155] For example, the user modifies the amount field in the contract file and clicks save, reads the latest content of the file, records the modified amount as the modified content data.

[0156] Step S602: Analyzing the content data to obtain an analysis result, the analysis result including at least one of whether the sensitive field is modified, whether there is an unauthorized operation or data abnormal change.

[0157] The analysis result refers to the judgment information generated after checking the modified content.

[0158] The sensitive field refers to the information field in the file related to privacy, security or key business, such as ID number, bank account number, price parameter, etc.

[0159] Data abnormal change refers to data change that does not conform to the conventional business logic, such as a sudden increase of 100 times in the amount, a jump in the state field, etc., which may indicate a mistake or malicious behavior.

[0160] Compare the modified content with the stored content of the previous version of the file to identify whether it involves sensitive fields such as ID number, bank account number, etc., and then judge whether unauthorized fields are modified according to the user permission table, and check whether the numerical value change is beyond the normal business range to obtain the analysis result.

[0161] Step S603: Detecting whether the user interface operation behavior of the tenant terminal to the target file meets the abnormal operation mode, the abnormal operation mode including the number of page switching within a unit time exceeding a first threshold or the single page dwell time being lower than a second threshold.

[0162] The user interface operation behavior refers to the sequence of actions of the user interacting with the file on the interface, such as clicking, scrolling, switching tabs, etc.

[0163] The abnormal operation mode refers to the behavior characteristics that do not conform to the normal manual operation habits.

[0164] The time and number of page switching during the operation of the tenant are recorded, the switching frequency per unit time is counted, and the time interval from entering a page to leaving is recorded. If the number of switching exceeds a preset first threshold or the single stay time is shorter than a preset second threshold, it is determined that the abnormal operation mode is met.

[0165] For example, if the user switches 25 different work sheets within 5 minutes during editing, and the average stay time of each work sheet is less than 2 seconds, it is determined that the abnormal operation mode is met.

[0166] Step S604: If yes, based on the analysis result, it is determined whether there is malicious modification.

[0167] Malicious modification refers to the intention of subjective intentional destruction or data tampering.

[0168] The content analysis result and operation behavior are combined to evaluate whether the modification has the intention of subjective intentional destruction or data tampering. Only when the content anomaly and behavior anomaly exist at the same time, it is inclined to determine as malicious modification.

[0169] Step S605: If yes, a warning signal is generated.

[0170] The warning signal refers to the prompt information automatically popped up after finding suspicious modification, which is used to remind the system administrator that there is abnormal operation, and lock the file or account if necessary.

[0171] For example, if it is detected that the user E modifies the contract amount and frequently switches pages, it is determined as malicious modification, and a red warning box is popped up on the administrator computer, prompting "abnormal modification behavior is found, operator U2025, involves contract number HT2025001, please check immediately".

[0172] By using the above technical solution, the file modification content is monitored in real time, whether the sensitive information is changed or abnormal data change occurs is identified, and whether there is suspicious operation mode such as frequent page switching and short stay time is judged by combining the user operation behavior. This scheme greatly improves the identification of malicious modification behavior, effectively distinguishes normal modification from hidden destruction, and reduces the data risk caused by misoperation or internal attack.

[0173] Embodiments of the present application disclose an abnormal detection method based on page switching behavior. Referring to Figure 7 The method comprises: Step S701: Obtain a switching page, the switching page comprising a first switching page and a second switching page.

[0174] The switching page refers to the process of jumping from one interface to another interface during operation. For example, jumping from a customer list to contract management.

[0175] The first switching page refers to the page that the user currently leaves, i.e., the page that is cut out.

[0176] The second switching page refers to the page that the user currently enters, i.e., the page that is cut in.

[0177] By listening to the page jump action of the user in the interface, the page that is left each time and the page that is entered are recorded, and the first switching page and the second switching page are obtained.

[0178] Step S702: Differences existing in the first switching page and the second switching page are obtained to obtain a difference result.

[0179] The difference result refers to the difference between the first switching page and the second switching page in the function type, the data sensitivity level, or the access permission, which is used to determine whether the page jump is abnormal.

[0180] By comparing the function type and the data sensitivity level of the first switching page and the second switching page, if it is found that the types are different or the sensitivity level is increased, it is determined that there is a difference.

[0181] Step S703: Based on the user interface operation behavior and the difference result, an operation sequence of the switching page is generated, the operation sequence contains multiple switching page events recorded in time sequence, and the switching page event includes switching time, cut-in page identifier, cut-out page identifier, and page stay duration.

