Business hall service system supporting multi-user security data circulation
By incorporating modules for multi-user identity and access control, secure data circulation and isolation, data lifecycle security management, and security monitoring and compliance auditing, the system addresses the issues of dynamic access control and data security protection in a multi-user environment for the business hall service system. This achieves fine-grained isolation and dynamic protection, thereby improving system security and resource utilization efficiency.
Patent Information
- Application Number
- CN202511497670.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-20
- Publication Date
- 2025-12-16
AI Technical Summary
Existing service hall systems struggle to achieve dynamic access control and data security protection in multi-user environments, failing to effectively address complex security threats and compliance requirements, especially lacking flexibility and fine-grained control in data transmission, storage, and processing.
It employs a multi-user identity and access control module, a secure data circulation and isolation module, a data lifecycle security management module, and a security monitoring and compliance audit module. Combined with technologies such as multi-layer encrypted transmission, multi-tenant data isolation, dynamic access control, and abnormal behavior detection, it achieves fine-grained access control, data encryption protection, end-to-end security protection, and intelligent monitoring.
It achieves fine-grained isolation and dynamic protection of multi-user data, improves system security and adaptability, can identify and respond to security threats in a timely manner, reduce false alarm rate, optimize resource utilization, and ensure data security and compliance throughout the entire lifecycle.
Smart Images

Figure CN121151091A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of electric digital data processing, and in particular to a business hall service system supporting multi-user secure data flow. BACKGROUND
[0002] With the deepening of information construction, the business hall service system has become the core business support platform of the industry such as communication operators, financial institutions, etc. These systems need to serve a large number of users with different permission levels at the same time, including ordinary customers, enterprise customers, business agents and internal management personnel, etc. In the environment of multi-user sharing resources, how to ensure the security of data in the process of collection, storage, transmission and processing, and prevent data leakage, tampering and illegal access, has become a key technical problem that must be solved in system design. The traditional business hall service system often uses a single identity authentication mechanism and a static permission management mode, which is difficult to cope with the increasingly complex security threats and compliance requirements.
[0003] In the field of multi-user data security management technology, the existing technology mainly uses the following algorithms. The first is a role-based access control algorithm, which realizes access control by assigning users to predefined roles and granting permissions to roles. The advantage of this algorithm is simple management and easy implementation, suitable for scenarios with relatively fixed organizational structure, but the disadvantage is lack of flexibility, unable to dynamically adjust permissions according to real-time business scenarios, and prone to permission conflicts when handling cross-role permission requirements. The second is an attribute-based access control algorithm, which makes access decisions based on multi-dimensional information such as user attributes, resource attributes and environmental attributes. Its advantages are high flexibility and fine-grained control capability, which can support complex access control strategies, but the disadvantage is that the strategy configuration is complex, the performance overhead is large, and the strategy management difficulty increases significantly in large-scale user scenarios. The third is a token-based access control algorithm, which controls resource access by issuing and verifying encrypted tokens. Its advantage is to support identity verification in a distributed environment, reducing the frequent identity authentication overhead, but the disadvantage is that the token lifecycle management is complex, there is a risk of token theft or replay attacks, and it is difficult to implement fine-grained auditing of data access processes.
[0004] In related patent technologies, US patent US7792301B2 discloses an access control and encryption technology in a multi-user system. The patent proposes to associate multiple information units with access control policies, and group the information units into encryption regions based on these policies, each encryption region is associated with a region root key, and data encryption and access control are achieved through a hierarchical key structure. However, the patent has the following shortcomings: the division of its encryption region is relatively static, it cannot dynamically adjust the isolation policy according to the real-time security behavior and business scenario of the user, it lacks effective conflict detection and processing mechanisms when facing high-concurrency access scenarios, and it does not consider the security management needs of data in the whole life cycle, especially lacking systematic technical solutions in data desensitization, retention and destruction.
[0005] Chinese patent CN107852417A discloses a multi-tenant identity and data security management cloud service system. The patent provides a cloud-based identity and access management service, the system receives identity management service requests from clients, performs identity verification on the requests, and accesses microservices based on the requests, and realizes identity management in a multi-tenant environment by determining user tenants and resource tenants. However, this patent also has obvious shortcomings: its identity verification mechanism mainly relies on traditional centralized verification mode, does not use emerging technologies such as distributed ledger to enhance the credibility and tamper-proofing ability of identity verification, only provides basic encryption protection in data transmission security, lacks multi-level encryption transmission mechanism and data integrity traceability ability, lacks intelligent processing means for sensitive data identification, classification and dynamic desensitization, and does not establish an intelligent analysis model based on user behavior characteristics in abnormal behavior detection, making it difficult to discover and respond to potential security threats in a timely manner. In addition, the patent lacks a quantitative evaluation mechanism for the isolation intensity of data between different tenants, and cannot dynamically adjust the resource allocation strategy according to the user's historical security behavior and data sensitivity level. SUMMARY
[0006] The purpose of the present application is to address the existing deficiencies and provide a business hall service system supporting multi-user secure data flow.
[0007] The present application adopts the following technical solutions:
[0008] A business hall service system supporting multi-user secure data flow, comprising a multi-user identity and access control module, a secure data flow and isolation module, a data life cycle security management module, and a security monitoring and compliance audit module.
[0009] The multi-user identity and access control module is responsible for establishing a trusted user identity system and implementing fine-grained permission management, the secure data flow and isolation module ensures encryption protection, integrity verification and effective isolation between multiple users during data transmission, the data lifecycle security management module covers the whole process of security protection from sensitive data identification, processing to destruction, and the security monitoring and compliance audit module ensures that the system continuously meets compliance requirements and responds to security threats in a timely manner through intelligent anomaly detection and full-link audit;
[0010] The multi-user identity and access control module includes a multi-channel access authentication unit, a distributed identity verification unit and a dynamic permission and access control unit, the multi-channel access authentication unit is responsible for receiving user access requests from external channels, establishing an encrypted communication channel and completing preliminary identity authentication, the distributed identity verification unit is used to store user identity information in the form of a hash digest in a trusted node, and the dynamic permission and access control unit is used to dynamically generate and adjust data access policies;
[0011] The secure data flow and isolation module includes a multi-layer encryption transmission unit, a multi-tenant data isolation unit and a data integrity and traceability unit, the multi-layer encryption transmission unit is used to implement encryption protection at three levels of underlying channels, middle messages and high-level fields to ensure data confidentiality and non-tamperability in each flow node, the multi-tenant data isolation unit is used to ensure that the data of multiple users is independent of each other when sharing system resources and to detect and handle data conflicts in concurrent scenarios, and the data integrity and traceability unit is used to perform integrity verification on data packets;
[0012] The data lifecycle security management module includes a sensitive data identification and classification unit, a dynamic desensitization and encryption unit and a data retention and destruction unit, the sensitive data identification and classification unit is used to automatically identify sensitive data fields in the system and classify and mark them according to security levels, the dynamic desensitization and encryption unit is used to implement dynamic desensitization processing on sensitive data and restore plaintext data for business processing under authorization, and the data retention and destruction unit is used to manage the retention period of data;
[0013] The security monitoring and compliance audit module includes an abnormal behavior detection unit, a compliance policy management unit and a full-link audit and alarm unit, the abnormal behavior detection unit is used to analyze user access behavior and data traffic characteristics in real time and identify abnormal access patterns, the compliance policy management unit is used to maintain and dynamically update privacy protection policies, define compliance boundaries for data collection, storage and sharing, and the full-link audit and alarm unit is used to record all operations in real time and generate complete audit logs.
[0014] Further, the multi-tenant data isolation unit comprises a tenant space allocation processor, an isolation boundary manager and a conflict detection processor, the tenant space allocation processor is used to allocate independent data storage space and computing resources for each user or user group, and natural isolation of data access is ensured through logical partitioning or physical isolation mechanism, the isolation boundary manager is used to maintain and enforce access boundary policies between tenants, monitor cross-tenant data access requests, and prevent unauthorized data cross-domain operations, and the conflict detection processor is used to detect data operation conflicts in real time in a multi-user concurrent access scenario.
[0015] The tenant space allocator calculates the resource isolation degree index R of the tenant u according to the following formula u :
[0016] ;
[0017] Wherein, H u is the historical security behavior score of the user u, H thr is the security threshold, k is the steepness parameter, m is the number of data types currently stored by the user u, S j is the sensitivity level coefficient of the jth type of data, V j is the storage capacity of the jth type of data, V total is the total storage capacity of the user, is the concurrent conflict penalty function, C u represents the number of data conflicts that occur within the user u in the recent time window.
[0018] Further, when the conflict detection processor detects that multiple users are concurrently accessing the same data resource, the concurrent risk coefficient CRC is calculated according to the following formula:
[0019] ;
[0020] Wherein, N con is the number of users currently concurrently accessing the data resource, N thr is the concurrent threshold value set by the system, R max and R min are the maximum and minimum values of the resource isolation degree index among the concurrent users, represents the time interval between the current access and the last access of the ith concurrent user, represents the average session duration of the ith concurrent user, w1, w2 and w3 are weight coefficients;
[0021] When the CRC exceeds the safety threshold, the system forces the access of the trusted user to be downgraded to read-only or delayed processing, and the isolation boundary manager executes the access isolation strategy.
[0022] Further, the abnormal behavior detection unit comprises a behavior feature extraction processor, an abnormal pattern recognition engine and a threat score processor, the behavior feature extraction processor is used for extracting key behavior features from the user access log, and constructing a user behavior portrait, the abnormal pattern recognition engine is used for establishing a normal behavior baseline model, comparing the deviation degree of the current behavior from the baseline in real time, and identifying an abnormal access pattern, and the threat score processor is used for quantitatively evaluating the risk of the detected abnormal behavior, combining threat intelligence and historical security events, and calculating a threat level score;
[0023] The behavior feature extraction processor calculates the time series behavior entropy TBE of the user u according to the following formula u :
[0024] ;
[0025] Wherein, T is the total number of time slices in the observation time window, p t is the frequency of access initiated by the user in the tth time slice, A t is the number of operation types in the tth time slice, is a jump sensitive coefficient.
[0026] Further, the abnormal pattern recognition engine calculates the abnormal deviation degree ABD of the current behavior of the user u according to the following formula u :
[0027] ;
[0028] Wherein, TBE cur is the time series behavior entropy of the current time window of the user, TBE bas is the average of the historical time series behavior entropy of the user, is the standard deviation of the historical time series behavior entropy, CRC avg is the recent average concurrent risk coefficient of the user, 、 and are deviation tolerance coefficients of different degrees, > > , R safe and R high are isolation degree threshold values, is a first amplification coefficient, is a second amplification coefficient;
[0029] When the ABD exceeds a preset threshold value, the abnormal pattern recognition engine determines that the current behavior of the user is abnormal behavior.
[0030] The beneficial effects obtained by the present application are:
[0031] The system proposes a resource isolation degree index calculation model, which comprehensively considers user historical safety behavior score, data sensitivity level, storage capacity distribution and concurrent conflict times and the like multi-dimensional factors, can dynamically quantify the resource isolation demand of each user, so that the tenant space allocation processor can allocate different isolation intensity for different users according to the calculation result, which not only ensures the strict isolation of high-risk users, but also improves the resource utilization efficiency of low-risk users, and has stronger adaptability and safety compared with the traditional static isolation strategy. The concurrent risk coefficient calculation mechanism introduced by the application can evaluate the conflict risk when multiple users concurrently access the same data resource in real time, and through analyzing parameters such as concurrent user quantity, resource isolation degree difference and access time characteristics, the application automatically triggers access degradation or delay processing strategy when detecting a high-risk concurrent scene, effectively preventing data inconsistency and security vulnerabilities caused by concurrent access. The time sequence behavior entropy and abnormal deviation degree calculation model provides a quantitative analysis means for abnormal behavior detection, the model constructs a user behavior portrait by analyzing user access frequency distribution, operation type change and behavior jump characteristics, and combines historical behavior baseline and concurrent risk coefficient for multi-dimensional deviation degree evaluation, which can identify abnormal access modes such as permission abuse and data theft in time, and has higher accuracy and lower false positive rate compared with the traditional rule-based detection method.
[0032] In order to further understand the features and technical contents of the present application, please refer to the following detailed description and drawings of the present application. However, the provided drawings are only used for reference and illustration, and are not used to limit the present application. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 It is a schematic diagram of the overall structure framework of the present application.
[0034] Figure 2 It is a schematic diagram of the multi-user identity and access control module of the present application.
[0035] Figure 3 It is a schematic diagram of the safe data flow and isolation module of the present application.
[0036] Figure 4 It is a schematic diagram of the data life cycle security management module of the present application.
[0037] Figure 5 It is a schematic diagram of the security monitoring and compliance audit module of the present application.
[0038] Figure 6 It is a schematic diagram of the security index comparison and analysis of the present application and the comparative scheme.