[0182] The operation sequence refers to the time of each page jump of the user, from which page the user cuts out, into which page the user enters, and how long the user stays in the previous page, which are connected in chronological order to form an operation record, and are used to restore the operation track.

[0183] The switching page event refers to the process in which the user jumps from one page to another page.

[0184] Step S704: The operation sequence is matched with the abnormal operation mode.

[0185] The number of page switching times in the operation sequence per unit time is compared with the first threshold value, and it is checked whether the page stay time each time is lower than the second threshold value, if one or both of them are satisfied, it is determined that the operation sequence is matched with the abnormal operation mode.

[0186] Step S705: If the matching is successful, the step of judging whether there is malicious modification based on the analysis result is performed.

[0187] For example, the user switches 25 pages in 3 minutes, and most of the stay time is less than 3 seconds, it is determined that the abnormal operation mode is matched, and whether there is malicious modification is judged in combination with the analysis result.

[0188] By adopting the technical scheme, the complete process of user page switching is recorded, the time, source, target and stay duration of each switching are extracted, and an ordered operation behavior sequence is generated in combination with the content difference between pages, and then matched with an abnormal pattern. The scheme greatly improves the recognition ability of hidden operation behaviors, effectively discovers suspicious actions such as frequent jumps and short stays, and reduces the risk of missing judgment caused by fragmented behaviors.

[0189] Based on the same inventive concept, the embodiments of the present application provide a resource security information data processing system, please refer to Figure 8 The system comprises: An acquisition module 801 is configured to acquire a registration request, an access request and an access permission. A memory 802 is configured to store a program of a resource security information data processing method. A processor 803, the program in the memory can be loaded and executed by the processor and implement the resource security information data processing method.

[0190] By adopting the technical scheme, the acquisition module acquires the registration request, the access request and the permission information of the tenant in real time, the processor calls the pre-stored security processing program in the memory, and performs security operations such as identity verification, behavior analysis, collaborative decision and encrypted transmission, thereby realizing the whole-process closed-loop management and control from user access to file operation, ensuring the data security and operation credibility, and providing an efficient and reliable integrated solution for resource security management in a multi-tenant environment.

[0191] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0192] The embodiments of the present application provide a computer readable storage medium, which stores a computer program capable of being loaded and executed by a processor to implement a resource security information data processing method.

[0193] The computer storage medium includes, for example, a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0194] Based on the same inventive concept, the embodiment of the present application provides a kind of intelligent terminal, including memory and processor, memory is stored with the computer program of the resource security information data processing method capable of being loaded and executed by processor.

[0195] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of functional modules is exemplified, and in actual application, the above-mentioned functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the above-described system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0196] The above are preferred embodiments of the present application, and do not limit the protection scope of the present application, any feature disclosed in the specification (including abstract and drawings) can be replaced by other equivalent or similar purpose alternative features, unless specifically described. That is, each feature is only an example of a series of equivalent or similar features.

Claims

1. A method for processing resource security information data, characterized in that, include: Receive registration requests submitted by tenant terminals; Based on the registration request, the tenant terminal undergoes first authentication to generate access permissions; Based on the registration request, a dedicated virtualization resource pool is allocated to the tenant terminal in the virtualization environment; In response to the access request submitted by the tenant terminal, obtain the access permission; Based on the access permissions, a second authentication is performed on the tenant terminal to obtain the authentication result; When the authentication result indicates that the authentication is successful, in response to the file operation instruction, the target data is encrypted to obtain encrypted data; The encrypted data is transmitted via data transfer, which includes uploading the encrypted data to the dedicated virtualization resource pool and downloading the encrypted data from the dedicated virtualization resource pool to the tenant terminal.

2. The resource security information data processing method according to claim 1, characterized in that, In response to file operation instructions, it also includes: Real-time collection of interactive behavior data, including mouse movement trajectory characteristics, mouse click frequency, and keyboard input delay interval; The interaction behavior data is compared with historical operation behavior to generate a similarity score; Based on the similarity score, it is determined whether the current operation behavior matches the tenant terminal operation behavior; If not, the file operation instruction is interrupted and execution is refused.