[0039] Figure 7 It is a schematic diagram of the system resource utilization rate change trend of the present application and the comparative scheme. DETAILED DESCRIPTION
[0040] The following is a detailed description of the embodiments of the application, which will enable one skilled in the art to understand the advantages and effects of the present application. The present application can be implemented or applied by other different embodiments, and the details in the specification can be modified and changed in various ways based on different views and applications without departing from the spirit of the present application. In addition, the drawings of the present application are only simple schematic illustrations and are not drawn according to the actual size, and it is declared in advance. The following embodiments will further illustrate the related technical content of the present application, but the disclosed content is not used to limit the protection scope of the present application.
[0041] Embodiment one.
[0042] The present embodiment provides a business hall service system supporting multi-user secure data flow, which combines Figure 1 , including a multi-user identity and access control module, a secure data flow and isolation module, a data life cycle security management module, and a security monitoring and compliance audit module;
[0043] The multi-user identity and access control module is responsible for establishing a trusted user identity system and implementing fine-grained permission control. The secure data flow and isolation module ensures encryption protection, integrity verification, and effective isolation between multiple users during data transmission. The data life cycle security management module covers the full process of security protection for sensitive data from identification, processing to destruction. The security monitoring and compliance audit module ensures that the system continuously meets compliance requirements and responds to security threats in a timely manner through intelligent anomaly detection and full-link audit;
[0044] The multi-user identity and access control module includes a multi-channel access authentication unit, a distributed identity verification unit, and a dynamic permission and access control unit. The multi-channel access authentication unit is responsible for receiving user access requests from external channels, establishing an encrypted communication channel, and completing preliminary identity authentication. The distributed identity verification unit is used to store user identity information in the form of a hash digest on a trusted node. The dynamic permission and access control unit is used to dynamically generate and adjust data access policies;
[0045] The secure data flow and isolation module includes a multi-layer encryption transmission unit, a multi-tenant data isolation unit, and a data integrity and traceability unit. The multi-layer encryption transmission unit is used to implement encryption protection at three levels: bottom channel, middle message, and high-level field, to ensure data confidentiality and tamper resistance in each flow node. The multi-tenant data isolation unit is used to ensure that the data of multiple users is independent of each other when sharing system resources and to detect and handle data conflicts in concurrent scenarios. The data integrity and traceability unit is used to perform integrity verification on data packets;
[0046] The data lifecycle security management module includes a sensitive data identification and classification unit, a dynamic desensitization and encryption unit, and a data retention and destruction unit. The sensitive data identification and classification unit is used to automatically identify sensitive data fields in the system and classify and mark them according to security levels. The dynamic desensitization and encryption unit is used to implement dynamic desensitization processing on sensitive data and restore plaintext data for business processing under authorization. The data retention and destruction unit is used to manage the retention period of data.
[0047] The security monitoring and compliance audit module includes an abnormal behavior detection unit, a compliance policy management unit, and a full-link audit and alarm unit. The abnormal behavior detection unit is used to analyze user access behavior and data traffic characteristics in real time and identify abnormal access patterns. The compliance policy management unit is used to maintain and dynamically update privacy protection policies, define compliance boundaries for data collection, storage, and sharing. The full-link audit and alarm unit is used to record all operations in real time and generate complete audit logs.
[0048] The multi-tenant data isolation unit includes a tenant space allocation processor, an isolation boundary manager, and a conflict detection processor. The tenant space allocation processor allocates independent data storage space and computing resources for each user or user group, ensuring natural isolation of data access through logical partitioning or physical isolation mechanisms. The isolation boundary manager maintains and enforces access boundary policies between tenants, monitors cross-tenant data access requests, and prevents unauthorized data cross-domain operations. The conflict detection processor detects data operation conflicts in real time in multi-user concurrent access scenarios.
[0049] The tenant space allocator calculates the resource isolation index R of tenant u according to the following formula u :
[0050] ;
[0051] where H u is the historical security behavior score of user u, H thr is the security threshold, k is the steepness parameter, m is the number of data types currently stored by user u, S j is the sensitivity level coefficient of the jth type of data, V j is the storage capacity of the jth type of data, V total is the total storage capacity of the user, is the concurrent conflict penalty function, C u represents the number of data conflicts that occurred within the recent time window for user u.
[0052] When the conflict detection processor detects multi-user concurrent access to the same data resource, a concurrency risk coefficient CRC is calculated according to the following formula:
[0053] ;
[0054] Wherein, N con is the number of users currently accessing the data resource, N thr is the concurrency threshold value set by the system, R max and R min are the maximum and minimum values of the resource isolation index of concurrent users respectively, represents the time interval between the current access and the last access of the ith concurrent user, represents the average session duration of the ith concurrent user, w1, w2 and w3 are weight coefficients respectively;
[0055] When the CRC exceeds the safety threshold, the system forces the access of the trusted user to be downgraded to read-only or delayed processing, and the access isolation strategy is executed by the isolation boundary manager.
[0056] The abnormal behavior detection unit includes a behavior feature extraction processor, an abnormal pattern recognition engine and a threat score processor, the behavior feature extraction processor is used to extract key behavior features from user access logs, and construct a user behavior portrait, the abnormal pattern recognition engine is used to establish a normal behavior baseline model, compare the deviation degree of the current behavior from the baseline in real time, and identify abnormal access patterns, and the threat score processor is used to quantitatively evaluate the risk of the detected abnormal behavior, and calculate the threat level score combined with threat intelligence and historical security events;
[0057] The behavior feature extraction processor calculates the time series behavior entropy TBE of the user u according to the following formula u :
[0058] ;
[0059] Wherein, T is the total number of time slices in the observation time window, p t is the frequency of access initiated by the user in the tth time slice, A t is the number of operation types in the tth time slice, is a jump sensitive coefficient.
[0060] The abnormal pattern recognition engine calculates the abnormal deviation degree ABD of the current behavior of the user u according to the following formula u :
[0061] ;
[0062] Wherein, TBE curTBE is a time-based entropy of the current time window of the user bas TBEH is a historical time-based entropy mean of the user CRC is a standard deviation of the historical time-based entropy avg R is a recent average concurrent risk coefficient of the user 、 and R is a deviation tolerance coefficient of different degrees > > R safe and R high is an isolation threshold is a first amplification coefficient is a second amplification coefficient
[0063] When the ABD exceeds a preset threshold, the abnormal mode recognition engine determines that the current behavior of the user is abnormal behavior.
[0064] Embodiment two.
[0065] The embodiment includes all the contents of embodiment one, and provides a service hall service system supporting multi-user secure data flow, including a multi-user identity and access control module, a secure data flow and isolation module, a data life cycle security management module, and a security monitoring and compliance audit module.
[0066] The multi-user identity and access control module is responsible for establishing a trusted user identity system and realizing fine-grained permission control, the secure data flow and isolation module ensures encryption protection, integrity verification, and effective isolation between multi-users during data transmission, the data life cycle security management module covers the whole process of security protection of sensitive data from identification, processing to destruction, and the security monitoring and compliance audit module realizes intelligent abnormal detection and full-link audit to ensure that the system continuously meets the compliance requirements and responds to security threats in a timely manner.
[0067] In combination with Figure 2 The multi-user identity and access control module includes a multi-channel access authentication unit, a distributed identity verification unit, and a dynamic permission and access control unit, the multi-channel access authentication unit is responsible for receiving user access requests from external channels, establishing an encrypted communication channel and completing preliminary identity authentication, the distributed identity verification unit is used to store user identity information in the form of a hash digest in a trusted node, and the dynamic permission and access control unit is used to dynamically generate and adjust data access strategies.
[0068] In combination with Figure 3The secure data flow circulation and isolation module comprises a multi-layer encryption transmission unit, a multi-tenant data isolation unit and a data integrity and traceability unit. The multi-layer encryption transmission unit is used to implement encryption protection at three levels of a bottom channel, a middle message and a high field to ensure data confidentiality and non-tamperability in each circulation node. The multi-tenant data isolation unit is used to ensure that the data of multiple users is independent of each other when sharing system resources and to detect and process data conflicts in a concurrent scenario. The data integrity and traceability unit is used to perform integrity checking on data packets.
[0069] In combination Figure 4 The data lifecycle security management module comprises a sensitive data identification and classification unit, a dynamic desensitization and encryption unit and a data retention and destruction unit. The sensitive data identification and classification unit is used to automatically identify sensitive data fields in the system and classify and mark them according to security levels. The dynamic desensitization and encryption unit is used to implement dynamic desensitization processing on sensitive data and restore plaintext data for business processing under authorization. The data retention and destruction unit is used to manage the retention period of data.
[0070] In combination Figure 5 The security monitoring and compliance audit module comprises an abnormal behavior detection unit, a compliance policy management unit and a full-link audit and alarm unit. The abnormal behavior detection unit is used to analyze user access behavior and data traffic characteristics in real time and identify abnormal access patterns. The compliance policy management unit is used to maintain and dynamically update privacy protection policies, define compliance boundaries for data collection, storage and sharing. The full-link audit and alarm unit is used to record all operations in real time and generate complete audit logs.
[0071] The multi-channel access authentication unit comprises a channel initialization processor, an encryption negotiation processor and an identity pre-verification processor. The channel initialization processor is used to identify the source type of a user access request, assign an independent communication session identifier according to terminal device characteristics, and establish an end-to-end secure connection. The encryption negotiation processor is used to negotiate encryption algorithms with the client, select the highest security level encryption suite supported by both parties, generate a session key and complete key exchange. The identity pre-verification processor is used to perform preliminary identity legality checks, verify the basic credential information provided by the user, and preliminarily filter and intercept abnormal access requests.
[0072] The distributed identity authentication unit comprises an identity hash generation processor, a blockchain verification processor and a smart contract executor, the identity hash generation processor is used for extracting user identity key attributes and generating a unique identity digest, the blockchain verification processor is used for writing the identity hash digest into a trusted node of a distributed ledger, and the smart contract executor is used for calling a preset identity authentication smart contract to automatically complete identity authenticity verification, multi-factor authentication triggering and consensus confirmation of a verification result;
[0073] The dynamic permission and access control unit comprises a permission policy generation processor, an access decision processor and a permission change monitoring processor, the permission policy generation processor is used for comprehensively analyzing multiple factors such as user identity types, business scenarios, time dimensions and the like, and dynamically constructing an access control policy set in accordance with the least permission principle, the access decision processor is used for real-time interception of a user's data access request, access control determination according to a currently valid permission policy, and decision of whether to allow the data operation, and the permission change monitoring processor is used for continuously tracking user role changes, business process changes and security events, and automatically triggering reevaluation and adjustment of the permission policy;
[0074] The multi-layer encryption transmission unit comprises a channel encryption processor, a message encryption processor and a field encryption processor, the channel encryption processor is used for establishing an encrypted channel at a transmission layer and performing end-to-end encryption on the entire data stream, the message encryption processor is used for performing secondary encryption on a business data packet at an application layer and performing overall encryption on a message main body content, and the field encryption processor is used for performing fine-grained encryption on sensitive fields in the data packet;
[0075] The multi-tenant data isolation unit comprises a tenant space allocation processor, an isolation boundary manager and a conflict detection processor, the tenant space allocation processor is used for allocating independent data storage spaces and computing resources for each user or user group, and ensuring natural isolation of data access through logical partitioning or physical isolation mechanisms, the isolation boundary manager is used for maintaining and enforcing access boundary strategies between tenants, monitoring cross-tenant data access requests and preventing unauthorized data cross-domain operations, and the conflict detection processor is used for real-time detection of data operation conflicts in a multi-user concurrent access scenario;
[0076] The tenant space allocator calculates a resource isolation degree index R of a tenant u according to the following formula u :
[0077] ;
[0078] wherein, H u is a historical security behavior score of the user u, H thris a security threshold, k is a steepness parameter, m is the number of data types currently stored by user u, S j is a sensitivity coefficient of the jth type of data, V j is the storage capacity of the jth type of data, V total is the total storage capacity of the user, is a concurrent conflict penalty function, C u represents the number of data conflicts that have occurred within a recent time window for user u;
[0079] The expression of the concurrent conflict penalty function is:
[0080] ;
[0081] wherein, is a conflict sensitivity coefficient;
[0082] The greater the resource isolation degree index of a user, the greater the isolation strength with which the tenant space allocator allocates space for the user;
[0083] The historical security behavior score has a value between 0 and 100 and is continuously updated by the abnormal behavior detection unit;
[0084] When the conflict detection processor detects multiple users accessing the same data resource concurrently, a concurrent risk coefficient CRC is calculated according to the following formula:
[0085] ;
[0086] wherein, N con is the number of users currently accessing the data resource, N thr is a concurrent threshold number set by the system, R max and R min are respectively the maximum and minimum values of the resource isolation degree index among the concurrent users, represents the time interval between the current access and the previous access of the ith concurrent user, represents the average session duration of the ith concurrent user, and w1, w2, and w3 are weight coefficients;
[0087] When the CRC exceeds the security threshold, the system forces the access of the trusted user to be downgraded to read-only or delayed processing, and the access isolation strategy is executed by the isolation boundary manager;
[0088] The data integrity and traceability unit includes an integrity verification processor, a hash chain constructor and a traceability record processor, the integrity verification processor is used for integrity verification of data packets, re-computing hash values at a data receiving end and comparing with original hash values to detect whether data is tampered in a transmission or storage process, the hash chain constructor is used for linking hash values of data operations in time sequence to form an immutable hash chain structure, and the traceability record processor is used for recording a complete circulation path of data in a system;