3. The resource security information data processing method according to claim 2, characterized in that, The method further includes: A delay mechanism is enabled, and an operation confirmation request message is pushed to the first authorized user terminal with the highest access rights. The operation confirmation request message is used to ask whether to continue executing the file operation instruction. Within the preset response waiting time, receive the job-level feedback result from the first authorized user terminal; If the received job level feedback result is ambiguous, the operation confirmation request message is pushed to a second authorized user terminal located within a preset geographical location range of the tenant terminal to obtain the location feedback result; Based on the job level feedback result and the location feedback result, determine whether to allow the continued execution of the file operation instruction according to preset rules; If not allowed, the file operation command will be interrupted.

4. The resource security information data processing method according to claim 3, characterized in that, The method further includes: A time-based feedback result axis is established, which is divided into a first time threshold interval and a second time threshold interval, wherein the first time threshold interval is earlier than the second time threshold interval. According to the feedback result axis, the location feedback result is divided into a first location feedback result and a second location feedback result. The first location feedback result includes a first approval feedback result and a first disapproval feedback result. The second location feedback result includes a second approval feedback result and a second disapproval feedback result. The first location feedback result is received within the first time threshold interval, and the second location feedback result is received within the second time threshold interval. Count the total number of first feedback results from the first location; Count the number of first sub-feedbacks of the first positive feedback result; The ratio is obtained based on the first total feedback quantity and the first sub-feedback quantity; If the ratio is higher than the consistency threshold, and the proportion of the first sub-feedback quantity to the preset total feedback quantity exceeds the first quantity threshold, then the first approval feedback result is taken as the preset rule. If the ratio is lower than the consensus threshold, a second majority feedback result is determined from the second approval feedback result and the second disapproval feedback result; If the second majority feedback result is the second approval feedback result, and the proportion of the second approval feedback result to the preset total number of feedback results is not less than the second quantity threshold, then the second approval feedback result shall be used as the preset rule.

5. The resource security information data processing method according to claim 1, characterized in that, Also includes: Receive the modification request for the target file submitted by the tenant terminal; Obtain the access control policy of the target file, wherein the access control policy includes multiple authorized user identifiers associated with the target file; The modification request is pushed to the user terminals corresponding to the multiple authorized user identifiers, and a voting timer is activated; During the timing period of the voting timer, the voting intention of the user terminal is received; Determine whether the number of votes received agreeing to modify the target file meets the voting threshold; If so, grant file modification permissions to the tenant terminal.

6. A resource security information data processing method according to claim 5, characterized in that, After granting file modification permissions to the tenant terminal, the following steps are included: Monitor modifications to the target file and obtain the modified content data; The content data is analyzed to obtain analysis results, which include at least one of the following: whether sensitive fields have been modified, whether there is unauthorized operation, or abnormal data changes. Detect whether the user interface operation behavior of the tenant terminal on the target file meets the abnormal operation mode, the abnormal operation mode includes the number of page switching times per unit time exceeding a first threshold or the single page dwell time being less than a second threshold; If the conditions are met, based on the analysis results, determine whether there is any malicious modification. If so, generate a warning signal.

7. A resource security information data processing method according to claim 6, characterized in that, The step of detecting whether the user interface operation behavior of the tenant terminal during the modification of the target file meets the abnormal operation mode includes: Obtain the switching page, which includes a first switching page and a second switching page; Based on the differences between the first and second switching pages, the difference results are obtained; Based on the user interface operation behavior and the difference results, an operation sequence for switching pages is generated. The operation sequence includes multiple page switching events recorded in chronological order. Each page switching event includes a switching time, an entry page identifier, an exit page identifier, and a page dwell time. Match the operation sequence with the abnormal operation pattern; If a match is found, proceed to the step of determining whether malicious modification exists based on the analysis results.

8. A resource security information data processing system, characterized in that, The system is used to execute the resource security information data processing method as described in any one of claims 1 to 7, including: The acquisition module is used to obtain registration requests, access requests, and access permissions; A memory for storing the program of the resource security information data processing method; The processor and the program in the memory can be loaded and executed by the processor to implement the resource security information data processing method.

9. A smart terminal, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer program is stored that can be loaded by a processor and execute the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Cluster access method and device, electronic equipment and storage medium

    CN117176415A

  • Enterprise digital service platform of multi-tenant and micro-service architecture

    CN118784712A

  • Software value evaluation method and device, electronic equipment and storage medium

    CN120807007A

  • Method and system for payment funding

    US20080183619A1

  • Efficient server side data retrieval for execution of client side applications

    US6615253B1