[0089] The sensitive data identification and classification unit includes a data scanning processor, a feature matching processor and a hierarchical marking processor, the data scanning processor is used for periodically or in real time scanning database tables, file storage and data flow in a system to comprehensively find potential sensitive data fields and contents, the feature matching processor is used for matching and intelligently identifying scanned data by using a predefined sensitive data rule library and a machine learning model to judge whether the data belongs to a sensitive type, and the hierarchical marking processor is used for dividing identified sensitive data into different security levels according to importance and leakage risk of the sensitive data and adding hierarchical labels in metadata;
[0090] The dynamic desensitization and encryption unit includes a desensitization rule engine, a dynamic mask processor and a ciphertext recovery processor, the desensitization rule engine is used for dynamically matching an applicable desensitization strategy according to a user role, a data sensitivity level and a business scenario, defining desensitization algorithms and desensitization strengths of different fields, the dynamic mask processor is used for executing desensitization operations such as masking, replacing and truncating on sensitive fields in real time before data display or transmission, and the ciphertext recovery processor is used for obtaining a decryption key through a key management system to restore encrypted or desensitized data to plaintext form in a case of having a legal authorization;
[0091] The data retention and destruction unit includes a retention policy manager, a life cycle monitoring processor and a secure destruction processor, the retention policy manager is used for configuring a minimum retention period and a maximum retention period of different types of data and establishing data archiving rules, the life cycle monitoring processor is used for continuously tracking a storage duration of data, automatically identifying data that is about to expire or has expired, and triggering a corresponding archiving or destruction process, and the secure destruction processor is used for performing an unrecoverable destruction operation on expired data;
[0092] The abnormal behavior detection unit comprises a behavior feature extraction processor, an abnormal pattern recognition engine and a threat score processor, the behavior feature extraction processor is configured to extract key behavior features from user access logs and construct a user behavior portrait, the abnormal pattern recognition engine is configured to establish a normal behavior baseline model, compare the deviation degree of current behavior from the baseline in real time, and identify abnormal access patterns, and the threat score processor is configured to quantitatively evaluate the risk of detected abnormal behavior, combine threat intelligence and historical security events, and calculate a threat level score;
[0093] The behavior feature extraction processor calculates the time series behavior entropy TBE of the user u according to the following formula u :
[0094] ;
[0095] Wherein, T is the total number of time slices in the observation time window, p t is the frequency of access initiated by the user in the tth time slice, A t is the number of operation types in the tth time slice, is a jump sensitive coefficient;
[0096] The greater the time series behavior entropy of the user is, the more random and disordered the user behavior is;
[0097] The abnormal pattern recognition engine calculates the abnormal deviation degree ABD of the current behavior of the user u according to the following formula u :
[0098] ;
[0099] Wherein, TBE cur is the time series behavior entropy of the current time window of the user, TBE bas is the average of the historical time series behavior entropy of the user, is the standard deviation of the historical time series behavior entropy, CRC avg is the recent average concurrent risk coefficient of the user, 、 and are different degrees of deviation tolerance coefficients, > > , R safe and R high are isolation threshold values, is a first amplification coefficient, is a second amplification coefficient;
[0100] When the ABD exceeds the preset threshold, the abnormal pattern recognition engine determines that the current behavior of the user is abnormal behavior;
[0101] The compliance strategy management unit includes a regulation update tracker, a strategy configuration processor and a differential privacy processor. The regulation update tracker is used to monitor the update of domestic and foreign data protection related laws and regulations in real time, automatically identify new regulations that affect system compliance requirements. The strategy configuration processor is used to configure compliance strategy parameters such as data collection range, storage period, cross-border transmission restriction, etc., and issue policy rules to each business system for execution. The differential privacy processor is used to inject accurately calculated noise into statistical query and data analysis results, preventing sensitive individual information from being inversely deduced through aggregated analysis while ensuring the usability of statistical results.
[0102] The full-link audit and alarm unit includes an operation log collector, an audit analysis processor and a multi-level alarm processor. The operation log collector is used to collect user operation logs in real time from each level of the system. The audit analysis processor is used to perform correlation analysis and pattern mining on the collected logs, identify security events such as rule violations and abuse of authority, and generate structured audit reports for regulatory review. The multi-level alarm processor triggers different levels of alarm responses according to the severity of security events, and can automatically execute emergency measures such as session freezing and account locking.
[0103] The i, j, t appearing in the above are ordinal numbers used to represent ordinal numbers, and have no actual meaning.
[0104] To verify the beneficial effects of the present patent scheme, we designed and implemented a complete set of comparative experiments. The experimental environment uses a real business hall business scenario, the test period is 30 consecutive days, and the comparison objects include the traditional static permission management scheme, the benchmark scheme based on role-based access control, and the multi-user secure data flow scheme proposed in the present patent.
[0105] Step 1: Experimental environment setup. We built three independent test environments, with hardware configurations of 64-core CPU, 256GB memory, 10TB storage server cluster, and network bandwidth of 10Gbps. The first environment deploys the traditional scheme, using centralized identity verification and static permission allocation mechanism, and data transmission only uses single-layer TLS encryption. The second environment deploys the benchmark scheme, using role-based access control and double-layer encryption mechanism. The third environment deploys the present patent scheme, which fully implements multi-channel access authentication, distributed identity verification, dynamic permission control, multi-layer encryption transmission, multi-tenant data isolation, and abnormal behavior detection. The three systems are connected to the same test database, containing 5 million customer records and 20 million business transaction records, with data sensitivity levels divided into four levels: public, internal, confidential and top secret.
[0106] Step two: security protection capability test. We constructed five types of security threat scenarios for testing, including abnormal login attempts, privilege boundary access, data tampering attacks, cross-tenant data theft, and distributed denial of service attacks. Each type of attack was performed 1000 times, and the detection rate, false positive rate, and response time of the system were counted. In terms of abnormal detection rate, the traditional scheme was 72%, the benchmark scheme was 65%, and the present patent scheme reached 95%, with an increase of more than 30%. In terms of false positive rate, the traditional scheme was 28%, the benchmark scheme was as high as 35%, and the present patent scheme reduced the false positive rate to 8% through the intelligent calculation model of time series behavior entropy and abnormal deviation degree, significantly reducing the interference of false positives on normal business. In the data isolation test, we simulated the scenario of multiple tenants accessing the same data resource concurrently. The isolation strength of the traditional scheme was only 75%, and even dropped to 58% in high-risk scenarios. However, the present patent scheme maintained an isolation strength of more than 94% in all scenarios through dynamic calculation of resource isolation index and real-time evaluation of concurrent risk coefficient, with a maximum of 98%.
[0107] Step three: resource utilization efficiency test. We simulated the actual workload changes of the business hall for 12 hours a day, with each 2-hour period as an observation period, and recorded the CPU utilization, memory occupancy, and storage I / O performance of the system. The resource utilization rate of the traditional scheme was only 45-52% during the low business peak period (0-4 hours), indicating obvious resource waste, while the resource utilization rate soared to 85-92% during the high business peak period (6-10 hours), close to the system limit and prone to service degradation. The resource utilization curve of the benchmark scheme was similar to that of the traditional scheme, with a significant peak-valley difference. In contrast, the present patent scheme maintained a stable resource utilization rate of 78-91% throughout the day through intelligent resource scheduling and conflict detection of tenant space allocation processors, avoiding both resource idling during the low peak period and system overload during the high peak period, with an average resource utilization efficiency improvement of about 15%.
[0108] The data is sorted as Figure 6 and Figure 7 .
[0109] Example three.
[0110] The present embodiment provides a specific implementation scheme of a business hall service system supporting multi-user secure data flow, which is deployed in the core business hall platform of a provincial communication operator, with a daily service user number reaching 500,000, including four types of user groups: enterprise customers, individual customers, agents, and internal operation personnel.
[0111] The system hardware architecture adopts a distributed cluster deployment method, including 8 Huawei Kunpeng 920 servers as computing nodes, each server is configured with a 64-core ARM processor, 512 GB DDR4 memory and 4 2TB NVMe solid state disks. The storage layer uses Inspur AS5600G2 distributed storage system, with a total capacity of 500TB, supporting a three-replica redundancy mechanism to ensure data reliability. The network layer uses Huawei CloudEngine S12700 switches to build a gigabit Ethernet network, equipped with Cisco ASA5585 firewall and Green Alliance IDS intrusion detection system. The blockchain node uses 5 Dell PowerEdge R740 servers deployed independently, running Hyperledger Fabric 2.4 version alliance chain, each node is configured with Intel Xeon Gold 6248R processor and 256GB memory.
[0112] In the implementation of the multi-user identity and access control module, the multi-channel access authentication unit supports five access channels: Web browser, Android / iOS mobile client, WeChat applet, open API and USSD short code. The channel initialization processor first identifies the User-Agent field of the access request to determine the terminal type, generates a 128-bit UUID as a unique identifier for each session, and establishes a secure connection based on the TLS 1.3 protocol. The encryption negotiation processor preferentially selects the AES-256-GCM encryption suite, and if the client does not support it, it is downgraded to AES-128-CBC, and the key exchange uses the ECDHE elliptic curve algorithm to ensure forward secrecy. The identity pre-authentication processor verifies the user-provided basic credentials such as mobile phone number, ID number or enterprise unified social credit code, and implements automatic interception for requests exceeding 10 failed attempts within 5 minutes for a single IP address and records them to the threat intelligence library.
[0113] In the distributed identity authentication unit, the identity hash generation processor extracts the last four digits of the user's mobile phone number, the first six and last four digits of the ID card number, and the registration timestamp, etc. Key attributes, and generates a 64-byte unique identity digest using the SHA-256 algorithm. The blockchain verification processor encapsulates the identity digest as transaction data and submits it to five consortium chain nodes through the Fabric Gateway for consensus verification. The Raft consensus algorithm is used to ensure data consistency, and the block generation time is controlled within 2 seconds. The smart contract executor calls the pre-deployed identity verification smart contract IdentityVerifier.go, which automatically reads the identity digest and compares it with the registered information on the chain. For new users, it triggers a two-factor authentication of SMS verification and face recognition. After verification, the new identity is written to the world state database and a JWT token is returned. Compared with the traditional centralized MySQL database verification, the blockchain distributed verification of this scheme has a response time of 850 milliseconds when 2000 users are concurrent, while the traditional scheme takes 2300 milliseconds, with a performance improvement of 63%.
[0114] The permission policy generation processor of the dynamic permission and access control unit analyzes the user's department, job level, business type, and current time to dynamically generate permission policies. For example, for ordinary sales staff, they can access customer basic information and package handling functions during working hours (8:00-18:00), and only have query permissions outside working hours and need additional SMS verification. For business supervisors, they have complete customer information viewing and business approval permissions in their responsible areas, and cross-area access is automatically downgraded to read-only permissions. The permission policy is stored in Redis cluster in JSON format, with a cache time of 30 minutes, and is automatically regenerated after expiration. The access decision processor uses the Casbin 2.77 version of the strategy engine for real-time judgment, and can process 120,000 access requests per second with a decision delay of no more than 5 milliseconds. The permission change monitoring processor subscribes to the Kafka message queue of the human resource system, and when it detects user role changes, department transfers, or resignation events, it automatically updates the permission policy within 30 seconds. Compared with the traditional scheme which needs 1-2 days of manual processing period, the efficiency is improved by more than 99%.
[0115] In the secure data flow and isolation module, the channel encryption processor of the multi-layer encryption transmission unit establishes a TLS 1.3 encrypted channel at the TCP layer, uses the AES-GCM algorithm with a 256-bit key strength to encrypt the entire data stream, and the transmission speed reaches 800 Mbps. The message encryption processor performs secondary encryption on the JSON format service data packet at the application layer, uses the domestic SM4 algorithm to meet the domestic password compliance requirements, and the encrypted message volume increases by about 15% but the security is significantly improved. The field encryption processor performs fine-grained encryption on 22 sensitive fields such as name, ID number, bank card number, and call record, uses the AES-256-CBC algorithm with the PKCS7 padding mode, and the key is stored in the hardware security module HSM and automatically replaced every 24 hours. The three-layer encryption mechanism makes it necessary to break the remaining two layers to obtain plaintext data even if one layer is broken, and the security factor is increased to 127 times that of traditional single-layer encryption.
[0116] The tenant space allocation processor of the multi-tenant data isolation unit creates independent MySQL database instances for enterprise customers, individual customers, agents, and operation personnel, and realizes natural isolation by using logical partitioning. Each database instance limits the maximum number of connections to 500, and the disk quota is dynamically adjusted according to the user's historical behavior. Users with good credit can obtain 50 GB of storage space, and users with security risks are limited to 10 GB. The isolation boundary manager implements cross-tenant access control through the database access proxy ProxySQL 2.5 version, and configures strict routing rules to ensure that the query request of tenant A will never be routed to the database of tenant B. In the stress test, when 3000 different tenants simultaneously initiate query requests, the cross-tenant data leakage event rate is zero, while the traditional shared database solution appears 12 times of cross-tenant data string reading under the same pressure. The conflict detection processor monitors the MySQL slow query log and InnoDB lock waiting events, and when it detects that more than 5 users concurrently modify the same customer record, it automatically downgrades the subsequent access to read-only mode and sends an alarm notification, avoiding deadlock and data inconsistency problems.
[0117] The data integrity and traceability unit's integrity verification processor calculates the SHA-256 hash value for each data packet and attaches it in the X-Data-Hash field of the HTTP Header. The receiving end recalculates the hash value and compares it with the original value. If they are inconsistent, the data packet is rejected and tampering events are recorded. In a 30-day production environment monitoring, the system accumulated 870 million data packets, detected 53 data tampering attempts, and the detection rate reached 100%. The hash chain builder links all data operation hash values by time order every hour. The current hash value contains the hash value of the previous hour, forming an immutable time chain. The hash chain is automatically uploaded to the blockchain for notarization every morning to ensure the authenticity of the audit log. The traceability record processor records the complete circulation path of each data in the PostgreSQL time series database TimescaleDB, including creation time, visitor, operation type, access location, and modified content. A single record occupies about 2KB of storage space, and querying the complete traceability chain of any data takes no more than 200 milliseconds.
[0118] The sensitive data identification and classification unit of the data lifecycle security management module uses the deep learning model BERT-Base-Chinese for intelligent identification. The data scanning processor performs a full scan every week, covering 120TB of data in MySQL, MongoDB, and Elasticsearch databases, which takes about 6 hours. The feature matching processor uses a sensitive data rule library containing 5000 rules and a machine learning model trained on 100,000 labeled samples to identify structured sensitive information such as ID numbers, mobile phone numbers, and bank card numbers with an accuracy of 99.2%, and unstructured text such as contract content and call records with an accuracy of 94.7%. The hierarchical marking processor marks the identified sensitive data as L1 public, L2 internal, L3 confidential, and L4 top secret, and adds a sensitivity_level field in the database metadata table to record the level information, providing a basis for subsequent desensitization and encryption strategies.
[0119] The dynamic de-identification and encryption unit's de-identification rule engine matches 30 pre-defined de-identification strategies according to user roles. For L4 top secret data, when ordinary employees access, the name is displayed as "Zhang **", the ID number is displayed as "3201 ****** 1234", and the mobile phone number is displayed as "1385678". Business managers can view the complete name and mobile phone number, but the ID number is still de-identified. Only system administrators can view the plaintext after obtaining double authorization. The dynamic masking processor uses the Java-implemented de-identification tool class DataMasker.java, which supports five de-identification algorithms: masking, replacement, truncation, hashing, and noise addition. The time-consuming for de-identification of a single field is 0.3 milliseconds, and the impact on system performance is negligible. The ciphertext recovery processor verifies whether the user has the data:decrypt permission when submitting a plaintext query request. After verification, it obtains the decryption key from the HSM and calls the OpenSSL library to perform AES decryption operations. The decrypted plaintext data only exists in memory and is not saved to disk. It is automatically cleared after the session ends, preventing sensitive data from being left behind.
[0120] The data retention and destruction unit's retention policy manager configures different data retention periods. Call records are retained for 5 months, SMS records are retained for 3 months, location information is retained for 48 hours, and business hall handling records are retained for 5 years. The lifecycle monitoring processor performs a scheduled task every day at 3 a.m. to scan the create_time field of all data tables to identify overdue data. Data that has reached the retention period is automatically archived to the Hadoop HDFS cold storage cluster, reducing storage costs by 80%. Data that exceeds the archiving period triggers a secure destruction process. The secure destruction processor uses the U.S. Department of Defense DoD 5220.22-M standard to perform seven overwrite operations: the first write is all 0, the second write is all 1, the third write is a random number, and so on. After seven cycles, physical deletion is performed to ensure that data cannot be recovered by any technical means. In an experiment to destroy 10 million test data, professional data recovery software R-Studio and EasyRecovery were unable to recover any valid information, and the data destruction completeness reached 100%.
[0121] The abnormal behavior detection unit of the security monitoring and compliance audit module uses the unsupervised learning algorithm IsolationForest for anomaly pattern recognition. The behavior feature extraction processor extracts 18 behavior features such as login time, access frequency, query keywords, download data volume, and session duration from Nginx access logs, application logs, and database audit logs. The Python Pandas library is used for data cleaning and feature engineering processing. The anomaly pattern recognition engine establishes a baseline model based on the past 30 days of historical behavior of normal users and stores it in Redis for real-time comparison. When abnormal behaviors such as logging into the system at 2 a.m., querying more than 10,000 customer records at a time, and downloading more than 500MB of data within 10 minutes are detected, the system automatically calculates the abnormal score. A score of more than 80 triggers a level one alarm, and a score of more than 90 triggers a session freeze. The threat score processor combines the external threat intelligence platform AlienVault OTX to automatically upgrade the threat level for access from known malicious IP addresses, and successfully prevents 23 suspected data theft attacks in the production environment.
[0122] The regulation update tracker of the compliance policy management unit subscribes to the official RSS feeds and mailing lists of the National Internet Information Office, the Ministry of Industry and Information Technology, and the Public Security Bureau Network Security Protection Bureau, automatically crawls the latest legal and regulatory documents. When a new policy is detected, the key provisions are extracted through natural language processing technology and an impact analysis report is generated for review by the compliance team. The policy configuration processor maintains a rule library containing 89 compliance rules, and the differential privacy processor injects Laplace noise into the data when generating statistical reports. The noise scale parameter epsilon is set to 0.1, which ensures the usability of the statistical results while preventing individual information from being derived through multiple queries. After 100 queries, the attacker's inference accuracy rate for individual information is only 51%, close to the level of random guessing.
[0123] The operation log collector of the full-link audit and alarm unit collects logs from each system node through Filebeat 8.11 agent, processes 120,000 log records per second, writes into the Elasticsearch 8.11 cluster after filtering and formatting by Logstash. The hot data of logs is retained for 90 days in SSD storage, and the cold data exceeding 90 days is archived to object storage OSS, with a total storage capacity of 80TB. The audit analysis processor uses Kibana of the ELK Stack for visual analysis and the Watcher component for rule matching, and 45 audit rules are configured to detect illegal operations. For example, when detecting behaviors such as user access during unauthorized period, batch export of customer data, modification of system configuration file, etc., an alarm is automatically generated. The multi-level alarm processor divides the alarm into four levels: prompt, warning, serious, and urgent. The prompt level sends email notification, the warning level sends SMS and enterprise WeChat message, the serious level triggers phone voice alarm and notifies the security team at the same time, and the urgent level automatically executes account lock and session termination on the basis of the foregoing. In a 6-month operation, the system has issued a total of 2347 alarms, of which only 63 are false positives, with a false positive rate of 2.7%, which is significantly lower than the false positive rate of 35% of the traditional scheme.
[0124] The above disclosed is only the preferred feasible embodiment of the present application, and does not limit the protection scope of the present application, so any equivalent technical change made according to the content of the present application specification and drawings is included in the protection scope of the present application, and in addition, the elements can be updated as the technology develops.
Claims
1. A service system of a business hall supporting multi-user secure data flow, characterized by, The multi-user identity and access control module, the secure data flow and isolation module, the data life cycle security management module, and the security monitoring and compliance audit module are included. The multi-user identity and access control module is responsible for establishing a trusted user identity system and implementing fine-grained permission control, the secure data flow and isolation module ensures encryption protection, integrity verification, and effective isolation between multiple users during data transmission, the data life cycle security management module covers the full-process security protection of sensitive data from identification, processing to destruction, and the security monitoring and compliance audit module ensures that the system continuously meets compliance requirements and responds to security threats in a timely manner through intelligent anomaly detection and full-link audit. The multi-user identity and access control module includes a multi-channel access authentication unit, a distributed identity verification unit, and a dynamic permission and access control unit. The multi-channel access authentication unit is responsible for receiving user access requests from external channels, establishing an encrypted communication channel, and completing preliminary identity authentication. The distributed identity verification unit stores user identity information in the form of a hash digest on a trusted node. The dynamic permission and access control unit dynamically generates and adjusts data access policies. The secure data flow and isolation module includes a multi-layer encryption transmission unit, a multi-tenant data isolation unit, and a data integrity and traceability unit. The multi-layer encryption transmission unit implements encryption protection at three levels: the underlying channel, the middle message, and the high-level field, to ensure data confidentiality and tamper resistance at each flow node. The multi-tenant data isolation unit ensures that multiple users' data are independent when sharing system resources and performs data conflict detection and processing in concurrent scenarios. The data integrity and traceability unit performs integrity verification on data packets. The data life cycle security management module includes a sensitive data identification and classification unit, a dynamic desensitization and encryption unit, and a data retention and destruction unit. The sensitive data identification and classification unit automatically identifies sensitive data fields in the system and classifies them according to security levels. The dynamic desensitization and encryption unit implements dynamic desensitization processing on sensitive data and restores plaintext data for business processing under authorization. The data retention and destruction unit manages the retention period of data. The security monitoring and compliance audit module includes an abnormal behavior detection unit, a compliance policy management unit, and a full-link audit and alarm unit. The abnormal behavior detection unit analyzes user access behavior and data traffic characteristics in real time and identifies abnormal access patterns. The compliance policy management unit maintains and dynamically updates privacy protection policies, defines compliance boundaries for data collection, storage, and sharing. The full-link audit and alarm unit records all operations in real time and generates complete audit logs.
2. The service system of a business hall supporting multi-user secure data stream communication according to claim 1, wherein, The multi-tenant data isolation unit comprises a tenant space allocation processor, an isolation boundary manager and a conflict detection processor, the tenant space allocation processor is used for allocating independent data storage space and computing resources for each user or user group, and natural isolation of data access is ensured through logical partitioning or physical isolation mechanism, the isolation boundary manager is used for maintaining and enforcing access boundary strategy between tenants, monitoring cross-tenant data access requests, and preventing unauthorized data cross-domain operation, and the conflict detection processor is used for detecting data operation conflicts in real time in a multi-user concurrent access scenario; The tenant space allocator calculates a resource isolation index R for a tenant u according to the following formula u : ; where H u is the historical security behavior score of user u, H thr is the security boundary threshold, k is the steepness parameter, m is the number of data types currently stored by user u, S j is the sensitivity level coefficient of the jth type of data, V j is the storage capacity of the jth type of data, V total is the total storage capacity of the user, is the concurrent conflict penalty function, C u represents the number of data conflicts that have occurred to user u within the recent time window.
3. The service system of a business hall supporting multi-user secure data stream communication according to claim 2, wherein, When the conflict detection processor detects that multiple users concurrently access the same data resource, a concurrent risk coefficient CRC is calculated according to the following formula: ; where N con is the number of users currently accessing the data resource concurrently, N thr is a concurrent threshold number set by the system, R max and R min are the maximum and minimum values of the resource isolation index of concurrent users, respectively, represents the time interval between the current access and the last access of the ith concurrent user, represents the average session duration of the ith concurrent user, and w1, w2, and w3 are weight coefficients. When the CRC exceeds a safety threshold, the system forces the access of the first trusted user to be downgraded to read-only or delayed processing, and the isolation boundary manager executes an access isolation strategy.
4. The service system of a business hall supporting multi-user secure data stream communication according to claim 3, wherein, The abnormal behavior detection unit comprises a behavior feature extraction processor, an abnormal pattern recognition engine and a threat scoring processor, the behavior feature extraction processor is used for extracting key behavior features from user access logs and constructing a user behavior portrait, the abnormal pattern recognition engine is used for establishing a normal behavior baseline model, comparing the deviation of the current behavior from the baseline in real time, and identifying abnormal access patterns, and the threat scoring processor is used for quantitatively evaluating the risk of the detected abnormal behavior, combining threat intelligence and historical security events, and calculating a threat level score; The behavior feature extraction processor calculates the time-series behavior entropy TBE of the user u according to the following formula u : ; wherein T is the total number of time slices within the observation time window, p t is the frequency of the user initiating access within the tth time slice, A t is the number of operation types within the tth time slice, is the jump sensitive coefficient.
5. The service system of a business hall supporting multi-user secure data stream communication according to claim 4, wherein, The anomaly pattern recognition engine computes the anomaly deviation degree ABD of the current behavior of the user u according to the following formula u : ; TBE cur is the time-based entropy of the current time window of the user, TBE bas is the historical time-based entropy mean of the user, is the standard deviation of the historical time-based entropy, CRC avg is the recent average concurrent risk coefficient of the user, , and are the deviation tolerance coefficients of different degrees, > > R safe and R high are the isolation degree threshold values, is the first-level amplification coefficient, is the second-level amplification coefficient. When the ABD exceeds a preset threshold, the abnormal pattern recognition engine determines that the current behavior of the user is abnormal behavior.
Citation Information
Patent Citations
Multi-tenant identity and data security management cloud service
CN107852417A
Access control and encryption in multi-user systems
US7792301B2
Cited By
Secret document output security control method and system based on security classification dynamic identification
CN121834865A
Security management and control method and system for secret-related document output based on secret level dynamic identification
CN121834865B
Hierarchical role permission dynamic authorization management and control system and method
CN122114752A